This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] System weird, antivirus seems at fault

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I went to the live chat section to ask about this slowness and LEURGY encouraged me to come here as well. The problem seemed to lie with my antivirus system (Kaspersky) which when trying to auto update would stick and keep "updating" for hours on end, even though the update was listed at 100%. This was using massive resources and keeping the rest of the system from working properly. He suggested that I run the malwarebytes scan, which I did, and it located a trojan.dropper which was fixed. But he also suggested I post a HJT log to make sure there were no more issues.
see below: (note, I also ran the malware bytes again (found nothing), and the ATR deal.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:01:04 PM, on 12/21/2009
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16945)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Maxtor\ManagerApp\OneTouch.exe
C:\Program Files\Maxtor\OneTouch Status\MaxMenuMgr.exe
C:\Program Files\ScanSoft\OmniPageSE2.0\opwareSE2.exe
C:\Program Files\Canon\Memory Card Utility\iP6600D\PDUiP6600DMon.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
C:\Program Files\TrueCredit Messenger\TCMTray.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Microsoft Location Finder\LocationFinder.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\System32\mobsync.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\GmoteServer\GmoteServer.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Java\jre6\bin\javaw.exe
C:\Program Files\MSN\MSNCoreFiles\msn.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Users\HP_Administrator\Documents\HijackThis.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:9022
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll
O2 - BHO: IconixBHOClass Class - {761233B6-F228-49E4-8F6B-668499D4E55A} - C:\Program Files\Iconix\IEAddOn\IconixBHO_41.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar\3.9.0\ViewBarBHO.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Common Files\Viewpoint\Toolbar Runtime\3.9.0\IEViewBar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [MaxtorOneTouch] C:\Program Files\Maxtor\ManagerApp\Onetouch.exe
O4 - HKLM\..\Run: [mxomssmenu] "C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe"
O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [PDUiP6600DMon] C:\Program Files\Canon\Memory Card Utility\iP6600D\PDUiP6600DMon.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe"
O4 - HKLM\..\Run: [TrueCredit Messenger Tray] "C:\Program Files\TrueCredit Messenger\TCMTray.exe" /Start
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Microsoft Location Finder] "C:\Program Files\Microsoft Location Finder\LocationFinder.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - .DEFAULT User Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
O4 - Startup: GmoteServer.lnk = C:\Program Files\GmoteServer\GmoteServer.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Updates From HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
O8 - Extra context menu item: Add to Banner Ad Blocker - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll
O9 - Extra button: (no name) - {400A6CFA-E326-4d61-A90C-9AD75358DC5F} - C:\Program Files\Iconix\IEAddOn\IconixBHO_41.dll
O9 - Extra 'Tools' menuitem: Email ID Preferences - {400A6CFA-E326-4d61-A90C-9AD75358DC5F} - C:\Program Files\Iconix\IEAddOn\IconixBHO_41.dll
O9 - Extra button: (no name) - {BC3F6B6D-2E49-4603-B028-7411655713F3} - C:\Program Files\Iconix\IEAddOn\IconixBHO_41.dll
O9 - Extra 'Tools' menuitem: About Email ID - {BC3F6B6D-2E49-4603-B028-7411655713F3} - C:\Program Files\Iconix\IEAddOn\IconixBHO_41.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\Windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\Windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O13 - Gopher Prefix:
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll,C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
O23 - Service: Intel® Quick Resume technology (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology Drivers\Elservice.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: Iconix Update Service (IconixService) - Unknown owner - C:\Program Files\Common Files\Iconix\IconixService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MaxBackServiceInt - Unknown owner - C:\Program Files\Maxtor\Maxtor Backup\MaxBackServiceInt.exe
O23 - Service: MaxSyncService (NTService1) - - C:\Program Files\Maxtor\Utils\SyncServices.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 13500 bytes
Hi TCHal,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Download the GMER Rootkit Scanner. Unzip it to your Desktop.

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

Double-click gmer.exe. The program will begin to run.

**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<— ROOKIT" entries unless advised!

If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked … leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.
If you do not receive notice about possible rootkit activity remain on the Rootkit/Malware tab & make sure the 'Show All' button is unticked.
  • Click the Scan button and let the program do its work. GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop

Download OTL to your desktop.
  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • Copy and paste the following bold text in to the window Under the Custom Scan box

    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    /md5stop
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.

Please post back with
  • GMER log
  • both OTL logs
Thanks Tom, I started off with the GMER rootkit deal, which didn't go so well. It began the scan, and even looked like it had finished, when I got the blue screen of death. once it restarted I got the following windows message: Problem signature: Problem Event Name: BlueScreen OS Version: 6.0.6000.2.0.0.768.3 Locale ID: 1033 Additional information about the problem: BCCode: 50 BCP1: 914F000B BCP2: 00000000 BCP3: 8A324C65 BCP4: 00000000 OS Version: 6_0_6000 Service Pack: 0_0 Product: 768_1 Files that help describe the problem: C:\Windows\Minidump\Mini122809-01.dmp C:\Users\HP_Administrator\AppData\Local\Temp\WER-214953-0.sysdata.xml C:\Users\HP_Administrator\AppData\Local\Temp\WERBA87.tmp.version.txt I'll try again
Following are the OTL logs:
OTL logfile created on: 12/28/2009 4:15:36 PM - Run 1
OTL by OldTimer - Version 3.1.20.1 Folder = C:\Users\HP_Administrator\Desktop
Windows Vista Home Premium Edition (Version = 6.0.6000) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6000.16945)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,014.00 Mb Total Physical Memory | 197.00 Mb Available Physical Memory | 19.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 49.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 177.66 Gb Total Space | 42.61 Gb Free Space | 23.98% Space Free | Partition Type: NTFS
Drive D: | 8.63 Gb Total Space | 0.33 Gb Free Space | 3.77% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: YOUR-4DACD0EA75
Current User Name: HP_Administrator
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Program Files\HP\HP Software Update\HPWuSchd2.exe File not found
PRC - C:\Users\HP_Administrator\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Iconix\IconixService.exe ()
PRC - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe (Kaspersky Lab)
PRC - c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe (Microsoft Corporation)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Java\jre6\bin\javaw.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\TrueCredit Messenger\TCMTray.exe (TransUnion Interactive)
PRC - C:\Program Files\GmoteServer\GmoteServer.exe ()
PRC - c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe (Viewpoint Corporation)
PRC - C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
PRC - C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe (Hewlett-Packard Company)
PRC - C:\Program Files\MSN\MSNCoreFiles\msn.exe (Microsoft Corporation)
PRC - C:\Windows\System32\igfxsrvc.exe (Intel Corporation)
PRC - C:\Windows\System32\igfxpers.exe (Intel Corporation)
PRC - C:\Windows\System32\hkcmd.exe (Intel Corporation)
PRC - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Windows\System32\drivers\XAudio.exe (Conexant Systems, Inc.)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple, Inc.)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Program Files\Microsoft Location Finder\LocationFinder.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
PRC - C:\Windows\System32\WUDFHost.exe (Microsoft Corporation)
PRC - C:\Windows\System32\wercon.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Maxtor\OneTouch Status\MaxMenuMgr.exe (Maxtor Corporation)
PRC - C:\Program Files\Maxtor\ManagerApp\OneTouch.exe (Maxtor Corporation)
PRC - C:\Program Files\Maxtor\Maxtor Backup\MaxBackServiceInt.exe ()
PRC - C:\Windows\System32\HPZipm12.exe (HP)
PRC - C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files\Maxtor\Utils\SyncServices.exe ( )
PRC - C:\Program Files\Canon\Memory Card Utility\iP6600D\PDUiP6600DMon.exe (CANON INC.)
PRC - C:\hp\KBD\kbd.exe (Hewlett-Packard Company)
PRC - C:\Program Files\ScanSoft\OmniPageSE2.0\opwareSE2.exe (ScanSoft, Inc.)
PRC - C:\Windows\System32\LEXBCES.EXE (Lexmark International, Inc.)
PRC - C:\Windows\System32\LEXPPS.EXE (Lexmark International, Inc.)
PRC - c:\Windows\system\hpsysdrv.exe (Hewlett-Packard Company)


========== Modules (SafeList) ==========

MOD - C:\Users\HP_Administrator\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\mzvkbd3.dll (Kaspersky Lab)
MOD - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\mzvkbd.dll (Kaspersky Lab)
MOD - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\kloehk.dll (Kaspersky Lab)
MOD - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\adialhk.dll (Kaspersky Lab)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (IconixService) – C:\Program Files\Common Files\Iconix\IconixService.exe ()
SRV - (WinHttpAutoProxySvc) – winhttp.dll (Microsoft Corporation)
SRV - (AVP) – C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe (Kaspersky Lab)
SRV - (MSSQL$MSSMLBIZ) SQL Server (MSSMLBIZ) – c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe (Microsoft Corporation)
SRV - (SQLWriter) – c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)
SRV - (SQLBrowser) – c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation)
SRV - (MSSQLServerADHelper) – c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe (Microsoft Corporation)
SRV - (LightScribeService) – C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
SRV - (iPod Service) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (WLSetupSvc) – C:\Program Files\Windows Live\installer\WLSetupSvc.exe (Microsoft Corporation)
SRV - (XAudioService) – C:\Windows\System32\drivers\XAudio.exe (Conexant Systems, Inc.)
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple, Inc.)
SRV - (IAANTMON) Intel® – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (Viewpoint Manager Service) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (ehstart) – C:\Windows\ehome\ehstart.dll (Microsoft Corporation)
SRV - (MaxBackServiceInt) – C:\Program Files\Maxtor\Maxtor Backup\MaxBackServiceInt.exe ()
SRV - (ELService) Intel® – C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology Drivers\ELService.exe (Intel Corporation)
SRV - (Pml Driver HPZ12) – C:\Windows\System32\HPZipm12.exe (HP)
SRV - (NTService1) – C:\Program Files\Maxtor\Utils\SyncServices.exe ( )
SRV - (ose) – c:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (IDriverT) – C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (LexBceS) – C:\Windows\System32\LEXBCES.EXE (Lexmark International, Inc.)


========== Driver Services (SafeList) ==========

DRV - (NuidFltr) – C:\Windows\System32\drivers\nuidfltr.sys (Microsoft Corporation)
DRV - (KLIF) – C:\Windows\System32\drivers\klif.sys (Kaspersky Lab)
DRV - (klbg) – C:\Windows\system32\drivers\klbg.sys (Kaspersky Lab)
DRV - (kl1) – C:\Windows\System32\drivers\kl1.sys (Kaspersky Lab)
DRV - (KLIM6) – C:\Windows\System32\drivers\klim6.sys (Kaspersky Lab)
DRV - (HSXHWBS2) – C:\Windows\System32\drivers\HSXHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\Windows\System32\drivers\HSX_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) – C:\Windows\System32\drivers\HSX_DP.sys (Conexant Systems, Inc.)
DRV - (igfx) – C:\Windows\System32\drivers\igdkmd32.sys (Intel Corporation)
DRV - (KLFLTDEV) – C:\Windows\System32\drivers\klfltdev.sys (Kaspersky Lab)
DRV - (USBAAPL) – C:\Windows\System32\drivers\usbaapl.sys (Apple, Inc.)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (PxHelp20) – C:\Windows\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\Windows\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)
DRV - (ql2300) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (adp94xx) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (elxstor) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adpahci) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (uliahci) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (iaStorV) – C:\Windows\system32\DRIVERS\iaStorV.sys (Intel Corporation)
DRV - (adpu320) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (ulsata2) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (vsmraid) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ql40xx) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (adpu160m) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (nvraid) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (SiSRaid4) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (nvstor) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (aic78xx) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (arcsas) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (LSI_SCSI) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (SiSRaid2) – C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (HpCISSs) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (arc) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (iteraid) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (LSI_SAS) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (Symc8xx) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (LSI_FC) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (Sym_u3) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (megasas) – C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (viaide) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (USB_RNDIS) – C:\Windows\System32\drivers\usb8023.sys (Microsoft Corporation)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (VSTHWBS2) – C:\Windows\System32\drivers\VSTBS23.SYS (Conexant Systems, Inc.)
DRV - (VST_DPV) – C:\Windows\System32\drivers\VSTDPV3.SYS (Conexant Systems, Inc.)
DRV - (ntrigdigi) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (e1express) Intel® – C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (E1G60) Intel® – C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (secdrv) – C:\Windows\System32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (iaStor) – C:\Windows\system32\drivers\iastor.sys (Intel Corporation)
DRV - (GEARAspiWDM) – C:\Windows\System32\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (mdmxsdk) – C:\Windows\System32\drivers\mdmxsdk.sys (Conexant)
DRV - (ELmon) – C:\Windows\System32\drivers\Elmon.sys (Intel Corporation)
DRV - (ELkbd) – C:\Windows\System32\drivers\Elkbd.sys (Intel Corporation)
DRV - (ELmou) – C:\Windows\System32\drivers\Elmou.sys (Intel Corporation)
DRV - (ELhid) – C:\Windows\System32\drivers\Elhid.sys (Intel Corporation)
DRV - (Ps2) – C:\Windows\System32\drivers\PS2.sys (Hewlett-Packard Company)
DRV - (MXOPSWD) – C:\Windows\System32\drivers\mxopswd.sys (Maxtor Corp.)
DRV - (pfc) – C:\Windows\System32\drivers\pfc.sys (Padus, Inc.)
DRV - (grmnusb) – C:\Windows\System32\drivers\grmnusb.sys (GARMIN Corp.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:9022

FF - HKLM\software\mozilla\Thunderbird\Extensions\\{eea12ec4-729d-4703-bc37-106ce9879ce2}: C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\THBExt [2009/03/01 16:34:17 | 00,000,000 | —D | M]

[2009/03/01 13:59:45 | 00,000,000 | —D | M] – C:\Users\HP_Administrator\AppData\Roaming\Mozilla\Extensions
[2009/03/01 13:59:45 | 00,000,000 | —D | M] – C:\Users\HP_Administrator\AppData\Roaming\Mozilla\Extensions\[removed]

O1 HOSTS File: (761 bytes) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll (Kaspersky Lab)
O2 - BHO: (IconixBHOClass Class) - {761233B6-F228-49E4-8F6B-668499D4E55A} - C:\Program Files\Iconix\IEAddOn\IconixBHO_41.dll ()
O2 - BHO: (Viewpoint Toolbar BHO) - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar\3.9.0\ViewBarBHO.dll (Viewpoint Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O3 - HKLM\..\Toolbar: (Viewpoint Toolbar) - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Common Files\Viewpoint\Toolbar Runtime\3.9.0\IEViewBar.dll (Viewpoint Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AVP] C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe (Kaspersky Lab)
O4 - HKLM..\Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe File not found
O4 - HKLM..\Run: [HPBootOp] C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe (Intel Corporation)
O4 - HKLM..\Run: [IgfxTray] C:\Windows\System32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [MaxtorOneTouch] C:\Program Files\Maxtor\ManagerApp\OneTouch.exe (Maxtor Corporation)
O4 - HKLM..\Run: [mxomssmenu] C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe (Maxtor Corporation)
O4 - HKLM..\Run: [OpwareSE2] C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe (ScanSoft, Inc.)
O4 - HKLM..\Run: [PDUiP6600DMon] C:\Program Files\Canon\Memory Card Utility\iP6600D\PDUiP6600DMon.exe (CANON INC.)
O4 - HKLM..\Run: [Persistence] C:\Windows\System32\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
O4 - HKLM..\Run: [Recguard] C:\Windows\SMINST\Recguard.exe ()
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [TrueCredit Messenger Tray] C:\Program Files\TrueCredit Messenger\TCMTray.exe (TransUnion Interactive)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe (Hewlett-Packard Company)
O4 - HKCU..\Run: [Microsoft Location Finder] C:\Program Files\Microsoft Location Finder\LocationFinder.exe (Microsoft Corporation)
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
O4 - Startup: C:\Users\HP_Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\GmoteServer.lnk = C:\Program Files\GmoteServer\GmoteServer.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 157
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles File not found
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Add to Banner Ad Blocker - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm ()
O8 - Extra context menu item: Easy-WebPrint Add To Print List - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint High Speed Print - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint Preview - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint Print - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O9 - Extra Button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll (Kaspersky Lab)
O9 - Extra 'Tools' menuitem : Email ID Preferences - {400A6CFA-E326-4d61-A90C-9AD75358DC5F} - C:\Program Files\Iconix\IEAddOn\IconixBHO_41.dll ()
O9 - Extra 'Tools' menuitem : About Email ID - {BC3F6B6D-2E49-4603-B028-7411655713F3} - C:\Program Files\Iconix\IEAddOn\IconixBHO_41.dll ()
O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\PLUGINS\NPDocBox.dll (Intertrust Technologies, Inc.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: //@mail.mar@/ ([]msn in Local intranet)
O15 - HKCU\..Trusted Domains: //@signup.mar@/ ([]msn in Computer)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file:///C:/WINDOWS/Java/classes/xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 [removed]
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll) - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\mzvkbd.dll (Kaspersky Lab)
O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll) - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\mzvkbd3.dll (Kaspersky Lab)
O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll) - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\adialhk.dll (Kaspersky Lab)
O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll) - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\kloehk.dll (Kaspersky Lab)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\klogon: DllName - C:\Windows\system32\klogon.dll - C:\Windows\System32\klogon.dll (Kaspersky Lab)
O20 - Winlogon\Notify\WgaLogon: DllName - WgaLogon.dll - WgaLogon.dll (Microsoft Corporation)
O20 - Winlogon\Notify\WRNotifier: DllName - WRLogonNTF.dll - File not found
O29 - HKLM SecurityProviders - (credssp.dll) - credssp.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 15:43:36 | 00,000,024 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2001/07/27 08:07:38 | 00,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O32 - AutoRun File - [2004/04/30 00:01:14 | 00,000,053 | -HS- | M] () - D:\Autorun.inf – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias [2006/11/02 05:18:47 | 00,000,000 | —D | M]
NetSvcs: Irmon - C:\Windows\System32\irmon.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
OTL cannot create restorepoints on Vista OSs!

========== Files/Folders - Created Within 30 Days ==========

[2009/12/28 16:06:23 | 00,513,536 | —- | C] (OldTimer Tools) – C:\Users\HP_Administrator\Desktop\OTL.exe
[2009/12/26 23:36:42 | 00,719,872 | —- | C] (Abysmal Software) – C:\Windows\System32\devil.dll
[2009/12/26 23:36:42 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Common Share
[2009/12/26 23:36:40 | 00,351,744 | —- | C] (The Public) – C:\Windows\System32\avisynth.dll
[2009/12/26 23:36:38 | 00,000,000 | —D | C] – C:\Program Files\OJOsoft
[2009/12/26 23:34:56 | 00,000,000 | —D | C] – C:\ProgramData\NCH Software
[2009/12/26 23:34:04 | 00,000,000 | —D | C] – C:\Program Files\NCH Software
[2009/12/24 13:16:16 | 00,000,000 | —D | C] – C:\Users\HP_Administrator\AppData\Local\Apple
[2009/12/24 13:15:35 | 00,000,000 | —D | C] – C:\Users\HP_Administrator\AppData\Local\Apple Computer
[2009/12/22 10:12:24 | 00,000,000 | —D | C] – C:\Users\HP_Administrator\AppData\Local\Adobe
[2009/12/11 03:04:09 | 00,024,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\nshhttp.dll
[2009/12/11 03:04:04 | 00,031,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\httpapi.dll
[2009/12/10 06:57:28 | 00,389,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2009/12/10 06:57:27 | 00,671,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2009/12/10 06:57:27 | 00,380,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2009/12/10 06:57:26 | 00,385,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2009/12/10 06:57:25 | 00,459,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2009/12/10 06:57:25 | 00,347,136 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2009/12/10 06:57:25 | 00,230,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2009/12/10 06:57:24 | 00,214,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2009/12/10 06:57:23 | 01,830,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2009/12/10 06:57:23 | 00,078,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieencode.dll
[2009/12/10 06:57:23 | 00,027,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2009/12/10 06:57:22 | 00,124,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\advpack.dll
[2009/12/10 06:57:22 | 00,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\admparse.dll
[2009/12/10 06:57:21 | 00,180,736 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2009/12/10 06:57:21 | 00,056,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2009/12/10 06:57:21 | 00,044,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2009/12/10 06:57:20 | 00,070,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2009/12/10 06:57:20 | 00,044,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2009/12/10 06:57:20 | 00,026,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2009/12/10 06:57:19 | 00,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakui.dll
[2009/12/10 06:57:18 | 00,048,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2009/12/10 06:57:17 | 01,383,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2009/12/09 21:19:49 | 00,232,960 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rastls.dll
[2009/12/09 21:19:48 | 00,274,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\raschap.dll
[6 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2009/12/28 16:15:04 | 04,980,736 | -HS- | M] () – C:\Users\HP_Administrator\NTUSER.DAT
[2009/12/28 16:05:02 | 00,513,536 | —- | M] (OldTimer Tools) – C:\Users\HP_Administrator\Desktop\OTL.exe
[2009/12/28 15:57:24 | 00,000,565 | —- | M] () – C:\Users\HP_Administrator\Documents\My Sharing Folders.lnk
[2009/12/28 15:51:00 | 00,002,240 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2009/12/28 15:50:59 | 00,002,240 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2009/12/28 15:50:55 | 00,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2009/12/28 15:50:33 | 00,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2009/12/28 15:50:23 | 10,637,35296 | -HS- | M] () – C:\hiberfil.sys
[2009/12/28 15:50:00 | 23,778,4514 | —- | M] () – C:\Windows\MEMORY.DMP
[2009/12/28 15:04:54 | 00,000,505 | —- | M] () – C:\Users\HP_Administrator\Desktop\Archive.zip - Shortcut.lnk
[2009/12/28 00:03:29 | 06,637,600 | -HS- | M] () – C:\Windows\System32\drivers\fidbox.dat
[2009/12/27 23:23:55 | 00,052,936 | -HS- | M] () – C:\Windows\System32\drivers\fidbox.idx
[2009/12/27 00:22:29 | 01,286,176 | -HS- | M] () – C:\Windows\System32\drivers\fidbox2.dat
[2009/12/27 00:15:49 | 00,005,476 | -HS- | M] () – C:\Windows\System32\drivers\fidbox2.idx
[2009/12/26 23:34:04 | 00,000,912 | —- | M] () – C:\Users\Public\Desktop\Prism Video Converter.lnk
[2009/12/25 18:46:17 | 00,000,284 | —- | M] () – C:\Windows\tasks\AppleSoftwareUpdate.job
[2009/12/24 18:02:04 | 00,043,008 | —- | M] () – C:\Users\HP_Administrator\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/12/24 11:48:43 | 00,685,882 | —- | M] () – C:\Windows\System32\perfh009.dat
[2009/12/24 11:48:43 | 00,130,510 | —- | M] () – C:\Windows\System32\perfc009.dat
[2009/12/24 11:48:42 | 00,813,620 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2009/12/21 20:00:54 | 00,001,885 | —- | M] () – C:\Users\HP_Administrator\Desktop\HijackThis.lnk
[2009/12/21 18:36:31 | 00,000,829 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/12/21 10:39:06 | 05,409,662 | -H– | M] () – C:\Users\HP_Administrator\AppData\Local\IconCache.db
[2009/12/21 08:38:51 | 00,045,232 | —- | M] () – C:\Users\HP_Administrator\AppData\Roaming\wklnhst.dat
[2009/12/13 11:14:15 | 00,001,898 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader 8.lnk
[2009/12/08 13:16:28 | 00,150,528 | —- | M] () – C:\Users\HP_Administrator\Documents\Metro Office Inventory List 2009.wps
[2009/12/03 16:14:06 | 00,038,224 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2009/12/03 16:13:56 | 00,019,160 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[6 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2009/12/28 15:22:44 | 23,778,4514 | —- | C] () – C:\Windows\MEMORY.DMP
[2009/12/28 15:04:54 | 00,000,505 | —- | C] () – C:\Users\HP_Administrator\Desktop\Archive.zip - Shortcut.lnk
[2009/12/26 23:34:04 | 00,000,912 | —- | C] () – C:\Users\Public\Desktop\Prism Video Converter.lnk
[2009/12/21 20:00:54 | 00,001,885 | —- | C] () – C:\Users\HP_Administrator\Desktop\HijackThis.lnk
[2009/12/21 18:36:31 | 00,000,829 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2008/03/25 15:56:08 | 00,147,456 | —- | C] () – C:\Windows\System32\igfxCoIn_v1461.dll
[2007/11/24 18:28:37 | 00,000,104 | —- | C] () – C:\Users\HP_Administrator\AppData\Local\fusioncache.dat
[2007/10/28 14:21:58 | 00,000,552 | —- | C] () – C:\Users\HP_Administrator\AppData\Local\d3d8caps.dat
[2007/10/28 14:21:33 | 00,043,008 | —- | C] () – C:\Users\HP_Administrator\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/10/28 07:30:28 | 00,000,680 | —- | C] () – C:\Users\HP_Administrator\AppData\Local\d3d9caps.dat
[2007/02/25 20:20:44 | 00,000,028 | —- | C] () – C:\Windows\pdf995.ini
[2007/02/25 15:13:00 | 00,000,121 | —- | C] () – C:\Windows\wpd99.drv
[2007/02/25 15:12:46 | 00,118,784 | —- | C] () – C:\Windows\System32\pdfmona.dll
[2007/02/25 15:12:46 | 00,051,716 | —- | C] () – C:\Windows\System32\pdf995mon.dll
[2007/02/11 12:19:00 | 00,000,000 | —- | C] () – C:\Windows\prestopm.INI
[2007/02/11 11:49:00 | 00,000,532 | —- | C] () – C:\Windows\MAXLINK.INI
[2007/02/11 11:47:32 | 00,040,960 | —- | C] () – C:\Windows\System32\IPPCPUID.DLL
[2007/02/11 11:47:32 | 00,000,105 | —- | C] () – C:\Windows\UMXADDIN.INI
[2007/02/11 11:47:26 | 00,011,776 | —- | C] () – C:\Windows\System32\pmsbfn32.dll
[2007/02/11 11:46:58 | 00,000,074 | —- | C] () – C:\Windows\PMINI.ini
[2006/12/23 18:07:05 | 00,045,232 | —- | C] () – C:\Users\HP_Administrator\AppData\Roaming\wklnhst.dat
[2006/12/22 22:24:26 | 00,684,032 | —- | C] () – C:\Windows\libeay32.dll
[2006/12/22 22:24:26 | 00,155,648 | —- | C] () – C:\Windows\ssleay32.dll
[2006/12/22 12:57:12 | 00,000,335 | —- | C] () – C:\Windows\lexstat.ini
[2006/12/21 22:52:40 | 00,000,029 | —- | C] () – C:\Windows\atid.ini
[2006/11/29 05:12:18 | 00,204,800 | —- | C] () – C:\Windows\System32\igfxCoIn_v1132.dll
[2006/11/29 04:37:12 | 00,467,264 | —- | C] () – C:\Windows\System32\igmedkrn.dll
[2006/11/02 06:35:32 | 00,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 01:40:29 | 00,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/10/20 11:38:42 | 00,000,061 | —- | C] () – C:\Windows\smscfg.ini
[2006/10/20 11:19:35 | 00,028,848 | —- | C] () – C:\Windows\System32\drivers\USBkey.sys
[2006/10/20 11:14:56 | 00,014,317 | —- | C] () – C:\Windows\System32\CHODDI.SYS
[2006/10/20 11:14:49 | 00,045,056 | —- | C] () – C:\Windows\System32\hpreg.dll
[2006/10/20 11:12:07 | 00,000,157 | —- | C] () – C:\Windows\QUICKEN.INI
[2006/10/20 11:01:48 | 00,000,058 | —- | C] () – C:\Windows\WININIT.INI
[2006/10/20 11:01:11 | 00,000,698 | —- | C] () – C:\Windows\NSSetDefaultBrowser.ini
[2006/10/20 10:52:44 | 00,000,753 | —- | C] () – C:\Windows\orun32.ini
[2006/10/20 10:31:31 | 00,323,584 | —- | C] () – C:\Windows\System32\pythoncom22.dll
[2006/10/20 10:31:31 | 00,094,208 | —- | C] () – C:\Windows\System32\pywintypes22.dll
[2006/10/20 10:31:15 | 00,016,896 | —- | C] () – C:\Windows\System32\bcbmm.dll
[2006/02/19 11:28:56 | 00,012,288 | —- | C] () – C:\Windows\Fonts\RandFont.dll
[2004/09/16 21:24:26 | 03,375,104 | —- | C] () – C:\Windows\System32\qt-mt331.dll
[2004/07/26 08:51:38 | 00,000,560 | —- | C] () – C:\Windows\System32\oeminfo.ini

========== LOP Check ==========

[2006/11/02 07:09:53 | 00,000,484 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2008/01/19 01:42:25 | 00,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\SoftwareDistribution\Download\b2ee164db645e6bc8d77bb51f082e3b3\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys
[2006/11/02 03:49:52 | 00,053,864 | —- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 – C:\Windows\System32\drivers\AGP440.sys
[2006/11/02 03:49:52 | 00,053,864 | —- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 – C:\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys

< MD5 for: ATAPI.SYS >
[2008/01/19 01:41:30 | 00,021,560 | —- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 – C:\Windows\SoftwareDistribution\Download\b2ee164db645e6bc8d77bb51f082e3b3\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
[2006/11/02 03:49:36 | 00,019,048 | —- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F – C:\Windows\System32\drivers\atapi.sys
[2006/11/02 03:49:36 | 00,019,048 | —- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
[2008/02/14 07:15:22 | 00,021,560 | —- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_7de13c21\atapi.sys
[2008/02/14 07:15:22 | 00,021,560 | —- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.16632_none_db337a442479c42c\atapi.sys
[2008/02/14 07:15:21 | 00,021,560 | —- | M] (Microsoft Corporation) MD5=E03E8C99D15D0381E02743C36AFC7C6F – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20757_none_dbac78a93da31a8b\atapi.sys

< MD5 for: CNGAUDIT.DLL >
[2006/11/02 03:46:03 | 00,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\System32\cngaudit.dll
[2006/11/02 03:46:03 | 00,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll

< MD5 for: IASTOR.SYS >
[2006/07/06 07:59:42 | 00,246,784 | —- | M] (Intel Corporation) MD5=019CF5F31C67030841233C545A0E217A – C:\cmdcons\iastor.sys
[2006/07/06 07:59:42 | 00,246,784 | —- | M] (Intel Corporation) MD5=019CF5F31C67030841233C545A0E217A – C:\hp\drivers\Intel_raid\iastor.sys
[2006/07/06 07:59:42 | 00,246,784 | —- | M] (Intel Corporation) MD5=019CF5F31C67030841233C545A0E217A – C:\Windows\System32\DriverStore\FileRepository\iastor.inf_606e6298\iaStor.sys
[2006/07/06 07:59:42 | 00,246,784 | —- | M] (Intel Corporation) MD5=019CF5F31C67030841233C545A0E217A – C:\Windows\System32\DriverStore\FileRepository\iastor.inf_91b96e38\iaStor.sys
[2006/05/11 12:30:52 | 00,247,808 | —- | M] (Intel Corporation) MD5=294110966CEDD127629C5BE48367C8CF – C:\hp\drivers\Intel_6.0.0.1022_WHQL\iaStor.sys
[2006/10/31 15:13:46 | 00,495,896 | —- | M] (Intel Corporation) MD5=81EC16AFD70E3432B8C573782CCFEE6D – C:\Program Files\Intel\Intel Matrix Storage Manager\Driver64\IaStor.sys
[2005/06/17 07:33:40 | 00,872,064 | —- | M] (Intel Corporation) MD5=9A65E42664D1534B68512CAAD0EFE963 – C:\hp\drivers\Intel_5_1_0_1022_PV\iastor.sys
[2006/10/31 14:46:36 | 00,250,368 | —- | M] (Intel Corporation) MD5=DE01BF14FFB150C779FD561BD0E3C5C5 – C:\Program Files\Intel\Intel Matrix Storage Manager\Driver\iaStor.sys
[2006/10/31 14:46:36 | 00,250,368 | —- | M] (Intel Corporation) MD5=DE01BF14FFB150C779FD561BD0E3C5C5 – C:\Windows\System32\drivers\iaStor.sys
[2006/10/31 14:46:36 | 00,250,368 | —- | M] (Intel Corporation) MD5=DE01BF14FFB150C779FD561BD0E3C5C5 – C:\Windows\System32\DriverStore\FileRepository\iastor.inf_ee67416f\iaStor.sys

< MD5 for: IASTORV.SYS >
[2008/01/19 01:42:51 | 00,235,064 | —- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 – C:\Windows\SoftwareDistribution\Download\b2ee164db645e6bc8d77bb51f082e3b3\x86_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_af11527887c7fa8f\iaStorV.sys
[2006/11/02 03:51:25 | 00,232,040 | —- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 – C:\Windows\System32\drivers\iaStorV.sys
[2006/11/02 03:51:25 | 00,232,040 | —- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 – C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys

< MD5 for: NETLOGON.DLL >
[2006/11/02 03:46:11 | 00,559,616 | —- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B – C:\Windows\System32\netlogon.dll
[2006/11/02 03:46:11 | 00,559,616 | —- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B – C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6000.16386_none_fb80f5473b0ed783\netlogon.dll
[2008/01/19 01:35:36 | 00,592,384 | —- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F – C:\Windows\SoftwareDistribution\Download\b2ee164db645e6bc8d77bb51f082e3b3\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll

< MD5 for: NVSTOR.SYS >
[2006/11/02 03:50:13 | 00,040,040 | —- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC – C:\Windows\System32\drivers\nvstor.sys
[2006/11/02 03:50:13 | 00,040,040 | —- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC – C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2008/01/19 01:42:09 | 00,045,112 | —- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 – C:\Windows\SoftwareDistribution\Download\b2ee164db645e6bc8d77bb51f082e3b3\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvstor.sys

< MD5 for: SCECLI.DLL >
[2008/01/19 01:36:19 | 00,177,152 | —- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 – C:\Windows\SoftwareDistribution\Download\b2ee164db645e6bc8d77bb51f082e3b3\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll
[2006/11/02 03:46:12 | 00,176,640 | —- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 – C:\Windows\System32\scecli.dll
[2006/11/02 03:46:12 | 00,176,640 | —- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 – C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6000.16386_none_35d7205fdc305e3e\scecli.dll

< %systemroot%\*. /mp /s >

< >

< >
< End of report >

OTL Extras logfile created on: 12/28/2009 4:15:36 PM - Run 1
OTL by OldTimer - Version 3.1.20.1 Folder = C:\Users\HP_Administrator\Desktop
Windows Vista Home Premium Edition (Version = 6.0.6000) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6000.16945)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,014.00 Mb Total Physical Memory | 197.00 Mb Available Physical Memory | 19.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 49.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 177.66 Gb Total Space | 42.61 Gb Free Space | 23.98% Space Free | Partition Type: NTFS
Drive D: | 8.63 Gb Total Space | 0.33 Gb Free Space | 3.77% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: YOUR-4DACD0EA75
Current User Name: HP_Administrator
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.chm [@ = chm.file] – "%SystemRoot%\hh.exe" %1
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
chm.file [open] – "%SystemRoot%\hh.exe" %1
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"AutoUpdateDisableNotify" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring" = 1
"" =

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 1
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – File not found
"C:\Program Files\MSN Messenger\msncall.exe" = C:\Program Files\MSN Messenger\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone) – (Microsoft Corporation)
"C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe" = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe:*:Enabled:Updates from HP – (Hewlett-Packard)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – File not found
"C:\Program Files\AIM6\aim6.exe" = C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM – File not found
"C:\Program Files\Ares\Ares.exe" = C:\Program Files\Ares\Ares.exe:*:Enabled:Ares p2p for windows – File not found
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader – File not found
"C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" = C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink – File not found
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)
"C:\Program Files\LimeWire\LimeWire.exe" = C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire – (Lime Wire, LLC)
"C:\Program Files\MSN Messenger\msncall.exe" = C:\Program Files\MSN Messenger\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone) – (Microsoft Corporation)
"C:\Program Files\MSN\MSNCoreFiles\msn.exe" = C:\Program Files\MSN\MSNCoreFiles\msn.exe:*:Enabled:msn – (Microsoft Corporation)
"C:\Program Files\Rhapsody\rhapsody.exe" = C:\Program Files\Rhapsody\rhapsody.exe:*:Enabled:Rhapsody – File not found
"C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe" = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe:*:Enabled:Updates from HP – (Hewlett-Packard)
"C:\WINDOWS\system32\fxsclnt.exe" = C:\WINDOWS\system32\fxsclnt.exe:*:Enabled:Microsoft Fax Console – File not found
"C:\WINDOWS\system32\usmt\migwiz.exe" = C:\WINDOWS\system32\usmt\migwiz.exe:*:Enabled:Files and Settings Transfer Wizard – File not found


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{03390984-A990-4FB0-BDCF-FE3FEAE527B5}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{051696D1-9046-4C82-8D26-65DD338B456B}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{067E55D6-F0B6-4621-917A-ACB75EB9493D}" = rport=10243 | protocol=6 | dir=out | app=system |
"{0D05B6B3-4F65-4597-9B4F-57B886FCD704}" = lport=7777 | protocol=17 | dir=in | app=c:\windows\ehome\ehshell.exe |
"{25ED56C0-E265-4CC8-BEA0-A1DA218D73F5}" = lport=138 | protocol=17 | dir=in | app=system |
"{2AC6C10C-DBBF-44F1-BFBE-A959FECBD7AE}" = lport=10243 | protocol=6 | dir=in | app=system |
"{317DCAE6-F109-4A9B-8BA3-726A47282876}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{357D3BB7-D111-4BF2-8695-9E632CE15FFA}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{3CA5C0E5-EEF0-46E3-9485-3EEBB717F391}" = lport=10244 | protocol=6 | dir=in | app=system |
"{3D0759DA-EE40-43F7-B0A2-E394A22D6483}" = lport=2869 | protocol=6 | dir=in | app=system |
"{3DF94F46-F9F6-4817-9D1A-C0B7081F81C0}" = rport=10244 | protocol=6 | dir=out | app=system |
"{3E2CEE38-8012-44F3-B43C-2A22E879E6E3}" = lport=3390 | protocol=6 | dir=in | app=system |
"{500EE5B2-B4DC-403A-A580-EC52695D548F}" = lport=137 | protocol=17 | dir=in | app=system |
"{558714BE-381E-4F5C-8B1B-2CE4BD3FCF35}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{64C5908A-6C27-47E4-AC1D-7222B2F19004}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{7049F41E-616A-4069-9F1E-EE1794F4725F}" = lport=139 | protocol=6 | dir=in | app=system |
"{832C4248-48A3-4E5A-A34D-E2FEC8B156A2}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=c:\windows\system32\svchost.exe |
"{84E7A3F3-4E57-45F4-8137-FCBDCFD3AD29}" = rport=138 | protocol=17 | dir=out | app=system |
"{88D5FB49-0756-47F6-8E39-2E5FE1041F3E}" = lport=2869 | protocol=6 | dir=in | app=system |
"{8C5F508D-AE39-4BCE-AC35-9AF742AC8D2F}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=c:\windows\system32\svchost.exe |
"{904AE118-0F08-4385-AA73-FD43383D3727}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{908A9E9F-92F8-4787-A10D-9BD1415B05EC}" = lport=554 | protocol=6 | dir=in | app=c:\windows\ehome\ehshell.exe |
"{94735398-4E3E-401D-B9B7-C3A33D2418C9}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=c:\windows\system32\svchost.exe |
"{9C26851B-4DEB-4AD0-B7C6-59BC3FDC6D1B}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{A7161D43-1CA0-4C66-A024-91E927937AF0}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{A8DA55CD-03F5-43DF-9C3B-6EF9C293ACD1}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=c:\windows\system32\svchost.exe |
"{AA6221AC-D636-4D8F-8B20-645CF5B99E45}" = lport=445 | protocol=6 | dir=in | app=system |
"{ACEF5258-188E-4AA5-B4FB-1DEFD1DEDCD4}" = rport=139 | protocol=6 | dir=out | app=system |
"{AFF041DB-A2B7-4F2E-ACD1-27F33437A199}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{B9E363EE-E4CF-448B-8AFC-FFD3F12502F7}" = rport=137 | protocol=17 | dir=out | app=system |
"{E939EBBF-AFA3-4AC5-A4DF-C7E8B18157BB}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{FBBA3B67-260B-4034-8828-404FDCD07846}" = rport=445 | protocol=6 | dir=out | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0A83231A-2239-4F9D-83AC-A9D3DF1F683F}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{0E2B4DFB-F201-4D29-8C84-E69E03D6CD4B}" = protocol=6 | dir=out | app=c:\windows\ehome\ehshell.exe |
"{189E8627-9142-43BC-A55C-41E116AE7893}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{1AD960B7-975C-4B63-A713-CE1413D83600}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{1C5B8426-5A73-477E-BDE7-0DF810D0A689}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{2FE99FA9-6C34-4A8F-B62C-B708B3FB4FEA}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{40029817-EB22-4686-B9F4-0975EEBFBD53}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{42E93F6D-1067-496D-B6EC-3DDC5A18F4FD}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{5CB96142-3849-4AD1-B86A-072DF487E0BD}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{5D717A69-DBB6-4939-93C3-0320F7D17146}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{60759683-283B-4542-9732-8F09DE28DF84}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{7439812D-1170-409A-9A0E-15EEF662D629}" = protocol=6 | dir=out | app=%systemroot%\system32\msra.exe |
"{77EDC3DD-7883-4505-85EC-FC1BA88A4BCD}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{8C92F3F3-C6CB-4E44-8F31-23915403AAF3}" = protocol=6 | dir=in | app=c:\windows\network diagnostic\xpnetdiag.exe |
"{9A3BB0B0-5DEF-487B-8B7A-A6730DF061AD}" = protocol=17 | dir=out | app=c:\windows\ehome\ehshell.exe |
"{A4B9D01F-0162-4A95-BF2E-32665407E425}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{A57B0FF6-9828-47A2-AB7B-DA3DC0B0F861}" = protocol=17 | dir=in | app=c:\windows\network diagnostic\xpnetdiag.exe |
"{A9D20B65-7DA2-4E51-9A06-8A30CEDAA7F3}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{AEDF06E4-0DCB-4C1F-BD2D-1202AB0E0003}" = protocol=6 | dir=in | app=%systemroot%\system32\msra.exe |
"{B2976955-D132-4DE1-AC02-02C8BC7AB401}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{B2A0E3FD-2428-438F-B1AC-2639ECF0FF52}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{B725C3E5-D07F-44FF-8769-79B914230623}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{C6EE60A7-20B9-417F-BF70-0A536AA5222E}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{C795335F-DFE4-4963-B2C7-992911CF3317}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{C8BF393F-8209-467D-94C9-2A9911E13030}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{E801FD8C-B32D-4335-958F-FCBE66CCD11E}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{E9DEE8F7-2E45-4D05-BA67-ABD1D01DA2F6}" = protocol=6 | dir=out | app=system |
"{EA49F6CD-1003-4678-B6CE-38CFDEDBA28A}" = protocol=6 | dir=out | svc=mcx2svc | app=c:\windows\system32\svchost.exe |
"{ECEF91C9-2D9D-435D-908E-DE84C5F8F7AC}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{F1C1ACCF-0AAB-497C-A4D5-CFFDBC553BFB}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{F9742DB5-5952-44C7-A026-E4A980C3D0E2}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{FDE3D9A1-82D7-4509-8263-30D4F45C8DFC}" = protocol=6 | dir=out | app=c:\windows\ehome\mcx2prov.exe |
"{FF029E58-D095-4F83-BD7C-3D41400FE355}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"TCP Query User{5102D78B-1EFD-40CC-9F7E-1A05C1166802}C:\program files\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |
"UDP Query User{9324F905-53ED-466F-BDC4-DBAC06BDF192}C:\program files\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0749256F-E98D-4EF1-A15B-AED26BCC1DC8}" = Sonic DVD for Photo Story 3 for Windows
"{0A65A3BD-54B5-4d0d-B084-7688507813F5}" = SlideShow
"{0E7DBD52-B097-4F2B-A7C7-F105B0D20FDB}" = LightScribe System Software 1.14.17.1
"{12BE3579-A34B-47BD-A65C-82B1754E71E1}" = D4100
"{1341D838-719C-4A05-B50F-49420CA1B4BB}" = HP Boot Optimizer
"{15C0AF59-4877-49B6-B8C6-A61CE54515F5}" = cp_OnlineProjectsConfig
"{18388EF8-E0A3-442B-8BFE-E2F1B3D05C91}" = iTunes
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{20749F76-4228-43AD-8AB5-E7B20D8040C4}" = hph_readme
"{22B3CC30-77B8-419C-AA4B-F571FDF5D66D}" = Windows Live Sign-in Assistant
"{23012310-3E05-46A5-88A9-C6CBCABCAC79}" = Customer Experience Enhancement
"{2376813B-2E5A-4641-B7B3-A0D5ADB55229}" = HPPhotoSmartExpress
"{26A24AE4-039D-4CA4-87B4-2F83216012FF}" = Java™ 6 Update 12
"{2818095F-FB6C-42C8-827E-0A406CC9AFF5}" = Quicken 2006
"{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}" = Microsoft SQL Server 2005 Express Edition (MSSMLBIZ)
"{2F58D60D-2BFD-4467-9B4D-64E7355C329D}" = Sonic_PrimoSDK
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{3248F0A8-6813-11D6-A77B-00B0D0150100}" = J2SE Runtime Environment 5.0 Update 10
"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java™ 6 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{33BF0960-DBA3-4187-B6CC-C969FCFA2D25}" = SkinsHP1
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{353D20CC-719B-4A60-AD33-D03F88C10330}" = Microsoft Office Accounting PayPal Addin
"{363790D2-DA98-41DD-9C9F-69FA36B169DE}" = PanoStandAlone
"{36D620AD-EEBA-4973-BA86-0C9AE6396620}" = OptionalContentQFolder
"{36DC3E2F-CD8C-4953-9E8F-9A1916D10AA1}" = hph_software
"{3C97C9C5-1AF3-41B0-B61C-185C06C75EE6}" = D4100_Help
"{416D80BA-6F6D-4672-B7CF-F54DA2F80B44}" = Microsoft Works
"{41E776A5-9B12-416D-9A12-B4F7B044EBED}" = CP_Package_Basic1
"{444B6A7B-0E26-4416-A43F-D1C9AAE6075D}" = Canon CanoScan Toolbox 4.8
"{44C05309-60F4-410B-BC32-31733CFF1A41}" = Microsoft Digital Image Starter Edition 2006 Editor
"{45B8A76B-57EC-4242-B019-066400CD8428}" = BufferChm
"{46614A49-222A-48EF-87A9-BFD603E608E1}" = Microsoft Office Accounting Fixed Asset Manager
"{4EA684E9-5C81-4033-A696-3019EC57AC3A}" = HPProductAssistant
"{4F41AD68-89F2-4262-A32C-2F70B01FCE9E}" = Photo Story 3 for Windows
"{4FE542EB-FF0B-4739-94DD-25C8AE0AB251}" = Microsoft Digital Image Starter Edition 2006 Library
"{50CD421F-CAFD-46C4-BEFD-E1C46FE63062}" = Manual CanoScan 8400F
"{53EE9E42-CECB-4C92-BF76-9CA65DAF8F1C}" = FullDPAppQFolder
"{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)
"{56B4002F-671C-49F4-984C-C760FE3806B5}" = Microsoft SQL Server VSS Writer
"{5BE42A03-E7B8-42A9-B1BB-FC48B03D58B8}" = Presto! PageManager 6.11
"{5FA793A6-0071-42C1-9355-8F69A428C44F}" = Microsoft Office Accounting ADP Payroll Addin
"{5FDD0538-C67A-4F67-B3F8-09D1AAF04D99}" = muvee autoProducer unPlugged 2.0
"{61100673-2546-42E1-BF92-467B5CB2AC6D}" = DeductionPro 2008
"{66100AC2-E525-42C9-8B60-7E500C9C274B}" = TrueCredit Messenger
"{66910000-8B30-4973-A159-6371345AFFA5}" = WebReg
"{6696D9A4-28A8-4F5A-8E9A-2E8974C8C39C}" = RandMap
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{6909F917-5499-482e-9AA1-FAD06A99F231}" = Toolbox
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{7059BDA7-E1DB-442C-B7A1-6144596720A4}" = HP Update
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7373184D-8E8F-4308-912A-3901071FA1AD}" = LightScribe Applications
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{79D5997E-BF79-48BB-8B41-9BE59C15C2D7}" = OmniPage SE 2.0
"{7A2B077D-D7AC-4215-B0FB-5EA581E549E6}" = Windows Vista Upgrade Advisor
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX
"{8105684D-8CA6-440D-8F58-7E5FD67A499D}" = Easy Internet Sign-up
"{82081779-4175-4666-A457-AB711CD37EF0}" = cp_LightScribeConfig
"{829DAAD6-BB11-4BB7-921B-07FFB703F944}" = CP_Package_Variety3
"{82E55892-6FFD-403F-AA97-D726846768AA}" = CP_AtenaShokunin1Config
"{8331C3EA-0C91-43AA-A4D4-27221C631139}" = Status
"{8377F24B-D4A7-4707-A468-DDF15A71056C}" = Qwest eChat Support Tools
"{866A0078-DEA7-4348-9C9A-999AF2991EAA}" = SlideShowMusic
"{86D28491-78AB-445C-A507-6F3FA81D7611}" = Canon iP6600D Memory Card Utility
"{86EF9FC4-F209-4520-B7E1-C7FF0EEBDFFF}" = Adobe Audition 1.5
"{8950D4E9-FC75-4F3F-B414-33F53F9B346A}" = TaxCut Minnesota 2008
"{8A534F71-3202-4464-A422-B767295E67B9}" = CP_Package_Variety2
"{8C711818-076E-475C-B95B-DF11CD9D8DBE}" = Microsoft Office Accounting Equifax Addin
"{8CB14A64-CEF4-4C8F-B1C8-1C3B8752CB55}" = Kaspersky Internet Security 2009
"{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}" = Unload
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{90A40409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office 2003 Web Components
"{93E5A317-24EC-4744-812C-16FECFE86E6A}" = CP_Package_Variety1
"{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant
"{95120000-003F-0409-0000-0000000FF1CE}" = Microsoft Office Excel Viewer
"{9C3F9580-F5CF-4288-894E-9FF0EB24A21C}" = Maxtor Backup
"{9F7AF7CD-E3D0-4C68-A3BA-C76C359B3AA8}" = LightScribe 1.4.105.1
"{9F7FC79B-3059-4264-9450-39EB368E3225}" = Microsoft Digital Image Library 9 - Blocker
"{A29800BA-0BF1-4E63-9F31-DF05A87F4104}" = InstantShareDevices
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A4DB0F6C-851E-44E3-82EF-40D1C215A5FD}" = Maxtor Encryption
"{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}" = Windows Live installer
"{A939D341-5A04-4E0A-BB55-3E65B386432D}" = Microsoft Office Small Business Connectivity Components
"{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.5
"{AC76BA86-7AD7-1033-7B44-A81300000003}_814" = KB408682
"{ACCCEE83-B49B-4964-8A4F-378B8FBC9F75}" = hph_ProductContext
"{B0717D5A-1976-482B-9ADF-F19631A541A4}" = Microsoft Office Accounting 2007
"{B19F9155-9337-4807-B5EF-ED471DDB2CCE}" = hph_software_req
"{B2157760-AA3C-4E2E-BFE6-D20BC52495D9}" = cp_PosterPrintConfig
"{B5C209B1-8DDB-4642-A573-375B951514CB}" = Apple Mobile Device Support
"{B6286A44-7505-471A-A72B-04EC2DB2F442}" = CueTour
"{B69CFE29-FD03-4E0A-87A7-6ED97F98E5B3}" = CP_Panorama1Config
"{B74F042E-E1B9-4A5B-8D46-387BB172F0A4}" = Apple Software Update
"{BBB33AD6-BCF7-4002-B6A0-6DC679AE5C18}" = TaxCut Premium + State + Efile 2008
"{BD68F46D-8A82-4664-8E68-F87C55BDEFD4}" = Microsoft SQL Server Native Client
"{C1C6767D-B395-43CB-BF99-051B58B86DA6}" = PhotoGallery
"{C3FAA091-B278-44A7-BF48-190811C5F9F7}" = cp_UpdateProjectsConfig
"{C7F54CF8-D6FB-4E0A-93A3-E68AE0D6C476}" = SolutionCenter
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D2261C4B-4D9B-4149-8472-31B7A2FEAB91}" = ArcSoft PhotoStudio 5.5
"{D2A3C9D5-0B56-4656-8277-7EDC65D62B6E}" = HP Photosmart and Deskjet 7.0 Software
"{DB518BA6-CB74-4EB6-9ABD-880B6D6E1F38}" = HpSdpAppCoreApp
"{DBC20735-34E6-4E97-A9E5-2066B66B243D}" = TrayApp
"{DE5DF44E-F8B1-480D-BC26-59410FACDBAC}" = ClientTools
"{E0D51394-1D45-460A-B62D-383BC4F8B335}" = QuickTime
"{E1B80DEE-A795-4258-8445-074C06AE3AB8}" = MarketResearch
"{EB21A812-671B-4D08-B974-2A347F0D8F70}" = HP Photosmart Essential
"{EC637522-73A5-4428-8B46-65A621529CC7}" = Microsoft Location Finder
"{ECA1A3B6-898F-4DCE-9F04-714CF3BA126B}" = Adobe Flash Player 10 Plugin
"{ED2C557E-9C18-41FF-B58E-A05EEF0B3B5F}" = CP_CalendarTemplates1
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F157460F-720E-482f-8625-AD7843891E5F}" = InstantShareDevicesMFC
"{FB15E224-67C3-491F-9F5C-F257BC418412}" = Destinations
"{FB4740B3-2530-452D-A825-F7AB246CA7DF}" = muvee autoProducer 5.0
"{FCE50DB8-C610-4C42-BE5C-193F46C6F812}" = Windows Live Messenger
"{FF268652-B3E8-494F-8343-1FC6DD0FF523}" = Maxtor OneTouch III
"Abacast Client" = Abacast Client
"Adobe Acrobat 5.0" = Adobe Acrobat 5.0
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Photoshop 7.0" = Adobe Photoshop 7.0
"Adobe Shockwave Player" = Adobe Shockwave Player
"Applian FLV Player2.0.24" = Applian FLV Player
"B3EE3001-DC24-4cd1-8743-5692C716659F" = Otto
"CANONBJ_Deinstall_CNMCP7D.DLL" = Canon iP6600D
"CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200C14F1" = Soft Data Fax Modem with SmartCP
"DDA23392-9C73-4909-A221-BC12C6D2664D" = GmoteServer
"Easy-PhotoPrint" = Canon Utilities Easy-PhotoPrint
"Easy-WebPrint" = Easy-WebPrint
"EL" = Intel® Quick Resume Technology Drivers
"HDMI" = Intel® Graphics Media Accelerator Driver
"HijackThis" = HijackThis 2.0.2
"HP Imaging Device Functions" = HP Imaging Device Functions 7.0
"HP Photo & Imaging" = HP Photosmart Premier Software 6.5
"HP Photosmart for Media Center PC" = HP Photosmart for Media Center PC
"HP Solution Center & Imaging Support Tools" = HP Solution Center 7.0
"HPExtendedCapabilities" = HP Customer Participation Program 7.0
"HPOOVClient-9972322 Uninstaller" = Updates from HP (remove only)
"Iconix eMail ID" = Iconix™ eMail ID
"InstallShield_{23012310-3E05-46A5-88A9-C6CBCABCAC79}" = Customer Experience Enhancement
"InstallShield_{8105684D-8CA6-440D-8F58-7E5FD67A499D}" = Easy Internet Sign-up
"InstallShield_{9C3F9580-F5CF-4288-894E-9FF0EB24A21C}" = Maxtor Backup
"InstallShield_{A4DB0F6C-851E-44E3-82EF-40D1C215A5FD}" = Maxtor Encryption
"InstallShield_{FF268652-B3E8-494F-8343-1FC6DD0FF523}" = Maxtor OneTouch III
"InstallWIX_{8CB14A64-CEF4-4C8F-B1C8-1C3B8752CB55}" = Kaspersky Internet Security 2009
"Lexmark Z700-P700 Series" = Lexmark Z700-P700 Series
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Office Accounting 2007" = Microsoft Office Accounting 2007
"Microsoft Office Accounting Equifax Addin" = Microsoft Office Accounting Equifax Addin
"Microsoft Office Accounting PayPal Addin" = Microsoft Office Accounting PayPal Addin
"Microsoft SQL Server 2005" = Microsoft SQL Server 2005
"mIRC" = mIRC
"Money2006b" = Microsoft Money 2006
"MSNINST" = MSN
"OfficeTrial" = Microsoft Office Standard Edition 2003 60 days trial
"OJOsoft Total Video Converter_is1" = OJOsoft Total Video Converter
"PC-Doctor 5 for Windows" = PC-Doctor 5 for Windows
"Pdf995" = Pdf995
"PdfEdit995" = PdfEdit995
"PictureItSuiteTrial_v12" = Microsoft Digital Image Starter Edition 2006
"Prism" = Prism Video Converter
"PROSet" = Intel® PRO Network Connections Drivers
"Python 2.2.3" = Python 2.2.3
"pywin32-py2.2" = Python 2.2 pywin32 extensions (build 203)
"RealPlayer 6.0" = RealPlayer
"Security Task Manager" = Security Task Manager 1.7e
"TaxCut Premium 2006" = TaxCut Premium 2006
"TrueCredit Messenger" = TrueCredit Messenger
"Viewpoint Manager" = Viewpoint Manager (Remove Only)
"Viewpoint Toolbar" = Viewpoint Toolbar
"ViewpointMediaPlayer" = Viewpoint Media Player
"WildTangent hpmedia Master Uninstall" = My HP Games
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WinISD beta" = WinISD beta
"WinRAR archiver" = WinRAR archiver
"Your Image Jasmine Jones 1.0.5" = Your Image Jasmine Jones
"Your Image NICHOLAS WARREN 1.0.5" = Your Image NICHOLAS WARREN

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"HJ ProDigital" = HJ ProDigital
"uTorrent" = µTorrent

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 3/6/2009 5:01:15 AM | Computer Name = your-4dacd0ea75 | Source = MsiInstaller | ID = 10005
Description =

Error - 3/9/2009 7:41:03 PM | Computer Name = your-4dacd0ea75 | Source = Application Hang | ID = 1002
Description = The program msn.exe version 9.50.39.1900 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 1f70 Start Time: 01c9a0f82e8c9af0 Termination Time: 65

Error - 3/9/2009 7:42:19 PM | Computer Name = your-4dacd0ea75 | Source = Application Hang | ID = 1002
Description = The program msn.exe version 9.50.39.1900 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 15f4 Start Time: 01c9a11084055360 Termination Time: 22

Error - 3/11/2009 4:18:26 AM | Computer Name = your-4dacd0ea75 | Source = Perflib | ID = 1008
Description = The Open Procedure for service "DFSR" in DLL "C:\Windows\System32\DfsrPerf.dll"
failed. Performance data for this service will not be available. The first four
bytes (DWORD) of the Data section contains the error code.

Error - 3/11/2009 4:18:30 AM | Computer Name = your-4dacd0ea75 | Source = Perflib | ID = 1010
Description = The Collect Procedure for the "EmdCache" service in DLL "C:\Windows\system32\emdmgmt.dll"
generated an exception or returned an invalid status. The performance data returned
by the counter DLL will not be returned in the Perf Data Block. The first four
bytes (DWORD) of the Data section contains the exception code or status code.

Error - 3/11/2009 4:18:31 AM | Computer Name = your-4dacd0ea75 | Source = Perflib | ID = 1005
Description = Unable to locate the open procedure "OpenIPSecPerformanceData" in
DLL "C:\Windows\System32\ipsecsvc.dll" for the "PolicyAgent" service. Performance
data for this service will not be available. The first four bytes (DWORD) of the
Data section contains the error code.

Error - 3/11/2009 4:18:31 AM | Computer Name = your-4dacd0ea75 | Source = Perflib | ID = 1018
Description = Disabled performance counter data collection for this session from
the "PolicyAgent" service because the performance counter library for that service
has generated one or more errors. The errors that forced this action have been
written to the application event log.

Error - 3/11/2009 4:29:13 PM | Computer Name = your-4dacd0ea75 | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Program Files\MSN\MSNCoreFiles\PI\FngrPrnt.dll".
Dependent
Assembly Microsoft.VC80.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 3/17/2009 10:57:03 AM | Computer Name = your-4dacd0ea75 | Source = Application Error | ID = 1000
Description = Faulting application Photoshop.exe, version 7.0.0.0, time stamp 0x3caf9b42,
faulting module Photoshop.exe, version 7.0.0.0, time stamp 0x3caf9b42, exception
code 0xc0000005, fault offset 0x007b9791, process id 0x1508, application start time
0x01c9a70f9907c0e0.

Error - 3/21/2009 4:05:51 AM | Computer Name = your-4dacd0ea75 | Source = MSDTC | ID = 4427
Description = Failed to initialize the needed name objects. Error Specifics: hr
= 0x80004005, d:\vistartm\com\complus\dtc\dtc\msdtcprx\src\dtcinit.cpp:670, CmdLine:
setup.exe /q /qn ADDLOCAL=SQL_Data_Files,SQL_Engine,SQL_SharedTools UPGRADE=SQL_Data_Files,SQL_Engine,SQL_SharedTools
LOGPATH="C:\Program Files\Microsoft SQL Server\90\Setup Bootstrap\LOG\Hotfix\SQL9Express_Hotfix_KB955

[ IntelDH Events ]
Error - 12/6/2009 8:11:31 PM | Computer Name = your-4dacd0ea75 | Source = IntelQRTD | ID = 7
Description = Could not attach to EL Acpi driver.

Error - 12/10/2009 5:28:40 AM | Computer Name = your-4dacd0ea75 | Source = IntelQRTD | ID = 7
Description = Could not attach to EL Acpi driver.

Error - 12/11/2009 5:25:56 AM | Computer Name = your-4dacd0ea75 | Source = IntelQRTD | ID = 7
Description = Could not attach to EL Acpi driver.

Error - 12/13/2009 1:06:16 PM | Computer Name = your-4dacd0ea75 | Source = IntelQRTD | ID = 7
Description = Could not attach to EL Acpi driver.

Error - 12/14/2009 5:25:07 AM | Computer Name = your-4dacd0ea75 | Source = IntelQRTD | ID = 7
Description = Could not attach to EL Acpi driver.

Error - 12/16/2009 10:07:10 PM | Computer Name = your-4dacd0ea75 | Source = IntelQRTD | ID = 7
Description = Could not attach to EL Acpi driver.

Error - 12/21/2009 12:44:29 PM | Computer Name = your-4dacd0ea75 | Source = IntelQRTD | ID = 7
Description = Could not attach to EL Acpi driver.

Error - 12/21/2009 5:30:36 PM | Computer Name = your-4dacd0ea75 | Source = IntelQRTD | ID = 7
Description = Could not attach to EL Acpi driver.

Error - 12/24/2009 1:41:55 PM | Computer Name = your-4dacd0ea75 | Source = IntelQRTD | ID = 7
Description = Could not attach to EL Acpi driver.

Error - 12/28/2009 5:24:11 PM | Computer Name = your-4dacd0ea75 | Source = IntelQRTD | ID = 7
Description = Could not attach to EL Acpi driver.

[ System Events ]
Error - 12/27/2009 11:54:46 AM | Computer Name = your-4dacd0ea75 | Source = WMPNetworkSvc | ID = 866333
Description = Proximity detection failed due to unknown error '0x80004004'. The
best proximity time detected was 10 milliseconds.

Error - 12/27/2009 11:58:01 AM | Computer Name = your-4dacd0ea75 | Source = WMPNetworkSvc | ID = 866333
Description = Proximity detection failed due to unknown error '0x80004004'. The
best proximity time detected was 19 milliseconds.

Error - 12/27/2009 12:01:15 PM | Computer Name = your-4dacd0ea75 | Source = WMPNetworkSvc | ID = 866333
Description = Proximity detection failed due to unknown error '0x80004004'. The
best proximity time detected was 19 milliseconds.

Error - 12/27/2009 12:04:29 PM | Computer Name = your-4dacd0ea75 | Source = WMPNetworkSvc | ID = 866333
Description = Proximity detection failed due to unknown error '0x80004004'. The
best proximity time detected was 20 milliseconds.

Error - 12/28/2009 5:07:22 AM | Computer Name = your-4dacd0ea75 | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description =

Error - 12/28/2009 5:05:37 PM | Computer Name = your-4dacd0ea75 | Source = Print | ID = 6161
Description = The document http://forums.whatthetech.com/System_weird…irus_seems_faul,
owned by HP_Administrator, failed to print on printer Canon Inkjet iP6600D. Try
to print the document again, or restart the print spooler. Data type: NT EMF 1.008.
Size of the spool file in bytes: 1769472. Number of bytes printed: 291380. Total
number of pages in the document: 5. Number of pages printed: 1. Client computer:
\\YOUR-4DACD0EA75. Win32 error code returned by the print processor: 0. The operation
completed successfully.

Error - 12/28/2009 5:22:42 PM | Computer Name = your-4dacd0ea75 | Source = EventLog | ID = 6008
Description = The previous system shutdown at 3:21:03 PM on 12/28/2009 was unexpected.

Error - 12/28/2009 5:50:36 PM | Computer Name = your-4dacd0ea75 | Source = EventLog | ID = 6008
Description = The previous system shutdown at 3:47:39 PM on 12/28/2009 was unexpected.

Error - 12/28/2009 5:51:41 PM | Computer Name = your-4dacd0ea75 | Source = Service Control Manager | ID = 7000
Description = The Parallel port driver service failed to start due to the following
error: %%1058

Error - 12/28/2009 5:56:33 PM | Computer Name = your-4dacd0ea75 | Source = Service Control Manager | ID = 7022
Description = The Windows Update service hung on starting.


< End of report >
TCHal,

Double click on OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Processes
explorer.exe

:OTL
PRC - C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe (Viewpoint Corporation)
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles File not found
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file:///C:/WINDOWS/Java/classes/xmldso.cab (Reg Error: Key error.)


:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
Please post the OTL log.
Here is the OTL log Tomk. Thanks again for your help. Seems like there is lots of stuff running in the background on my system. All processes killed ========== PROCESSES ========== No active process named explorer.exe was found! ========== OTL ========== No active process named ViewMgr.exe was found! Process ViewpointService.exe killed successfully! Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}\ deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\HP Software Update deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\InstallTheme deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\InstallVisualStyle deleted successfully. Starting removal of ActiveX control {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} C:\WINDOWS\Downloaded Program Files\erma.inf not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found. Starting removal of ActiveX control {E2883E8F-472F-4FB0-9522-AC9BF37916A7} C:\WINDOWS\Downloaded Program Files\gp.inf not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found. File oft XML Parser for Java file:///C:/WINDOWS/Java/classes/xmldso.cab not found. Starting removal of ActiveX control Microsoft XML Parser for Java Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Microsoft XML Parser for Java\DownloadInformation\\INF . Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Microsoft XML Parser for Java\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\Microsoft XML Parser for Java\ not found. ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: All Users User: Application Data User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 32902 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: HP_Administrator ->Temp folder emptied: 593741117 bytes ->Temporary Internet Files folder emptied: 122104614 bytes ->Java cache emptied: 0 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 23700992 bytes Windows Temp folder emptied: 5546243 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 711.00 mb OTL by OldTimer - Version 3.1.20.1 log created on 12282009_173735 Files\Folders moved on Reboot… Registry entries deleted on Reboot…
TCHal,

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://forums.whatthetech.com/How_Disable_…ams_t96260.html

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
It's been up and running for 30 mins and still at the same point: "attempting to create a new system restore point", I think it's froze up. I didn't click the mouse at all either.
TCHal,

Yep. That sounds froze. Please reboot.

Then run this scanner.

Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and the click UPLOAD.
hope i did this correctly, here they are: DDS (Ver_09-12-01.01) - NTFSx86 Run by [removed] at 14:52:05.01 on Wed 12/30/2009 Internet Explorer: 7.0.6000.16945 Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.1014.148 [GMT -6:00] AV: Kaspersky Internet Security *On-access scanning enabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0} SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} SP: Kaspersky Internet Security *enabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0} FW: Kaspersky Internet Security *enabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\Dwm.exe C:\WINDOWS\system32\LEXBCES.EXE C:\Windows\system32\taskeng.exe C:\WINDOWS\system32\LEXPPS.EXE C:\Windows\System32\spoolsv.exe C:\Windows\Explorer.EXE C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe C:\Program Files\Common Files\Iconix\IconixService.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\Maxtor\Maxtor Backup\MaxBackServiceInt.exe c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe C:\Program Files\Maxtor\ManagerApp\OneTouch.exe C:\Program Files\Maxtor\OneTouch Status\MaxMenuMgr.exe C:\Program Files\ScanSoft\OmniPageSE2.0\opwareSE2.exe C:\Program Files\Canon\Memory Card Utility\iP6600D\PDUiP6600DMon.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Windows\RtHDVCpl.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe C:\Windows\System32\igfxpers.exe C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe C:\Program Files\TrueCredit Messenger\TCMTray.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Microsoft Location Finder\LocationFinder.exe C:\Windows\ehome\ehtray.exe C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\Windows\system32\igfxsrvc.exe C:\WINDOWS\system32\HPZipm12.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files\GmoteServer\GmoteServer.exe C:\Program Files\Viewpoint\Common\ViewpointService.exe C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\WUDFHost.exe C:\Windows\system32\DRIVERS\xaudio.exe C:\Windows\System32\mobsync.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\Java\jre6\bin\javaw.exe C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files\iPod\bin\iPodService.exe C:\Windows\system32\taskeng.exe C:\HP\KBD\KBD.EXE c:\windows\system\hpsysdrv.exe C:\Windows\system32\WerCon.exe C:\Program Files\MSN\MSNCoreFiles\MSN.EXE C:\WINDOWS\system32\svchost.exe -k usnsvc C:\Windows\system32\wuauclt.exe C:\Users\HP_Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Y4P5MFHK\dds[1].scr C:\Windows\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=PAVILION&pf=desktop uSearch Bar = hxxp://www.google.com/ie uSearch Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=PAVILION&pf=desktop mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=PAVILION&pf=desktop mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=64&bd=PAVILION&pf=desktop uInternet Settings,ProxyServer = http=127.0.0.1:9022 mSearchAssistant = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=PAVILION&pf=desktop BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - c:\program files\kaspersky lab\kaspersky internet security 2009\ievkbd.dll BHO: IconixBHOClass Class: {761233b6-f228-49e4-8f6b-668499d4e55a} - c:\program files\iconix\ieaddon\IconixBHO_41.dll BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Viewpoint Toolbar BHO: {a7327c09-b521-4edb-8509-7d2660c9ec98} - c:\program files\viewpoint\viewpoint toolbar\3.9.0\ViewBarBHO.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll TB: Easy-WebPrint: {327c2873-e90d-4c37-aa9d-10ac9baba46c} - c:\program files\canon\easy-webprint\Toolband.dll TB: Viewpoint Toolbar: {f8ad5aa5-d966-4667-9daf-2561d68b2012} - c:\program files\common files\viewpoint\toolbar runtime\3.9.0\IEViewBar.dll TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun uRun: [Microsoft Location Finder] "c:\program files\microsoft location finder\LocationFinder.exe" uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe uRun: [LightScribe Control Panel] c:\program files\common files\lightscribe\LightScribeControlPanel.exe -hidden uRun: [msnmsgr] "c:\program files\msn messenger\msnmsgr.exe" /background uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide mRun: [HPBootOp] "c:\program files\hewlett-packard\hp boot optimizer\HPBootOp.exe" /run mRun: [MaxtorOneTouch] c:\program files\maxtor\managerapp\Onetouch.exe mRun: [mxomssmenu] "c:\program files\maxtor\onetouch status\maxmenumgr.exe" mRun: [OpwareSE2] "c:\program files\scansoft\omnipagese2.0\OpwareSE2.exe" mRun: [PDUiP6600DMon] c:\program files\canon\memory card utility\ip6600d\PDUiP6600DMon.exe mRun: [Recguard] c:\windows\sminst\RECGUARD.EXE mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot mRun: [RtHDVCpl] RtHDVCpl.exe mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [IAAnotif] "c:\program files\intel\intel matrix storage manager\Iaanotif.exe" mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [AVP] "c:\program files\kaspersky lab\kaspersky internet security 2009\avp.exe" mRun: [TrueCredit Messenger Tray] "c:\program files\truecredit messenger\TCMTray.exe" /Start mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript StartupFolder: c:\users\hp_adm~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\gmotes~1.lnk - c:\program files\gmoteserver\GmoteServer.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\update~1.lnk - c:\program files\updates from hp\9972322\program\Updates from HP.exe IE: Add to Banner Ad Blocker - c:\program files\kaspersky lab\kaspersky internet security 2009\ie_banner_deny.htm IE: Easy-WebPrint Add To Print List - c:\program files\canon\easy-webprint\Resource.dll/RC_AddToList.html IE: Easy-WebPrint High Speed Print - c:\program files\canon\easy-webprint\Resource.dll/RC_HSPrint.html IE: Easy-WebPrint Preview - c:\program files\canon\easy-webprint\Resource.dll/RC_Preview.html IE: Easy-WebPrint Print - c:\program files\canon\easy-webprint\Resource.dll/RC_Print.html IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\MSMSGS.EXE IE: {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - {85E0B171-04FA-11D1-B7DA-00A0C90348D6} - c:\program files\kaspersky lab\kaspersky internet security 2009\SCIEPlgn.dll IE: {400A6CFA-E326-4d61-A90C-9AD75358DC5F} - {44E212AB-13EA-4CA4-BE65-197FBA170412} - c:\program files\iconix\ieaddon\IconixBHO_41.dll IE: {BC3F6B6D-2E49-4603-B028-7411655713F3} - {0CC2F28D-D415-4FC6-A2E4-54B4D983609A} - c:\program files\iconix\ieaddon\IconixBHO_41.dll Notify: igfxcui - igfxdev.dll Notify: klogon - c:\windows\system32\klogon.dll Notify: WRNotifier - WRLogonNTF.dll AppInit_DLLs: c:\progra~1\kasper~1\kasper~1\mzvkbd.dll c:\progra~1\kasper~1\kasper~1\mzvkbd3.dll c:\progra~1\kasper~1\kasper~1\adialhk.dll c:\progra~1\kasper~1\kasper~1\kloehk.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - %SystemRoot%\system32\wpdshserviceobj.dll mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe" ============= SERVICES / DRIVERS =============== R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-1-29 33808] R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\drivers\klim6.sys [2008-7-9 20496] R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\drivers\klfltdev.sys [2008-3-13 26640] S3 VST_DPV;VST_DPV;c:\windows\system32\drivers\VSTDPV3.SYS [2006-11-2 987648] S3 VSTHWBS2;VSTHWBS2;c:\windows\system32\drivers\VSTBS23.SYS [2006-11-2 251904] =============== Created Last 30 ================ 2009-12-29 03:08:07 98816 —-a-w- c:\windows\sed.exe 2009-12-29 03:08:07 77312 —-a-w- c:\windows\MBR.exe 2009-12-29 03:08:07 261632 —-a-w- c:\windows\PEV.exe 2009-12-29 03:08:07 161792 —-a-w- c:\windows\SWREG.exe 2009-12-29 03:07:52 0 d-s—w- C:\ComboFix 2009-12-28 23:37:35 0 d—–w- C:\_OTL 2009-12-28 21:22:44 172625346 —-a-w- c:\windows\MEMORY.DMP 2009-12-27 05:36:42 719872 —-a-w- c:\windows\system32\devil.dll 2009-12-27 05:36:42 0 d—–w- c:\program files\common files\Common Share 2009-12-27 05:36:40 351744 —-a-w- c:\windows\system32\avisynth.dll 2009-12-27 05:36:38 0 d—–w- c:\program files\OJOsoft 2009-12-27 05:34:56 0 d—–w- c:\programdata\NCH Software 2009-12-27 05:34:04 0 d—–w- c:\program files\NCH Software 2009-12-13 19:38:18 378368 —-a-w- c:\windows\system32\winhttp.dll 2009-12-13 16:52:23 494592 —-a-w- c:\windows\system32\kerberos.dll 2009-12-13 16:52:18 272384 —-a-w- c:\windows\system32\schannel.dll 2009-12-11 09:04:09 24064 —-a-w- c:\windows\system32\nshhttp.dll 2009-12-11 09:04:05 396800 —-a-w- c:\windows\system32\drivers\http.sys 2009-12-11 09:04:04 31232 —-a-w- c:\windows\system32\httpapi.dll 2009-12-10 03:19:49 232960 —-a-w- c:\windows\system32\rastls.dll 2009-12-10 03:19:48 274432 —-a-w- c:\windows\system32\raschap.dll ==================== Find3M ==================== 2009-12-29 18:29:14 45498 —-a-w- c:\users\hp_adm~1\appdata\roaming\wklnhst.dat 2009-12-29 17:56:35 5476 –sha-w- c:\windows\system32\drivers\fidbox2.idx 2009-12-29 17:56:34 6637600 –sha-w- c:\windows\system32\drivers\fidbox.dat 2009-12-29 17:56:34 52936 –sha-w- c:\windows\system32\drivers\fidbox.idx 2009-12-29 17:56:34 1286176 –sha-w- c:\windows\system32\drivers\fidbox2.dat 2009-12-21 17:17:30 86016 —-a-w- c:\windows\inf\infstor.dat 2009-12-21 17:17:30 51200 —-a-w- c:\windows\inf\infpub.dat 2009-12-21 17:17:29 86016 —-a-w- c:\windows\inf\infstrng.dat 2009-12-03 22:14:06 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-12-03 22:13:56 19160 —-a-w- c:\windows\system32\drivers\mbam.sys 2009-11-03 02:42:06 195456 ——w- c:\windows\system32\MpSigStub.exe 2009-10-29 07:59:17 2048 —-a-w- c:\windows\system32\tzres.dll 2009-10-27 15:05:11 832512 —-a-w- c:\windows\system32\wininet.dll 2009-10-27 15:01:43 56320 —-a-w- c:\windows\system32\iesetup.dll 2009-10-27 15:01:39 78336 —-a-w- c:\windows\system32\ieencode.dll 2009-10-27 14:59:14 72704 —-a-w- c:\windows\system32\admparse.dll 2009-10-27 12:27:14 26624 —-a-w- c:\windows\system32\ieUnatt.exe 2009-10-27 10:56:00 48128 —-a-w- c:\windows\system32\mshtmler.dll 2008-12-11 09:19:17 174 –sha-w- c:\program files\desktop.ini 2008-06-12 08:12:23 665600 —-a-w- c:\windows\inf\drvindex.dat 2006-11-02 12:42:02 30674 —-a-w- c:\windows\inf\perflib\0409\perfd.dat 2006-11-02 12:42:02 30674 —-a-w- c:\windows\inf\perflib\0409\perfc.dat 2006-11-02 12:42:02 287440 —-a-w- c:\windows\inf\perflib\0409\perfi.dat 2006-11-02 12:42:02 287440 —-a-w- c:\windows\inf\perflib\0409\perfh.dat 2006-11-02 09:20:21 287440 —-a-w- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 09:20:21 287440 —-a-w- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 09:20:19 30674 —-a-w- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 09:20:19 30674 —-a-w- c:\windows\inf\perflib\0000\perfc.dat 2007-10-28 03:23:01 22 –sha-w- c:\windows\sminst\HPCD.sys ============= FINISH: 14:55:07.50 ===============

Attachments:

TCHal,

You did fine.

Your Java is out of date and you have other old versions still on your computer, those old versions are now a security vulnerability:

Please download JavaRa to your desktop and unzip it to its own folder
  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest Java Runtime Environment (JRE) version for your computer - Version 6 update 17

Download Rooter.exe to your desktop

  • Then doubleclick it to start the tool
  • A Notepad file containing the report will open, also found at %systemdrive%\Rooter.txt. Post that here
yikes, maybe my malware is on to me. got the following response from the java site: Error 403 - Forbidden You tried to access a document for which you don't have privileges. then the following from the rooter site: The bandwidth or page view limit for this site has been exceeded and the page cannot be viewed at this time. Once the site is below the limit, it will once again begin serving as normal.
thanks Tomk, here is the rooter log:

Rooter.exe (v1.0.2) by Eric_71
.
The token does not have the SeDebugPrivilege privilege ! (error:1300)
Can not acquire SeDebugPrivilege !
Please run the tool as administrator ..

.
Windows Vista Home Edition (6.0.6000)
[32_bits] - x86 Family 6 Model 15 Stepping 6, GenuineIntel
.
Error OpenService (wscsvc) : 6
Error OpenSCManager : 5
Error OpenService (MpsSvc) : 6
Windows Defender -> Enabled
User Account Control (UAC) -> Enabled
.
Internet Explorer 7.0.6000.16945
.
C:\ [Fixed-NTFS] .. ( Total:177 Go - Free:34 Go )
D:\ [Fixed-FAT32] .. ( Total:8 Go - Free:0 Go )
E:\ [CD_Rom]
F:\ [Removable]
G:\ [Removable]
H:\ [Removable]
I:\ [Removable]
J:\ [Removable]
.
Scan : 18:26.22
Path : C:\Users\HP_Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BPX1ORSS\Rooter[1].exe
User : HP_Administrator ( Administrator -> YES )
.
———————-\\ Processes
.
Locked [System Process] (0)
Locked System (4)
Locked smss.exe (496)
Locked csrss.exe (568)
Locked wininit.exe (608)
Locked csrss.exe (616)
Locked services.exe (652)
Locked lsass.exe (664)
Locked lsm.exe (672)
Locked winlogon.exe (748)
Locked svchost.exe (860)
Locked svchost.exe (920)
Locked svchost.exe (960)
Locked svchost.exe (1052)
Locked svchost.exe (1104)
Locked svchost.exe (1132)
Locked audiodg.exe (1228)
Locked SLsvc.exe (1316)
Locked svchost.exe (1356)
Locked LEXBCES.EXE (1680)
______ C:\Windows\system32\Dwm.exe (1720)
______ C:\Windows\system32\taskeng.exe (1728)
Locked LEXPPS.EXE (1772)
Locked spoolsv.exe (1812)
Locked svchost.exe (1848)
______ C:\Windows\Explorer.EXE (1936)
______ C:\Program Files\Windows Defender\MSASCui.exe (1656)
______ C:\Program Files\Maxtor\ManagerApp\OneTouch.exe (1752)
______ C:\Program Files\Maxtor\OneTouch Status\MaxMenuMgr.exe (2012)
______ C:\Program Files\ScanSoft\OmniPageSE2.0\opwareSE2.exe (696)
______ C:\Program Files\Canon\Memory Card Utility\iP6600D\PDUiP6600DMon.exe (1340)
______ C:\Program Files\Common Files\Real\Update_OB\realsched.exe (1476)
______ C:\Windows\RtHDVCpl.exe (1080)
______ C:\Program Files\iTunes\iTunesHelper.exe (1032)
______ C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (1196)
______ C:\Windows\System32\hkcmd.exe (1220)
______ C:\Windows\System32\igfxpers.exe (524)
______ C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe (1364)
______ C:\Windows\system32\igfxsrvc.exe (1172)
______ C:\Program Files\TrueCredit Messenger\TCMTray.exe (2068)
______ C:\Program Files\Windows Sidebar\sidebar.exe (2104)
______ C:\Program Files\Microsoft Location Finder\LocationFinder.exe (2120)
______ C:\Windows\ehome\ehtray.exe (2128)
______ C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe (2136)
______ C:\Program Files\MSN Messenger\msnmsgr.exe (2144)
______ C:\Program Files\Windows Media Player\wmpnscfg.exe (2152)
______ C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (2192)
Locked AppleMobileDeviceService.exe (2248)
Locked avp.exe (2280)
Locked svchost.exe (2300)
Locked IAANTmon.exe (2332)
Locked IconixService.exe (2348)
______ C:\Windows\ehome\ehmsas.exe (2552)
Locked LSSrvc.exe (2636)
Locked MaxBackServiceInt.exe (2648)
Locked sqlservr.exe (2668)
Locked SyncServices.exe (2720)
Locked HPZipm12.exe (2888)
Locked svchost.exe (2908)
Locked sqlbrowser.exe (2928)
Locked sqlwriter.exe (2972)
Locked svchost.exe (2988)
Locked ViewpointService.exe (3092)
Locked svchost.exe (3108)
Locked SearchIndexer.exe (3136)
Locked XAudio.exe (3220)
Locked WUDFHost.exe (3228)
Locked wmpnetwk.exe (3984)
______ C:\Windows\System32\mobsync.exe (1440)
Locked taskeng.exe (2312)
______ C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe (3768)
Locked ViewMgr.exe (3060)
Locked iPodService.exe (4192)
______ C:\Windows\system32\wuauclt.exe (4508)
Locked svchost.exe (4784)
______ C:\HP\KBD\KBD.EXE (6124)
______ C:\Windows\system32\WerCon.exe (5080)
______ c:\windows\system\hpsysdrv.exe (4412)
______ C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe (1500)
Locked msiexec.exe (4512)
Locked svchost.exe (3872)
Locked jusched.exe (5536)
______ C:\Program Files\MSN\MSNCoreFiles\MSN.EXE (4008)
Locked SearchProtocolHost.exe (848)
______ C:\Users\HP_Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BPX1ORSS\Rooter[1].exe (5128)
Locked SearchFilterHost.exe (3884)
.
———————-\\ Device\Harddisk0\
.
\Device\Harddisk0 [Sectors : 63 x 512 Bytes]
.
\Device\Harddisk0\Partition1 –[ MBR ]– (Start_Offset:32256 | Length:190760661504)
\Device\Harddisk0\Partition2 (Start_Offset:190768919040 | Length:9278115840)
.
———————-\\ Scheduled Tasks
.
C:\Windows\Tasks\AppleSoftwareUpdate.job
C:\Windows\Tasks\desktop.ini
C:\Windows\Tasks\SA.DAT
C:\Windows\Tasks\SCHEDLGU.TXT
.
———————-\\ Registry
.
.
———————-\\ Files & Folders
.
———————-\\ Scan completed at 18:27.03
.
C:\Rooter$\Rooter_1.txt - (30/12/2009 | 18:27.03)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI