This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Many problems!

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My laptop is getting false Windows Security Warnings. It also will not run Malwarebytes or let me uninstall it and reinstall. I have tried some of the self help but have had no success. It is also running very slow and is have a difficult time opening anything. I really need some help here. Thanks Bill ROOTREPEAL © AD, 2007-2009 ================================================== Scan Start Time: 2009/09/12 21:20 Program Version: Version 1.3.5.0 Windows Version: Windows XP Media Center Edition SP3 ================================================== Drivers ——————- Name: 1394BUS.SYS Image Path: C:\WINDOWS\system32\DRIVERS\1394BUS.SYS Address: 0xF74A7000 Size: 57344 File Visible: - Signed: - Status: - Name: ACPI.sys Image Path: ACPI.sys Address: 0xF7358000 Size: 187776 File Visible: - Signed: - Status: - Name: ACPI_HAL Image Path: \Driver\ACPI_HAL Address: 0x804D7000 Size: 2066048 File Visible: - Signed: - Status: - Name: ACPIEC.sys Image Path: ACPIEC.sys Address: 0xF78A3000 Size: 11648 File Visible: - Signed: - Status: - Name: afd.sys Image Path: C:\WINDOWS\System32\drivers\afd.sys Address: 0xEE815000 Size: 138496 File Visible: - Signed: - Status: - Name: AmdK8.sys Image Path: C:\WINDOWS\system32\DRIVERS\AmdK8.sys Address: 0xF7547000 Size: 57344 File Visible: - Signed: - Status: - Name: arp1394.sys Image Path: C:\WINDOWS\system32\DRIVERS\arp1394.sys Address: 0xF76C7000 Size: 60800 File Visible: - Signed: - Status: - Name: atapi.sys Image Path: atapi.sys Address: 0xF72CC000 Size: 96512 File Visible: - Signed: - Status: - Name: ati2cqag.dll Image Path: C:\WINDOWS\System32\ati2cqag.dll Address: 0xBFA17000 Size: 237568 File Visible: - Signed: - Status: - Name: ati2dvag.dll Image Path: C:\WINDOWS\System32\ati2dvag.dll Address: 0xBF9D5000 Size: 270336 File Visible: - Signed: - Status: - Name: ati2mtag.sys Image Path: C:\WINDOWS\system32\DRIVERS\ati2mtag.sys Address: 0xF6FC6000 Size: 1470464 File Visible: - Signed: - Status: - Name: ati3duag.dll Image Path: C:\WINDOWS\System32\ati3duag.dll Address: 0xBFA87000 Size: 2519040 File Visible: - Signed: - Status: - Name: atikvmag.dll Image Path: C:\WINDOWS\System32\atikvmag.dll Address: 0xBFA51000 Size: 221184 File Visible: - Signed: - Status: - Name: ativvaxx.dll Image Path: C:\WINDOWS\System32\ativvaxx.dll Address: 0xBFCEE000 Size: 1105920 File Visible: - Signed: - Status: - Name: ATMFD.DLL Image Path: C:\WINDOWS\System32\ATMFD.DLL Address: 0xBFFA0000 Size: 286720 File Visible: - Signed: - Status: - Name: audstub.sys Image Path: C:\WINDOWS\system32\DRIVERS\audstub.sys Address: 0xF7B05000 Size: 3072 File Visible: - Signed: - Status: - Name: BATTC.SYS Image Path: C:\WINDOWS\system32\DRIVERS\BATTC.SYS Address: 0xF789F000 Size: 16384 File Visible: - Signed: - Status: - Name: bcmwl5.sys Image Path: C:\WINDOWS\system32\DRIVERS\bcmwl5.sys Address: 0xF6ED4000 Size: 424320 File Visible: - Signed: - Status: - Name: Beep.SYS Image Path: C:\WINDOWS\System32\Drivers\Beep.SYS Address: 0xF79A5000 Size: 4224 File Visible: - Signed: - Status: - Name: BOOTVID.dll Image Path: C:\WINDOWS\system32\BOOTVID.dll Address: 0xF7897000 Size: 12288 File Visible: - Signed: - Status: - Name: camc6aud.sys Image Path: C:\WINDOWS\system32\drivers\camc6aud.sys Address: 0xF7597000 Size: 38016 File Visible: - Signed: - Status: - Name: camc6hal.sys Image Path: C:\WINDOWS\system32\drivers\camc6hal.sys Address: 0xF6E2E000 Size: 349312 File Visible: - Signed: - Status: - Name: Cdfs.SYS Image Path: C:\WINDOWS\System32\Drivers\Cdfs.SYS Address: 0xF6BED000 Size: 63744 File Visible: - Signed: - Status: - Name: cdrom.sys Image Path: C:\WINDOWS\system32\DRIVERS\cdrom.sys Address: 0xF7567000 Size: 62976 File Visible: - Signed: - Status: - Name: CLASSPNP.SYS Image Path: C:\WINDOWS\system32\DRIVERS\CLASSPNP.SYS Address: 0xF74E7000 Size: 53248 File Visible: - Signed: - Status: - Name: CmBatt.sys Image Path: C:\WINDOWS\system32\DRIVERS\CmBatt.sys Address: 0xF793F000 Size: 13952 File Visible: - Signed: - Status: - Name: compbatt.sys Image Path: compbatt.sys Address: 0xF789B000 Size: 10240 File Visible: - Signed: - Status: - Name: disk.sys Image Path: disk.sys Address: 0xF74D7000 Size: 36352 File Visible: - Signed: - Status: - Name: dmio.sys Image Path: dmio.sys Address: 0xF72E4000 Size: 153344 File Visible: - Signed: - Status: - Name: dmload.sys Image Path: dmload.sys Address: 0xF798B000 Size: 5888 File Visible: - Signed: - Status: - Name: drmk.sys Image Path: C:\WINDOWS\system32\drivers\drmk.sys Address: 0xF75A7000 Size: 61440 File Visible: - Signed: - Status: - Name: dump_atapi.sys Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys Address: 0xEE73A000 Size: 98304 File Visible: No Signed: - Status: - Name: dump_WMILIB.SYS Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS Address: 0xF79B7000 Size: 8192 File Visible: No Signed: - Status: - Name: Dxapi.sys Image Path: C:\WINDOWS\System32\drivers\Dxapi.sys Address: 0xF6A9A000 Size: 12288 File Visible: - Signed: - Status: - Name: dxg.sys Image Path: C:\WINDOWS\System32\drivers\dxg.sys Address: 0xBF9C3000 Size: 73728 File Visible: - Signed: - Status: - Name: dxgthk.sys Image Path: C:\WINDOWS\System32\drivers\dxgthk.sys Address: 0xF7B75000 Size: 4096 File Visible: - Signed: - Status: - Name: EABFiltr.sys Image Path: C:\WINDOWS\system32\drivers\EABFiltr.sys Address: 0xF79B3000 Size: 7936 File Visible: - Signed: - Status: - Name: Fips.SYS Image Path: C:\WINDOWS\System32\Drivers\Fips.SYS Address: 0xF76F7000 Size: 44544 File Visible: - Signed: - Status: - Name: fltmgr.sys Image Path: fltmgr.sys Address: 0xF719C000 Size: 129792 File Visible: - Signed: - Status: - Name: Fs_Rec.SYS Image Path: C:\WINDOWS\System32\Drivers\Fs_Rec.SYS Address: 0xF79A1000 Size: 7936 File Visible: - Signed: - Status: - Name: ftdisk.sys Image Path: ftdisk.sys Address: 0xF730A000 Size: 125056 File Visible: - Signed: - Status: - Name: GEARAspiWDM.sys Image Path: C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys Address: 0xF774F000 Size: 28672 File Visible: - Signed: - Status: - Name: hal.dll Image Path: C:\WINDOWS\system32\hal.dll Address: 0x806D0000 Size: 131840 File Visible: - Signed: - Status: - Name: HSF_CNXT.sys Image Path: C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys Address: 0xF6C24000 Size: 718464 File Visible: - Signed: - Status: - Name: HSF_DP.sys Image Path: C:\WINDOWS\system32\DRIVERS\HSF_DP.sys Address: 0xF6CD4000 Size: 1035008 File Visible: - Signed: - Status: - Name: HSFHWATI.sys Image Path: C:\WINDOWS\system32\DRIVERS\HSFHWATI.sys Address: 0xF6DD1000 Size: 231424 File Visible: - Signed: - Status: - Name: HTTP.sys Image Path: C:\WINDOWS\System32\Drivers\HTTP.sys Address: 0xEBC99000 Size: 264832 File Visible: - Signed: - Status: - Name: i8042prt.sys Image Path: C:\WINDOWS\system32\DRIVERS\i8042prt.sys Address: 0xF7587000 Size: 52480 File Visible: - Signed: - Status: - Name: imapi.sys Image Path: C:\WINDOWS\system32\DRIVERS\imapi.sys Address: 0xF7557000 Size: 42112 File Visible: - Signed: - Status: - Name: io.sys Image Path: C:\WINDOWS\system32\drivers\io.sys Address: 0xF7BC6000 Size: 2944 File Visible: - Signed: - Status: - Name: ipnat.sys Image Path: C:\WINDOWS\system32\DRIVERS\ipnat.sys Address: 0xEE837000 Size: 152832 File Visible: - Signed: - Status: - Name: ipsec.sys Image Path: C:\WINDOWS\system32\DRIVERS\ipsec.sys Address: 0xEE8DE000 Size: 75264 File Visible: - Signed: - Status: - Name: isapnp.sys Image Path: isapnp.sys Address: 0xF7487000 Size: 37248 File Visible: - Signed: - Status: - Name: kbdclass.sys Image Path: C:\WINDOWS\system32\DRIVERS\kbdclass.sys Address: 0xF775F000 Size: 24576 File Visible: - Signed: - Status: - Name: KDCOM.DLL Image Path: C:\WINDOWS\system32\KDCOM.DLL Address: 0xF7987000 Size: 8192 File Visible: - Signed: - Status: - Name: kmixer.sys Image Path: C:\WINDOWS\system32\drivers\kmixer.sys Address: 0xBAF35000 Size: 172416 File Visible: - Signed: - Status: - Name: ks.sys Image Path: C:\WINDOWS\system32\DRIVERS\ks.sys Address: 0xF6F6B000 Size: 143360 File Visible: - Signed: - Status: - Name: KSecDD.sys Image Path: KSecDD.sys Address: 0xF72A3000 Size: 92288 File Visible: - Signed: - Status: - Name: MCSTRM.SYS Image Path: C:\WINDOWS\System32\Drivers\MCSTRM.SYS Address: 0xF79E7000 Size: 7360 File Visible: - Signed: - Status: - Name: mdmxsdk.sys Image Path: C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys Address: 0xEBC7D000 Size: 11840 File Visible: - Signed: - Status: - Name: mnmdd.SYS Image Path: C:\WINDOWS\System32\Drivers\mnmdd.SYS Address: 0xF79A9000 Size: 4224 File Visible: - Signed: - Status: - Name: Modem.SYS Image Path: C:\WINDOWS\System32\Drivers\Modem.SYS Address: 0xF77AF000 Size: 30080 File Visible: - Signed: - Status: - Name: mouclass.sys Image Path: C:\WINDOWS\system32\DRIVERS\mouclass.sys Address: 0xF776F000 Size: 23040 File Visible: - Signed: - Status: - Name: MountMgr.sys Image Path: MountMgr.sys Address: 0xF74B7000 Size: 42368 File Visible: - Signed: - Status: - Name: mrxdav.sys Image Path: C:\WINDOWS\system32\DRIVERS\mrxdav.sys Address: 0xEBD2A000 Size: 180608 File Visible: - Signed: - Status: - Name: mrxsmb.sys Image Path: C:\WINDOWS\system32\DRIVERS\mrxsmb.sys Address: 0xEE752000 Size: 455296 File Visible: - Signed: - Status: - Name: Msfs.SYS Image Path: C:\WINDOWS\System32\Drivers\Msfs.SYS Address: 0xF784F000 Size: 19072 File Visible: - Signed: - Status: - Name: msgpc.sys Image Path: C:\WINDOWS\system32\DRIVERS\msgpc.sys Address: 0xF75E7000 Size: 35072 File Visible: - Signed: - Status: - Name: mssmbios.sys Image Path: C:\WINDOWS\system32\DRIVERS\mssmbios.sys Address: 0xF7977000 Size: 15488 File Visible: - Signed: - Status: - Name: Mup.sys Image Path: Mup.sys Address: 0xF71BC000 Size: 105344 File Visible: - Signed: - Status: - Name: NDIS.sys Image Path: NDIS.sys Address: 0xF71D6000 Size: 182656 File Visible: - Signed: - Status: - Name: ndistapi.sys Image Path: C:\WINDOWS\system32\DRIVERS\ndistapi.sys Address: 0xF7953000 Size: 10112 File Visible: - Signed: - Status: - Name: ndisuio.sys Image Path: C:\WINDOWS\system32\DRIVERS\ndisuio.sys Address: 0xEC332000 Size: 14592 File Visible: - Signed: - Status: - Name: ndiswan.sys Image Path: C:\WINDOWS\system32\DRIVERS\ndiswan.sys Address: 0xF6C0D000 Size: 91520 File Visible: - Signed: - Status: - Name: NDProxy.SYS Image Path: C:\WINDOWS\System32\Drivers\NDProxy.SYS Address: 0xF7607000 Size: 40576 File Visible: - Signed: - Status: - Name: netbios.sys Image Path: C:\WINDOWS\system32\DRIVERS\netbios.sys Address: 0xF76D7000 Size: 34688 File Visible: - Signed: - Status: - Name: netbt.sys Image Path: C:\WINDOWS\system32\DRIVERS\netbt.sys Address: 0xEE85D000 Size: 162816 File Visible: - Signed: - Status: - Name: nic1394.sys Image Path: C:\WINDOWS\system32\DRIVERS\nic1394.sys Address: 0xF7537000 Size: 61824 File Visible: - Signed: - Status: - Name: Npfs.SYS Image Path: C:\WINDOWS\System32\Drivers\Npfs.SYS Address: 0xF785F000 Size: 30848 File Visible: - Signed: - Status: - Name: Ntfs.sys Image Path: Ntfs.sys Address: 0xF7203000 Size: 574976 File Visible: - Signed: - Status: - Name: ntkrnlpa.exe Image Path: C:\WINDOWS\system32\ntkrnlpa.exe Address: 0x804D7000 Size: 2066048 File Visible: - Signed: - Status: - Name: Null.SYS Image Path: C:\WINDOWS\System32\Drivers\Null.SYS Address: 0xF7B44000 Size: 2944 File Visible: - Signed: - Status: - Name: nwlnkipx.sys Image Path: C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys Address: 0xEC2B4000 Size: 88320 File Visible: - Signed: - Status: - Name: nwlnknb.sys Image Path: C:\WINDOWS\system32\DRIVERS\nwlnknb.sys Address: 0xF76E7000 Size: 63232 File Visible: - Signed: - Status: - Name: nwlnkspx.sys Image Path: C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys Address: 0xEC114000 Size: 55936 File Visible: - Signed: - Status: - Name: ohci1394.sys Image Path: ohci1394.sys Address: 0xF7497000 Size: 61696 File Visible: - Signed: - Status: - Name: OPRGHDLR.SYS Image Path: C:\WINDOWS\system32\DRIVERS\OPRGHDLR.SYS Address: 0xF7A50000 Size: 4096 File Visible: - Signed: - Status: - Name: PartMgr.sys Image Path: PartMgr.sys Address: 0xF770F000 Size: 19712 File Visible: - Signed: - Status: - Name: pci.sys Image Path: pci.sys Address: 0xF7347000 Size: 68224 File Visible: - Signed: - Status: - Name: pciide.sys Image Path: pciide.sys Address: 0xF7A4F000 Size: 3328 File Visible: - Signed: - Status: - Name: PCIIDEX.SYS Image Path: C:\WINDOWS\system32\DRIVERS\PCIIDEX.SYS Address: 0xF7707000 Size: 28672 File Visible: - Signed: - Status: - Name: pcmcia.sys Image Path: pcmcia.sys Address: 0xF7329000 Size: 120192 File Visible: - Signed: - Status: - Name: PnpManager Image Path: \Driver\PnpManager Address: 0x804D7000 Size: 2066048 File Visible: - Signed: - Status: - Name: portcls.sys Image Path: C:\WINDOWS\system32\drivers\portcls.sys Address: 0xF6E0A000 Size: 147456 File Visible: - Signed: - Status: - Name: psched.sys Image Path: C:\WINDOWS\system32\DRIVERS\psched.sys Address: 0xF6B5C000 Size: 69120 File Visible: - Signed: - Status: - Name: ptilink.sys Image Path: C:\WINDOWS\system32\DRIVERS\ptilink.sys Address: 0xF77DF000 Size: 17792 File Visible: - Signed: - Status: - Name: PxHelp20.sys Image Path: PxHelp20.sys Address: 0xF74F7000 Size: 35712 File Visible: - Signed: - Status: - Name: rasacd.sys Image Path: C:\WINDOWS\system32\DRIVERS\rasacd.sys Address: 0xF792F000 Size: 8832 File Visible: - Signed: - Status: - Name: rasl2tp.sys Image Path: C:\WINDOWS\system32\DRIVERS\rasl2tp.sys Address: 0xF75B7000 Size: 51328 File Visible: - Signed: - Status: - Name: raspppoe.sys Image Path: C:\WINDOWS\system32\DRIVERS\raspppoe.sys Address: 0xF75C7000 Size: 41472 File Visible: - Signed: - Status: - Name: raspptp.sys Image Path: C:\WINDOWS\system32\DRIVERS\raspptp.sys Address: 0xF75D7000 Size: 48384 File Visible: - Signed: - Status: - Name: raspti.sys Image Path: C:\WINDOWS\system32\DRIVERS\raspti.sys Address: 0xF77EF000 Size: 16512 File Visible: - Signed: - Status: - Name: RAW Image Path: \FileSystem\RAW Address: 0x804D7000 Size: 2066048 File Visible: - Signed: - Status: - Name: rdbss.sys Image Path: C:\WINDOWS\system32\DRIVERS\rdbss.sys Address: 0xEE7C2000 Size: 175744 File Visible: - Signed: - Status: - Name: RDPCDD.sys Image Path: C:\WINDOWS\System32\DRIVERS\RDPCDD.sys Address: 0xF79AD000 Size: 4224 File Visible: - Signed: - Status: - Name: rdpdr.sys Image Path: C:\WINDOWS\system32\DRIVERS\rdpdr.sys Address: 0xF6B04000 Size: 196224 File Visible: - Signed: - Status: - Name: redbook.sys Image Path: C:\WINDOWS\system32\DRIVERS\redbook.sys Address: 0xF7577000 Size: 57600 File Visible: - Signed: - Status: - Name: rootrepeal.sys Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys Address: 0xBAF25000 Size: 49152 File Visible: No Signed: - Status: - Name: Rtnicxp.sys Image Path: C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys Address: 0xF6E84000 Size: 78720 File Visible: - Signed: - Status: - Name: sdbus.sys Image Path: C:\WINDOWS\system32\DRIVERS\sdbus.sys Address: 0xF6E98000 Size: 79232 File Visible: - Signed: - Status: - Name: Serial.sys Image Path: Serial.sys Address: 0xF7507000 Size: 64512 File Visible: - Signed: - Status: - Name: sr.sys Image Path: sr.sys Address: 0xF72BA000 Size: 73472 File Visible: - Signed: - Status: - Name: srv.sys Image Path: C:\WINDOWS\system32\DRIVERS\srv.sys Address: 0xEBB57000 Size: 333952 File Visible: - Signed: - Status: - Name: swenum.sys Image Path: C:\WINDOWS\system32\DRIVERS\swenum.sys Address: 0xF7997000 Size: 4352 File Visible: - Signed: - Status: - Name: SynTP.sys Image Path: C:\WINDOWS\system32\DRIVERS\SynTP.sys Address: 0xF6F3C000 Size: 190400 File Visible: - Signed: - Status: - Name: sysaudio.sys Image Path: C:\WINDOWS\system32\drivers\sysaudio.sys Address: 0xEE982000 Size: 60800 File Visible: - Signed: - Status: - Name: tcpip.sys Image Path: C:\WINDOWS\system32\DRIVERS\tcpip.sys Address: 0xEE885000 Size: 361600 File Visible: - Signed: - Status: - Name: TDI.SYS Image Path: C:\WINDOWS\system32\DRIVERS\TDI.SYS Address: 0xF77CF000 Size: 20480 File Visible: - Signed: - Status: - Name: termdd.sys Image Path: C:\WINDOWS\system32\DRIVERS\termdd.sys Address: 0xF75F7000 Size: 40704 File Visible: - Signed: - Status: - Name: tifm21.sys Image Path: C:\WINDOWS\system32\drivers\tifm21.sys Address: 0xF6EAC000 Size: 162432 File Visible: - Signed: - Status: - Name: update.sys Image Path: C:\WINDOWS\system32\DRIVERS\update.sys Address: 0xF6AA6000 Size: 384768 File Visible: - Signed: - Status: - Name: USBD.SYS Image Path: C:\WINDOWS\system32\DRIVERS\USBD.SYS Address: 0xF798F000 Size: 8192 File Visible: - Signed: - Status: - Name: usbehci.sys Image Path: C:\WINDOWS\system32\DRIVERS\usbehci.sys Address: 0xF773F000 Size: 30208 File Visible: - Signed: - Status: - Name: usbhub.sys Image Path: C:\WINDOWS\system32\DRIVERS\usbhub.sys Address: 0xF7637000 Size: 59520 File Visible: - Signed: - Status: - Name: usbohci.sys Image Path: C:\WINDOWS\system32\DRIVERS\usbohci.sys Address: 0xF7737000 Size: 17152 File Visible: - Signed: - Status: - Name: USBPORT.SYS Image Path: C:\WINDOWS\system32\DRIVERS\USBPORT.SYS Address: 0xF6F8E000 Size: 147456 File Visible: - Signed: - Status: - Name: vga.sys Image Path: C:\WINDOWS\System32\drivers\vga.sys Address: 0xF783F000 Size: 20992 File Visible: - Signed: - Status: - Name: VIDEOPRT.SYS Image Path: C:\WINDOWS\system32\DRIVERS\VIDEOPRT.SYS Address: 0xF6FB2000 Size: 81920 File Visible: - Signed: - Status: - Name: VolSnap.sys Image Path: VolSnap.sys Address: 0xF74C7000 Size: 52352 File Visible: - Signed: - Status: - Name: wanarp.sys Image Path: C:\WINDOWS\system32\DRIVERS\wanarp.sys Address: 0xF76B7000 Size: 34560 File Visible: - Signed: - Status: - Name: watchdog.sys Image Path: C:\WINDOWS\System32\watchdog.sys Address: 0xF7727000 Size: 20480 File Visible: - Signed: - Status: - Name: wdmaud.sys Image Path: C:\WINDOWS\system32\drivers\wdmaud.sys Address: 0xEC097000 Size: 83072 File Visible: - Signed: - Status: - Name: Win32k Image Path: \Driver\Win32k Address: 0xBF800000 Size: 1847296 File Visible: - Signed: - Status: - Name: win32k.sys Image Path: C:\WINDOWS\System32\win32k.sys Address: 0xBF800000 Size: 1847296 File Visible: - Signed: - Status: - Name: wmiacpi.sys Image Path: C:\WINDOWS\system32\DRIVERS\wmiacpi.sys Address: 0xF7923000 Size: 8832 File Visible: - Signed: - Status: - Name: WMILIB.SYS Image Path: C:\WINDOWS\system32\DRIVERS\WMILIB.SYS Address: 0xF7989000 Size: 8192 File Visible: - Signed: - Status: - Name: WMIxWDM Image Path: \Driver\WMIxWDM Address: 0x804D7000 Size: 2066048 File Visible: - Signed: - Status: - Name: WudfPf.sys Image Path: WudfPf.sys Address: 0xF7290000 Size: 77568 File Visible: - Signed: - Status: - DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 21:17:54.89 on Sat 09/12/2009 Internet Explorer: 7.0.5730.11 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.367 [GMT -4:00] AV: Protection System *On-access scanning enabled* (Outdated) {28e00e3b-806e-4533-925c-f4c3d79514b9} ============== Running Processes =============== C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\ctfmon.exe svchost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\WINDOWS\ehome\ehtray.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe C:\Program Files\HP\QuickPlay\QPService.exe C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe C:\WINDOWS\system32\PSIService.exe C:\Program Files\OBD2 TekLink Consumer\TekInit.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe C:\Program Files\HP\hpcoretech\hpcmpmgr.exe svchost.exe C:\WINDOWS\system32\hphmon05.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe C:\Program Files\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe C:\Program Files\Common Files\Corel\Corel PhotoDownloader\Corel Photo Downloader.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\DNA\btdna.exe C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe C:\WINDOWS\system32\dllhost.exe C:\Program Files\iPod\bin\iPodService.exe C:\PROGRA~1\hpq\Shared\HPQTOA~1.EXE C:\WINDOWS\system32\wscsvc32.exe C:\WINDOWS\system32\net.exe C:\WINDOWS\system32\net1.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Internet Explorer\Iexplore.exe C:\Documents and Settings\William\Desktop\dds.scr ============== Pseudo HJT Report =============== uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=pavilion&pf=laptop uInternet Settings,ProxyServer = http=localhost:7171 uInternet Settings,ProxyOverride = *.local BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: Winamp Toolbar BHO: {25cee8ec-5730-41bc-8b58-22ddc8ab8c20} - c:\program files\winamp toolbar\winamptb.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_03\bin\ssv.dll BHO: CoolIrisIEHelperObject.CoolIrisIEBHO: {ad0bab4b-212d-45d7-9e5b-cb1579132715} - c:\program files\cooliris\CoolIrisIEHelperObject.dll BHO: PicLens plug-in for Internet Explorer: {eaee5c74-6d0d-4aca-9232-0da4a7b866ba} - c:\program files\piclensie\PicLens.dll TB: Winamp Toolbar: {ebf2ba02-9094-4c5a-858b-bb198f3d8de2} - c:\program files\winamp toolbar\winamptb.dll uRun: [Aim6] uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [BitTorrent DNA] "c:\program files\dna\btdna.exe" uRun: [Protection System] "c:\program files\protection system\psystem.exe" -noscan mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName mRun: [ehTray] c:\windows\ehome\ehtray.exe mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [ATIPTA] "c:\program files\ati technologies\ati control panel\atiptaxx.exe" mRun: [Cpqset] c:\program files\hpq\default settings\cpqset.exe mRun: [eabconfg.cpl] c:\program files\hpq\quick launch buttons\EabServr.exe /Start mRun: [QPService] "c:\program files\hp\quickplay\QPService.exe" mRun: [hpWirelessAssistant] c:\program files\hpq\hp wireless assistant\HP Wireless Assistant.exe mRun: [Adobe Photo Downloader] "c:\program files\adobe\photoshop album starter edition\3.2\apps\apdproxy.exe" mRun: [OBD2_TekLink_Start2.0] "c:\program files\obd2 teklink consumer\TekInit.exe" mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [HPHUPD05] c:\program files\hp\\{5372b9a6-6e51-4f90-9b40-e0a3b8475c4e}\hphupd05.exe mRun: [HP Component Manager] "c:\program files\hp\hpcoretech\hpcmpmgr.exe" mRun: [HPHmon05] c:\windows\system32\hphmon05.exe mRun: [HPDJ Taskbar Utility] c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [ISUSPM Startup] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -startup mRun: [Corel File Shell Monitor] c:\program files\corel\corel paint shop pro photo x2\CorelIOMonitor.exe mRun: [Corel Photo Downloader] "c:\program files\common files\corel\corel photodownloader\Corel Photo Downloader.exe" -startup StartupFolder: c:\docume~1\william\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpphot~1.lnk - c:\program files\hp\digital imaging\bin\hpqthb08.exe uPolicies-explorer: NoResolveTrack = 1 (0x1) uPolicies-explorer: NoThumbnailCache = 1 (0x1) mPolicies-explorer: NoResolveTrack = 1 (0x1) IE: {449DB14A-F988-4fd8-9361-F212D7B6414B} - c:\program files\cooliris\CoolIrisPreferences.exe IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_03\bin\ssv.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll Trusted Zone: line6.net DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204 DPF: {54BE6B6F-3056-470B-97E1-BB92E051B6C4} - hxxp://h20264.www2.hp.com/ediags/dd/install/HPDriverDiagnosticsxp2k.cab DPF: {61628958-4627-48F4-99FD-30719188568D} - hxxp://www.ifrontiers.com/ActiveX/XCheck.CAB DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} - hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1195829752453 DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} - hxxps://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {BCBC9371-595D-11D4-A96D-00105A1CEF6C} - hxxp://onlinedesigner.hgtv.com/images/app/view22rte.cab DPF: {BCBC9371-9827-11DA-A72B-0800200C9A66} - hxxp://merillat.view22.com/release_3_9_177/View22RTEv4.cab DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll Notify: AtiExtEvent - Ati2evxx.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll LSA: Notification Packages = scecli scecli ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\william\applic~1\mozilla\firefox\profiles\ehedr4y9.default\ FF - prefs.js: browser.startup.homepage - hxxp://my.ebay.com/ws/eBayISAPI.dll?MyEbayBeta&gbh=1&rand=148178149 FF - prefs.js: keyword.URL - hxxp://toolbar.ask.com/toolbarv/askRedirect?o=101757&gct=&gc=1&q= FF - prefs.js: network.proxy.http - localhost FF - prefs.js: network.proxy.http_port - 7070 FF - prefs.js: network.proxy.type - 4 FF - component: c:\documents and settings\william\application data\mozilla\firefox\profiles\ehedr4y9.default\extensions\[removed]\components\coolirisstub.dll FF - plugin: c:\documents and settings\william\application data\mozilla\firefox\profiles\ehedr4y9.default\extensions\[removed]\platform\winnt_x86-msvc\plugins\npmnqmp071101000055.dll FF - plugin: c:\documents and settings\william\application data\mozilla\firefox\profiles\ehedr4y9.default\extensions\[removed]\plugins\npcoolirisplugin.dll FF - plugin: c:\documents and settings\william\application data\mozilla\plugins\npcoolirisplugin.dll FF - plugin: c:\program files\mozilla firefox\plugins\npbittorrent.dll FF - plugin: c:\program files\mozilla firefox\plugins\npmusicn.dll ============= SERVICES / DRIVERS =============== R2 io.sys;IO.DLL Driver;c:\windows\system32\drivers\io.sys [2007-8-11 5152] R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328] R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592] R3 HSFHWATI;HSFHWATI;c:\windows\system32\drivers\HSFHWATI.sys [2007-7-30 231424] S1 f5940828;f5940828;c:\windows\system32\drivers\f5940828.sys –> c:\windows\system32\drivers\f5940828.sys [?] S2 ProtectedStorageWMPNetworkSvc;Protected Storage ProtectedStorageWMPNetworkSvc;c:\windows\system32\adsntv.exe srv –> c:\windows\system32\adsntv.exe srv [?] S3 L6TPortGX;Service - Line 6 TonePort GX;c:\windows\system32\drivers\L6TPortGX.sys [2008-10-18 521472] =============== Created Last 30 ================ 2009-09-12 21:08 –d—– c:\program files\Protection System 2009-09-12 20:39 31,232 a——- c:\windows\system32\wingenocx.dll 2009-09-12 20:25 –d—– c:\program files\ESET 2009-09-12 17:25 7,396 a——- c:\windows\system32\drivers\pctcore.cat 2009-09-12 16:03 693,760 a——- c:\windows\isRS-000.tmp 2009-09-12 16:02 –d—– C:\7f3f0a554297b8fe125190b7e0f470ad 2009-09-12 11:44 4,824 a——- c:\windows\system32\tmp.reg 2009-09-12 11:42 –d—– c:\temp\SmitfraudFix 2009-09-11 23:57 61,440 a——- c:\windows\system32\drivers\vokxr.sys 2009-09-11 21:40 1,012,224 a——- c:\windows\system32\wscsvc32.exe 2009-09-08 19:08 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-09-08 19:08 19,160 a——- c:\windows\system32\drivers\mbam.sys 2009-09-08 19:08 –d—– c:\program files\Malwarebytes' Anti-Malware ==================== Find3M ==================== 2009-08-23 18:22 2,828 a–sh— c:\windows\system32\KGyGaAvL.sys 2009-07-10 19:52 2,828 a–sh— c:\docume~1\alluse~1\applic~1\KGyGaAvL.sys 2009-07-10 19:49 88 —shr– c:\docume~1\alluse~1\applic~1\621101D524.sys 2007-07-31 17:23 88 —shr– c:\windows\system32\621101D524.sys 2009-04-28 17:30 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009042820090429\index.dat ============= FINISH: 21:19:28.87 =============== UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-06-26.01) Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 7/30/2007 8:42:49 PM System Uptime: 9/12/2009 9:04:57 PM (0 hours ago) Motherboard: Hewlett-Packard | | 309B Processor: AMD Turion™ 64 Mobile Technology ML-34 | U23 | 1790/mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 93 GiB total, 61.561 GiB free. D: is CDROM () ==== Disabled Device Manager Items ============= ==== System Restore Points =================== RP617: 9/11/2009 9:40:27 PM - Windows Defender Checkpoint RP618: 9/11/2009 9:40:28 PM - System Checkpoint RP619: 9/11/2009 9:40:28 PM - Windows Defender Checkpoint RP620: 9/11/2009 9:40:30 PM - System Checkpoint RP621: 9/11/2009 9:40:30 PM - Windows Defender Checkpoint RP622: 9/11/2009 9:40:31 PM - System Checkpoint RP623: 9/11/2009 9:40:32 PM - System Checkpoint RP624: 9/11/2009 9:40:32 PM - Windows Defender Checkpoint RP625: 9/11/2009 9:40:32 PM - System Checkpoint RP626: 9/11/2009 9:40:32 PM - Windows Defender Checkpoint RP627: 9/11/2009 9:40:32 PM - System Checkpoint RP628: 9/11/2009 9:40:33 PM - Windows Defender Checkpoint RP629: 9/11/2009 9:40:33 PM - System Checkpoint RP630: 9/11/2009 9:40:33 PM - Windows Defender Checkpoint RP631: 9/11/2009 9:40:34 PM - System Checkpoint RP632: 9/11/2009 9:40:35 PM - Windows Defender Checkpoint RP633: 9/11/2009 9:40:35 PM - System Checkpoint RP634: 9/11/2009 9:40:35 PM - System Checkpoint RP635: 9/11/2009 9:40:35 PM - System Checkpoint RP636: 9/11/2009 9:40:35 PM - System Checkpoint RP637: 9/11/2009 9:40:36 PM - System Checkpoint RP638: 9/11/2009 9:40:36 PM - System Checkpoint RP639: 9/11/2009 9:40:36 PM - System Checkpoint RP640: 9/11/2009 9:40:36 PM - Unsigned driver install RP641: 9/11/2009 9:40:36 PM - Unsigned driver install RP642: 9/11/2009 9:40:37 PM - System Checkpoint RP643: 9/11/2009 9:40:37 PM - System Checkpoint RP644: 9/11/2009 9:40:39 PM - System Checkpoint RP645: 9/11/2009 9:40:40 PM - System Checkpoint RP646: 9/11/2009 9:40:41 PM - System Checkpoint RP647: 9/11/2009 9:40:41 PM - System Checkpoint RP648: 9/11/2009 9:40:42 PM - System Checkpoint RP649: 9/11/2009 9:40:44 PM - System Checkpoint RP650: 9/11/2009 9:40:45 PM - System Checkpoint RP651: 9/11/2009 9:40:46 PM - System Checkpoint RP652: 9/11/2009 9:40:46 PM - System Checkpoint RP653: 9/11/2009 9:40:46 PM - System Checkpoint RP654: 9/11/2009 9:40:47 PM - System Checkpoint RP655: 9/11/2009 9:40:47 PM - System Checkpoint RP656: 9/11/2009 9:40:48 PM - System Checkpoint RP657: 9/11/2009 9:40:48 PM - System Checkpoint RP658: 9/11/2009 9:40:48 PM - System Checkpoint RP659: 9/11/2009 9:40:48 PM - System Checkpoint RP660: 9/11/2009 9:40:49 PM - System Checkpoint RP661: 9/11/2009 9:40:51 PM - System Checkpoint RP662: 9/11/2009 9:40:51 PM - System Checkpoint RP663: 9/11/2009 9:40:52 PM - System Checkpoint RP664: 9/11/2009 9:40:52 PM - System Checkpoint RP665: 9/11/2009 9:40:52 PM - System Checkpoint RP666: 9/11/2009 9:40:52 PM - Removed Dyno-Scan for Windows 6.5.0 RP667: 9/11/2009 9:40:52 PM - System Checkpoint RP668: 9/11/2009 9:40:52 PM - System Checkpoint RP669: 9/11/2009 9:40:53 PM - System Checkpoint RP670: 9/11/2009 9:40:54 PM - System Checkpoint RP671: 9/11/2009 9:40:54 PM - System Checkpoint RP672: 9/11/2009 9:40:55 PM - System Checkpoint RP673: 9/11/2009 9:40:56 PM - System Checkpoint RP674: 9/11/2009 9:40:56 PM - System Checkpoint RP675: 9/11/2009 9:40:56 PM - System Checkpoint RP676: 9/11/2009 9:40:57 PM - System Checkpoint RP677: 9/11/2009 9:40:58 PM - System Checkpoint RP678: 9/11/2009 9:40:58 PM - System Checkpoint RP679: 9/11/2009 9:40:59 PM - System Checkpoint RP680: 9/11/2009 9:40:59 PM - System Checkpoint RP681: 9/11/2009 9:40:59 PM - System Checkpoint RP682: 9/11/2009 9:40:59 PM - System Checkpoint RP683: 9/11/2009 9:40:59 PM - System Checkpoint RP684: 9/11/2009 9:41:00 PM - System Checkpoint RP685: 9/11/2009 9:41:00 PM - System Checkpoint RP686: 9/11/2009 9:41:00 PM - System Checkpoint RP687: 9/11/2009 9:41:00 PM - System Checkpoint ==== Installed Programs ====================== Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742) Adobe Flash Player 10 Plugin Adobe Flash Player ActiveX Adobe Reader 8.1.2 Adobe Reader 8.1.2 Security Update 1 (KB403742) Adobe Shockwave Player Adobe® Photoshop® Album Starter Edition 3.2 AIM 6 Amazon MP3 Downloader 1.0.3 Apple Mobile Device Support Apple Software Update Athlon 64 Processor Driver ATI - Software Uninstall Utility ATI Control Panel ATI Display Driver Audio Tuner (remove only) BitTorrent Broadcom 802.11 Wireless LAN Adapter BufferChm Canon Camera WIA Driver Canon EOS 20D WIA Driver Canon Utilities EOS Capture 1.5 Conexant AC-Link Audio CoolIris Corel Paint Shop Pro Photo X2 Corel Paint Shop Pro Photo XI CP_AtenaShokunin1Config CP_CalendarTemplates1 cp_LightScribeConfig cp_OnlineProjectsConfig CP_Package_Basic1 CP_Package_Variety1 CP_Package_Variety2 CP_Package_Variety3 CP_Panorama1Config cp_PosterPrintConfig cp_UpdateProjectsConfig Critical Update for Windows Media Player 11 (KB959772) CueTour Destinations DeviceManagementQFolder DNA EA SPORTS online 2006 EOS Capture 1.5 ERUNT 1.1j ESET Online Scanner v3 FullDPAppQFolder Garmin Communicator Plugin Garmin POI Loader Garmin USB Drivers Garmin WebUpdater Google SketchUp 6 HijackThis 2.0.2 Hotfix for Windows Internet Explorer 7 (KB947864) Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 10 (KB903157) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB952287) HP Driver Diagnostics HP Help and Support HP Imaging Device Functions 6.0 HP Photosmart Premier Software 6.0 HP Product Detection HP QuickPlay 2.0 HP Rhapsody HP Software Update HP User Guides–System Recovery HP User Guides 0026 HP Wireless Assistant 2.00 C1 InstantShareDevices iTunes J2SE Runtime Environment 5.0 Update 6 JAlbum 7.2 Java™ 6 Update 2 Java™ 6 Update 3 LG USB Modem driver LightScribe 1.4.136.1 Line 6 Uninstaller Malwarebytes' Anti-Malware Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB928366) Microsoft .NET Framework 2.0 Microsoft .NET Framework 3.0 Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft Office Professional Edition 2003 Microsoft Silverlight Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 Redistributable Mozilla Firefox (3.0.14) MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB954430) MSXML 6 Service Pack 2 (KB954459) muvee autoProducer 4.5 OBD2 TekLink OptionalContentQFolder PhotoGallery Photosmart 140,240,7200,7600,7700,7900 Series PicLens for Internet Explorer Power Tab Editor 1.7 PSShortcutsP PSUsage Quick Launch Buttons 5.20 G1 QuickTime RandMap REALTEK Gigabit and Fast Ethernet NIC Driver RegiStax Version 4 Registry Easy v4.7 Rhapsody Rhapsody Player Engine Security Update for Windows Internet Explorer 7 (KB929969) Security Update for Windows Internet Explorer 7 (KB933566) Security Update for Windows Internet Explorer 7 (KB937143) Security Update for Windows Internet Explorer 7 (KB938127) Security Update for Windows Internet Explorer 7 (KB939653) Security Update for Windows Internet Explorer 7 (KB942615) Security Update for Windows Internet Explorer 7 (KB944533) Security Update for Windows Internet Explorer 7 (KB950759) Security Update for Windows Internet Explorer 7 (KB953838) Security Update for Windows Internet Explorer 7 (KB956390) Security Update for Windows Internet Explorer 7 (KB958215) Security Update for Windows Internet Explorer 7 (KB960714) Security Update for Windows Internet Explorer 7 (KB961260) Security Update for Windows Internet Explorer 7 (KB963027) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows Media Player 10 (KB936782) Security Update for Windows Media Player 11 (KB936782) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB938464-v2) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951376) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB953839) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956391) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB957095) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958690) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960715) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB961373) SkinsHP1 Soft Data Fax Modem with SmartCP Sonic Audio Module Sonic Copy Module Sonic Data Module Sonic Express Labeler Sonic MyDVD Plus Sonic Update Manager Sonic_PrimoSDK Spybot - Search & Destroy Synaptics Pointing Device Driver Texas Instruments PCIxx21/x515/xx12 drivers. Tiger Woods PGA TOUR 06 TIPCI UltraISO Premium V9.31 Unload Update for Windows Media Player 10 (KB913800) Update for Windows Media Player 10 (KB926251) Update for Windows XP (KB951072-v2) Update for Windows XP (KB951978) Update for Windows XP (KB955839) Update for Windows XP (KB967715) Update Rollup 2 for Windows XP Media Center Edition 2005 WebFldrs XP Winamp Winamp Remote Winamp Toolbar for Internet Explorer Windows Communication Foundation Windows Defender Windows Driver Package - Garmin (grmnusb) GARMIN Devices (03/08/2007 2.2.1.0) Windows Genuine Advantage Validation Tool (KB892130) Windows Imaging Component Windows Internet Explorer 7 Windows Media Format 11 runtime Windows Media Player 11 Windows Media Player Firefox Plugin Windows Presentation Foundation Windows Workflow Foundation Windows XP Media Center Edition 2005 KB894553 Windows XP Media Center Edition 2005 KB925766 Windows XP Service Pack 3 WinRAR archiver Wireless Home Network Setup XML Paper Specification Shared Components Pack 1.0 ==== Event Viewer Messages From Past Week ======== 9/6/2009 8:46:15 AM, error: Service Control Manager [7000] - The Automatic Updates service failed to start due to the following error: The system cannot find the file specified. 9/6/2009 8:46:15 AM, error: DCOM [10005] - DCOM got error "%2" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334} 9/6/2009 12:10:22 AM, error: Service Control Manager [7031] - The Windows Defender service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 15000 milliseconds: Restart the service. 9/12/2009 7:18:22 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the PC Tools Security Service service to connect. 9/12/2009 7:18:22 PM, error: Service Control Manager [7000] - The PC Tools Security Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 9/12/2009 4:47:51 PM, error: Service Control Manager [7031] - The Media Center Extender Service service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service. 9/12/2009 4:39:27 PM, error: Service Control Manager [7031] - The DCOM Server Process Launcher service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Reboot the machine. 9/12/2009 2:57:44 PM, error: Service Control Manager [7034] - The PC Tools Security Service service terminated unexpectedly. It has done this 1 time(s). 9/12/2009 2:53:48 PM, error: Service Control Manager [7034] - The LightScribeService Direct Disc Labeling Service service terminated unexpectedly. It has done this 1 time(s). 9/12/2009 2:53:32 PM, error: Service Control Manager [7034] - The Machine Debug Manager service terminated unexpectedly. It has done this 2 time(s). 9/12/2009 2:52:43 PM, error: Service Control Manager [7034] - The PC Tools Auxiliary Service service terminated unexpectedly. It has done this 1 time(s). 9/12/2009 2:40:17 PM, error: Service Control Manager [7031] - The COM+ System Application service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 1000 milliseconds: Restart the service. 9/12/2009 2:38:52 PM, error: Service Control Manager [7034] - The Media Center Scheduler Service service terminated unexpectedly. It has done this 1 time(s). 9/12/2009 12:20:08 PM, error: Service Control Manager [7031] - The Media Center Extender Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service. 9/12/2009 12:13:34 PM, error: Service Control Manager [7031] - The Media Center Receiver Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service. 9/12/2009 12:13:13 PM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 4 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 9/12/2009 12:08:22 PM, error: Service Control Manager [7034] - The Protexis Licensing V2 service terminated unexpectedly. It has done this 1 time(s). 9/12/2009 12:08:04 PM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 3 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 9/12/2009 12:07:43 PM, error: Service Control Manager [7034] - The hpqwmiex service terminated unexpectedly. It has done this 1 time(s). 9/12/2009 12:07:13 PM, error: Service Control Manager [7034] - The iPod Service service terminated unexpectedly. It has done this 1 time(s). 9/12/2009 12:06:58 PM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 9/12/2009 12:06:11 PM, error: Service Control Manager [7034] - The ProtexisLicensing service terminated unexpectedly. It has done this 1 time(s). 9/12/2009 12:05:54 PM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 9/12/2009 12:05:48 PM, error: Service Control Manager [7034] - The Application Layer Gateway Service service terminated unexpectedly. It has done this 1 time(s). 9/12/2009 12:05:14 PM, error: Service Control Manager [7034] - The Machine Debug Manager service terminated unexpectedly. It has done this 1 time(s). 9/12/2009 11:41:18 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811} 9/12/2009 11:33:40 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AmdK8 eabfiltr Fips 9/12/2009 11:33:29 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 9/11/2009 11:55:28 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD AmdK8 eabfiltr Fips IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip 9/11/2009 11:55:28 PM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning. 9/11/2009 11:55:28 PM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning. 9/11/2009 11:55:28 PM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning. 9/11/2009 11:55:28 PM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning. 9/11/2009 11:55:28 PM, error: Service Control Manager [7001] - The Apple Mobile Device service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning. 9/11/2009 11:55:24 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E} 9/11/2009 11:54:52 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} ==== End Of File ===========================
1) I assume that you haven't yet installed the Trend product as nothing shows up in the log - why not? 2) Is the product licensed for your personal use or supplied by your company? 3) Is the PC a business PC?
1. I have not installed it as I am having second thoughts about that product. 2. The product is supplied by my company. ( Reason for second thoughts, I do not want to have to use their tech support) 3. It is my personal laptop. I really want to fix this machine and will use the software recommended here. My issues are getting worse as I am now getting audio advertising while the computer is on and it keeps asking me to delete Malwarebytes.
Take a trip to this webpage for download links and instructions for running Combofix by sUBs: http://www.bleepingcomputer.com/combofix/how-to-use-combofix *
  • When prompted to save Combofix, change the filename BEFORE saving it - any name will do, as long as it has .exe at the end.
  • Please be aware that this tool may require the PC to be rebooted so close any programs you have open before you start.
  • When CF has finished, it will produce a log - C:\ComboFix.txt - copy and paste it into your next reply.
  • Post a fresh DDS log as well.
  • Let me know how the PC is behaving.
* There are two points to note from the instructions page:

1) The Recovery Console.

It is recommended that you install this as, in certain circumstances, it may be the difference between a successful repair and a reformat. If you are uncertain as to whether or not you already have the Recovery Console installed, simply run CF and it will prompt you if it does not detect it.
CF will complete some, but not all, of it's removal tasks without the installation of the Console, so you are free to choose whether you want to complete this step, but it is in your interests to do so.

2) Disabling your Anti-Virus.

CF has been the victim of false-positive detections on occasion and a resident AV may incorrectly identify and delete part of the tool which won't do it much good. If you don't disable your AV, you may not get the results you hoped for!
I have run Combofix and here is the log along with the DDS log. I computer seems to be better as I have not seen any popup activity in the past half hour sine I ran Combofix.

ComboFix 09-09-14.02 - William 09/14/2009 16:32.1.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.678 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\fixer.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\Protection System
c:\program files\Protection System\core.cga
c:\windows\kb913800.exe
c:\windows\system32\_005108_.tmp.dll
c:\windows\system32\_005109_.tmp.dll
c:\windows\system32\_005110_.tmp.dll
c:\windows\system32\_005111_.tmp.dll
c:\windows\system32\_005118_.tmp.dll
c:\windows\system32\_005119_.tmp.dll
c:\windows\system32\_005120_.tmp.dll
c:\windows\system32\_005121_.tmp.dll
c:\windows\system32\_005123_.tmp.dll
c:\windows\system32\_005124_.tmp.dll
c:\windows\system32\_005127_.tmp.dll
c:\windows\system32\_005128_.tmp.dll
c:\windows\system32\_005131_.tmp.dll
c:\windows\system32\_005132_.tmp.dll
c:\windows\system32\_005134_.tmp.dll
c:\windows\system32\_005137_.tmp.dll
c:\windows\system32\_005138_.tmp.dll
c:\windows\system32\_005143_.tmp.dll
c:\windows\system32\_005145_.tmp.dll
c:\windows\system32\_005148_.tmp.dll
c:\windows\system32\_005150_.tmp.dll
c:\windows\system32\_005151_.tmp.dll
c:\windows\system32\_005152_.tmp.dll
c:\windows\system32\_005153_.tmp.dll
c:\windows\system32\_005154_.tmp.dll
c:\windows\system32\_005157_.tmp.dll
c:\windows\system32\_005158_.tmp.dll
c:\windows\system32\_005159_.tmp.dll
c:\windows\system32\_005160_.tmp.dll
c:\windows\system32\_005161_.tmp.dll
c:\windows\system32\_005166_.tmp.dll
c:\windows\system32\_005168_.tmp.dll
c:\windows\system32\_005169_.tmp.dll
c:\windows\system32\_id.dat
c:\windows\system32\1760463630.dat
c:\windows\system32\drivers\UAClwbltewxdu.sys
c:\windows\system32\nfr.assembly
c:\windows\system32\tmp.reg
c:\windows\system32\UACfyqotiupdv.dll
c:\windows\system32\UACimxbnyrobq.dll
c:\windows\system32\uacinit.dll
c:\windows\system32\UACqhbqqltuwc.dll
c:\windows\system32\UACrmhpmowqjb.dll
c:\windows\system32\UACyqxuxqelkl.dat
c:\windows\system32\wingenocx.dll
c:\windows\system32\wscsvc32.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_UACd.sys
——-\Legacy_UACd.sys
——-\Legacy_PROTECTEDSTORAGEWMPNETWORKSVC
——-\Service_ProtectedStorageWMPNetworkSvc


((((((((((((((((((((((((( Files Created from 2009-08-14 to 2009-09-14 )))))))))))))))))))))))))))))))
.

2009-09-14 20:16 . 2009-09-14 20:18 ——– d—–w- C:\fixer
2009-09-13 01:16 . 2009-09-13 01:16 ——– d—–w- c:\program files\ERUNT
2009-09-13 00:25 . 2009-09-13 00:25 ——– d—–w- c:\program files\ESET
2009-09-12 20:02 . 2009-09-12 20:02 ——– d—–w- C:\7f3f0a554297b8fe125190b7e0f470ad
2009-09-12 18:36 . 2009-09-12 23:22 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-09-12 15:42 . 2009-09-12 23:55 ——– d—–w- c:\temp\SmitfraudFix
2009-09-12 03:57 . 2009-09-12 03:57 61440 —-a-w- c:\windows\system32\drivers\vokxr.sys
2009-09-08 23:08 . 2009-09-10 18:54 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-08 23:08 . 2009-09-10 18:53 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-09-08 23:08 . 2009-09-13 01:05 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-14 21:09 . 2009-03-09 21:03 ——– d—–w- c:\program files\DNA
2009-09-14 21:09 . 2009-03-09 21:03 ——– d—–w- c:\documents and settings\William\Application Data\DNA
2009-09-12 21:25 . 2009-09-12 21:25 7396 —-a-w- c:\windows\system32\drivers\pctcore.cat
2009-09-12 20:12 . 2007-07-31 01:26 1324 —-a-w- c:\windows\system32\d3d9caps.dat
2009-09-12 19:07 . 2008-11-26 00:19 ——– d—–w- c:\program files\Registry Easy
2009-08-23 22:47 . 2007-07-31 21:23 ——– d—–w- c:\documents and settings\William\Application Data\Corel
2009-08-23 22:22 . 2007-07-31 21:23 2828 –sha-w- c:\windows\system32\KGyGaAvL.sys
2009-08-15 16:24 . 2009-08-14 18:10 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2009-08-15 16:24 . 2009-08-14 18:10 ——– d—–w- c:\program files\NOS
2009-07-10 23:52 . 2009-02-22 02:10 2828 –sha-w- c:\documents and settings\All Users\Application Data\KGyGaAvL.sys
2009-07-10 23:49 . 2009-02-22 02:10 88 –sh–r- c:\documents and settings\All Users\Application Data\621101D524.sys
2007-07-31 21:23 . 2007-07-31 21:23 88 –sh–r- c:\windows\system32\621101D524.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-03-09 321344]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-10 208952]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-10 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-10 455168]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-06-19 729178]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-12-02 344064]
"Cpqset"="c:\program files\HPQ\Default Settings\cpqset.exe" [2005-08-01 233534]
"eabconfg.cpl"="c:\program files\HPQ\Quick Launch Buttons\EabServr.exe" [2005-12-22 405504]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2005-12-12 94208]
"hpWirelessAssistant"="c:\program files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2005-12-13 507904]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 63712]
"OBD2_TekLink_Start2.0"="c:\program files\OBD2 TekLink Consumer\TekInit.exe" [2006-10-16 45056]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-01-15 267048]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-01-10 385024]
"HPHUPD05"="c:\program files\HP\\{5372B9A6-6E51-4f90-9B40-E0A3B8475C4E}\hphupd05.exe" [2005-07-08 49152]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 241664]
"HPHmon05"="c:\windows\system32\hphmon05.exe" [2005-07-08 491520]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe" [2005-07-08 176128]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2005-08-11 249856]
"Corel File Shell Monitor"="c:\program files\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe" [2009-01-21 16712]
"Corel Photo Downloader"="c:\program files\Common Files\Corel\Corel PhotoDownloader\Corel Photo Downloader.exe" [2008-12-18 532808]

c:\documents and settings\William\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Photosmart Premier Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2005-9-24 73728]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
"NoThumbnailCache"= 1 (0x1)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\JAlbum7.2\\JAlbumWin.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\Orb.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"7070:TCP"= 7070:TCP:nfr

R2 io.sys;IO.DLL Driver;c:\windows\system32\drivers\io.sys [8/11/2007 9:15 PM 5152]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
R3 HSFHWATI;HSFHWATI;c:\windows\system32\drivers\HSFHWATI.sys [7/30/2007 8:52 PM 231424]
S1 f5940828;f5940828;c:\windows\system32\drivers\f5940828.sys –> c:\windows\system32\drivers\f5940828.sys [?]
S3 L6TPortGX;Service - Line 6 TonePort GX;c:\windows\system32\drivers\L6TPortGX.sys [10/18/2008 7:59 PM 521472]
.
Contents of the 'Scheduled Tasks' folder

2009-09-12 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 19:57]

2009-09-14 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 23:20]

2009-05-19 c:\windows\Tasks\Schedule Task Weekly.job
- c:\program files\Registry Easy\RE.exe [2008-11-26 21:30]
.
.
——- Supplementary Scan ——-
.
uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=pavilion&pf=laptop
uInternet Settings,ProxyServer = http=localhost:7171
uInternet Settings,ProxyOverride = *.local
IE: {{449DB14A-F988-4fd8-9361-F212D7B6414B} - c:\program files\CoolIris\CoolIrisPreferences.exe
Trusted Zone: line6.net
DPF: {61628958-4627-48F4-99FD-30719188568D} - hxxp://www.ifrontiers.com/ActiveX/XCheck.CAB
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {BCBC9371-9827-11DA-A72B-0800200C9A66} - hxxp://merillat.view22.com/release_3_9_177/View22RTEv4.cab
FF - ProfilePath - c:\documents and settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\
FF - prefs.js: browser.startup.homepage - hxxp://my.ebay.com/ws/eBayISAPI.dll?MyEbayBeta&gbh=1&rand=148178149
FF - prefs.js: keyword.URL - hxxp://toolbar.ask.com/toolbarv/askRedirect?o=101757&gct=&gc=1&q=
FF - prefs.js: network.proxy.http - localhost
FF - prefs.js: network.proxy.http_port - 7070
FF - prefs.js: network.proxy.type - 4
FF - component: c:\documents and settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\extensions\[removed]\components\coolirisstub.dll
FF - plugin: c:\documents and settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npmnqmp071101000055.dll
FF - plugin: c:\documents and settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\extensions\[removed]\plugins\npcoolirisplugin.dll
FF - plugin: c:\documents and settings\William\Application Data\Mozilla\plugins\npcoolirisplugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmusicn.dll
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-Protection System - c:\program files\Protection System\psystem.exe
HKCU-Run-Aim6 - (no file)
MSConfigStartUp-CTFMON - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-14 17:08
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = c:\program files\HPQ\Default Settings\cpqset.exe????????3?6?6?6??????? ???B?????????????hLC? ??????

scanning hidden files …


**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(844)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(4076)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\PSIService.exe
c:\program files\Common Files\Protexis\License Service\PsiService_2.exe
c:\windows\ehome\mcrdsvc.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\windows\system32\dllhost.exe
c:\program files\HP\Digital Imaging\bin\hpqimzone.exe
c:\program files\iPod\bin\iPodService.exe
c:\progra~1\HPQ\shared\HPQTOA~1.EXE
.
**************************************************************************
.
Completion time: 2009-09-14 17:18 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-14 21:17

Pre-Run: 65,662,332,928 bytes free
Post-Run: 68,329,119,744 bytes free

Current=1 Default=1 Failed=0 LastKnownGood=5 Sets=1,2,3,5
251 — E O F — 2009-05-22 01:45



DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 17:22:13.23 on Mon 09/14/2009
Internet Explorer: 7.0.5730.11
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.507 [GMT -4:00]


============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\PSIService.exe
C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
svchost.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\hphmon05.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe
C:\Program Files\Common Files\Corel\Corel PhotoDownloader\Corel Photo Downloader.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\DNA\btdna.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\hpq\Shared\HPQTOA~1.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\William\Desktop\dds.scr

============== Pseudo HJT Report ===============

uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=pavilion&pf=laptop
uInternet Settings,ProxyServer = http=localhost:7171
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Winamp Toolbar BHO: {25cee8ec-5730-41bc-8b58-22ddc8ab8c20} - c:\program files\winamp toolbar\winamptb.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_03\bin\ssv.dll
BHO: CoolIrisIEHelperObject.CoolIrisIEBHO: {ad0bab4b-212d-45d7-9e5b-cb1579132715} - c:\program files\cooliris\CoolIrisIEHelperObject.dll
BHO: PicLens plug-in for Internet Explorer: {eaee5c74-6d0d-4aca-9232-0da4a7b866ba} - c:\program files\piclensie\PicLens.dll
TB: Winamp Toolbar: {ebf2ba02-9094-4c5a-858b-bb198f3d8de2} - c:\program files\winamp toolbar\winamptb.dll
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [BitTorrent DNA] "c:\program files\dna\btdna.exe"
mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [ATIPTA] "c:\program files\ati technologies\ati control panel\atiptaxx.exe"
mRun: [Cpqset] c:\program files\hpq\default settings\cpqset.exe
mRun: [eabconfg.cpl] c:\program files\hpq\quick launch buttons\EabServr.exe /Start
mRun: [QPService] "c:\program files\hp\quickplay\QPService.exe"
mRun: [hpWirelessAssistant] c:\program files\hpq\hp wireless assistant\HP Wireless Assistant.exe
mRun: [Adobe Photo Downloader] "c:\program files\adobe\photoshop album starter edition\3.2\apps\apdproxy.exe"
mRun: [OBD2_TekLink_Start2.0] "c:\program files\obd2 teklink consumer\TekInit.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [HPHUPD05] c:\program files\hp\\{5372b9a6-6e51-4f90-9b40-e0a3b8475c4e}\hphupd05.exe
mRun: [HP Component Manager] "c:\program files\hp\hpcoretech\hpcmpmgr.exe"
mRun: [HPHmon05] c:\windows\system32\hphmon05.exe
mRun: [HPDJ Taskbar Utility] c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [ISUSPM Startup] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -startup
mRun: [Corel File Shell Monitor] c:\program files\corel\corel paint shop pro photo x2\CorelIOMonitor.exe
mRun: [Corel Photo Downloader] "c:\program files\common files\corel\corel photodownloader\Corel Photo Downloader.exe" -startup
StartupFolder: c:\docume~1\william\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpphot~1.lnk - c:\program files\hp\digital imaging\bin\hpqthb08.exe
uPolicies-explorer: NoResolveTrack = 1 (0x1)
uPolicies-explorer: NoThumbnailCache = 1 (0x1)
mPolicies-explorer: NoResolveTrack = 1 (0x1)
IE: {449DB14A-F988-4fd8-9361-F212D7B6414B} - c:\program files\cooliris\CoolIrisPreferences.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_03\bin\ssv.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
Trusted Zone: line6.net
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {54BE6B6F-3056-470B-97E1-BB92E051B6C4} - hxxp://h20264.www2.hp.com/ediags/dd/install/HPDriverDiagnosticsxp2k.cab
DPF: {61628958-4627-48F4-99FD-30719188568D} - hxxp://www.ifrontiers.com/ActiveX/XCheck.CAB
DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} - hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1195829752453
DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} - hxxps://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {BCBC9371-595D-11D4-A96D-00105A1CEF6C} - hxxp://onlinedesigner.hgtv.com/images/app/view22rte.cab
DPF: {BCBC9371-9827-11DA-A72B-0800200C9A66} - hxxp://merillat.view22.com/release_3_9_177/View22RTEv4.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll
Notify: AtiExtEvent - Ati2evxx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\william\applic~1\mozilla\firefox\profiles\ehedr4y9.default\
FF - prefs.js: browser.startup.homepage - hxxp://my.ebay.com/ws/eBayISAPI.dll?MyEbayBeta&gbh=1&rand=148178149
FF - prefs.js: keyword.URL - hxxp://toolbar.ask.com/toolbarv/askRedirect?o=101757&gct=&gc=1&q=
FF - prefs.js: network.proxy.http - localhost
FF - prefs.js: network.proxy.http_port - 7070
FF - prefs.js: network.proxy.type - 4
FF - component: c:\documents and settings\william\application data\mozilla\firefox\profiles\ehedr4y9.default\extensions\[removed]\components\coolirisstub.dll

============= SERVICES / DRIVERS ===============

R2 io.sys;IO.DLL Driver;c:\windows\system32\drivers\io.sys [2007-8-11 5152]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
R3 HSFHWATI;HSFHWATI;c:\windows\system32\drivers\HSFHWATI.sys [2007-7-30 231424]
S1 f5940828;f5940828;c:\windows\system32\drivers\f5940828.sys –> c:\windows\system32\drivers\f5940828.sys [?]
S3 L6TPortGX;Service - Line 6 TonePort GX;c:\windows\system32\drivers\L6TPortGX.sys [2008-10-18 521472]

=============== Created Last 30 ================

2009-09-14 16:18 a-dshr– C:\cmdcons
2009-09-14 16:16 229,888 a——- c:\windows\PEV.exe
2009-09-14 16:16 161,792 a——- c:\windows\SWREG.exe
2009-09-14 16:16 98,816 a——- c:\windows\sed.exe
2009-09-14 16:16 –d—– C:\fixer
2009-09-12 20:25 –d—– c:\program files\ESET
2009-09-12 17:25 7,396 a——- c:\windows\system32\drivers\pctcore.cat
2009-09-12 16:02 –d—– C:\7f3f0a554297b8fe125190b7e0f470ad
2009-09-12 11:42 –d—– c:\temp\SmitfraudFix
2009-09-11 23:57 61,440 a——- c:\windows\system32\drivers\vokxr.sys
2009-09-08 19:08 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-08 19:08 19,160 a——- c:\windows\system32\drivers\mbam.sys
2009-09-08 19:08 –d—– c:\program files\Malwarebytes' Anti-Malware

==================== Find3M ====================

2009-08-23 18:22 2,828 a–sh— c:\windows\system32\KGyGaAvL.sys
2009-07-10 19:52 2,828 a–sh— c:\docume~1\alluse~1\applic~1\KGyGaAvL.sys
2009-07-10 19:49 88 —shr– c:\docume~1\alluse~1\applic~1\621101D524.sys
2007-07-31 17:23 88 —shr– c:\windows\system32\621101D524.sys
2009-04-28 17:30 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009042820090429\index.dat

============= FINISH: 17:22:28.76 ===============
Malwarebytes' Anti-Malware 1.41 Database version: 2805 Windows 5.1.2600 Service Pack 3 9/15/2009 5:44:57 PM mbam-log-2009-09-15 (17-44-57).txt Scan type: Full Scan (C:\|) Objects scanned: 191186 Time elapsed: 1 hour(s), 14 minute(s), 39 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 9 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\Qoobox\Quarantine\C\WINDOWS\system32\UACfyqotiupdv.dll.vir (Trojan.Agent) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\C\WINDOWS\system32\UACimxbnyrobq.dll.vir (Rootkit.TDSS) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\C\WINDOWS\system32\wingenocx.dll.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\C\WINDOWS\system32\wscsvc32.exe.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{B0AB14E0-BED2-43EE-9F42-F1FACCB51CB9}\RP687\A0284146.dll (Trojan.Agent) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{B0AB14E0-BED2-43EE-9F42-F1FACCB51CB9}\RP687\A0284148.dll (Rootkit.TDSS) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{B0AB14E0-BED2-43EE-9F42-F1FACCB51CB9}\RP688\A0284209.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{B0AB14E0-BED2-43EE-9F42-F1FACCB51CB9}\RP688\A0284210.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{B0AB14E0-BED2-43EE-9F42-F1FACCB51CB9}\RP632\A0259886.sys (Rootkit.Rustock) -> Quarantined and deleted successfully.
OK, you'll need to get the anti-virus up and running now. If you don't want to go with the Trend option, there are three freebies that are commonly used:

AVG Free Edition: Available here.
avast! 4 Home Edition: Available here.
AntiVir Personal Edition Classic : Available here.

It's down to opinion which is best, so take a wild stab and install one. Run a full scan and let it delete anything it finds - let me know what it does find though.

Also, download a copy of HJTInstall.exe from here and save it to your Desktop
  • Double click HJTInstall.exe to begin installation.
  • Accept the installation location, which by default is C:\Program Files\Trend Micro\HijackThis or click the Browse… button if you want to chose somewhere else and then click Install
  • Once HJT has installed, a shortcut will be created on your Desktop and HJT will run automatically.
  • You will need to accept the EULA, if it appears, to be able to use the tool.
  • When HJT opens, click on the Do a system scan and save a log file button.
  • When HJT has finished scanning, a window entitled "hijackthis.log" will open - when you close this window the log will be saved into the Hijackthis folder.
  • Copy and paste this into your next reply.
I installed AVG and ran a scan. Below is a log of what it found along with the HJ log.
Scan "Scan whole computer" was finished.
No infection was found during this scan
Folders selected for scanning:;"Scan whole computer"
Scan started:;"Wednesday, September 16, 2009, 4:59:28 PM"
Scan finished:;"Wednesday, September 16, 2009, 7:00:06 PM (2 hour(s) 37 second(s))"
Total object scanned:;"542982"
User who launched the scan:;"William"

Warnings
File;"Infection";"Result"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite;"Found Tracking cookie.Atdmt";"Healed"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\247realmedia.com.125a868c;"Found Tracking cookie.247realmedia";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\247realmedia.com.22701b7f;"Found Tracking cookie.247realmedia";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\247realmedia.com.855b46d;"Found Tracking cookie.247realmedia";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\247realmedia.com.b4c2ad0b;"Found Tracking cookie.247realmedia";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\247realmedia.com.964cd308;"Found Tracking cookie.247realmedia";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\247realmedia.com.d90d45cf;"Found Tracking cookie.247realmedia";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\2o7.net.159cd052;"Found Tracking cookie.2o7";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\2o7.net.1a6a6c0d;"Found Tracking cookie.2o7";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\2o7.net.267edbdc;"Found Tracking cookie.2o7";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\2o7.net.28333ed;"Found Tracking cookie.2o7";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\2o7.net.29c43642;"Found Tracking cookie.2o7";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\2o7.net.2bd99548;"Found Tracking cookie.2o7";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\2o7.net.470af26a;"Found Tracking cookie.2o7";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\2o7.net.6e21ae42;"Found Tracking cookie.2o7";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\2o7.net.931d9248;"Found Tracking cookie.2o7";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\2o7.net.6d1dd7eb;"Found Tracking cookie.2o7";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\2o7.net.7919062b;"Found Tracking cookie.2o7";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\2o7.net.84c199e2;"Found Tracking cookie.2o7";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\2o7.net.93690267;"Found Tracking cookie.2o7";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\2o7.net.ac9296d1;"Found Tracking cookie.2o7";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\2o7.net.b58e9c50;"Found Tracking cookie.2o7";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\2o7.net.33677c41;"Found Tracking cookie.2o7";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\2o7.net.3ace56c;"Found Tracking cookie.2o7";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\2o7.net.3e9c1f81;"Found Tracking cookie.2o7";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\2o7.net.41f3f5fd;"Found Tracking cookie.2o7";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\2o7.net.4400f07a;"Found Tracking cookie.2o7";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\2o7.net.54ed237e;"Found Tracking cookie.2o7";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\2o7.net.6000245f;"Found Tracking cookie.2o7";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\2o7.net.6492a00e;"Found Tracking cookie.2o7";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\2o7.net.697706d6;"Found Tracking cookie.2o7";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\2o7.net.6d030ef9;"Found Tracking cookie.2o7";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\2o7.net.71112ed5;"Found Tracking cookie.2o7";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\2o7.net.7815c7ab;"Found Tracking cookie.2o7";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\2o7.net.7ae9c250;"Found Tracking cookie.2o7";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\2o7.net.ae5b0007;"Found Tracking cookie.2o7";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\2o7.net.c457807b;"Found Tracking cookie.2o7";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\2o7.net.c475eb26;"Found Tracking cookie.2o7";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\2o7.net.7c6f0705;"Found Tracking cookie.2o7";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\2o7.net.7d89a0a8;"Found Tracking cookie.2o7";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\2o7.net.85d5b5f0;"Found Tracking cookie.2o7";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\2o7.net.8ebc6e2a;"Found Tracking cookie.2o7";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\2o7.net.95e64c93;"Found Tracking cookie.2o7";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\2o7.net.9a526fbf;"Found Tracking cookie.2o7";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\2o7.net.ac5209af;"Found Tracking cookie.2o7";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\2o7.net.ae6e14c4;"Found Tracking cookie.2o7";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\2o7.net.b271730a;"Found Tracking cookie.2o7";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\2o7.net.bf397cd;"Found Tracking cookie.2o7";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\2o7.net.cb19198d;"Found Tracking cookie.2o7";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\2o7.net.cd287d37;"Found Tracking cookie.2o7";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\2o7.net.db5b9f2d;"Found Tracking cookie.2o7";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\2o7.net.e2b68039;"Found Tracking cookie.2o7";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\2o7.net.e802a7ab;"Found Tracking cookie.2o7";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\2o7.net.edf86f4f;"Found Tracking cookie.2o7";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\adbrite.com.44f92a69;"Found Tracking cookie.Adbrite";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\adbrite.com.71beeff9;"Found Tracking cookie.Adbrite";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\adbrite.com.d5e309c2;"Found Tracking cookie.Adbrite";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\advertising.com.203aa218;"Found Tracking cookie.Advertising";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\advertising.com.525a5fb9;"Found Tracking cookie.Advertising";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\advertising.com.7ae8f949;"Found Tracking cookie.Advertising";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\atdmt.com.7247c262;"Found Tracking cookie.Atdmt";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\burstbeacon.com.c4fe2ebb;"Found Tracking cookie.Burstbeacon";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\casalemedia.com.156cbc67;"Found Tracking cookie.Casalemedia";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\2o7.net.e31bc356;"Found Tracking cookie.2o7";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\advertising.com.1dfa2206;"Found Tracking cookie.Advertising";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\casalemedia.com.1773afc;"Found Tracking cookie.Casalemedia";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\casalemedia.com.650648e8;"Found Tracking cookie.Casalemedia";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\casalemedia.com.80ad4799;"Found Tracking cookie.Casalemedia";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\casalemedia.com.8c65eddd;"Found Tracking cookie.Casalemedia";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\casalemedia.com.987e6b46;"Found Tracking cookie.Casalemedia";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\casalemedia.com.fb62dd4b;"Found Tracking cookie.Casalemedia";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\hitbox.com.2b95f8a3;"Found Tracking cookie.Hitbox";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\msnportal.112.2o7.net.7225be6f;"Found Tracking cookie.2o7";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\realmedia.com.125a868c;"Found Tracking cookie.Realmedia";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\realmedia.com.68087763;"Found Tracking cookie.Realmedia";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\realmedia.com.855b46d;"Found Tracking cookie.Realmedia";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\realmedia.com.e14be39e;"Found Tracking cookie.Realmedia";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\revsci.net.55564293;"Found Tracking cookie.Revsci";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\revsci.net.6215368c;"Found Tracking cookie.Revsci";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\atdmt.com.f4b86dca;"Found Tracking cookie.Atdmt";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\bs.serving-sys.com.5bf1f00f;"Found Tracking cookie.Serving-sys";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\burstnet.com.c4fe2ebb;"Found Tracking cookie.Burstnet";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\burstnet.com.ce59db3e;"Found Tracking cookie.Burstnet";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\casalemedia.com.12e6c053;"Found Tracking cookie.Casalemedia";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\serving-sys.com.255d6f2f;"Found Tracking cookie.Serving-sys";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\serving-sys.com.400f83f;"Found Tracking cookie.Serving-sys";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\serving-sys.com.4b416ef8;"Found Tracking cookie.Serving-sys";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\serving-sys.com.606c3d3b;"Found Tracking cookie.Serving-sys";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\serving-sys.com.6a1cf9e8;"Found Tracking cookie.Serving-sys";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\burstnet.com.27341d57;"Found Tracking cookie.Burstnet";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\burstnet.com.a3218a37;"Found Tracking cookie.Burstnet";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\casalemedia.com.3a28db8d;"Found Tracking cookie.Casalemedia";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\doubleclick.net.d120a313;"Found Tracking cookie.Doubleclick";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\serving-sys.com.c9034af6;"Found Tracking cookie.Serving-sys";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\tacoda.net.c4fe2ebb;"Found Tracking cookie.Tacoda";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\questionmarket.com.3eb5a9f1;"Found Tracking cookie.Questionmarket";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\revsci.net.f1b6b2e;"Found Tracking cookie.Revsci";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\statse.webtrendslive.com.b4ca7df0;"Found Tracking cookie.Webtrendslive";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\tacoda.net.27341d57;"Found Tracking cookie.Tacoda";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\trafficmp.com.a00e30b4;"Found Tracking cookie.Trafficmp";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\tacoda.net.4366831a;"Found Tracking cookie.Tacoda";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\trafficmp.com.37644bdb;"Found Tracking cookie.Trafficmp";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\trafficmp.com.e2e71e33;"Found Tracking cookie.Trafficmp";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\trafficmp.com.ae53b8b;"Found Tracking cookie.Trafficmp";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\trafficmp.com.f3e5803e;"Found Tracking cookie.Trafficmp";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\tribalfusion.com.5eef93d0;"Found Tracking cookie.Tribalfusion";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\tribalfusion.com.7610f0e0;"Found Tracking cookie.Tribalfusion";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\tribalfusion.com.8b22ad8c;"Found Tracking cookie.Tribalfusion";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\tribalfusion.com.9bc3e98f;"Found Tracking cookie.Tribalfusion";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\tribalfusion.com.dcc03271;"Found Tracking cookie.Tribalfusion";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\zedo.com.6a4b36ab;"Found Tracking cookie.Zedo";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\zedo.com.775ee79c;"Found Tracking cookie.Zedo";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\2o7.net.fad80487;"Found Tracking cookie.2o7";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\ad.yieldmanager.com.539b0606;"Found Tracking cookie.Yieldmanager";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\ad.yieldmanager.com.557bf2b0;"Found Tracking cookie.Yieldmanager";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\ad.yieldmanager.com.712ec9fe;"Found Tracking cookie.Yieldmanager";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\ad.yieldmanager.com.830b6f08;"Found Tracking cookie.Yieldmanager";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\ad.yieldmanager.com.8a47878;"Found Tracking cookie.Yieldmanager";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\ad.yieldmanager.com.b68f2b7b;"Found Tracking cookie.Yieldmanager";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\ad.yieldmanager.com.e626e6be;"Found Tracking cookie.Yieldmanager";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\ad.yieldmanager.com.ff92306;"Found Tracking cookie.Yieldmanager";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\adbrite.com.557c9f74;"Found Tracking cookie.Adbrite";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\adbrite.com.775ee79c;"Found Tracking cookie.Adbrite";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\adbrite.com.e1f04284;"Found Tracking cookie.Adbrite";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\adengage.com.6b2a3f1;"Found Tracking cookie.Adengage";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\admarketplace.net.61a250a;"Found Tracking cookie.Admarketplace";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\adrevolver.com.4a719aa9;"Found Tracking cookie.Adrevolver";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\adrevolver.com.9b9d670a;"Found Tracking cookie.Adrevolver";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\adrevolver.com.b595d4db;"Found Tracking cookie.Adrevolver";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\adrevolver.com.f6cfcad4;"Found Tracking cookie.Adrevolver";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\atdmt.com.74c5668;"Found Tracking cookie.Atdmt";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\advertising.com.1820df7a;"Found Tracking cookie.Advertising";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\advertising.com.b624fa46;"Found Tracking cookie.Advertising";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\advertising.com.f62113d5;"Found Tracking cookie.Advertising";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\atdmt.com.9e6d7fd3;"Found Tracking cookie.Atdmt";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\atdmt.com.ce59db3e;"Found Tracking cookie.Atdmt";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\doubleclick.net.ce59db3e;"Found Tracking cookie.Doubleclick";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\fastclick.net.57e8da10;"Found Tracking cookie.Fastclick";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\fastclick.net.6fd479aa;"Found Tracking cookie.Fastclick";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\fastclick.net.8a6435e9;"Found Tracking cookie.Fastclick";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\fastclick.net.8dd1284a;"Found Tracking cookie.Fastclick";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\atdmt.com.b3e33b5f;"Found Tracking cookie.Atdmt";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\bluestreak.com.bf396750;"Found Tracking cookie.Bluestreak";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\doubleclick.net.bf396750;"Found Tracking cookie.Doubleclick";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\fastclick.net.94ca190b;"Found Tracking cookie.Fastclick";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\fastclick.net.9b41aa53;"Found Tracking cookie.Fastclick";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\fastclick.net.fac3d6f0;"Found Tracking cookie.Fastclick";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\hitbox.com.bbf2a6e8;"Found Tracking cookie.Hitbox";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\m.webtrends.com.b4ca7df0;"Found Tracking cookie.Webtrends";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\media.adrevolver.com.2be00b0;"Found Tracking cookie.Adrevolver";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\media.adrevolver.com.539b0606;"Found Tracking cookie.Adrevolver";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\media.adrevolver.com.57f415b5;"Found Tracking cookie.Adrevolver";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\revsci.net.247efa56;"Found Tracking cookie.Revsci";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\pro-market.net.b51604f4;"Found Tracking cookie.Pro-market";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\pro-market.net.bbf67f2d;"Found Tracking cookie.Pro-market";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\realmedia.com.a2b49f1a;"Found Tracking cookie.Realmedia";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\revsci.net.4a124674;"Found Tracking cookie.Revsci";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\revsci.net.738d89d;"Found Tracking cookie.Revsci";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\revsci.net.e1150a02;"Found Tracking cookie.Revsci";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\revsci.net.f7ac007f;"Found Tracking cookie.Revsci";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\stat.dealtime.com.f58c396a;"Found Tracking cookie.Dealtime";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\yadro.ru.c77afad5;"Found Tracking cookie.Yadro";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\media.adrevolver.com.7fd89687;"Found Tracking cookie.Adrevolver";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\mediaplex.com.323e9a10;"Found Tracking cookie.Mediaplex";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\mediaplex.com.f652b123;"Found Tracking cookie.Mediaplex";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\overture.com.e626e6be;"Found Tracking cookie.Overture";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\realmedia.com.6b2e2a72;"Found Tracking cookie.Realmedia";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\questionmarket.com.4dd5e426;"Found Tracking cookie.Questionmarket";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\revsci.net.8642c85d;"Found Tracking cookie.Revsci";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\revsci.net.a5874ce1;"Found Tracking cookie.Revsci";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\revsci.net.a5a8b88c;"Found Tracking cookie.Revsci";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\zedo.com.14a38114;"Found Tracking cookie.Zedo";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\mediaplex.com.dc30fb3c;"Found Tracking cookie.Mediaplex";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\overture.com.52ca467a;"Found Tracking cookie.Overture";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\revsci.net.27e60b8d;"Found Tracking cookie.Revsci";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\revsci.net.2df99d79;"Found Tracking cookie.Revsci";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\revsci.net.44927ec;"Found Tracking cookie.Revsci";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\revsci.net.50e13b1b;"Found Tracking cookie.Revsci";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\revsci.net.e9dbeb91;"Found Tracking cookie.Revsci";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\searchportal.information.com.3a8d7204;"Found Tracking cookie.Information";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\tribalfusion.com.ff8546b9;"Found Tracking cookie.Tribalfusion";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\zedo.com.27f1639b;"Found Tracking cookie.Zedo";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\zedo.com.a5b6a132;"Found Tracking cookie.Zedo";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\zedo.com.c1dd09f2;"Found Tracking cookie.Zedo";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\zedo.com.f1d14556;"Found Tracking cookie.Zedo";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\zedo.com.f462b69f;"Found Tracking cookie.Zedo";"Moved to Virus Vault"
C:\Documents and Settings\William\Application Data\Mozilla\Firefox\Profiles\ehedr4y9.default\cookies.sqlite:\zedo.com.ff8ec9c0;"Found Tracking cookie.Zedo";"Moved to Virus Vault"
C:\Documents and Settings\William\Cookies\william@247realmedia[2].txt;"Found Tracking cookie.247realmedia";"Moved to Virus Vault"
C:\Documents and Settings\William\Cookies\william@247realmedia[2].txt:\247realmedia.com.125a868c;"Found Tracking cookie.247realmedia";"Moved to Virus Vault"
C:\Documents and Settings\William\Cookies\william@247realmedia[2].txt:\247realmedia.com.855b46d;"Found Tracking cookie.247realmedia";"Moved to Virus Vault"
C:\Documents and Settings\William\Cookies\william@2o7[2].txt;"Found Tracking cookie.2o7";"Moved to Virus Vault"
C:\Documents and Settings\William\Cookies\william@2o7[2].txt:\2o7.net.29c43642;"Found Tracking cookie.2o7";"Moved to Virus Vault"
C:\Documents and Settings\William\Cookies\william@2o7[2].txt:\2o7.net.990a393c;"Found Tracking cookie.2o7";"Moved to Virus Vault"
C:\Documents and Settings\William\Cookies\william@2o7[2].txt:\2o7.net.ebf63e2a;"Found Tracking cookie.2o7";"Moved to Virus Vault"
C:\Documents and Settings\William\Cookies\william@2o7[2].txt:\2o7.net.f06da886;"Found Tracking cookie.2o7";"Moved to Virus Vault"
C:\Documents and Settings\William\Cookies\william@admarketplace[1].txt;"Found Tracking cookie.Admarketplace";"Moved to Virus Vault"
C:\Documents and Settings\William\Cookies\william@admarketplace[1].txt:\admarketplace.net.61a250a;"Found Tracking cookie.Admarketplace";"Moved to Virus Vault"
C:\Documents and Settings\William\Cookies\[removed]-sys[2].txt;"Found Tracking cookie.Serving-sys";"Moved to Virus Vault"
C:\Documents and Settings\William\Cookies\[removed]-sys[2].txt:\bs.serving-sys.com.5bf1f00f;"Found Tracking cookie.Serving-sys";"Moved to Virus Vault"
C:\Documents and Settings\William\Cookies\william@overture[2].txt;"Found Tracking cookie.Overture";"Moved to Virus Vault"
C:\Documents and Settings\William\Cookies\william@overture[2].txt:\overture.com.52ca467a;"Found Tracking cookie.Overture";"Moved to Virus Vault"
C:\Documents and Settings\William\Cookies\william@overture[2].txt:\overture.com.e626e6be;"Found Tracking cookie.Overture";"Moved to Virus Vault"
C:\Documents and Settings\William\Cookies\william@questionmarket[1].txt;"Found Tracking cookie.Questionmarket";"Moved to Virus Vault"
C:\Documents and Settings\William\Cookies\william@questionmarket[1].txt:\questionmarket.com.3eb5a9f1;"Found Tracking cookie.Questionmarket";"Moved to Virus Vault"
C:\Documents and Settings\William\Cookies\william@questionmarket[1].txt:\questionmarket.com.4dd5e426;"Found Tracking cookie.Questionmarket";"Moved to Virus Vault"
C:\Documents and Settings\William\Cookies\william@questionmarket[1].txt:\questionmarket.com.767e4302;"Found Tracking cookie.Questionmarket";"Moved to Virus Vault"
C:\Documents and Settings\William\Cookies\william@serving-sys[1].txt;"Found Tracking cookie.Serving-sys";"Moved to Virus Vault"
C:\Documents and Settings\William\Cookies\william@serving-sys[1].txt:\serving-sys.com.255d6f2f;"Found Tracking cookie.Serving-sys";"Moved to Virus Vault"
C:\Documents and Settings\William\Cookies\william@serving-sys[1].txt:\serving-sys.com.400f83f;"Found Tracking cookie.Serving-sys";"Moved to Virus Vault"
C:\Documents and Settings\William\Cookies\william@serving-sys[1].txt:\serving-sys.com.4b416ef8;"Found Tracking cookie.Serving-sys";"Moved to Virus Vault"
C:\Documents and Settings\William\Cookies\william@serving-sys[1].txt:\serving-sys.com.606c3d3b;"Found Tracking cookie.Serving-sys";"Moved to Virus Vault"
C:\Documents and Settings\William\Cookies\william@serving-sys[1].txt:\serving-sys.com.6a1cf9e8;"Found Tracking cookie.Serving-sys";"Moved to Virus Vault"
C:\Documents and Settings\William\Cookies\william@serving-sys[1].txt:\serving-sys.com.c9034af6;"Found Tracking cookie.Serving-sys";"Moved to Virus Vault"
C:\Documents and Settings\William\Cookies\william@tacoda[1].txt;"Found Tracking cookie.Tacoda";"Moved to Virus Vault"
C:\Documents and Settings\William\Cookies\william@tacoda[1].txt:\tacoda.net.5935e89;"Found Tracking cookie.Tacoda";"Moved to Virus Vault"
C:\Documents and Settings\William\Cookies\william@tacoda[1].txt:\tacoda.net.c4fe2ebb;"Found Tracking cookie.Tacoda";"Moved to Virus Vault"
C:\Documents and Settings\William\Cookies\william@tacoda[1].txt:\tacoda.net.27341d57;"Found Tracking cookie.Tacoda";"Moved to Virus Vault"
C:\Documents and Settings\William\Cookies\william@tacoda[1].txt:\tacoda.net.4366831a;"Found Tracking cookie.Tacoda";"Moved to Virus Vault"
C:\Documents and Settings\William\Cookies\william@tacoda[1].txt:\tacoda.net.cd7ce44f;"Found Tracking cookie.Tacoda";"Moved to Virus Vault"
C:\Documents and Settings\William\Cookies\william@tacoda[1].txt:\tacoda.net.ed9c50d1;"Found Tracking cookie.Tacoda";"Moved to Virus Vault"
C:\Documents and Settings\William\Cookies\william@trafficmp[2].txt;"Found Tracking cookie.Trafficmp";"Moved to Virus Vault"
C:\Documents and Settings\William\Cookies\william@trafficmp[2].txt:\trafficmp.com.37644bdb;"Found Tracking cookie.Trafficmp";"Moved to Virus Vault"
C:\Documents and Settings\William\Cookies\william@trafficmp[2].txt:\trafficmp.com.a00e30b4;"Found Tracking cookie.Trafficmp";"Moved to Virus Vault"
C:\Documents and Settings\William\Cookies\william@trafficmp[2].txt:\trafficmp.com.ae53b8b;"Found Tracking cookie.Trafficmp";"Moved to Virus Vault"
C:\Documents and Settings\William\Cookies\william@trafficmp[2].txt:\trafficmp.com.e2e71e33;"Found Tracking cookie.Trafficmp";"Moved to Virus Vault"
C:\Documents and Settings\William\Cookies\william@trafficmp[2].txt:\trafficmp.com.f3e5803e;"Found Tracking cookie.Trafficmp";"Moved to Virus Vault"


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:06:42 PM, on 9/16/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16876)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\Program Files\OBD2 TekLink Consumer\TekInit.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\hphmon05.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe
C:\Program Files\Common Files\Corel\Corel PhotoDownloader\Corel Photo Downloader.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\PSIService.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\dllhost.exe
C:\PROGRA~1\hpq\Shared\HPQTOA~1.EXE
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:7171
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Winamp Toolbar BHO - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: CoolIrisIEHelperObject.CoolIrisIEBHO - {AD0BAB4B-212D-45D7-9E5B-CB1579132715} - C:\Program Files\CoolIris\CoolIrisIEHelperObject.dll
O2 - BHO: PicLens plug-in for Internet Explorer - {EAEE5C74-6D0D-4aca-9232-0DA4A7B866BA} - C:\Program Files\PicLensIE\PicLens.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [OBD2_TekLink_Start2.0] "C:\Program Files\OBD2 TekLink Consumer\TekInit.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HPHUPD05] C:\Program Files\HP\\{5372B9A6-6E51-4f90-9B40-E0A3B8475C4E}\hphupd05.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\system32\hphmon05.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
O4 - HKLM\..\Run: [Corel File Shell Monitor] C:\Program Files\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe
O4 - HKLM\..\Run: [Corel Photo Downloader] "C:\Program Files\Common Files\Corel\Corel PhotoDownloader\Corel Photo Downloader.exe" -startup
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: CoolIris Preferences - {449DB14A-F988-4fd8-9361-F212D7B6414B} - C:\Program Files\CoolIris\CoolIrisPreferences.exe
O9 - Extra 'Tools' menuitem: CoolIris Preferences - {449DB14A-F988-4fd8-9361-F212D7B6414B} - C:\Program Files\CoolIris\CoolIrisPreferences.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O15 - Trusted Zone: *.line6.net
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {54BE6B6F-3056-470B-97E1-BB92E051B6C4} (DeviceEnum Class) - http://h20264.www2.hp.com/ediags/dd/instal…nosticsxp2k.cab
O16 - DPF: {61628958-4627-48F4-99FD-30719188568D} (XCheck Control) - http://www.ifrontiers.com/ActiveX/XCheck.CAB
O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/inst…ctDetection.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1195829752453
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {BCBC9371-595D-11D4-A96D-00105A1CEF6C} (View22RTE Class) - http://onlinedesigner.hgtv.com/images/app/view22rte.cab
O16 - DPF: {BCBC9371-9827-11DA-A72B-0800200C9A66} (View22RTEv4 Class) - http://merillat.view22.com/release_3_9_177/View22RTEv4.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe

–
End of file - 10700 bytes
You have a couple of three entries in your log that point to files on your PC that I would like to have checked - if they are still present.

Please go to Jotti's and click on the Browse… button at the top and navigate to the following files in turn, and then click on Submit:

c:\windows\system32\621101D524.sys
c:\windows\system32\drivers\vokxr.sys
c:\windows\system32\drivers\f5940828.sys


When all the scans have been completed, please copy and paste the results into your next reply.

If this site is busy, try VirusTotal: Click the Browse … button, navigate to the file and double click it and then click the Send button.

You may need to set Windows to show All Hidden Files and Folders - Instructions can be found here.
* These files are hidden to stop you accidentally removing something important.
It is advisable to hide them again after you have done.
*

Let me know how the PC is behaving as well.
Scans were done at Virus total. I could only find c:\windows\system32\621101D524.sys and c:\windows\system32\drivers\vokxr.sys on my computer. And the computer seems to running fine but kind of slow when browsing the web.


File vokxr.sys received on 2009.09.17 20:31:28 (UTC)
Current status: Loading … queued waiting scanning finished NOT FOUND STOPPED
Result: 11/41 (26.83%)
Loading server information…
Your file is queued in position: 3.
Estimated start time is between 61 and 87 seconds.
Do not close the window until scan is complete.
The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result.
If you are waiting for more than five minutes you have to resend your file.
Your file is being scanned by VirusTotal in this moment,
results will be shown as they're generated.
Compact Compact
Print results Print results
Your file has expired or does not exists.
Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time.

You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished.
Email:

Antivirus Version Last Update Result
a-squared 4.5.0.24 2009.09.17 -
AhnLab-V3 5.0.0.2 2009.09.17 Win-Trojan/Avenger.61440
AntiVir 7.9.1.19 2009.09.17 -
Antiy-AVL 2.0.3.7 2009.09.17 Hoax/Win32.Agent.gen
Authentium 5.1.2.4 2009.09.17 -
Avast 4.8.1351.0 2009.09.17 -
AVG 8.5.0.412 2009.09.17 -
BitDefender 7.2 2009.09.17 -
CAT-QuickHeal 10.00 2009.09.17 Trojan.Agent.ATV
ClamAV 0.94.1 2009.09.17 -
Comodo 2352 2009.09.17 -
DrWeb 5.0.0.12182 2009.09.17 -
eSafe 7.0.17.0 2009.09.17 Win32.Banker
eTrust-Vet 31.6.6743 2009.09.17 -
F-Prot 4.5.1.85 2009.09.17 -
F-Secure 8.0.14470.0 2009.09.17 -
Fortinet 3.120.0.0 2009.09.17 -
GData 19 2009.09.17 -
Ikarus T3.1.1.72.0 2009.09.17 -
Jiangmin 11.0.800 2009.09.17 Hoax.Agent.f
K7AntiVirus 7.10.847 2009.09.17 Trojan.Win32.Malware.1
Kaspersky 7.0.0.125 2009.09.17 -
McAfee 5744 2009.09.17 -
McAfee+Artemis 5744 2009.09.17 -
McAfee-GW-Edition 6.8.5 2009.09.17 -
Microsoft 1.5005 2009.09.17 -
NOD32 4435 2009.09.17 -
Norman 6.01.09 2009.09.17 W32/Renos.CNZ
nProtect 2009.1.8.0 2009.09.17 Trojan/W32.Agent.61440.JQ
Panda 10.0.2.2 2009.09.17 Rootkit/Agent.LNB
PCTools 4.4.2.0 2009.09.17 -
Prevx 3.0 2009.09.17 High Risk Worm
Rising 21.47.34.00 2009.09.17 -
Sophos 4.45.0 2009.09.17 -
Sunbelt 3.2.1858.2 2009.09.17 -
Symantec 1.4.4.12 2009.09.17 -
TheHacker [removed].404 2009.09.15 -
TrendMicro 8.950.0.1094 2009.09.17 -
VBA32 3.12.10.10 2009.09.17 -
ViRobot 2009.9.17.1941 2009.09.17 Hoax..Agent.61440
VirusBuster 4.6.5.0 2009.09.17 -
Additional information
File size: 61440 bytes
MD5…: 589312a3b46721c5a751e4d5222a89be
SHA1..: 3a497d3968a4f6e3c648d196da38e5f98e75ec30
SHA256: 03cbe6df7f5605a3659ffe27a1184a8d9066436a17d7bac9cceb122de74f69ae
ssdeep: 768:UzNrXvTHr4DU6K5H5VLvDcLugwoMcq5+x7J1uQ9VP:QTG2VrOuN+lJpP
PEiD..: -
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0xd394
timedatestamp…..: 0x476b398b (Fri Dec 21 03:56:59 2007)
machinetype…….: 0x14c (I386)

( 5 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x400 0xd756 0xd780 5.52 e0dc8fff10e3a7c6343455cd02a67954
.rdata 0xdb80 0x10e 0x180 3.44 d2fd0bc28e070ccc67879e04b7cd5302
.data 0xdd00 0xc0 0x100 0.04 66a415a49d751cb335895306ecfb3389
INIT 0xde00 0x376 0x380 5.17 79cc3d62ef3ba8053786e08dc9b6cddc
.reloc 0xe180 0xe2c 0xe80 6.60 4f845320301140370066cbceee4c5e4c

( 1 imports )
> ntoskrnl.exe: ZwWriteFile, wcslen, RtlUpcaseUnicodeChar, ZwClose, ZwCreateFile, RtlInitUnicodeString, wcscat, wcscpy, _wcsicmp, ZwQueryValueKey, ZwOpenKey, ZwDeleteKey, swprintf, ZwEnumerateKey, ExFreePoolWithTag, DbgPrint, ExAllocatePoolWithTag, RtlPrefixUnicodeString, RtlDeleteRegistryValue, ZwSetValueKey, RtlWriteRegistryValue, ZwEnumerateValueKey, ZwOpenFile, ZwSetInformationFile, KeTickCount, ZwQueryInformationFile, KeBugCheck, MmGetSystemRoutineAddress, ZwFlushKey, PsTerminateSystemThread, KeSetPriorityThread, KeGetCurrentThread, RtlCheckRegistryKey, KeDelayExecutionThread, ZwReadFile, PsCreateSystemThread, PsGetVersion

( 0 exports )
RDS…: NSRL Reference Data Set
-
pdfid.: -
trid..: Clipper DOS Executable (33.3%)
Generic Win/DOS Executable (33.0%)
DOS Executable Generic (33.0%)
VXD Driver (0.5%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.1%)
http://info.prevx.com/aboutprogramtext.asp?PX5=0D0120F6002DA0A9F00500511CA22500289EA8D6
ThreatExpert info: http://www.threatexpert.com/report.aspx?md5=589312a3b46721c5a751e4d5222a89be
sigcheck:
publisher….: n/a
copyright….: n/a
product……: n/a
description..: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments…..: n/a
signers……: -
signing date.: -
verified…..: Unsigned


File 621101D524.sys received on 2009.09.17 20:39:35 (UTC)
Current status: Loading … queued waiting scanning finished NOT FOUND STOPPED
Result: 0/41 (0%)
Loading server information…
Your file is queued in position: ___.
Estimated start time is between ___ and ___ .
Do not close the window until scan is complete.
The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result.
If you are waiting for more than five minutes you have to resend your file.
Your file is being scanned by VirusTotal in this moment,
results will be shown as they're generated.
Compact Compact
Print results Print results
Your file has expired or does not exists.
Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time.

You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished.
Email:

Antivirus Version Last Update Result
a-squared 4.5.0.24 2009.09.17 -
AhnLab-V3 5.0.0.2 2009.09.17 -
AntiVir 7.9.1.19 2009.09.17 -
Antiy-AVL 2.0.3.7 2009.09.17 -
Authentium 5.1.2.4 2009.09.17 -
Avast 4.8.1351.0 2009.09.17 -
AVG 8.5.0.412 2009.09.17 -
BitDefender 7.2 2009.09.17 -
CAT-QuickHeal 10.00 2009.09.17 -
ClamAV 0.94.1 2009.09.17 -
Comodo 2352 2009.09.17 -
DrWeb 5.0.0.12182 2009.09.17 -
eSafe 7.0.17.0 2009.09.17 -
eTrust-Vet 31.6.6743 2009.09.17 -
F-Prot 4.5.1.85 2009.09.17 -
F-Secure 8.0.14470.0 2009.09.17 -
Fortinet 3.120.0.0 2009.09.17 -
GData 19 2009.09.17 -
Ikarus T3.1.1.72.0 2009.09.17 -
Jiangmin 11.0.800 2009.09.17 -
K7AntiVirus 7.10.847 2009.09.17 -
Kaspersky 7.0.0.125 2009.09.17 -
McAfee 5744 2009.09.17 -
McAfee+Artemis 5744 2009.09.17 -
McAfee-GW-Edition 6.8.5 2009.09.17 -
Microsoft 1.5005 2009.09.17 -
NOD32 4435 2009.09.17 -
Norman 6.01.09 2009.09.17 -
nProtect 2009.1.8.0 2009.09.17 -
Panda 10.0.2.2 2009.09.17 -
PCTools 4.4.2.0 2009.09.17 -
Prevx 3.0 2009.09.17 -
Rising 21.47.34.00 2009.09.17 -
Sophos 4.45.0 2009.09.17 -
Sunbelt 3.2.1858.2 2009.09.17 -
Symantec 1.4.4.12 2009.09.17 -
TheHacker [removed].404 2009.09.15 -
TrendMicro 8.950.0.1094 2009.09.17 -
VBA32 3.12.10.10 2009.09.17 -
ViRobot 2009.9.17.1941 2009.09.17 -
VirusBuster 4.6.5.0 2009.09.17 -
Additional information
File size: 88 bytes
MD5…: 33e3777e3c6e04276f31a30d0ad3f854
SHA1..: d235b8a8fe9df69e125bdf839d5bd7858b9ce938
SHA256: 1e8dd8176146b9cff0c07868b4f98e5ba4c30ea2c2f0ca4ce1bc1f4859bdc7a4
ssdeep: 3:hl/JgMlll/IWu7n:K2I1n
PEiD..: -
PEInfo: -
RDS…: NSRL Reference Data Set
-
pdfid.: -
trid..: MS Flight Simulator Aircraft Performance Info (100.0%)
sigcheck:
publisher….: n/a
copyright….: n/a
product……: n/a
description..: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments…..: n/a
signers……: -
signing date.: -
verified…..: Unsigned
We better have a poke around then. Pay a visit to the Kaspersky Online Scanner 7 - I.E. is preferred for this scan.
  • Read the Information panel and then click Accept.
  • Allow the ActiveX download if necessary.
  • Both the anti-virus engine and database will need to be downloaded, which may take a little time.
  • Once this has been completed, select My Computer from the Scan section on the left hand side.
  • Put the kettle on!
  • Although it is recommended by Kaspersky that you should disable your anti-virus scanner before starting this scan, it should work OK with it still active - it does on my PC.
    Although you may find the scan speed increases if you carry out this step, I never like to disable my resident scanner while online, so I don't.
  • When the scan has completed, click View scan report at the bottom.
  • Click Save Report As…
  • Enter a name for the file in the Filename: text box and then click the down arrow to the right of Save as type: and select text file (*.txt)
  • Click Save and pick a location for the file - the Desktop is always handy.
Copy and paste the report into your next reply along with a fresh HJT log, run in Normal Mode, and a description of how your PC is behaving.
Here are the scan results. And the computer is running fine except IE or Firefox run very slow.

——————————————————————————–
KASPERSKY ONLINE SCANNER 7.0: scan report
Thursday, September 17, 2009
Operating system: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Thursday, September 17, 2009 23:08:28
Records in database: 2846139
——————————————————————————–

Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes

Scan area - My Computer:
C:\
D:\

Scan statistics:
Objects scanned: 90497
Threats found: 6
Infected objects found: 9
Suspicious objects found: 50
Scan duration: 02:30:55


File name / Threat / Threats count
C:\Documents and Settings\William\Application Data\Sun\Java\Deployment\cache\6.0\45\4e06e6d-5bbe25ba Infected: Trojan.Java.ClassLoader.as 3
C:\Documents and Settings\William\Local Settings\Application Data\Identities\{2D9FBA8C-31B8-430E-A746-D61E22698F06}\Microsoft\Outlook Express\Deleted Items.dbx Suspicious: Trojan-Spy.HTML.Fraud.gen 50
C:\Documents and Settings\William\Local Settings\Application Data\Identities\{2D9FBA8C-31B8-430E-A746-D61E22698F06}\Microsoft\Outlook Express\Deleted Items.dbx Infected: Trojan-Spy.HTML.Bankfraud.sv 2
C:\Documents and Settings\William\Local Settings\Application Data\Identities\{2D9FBA8C-31B8-430E-A746-D61E22698F06}\Microsoft\Outlook Express\Deleted Items.dbx Infected: Exploit.Win32.PDF-URI.k 1
C:\Documents and Settings\William\Local Settings\Application Data\Identities\{2D9FBA8C-31B8-430E-A746-D61E22698F06}\Microsoft\Outlook Express\Deleted Items.dbx Infected: Trojan.Win32.Pakes.bpa 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\UACqhbqqltuwc.dll.vir Infected: Packed.Win32.TDSS.y 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\UACrmhpmowqjb.dll.vir Infected: Packed.Win32.TDSS.y 1

Selected area has been scanned.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:16:36 PM, on 9/17/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16876)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\PSIService.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\Program Files\OBD2 TekLink Consumer\TekInit.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\hphmon05.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe
C:\Program Files\Common Files\Corel\Corel PhotoDownloader\Corel Photo Downloader.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\DNA\btdna.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\dllhost.exe
C:\PROGRA~1\hpq\Shared\HPQTOA~1.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:7171
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Winamp Toolbar BHO - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: CoolIrisIEHelperObject.CoolIrisIEBHO - {AD0BAB4B-212D-45D7-9E5B-CB1579132715} - C:\Program Files\CoolIris\CoolIrisIEHelperObject.dll
O2 - BHO: PicLens plug-in for Internet Explorer - {EAEE5C74-6D0D-4aca-9232-0DA4A7B866BA} - C:\Program Files\PicLensIE\PicLens.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [OBD2_TekLink_Start2.0] "C:\Program Files\OBD2 TekLink Consumer\TekInit.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HPHUPD05] C:\Program Files\HP\\{5372B9A6-6E51-4f90-9B40-E0A3B8475C4E}\hphupd05.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\system32\hphmon05.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
O4 - HKLM\..\Run: [Corel File Shell Monitor] C:\Program Files\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe
O4 - HKLM\..\Run: [Corel Photo Downloader] "C:\Program Files\Common Files\Corel\Corel PhotoDownloader\Corel Photo Downloader.exe" -startup
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: CoolIris Preferences - {449DB14A-F988-4fd8-9361-F212D7B6414B} - C:\Program Files\CoolIris\CoolIrisPreferences.exe
O9 - Extra 'Tools' menuitem: CoolIris Preferences - {449DB14A-F988-4fd8-9361-F212D7B6414B} - C:\Program Files\CoolIris\CoolIrisPreferences.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O15 - Trusted Zone: *.line6.net
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {54BE6B6F-3056-470B-97E1-BB92E051B6C4} (DeviceEnum Class) - http://h20264.www2.hp.com/ediags/dd/instal…nosticsxp2k.cab
O16 - DPF: {61628958-4627-48F4-99FD-30719188568D} (XCheck Control) - http://www.ifrontiers.com/ActiveX/XCheck.CAB
O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/inst…ctDetection.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1195829752453
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {BCBC9371-595D-11D4-A96D-00105A1CEF6C} (View22RTE Class) - http://onlinedesigner.hgtv.com/images/app/view22rte.cab
O16 - DPF: {BCBC9371-9827-11DA-A72B-0800200C9A66} (View22RTEv4 Class) - http://merillat.view22.com/release_3_9_177/View22RTEv4.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe

–
End of file - 10790 bytes

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI