This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Stella's New Laptop

21 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Fatal blue screen Core dump screen I did msconfig enabled only the things I thought were needed to boot and get online. I ran ERUNT AVS cleaner and mbam Here is the results of the mbam scan Malwarebytes' Anti-Malware 1.40 Database version: 2551 Windows 6.0.6001 Service Pack 1 8/27/2009 1:09:30 PM mbam-log-2009-08-27 (13-09-30).txt Scan type: Quick Scan Objects scanned: 75575 Time elapsed: 2 minute(s), 6 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 2 Registry Values Infected: 0 Registry Data Items Infected: 1 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8ca5ed52-f3fb-4414-a105-2e3491156990} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{8ca5ed52-f3fb-4414-a105-2e3491156990} (Trojan.BHO) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: C:\Program Files (x86)\iWin Games\iWinGamesHookIE.dll (Trojan.BHO) -> Quarantined and deleted successfully.
hello maax

Welcome to the What the tech Forums
My name is mschroe919 and I am going help you
I would like to help you So if you would….
Please be patient and I will be back as soon as possible.
when you do these and post them

FIRST:


Please while I am gone do these steps:

Show hidden files, Here is how:

Windows XP

* Click Start.
* Open My Computer.
* Select the Tools menu and click Folder Options.
* Select the View Tab.
* Under the Hidden files and folders heading select Show hidden files and folders.
* Uncheck the Hide protected operating system files (recommended) option.
* Click Yes to confirm.
* Click OK.

NEXT:

Please download ATF Cleaner by Atribune.

Download it

HERE:

This program is for XP and Windows 2000 and vista
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

NEXT:

We need to download HijackThis, download it here
http://www.rosoftdownload.com/admin/images…/HJTInstall.exe
once downloaded click on it to install
By default it will install in c:\program files.Don't change the location
Then navigate to that directory and double-click on the hijackthis.exe file. When the program is started click on the Scan button and then the Save Log button to create a log of your information.
Once the log is saved copy and paste please it here don' try to attacht it just copy and paste
good luck

Be sure not to delete anything intill said ok to. also don't run any other cleanup programs till we
get done it may goof ours up.
Also if you have any questions feel fre to ask first.

When you post another HJT log , let me know how your PC is behavuing

I will be waiting to see new logs

mschroe919
running vista on this computer not xp

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:20:15 PM, on 8/27/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18813)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe
C:\Program Files (x86)\Hp\Digital Imaging\bin\hpqtra08.exe
C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe
C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe
C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
C:\Program Files (x86)\Hewlett-Packard\Media\TV\TVAgent.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files (x86)\Hp\HP Software Update\hpwuSchd2.exe
C:\Program Files (x86)\Java\jre6\bin\jusched.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqToaster.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf=cnnb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf=cnnb
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf=cnnb
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\16.5.0.135\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\16.5.0.135\IPSBHO.DLL
O2 - BHO: Microsoft Live Search Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0541.0\msneshellx.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\16.5.0.135\coIEPlg.dll
O3 - Toolbar: Microsoft Live Search Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0541.0\msneshellx.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [DVDAgent] "C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe"
O4 - HKLM\..\Run: [TSMAgent] "C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe"
O4 - HKLM\..\Run: [CLMLServer for HP TouchSmart] "C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe"
O4 - HKLM\..\Run: [TVAgent] "C:\Program Files (x86)\Hewlett-Packard\Media\TV\TVAgent.exe"
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Hewlett-Packard\Media\Webcam" update "Software\Hewlett-Packard\Media\Webcam"
O4 - HKLM\..\Run: [UpdateLBPShortCut] "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
O4 - HKLM\..\Run: [UpdatePSTShortCut] "C:\Program Files (x86)\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"
O4 - HKLM\..\Run: [QlbCtrl.exe] "C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" /Start
O4 - HKLM\..\Run: [UpdateP2GoShortCut] "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
O4 - HKLM\..\Run: [UpdatePDIRShortCut] "C:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\PowerDirector" UpdateWithCreateOnce "SOFTWARE\CyberLink\PowerDirector\7.0"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [WirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [HPAdvisor] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files (x86)\ERUNT\AUTOBACK.EXE
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files (x86)\Hp\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O13 - Gopher Prefix:
O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:\Program Files (x86)\Norton Internet Security\Engine\16.5.0.135\coIEPlg.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\Windows\system32\Hpservice.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Recovery Service for Windows - Unknown owner - C:\Program Files (x86)\SMINST\BLService.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: Audio Service (STacSV) - Unknown owner - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_7477fb4c\STacSV64.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 10648 bytes
hi maax

You don't need to pm me we all are doing all logs as fast as we can it takes time to read a log. Next I don't see anything jumping out that is real bad, but we must do some more checking. By the way did you make all folders unhidden before you reun malwarbytes? if ru before you unhid the folders try running again after the silent runners I am giving you now.

[bNEXT


use Internet Explore, please download by clicking on this link SILENT RUNNERS LINK save it to your Desktop

Run Silent Runner's by doubleclicking the "Silent Runners" icon on your desktop.
You will see a text file appear on the desktop - it's not done, let it run (it won't appear to be doing anything!)

Once you receive the prompt All Done! , yo can then attach this text file log to your next message.
NOTE: If you receive any warning messages from your antivirus or antispyware programs about a script trying to be run , please choose to allow the script to run.
Malwarebytes' Anti-Malware 1.40
Database version: 2551
Windows 6.0.6001 Service Pack 1

8/27/2009 3:48:42 PM
mbam-log-2009-08-27 (15-48-42).txt

Scan type: Quick Scan
Objects scanned: 75581
Time elapsed: 2 minute(s), 4 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)




"Silent Runners.vbs", revision 59, http://www.silentrunners.org/
Operating System: Windows Vista
Output limited to non-default values, except where indicated by "{++}"


Startup items buried in registry:
———————————

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
"LightScribe Control Panel" = "C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden" ["Hewlett-Packard Company"]
"HPAdvisor" = "C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN" [null data]
"ehTray.exe" = "C:\Windows\ehome\ehTray.exe" [MS]

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
"IgfxTray" = "C:\Windows\system32\igfxtray.exe" ["Intel Corporation"]
"HotKeysCmds" = "C:\Windows\system32\hkcmd.exe" ["Intel Corporation"]
"Persistence" = "C:\Windows\system32\igfxpers.exe" ["Intel Corporation"]
"SynTPEnh" = "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" ["Synaptics, Inc."]
"SysTrayApp" = "C:\Program Files\IDT\WDM\sttray64.exe"
"SmartMenu" = "C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe"
"Windows Defender" = "C:\Program Files\Windows Defender\MSASCui.exe -hide"
"SunJavaUpdateSched" = ""C:\Program Files\Java\jre6\bin\jusched.exe"" ["Sun Microsystems, Inc."]

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{DBC80044-A445-435b-BC74-9C25C1C588A9}\(Default) = (no title provided)
-> {HKLM…CLSID} = "Java™ Plug-In 2 SSV Helper"
\InProcServer32\(Default) = "C:\Program Files\Java\jre6\bin\jp2ssv.dll" ["Sun Microsystems, Inc."]

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
"{28803F59-3A75-4058-995F-4EE5503B023C}" = "Wireless Devices"
-> {HKLM…CLSID} = "Bluetooth Devices"
\InProcServer32\(Default) = "C:\Windows\system32\FunctionDiscoveryFolder.dll" [MS]
"{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler"
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office12\MSOHEVI.DLL" [MS]
"{993BE281-6695-4BA5-8A2A-7AACBFAAB69E}" = "Microsoft Office Metadata Handler"
-> {HKLM…CLSID} = "Microsoft Office Metadata Handler"
\InProcServer32\(Default) = "C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll" [MS]
"{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97}" = "Microsoft Office Thumbnail Handler"
-> {HKLM…CLSID} = "Microsoft Office Thumbnail Handler"
\InProcServer32\(Default) = "C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll" [MS]
"{7F67036B-66F1-411A-AD85-759FB9C5B0DB}" = "ShellViewRTF"
-> {HKLM…CLSID} = "ShellViewRTF"
\InProcServer32\(Default) = "C:\Program Files (x86)\Sminst\ShellvRTF64.dll" ["XSS"]
"{2F603045-309F-11CF-9774-0020AFD0CFF6}" = "Synaptics Control Panel"
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\Program Files\Synaptics\SynTP\SynTPCpl.dll" ["Synaptics, Inc."]
"{11016101-E366-4D22-BC06-4ADA335C892B}" = "IE History and Feeds Shell Data Source for Windows Search"
-> {HKLM…CLSID} = "IE History and Feeds Shell Data Source for Windows Search"
\InProcServer32\(Default) = "C:\Windows\System32\ieframe.dll" [MS]

HKLM\SOFTWARE\Classes\PROTOCOLS\Filter\
<> text/xml\CLSID = "{807563E5-5146-11D5-A672-00B0D022E945}"
-> {HKLM…CLSID} = "Microsoft Office InfoPath XML Mime Filter"
\InProcServer32\(Default) = "C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL" [MS]

HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\
Symantec.Norton.Antivirus.IEContextMenu\(Default) = "{FAD61B3D-699D-49B2-BE16-7F82CB4C59CA}"
-> {HKLM…CLSID} = "IEContextMenu Class"
\InProcServer32\(Default) = ""C:\Program Files (x86)\Norton Internet Security\Engine64\16.5.0.135\NavShExt.dll"" ["Symantec Corporation"]

HKLM\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\
Symantec.Norton.Antivirus.IEContextMenu\(Default) = "{FAD61B3D-699D-49B2-BE16-7F82CB4C59CA}"
-> {HKLM…CLSID} = "IEContextMenu Class"
\InProcServer32\(Default) = ""C:\Program Files (x86)\Norton Internet Security\Engine64\16.5.0.135\NavShExt.dll"" ["Symantec Corporation"]


Default executables:
——————–

HKLM\SOFTWARE\Classes\.hta\(Default) = "htafile"
<> HKLM\SOFTWARE\Classes\htafile\shell\open\command\(Default) = "C:\Windows\SysWOW64\mshta.exe "%1" %*" [MS]


Group Policies {GPedit.msc branch and setting}:
———————————————–

Note: detected settings may not have any effect.

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\

"NoActiveDesktop" = (REG_DWORD) dword:0x00000001
{unrecognized setting}

"ForceActiveDesktopOn" = (REG_DWORD) dword:0x00000000
{unrecognized setting}

"NoActiveDesktopChanges" = (REG_DWORD) dword:0x00000000
{unrecognized setting}

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\

"ConsentPromptBehaviorAdmin" = (REG_DWORD) dword:0x00000002
{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
User Account Control: Behavior Of The Elevation Prompt For Administrators In Admin Approval Mode}

"ConsentPromptBehaviorUser" = (REG_DWORD) dword:0x00000001
{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
User Account Control: Behavior Of The Elevation Prompt For Standard Users}

"EnableInstallerDetection" = (REG_DWORD) dword:0x00000001
{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
User Account Control: Detect Application Installations And Prompt For Elevation}

"EnableLUA" = (REG_DWORD) dword:0x00000001
{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
User Account Control: Run All Administrators In Admin Approval Mode}

"EnableSecureUIAPaths" = (REG_DWORD) dword:0x00000001
{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
User Account Control: Only elevate UIAccess applications that are installed in secure locations}

"EnableVirtualization" = (REG_DWORD) dword:0x00000001
{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
User Account Control: Virtualize file and registry write failures to per-user locations}

"PromptOnSecureDesktop" = (REG_DWORD) dword:0x00000001
{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
User Account Control: Switch to the secure desktop when prompting for elevation}

"shutdownwithoutlogon" = (REG_DWORD) dword:0x00000001
{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
Shutdown: Allow system to be shut down without having to log on}

"undockwithoutlogon" = (REG_DWORD) dword:0x00000001
{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
Devices: Allow undock without having to log on}

"FilterAdministratorToken" = (REG_DWORD) dword:0x00000000
{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
User Account Control: Admin Approval Mode for the Built-in Administrator Account}

"EnableUIADesktopToggle" = (REG_DWORD) dword:0x00000000
{unrecognized setting}


Active Desktop and Wallpaper:
—————————–

Active Desktop may be disabled at this entry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState

Displayed if Active Desktop enabled and wallpaper not set by Group Policy:
HKCU\Software\Microsoft\Internet Explorer\Desktop\General\
"Wallpaper" = "C:\Windows\web\Wallpaper\img24.jpg"

Displayed if Active Desktop disabled and wallpaper not set by Group Policy:
HKCU\Control Panel\Desktop\
"Wallpaper" = "C:\Windows\web\Wallpaper\img24.jpg"


Enabled Screen Saver:
———————

HKCU\Control Panel\Desktop\
"SCRNSAVE.EXE" = "C:\Windows\system32\logon.scr" [MS]


Windows Portable Device AutoPlay Handlers
—————————————–

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\

HPAutoplayPSE\
"Provider" = "HP Photosmart Essential 3.0"
"InvokeProgID" = "HpqPSApl.Autoplay"
"InvokeVerb" = "Play"
HKLM\SOFTWARE\Classes\HpqPSApl.Autoplay\shell\Play\DropTarget\CLSID = "{A6873065-D632-4615-A3A9-C5F05EE109C1}"
-> {HKLM…CLSID} = (no title provided)
\LocalServer32\(Default) = "C:\Program Files (x86)\HP\Digital Imaging\bin\HpqPsApl.exe" ["Hewlett-Packard"]

HPMSDVDPlayDVDMovieOnArrival\
"Provider" = "HP MediaSmart DVD"
"InvokeProgID" = "DVD"
"InvokeVerb" = "PlayWithHPMediaSmartDVD"
HKLM\SOFTWARE\Classes\DVD\shell\PlayWithHPMediaSmartDVD\Command\(Default) = ""C:\Program Files (x86)\Hewlett-Packard\Media\DVD\HPDVDSmart.exe" AUTOPLAY MOVIE "%L"" ["CyberLink Corp."]

HPMSDVDPlayVCDMovieOnArrival\
"Provider" = "HP MediaSmart DVD"
"InvokeProgID" = "VCD"
"InvokeVerb" = "PlayWithHPMediaSmartDVD"
HKLM\SOFTWARE\Classes\VCD\shell\PlayWithHPMediaSmartDVD\Command\(Default) = ""C:\Program Files (x86)\Hewlett-Packard\Media\DVD\HPDVDSmart.exe" AUTOPLAY MOVIE "%L"" ["CyberLink Corp."]

MSPlayCDAudioOnArrival\
"Provider" = "@wmploc.dll,-6502"
"InvokeProgID" = "WMP.AudioCD"
"InvokeVerb" = "play"
HKLM\SOFTWARE\Classes\WMP.AudioCD\shell\play\command\(Default) = ""C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /prefetch:3 /device:AudioCD "%L"" [MS]

MSPlayDVDMovieOnArrival\
"Provider" = "@wmploc.dll,-6502"
"InvokeProgID" = "WMP.DVD"
"InvokeVerb" = "play"
HKLM\SOFTWARE\Classes\WMP.DVD\shell\play\command\(Default) = ""C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /prefetch:4 /device:DVD "%L"" [MS]

MSPlaySuperVideoCDMovieOnArrival\
"Provider" = "@wmploc.dll,-6502"
"InvokeProgID" = "WMP.VCD"
"InvokeVerb" = "play"
HKLM\SOFTWARE\Classes\WMP.VCD\shell\play\command\(Default) = ""C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /prefetch:4 /device:VCD "%L"" [MS]

MSPlayVideoCDMovieOnArrival\
"Provider" = "@wmploc.dll,-6502"
"InvokeProgID" = "WMP.VCD"
"InvokeVerb" = "play"
HKLM\SOFTWARE\Classes\WMP.VCD\shell\play\command\(Default) = ""C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /prefetch:4 /device:VCD "%L"" [MS]

MSRipCDAudioOnArrival\
"Provider" = "@wmploc.dll,-6502"
"InvokeProgID" = "WMP.RipCD"
"InvokeVerb" = "Rip"
HKLM\SOFTWARE\Classes\WMP.RipCD\shell\Rip\Command\(Default) = ""C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /prefetch:3 /RipAudioCD "%L" " [MS]

MSWMPBurnCDOnArrival\
"Provider" = "@wmploc.dll,-6502"
"InvokeProgID" = "WMP.BurnCD"
"InvokeVerb" = "Burn"
HKLM\SOFTWARE\Classes\WMP.BurnCD\shell\Burn\Command\(Default) = ""C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /prefetch:3 /Task:CDWrite /Device:"%L" " [MS]

MSWMPBurnDataDVDArrival\
"Provider" = "@wmploc.dll,-6502"
"InvokeProgID" = "WMP.BurnDVD"
"InvokeVerb" = "Burn"
HKLM\SOFTWARE\Classes\WMP.BurnDVD\shell\Burn\Command\(Default) = ""C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /prefetch:3 /Task:DVDWrite /Device:"%L" " [MS]

muveePicturesOnArrival\
"Provider" = "muvee Reveal"
"InvokeProgID" = "Picture"
"InvokeVerb" = "OpenWithMuveeReveal"
HKLM\SOFTWARE\Classes\Picture\shell\OpenWithMuveeReveal\Command\(Default) = ""C:\Program Files (x86)\muvee Technologies\muvee Reveal - SE\muveereveal.exe" -mediaarrival=%L" [null data]

muveeVideoCameraArrivalCaptureWizard\
"Provider" = "muvee Reveal"
"ProgID" = "Shell.HWEventHandlerShellExecute"
"InitCmdLine" = ""C:\Program Files (x86)\muvee Technologies\muvee Reveal - SE\muveereveal.exe" -capture"
HKLM\SOFTWARE\Classes\Shell.HWEventHandlerShellExecute\CLSID\(Default) = "{FFB8655F-81B9-4fce-B89C-9A6BA76D13E7}"
-> {HKLM…CLSID} = "Shell Execute Hardware Event Handler"
\LocalServer32\(Default) = "C:\Windows\System32\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {FFB8655F-81B9-4fce-B89C-9A6BA76D13E7}" [MS]

muveeVideoOnArrival\
"Provider" = "muvee Reveal"
"InvokeProgID" = "Picture"
"InvokeVerb" = "OpenWithMuveeReveal"
HKLM\SOFTWARE\Classes\Picture\shell\OpenWithMuveeReveal\Command\(Default) = ""C:\Program Files (x86)\muvee Technologies\muvee Reveal - SE\muveereveal.exe" -mediaarrival=%L" [null data]

P2GCDBurningOnArrival\
"Provider" = "Power2Go"
"InvokeProgID" = "BlankCD"
"InvokeVerb" = "OpenWithPower2Go"
HKLM\SOFTWARE\Classes\BlankCD\shell\OpenWithPower2Go\Command\(Default) = ""C:\Program Files (x86)\CyberLink\Power2Go\Power2Go.exe" "%L"" ["CyberLink Corp."]

P2GDVDBurningOnArrival\
"Provider" = "Power2Go"
"InvokeProgID" = "BlankDVD"
"InvokeVerb" = "OpenWithPower2Go"
HKLM\SOFTWARE\Classes\BlankDVD\shell\OpenWithPower2Go\Command\(Default) = ""C:\Program Files (x86)\CyberLink\Power2Go\Power2Go.exe" "%L"" ["CyberLink Corp."]

PDirDVArrival\
"Provider" = "PowerDirector"
"ProgID" = "Shell.HWEventHandlerShellExecute"
"InitCmdLine" = ""C:\Program Files (x86)\CyberLink\PowerDirector\PDR.exe" /DV"
HKLM\SOFTWARE\Classes\Shell.HWEventHandlerShellExecute\CLSID\(Default) = "{FFB8655F-81B9-4fce-B89C-9A6BA76D13E7}"
-> {HKLM…CLSID} = "Shell Execute Hardware Event Handler"
\LocalServer32\(Default) = "C:\Windows\System32\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {FFB8655F-81B9-4fce-B89C-9A6BA76D13E7}" [MS]

Power2GoPlayCDAudioOnArrival\
"Provider" = "Power2Go"
"InvokeProgID" = "AudioCD"
"InvokeVerb" = "PlayWithPower2Go"
HKLM\SOFTWARE\Classes\AudioCD\shell\PlayWithPower2Go\Command\(Default) = ""C:\Program Files (x86)\CyberLink\Power2Go\Power2Go.exe" /AudioRipper "%L"" ["CyberLink Corp."]

PStarterBlankCDArrival\
"Provider" = "DVD Suite"
"InvokeProgID" = "BlankCD"
"InvokeVerb" = "OpenWithPowerStarter"
HKLM\SOFTWARE\Classes\BlankCD\shell\OpenWithPowerStarter\Command\(Default) = ""C:\Program Files (x86)\CyberLink\DVD Suite\PowerStarter.exe" "%L"" ["CyberLink"]

PStarterDVDBurningOnArrival\
"Provider" = "DVD Suite"
"InvokeProgID" = "BlankDVD"
"InvokeVerb" = "OpenWithPowerStarter"
HKLM\SOFTWARE\Classes\BlankDVD\shell\OpenWithPowerStarter\Command\(Default) = ""C:\Program Files (x86)\CyberLink\DVD Suite\PowerStarter.exe" "%L"" ["CyberLink"]

PStarterMixedCDArrival\
"Provider" = "DVD Suite"
"InvokeProgID" = "MixedContent"
"InvokeVerb" = "OpenWithPowerStarter"
HKLM\SOFTWARE\Classes\MixedContent\shell\OpenWithPowerStarter\Command\(Default) = ""C:\Program Files (x86)\CyberLink\DVD Suite\PowerStarter.exe" "%L"" ["CyberLink"]

PStarterMusicFilesArrival\
"Provider" = "DVD Suite"
"InvokeProgID" = "MusicFiles"
"InvokeVerb" = "OpenWithPowerStarter"
HKLM\SOFTWARE\Classes\MusicFiles\shell\OpenWithPowerStarter\Command\(Default) = ""C:\Program Files (x86)\CyberLink\DVD Suite\PowerStarter.exe" "%L"" ["CyberLink"]

PStarterPicturesArrival\
"Provider" = "DVD Suite"
"InvokeProgID" = "Picture"
"InvokeVerb" = "OpenWithPowerStarter"
HKLM\SOFTWARE\Classes\Picture\shell\OpenWithPowerStarter\Command\(Default) = ""C:\Program Files (x86)\CyberLink\DVD Suite\PowerStarter.exe" "%L"" ["CyberLink"]

PStarterVideoFilesArrival\
"Provider" = "DVD Suite"
"InvokeProgID" = "VideoFiles"
"InvokeVerb" = "OpenWithPowerStarter"
HKLM\SOFTWARE\Classes\VideoFiles\shell\OpenWithPowerStarter\Command\(Default) = ""C:\Program Files (x86)\CyberLink\DVD Suite\PowerStarter.exe" "%L"" ["CyberLink"]

WIA_{7D1D91D6-5AFC-4608-9BDE-F69B2E575261}\
"Provider" = "HP Photosmart Essential 3.0"
"CLSID" = "{A55803CC-4D53-404c-8557-FD63DBA95D24}"
"InitCmdLine" = "/WiaCmd;C:\Program Files (x86)\HP\Digital Imaging\bin\HpqPsApl.exe;"
-> {HKLM…CLSID} = "WPDShextAutoplay"
\LocalServer32\(Default) = "C:\Windows\system32\WPDShextAutoplay.exe" [MS]

WIA_{A86CE40C-1B18-4caa-A58F-D0AD152FCEB0}\
"Provider" = "muvee Reveal"
"CLSID" = "{A55803CC-4D53-404c-8557-FD63DBA95D24}"
"InitCmdLine" = "/WiaCmd;"C:\Program Files (x86)\muvee Technologies\muvee Reveal - SE\muveereveal.exe" /StiDevice:%1 /StiEvent:%2;"
-> {HKLM…CLSID} = "WPDShextAutoplay"
\LocalServer32\(Default) = "C:\Windows\system32\WPDShextAutoplay.exe" [MS]


Startup items in "Stella" & "All Users" startup folders:
——————————————————–

C:\Users\Stella\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
"ERUNT AutoBackup" -> shortcut to: "C:\Program Files (x86)\ERUNT\AUTOBACK.EXE %SystemRoot%\ERDNT\AutoBackup\#Date# /noconfirmdelete /noprogresswindow" [null data]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
"HP Digital Imaging Monitor" -> shortcut to: "C:\Program Files (x86)\Hp\Digital Imaging\bin\hpqtra08.exe" ["Hewlett-Packard Co."]


Winsock2 Service Provider DLLs:
——————————-

Namespace Service Providers

HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
000000000001\LibraryPath = "%SystemRoot%\system32\NLAapi.dll" [MS]
000000000002\LibraryPath = "%SystemRoot%\system32\napinsp.dll" [MS]
000000000003\LibraryPath = "%SystemRoot%\system32\pnrpnsp.dll" [MS]
000000000004\LibraryPath = "%SystemRoot%\system32\pnrpnsp.dll" [MS]
000000000005\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
000000000006\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
000000000007\LibraryPath = "%SystemRoot%\system32\wshbth.dll" [MS]

Transport Service Providers

HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
%SystemRoot%\system32\mswsock.dll [MS], 01 - 11


Miscellaneous IE Hijack Points
——————————

C:\WINDOWS\INF\IERESET.INF (used to "Reset Web Settings")
<> C:\WINDOWS\INF\IERESET.INF was not found!

HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs\
<> "InPrivate" = "res://ieframe.dll/inprivate.htm" [MS]


Running Services (Display Name, Service Name, Path {Service DLL}):
——————————————————————

Audio Service, STacSV, "C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_7477fb4c\STacSV64.exe" ["IDT, Inc."]
CNG Key Isolation, KeyIso, "C:\Windows\system32\lsass.exe" [MS]
Com4QLBEx, Com4QLBEx, ""C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe"" ["Hewlett-Packard Development Company, L.P."]
Computer Browser, Browser, "C:\Windows\System32\svchost.exe -k netsvcs" {"C:\Windows\System32\browser.dll" [MS]}
Extensible Authentication Protocol, EapHost, "C:\Windows\System32\svchost.exe -k netsvcs" {"C:\Windows\System32\eapsvc.dll" [MS]}
HP CUE DeviceDiscovery Service, hpqddsvc, "C:\Windows\system32\svchost.exe -k hpdevmgmt" {"C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll" ["Hewlett-Packard Co."]}
HP Network Devices Support, HPSLPSVC, "C:\Windows\system32\svchost.exe -k HPService" {"C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL" ["Hewlett-Packard Co."]}
HP Service, hpsrv, "C:\Windows\system32\Hpservice.exe" ["Hewlett-Packard Corporation"]
hpqcxs08, hpqcxs08, "C:\Windows\system32\svchost.exe -k hpdevmgmt" {"C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll" ["Hewlett-Packard Co."]}
hpqwmiex, hpqwmiex, ""C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe"" ["Hewlett-Packard Development Company, L.P."]
Human Interface Device Access, hidserv, "C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted" {"C:\Windows\system32\hidserv.dll" [MS]}
LightScribeService Direct Disc Labeling Service, LightScribeService, ""C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe"" ["Hewlett-Packard Company"]
Net Driver HPZ12, Net Driver HPZ12, "C:\Windows\System32\svchost.exe -k HPZ12" {"C:\Windows\system32\HPZinw12.dll" ["Hewlett-Packard"]}
Pml Driver HPZ12, Pml Driver HPZ12, "C:\Windows\System32\svchost.exe -k HPZ12" {"C:\Windows\system32\HPZipm12.dll" ["Hewlett-Packard"]}
Recovery Service for Windows, Recovery Service for Windows, "C:\Program Files (x86)\SMINST\BLService.exe" [null data]
Windows Driver Foundation - User-mode Driver Framework, wudfsvc, "C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted" {"C:\Windows\System32\WUDFSvc.dll" [MS]}
Windows Image Acquisition (WIA), stisvc, "C:\Windows\system32\svchost.exe -k imgsvc" {"C:\Windows\System32\wiaservc.dll" [MS]}
Windows Presentation Foundation Font Cache 3.0.0.0, FontCache3.0.0.0, "C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe" [MS]
WLAN AutoConfig, Wlansvc, "C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted" {"C:\Windows\System32\wlansvc.dll" [MS]}


Print Monitors:
—————

HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\
PCL Language Monitor\Driver = "hpz3l692.dll" ["Hewlett-Packard Company"]


———- (launch time: 2009-08-27 15:45:22)
<>: Suspicious data at a malware launch point.
<>: Suspicious data at a browser hijack point.

+ This report excludes default entries except where indicated.
+ To see *everywhere* the script checks and *everything* it finds,
launch it from a command prompt or a shortcut with the -all parameter.
+ To search all directories of local fixed drives for DESKTOP.INI
DLL launch points, use the -supp parameter or answer "No" at the
first message box and "Yes" at the second message box.
———- (total run time: 26 seconds, including 6 seconds for message boxes)
your log is a little tougher because of the 64bit system lets do this:

Download OTSto your Desktop
  • Close ALL OTHER PROGRAMS.
  • Double-click on OTS.exe to start the program.
  • Check the box that says Scan All Users
  • Check the box that says 64 bit
  • Under Additional Scans check the following:
    • File - Lop Check
    • File - Purity Scan
    • Evnt - EvtViewer (last 10)
  • Now click the Run Scan button on the toolbar.
  • Let it run unhindered until it finishes.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
Please attach the log in your next post.


good luck mschroe919
Start OTS
Copy/Paste the information inside the quotebox below into the panel where it says "Paste fix here" and then click the Run Fix button.


[Kill All Processes]
[Unregister Dlls]
[Win32 Services - Safe List]
YY -> (iWinTrusted) iWinTrusted [Win32_Shared | Disabled | Stopped] -> C:\Program Files (x86)\iWin Games\iWinTrusted.exe
[Registry - Safe List]
< Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\
YN -> WebBrowser\\"{604BC32A-9680-40D1-9AC6-E06B23A1BA4C}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
< Vista Active Application Exception Rules > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules
YN -> {3338E20B-0EAD-41C3-802A-C9642A690BB7} -> profile=public | protocol=6 | dir=in | action=allow | name=iwin games updater. | app=c:\program files (x86)\iwin games\webupdater.exe |
YN -> {6083B36E-438C-4553-882E-DD761C616D4A} -> profile=public | protocol=6 | dir=in | action=allow | name=iwin games application. | app=c:\program files (x86)\iwin games\iwingames.exe |
YN -> {65CBF4F3-907F-401A-929F-E55FCC992C22} -> profile=public | protocol=17 | dir=in | action=allow | name=iwin games application. | app=c:\program files (x86)\iwin games\iwingames.exe |
[Files/Folders - Created Within 30 Days]
NY -> iWin Games -> C:\Program Files (x86)\iWin Games
NY -> iWin -> C:\Users\Public\Documents\iWin
NY -> iWin Games -> C:\ProgramData\iWin Games
NY -> Play iWin Games.lnk -> C:\Users\Public\Desktop\Play iWin Games.lnk
NY -> iWin.com Games -> C:\Program Files (x86)\iWin.com Games
[Files/Folders - Modified Within 30 Days]
NY -> Play iWin Games.lnk -> C:\Users\Public\Desktop\Play iWin Games.lnk
[Purity]
[Empty Temp Folders]
[Start Explorer]
[Reboot]


The fix should only take a very short time. When the fix is completed a message box will popup either telling you that it is finished, or that a reboot is needed to complete the fix. If the fix is complete, click the Ok button and Notepad will open with a log of actions taken during the fix. Post that log back here in your next reply.

If a reboot is required, click the "Yes" button to reboot the machine. After the reboot, OTS will finish moving any files that could not be moved during the fix and NotePad will open with the final results at that time. Post that log back here in your next reply
All Processes Killed [Win32 Services - Safe List] No service named iWinTrusted was found to stop! No service named iWinTrusted was found to delete! File C:\Program Files (x86)\iWin Games\iWinTrusted.exe not found. [Registry - Safe List] Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{604BC32A-9680-40D1-9AC6-E06B23A1BA4C}\ not found. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{3338E20B-0EAD-41C3-802A-C9642A690BB7} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3338E20B-0EAD-41C3-802A-C9642A690BB7}\ not found. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{6083B36E-438C-4553-882E-DD761C616D4A} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6083B36E-438C-4553-882E-DD761C616D4A}\ not found. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{65CBF4F3-907F-401A-929F-E55FCC992C22} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{65CBF4F3-907F-401A-929F-E55FCC992C22}\ not found. [Files/Folders - Created Within 30 Days] C:\Program Files (x86)\iWin Games\sounds folder moved successfully. C:\Program Files (x86)\iWin Games\pages folder moved successfully. C:\Program Files (x86)\iWin Games\gamepage\styles folder moved successfully. C:\Program Files (x86)\iWin Games\gamepage\scripts folder moved successfully. C:\Program Files (x86)\iWin Games\gamepage\images\product folder moved successfully. C:\Program Files (x86)\iWin Games\gamepage\images\plans folder moved successfully. C:\Program Files (x86)\iWin Games\gamepage\images\ous folder moved successfully. C:\Program Files (x86)\iWin Games\gamepage\images\misc folder moved successfully. C:\Program Files (x86)\iWin Games\gamepage\images\global folder moved successfully. C:\Program Files (x86)\iWin Games\gamepage\images\common folder moved successfully. C:\Program Files (x86)\iWin Games\gamepage\images\buttons folder moved successfully. C:\Program Files (x86)\iWin Games\gamepage\images folder moved successfully. C:\Program Files (x86)\iWin Games\gamepage\css folder moved successfully. C:\Program Files (x86)\iWin Games\gamepage folder moved successfully. C:\Program Files (x86)\iWin Games\firefox\chrome folder moved successfully. C:\Program Files (x86)\iWin Games\firefox folder moved successfully. C:\Program Files (x86)\iWin Games folder moved successfully. C:\Users\Public\Documents\iWin\MahjongQuest2 folder moved successfully. C:\Users\Public\Documents\iWin\JQSolitaire2\cfg\layouts folder moved successfully. C:\Users\Public\Documents\iWin\JQSolitaire2\cfg folder moved successfully. C:\Users\Public\Documents\iWin\JQSolitaire2 folder moved successfully. C:\Users\Public\Documents\iWin\JewelQuest2\cfg\animations folder moved successfully. C:\Users\Public\Documents\iWin\JewelQuest2\cfg folder moved successfully. C:\Users\Public\Documents\iWin\JewelQuest2 folder moved successfully. C:\Users\Public\Documents\iWin\JewelQuest folder moved successfully. C:\Users\Public\Documents\iWin folder moved successfully. C:\ProgramData\iWin Games\opal folder moved successfully. C:\ProgramData\iWin Games\drm\data folder moved successfully. C:\ProgramData\iWin Games\drm folder moved successfully. C:\ProgramData\iWin Games folder moved successfully. C:\Users\Public\Desktop\Play iWin Games.lnk moved successfully. C:\Program Files (x86)\iWin.com Games\Mah Jong Quest II\splash folder moved successfully. C:\Program Files (x86)\iWin.com Games\Mah Jong Quest II\puzzles folder moved successfully. C:\Program Files (x86)\iWin.com Games\Mah Jong Quest II\images\tile folder moved successfully. C:\Program Files (x86)\iWin.com Games\Mah Jong Quest II\images\quest\opening folder moved successfully. C:\Program Files (x86)\iWin.com Games\Mah Jong Quest II\images\quest\ending folder moved successfully. C:\Program Files (x86)\iWin.com Games\Mah Jong Quest II\images\quest\CH8 folder moved successfully. C:\Program Files (x86)\iWin.com Games\Mah Jong Quest II\images\quest\CH7 folder moved successfully. C:\Program Files (x86)\iWin.com Games\Mah Jong Quest II\images\quest\CH6 folder moved successfully. C:\Program Files (x86)\iWin.com Games\Mah Jong Quest II\images\quest\CH5 folder moved successfully. C:\Program Files (x86)\iWin.com Games\Mah Jong Quest II\images\quest\CH4 folder moved successfully. C:\Program Files (x86)\iWin.com Games\Mah Jong Quest II\images\quest\CH3 folder moved successfully. C:\Program Files (x86)\iWin.com Games\Mah Jong Quest II\images\quest\CH2 folder moved successfully. C:\Program Files (x86)\iWin.com Games\Mah Jong Quest II\images\quest\CH1 folder moved successfully. C:\Program Files (x86)\iWin.com Games\Mah Jong Quest II\images\quest folder moved successfully. C:\Program Files (x86)\iWin.com Games\Mah Jong Quest II\images\monster folder moved successfully. C:\Program Files (x86)\iWin.com Games\Mah Jong Quest II\images\interface folder moved successfully. C:\Program Files (x86)\iWin.com Games\Mah Jong Quest II\images\hats folder moved successfully. C:\Program Files (x86)\iWin.com Games\Mah Jong Quest II\images\flash folder moved successfully. C:\Program Files (x86)\iWin.com Games\Mah Jong Quest II\images folder moved successfully. C:\Program Files (x86)\iWin.com Games\Mah Jong Quest II\fonts folder moved successfully. C:\Program Files (x86)\iWin.com Games\Mah Jong Quest II\cfg folder moved successfully. C:\Program Files (x86)\iWin.com Games\Mah Jong Quest II\audio\quest\poems folder moved successfully. C:\Program Files (x86)\iWin.com Games\Mah Jong Quest II\audio\quest\opening folder moved successfully. C:\Program Files (x86)\iWin.com Games\Mah Jong Quest II\audio\quest\moongates folder moved successfully. C:\Program Files (x86)\iWin.com Games\Mah Jong Quest II\audio\quest\ending folder moved successfully. C:\Program Files (x86)\iWin.com Games\Mah Jong Quest II\audio\quest folder moved successfully. C:\Program Files (x86)\iWin.com Games\Mah Jong Quest II\audio folder moved successfully. C:\Program Files (x86)\iWin.com Games\Mah Jong Quest II folder moved successfully. C:\Program Files (x86)\iWin.com Games\Jewel Quest Solitaire II\splash folder moved successfully. C:\Program Files (x86)\iWin.com Games\Jewel Quest Solitaire II\images\story folder moved successfully. C:\Program Files (x86)\iWin.com Games\Jewel Quest Solitaire II\images\mainmenu folder moved successfully. C:\Program Files (x86)\iWin.com Games\Jewel Quest Solitaire II\images\game folder moved successfully. C:\Program Files (x86)\iWin.com Games\Jewel Quest Solitaire II\images folder moved successfully. C:\Program Files (x86)\iWin.com Games\Jewel Quest Solitaire II\fonts folder moved successfully. C:\Program Files (x86)\iWin.com Games\Jewel Quest Solitaire II\cfg\layouts folder moved successfully. C:\Program Files (x86)\iWin.com Games\Jewel Quest Solitaire II\cfg\animations folder moved successfully. C:\Program Files (x86)\iWin.com Games\Jewel Quest Solitaire II\cfg folder moved successfully. C:\Program Files (x86)\iWin.com Games\Jewel Quest Solitaire II\audio folder moved successfully. C:\Program Files (x86)\iWin.com Games\Jewel Quest Solitaire II folder moved successfully. C:\Program Files (x86)\iWin.com Games\Jewel Quest II\splash folder moved successfully. C:\Program Files (x86)\iWin.com Games\Jewel Quest II\images folder moved successfully. C:\Program Files (x86)\iWin.com Games\Jewel Quest II\fonts folder moved successfully. C:\Program Files (x86)\iWin.com Games\Jewel Quest II\cfg\animations folder moved successfully. C:\Program Files (x86)\iWin.com Games\Jewel Quest II\cfg folder moved successfully. C:\Program Files (x86)\iWin.com Games\Jewel Quest II\audio folder moved successfully. C:\Program Files (x86)\iWin.com Games\Jewel Quest II folder moved successfully. C:\Program Files (x86)\iWin.com Games\Jewel Quest\splash folder moved successfully. C:\Program Files (x86)\iWin.com Games\Jewel Quest\images folder moved successfully. C:\Program Files (x86)\iWin.com Games\Jewel Quest\fonts folder moved successfully. C:\Program Files (x86)\iWin.com Games\Jewel Quest\cfg folder moved successfully. C:\Program Files (x86)\iWin.com Games\Jewel Quest\audio folder moved successfully. C:\Program Files (x86)\iWin.com Games\Jewel Quest folder moved successfully. C:\Program Files (x86)\iWin.com Games folder moved successfully. [Files/Folders - Modified Within 30 Days] File C:\Users\Public\Desktop\Play iWin Games.lnk not found! [Purity] Purity scan complete. [Empty Temp Folders] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Public User: Stella File delete failed. C:\Users\Stella\AppData\Local\Temp\ehmsas.txt scheduled to be deleted on reboot. ->Temp folder emptied: 7916 bytes File delete failed. C:\Users\Stella\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. ->Temporary Internet Files folder emptied: 123125329 bytes ->Java cache emptied: 14046590 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes Windows Temp folder emptied: 87820 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 130.94 mb < End of fix log > OTS by OldTimer - Version 3.0.10.3 fix logfile created on 08272009_185033 Files\Folders moved on Reboot… File\Folder C:\Users\Stella\AppData\Local\Temp\ehmsas.txt not found! Registry entries deleted on Reboot…
Hi maax,
getting better lets do this now please:

  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.


NEXT

**Vista users - right click on the IE icon and run as administrator

Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply


In your next reply please include
  • MBAM Log
  • Kaspersky report

good luck mschroe919
•Kaspersky will only run 32-bit Malwarebytes' Anti-Malware 1.40 Database version: 2551 Windows 6.0.6001 Service Pack 1 8/27/2009 8:46:34 PM mbam-log-2009-08-27 (20-46-34).txt Scan type: Quick Scan Objects scanned: 75649 Time elapsed: 1 minute(s), 49 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Sorry it used to but changed do this instead:

Go here to run an online scanner from ESET.
  • Note: You will need to use Internet explorer for this scan
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\Eset\Eset Online Scanner\log.txt
  • Copy and paste that log as a reply to this topic and also let me know how things are now.



OR

Please go HERE to run Panda's ActiveScan
  • Once you are on the Panda site click the Scan your PC Now button
  • A new window will open…click the Check Now button
  • Enter your Country
  • Enter your State/Province
  • Enter your e-mail address and click send
  • Select either Home User or Company
  • Click the big Scan Now button
  • If it wants to install an ActiveX component allow it
  • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
  • When download is complete, click on My Computer to start the scan
  • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location.
    Post the contents of the ActiveScan report
sorry never had all of them to not work on vista 64 bit:

Try one of these:

As a Vista user I will require that all the programs I ask you to run, be run by right clicking the icon and selecting Run as Administrator.


  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.


OR


Please download Dr.Web CureIt . Save it to your desktop:
  • Doubleclick the drweb-cureit.exe file and click Scan to run express scan. Click OK in the pop-up window to allow the scan.
  • This will scan the files currently running in memory and if something is found, click the Yes button when it asks you if you want to cure it. This is only a short scan.
  • Once the short scan has finished, select Complete scan.
  • Click the green arrow [external image: Posted Image] at the right, and the scan will start.
  • Click Yes to all if it asks if you want to cure/move the file.
  • When the scan has finished, in the menu, click File and choose Save report list
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Note:this report may need to be renamed to Dr.Web.txt in order to post it on the forum.
  • Please post the Dr.Web.txt report in your next reply
  • Close Dr.Web Cureit.
  • Important! Reboot your computer because it could be possible that files in use will be moved/deleted during reboot.
NOTE. During the scan, pop-up window will open asking for full version purchase. Simply close the window by clicking on the X in the upper right corner.

good luck mschroe919
How close and can I pick this up tomorrow?


OTL logfile created on: 8/27/2009 10:15:15 PM - Run 1
OTL by OldTimer - Version 3.0.10.7 Folder = C:\Users\Stella\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18813)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.90 Gb Total Physical Memory | 2.53 Gb Available Physical Memory | 64.77% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 452.13 Gb Total Space | 389.16 Gb Free Space | 86.07% Space Free | Partition Type: NTFS
Drive D: | 13.62 Gb Total Space | 2.09 Gb Free Space | 15.35% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: STELLA-PC
Current User Name: Stella
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
PRC - C:\Program Files (x86)\SMINST\BLService.exe ()
PRC - C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe (Hewlett-Packard Company)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe (Hewlett-Packard)
PRC - C:\Program Files (x86)\Hp\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
PRC - C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe (CyberLink)
PRC - C:\Program Files (x86)\Hewlett-Packard\Media\TV\TVAgent.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe ( Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files (x86)\Hp\HP Software Update\hpwuSchd2.exe (Hewlett-Packard)
PRC - C:\Program Files (x86)\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqToaster.exe ()
PRC - C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe (Hewlett-Packard Co.)
PRC - C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe (Hewlett-Packard Co.)
PRC - C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe (Hewlett-Packard)
PRC - C:\Users\Stella\Desktop\OTL.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV:64bit: - (AESTFilters [Disabled | Stopped]) – C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_7477fb4c\AESTSr64.exe ()
SRV:64bit: - (BthServ [Disabled | Stopped]) – C:\Windows\SysNative\bthserv.dll ()
SRV:64bit: - (hpsrv [Auto | Running]) – C:\Windows\SysNative\Hpservice.exe ()
SRV:64bit: - (STacSV [Auto | Running]) – C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_7477fb4c\STacSV64.exe ()
SRV:64bit: - (WinDefend [Auto | Stopped]) – C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SRV:64bit: - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_64 [On_Demand | Stopped]) – C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (Com4QLBEx [On_Demand | Running]) – C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe (Hewlett-Packard Development Company, L.P.)
SRV - (ehRecvr [On_Demand | Stopped]) – C:\Windows\ehome\ehRecvr.exe (Microsoft Corporation)
SRV - (ehSched [On_Demand | Stopped]) – C:\Windows\ehome\ehsched.exe (Microsoft Corporation)
SRV - (ehstart [Auto | Stopped]) – C:\Windows\ehome\ehstart.dll (Microsoft Corporation)
SRV - (FontCache3.0.0.0 [On_Demand | Running]) – C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (GameConsoleService [Disabled | Stopped]) – C:\Program Files (x86)\HP Games\My HP Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (HP Health Check Service [Disabled | Stopped]) – c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe (Hewlett-Packard)
SRV - (hpqcxs08 [On_Demand | Running]) – C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll (Hewlett-Packard Co.)
SRV - (hpqddsvc [Auto | Running]) – C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll (Hewlett-Packard Co.)
SRV - (hpqwmiex [On_Demand | Running]) – C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe (Hewlett-Packard Development Company, L.P.)
SRV - (HPSLPSVC [Auto | Running]) – C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL (Hewlett-Packard Co.)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (idsvc [Unknown | Stopped]) – C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (KeyIso [On_Demand | Running]) – C:\Windows\SysWow64\keyiso.dll (Microsoft Corporation)
SRV - (LightScribeService [Auto | Running]) – C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
SRV - (MSDTC [Unknown | Stopped]) – C:\Windows\SysWow64\Msdtc [2006/11/02 09:34:14 | 00,000,000 | —D | M]
SRV - (Netlogon [On_Demand | Stopped]) – C:\Windows\SysWow64\netlogon.dll (Microsoft Corporation)
SRV - (Norton Internet Security [Disabled | Stopped]) – C:\Program Files (x86)\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe (Symantec Corporation)
SRV - (odserv [Disabled | Stopped]) – C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (ose [Disabled | Stopped]) – C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (Recovery Service for Windows [Auto | Running]) – C:\Program Files (x86)\SMINST\BLService.exe ()
SRV - (RichVideo [Disabled | Stopped]) – C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe ()
SRV - (TVCapSvc [Disabled | Stopped]) – C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe ()
SRV - (TVSched [Disabled | Stopped]) – C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe ()
SRV - (vds [On_Demand | Stopped]) – C:\Windows\SysWow64\Wbem\vds.mof ()
SRV - (VSS [On_Demand | Stopped]) – C:\Windows\SysWow64\Wbem\vss.mof ()

========== Driver Services (SafeList) ==========

DRV:64bit: - (Accelerometer [On_Demand | Running]) – C:\Windows\SysNative\DRIVERS\Accelerometer.sys ()
DRV:64bit: - (athr [On_Demand | Running]) – C:\Windows\SysNative\DRIVERS\athrx.sys ()
DRV:64bit: - (BHDrvx64 [System | Running]) – C:\Windows\SysNative\drivers\NISx64\1005000.087\BHDrvx64.sys ()
DRV:64bit: - (BthEnum [On_Demand | Stopped]) – C:\Windows\SysNative\DRIVERS\BthEnum.sys ()
DRV:64bit: - (BthPan [On_Demand | Stopped]) – C:\Windows\SysNative\DRIVERS\bthpan.sys ()
DRV:64bit: - (BTHPORT [On_Demand | Stopped]) – C:\Windows\SysNative\Drivers\BTHport.sys ()
DRV:64bit: - (BTHUSB [On_Demand | Stopped]) – C:\Windows\SysNative\Drivers\BTHUSB.sys ()
DRV:64bit: - (ccHP [System | Running]) – C:\Windows\SysNative\Drivers\NISx64\1005000.087\ccHPx64.sys ()
DRV:64bit: - (CmBatt [On_Demand | Running]) – C:\Windows\SysNative\DRIVERS\CmBatt.sys ()
DRV:64bit: - (enecir [On_Demand | Running]) – C:\Windows\SysNative\DRIVERS\enecir.sys ()
DRV:64bit: - (HdAudAddService [On_Demand | Stopped]) – C:\Windows\SysNative\drivers\HdAudio.sys ()
DRV:64bit: - (hpdskflt [Boot | Running]) – C:\Windows\SysNative\DRIVERS\hpdskflt.sys ()
DRV:64bit: - (HpqKbFiltr [On_Demand | Running]) – C:\Windows\SysNative\DRIVERS\HpqKbFiltr.sys ()
DRV:64bit: - (igfx [On_Demand | Running]) – C:\Windows\SysNative\DRIVERS\igdkmd64.sys ()
DRV:64bit: - (IntcHdmiAddService [On_Demand | Running]) – C:\Windows\SysNative\drivers\IntcHdmi.sys ()
DRV:64bit: - (NETw3v64 [On_Demand | Stopped]) – C:\Windows\SysNative\DRIVERS\NETw3v64.sys ()
DRV:64bit: - (RFCOMM [On_Demand | Stopped]) – C:\Windows\SysNative\DRIVERS\rfcomm.sys ()
DRV:64bit: - (RTL8169 [On_Demand | Running]) – C:\Windows\SysNative\DRIVERS\Rtlh64.sys ()
DRV:64bit: - (RTSTOR [On_Demand | Running]) – C:\Windows\SysNative\drivers\RTSTOR64.SYS ()
DRV:64bit: - (sdbus [On_Demand | Stopped]) – C:\Windows\SysNative\DRIVERS\sdbus.sys ()
DRV:64bit: - (SRTSP [On_Demand | Stopped]) – C:\Windows\SysNative\Drivers\NISx64\1005000.087\SRTSP64.SYS ()
DRV:64bit: - (SRTSPX [System | Running]) – C:\Windows\SysNative\drivers\NISx64\1005000.087\SRTSPX64.SYS ()
DRV:64bit: - (STHDA [On_Demand | Running]) – C:\Windows\SysNative\DRIVERS\stwrt64.sys ()
DRV:64bit: - (StillCam [On_Demand | Running]) – C:\Windows\SysNative\DRIVERS\serscan.sys ()
DRV:64bit: - (SymEFA [Boot | Running]) – C:\Windows\SysNative\drivers\NISx64\1005000.087\SYMEFA64.SYS ()
DRV:64bit: - (SymEvent [On_Demand | Running]) – C:\Windows\SysNative\Drivers\SYMEVENT64x86.SYS ()
DRV:64bit: - (SYMFW [On_Demand | Running]) – C:\Windows\SysNative\Drivers\NISx64\1005000.087\SYMFW.SYS ()
DRV:64bit: - (SymIM [System | Running]) – C:\Windows\SysNative\DRIVERS\SymIMv.sys ()
DRV:64bit: - (SYMNDISV [On_Demand | Running]) – C:\Windows\SysNative\Drivers\NISx64\1005000.087\SYMNDISV.SYS ()
DRV:64bit: - (SYMTDI [System | Running]) – C:\Windows\SysNative\Drivers\NISx64\1005000.087\SYMTDI.SYS ()
DRV:64bit: - (SynTP [On_Demand | Running]) – C:\Windows\SysNative\DRIVERS\SynTP.sys ()
DRV:64bit: - (usbvideo [On_Demand | Running]) – C:\Windows\SysNative\Drivers\usbvideo.sys ()
DRV:64bit: - (yukonx64 [On_Demand | Stopped]) – C:\Windows\SysNative\DRIVERS\yk60x64.sys ()
DRV - (eeCtrl [System | Running]) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv [On_Demand | Running]) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (IDSVia64 [System | Running]) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20090810.001\IDSvia64.sys (Symantec Corporation)
DRV - (mpsdrv [On_Demand | Running]) – C:\Windows\SysWow64\Wbem\mpsdrv.mof ()
DRV - (NAVENG [On_Demand | Stopped]) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090826.053\ENG64.SYS (Symantec Corporation)
DRV - (NAVEX15 [On_Demand | Stopped]) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090826.053\EX64.SYS (Symantec Corporation)
DRV - (Tcpip [Boot | Running]) – C:\Windows\SysWow64\Wbem\tcpip.mof ()
DRV - ({55662437-DA8C-40c0-AADA-2C816A897A49} [Auto | Running]) – C:\Program Files (x86)\Hewlett-Packard\Media\DVD\000.fcl (CyberLink Corp.)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cnnb
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\System32\blank.htm
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cnnb
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cnnb
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cnnb

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cnnb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/07/16 09:15:20 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2 [2009/07/14 18:30:02 | 00,000,000 | —D | M]


O1 HOSTS File: (761 bytes) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\16.5.0.135\coIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\16.5.0.135\IPSBHO.DLL (Symantec Corporation)
O2 - BHO: (Microsoft Live Search Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0541.0\msneshellx.dll (Microsoft Corp.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (Microsoft Live Search Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0541.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\16.5.0.135\coIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\16.5.0.135\coIEPlg.dll (Symantec Corporation)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe ()
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe ()
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe ()
O4:64bit: - HKLM..\Run: [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe (Hewlett-Packard)
O4:64bit: - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4:64bit: - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [CLMLServer for HP TouchSmart] C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe (CyberLink)
O4 - HKLM..\Run: [DVDAgent] C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe (CyberLink Corp.)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe (Hewlett-Packard)
O4 - HKLM..\Run: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe (Hewlett-Packard)
O4 - HKLM..\Run: [QlbCtrl.exe] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe ( Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files (x86)\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [TSMAgent] C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe (CyberLink Corp.)
O4 - HKLM..\Run: [TVAgent] C:\Program Files (x86)\Hewlett-Packard\Media\TV\TVAgent.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UCam_Menu] C:\Program Files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateLBPShortCut] C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateP2GoShortCut] C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePDIRShortCut] C:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePSTShortCut] C:\Program Files (x86)\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [WirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe (Hewlett-Packard)
O4 - HKCU..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe (Microsoft Corporation)
O4 - HKCU..\Run: [HPAdvisor] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe (Hewlett-Packard)
O4 - HKCU..\Run: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe (Hewlett-Packard Company)
O4 - Startup: C:\Users\Stella\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files (x86)\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceActiveDesktopOn = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O8:64bit: - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files (x86)\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Windows\SysNative\wshbth.dll ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Windows\SysWow64\wshbth.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_12)
O16 - DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_12)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_12)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18:64bit: - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll ()
O18:64bit: - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll ()
O18:64bit: - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll ()
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll ()
O18:64bit: - Protocol\Handler\symres {AA1061FE-6C41-421f-9344-69640C9732AB} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll ()
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files (x86)\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files (x86)\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\symres {AA1061FE-6C41-421f-9344-69640C9732AB} - C:\Program Files (x86)\Norton Internet Security\Engine\16.5.0.135\coIEPlg.dll (Symantec Corporation)
O18:64bit: - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - C:\Windows\SysNative\igfxdev.dll ()
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\Windows\SysWow64\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found

========== Files/Folders - Created Within 30 Days ==========

[2009/08/27 22:12:54 | 00,514,048 | —- | C] (OldTimer Tools) – C:\Users\Stella\Desktop\OTL.exe
[2009/08/27 21:20:03 | 00,000,000 | —D | C] – C:\Program Files (x86)\ESET
[2009/08/27 18:39:59 | 00,000,000 | —D | C] – C:\_OTS
[2009/08/27 17:29:27 | 00,514,048 | —- | C] (OldTimer Tools) – C:\Users\Stella\Desktop\OTS.exe
[2009/08/27 15:43:36 | 00,400,192 | —- | C] () – C:\Users\Stella\Desktop\Silent Runners.vbs
[2009/08/27 14:19:32 | 00,001,928 | —- | C] () – C:\Users\Stella\Desktop\HijackThis.lnk
[2009/08/27 14:19:32 | 00,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2009/08/27 14:18:21 | 00,812,344 | —- | C] (Trend Micro Inc.) – C:\Users\Stella\Desktop\HJTInstall.exe
[2009/08/27 14:10:55 | 02,004,727 | -H– | C] () – C:\Users\Stella\AppData\Local\IconCache.db
[2009/08/27 13:05:13 | 00,000,000 | —D | C] – C:\Users\Stella\AppData\Roaming\Malwarebytes
[2009/08/27 13:05:11 | 00,000,848 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/08/27 13:05:09 | 00,038,160 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2009/08/27 13:05:06 | 00,022,040 | —- | C] () – C:\Windows\SysNative\drivers\mbam.sys
[2009/08/27 13:05:06 | 00,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2009/08/27 13:05:06 | 00,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2009/08/27 13:03:37 | 03,942,080 | —- | C] (Malwarebytes Corporation ) – C:\Users\Stella\Desktop\mbam-setup.exe
[2009/08/27 13:00:37 | 00,050,688 | —- | C] (Atribune.org) – C:\Users\Stella\Desktop\ATF-Cleaner.exe
[2009/08/27 12:58:37 | 00,000,000 | —D | C] – C:\Windows\ERDNT
[2009/08/27 12:58:09 | 00,000,943 | —- | C] () – C:\Users\Stella\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/08/27 12:58:00 | 00,000,763 | —- | C] () – C:\Users\Stella\Desktop\NTREGOPT.lnk
[2009/08/27 12:58:00 | 00,000,744 | —- | C] () – C:\Users\Stella\Desktop\ERUNT.lnk
[2009/08/27 12:57:59 | 00,000,000 | —D | C] – C:\Program Files (x86)\ERUNT
[2009/08/27 12:48:23 | 41,932,10368 | -HS- | C] () – C:\hiberfil.sys
[2009/08/27 12:45:52 | 00,000,000 | —D | C] – C:\Windows\pss
[2009/08/27 05:19:21 | 00,000,000 | —D | C] – C:\Windows\Minidump
[2009/08/27 05:18:43 | 48,340,3331 | —- | C] () – C:\Windows\MEMORY.DMP
[2009/08/27 05:08:21 | 00,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\tzres.dll
[2009/08/27 05:08:21 | 00,002,048 | —- | C] () – C:\Windows\SysNative\tzres.dll
[2009/08/26 06:06:56 | 00,000,949 | —- | C] () – C:\Users\Stella\Desktop\Internet Explorer (64-bit) (2).lnk
[2009/08/26 06:02:57 | 04,682,824 | —- | C] () – C:\Windows\SysNative\ntoskrnl.exe
[2009/08/26 06:02:28 | 00,032,256 | —- | C] () – C:\Windows\SysNative\Apphlpdm.dll
[2009/08/26 06:02:28 | 00,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\Apphlpdm.dll
[2009/08/26 06:02:27 | 04,240,384 | —- | C] (Microsoft) – C:\Windows\SysWow64\GameUXLegacyGDFs.dll
[2009/08/26 06:02:27 | 04,240,384 | —- | C] () – C:\Windows\SysNative\GameUXLegacyGDFs.dll
[2009/08/25 14:32:35 | 00,000,000 | —D | C] – C:\Users\Stella\AppData\Local\Yahoo
[2009/08/25 14:29:36 | 00,000,000 | —D | C] – C:\ProgramData\Yahoo!
[2009/08/20 09:25:06 | 00,000,000 | -HSD | C] – C:\Users\Public\Documents\MCE Logs
[2009/08/20 09:05:10 | 00,084,455 | —- | C] () – C:\Users\Stella\Documents\0820090729a.jpg
[2009/08/18 09:20:13 | 00,034,309 | —- | C] () – C:\Users\Stella\Documents\Police Signal Codes.docx
[2009/08/16 14:53:40 | 00,017,276 | —- | C] () – C:\Users\Stella\Documents\FAMILY TREE.xlsx
[2009/08/16 10:18:30 | 00,656,384 | —- | C] () – C:\Windows\SysNative\kerberos.dll
[2009/08/16 10:18:29 | 01,692,160 | —- | C] () – C:\Windows\SysNative\lsasrv.dll
[2009/08/16 10:18:29 | 00,268,800 | —- | C] () – C:\Windows\SysNative\msv1_0.dll
[2009/08/16 10:18:28 | 00,499,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\kerberos.dll
[2009/08/16 10:18:28 | 00,213,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msv1_0.dll
[2009/08/16 10:18:28 | 00,205,312 | —- | C] () – C:\Windows\SysNative\wdigest.dll
[2009/08/16 10:18:28 | 00,175,104 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wdigest.dll
[2009/08/16 10:18:27 | 00,515,656 | —- | C] () – C:\Windows\SysNative\drivers\ksecdd.sys
[2009/08/16 10:18:27 | 00,338,944 | —- | C] () – C:\Windows\SysNative\schannel.dll
[2009/08/16 10:18:26 | 00,270,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\schannel.dll
[2009/08/16 10:18:26 | 00,094,720 | —- | C] () – C:\Windows\SysNative\secur32.dll
[2009/08/16 10:18:26 | 00,076,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\secur32.dll
[2009/08/16 10:18:26 | 00,011,264 | —- | C] () – C:\Windows\SysNative\lsass.exe
[2009/08/13 08:50:48 | 00,000,000 | —D | C] – C:\Users\Stella\AppData\Roaming\CyberLink
[2009/08/12 22:26:09 | 02,423,296 | —- | C] () – C:\Windows\SysNative\mstscax.dll
[2009/08/12 22:26:08 | 02,066,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mstscax.dll
[2009/08/12 22:26:02 | 00,088,576 | —- | C] () – C:\Windows\SysNative\atl.dll
[2009/08/12 22:26:02 | 00,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\atl.dll
[2009/08/12 22:25:57 | 00,202,752 | —- | C] () – C:\Windows\SysNative\wkssvc.dll
[2009/08/12 22:25:54 | 00,108,544 | —- | C] () – C:\Windows\SysNative\avifil32.dll
[2009/08/12 22:25:54 | 00,093,184 | —- | C] () – C:\Windows\SysNative\mciavi32.dll
[2009/08/12 22:25:54 | 00,076,800 | —- | C] () – C:\Windows\SysNative\avicap32.dll
[2009/08/12 22:25:53 | 00,091,136 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\avifil32.dll
[2009/08/12 22:25:35 | 13,426,176 | —- | C] () – C:\Windows\SysNative\wmp.dll
[2009/08/12 22:25:30 | 10,624,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wmp.dll
[2009/08/12 22:25:30 | 00,368,128 | —- | C] () – C:\Windows\SysNative\wmpdxm.dll
[2009/08/12 22:25:30 | 00,313,344 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wmpdxm.dll
[2009/08/12 22:25:27 | 00,009,216 | —- | C] () – C:\Windows\SysNative\spwmp.dll
[2009/08/12 22:25:27 | 00,007,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\spwmp.dll
[2009/08/12 22:25:26 | 00,005,120 | —- | C] () – C:\Windows\SysNative\msdxm.ocx
[2009/08/12 22:25:26 | 00,005,120 | —- | C] () – C:\Windows\SysNative\dxmasf.dll
[2009/08/12 22:25:26 | 00,004,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msdxm.ocx
[2009/08/12 22:25:26 | 00,004,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dxmasf.dll
[2009/08/12 22:25:25 | 08,147,968 | —- | C] () – C:\Windows\SysNative\wmploc.DLL
[2009/08/12 22:25:25 | 08,147,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wmploc.DLL
[2009/08/12 22:25:25 | 00,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msdxm.tlb
[2009/08/12 22:25:25 | 00,043,520 | —- | C] () – C:\Windows\SysNative\msdxm.tlb
[2009/08/12 22:25:25 | 00,018,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\amcompat.tlb
[2009/08/12 22:25:25 | 00,018,432 | —- | C] () – C:\Windows\SysNative\amcompat.tlb
[2009/08/11 09:29:31 | 00,000,000 | —D | C] – C:\Users\Stella\AppData\Local\HP
[2009/08/11 09:28:26 | 00,000,000 | —D | C] – C:\Users\Stella\AppData\Local\CyberLink
[2009/08/11 09:28:25 | 00,000,000 | —D | C] – C:\Users\Stella\AppData\Local\PowerCinema
[2009/08/03 17:14:11 | 00,003,584 | —- | C] () – C:\Users\Stella\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/08/01 07:28:43 | 00,000,904 | —- | C] () – C:\Users\Public\Desktop\Acrobat.com.lnk
[2009/08/01 07:28:10 | 00,000,000 | —D | C] – C:\Users\Stella\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2009/08/01 07:25:31 | 00,234,500 | —- | C] () – C:\Users\Stella\Documents\Bank Bus.July 2009.xps
[2009/07/30 16:17:30 | 00,000,374 | —- | C] () – C:\Users\Stella\Desktop\Documents - Shortcut.lnk
[2009/07/29 07:18:20 | 09,233,408 | —- | C] () – C:\Windows\SysNative\mshtml.dll
[2009/07/29 07:18:20 | 05,937,152 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtml.dll
[2009/07/29 07:18:18 | 12,458,496 | —- | C] () – C:\Windows\SysNative\ieframe.dll
[2009/07/29 07:18:18 | 11,067,392 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieframe.dll
[2009/07/29 07:18:17 | 02,334,208 | —- | C] () – C:\Windows\SysNative\iertutil.dll
[2009/07/29 07:18:17 | 01,985,536 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iertutil.dll
[2009/07/29 07:18:16 | 01,484,288 | —- | C] () – C:\Windows\SysNative\urlmon.dll
[2009/07/29 07:18:16 | 01,208,832 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\urlmon.dll
[2009/07/29 07:18:16 | 01,146,880 | —- | C] () – C:\Windows\SysNative\wininet.dll
[2009/07/29 07:18:16 | 00,915,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wininet.dll
[2009/07/29 07:18:16 | 00,594,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeeds.dll
[2009/07/29 07:18:16 | 00,458,240 | —- | C] () – C:\Windows\SysNative\iedkcs32.dll
[2009/07/29 07:18:16 | 00,243,712 | —- | C] () – C:\Windows\SysNative\occache.dll
[2009/07/29 07:18:16 | 00,206,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\occache.dll
[2009/07/29 07:18:15 | 01,538,560 | —- | C] () – C:\Windows\SysNative\inetcpl.cpl
[2009/07/29 07:18:15 | 01,469,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2009/07/29 07:18:15 | 00,700,928 | —- | C] () – C:\Windows\SysNative\msfeeds.dll
[2009/07/29 07:18:15 | 00,386,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iedkcs32.dll
[2009/07/29 07:18:15 | 00,184,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2009/07/29 07:18:15 | 00,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2009/07/29 07:18:15 | 00,162,816 | —- | C] () – C:\Windows\SysNative\ieUnatt.exe
[2009/07/29 07:18:15 | 00,133,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2009/07/29 07:18:15 | 00,070,656 | —- | C] () – C:\Windows\SysNative\ie4uinit.exe
[2009/07/29 07:18:15 | 00,055,296 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedsbs.dll
[2009/07/29 07:18:14 | 01,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtml.tlb
[2009/07/29 07:18:14 | 01,638,912 | —- | C] () – C:\Windows\SysNative\mshtml.tlb
[2009/07/29 07:18:14 | 00,252,416 | —- | C] () – C:\Windows\SysNative\iepeers.dll
[2009/07/29 07:18:14 | 00,219,136 | —- | C] () – C:\Windows\SysNative\ieui.dll
[2009/07/29 07:18:14 | 00,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ie4uinit.exe
[2009/07/29 07:18:14 | 00,132,096 | —- | C] () – C:\Windows\SysNative\iesysprep.dll
[2009/07/29 07:18:14 | 00,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2009/07/29 07:18:14 | 00,077,312 | —- | C] () – C:\Windows\SysNative\iesetup.dll
[2009/07/29 07:18:14 | 00,072,192 | —- | C] () – C:\Windows\SysNative\iernonce.dll
[2009/07/29 07:18:14 | 00,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2009/07/29 07:18:14 | 00,071,680 | —- | C] () – C:\Windows\SysNative\msfeedsbs.dll
[2009/07/29 07:18:14 | 00,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2009/07/29 07:18:14 | 00,031,744 | —- | C] () – C:\Windows\SysNative\jsproxy.dll
[2009/07/29 07:18:14 | 00,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jsproxy.dll
[2009/07/29 07:18:14 | 00,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2009/07/29 07:18:14 | 00,012,288 | —- | C] () – C:\Windows\SysNative\msfeedssync.exe
[2009/07/29 07:18:13 | 00,057,667 | —- | C] () – C:\Windows\SysWow64\ieuinit.inf
[2009/07/29 07:18:13 | 00,057,667 | —- | C] () – C:\Windows\SysNative\ieuinit.inf
[2008/01/20 22:50:05 | 00,060,124 | —- | C] () – C:\Windows\SysWow64\tcpmon.ini
[2008/01/20 22:49:49 | 00,368,640 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2006/11/02 08:34:27 | 00,000,219 | —- | C] () – C:\Windows\system.ini
[2006/11/02 08:34:27 | 00,000,179 | —- | C] () – C:\Windows\win.ini

========== Files - Modified Within 30 Days ==========

[2009/08/27 22:13:56 | 00,514,048 | —- | M] (OldTimer Tools) – C:\Users\Stella\Desktop\OTL.exe
[2009/08/27 20:59:17 | 00,003,216 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2009/08/27 20:59:17 | 00,003,216 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2009/08/27 18:59:22 | 00,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2009/08/27 18:59:12 | 00,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2009/08/27 18:59:08 | 41,932,10368 | -HS- | M] () – C:\hiberfil.sys
[2009/08/27 18:59:05 | 48,340,3331 | —- | M] () – C:\Windows\MEMORY.DMP
[2009/08/27 18:58:13 | 02,004,727 | -H– | M] () – C:\Users\Stella\AppData\Local\IconCache.db
[2009/08/27 17:29:28 | 00,514,048 | —- | M] (OldTimer Tools) – C:\Users\Stella\Desktop\OTS.exe
[2009/08/27 15:43:38 | 00,400,192 | —- | M] () – C:\Users\Stella\Desktop\Silent Runners.vbs
[2009/08/27 14:19:32 | 00,001,928 | —- | M] () – C:\Users\Stella\Desktop\HijackThis.lnk
[2009/08/27 14:18:51 | 00,812,344 | —- | M] (Trend Micro Inc.) – C:\Users\Stella\Desktop\HJTInstall.exe
[2009/08/27 13:05:11 | 00,000,848 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/08/27 13:04:07 | 03,942,080 | —- | M] (Malwarebytes Corporation ) – C:\Users\Stella\Desktop\mbam-setup.exe
[2009/08/27 13:00:46 | 00,050,688 | —- | M] (Atribune.org) – C:\Users\Stella\Desktop\ATF-Cleaner.exe
[2009/08/27 12:58:09 | 00,000,943 | —- | M] () – C:\Users\Stella\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/08/27 12:58:00 | 00,000,763 | —- | M] () – C:\Users\Stella\Desktop\NTREGOPT.lnk
[2009/08/27 12:58:00 | 00,000,744 | —- | M] () – C:\Users\Stella\Desktop\ERUNT.lnk
[2009/08/27 05:13:53 | 00,000,012 | —- | M] () – C:\Windows\bthservsdp.dat
[2009/08/26 06:06:56 | 00,000,949 | —- | M] () – C:\Users\Stella\Desktop\Internet Explorer (64-bit) (2).lnk
[2009/08/22 05:16:10 | 00,000,680 | —- | M] () – C:\Users\Stella\AppData\Local\d3d9caps.dat
[2009/08/20 09:05:10 | 00,084,455 | —- | M] () – C:\Users\Stella\Documents\0820090729a.jpg
[2009/08/18 09:22:43 | 00,034,309 | —- | M] () – C:\Users\Stella\Documents\Police Signal Codes.docx
[2009/08/16 14:53:40 | 00,017,276 | —- | M] () – C:\Users\Stella\Documents\FAMILY TREE.xlsx
[2009/08/14 17:22:03 | 00,000,338 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForStella.job
[2009/08/03 17:15:15 | 00,690,960 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2009/08/03 17:15:15 | 00,595,684 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2009/08/03 17:15:15 | 00,101,350 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2009/08/03 17:14:15 | 00,003,584 | —- | M] () – C:\Users\Stella\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/08/03 13:36:28 | 00,038,160 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2009/08/03 13:36:08 | 00,022,040 | —- | M] () – C:\Windows\SysNative\drivers\mbam.sys
[2009/08/01 14:30:33 | 00,001,917 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2009/08/01 07:28:43 | 00,000,904 | —- | M] () – C:\Users\Public\Desktop\Acrobat.com.lnk
[2009/08/01 07:25:35 | 00,234,500 | —- | M] () – C:\Users\Stella\Documents\Bank Bus.July 2009.xps
[2009/07/30 16:17:30 | 00,000,374 | —- | M] () – C:\Users\Stella\Desktop\Documents - Shortcut.lnk
[2009/07/29 21:20:46 | 26,162,632 | —- | M] () – C:\Windows\SysNative\mrt.exe

========== LOP Check ==========

[2009/08/27 13:05:13 | 00,000,000 | —D | M] – C:\Users\Stella\AppData\Roaming
[2009/08/01 07:28:10 | 00,000,000 | —D | M] – C:\Users\Stella\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2009/08/13 08:50:48 | 00,000,000 | —D | M] – C:\Users\Stella\AppData\Roaming\CyberLink
[2006/11/02 11:07:25 | 00,000,000 | —D | M] – C:\Users\Stella\AppData\Roaming\Media Center Programs
[2009/07/19 18:57:37 | 00,000,000 | —D | M] – C:\Users\Stella\AppData\Roaming\WildTangent
[2009/08/14 17:22:03 | 00,000,338 | —- | M] () – C:\Windows\Tasks\HPCeeScheduleForStella.job
[2009/08/27 18:59:22 | 00,000,006 | -H– | M] () – C:\Windows\Tasks\SA.DAT
[2009/08/27 14:10:58 | 00,032,552 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========


< End of report >


OTL Extras logfile created on: 8/27/2009 10:15:15 PM - Run 1
OTL by OldTimer - Version 3.0.10.7 Folder = C:\Users\Stella\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18813)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.90 Gb Total Physical Memory | 2.53 Gb Available Physical Memory | 64.77% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 452.13 Gb Total Space | 389.16 Gb Free Space | 86.07% Space Free | Partition Type: NTFS
Drive D: | 13.62 Gb Total Space | 2.09 Gb Free Space | 15.35% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: STELLA-PC
Current User Name: Stella
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl[@ = cplfile] – C:\Windows\SysNative\control.exe ()
.hlp[@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.html[@ = htmlfile] – C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation)
.inf[@ = inffile] – C:\Windows\SysNative\NOTEPAD.EXE ()
.ini[@ = inifile] – C:\Windows\SysNative\NOTEPAD.EXE ()
.url[@ = InternetShortcut] – C:\Windows\System32\ieframe.DLL (Microsoft Corporation)
.js[@ = JSFile] – C:\Windows\SysNative\WScript.exe ()
.jse[@ = JSEFile] – C:\Windows\SysNative\WScript.exe ()
.txt[@ = txtfile] – C:\Windows\SysNative\NOTEPAD.EXE ()
.vbe[@ = VBEFile] – C:\Windows\SysNative\WScript.exe ()
.vbs[@ = VBSFile] – C:\Windows\SysNative\WScript.exe ()
.wsf[@ = WSFFile] – C:\Windows\SysNative\WScript.exe ()
.wsh[@ = WSHFile] – C:\Windows\SysNative\WScript.exe ()

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = htmlfile] – C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation)
.reg [@ = regfile] – C:\Windows\SysWow64\regedit.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = 9F 9E 16 8C DC 5B C8 01 [binary data]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"oobe_av" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{2368C798-EAF3-463A-905A-2BADA1003D2C}" = rport=427 | protocol=17 | dir=in | svc=hpslpsvc | app=c:\windows\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{01A0E17F-3958-4E08-88AC-AECC40DB070C}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\tv\qp.exe |
"{08D49EFA-6075-4564-B76D-DA0FACFF2464}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqtra08.exe |
"{0A09EED7-5352-402C-AB7D-D49826661F54}" = protocol=6 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe |
"{1B46BD1A-996D-4D61-8347-F23DA6C86FBC}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\tv\qpservice.exe |
"{1E5C9545-A96E-4536-8633-F1EC84507D50}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqsudi.exe |
"{31256C6A-134D-44F9-8603-8074BA5C0136}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hpdvdsmart.exe |
"{513C12ED-52A4-4742-AB51-30488DAFF5D9}" = protocol=17 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe |
"{574EC9B2-1590-4A06-BB32-B94386C1D43B}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{680B359E-5169-43CD-8CD2-B20B5B405079}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\clml\clmlsvc.exe |
"{7EE80282-AEA0-4A97-B6D7-5132470A821E}" = dir=in | app=c:\program files (x86)\common files\hp\digital imaging\bin\hpqphotocrm.exe |
"{85CA64C5-0E24-49D3-962C-757C4D4EF5EA}" = dir=in | app=c:\program files (x86)\cyberlink\powerdirector\pdr.exe |
"{9E2EA70D-A6E0-483B-A593-C64C48C18C58}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqgpc01.exe |
"{A35FF97B-AA51-4411-860D-29990524F34D}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqpsapp.exe |
"{A41927EA-CBBA-4942-9BCD-626B68477D69}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqkygrp.exe |
"{A67DAC51-590B-4ADE-A5A6-E8B61E545E35}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpoews01.exe |
"{A79A5A50-5E41-482A-976E-7477F4CA1495}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\hptouchsmartvideo.exe |
"{A9576165-3DF6-4B42-BF83-668E0C38B4F7}" = protocol=17 | dir=in | app=c:\program files (x86)\iwin games\webupdater.exe |
"{B84CB06C-077C-4A39-9EBE-B594D52F5888}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hptouchsmartmusic.exe |
"{B894CF8C-B431-4C80-BAD0-6F8A5E68D395}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\kernel\clml\clmlsvc.exe |
"{C4CA4B22-0481-4462-8187-DC25A052AFF6}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqgplgtupl.exe |
"{CAE41ADC-9D05-4DB1-8BED-BDEAD58C7871}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqste08.exe |
"{CC10051D-EB96-4904-8DDB-23ABA11C1E33}" = dir=in | app=e:\setup\hpznui40.exe |
"{CDCBFCBC-C1BB-4230-9CC7-EBC542D5D09D}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\tsmagent.exe |
"{D31CFADD-BA90-41DB-8799-1128C9F84576}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\hptouchsmartmusic.exe |
"{D7494EBB-6440-4C53-9CB6-1D075E2761EC}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{DBADE3E2-6607-4648-97EA-C4359897A519}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hptouchsmartvideo.exe |
"{E047F2E8-782A-41A4-BDEB-53F50943ADE1}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\hptouchsmartphoto.exe |
"{E1424513-DB8A-4EF6-863F-8C1A000AC022}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hptouchsmartphoto.exe |
"{EAAD154C-C466-4370-95E2-A5BEEFB3BDA2}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqpse.exe |
"{ED5D8508-4F13-4B10-BFC1-6C0F1A6CB1A0}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hposid01.exe |
"{EE34DD38-8A33-4849-A498-F83839472697}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpiscnapp.exe |
"{F4E3F926-4D97-4394-BF90-189711ED7006}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\tsmagent.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{0BC595C4-F736-4EB4-A1C0-32C7E81800F0}" = HP MediaSmart SmartMenu
"{26A24AE4-039D-4CA4-87B4-2F86416012FF}" = Java™ 6 Update 12 (64-bit)
"{2F97CE84-9C33-4631-821B-85EA371EA254}" = ProtectSmart Hard Drive Protection
"{4FFA2088-8317-3B14-93CD-4C699DB37843}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729
"{78F697ED-EC97-4D8D-881D-838984EA9855}" = 64 Bit HP CIO Components Installer
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{BED1705F-7558-40f7-9F52-6C6FBD58EA2E}" = HP Photosmart C4500 All-In-One Driver Software 11.0 Rel .4
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{DDEDFD63-E430-4b0c-8D61-5E4E7280F027}" = Network64
"{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148
"703AB19C282B6ED3F1D3CE92F8DAA864B68A7C91" = ENE CIR Receiver Driver (12/30/2008 2.7.2.0)
"HDMI" = Intel® Graphics Media Accelerator Driver
"HP Imaging Device Functions" = HP Imaging Device Functions 11.0
"HP Photosmart Essential" = HP Photosmart Essential 3.0
"HP Smart Web Printing" = HP Smart Web Printing
"HP Solution Center & Imaging Support Tools" = HP Solution Center 11.0
"HPExtendedCapabilities" = HP Customer Participation Program 11.0
"HPOCR" = OCR Software by I.R.I.S. 11.0
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Shop for HP Supplies" = Shop for HP Supplies
"SynTPDeinstKey" = Synaptics Pointing Device Driver

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{004B0DCB-4C60-465B-8F01-44B0A4111187}" = SlingPlayer
"{0054A0F6-00C9-4498-B821-B5C9578F433E}" = HP Help and Support
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = HP MediaSmart Webcam
"{0289B35E-DC07-4c7a-9710-BBD686EA4B7D}" = Status
"{09633A5E-3089-41A8-9FF1-382171423C5D}" = PSSWCORE
"{0E7DBD52-B097-4F2B-A7C7-F105B0D20FDB}" = LightScribe System Software 1.14.17.1
"{154A4184-1A3D-4BF9-A5AE-4FA1660445F3}" = HP Total Care Advisor
"{15B8AFD9-92E9-4E86-96D9-83FAC510B82E}" = HPPhotoSmartPhotobookWebPack1
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
"{22F761D1-8063-4170-ADF7-2D2F47834CA9}" = VideoToolkit01
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{26A24AE4-039D-4CA4-87B4-2F83216012FF}" = Java™ 6 Update 13
"{27197499-7680-4208-8FD8-5439CDB0FDC1}" = HPProductAssistant
"{27F00C63-449B-2FAB-CBE8-24AB80E17449}" = Acrobat.com
"{2AFEAA03-2DFE-4519-A629-EDAB6541ABE9}" = HPSSupply
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.40 M1
"{352310C3-E46B-42D3-8F32-54721FDD72D9}" = NetZero Preloader
"{372ED957-0FB5-487B-B51A-388B3D393F7A}" = HP User Guides 0135
"{3877C901-7B90-4727-A639-B6ED2DD59D43}" = ESU for Microsoft Vista
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{43C0C354-A185-4D2D-A057-67C9160460E1}" = PS_AIO_04_C4580_Software_Min
"{462DED50-EC2E-4237-ABCF-B5C463C0EE51}" = HP Wireless Assistant
"{47F36D92-E58E-456D-B73C-3382737E4C42}" = HP Update
"{4A3D0CF8-60FF-4CEF-91A4-A1F001424602}" = DocProc
"{4E7C28C7-D5DA-4E9F-A1CA-60490B54AE35}" = UnloadSupport
"{57A5AEC1-97FC-474D-92C4-908FCC2253D4}" = HP Customer Experience Enhancements
"{593A6CAF-E114-4e31-884F-74FF349E8E36}" = SolutionCenter
"{6423EF83-6E1D-4D22-A36F-689CD19FD4D2}" = Juno Preloader
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{67626E09-5366-4480-8F1E-93FADF50CA15}" = HP MediaSmart TV
"{6A370610-3778-44AF-9AAC-69B2FD1A3356}" = Microsoft Live Search Toolbar
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{70E1E357-E57C-4284-B04E-58196DC27BC1}" = PanoStandAlone
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{732A3F80-008B-4350-BD58-EC5AE98707B8}" = HP Common Access Service Library
"{7641710F-A4AD-4EAE-889C-4958BE3F169C}" = C4580
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7B798B31-2F33-4DC8-BDA4-D36488E86636}" = Slingbox - Watch Your TV Anywhere
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 8168 8101E 8102E Ethernet Driver
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{E64BA721-2310-4B55-BE5A-2925F9706192}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002A-0409-1000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0116-0409-1000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95A747E0-DF19-46CB-A622-20A0107201BD}" = HP Total Care Setup
"{9C2D4047-0E40-499a-AC7A-C4B9BB12FE03}" = TrayApp
"{9F4EE72A-C5C9-42ad-ABEF-427690843577}" = MarketResearch
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A6A195F5-BCAB-4F38-8459-DF693303CD8D}" = PS_AIO_04_C4580_ProductContext
"{AA2E8A46-B45E-4aea-8A23-88AB57D04523}" = WebReg
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1.3
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}" = HP MediaSmart Music/Photo/Video
"{BF08AB1C-3357-4f20-A200-8EBB8EF27C59}" = BufferChm
"{C3A32068-8AB1-4327-BB16-BED9C6219DC7}" = Atheros Driver Installation Program
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{C89B5E3A-690F-4CEE-909A-BF869E198B0A}" = Scan
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CC0E1AE3-091D-4969-B151-7AC142062C28}" = SmartWebPrinting
"{CE7E3BE0-2DD3-4416-A690-F9E4A99A8CFF}" = HP Active Support Library
"{D16B4BE6-8B10-422f-8034-96D1CA9483B5}" = GPBaseService
"{D23E2520-0EAA-4AC3-A47E-A551C70D4FED}" = C4580_Help
"{D4278897-1541-493E-9D39-59CC6AB0FC09}" = PS_AIO_04_C4580_Software
"{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}" = HP Photosmart Essential 2.5
"{DC24971E-1946-445D-8A82-CE685433FA7D}" = Realtek USB 2.0 Card Reader
"{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio
"{E535C94A-B87F-4182-BEA8-1E9322078D3E}" = Cards_Calendar_OrderGift_DoMorePlugout
"{E8020EC7-5DD8-80C9-7237-7B2E9BDA8CC6}" = muvee Reveal
"{E96B0085-6659-486b-A221-5042A042728D}" = Toolbox
"{ECEE0279-785F-4CB3-9F28-E69813234BF8}" = SPORE Creature Creator Trial Edition
"{EF1ADA5A-0B1A-4662-8C55-7475A61D8B65}" = DeviceDiscovery
"{EF9E56EE-0243-4BAD-88F4-5E7508AA7D96}" = Destination Component
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Bejeweled 2 Deluxe 1.1" = Bejeweled 2 Deluxe 1.1
"ERUNT_is1" = ERUNT 1.1j
"ESET Online Scanner" = ESET Online Scanner v3
"HijackThis" = HijackThis 2.0.2
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"HP.MediaSmartSlingPlayer_is1" = HP MediaSmart SlingPlayer
"InstallShield_{004B0DCB-4C60-465B-8F01-44B0A4111187}" = SlingPlayer
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = HP MediaSmart Webcam
"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"InstallShield_{67626E09-5366-4480-8F1E-93FADF50CA15}" = HP MediaSmart TV
"InstallShield_{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}" = HP MediaSmart Music/Photo/Video
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"InstallShield_{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"iWinArcade" = iWin Games (remove only)
"Jewel Quest" = Jewel Quest (remove only)
"Jewel Quest II" = Jewel Quest II (remove only)
"Jewel Quest Solitaire II" = Jewel Quest Solitaire II (remove only)
"Mah Jong Quest II" = Mah Jong Quest II (remove only)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"NIS" = Norton Internet Security
"WildTangent hp Master Uninstall" = My HP Games
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Toolbar" = Yahoo! Toolbar

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 8/23/2009 7:14:27 AM | Computer Name = Stella-PC | Source = WinMgmt | ID = 10
Description =

Error - 8/24/2009 7:07:29 AM | Computer Name = Stella-PC | Source = WinMgmt | ID = 10
Description =

Error - 8/24/2009 3:26:26 PM | Computer Name = Stella-PC | Source = WinMgmt | ID = 10
Description =

Error - 8/25/2009 9:57:29 AM | Computer Name = Stella-PC | Source = WinMgmt | ID = 10
Description =

Error - 8/26/2009 8:59:50 AM | Computer Name = Stella-PC | Source = WinMgmt | ID = 10
Description =

Error - 8/26/2009 7:12:53 PM | Computer Name = Stella-PC | Source = WinMgmt | ID = 10
Description =

Error - 8/27/2009 5:03:23 AM | Computer Name = Stella-PC | Source = WinMgmt | ID = 10
Description =

Error - 8/27/2009 5:28:53 AM | Computer Name = Stella-PC | Source = WinMgmt | ID = 10
Description =

Error - 8/27/2009 5:29:11 AM | Computer Name = Stella-PC | Source = EventSystem | ID = 4609
Description =

Error - 8/27/2009 5:33:18 AM | Computer Name = Stella-PC | Source = EventSystem | ID = 4609
Description =

[ System Events ]
Error - 8/27/2009 5:29:50 AM | Computer Name = Stella-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 8/27/2009 5:33:18 AM | Computer Name = Stella-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 8/27/2009 5:33:18 AM | Computer Name = Stella-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 8/27/2009 5:33:51 AM | Computer Name = Stella-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 8/27/2009 5:33:51 AM | Computer Name = Stella-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 8/27/2009 5:35:53 AM | Computer Name = Stella-PC | Source = HTTP | ID = 15016
Description =

Error - 8/27/2009 5:37:40 AM | Computer Name = Stella-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 5:36:30 AM on 8/27/2009 was unexpected.

Error - 8/27/2009 5:37:50 AM | Computer Name = Stella-PC | Source = HTTP | ID = 15016
Description =

Error - 8/27/2009 5:40:58 AM | Computer Name = Stella-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 5:38:27 AM on 8/27/2009 was unexpected.

Error - 8/27/2009 5:41:00 AM | Computer Name = Stella-PC | Source = HTTP | ID = 15016
Description =


< End of report >

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI