[Resolved] Winupdate86.exe trojan
27 min read
- Logs from malware removal programs (DDS is one of them) can take some time to analyze. I need you to be patient while I analyze any logs you post.
- Please make sure to carefully read any instruction that I give you.
Reading too lightly will cause you to miss important steps, which could have destructive effects. - If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
- These instructions have been specifically tailored to your computer and the issues you are experiencing with your computer. It's important to note that these instructions are not suitable for any other computer, even if the issues are fairly similar.
- Do not do things I do not ask for, such as running a spyware scan on your computer. The one thing that you should always do, is to make sure sure that your anti-virus definitions are up-to-date!
- If I instruct you to download a specific tool in which you already have, please delete the copy that you have and re-download the tool. The reason I ask you to do this is because these tools are updated fairly regularly.
- Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
- I am going to stick with you until ALL malware is gone from your system. I would appreciate it if you would do the same. From this point, we're in this together
Because of this, you must reply within five days. I will post a reminder should you seem to fail to do this, however, if you fail to reply within three days then,
unless I have been notified of your absence in advance, the topic shall be closed! - Please do not PM me directly for help. If you have any questions, post them in this topic.
- Lastly, I am no magician. I will try very hard to fix your issues, but no promises can be made. Also be aware that some infections are so severe that you might need to resort to reformatting and reinstalling your operating system.
Don't worry, this only happens in severe cases, but it sadly does happen. Be prepared to back up your data. Have means of backing up your data available.
This may cause a delay, but I will do my best to keep it as short as possible.
I am checking over your log, I will post back shortly with instructions.
Lets see if we can get your computer to boot up properly. Please follow the instructions in order.
Note:
If one method doesn't work proceed with the next.
Start the computer by using the last known good configuration. To start the computer by using the last known good configuration, follow these steps:
- Restart your computer.
- As the computer starts to boot-up, Tap the F8 KEY repeatedly,
- This will bring up a menu.
- Use the Up and Down Arrow Keys to scroll to Last Known Good Configuration
- Then press the Enter Key on your Keyboard
- Go into your usual account
If that doesn't work try this:
Entering Safe Mode
- Restart your computer.
- As the computer starts to boot-up, Tap the F8 KEY repeatedly,
- This will bring up a menu.
- Use the Up and Down Arrow Keys to scroll to Safe Mode
- Then press the Enter Key on your Keyboard
- Go into your usual account
Upon reboot of your computer attempt to log into your computer normally. If you are successfully in getting to your desktop please go ahead and run OTL, GMER. Instructions for running these tools can be found below.
Note:
In the event that you are unable to boot your computer in Normal mode please attempt to boot using Last Known Good Configuration. If you are still unable to access your desktop then please attempt booting into Safe Mode. If after trying booting into Safe Mode you are still unable to load your desktop then please post back here for further instructions.
Next:
OTL Custom Scan
- Download OTL to your desktop.
- Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
- When the window appears, underneath Output at the top change it to Minimal Output.
- Check the boxes beside LOP Check and Purity Check.
- Under Custom Scan paste this in
netsvcs
%SYSTEMDRIVE%\*.exe
/md5start
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
sceclt.dll
ntelogon.dll
logevent.dll
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
nvrd32.sys
/md5stop
%systemroot%\*. /mp /s
CREATERESTOREPOINT
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles - Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
- When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
- Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
- You may need two posts to fit them both in.
Scanning with GMER
Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.
[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
- Extract the contents of the zipped file to desktop.
- Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
- If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
[external image: Posted Image]
Click the image to enlarge it
- In the right panel, you will see several boxes that have been checked. Uncheck the following …
- Sections
- IAT/EAT
- Drives/Partition other than Systemdrive (typically C:\)
- Show All (don't miss this one)
- Then click the Scan button & wait for it to finish.
- Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
- Save it where you can easily find it, such as your desktop, and attach it in your reply.
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Next:
Please make sure you include the following items in your next post:
1. The log that was produced after running OTL.
2. The log that was produced after running GMER.
3. An update on how your computer is currently running.
Insert the Windows XP CD into your computer and then restart your computer.
Press 'R' to enter the Recovery Console.
The Recovery Console will start and ask you which Windows installation you would like to log on to. If you have multiple Windows installations, it will list each one, and you would enter the number associated with the installation you would like to work on and press enter. If you have just one Windows installation, type 1 and press enter.
You will need to enter the administrator password. If a password was not set then leave the password field blank and press Enter.From the Command Prompt please type the following lines, one at a time, hit the Enter key after each line.
(If your CD drive is not D - change it to the appropriate letter)
cd system32
copy userinit.exe winupdate86.exe
copy userinit.exe winlogon86.exe
Note:
In the first line there is a space after cd
In the second line there is a space after copy and one after userinit.exe
In the third line there is a space after copy and one after userinit.exe
After hitting Enter for the first line you will see that the cursor will go to a new prompt if successful (you should see that it says: c:\windows\system32) if it is not successfully you will see a message similar to this: "The system cannot find the path specified."
After hitting Enter for the first line you will receive a message that says: "1 file(s) copied message"
After hitting Enter for the second line you will receive a message that says: "1 file(s) copied message"
Next:
In the Command Prompt type: exit
Note: This command will exit the recovery console and reboot your computer.
NOTE: If you have any questions while being in the Recovery Console please STOP and ask me for clarification before you continue.
OTL logfile created on: 1/26/2010 7:27:02 AM - Run 1
OTL by OldTimer - Version 3.1.25.4 Folder = C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75\Desktop
Windows XP Media Center Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1,015.00 Mb Total Physical Memory | 539.00 Mb Available Physical Memory | 53.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 84.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 224.12 Gb Total Space | 51.27 Gb Free Space | 22.87% Space Free | Partition Type: NTFS
Drive D: | 8.74 Gb Total Space | 0.44 Gb Free Space | 5.06% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive J: | 298.02 Gb Total Space | 97.53 Gb Free Space | 32.72% Space Free | Partition Type: FAT32
Computer Name: YOUR-4DACD0EA75
Current User Name: HP_Administrator
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe ()
PRC - C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (Symantec Corporation)
PRC - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (Symantec Corporation)
PRC - c:\Program Files\Common Files\Symantec Shared\CCPROXY.EXE (Symantec Corporation)
PRC - c:\Program Files\Common Files\Symantec Shared\CCSETMGR.EXE (Symantec Corporation)
PRC - c:\Program Files\Common Files\Symantec Shared\CCEVTMGR.EXE (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\CCAPP.EXE (Symantec Corporation)
PRC - c:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE (Symantec Corporation)
PRC - C:\Program Files\My Book\WD Backup\uBBMonitor.exe (ArcSoft, Inc.)
PRC - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)
PRC - C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe (Hewlett-Packard)
PRC - C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
PRC - C:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe (Sonic Solutions)
PRC - C:\Program Files\DISC\DISCover.exe (Digital Interactive Systems Corporation)
PRC - C:\Program Files\DISC\DISCUpdMgr.exe (Digital Interactive Systems Corporation, Inc.)
PRC - C:\Program Files\DISC\DiscStreamHub.exe (Digital Interactive Systems Corporation, Inc.)
PRC - C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
PRC - C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
PRC - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe (Symantec Corporation)
PRC - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\WINDOWS\ALCWZRD.EXE (RealTek Semicoductor Corp.)
PRC - C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
PRC - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe (Symantec Corporation)
PRC - C:\Program Files\Java\jre1.5.0_05\bin\jucheck.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\WINDOWS\arpwrmsg.exe (Microsoft)
PRC - C:\WINDOWS\arservice.exe (Microsoft)
PRC - C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.)
PRC - C:\hp\KBD\kbd.exe (Hewlett-Packard Company)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
PRC - c:\WINDOWS\system\hpsysdrv.exe (Hewlett-Packard Company)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75\Desktop\OTL.exe (OldTimer Tools)
MOD - c:\Program Files\Common Files\Symantec Shared\CCL40.DLL (Symantec Corporation)
MOD - C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75\Local Settings\Temp\IadHide5.dll (BackWeb)
MOD - C:\Program Files\Common Files\Symantec Shared\AntiSpam\asOEHook.dll (Symantec Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msvcp71.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msvcr71.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (Symantec Core LC) – C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe ()
SRV - (LiveUpdate Notice Service) – C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (Symantec Corporation)
SRV - (SNDSrvc) – c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (Symantec Corporation)
SRV - (ccProxy) – c:\Program Files\Common Files\Symantec Shared\ccProxy.exe (Symantec Corporation)
SRV - (ccSetMgr) – c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
SRV - (ccEvtMgr) – c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
SRV - (NSCService) – c:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE (Symantec Corporation)
SRV - (LiveUpdate) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_0.EXE (Symantec Corporation)
SRV - (Automatic LiveUpdate Scheduler) – C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (Symantec Corporation)
SRV - (LightScribeService) – C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
SRV - (comHost) – c:\Program Files\Norton Internet Security\comHost.exe (Symantec Corporation)
SRV - (navapsvc) – c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe (Symantec Corporation)
SRV - (ccISPwdSvc) – c:\Program Files\Norton Internet Security\ccPwdSvc.exe (Symantec Corporation)
SRV - (SPBBCSvc) – c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe (Symantec Corporation)
SRV - (SAVScan) – c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe (Symantec Corporation)
SRV - (ARSVC) – C:\WINDOWS\arservice.exe (Microsoft)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (IDriverT) – C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (aspnet_state) – C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe (Microsoft Corporation)
SRV - (ose) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (SymEvent) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (NAVEX15) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20100125.003\NAVEX15.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (NAVENG) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20100125.003\NAVENG.SYS (Symantec Corporation)
DRV - (SYMIDSCO) – C:\Program Files\Common Files\Symantec Shared\SymcData\idsdefs\20100119.001\SymIDSCo.sys (Symantec Corporation)
DRV - (SYMTDI) – C:\WINDOWS\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (SYMREDRV) – C:\WINDOWS\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (SYMIDS) – C:\WINDOWS\System32\Drivers\SYMIDS.SYS (Symantec Corporation)
DRV - (SYMNDIS) – C:\WINDOWS\System32\Drivers\SYMNDIS.SYS (Symantec Corporation)
DRV - (SYMFW) – C:\WINDOWS\System32\Drivers\SYMFW.SYS (Symantec Corporation)
DRV - (SYMDNS) – C:\WINDOWS\System32\Drivers\SYMDNS.SYS (Symantec Corporation)
DRV - (symlcbrd) – C:\WINDOWS\system32\drivers\symlcbrd.sys (Symantec Corporation)
DRV - (ialm) – C:\WINDOWS\system32\drivers\ialmnt5.sys (Intel Corporation)
DRV - (AgereSoftModem) – C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (RT73) – C:\WINDOWS\system32\drivers\rt73.sys (Ralink Technology, Corp.)
DRV - (Ps2) – C:\WINDOWS\system32\drivers\PS2.sys (Hewlett-Packard Company)
DRV - (HSXHWBS2) – C:\WINDOWS\system32\drivers\HSXHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsx) – C:\WINDOWS\system32\drivers\HSX_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSX_DP) – C:\WINDOWS\system32\drivers\HSX_DP.sys (Conexant Systems, Inc.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (mdmxsdk) – C:\WINDOWS\system32\drivers\mdmxsdk.sys (Conexant)
DRV - (SPBBCDrv) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (SAVRTPEL) – c:\Program Files\Norton Internet Security\Norton AntiVirus\Savrtpel.sys (Symantec Corporation)
DRV - (SAVRT) – c:\Program Files\Norton Internet Security\Norton AntiVirus\savrt.sys (Symantec Corporation)
DRV - (PxHelp20) – C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (ftsata2) – C:\WINDOWS\system32\DRIVERS\ftsata2.sys (Promise Technology, Inc.)
DRV - (iaStor) – C:\WINDOWS\system32\DRIVERS\iaStor.sys (Intel Corporation)
DRV - (E100B) Intel® – C:\WINDOWS\system32\drivers\e100b325.sys (Intel Corporation)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\Hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (HdAudAddService) – C:\WINDOWS\system32\drivers\Hdaudio.sys (Windows ® Server 2003 DDK provider)
DRV - (Secdrv) – C:\WINDOWS\system32\drivers\secdrv.sys ()
DRV - (Ptilink) – C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)
DRV - (rtl8139) Realtek RTL8139(A/B/C) – C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)
DRV - (bb-run) – C:\WINDOWS\system32\DRIVERS\bb-run.sys (Promise Technology, Inc.)
DRV - (HidBatt) – C:\WINDOWS\system32\drivers\hidbatt.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\software\mozilla\Netscape Browser 8.0.4.0\Extensions\\Components: C:\Program Files\Netscape\Netscape Browser\Components [2006/05/24 22:24:55 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Netscape Browser 8.0.4.0\Extensions\\Plugins: C:\Program Files\Netscape\Netscape Browser\Plugins [2006/05/24 22:36:37 | 00,000,000 | —D | M]
O1 HOSTS File: ([2004/08/10 06:00:00 | 00,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (CNavExtBho Class) - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll (Symantec Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O2 - BHO: (hpWebHelper Class) - {AAAE832A-5FFF-4661-9C8F-369692D1DCB9} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\WebHelper.dll (TODO: )
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Norton AntiVirus) - {C4069E3A-68F1-403E-B40E-20066696354B} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\ShellBrowser: (Norton AntiVirus) - {C4069E3A-68F1-403E-B40E-20066696354B} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [AlwaysReady Power Message APP] C:\WINDOWS\arpwrmsg.exe (Microsoft)
O4 - HKLM..\Run: [ccApp] c:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [DISCover] C:\Program Files\DISC\DISCover.exe (Digital Interactive Systems Corporation)
O4 - HKLM..\Run: [DiscUpdateManager] C:\Program Files\DISC\DISCUpdMgr.exe (Digital Interactive Systems Corporation, Inc.)
O4 - HKLM..\Run: [DMAScheduler] c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe (Sonic Solutions)
O4 - HKLM..\Run: [High Definition Audio Property Page Shortcut] C:\WINDOWS\System32\HdAShCut.exe (Windows ® Server 2003 DDK provider)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [HPBootOp] C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe (Hewlett-Packard)
O4 - HKLM..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [PCDrProfiler] File not found
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\Recguard.exe ()
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [Symantec PIF AlertEng] C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (Symantec Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Development Company, L.P.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Updates From HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe (Hewlett-Packard)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WD Backup Monitor.lnk = C:\Program Files\My Book\WD Backup\uBBMonitor.exe (ArcSoft, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &Google Search - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: &Translate English Word - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Backward Links - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Cached Snapshot of Page - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Similar Pages - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Translate Page into English - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\NPJPI150_05.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ()
O9 - Extra 'Tools' menuitem : Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ()
O15 - HKLM\..Trusted Domains: trymedia.com ([]http in Trusted sites)
O15 - HKLM\..Trusted Domains: trymedia.com ([]https in Trusted sites)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_05)
O16 - DPF: {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_05)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 192.168.2.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/05/24 22:39:42 | 00,000,100 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2001/07/27 15:07:38 | 00,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O32 - AutoRun File - [2004/04/30 07:01:14 | 00,000,053 | -HS- | M] () - D:\Autorun.inf – [ FAT32 ]
O32 - AutoRun File - [2007/03/29 15:00:54 | 00,000,000 | —D | M] - J:\autorun – [ FAT32 ]
O32 - AutoRun File - [2005/11/17 16:06:10 | 00,000,069 | -H– | M] () - J:\autorun.inf – [ FAT32 ]
O33 - MountPoints2\{398506f8-0a75-11df-94cb-0014a5a9f7a0}\Shell\AutoRun\command - "" = J:\WD_Windows_Tools\Setup.exe – [2007/03/13 12:08:34 | 00,208,896 | —- | M] ()
O33 - MountPoints2\{cef87f0f-0885-11df-94c7-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{cef87f0f-0885-11df-94c7-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2005/11/14 21:13:14 | 00,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (53765113575899136)
========== Files/Folders - Created Within 30 Days ==========
[2010/01/26 07:23:43 | 00,547,840 | —- | C] (OldTimer Tools) – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75\Desktop\OTL.exe
[2010/01/23 20:24:05 | 00,019,200 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\hidbatt.sys
[2010/01/23 20:24:05 | 00,014,080 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\battc.sys
[2010/01/23 19:46:55 | 00,000,000 | RHSD | C] – C:\WINDOWS\System32\dllcache
[2010/01/23 19:01:02 | 00,000,000 | —D | C] – C:\WINDOWS\System32\LogFiles
[2010/01/23 18:44:53 | 00,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75\My Documents\Symantec
[2010/01/23 18:42:56 | 00,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75\Application Data\Macromedia
[2010/01/23 18:42:54 | 00,000,000 | –SD | C] – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75\UserData
[2010/01/23 18:40:16 | 00,000,000 | RHSD | C] – C:\cmdcons
[2010/01/23 18:40:14 | 00,000,000 | —D | C] – C:\WINDOWS\setup.pss
[2010/01/23 18:39:56 | 00,000,000 | —D | C] – C:\WINDOWS\setupupd
[2010/01/23 18:39:42 | 00,000,000 | RH-D | C] – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75\Recent
[2010/01/23 18:39:07 | 00,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75\Application Data\ArcSoft
[2010/01/23 18:35:31 | 00,000,000 | –SD | C] – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75\Application Data\Microsoft
[2010/01/23 18:35:31 | 00,000,000 | –SD | C] – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75\Cookies
[2010/01/23 18:35:31 | 00,000,000 | RH-D | C] – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75\Application Data
[2010/01/23 18:35:31 | 00,000,000 | R–D | C] – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75\Favorites
[2010/01/23 18:35:31 | 00,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75\Application Data\Symantec
[2010/01/23 18:35:31 | 00,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75\Application Data\Real
[2010/01/23 18:35:31 | 00,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75\Application Data\Intuit
[2010/01/23 18:35:31 | 00,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75\Application Data\Identities
[2010/01/23 18:35:31 | 00,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75\Desktop
[2010/01/23 18:35:30 | 00,000,000 | RH-D | C] – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75\SendTo
[2010/01/23 18:35:30 | 00,000,000 | R–D | C] – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75\Start Menu
[2010/01/23 18:35:30 | 00,000,000 | R–D | C] – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75\My Documents\My Videos
[2010/01/23 18:35:30 | 00,000,000 | R–D | C] – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75\My Documents\My Pictures
[2010/01/23 18:35:30 | 00,000,000 | R–D | C] – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75\My Documents\My Music
[2010/01/23 18:35:30 | 00,000,000 | R–D | C] – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75\My Documents
[2010/01/23 18:35:30 | 00,000,000 | -H-D | C] – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75\Templates
[2010/01/23 18:35:30 | 00,000,000 | -H-D | C] – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75\PrintHood
[2010/01/23 18:35:30 | 00,000,000 | -H-D | C] – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75\NetHood
[2010/01/23 18:35:30 | 00,000,000 | -H-D | C] – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75\Local Settings
[2010/01/23 18:35:30 | 00,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75\WINDOWS
[2010/01/23 18:35:30 | 00,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75\Local Settings\Application Data\Wildtangent
[2010/01/23 18:35:30 | 00,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75\Local Settings\Application Data\Microsoft
[2010/01/23 18:35:30 | 00,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75\Local Settings\Application Data\Google
[2010/01/23 18:35:30 | 00,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75\Local Settings\Application Data\ApplicationHistory
[2010/01/23 18:35:30 | 00,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75\Local Settings\Application Data\{3248F0A6-6813-11D6-A77B-00B0D0150050}
[2010/01/23 18:31:38 | 00,000,000 | —D | C] – C:\WINDOWS\System32\SoftwareDistribution
[2010/01/03 20:00:04 | 00,137,216 | —- | C] (Microsoft Corporation) – C:\eujbmv.exe
[2010/01/03 20:00:02 | 00,025,088 | —- | C] (oVjlvHNMYbMghh) – C:\khkil.exe
[2009/12/29 12:50:17 | 00,000,000 | —D | C] – C:\WINDOWS\Hewlett-Packard
[2009/08/19 06:02:01 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple
[2009/06/27 00:52:02 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Eastman Kodak Company
[2009/03/09 15:41:45 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Webroot
[2008/11/12 09:27:24 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\McAfee
[2008/11/02 12:35:42 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\COMCASTTOOLBAR
[2006/10/04 19:40:21 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Webroot
[2006/05/24 21:35:48 | 00,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2006/05/24 21:35:48 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2006/05/24 21:35:46 | 00,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2006/05/24 21:35:46 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2006/02/19 12:28:56 | 00,012,288 | —- | C] (Hewlett-Packard Development Company, L.P.) – C:\WINDOWS\Fonts\RandFont.dll
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/01/26 07:29:56 | 01,048,576 | -H– | M] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75\NTUSER.DAT
[2010/01/26 07:27:00 | 00,000,418 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{CC6F506D-8F37-4647-8DE0-E2DD27E6F3C0}.job
[2010/01/26 07:23:00 | 00,000,970 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2548808050-2775696317-4293638226-1009UA.job
[2010/01/26 06:53:09 | 00,000,248 | —- | M] () – C:\WINDOWS\System\hpsysdrv.dat
[2010/01/26 06:32:35 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/01/26 06:32:22 | 00,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/01/26 06:32:18 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/01/26 06:32:13 | 10,646,85568 | -HS- | M] () – C:\hiberfil.sys
[2010/01/23 20:24:40 | 00,000,231 | —- | M] () – C:\WINDOWS\system.ini
[2010/01/23 19:03:54 | 00,000,178 | -HS- | M] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75\ntuser.ini
[2010/01/23 19:02:40 | 00,003,584 | —- | M] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/01/23 18:50:35 | 00,124,464 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2010/01/23 18:50:35 | 00,060,808 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\S32EVNT1.DLL
[2010/01/23 18:50:35 | 00,010,635 | —- | M] () – C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2010/01/23 18:50:35 | 00,000,806 | —- | M] () – C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2010/01/23 18:46:22 | 00,001,879 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Updates From HP.lnk
[2010/01/23 18:45:40 | 00,000,570 | —- | M] () – C:\WINDOWS\tasks\Norton AntiVirus - Run Full System Scan - HP_Administrator.job
[2010/01/23 18:40:32 | 00,382,022 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/01/23 18:40:32 | 00,053,640 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/01/23 18:40:32 | 00,000,281 | RHS- | M] () – C:\boot.ini
[2010/01/23 18:40:30 | 00,441,626 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/01/23 18:37:47 | 00,001,839 | RHS- | M] () – C:\WINDOWS\System32\drivers\103C_HP_CPC_EX262AA-ABA s7530n_YC_0Pavi_QCNH628_E63NAemMPA3_48_IOnyx2_SASUSTeK Computer INC._V1.xx_B3.06_T051028_WXP2_L409_M1016_J250_7Intel_8Pentium M_91.7_#060911_N80861064_Z11C10620_G80862582.MRK
[2010/01/23 18:37:15 | 00,001,844 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Easy Internet Sign-up.lnk
[2010/01/23 18:37:15 | 00,000,480 | —- | M] () – C:\WINDOWS\tasks\Easy Internet Sign-up.job
[2010/01/23 18:35:11 | 00,196,960 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/01/23 18:34:00 | 00,001,111 | —- | M] () – C:\WINDOWS\System32\$winnt$.inf
[2010/01/23 18:33:35 | 00,262,144 | —- | M] () – C:\Documents and Settings\All Users\NTUSER.DAT
[2010/01/23 18:32:44 | 00,000,211 | RHS- | M] () – C:\BOOT.BAK
[2010/01/23 16:23:00 | 00,000,918 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2548808050-2775696317-4293638226-1009Core.job
[2010/01/22 09:24:32 | 00,284,915 | —- | M] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75\Desktop\gmer.zip
[2010/01/22 09:23:50 | 00,547,840 | —- | M] (OldTimer Tools) – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75\Desktop\OTL.exe
[2010/01/06 07:02:02 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/01/03 20:00:39 | 00,000,001 | —- | M] () – C:\s
[2010/01/03 20:00:09 | 00,137,216 | —- | M] (Microsoft Corporation) – C:\eujbmv.exe
[2010/01/03 20:00:03 | 00,043,066 | —- | M] () – C:\qfhtgw.exe
[2010/01/03 20:00:03 | 00,025,088 | —- | M] (oVjlvHNMYbMghh) – C:\khkil.exe
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/01/26 07:23:46 | 00,284,915 | —- | C] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75\Desktop\gmer.zip
[2010/01/23 19:02:40 | 00,003,584 | —- | C] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/01/23 18:48:20 | 00,010,635 | —- | C] () – C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2010/01/23 18:48:20 | 00,000,806 | —- | C] () – C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2010/01/23 18:46:22 | 00,001,879 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Updates From HP.lnk
[2010/01/23 18:45:40 | 00,000,570 | —- | C] () – C:\WINDOWS\tasks\Norton AntiVirus - Run Full System Scan - HP_Administrator.job
[2010/01/23 18:40:28 | 00,000,211 | RHS- | C] () – C:\BOOT.BAK
[2010/01/23 18:40:21 | 00,260,272 | RHS- | C] () – C:\cmldr
[2010/01/23 18:37:44 | 00,001,839 | RHS- | C] () – C:\WINDOWS\System32\drivers\103C_HP_CPC_EX262AA-ABA s7530n_YC_0Pavi_QCNH628_E63NAemMPA3_48_IOnyx2_SASUSTeK Computer INC._V1.xx_B3.06_T051028_WXP2_L409_M1016_J250_7Intel_8Pentium M_91.7_#060911_N80861064_Z11C10620_G80862582.MRK
[2010/01/23 18:37:43 | 10,646,85568 | -HS- | C] () – C:\hiberfil.sys
[2010/01/23 18:37:15 | 00,000,480 | —- | C] () – C:\WINDOWS\tasks\Easy Internet Sign-up.job
[2010/01/23 18:35:34 | 00,000,136 | —- | C] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75\Local Settings\Application Data\fusioncache.dat
[2010/01/23 18:35:30 | 00,000,178 | -HS- | C] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75\ntuser.ini
[2010/01/23 18:35:29 | 01,048,576 | -H– | C] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75\NTUSER.DAT
[2010/01/23 18:33:31 | 00,002,088 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AOL Latino 3 Meses Incluidos.lnk
[2010/01/23 18:33:31 | 00,001,944 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AOL 3 Months Included.lnk
[2010/01/23 18:33:31 | 00,001,908 | —- | C] () – C:\Documents and Settings\All Users\Desktop\eBay.lnk
[2010/01/23 18:33:31 | 00,001,857 | —- | C] () – C:\Documents and Settings\All Users\Desktop\MSN.lnk
[2010/01/23 18:33:31 | 00,001,659 | —- | C] () – C:\Documents and Settings\All Users\Desktop\3 Month Trial AOL Music Now.lnk
[2010/01/23 18:33:31 | 00,001,540 | —- | C] () – C:\Documents and Settings\All Users\Desktop\HP Extended Service Plans.lnk
[2010/01/23 18:33:30 | 00,001,882 | —- | C] () – C:\Documents and Settings\All Users\Desktop\My HP Games.lnk
[2010/01/23 18:33:30 | 00,001,878 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Microsoft Office 2003 Edition 60 Days Trial Welcome Tour.lnk
[2010/01/23 18:33:30 | 00,001,756 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Netscape Browser.lnk
[2010/01/23 18:33:30 | 00,001,580 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Quicken New User Edition 2006.lnk
[2010/01/23 18:33:30 | 00,000,908 | —- | C] () – C:\Documents and Settings\All Users\Desktop\RealPlayer.lnk
[2010/01/23 18:33:30 | 00,000,656 | —- | C] () – C:\Documents and Settings\All Users\Desktop\HP Rhapsody.lnk
[2010/01/23 18:33:21 | 00,001,844 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Easy Internet Sign-up.lnk
[2010/01/03 20:00:39 | 00,000,001 | —- | C] () – C:\s
[2010/01/03 20:00:02 | 00,043,066 | —- | C] () – C:\qfhtgw.exe
[2009/10/04 18:53:30 | 00,000,251 | —- | C] () – C:\Program Files\wt3d.ini
[2008/12/22 10:40:46 | 00,000,043 | —- | C] () – C:\WINDOWS\spookydisplay.ini
[2007/07/05 09:11:05 | 00,000,000 | —- | C] () – C:\WINDOWS\SETUP32.INI
[2007/02/24 16:26:36 | 00,000,022 | —- | C] () – C:\WINDOWS\kodakpcd.HP_Administrator.ini
[2007/02/06 10:32:06 | 00,000,354 | —- | C] () – C:\WINDOWS\ka.ini
[2006/12/03 16:58:02 | 00,000,701 | —- | C] () – C:\WINDOWS\HEGames.ini
[2006/12/03 14:26:50 | 00,002,274 | —- | C] () – C:\WINDOWS\disney.ini
[2006/12/01 08:51:55 | 00,000,214 | —- | C] () – C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2006/10/15 20:29:52 | 00,000,964 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2006/10/04 19:40:11 | 00,684,032 | —- | C] () – C:\WINDOWS\libeay32.dll
[2006/10/04 19:40:11 | 00,155,648 | —- | C] () – C:\WINDOWS\ssleay32.dll
[2006/09/29 11:05:32 | 00,000,000 | —- | C] () – C:\WINDOWS\MSDraw.ini
[2006/09/23 16:23:21 | 00,000,000 | —- | C] () – C:\WINDOWS\PTWebCam.INI
[2006/09/17 15:14:58 | 00,000,067 | —- | C] () – C:\WINDOWS\encore_launcher.ini
[2006/09/17 14:37:52 | 00,000,434 | —- | C] () – C:\WINDOWS\Operation.ini
[2006/09/13 19:19:01 | 00,000,227 | —- | C] () – C:\WINDOWS\HP_CounterReport_Update_HPSU.ini
[2006/09/13 18:57:53 | 00,000,206 | —- | C] () – C:\WINDOWS\HPGdiPlus.ini
[2006/09/12 17:44:32 | 00,000,489 | —- | C] () – C:\WINDOWS\lexstat.ini
[2006/05/24 23:11:09 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/05/24 22:48:03 | 00,028,848 | —- | C] () – C:\WINDOWS\System32\drivers\USBkey.sys
[2006/05/24 22:42:43 | 00,014,317 | —- | C] () – C:\WINDOWS\System32\CHODDI.SYS
[2006/05/24 22:42:32 | 00,045,056 | —- | C] () – C:\WINDOWS\System32\hpreg.dll
[2006/05/24 22:39:59 | 00,000,174 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2006/05/24 22:37:15 | 00,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/05/24 22:25:39 | 00,000,157 | —- | C] () – C:\WINDOWS\WININIT.INI
[2006/05/24 22:25:00 | 00,000,698 | —- | C] () – C:\WINDOWS\NSSetDefaultBrowser.ini
[2006/05/24 22:09:28 | 00,001,703 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2006/05/24 22:08:19 | 00,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2006/05/24 22:03:58 | 00,000,791 | —- | C] () – C:\WINDOWS\orun32.ini
[2006/05/24 21:39:13 | 00,323,584 | —- | C] () – C:\WINDOWS\System32\pythoncom22.dll
[2006/05/24 21:39:13 | 00,094,208 | —- | C] () – C:\WINDOWS\System32\pywintypes22.dll
[2006/05/24 21:38:53 | 00,016,896 | —- | C] () – C:\WINDOWS\System32\bcbmm.dll
[2006/03/17 19:23:44 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2005/08/05 23:01:54 | 00,239,104 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2005/08/03 01:19:16 | 00,050,176 | —- | C] () – C:\WINDOWS\armcex.dll
[2004/08/09 23:00:00 | 00,081,920 | —- | C] () – C:\WINDOWS\System32\ieencode.dll
[2004/08/09 23:00:00 | 00,027,440 | —- | C] () – C:\WINDOWS\System32\drivers\secdrv.sys
[2004/07/26 09:51:38 | 00,000,560 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2003/01/08 00:05:08 | 00,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2001/07/07 00:30:00 | 00,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini
========== LOP Check ==========
[2008/11/09 19:33:24 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BVRP Software
[2008/11/12 15:40:22 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Comcast
[2006/05/24 22:23:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Digital Interactive Systems Corporation
[2009/06/27 01:02:37 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Eastman Kodak Company
[2009/08/03 15:33:14 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\kds_kodak
[2009/11/24 16:35:07 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LightScribe
[2009/11/13 11:19:43 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSScanAppDataDir
[2007/09/17 05:09:13 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\muvee Technologies
[2009/10/12 19:18:59 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nova Development
[2009/10/04 18:53:23 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Otto
[2008/11/23 07:55:21 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sony
[2008/10/31 09:51:53 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SupportSoft
[2009/04/07 20:07:45 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2010/01/23 18:37:15 | 00,000,480 | —- | M] () – C:\WINDOWS\Tasks\Easy Internet Sign-up.job
[2008/11/09 21:47:14 | 00,000,362 | —- | M] () – C:\WINDOWS\Tasks\McDefragTask.job
[2009/12/01 02:24:13 | 00,000,354 | —- | M] () – C:\WINDOWS\Tasks\McQcTask.job
[2010/01/26 07:27:00 | 00,000,418 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{CC6F506D-8F37-4647-8DE0-E2DD27E6F3C0}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
[2010/01/03 20:00:09 | 00,137,216 | —- | M] (Microsoft Corporation) – C:\eujbmv.exe
[2010/01/03 20:00:03 | 00,025,088 | —- | M] (oVjlvHNMYbMghh) – C:\khkil.exe
[2010/01/03 20:00:03 | 00,043,066 | —- | M] () – C:\qfhtgw.exe
[2005/10/31 10:56:00 | 00,700,416 | —- | M] (LimeWire) – C:\StubInstaller.exe
< MD5 for: AGP440.SYS >
[2004/08/10 06:00:00 | 16,971,599 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008/11/02 11:17:40 | 23,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2004/08/09 16:00:00 | 16,971,599 | —- | M] () .cab file – C:\WINDOWS\I386\sp2.cab:AGP440.sys
[2008/11/02 11:17:40 | 23,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 13:36:38 | 00,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
< MD5 for: ATAPI.SYS >
[2004/08/10 06:00:00 | 16,971,599 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008/11/02 11:17:40 | 23,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2004/08/09 16:00:00 | 16,971,599 | —- | M] () .cab file – C:\WINDOWS\I386\sp2.cab:atapi.sys
[2008/11/02 11:17:40 | 23,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/13 13:40:30 | 00,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2004/08/04 00:59:44 | 00,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2004/08/04 07:59:44 | 00,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\system32\dllcache\atapi.sys
[2004/08/04 07:59:44 | 00,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/09 23:00:00 | 00,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\system32\ReinstallBackups\0009\DriverFiles\i386\atapi.sys
[2004/08/04 07:59:44 | 00,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\system32\ReinstallBackups\0010\DriverFiles\i386\atapi.sys
< MD5 for: EVENTLOG.DLL >
[2008/04/13 19:11:53 | 00,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2004/08/09 16:00:00 | 00,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
[2004/08/09 23:00:00 | 00,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\system32\dllcache\eventlog.dll
[2004/08/09 23:00:00 | 00,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\system32\eventlog.dll
< MD5 for: IASTOR.SYS >
[2005/06/17 08:33:40 | 00,872,064 | —- | M] (Intel Corporation) MD5=9A65E42664D1534B68512CAAD0EFE963 – C:\hp\drivers\Intel_5_1_0_1022_PV\iastor.sys
[2005/06/17 08:33:40 | 00,872,064 | —- | M] (Intel Corporation) MD5=9A65E42664D1534B68512CAAD0EFE963 – C:\WINDOWS\system32\drivers\iaStor.sys
< MD5 for: NETLOGON.DLL >
[2008/04/13 19:12:01 | 00,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2004/08/09 16:00:00 | 00,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
[2004/08/09 23:00:00 | 00,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\system32\dllcache\netlogon.dll
[2004/08/09 23:00:00 | 00,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\system32\netlogon.dll
< MD5 for: SCECLI.DLL >
[2004/08/09 16:00:00 | 00,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2004/08/09 23:00:00 | 00,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\system32\dllcache\scecli.dll
[2004/08/09 23:00:00 | 00,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\system32\scecli.dll
[2008/04/13 19:12:05 | 00,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[2005/07/26 06:39:44 | 01,267,200 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\comsvcs.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles >
< End of report >
I need for you to locate a file on your desktop named: Extras.txt
Please post the contents of this file in your next reply.
Next:
OTL Fix
Run OTL.exe
- Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL
:Reg [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] ""=- :OTL O4 - HKLM..\Run: [PCDrProfiler] File not found O15 - HKLM\..Trusted Domains: trymedia.com ([]http in Trusted sites) O15 - HKLM\..Trusted Domains: trymedia.com ([]https in Trusted sites) O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone. O33 - MountPoints2\{398506f8-0a75-11df-94cb-0014a5a9f7a0}\Shell\AutoRun\command - "" = J:\WD_Windows_Tools\Setup.exe – [2007/03/13 12:08:34 | 00,208,896 | —- | M] () [2010/01/03 20:00:04 | 00,137,216 | —- | C] (Microsoft Corporation) – C:\eujbmv.exe [2010/01/03 20:00:02 | 00,025,088 | —- | C] (oVjlvHNMYbMghh) – C:\khkil.exe [2010/01/03 20:00:39 | 00,000,001 | —- | M] () – C:\s [2010/01/03 20:00:03 | 00,043,066 | —- | M] () – C:\qfhtgw.exe :Commands [emptytemp] [start explorer] [Reboot] - Then click the Run Fix button at the top
- Let the program run unhindered, reboot when it is done
- Then post a new OTL log (don't check the boxes beside LOP Check or Purity this time)
I would like for you to run GMER. I'll include directions for how to run it below:
Scanning with GMER
Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.
[external image: Posted Image]
- Extract the contents of the zipped file to desktop.
- Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
- If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
[external image: Posted Image]
Click the image to enlarge it
- In the right panel, you will see several boxes that have been checked. Uncheck the following …
- Sections
- IAT/EAT
- Drives/Partition other than Systemdrive (typically C:\)
- Show All (don't miss this one)
- Then click the Scan button & wait for it to finish.
- Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
- Save it where you can easily find it, such as your desktop, and attach it in your reply.
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Next:
Please make sure you include the following items in your next post:
1. The contents of the Extras.txt file.
2. The log that was produced after running OTL.
3. The log that was produced after running GMER.
4. An update on how your computer is currently running.
Download ComboFix from one of the following locations:
Link 1
Link 2
VERY IMPORTANT !!! Save ComboFix.exe to your Desktop
* IMPORTANT - Disable your Anti-Virus and Anti-Spyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
- Double click on ComboFix.exe & follow the prompts.
- Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
[external image: Posted Image]
- Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
[external image: Posted Image]
- Click on Yes, to continue scanning for malware.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
Please make sure you include the ComboFix log in your next reply as well as describe how your computer is running now
OTL Extras logfile created on: 1/26/2010 7:27:02 AM - Run 1
OTL by OldTimer - Version 3.1.25.4 Folder = C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75\Desktop
Windows XP Media Center Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1,015.00 Mb Total Physical Memory | 539.00 Mb Available Physical Memory | 53.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 84.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 224.12 Gb Total Space | 51.27 Gb Free Space | 22.87% Space Free | Partition Type: NTFS
Drive D: | 8.74 Gb Total Space | 0.44 Gb Free Space | 5.06% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive J: | 298.02 Gb Total Space | 97.53 Gb Free Space | 32.72% Space Free | Partition Type: FAT32
Computer Name: YOUR-4DACD0EA75
Current User Name: HP_Administrator
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 1
"FirewallDisableNotify" = 1
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe" = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe:*:Enabled:Updates from HP – (Hewlett-Packard)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe" = C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe – ()
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe – ( )
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe:*:Enabled:hpqnrs08.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\DISC\DISCover.exe" = C:\Program Files\DISC\DISCover.exe:*:Enabled:DISCover Drop & Play System – (Digital Interactive Systems Corporation)
"C:\Program Files\DISC\DiscStreamHub.exe" = C:\Program Files\DISC\DiscStreamHub.exe:*:Enabled:DISCover Stream Hub – (Digital Interactive Systems Corporation, Inc.)
"C:\Program Files\DISC\myFTP.exe" = C:\Program Files\DISC\myFTP.exe:*:Enabled:DISCover FTP – (Digital Interactive Systems Corporation, Inc.)
"C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe" = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe:*:Enabled:Updates from HP – (Hewlett-Packard)
"C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" = C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink – File not found
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{075473F5-846A-448B-BCB3-104AA1760205}" = Sonic RecordNow Data
"{0A65A3BD-54B5-4d0d-B084-7688507813F5}" = SlideShow
"{0B33B738-AD79-4E32-90C5-E67BFB10BBFF}" = AiO_Scan
"{0BF5FBE7-3907-4A1F-9E48-8B66E52850D6}" = TrayApp
"{1248C09A-BD6B-47F5-BF3F-CD2B700D9FCB}" = ccCommon
"{12E2B9E9-05B1-407d-B0FD-B5F350535125}" = Norton Internet Security
"{1341D838-719C-4A05-B50F-49420CA1B4BB}" = HP Boot Optimizer
"{15C0AF59-4877-49B6-B8C6-A61CE54515F5}" = cp_OnlineProjectsConfig
"{1E1F1E70-14D8-4380-8652-BD1A895A7D65}" = Status
"{21657574-BD54-48A2-9450-EB03B2C7FC29}" = Sonic MyDVD Plus
"{23012310-3E05-46A5-88A9-C6CBCABCAC79}" = Customer Experience Enhancement
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2376813B-2E5A-4641-B7B3-A0D5ADB55229}" = HPPhotoSmartExpress
"{27428D1B-8CBA-4EEA-B9C0-A23CA7B4FCC1}" = muvee autoProducer 5.0
"{2818095F-FB6C-42C8-827E-0A406CC9AFF5}" = Quicken 2006
"{2C5D07FB-31A2-4F2D-9FDA-0B24ACD42BD0}" = HP Deskjet Printer Preload
"{2EBF25F1-F8A2-40EA-92BE-931C142A44E2}" = CC_ccProxyExt
"{2F58D60D-2BFD-4467-9B4D-64E7355C329D}" = Sonic_PrimoSDK
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
"{30738666-9805-4926-A78F-91DA33B6C437}" = ccPxyCore
"{31263605-FC84-4787-B847-BA445B147E24}" = ScannerCopy
"{3248F0A8-6813-11D6-A77B-00B0D0150050}" = J2SE Runtime Environment 5.0 Update 5
"{33BF0960-DBA3-4187-B6CC-C969FCFA2D25}" = SkinsHP1
"{33D6CC28-9F75-4d1b-A11D-98895B3A3729}" = HP Photosmart 330,380,420,470,7800,8000,8200 Series
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{352F5013-07DC-446D-8DB6-38F339086C60}" = LightScribe 1.4.84.1
"{3672B097-EA69-4bfe-B92F-29AE6D9D2B34}" = Norton Internet Security
"{36D620AD-EEBA-4973-BA86-0C9AE6396620}" = OptionalContentQFolder
"{3CF99DC3-38FD-46E6-A6B4-9C70074E020C}" = DocumentViewer
"{416D80BA-6F6D-4672-B7CF-F54DA2F80B44}" = Microsoft Works
"{41E776A5-9B12-416D-9A12-B4F7B044EBED}" = CP_Package_Basic1
"{449F3A9E-9903-4a0d-A209-08030D45A935}" = Norton Internet Security
"{45B8A76B-57EC-4242-B019-066400CD8428}" = BufferChm
"{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP DVD Play 2.1
"{48185814-A224-447a-81DA-71BD20580E1B}" = Norton Internet Security
"{4BE53DB2-C1F2-44D1-A9AB-1630BA7F2AF1}" = SolutionCenter
"{54E3707F-808E-4fd4-95C9-15D1AB077E5D}" = NewCopy
"{5677563D-0CB1-485F-9E18-C5025306BB3F}" = Norton AntiSpam
"{5B79CFD1-6845-4158-9D7D-6BE89DF2C135}" = HP PSC & OfficeJet 5.3.B
"{5D61626A-BD55-4e42-82EE-4AE89D8FD050}" = HP Photosmart Cameras 6.0
"{5FDD0538-C67A-4F67-B3F8-09D1AAF04D99}" = muvee autoProducer unPlugged 2.0
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Sonic Express Labeler
"{6696D9A4-28A8-4F5A-8E9A-2E8974C8C39C}" = RandMap
"{68763C27-235D-4165-A961-FDEA228CE504}" = AiOSoftwareNPI
"{6A118C80-B382-41c0-8907-CDD0BF5EFE6E}" = CameraDrivers
"{729DF902-05F9-4C00-9E6D-411119824E5F}" = hpiCamDrvQFolder
"{736C803C-DD3B-4015-BC51-AFB9E67B9076}" = Readme
"{755EC5E3-FD51-46bd-A57F-7A2D56FBF061}" = PSTAPlugin
"{769A295C-DCF4-41d6-AFBA-7D9394B23AFE}" = PSPrinters08
"{77772678-817F-4401-9301-ED1D01A8DA56}" = SPBBC
"{7850A6D2-CBEA-4728-9877-F1BEDEA9F619}" = AiOSoftware
"{8105684D-8CA6-440D-8F58-7E5FD67A499D}" = Easy Internet Sign-up
"{82081779-4175-4666-A457-AB711CD37EF0}" = cp_LightScribeConfig
"{829DAAD6-BB11-4BB7-921B-07FFB703F944}" = CP_Package_Variety3
"{82A5BF38-8461-4A5C-B2C9-24F5256D92A6}" = Norton Protection Center
"{82E55892-6FFD-403F-AA97-D726846768AA}" = CP_AtenaShokunin1Config
"{866A0078-DEA7-4348-9C9A-999AF2991EAA}" = SlideShowMusic
"{8A534F71-3202-4464-A422-B767295E67B9}" = CP_Package_Variety2
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver
"{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}" = Unload
"{91120409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Standard Edition 2003
"{93E5A317-24EC-4744-812C-16FECFE86E6A}" = CP_Package_Variety1
"{A01FC76F-CC09-4658-9E37-5C2F635EE708}" = Microsoft Office 2003 Edition 60 Days Trial Welcome Tour
"{A29800BA-0BF1-4E63-9F31-DF05A87F4104}" = InstantShareDevices
"{A3455242-DAE0-4523-8242-FD82706ABF4B}" = CameraDrivers
"{A93C9E60-29B6-49da-BA21-F70AC6AADE20}" = Norton Internet Security
"{AADFE0B9-F905-4d5f-A144-0ADB2EFA747B}" = Norton Internet Security
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Sonic RecordNow Audio
"{AC76BA86-7AD7-1033-7B44-A70500000002}" = Adobe Reader 7.0.5
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Sonic RecordNow Copy
"{B2157760-AA3C-4E2E-BFE6-D20BC52495D9}" = cp_PosterPrintConfig
"{B6286A44-7505-471A-A72B-04EC2DB2F442}" = CueTour
"{B69CFE29-FD03-4E0A-87A7-6ED97F98E5B3}" = CP_Panorama1Config
"{B7C61755-DB48-4003-948F-3D34DB8EAF69}" = MSRedist
"{B9DD2DE0-27BE-4e6b-AAD8-0D960ABF87FD}" = CameraUserGuides
"{BB85ED9C-AFC9-43BD-B8DC-258C3C7DF72E}" = HP Software Update
"{BF4E9ED0-EF26-4A4C-A123-6A6A1ABEE411}" = DocProc
"{C0F00024-FC80-4B13-A0D0-81154ACF03AD}" = SymNet
"{C1C6767D-B395-43CB-BF99-051B58B86DA6}" = PhotoGallery
"{C3FAA091-B278-44A7-BF48-190811C5F9F7}" = cp_UpdateProjectsConfig
"{C6812939-B117-48E6-A3BA-1709C14A3C8C}" = Scan
"{C6F5B6CF-609C-428E-876F-CA83176C021B}" = Norton AntiVirus 2006
"{C8753E28-2680-49BF-BD48-DD38FD086EFE}" = AiO_Scan_CDA
"{C98E8D9D-21DE-4F87-A9B7-142BB89840FC}" = Toolbox
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE24344F-DFD8-40C8-8FD8-C9740B5F25AC}" = Fax
"{DAAD5187-62C5-4AD6-A526-803C18C4944D}" = HP Web Helper
"{DB518BA6-CB74-4EB6-9ABD-880B6D6E1F38}" = HpSdpAppCoreApp
"{DBA4DB9D-EE51-4944-A419-98AB1F1249C8}" = LiveUpdate Notice (Symantec Corporation)
"{DEBB2986-15B0-4D28-95FA-5C966A396589}" = HPProductAssistant
"{E3EFA461-EB83-4C3B-9C47-2C1D58A01555}" = Norton Internet Security
"{E5A1DE9A-A21C-43A1-B06D-5146BAF62033}" = PanoStandAlone
"{E5A8DDAB-AE80-48C6-A75B-D0FAB83B299D}" = HP PSC & OfficeJet 6.1.A
"{E5EE9939-259F-4DE2-8023-5C49E16A4F43}" = Norton Internet Security
"{E85FA9A1-C241-4698-893B-DD99509B8DB0}" = Norton WMI Update
"{EC2715CE-C182-483C-84CC-81D7D914CF14}" = WebReg
"{ED2C557E-9C18-41FF-B58E-A05EEF0B3B5F}" = CP_CalendarTemplates1
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F6076EF9-08E1-442F-B6A2-BFB61B295A14}" = Fax_CDA
"{F64306A5-4C32-41bb-B153-53986527FAB4}" = Norton WMI Update
"{F80239D8-7811-4D5E-B033-0D0BBFE32920}" = HP DigitalMedia Archive
"{FB15E224-67C3-491F-9F5C-F257BC418412}" = Destinations
"{FBB980B0-63F8-4B48-8D65-90F1D9F81D9F}" = NewCopy_CDA
"{FFB4DD53-28B7-4981-BFF0-9BD801F61095}" = Norton Internet Security
"12133444-BF36-4d4e-B7FB-A3424C645DE4" = GemMaster Mystic
"Agere Systems Soft Modem" = Agere Systems PCI-SV92PP Soft Modem
"AwayMode160" = Microsoft Away Mode
"B3EE3001-DC24-4cd1-8743-5692C716659F" = Otto
"CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200C14F1" = Data Fax SoftModem with SmartCP
"DISCover" = DISCover
"HP Document Viewer" = HP Document Viewer 6.1
"HP Game Console" = HP Game Console
"HP Imaging Device Functions" = HP Imaging Device Functions 7.0
"HP Photo & Imaging" = HP Photosmart Premier Software 6.5
"HP Photosmart for Media Center PC" = HP Photosmart for Media Center PC
"HP Rhapsody" = HP Rhapsody
"HP Solution Center & Imaging Support Tools" = HP Solution Center and Imaging Support Tools 6.1
"HPOOVClient-9972322 Uninstaller" = Updates from HP (remove only)
"InstallShield_{23012310-3E05-46A5-88A9-C6CBCABCAC79}" = Customer Experience Enhancement
"InstallShield_{8105684D-8CA6-440D-8F58-7E5FD67A499D}" = Easy Internet Sign-up
"LiveUpdate" = LiveUpdate 3.0 (Symantec Corporation)
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Money2006b" = Microsoft Money 2006
"Netscape Browser" = Netscape Browser (remove only)
"PC-Doctor 5 for Windows" = PC-Doctor 5 for Windows
"PROSet" = Intel® PRO Network Connections Drivers
"Python 2.2.3" = Python 2.2.3
"pywin32-py2.2" = Python 2.2 pywin32 extensions (build 203)
"RealPlayer 6.0" = RealPlayer
"SymSetup.{A93C9E60-29B6-49da-BA21-F70AC6AADE20}" = Norton Internet Security 2006 (Symantec Corporation)
"WildTangent CDA" = WildTangent Web Driver
"Windows Media Format Runtime" = Windows Media Format Runtime
"WT004613" = Tornado Jockey
"WT005513" = Super Granny
"WT005515" = Polar Bowler
"WT005517" = Blasterball 2 Remix
"WT005518" = Polar Golfer
"WT005519" = Ricochet Lost Worlds
"WT005520" = Blackhawk Striker 2
"WT005521" = Blasterball 2 Revolution
"WT005523" = Tradewinds
"WT005524" = Bounce Symphony
"WT005630" = Alien Outbreak 2
"WT005631" = Fairies
"WT005632" = Snowy The Bears Adventure
"WT005634" = Bejeweled 2 Deluxe
"WT005635" = Big Kahuna Reef
"WT005636" = Bookworm Deluxe
"WT005637" = Chuzzle Deluxe
"WT005638" = Diner Dash
"WT005639" = Family Feud
"WT005640" = Flip Words
"WT005641" = Insaniquarium Deluxe
"WT005642" = Jewel Quest
"WT005643" = Mah Jong Quest
"WT005644" = Mystery Case Files
"WT005645" = Poker Superstars
"WT005646" = SCRABBLE
"WT005647" = Slingo Deluxe
"WT005648" = Tennis Titans
"WT006069" = FATE
"WT006072" = Ancient Sudoku
< End of report >
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI