This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Full of Trojans!

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My daughter has a new HP dv7 1275 Pavilion notebook running Vista Home premium 64 bit. She googled something and was swamped with viruses when she connected to the link. She received a notification and I am not sure if it was actually the Trend anti-virus, Vista or a trojan window trying to get her to download more. I ranTrend anti-virus that came with the computer and it doesn't detect anything. Great. I ran malwarebytes and only 2 things were selected and both were Hijack related so I didn't do anything. I ran hijack this and had it analyzed at another site and it shows a lot of infection. Here is the Hijack log below. We are grateful for your assistance. Thank you.



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:31:48 PM, on 8/3/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18813)
Boot mode:Normal

Running processes:
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe
C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe
C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files (x86)\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files (x86)\Hp\HP Software Update\hpwuSchd2.exe
C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files (x86)\Hewlett-Packard\Media\TV\TVAgent.exe
C:\Program Files (x86)\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\SysWow64\Macromed\Flash\FlashUtil10b.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf=cnnb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://refdesk.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf=cnnb
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf=cnnb
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Microsoft Live Search Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0541.0\msneshellx.dll
O3 - Toolbar: Microsoft Live Search Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0541.0\msneshellx.dll
O4 - HKLM\..\Run: [DVDAgent] "C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe"
O4 - HKLM\..\Run: [TSMAgent] "C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe"
O4 - HKLM\..\Run: [CLMLServer for HP TouchSmart] "C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe"
O4 - HKLM\..\Run: [UpdateLBPShortCut] "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
O4 - HKLM\..\Run: [UpdatePSTShortCut] "C:\Program Files (x86)\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"
O4 - HKLM\..\Run: [QlbCtrl.exe] "C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" /Start
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [UpdateP2GoShortCut] "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
O4 - HKLM\..\Run: [UpdatePDIRShortCut] "C:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\PowerDirector" UpdateWithCreateOnce "SOFTWARE\CyberLink\PowerDirector\7.0"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Hewlett-Packard\Media\Webcam" update "Software\Hewlett-Packard\Media\Webcam"
O4 - HKLM\..\Run: [TVAgent] "C:\Program Files (x86)\Hewlett-Packard\Media\TV\TVAgent.exe"
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~2\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~2\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20270.www2.hp.com/ediags/gmn2/inst…tDetection2.cab
O23 - Service: Andrea ST Filters Service (AESTFilters) - Unknown owner - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_bd5387da\AESTSr64.exe (file missing)
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Unknown owner - C:\Windows\system32\agr64svc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\Windows\system32\Hpservice.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Recovery Service for Windows - Unknown owner - C:\Program Files (x86)\SMINST\BLService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: Audio Service (STacSV) - Unknown owner - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_bd5387da\STacSV64.exe (file missing)
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
O23 - Service: TV Background Capture Service (TVBCS) (TVCapSvc) - Unknown owner - C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe
O23 - Service: TV Task Scheduler (TVTS) (TVSched) - Unknown owner - C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 11356 bytes

I ran hijack this and had it analyzed at another site and it shows a lot of infection

?? what site (if it was an online scanner - ignore it) - I don't see any infection showing in that log, let's take a deeper look

can you also describe exactly what symptoms she is experiencing?

(you may have encountered strange results because you are running a 64 bit syatem)

Please run the Malwarebytes program again, allow it to update and allow it to remove what it finds and post the resulting log,

then run this following program

For vista machines

As a Vista user I will require that all the programs I ask you to run, be run by right clicking the icon and selecting Run as Administrator. Otherwise some programs may fail to operate correctly


  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
the site I used to parse the HiJack this log is hjt.networktechs.com. (I am not a geek) logo on their web page.

Here is the OTL.txt and the Extras.txt logs below:

OTL logfile created on: 8/3/2009 9:16:07 PM - Run 1
OTL by OldTimer - Version 3.0.10.4 Folder = C:\Users\Owner\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18813)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 2.23 Gb Available Physical Memory | 55.89% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 451.78 Gb Total Space | 302.19 Gb Free Space | 66.89% Space Free | Partition Type: NTFS
Drive D: | 13.98 Gb Total Space | 2.13 Gb Free Space | 15.22% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: OWNER-PC
Current User Name: Owner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
PRC - C:\Program Files (x86)\SMINST\BLService.exe ()
PRC - C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe ()
PRC - C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe ()
PRC - C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe ()
PRC - C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe (Hewlett-Packard Company)
PRC - C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe (CyberLink)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe ( Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files (x86)\Java\jre1.6.0_07\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files (x86)\Hp\HP Software Update\hpwuSchd2.exe (Hewlett-Packard)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files (x86)\Hewlett-Packard\Media\TV\TVAgent.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files (x86)\Internet Explorer\IELowutil.exe (Microsoft Corporation)
PRC - C:\Users\Owner\Desktop\OTL.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV:64bit: - (AESTFilters [Auto | Running]) – C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_bd5387da\AESTSr64.exe ()
SRV:64bit: - (AgereModemAudio [Auto | Running]) – C:\Windows\SysNative\agr64svc.exe ()
SRV:64bit: - (BthServ [Auto | Running]) – C:\Windows\SysNative\bthserv.dll ()
SRV:64bit: - (hpsrv [Auto | Running]) – C:\Windows\SysNative\Hpservice.exe ()
SRV:64bit: - (SfCtlCom [Auto | Running]) – C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe (Trend Micro Inc.)
SRV:64bit: - (STacSV [Auto | Running]) – C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_bd5387da\STacSV64.exe ()
SRV:64bit: - (TMBMServer [Auto | Running]) – C:\Program Files\Trend Micro\BM\TMBMSRV.exe (Trend Micro Inc.)
SRV:64bit: - (tmproxy [On_Demand | Running]) – C:\Program Files\Trend Micro\Internet Security\TmProxy.exe (Trend Micro Inc.)
SRV:64bit: - (WinDefend [Auto | Running]) – C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SRV:64bit: - (WMPNetworkSvc [On_Demand | Running]) – C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_64 [On_Demand | Stopped]) – C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (Com4QLBEx [On_Demand | Running]) – C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe (Hewlett-Packard Development Company, L.P.)
SRV - (ehRecvr [On_Demand | Stopped]) – C:\Windows\ehome\ehRecvr.exe (Microsoft Corporation)
SRV - (ehSched [On_Demand | Stopped]) – C:\Windows\ehome\ehsched.exe (Microsoft Corporation)
SRV - (ehstart [Auto | Stopped]) – C:\Windows\ehome\ehstart.dll (Microsoft Corporation)
SRV - (FontCache3.0.0.0 [On_Demand | Running]) – C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (GameConsoleService [On_Demand | Stopped]) – C:\Program Files (x86)\HP Games\My HP Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (HP Health Check Service [Auto | Running]) – c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe (Hewlett-Packard)
SRV - (hpqwmiex [On_Demand | Running]) – C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe (Hewlett-Packard Development Company, L.P.)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (idsvc [Unknown | Stopped]) – C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (KeyIso [On_Demand | Running]) – C:\Windows\SysWow64\keyiso.dll (Microsoft Corporation)
SRV - (LightScribeService [Auto | Running]) – C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
SRV - (MSDTC [Unknown | Stopped]) – C:\Windows\SysWow64\Msdtc [2006/11/02 08:34:14 | 00,000,000 | —D | M]
SRV - (Netlogon [On_Demand | Stopped]) – C:\Windows\SysWow64\netlogon.dll (Microsoft Corporation)
SRV - (odserv [On_Demand | Stopped]) – C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (Recovery Service for Windows [Auto | Running]) – C:\Program Files (x86)\SMINST\BLService.exe ()
SRV - (RichVideo [Auto | Running]) – C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe ()
SRV - (TVCapSvc [Auto | Running]) – C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe ()
SRV - (TVSched [Auto | Running]) – C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe ()
SRV - (vds [On_Demand | Stopped]) – C:\Windows\SysWow64\Wbem\vds.mof ()
SRV - (VSS [On_Demand | Stopped]) – C:\Windows\SysWow64\Wbem\vss.mof ()

========== Driver Services (SafeList) ==========

DRV:64bit: - (Accelerometer [On_Demand | Running]) – C:\Windows\SysNative\DRIVERS\Accelerometer.sys ()
DRV:64bit: - (AgereSoftModem [On_Demand | Running]) – C:\Windows\SysNative\DRIVERS\agrsm64.sys ()
DRV:64bit: - (BthEnum [On_Demand | Stopped]) – C:\Windows\SysNative\DRIVERS\BthEnum.sys ()
DRV:64bit: - (BthPan [On_Demand | Stopped]) – C:\Windows\SysNative\DRIVERS\bthpan.sys ()
DRV:64bit: - (BTHPORT [On_Demand | Stopped]) – C:\Windows\SysNative\Drivers\BTHport.sys ()
DRV:64bit: - (BTHUSB [On_Demand | Stopped]) – C:\Windows\SysNative\Drivers\BTHUSB.sys ()
DRV:64bit: - (CmBatt [On_Demand | Running]) – C:\Windows\SysNative\DRIVERS\CmBatt.sys ()
DRV:64bit: - (enecir [On_Demand | Running]) – C:\Windows\SysNative\DRIVERS\enecir.sys ()
DRV:64bit: - (HdAudAddService [On_Demand | Stopped]) – C:\Windows\SysNative\drivers\HdAudio.sys ()
DRV:64bit: - (hpdskflt [Boot | Running]) – C:\Windows\SysNative\DRIVERS\hpdskflt.sys ()
DRV:64bit: - (HpqKbFiltr [On_Demand | Running]) – C:\Windows\SysNative\DRIVERS\HpqKbFiltr.sys ()
DRV:64bit: - (JMCR [On_Demand | Stopped]) – C:\Windows\SysNative\DRIVERS\jmcr.sys ()
DRV:64bit: - (NETw3v64 [On_Demand | Stopped]) – C:\Windows\SysNative\DRIVERS\NETw3v64.sys ()
DRV:64bit: - (NETw5v64 [On_Demand | Running]) – C:\Windows\SysNative\DRIVERS\NETw5v64.sys ()
DRV:64bit: - (NVHDA [On_Demand | Running]) – C:\Windows\SysNative\drivers\nvhda64v.sys ()
DRV:64bit: - (RFCOMM [On_Demand | Stopped]) – C:\Windows\SysNative\DRIVERS\rfcomm.sys ()
DRV:64bit: - (RTL8169 [On_Demand | Running]) – C:\Windows\SysNative\DRIVERS\Rtlh64.sys ()
DRV:64bit: - (sdbus [On_Demand | Stopped]) – C:\Windows\SysNative\DRIVERS\sdbus.sys ()
DRV:64bit: - (STHDA [On_Demand | Running]) – C:\Windows\SysNative\DRIVERS\stwrt64.sys ()
DRV:64bit: - (SynTP [On_Demand | Running]) – C:\Windows\SysNative\DRIVERS\SynTP.sys ()
DRV:64bit: - (tmpreflt [Auto | Running]) – C:\Windows\SysNative\DRIVERS\tmpreflt.sys ()
DRV:64bit: - (tmtdi [System | Running]) – C:\Windows\SysNative\DRIVERS\tmtdi.sys ()
DRV:64bit: - (tmxpflt [Auto | Running]) – C:\Windows\SysNative\DRIVERS\tmxpflt.sys ()
DRV:64bit: - (usbvideo [On_Demand | Running]) – C:\Windows\SysNative\Drivers\usbvideo.sys ()
DRV:64bit: - (vsapint [Auto | Running]) – C:\Windows\SysNative\DRIVERS\vsapint.sys ()
DRV:64bit: - (yukonx64 [On_Demand | Stopped]) – C:\Windows\SysNative\DRIVERS\yk60x64.sys ()
DRV - (mpsdrv [On_Demand | Running]) – C:\Windows\SysWow64\Wbem\mpsdrv.mof ()
DRV - (Tcpip [Boot | Running]) – C:\Windows\SysWow64\Wbem\tcpip.mof ()
DRV - ({55662437-DA8C-40c0-AADA-2C816A897A49} [Auto | Running]) – C:\Program Files (x86)\Hewlett-Packard\Media\DVD\000.fcl (Cyberlink Corp.)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf=cnnb
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\System32\blank.htm
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf=cnnb
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf=cnnb
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf=cnnb

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf=cnnb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://refdesk.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/07/21 23:50:55 | 00,000,000 | —D | M]


O1 HOSTS File: (761 bytes) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Microsoft Live Search Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0541.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (Microsoft Live Search Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0541.0\msneshellx.dll (Microsoft Corp.)
O4:64bit: - HKLM..\Run: [NvCplDaemon] C:\Windows\SysNative\NvCpl.DLL ()
O4:64bit: - HKLM..\Run: [NvMediaCenter] C:\Windows\SysNative\NvMcTray.DLL ()
O4:64bit: - HKLM..\Run: [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe (Hewlett-Packard)
O4:64bit: - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4:64bit: - HKLM..\Run: [UfSeAgnt.exe] C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe (Trend Micro Inc.)
O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [CLMLServer for HP TouchSmart] C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe (CyberLink)
O4 - HKLM..\Run: [DVDAgent] C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe (CyberLink Corp.)
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe (Hewlett-Packard)
O4 - HKLM..\Run: [hpWirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [QlbCtrl.exe] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe ( Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files (x86)\Java\jre1.6.0_07\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [TSMAgent] C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe (CyberLink Corp.)
O4 - HKLM..\Run: [TVAgent] C:\Program Files (x86)\Hewlett-Packard\Media\TV\TVAgent.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UCam_Menu] C:\Program Files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateLBPShortCut] C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateP2GoShortCut] C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePDIRShortCut] C:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePSTShortCut] C:\Program Files (x86)\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKCU..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe (Microsoft Corporation)
O4 - HKCU..\Run: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe (Hewlett-Packard Company)
O4 - HKCU..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceActiveDesktopOn = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
O8:64bit: - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre1.6.0_07\bin\npjpi160_07.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files (x86)\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Windows\SysNative\wshbth.dll ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Windows\SysWow64\wshbth.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20270.www2.hp.com/ediags/gmn2/inst…tDetection2.cab (GMNRev Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll ()
O18:64bit: - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll ()
O18:64bit: - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll ()
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll ()
O18:64bit: - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll ()
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files (x86)\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files (x86)\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\Windows\SysWow64\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found

========== Files/Folders - Created Within 30 Days ==========

[2009/08/03 21:13:05 | 00,514,048 | —- | C] (OldTimer Tools) – C:\Users\Owner\Desktop\OTL.exe
[2009/08/03 17:37:36 | 00,000,000 | —D | C] – C:\Users\Owner\AppData\Roaming\Malwarebytes
[2009/08/03 17:37:34 | 00,000,848 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/08/03 17:37:32 | 00,038,160 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2009/08/03 17:37:30 | 00,022,040 | —- | C] () – C:\Windows\SysNative\drivers\mbam.sys
[2009/08/03 17:37:30 | 00,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2009/08/03 17:37:30 | 00,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2009/08/03 17:31:39 | 00,001,928 | —- | C] () – C:\Users\Owner\Desktop\HijackThis.lnk
[2009/08/03 17:31:38 | 00,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2009/07/28 15:40:07 | 09,233,408 | —- | C] () – C:\Windows\SysNative\mshtml.dll
[2009/07/28 15:40:07 | 05,937,152 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtml.dll
[2009/07/28 15:40:06 | 11,067,392 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieframe.dll
[2009/07/28 15:40:05 | 12,458,496 | —- | C] () – C:\Windows\SysNative\ieframe.dll
[2009/07/28 15:40:04 | 02,334,208 | —- | C] () – C:\Windows\SysNative\iertutil.dll
[2009/07/28 15:40:04 | 01,985,536 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iertutil.dll
[2009/07/28 15:40:04 | 01,484,288 | —- | C] () – C:\Windows\SysNative\urlmon.dll
[2009/07/28 15:40:04 | 01,208,832 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\urlmon.dll
[2009/07/28 15:40:04 | 01,146,880 | —- | C] () – C:\Windows\SysNative\wininet.dll
[2009/07/28 15:40:04 | 00,915,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wininet.dll
[2009/07/28 15:40:04 | 00,594,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeeds.dll
[2009/07/28 15:40:04 | 00,458,240 | —- | C] () – C:\Windows\SysNative\iedkcs32.dll
[2009/07/28 15:40:04 | 00,243,712 | —- | C] () – C:\Windows\SysNative\occache.dll
[2009/07/28 15:40:04 | 00,206,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\occache.dll
[2009/07/28 15:40:03 | 01,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtml.tlb
[2009/07/28 15:40:03 | 01,638,912 | —- | C] () – C:\Windows\SysNative\mshtml.tlb
[2009/07/28 15:40:03 | 01,538,560 | —- | C] () – C:\Windows\SysNative\inetcpl.cpl
[2009/07/28 15:40:03 | 01,469,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2009/07/28 15:40:03 | 00,700,928 | —- | C] () – C:\Windows\SysNative\msfeeds.dll
[2009/07/28 15:40:03 | 00,386,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iedkcs32.dll
[2009/07/28 15:40:03 | 00,252,416 | —- | C] () – C:\Windows\SysNative\iepeers.dll
[2009/07/28 15:40:03 | 00,219,136 | —- | C] () – C:\Windows\SysNative\ieui.dll
[2009/07/28 15:40:03 | 00,184,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2009/07/28 15:40:03 | 00,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ie4uinit.exe
[2009/07/28 15:40:03 | 00,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2009/07/28 15:40:03 | 00,162,816 | —- | C] () – C:\Windows\SysNative\ieUnatt.exe
[2009/07/28 15:40:03 | 00,133,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2009/07/28 15:40:03 | 00,132,096 | —- | C] () – C:\Windows\SysNative\iesysprep.dll
[2009/07/28 15:40:03 | 00,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2009/07/28 15:40:03 | 00,077,312 | —- | C] () – C:\Windows\SysNative\iesetup.dll
[2009/07/28 15:40:03 | 00,072,192 | —- | C] () – C:\Windows\SysNative\iernonce.dll
[2009/07/28 15:40:03 | 00,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2009/07/28 15:40:03 | 00,071,680 | —- | C] () – C:\Windows\SysNative\msfeedsbs.dll
[2009/07/28 15:40:03 | 00,070,656 | —- | C] () – C:\Windows\SysNative\ie4uinit.exe
[2009/07/28 15:40:03 | 00,057,667 | —- | C] () – C:\Windows\SysWow64\ieuinit.inf
[2009/07/28 15:40:03 | 00,057,667 | —- | C] () – C:\Windows\SysNative\ieuinit.inf
[2009/07/28 15:40:03 | 00,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2009/07/28 15:40:03 | 00,055,296 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedsbs.dll
[2009/07/28 15:40:03 | 00,031,744 | —- | C] () – C:\Windows\SysNative\jsproxy.dll
[2009/07/28 15:40:03 | 00,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jsproxy.dll
[2009/07/28 15:40:03 | 00,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2009/07/28 15:40:03 | 00,012,288 | —- | C] () – C:\Windows\SysNative\msfeedssync.exe
[2009/07/27 14:08:34 | 00,000,966 | —- | C] () – C:\Users\Owner\Desktop\Auslogics BoostSpeed.lnk
[2009/07/27 13:47:41 | 00,000,000 | —D | C] – C:\Users\Owner\AppData\Local\Adobe
[2009/07/27 13:22:16 | 00,000,000 | —D | C] – C:\Users\Owner\AppData\Roaming\Auslogics
[2009/07/27 13:22:13 | 00,000,971 | —- | C] () – C:\Users\Owner\Desktop\Auslogics Disk Defrag.lnk
[2009/07/27 13:22:12 | 00,000,000 | —D | C] – C:\Program Files (x86)\Auslogics
[2009/07/22 16:12:46 | 00,031,871 | —- | C] () – C:\ProgramData\nvModes.dat
[2009/07/22 16:12:46 | 00,031,871 | —- | C] () – C:\ProgramData\nvModes.001
[2009/07/22 00:28:47 | 00,000,000 | —D | C] – C:\Users\Owner\Documents\reg backup
[2009/07/22 00:23:00 | 00,000,892 | —- | C] () – C:\Users\Owner\Desktop\Eusing Free Registry Cleaner.lnk
[2009/07/22 00:22:59 | 00,000,000 | —D | C] – C:\Program Files (x86)\Eusing Free Registry Cleaner
[2009/07/21 23:56:41 | 00,000,680 | —- | C] () – C:\Users\Owner\AppData\Local\d3d9caps.dat
[2009/07/21 23:45:25 | 00,049,160 | —- | C] () – C:\Windows\SysNative\infocardcpl.cpl
[2009/07/21 23:45:24 | 00,037,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\infocardcpl.cpl
[2009/07/21 23:45:12 | 00,011,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\icardres.dll
[2009/07/21 23:45:12 | 00,011,264 | —- | C] () – C:\Windows\SysNative\icardres.dll
[2009/07/21 23:45:11 | 00,052,760 | —- | C] () – C:\Windows\SysNative\PresentationHostProxy.dll
[2009/07/21 23:45:11 | 00,043,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PresentationHostProxy.dll
[2009/07/21 23:45:10 | 01,168,928 | —- | C] () – C:\Windows\SysNative\PresentationNative_v0300.dll
[2009/07/21 23:45:10 | 00,781,344 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PresentationNative_v0300.dll
[2009/07/21 23:45:10 | 00,167,432 | —- | C] () – C:\Windows\SysNative\infocardapi.dll
[2009/07/21 23:45:09 | 01,383,936 | —- | C] () – C:\Windows\SysNative\icardagt.exe
[2009/07/21 23:45:09 | 00,622,080 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\icardagt.exe
[2009/07/21 23:45:09 | 00,097,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\infocardapi.dll
[2009/07/21 23:44:59 | 00,126,520 | —- | C] () – C:\Windows\SysNative\PresentationCFFRasterizerNative_v0300.dll
[2009/07/21 23:44:59 | 00,105,016 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PresentationCFFRasterizerNative_v0300.dll
[2009/07/21 23:44:55 | 00,357,904 | —- | C] () – C:\Windows\SysNative\PresentationHost.exe
[2009/07/21 23:44:55 | 00,326,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PresentationHost.exe
[2009/07/21 23:36:40 | 00,041,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\netfxperf.dll
[2009/07/21 23:36:40 | 00,013,824 | —- | C] () – C:\Windows\SysNative\netfxperf.dll
[2009/07/21 23:36:23 | 00,112,120 | —- | C] () – C:\Windows\SysNative\dfshim.dll
[2009/07/21 23:36:23 | 00,096,760 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dfshim.dll
[2009/07/21 23:36:15 | 00,406,528 | —- | C] () – C:\Windows\SysNative\mscoree.dll
[2009/07/21 23:36:15 | 00,282,112 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mscoree.dll
[2009/07/21 23:36:02 | 00,158,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mscorier.dll
[2009/07/21 23:36:02 | 00,158,208 | —- | C] () – C:\Windows\SysNative\mscorier.dll
[2009/07/21 23:35:58 | 00,076,288 | —- | C] () – C:\Windows\SysNative\mscories.dll
[2009/07/21 23:35:56 | 00,083,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mscories.dll
[2009/07/21 16:17:28 | 00,000,000 | —D | C] – C:\Users\Owner\AppData\Roaming\Reg Tool
[2009/07/21 16:17:06 | 00,000,000 | —D | C] – C:\Program Files (x86)\Reg Tool
[2009/07/19 14:00:57 | 00,000,000 | —D | C] – C:\Program Files (x86)\MSXML 4.0
[2009/07/19 13:58:48 | 00,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\tzres.dll
[2009/07/19 13:58:48 | 00,002,048 | —- | C] () – C:\Windows\SysNative\tzres.dll
[2009/07/18 11:29:27 | 00,558,592 | —- | C] () – C:\Windows\SysNative\EncDec.dll
[2009/07/18 11:29:26 | 00,428,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\EncDec.dll
[2009/07/18 11:29:26 | 00,289,792 | —- | C] () – C:\Windows\SysNative\psisrndr.ax
[2009/07/18 11:29:26 | 00,217,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\psisrndr.ax
[2009/07/18 11:29:25 | 00,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\psisdecd.dll
[2009/07/18 11:29:23 | 00,375,808 | —- | C] () – C:\Windows\SysNative\psisdecd.dll
[2009/07/18 11:29:23 | 00,227,328 | —- | C] () – C:\Windows\SysNative\mpg2splt.ax
[2009/07/18 11:29:23 | 00,177,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mpg2splt.ax
[2009/07/18 11:29:23 | 00,101,376 | —- | C] () – C:\Windows\SysNative\MSNP.ax
[2009/07/18 11:29:23 | 00,080,896 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MSNP.ax
[2009/07/18 11:28:19 | 01,280,512 | —- | C] () – C:\Windows\SysNative\rpcrt4.dll
[2009/07/18 11:28:19 | 00,677,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\rpcrt4.dll
[2009/07/18 11:28:14 | 00,451,584 | —- | C] () – C:\Windows\SysNative\drivers\srv.sys
[2009/07/18 11:28:13 | 01,691,648 | —- | C] () – C:\Windows\SysNative\connect.dll
[2009/07/18 11:28:12 | 01,645,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\connect.dll
[2009/07/18 11:28:11 | 01,809,408 | —- | C] () – C:\Windows\SysNative\msxml3.dll
[2009/07/18 11:28:11 | 01,191,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msxml3.dll
[2009/07/18 11:27:53 | 00,791,552 | —- | C] () – C:\Windows\SysNative\localspl.dll
[2009/07/18 11:27:53 | 00,636,928 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\localspl.dll
[2009/07/18 11:27:51 | 00,439,808 | —- | C] () – C:\Windows\SysNative\winhttp.dll
[2009/07/18 11:27:51 | 00,376,832 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\winhttp.dll
[2009/07/18 11:27:49 | 00,334,336 | —- | C] () – C:\Windows\SysNative\schannel.dll
[2009/07/18 11:27:49 | 00,268,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\schannel.dll
[2009/07/18 11:27:40 | 01,208,832 | —- | C] () – C:\Windows\SysNative\kernel32.dll
[2009/07/18 11:27:39 | 01,691,648 | —- | C] () – C:\Windows\SysNative\lsasrv.dll
[2009/07/18 11:27:38 | 00,855,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\kernel32.dll
[2009/07/18 11:27:38 | 00,094,720 | —- | C] () – C:\Windows\SysNative\secur32.dll
[2009/07/18 11:27:38 | 00,076,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\secur32.dll
[2009/07/18 11:27:38 | 00,025,600 | —- | C] () – C:\Windows\SysNative\amxread.dll
[2009/07/18 11:27:38 | 00,024,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\amxread.dll
[2009/07/18 11:27:38 | 00,015,872 | —- | C] () – C:\Windows\SysNative\apilogen.dll
[2009/07/18 11:27:38 | 00,013,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\apilogen.dll
[2009/07/18 11:27:30 | 00,388,608 | —- | C] () – C:\Windows\SysNative\gdi32.dll
[2009/07/18 11:27:30 | 00,303,104 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\gdi32.dll
[2009/07/18 11:27:28 | 01,729,024 | —- | C] () – C:\Windows\SysNative\msxml6.dll
[2009/07/18 11:27:28 | 01,334,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msxml6.dll
[2009/07/18 11:27:26 | 00,272,896 | —- | C] () – C:\Windows\SysNative\drivers\mrxsmb10.sys
[2009/07/18 11:27:24 | 00,324,608 | —- | C] () – C:\Windows\SysNative\PortableDeviceApi.dll
[2009/07/18 11:27:24 | 00,241,152 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PortableDeviceApi.dll
[2009/07/18 11:27:22 | 02,742,272 | —- | C] () – C:\Windows\SysNative\win32k.sys
[2009/07/18 11:27:18 | 04,692,448 | —- | C] () – C:\Windows\SysNative\ntoskrnl.exe
[2009/07/18 11:27:18 | 01,030,656 | —- | C] () – C:\Windows\SysNative\printfilterpipelinesvc.exe
[2009/07/18 11:27:17 | 00,718,336 | —- | C] () – C:\Windows\SysNative\rpcss.dll
[2009/07/18 11:27:16 | 00,231,424 | —- | C] () – C:\Windows\SysNative\sdohlp.dll
[2009/07/18 11:27:16 | 00,183,296 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\sdohlp.dll
[2009/07/18 11:27:16 | 00,163,840 | —- | C] () – C:\Windows\SysNative\iasrecst.dll
[2009/07/18 11:27:16 | 00,098,304 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iasrecst.dll
[2009/07/18 11:27:16 | 00,075,776 | —- | C] () – C:\Windows\SysNative\iasads.dll
[2009/07/18 11:27:16 | 00,061,440 | —- | C] () – C:\Windows\SysNative\iasdatastore.dll
[2009/07/18 11:27:16 | 00,054,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iasads.dll
[2009/07/18 11:27:16 | 00,044,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iasdatastore.dll
[2009/07/18 11:27:16 | 00,036,352 | —- | C] () – C:\Windows\SysNative\printfilterpipelineprxy.dll
[2009/07/18 11:27:16 | 00,024,576 | —- | C] () – C:\Windows\SysNative\iashost.exe
[2009/07/18 11:27:16 | 00,017,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iashost.exe
[2009/07/18 11:27:06 | 03,080,704 | —- | C] (Microsoft Corporation) – C:\Windows\explorer.exe
[2009/07/18 11:27:06 | 02,927,104 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\explorer.exe
[2009/07/18 11:27:04 | 00,366,080 | —- | C] () – C:\Windows\SysNative\atmfd.dll
[2009/07/18 11:27:04 | 00,289,792 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\atmfd.dll
[2009/07/18 11:27:04 | 00,189,440 | —- | C] () – C:\Windows\SysNative\t2embed.dll
[2009/07/18 11:27:04 | 00,156,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\t2embed.dll
[2009/07/18 11:27:04 | 00,096,256 | —- | C] () – C:\Windows\SysNative\fontsub.dll
[2009/07/18 11:27:04 | 00,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\fontsub.dll
[2009/07/18 11:27:04 | 00,048,128 | —- | C] () – C:\Windows\SysNative\atmlib.dll
[2009/07/18 11:27:04 | 00,010,240 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dciman32.dll
[2009/07/18 11:27:01 | 02,868,736 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mf.dll
[2009/07/18 11:27:00 | 03,547,648 | —- | C] () – C:\Windows\SysNative\mf.dll
[2009/07/18 11:26:59 | 02,900,480 | —- | C] () – C:\Windows\SysNative\WMVCORE.DLL
[2009/07/18 11:26:59 | 02,386,944 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\WMVCORE.DLL
[2009/07/18 11:26:59 | 01,245,184 | —- | C] () – C:\Windows\SysNative\WMNetMgr.dll
[2009/07/18 11:26:59 | 00,996,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\WMNetMgr.dll
[2009/07/18 11:26:59 | 00,112,640 | —- | C] () – C:\Windows\SysNative\logagent.exe
[2009/07/18 11:26:59 | 00,094,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\logagent.exe
[2009/07/18 11:26:48 | 00,730,112 | —- | C] () – C:\Windows\SysNative\msdtcprx.dll
[2009/07/18 11:26:48 | 00,562,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msdtcprx.dll
[2009/07/18 11:26:48 | 00,048,640 | —- | C] () – C:\Windows\SysNative\xolehlp.dll
[2009/07/18 11:26:48 | 00,038,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xolehlp.dll
[2009/07/18 11:26:44 | 12,897,792 | —- | C] () – C:\Windows\SysNative\shell32.dll
[2009/07/18 11:26:42 | 11,580,928 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\shell32.dll
[2009/07/18 11:26:34 | 00,176,640 | —- | C] () – C:\Windows\SysNative\Faultrep.dll
[2009/07/18 11:26:34 | 00,147,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\Faultrep.dll
[2009/07/18 11:26:34 | 00,120,832 | —- | C] () – C:\Windows\SysNative\wersvc.dll
[2009/07/18 11:26:32 | 00,841,216 | —- | C] () – C:\Windows\SysNative\WindowsCodecs.dll
[2009/07/18 11:26:32 | 00,712,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\WindowsCodecs.dll
[2009/07/18 11:26:32 | 00,470,016 | —- | C] () – C:\Windows\SysNative\PhotoMetadataHandler.dll
[2009/07/18 11:26:32 | 00,425,472 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PhotoMetadataHandler.dll
[2009/07/18 11:26:32 | 00,386,560 | —- | C] () – C:\Windows\SysNative\WindowsCodecsExt.dll
[2009/07/18 11:26:32 | 00,347,136 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\WindowsCodecsExt.dll
[2009/07/17 22:24:04 | 00,000,000 | —D | C] – C:\Windows\SysNative\log
[2009/07/17 22:21:31 | 00,000,000 | -HSD | C] – C:\Users\Public\Documents\MCE Logs
[2009/07/17 22:08:38 | 00,161,792 | —- | C] () – C:\Windows\SysNative\advpack.dll
[2009/07/17 22:08:38 | 00,088,064 | —- | C] () – C:\Windows\SysNative\admparse.dll
[2009/07/17 22:08:38 | 00,022,528 | —- | C] () – C:\Windows\SysNative\corpol.dll
[2009/07/17 22:08:37 | 00,223,232 | —- | C] () – C:\Windows\SysNative\msls31.dll
[2009/07/17 22:08:37 | 00,157,696 | —- | C] () – C:\Windows\SysNative\ieakeng.dll
[2009/07/17 22:08:37 | 00,128,512 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\advpack.dll
[2009/07/17 22:08:37 | 00,125,952 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieakeng.dll
[2009/07/17 22:08:37 | 00,085,504 | —- | C] () – C:\Windows\SysNative\icardie.dll
[2009/07/17 22:08:37 | 00,077,824 | —- | C] () – C:\Windows\SysNative\tdc.ocx
[2009/07/17 22:08:37 | 00,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\admparse.dll
[2009/07/17 22:08:37 | 00,066,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\tdc.ocx
[2009/07/17 22:08:37 | 00,059,904 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\icardie.dll
[2009/07/17 22:08:37 | 00,018,944 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\corpol.dll
[2009/07/17 22:08:36 | 00,156,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msls31.dll
[2009/07/17 22:08:36 | 00,125,952 | —- | C] () – C:\Windows\SysNative\inseng.dll
[2009/07/17 22:08:36 | 00,076,288 | —- | C] () – C:\Windows\SysNative\wextract.exe
[2009/07/17 22:08:36 | 00,066,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wextract.exe
[2009/07/17 22:08:36 | 00,055,808 | —- | C] () – C:\Windows\SysNative\licmgr10.dll
[2009/07/17 22:08:36 | 00,052,736 | —- | C] () – C:\Windows\SysNative\imgutil.dll
[2009/07/17 22:08:35 | 00,508,416 | —- | C] () – C:\Windows\SysNative\dxtmsft.dll
[2009/07/17 22:08:35 | 00,481,280 | —- | C] () – C:\Windows\SysNative\ieapfltr.dll
[2009/07/17 22:08:35 | 00,445,952 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dll
[2009/07/17 22:08:35 | 00,348,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dxtmsft.dll
[2009/07/17 22:08:35 | 00,063,488 | —- | C] () – C:\Windows\SysNative\pngfilt.dll
[2009/07/17 22:08:35 | 00,046,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\pngfilt.dll
[2009/07/17 22:08:35 | 00,034,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\imgutil.dll
[2009/07/17 22:08:34 | 01,062,912 | —- | C] () – C:\Windows\SysNative\mstime.dll
[2009/07/17 22:08:34 | 00,611,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mstime.dll
[2009/07/17 22:08:34 | 00,318,464 | —- | C] () – C:\Windows\SysNative\dxtrans.dll
[2009/07/17 22:08:34 | 00,216,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dxtrans.dll
[2009/07/17 22:08:34 | 00,096,768 | —- | C] () – C:\Windows\SysNative\mshtmled.dll
[2009/07/17 22:08:33 | 00,304,640 | —- | C] () – C:\Windows\SysNative\webcheck.dll
[2009/07/17 22:08:33 | 00,271,872 | —- | C] () – C:\Windows\SysNative\ieaksie.dll
[2009/07/17 22:08:33 | 00,241,664 | —- | C] () – C:\Windows\SysNative\msrating.dll
[2009/07/17 22:08:33 | 00,236,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\webcheck.dll
[2009/07/17 22:08:33 | 00,229,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieaksie.dll
[2009/07/17 22:08:33 | 00,193,536 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msrating.dll
[2009/07/17 22:08:33 | 00,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieakui.dll
[2009/07/17 22:08:33 | 00,163,840 | —- | C] () – C:\Windows\SysNative\ieakui.dll
[2009/07/17 22:08:33 | 00,131,584 | —- | C] () – C:\Windows\SysNative\PDMSetup.exe
[2009/07/17 22:08:33 | 00,129,024 | —- | C] () – C:\Windows\SysNative\RegisterIEPKEYs.exe
[2009/07/17 22:08:33 | 00,128,512 | —- | C] () – C:\Windows\SysNative\SetIEInstalledDate.exe
[2009/07/17 22:08:33 | 00,125,440 | —- | C] () – C:\Windows\SysNative\SetDepNx.exe
[2009/07/17 22:08:33 | 00,094,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inseng.dll
[2009/07/17 22:08:33 | 00,066,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2009/07/17 22:08:33 | 00,043,008 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2009/07/17 22:08:33 | 00,041,984 | —- | C] () – C:\Windows\SysNative\mshta.exe
[2009/07/17 22:08:32 | 00,817,664 | —- | C] () – C:\Windows\SysNative\jscript.dll
[2009/07/17 22:08:32 | 00,726,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2009/07/17 22:08:32 | 00,612,864 | —- | C] () – C:\Windows\SysNative\vbscript.dll
[2009/07/17 22:08:32 | 00,420,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\vbscript.dll
[2009/07/17 22:08:32 | 00,278,528 | —- | C] () – C:\Windows\SysNative\WinFXDocObj.exe
[2009/07/17 22:08:32 | 00,208,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\WinFXDocObj.exe
[2009/07/17 22:08:31 | 00,108,032 | —- | C] () – C:\Windows\SysNative\url.dll
[2009/07/17 22:08:31 | 00,105,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2009/07/17 22:08:31 | 00,048,128 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmler.dll
[2009/07/17 22:08:31 | 00,048,128 | —- | C] () – C:\Windows\SysNative\mshtmler.dll
[2009/07/17 22:08:30 | 00,385,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2009/07/17 22:08:29 | 00,479,744 | —- | C] () – C:\Windows\SysNative\html.iec
[2009/07/17 22:08:28 | 00,045,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshta.exe
[2009/07/17 22:08:27 | 03,698,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dat
[2009/07/17 22:08:27 | 03,698,584 | —- | C] () – C:\Windows\SysNative\ieapfltr.dat
[2009/07/17 22:08:27 | 00,169,472 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iexpress.exe
[2009/07/17 22:08:27 | 00,107,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2009/07/17 22:08:27 | 00,107,008 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\SetIEInstalledDate.exe
[2009/07/17 22:08:27 | 00,103,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\SetDepNx.exe
[2009/07/17 22:08:26 | 00,193,536 | —- | C] () – C:\Windows\SysNative\iexpress.exe
[2009/07/17 22:08:26 | 00,109,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PDMSetup.exe
[2009/07/17 22:06:53 | 00,032,256 | —- | C] () – C:\Windows\SysNative\Apphlpdm.dll
[2009/07/17 22:06:53 | 00,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\Apphlpdm.dll
[2009/07/17 22:06:52 | 04,240,384 | —- | C] (Microsoft) – C:\Windows\SysWow64\GameUXLegacyGDFs.dll
[2009/07/17 22:06:52 | 04,240,384 | —- | C] () – C:\Windows\SysNative\GameUXLegacyGDFs.dll
[2009/07/17 21:07:54 | 00,000,000 | —D | C] – C:\Users\Owner\AppData\Roaming\Macromedia
[2009/07/17 21:06:44 | 02,289,688 | —- | C] () – C:\Windows\SysNative\wuaueng.dll
[2009/07/17 21:06:44 | 01,717,248 | —- | C] () – C:\Windows\SysNative\wucltux.dll
[2009/07/17 21:06:44 | 00,054,296 | —- | C] () – C:\Windows\SysNative\wuauclt.exe
[2009/07/17 21:06:44 | 00,043,032 | —- | C] () – C:\Windows\SysNative\wups2.dll
[2009/07/17 21:06:32 | 00,035,352 | —- | C] () – C:\Windows\SysNative\wups.dll
[2009/07/17 21:06:32 | 00,034,328 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wups.dll
[2009/07/17 21:06:31 | 00,685,592 | —- | C] () – C:\Windows\SysNative\wuapi.dll
[2009/07/17 21:06:31 | 00,561,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wuapi.dll
[2009/07/17 21:06:31 | 00,093,184 | —- | C] () – C:\Windows\SysNative\wudriver.dll
[2009/07/17 21:06:31 | 00,083,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wudriver.dll
[2009/07/17 21:06:19 | 00,175,376 | —- | C] () – C:\Windows\SysNative\wuwebv.dll
[2009/07/17 21:06:19 | 00,162,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wuwebv.dll
[2009/07/17 21:06:19 | 00,033,792 | —- | C] () – C:\Windows\SysNative\wuapp.exe
[2009/07/17 21:06:19 | 00,031,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wuapp.exe
[2009/07/17 05:12:23 | 00,000,000 | —D | C] – C:\Users\Owner\Documents\LDW
[2009/07/17 03:55:49 | 00,000,000 | —D | C] – C:\Users\Owner\Documents\Jojos Fashion Show
[2009/07/17 03:55:49 | 00,000,000 | —D | C] – C:\Users\Owner\AppData\Roaming\Gamelab
[2009/07/17 03:14:46 | 00,000,000 | —D | C] – C:\Users\Owner\AppData\Local\Microsoft Games
[2009/07/17 02:24:03 | 00,000,000 | —D | C] – C:\Users\Owner\Documents\Poker Superstars III - Gold Chip Challenge Documents
[2009/07/17 02:24:03 | 00,000,000 | —D | C] – C:\Users\Owner\AppData\Roaming\funkitron
[2009/07/16 22:16:08 | 00,000,000 | —D | C] – C:\Users\Owner\AppData\Roaming\Adobe
[2009/07/16 13:28:53 | 00,000,000 | —D | C] – C:\Users\Owner\AppData\Roaming\WildTangent
[2009/07/16 13:23:17 | 00,000,418 | -H– | C] () – C:\Windows\tasks\User_Feed_Synchronization-{18E75812-6A4E-4E32-A842-2174100493F0}.job
[2009/07/15 19:56:28 | 00,000,000 | —D | C] – C:\Users\Owner\AppData\Local\IsolatedStorage
[2009/07/15 19:35:49 | 00,000,000 | —D | C] – C:\Users\Owner\Documents\Webcam
[2009/07/15 19:35:38 | 00,000,000 | —D | C] – C:\Users\Owner\AppData\Roaming\CyberLink
[2009/07/15 19:10:07 | 00,008,704 | —- | C] () – C:\Users\Owner\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/07/15 18:51:26 | 00,000,944 | —- | C] () – C:\Users\Owner\Desktop\Windows Media Player.lnk
[2008/01/20 21:50:05 | 00,060,124 | —- | C] () – C:\Windows\SysWow64\tcpmon.ini
[2008/01/20 21:49:49 | 00,368,640 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2006/11/02 07:34:27 | 00,000,219 | —- | C] () – C:\Windows\system.ini
[2006/11/02 07:34:27 | 00,000,144 | —- | C] () – C:\Windows\win.ini

========== Files - Modified Within 30 Days ==========

[2009/08/03 21:16:26 | 00,000,761 | —- | M] () – C:\Windows\SysNative\drivers\etc\tmvsthfud.bin
[2009/08/03 21:16:25 | 00,000,761 | —- | M] () – C:\Windows\SysNative\drivers\etc\tmvsthfss.bin
[2009/08/03 21:15:26 | 00,003,216 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2009/08/03 21:15:26 | 00,003,216 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2009/08/03 21:13:08 | 00,514,048 | —- | M] (OldTimer Tools) – C:\Users\Owner\Desktop\OTL.exe
[2009/08/03 20:29:34 | 00,000,418 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{18E75812-6A4E-4E32-A842-2174100493F0}.job
[2009/08/03 17:37:34 | 00,000,848 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/08/03 17:31:39 | 00,001,928 | —- | M] () – C:\Users\Owner\Desktop\HijackThis.lnk
[2009/08/03 16:56:21 | 00,690,960 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2009/08/03 16:56:21 | 00,595,684 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2009/08/03 16:56:21 | 00,101,350 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2009/08/03 16:55:14 | 00,031,871 | —- | M] () – C:\ProgramData\nvModes.001
[2009/08/03 16:55:12 | 00,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2009/08/03 15:15:27 | 00,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2009/08/03 15:15:19 | 42,928,25088 | -HS- | M] () – C:\hiberfil.sys
[2009/08/03 15:14:34 | 00,000,012 | —- | M] () – C:\Windows\bthservsdp.dat
[2009/08/03 13:36:28 | 00,038,160 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2009/08/03 13:36:08 | 00,022,040 | —- | M] () – C:\Windows\SysNative\drivers\mbam.sys
[2009/07/29 04:49:27 | 02,764,058 | -H– | M] () – C:\Users\Owner\AppData\Local\IconCache.db
[2009/07/28 21:43:19 | 00,000,680 | —- | M] () – C:\Users\Owner\AppData\Local\d3d9caps.dat
[2009/07/27 21:56:54 | 00,075,280 | —- | M] () – C:\Users\Owner\AppData\Local\GDIPFONTCACHEV1.DAT
[2009/07/27 21:56:28 | 00,306,984 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2009/07/27 14:08:34 | 00,000,966 | —- | M] () – C:\Users\Owner\Desktop\Auslogics BoostSpeed.lnk
[2009/07/27 13:22:13 | 00,000,971 | —- | M] () – C:\Users\Owner\Desktop\Auslogics Disk Defrag.lnk
[2009/07/22 16:15:08 | 00,031,871 | —- | M] () – C:\ProgramData\nvModes.dat
[2009/07/22 00:23:00 | 00,000,892 | —- | M] () – C:\Users\Owner\Desktop\Eusing Free Registry Cleaner.lnk
[2009/07/21 17:11:15 | 01,146,880 | —- | M] () – C:\Windows\SysNative\wininet.dll
[2009/07/21 17:11:04 | 01,484,288 | —- | M] () – C:\Windows\SysNative\urlmon.dll
[2009/07/21 17:09:54 | 00,243,712 | —- | M] () – C:\Windows\SysNative\occache.dll
[2009/07/21 17:07:37 | 09,233,408 | —- | M] () – C:\Windows\SysNative\mshtml.dll
[2009/07/21 17:07:34 | 00,700,928 | —- | M] () – C:\Windows\SysNative\msfeeds.dll
[2009/07/21 17:07:34 | 00,071,680 | —- | M] () – C:\Windows\SysNative\msfeedsbs.dll
[2009/07/21 17:06:56 | 00,031,744 | —- | M] () – C:\Windows\SysNative\jsproxy.dll
[2009/07/21 17:06:48 | 01,538,560 | —- | M] () – C:\Windows\SysNative\inetcpl.cpl
[2009/07/21 17:06:31 | 02,334,208 | —- | M] () – C:\Windows\SysNative\iertutil.dll
[2009/07/21 17:06:31 | 00,219,136 | —- | M] () – C:\Windows\SysNative\ieui.dll
[2009/07/21 17:06:31 | 00,132,096 | —- | M] () – C:\Windows\SysNative\iesysprep.dll
[2009/07/21 17:06:31 | 00,077,312 | —- | M] () – C:\Windows\SysNative\iesetup.dll
[2009/07/21 17:06:30 | 12,458,496 | —- | M] () – C:\Windows\SysNative\ieframe.dll
[2009/07/21 17:06:30 | 00,252,416 | —- | M] () – C:\Windows\SysNative\iepeers.dll
[2009/07/21 17:06:30 | 00,072,192 | —- | M] () – C:\Windows\SysNative\iernonce.dll
[2009/07/21 17:06:27 | 00,458,240 | —- | M] () – C:\Windows\SysNative\iedkcs32.dll
[2009/07/21 16:52:28 | 00,915,456 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\wininet.dll
[2009/07/21 16:52:13 | 01,208,832 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\urlmon.dll
[2009/07/21 16:50:46 | 00,206,848 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\occache.dll
[2009/07/21 16:48:31 | 05,937,152 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mshtml.dll
[2009/07/21 16:48:27 | 00,594,432 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msfeeds.dll
[2009/07/21 16:48:27 | 00,055,296 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedsbs.dll
[2009/07/21 16:47:47 | 00,025,600 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\jsproxy.dll
[2009/07/21 16:47:41 | 01,469,440 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2009/07/21 16:47:28 | 00,164,352 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2009/07/21 16:47:28 | 00,109,056 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2009/07/21 16:47:27 | 01,985,536 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iertutil.dll
[2009/07/21 16:47:27 | 00,071,680 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2009/07/21 16:47:26 | 11,067,392 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieframe.dll
[2009/07/21 16:47:26 | 00,184,320 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2009/07/21 16:47:26 | 00,055,808 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2009/07/21 16:47:21 | 00,386,048 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iedkcs32.dll
[2009/07/21 15:34:53 | 00,162,816 | —- | M] () – C:\Windows\SysNative\ieUnatt.exe
[2009/07/21 15:34:41 | 00,070,656 | —- | M] () – C:\Windows\SysNative\ie4uinit.exe
[2009/07/21 15:34:12 | 00,012,288 | —- | M] () – C:\Windows\SysNative\msfeedssync.exe
[2009/07/21 15:34:00 | 01,638,912 | —- | M] () – C:\Windows\SysNative\mshtml.tlb
[2009/07/21 15:13:58 | 00,133,632 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2009/07/21 15:13:51 | 00,173,056 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ie4uinit.exe
[2009/07/21 15:13:15 | 00,013,312 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2009/07/21 15:12:49 | 01,638,912 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mshtml.tlb
[2009/07/21 14:09:32 | 00,057,667 | —- | M] () – C:\Windows\SysNative\ieuinit.inf
[2009/07/21 13:31:43 | 00,057,667 | —- | M] () – C:\Windows\SysWow64\ieuinit.inf
[2009/07/17 21:20:40 | 00,008,704 | —- | M] () – C:\Users\Owner\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/07/15 18:51:26 | 00,000,944 | —- | M] () – C:\Users\Owner\Desktop\Windows Media Player.lnk
[2009/07/07 08:43:32 | 26,410,432 | —- | M] () – C:\Windows\SysNative\mrt.exe

========== LOP Check ==========

[2009/08/03 17:37:36 | 00,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming
[2009/07/27 14:10:15 | 00,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\Auslogics
[2009/07/23 22:32:29 | 00,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\CyberLink
[2009/07/17 02:24:03 | 00,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\funkitron
[2009/07/17 03:55:49 | 00,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\Gamelab
[2006/11/02 10:07:25 | 00,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\Media Center Programs
[2009/07/21 23:39:58 | 00,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\Reg Tool
[2009/07/16 13:28:53 | 00,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\WildTangent
[2009/03/01 23:00:36 | 00,000,334 | —- | M] () – C:\Windows\Tasks\HPCeeScheduleForOwner.job
[2009/08/03 15:15:27 | 00,000,006 | -H– | M] () – C:\Windows\Tasks\SA.DAT
[2009/08/03 15:14:34 | 00,028,354 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2009/08/03 20:29:34 | 00,000,418 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{18E75812-6A4E-4E32-A842-2174100493F0}.job

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 116 bytes -> C:\ProgramData\Temp:679ABA25
@Alternate Data Stream - 109 bytes -> C:\ProgramData\Temp:D1B5B4F1
< End of report >


And the Extra.txt file :

OTL Extras logfile created on: 8/3/2009 9:16:07 PM - Run 1
OTL by OldTimer - Version 3.0.10.4 Folder = C:\Users\Owner\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18813)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 2.23 Gb Available Physical Memory | 55.89% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 451.78 Gb Total Space | 302.19 Gb Free Space | 66.89% Space Free | Partition Type: NTFS
Drive D: | 13.98 Gb Total Space | 2.13 Gb Free Space | 15.22% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: OWNER-PC
Current User Name: Owner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl[@ = cplfile] – C:\Windows\SysNative\control.exe ()
.hlp[@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.html[@ = htmlfile] – C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation)
.inf[@ = inffile] – C:\Windows\SysNative\NOTEPAD.EXE ()
.ini[@ = inifile] – C:\Windows\SysNative\NOTEPAD.EXE ()
.url[@ = InternetShortcut] – C:\Windows\System32\ieframe.DLL (Microsoft Corporation)
.js[@ = JSFile] – C:\Windows\SysNative\WScript.exe ()
.jse[@ = JSEFile] – C:\Windows\SysNative\WScript.exe ()
.txt[@ = txtfile] – C:\Windows\SysNative\NOTEPAD.EXE ()
.vbe[@ = VBEFile] – C:\Windows\SysNative\WScript.exe ()
.vbs[@ = VBSFile] – C:\Windows\SysNative\WScript.exe ()
.wsf[@ = WSFFile] – C:\Windows\SysNative\WScript.exe ()
.wsh[@ = WSHFile] – C:\Windows\SysNative\WScript.exe ()

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = htmlfile] – C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation)
.reg [@ = regfile] – C:\Windows\SysWow64\regedit.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"AutoUpdateDisableNotify" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = 9F 9E 16 8C DC 5B C8 01 [binary data]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"oobe_av" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{00D35D91-1CDE-4576-AC4D-1B259FEC241C}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{078FE452-9ED0-4768-9855-A9DBAEB595D8}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\hptouchsmartmusic.exe |
"{19E8E656-76AE-4470-96E0-4BEA5F9AEBB0}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\clml\clmlsvc.exe |
"{2EEEA6B3-E8FE-461E-8751-D71BD9720753}" = dir=in | app=c:\program files (x86)\cyberlink\powerdirector\pdr.exe |
"{304C2BE3-D5CC-48FE-A67C-2198564D633C}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{650FFD20-1E5B-4A5F-ACBC-67B1846CFB08}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\tsmagent.exe |
"{91758C50-8748-43E4-BB69-63968C2D0ED8}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hpdvdsmart.exe |
"{A6A20D56-2776-492D-BAC8-15DB78796A1A}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\hptouchsmartvideo.exe |
"{FC81E99C-46F8-4250-A26D-3A885AFE5799}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\hptouchsmartphoto.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{2F97CE84-9C33-4631-821B-85EA371EA254}" = ProtectSmart Hard Drive Protection
"{4FFA2088-8317-3B14-93CD-4C699DB37843}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729
"{718D791F-F4E8-4aa7-98A6-15FDED17BDD0}" = Trend Micro AntiVirus
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{A621B45A-D138-4A95-BE10-7CABA05EF94E}" = Trend Micro AntiVirus
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D2F7994F-661E-46D1-A1DF-67F2887AAA7E}" = HP MediaSmart SmartMenu
"Agere Systems Soft Modem" = Agere Systems HDA Modem
"B30ECD0209A21D638611F893829C8AF3A483A302" = Windows Driver Package - ENE (enecir) HIDClass (04/29/2008 2.5.0.0)
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"NVIDIA Drivers" = NVIDIA Drivers
"SynTPDeinstKey" = Synaptics Pointing Device Driver

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{004B0DCB-4C60-465B-8F01-44B0A4111187}" = SlingPlayer
"{0054A0F6-00C9-4498-B821-B5C9578F433E}" = HP Help and Support
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = HP MediaSmart Webcam
"{082702D5-5DD8-4600-BCE5-48B15174687F}" = HP Doc Viewer
"{0E7DBD52-B097-4F2B-A7C7-F105B0D20FDB}" = LightScribe System Software 1.14.17.1
"{149BBCB8-674F-48D2-969C-9D0EA88DA7D6}" = HP User Guides 0129
"{154A4184-1A3D-4BF9-A5AE-4FA1660445F3}" = HP Total Care Advisor
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
"{254C37AA-6B72-4300-84F6-98A82419187E}" = Hewlett-Packard Active Check for Health Check
"{26604C7E-A313-4D12-867F-7C6E7820BE4C}" = JMicron JMB38X Flash Media Controller
"{30D3B7BC-5798-45D9-822D-05CA18F39E99}" = HPTCSSetup
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.40 H2
"{352310C3-E46B-42D3-8F32-54721FDD72D9}" = NetZero Preloader
"{3877C901-7B90-4727-A639-B6ED2DD59D43}" = ESU for Microsoft Vista
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{45A136EC-88BF-4B95-99F5-C45D3930E1CC}" = HP MULTIPLE MODEM INSTALLER for VISTA
"{57A5AEC1-97FC-474D-92C4-908FCC2253D4}" = HP Customer Experience Enhancements
"{5DAA9C36-8F8B-462F-8CCA-E205BC3751F5}" = HP Active Support Library
"{6423EF83-6E1D-4D22-A36F-689CD19FD4D2}" = Juno Preloader
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = Hewlett-Packard Asset Agent for Health Check
"{67626E09-5366-4480-8F1E-93FADF50CA15}" = HP MediaSmart TV
"{6A370610-3778-44AF-9AAC-69B2FD1A3356}" = Microsoft Live Search Toolbar
"{7216871F-869E-437C-B9BF-2A13F2DCE63F}_is1" = Auslogics BoostSpeed
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{7B798B31-2F33-4DC8-BDA4-D36488E86636}" = Slingbox - Watch Your TV Anywhere
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 8168 8101E 8102E Ethernet Driver
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{9ADABDDE-9644-461B-9E73-83FA3EFCAB50}" = HP Wireless Assistant
"{AC76BA86-7AD7-1033-7B44-A90000000001}" = Adobe Reader 9
"{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}" = HP MediaSmart Music/Photo/Video
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{C8FD5BC1-92EF-4C15-92A9-F9AC7F61985F}" = HP Update
"{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}" = HP Product Detection
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"{DD35C328-F115-BEDA-6EEE-E00C5AACCCBC}" = muvee Reveal
"{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1" = Auslogics Disk Defrag
"{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio
"{ECEE0279-785F-4CB3-9F28-E69813234BF8}" = SPORE Creature Creator Trial Edition
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Eusing Free Registry Cleaner" = Eusing Free Registry Cleaner
"HijackThis" = HijackThis 2.0.2
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"InstallShield_{004B0DCB-4C60-465B-8F01-44B0A4111187}" = SlingPlayer
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = HP MediaSmart Webcam
"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"InstallShield_{67626E09-5366-4480-8F1E-93FADF50CA15}" = HP MediaSmart TV
"InstallShield_{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}" = HP MediaSmart Music/Photo/Video
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"InstallShield_{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"WildTangent hp Master Uninstall" = My HP Games

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 7/28/2009 11:41:09 PM | Computer Name = Owner-PC | Source = WinMgmt | ID = 10
Description =

Error - 7/29/2009 5:29:21 AM | Computer Name = Owner-PC | Source = WinMgmt | ID = 10
Description =

Error - 7/29/2009 5:51:07 AM | Computer Name = Owner-PC | Source = WinMgmt | ID = 10
Description =

Error - 7/29/2009 11:43:28 PM | Computer Name = Owner-PC | Source = WinMgmt | ID = 10
Description =

Error - 7/30/2009 11:44:20 AM | Computer Name = Owner-PC | Source = WinMgmt | ID = 10
Description =

Error - 7/30/2009 7:18:47 PM | Computer Name = Owner-PC | Source = WinMgmt | ID = 10
Description =

Error - 7/31/2009 1:32:51 AM | Computer Name = Owner-PC | Source = WinMgmt | ID = 10
Description =

Error - 7/31/2009 2:55:37 AM | Computer Name = Owner-PC | Source = WinMgmt | ID = 10
Description =

Error - 7/31/2009 3:25:07 PM | Computer Name = Owner-PC | Source = WinMgmt | ID = 10
Description =

Error - 8/2/2009 12:00:07 AM | Computer Name = Owner-PC | Source = WinMgmt | ID = 10
Description =

[ System Events ]
Error - 8/2/2009 8:36:24 PM | Computer Name = Owner-PC | Source = PlugPlayManager | ID = 12
Description = The device 'JMB38X SD Host Controller' (PCI\VEN_197B&DEV_2381&SUBSYS_30F4103C&REV_00\4&120488ab&0&02E4)
disappeared from the system without first being prepared for removal.

Error - 8/2/2009 8:36:24 PM | Computer Name = Owner-PC | Source = PlugPlayManager | ID = 12
Description = The device 'JMB38X MS Host Controller' (PCI\VEN_197B&DEV_2383&SUBSYS_30F4103C&REV_00\4&120488ab&0&03E4)
disappeared from the system without first being prepared for removal.

Error - 8/2/2009 8:36:24 PM | Computer Name = Owner-PC | Source = PlugPlayManager | ID = 12
Description = The device 'JMB38X xD Host Controller' (PCI\VEN_197B&DEV_2384&SUBSYS_30F4103C&REV_00\4&120488ab&0&04E4)
disappeared from the system without first being prepared for removal.

Error - 8/2/2009 11:36:09 PM | Computer Name = Owner-PC | Source = HTTP | ID = 15016
Description =

Error - 8/2/2009 11:36:19 PM | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 8/2/2009 11:36:19 PM | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7026
Description =

Error - 8/2/2009 11:40:55 PM | Computer Name = Owner-PC | Source = PlugPlayManager | ID = 12
Description = The device 'JMB38X SD/MMC Host Controller' (PCI\VEN_197B&DEV_2382&SUBSYS_30F4103C&REV_00\4&120488ab&0&01E4)
disappeared from the system without first being prepared for removal.

Error - 8/2/2009 11:40:55 PM | Computer Name = Owner-PC | Source = PlugPlayManager | ID = 12
Description = The device 'JMB38X SD Host Controller' (PCI\VEN_197B&DEV_2381&SUBSYS_30F4103C&REV_00\4&120488ab&0&02E4)
disappeared from the system without first being prepared for removal.

Error - 8/2/2009 11:40:55 PM | Computer Name = Owner-PC | Source = PlugPlayManager | ID = 12
Description = The device 'JMB38X MS Host Controller' (PCI\VEN_197B&DEV_2383&SUBSYS_30F4103C&REV_00\4&120488ab&0&03E4)
disappeared from the system without first being prepared for removal.

Error - 8/2/2009 11:40:55 PM | Computer Name = Owner-PC | Source = PlugPlayManager | ID = 12
Description = The device 'JMB38X xD Host Controller' (PCI\VEN_197B&DEV_2384&SUBSYS_30F4103C&REV_00\4&120488ab&0&04E4)
disappeared from the system without first being prepared for removal.


< End of report >
Thanks again
You better have a look at hijack this again also here I've run it again. it wouldn't let me scan host files and had me run Hijackthis by right clicking the icon and "run as administrator"

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:40:36 PM, on 8/3/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18813)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe
C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe
C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files (x86)\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files (x86)\Hp\HP Software Update\hpwuSchd2.exe
C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files (x86)\Hewlett-Packard\Media\TV\TVAgent.exe
C:\Program Files (x86)\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
C:\Program Files (x86)\Internet Explorer\IELowutil.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf=cnnb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://refdesk.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf=cnnb
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf=cnnb
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Microsoft Live Search Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0541.0\msneshellx.dll
O3 - Toolbar: Microsoft Live Search Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0541.0\msneshellx.dll
O4 - HKLM\..\Run: [DVDAgent] "C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe"
O4 - HKLM\..\Run: [TSMAgent] "C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe"
O4 - HKLM\..\Run: [CLMLServer for HP TouchSmart] "C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe"
O4 - HKLM\..\Run: [UpdateLBPShortCut] "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
O4 - HKLM\..\Run: [UpdatePSTShortCut] "C:\Program Files (x86)\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"
O4 - HKLM\..\Run: [QlbCtrl.exe] "C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" /Start
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [UpdateP2GoShortCut] "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
O4 - HKLM\..\Run: [UpdatePDIRShortCut] "C:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\PowerDirector" UpdateWithCreateOnce "SOFTWARE\CyberLink\PowerDirector\7.0"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Hewlett-Packard\Media\Webcam" update "Software\Hewlett-Packard\Media\Webcam"
O4 - HKLM\..\Run: [TVAgent] "C:\Program Files (x86)\Hewlett-Packard\Media\TV\TVAgent.exe"
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /install /silent
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~2\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~2\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20270.www2.hp.com/ediags/gmn2/inst…tDetection2.cab
O23 - Service: Andrea ST Filters Service (AESTFilters) - Unknown owner - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_bd5387da\AESTSr64.exe (file missing)
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Unknown owner - C:\Windows\system32\agr64svc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\Windows\system32\Hpservice.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Recovery Service for Windows - Unknown owner - C:\Program Files (x86)\SMINST\BLService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: Audio Service (STacSV) - Unknown owner - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_bd5387da\STacSV64.exe (file missing)
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
O23 - Service: TV Background Capture Service (TVBCS) (TVCapSvc) - Unknown owner - C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe
O23 - Service: TV Task Scheduler (TVTS) (TVSched) - Unknown owner - C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 11382 bytes


Thanks for your help
Please do the following:

  • Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file path into the "Suspicious files to scan" box on the top of the page:


    C:\Windows\SysNative\drivers\etc\tmvsthfss.bin

  • Click on the Upload button
  • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.


NEXT:

[external image: Posted Image]
Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older version Java components and update.

  • Download the latest version of Java Runtime Environment (JRE) 6 and save it to your desktop.
  • Scroll down to where it says "Java SE Runtime Environment (JRE) 6 Update 14. The Java SE Runtime Environment (JRE) allows end-users to run Java applications."
  • Click the "Download" button to the right.
  • Select the Windows platform from the dropdown menu.
  • Read the License Agreement and then check the box that says: " I agree to the Java SE Runtime Environment 6 with JavaFX License Agreement". Click on Continue.The page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Now go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE or Java™ 6) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java version.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u14-windows-i586-p.exe to install the newest version.
  • After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - Leave BOTH CheckedApplications and AppletsTrace and Log Files
  • Click OK on Delete Temporary Files Window

    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.


NEXT


  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


**Vista users - right click on the IE icon and run as administrator

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take quite a long time to download.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply


Also, please advise how the computer is running and if there are any outstanding issues.



( also - yours host file is fine and running as admin is normal - you are running a 64bit vista)
Ok first thing - have a problem with VirSCAN.org FREE on-line scan service. It won't allow me to copy and paste the file path into the box nor will it let me type it in. Next I browsed and searched back through C to windows to sysNative but I don't find sysNative. Because you put this task first I did not complete the others yet as this may need to be done first. I did download jre-6u14-windows-i586-p.exeon my desktop but I am holding here until I can resolve VirScan What to do?
Hi,

Try this scanner instead,

  • Use the browse button on that page to navigate to the location of the file to be scanned.
  • In the right hand panel,
  • click on the file C:\Windows\SysNative\drivers\etc\tmvsthfss.bin
  • then click the open button.
  • The file will now be displayed in the submit box.
  • Scroll down a bit and click "send file", wait for the results

You may have to Unhide files and folders to browse to the file as Sysnative is a hidden folder

  • Close all programs so that you are at your desktop.
  • Open the Control Panel menu and click Folder Options.
  • After the new window appears select the View tab.
  • Put a checkmark in the checkbox labeled Display the contents of system folders.
  • Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
  • Remove the checkmark from the checkbox labeled Hide file extensions for known file types.
  • Remove the checkmark from the checkbox labeled Hide protected operating system files.
  • Press the Apply button and then the OK button and exit My Computer.
  • Now your computer is configured to show all hidden files.

If still no luck, move on to the next steps.
Ok I ran the extra steps to show hidden files but I never saw it C:/windows/sysnative not there. So I was unable to use VirSCAN.org I moved on to the next steps. I intsalled jre-6u14-windows-i586-p.exe and ran through those steps. Seems ok. Open and updated MBAM and ran quickscan and it removed a couple of items. (log for MBAM is below next step) I go to the Kaspersky site it scans my computer configuration and this message window comes up: You need to install Java version 1.6 or later to run Kaspersky Online Scanner 7.0 Here is the log from MBAM: Malwarebytes' Anti-Malware 1.40 Database version: 2560 Windows 6.0.6001 Service Pack 1 8/4/2009 2:36:51 PM mbam-log-2009-08-04 (14-36-51).txt Scan type: Quick Scan Objects scanned: 74906 Time elapsed: 2 minute(s), 47 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 2 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowSearch (Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) I'm ready for more instruction. Thank you
Hi,

The Java Addon in IE is disabled.

Go to Tools > Internet Options > Advanced tab. Click Reset then OK and exit IE

Re-open IE and ensure the Java add-ons are enabled.

[external image: Posted Image]

If that scan still will not run try this one

Go here to run an online scanner from ESET.
  • Note: You will need to use Internet explorer for this scan
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\Eset\Eset Online Scanner\log.txt
  • Copy and paste that log as a reply to this topic and also let me know how things are now.
I went to Tools > Internet Options > Advanced tab. Click Reset then OK and exited IE Next I went to Manage add-ons and Java wasn't listed there. also there wan't a choice of enable and disable. This step was Skipped Next I did ESET and here is the notepad logfile. ESETSmartInstaller@High as CAB hook log: OnlineScanner64.ocx - registred OK OnlineScanner.ocx - registred OK esets_scanner_update returned -1 esets_gle=53251 After I ran the scan ESET said there wasn't any virus detected. What's next? Thanks.
I went to Tools > Internet Options > Advanced tab. Click Reset then OK and exited IE Next I went to Manage add-ons and Java wasn't listed there. also there wan't a choice of enable and disable. This step was Skipped Next I did ESET and here is the notepad logfile. ESETSmartInstaller@High as CAB hook log: OnlineScanner64.ocx - registred OK OnlineScanner.ocx - registred OK esets_scanner_update returned -1 esets_gle=53251 After I ran the scan ESET said there wasn't any virus detected. What's next? Thanks.
I'm sorry but not really. this is a new computer, haven't had it long, I don't use it. It is my daughters. So she has been waiting until I get done with this assistance before she gets back on. I haven't done anything but work with you. I can tell you it seems to be operating just fine. I still have a question about all the missing files in the HiJack This report from nnetwork techs.com. There it is reported as a potential bad issue. I would like to make that go away. What do you think? Thanks once again.
Those are not missing entries.

HJT is not designed for 64 bit systems, it just cannot read those files.

That is the problem with online HJT scanners - the OS isn't taken into account.

Ignore those results.

From what I can see, the machine appears to be clean.

We just need to clean up the tools used:

Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.


Now set a new restore point.


Now we need to create a new clean SYSTEM RESTORE point.

  • Close and save any documents that you may have open.
  • Open up the Start Menu and right-click on "Computer", and then select "Properties"
  • This will take you into the System area of Control Panel. Click on the "Advanced system settings" on the left hand side.
  • Now select the "System Protection" tab to get to the System Restore section.
  • Click the "Create" button to create a new restore point. You'll be prompted for a name, and you might want to give it a useful name that you'll be able to easily identify later.
  • Click the Create button, and then the system will create the restore point.
  • When it's all finished, you'll get a message saying it's completed successfully.
  • You will now have a new restore point

Then remove all previous Restore Points
  • Click Start Menu > Run > copy and paste
  • cleanmgr into the run box
  • At the top, click on the More Options tab, under System Restore and Shadow Copies group,
  • Click the Clean up button,
  • Vista will ask you if you’re sure, click on Yes button.
  • When finished, click on Cancel button to exit.

NEXT


Below are my usual closing recommendations - take from them what you wish

Below I have included a number of recommendations for how to protect your computer against malware infections.

  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them
    Then consider a password keeper, to keep all your passwords safe.

  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.
  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.

  • MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

    WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox and IE

  • Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more
    secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in pop up
    blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from
    Here


    If you choose to use Firefox, I highly recommend this add-on to keep your PC even more secure.
    • NoScript - for blocking ads and other potential website attacks

  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.
  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.
  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
    Think Prevention.
    PC Safety and Security–What Do I Need?.


**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.


Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.
Ok 0n HJT and 64 bit OS Is there some kind of HJT for 64 bit? Next I did the OTL.exe Next I created a new restore point Third, When I open Start, there isn't a run option available like in the xp os Next I type run in the search box and the run box came up. Next I typed in cleanmgr and I clicked on it. There is no copy and paste for cleanmgr and I get a disk cleanup options box with three choices 1 choose which files to clean up 2. My files only 3, files from all users on this computer. What I don't see is this "At the top, click on the More Options tab, under System Restore and Shadow Copies group, Click the Clean up button," By the way some of the things you ask for me to do are not available like the way you said to do it but I found the way to get it done In other words it's like the OS is a little different, Wha do I do now? Thank you.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI