This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Cannot Auto Update and Popups

28 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Two days ago (I think) MY wife was browsing on IE and got lots of error messages (I don't know what they were something about an invalid image or bad image)
I told her to do a system restore to the latest date.
This got rid of the error messages, but now…
Whether in Firefox or IE, I get pop-ups every minute or so.
AVG immediately deletes something but they keep coming back.
Around the same time Auto updates turned off and every time I turn them on they turn right back off.

It's been a while since I've been on there use to be a HighJack This Thread, but I didn't see it. At any rate if HJT is still used, here it is. It is quite possible that mine is out of date… Sorry if this is the case.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:20:45 PM, on 2/9/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\arservice.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\PSIService.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\rasesnet.tmp
C:\WINDOWS\system32\net.net
C:\WINDOWS\system32\mshta.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://swagbucks.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
R3 - URLSearchHook: Swag Bucks Toolbar - {8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94} - C:\Program Files\Swag_Bucks\tbSwa1.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Swag Bucks Toolbar - {8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94} - C:\Program Files\Swag_Bucks\tbSwa1.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll
O3 - Toolbar: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Swag Bucks Toolbar - {8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94} - C:\Program Files\Swag_Bucks\tbSwa1.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Monitor] "C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe"
O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [jedugikuf] Rundll32.exe "c:\windows\system32\hazafupe.dll",a
O4 - HKLM\..\Run: [net] "C:\WINDOWS\system32\net.net"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.trymedia.com (HKLM)
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/betapit/PCPitStop.CAB
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/Risk/Images/stg_drm.ocx
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} (PogoWebLauncher Control) - http://www.pogo.com/cdl/launcher/PogoWebLa…erInstaller.CAB
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
O16 - DPF: {45A0A292-ECC6-4D8F-9EA9-A4BD411D24C1} (king.com) - http://www.king.com/ctl/kingcomie.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {54BE6B6F-3056-470B-97E1-BB92E051B6C4} (DeviceEnum Class) - http://h20264.www2.hp.com/ediags/dd/instal…nosticsxp2k.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.0…oUploader55.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} (CBSTIEPrint Class) - http://offers.e-centives.com/cif/download/bin/actxcab.cab
O16 - DPF: {BE319D04-18BD-4B34-AECC-EE7CB610FCA9} (BewitchedGameClass Control) - http://download.games.yahoo.com/games/web_…itched/main.cab
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/Monopoly/Images/armhelper.ocx
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/hpdj/en/check/qdiagh.cab?326
O16 - DPF: {F137B9BA-89EA-4B04-9C67-2074A9DF61FD} (Photo Upload Plugin Class) - http://cvs.pnimedia.com/upload/activex/v2_…upv2.0.0.10.cab?
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (DownloadManager Control) - http://dlm.tools.akamai.com/dlmanager/vers…ivex-latest.cab
O18 - Protocol: intu-help-qb2 - {84D77A00-41B5-4B8B-8ADF-86486D72E749} - C:\Program Files\Intuit\QuickBooks 2009\HelpAsyncPluggableProtocol.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)
O20 - AppInit_DLLs: c:\windows\system32\libukifu.dll c:\windows\system32\hazafupe.dll,moyomego.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O21 - SSODL: wukatuhow - {b8dd6e4d-809f-412f-a2a2-cc3789aa7f12} - c:\windows\system32\libukifu.dll (file missing)
O21 - SSODL: kaludafap - {141a9890-8ffc-4f80-92b7-7b9b6d992846} - c:\windows\system32\hazafupe.dll
O22 - SharedTaskScheduler: kupuhivus - {b8dd6e4d-809f-412f-a2a2-cc3789aa7f12} - c:\windows\system32\libukifu.dll (file missing)
O22 - SharedTaskScheduler: tokatiluy - {141a9890-8ffc-4f80-92b7-7b9b6d992846} - c:\windows\system32\hazafupe.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LeapFrog Connect Device Service - Unknown owner - C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: QBCFMonitorService - Intuit - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

–
End of file - 14106 bytes
Hi Amebeo, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.


I do see some vundo hopping around in there.


Download and save to your desktop Malwarebytes Anti-Malware

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.




Download OTL to your desktop.
  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.

No need for a Hijackthis log this time.

Please post back with
  • MBAM log
  • both OTL logs
Are you experiencing any browser or search redirects?

How's the computer?

Thanks
There have been no redirects; only pop-ups.

The computer is running fair other than that… A little slow at times, but in general no other complaints.

The mbam.exe scan…

Unable to execute file:
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe

CreateProcess failed; code 2
The system cannot find the file specified.

I recall having problems with mbam in the past… not sure if this is the same error… I think I had trouble updating mbam in the past.

OTL logfile created on: 2/9/2010 9:15:24 PM - Run 1
OTL by OldTimer - Version 3.1.28.0 Folder = C:\Documents and Settings\HP_Administrator\Desktop\Neil's Shortcuts\PC Upkeep\Setups
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

958.00 Mb Total Physical Memory | 327.00 Mb Available Physical Memory | 34.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 72.00% Paging File free
Paging file location(s): C:\pagefile.sys 1440 2880 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 177.79 Gb Total Space | 79.14 Gb Free Space | 44.51% Space Free | Partition Type: NTFS
Drive D: | 8.50 Gb Total Space | 1.12 Gb Free Space | 13.13% Space Free | Partition Type: FAT32
Drive E: | 326.31 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: NEIL
Current User Name: HP_Administrator
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\HP_Administrator\Desktop\Neil's Shortcuts\PC Upkeep\Setups\OTL.exe File not found
PRC - C:\WINDOWS\system32\net.net ()
PRC - C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe ()
PRC - C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe ()
PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (Intuit)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
PRC - C:\WINDOWS\system32\PSIService.exe ()
PRC - C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
PRC - C:\Program Files\Sony\SonicStage\SSAAD.exe ()
PRC - C:\WINDOWS\system32\ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\WINDOWS\arservice.exe (Microsoft)
PRC - C:\Program Files\Hewlett-Packard\HP Software Update\hpwuSchd2.exe (Hewlett-Packard Co.)


========== Modules (SafeList) ==========

MOD - C:\WINDOWS\system32\hazafupe.dll ()
MOD - C:\WINDOWS\system32\moyomego.dll ()


========== Win32 Services (SafeList) ==========

SRV - (gupdate) Google Update Service (gupdate) – C:\Program Files\Google\Update\GoogleUpdate.exe (Google Inc.)
SRV - (iPod Service) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (avg8emc) – C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg8wd) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (LeapFrog Connect Device Service) – C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe ()
SRV - (gusvc) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (Bonjour Service) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (vsmon) – C:\WINDOWS\System32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
SRV - (QBCFMonitorService) – C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (Intuit)
SRV - (QBFCService) – C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe (Intuit Inc.)
SRV - (Viewpoint Manager Service) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (ProtexisLicensing) – C:\WINDOWS\system32\PSIService.exe ()
SRV - (SSScsiSV) – C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe (Sony Corporation)
SRV - (MSCSPTISRV) – C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe (Sony Corporation)
SRV - (PACSPTISVR) – C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe (Sony Corporation)
SRV - (SPTISRV) – C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe (Sony Corporation)
SRV - (LightScribeService) – C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
SRV - (RMSvc) – C:\WINDOWS\ehome\RMSvc.exe (Microsoft Corporation)
SRV - (AdobeActiveFileMonitor4.0) – C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe ()
SRV - (Ati HotKey Poller) – C:\WINDOWS\system32\ati2evxx.exe (ATI Technologies Inc.)
SRV - (ARSVC) – C:\WINDOWS\arservice.exe (Microsoft)
SRV - (IDriverT) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (ose) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (AvgLdx86) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (FlyUsb) – C:\WINDOWS\system32\drivers\FlyUsb.sys (LeapFrog)
DRV - (AvgTdiX) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (GEARAspiWDM) – C:\WINDOWS\system32\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (vsdatant) – C:\WINDOWS\system32\vsdatant.sys (Check Point Software Technologies LTD)
DRV - (srescan) – C:\WINDOWS\system32\ZoneLabs\srescan.sys (Check Point Software Technologies LTD)
DRV - (GcKernel) – C:\WINDOWS\system32\drivers\gckernel.sys (Microsoft Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (atapi) – C:\WINDOWS\system32\DRIVERS\atapi.sys ()
DRV - (Secdrv) – C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (SDTHOOK) – C:\WINDOWS\system32\drivers\SDTHOOK.SYS (Panda Software)
DRV - (PxHelp20) – C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (Ps2) – C:\WINDOWS\system32\drivers\PS2.sys (Hewlett-Packard Company)
DRV - (ftsata2) – C:\WINDOWS\system32\DRIVERS\ftsata2.sys (Promise Technology, Inc.)
DRV - (iaStor) – C:\WINDOWS\system32\DRIVERS\iaStor.sys (Intel Corporation)
DRV - (AmdK8) – C:\WINDOWS\system32\drivers\AmdK8.sys (Advanced Micro Devices)
DRV - (HPZius12) – C:\WINDOWS\system32\drivers\HPZius12.sys (HP)
DRV - (HPZipr12) – C:\WINDOWS\system32\drivers\HPZipr12.sys (HP)
DRV - (HPZid412) – C:\WINDOWS\system32\drivers\HPZid412.sys (HP)
DRV - (RTL8023xp) – C:\WINDOWS\system32\drivers\Rtlnicxp.sys (Realtek Semiconductor Corporation )
DRV - (HSFHWBS2) – C:\WINDOWS\system32\drivers\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) – C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (AFS2K) – C:\WINDOWS\system32\drivers\AFS2K.SYS (Oak Technology Inc.)
DRV - (2WIREPCP) – C:\WINDOWS\system32\drivers\2WirePCP.sys (2Wire, Inc.)
DRV - (Ptilink) – C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)
DRV - (rtl8139) Realtek RTL8139(A/B/C) – C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)
DRV - (MDC8021X) AEGIS Protocol (IEEE 802.1x) – C:\WINDOWS\system32\drivers\mdc8021x.sys (Meetinghouse Data Communications)
DRV - (mdmxsdk) – C:\WINDOWS\system32\drivers\mdmxsdk.sys (Conexant)
DRV - (cdrbsdrv) – C:\WINDOWS\system32\drivers\CDRBSDRV.SYS (B.H.A Corporation)
DRV - (bb-run) – C:\WINDOWS\system32\DRIVERS\bb-run.sys (Promise Technology, Inc.)
DRV - (sonypvs1) – C:\WINDOWS\system32\drivers\sonypvs1.sys (Sony Corporation)
DRV - (SWUSBFLT) – C:\WINDOWS\system32\drivers\SWUSBFLT.SYS (Microsoft Corporation)
DRV - (HIDSwvd) – C:\WINDOWS\system32\drivers\hidswvd.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://swagbucks.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94} - C:\Program Files\Swag_Bucks\tbSwa1.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://swagbucks.com/?cmd=home"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.1.3
FF - prefs.js..extensions.enabledItems: [removed]:1.11.6
FF - prefs.js..extensions.enabledItems: {99B98C2C-7274-45a3-A640-D9DF1A1C8460}:1.4
FF - prefs.js..extensions.enabledItems: {35106bca-6c78-48c7-ac28-56df30b51d2d}:1.2.4
FF - prefs.js..network.proxy.no_proxies_on: "*.local"

FF - HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/02/08 22:40:14 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/02/08 22:40:14 | 000,000,000 | —D | M]

[2009/07/26 08:19:14 | 000,000,000 | —D | M] – C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Extensions
[2009/07/26 08:19:14 | 000,000,000 | —D | M] – C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Extensions\[removed]
[2010/02/09 12:02:49 | 000,000,000 | —D | M] – C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\y836keys.default\extensions
[2010/02/08 22:48:36 | 000,000,000 | —D | M] (PopupMaster) – C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\y836keys.default\extensions\{35106bca-6c78-48c7-ac28-56df30b51d2d}
[2010/02/08 22:47:12 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\y836keys.default\extensions\{6614d11d-d21d-b211-ae23-815234e1ebb5}
[2010/02/08 22:46:42 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\y836keys.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2010/02/08 22:48:36 | 000,000,000 | —D | M] (CookieCuller) – C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\y836keys.default\extensions\{99B98C2C-7274-45a3-A640-D9DF1A1C8460}
[2010/02/08 20:10:41 | 000,000,000 | —D | M] (Adblock Plus) – C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\y836keys.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009/10/16 23:07:21 | 000,000,000 | —D | M] – C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\y836keys.default\extensions\[removed]
[2010/02/08 22:39:14 | 000,000,000 | —D | M] – C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\y836keys.default\extensions\[removed]
[2009/11/06 17:38:45 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/01/18 22:21:34 | 000,393,216 | —- | M] (Invenda Corporation) – C:\Program Files\Mozilla Firefox\plugins\NPcol400.dll
[2008/06/18 01:43:04 | 000,086,016 | —- | M] (Coupons, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
[2009/03/18 09:03:40 | 000,214,272 | —- | M] (Midasplayer Ltd) – C:\Program Files\Mozilla Firefox\plugins\npmidas.dll
[2007/04/16 12:07:12 | 000,180,293 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\npViewpoint.dll

O1 HOSTS File: ([2004/08/10 14:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Yahoo! IE Services Button) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Swag Bucks Toolbar) - {8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94} - C:\Program Files\Swag_Bucks\tbSwa1.dll (Conduit Ltd.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Swag Bucks Toolbar) - {8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94} - C:\Program Files\Swag_Bucks\tbSwa1.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Yahoo! ¤u¨ã¦C) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Swag Bucks Toolbar) - {8BDEA9D6-6F62-45EB-8EE9-8A81AF0D2F94} - C:\Program Files\Swag_Bucks\tbSwa1.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! ¤u¨ã¦C) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\hpwuSchd2.exe (Hewlett-Packard Co.)
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [jedugikuf] C:\WINDOWS\System32\hazafupe.DLL ()
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [Monitor] C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe ()
O4 - HKLM..\Run: [net] C:\WINDOWS\System32\net.net ()
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask.exe (Apple Inc.)
O4 - HKLM..\Run: [SsAAD.exe] C:\Program Files\Sony\SonicStage\SSAAD.exe ()
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll (Google Inc.)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O9 - Extra Button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ()
O9 - Extra 'Tools' menuitem : Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: trymedia.com ([]http in Trusted sites)
O15 - HKLM\..Trusted Domains: trymedia.com ([]https in Trusted sites)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab (Checkers Class)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/e/4…/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://pcpitstop.com/betapit/PCPitStop.CAB (PCPitstop Utility)
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} file:///C:/Program%20Files/Risk/Images/stg_drm.ocx (SpinTop DRM Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/C/0…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab (Minesweeper Flags Class)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} http://www.pogo.com/cdl/launcher/PogoWebLa…erInstaller.CAB (PogoWebLauncher Control)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://photo.walgreens.com/WalgreensActivia.cab (Snapfish Activia)
O16 - DPF: {45A0A292-ECC6-4D8F-9EA9-A4BD411D24C1} http://www.king.com/ctl/kingcomie.cab (king.com)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {54BE6B6F-3056-470B-97E1-BB92E051B6C4} http://h20264.www2.hp.com/ediags/dd/instal…nosticsxp2k.cab (DeviceEnum Class)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://go.divx.com/plugin/DivXBrowserPlugin.cab (DivXBrowserPlugin Object)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab (MessengerStatsClient Class)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} http://web1.shutterfly.com/downloads/Uploader.cab (Shutterfly Picture Upload Plugin)
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} http://acs.pandasoftware.com/activescan/as5free/asinst.cab (ActiveScan Installer Class)
O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} http://offers.e-centives.com/cif/download/bin/actxcab.cab (CBSTIEPrint Class)
O16 - DPF: {BE319D04-18BD-4B34-AECC-EE7CB610FCA9} http://download.games.yahoo.com/games/web_…itched/main.cab (BewitchedGameClass Control)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} file:///C:/Program%20Files/Monopoly/Images/armhelper.ocx (ArmHelper Control)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} http://h30043.www3.hp.com/hpdj/en/check/qdiagh.cab?326 (QDiagHUpdateObj Class)
O16 - DPF: {F137B9BA-89EA-4B04-9C67-2074A9DF61FD} http://cvs.pnimedia.com/upload/activex/v2_…upv2.0.0.10.cab? (Photo Upload Plugin Class)
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} http://dlm.tools.akamai.com/dlmanager/vers…ivex-latest.cab (DownloadManager Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\intu-help-qb2 {84D77A00-41B5-4b8b-8ADF-86486D72E749} - C:\Program Files\Intuit\QuickBooks 2009\HelpAsyncPluggableProtocol.dll (Intuit, Inc.)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - AppInit_DLLs: (c:\windows\system32\libukifu.dll c:\windows\system32\hazafupe.dll) - C:\WINDOWS\System32\libukifu.dll File not found
O20 - AppInit_DLLs: (moyomego.dll) - C:\WINDOWS\System32\moyomego.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\NavLogon: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O21 - SSODL: kaludafap - {141a9890-8ffc-4f80-92b7-7b9b6d992846} - C:\WINDOWS\system32\hazafupe.dll ()
O21 - SSODL: wukatuhow - {b8dd6e4d-809f-412f-a2a2-cc3789aa7f12} - C:\WINDOWS\System32\libukifu.dll File not found
O22 - SharedTaskScheduler: {141a9890-8ffc-4f80-92b7-7b9b6d992846} - tokatiluy - C:\WINDOWS\system32\hazafupe.dll ()
O22 - SharedTaskScheduler: {b8dd6e4d-809f-412f-a2a2-cc3789aa7f12} - kupuhivus - C:\WINDOWS\System32\libukifu.dll File not found
O24 - Desktop WallPaper: C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/05/14 17:49:12 | 000,000,150 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2001/07/28 05:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O32 - AutoRun File - [2004/04/30 06:01:14 | 000,000,053 | -HS- | M] () - D:\Autorun.inf – [ FAT32 ]
O32 - AutoRun File - [1997/07/03 03:48:24 | 000,000,067 | R— | M] () - E:\AUTORUN.INF – [ CDFS ]
O33 - MountPoints2\D\Shell - "" = AutoRun
O33 - MountPoints2\D\Shell\AutoRun - "" = Auto&Play;
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/02/09 21:04:24 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2010/02/08 22:39:27 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Cooliris
[2010/02/08 01:57:51 | 000,000,000 | —D | C] – C:\WINDOWS\Minidump
[2010/02/03 21:10:30 | 000,000,000 | —D | C] – C:\Program Files\Train3D
[2010/02/03 21:02:10 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\temp.001
[2010/02/03 21:02:10 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\temp.000
[2010/01/28 15:00:25 | 000,188,960 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\WINGDE.DLL
[2010/01/28 15:00:25 | 000,092,208 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\WING.DLL
[2010/01/28 15:00:25 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\WING32.DLL
[2010/01/28 15:00:25 | 000,006,736 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\WINGDIB.DRV
[2010/01/28 15:00:25 | 000,005,024 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\WINGPAL.WND
[2010/01/18 22:21:22 | 000,443,944 | —- | C] (E-centives ) – C:\Documents and Settings\HP_Administrator\Desktop\CouponActivator.exe
[2009/09/07 13:12:07 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Swag_Bucks
[2009/07/21 21:01:46 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2009/07/01 11:00:42 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2009/03/31 20:24:33 | 000,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2009/03/31 20:24:26 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\HPQ
[2009/03/29 09:34:17 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2009/01/05 14:12:02 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple
[2009/01/02 11:04:39 | 000,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2009/01/02 11:04:39 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2008/12/10 20:38:36 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Intuit
[2008/04/15 18:05:30 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Google
[2008/04/15 18:05:27 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Viewpoint
[2007/08/01 14:19:14 | 000,774,144 | —- | C] (RealNetworks, Inc.) – C:\Program Files\RngInterstitial.dll
[2005/05/12 09:36:48 | 000,012,288 | —- | C] (Hewlett-Packard Co.) – C:\WINDOWS\Fonts\RandFont.dll
[50 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[42 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2099/01/01 12:00:00 | 000,093,184 | -HS- | M] () – C:\WINDOWS\System32\hazafupe.dll
[2099/01/01 12:00:00 | 000,061,440 | -HS- | M] () – C:\WINDOWS\System32\zahatahe.dll
[2099/01/01 12:00:00 | 000,054,272 | -HS- | M] () – C:\WINDOWS\System32\vamegeye.dll
[2099/01/01 12:00:00 | 000,054,272 | -HS- | M] () – C:\WINDOWS\System32\moyomego.dll
[2099/01/01 12:00:00 | 000,054,272 | -HS- | M] () – C:\WINDOWS\System32\gahipewo.dll
[2099/01/01 12:00:00 | 000,054,272 | -HS- | M] () – C:\WINDOWS\System32\fanenoto.dll
[2099/01/01 12:00:00 | 000,039,424 | -HS- | M] () – C:\WINDOWS\System32\jimiwemo.dll
[2099/01/01 12:00:00 | 000,039,424 | -HS- | M] () – C:\WINDOWS\System32\bimedufo.dll
[2010/02/09 21:24:32 | 000,006,456 | -H– | M] () – C:\WINDOWS\System32\dikabagu
[2010/02/09 21:11:04 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/02/09 21:11:04 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/02/09 21:08:35 | 000,000,707 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/02/09 21:00:00 | 000,000,296 | —- | M] () – C:\WINDOWS\tasks\dcsmkojo.job
[2010/02/09 20:01:04 | 000,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2010/02/09 19:58:45 | 000,057,344 | —- | M] () – C:\WINDOWS\System32\net.net
[2010/02/09 11:52:06 | 055,322,153 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/02/09 11:49:03 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/02/09 11:48:57 | 000,352,608 | -H– | M] () – C:\WINDOWS\System32\vsconfig.xml
[2010/02/09 11:47:59 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/02/09 11:47:42 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/02/09 11:47:40 | 1005,113,344 | -HS- | M] () – C:\hiberfil.sys
[2010/02/08 22:59:23 | 007,950,336 | —- | M] () – C:\Documents and Settings\HP_Administrator\ntuser.dat
[2010/02/08 22:58:53 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\HP_Administrator\ntuser.ini
[2010/02/08 19:16:31 | 000,001,138 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\Facebook Home.url
[2010/02/08 14:12:06 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/02/08 03:00:00 | 000,000,518 | —- | M] () – C:\WINDOWS\tasks\SpywareStop Scheduled Scan.job
[2010/02/07 17:41:07 | 004,285,014 | -H– | M] () – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\IconCache.db
[2010/02/05 21:55:17 | 000,743,752 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\Gallatin Steel Company.tif
[2010/02/03 21:10:01 | 000,253,952 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Setup1.exe
[2010/02/03 21:10:00 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\WINDOWS\temp.001
[2010/02/03 21:02:11 | 000,000,362 | —- | M] () – C:\WINDOWS\ST6UNST.000
[2010/02/03 21:02:10 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\WINDOWS\temp.000
[2010/02/03 20:04:07 | 000,040,448 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\Meijer.doc
[2010/01/28 18:07:12 | 000,000,294 | —- | M] () – C:\WINDOWS\EReg077.dat
[2010/01/28 15:00:32 | 000,000,574 | —- | M] () – C:\Documents and Settings\All Users\Desktop\CompuServe v2.5 Setup.lnk
[2010/01/28 15:00:22 | 000,000,216 | —- | M] () – C:\WINDOWS\TLCAPPS.INI
[2010/01/26 13:52:42 | 000,004,212 | -H– | M] () – C:\WINDOWS\System32\zllictbl.dat
[2010/01/21 19:20:06 | 000,000,629 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\Reader Rabbit's Toddler (2).lnk
[2010/01/21 18:55:59 | 000,086,016 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\2009.xls
[2010/01/19 21:39:36 | 000,142,495 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2010/01/19 16:45:14 | 000,048,640 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\Neil Petty - Industrial Electrician.doc
[2010/01/18 22:21:23 | 000,443,944 | —- | M] (E-centives ) – C:\Documents and Settings\HP_Administrator\Desktop\CouponActivator.exe
[2010/01/18 21:04:04 | 000,002,137 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/01/13 22:34:51 | 000,230,808 | R— | M] (Coupons, Inc.) – C:\WINDOWS\System32\cpnprt2.cid
[2010/01/13 22:10:23 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[50 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[42 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2099/01/01 12:00:00 | 000,093,184 | -HS- | C] () – C:\WINDOWS\System32\hazafupe.dll
[2099/01/01 12:00:00 | 000,061,440 | -HS- | C] () – C:\WINDOWS\System32\zahatahe.dll
[2099/01/01 12:00:00 | 000,054,272 | -HS- | C] () – C:\WINDOWS\System32\vamegeye.dll
[2099/01/01 12:00:00 | 000,054,272 | -HS- | C] () – C:\WINDOWS\System32\moyomego.dll
[2099/01/01 12:00:00 | 000,054,272 | -HS- | C] () – C:\WINDOWS\System32\gahipewo.dll
[2099/01/01 12:00:00 | 000,054,272 | -HS- | C] () – C:\WINDOWS\System32\fanenoto.dll
[2099/01/01 12:00:00 | 000,039,424 | -HS- | C] () – C:\WINDOWS\System32\jimiwemo.dll
[2099/01/01 12:00:00 | 000,039,424 | -HS- | C] () – C:\WINDOWS\System32\bimedufo.dll
[2099/01/01 12:00:00 | 000,006,456 | -H– | C] () – C:\WINDOWS\System32\dikabagu
[2010/02/09 21:08:35 | 000,000,707 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/02/09 19:58:45 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\net.net
[2010/02/09 12:46:49 | 000,000,296 | —- | C] () – C:\WINDOWS\tasks\dcsmkojo.job
[2010/02/09 11:47:40 | 1005,113,344 | -HS- | C] () – C:\hiberfil.sys
[2010/02/07 15:31:03 | 007,950,336 | —- | C] () – C:\Documents and Settings\HP_Administrator\ntuser.dat
[2010/02/05 21:55:16 | 000,743,752 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\Gallatin Steel Company.tif
[2010/02/03 21:06:50 | 000,000,886 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/02/03 21:06:50 | 000,000,882 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/02/03 21:02:10 | 000,000,362 | —- | C] () – C:\WINDOWS\ST6UNST.000
[2010/01/28 18:07:11 | 000,000,294 | —- | C] () – C:\WINDOWS\EReg077.dat
[2010/01/28 15:00:32 | 000,000,574 | —- | C] () – C:\Documents and Settings\All Users\Desktop\CompuServe v2.5 Setup.lnk
[2010/01/21 19:20:06 | 000,000,629 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\Reader Rabbit's Toddler (2).lnk
[2009/09/21 18:32:56 | 000,000,216 | —- | C] () – C:\WINDOWS\TLCAPPS.INI
[2009/07/22 20:03:42 | 000,000,110 | —- | C] () – C:\WINDOWS\{47FB62DF-832D-485F-95FC-C93BB08B8FE3}_WiseFW.ini
[2008/12/19 22:41:13 | 000,000,067 | —- | C] () – C:\Documents and Settings\HP_Administrator\Application Data\photoshow_express_setup.txt
[2008/12/09 15:32:54 | 000,000,095 | —- | C] () – C:\WINDOWS\QBChanUtil_Trigger.ini
[2008/09/13 09:45:51 | 000,000,023 | —- | C] () – C:\WINDOWS\MathMagic Personal 3.64.INI
[2008/09/13 09:45:11 | 000,016,498 | —- | C] () – C:\Program Files\setuplog.txt
[2008/09/13 09:45:11 | 000,015,834 | —- | C] () – C:\Program Files\uninstall.log
[2008/05/21 17:33:21 | 000,000,343 | —- | C] () – C:\WINDOWS\SIERRA.INI
[2008/03/14 14:32:38 | 000,000,343 | —- | C] () – C:\WINDOWS\ULead32.ini
[2008/02/23 18:10:33 | 000,000,071 | —- | C] () – C:\WINDOWS\Pex.INI
[2008/02/04 17:23:10 | 000,693,792 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.DLL
[2008/02/02 22:36:02 | 000,002,947 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/10/29 19:24:32 | 000,000,190 | —- | C] () – C:\Documents and Settings\HP_Administrator\Application Data\G-Force Prefs (WindowsMediaPlayer).txt
[2007/08/03 14:09:41 | 000,003,454 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2007/08/03 14:09:41 | 000,000,008 | RHS- | C] () – C:\WINDOWS\System32\8036B57683.sys
[2007/08/03 14:08:46 | 001,300,048 | —- | C] () – C:\Documents and Settings\All Users\Application Data\pswi_preloaded.exe
[2007/05/21 18:43:37 | 000,000,560 | —- | C] () – C:\Documents and Settings\HP_Administrator\Application Data\ViewerApp.dat
[2007/05/14 17:47:01 | 000,003,654 | —- | C] () – C:\WINDOWS\System32\drivers\Sonyhcp.dll
[2007/05/13 18:58:44 | 000,098,304 | —- | C] () – C:\WINDOWS\System32\resourceGeneric.dll
[2007/01/29 12:23:40 | 000,011,776 | —- | C] () – C:\WINDOWS\System32\ZPORT4AS.dll
[2007/01/19 20:42:01 | 000,000,000 | —- | C] () – C:\WINDOWS\PROTOCOL.INI
[2006/10/14 15:06:20 | 000,796,584 | —- | C] () – C:\WINDOWS\System32\libeay32_0.9.6l.dll
[2006/08/26 15:13:30 | 000,000,000 | —- | C] () – C:\Documents and Settings\HP_Administrator\Application Data\wklnhst.dat
[2006/08/19 08:45:20 | 000,372,736 | —- | C] () – C:\WINDOWS\System32\hpzidi01.dll
[2006/08/19 08:45:19 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\hpzids01.dll
[2006/07/09 20:58:44 | 000,000,091 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2006/05/06 19:20:36 | 000,065,382 | —- | C] () – C:\Documents and Settings\HP_Administrator\Application Data\PatchUpdate_HP_CounterReport_Update_HPSU.log
[2006/05/06 19:20:36 | 000,000,227 | —- | C] () – C:\WINDOWS\HP_CounterReport_Update_HPSU.ini
[2006/05/06 19:20:25 | 000,002,202 | —- | C] () – C:\Documents and Settings\HP_Administrator\Application Data\HPSU_48BitScanUpdate.log
[2006/05/06 19:20:25 | 000,000,214 | —- | C] () – C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2006/05/06 19:19:00 | 000,003,013 | —- | C] () – C:\Documents and Settings\HP_Administrator\Application Data\PatchUpdate_InstantShareJPG.log
[2006/05/06 19:19:00 | 000,000,214 | —- | C] () – C:\WINDOWS\HP_InstantSHareJPG.ini
[2006/05/06 19:17:50 | 000,006,926 | —- | C] () – C:\Documents and Settings\HP_Administrator\Application Data\GdiplusUpgrade_MSIApproach_Wrapper.log
[2006/05/06 19:17:50 | 000,000,206 | —- | C] () – C:\WINDOWS\HPGdiPlus.ini
[2006/05/06 19:01:58 | 000,049,385 | —- | C] () – C:\Documents and Settings\HP_Administrator\Application Data\Update_HP_RedboxHprblog_HPSU.log
[2006/05/06 19:01:58 | 000,000,221 | —- | C] () – C:\WINDOWS\HP_RedboxHprblog_HPSU.ini
[2006/05/03 17:56:01 | 000,000,000 | —- | C] () – C:\WINDOWS\vpc32.INI
[2006/04/30 17:57:19 | 000,043,520 | —- | C] () – C:\WINDOWS\System32\CmdLineExt03.dll
[2006/04/30 17:45:50 | 000,021,840 | —- | C] () – C:\WINDOWS\System32\SIntfNT.dll
[2006/04/30 17:45:50 | 000,017,212 | —- | C] () – C:\WINDOWS\System32\SIntf32.dll
[2006/04/30 17:45:50 | 000,012,067 | —- | C] () – C:\WINDOWS\System32\SIntf16.dll
[2006/04/04 20:39:06 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\YCRWin32.dll
[2006/03/22 16:10:12 | 000,000,028 | —- | C] () – C:\WINDOWS\atid.ini
[2006/03/07 21:18:06 | 000,026,112 | —- | C] () – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/03/06 22:47:17 | 000,004,599 | —- | C] () – C:\WINDOWS\hpdj5600.ini
[2006/03/05 12:44:51 | 000,000,139 | —- | C] () – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\fusioncache.dat
[2005/12/02 19:21:27 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/12/02 19:02:13 | 000,022,396 | —- | C] () – C:\WINDOWS\System32\drivers\USBkey.sys
[2005/12/02 18:57:42 | 000,014,316 | —- | C] () – C:\WINDOWS\System32\CHODDI.SYS
[2005/12/02 18:57:35 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\hpreg.dll
[2005/12/02 18:55:33 | 000,000,099 | —- | C] () – C:\WINDOWS\Quicken.ini
[2005/12/02 18:52:27 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/12/02 18:48:06 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2005/12/02 18:48:06 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2005/12/02 18:48:06 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2005/12/02 18:48:06 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2005/12/02 18:48:06 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2005/12/02 18:48:06 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2005/12/02 18:42:51 | 000,000,108 | —- | C] () – C:\WINDOWS\WININIT.INI
[2005/12/02 18:41:57 | 000,000,698 | —- | C] () – C:\WINDOWS\NSSetDefaultBrowser.ini
[2005/12/02 18:31:59 | 000,005,466 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2005/12/02 18:16:15 | 000,000,791 | —- | C] () – C:\WINDOWS\orun32.ini
[2005/12/02 18:09:57 | 000,323,584 | —- | C] () – C:\WINDOWS\System32\pythoncom22.dll
[2005/12/02 18:09:57 | 000,094,208 | —- | C] () – C:\WINDOWS\System32\pywintypes22.dll
[2005/12/02 18:09:42 | 000,016,896 | —- | C] () – C:\WINDOWS\System32\bcbmm.dll
[2005/10/05 15:50:52 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2005/08/06 00:01:54 | 000,235,008 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2005/08/03 02:19:16 | 000,050,176 | —- | C] () – C:\WINDOWS\armcex.dll
[2004/09/16 13:26:40 | 000,012,634 | —- | C] () – C:\WINDOWS\System32\drivers\ADFUUD.SYS
[2004/08/10 07:00:00 | 000,096,512 | —- | C] () – C:\WINDOWS\System32\drivers\atapi.sys
[2004/07/26 17:51:38 | 000,000,560 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2003/01/08 01:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2001/07/07 01:30:00 | 000,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini
[1998/08/16 05:00:00 | 000,004,096 | —- | C] () – C:\WINDOWS\System32\sysres.dll

========== LOP Check ==========

[2008/07/05 16:38:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\acccore
[2008/01/27 19:51:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Broderbund Software
[2008/12/09 15:32:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\COMMON FILES
[2006/04/12 10:43:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Digital Interactive Systems Corporation
[2006/05/03 14:59:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\espionServerData
[2009/07/22 19:52:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Leapfrog
[2007/06/29 13:10:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\muvee Technologies
[2006/03/07 11:50:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Napster
[2009/03/23 18:30:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2009/07/29 21:19:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\RoboForm
[2007/08/01 14:24:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SpinTop Games
[2008/12/10 20:47:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SQL Anywhere 10
[2009/01/18 20:23:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/08/02 09:42:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2009/06/15 14:06:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/09/29 10:17:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/04/06 14:05:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2009/03/18 19:46:39 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{92E7A367-8E12-4830-AA70-29C32E331A81}
[2010/02/09 21:00:00 | 000,000,296 | —- | M] () – C:\WINDOWS\Tasks\dcsmkojo.job
[2010/02/08 03:00:00 | 000,000,518 | —- | M] () – C:\WINDOWS\Tasks\SpywareStop Scheduled Scan.job

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 96 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3F2F06F2
@Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CB16385F
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:588B60C7
@Alternate Data Stream - 111 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7B212553
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:52B72A7C
@Alternate Data Stream - 102 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:EA34E08F
< End of report >


OTL Extras logfile created on: 2/9/2010 9:15:24 PM - Run 1
OTL by OldTimer - Version 3.1.28.0 Folder = C:\Documents and Settings\HP_Administrator\Desktop\Neil's Shortcuts\PC Upkeep\Setups
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

958.00 Mb Total Physical Memory | 327.00 Mb Available Physical Memory | 34.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 72.00% Paging File free
Paging file location(s): C:\pagefile.sys 1440 2880 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 177.79 Gb Total Space | 79.14 Gb Free Space | 44.51% Space Free | Partition Type: NTFS
Drive D: | 8.50 Gb Total Space | 1.12 Gb Free Space | 13.13% Space Free | Partition Type: FAT32
Drive E: | 326.31 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: NEIL
Current User Name: HP_Administrator
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"3776:UDP" = 3776:UDP:*:Enabled:Media Center Extender Service
"3390:TCP" = 3390:TCP:*:Enabled:Remote Media Center Experience
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\MSN Messenger\livecall.exe" = C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone) – File not found
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe" = C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe – ()
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe – ()
"C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe – ( )
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe – (Hewlett-Packard Co.)
"C:\Program Files\DISC\DISCover.exe" = C:\Program Files\DISC\DISCover.exe:*:Enabled:DISCover Drop & Play System – (Digital Interactive Systems Corporation)
"C:\Program Files\DISC\DiscStreamHub.exe" = C:\Program Files\DISC\DiscStreamHub.exe:*:Enabled:DISCover Stream Hub – (Digital Interactive Systems Corporation, Inc.)
"C:\Program Files\DISC\myFTP.exe" = C:\Program Files\DISC\myFTP.exe:*:Enabled:DISCover FTP – (Digital Interactive Systems Corporation, Inc.)
"C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" = C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink – File not found
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader – (AOL LLC)
"C:\Program Files\Common Files\AOL\1143062075\ee\aolsoftware.exe" = C:\Program Files\Common Files\AOL\1143062075\ee\aolsoftware.exe:*:Enabled:AOL Services – File not found
"C:\Program Files\Common Files\AOL\1143062075\ee\aim6.exe" = C:\Program Files\Common Files\AOL\1143062075\ee\aim6.exe:*:Enabled:AIM – File not found
"C:\WINDOWS\ehome\ehshell.exe" = C:\WINDOWS\ehome\ehshell.exe:LocalSubNet:Enabled:Media Center – (Microsoft Corporation)
"C:\Program Files\Yahoo!\Messenger\YPager.exe" = C:\Program Files\Yahoo!\Messenger\YPager.exe:*:Enabled:Yahoo! Messenger – File not found
"C:\Program Files\Yahoo!\Messenger\YServer.exe" = C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server – (Yahoo! Inc.)
"C:\Program Files\Adobe\Photoshop Elements 4.0\AdobePhotoshopElementsMediaServer.exe" = C:\Program Files\Adobe\Photoshop Elements 4.0\AdobePhotoshopElementsMediaServer.exe:*:Disabled:Adobe Photoshop Elements Media Server – ()
"C:\Program Files\Hewlett-Packard\HP Software Update\HPWUCli.exe" = C:\Program Files\Hewlett-Packard\HP Software Update\HPWUCli.exe:*:Enabled:HP Software Update Client – (Hewlett-Packard)
"E:\Setup.exe" = E:\Setup.exe:*:Enabled:Setup – ()
"C:\Program Files\Internet Explorer\IEXPLORE.EXE" = C:\Program Files\Internet Explorer\IEXPLORE.EXE:*:Disabled:Internet Explorer – (Microsoft Corporation)
"C:\Program Files\AIM6\aim6.exe" = C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM – (AOL LLC)
"C:\Program Files\MSN Messenger\livecall.exe" = C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone) – File not found
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger – (Yahoo! Inc.)
"C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" = C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe:*:Disabled:Malwarebytes' Anti-Malware – File not found
"C:\Program Files\Steam\steamapps\common\empire total war demo\Empire.exe" = C:\Program Files\Steam\steamapps\common\empire total war demo\Empire.exe:*:Enabled:Empire: Total War Demo – (The Creative Assembly Ltd)
"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour – (Apple Inc.)
"C:\Documents and Settings\HP_Administrator\Desktop\Neil's Shortcuts\Games\Magic\Manalink.exe" = C:\Documents and Settings\HP_Administrator\Desktop\Neil's Shortcuts\Games\Magic\Manalink.exe:*:Enabled:manalink – (MicroProse Software, Inc.)
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox – (Mozilla Corporation)
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)
"C:\WINDOWS\explorer.exe" = C:\WINDOWS\explorer.exe:*:Enabled:Explorer – (Microsoft Corporation)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{03B1B42B-F6DE-41d9-8CFF-DC44E895C7A7}" = PhotoGallery
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{0611BD4E-4FE4-4a62-B0C0-18A4CC463428}" = CP_Package_Variety1
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{075473F5-846A-448B-BCB3-104AA1760205}" = Sonic RecordNow Data
"{09984AEC-6B9F-4ca7-B78D-CB44D4771DA3}" = Destinations
"{0B33B738-AD79-4E32-90C5-E67BFB10BBFF}" = AiO_Scan
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{11C98E1A-EC91-4B38-B44C-C562292D8453}" = Adobe Premiere Elements 2.0
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{15EE79F4-4ED1-4267-9B0F-351009325D7D}" = HP Software Update
"{16BE87BC-69F5-4D36-8CF0-E1CB3ACD5ED3}" = HP Driver Diagnostics
"{172975EB-9465-4861-95B5-C7BB6D3DE62A}" = DocumentViewer
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1C139D7D-9FEA-468d-A9C8-2A6E3BDE564A}" = CP_Package_Variety3
"{1E2F8AE3-3437-44E6-BB75-E95751D6B83F}" = Picture Package
"{1F51A0CA-2BDD-474E-BB90-C7FA8EA78F52}" = ImageMixer VCD/DVD2 for OLYMPUS
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{2070F79D-46BC-4EEA-8F02-9B4DCABAE7CB}" = iPod for Windows 2006-03-23
"{21657574-BD54-48A2-9450-EB03B2C7FC29}" = Sonic MyDVD Plus
"{21DB3D90-D816-4092-A260-CA3F6B55A6DD}" = Sonic_PrimoSDK
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{23A7B376-BBEC-4e76-BBD7-0F155E70D74B}" = CP_Panorama1Config
"{23FE964A-853B-4176-86D7-9E18B5CA1FC0}" = Media Center Extender
"{2818095F-FB6C-42C8-827E-0A406CC9AFF5}" = Quicken 2006
"{2C5D07FB-31A2-4F2D-9FDA-0B24ACD42BD0}" = HP Deskjet Printer Preload
"{2CADCEAB-D5DA-44D6-B5FC-7DEE87AB3C0C}" = Unload
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
"{30C19FF2-7FBA-4d09-B9DE-1659977F64F6}" = TrayApp
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java™ SE Runtime Environment 6 Update 1
"{32BDCCB8-9DC8-496d-9DB1-F77510775BDB}" = InstantShareDevices
"{33D6CC28-9F75-4d1b-A11D-98895B3A3729}" = HP Photosmart 330,380,420,470,7800,8000,8200 Series
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{36E47DA1-10E1-45d9-8B19-14D19607CDCF}" = CP_CalendarTemplates1
"{382E94C0-6E22-44e4-B003-8EB31DFE296F}" = cp_LightScribeConfig
"{388E4B09-3E71-4649-8921-F44A3A2954A7}" = Microsoft Visual Studio 2005 Tools for Office Runtime
"{3912A629-0020-0005-3757-2FBA74D4DF0A}" = InterVideo WinDVD Player
"{3AC54383-31D1-4907-961B-B12CBB1D0AE8}" = MobileMe Control Panel
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3B55590C-8A9B-4BD6-B489-744B63026A2A}" =
"{3BA95526-6AE0-4B87-A62D-17187EF565FC}" = HP Boot Optimizer
"{3C0BAFCA-BDB8-492B-8845-DC0A4B4C1823}" = HPDeskjet5400Series
"{3E386744-10FA-44b2-98C9-DF7A270DECB3}" = HP PSC & OfficeJet 5.3.A
"{3FA195A0-10BE-4315-9B7C-1486845BD002}" = LeapFrog Tag Junior Plugin
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{416D80BA-6F6D-4672-B7CF-F54DA2F80B44}" = Microsoft Works
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{47FB62DF-832D-485F-95FC-C93BB08B8FE3}" = LeapFrog Connect
"{51D386C4-0227-46A9-AC45-61F0A50E7AFF}" = Rome - Total War
"{5421155F-B033-49DB-9B33-8F80F233D4D5}" = GdiplusUpgrade
"{54E3707F-808E-4fd4-95C9-15D1AB077E5D}" = NewCopy
"{567C23E1-7580-4185-B8C2-30805677297C}" = NewCopy_CDA
"{56EE8B17-8274-418d-89AC-C057C5DB251E}" = RandMap
"{56F8AFC3-FA98-4ff1-9673-8A026CBF85BE}" = WebReg
"{5A01C58E-B0EC-49b9-AD71-7C0468688087}" = CP_Package_Basic1
"{5A3F6A80-7913-475E-8B96-477A952CFA43}" = SupportSoft Assisted Service
"{5B79CFD1-6845-4158-9D7D-6BE89DF2C135}" = HP PSC & OfficeJet 5.3.B
"{5C29CB8B-AC1E-4114-8D68-9CD080140D4A}" = Sony USB Driver
"{5EC786D5-C0CA-42E0-AF88-5379EF9D91EC}" = First Step Guide
"{5F26311C-B135-4F7F-B11E-8E650F83651E}" = DeviceFunctionQFolder
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Sonic Express Labeler
"{66BA8C26-AFE4-4408-807B-43E76B57EF53}" = SkinsHP1
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6BB6627C-694F-4FDC-A3E5-C7F4BED4C724}" = DocProc
"{6DCB9F1F-3BCC-4078-B90C-439017F1806C}" = Crystalize 2
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{71d6ce84-b7dc-4166-8e0d-56c1c37bfb5a}" =
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{755EC5E3-FD51-46bd-A57F-7A2D56FBF061}" = PSTAPlugin
"{769A295C-DCF4-41d6-AFBA-7D9394B23AFE}" = PSPrinters08
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7850A6D2-CBEA-4728-9877-F1BEDEA9F619}" = AiOSoftware
"{7C03270C-4FAB-4F5C-B10D-52FEDA190790}" = DocumentViewerQFolder
"{7E27304E-BAA2-4d90-A34E-76641FAFABB4}" = CP_AtenaShokunin1Config
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11052313}" = Magic Match
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-115286387}" = Operation Mania
"{83073C45-3003-4671-9A86-243AAADD915A}" = Microsoft Calculator Plus
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C3727F2-8E37-49E4-820C-03B1677F53B6}" = Stronghold Crusader
"{8EDBA74D-0686-4C99-BFDD-F894678E5102}" = Adobe Common File Installer
"{8FFC924C-ED06-44CB-8867-3CA778ECE903}" = Adobe Help Center 2.0
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{91120409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Standard Edition 2003
"{91477C6F-EC7C-4BFC-BBE1-E45908019DED}" = LightScribe 1.4.52.1
"{91490409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office 2003 Primary Interop Assemblies
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD Player
"{923A7F5A-1E8C-4FBE-8DF6-85940A60A79F}" = Readme
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{98936CBC-5E7A-4AD7-B05B-6D34C7C68E37}" = Hoyle Board Games 2005
"{9A2F0810-3619-4E86-9072-973FBE1679C5}" = QuickBooks Simple Start 2009
"{9E17C94B-913A-48A4-B1A8-8CE25157C170}" = Media Player Product Tool 5.20
"{A040AC77-C1AA-4CC9-8931-9F648AF178F6}" = VC 9.0 Runtime
"{A0EB195B-5876-48E6-879D-33D4B2102610}" = SonicStage 3.4
"{A195B13E-A5E3-4BAF-A995-7F70F445CD06}" = ScannerCopy
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A3455242-DAE0-4523-8242-FD82706ABF4B}" = CameraDrivers
"{A5BB5365-EFB4-44c3-A7E2-EB59B7EFD23D}" = CueTour
"{A6FDF86A-F541-4E7B-AEA0-8849A2A700D5}" = iTunes
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Sonic RecordNow Audio
"{AC76BA86-7AD7-1033-7B44-A71000000002}" = Adobe Reader 7.1.0
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Sonic RecordNow Copy
"{B276997E-4367-4b1b-A39C-4CAE7464337A}" = AiO_Scan_CDA
"{B44AA698-B221-4B3B-8CA5-E65EF6A5AF26}" = Hoyle Card Games 2005
"{B4D279F1-4309-49cc-A4B5-3A0D2E59C7B5}" = PanoStandAlone
"{B60E7826-F117-4d26-8165-D2DC5A494AB0}" = Fax_CDA
"{B64E3AFC-59EF-4f18-BF11-E751462450D3}" = AiOSoftwareNPI
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{B824B5C9-849F-4b9e-9EA7-6FD8CD8116DA}" = CP_Package_Variety2
"{B996AE66-10DB-4ac5-B151-E8B4BFBC42FC}" = BufferChm
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C104580B-1C79-4d73-9BF0-CA0B184296A4}" = cp_LightScribePlugin
"{C4124E95-5061-4776-8D5D-E3D931C778E1}" = Microsoft VC9 runtime libraries
"{C506A18C-1469-4678-B094-F4EC9DAE6DB7}" = Scan
"{C83A12B9-B31B-461A-BBD4-CE9B988094F1}" = HP Photosmart Cameras 5.0
"{C917BA70-28A3-4C74-B163-41FD8C8E1A5A}" = Stronghold
"{C98E5F1B-5C2B-4FD1-BDF9-F3779DCAAA16}" =
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE24344F-DFD8-40C8-8FD8-C9740B5F25AC}" = Fax
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CF2606C7-63AF-40F4-8919-F2EC654ACC91}" = Napster for Windows Media Player
"{CFB17307-B244-4EAD-AE8E-CDAF440477C2}" = OpenMG Secure Module 4.4.00
"{D518592A-0F1E-40ca-BECB-3D3F026C6B0D}" = CameraDrivers
"{D9CDB463-BB48-4B80-B1B6-5B940A4621E0}" = AutoStreamer
"{DB518BA6-CB74-4EB6-9ABD-880B6D6E1F38}" = HpSdpAppCoreApp
"{DFB0FED6-0010-4E9B-A402-E513F2459161}" = muvee autoProducer unPlugged 1.2
"{E34351A4-4B10-4DFF-96BC-84C642D9C625}" = The Print Shop 22
"{E3F90083-80D4-4b5a-87C7-E97E12F5516D}" = HPProductAssistant
"{E7137AFD-4E43-47A6-BDC7-533808F72B36}" = muvee autoProducer 4.5
"{E85FA9A1-C241-4698-893B-DD99509B8DB0}" =
"{E9787678-551D-4478-9682-DBB587257110}" =
"{EA103B64-C0E4-4C0E-A506-751590E1653D}" = SolutionCenter
"{EB57A16E-500D-43d7-85B9-FBE279EBBA6E}" = HP Deskjet 5400 series
"{EBB7C1C1-D439-4D9B-9FDC-954C10F266B0}" = Adobe Photoshop Elements 4.0
"{ECFDD6BD-E0C0-41CC-A171-E6D6AF4C0E93}" = HP Software Update
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F4C2E5F5-2970-45f4-ABD3-C180C4D961C4}" = Status
"{F64306A5-4C32-41bb-B153-53986527FAB4}" =
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{F80239D8-7811-4D5E-B033-0D0BBFE32920}" = HP DigitalMedia Archive
"{F8C6BABF-0837-4EA0-AD6C-8E5A392A7538}" = ImageMixer VCD2
"{FD69C8CB-6964-432C-98AB-A5A09ED50EEA}" = Barbarian Invasion
"12133444-BF36-4d4e-B7FB-A3424C645DE4" = GemMaster Mystic
"781745E87AFF80C0C1388CFF79D19ECAB2E9BB47" = Windows Driver Package - LeapFrog (FlyUsb) USB (11/05/2008 1.1.1.0)
"Ad-Aware SE Plus" = Ad-Aware SE Plus
"AddressBook" =
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop Elements 4" = Adobe Photoshop Elements 4.0
"AIM_6" = AIM 6
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.9
"ATI Display Driver" = ATI Display Driver
"AudioPlugin.dll" =
"AVG8Uninstall" = AVG Free 8.5
"AwayMode160" = Microsoft Away Mode
"B3EE3001-DC24-4cd1-8743-5692C716659F" = Otto
"BFGC" = Big Fish Games Client
"BFG-Hidden Mysteries - Buckingham Palace" = Hidden Mysteries: Buckingham Palace ™
"C-evo" = C-evo
"CNXT_MODEM_PCI_VEN_14F1&DEV;_2F20&SUBSYS;_200C14F1" = Data Fax SoftModem with SmartCP
"Connection Manager" =
"CopyNow.dll" =
"Coupon Printer for Windows4.0" = Coupon Printer for Windows
"DataPlugin.dll" =
"DirectAnimation" =
"DirectDrawEx" =
"DISCover" = DISCover
"DXM_Runtime" =
"EAFunctions.dll" =
"EHome Devices" = Media Center Extender
"ERUNT_is1" = ERUNT 1.1j
"Flickr Uploadr" = Flickr Uploadr 3.2.1
"Fontcore" =
"Gangsters" = Gangsters
"Google Updater" = Google Updater
"HijackThis" = HijackThis 2.0.2
"Home Daycare Forms03-1" = Home Daycare Forms
"HP Document Viewer" = HP Document Viewer 5.3
"HP Image Zone for Media Center PC" = HP Image Zone for Media Center PC
"HP Imaging Device Functions" = HP Imaging Device Functions 5.3
"HP Photo & Imaging" = HP Image Zone 5.3
"HP Solution Center & Imaging Support Tools" = HP Solution Center & Imaging Support Tools 5.3
"ICW" =
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"IE40" =
"IE4Data" =
"IE5BAKEX" =
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"IEData" =
"InstallShield Uninstall Information" =
"InstallShield_{2070F79D-46BC-4EEA-8F02-9B4DCABAE7CB}" = iPod for Windows 2006-03-23
"InstallShield_{CFB17307-B244-4EAD-AE8E-CDAF440477C2}" = OpenMG Secure Module 4.4.00
"InstallShield_{DB518BA6-CB74-4EB6-9ABD-880B6D6E1F38}" =
"IntelliMover Data Transfer Demo" = Remove IntelliMover Demo
"king.com" = king.com (remove only)
"Macromedia Shockwave Player" = Macromedia Shockwave Player
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"MathMagic Personal Edition 3.64" = MathMagic Personal Edition 3.64
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Interactive Training" =
"Microsoft Visual Studio 2005 Tools for Office Runtime" = Visual Studio 2005 Tools for Office Second Edition Runtime
"MobileOptionPack" =
"Money2005b" = Microsoft Money 2005
"Mozilla Firefox (3.6)" = Mozilla Firefox (3.6)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSI30a-KB884016" =
"MSI30-Beta1" =
"MSI30-Beta2" =
"MSI30-KB884016" =
"MSI30-RC1" =
"MSI30-RC2" =
"MSI31-Beta" =
"MSI31-RC1" =
"net" = Advertisement Service
"NetMeeting" =
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"OpenMG HotFix4.4-05-12-06-01" = OpenMG Limited Patch 4.4-06-13-19-01
"OutlookExpress" =
"Panda ActiveScan" = Panda ActiveScan
"PC Doc Pro_is1" = PC Doc Pro 3.7
"PC-Doctor 5 for Windows" = PC-Doctor 5 for Windows
"PCHealth" =
"Peoples Tactics_is1" = v1.0.26f
"Pharaoh" = Pharaoh
"PhotoMix_is1" = PhotoMix 5.3
"PremElem20" = Adobe Premiere Elements 2.0
"PS2" = PS2
"Python 2.2.3" = Python 2.2.3
"pywin32-py2.2" = Python 2.2 pywin32 extensions (build 203)
"RealArcade 1.2" = RealArcade
"RealJukebox 1.0" =
"RealPlayer 6.0" = RealPlayer
"rrpw32.exe" = Reader Rabbit's Preschool
"RRTW32.EXE" = Reader Rabbit's Toddler
"SchedulingAgent" =
"Shockwave" =
"Shogun Total War" = Shogun Total War
"SkyHillKIDSforWindows_is1" = Minute Menu Kids
"ST6UNST #1" = Hero Editor V0.96
"ST6UNST #2" = Hero Editor V0.96 (C:\Program Files\Hero Editor\)
"ST6UNST #3" = Train3D
"Steam App 10620" = Empire: Total War Demo
"Swag_Bucks Toolbar" = Swag_Bucks Toolbar
"UnityWebPlayer" = Unity Web Player
"UPCShell" = LeapFrog Connect
"ViewpointMediaPlayer" = Viewpoint Media Player
"Walgreens PhotoShow Express 4" = Walgreens PhotoShow Express 4
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"WebPost" = Microsoft Web Publishing Wizard 1.52
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinSPWW2v1 DL Edition" = WinSPWW2v1 DL Edition
"winusb0100" = Microsoft WinUsb 1.0
"WMCSetup" = Windows Media Connect
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01007" = Microsoft User-Mode Driver Framework Feature Pack 1.7
"Yahoo! Extras" = Yahoo! Browser Services
"Yahoo! Photos Drag-Drop Uploader 1v7" = Yahoo! Photos Easy Upload Tool 1v7
"ZoneAlarm Pro" = ZoneAlarm Pro

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Hidden Expedition - Everest" = Hidden Expedition - Everest (remove only)

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 2/3/2010 10:12:26 PM | Computer Name = NEIL | Source = Application Error | ID = 1000
Description = Faulting application train3d.exe, version 0.2.0.2, faulting module
ntdll.dll, version 5.1.2600.5755, fault address 0x00028c0b.

Error - 2/3/2010 10:12:28 PM | Computer Name = NEIL | Source = Application Error | ID = 1000
Description = Faulting application train3d.exe, version 0.2.0.2, faulting module
msvbvm60.dll, version 6.0.98.2, fault address 0x000daa54.

Error - 2/4/2010 2:08:05 PM | Computer Name = NEIL | Source = Application Hang | ID = 1002
Description = Hanging application WINWORD.EXE, version 11.0.8313.0, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 2/7/2010 6:33:26 PM | Computer Name = NEIL | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 2/7/2010 6:33:27 PM | Computer Name = NEIL | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 2/7/2010 6:33:27 PM | Computer Name = NEIL | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 2/7/2010 6:33:27 PM | Computer Name = NEIL | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 2/8/2010 8:37:58 PM | Computer Name = NEIL | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 2/8/2010 8:38:14 PM | Computer Name = NEIL | Source = Application Hang | ID = 1001
Description = Fault bucket 1180947459.

Error - 2/8/2010 11:31:25 PM | Computer Name = NEIL | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

[ System Events ]
Error - 2/9/2010 12:04:17 AM | Computer Name = NEIL | Source = Service Control Manager | ID = 7001
Description = The TrueVector Internet Monitor service depends on the vsdatant service
which failed to start because of the following error: %%31

Error - 2/9/2010 12:04:17 AM | Computer Name = NEIL | Source = Service Control Manager | ID = 7001
Description = The Apple Mobile Device service depends on the TCP/IP Protocol Driver
service which failed to start because of the following error: %%31

Error - 2/9/2010 12:04:17 AM | Computer Name = NEIL | Source = Service Control Manager | ID = 7001
Description = The Bonjour Service service depends on the TCP/IP Protocol Driver
service which failed to start because of the following error: %%31

Error - 2/9/2010 12:04:17 AM | Computer Name = NEIL | Source = Service Control Manager | ID = 7001
Description = The IPSEC Services service depends on the IPSEC driver service which
failed to start because of the following error: %%31

Error - 2/9/2010 12:04:17 AM | Computer Name = NEIL | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
AFD AmdK8 AvgLdx86 AvgMfx86 AvgTdiX Fips IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip vsdatant

Error - 2/9/2010 12:04:34 AM | Computer Name = NEIL | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}

Error - 2/9/2010 12:46:25 PM | Computer Name = NEIL | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 2/9/2010 9:18:20 PM | Computer Name = NEIL | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}

Error - 2/9/2010 9:18:33 PM | Computer Name = NEIL | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}

Error - 2/9/2010 9:18:36 PM | Computer Name = NEIL | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}


< End of report >
Hi Amebeo,

Let's clean some of this up and go deeper. You have a nasty but I can only see part of it.

Next, Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:OTL
PRC - C:\WINDOWS\system32\net.net ()
MOD - C:\WINDOWS\system32\hazafupe.dll ()
MOD - C:\WINDOWS\system32\moyomego.dll ()
O4 - HKLM..\Run: [jedugikuf] C:\WINDOWS\System32\hazafupe.DLL ()
O4 - HKLM..\Run: [net] C:\WINDOWS\System32\net.net ()
O20 - AppInit_DLLs: (c:\windows\system32\libukifu.dll c:\windows\system32\hazafupe.dll) - C:\WINDOWS\System32\libukifu.dll File not found
O20 - AppInit_DLLs: (moyomego.dll) - C:\WINDOWS\System32\moyomego.dll ()
O21 - SSODL: kaludafap - {141a9890-8ffc-4f80-92b7-7b9b6d992846} - C:\WINDOWS\system32\hazafupe.dll ()
O21 - SSODL: wukatuhow - {b8dd6e4d-809f-412f-a2a2-cc3789aa7f12} - C:\WINDOWS\System32\libukifu.dll File not found
O22 - SharedTaskScheduler: {141a9890-8ffc-4f80-92b7-7b9b6d992846} - tokatiluy - C:\WINDOWS\system32\hazafupe.dll ()
O22 - SharedTaskScheduler: {b8dd6e4d-809f-412f-a2a2-cc3789aa7f12} - kupuhivus - C:\WINDOWS\System32\libukifu.dll File not found
[42 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2099/01/01 12:00:00 | 000,093,184 | -HS- | M] () – C:\WINDOWS\System32\hazafupe.dll
[2099/01/01 12:00:00 | 000,061,440 | -HS- | M] () – C:\WINDOWS\System32\zahatahe.dll
[2099/01/01 12:00:00 | 000,054,272 | -HS- | M] () – C:\WINDOWS\System32\vamegeye.dll
[2099/01/01 12:00:00 | 000,054,272 | -HS- | M] () – C:\WINDOWS\System32\moyomego.dll
[2099/01/01 12:00:00 | 000,054,272 | -HS- | M] () – C:\WINDOWS\System32\gahipewo.dll
[2099/01/01 12:00:00 | 000,054,272 | -HS- | M] () – C:\WINDOWS\System32\fanenoto.dll
[2099/01/01 12:00:00 | 000,039,424 | -HS- | M] () – C:\WINDOWS\System32\jimiwemo.dll
[2099/01/01 12:00:00 | 000,039,424 | -HS- | M] () – C:\WINDOWS\System32\bimedufo.dll
[2010/02/09 21:24:32 | 000,006,456 | -H– | M] () – C:\WINDOWS\System32\dikabagu
[2010/02/09 21:00:00 | 000,000,296 | —- | M] () – C:\WINDOWS\tasks\dcsmkojo.job
[2010/02/09 19:58:45 | 000,057,344 | —- | M] () – C:\WINDOWS\System32\net.net
[50 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2010/02/08 03:00:00 | 000,000,518 | —- | M] () – C:\WINDOWS\tasks\SpywareStop Scheduled Scan.job

:Commands
[createrestorepoint]
[emptytemp]
[start explorer]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.




Next


Go HERE to get a copy of GMER. Scroll down to the Download section and click Download EXE. Save it to your desktop.

Before scanning with GMER, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

  • Double click on the file you downloaded. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries



If GMER will not run in normal windows, please try running it in safe mode.

Please post back with
  • OTL fix log
  • GMER log
  • new OTL scan log taken after all other steps, there will only be an OTL.txt this time
Thanks
Well… I copy pasted the and clicked run fix as requested…. The computer rebooted as expected… I was able to save the log… Then I tried to sign online through firefox. While loading my homepage everything just seemed to stop, not freeze but not load. I could open a new tab but nothing would load. I closed firefox and tried IE but it wouldn't open. In fact nothing would open. I could load, open, or do nothing. I could not even shut down or restart. I manually shut down. I had to go back to work (that's where I'm posting from) I will retry when I get home tonight. Is this something expected or a fluke? If I cannot get on from home I will get to a PC to see if I can download the GMER.exe onto a flash drive and take it home to run and post the logs from another PC in the same manner. UPDATE: the log I saved to my desktop from OTL would not open and everything is running very slow and prone to freezing.
Hi Amebeo, No that was totatly unexpected as we lefft the main infection alone until we have more information about it. Try GMER. If it runs please post the log. Also, do you have an XP disk, we may need to go a different route. Thanks
I do have the xp disk but it is a very old version SP1 I think… I did do a slipstream (Ithink that is what it was called) with SP3 but that was about 6 months or more ago. At present, I cannot even open a file. Cannot start in safe mode… when I boot up, press F8, select safe mode, it goes through a list of files on a black screen then restarts and asks me again safe or normal mode. This repeats until I select Start Windows Normaly. Cannot do a sysetm restore. Cannot sign on line Cannot open anything. My wife just wants me to get her pictures off there. I guess I'm gonna call around and see who localy can do that. My worrie is that since I cann't do anything how can I fix it? Let me know. On my luch I'll try to find that disk I made.
Hi Amebeo,

I think either disk will work. See if you can locate them as all we want to do is to access the Recovery Console.

If you have a USB device such as a flashdrive and access to another machine that you can burn an iso image with we should be able to get the pictures and other personal data off the computer. This iso has FireFox on it so you should be able go on line and return to this thread from the infected computer. We should also be able to run some scans on the computer now.


Let's start with making the iso image.

Two programs to download

First

ISOBurner this will allow you to burn REATOGO-X-PE ISO to a cd and make it bootable. Just install the programme, from there on in it is fairly automatic. Instructions

Second

Download OTLPE Network.iso and burn to a CD using a program capable of burning an iso. NOTE: This file is 429Mb in size so it may take some time to download.

note: when saving this program make sure you save it with the save as file type set to all files and the file after it is downloaded is 429mb.

After the file is downloaded, double click it, this will then open ISOBurner to burn the file to CD.




After it has completed burning, put in cd in the effected computer and reboot.

On the ailing computer make sure the cd is set to be the first drive booted from. This can be set in the bios. When the computer is first started you should be given an option to boot to setup. You will be told which key to press to enter setup. As each computer is different you will need to look for a setting called Boot Order or similar. Follow the instructions there to set the cd first in the order. Save the changes, if you made any, and exit setup. The computer should now boot from the cd.

Please be patient as it is running from the cd and can be quiet slow. One of the first screens you will see is a confirmation it is booting from the cd. This will be followed by a screen saying starting Reatogo X PE. It may take awhile to load the necessary files. You should be presented with a light blue screen followed shorty by a Reatogo desktop. It will have what looks like a Swiss Army knife and some icons on it.


Please post back once you have made the iso and are on line or if you are having difficulty creating the iso.

Thanks
Iso created, boot was successful… Awaiting orders I will be back after work Oh and I may have found my xp sp3 slipstream disk… (I say might because I didn't label it) I still have my original xp disk though.
Hi Amebeo,

Good to "see" you here. we may need the disk(s) but let's see what we can do first.

First we'll se if we can get the log from the OTL fix we ran.

On the desktop you should see a "MyComputer" icon. Double click it to open it.
  • At the top click on Folders
  • Double click on local disk(c:)
  • Navigate to C:\_OTL\MovedFiles
  • In the right hand panel locate a file with a name consisting of numbers and a log extention. The name represents the date time we ran the OTL fix. Similar to 02102010 xxxxxx.log
  • Please post it's contents
You can close that window.

Next

On the desktop, please locate OTLPE
  • Double-click on the OTLPE icon.
  • When asked "Do you wish to load the remote registry", select Yes
  • When asked "Do you wish to load remote user profile(s) for scanning", select Yes
  • Ensure the box "Automatically Load All Remaining Users" is checked and press OK
  • OTL should now start. Change the following settings
    • Change Standard Registry to All
    • In the window under Custom Scans/Fixes copy and paste the following


      netsvcs
      %SYSTEMDRIVE%\*.exe
      /md5start
      eventlog.dll
      scecli.dll
      netlogon.dll
      cngaudit.dll
      sceclt.dll
      ntelogon.dll
      logevent.dll
      iaStor.sys
      nvstor.sys
      atapi.sys
      IdeChnDr.sys
      viasraid.sys
      AGP440.sys
      vaxscsi.sys
      nvatabus.sys
      viamraid.sys
      nvata.sys
      nvgts.sys
      iastorv.sys
      ViPrt.sys
      eNetHook.dll
      ahcix86.sys
      KR10N.sys
      nvstor32.sys
      ahcix86s.sys
      nvrd32.sys
      symmpi.sys
      adp3132.sys
      mv61xx.sys
      /md5stop
      %systemroot%\*. /mp /s
      %systemroot%\system32\*.dll /lockedfiles
      %systemroot%\Tasks\*.job /lockedfiles
      %systemroot%\system32\drivers\*.sys /lockedfiles
      %systemroot%\System32\config\*.sav


  • Press Run Scan to start the scan.
  • When finished, the file will be saved in drive C:\OTL.txt

If you wish to back up your pictures you can copy them to a usb device. You won't be able to use your CD as we are running OTLPE from it.

Just work from within the "MY Computer" window.

Please post
  • OTL fix log you retrieved
  • OTLPE scan log

Thanks
All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
No active process named net.net was found!
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\jedugikuf deleted successfully.
C:\WINDOWS\system32\hazafupe.dll moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\net deleted successfully.
C:\WINDOWS\system32\net.net moved successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:c:\windows\system32\libukifu.dll c:\windows\system32\hazafupe.dll deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:moyomego.dll deleted successfully.
C:\WINDOWS\system32\moyomego.dll moved successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\kaludafap deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{141a9890-8ffc-4f80-92b7-7b9b6d992846}\ deleted successfully.
File C:\WINDOWS\system32\hazafupe.dll not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\wukatuhow deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b8dd6e4d-809f-412f-a2a2-cc3789aa7f12}\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\\{141a9890-8ffc-4f80-92b7-7b9b6d992846} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{141a9890-8ffc-4f80-92b7-7b9b6d992846}\ deleted successfully.
File C:\WINDOWS\system32\hazafupe.dll not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\\{b8dd6e4d-809f-412f-a2a2-cc3789aa7f12} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b8dd6e4d-809f-412f-a2a2-cc3789aa7f12}\ not found.
C:\WINDOWS\System32\dllcache\SET92.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SET93.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SET94.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SET95.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SET96.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SET97.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SET98.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SET99.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SET9A.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SET9B.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SET9C.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SET9D.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SET9E.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SET9F.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SETA0.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SETA1.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SETA2.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SETA3.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SETA4.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SETA5.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SETA6.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SETA7.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SETA8.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SETA9.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SETAA.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SETAB.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SETAC.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SETAD.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SETAE.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SETAF.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SETB0.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SETB1.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SETB2.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SETB3.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SETB4.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SETB5.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SETB6.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SETB7.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SETB8.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SETB9.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SETBA.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SETBB.tmp deleted successfully.
C:\WINDOWS\000001_.tmp deleted successfully.
C:\WINDOWS\003242_.tmp deleted successfully.
C:\WINDOWS\3FA195A010BE43159B7C1486845BD002.TMP\WiseCustomCall.dll deleted successfully.
C:\WINDOWS\3FA195A010BE43159B7C1486845BD002.TMP\WiseCustomCalla.dll deleted successfully.
C:\WINDOWS\3FA195A010BE43159B7C1486845BD002.TMP\WiseCustomCalla2.exe deleted successfully.
C:\WINDOWS\3FA195A010BE43159B7C1486845BD002.TMP\WiseData.ini deleted successfully.
C:\WINDOWS\3FA195A010BE43159B7C1486845BD002.TMP folder deleted successfully.
File C:\WINDOWS\System32\hazafupe.dll not found.
File C:\WINDOWS\System32\zahatahe.dll not found.
C:\WINDOWS\system32\vamegeye.dll moved successfully.
File C:\WINDOWS\System32\moyomego.dll not found.
C:\WINDOWS\system32\gahipewo.dll moved successfully.
C:\WINDOWS\system32\fanenoto.dll moved successfully.
C:\WINDOWS\system32\jimiwemo.dll moved successfully.
C:\WINDOWS\system32\bimedufo.dll moved successfully.
C:\WINDOWS\system32\dikabagu moved successfully.
File C:\WINDOWS\tasks\dcsmkojo.job not found.
File C:\WINDOWS\System32\net.net not found.
C:\WINDOWS\System32\bohumoye.dll.tmp deleted successfully.
C:\WINDOWS\System32\CONFIG.TMP deleted successfully.
C:\WINDOWS\System32\jemaluja.dll.tmp deleted successfully.
C:\WINDOWS\System32\samazaho.dll.tmp deleted successfully.
C:\WINDOWS\System32\SET100.tmp deleted successfully.
C:\WINDOWS\System32\SET101.tmp deleted successfully.
C:\WINDOWS\System32\SET102.tmp deleted successfully.
C:\WINDOWS\System32\SET103.tmp deleted successfully.
C:\WINDOWS\System32\SET105.tmp deleted successfully.
C:\WINDOWS\System32\SET4F.tmp deleted successfully.
C:\WINDOWS\System32\SET50.tmp deleted successfully.
C:\WINDOWS\System32\SETA0.tmp deleted successfully.
C:\WINDOWS\System32\SETA5.tmp deleted successfully.
C:\WINDOWS\System32\SETAC.tmp deleted successfully.
C:\WINDOWS\System32\SETD1.tmp deleted successfully.
C:\WINDOWS\System32\SETD2.tmp deleted successfully.
C:\WINDOWS\System32\SETD4.tmp deleted successfully.
C:\WINDOWS\System32\SETD5.tmp deleted successfully.
C:\WINDOWS\System32\SETD6.tmp deleted successfully.
C:\WINDOWS\System32\SETD7.tmp deleted successfully.
C:\WINDOWS\System32\SETD8.tmp deleted successfully.
C:\WINDOWS\System32\SETDA.tmp deleted successfully.
C:\WINDOWS\System32\SETDC.tmp deleted successfully.
C:\WINDOWS\System32\SETDD.tmp deleted successfully.
C:\WINDOWS\System32\SETDE.tmp deleted successfully.
C:\WINDOWS\System32\SETE1.tmp deleted successfully.
C:\WINDOWS\System32\SETE2.tmp deleted successfully.
C:\WINDOWS\System32\SETE5.tmp deleted successfully.
C:\WINDOWS\System32\SETE6.tmp deleted successfully.
C:\WINDOWS\System32\SETE8.tmp deleted successfully.
C:\WINDOWS\System32\SETEA.tmp deleted successfully.
C:\WINDOWS\System32\SETEB.tmp deleted successfully.
C:\WINDOWS\System32\SETEC.tmp deleted successfully.
C:\WINDOWS\System32\SETED.tmp deleted successfully.
C:\WINDOWS\System32\SETEE.tmp deleted successfully.
C:\WINDOWS\System32\SETEF.tmp deleted successfully.
C:\WINDOWS\System32\SETF0.tmp deleted successfully.
C:\WINDOWS\System32\SETF1.tmp deleted successfully.
C:\WINDOWS\System32\SETF3.tmp deleted successfully.
C:\WINDOWS\System32\SETF4.tmp deleted successfully.
C:\WINDOWS\System32\SETF5.tmp deleted successfully.
C:\WINDOWS\System32\SETF6.tmp deleted successfully.
C:\WINDOWS\System32\SETF7.tmp deleted successfully.
C:\WINDOWS\System32\SETF8.tmp deleted successfully.
C:\WINDOWS\System32\SETF9.tmp deleted successfully.
C:\WINDOWS\System32\SETFA.tmp deleted successfully.
C:\WINDOWS\System32\SETFB.tmp deleted successfully.
C:\WINDOWS\System32\SETFC.tmp deleted successfully.
C:\WINDOWS\System32\SETFD.tmp deleted successfully.
C:\WINDOWS\System32\SETFE.tmp deleted successfully.
C:\WINDOWS\tasks\SpywareStop Scheduled Scan.job moved successfully.
========== COMMANDS ==========
Restore point Set: OTL Restore Point (64424509440)

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 241441 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: HP_Administrator
->Temp folder emptied: 23073443 bytes
->Temporary Internet Files folder emptied: 14734689 bytes
->Java cache emptied: 689346625 bytes
->FireFox cache emptied: 92731760 bytes

User: LocalService
->Temp folder emptied: 66051 bytes
->Temporary Internet Files folder emptied: 163974 bytes

User: MCX1
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: MCX2
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: MCX3
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: NetworkService
->Temp folder emptied: 2621136 bytes
->Temporary Internet Files folder emptied: 98510955 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 1341289 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 23970461 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 357319096 bytes

Total Files Cleaned = 1,244.00 mb


OTL by OldTimer - Version 3.1.28.0 log created on 02102010_122739

Files\Folders moved on Reboot…
File\Folder C:\Documents and Settings\HP_Administrator\Local Settings\Temp\Temporary Internet Files\Content.IE5\DXUPOV2Y\p;vpec=sp;atf=1;atf=s;pfl=1;dt=s;!c=hagl;!c=hagn;afid=356682832;dsid=699259;cp3=ret;cp3=cmt;;tt=j;u=b0031iew2oo13p3flw
q,f0f12sa,g10005c;sz=728x90;tile=1;ord=5948120701051589;[1] not found!
File\Folder C:\Documents and Settings\HP_Administrator\Local Settings\Temp\Temporary Internet Files\Content.IE5\DXUPOV2Y\p;vpec=sp;atf=1;atf=s;pfl=1;dt=s;!c=hagl;!c=hagn;afid=356682832;dsid=699259;cp3=ret;cp3=cmt;;tt=j;u=b0032iew2oo13p3flw
q,f0f12sa,g10005c;sz=728x90;tile=2;ord=5948120701051589;[1] not found!
File\Folder C:\Documents and Settings\HP_Administrator\Local Settings\Temp\Temporary Internet Files\Content.IE5\8TR2XC8I\ec=tgt;ec=tls;ec=tmu;ec=ttec;ia=pc;p=1;pec=be;to=kyb;vec=sp;vpec=sp;atf=1;a
tf=s;pfl=1;dt=s;!c=hagl;!c=hagn;;afid=356682832;dsid=699259;;sz=888x11;ord=5948120701051589;_g_cv=1[1
] not found!
C:\Documents and Settings\HP_Administrator\Local Settings\Temp\4.tmp moved successfully.
File\Folder C:\WINDOWS\temp\ZLT04c7d.TMP not found!

Registry entries deleted on Reboot…


OTL logfile created on: 2/11/2010 10:15:32 PM - Run
OTLPE by OldTimer - Version 3.1.28.0 Folder = X:\Programs\OTLPE
Microsoft Windows XP Service Pack 3 (Version = 5.1.2600) - Type = SYSTEM
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

958.00 Mb Total Physical Memory | 645.00 Mb Available Physical Memory | 67.00% Memory free
858.00 Mb Paging File | 672.00 Mb Available in Paging File | 78.00% Paging File free
Paging file location(s): C:\pagefile.sys 1440 2880 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 177.79 Gb Total Space | 79.94 Gb Free Space | 44.96% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
Drive H: | 8.50 Gb Total Space | 1.12 Gb Free Space | 13.13% Space Free | Partition Type: FAT32
I: Drive not present or media not loaded
Drive X: | 429.26 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: REATOGO
Current User Name: SYSTEM
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
Using ControlSet: ControlSet001

========== Win32 Services (SafeList) ==========

SRV - [2010/02/03 21:06:40 | 000,135,664 | —- | M] (Google Inc.) [Auto] – C:\Program Files\Google\Update\GoogleUpdate.exe – (gupdate) Google Update Service (gupdate)
SRV - [2009/11/12 16:33:00 | 000,545,568 | —- | M] (Apple Inc.) [On_Demand] – C:\Program Files\iPod\bin\iPodService.exe – (iPod Service)
SRV - [2009/08/28 08:13:46 | 000,908,056 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto] – C:\Program Files\AVG\AVG8\avgemc.exe – (avg8emc)
SRV - [2009/08/28 08:13:38 | 000,297,752 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto] – C:\Program Files\AVG\AVG8\avgwdsvc.exe – (avg8wd)
SRV - [2009/07/09 11:22:18 | 000,144,712 | —- | M] (Apple Inc.) [Auto] – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe – (Apple Mobile Device)
SRV - [2009/05/07 15:50:24 | 001,089,536 | —- | M] () [Auto] – C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe – (LeapFrog Connect Device Service)
SRV - [2009/03/29 09:33:48 | 000,183,280 | —- | M] (Google) [Auto] – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe – (gusvc)
SRV - [2008/12/12 10:17:38 | 000,238,888 | —- | M] (Apple Inc.) [Auto] – C:\Program Files\Bonjour\mDNSResponder.exe – (Bonjour Service)
SRV - [2008/10/09 14:25:32 | 002,405,776 | —- | M] (Check Point Software Technologies LTD) [Auto] – C:\WINDOWS\System32\ZoneLabs\vsmon.exe – (vsmon)
SRV - [2008/09/10 22:37:36 | 000,024,576 | —- | M] (Intuit) [Auto] – C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe – (QBCFMonitorService)
SRV - [2008/08/08 21:10:46 | 000,061,440 | —- | M] (Intuit Inc.) [On_Demand] – C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe – (QBFCService)
SRV - [2007/01/04 16:38:08 | 000,024,652 | —- | M] (Viewpoint Corporation) [Auto] – C:\Program Files\Viewpoint\Common\ViewpointService.exe – (Viewpoint Manager Service)
SRV - [2006/11/02 19:40:12 | 000,174,656 | —- | M] () [Auto] – C:\WINDOWS\system32\PSIService.exe – (ProtexisLicensing)
SRV - [2006/01/06 21:25:12 | 000,069,632 | —- | M] (Sony Corporation) [Disabled] – C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe – (SSScsiSV)
SRV - [2005/11/24 16:03:22 | 000,053,337 | —- | M] (Sony Corporation) [On_Demand] – C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe – (MSCSPTISRV)
SRV - [2005/11/24 15:57:44 | 000,053,337 | —- | M] (Sony Corporation) [On_Demand] – C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe – (PACSPTISVR)
SRV - [2005/11/24 15:47:30 | 000,069,718 | —- | M] (Sony Corporation) [Disabled] – C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe – (SPTISRV)
SRV - [2005/10/23 08:46:44 | 000,069,632 | —- | M] (Hewlett-Packard Company) [Disabled] – C:\Program Files\Common Files\LightScribe\LSSrvc.exe – (LightScribeService)
SRV - [2005/10/20 19:55:40 | 000,028,160 | —- | M] (Microsoft Corporation) [Disabled] – C:\WINDOWS\ehome\RMSvc.exe – (RMSvc)
SRV - [2005/09/09 02:24:30 | 000,102,400 | —- | M] () [Disabled] – C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe – (AdobeActiveFileMonitor4.0)
SRV - [2005/08/14 00:29:40 | 000,376,832 | —- | M] (ATI Technologies Inc.) [Auto] – C:\WINDOWS\system32\ati2evxx.exe – (Ati HotKey Poller)
SRV - [2005/08/03 02:19:16 | 000,058,880 | —- | M] (Microsoft) [Auto] – C:\WINDOWS\arservice.exe – (ARSVC)
SRV - [2005/04/03 23:41:10 | 000,069,632 | —- | M] (Macrovision Corporation) [On_Demand] – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe – (IDriverT)
SRV - [2004/09/29 11:14:36 | 000,069,632 | —- | M] (HP) [Boot] – C:\WINDOWS\system32\HPZipm12.exe – (Pml Driver HPZ12)
SRV - [2003/07/28 22:28:22 | 000,089,136 | —- | M] (Microsoft Corporation) [On_Demand] – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE – (ose)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand] – – (WDICA)
DRV - File not found [Kernel | On_Demand] – – (PDRFRAME)
DRV - File not found [Kernel | On_Demand] – – (PDRELI)
DRV - File not found [Kernel | On_Demand] – – (PDFRAME)
DRV - File not found [Kernel | On_Demand] – – (PDCOMP)
DRV - File not found [Kernel | System] – – (PCIDump)
DRV - File not found [Kernel | System] – – (lbrtfdc)
DRV - File not found [Kernel | System] – – (i2omgmt)
DRV - File not found [Kernel | System] – – (Changer)
DRV - [2009/08/28 08:13:53 | 000,335,240 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System] – C:\WINDOWS\System32\Drivers\avgldx86.sys – (AvgLdx86)
DRV - [2009/08/28 08:13:53 | 000,027,784 | —- | M] (AVG Technologies CZ, s.r.o.) [File_System | System] – C:\WINDOWS\System32\Drivers\avgmfx86.sys – (AvgMfx86)
DRV - [2009/06/06 09:41:36 | 000,018,560 | —- | M] (LeapFrog) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\FlyUsb.sys – (FlyUsb)
DRV - [2009/05/20 08:51:26 | 000,108,552 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System] – C:\WINDOWS\System32\Drivers\avgtdix.sys – (AvgTdiX)
DRV - [2009/05/18 13:17:00 | 000,026,600 | —- | M] (GEAR Software Inc.) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\GEARAspiWDM.sys – (GEARAspiWDM)
DRV - [2008/10/09 14:25:36 | 000,353,680 | —- | M] (Check Point Software Technologies LTD) [Kernel | System] – C:\WINDOWS\system32\vsdatant.sys – (vsdatant)
DRV - [2008/04/21 07:19:58 | 000,051,648 | —- | M] (Check Point Software Technologies LTD) [Kernel | Boot] – C:\WINDOWS\system32\ZoneLabs\srescan.sys – (srescan)
DRV - [2008/04/13 13:45:32 | 000,059,136 | —- | M] (Microsoft Corporation) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\gckernel.sys – (GcKernel)
DRV - [2008/04/13 13:45:12 | 000,060,032 | —- | M] (Microsoft Corporation) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\usbaudio.sys – (usbaudio) USB Audio Driver (WDM)
DRV - [2008/04/13 13:40:30 | 000,096,512 | —- | M] () [Kernel | Boot] – C:\WINDOWS\system32\drivers\atapi.sys – (atapi)
DRV - [2007/11/13 05:25:53 | 000,020,480 | —- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\secdrv.sys – (Secdrv)
DRV - [2007/06/05 10:56:40 | 000,044,928 | —- | M] (Panda Software) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\SDTHOOK.SYS – (SDTHOOK)
DRV - [2005/10/26 15:12:48 | 000,020,640 | —- | M] (Sonic Solutions) [Kernel | Boot] – C:\WINDOWS\system32\drivers\pxhelp20.sys – (PxHelp20)
DRV - [2005/08/29 17:11:00 | 003,644,928 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\ALCXWDM.SYS – (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2005/08/14 00:35:54 | 001,313,792 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\ati2mtag.sys – (ati2mtag)
DRV - [2005/07/04 02:30:34 | 000,026,624 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\PS2.sys – (Ps2)
DRV - [2005/06/30 03:03:18 | 000,175,104 | —- | M] (Promise Technology, Inc.) [Kernel | Boot] – C:\WINDOWS\system32\drivers\ftsata2.sys – (ftsata2)
DRV - [2005/06/17 16:33:40 | 000,872,064 | —- | M] (Intel Corporation) [Kernel | Boot] – C:\WINDOWS\system32\drivers\iaStor.sys – (iaStor)
DRV - [2005/03/09 16:53:00 | 000,036,352 | —- | M] (Advanced Micro Devices) [Kernel | System] – C:\WINDOWS\system32\drivers\AmdK8.sys – (AmdK8)
DRV - [2005/03/08 13:52:28 | 000,021,744 | —- | M] (HP) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\HPZius12.sys – (HPZius12)
DRV - [2005/03/08 13:52:28 | 000,016,496 | —- | M] (HP) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\HPZipr12.sys – (HPZipr12)
DRV - [2005/03/08 13:52:26 | 000,051,120 | —- | M] (HP) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\HPZid412.sys – (HPZid412)
DRV - [2005/03/04 13:10:26 | 000,074,496 | —- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\Rtlnicxp.sys – (RTL8023xp)
DRV - [2004/12/15 17:18:32 | 000,220,928 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\HSFHWBS2.sys – (HSFHWBS2)
DRV - [2004/12/15 17:18:28 | 000,703,232 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\HSF_CNXT.sys – (winachsf)
DRV - [2004/12/15 17:18:26 | 001,038,208 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\HSF_DP.sys – (HSF_DP)
DRV - [2004/10/07 20:16:04 | 000,035,840 | —- | M] (Oak Technology Inc.) [Kernel | System] – C:\WINDOWS\system32\drivers\AFS2K.SYS – (AFS2K)
DRV - [2004/09/15 03:42:14 | 000,068,672 | R— | M] (2Wire, Inc.) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\2WirePCP.sys – (2WIREPCP)
DRV - [2004/08/10 07:00:00 | 000,017,792 | —- | M] (Parallel Technologies, Inc.) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\ptilink.sys – (Ptilink)
DRV - [2004/08/10 07:00:00 | 000,007,936 | —- | M] (Microsoft Corporation) [Recognizer | System] – C:\WINDOWS\system32\drivers\fs_rec.sys – (Fs_Rec)
DRV - [2004/08/10 07:00:00 | 000,002,864 | —- | M] (Microsoft Corporation) [Adapter | On_Demand] – C:\WINDOWS\system32\winsock.dll – (Winsock)
DRV - [2004/08/04 00:31:34 | 000,020,992 | —- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\RTL8139.sys – (rtl8139) Realtek RTL8139(A/B/C)
DRV - [2004/04/13 19:20:08 | 000,015,781 | R— | M] (Meetinghouse Data Communications) [Kernel | Auto] – C:\WINDOWS\system32\drivers\mdc8021x.sys – (MDC8021X) AEGIS Protocol (IEEE 802.1x)
DRV - [2004/03/17 13:04:14 | 000,013,059 | —- | M] (Conexant) [Kernel | Auto] – C:\WINDOWS\system32\drivers\mdmxsdk.sys – (mdmxsdk)
DRV - [2004/03/08 12:55:50 | 000,013,567 | —- | M] (B.H.A Corporation) [Kernel | System] – C:\WINDOWS\system32\drivers\CDRBSDRV.SYS – (cdrbsdrv)
DRV - [2003/11/05 17:45:12 | 000,017,408 | —- | M] (Promise Technology, Inc.) [Kernel | Boot] – C:\WINDOWS\system32\drivers\bb-run.sys – (bb-run)
DRV - [2002/10/15 21:41:06 | 000,102,220 | —- | M] (Sony Corporation) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\sonypvs1.sys – (sonypvs1)
DRV - [2001/08/17 14:02:56 | 000,003,968 | —- | M] (Microsoft Corporation) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\SWUSBFLT.SYS – (SWUSBFLT)
DRV - [2001/08/17 14:02:50 | 000,002,688 | —- | M] (Microsoft Corporation) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\hidswvd.sys – (HIDSwvd)


========== Standard Registry (All) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie


IE - HKU\Administrator_ON_C\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKU\Administrator_ON_C\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKU\Administrator_ON_C\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
IE - HKU\Administrator_ON_C\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)
IE - HKU\Administrator_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\HP_Administrator_ON_C\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKU\HP_Administrator_ON_C\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKU\HP_Administrator_ON_C\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKU\HP_Administrator_ON_C\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKU\HP_Administrator_ON_C\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://swagbucks.com/
IE - HKU\HP_Administrator_ON_C\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKU\HP_Administrator_ON_C\..\URLSearchHook: {8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94} - C:\Program Files\Swag_Bucks\tbSwa1.dll (Conduit Ltd.)
IE - HKU\HP_Administrator_ON_C\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)
IE - HKU\HP_Administrator_ON_C\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
IE - HKU\HP_Administrator_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\HP_Administrator_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local


IE - HKU\MCX1_ON_C\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
IE - HKU\MCX1_ON_C\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
IE - HKU\MCX1_ON_C\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKU\MCX1_ON_C\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
IE - HKU\MCX1_ON_C\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
IE - HKU\MCX1_ON_C\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)
IE - HKU\MCX1_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\MCX2_ON_C\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
IE - HKU\MCX2_ON_C\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
IE - HKU\MCX2_ON_C\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKU\MCX2_ON_C\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
IE - HKU\MCX2_ON_C\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
IE - HKU\MCX2_ON_C\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://red.clientapps.yahoo.com/customize/…/search/ie.html
IE - HKU\MCX2_ON_C\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)
IE - HKU\MCX2_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\MCX3_ON_C\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
IE - HKU\MCX3_ON_C\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
IE - HKU\MCX3_ON_C\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKU\MCX3_ON_C\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
IE - HKU\MCX3_ON_C\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
IE - HKU\MCX3_ON_C\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://red.clientapps.yahoo.com/customize/…/search/ie.html
IE - HKU\MCX3_ON_C\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)
IE - HKU\MCX3_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\NetworkService_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/09/01 21:00:40 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/02/08 22:40:14 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/02/08 22:40:14 | 000,000,000 | —D | M]

[2009/11/06 17:38:45 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/02/08 22:40:14 | 000,000,000 | —D | M] (Default) – C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2010/02/08 22:40:00 | 000,023,000 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\browserdirprovider.dll
[2010/02/08 22:40:00 | 000,138,712 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\brwsrcmp.dll
[2010/01/18 22:21:34 | 000,393,216 | —- | M] (Invenda Corporation) – C:\Program Files\Mozilla Firefox\plugins\NPcol400.dll
[2008/06/18 01:43:04 | 000,086,016 | —- | M] (Coupons, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
[2009/03/18 09:03:40 | 000,214,272 | —- | M] (Midasplayer Ltd) – C:\Program Files\Mozilla Firefox\plugins\npmidas.dll
[2010/02/08 22:40:06 | 000,064,984 | —- | M] (mozilla.org) – C:\Program Files\Mozilla Firefox\plugins\npnul32.dll
[2009/12/25 07:58:57 | 000,159,744 | —- | M] (Apple Inc.) – C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
[2009/12/25 07:58:57 | 000,159,744 | —- | M] (Apple Inc.) – C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
[2009/12/25 07:58:57 | 000,159,744 | —- | M] (Apple Inc.) – C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
[2009/12/25 07:58:58 | 000,159,744 | —- | M] (Apple Inc.) – C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
[2009/12/25 07:58:58 | 000,159,744 | —- | M] (Apple Inc.) – C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
[2009/12/25 07:58:58 | 000,159,744 | —- | M] (Apple Inc.) – C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
[2009/12/25 07:58:58 | 000,159,744 | —- | M] (Apple Inc.) – C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
[2007/04/16 12:07:12 | 000,180,293 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\npViewpoint.dll
[2010/02/08 22:40:08 | 000,001,394 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\amazondotcom.xml
[2010/02/08 22:40:08 | 000,002,193 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\answers.xml
[2010/02/08 22:40:08 | 000,001,534 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\creativecommons.xml
[2010/02/08 22:40:08 | 000,002,344 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay.xml
[2010/02/08 22:40:08 | 000,002,371 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\google.xml
[2010/02/08 22:40:08 | 000,001,178 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\wikipedia.xml
[2010/02/08 22:40:08 | 000,001,096 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo.xml

O1 HOSTS File: ([2004/08/10 14:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Yahoo! IE Services Button) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Swag Bucks Toolbar) - {8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94} - C:\Program Files\Swag_Bucks\tbSwa1.dll (Conduit Ltd.)
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Swag Bucks Toolbar) - {8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94} - C:\Program Files\Swag_Bucks\tbSwa1.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Yahoo! ¤u¨ã¦C) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKU\Administrator_ON_C\..\Toolbar\WebBrowser: (&Address) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O3 - HKU\Administrator_ON_C\..\Toolbar\WebBrowser: (&Links) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O3 - HKU\Administrator_ON_C\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKU\HP_Administrator_ON_C\..\Toolbar\ShellBrowser: (&Address) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O3 - HKU\HP_Administrator_ON_C\..\Toolbar\ShellBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKU\HP_Administrator_ON_C\..\Toolbar\WebBrowser: (&Address) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O3 - HKU\HP_Administrator_ON_C\..\Toolbar\WebBrowser: (&Links) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O3 - HKU\HP_Administrator_ON_C\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKU\HP_Administrator_ON_C\..\Toolbar\WebBrowser: (Swag Bucks Toolbar) - {8BDEA9D6-6F62-45EB-8EE9-8A81AF0D2F94} - C:\Program Files\Swag_Bucks\tbSwa1.dll (Conduit Ltd.)
O3 - HKU\HP_Administrator_ON_C\..\Toolbar\WebBrowser: (Yahoo! ¤u¨ã¦C) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKU\HP_Administrator_ON_C\..\Toolbar\WebBrowser: (&Links) - {F2CF5485-4E02-4F68-819C-B92DE9277049} - C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)
O3 - HKU\MCX1_ON_C\..\Toolbar\WebBrowser: (&Address) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O3 - HKU\MCX1_ON_C\..\Toolbar\WebBrowser: (&Links) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O3 - HKU\MCX1_ON_C\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKU\MCX2_ON_C\..\Toolbar\WebBrowser: (&Address) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O3 - HKU\MCX2_ON_C\..\Toolbar\WebBrowser: (&Links) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O3 - HKU\MCX2_ON_C\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKU\MCX3_ON_C\..\Toolbar\WebBrowser: (&Address) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O3 - HKU\MCX3_ON_C\..\Toolbar\WebBrowser: (&Links) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O3 - HKU\MCX3_ON_C\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\hpwuSchd2.exe (Hewlett-Packard Co.)
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [jedugikuf] C:\WINDOWS\System32\melasora.DLL ()
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [Monitor] C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe ()
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask.exe (Apple Inc.)
O4 - HKLM..\Run: [SsAAD.exe] C:\Program Files\Sony\SonicStage\SSAAD.exe ()
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKU\Administrator_ON_C..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)
O4 - HKU\HP_Administrator_ON_C..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)
O4 - HKU\HP_Administrator_ON_C..\Run: [msnmsgr] C:\Program Files\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
O4 - HKU\HP_Administrator_ON_C..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKU\HP_Administrator_ON_C..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
O4 - HKU\MCX1_ON_C..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)
O4 - HKU\MCX2_ON_C..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)
O4 - HKU\MCX3_ON_C..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKU\Administrator_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\HP_Administrator_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\LocalService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\MCX1_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\MCX2_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\MCX3_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\NetworkService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ()
O9 - Extra 'Tools' menuitem : Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ()
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\WINDOWS\system32\winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\system32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\system32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: trymedia.com ([]http in Trusted sites)
O15 - HKLM\..Trusted Domains: trymedia.com ([]https in Trusted sites)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab (Checkers Class)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/e/4…/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://pcpitstop.com/betapit/PCPitStop.CAB (PCPitstop Utility)
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} file:///C:/Program%20Files/Risk/Images/stg_drm.ocx (SpinTop DRM Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/C/0…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab (Minesweeper Flags Class)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} http://www.pogo.com/cdl/launcher/PogoWebLa…erInstaller.CAB (PogoWebLauncher Control)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://photo.walgreens.com/WalgreensActivia.cab (Snapfish Activia)
O16 - DPF: {45A0A292-ECC6-4D8F-9EA9-A4BD411D24C1} http://www.king.com/ctl/kingcomie.cab (king.com)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {54BE6B6F-3056-470B-97E1-BB92E051B6C4} http://h20264.www2.hp.com/ediags/dd/instal…nosticsxp2k.cab (DeviceEnum Class)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://go.divx.com/plugin/DivXBrowserPlugin.cab (DivXBrowserPlugin Object)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab (MessengerStatsClient Class)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} http://web1.shutterfly.com/downloads/Uploader.cab (Shutterfly Picture Upload Plugin)
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} http://acs.pandasoftware.com/activescan/as5free/asinst.cab (ActiveScan Installer Class)
O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} http://offers.e-centives.com/cif/download/bin/actxcab.cab (CBSTIEPrint Class)
O16 - DPF: {BE319D04-18BD-4B34-AECC-EE7CB610FCA9} http://download.games.yahoo.com/games/web_…itched/main.cab (BewitchedGameClass Control)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} file:///C:/Program%20Files/Monopoly/Images/armhelper.ocx (ArmHelper Control)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} http://h30043.www3.hp.com/hpdj/en/check/qdiagh.cab?326 (QDiagHUpdateObj Class)
O16 - DPF: {F137B9BA-89EA-4B04-9C67-2074A9DF61FD} http://cvs.pnimedia.com/upload/activex/v2_…upv2.0.0.10.cab? (Photo Upload Plugin Class)
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} http://dlm.tools.akamai.com/dlmanager/vers…ivex-latest.cab (DownloadManager Control)
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\intu-help-qb2 {84D77A00-41B5-4b8b-8ADF-86486D72E749} - C:\Program Files\Intuit\QuickBooks 2009\HelpAsyncPluggableProtocol.dll (Intuit, Inc.)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\system32\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\qbwc {FC598A64-626C-4447-85B8-53150405FD57} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\sysimage {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\system32\wiascr.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\Class Install Handler {32B533BB-EDAE-11d0-BD5A-00AA00B92AF1} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\deflate {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\gzip {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\lzdhtml {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/webviewhtml {733AC4CB-F1A4-11d0-B951-00A0C90312E1} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (c:\windows\system32\libukifu.dll) - C:\WINDOWS\System32\libukifu.dll File not found
O20 - AppInit_DLLs: (moyomego.dll) - File not found
O20 - AppInit_DLLs: (c:\windows\system32\melasora.dll) - C:\WINDOWS\system32\melasora.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (rundll32.exe) - File not found
O20 - HKLM Winlogon: Shell - (ajhg.kqo) - File not found
O20 - HKLM Winlogon: Shell - (prect) - File not found
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\sdra64.exe) - C:\WINDOWS\system32\sdra64.exe (aSRcyOXSlEIiW)
O20 - HKLM Winlogon: UIHost - (logonui.exe) - C:\WINDOWS\System32\logonui.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\WINDOWS\System32\sysdm.cpl (Microsoft Corporation)
O20 - HKU\MCX1_ON_C Winlogon: Shell - (C:\WINDOWS\eHome\McrMgr.exe) - C:\WINDOWS\ehome\mcrmgr.exe (Microsoft Corporation)
O20 - HKU\MCX2_ON_C Winlogon: Shell - (C:\WINDOWS\eHome\McrMgr.exe) - C:\WINDOWS\ehome\mcrmgr.exe (Microsoft Corporation)
O20 - HKU\MCX3_ON_C Winlogon: Shell - (C:\WINDOWS\eHome\McrMgr.exe) - C:\WINDOWS\ehome\mcrmgr.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\crypt32chain: DllName - crypt32.dll - C:\WINDOWS\System32\crypt32.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cryptnet: DllName - cryptnet.dll - C:\WINDOWS\System32\cryptnet.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cscdll: DllName - cscdll.dll - C:\WINDOWS\System32\cscdll.dll (Microsoft Corporation)
O20 - Winlogon\Notify\dimsntfy: DllName - %SystemRoot%\System32\dimsntfy.dll - C:\WINDOWS\system32\dimsntfy.dll (Microsoft Corporation)
O20 - Winlogon\Notify\NavLogon: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O20 - Winlogon\Notify\ScCertProp: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\Schedule: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\sclgntfy: DllName - sclgntfy.dll - C:\WINDOWS\System32\sclgntfy.dll (Microsoft Corporation)
O20 - Winlogon\Notify\SensLogn: DllName - WlNotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\termsrv: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\WgaLogon: DllName - WgaLogon.dll - C:\WINDOWS\System32\WgaLogon.dll (Microsoft Corporation)
O20 - Winlogon\Notify\wlballoon: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: ladatizuk - {71360016-f38c-4a18-b416-7d26a6eeb975} - C:\WINDOWS\system32\melasora.dll ()
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WINDOWS\system32\webcheck.dll (Microsoft Corporation)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {71360016-f38c-4a18-b416-7d26a6eeb975} - tokatiluy - C:\WINDOWS\system32\melasora.dll ()
O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\welcome.htm
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\welcome.htm
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msapsspc.dll) - C:\WINDOWS\System32\msapsspc.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (schannel.dll) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (digest.dll) - C:\WINDOWS\System32\digest.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msnsspc.dll) - C:\WINDOWS\System32\msnsspc.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (kerberos) - C:\WINDOWS\System32\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) - C:\WINDOWS\System32\wdigest.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/05/14 17:49:12 | 000,000,150 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2001/07/28 05:07:38 | 000,000,000 | -HS- | M] () - H:\AUTOEXEC.BAT – [ FAT32 ]
O32 - AutoRun File - [2004/04/30 06:01:14 | 000,000,053 | -HS- | M] () - H:\Autorun.inf – [ FAT32 ]
O32 - AutoRun File - [2006/03/24 06:06:41 | 000,000,053 | R— | M] () - X:\AUTORUN.INF – [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2005/09/01 14:12:30 | 000,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

========== Files/Folders - Created Within 30 Days ==========

[2010/02/11 12:47:51 | 000,000,000 | -HSD | C] – C:\WINDOWS\System32\lowsec
[2010/02/10 12:27:39 | 000,000,000 | —D | C] – C:\_OTL
[2010/02/09 22:09:17 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/02/09 22:09:14 | 000,019,160 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/02/09 22:09:14 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/02/09 22:01:23 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010/02/09 21:04:24 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2010/02/09 19:58:51 | 000,000,000 | -HSD | C] – C:\Documents and Settings\LocalService\IETldCache
[2010/02/09 07:45:48 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Administrator\PrivacIE
[2010/02/08 22:39:27 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Cooliris
[2010/02/08 01:57:51 | 000,000,000 | —D | C] – C:\WINDOWS\Minidump
[2010/02/07 17:50:02 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Administrator\IETldCache
[2010/02/03 21:10:30 | 000,000,000 | —D | C] – C:\Program Files\Train3D
[2010/02/03 21:02:10 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\temp.001
[2010/02/03 21:02:10 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\temp.000
[2010/01/28 15:00:25 | 000,188,960 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\WINGDE.DLL
[2010/01/28 15:00:25 | 000,092,208 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\WING.DLL
[2010/01/28 15:00:25 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\WING32.DLL
[2010/01/28 15:00:25 | 000,006,736 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\WINGDIB.DRV
[2010/01/28 15:00:25 | 000,005,024 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\WINGPAL.WND
[2010/01/18 22:21:22 | 000,443,944 | —- | C] (E-centives ) – C:\Documents and Settings\HP_Administrator\Desktop\CouponActivator.exe
[2007/08/01 14:19:14 | 000,774,144 | —- | C] (RealNetworks, Inc.) – C:\Program Files\RngInterstitial.dll
[2005/05/12 09:36:48 | 000,012,288 | —- | C] (Hewlett-Packard Co.) – C:\WINDOWS\Fonts\RandFont.dll

========== Files - Modified Within 30 Days ==========

[2099/01/01 12:00:00 | 000,093,696 | -HS- | M] () – C:\WINDOWS\System32\korumore.dll
[2099/01/01 12:00:00 | 000,093,184 | -HS- | M] () – C:\WINDOWS\System32\melasora.dll
[2099/01/01 12:00:00 | 000,062,464 | -HS- | M] () – C:\WINDOWS\System32\vugukibo.dll
[2099/01/01 12:00:00 | 000,039,424 | -HS- | M] () – C:\WINDOWS\System32\vedilune.dll
[2099/01/01 12:00:00 | 000,039,424 | -HS- | M] () – C:\WINDOWS\System32\gizokoro.dll
[2010/02/11 12:51:10 | 000,262,144 | —- | M] () – C:\Documents and Settings\NetworkService\NTUSER.DAT
[2010/02/11 12:51:10 | 000,241,664 | —- | M] () – C:\Documents and Settings\LocalService\ntuser.dat
[2010/02/11 12:51:08 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/02/11 12:50:56 | 007,950,336 | —- | M] () – C:\Documents and Settings\HP_Administrator\ntuser.dat
[2010/02/11 12:50:50 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/02/11 12:50:45 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\HP_Administrator\ntuser.ini
[2010/02/11 12:48:38 | 055,460,643 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/02/11 12:44:46 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/02/11 12:44:40 | 000,352,608 | -H– | M] () – C:\WINDOWS\System32\vsconfig.xml
[2010/02/11 12:43:55 | 000,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2010/02/11 12:43:35 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/02/11 12:43:12 | 1005,113,344 | -HS- | M] () – C:\hiberfil.sys
[2010/02/10 18:00:36 | 000,000,296 | —- | M] () – C:\WINDOWS\tasks\ntmvdegi.job
[2010/02/10 12:31:44 | 000,001,744 | -H– | M] () – C:\WINDOWS\System32\dikabagu
[2010/02/10 12:11:01 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/02/09 11:46:26 | 001,048,576 | —- | M] () – C:\Documents and Settings\Administrator\ntuser.dat
[2010/02/09 11:46:26 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Administrator\ntuser.ini
[2010/02/08 19:16:31 | 000,001,138 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\Facebook Home.url
[2010/02/08 14:12:06 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/02/07 17:41:07 | 004,285,014 | -H– | M] () – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\IconCache.db
[2010/02/05 21:55:17 | 000,743,752 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\Gallatin Steel Company.tif
[2010/02/03 21:10:01 | 000,253,952 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Setup1.exe
[2010/02/03 21:10:00 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\WINDOWS\temp.001
[2010/02/03 21:02:11 | 000,000,362 | —- | M] () – C:\WINDOWS\ST6UNST.000
[2010/02/03 21:02:10 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\WINDOWS\temp.000
[2010/02/03 20:04:07 | 000,040,448 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\Meijer.doc
[2010/01/28 18:07:12 | 000,000,294 | —- | M] () – C:\WINDOWS\EReg077.dat
[2010/01/28 15:00:22 | 000,000,216 | —- | M] () – C:\WINDOWS\TLCAPPS.INI
[2010/01/26 13:52:42 | 000,004,212 | -H– | M] () – C:\WINDOWS\System32\zllictbl.dat
[2010/01/21 19:20:06 | 000,000,629 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\Reader Rabbit's Toddler (2).lnk
[2010/01/21 18:55:59 | 000,086,016 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\2009.xls
[2010/01/19 21:39:36 | 000,142,495 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2010/01/19 16:45:14 | 000,048,640 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\Neil Petty - Industrial Electrician.doc
[2010/01/18 22:21:23 | 000,443,944 | —- | M] (E-centives ) – C:\Documents and Settings\HP_Administrator\Desktop\CouponActivator.exe
[2010/01/13 22:34:51 | 000,230,808 | R— | M] (Coupons, Inc.) – C:\WINDOWS\System32\cpnprt2.cid
[2010/01/13 22:10:23 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK

========== Files Created - No Company Name ==========

[2099/01/01 12:00:00 | 000,093,696 | -HS- | C] () – C:\WINDOWS\System32\korumore.dll
[2099/01/01 12:00:00 | 000,093,184 | -HS- | C] () – C:\WINDOWS\System32\melasora.dll
[2099/01/01 12:00:00 | 000,062,464 | -HS- | C] () – C:\WINDOWS\System32\vugukibo.dll
[2099/01/01 12:00:00 | 000,039,424 | -HS- | C] () – C:\WINDOWS\System32\vedilune.dll
[2099/01/01 12:00:00 | 000,039,424 | -HS- | C] () – C:\WINDOWS\System32\gizokoro.dll
[2010/02/10 12:28:28 | 000,000,296 | —- | C] () – C:\WINDOWS\tasks\ntmvdegi.job
[2010/02/10 12:28:25 | 000,001,744 | -H– | C] () – C:\WINDOWS\System32\dikabagu
[2010/02/09 11:47:40 | 1005,113,344 | -HS- | C] () – C:\hiberfil.sys
[2010/02/07 15:31:03 | 007,950,336 | —- | C] () – C:\Documents and Settings\HP_Administrator\ntuser.dat
[2010/02/07 15:31:03 | 000,241,664 | —- | C] () – C:\Documents and Settings\LocalService\ntuser.dat
[2010/02/05 21:55:16 | 000,743,752 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\Gallatin Steel Company.tif
[2010/02/03 21:06:50 | 000,000,886 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/02/03 21:06:50 | 000,000,882 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/02/03 21:02:10 | 000,000,362 | —- | C] () – C:\WINDOWS\ST6UNST.000
[2010/01/28 18:07:11 | 000,000,294 | —- | C] () – C:\WINDOWS\EReg077.dat
[2010/01/21 19:20:06 | 000,000,629 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\Reader Rabbit's Toddler (2).lnk
[2009/09/21 18:32:56 | 000,000,216 | —- | C] () – C:\WINDOWS\TLCAPPS.INI
[2009/07/22 20:03:42 | 000,000,110 | —- | C] () – C:\WINDOWS\{47FB62DF-832D-485F-95FC-C93BB08B8FE3}_WiseFW.ini
[2008/12/19 22:41:13 | 000,000,067 | —- | C] () – C:\Documents and Settings\HP_Administrator\Application Data\photoshow_express_setup.txt
[2008/12/09 15:32:54 | 000,000,095 | —- | C] () – C:\WINDOWS\QBChanUtil_Trigger.ini
[2008/09/13 09:45:51 | 000,000,023 | —- | C] () – C:\WINDOWS\MathMagic Personal 3.64.INI
[2008/09/13 09:45:11 | 000,016,498 | —- | C] () – C:\Program Files\setuplog.txt
[2008/09/13 09:45:11 | 000,015,834 | —- | C] () – C:\Program Files\uninstall.log
[2008/05/21 17:33:21 | 000,000,343 | —- | C] () – C:\WINDOWS\SIERRA.INI
[2008/03/14 14:32:38 | 000,000,343 | —- | C] () – C:\WINDOWS\ULead32.ini
[2008/02/23 18:10:33 | 000,000,071 | —- | C] () – C:\WINDOWS\Pex.INI
[2008/02/04 17:23:10 | 000,693,792 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.DLL
[2008/02/03 12:19:20 | 000,006,144 | —- | C] () – C:\Documents and Settings\MCX3\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/02/03 10:51:00 | 000,000,127 | —- | C] () – C:\Documents and Settings\MCX3\Local Settings\Application Data\fusioncache.dat
[2007/10/29 19:24:32 | 000,000,190 | —- | C] () – C:\Documents and Settings\HP_Administrator\Application Data\G-Force Prefs (WindowsMediaPlayer).txt
[2007/08/03 14:09:41 | 000,003,454 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2007/08/03 14:09:41 | 000,000,008 | RHS- | C] () – C:\WINDOWS\System32\8036B57683.sys
[2007/05/21 18:43:37 | 000,000,560 | —- | C] () – C:\Documents and Settings\HP_Administrator\Application Data\ViewerApp.dat
[2007/05/14 17:47:01 | 000,003,654 | —- | C] () – C:\WINDOWS\System32\drivers\Sonyhcp.dll
[2007/05/13 18:58:44 | 000,098,304 | —- | C] () – C:\WINDOWS\System32\resourceGeneric.dll
[2007/01/29 12:23:40 | 000,011,776 | —- | C] () – C:\WINDOWS\System32\ZPORT4AS.dll
[2007/01/19 20:42:01 | 000,000,000 | —- | C] () – C:\WINDOWS\PROTOCOL.INI
[2006/10/14 15:06:20 | 000,796,584 | —- | C] () – C:\WINDOWS\System32\libeay32_0.9.6l.dll
[2006/10/14 12:58:32 | 000,000,127 | —- | C] () – C:\Documents and Settings\MCX2\Local Settings\Application Data\fusioncache.dat
[2006/08/26 15:13:30 | 000,000,000 | —- | C] () – C:\Documents and Settings\HP_Administrator\Application Data\wklnhst.dat
[2006/08/19 08:45:20 | 000,372,736 | —- | C] () – C:\WINDOWS\System32\hpzidi01.dll
[2006/08/19 08:45:19 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\hpzids01.dll
[2006/07/09 20:58:44 | 000,000,091 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2006/05/06 19:20:36 | 000,065,382 | —- | C] () – C:\Documents and Settings\HP_Administrator\Application Data\PatchUpdate_HP_CounterReport_Update_HPSU.log
[2006/05/06 19:20:36 | 000,000,227 | —- | C] () – C:\WINDOWS\HP_CounterReport_Update_HPSU.ini
[2006/05/06 19:20:25 | 000,002,202 | —- | C] () – C:\Documents and Settings\HP_Administrator\Application Data\HPSU_48BitScanUpdate.log
[2006/05/06 19:20:25 | 000,000,214 | —- | C] () – C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2006/05/06 19:19:00 | 000,003,013 | —- | C] () – C:\Documents and Settings\HP_Administrator\Application Data\PatchUpdate_InstantShareJPG.log
[2006/05/06 19:19:00 | 000,000,214 | —- | C] () – C:\WINDOWS\HP_InstantSHareJPG.ini
[2006/05/06 19:17:50 | 000,006,926 | —- | C] () – C:\Documents and Settings\HP_Administrator\Application Data\GdiplusUpgrade_MSIApproach_Wrapper.log
[2006/05/06 19:17:50 | 000,000,206 | —- | C] () – C:\WINDOWS\HPGdiPlus.ini
[2006/05/06 19:01:58 | 000,049,385 | —- | C] () – C:\Documents and Settings\HP_Administrator\Application Data\Update_HP_RedboxHprblog_HPSU.log
[2006/05/06 19:01:58 | 000,000,221 | —- | C] () – C:\WINDOWS\HP_RedboxHprblog_HPSU.ini
[2006/05/03 17:56:01 | 000,000,000 | —- | C] () – C:\WINDOWS\vpc32.INI
[2006/04/30 17:57:19 | 000,043,520 | —- | C] () – C:\WINDOWS\System32\CmdLineExt03.dll
[2006/04/30 17:45:50 | 000,021,840 | —- | C] () – C:\WINDOWS\System32\SIntfNT.dll
[2006/04/30 17:45:50 | 000,017,212 | —- | C] () – C:\WINDOWS\System32\SIntf32.dll
[2006/04/30 17:45:50 | 000,012,067 | —- | C] () – C:\WINDOWS\System32\SIntf16.dll
[2006/04/04 20:39:06 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\YCRWin32.dll
[2006/03/24 18:25:28 | 000,003,584 | —- | C] () – C:\Documents and Settings\MCX1\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/03/24 18:10:11 | 000,000,127 | —- | C] () – C:\Documents and Settings\MCX1\Local Settings\Application Data\fusioncache.dat
[2006/03/22 16:10:12 | 000,000,028 | —- | C] () – C:\WINDOWS\atid.ini
[2006/03/07 21:18:06 | 000,026,112 | —- | C] () – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/03/06 22:47:17 | 000,004,599 | —- | C] () – C:\WINDOWS\hpdj5600.ini
[2006/03/05 12:44:51 | 000,000,139 | —- | C] () – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\fusioncache.dat
[2005/12/02 19:21:27 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/12/02 19:02:13 | 000,022,396 | —- | C] () – C:\WINDOWS\System32\drivers\USBkey.sys
[2005/12/02 18:57:42 | 000,014,316 | —- | C] () – C:\WINDOWS\System32\CHODDI.SYS
[2005/12/02 18:57:35 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\hpreg.dll
[2005/12/02 18:55:33 | 000,000,099 | —- | C] () – C:\WINDOWS\Quicken.ini
[2005/12/02 18:52:27 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/12/02 18:48:06 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2005/12/02 18:48:06 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2005/12/02 18:48:06 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2005/12/02 18:48:06 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2005/12/02 18:48:06 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2005/12/02 18:48:06 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2005/12/02 18:42:51 | 000,000,108 | —- | C] () – C:\WINDOWS\WININIT.INI
[2005/12/02 18:41:57 | 000,000,698 | —- | C] () – C:\WINDOWS\NSSetDefaultBrowser.ini
[2005/12/02 18:16:15 | 000,000,791 | —- | C] () – C:\WINDOWS\orun32.ini
[2005/12/02 18:13:04 | 000,000,136 | —- | C] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\fusioncache.dat
[2005/12/02 18:09:57 | 000,323,584 | —- | C] () – C:\WINDOWS\System32\pythoncom22.dll
[2005/12/02 18:09:57 | 000,094,208 | —- | C] () – C:\WINDOWS\System32\pywintypes22.dll
[2005/12/02 18:09:42 | 000,016,896 | —- | C] () – C:\WINDOWS\System32\bcbmm.dll
[2005/10/05 15:50:52 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2005/08/06 00:01:54 | 000,235,008 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2005/08/03 02:19:16 | 000,050,176 | —- | C] () – C:\WINDOWS\armcex.dll
[2004/09/16 13:26:40 | 000,012,634 | —- | C] () – C:\WINDOWS\System32\drivers\ADFUUD.SYS
[2004/08/10 07:00:00 | 000,096,512 | —- | C] () – C:\WINDOWS\System32\drivers\atapi.sys
[2004/07/26 17:51:38 | 000,000,560 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2003/01/08 01:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2001/07/07 01:30:00 | 000,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini
[1998/08/16 05:00:00 | 000,004,096 | —- | C] () – C:\WINDOWS\System32\sysres.dll

========== LOP Check ==========

[2005/12/02 18:40:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Digital Interactive Systems Corporation
[2005/12/02 18:40:50 | 000,000,000 | —D | M] – C:\Documents and Settings\MCX1\Application Data\Digital Interactive Systems Corporation
[2005/12/02 18:40:50 | 000,000,000 | —D | M] – C:\Documents and Settings\MCX2\Application Data\Digital Interactive Systems Corporation
[2005/12/02 18:40:50 | 000,000,000 | —D | M] – C:\Documents and Settings\MCX3\Application Data\Digital Interactive Systems Corporation
[2010/02/10 18:00:36 | 000,000,296 | —- | M] () – C:\WINDOWS\Tasks\ntmvdegi.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >
[2009/03/11 18:57:50 | 000,997,616 | —- | M] (Microsoft Corporation) – C:\WindowsXP-KB894179-x86-ENU.exe


< MD5 for: AGP440.SYS >
[2004/08/10 14:00:00 | 016,971,599 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008/04/14 04:51:44 | 020,056,462 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2004/08/10 07:00:00 | 016,971,599 | —- | M] () .cab file – C:\WINDOWS\I386\sp2.cab:AGP440.sys
[2008/04/14 04:51:44 | 020,056,462 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 13:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 13:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\dllcache\agp440.sys
[2008/04/13 13:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\drivers\agp440.sys

< MD5 for: ATAPI.SYS >
[2004/08/10 14:00:00 | 016,971,599 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008/04/14 04:51:44 | 020,056,462 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2004/08/10 07:00:00 | 016,971,599 | —- | M] () .cab file – C:\WINDOWS\I386\sp2.cab:atapi.sys
[2008/04/14 04:51:44 | 020,056,462 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\dllcache\atapi.sys
[2004/08/04 08:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | —- | M] () MD5=EA54621D39A62427A41B63CABBEF9A81 – C:\WINDOWS\system32\drivers\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2008/04/13 19:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 19:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\dllcache\eventlog.dll
[2008/04/13 19:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\eventlog.dll
[2004/08/10 07:00:00 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll

< MD5 for: IASTOR.SYS >
[2005/06/17 16:33:40 | 000,872,064 | —- | M] (Intel Corporation) MD5=9A65E42664D1534B68512CAAD0EFE963 – C:\hp\drivers\Intel_5_1_0_1022_PV\iastor.sys
[2005/06/17 16:33:40 | 000,872,064 | —- | M] (Intel Corporation) MD5=9A65E42664D1534B68512CAAD0EFE963 – C:\WINDOWS\system32\drivers\iaStor.sys

< MD5 for: NETLOGON.DLL >
[2008/04/13 19:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 19:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\dllcache\netlogon.dll
[2008/04/13 19:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\netlogon.dll
[2004/08/10 07:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll

< MD5 for: SCECLI.DLL >
[2004/08/10 07:00:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/13 19:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 19:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\dllcache\scecli.dll
[2008/04/13 19:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2008/06/20 12:46:57 | 000,147,968 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\dnsapi.dll
[2009/12/21 14:14:02 | 011,070,464 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\ieframe.dll
[2009/12/21 14:14:03 | 001,985,536 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\iertutil.dll
[2008/04/13 19:12:00 | 000,274,944 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\mstask.dll
[2008/04/13 19:12:02 | 000,067,072 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\ntdsapi.dll
[2008/06/17 14:02:19 | 008,461,312 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\shell32.dll

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2005/08/30 23:51:10 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2005/08/30 23:51:10 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2005/08/30 23:51:10 | 000,888,832 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< End of report >
Hi Amebeo,


A little manual work for you to start with. We will rename a file and copy a new copy of it into the C:\WINDOWS\system32\drivers folder.

Double click "MY Computer"
  • Double click local drive(c:)
  • At the top click Folders
  • Next click View
  • Click Folder Options
  • Click the view tab
  • check Display the contents of system folders
  • check Show hidden files and folders
  • uncheck "Hide extensions for known file types" box
  • uncheck "Hide protecting operating system files" box
Click apply, click ok

Navigate to this folder C:\WINDOWS\system32\dllcache
  • In the right hand panel locate this file atapi.sys
  • Right click it and select copy

Next, in the left hand panel, navigate to this folder C:\WINDOWS\system32\drivers
  • In the left hand panel locate this file atapi.sys
  • Right click it and select rename
  • On the keyboard, type atapi.old
  • Hit enter and accept any warning you may be given

In the left hand panel right click on the drivers folder and select paste.

Please confirm the presence of both atapi.old and atapi.sys are present in the left hand panel. Please note atapi.sys may be located at the bottom of the list.

Close the window.



Next, Double click on OTLPE.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:OTL
O4 - HKLM..\Run: [jedugikuf] C:\WINDOWS\System32\melasora.DLL ()
O20 - AppInit_DLLs: (c:\windows\system32\libukifu.dll) - C:\WINDOWS\System32\libukifu.dll File not found
O20 - AppInit_DLLs: (moyomego.dll) - File not found
O20 - AppInit_DLLs: (c:\windows\system32\melasora.dll) - C:\WINDOWS\system32\melasora.dll ()
O20 - HKLM Winlogon: Shell - (ajhg.kqo) - File not found
O20 - HKLM Winlogon: Shell - (prect) - File not found
O21 - SSODL: ladatizuk - {71360016-f38c-4a18-b416-7d26a6eeb975} - C:\WINDOWS\system32\melasora.dll ()
O22 - SharedTaskScheduler: {71360016-f38c-4a18-b416-7d26a6eeb975} - tokatiluy - C:\WINDOWS\system32\melasora.dll ()
[2010/02/11 12:47:51 | 000,000,000 | -HSD | C] – C:\WINDOWS\System32\lowsec
[2099/01/01 12:00:00 | 000,093,696 | -HS- | M] () – C:\WINDOWS\System32\korumore.dll
[2099/01/01 12:00:00 | 000,093,184 | -HS- | M] () – C:\WINDOWS\System32\melasora.dll
[2099/01/01 12:00:00 | 000,062,464 | -HS- | M] () – C:\WINDOWS\System32\vugukibo.dll
[2099/01/01 12:00:00 | 000,039,424 | -HS- | M] () – C:\WINDOWS\System32\vedilune.dll
[2099/01/01 12:00:00 | 000,039,424 | -HS- | M] () – C:\WINDOWS\System32\gizokoro.dll
2010/02/10 18:00:36 | 000,000,296 | —- | M] () – C:\WINDOWS\tasks\ntmvdegi.job
[2010/02/10 12:31:44 | 000,001,744 | -H– | M] () – C:\WINDOWS\System32\dikabagu

Then click the Run Fix button at the top
  • Let the program run unhindered
Should OTLPE request a reboot, please allow it but boot back into the computer with the CD iso to allow OTLPE to finish.

Once the program has finished, if the log doesn't popup you will find it at C:\_OTL\MovedFiles the same as you did before.

Please post the log then click the start button located at the bottom left of the REATOGO desktop. Click Shutdown.

The CD should eject and the computer will shut down. Try to boot the computer normally. Let me know when you are in normal windows.

Thanks
I will get on that on my lunch break… I have a question though. I can borrow a portable cd/dvd burner will that work to burn the pictures too, or is that not possible with the boot disk? If not I 3 flash drives I can use to transfer them to another pc for burning to cds.
Hi I'm not sure if you will be able to burn them to a CD as not all the drivers will be available. You can try it though as long as it's a usb device.
Typo notice: at the line
Next click view tab - Folder Options was found under Tools

========== SERVICES/DRIVERS ==========
========== OTL ==========
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\jedugikuf deleted successfully.
C:\WINDOWS\system32\melasora.dll moved successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:c:\windows\system32\libukifu.dll deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:moyomego.dll deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:c:\windows\system32\melasora.dll deleted successfully.
File C:\WINDOWS\system32\melasora.dll not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell:ajhg.kqo deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell:prect deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\ladatizuk deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71360016-f38c-4a18-b416-7d26a6eeb975}\ deleted successfully.
File C:\WINDOWS\system32\melasora.dll not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\\{71360016-f38c-4a18-b416-7d26a6eeb975} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71360016-f38c-4a18-b416-7d26a6eeb975}\ not found.
File C:\WINDOWS\system32\melasora.dll not found.
C:\WINDOWS\System32\lowsec folder moved successfully.
C:\WINDOWS\system32\korumore.dll moved successfully.
File C:\WINDOWS\System32\melasora.dll not found.
C:\WINDOWS\system32\vugukibo.dll moved successfully.
C:\WINDOWS\system32\vedilune.dll moved successfully.
C:\WINDOWS\system32\gizokoro.dll moved successfully.
C:\WINDOWS\system32\dikabagu moved successfully.

OTLPE by OldTimer - Version 3.1.28.0 log created on 02122010_124055

I will post back after restarting my computer

Thank you

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI