Hi six,
Did you fix anything with HijackThis or disable anything via msconfig?
Are these search redirects or browser redirects also?
Which browser do you use? How is your connection now?
It looks like you attempted to reinstall ESET with an older version to try to fix the problem.
Hi again
#1 no
#2 search redirects only
#3 windows internet explorer, connection is the same, works if I get on right away but if I wait it locks out eset and won't let me connection through browsers.
#4 I stuck the eset disc in to see if reloading it would fix it a few days ago, it told me newer version available and I left it alone after that.
When I didn't manually start ESET right away at startup I get an error message saying "kernel not found" and it won't let me start it at all unless I restart the computer and manually start ESET right away.
Eset use to auto start when I booted up, any idea how I get it to do that again or why it stopped doing it?
Here are the logs you asked for, Thanks again for your time!!!
All processes killed
========== OTL ==========
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}\ not found.
HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully!
HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully!
HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer| /E : value set successfully!
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\KernelFaultCheck deleted successfully.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
C:\sqmdata00.sqm moved successfully.
C:\sqmdata01.sqm moved successfully.
C:\sqmdata02.sqm moved successfully.
C:\sqmdata03.sqm moved successfully.
C:\sqmdata04.sqm moved successfully.
C:\sqmdata05.sqm moved successfully.
C:\sqmdata06.sqm moved successfully.
C:\sqmdata07.sqm moved successfully.
C:\sqmdata08.sqm moved successfully.
C:\sqmdata09.sqm moved successfully.
C:\sqmdata10.sqm moved successfully.
C:\sqmdata11.sqm moved successfully.
C:\sqmdata12.sqm moved successfully.
C:\sqmdata13.sqm moved successfully.
C:\sqmdata14.sqm moved successfully.
C:\sqmdata15.sqm moved successfully.
C:\sqmdata16.sqm moved successfully.
C:\sqmdata17.sqm moved successfully.
C:\sqmdata18.sqm moved successfully.
C:\sqmdata19.sqm moved successfully.
C:\sqmnoopt00.sqm moved successfully.
C:\sqmnoopt01.sqm moved successfully.
C:\sqmnoopt02.sqm moved successfully.
C:\sqmnoopt03.sqm moved successfully.
C:\sqmnoopt04.sqm moved successfully.
C:\sqmnoopt05.sqm moved successfully.
C:\sqmnoopt06.sqm moved successfully.
C:\sqmnoopt07.sqm moved successfully.
C:\sqmnoopt08.sqm moved successfully.
C:\sqmnoopt09.sqm moved successfully.
C:\sqmnoopt10.sqm moved successfully.
C:\sqmnoopt11.sqm moved successfully.
C:\sqmnoopt12.sqm moved successfully.
C:\sqmnoopt13.sqm moved successfully.
C:\sqmnoopt14.sqm moved successfully.
C:\sqmnoopt15.sqm moved successfully.
C:\sqmnoopt16.sqm moved successfully.
C:\sqmnoopt17.sqm moved successfully.
C:\sqmnoopt18.sqm moved successfully.
C:\sqmnoopt19.sqm moved successfully.
========== COMMANDS ==========
Restore point Set: OTL Restore Point (64424509440)
[EMPTYTEMP]
User: All Users
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes
User: LocalService
->Temp folder emptied: 65748 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 49286 bytes
User: Owner
->Temp folder emptied: 27034914 bytes
->Temporary Internet Files folder emptied: 92680817 bytes
->Java cache emptied: 33980880 bytes
User: TEMP
->Temporary Internet Files folder emptied: 32768 bytes
User: TEMP.YOUR-O0KWKW9JWC
->Temporary Internet Files folder emptied: 32768 bytes
User: TEMP.YOUR-O0KWKW9JWC.000
->Temporary Internet Files folder emptied: 32768 bytes
User: TEMP.YOUR-O0KWKW9JWC.001
->Temporary Internet Files folder emptied: 32768 bytes
User: TEMP.YOUR-O0KWKW9JWC.002
->Temporary Internet Files folder emptied: 32768 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 219321 bytes
%systemroot%\System32 .tmp files removed: 2577 bytes
Windows Temp folder emptied: 2550572815 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 502056 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33728 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 2,580.00 mb
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
OTL by OldTimer - Version 3.1.21.2 log created on 01092010_082608
Files\Folders moved on Reboot…
Registry entries deleted on Reboot…
………..
OTL logfile created on: 1/9/2010 8:50:51 AM - Run 2
OTL by OldTimer - Version 3.1.21.2 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 84.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 90.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 105.65 Gb Total Space | 59.26 Gb Free Space | 56.09% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
Drive I: | 6.12 Gb Total Space | 2.61 Gb Free Space | 42.72% Space Free | Partition Type: FAT32
Computer Name: YOUR-O0KWKW9JWC
Current User Name: Owner
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe (ESET)
PRC - C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)
PRC - C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
PRC - C:\Program Files\Qwest\Quickcare\bin\sprtcmd.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\SupportSoft\bin\sprtlisten.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple, Inc.)
PRC - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqgalry.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\Softex\OmniPass\omniServ.exe ()
PRC - C:\Program Files\Softex\OmniPass\OPXPApp.exe ()
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
MOD - C:\Program Files\Qwest\Quickcare\bin\sprthook.dll (SupportSoft, Inc.)
MOD - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
MOD - C:\WINDOWS\system32\msvcp60.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\linkinfo.dll (Microsoft Corporation)
========== Win32 Services (All) ==========
SRV - (JavaQuickStarterService) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (lanmanworkstation) – C:\WINDOWS\system32\wkssvc.dll (Microsoft Corporation)
SRV - (EhttpSrv) – C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe (ESET)
SRV - (ekrn) – C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe (ESET)
SRV - (NVSvc) – C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
SRV - (RpcSs) Remote Procedure Call (RPC) – C:\WINDOWS\system32\rpcss.dll (Microsoft Corporation)
SRV - (DcomLaunch) – C:\WINDOWS\system32\rpcss.dll (Microsoft Corporation)
SRV - (PlugPlay) – C:\WINDOWS\system32\services.exe (Microsoft Corporation)
SRV - (Eventlog) – C:\WINDOWS\system32\services.exe (Microsoft Corporation)
SRV - (SupportSoft RemoteAssist) – C:\Program Files\Common Files\SupportSoft\bin\ssrc.exe (SupportSoft, Inc.)
SRV - (FontCache3.0.0.0) – c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (idsvc) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (NetTcpPortSharing) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (aspnet_state) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (EventSystem) – C:\WINDOWS\system32\es.dll (Microsoft Corporation)
SRV - (Nla) Network Location Awareness (NLA) – C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
SRV - (WSearch) – C:\WINDOWS\System32\SearchIndexer.exe (Microsoft Corporation)
SRV - (WmiApSrv) – C:\WINDOWS\system32\wbem\wmiapsrv.exe (Microsoft Corporation)
SRV - (VSS) – C:\WINDOWS\system32\vssvc.exe (Microsoft Corporation)
SRV - (UPS) – C:\WINDOWS\system32\ups.exe (Microsoft Corporation)
SRV - (Spooler) – C:\WINDOWS\system32\spoolsv.exe (Microsoft Corporation)
SRV - (HidServ) – C:\WINDOWS\system32\svchost.exe (Microsoft Corporation)
SRV - (AppMgmt) – C:\WINDOWS\system32\svchost.exe (Microsoft Corporation)
SRV - (SysmonLog) – C:\WINDOWS\system32\smlogsvc.exe (Microsoft Corporation)
SRV - (RDSessMgr) – C:\WINDOWS\system32\sessmgr.exe (Microsoft Corporation)
SRV - (SCardSvr) – C:\WINDOWS\system32\scardsvr.exe (Microsoft Corporation)
SRV - (NetDDEdsdm) – C:\WINDOWS\system32\netdde.exe (Microsoft Corporation)
SRV - (NetDDE) – C:\WINDOWS\system32\netdde.exe (Microsoft Corporation)
SRV - (MSIServer) – C:\WINDOWS\System32\msiexec.exe (Microsoft Corporation)
SRV - (MSDTC) – C:\WINDOWS\system32\msdtc.exe (Microsoft Corporation)
SRV - (mnmsrvc) – C:\WINDOWS\system32\mnmsrvc.exe (Microsoft Corporation)
SRV - (RpcLocator) Remote Procedure Call (RPC) – C:\WINDOWS\system32\locator.exe (Microsoft Corporation)
SRV - (SamSs) – C:\WINDOWS\system32\lsass.exe (Microsoft Corporation)
SRV - (ProtectedStorage) – C:\WINDOWS\system32\lsass.exe (Microsoft Corporation)
SRV - (PolicyAgent) – C:\WINDOWS\system32\lsass.exe (Microsoft Corporation)
SRV - (NtLmSsp) – C:\WINDOWS\system32\lsass.exe (Microsoft Corporation)
SRV - (Netlogon) – C:\WINDOWS\system32\lsass.exe (Microsoft Corporation)
SRV - (ImapiService) – C:\WINDOWS\system32\imapi.exe (Microsoft Corporation)
SRV - (Fax) – C:\WINDOWS\system32\fxssvc.exe (Microsoft Corporation)
SRV - (dmadmin) – C:\WINDOWS\System32\dmadmin.exe (Microsoft Corp., Veritas Software)
SRV - (SwPrv) – C:\WINDOWS\System32\dllhost.exe (Microsoft Corporation)
SRV - (COMSysApp) – C:\WINDOWS\System32\dllhost.exe (Microsoft Corporation)
SRV - (ClipSrv) – C:\WINDOWS\system32\clipsrv.exe (Microsoft Corporation)
SRV - (CiSvc) – C:\WINDOWS\system32\cisvc.exe (Microsoft Corporation)
SRV - (ALG) – C:\WINDOWS\system32\alg.exe (Microsoft Corporation)
SRV - (WZCSVC) – C:\WINDOWS\system32\wzcsvc.dll (Microsoft Corporation)
SRV - (xmlprov) – C:\WINDOWS\system32\xmlprov.dll (Microsoft Corporation)
SRV - (wuauserv) – C:\WINDOWS\system32\wuauserv.dll (Microsoft Corporation)
SRV - (wscsvc) – C:\WINDOWS\system32\wscsvc.dll (Microsoft Corporation)
SRV - (winmgmt) – C:\WINDOWS\system32\wbem\wmisvc.dll (Microsoft Corporation)
SRV - (stisvc) Windows Image Acquisition (WIA) – C:\WINDOWS\system32\wiaservc.dll (Microsoft Corporation)
SRV - (upnphost) – C:\WINDOWS\system32\upnphost.dll (Microsoft Corporation)
SRV - (W32Time) – C:\WINDOWS\system32\w32time.dll (Microsoft Corporation)
SRV - (WebClient) – C:\WINDOWS\system32\webclnt.dll (Microsoft Corporation)
SRV - (HTTPFilter) – C:\WINDOWS\system32\w3ssl.dll (Microsoft Corporation)
SRV - (TermService) – C:\WINDOWS\system32\termsrv.dll (Microsoft Corporation)
SRV - (TapiSrv) – C:\WINDOWS\system32\tapisrv.dll (Microsoft Corporation)
SRV - (srservice) – C:\WINDOWS\system32\srsvc.dll (Microsoft Corporation)
SRV - (lanmanserver) – C:\WINDOWS\system32\srvsvc.dll (Microsoft Corporation)
SRV - (TrkWks) – C:\WINDOWS\system32\trkwks.dll (Microsoft Corporation)
SRV - (SSDPSRV) – C:\WINDOWS\system32\ssdpsrv.dll (Microsoft Corporation)
SRV - (Schedule) – C:\WINDOWS\system32\schedsvc.dll (Microsoft Corporation)
SRV - (Themes) – C:\WINDOWS\system32\shsvcs.dll (Microsoft Corporation)
SRV - (ShellHWDetection) – C:\WINDOWS\system32\shsvcs.dll (Microsoft Corporation)
SRV - (FastUserSwitchingCompatibility) – C:\WINDOWS\system32\shsvcs.dll (Microsoft Corporation)
SRV - (SENS) – C:\WINDOWS\system32\sens.dll (Microsoft Corporation)
SRV - (seclogon) – C:\WINDOWS\system32\seclogon.dll (Microsoft Corporation)
SRV - (BITS) – C:\WINDOWS\system32\qmgr.dll (Microsoft Corporation)
SRV - (napagent) – C:\WINDOWS\system32\qagentrt.dll (Microsoft Corporation)
SRV - (RasMan) – C:\WINDOWS\system32\rasmans.dll (Microsoft Corporation)
SRV - (RasAuto) – C:\WINDOWS\system32\rasauto.dll (Microsoft Corporation)
SRV - (NtmsSvc) – C:\WINDOWS\system32\ntmssvc.dll (Microsoft Corporation)
SRV - (helpsvc) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (Netman) – C:\WINDOWS\system32\netman.dll (Microsoft Corporation)
SRV - (Messenger) – C:\WINDOWS\system32\msgsvc.dll (Microsoft Corporation)
SRV - (RemoteAccess) – C:\WINDOWS\system32\mprdim.dll (Microsoft Corporation)
SRV - (hkmsvc) – C:\WINDOWS\system32\kmsvc.dll (Microsoft Corporation)
SRV - (LmHosts) – C:\WINDOWS\system32\lmhsvc.dll (Microsoft Corporation)
SRV - (SharedAccess) Windows Firewall/Internet Connection Sharing (ICS) – C:\WINDOWS\system32\ipnathlp.dll (Microsoft Corporation)
SRV - (ERSvc) – C:\WINDOWS\system32\ersvc.dll (Microsoft Corporation)
SRV - (Dot3svc) – C:\WINDOWS\system32\dot3svc.dll (Microsoft Corporation)
SRV - (Dnscache) – C:\WINDOWS\system32\dnsrslvr.dll (Microsoft Corporation)
SRV - (EapHost) – C:\WINDOWS\system32\eapsvc.dll (Microsoft Corporation)
SRV - (dmserver) – C:\WINDOWS\system32\dmserver.dll (Microsoft Corp.)
SRV - (Dhcp) – C:\WINDOWS\system32\dhcpcsvc.dll (Microsoft Corporation)
SRV - (CryptSvc) – C:\WINDOWS\system32\cryptsvc.dll (Microsoft Corporation)
SRV - (Browser) – C:\WINDOWS\system32\browser.dll (Microsoft Corporation)
SRV - (AudioSrv) – C:\WINDOWS\system32\audiosrv.dll (Microsoft Corporation)
SRV - (Alerter) – C:\WINDOWS\system32\alrsvc.dll (Microsoft Corporation)
SRV - (sprtlisten) – C:\Program Files\Common Files\supportsoft\bin\sprtlisten.exe (SupportSoft, Inc.)
SRV - (WLSetupSvc) – C:\Program Files\Windows Live\installer\WLSetupSvc.exe (Microsoft Corporation)
SRV - (usnjsvc) – C:\Program Files\Windows Live\Messenger\usnsvc.exe (Microsoft Corporation)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple, Inc.)
SRV - (WmdmPmSN) – C:\WINDOWS\system32\mspmsnsv.dll (Microsoft Corporation)
SRV - (WMPNetworkSvc) – C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)
SRV - (WudfSvc) – C:\WINDOWS\system32\WudfSvc.dll (Microsoft Corporation)
SRV - (omniserv) – C:\Program Files\Softex\OmniPass\omniServ.exe ()
SRV - (Pml Driver HPH11) – C:\WINDOWS\system32\hphipm11.exe (HP)
SRV - (RSVP) – C:\WINDOWS\system32\rsvp.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASENUM) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (epfwtdir) – C:\WINDOWS\system32\drivers\epfwtdir.sys (ESET)
DRV - (ehdrv) – C:\WINDOWS\system32\drivers\ehdrv.sys (ESET)
DRV - (eamon) – C:\WINDOWS\system32\drivers\eamon.sys (ESET)
DRV - (RTL8023xp) – C:\WINDOWS\system32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation )
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (Secdrv) – C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (PxHelp20) – C:\WINDOWS\System32\DRIVERS\PxHelp20.sys (Sonic Solutions)
DRV - (hamachi_oem) – C:\WINDOWS\system32\drivers\gan_adapter.sys (Applied Networking Inc.)
DRV - (Ps2) – C:\WINDOWS\system32\drivers\PS2.sys (Hewlett-Packard Company)
DRV - (HPZius12) – C:\WINDOWS\system32\drivers\HPZius12.sys (HP)
DRV - (HPZipr12) – C:\WINDOWS\system32\drivers\HPZipr12.sys (HP)
DRV - (HPZid412) – C:\WINDOWS\system32\drivers\HPZid412.sys (HP)
DRV - (AFS2K) – C:\WINDOWS\system32\drivers\AFS2K.SYS (Oak Technology Inc.)
DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (S3Psddr) – C:\WINDOWS\system32\drivers\s3gnbm.sys (S3 Graphics, Inc.)
DRV - (ltmodem5) – C:\WINDOWS\system32\drivers\ltmdmnt.sys (Agere Systems)
DRV - (LMouFlt2) – C:\WINDOWS\system32\drivers\LMouFlt2.Sys (Logitech, Inc.)
DRV - (L8042pr2) – C:\WINDOWS\system32\drivers\L8042pr2.Sys (Logitech, Inc.)
DRV - (MxlW2k) – C:\WINDOWS\system32\drivers\MxlW2k.sys (MusicMatch, Inc.)
DRV - ({6080A529-897E-4629-A488-ABA0C29B635E}) Intel® Graphics Platform (SoftBIOS) – C:\WINDOWS\system32\drivers\ialmsbw.sys (Intel Corporation)
DRV - ({D31A0762-0CEB-444e-ACFF-B049A1F6FE91}) Intel® Graphics Chipset (KCH) – C:\WINDOWS\system32\drivers\ialmkchw.sys (Intel Corporation)
DRV - (ialm) – C:\WINDOWS\system32\drivers\ialmnt5.sys (Intel Corporation)
DRV - (SiS315) – C:\WINDOWS\system32\drivers\sisgrp.sys (Silicon Integrated Systems Corporation)
DRV - (fasttx2k) – C:\WINDOWS\System32\DRIVERS\fasttx2k.sys (Promise Technology, Inc.)
DRV - (viaagp1) – C:\WINDOWS\System32\DRIVERS\viaagp1.sys (VIA Technologies, Inc.)
DRV - (SISAGP) – C:\WINDOWS\System32\DRIVERS\SISAGPX.sys (Silicon Integrated Systems Corporation)
DRV - (drvmcdb) – C:\WINDOWS\System32\DRIVERS\drvmcdb.sys (VERITAS Software, Inc.)
DRV - (rtl8139) – C:\WINDOWS\system32\drivers\R8139n51.sys (Realtek Semiconductor Corporation )
DRV - (pfc) – C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
DRV - (nv_agp) – C:\WINDOWS\System32\DRIVERS\nv_agp.sys (NVIDIA Corporation)
DRV - (Ptilink) – C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://qwest.live.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [Binary data over 100 bytes]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://qwest.live.com
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://qwest.live.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://srch-us8.hpwis.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://srch-us8.hpwis.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://my.yahoo.com/
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\CNNSI, = search.sportsillustrated.cnn.com/pages/search.jsp?query=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\Dictionary, = dictionary.reference.com/search?q=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\Google, = google.com/search?q=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\GoogleGroups, = groups-beta.google.com/groups?q=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\GoogleImages, = images.google.com/images?hl=en&lr=&q=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\GoogleNews, = news.google.com/news?tab=gn&hl=en&ie=UTF-8&q=%s&btnG=Search+News
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\KB, = support.microsoft.com/search/default.aspx?query=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\KBDLL, = support.microsoft.com/dllhelp/default.aspx?dlltype=file&l=55&alpha=%s&S=1
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\Movies, = fandango.com/my_box_office.asp?searchby=2&txtCityZip=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\MSN, = search.msn.com/results.asp?q=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\Thesaurus, = thesaurus.reference.com/search?q=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\Weather, = weather.com/weather/local/%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\Yahoo, = search.yahoo.com/search?p=%s
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\software\mozilla\Thunderbird\Extensions\\[removed]: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2009/06/11 17:50:23 | 00,000,000 | —D | M]
[2009/04/28 16:27:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions
O1 HOSTS File: (98 bytes) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Windows Live Toolbar Helper) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (hp toolkit) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\hp\EXPLOREBAR\HPTOOLKT.DLL (Hewlett-Packard Company)
O3 - HKLM\..\Toolbar: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\ShellBrowser: (hp toolkit) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\hp\EXPLOREBAR\HPTOOLKT.DLL (Hewlett-Packard Company)
O3 - HKCU\..\Toolbar\WebBrowser: (hp toolkit) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\hp\EXPLOREBAR\HPTOOLKT.DLL (Hewlett-Packard Company)
O3 - HKCU\..\Toolbar\WebBrowser: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [QuickCare] C:\Program Files\Qwest\Quickcare\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKCU..\Run: [igndlm.exe] C:\Program Files\Download Manager\DLM.exe (IGN Entertainment)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe (Intuit Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Updates from HP.lnk = C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\Owner\Start Menu\Programs\Startup\GameSpot Download Manager.lnk = C:\Program Files\GameSpot\GameSpotDownloadManager_Win32.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &ieSpell Options - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O8 - Extra context menu item: &Windows Live Search - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O8 - Extra context menu item: Check &Spelling - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O8 - Extra context menu item: Lookup on Merriam Webster - C:\Program Files\ieSpell\Merriam Webster.HTM ()
O8 - Extra context menu item: Lookup on Wikipedia - C:\Program Files\ieSpell\wikipedia.HTM ()
O9 - Extra Button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra 'Tools' menuitem : ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra 'Tools' menuitem : ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\PLUGINS\NPDocBox.dll (InterTrust Technologies Corporation, Inc.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://a1540.g.akamai.net/7/1540/52/200705…ex/qtplugin.cab (Reg Error: Key error.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/8/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.9.113.cab (CDownloadCtrl Object)
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} https://www-secure.symantec.com/techsupp/as…abs/tgctlsr.cab (Symantec Script Runner Class)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://update.microsoft.com/windowsupdate/…b?1162338879046 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://update.microsoft.com/microsoftupdat…b?1222980964593 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} http://www.crucial.com/controls/cpcScanner.cab (Crucial cpcScan)
O16 - DPF: {A9F8D9EC-3D0A-4A60-BD82-FBD64BAD370D}
http://h20264.www2.hp.com/ediags/dd/instal…nosticsxp2k.cab (DDRevision Class)
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_09)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_10)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_11)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/flash…ent/swflash.cab (Shockwave Flash Object)
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.2.1.cab (Reg Error: Key error.)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O20 - Winlogon\Notify\OPXPGina: DllName - C:\Program Files\Softex\OmniPass\opxpgina.dll - C:\Program Files\Softex\OmniPass\OPXPGina.dll ()
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2003/04/09 22:19:17 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2001/07/28 07:07:38 | 00,000,000 | -HS- | M] () - I:\AUTOEXEC.BAT – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*
MsConfig - State: "system.ini" - 0
MsConfig - State: "win.ini" - 0
MsConfig - State: "bootini" - 0
MsConfig - State: "services" - 0
MsConfig - State: "startup" - 0
========== Files/Folders - Created Within 30 Days ==========
[2010/01/09 08:26:08 | 00,000,000 | —D | C] – C:\_OTL
[2010/01/08 18:59:23 | 00,513,536 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2010/01/07 05:38:16 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/07/21 22:14:30 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2009/06/04 10:22:13 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\ESET
[2009/04/28 16:25:18 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Mozilla
[2007/07/30 19:03:22 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2007/07/19 21:31:58 | 00,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2006/11/01 21:16:30 | 00,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
========== Files - Modified Within 30 Days ==========
[2010/01/09 08:31:10 | 00,205,272 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2010/01/09 08:31:05 | 00,000,254 | —- | M] () – C:\WINDOWS\tasks\Check Updates for Windows Live Toolbar.job
[2010/01/09 08:30:59 | 00,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/01/09 08:30:44 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/01/09 08:30:41 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/01/09 08:30:38 | 32,205,57824 | -HS- | M] () – C:\hiberfil.sys
[2010/01/09 08:29:04 | 04,718,592 | -H– | M] () – C:\Documents and Settings\Owner\NTUSER.DAT
[2010/01/09 08:29:04 | 00,000,178 | -HS- | M] () – C:\Documents and Settings\Owner\ntuser.ini
[2010/01/09 08:29:00 | 00,000,268 | -H– | M] () – C:\sqmdata00.sqm
[2010/01/09 08:29:00 | 00,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
[2010/01/09 08:28:23 | 00,000,098 | —- | M] () – C:\WINDOWS\System32\drivers\etc\Hosts
[2010/01/09 00:34:02 | 06,435,682 | -H– | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\IconCache.db
[2010/01/08 18:59:23 | 00,513,536 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2010/01/08 17:29:22 | 00,284,915 | —- | M] () – C:\Documents and Settings\Owner\Desktop\gmer.zip
[2010/01/07 05:38:18 | 00,001,745 | —- | M] () – C:\Documents and Settings\Owner\Desktop\HijackThis.lnk
========== Files Created - No Company Name ==========
[2010/01/09 08:29:00 | 00,000,268 | -H– | C] () – C:\sqmdata00.sqm
[2010/01/09 08:29:00 | 00,000,244 | -H– | C] () – C:\sqmnoopt00.sqm
[2010/01/08 17:29:48 | 00,284,915 | —- | C] () – C:\Documents and Settings\Owner\Desktop\gmer.zip
[2010/01/07 05:38:17 | 00,001,745 | —- | C] () – C:\Documents and Settings\Owner\Desktop\HijackThis.lnk
[2009/09/10 11:43:49 | 00,095,856 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2009/06/10 07:36:07 | 00,000,911 | —- | C] () – C:\WINDOWS\STA2.ini
[2009/04/28 15:25:03 | 00,002,928 | —- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\81F79ABC-AB11-494C-859E-88424AA60ADF.txt
[2009/04/28 15:24:16 | 00,003,756 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\81F79ABC-AB11-494C-859E-88424AA60ADF.txt
[2008/11/18 17:34:20 | 00,000,262 | —- | C] () – C:\WINDOWS\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2008/07/21 16:14:10 | 00,073,728 | —- | C] () – C:\WINDOWS\System32\RtNicProp32.dll
[2007/11/26 21:56:28 | 00,151,415 | —- | C] () – C:\WINDOWS\System32\xlive.dll.cat
[2007/09/27 10:51:02 | 00,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 10:48:48 | 00,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 10:48:28 | 00,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2007/07/23 08:03:32 | 00,053,248 | —- | C] () – C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2007/07/23 08:03:32 | 00,053,248 | —- | C] () – C:\WINDOWS\System32\AgCPanelSwedish.dll
[2007/07/23 08:03:32 | 00,053,248 | —- | C] () – C:\WINDOWS\System32\AgCPanelSpanish.dll
[2007/07/23 08:03:30 | 00,053,248 | —- | C] () – C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2007/07/23 08:03:30 | 00,053,248 | —- | C] () – C:\WINDOWS\System32\AgCPanelPortugese.dll
[2007/07/23 08:03:30 | 00,053,248 | —- | C] () – C:\WINDOWS\System32\AgCPanelKorean.dll
[2007/07/23 08:03:30 | 00,053,248 | —- | C] () – C:\WINDOWS\System32\AgCPanelJapanese.dll
[2007/07/23 08:03:30 | 00,053,248 | —- | C] () – C:\WINDOWS\System32\AgCPanelGerman.dll
[2007/07/23 08:03:30 | 00,053,248 | —- | C] () – C:\WINDOWS\System32\AgCPanelFrench.dll
[2006/12/30 02:29:35 | 00,006,144 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/12/02 18:13:19 | 00,000,214 | —- | C] () – C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2006/11/24 18:24:46 | 00,021,840 | —- | C] () – C:\WINDOWS\System32\SIntfNT.dll
[2006/11/24 18:24:45 | 00,017,212 | —- | C] () – C:\WINDOWS\System32\SIntf32.dll
[2006/11/24 18:24:45 | 00,012,067 | —- | C] () – C:\WINDOWS\System32\SIntf16.dll
[2006/11/14 19:57:18 | 00,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2006/11/08 05:52:36 | 00,061,678 | —- | C] () – C:\Documents and Settings\Owner\Application Data\PFP100JPR.{PB
[2006/11/08 05:52:36 | 00,012,358 | —- | C] () – C:\Documents and Settings\Owner\Application Data\PFP100JCM.{PB
[2006/11/01 16:23:02 | 00,000,128 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\fusioncache.dat
[2006/11/01 15:52:30 | 00,001,109 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2006/10/31 16:40:31 | 00,019,968 | —- | C] () – C:\WINDOWS\System32\cpuinf32.dll
[2006/08/11 21:45:20 | 00,581,632 | —- | C] () – C:\WINDOWS\System32\nvhwvid.dll
[2006/08/11 21:43:00 | 01,724,416 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2006/08/11 21:43:00 | 01,101,824 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2006/08/11 21:43:00 | 00,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2004/09/13 16:35:56 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2003/04/10 04:35:00 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2003/04/10 04:21:36 | 00,000,051 | —- | C] () – C:\WINDOWS\System32\mshrml.ini
[2003/04/10 01:51:07 | 00,000,438 | —- | C] () – C:\WINDOWS\System32\1_ssetup.ini
[2003/04/10 01:51:07 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\sunistlog.ini
[2003/04/10 00:32:34 | 00,094,208 | —- | C] () – C:\WINDOWS\System32\PcdrKernelModeServices.dll
[2003/04/10 00:32:34 | 00,077,824 | —- | C] () – C:\WINDOWS\System32\ProgressTrace.dll
[2003/04/10 00:06:10 | 00,167,936 | —- | C] () – C:\WINDOWS\System32\PCDrJNI_1_1.dll
[2003/04/10 00:03:38 | 00,045,056 | —- | C] () – C:\WINDOWS\System32\hpreg.dll
[2003/04/10 00:03:38 | 00,024,576 | —- | C] () – C:\WINDOWS\System32\syscontr.dll
[2003/04/09 23:57:15 | 00,000,052 | —- | C] () – C:\WINDOWS\intuprof.ini
[2003/04/09 23:57:04 | 00,000,626 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2003/04/09 23:16:44 | 00,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2003/04/09 23:08:03 | 00,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2003/04/09 23:08:01 | 01,507,328 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2003/04/09 22:55:02 | 00,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2003/04/09 22:44:58 | 00,299,073 | —- | C] () – C:\WINDOWS\System32\PythonCOM22.dll
[2003/04/09 22:44:58 | 00,065,536 | —- | C] () – C:\WINDOWS\System32\PyWinTypes22.dll
[2003/04/09 22:44:29 | 00,016,896 | —- | C] () – C:\WINDOWS\System32\bcbmm.dll
[2003/04/09 22:23:21 | 00,000,802 | —- | C] () – C:\WINDOWS\orun32.ini
[2003/04/09 22:05:45 | 00,000,659 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2001/08/14 18:47:08 | 00,020,480 | —- | C] () – C:\WINDOWS\System32\vxpsapi.dll
========== Custom Scans ==========
========== HijackThis Backups ==========
C:\Program Files\Trend Micro\HijackThis\backups\backup-20100108-172739-582
O3 - Toolbar: (no name) - {90222687-F593-4738-B738-FBEE9C7B26DF} - (no file)
C:\Program Files\Trend Micro\HijackThis\backups\backup-20100108-172739-803
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;
C:\Program Files\Trend Micro\HijackThis\backups\backup-20100108-172739-885
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:7171
======= End HijackThis Backups =========
< End of report >