This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Internet Slow and/or unresponsive

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Internet while either on IE of Firefox running slow… Not really slow, when it decides to load the page it loads well and quickly. For some links will load fine and sometime not at all I will refresh and again and again and again and go back and click the link again… and eventually the page will load. Sometimes some pages, like comcast.net, will load half the page but not the link to check my e-mail
Hello and :welcome: Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise. This may cause a delay, but I will do my best to keep it as short as possible. I will post back shortly with instructions.
Hello inzanity and thank you for the response. I don't know that it's relevant but Oldman960 recently helped me clear some infections. After he cleared me every thing seemed to run fine. until now… The only other noticeable thing between then and now is a long start up time. It seems that windows is taking way too long to load. at start up. Thanks Amebeo
Hi,

I will be helping you on removing malwares on your computer. Log research takes time, so please be patient and I'd be grateful if you would note the following:
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Do not install/uninstall anything on your computer unless advised.
  • Do not run any other scanning tools other than those instructed for you to use.
  • Follow the instructions on the order they are given.
  • Stay with this thread until advised when your computer is clean. Absence of symptoms does not necessarily mean a clean computer.
  • If you are being helped regarding this problem on another forum please advice us so that we can close this thread.
  • If you do not reply within 3 days after my last response, I will be asking you whether you still need assistance and if you still don't reply within 24 hours then the topic will be closed.
  • And lastly, if you have any questions, please ask before proceeding with any of the advised fixes.

_________________________________________________



OTL:
  • Download OTL to your desktop.
  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • Copy and paste the following bold text into the box under Custom Scan

    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    /md5stop
    CREATERESTOREPOINT

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Please copy (Edit->Select All, Edit->Copy) the contents of the OTL.txt and post it with your next reply along with the OTL fix log.

–Next–

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


To post in your next reply:
1. OTL logs.
2. GMER log.
Downloaded OTL and ran without a hitch the logs are as follows:

OTL logfile created on: 3/12/2010 11:30:23 PM - Run 1
OTL by OldTimer - Version 3.1.37.0 Folder = C:\Documents and Settings\HP_Administrator\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

958.00 Mb Total Physical Memory | 471.00 Mb Available Physical Memory | 49.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 81.00% Paging File free
Paging file location(s): C:\pagefile.sys 1440 2880 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 177.79 Gb Total Space | 78.80 Gb Free Space | 44.32% Space Free | Partition Type: NTFS
Drive D: | 8.50 Gb Total Space | 1.12 Gb Free Space | 13.14% Space Free | Partition Type: FAT32
Drive E: | 684.06 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: NEIL
Current User Name: HP_Administrator
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\HP_Administrator\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe ()
PRC - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (Intuit)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe (Nero AG)
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
PRC - C:\WINDOWS\system32\PSIService.exe ()
PRC - C:\Program Files\Sony\SonicStage\SSAAD.exe ()
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\WINDOWS\arservice.exe (Microsoft)
PRC - C:\Program Files\Hewlett-Packard\HP Software Update\hpwuSchd2.exe (Hewlett-Packard Co.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\HP_Administrator\Desktop\OTL.exe (OldTimer Tools)


========== Win32 Services (SafeList) ==========

SRV - (avg9wd) – C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (getPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (vsmon) – C:\WINDOWS\System32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
SRV - (LeapFrog Connect Device Service) – C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe ()
SRV - (QBCFMonitorService) – C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (Intuit)
SRV - (QBFCService) – C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe (Intuit Inc.)
SRV - (InCDsrv) – C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe (Nero AG)
SRV - (Viewpoint Manager Service) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (ProtexisLicensing) – C:\WINDOWS\system32\PSIService.exe ()
SRV - (SSScsiSV) – C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe (Sony Corporation)
SRV - (MSCSPTISRV) – C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe (Sony Corporation)
SRV - (PACSPTISVR) – C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe (Sony Corporation)
SRV - (SPTISRV) – C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe (Sony Corporation)
SRV - (AdobeActiveFileMonitor4.0) – C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe ()
SRV - (ARSVC) – C:\WINDOWS\arservice.exe (Microsoft)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)


========== Driver Services (SafeList) ==========

DRV - (AvgTdiX) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (vsdatant) – C:\WINDOWS\system32\vsdatant.sys (Check Point Software Technologies LTD)
DRV - (PSI) – C:\WINDOWS\system32\drivers\psi_mf.sys (Secunia)
DRV - (FlyUsb) – C:\WINDOWS\system32\drivers\FlyUsb.sys (LeapFrog)
DRV - (GcKernel) – C:\WINDOWS\system32\drivers\gckernel.sys (Microsoft Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (SDTHOOK) – C:\WINDOWS\system32\drivers\SDTHOOK.SYS (Panda Software)
DRV - (incdrm) – C:\WINDOWS\system32\drivers\InCDRm.sys (Nero AG)
DRV - (InCDPass) – C:\WINDOWS\system32\drivers\InCDPass.sys (Nero AG)
DRV - (InCDfs) – C:\WINDOWS\system32\drivers\InCDfs.sys (Nero AG)
DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (Ps2) – C:\WINDOWS\system32\drivers\PS2.sys (Hewlett-Packard Company)
DRV - (ftsata2) – C:\WINDOWS\system32\DRIVERS\ftsata2.sys (Promise Technology, Inc.)
DRV - (iaStor) – C:\WINDOWS\system32\DRIVERS\iaStor.sys (Intel Corporation)
DRV - (AmdK8) – C:\WINDOWS\system32\drivers\AmdK8.sys (Advanced Micro Devices)
DRV - (RTL8023xp) – C:\WINDOWS\system32\drivers\Rtlnicxp.sys (Realtek Semiconductor Corporation )
DRV - (HSFHWBS2) – C:\WINDOWS\system32\drivers\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) – C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (AFS2K) – C:\WINDOWS\system32\drivers\AFS2K.SYS (Oak Technology Inc.)
DRV - (2WIREPCP) – C:\WINDOWS\system32\drivers\2WirePCP.sys (2Wire, Inc.)
DRV - (rtl8139) Realtek RTL8139(A/B/C) – C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)
DRV - (MDC8021X) AEGIS Protocol (IEEE 802.1x) – C:\WINDOWS\system32\drivers\mdc8021x.sys (Meetinghouse Data Communications)
DRV - (cdrbsdrv) – C:\WINDOWS\system32\drivers\CDRBSDRV.SYS (B.H.A Corporation)
DRV - (bb-run) – C:\WINDOWS\system32\DRIVERS\bb-run.sys (Promise Technology, Inc.)
DRV - (sonypvs1) – C:\WINDOWS\system32\drivers\sonypvs1.sys (Sony Corporation)
DRV - (SWUSBFLT) – C:\WINDOWS\system32\drivers\SWUSBFLT.SYS (Microsoft Corporation)
DRV - (HIDSwvd) – C:\WINDOWS\system32\drivers\hidswvd.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://swagbucks.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94} - C:\Program Files\Swag_Bucks\tbSwa0.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://swagbucks.com/?cmd=home"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.1.3
FF - prefs.js..extensions.enabledItems: [removed]:1.11.6
FF - prefs.js..extensions.enabledItems: {99B98C2C-7274-45a3-A640-D9DF1A1C8460}:1.4
FF - prefs.js..extensions.enabledItems: {35106bca-6c78-48c7-ac28-56df30b51d2d}:1.2.4
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:[removed]
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.716
FF - prefs.js..network.proxy.no_proxies_on: "*.local"

FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox [2010/02/26 12:14:49 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/02/19 00:37:03 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/02/14 11:03:14 | 000,000,000 | —D | M]

[2009/07/26 08:19:14 | 000,000,000 | —D | M] – C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Extensions
[2009/07/26 08:19:14 | 000,000,000 | —D | M] – C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Extensions\[removed]
[2010/03/12 20:11:23 | 000,000,000 | —D | M] – C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\y836keys.default\extensions
[2009/09/03 11:18:00 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\y836keys.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/02/08 22:48:36 | 000,000,000 | —D | M] (PopupMaster) – C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\y836keys.default\extensions\{35106bca-6c78-48c7-ac28-56df30b51d2d}
[2010/02/08 22:47:12 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\y836keys.default\extensions\{6614d11d-d21d-b211-ae23-815234e1ebb5}
[2010/02/08 22:46:42 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\y836keys.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2010/02/08 22:48:36 | 000,000,000 | —D | M] (CookieCuller) – C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\y836keys.default\extensions\{99B98C2C-7274-45a3-A640-D9DF1A1C8460}
[2010/02/08 20:10:41 | 000,000,000 | —D | M] (Adblock Plus) – C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\y836keys.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/02/14 10:59:37 | 000,000,000 | —D | M] (Adobe DLM (powered by getPlus®)) – C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\y836keys.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2010/02/08 22:39:14 | 000,000,000 | —D | M] – C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\y836keys.default\extensions\[removed]
[2010/03/12 20:11:23 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/01/18 22:21:34 | 000,393,216 | —- | M] (Invenda Corporation) – C:\Program Files\Mozilla Firefox\plugins\NPcol400.dll
[2009/11/19 17:16:28 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
[2009/03/18 09:03:40 | 000,214,272 | —- | M] (Midasplayer Ltd) – C:\Program Files\Mozilla Firefox\plugins\npmidas.dll
[2009/11/19 17:16:29 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npMozCouponPrinter.dll
[2007/04/16 12:07:12 | 000,180,293 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\npViewpoint.dll

O1 HOSTS File: ([2010/02/12 22:26:44 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Yahoo! IE Services Button) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Swag Bucks Toolbar) - {8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94} - C:\Program Files\Swag_Bucks\tbSwa0.dll (Conduit Ltd.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Swag Bucks Toolbar) - {8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94} - C:\Program Files\Swag_Bucks\tbSwa0.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Yahoo! ¤u¨ã¦C) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Swag Bucks Toolbar) - {8BDEA9D6-6F62-45EB-8EE9-8A81AF0D2F94} - C:\Program Files\Swag_Bucks\tbSwa0.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! ¤u¨ã¦C) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\hpwuSchd2.exe (Hewlett-Packard Co.)
O4 - HKLM..\Run: [SsAAD.exe] C:\Program Files\Sony\SonicStage\SSAAD.exe ()
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [ZoneAlarm Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll (Google Inc.)
O9 - Extra Button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O9 - Extra Button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ()
O9 - Extra 'Tools' menuitem : Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: trymedia.com ([]http in Trusted sites)
O15 - HKLM\..Trusted Domains: trymedia.com ([]https in Trusted sites)
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab (Checkers Class)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/e/4…/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://pcpitstop.com/betapit/PCPitStop.CAB (PCPitstop Utility)
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} file:///C:/Program%20Files/Risk/Images/stg_drm.ocx (SpinTop DRM Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/C/0…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab (Minesweeper Flags Class)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} http://www.pogo.com/cdl/launcher/PogoWebLa…erInstaller.CAB (PogoWebLauncher Control)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://photo.walgreens.com/WalgreensActivia.cab (Snapfish Activia)
O16 - DPF: {45A0A292-ECC6-4D8F-9EA9-A4BD411D24C1} http://www.king.com/ctl/kingcomie.cab (king.com)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {54BE6B6F-3056-470B-97E1-BB92E051B6C4} http://h20264.www2.hp.com/ediags/dd/instal…nosticsxp2k.cab (DeviceEnum Class)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://go.divx.com/plugin/DivXBrowserPlugin.cab (DivXBrowserPlugin Object)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab (MessengerStatsClient Class)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} http://web1.shutterfly.com/downloads/Uploader.cab (Shutterfly Picture Upload Plugin)
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} http://acs.pandasoftware.com/activescan/as5free/asinst.cab (ActiveScan Installer Class)
O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} http://offers.e-centives.com/cif/download/bin/actxcab.cab (CBSTIEPrint Class)
O16 - DPF: {BE319D04-18BD-4B34-AECC-EE7CB610FCA9} http://download.games.yahoo.com/games/web_…itched/main.cab (BewitchedGameClass Control)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} file:///C:/Program%20Files/Monopoly/Images/armhelper.ocx (ArmHelper Control)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} http://h30043.www3.hp.com/hpdj/en/check/qdiagh.cab?326 (QDiagHUpdateObj Class)
O16 - DPF: {F137B9BA-89EA-4B04-9C67-2074A9DF61FD} http://cvs.pnimedia.com/upload/activex/v2_…upv2.0.0.10.cab? (Photo Upload Plugin Class)
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} http://dlm.tools.akamai.com/dlmanager/vers…ivex-latest.cab (DownloadManager Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\intu-help-qb2 {84D77A00-41B5-4b8b-8ADF-86486D72E749} - C:\Program Files\Intuit\QuickBooks 2009\HelpAsyncPluggableProtocol.dll (Intuit, Inc.)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop WallPaper: C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/05/14 17:49:12 | 000,000,150 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2001/07/28 05:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O32 - AutoRun File - [2003/03/13 08:11:46 | 000,000,049 | R— | M] () - E:\Autorun.inf – [ CDFS ]
O32 - AutoRun File - [2000/06/26 14:25:24 | 000,131,072 | R— | M] (Impressions Games) - E:\autorun.exe – [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2005/09/01 14:12:30 | 000,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16891891626803200)

========== Files/Folders - Created Within 30 Days ==========

[2010/03/12 23:27:50 | 000,555,520 | —- | C] (OldTimer Tools) – C:\Documents and Settings\HP_Administrator\Desktop\OTL.exe
[2010/03/11 10:43:53 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Desktop\freezer recipes
[2010/03/06 08:40:04 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Temp
[2010/02/26 12:15:45 | 000,000,000 | -H-D | C] – C:\$AVG
[2010/02/26 12:14:46 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\avg9
[2010/02/26 12:12:21 | 000,000,000 | —D | C] – C:\WINDOWS\SxsCaPendDel
[2010/02/26 12:05:26 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2010/02/26 12:05:26 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2010/02/26 12:05:25 | 000,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2010/02/26 12:05:25 | 000,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2010/02/18 11:00:10 | 000,000,000 | —D | C] – C:\Program Files\Turbo Tax Audit Support Center
[2010/02/14 12:11:41 | 000,103,816 | —- | C] (Check Point Software Technologies LTD) – C:\WINDOWS\System32\zlcommdb.dll
[2010/02/14 12:11:41 | 000,069,000 | —- | C] (Check Point Software Technologies LTD) – C:\WINDOWS\System32\zlcomm.dll
[2010/02/14 12:11:31 | 000,041,864 | —- | C] (Check Point Software Technologies LTD) – C:\WINDOWS\System32\vswmi.dll
[2010/02/14 12:11:28 | 001,238,408 | —- | C] (Check Point Software Technologies LTD) – C:\WINDOWS\System32\zpeng25.dll
[2010/02/14 12:11:27 | 000,299,912 | —- | C] (Check Point Software Technologies LTD) – C:\WINDOWS\System32\vspubapi.dll
[2010/02/14 12:11:26 | 000,107,912 | —- | C] (Check Point Software Technologies LTD) – C:\WINDOWS\System32\vsmonapi.dll
[2010/02/14 12:11:25 | 000,486,280 | —- | C] (Check Point Software Technologies LTD) – C:\WINDOWS\System32\vsdatant.sys
[2010/02/14 12:11:25 | 000,112,008 | —- | C] (Check Point Software Technologies LTD) – C:\WINDOWS\System32\vsdata.dll
[2010/02/14 12:08:24 | 000,227,720 | —- | C] (Check Point Software Technologies LTD) – C:\WINDOWS\System32\vsinit.dll
[2010/02/14 12:08:23 | 000,620,936 | —- | C] (Check Point Software Technologies LTD) – C:\WINDOWS\System32\vsutil.dll
[2010/02/14 12:02:57 | 000,000,000 | —D | C] – C:\Program Files\Secunia
[2010/02/14 11:56:11 | 000,000,000 | —D | C] – C:\Program Files\SpywareBlaster
[2010/02/14 11:18:51 | 000,181,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\MpSigStub.exe
[2010/02/14 11:18:01 | 000,000,000 | —D | C] – C:\Program Files\Windows Defender
[2010/02/14 10:59:46 | 000,000,000 | —D | C] – C:\Program Files\NOS
[2010/02/14 10:59:46 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\NOS
[2010/02/13 23:54:22 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\My Documents\CyberLink
[2010/02/13 23:51:45 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Application Data\CyberLink
[2010/02/13 23:51:27 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\CyberLink
[2010/02/13 23:42:00 | 000,000,000 | —D | C] – C:\MyWorks
[2010/02/13 23:39:34 | 000,024,064 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msxml3a.dll
[2010/02/13 23:38:35 | 000,000,000 | —D | C] – C:\Program Files\CyberLink
[2010/02/13 21:38:01 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Ahead
[2010/02/13 21:36:30 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Application Data\Ahead
[2010/02/13 21:33:58 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Nero
[2010/02/13 21:33:57 | 000,000,000 | —D | C] – C:\Program Files\Nero
[2010/02/13 21:33:57 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Ahead
[2010/02/13 10:51:39 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sun
[2010/02/13 10:51:38 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2010/02/13 10:51:10 | 000,411,368 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deploytk.dll
[2010/02/13 10:51:10 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/02/13 10:51:10 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/02/13 10:51:10 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/02/13 10:51:10 | 000,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2010/02/13 10:20:59 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2010/02/09 22:01:23 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010/02/09 21:04:24 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2009/09/07 13:12:07 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Swag_Bucks
[2009/07/01 11:00:42 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2009/03/31 20:24:26 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\HPQ
[2009/03/29 09:34:17 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2009/01/05 14:12:02 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple
[2008/12/10 20:38:36 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Intuit
[2008/04/15 18:05:30 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Google
[2008/04/15 18:05:27 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Viewpoint
[2007/08/01 14:19:14 | 000,774,144 | —- | C] (RealNetworks, Inc.) – C:\Program Files\RngInterstitial.dll
[2005/05/12 09:36:48 | 000,012,288 | —- | C] (Hewlett-Packard Co.) – C:\WINDOWS\Fonts\RandFont.dll

========== Files - Modified Within 30 Days ==========

[2010/03/12 23:27:53 | 000,555,520 | —- | M] (OldTimer Tools) – C:\Documents and Settings\HP_Administrator\Desktop\OTL.exe
[2010/03/12 23:20:24 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/03/12 23:20:18 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/03/12 23:20:08 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\HP_Administrator\ntuser.ini
[2010/03/12 22:46:00 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/03/12 22:26:06 | 000,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2010/03/12 22:09:25 | 057,034,342 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/03/12 20:27:26 | 000,029,696 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\Possible Employment.doc
[2010/03/12 07:37:33 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/03/12 07:37:01 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/03/12 07:36:57 | 1005,113,344 | -HS- | M] () – C:\hiberfil.sys
[2010/03/11 23:06:52 | 008,650,752 | —- | M] () – C:\Documents and Settings\HP_Administrator\ntuser.dat
[2010/03/11 21:08:13 | 000,048,640 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\Neil Petty - Industrial Electrician.doc
[2010/03/11 20:34:07 | 000,020,480 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\Homemade Mocha Frappuccino.doc
[2010/03/11 19:57:21 | 000,022,516 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\Academic Transcript.zip
[2010/03/11 19:39:06 | 000,525,076 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/03/11 19:39:06 | 000,445,700 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/03/11 19:39:06 | 000,072,780 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/03/11 00:00:40 | 000,107,008 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\Simply Asia Seasoning Mixes.doc
[2010/03/10 08:25:59 | 000,000,809 | —- | M] () – C:\WINDOWS\win.ini
[2010/03/09 21:40:49 | 000,232,448 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\Academic Transcript.doc
[2010/03/08 23:01:06 | 001,581,570 | -H– | M] () – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\IconCache.db
[2010/03/08 14:12:04 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/03/07 20:48:54 | 000,021,840 | —- | M] () – C:\WINDOWS\System32\SIntfNT.dll
[2010/03/07 20:48:54 | 000,017,212 | —- | M] () – C:\WINDOWS\System32\SIntf32.dll
[2010/03/07 20:48:54 | 000,012,067 | —- | M] () – C:\WINDOWS\System32\SIntf16.dll
[2010/03/03 21:51:09 | 000,000,254 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\Kroger.url
[2010/02/28 19:05:43 | 000,004,212 | -H– | M] () – C:\WINDOWS\System32\zllictbl.dat
[2010/02/26 12:15:33 | 000,360,584 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2010/02/26 12:15:33 | 000,333,192 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2010/02/26 12:15:33 | 000,142,495 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2010/02/26 12:15:33 | 000,028,424 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2010/02/26 12:15:10 | 000,001,518 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG Free 9.0.lnk
[2010/02/26 12:15:09 | 000,012,464 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2010/02/26 12:14:51 | 000,113,461 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\iavichjw.avm
[2010/02/24 09:16:06 | 000,181,632 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MpSigStub.exe
[2010/02/23 22:02:12 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/02/23 18:29:22 | 000,000,162 | -H– | M] () – C:\Documents and Settings\HP_Administrator\Desktop\~$ekly Deals.doc
[2010/02/20 07:53:04 | 000,418,099 | -H– | M] () – C:\WINDOWS\System32\vsconfig.xml
[2010/02/18 15:14:05 | 000,001,417 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\Reader Rabbit's Preschool (2).lnk
[2010/02/18 11:00:15 | 000,000,861 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Turbo Tax Audit Support Center.lnk
[2010/02/18 10:56:32 | 000,148,019 | —- | M] () – C:\Documents and Settings\HP_Administrator\My Documents\TaxReturn2009.pdf
[2010/02/17 07:52:49 | 000,000,162 | -H– | M] () – C:\Documents and Settings\HP_Administrator\Desktop\~$S Weekly Ad 2.doc
[2010/02/15 08:49:43 | 000,000,279 | RHS- | M] () – C:\boot.ini
[2010/02/15 08:49:43 | 000,000,264 | —- | M] () – C:\WINDOWS\system.ini
[2010/02/14 11:03:15 | 000,001,740 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2010/02/14 10:43:40 | 001,241,312 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/02/13 23:38:43 | 000,001,732 | —- | M] () – C:\Documents and Settings\All Users\Desktop\CyberLink DVD Suite.lnk
[2010/02/13 21:38:50 | 000,001,785 | —- | M] () – C:\Documents and Settings\All Users\Desktop\LightScribe.lnk
[2010/02/13 21:37:49 | 000,001,890 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Nero Online Upgrade.lnk
[2010/02/13 21:37:48 | 000,002,372 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Nero StartSmart Essentials.lnk
[2010/02/13 10:50:55 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deploytk.dll
[2010/02/13 10:50:55 | 000,153,376 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/02/13 10:50:55 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/02/13 10:50:55 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/02/13 10:50:55 | 000,073,728 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2010/02/12 22:26:44 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2010/02/11 12:46:16 | 000,000,008 | —- | M] () – C:\Documents and Settings\All Users\Application Data\mswintmp.dat

========== Files Created - No Company Name ==========

[2010/03/11 20:34:06 | 000,020,480 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\Homemade Mocha Frappuccino.doc
[2010/03/11 19:57:21 | 000,022,516 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\Academic Transcript.zip
[2010/03/11 00:00:40 | 000,107,008 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\Simply Asia Seasoning Mixes.doc
[2010/03/09 22:39:11 | 000,029,696 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\Possible Employment.doc
[2010/03/09 21:40:49 | 000,232,448 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\Academic Transcript.doc
[2010/03/03 21:51:09 | 000,000,254 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\Kroger.url
[2010/02/28 17:46:59 | 000,000,868 | —- | C] () – C:\WINDOWS\tasks\Google Software Updater.job
[2010/02/28 10:36:49 | 000,012,067 | —- | C] () – C:\WINDOWS\System32\SIntf16.dll
[2010/02/26 12:15:10 | 000,001,518 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AVG Free 9.0.lnk
[2010/02/23 18:29:22 | 000,000,162 | -H– | C] () – C:\Documents and Settings\HP_Administrator\Desktop\~$ekly Deals.doc
[2010/02/18 15:14:05 | 000,001,417 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\Reader Rabbit's Preschool (2).lnk
[2010/02/18 11:00:15 | 000,000,861 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Turbo Tax Audit Support Center.lnk
[2010/02/18 10:56:32 | 000,148,019 | —- | C] () – C:\Documents and Settings\HP_Administrator\My Documents\TaxReturn2009.pdf
[2010/02/17 07:52:49 | 000,000,162 | -H– | C] () – C:\Documents and Settings\HP_Administrator\Desktop\~$S Weekly Ad 2.doc
[2010/02/14 11:03:15 | 000,001,740 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2010/02/13 23:38:43 | 000,001,732 | —- | C] () – C:\Documents and Settings\All Users\Desktop\CyberLink DVD Suite.lnk
[2010/02/13 21:38:50 | 000,001,785 | —- | C] () – C:\Documents and Settings\All Users\Desktop\LightScribe.lnk
[2010/02/13 21:37:48 | 000,002,372 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Nero StartSmart Essentials.lnk
[2010/02/13 21:37:48 | 000,001,890 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Nero Online Upgrade.lnk
[2010/02/11 12:46:15 | 000,000,008 | —- | C] () – C:\Documents and Settings\All Users\Application Data\mswintmp.dat
[2009/09/21 18:32:56 | 000,000,216 | —- | C] () – C:\WINDOWS\TLCAPPS.INI
[2009/07/22 20:03:42 | 000,000,110 | —- | C] () – C:\WINDOWS\{47FB62DF-832D-485F-95FC-C93BB08B8FE3}_WiseFW.ini
[2008/12/19 22:41:13 | 000,000,067 | —- | C] () – C:\Documents and Settings\HP_Administrator\Application Data\photoshow_express_setup.txt
[2008/12/09 15:32:54 | 000,000,095 | —- | C] () – C:\WINDOWS\QBChanUtil_Trigger.ini
[2008/09/13 09:45:51 | 000,000,023 | —- | C] () – C:\WINDOWS\MathMagic Personal 3.64.INI
[2008/09/13 09:45:11 | 000,016,498 | —- | C] () – C:\Program Files\setuplog.txt
[2008/09/13 09:45:11 | 000,015,834 | —- | C] () – C:\Program Files\uninstall.log
[2008/05/21 17:33:21 | 000,000,343 | —- | C] () – C:\WINDOWS\SIERRA.INI
[2008/03/14 14:32:38 | 000,000,343 | —- | C] () – C:\WINDOWS\ULead32.ini
[2008/02/23 18:10:33 | 000,000,071 | —- | C] () – C:\WINDOWS\Pex.INI
[2008/02/04 17:23:10 | 000,693,792 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.DLL
[2008/02/02 22:36:02 | 000,002,947 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/10/29 19:24:32 | 000,000,190 | —- | C] () – C:\Documents and Settings\HP_Administrator\Application Data\G-Force Prefs (WindowsMediaPlayer).txt
[2007/08/03 14:09:41 | 000,003,454 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2007/08/03 14:09:41 | 000,000,008 | RHS- | C] () – C:\WINDOWS\System32\8036B57683.sys
[2007/08/03 14:08:46 | 001,300,048 | —- | C] () – C:\Documents and Settings\All Users\Application Data\pswi_preloaded.exe
[2007/05/21 18:43:37 | 000,000,560 | —- | C] () – C:\Documents and Settings\HP_Administrator\Application Data\ViewerApp.dat
[2007/05/14 17:47:01 | 000,003,654 | —- | C] () – C:\WINDOWS\System32\drivers\Sonyhcp.dll
[2007/05/13 18:58:44 | 000,098,304 | —- | C] () – C:\WINDOWS\System32\resourceGeneric.dll
[2007/01/29 12:23:40 | 000,011,776 | —- | C] () – C:\WINDOWS\System32\ZPORT4AS.dll
[2007/01/19 20:42:01 | 000,000,000 | —- | C] () – C:\WINDOWS\PROTOCOL.INI
[2006/10/14 15:06:20 | 000,796,584 | —- | C] () – C:\WINDOWS\System32\libeay32_0.9.6l.dll
[2006/08/26 15:13:30 | 000,000,000 | —- | C] () – C:\Documents and Settings\HP_Administrator\Application Data\wklnhst.dat
[2006/08/19 08:45:20 | 000,372,736 | —- | C] () – C:\WINDOWS\System32\hpzidi01.dll
[2006/08/19 08:45:19 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\hpzids01.dll
[2006/07/09 20:58:44 | 000,000,091 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2006/05/06 19:20:36 | 000,065,382 | —- | C] () – C:\Documents and Settings\HP_Administrator\Application Data\PatchUpdate_HP_CounterReport_Update_HPSU.log
[2006/05/06 19:20:36 | 000,000,227 | —- | C] () – C:\WINDOWS\HP_CounterReport_Update_HPSU.ini
[2006/05/06 19:20:25 | 000,002,202 | —- | C] () – C:\Documents and Settings\HP_Administrator\Application Data\HPSU_48BitScanUpdate.log
[2006/05/06 19:20:25 | 000,000,214 | —- | C] () – C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2006/05/06 19:19:00 | 000,003,013 | —- | C] () – C:\Documents and Settings\HP_Administrator\Application Data\PatchUpdate_InstantShareJPG.log
[2006/05/06 19:19:00 | 000,000,214 | —- | C] () – C:\WINDOWS\HP_InstantSHareJPG.ini
[2006/05/06 19:17:50 | 000,006,926 | —- | C] () – C:\Documents and Settings\HP_Administrator\Application Data\GdiplusUpgrade_MSIApproach_Wrapper.log
[2006/05/06 19:17:50 | 000,000,206 | —- | C] () – C:\WINDOWS\HPGdiPlus.ini
[2006/05/06 19:01:58 | 000,049,385 | —- | C] () – C:\Documents and Settings\HP_Administrator\Application Data\Update_HP_RedboxHprblog_HPSU.log
[2006/05/06 19:01:58 | 000,000,221 | —- | C] () – C:\WINDOWS\HP_RedboxHprblog_HPSU.ini
[2006/05/03 17:56:01 | 000,000,000 | —- | C] () – C:\WINDOWS\vpc32.INI
[2006/04/30 17:57:19 | 000,043,520 | —- | C] () – C:\WINDOWS\System32\CmdLineExt03.dll
[2006/04/30 17:45:50 | 000,021,840 | —- | C] () – C:\WINDOWS\System32\SIntfNT.dll
[2006/04/30 17:45:50 | 000,017,212 | —- | C] () – C:\WINDOWS\System32\SIntf32.dll
[2006/04/04 20:39:06 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\YCRWin32.dll
[2006/03/22 16:10:12 | 000,000,028 | —- | C] () – C:\WINDOWS\atid.ini
[2006/03/07 21:18:06 | 000,026,112 | —- | C] () – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/03/06 22:47:17 | 000,004,599 | —- | C] () – C:\WINDOWS\hpdj5600.ini
[2006/03/05 12:44:51 | 000,000,139 | —- | C] () – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\fusioncache.dat
[2005/12/02 19:21:27 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/12/02 19:02:13 | 000,022,396 | —- | C] () – C:\WINDOWS\System32\drivers\USBkey.sys
[2005/12/02 18:57:42 | 000,014,316 | —- | C] () – C:\WINDOWS\System32\CHODDI.SYS
[2005/12/02 18:57:35 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\hpreg.dll
[2005/12/02 18:55:33 | 000,000,099 | —- | C] () – C:\WINDOWS\Quicken.ini
[2005/12/02 18:52:27 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/12/02 18:48:06 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2005/12/02 18:48:06 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2005/12/02 18:48:06 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2005/12/02 18:48:06 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2005/12/02 18:48:06 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2005/12/02 18:48:06 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2005/12/02 18:42:51 | 000,000,108 | —- | C] () – C:\WINDOWS\WININIT.INI
[2005/12/02 18:41:57 | 000,000,698 | —- | C] () – C:\WINDOWS\NSSetDefaultBrowser.ini
[2005/12/02 18:31:59 | 000,005,466 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2005/12/02 18:16:15 | 000,000,791 | —- | C] () – C:\WINDOWS\orun32.ini
[2005/12/02 18:09:57 | 000,323,584 | —- | C] () – C:\WINDOWS\System32\pythoncom22.dll
[2005/12/02 18:09:57 | 000,094,208 | —- | C] () – C:\WINDOWS\System32\pywintypes22.dll
[2005/12/02 18:09:42 | 000,016,896 | —- | C] () – C:\WINDOWS\System32\bcbmm.dll
[2005/10/05 15:50:52 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2005/08/06 00:01:54 | 000,235,008 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2005/08/03 02:19:16 | 000,050,176 | —- | C] () – C:\WINDOWS\armcex.dll
[2004/09/16 13:26:40 | 000,012,634 | —- | C] () – C:\WINDOWS\System32\drivers\ADFUUD.SYS
[2004/07/26 17:51:38 | 000,000,560 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2003/01/08 01:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2001/07/07 01:30:00 | 000,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini
[1998/08/16 05:00:00 | 000,004,096 | —- | C] () – C:\WINDOWS\System32\sysres.dll

========== LOP Check ==========

[2008/07/05 16:38:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\acccore
[2010/02/26 12:14:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2008/01/27 19:51:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Broderbund Software
[2008/12/09 15:32:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\COMMON FILES
[2006/04/12 10:43:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Digital Interactive Systems Corporation
[2006/05/03 14:59:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\espionServerData
[2009/07/22 19:52:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Leapfrog
[2007/06/29 13:10:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\muvee Technologies
[2006/03/07 11:50:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Napster
[2009/03/23 18:30:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2009/07/29 21:19:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\RoboForm
[2007/08/01 14:24:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SpinTop Games
[2008/12/10 20:47:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SQL Anywhere 10
[2009/01/18 20:23:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/08/02 09:42:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2009/06/15 14:06:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/09/29 10:17:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/04/06 14:05:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2009/03/18 19:46:39 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{92E7A367-8E12-4830-AA70-29C32E331A81}

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >
[2009/03/11 18:57:50 | 000,997,616 | —- | M] (Microsoft Corporation) – C:\WindowsXP-KB894179-x86-ENU.exe


< MD5 for: AGP440.SYS >
[2004/08/10 14:00:00 | 016,971,599 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008/04/14 04:51:44 | 020,056,462 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2004/08/10 07:00:00 | 016,971,599 | —- | M] () .cab file – C:\WINDOWS\I386\sp2.cab:AGP440.sys
[2008/04/14 04:51:44 | 020,056,462 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 13:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ERDNT\cache\agp440.sys
[2008/04/13 13:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 13:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\dllcache\agp440.sys
[2008/04/13 13:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\drivers\agp440.sys

< MD5 for: ATAPI.SYS >
[2004/08/10 14:00:00 | 016,971,599 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008/04/14 04:51:44 | 020,056,462 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2004/08/10 07:00:00 | 016,971,599 | —- | M] () .cab file – C:\WINDOWS\I386\sp2.cab:atapi.sys
[2008/04/14 04:51:44 | 020,056,462 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ERDNT\cache\atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\dllcache\atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/04 08:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\$NtServicePackUninstall$\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2008/04/13 19:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ERDNT\cache\eventlog.dll
[2008/04/13 19:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 19:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\dllcache\eventlog.dll
[2008/04/13 19:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\eventlog.dll
[2004/08/10 07:00:00 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll

< MD5 for: IASTOR.SYS >
[2005/06/17 16:33:40 | 000,872,064 | —- | M] (Intel Corporation) MD5=9A65E42664D1534B68512CAAD0EFE963 – C:\hp\drivers\Intel_5_1_0_1022_PV\iastor.sys
[2005/06/17 16:33:40 | 000,872,064 | —- | M] (Intel Corporation) MD5=9A65E42664D1534B68512CAAD0EFE963 – C:\WINDOWS\system32\drivers\iaStor.sys

< MD5 for: NETLOGON.DLL >
[2008/04/13 19:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ERDNT\cache\netlogon.dll
[2008/04/13 19:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 19:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\dllcache\netlogon.dll
[2008/04/13 19:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\netlogon.dll
[2004/08/10 07:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll

< MD5 for: SCECLI.DLL >
[2004/08/10 07:00:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/13 19:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ERDNT\cache\scecli.dll
[2008/04/13 19:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 19:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\dllcache\scecli.dll
[2008/04/13 19:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\scecli.dll

========== Alternate Data Streams ==========

@Alternate Data Stream - 96 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3F2F06F2
@Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CB16385F
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:588B60C7
@Alternate Data Stream - 111 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7B212553
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:52B72A7C
@Alternate Data Stream - 102 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:EA34E08F
< End of report >

OTL Extras logfile created on: 3/12/2010 11:30:23 PM - Run 1
OTL by OldTimer - Version 3.1.37.0 Folder = C:\Documents and Settings\HP_Administrator\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

958.00 Mb Total Physical Memory | 471.00 Mb Available Physical Memory | 49.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 81.00% Paging File free
Paging file location(s): C:\pagefile.sys 1440 2880 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 177.79 Gb Total Space | 78.80 Gb Free Space | 44.32% Space Free | Partition Type: NTFS
Drive D: | 8.50 Gb Total Space | 1.12 Gb Free Space | 13.14% Space Free | Partition Type: FAT32
Drive E: | 684.06 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: NEIL
Current User Name: HP_Administrator
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"3776:UDP" = 3776:UDP:*:Enabled:Media Center Extender Service
"3390:TCP" = 3390:TCP:*:Enabled:Remote Media Center Experience
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\MSN Messenger\livecall.exe" = C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone) – File not found
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe" = C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe – ()
"C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe – ( )
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe – (Hewlett-Packard Co.)
"C:\Program Files\DISC\DISCover.exe" = C:\Program Files\DISC\DISCover.exe:*:Enabled:DISCover Drop & Play System – (Digital Interactive Systems Corporation)
"C:\Program Files\DISC\DiscStreamHub.exe" = C:\Program Files\DISC\DiscStreamHub.exe:*:Enabled:DISCover Stream Hub – (Digital Interactive Systems Corporation, Inc.)
"C:\Program Files\DISC\myFTP.exe" = C:\Program Files\DISC\myFTP.exe:*:Enabled:DISCover FTP – (Digital Interactive Systems Corporation, Inc.)
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader – (AOL LLC)
"C:\WINDOWS\ehome\ehshell.exe" = C:\WINDOWS\ehome\ehshell.exe:LocalSubNet:Enabled:Media Center – (Microsoft Corporation)
"C:\Program Files\Yahoo!\Messenger\YServer.exe" = C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server – (Yahoo! Inc.)
"C:\Program Files\Adobe\Photoshop Elements 4.0\AdobePhotoshopElementsMediaServer.exe" = C:\Program Files\Adobe\Photoshop Elements 4.0\AdobePhotoshopElementsMediaServer.exe:*:Disabled:Adobe Photoshop Elements Media Server – ()
"C:\Program Files\Hewlett-Packard\HP Software Update\HPWUCli.exe" = C:\Program Files\Hewlett-Packard\HP Software Update\HPWUCli.exe:*:Enabled:HP Software Update Client – (Hewlett-Packard)
"C:\Program Files\AIM6\aim6.exe" = C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM – (AOL LLC)
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger – (Yahoo! Inc.)
"C:\Program Files\Steam\steamapps\common\empire total war demo\Empire.exe" = C:\Program Files\Steam\steamapps\common\empire total war demo\Empire.exe:*:Enabled:Empire: Total War Demo – (The Creative Assembly Ltd)
"C:\Documents and Settings\HP_Administrator\Desktop\Neil's Shortcuts\Games\Magic\Manalink.exe" = C:\Documents and Settings\HP_Administrator\Desktop\Neil's Shortcuts\Games\Magic\Manalink.exe:*:Enabled:manalink – (MicroProse Software, Inc.)
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox – (Mozilla Corporation)
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)
"C:\Program Files\AVG\AVG9\avgupd.exe" = C:\Program Files\AVG\AVG9\avgupd.exe:*:Enabled:avgupd.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgnsx.exe" = C:\Program Files\AVG\AVG9\avgnsx.exe:*:Enabled:avgnsx.exe – (AVG Technologies CZ, s.r.o.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{03B1B42B-F6DE-41d9-8CFF-DC44E895C7A7}" = PhotoGallery
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{0611BD4E-4FE4-4a62-B0C0-18A4CC463428}" = CP_Package_Variety1
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{075473F5-846A-448B-BCB3-104AA1760205}" = Sonic RecordNow Data
"{09984AEC-6B9F-4ca7-B78D-CB44D4771DA3}" = Destinations
"{0B33B738-AD79-4E32-90C5-E67BFB10BBFF}" = AiO_Scan
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{11C98E1A-EC91-4B38-B44C-C562292D8453}" = Adobe Premiere Elements 2.0
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{15EE79F4-4ED1-4267-9B0F-351009325D7D}" = HP Software Update
"{16BE87BC-69F5-4D36-8CF0-E1CB3ACD5ED3}" = HP Driver Diagnostics
"{172975EB-9465-4861-95B5-C7BB6D3DE62A}" = DocumentViewer
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1C139D7D-9FEA-468d-A9C8-2A6E3BDE564A}" = CP_Package_Variety3
"{1E2F8AE3-3437-44E6-BB75-E95751D6B83F}" = Picture Package
"{1F51A0CA-2BDD-474E-BB90-C7FA8EA78F52}" = ImageMixer VCD/DVD2 for OLYMPUS
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = DVD Suite
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{2070F79D-46BC-4EEA-8F02-9B4DCABAE7CB}" = iPod for Windows 2006-03-23
"{21657574-BD54-48A2-9450-EB03B2C7FC29}" = Sonic MyDVD Plus
"{21DB3D90-D816-4092-A260-CA3F6B55A6DD}" = Sonic_PrimoSDK
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{23A7B376-BBEC-4e76-BBD7-0F155E70D74B}" = CP_Panorama1Config
"{23FE964A-853B-4176-86D7-9E18B5CA1FC0}" = Media Center Extender
"{26A24AE4-039D-4CA4-87B4-2F83216018FF}" = Java™ 6 Update 18
"{2818095F-FB6C-42C8-827E-0A406CC9AFF5}" = Quicken 2006
"{2C5D07FB-31A2-4F2D-9FDA-0B24ACD42BD0}" = HP Deskjet Printer Preload
"{2CADCEAB-D5DA-44D6-B5FC-7DEE87AB3C0C}" = Unload
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
"{30C19FF2-7FBA-4d09-B9DE-1659977F64F6}" = TrayApp
"{32BDCCB8-9DC8-496d-9DB1-F77510775BDB}" = InstantShareDevices
"{33D6CC28-9F75-4d1b-A11D-98895B3A3729}" = HP Photosmart 330,380,420,470,7800,8000,8200 Series
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{36E47DA1-10E1-45d9-8B19-14D19607CDCF}" = CP_CalendarTemplates1
"{382E94C0-6E22-44e4-B003-8EB31DFE296F}" = cp_LightScribeConfig
"{388E4B09-3E71-4649-8921-F44A3A2954A7}" = Microsoft Visual Studio 2005 Tools for Office Runtime
"{3912A629-0020-0005-3757-2FBA74D4DF0A}" = InterVideo WinDVD Player
"{3AC54383-31D1-4907-961B-B12CBB1D0AE8}" = MobileMe Control Panel
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3B55590C-8A9B-4BD6-B489-744B63026A2A}" =
"{3BA95526-6AE0-4B87-A62D-17187EF565FC}" = HP Boot Optimizer
"{3C0BAFCA-BDB8-492B-8845-DC0A4B4C1823}" = HPDeskjet5400Series
"{3E386744-10FA-44b2-98C9-DF7A270DECB3}" = HP PSC & OfficeJet 5.3.A
"{3FA195A0-10BE-4315-9B7C-1486845BD002}" = LeapFrog Tag Junior Plugin
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{416D80BA-6F6D-4672-B7CF-F54DA2F80B44}" = Microsoft Works
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{456C9A7C-67D1-4013-8DBF-A3F7E5D81033}" = Nero 7 Essentials
"{47FB62DF-832D-485F-95FC-C93BB08B8FE3}" = LeapFrog Connect
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{51D386C4-0227-46A9-AC45-61F0A50E7AFF}" = Rome - Total War
"{5421155F-B033-49DB-9B33-8F80F233D4D5}" = GdiplusUpgrade
"{54E3707F-808E-4fd4-95C9-15D1AB077E5D}" = NewCopy
"{567C23E1-7580-4185-B8C2-30805677297C}" = NewCopy_CDA
"{56EE8B17-8274-418d-89AC-C057C5DB251E}" = RandMap
"{56F8AFC3-FA98-4ff1-9673-8A026CBF85BE}" = WebReg
"{5A01C58E-B0EC-49b9-AD71-7C0468688087}" = CP_Package_Basic1
"{5A3F6A80-7913-475E-8B96-477A952CFA43}" = SupportSoft Assisted Service
"{5B79CFD1-6845-4158-9D7D-6BE89DF2C135}" = HP PSC & OfficeJet 5.3.B
"{5C29CB8B-AC1E-4114-8D68-9CD080140D4A}" = Sony USB Driver
"{5EC786D5-C0CA-42E0-AF88-5379EF9D91EC}" = First Step Guide
"{5F26311C-B135-4F7F-B11E-8E650F83651E}" = DeviceFunctionQFolder
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Sonic Express Labeler
"{66BA8C26-AFE4-4408-807B-43E76B57EF53}" = SkinsHP1
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6BB6627C-694F-4FDC-A3E5-C7F4BED4C724}" = DocProc
"{6DCB9F1F-3BCC-4078-B90C-439017F1806C}" = Crystalize 2
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{71d6ce84-b7dc-4166-8e0d-56c1c37bfb5a}" =
"{755EC5E3-FD51-46bd-A57F-7A2D56FBF061}" = PSTAPlugin
"{769A295C-DCF4-41d6-AFBA-7D9394B23AFE}" = PSPrinters08
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7850A6D2-CBEA-4728-9877-F1BEDEA9F619}" = AiOSoftware
"{7C03270C-4FAB-4F5C-B10D-52FEDA190790}" = DocumentViewerQFolder
"{7E27304E-BAA2-4d90-A34E-76641FAFABB4}" = CP_AtenaShokunin1Config
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11052313}" = Magic Match
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-115286387}" = Operation Mania
"{83073C45-3003-4671-9A86-243AAADD915A}" = Microsoft Calculator Plus
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C3727F2-8E37-49E4-820C-03B1677F53B6}" = Stronghold Crusader
"{8EDBA74D-0686-4C99-BFDD-F894678E5102}" = Adobe Common File Installer
"{8FFC924C-ED06-44CB-8867-3CA778ECE903}" = Adobe Help Center 2.0
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{91120409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Standard Edition 2003
"{91490409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office 2003 Primary Interop Assemblies
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD Player
"{923A7F5A-1E8C-4FBE-8DF6-85940A60A79F}" = Readme
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{98936CBC-5E7A-4AD7-B05B-6D34C7C68E37}" = Hoyle Board Games 2005
"{9A2F0810-3619-4E86-9072-973FBE1679C5}" = QuickBooks Simple Start 2009
"{9E17C94B-913A-48A4-B1A8-8CE25157C170}" = Media Player Product Tool 5.20
"{A040AC77-C1AA-4CC9-8931-9F648AF178F6}" = VC 9.0 Runtime
"{A06275F4-324B-4E85-95E6-87B2CD729401}" = Windows Defender
"{A0EB195B-5876-48E6-879D-33D4B2102610}" = SonicStage 3.4
"{A195B13E-A5E3-4BAF-A995-7F70F445CD06}" = ScannerCopy
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A3455242-DAE0-4523-8242-FD82706ABF4B}" = CameraDrivers
"{A5BB5365-EFB4-44c3-A7E2-EB59B7EFD23D}" = CueTour
"{A6FDF86A-F541-4E7B-AEA0-8849A2A700D5}" = iTunes
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Sonic RecordNow Audio
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Sonic RecordNow Copy
"{B276997E-4367-4b1b-A39C-4CAE7464337A}" = AiO_Scan_CDA
"{B44AA698-B221-4B3B-8CA5-E65EF6A5AF26}" = Hoyle Card Games 2005
"{B4D279F1-4309-49cc-A4B5-3A0D2E59C7B5}" = PanoStandAlone
"{B60E7826-F117-4d26-8165-D2DC5A494AB0}" = Fax_CDA
"{B64E3AFC-59EF-4f18-BF11-E751462450D3}" = AiOSoftwareNPI
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = PowerProducer
"{B824B5C9-849F-4b9e-9EA7-6FD8CD8116DA}" = CP_Package_Variety2
"{B996AE66-10DB-4ac5-B151-E8B4BFBC42FC}" = BufferChm
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C104580B-1C79-4d73-9BF0-CA0B184296A4}" = cp_LightScribePlugin
"{C4124E95-5061-4776-8D5D-E3D931C778E1}" = Microsoft VC9 runtime libraries
"{C506A18C-1469-4678-B094-F4EC9DAE6DB7}" = Scan
"{C83A12B9-B31B-461A-BBD4-CE9B988094F1}" = HP Photosmart Cameras 5.0
"{C917BA70-28A3-4C74-B163-41FD8C8E1A5A}" = Stronghold
"{C98E5F1B-5C2B-4FD1-BDF9-F3779DCAAA16}" =
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE24344F-DFD8-40C8-8FD8-C9740B5F25AC}" = Fax
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CF2606C7-63AF-40F4-8919-F2EC654ACC91}" = Napster for Windows Media Player
"{CFB17307-B244-4EAD-AE8E-CDAF440477C2}" = OpenMG Secure Module 4.4.00
"{D518592A-0F1E-40ca-BECB-3D3F026C6B0D}" = CameraDrivers
"{D9CDB463-BB48-4B80-B1B6-5B940A4621E0}" = AutoStreamer
"{DB518BA6-CB74-4EB6-9ABD-880B6D6E1F38}" = HpSdpAppCoreApp
"{DFB0FED6-0010-4E9B-A402-E513F2459161}" = muvee autoProducer unPlugged 1.2
"{E1180142-3B31-4DCC-9D27-7AC2D37662BF}" = LightScribe 1.4.124.1
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{E34351A4-4B10-4DFF-96BC-84C642D9C625}" = The Print Shop 22
"{E371C150-A9F1-49CE-ACC1-51AEFD01C1D4}_is1" = Turbo Tax Audit Support Center 3.0
"{E3F90083-80D4-4b5a-87C7-E97E12F5516D}" = HPProductAssistant
"{E7137AFD-4E43-47A6-BDC7-533808F72B36}" = muvee autoProducer 4.5
"{E85FA9A1-C241-4698-893B-DD99509B8DB0}" =
"{E9787678-551D-4478-9682-DBB587257110}" =
"{EA103B64-C0E4-4C0E-A506-751590E1653D}" = SolutionCenter
"{EB57A16E-500D-43d7-85B9-FBE279EBBA6E}" = HP Deskjet 5400 series
"{EBB7C1C1-D439-4D9B-9FDC-954C10F266B0}" = Adobe Photoshop Elements 4.0
"{ECFDD6BD-E0C0-41CC-A171-E6D6AF4C0E93}" = HP Software Update
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F4C2E5F5-2970-45f4-ABD3-C180C4D961C4}" = Status
"{F64306A5-4C32-41bb-B153-53986527FAB4}" =
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{F80239D8-7811-4D5E-B033-0D0BBFE32920}" = HP DigitalMedia Archive
"{F8C6BABF-0837-4EA0-AD6C-8E5A392A7538}" = ImageMixer VCD2
"{FD69C8CB-6964-432C-98AB-A5A09ED50EEA}" = Barbarian Invasion
"12133444-BF36-4d4e-B7FB-A3424C645DE4" = GemMaster Mystic
"781745E87AFF80C0C1388CFF79D19ECAB2E9BB47" = Windows Driver Package - LeapFrog (FlyUsb) USB (11/05/2008 1.1.1.0)
"Ad-Aware SE Plus" = Ad-Aware SE Plus
"AddressBook" =
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop Elements 4" = Adobe Photoshop Elements 4.0
"AIM_6" = AIM 6
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.9
"ATI Display Driver" = ATI Display Driver
"AudioPlugin.dll" =
"AVG9Uninstall" = AVG Free 9.0
"AwayMode160" = Microsoft Away Mode
"B3EE3001-DC24-4cd1-8743-5692C716659F" = Otto
"BFGC" = Big Fish Games Client
"BFG-Hidden Mysteries - Buckingham Palace" = Hidden Mysteries: Buckingham Palace ™
"C-evo" = C-evo
"CNXT_MODEM_PCI_VEN_14F1&DEV;_2F20&SUBSYS;_200C14F1" = Data Fax SoftModem with SmartCP
"Connection Manager" =
"CopyNow.dll" =
"Coupon Printer for Windows4.0" = Coupon Printer for Windows
"Coupon Printer for Windows5.0.0.0" = Coupon Printer for Windows
"DataPlugin.dll" =
"DirectAnimation" =
"DirectDrawEx" =
"DXM_Runtime" =
"EAFunctions.dll" =
"EHome Devices" = Media Center Extender
"ERUNT_is1" = ERUNT 1.1j
"Flickr Uploadr" = Flickr Uploadr 3.2.1
"Fontcore" =
"Google Updater" = Google Updater
"HijackThis" = HijackThis 2.0.2
"Home Daycare Forms03-1" = Home Daycare Forms
"HP Document Viewer" = HP Document Viewer 5.3
"HP Image Zone for Media Center PC" = HP Image Zone for Media Center PC
"HP Imaging Device Functions" = HP Imaging Device Functions 5.3
"HP Photo & Imaging" = HP Image Zone 5.3
"HP Solution Center & Imaging Support Tools" = HP Solution Center & Imaging Support Tools 5.3
"ICW" =
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"IE40" =
"IE4Data" =
"IE5BAKEX" =
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"IEData" =
"InstallShield Uninstall Information" =
"InstallShield_{2070F79D-46BC-4EEA-8F02-9B4DCABAE7CB}" = iPod for Windows 2006-03-23
"InstallShield_{CFB17307-B244-4EAD-AE8E-CDAF440477C2}" = OpenMG Secure Module 4.4.00
"InstallShield_{DB518BA6-CB74-4EB6-9ABD-880B6D6E1F38}" =
"IntelliMover Data Transfer Demo" = Remove IntelliMover Demo
"king.com" = king.com (remove only)
"Macromedia Shockwave Player" = Macromedia Shockwave Player
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"MathMagic Personal Edition 3.64" = MathMagic Personal Edition 3.64
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Interactive Training" =
"Microsoft Visual Studio 2005 Tools for Office Runtime" = Visual Studio 2005 Tools for Office Second Edition Runtime
"MobileOptionPack" =
"Money2005b" = Microsoft Money 2005
"Mozilla Firefox (3.6)" = Mozilla Firefox (3.6)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSI30a-KB884016" =
"MSI30-Beta1" =
"MSI30-Beta2" =
"MSI30-KB884016" =
"MSI30-RC1" =
"MSI30-RC2" =
"MSI31-Beta" =
"MSI31-RC1" =
"NetMeeting" =
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"OpenMG HotFix4.4-05-12-06-01" = OpenMG Limited Patch 4.4-06-13-19-01
"OutlookExpress" =
"Panda ActiveScan" = Panda ActiveScan
"PC-Doctor 5 for Windows" = PC-Doctor 5 for Windows
"PCHealth" =
"Peoples Tactics_is1" = v1.0.26f
"Pharaoh" = Pharaoh
"PhotoMix_is1" = PhotoMix 5.3
"PremElem20" = Adobe Premiere Elements 2.0
"PS2" = PS2
"Python 2.2.3" = Python 2.2.3
"pywin32-py2.2" = Python 2.2 pywin32 extensions (build 203)
"RealArcade 1.2" = RealArcade
"RealJukebox 1.0" =
"RealPlayer 6.0" = RealPlayer
"rrpw32.exe" = Reader Rabbit's Preschool
"RRTW32.EXE" = Reader Rabbit's Toddler
"SchedulingAgent" =
"Secunia PSI" = Secunia PSI
"Shockwave" =
"SkyHillKIDSforWindows_is1" = Minute Menu Kids
"SpywareBlaster_is1" = SpywareBlaster 4.2
"ST6UNST #1" = Hero Editor V0.96
"ST6UNST #2" = Hero Editor V0.96 (C:\Program Files\Hero Editor\)
"ST6UNST #3" = Train3D
"Swag_Bucks Toolbar" = Swag_Bucks Toolbar
"UnityWebPlayer" = Unity Web Player
"UPCShell" = LeapFrog Connect
"ViewpointMediaPlayer" = Viewpoint Media Player
"Walgreens PhotoShow Express 4" = Walgreens PhotoShow Express 4
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"WebPost" = Microsoft Web Publishing Wizard 1.52
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinSPWW2v1 DL Edition" = WinSPWW2v1 DL Edition
"winusb0100" = Microsoft WinUsb 1.0
"WMCSetup" = Windows Media Connect
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01007" = Microsoft User-Mode Driver Framework Feature Pack 1.7
"Yahoo! Extras" = Yahoo! Browser Services
"Yahoo! Photos Drag-Drop Uploader 1v7" = Yahoo! Photos Easy Upload Tool 1v7
"ZoneAlarm Pro" = ZoneAlarm Pro

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Hidden Expedition - Everest" = Hidden Expedition - Everest (remove only)

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 3/11/2010 2:48:39 PM | Computer Name = NEIL | Source = Google Update | ID = 20
Description =

Error - 3/11/2010 3:48:38 PM | Computer Name = NEIL | Source = Google Update | ID = 20
Description =

Error - 3/11/2010 4:48:41 PM | Computer Name = NEIL | Source = Google Update | ID = 20
Description =

Error - 3/11/2010 5:48:40 PM | Computer Name = NEIL | Source = Google Update | ID = 20
Description =

Error - 3/11/2010 6:48:39 PM | Computer Name = NEIL | Source = Google Update | ID = 20
Description =

Error - 3/11/2010 7:48:37 PM | Computer Name = NEIL | Source = Google Update | ID = 20
Description =

Error - 3/11/2010 8:48:38 PM | Computer Name = NEIL | Source = Google Update | ID = 20
Description =

Error - 3/11/2010 9:48:38 PM | Computer Name = NEIL | Source = Google Update | ID = 20
Description =

Error - 3/11/2010 10:48:38 PM | Computer Name = NEIL | Source = Google Update | ID = 20
Description =

Error - 3/11/2010 11:48:39 PM | Computer Name = NEIL | Source = Google Update | ID = 20
Description =

[ System Events ]
Error - 3/7/2010 9:53:20 AM | Computer Name = NEIL | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the TrueVector Internet Monitor
service to connect.

Error - 3/7/2010 9:53:20 AM | Computer Name = NEIL | Source = Service Control Manager | ID = 7000
Description = The TrueVector Internet Monitor service failed to start due to the
following error: %%1053

Error - 3/9/2010 9:09:52 AM | Computer Name = NEIL | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the TrueVector Internet Monitor
service to connect.

Error - 3/9/2010 9:09:52 AM | Computer Name = NEIL | Source = Service Control Manager | ID = 7000
Description = The TrueVector Internet Monitor service failed to start due to the
following error: %%1053

Error - 3/10/2010 7:56:23 AM | Computer Name = NEIL | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the TrueVector Internet Monitor
service to connect.

Error - 3/10/2010 7:56:23 AM | Computer Name = NEIL | Source = Service Control Manager | ID = 7000
Description = The TrueVector Internet Monitor service failed to start due to the
following error: %%1053

Error - 3/11/2010 8:37:56 AM | Computer Name = NEIL | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the TrueVector Internet Monitor
service to connect.

Error - 3/11/2010 8:37:56 AM | Computer Name = NEIL | Source = Service Control Manager | ID = 7000
Description = The TrueVector Internet Monitor service failed to start due to the
following error: %%1053

Error - 3/12/2010 8:38:01 AM | Computer Name = NEIL | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the TrueVector Internet Monitor
service to connect.

Error - 3/12/2010 8:38:01 AM | Computer Name = NEIL | Source = Service Control Manager | ID = 7000
Description = The TrueVector Internet Monitor service failed to start due to the
following error: %%1053


< End of report >



Gmer downloaded without a hitch but while trying to complete the following instruction

In the right panel, you will see several boxes that have been checked. Uncheck the following …

* Sections
* IAT/EAT
* Drives/Partition other than Systemdrive (typically C:\)
* Show All (don't miss this one)

CPU usage goes to 100% Gmer "Not Responding" and I can do nothing
I restarted the PC and tried a second time with the same results… It's late I'm tired and out of patients for the day
I will attempt again tomorrow when I wake
I will post the remaining log as soon as I get it… Would it be better to try it in safe mode or no?

Thanks
Amebeo
Hi,

Please do the following:
Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean
–Next–
  • Open Malwarebytes.
  • Click on the Update tab.
  • Click Check for Updates button.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post back the log.
–Next–

Would it be better to try it in safe mode or no?

Yes please, try running it in safe mode and uncheck "Files" on the right hand column by clicking on the box beside it, if that still wont work then do the following:

We Need to check for Rootkits with RootRepeal
Please download RootRepeal one of these locations and save it to your desktop
Here
Here
Here
  • Open [external image: Posted Image] on your desktop.
  • Click the [external image: Posted Image] tab.
  • Click the [external image: Posted Image] button.
  • Check just these boxes:
  • [external image: Posted Image]
  • Push Ok
  • Check the box for your main system drive (Usually C:, and press Ok.
  • Allow RootRepeal to run a scan of your system. This may take some time.
  • Once the scan completes, push the [external image: Posted Image] button. Save the log to your desktop, using a distinctive name, such as RootRepeal.txt. Include this report in your post.
To post in your next reply:
1. Malwarebytes' log.
2. GMER / RootRepeal log.
Gmer ran fine in safemode, but seems a little short. Does it seem right?

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-03-13 12:38:11
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\uxldqpob.sys


—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs bb-run.sys (Promise Disk Accelerator/Promise Technology, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 arkbcfltr.sys (Microsoft AR PS/2 Keyboard Filter Driver (Beta 2 Release 2)/Microsoft Corporation)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 arkbcfltr.sys (Microsoft AR PS/2 Keyboard Filter Driver (Beta 2 Release 2)/Microsoft Corporation)

Device atapi.sys (IDE/ATAPI Port Driver/Microsoft Corporation)
Device ACPI.sys (ACPI Driver for NT/Microsoft Corporation)

AttachedDevice \FileSystem\Fastfat \Fat bb-run.sys (Promise Disk Accelerator/Promise Technology, Inc.)

—- EOF - GMER 1.0.15 —-


TFC ran fine but chutdown didn't go as expected… PC got stuck on Windows is Shutting Down screen, however, it did remove the files.

MalewareBytes ran fine as well

Malwarebytes' Anti-Malware 1.44
Database version: 3863
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

3/13/2010 1:16:33 PM
mbam-log-2010-03-13 (13-16-33).txt

Scan type: Quick Scan
Objects scanned: 168271
Time elapsed: 7 minute(s), 57 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Documents and Settings\All Users\Application Data\mswintmp.dat (Malware.Trace) -> Quarantined and deleted successfully.


Thank you
Amebeo
Hi,

There are open ports for your Remote Media Center Experience, did you set this up?

–Next–

Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
–Next–
  • Open OTL.exe.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • There will only be a single log produced. OTL.Txt.
    Note:This log can be located in the OTL. folder on you C:\ drive if it fails to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of this file and post it with your next reply.
To post in your next reply:
1. Kaspersky log.
2. OTL log.
3. How is your computer?

There are open ports for your Remote Media Center Experience, did you set this up?


It is possible that I could have… The only thing I can think of is file sharing to my xbox 360 but I don't use that anymore, so I see no reason for it to be this way currently.

——————————————————————————–
KASPERSKY ONLINE SCANNER 7.0: scan report
Tuesday, March 16, 2010
Operating system: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Monday, March 15, 2010 22:45:36
Records in database: 3808822
——————————————————————————–

Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes

Scan area - My Computer:
C:\
D:\
E:\
F:\
G:\
H:\
I:\

Scan statistics:
Objects scanned: 217737
Threats found: 3
Infected objects found: 10
Suspicious objects found: 0
Scan duration: 06:16:38


File name / Threat / Threats count
C:\hp\recovery\wizard\fscommand\AppRecoveryLink_ret.exe Infected: Trojan-Spy.Win32.Agent.beaf 1
C:\hp\recovery\wizard\fscommand\CDLogic_ret.exe Infected: Trojan-Spy.Win32.Agent.bdzz 1
C:\hp\recovery\wizard\fscommand\CreatorLink_ret.exe Infected: Trojan-Spy.Win32.Agent.beaf 1
C:\hp\recovery\wizard\fscommand\RecordnowLink_ret.exe Infected: Trojan-Spy.Win32.Agent.beaf 1
C:\hp\recovery\wizard\fscommand\RestoreLink_ret.exe Infected: Trojan-Spy.Win32.Agent.beaf 1
C:\hp\recovery\wizard\fscommand\RTCDLink_ret.exe Infected: Trojan-Spy.Win32.Agent.beaf 1
C:\hp\recovery\wizard\fscommand\RunLink_ret.exe Infected: Trojan-Spy.Win32.Agent.beaf 1
C:\hp\recovery\wizard\fscommand\SysRecoveryLink_ret.exe Infected: Trojan-Spy.Win32.Agent.beaf 1
C:\hp\recovery\wizard\fscommand\WizardLink_ret.exe Infected: Trojan-Spy.Win32.Agent.beaf 1
C:\WINDOWS\Web\Wallpaper\welcome\AWhelper.dll Infected: not-a-virus:AdWare.Win32.WebHancer.x 1

Selected area has been scanned.

OTL logfile created on: 3/16/2010 7:15:52 AM - Run 2
OTL by OldTimer - Version 3.1.37.0 Folder = C:\Documents and Settings\HP_Administrator\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

958.00 Mb Total Physical Memory | 639.00 Mb Available Physical Memory | 67.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 80.00% Paging File free
Paging file location(s): C:\pagefile.sys 1440 2880 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 177.79 Gb Total Space | 74.44 Gb Free Space | 41.87% Space Free | Partition Type: NTFS
Drive D: | 8.50 Gb Total Space | 1.12 Gb Free Space | 13.14% Space Free | Partition Type: FAT32
Drive E: | 544.21 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: NEIL
Current User Name: HP_Administrator
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Documents and Settings\HP_Administrator\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe ()
PRC - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (Intuit)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe (Nero AG)
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
PRC - C:\WINDOWS\system32\PSIService.exe ()
PRC - C:\Program Files\Sony\SonicStage\SSAAD.exe ()
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\WINDOWS\arservice.exe (Microsoft)
PRC - C:\Program Files\Hewlett-Packard\HP Software Update\hpwuSchd2.exe (Hewlett-Packard Co.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\HP_Administrator\Desktop\OTL.exe (OldTimer Tools)


========== Win32 Services (SafeList) ==========

SRV - (avg9wd) – C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (getPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (vsmon) – C:\WINDOWS\System32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
SRV - (LeapFrog Connect Device Service) – C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe ()
SRV - (QBCFMonitorService) – C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (Intuit)
SRV - (QBFCService) – C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe (Intuit Inc.)
SRV - (InCDsrv) – C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe (Nero AG)
SRV - (Viewpoint Manager Service) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (ProtexisLicensing) – C:\WINDOWS\system32\PSIService.exe ()
SRV - (SSScsiSV) – C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe (Sony Corporation)
SRV - (MSCSPTISRV) – C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe (Sony Corporation)
SRV - (PACSPTISVR) – C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe (Sony Corporation)
SRV - (SPTISRV) – C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe (Sony Corporation)
SRV - (AdobeActiveFileMonitor4.0) – C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe ()
SRV - (ARSVC) – C:\WINDOWS\arservice.exe (Microsoft)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)


========== Driver Services (SafeList) ==========

DRV - (AvgTdiX) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (vsdatant) – C:\WINDOWS\system32\vsdatant.sys (Check Point Software Technologies LTD)
DRV - (PSI) – C:\WINDOWS\system32\drivers\psi_mf.sys (Secunia)
DRV - (FlyUsb) – C:\WINDOWS\system32\drivers\FlyUsb.sys (LeapFrog)
DRV - (GcKernel) – C:\WINDOWS\system32\drivers\gckernel.sys (Microsoft Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (SDTHOOK) – C:\WINDOWS\system32\drivers\SDTHOOK.SYS (Panda Software)
DRV - (incdrm) – C:\WINDOWS\system32\drivers\InCDRm.sys (Nero AG)
DRV - (InCDPass) – C:\WINDOWS\system32\drivers\InCDPass.sys (Nero AG)
DRV - (InCDfs) – C:\WINDOWS\system32\drivers\InCDfs.sys (Nero AG)
DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (Ps2) – C:\WINDOWS\system32\drivers\PS2.sys (Hewlett-Packard Company)
DRV - (ftsata2) – C:\WINDOWS\system32\DRIVERS\ftsata2.sys (Promise Technology, Inc.)
DRV - (iaStor) – C:\WINDOWS\system32\DRIVERS\iaStor.sys (Intel Corporation)
DRV - (AmdK8) – C:\WINDOWS\system32\drivers\AmdK8.sys (Advanced Micro Devices)
DRV - (RTL8023xp) – C:\WINDOWS\system32\drivers\Rtlnicxp.sys (Realtek Semiconductor Corporation )
DRV - (HSFHWBS2) – C:\WINDOWS\system32\drivers\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) – C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (AFS2K) – C:\WINDOWS\system32\drivers\AFS2K.SYS (Oak Technology Inc.)
DRV - (2WIREPCP) – C:\WINDOWS\system32\drivers\2WirePCP.sys (2Wire, Inc.)
DRV - (rtl8139) Realtek RTL8139(A/B/C) – C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)
DRV - (MDC8021X) AEGIS Protocol (IEEE 802.1x) – C:\WINDOWS\system32\drivers\mdc8021x.sys (Meetinghouse Data Communications)
DRV - (cdrbsdrv) – C:\WINDOWS\system32\drivers\CDRBSDRV.SYS (B.H.A Corporation)
DRV - (bb-run) – C:\WINDOWS\system32\DRIVERS\bb-run.sys (Promise Technology, Inc.)
DRV - (sonypvs1) – C:\WINDOWS\system32\drivers\sonypvs1.sys (Sony Corporation)
DRV - (SWUSBFLT) – C:\WINDOWS\system32\drivers\SWUSBFLT.SYS (Microsoft Corporation)
DRV - (HIDSwvd) – C:\WINDOWS\system32\drivers\hidswvd.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://swagbucks.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94} - C:\Program Files\Swag_Bucks\tbSwa0.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://swagbucks.com/?cmd=home"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.1.3
FF - prefs.js..extensions.enabledItems: [removed]:1.11.6
FF - prefs.js..extensions.enabledItems: {99B98C2C-7274-45a3-A640-D9DF1A1C8460}:1.4
FF - prefs.js..extensions.enabledItems: {35106bca-6c78-48c7-ac28-56df30b51d2d}:1.2.4
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:[removed]
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.783
FF - prefs.js..network.proxy.no_proxies_on: "*.local"

FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox [2010/03/14 11:04:22 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/02/19 01:37:03 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/02/14 12:03:14 | 000,000,000 | —D | M]

[2009/07/26 09:19:14 | 000,000,000 | —D | M] – C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Extensions
[2009/07/26 09:19:14 | 000,000,000 | —D | M] – C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Extensions\[removed]
[2010/03/15 14:06:41 | 000,000,000 | —D | M] – C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\y836keys.default\extensions
[2009/09/03 12:18:00 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\y836keys.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/02/08 23:48:36 | 000,000,000 | —D | M] (PopupMaster) – C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\y836keys.default\extensions\{35106bca-6c78-48c7-ac28-56df30b51d2d}
[2010/02/08 23:47:12 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\y836keys.default\extensions\{6614d11d-d21d-b211-ae23-815234e1ebb5}
[2010/02/08 23:46:42 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\y836keys.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2010/02/08 23:48:36 | 000,000,000 | —D | M] (CookieCuller) – C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\y836keys.default\extensions\{99B98C2C-7274-45a3-A640-D9DF1A1C8460}
[2010/02/08 21:10:41 | 000,000,000 | —D | M] (Adblock Plus) – C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\y836keys.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/02/14 11:59:37 | 000,000,000 | —D | M] (Adobe DLM (powered by getPlus®)) – C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\y836keys.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2010/02/08 23:39:14 | 000,000,000 | —D | M] – C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\y836keys.default\extensions\[removed]
[2010/03/15 14:06:41 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/01/18 23:21:34 | 000,393,216 | —- | M] (Invenda Corporation) – C:\Program Files\Mozilla Firefox\plugins\NPcol400.dll
[2009/11/19 18:16:28 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
[2009/03/18 10:03:40 | 000,214,272 | —- | M] (Midasplayer Ltd) – C:\Program Files\Mozilla Firefox\plugins\npmidas.dll
[2009/11/19 18:16:29 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npMozCouponPrinter.dll
[2007/04/16 13:07:12 | 000,180,293 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\npViewpoint.dll

O1 HOSTS File: ([2010/02/12 23:26:44 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Yahoo! IE Services Button) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Swag Bucks Toolbar) - {8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94} - C:\Program Files\Swag_Bucks\tbSwa0.dll (Conduit Ltd.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Swag Bucks Toolbar) - {8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94} - C:\Program Files\Swag_Bucks\tbSwa0.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Yahoo! ¤u¨ã¦C) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Swag Bucks Toolbar) - {8BDEA9D6-6F62-45EB-8EE9-8A81AF0D2F94} - C:\Program Files\Swag_Bucks\tbSwa0.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! ¤u¨ã¦C) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\hpwuSchd2.exe (Hewlett-Packard Co.)
O4 - HKLM..\Run: [SsAAD.exe] C:\Program Files\Sony\SonicStage\SSAAD.exe ()
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [ZoneAlarm Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: C:\Documents and Settings\HP_Administrator\Start Menu\Programs\Startup\V CAST Media Monitor.lnk = C:\Program Files\V CAST Media Manager\MEMonitor.exe (Smith Micro, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll (Google Inc.)
O9 - Extra Button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O9 - Extra Button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ()
O9 - Extra 'Tools' menuitem : Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: trymedia.com ([]http in Trusted sites)
O15 - HKLM\..Trusted Domains: trymedia.com ([]https in Trusted sites)
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab (Checkers Class)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/e/4…/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://pcpitstop.com/betapit/PCPitStop.CAB (PCPitstop Utility)
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} file:///C:/Program%20Files/Risk/Images/stg_drm.ocx (SpinTop DRM Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/C/0…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab (Minesweeper Flags Class)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} http://www.pogo.com/cdl/launcher/PogoWebLa…erInstaller.CAB (PogoWebLauncher Control)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://photo.walgreens.com/WalgreensActivia.cab (Snapfish Activia)
O16 - DPF: {45A0A292-ECC6-4D8F-9EA9-A4BD411D24C1} http://www.king.com/ctl/kingcomie.cab (king.com)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {54BE6B6F-3056-470B-97E1-BB92E051B6C4} http://h20264.www2.hp.com/ediags/dd/instal…nosticsxp2k.cab (DeviceEnum Class)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://go.divx.com/plugin/DivXBrowserPlugin.cab (DivXBrowserPlugin Object)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab (MessengerStatsClient Class)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} http://web1.shutterfly.com/downloads/Uploader.cab (Shutterfly Picture Upload Plugin)
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} http://acs.pandasoftware.com/activescan/as5free/asinst.cab (ActiveScan Installer Class)
O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} http://offers.e-centives.com/cif/download/bin/actxcab.cab (CBSTIEPrint Class)
O16 - DPF: {BE319D04-18BD-4B34-AECC-EE7CB610FCA9} http://download.games.yahoo.com/games/web_…itched/main.cab (BewitchedGameClass Control)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} file:///C:/Program%20Files/Monopoly/Images/armhelper.ocx (ArmHelper Control)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} http://h30043.www3.hp.com/hpdj/en/check/qdiagh.cab?326 (QDiagHUpdateObj Class)
O16 - DPF: {F137B9BA-89EA-4B04-9C67-2074A9DF61FD} http://cvs.pnimedia.com/upload/activex/v2_…upv2.0.0.10.cab? (Photo Upload Plugin Class)
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} http://dlm.tools.akamai.com/dlmanager/vers…ivex-latest.cab (DownloadManager Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\intu-help-qb2 {84D77A00-41B5-4b8b-8ADF-86486D72E749} - C:\Program Files\Intuit\QuickBooks 2009\HelpAsyncPluggableProtocol.dll (Intuit, Inc.)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop WallPaper: C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/05/14 18:49:12 | 000,000,150 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2001/07/28 05:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O32 - AutoRun File - [2000/04/02 13:36:38 | 000,000,030 | R— | M] () - E:\AUTORUN.INF – [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/03/14 13:25:08 | 000,000,000 | —D | C] – C:\Program Files\Total War
[2010/03/14 10:41:58 | 000,012,464 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2010/03/13 23:34:52 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Application Data\Smith Micro
[2010/03/13 23:33:41 | 000,000,000 | —D | C] – C:\Program Files\LG Electronics
[2010/03/13 23:33:07 | 000,319,456 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\DIFxAPI.dll
[2010/03/13 23:32:51 | 000,000,000 | —D | C] – C:\Program Files\CASIO
[2010/03/13 23:32:32 | 000,000,000 | —D | C] – C:\Program Files\Samsung
[2010/03/13 23:31:14 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Research In Motion
[2010/03/13 23:31:13 | 000,000,000 | —D | C] – C:\Program Files\Research In Motion
[2010/03/13 23:30:07 | 000,000,000 | —D | C] – C:\Program Files\Xiph.Org
[2010/03/13 23:29:47 | 000,000,000 | —D | C] – C:\Program Files\V CAST Media Manager
[2010/03/13 23:29:46 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Tarma Installer
[2010/03/13 11:14:59 | 000,472,064 | —- | C] ( ) – C:\Documents and Settings\HP_Administrator\Desktop\RootRepeal.exe
[2010/03/13 11:11:07 | 000,444,416 | —- | C] (OldTimer Tools) – C:\Documents and Settings\HP_Administrator\Desktop\TFC.exe
[2010/03/13 00:56:06 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Desktop\gmer
[2010/03/13 00:27:50 | 000,555,520 | —- | C] (OldTimer Tools) – C:\Documents and Settings\HP_Administrator\Desktop\OTL.exe
[2010/03/11 11:43:53 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Desktop\freezer recipes
[2010/03/06 09:40:04 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Temp
[2010/02/26 13:15:45 | 000,000,000 | -H-D | C] – C:\$AVG
[2010/02/26 13:14:46 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\avg9
[2010/02/26 13:12:21 | 000,000,000 | —D | C] – C:\WINDOWS\SxsCaPendDel
[2010/02/26 13:05:26 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2010/02/26 13:05:26 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2010/02/26 13:05:25 | 000,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2010/02/26 13:05:25 | 000,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2010/02/18 12:00:10 | 000,000,000 | —D | C] – C:\Program Files\Turbo Tax Audit Support Center
[2010/02/14 13:11:41 | 000,103,816 | —- | C] (Check Point Software Technologies LTD) – C:\WINDOWS\System32\zlcommdb.dll
[2010/02/14 13:11:41 | 000,069,000 | —- | C] (Check Point Software Technologies LTD) – C:\WINDOWS\System32\zlcomm.dll
[2010/02/14 13:11:31 | 000,041,864 | —- | C] (Check Point Software Technologies LTD) – C:\WINDOWS\System32\vswmi.dll
[2010/02/14 13:11:28 | 001,238,408 | —- | C] (Check Point Software Technologies LTD) – C:\WINDOWS\System32\zpeng25.dll
[2010/02/14 13:11:27 | 000,299,912 | —- | C] (Check Point Software Technologies LTD) – C:\WINDOWS\System32\vspubapi.dll
[2010/02/14 13:11:26 | 000,107,912 | —- | C] (Check Point Software Technologies LTD) – C:\WINDOWS\System32\vsmonapi.dll
[2010/02/14 13:11:25 | 000,486,280 | —- | C] (Check Point Software Technologies LTD) – C:\WINDOWS\System32\vsdatant.sys
[2010/02/14 13:11:25 | 000,112,008 | —- | C] (Check Point Software Technologies LTD) – C:\WINDOWS\System32\vsdata.dll
[2010/02/14 13:08:24 | 000,227,720 | —- | C] (Check Point Software Technologies LTD) – C:\WINDOWS\System32\vsinit.dll
[2010/02/14 13:08:23 | 000,620,936 | —- | C] (Check Point Software Technologies LTD) – C:\WINDOWS\System32\vsutil.dll
[2010/02/14 13:02:57 | 000,000,000 | —D | C] – C:\Program Files\Secunia
[2010/02/14 12:56:11 | 000,000,000 | —D | C] – C:\Program Files\SpywareBlaster
[2010/02/14 12:18:51 | 000,181,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\MpSigStub.exe
[2010/02/14 12:18:01 | 000,000,000 | —D | C] – C:\Program Files\Windows Defender
[2010/02/14 11:59:46 | 000,000,000 | —D | C] – C:\Program Files\NOS
[2010/02/14 11:59:46 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\NOS
[2010/02/09 23:01:23 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010/02/09 22:04:24 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2009/09/07 14:12:07 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Swag_Bucks
[2009/07/01 12:00:42 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2009/03/31 21:24:26 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\HPQ
[2009/03/29 10:34:17 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2009/01/05 15:12:02 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple
[2008/12/10 21:38:36 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Intuit
[2008/04/15 19:05:30 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Google
[2008/04/15 19:05:27 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Viewpoint
[2007/08/01 15:19:14 | 000,774,144 | —- | C] (RealNetworks, Inc.) – C:\Program Files\RngInterstitial.dll
[2005/05/12 10:36:48 | 000,012,288 | —- | C] (Hewlett-Packard Co.) – C:\WINDOWS\Fonts\RandFont.dll

========== Files - Modified Within 30 Days ==========

[2010/03/16 06:48:42 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/03/15 22:46:14 | 057,179,884 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/03/15 18:58:16 | 000,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2010/03/15 14:12:06 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/03/15 08:46:02 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/03/15 08:27:00 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/03/15 08:26:23 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/03/15 08:25:51 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/03/15 08:25:48 | 1005,113,344 | -HS- | M] () – C:\hiberfil.sys
[2010/03/14 23:19:44 | 008,650,752 | —- | M] () – C:\Documents and Settings\HP_Administrator\ntuser.dat
[2010/03/14 23:19:44 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\HP_Administrator\ntuser.ini
[2010/03/14 23:19:31 | 002,110,568 | -H– | M] () – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\IconCache.db
[2010/03/14 23:10:13 | 000,000,049 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2010/03/14 19:33:15 | 000,094,208 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\Simply Asia Seasoning Mixes.doc
[2010/03/14 13:33:43 | 000,000,561 | —- | M] () – C:\WINDOWS\eReg.dat
[2010/03/14 10:42:04 | 000,242,696 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2010/03/14 10:41:58 | 000,012,464 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2010/03/14 10:41:57 | 000,029,512 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2010/03/14 10:37:19 | 000,216,200 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2010/03/14 10:35:01 | 000,445,700 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/03/14 10:35:01 | 000,072,780 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/03/14 10:34:59 | 000,527,912 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/03/14 10:28:51 | 001,241,312 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/03/14 01:15:47 | 000,078,848 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\March to Save Mega Event.doc
[2010/03/13 23:35:30 | 000,000,752 | —- | M] () – C:\Documents and Settings\HP_Administrator\Start Menu\Programs\Startup\V CAST Media Monitor.lnk
[2010/03/13 23:30:13 | 000,000,822 | —- | M] () – C:\Documents and Settings\All Users\Desktop\V CAST Media Manager.lnk
[2010/03/13 11:15:05 | 000,472,064 | —- | M] ( ) – C:\Documents and Settings\HP_Administrator\Desktop\RootRepeal.exe
[2010/03/13 11:11:11 | 000,444,416 | —- | M] (OldTimer Tools) – C:\Documents and Settings\HP_Administrator\Desktop\TFC.exe
[2010/03/13 00:45:52 | 000,284,915 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\gmer.zip
[2010/03/13 00:27:53 | 000,555,520 | —- | M] (OldTimer Tools) – C:\Documents and Settings\HP_Administrator\Desktop\OTL.exe
[2010/03/12 21:27:26 | 000,029,696 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\Possible Employment.doc
[2010/03/11 22:08:13 | 000,048,640 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\Neil Petty - Industrial Electrician.doc
[2010/03/11 21:34:07 | 000,020,480 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\Homemade Mocha Frappuccino.doc
[2010/03/11 20:57:21 | 000,022,516 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\Academic Transcript.zip
[2010/03/10 09:25:59 | 000,000,809 | —- | M] () – C:\WINDOWS\win.ini
[2010/03/09 22:40:49 | 000,232,448 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\Academic Transcript.doc
[2010/03/07 21:48:54 | 000,021,840 | —- | M] () – C:\WINDOWS\System32\SIntfNT.dll
[2010/03/07 21:48:54 | 000,017,212 | —- | M] () – C:\WINDOWS\System32\SIntf32.dll
[2010/03/07 21:48:54 | 000,012,067 | —- | M] () – C:\WINDOWS\System32\SIntf16.dll
[2010/03/03 22:51:09 | 000,000,254 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\Kroger.url
[2010/02/28 20:05:43 | 000,004,212 | -H– | M] () – C:\WINDOWS\System32\zllictbl.dat
[2010/02/26 13:15:33 | 000,142,495 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2010/02/26 13:15:10 | 000,001,518 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG Free 9.0.lnk
[2010/02/26 13:14:51 | 000,113,461 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\iavichjw.avm
[2010/02/24 10:16:06 | 000,181,632 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MpSigStub.exe
[2010/02/23 23:02:12 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/02/23 19:29:22 | 000,000,162 | -H– | M] () – C:\Documents and Settings\HP_Administrator\Desktop\~$ekly Deals.doc
[2010/02/20 08:53:04 | 000,418,099 | -H– | M] () – C:\WINDOWS\System32\vsconfig.xml
[2010/02/18 16:14:05 | 000,001,417 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\Reader Rabbit's Preschool (2).lnk
[2010/02/18 12:00:15 | 000,000,861 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Turbo Tax Audit Support Center.lnk
[2010/02/18 11:56:32 | 000,148,019 | —- | M] () – C:\Documents and Settings\HP_Administrator\My Documents\TaxReturn2009.pdf
[2010/02/17 08:52:49 | 000,000,162 | -H– | M] () – C:\Documents and Settings\HP_Administrator\Desktop\~$S Weekly Ad 2.doc
[2010/02/15 09:49:43 | 000,000,279 | RHS- | M] () – C:\boot.ini
[2010/02/15 09:49:43 | 000,000,264 | —- | M] () – C:\WINDOWS\system.ini
[2010/02/14 12:03:15 | 000,001,740 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk

========== Files Created - No Company Name ==========

[2010/03/14 01:15:46 | 000,078,848 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\March to Save Mega Event.doc
[2010/03/13 23:38:01 | 000,000,049 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2010/03/13 23:34:54 | 000,000,752 | —- | C] () – C:\Documents and Settings\HP_Administrator\Start Menu\Programs\Startup\V CAST Media Monitor.lnk
[2010/03/13 23:30:13 | 000,000,822 | —- | C] () – C:\Documents and Settings\All Users\Desktop\V CAST Media Manager.lnk
[2010/03/13 13:39:17 | 1005,113,344 | -HS- | C] () – C:\hiberfil.sys
[2010/03/13 00:45:50 | 000,284,915 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\gmer.zip
[2010/03/11 21:34:06 | 000,020,480 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\Homemade Mocha Frappuccino.doc
[2010/03/11 20:57:21 | 000,022,516 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\Academic Transcript.zip
[2010/03/11 01:00:40 | 000,094,208 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\Simply Asia Seasoning Mixes.doc
[2010/03/09 23:39:11 | 000,029,696 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\Possible Employment.doc
[2010/03/09 22:40:49 | 000,232,448 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\Academic Transcript.doc
[2010/03/03 22:51:09 | 000,000,254 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\Kroger.url
[2010/02/28 18:46:59 | 000,000,868 | —- | C] () – C:\WINDOWS\tasks\Google Software Updater.job
[2010/02/28 11:36:49 | 000,012,067 | —- | C] () – C:\WINDOWS\System32\SIntf16.dll
[2010/02/26 13:15:10 | 000,001,518 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AVG Free 9.0.lnk
[2010/02/23 19:29:22 | 000,000,162 | -H– | C] () – C:\Documents and Settings\HP_Administrator\Desktop\~$ekly Deals.doc
[2010/02/18 16:14:05 | 000,001,417 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\Reader Rabbit's Preschool (2).lnk
[2010/02/18 12:00:15 | 000,000,861 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Turbo Tax Audit Support Center.lnk
[2010/02/18 11:56:32 | 000,148,019 | —- | C] () – C:\Documents and Settings\HP_Administrator\My Documents\TaxReturn2009.pdf
[2010/02/17 08:52:49 | 000,000,162 | -H– | C] () – C:\Documents and Settings\HP_Administrator\Desktop\~$S Weekly Ad 2.doc
[2010/02/14 12:03:15 | 000,001,740 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2009/09/21 19:32:56 | 000,000,216 | —- | C] () – C:\WINDOWS\TLCAPPS.INI
[2009/07/22 21:03:42 | 000,000,110 | —- | C] () – C:\WINDOWS\{47FB62DF-832D-485F-95FC-C93BB08B8FE3}_WiseFW.ini
[2008/12/19 23:41:13 | 000,000,067 | —- | C] () – C:\Documents and Settings\HP_Administrator\Application Data\photoshow_express_setup.txt
[2008/12/09 16:32:54 | 000,000,095 | —- | C] () – C:\WINDOWS\QBChanUtil_Trigger.ini
[2008/09/13 10:45:51 | 000,000,023 | —- | C] () – C:\WINDOWS\MathMagic Personal 3.64.INI
[2008/09/13 10:45:11 | 000,016,498 | —- | C] () – C:\Program Files\setuplog.txt
[2008/09/13 10:45:11 | 000,015,834 | —- | C] () – C:\Program Files\uninstall.log
[2008/05/21 18:33:21 | 000,000,343 | —- | C] () – C:\WINDOWS\SIERRA.INI
[2008/03/14 15:32:38 | 000,000,343 | —- | C] () – C:\WINDOWS\ULead32.ini
[2008/02/23 19:10:33 | 000,000,071 | —- | C] () – C:\WINDOWS\Pex.INI
[2008/02/04 18:23:10 | 000,693,792 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.DLL
[2008/02/02 23:36:02 | 000,002,947 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/10/29 20:24:32 | 000,000,190 | —- | C] () – C:\Documents and Settings\HP_Administrator\Application Data\G-Force Prefs (WindowsMediaPlayer).txt
[2007/08/03 15:09:41 | 000,003,454 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2007/08/03 15:09:41 | 000,000,008 | RHS- | C] () – C:\WINDOWS\System32\8036B57683.sys
[2007/08/03 15:08:46 | 001,300,048 | —- | C] () – C:\Documents and Settings\All Users\Application Data\pswi_preloaded.exe
[2007/05/21 19:43:37 | 000,000,560 | —- | C] () – C:\Documents and Settings\HP_Administrator\Application Data\ViewerApp.dat
[2007/05/14 18:47:01 | 000,003,654 | —- | C] () – C:\WINDOWS\System32\drivers\Sonyhcp.dll
[2007/05/13 19:58:44 | 000,098,304 | —- | C] () – C:\WINDOWS\System32\resourceGeneric.dll
[2007/01/29 13:23:40 | 000,011,776 | —- | C] () – C:\WINDOWS\System32\ZPORT4AS.dll
[2007/01/19 21:42:01 | 000,000,000 | —- | C] () – C:\WINDOWS\PROTOCOL.INI
[2006/10/14 16:06:20 | 000,796,584 | —- | C] () – C:\WINDOWS\System32\libeay32_0.9.6l.dll
[2006/08/26 16:13:30 | 000,000,000 | —- | C] () – C:\Documents and Settings\HP_Administrator\Application Data\wklnhst.dat
[2006/08/19 09:45:20 | 000,372,736 | —- | C] () – C:\WINDOWS\System32\hpzidi01.dll
[2006/08/19 09:45:19 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\hpzids01.dll
[2006/07/09 21:58:44 | 000,000,091 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2006/05/06 20:20:36 | 000,065,382 | —- | C] () – C:\Documents and Settings\HP_Administrator\Application Data\PatchUpdate_HP_CounterReport_Update_HPSU.log
[2006/05/06 20:20:36 | 000,000,227 | —- | C] () – C:\WINDOWS\HP_CounterReport_Update_HPSU.ini
[2006/05/06 20:20:25 | 000,002,202 | —- | C] () – C:\Documents and Settings\HP_Administrator\Application Data\HPSU_48BitScanUpdate.log
[2006/05/06 20:20:25 | 000,000,214 | —- | C] () – C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2006/05/06 20:19:00 | 000,003,013 | —- | C] () – C:\Documents and Settings\HP_Administrator\Application Data\PatchUpdate_InstantShareJPG.log
[2006/05/06 20:19:00 | 000,000,214 | —- | C] () – C:\WINDOWS\HP_InstantSHareJPG.ini
[2006/05/06 20:17:50 | 000,006,926 | —- | C] () – C:\Documents and Settings\HP_Administrator\Application Data\GdiplusUpgrade_MSIApproach_Wrapper.log
[2006/05/06 20:17:50 | 000,000,206 | —- | C] () – C:\WINDOWS\HPGdiPlus.ini
[2006/05/06 20:01:58 | 000,049,385 | —- | C] () – C:\Documents and Settings\HP_Administrator\Application Data\Update_HP_RedboxHprblog_HPSU.log
[2006/05/06 20:01:58 | 000,000,221 | —- | C] () – C:\WINDOWS\HP_RedboxHprblog_HPSU.ini
[2006/05/03 18:56:01 | 000,000,000 | —- | C] () – C:\WINDOWS\vpc32.INI
[2006/04/30 18:57:19 | 000,043,520 | —- | C] () – C:\WINDOWS\System32\CmdLineExt03.dll
[2006/04/30 18:45:50 | 000,021,840 | —- | C] () – C:\WINDOWS\System32\SIntfNT.dll
[2006/04/30 18:45:50 | 000,017,212 | —- | C] () – C:\WINDOWS\System32\SIntf32.dll
[2006/04/04 21:39:06 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\YCRWin32.dll
[2006/03/22 17:10:12 | 000,000,028 | —- | C] () – C:\WINDOWS\atid.ini
[2006/03/07 22:18:06 | 000,026,112 | —- | C] () – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/03/06 23:47:17 | 000,004,599 | —- | C] () – C:\WINDOWS\hpdj5600.ini
[2006/03/05 13:44:51 | 000,000,139 | —- | C] () – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\fusioncache.dat
[2005/12/02 20:21:27 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/12/02 20:02:13 | 000,022,396 | —- | C] () – C:\WINDOWS\System32\drivers\USBkey.sys
[2005/12/02 19:57:42 | 000,014,316 | —- | C] () – C:\WINDOWS\System32\CHODDI.SYS
[2005/12/02 19:57:35 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\hpreg.dll
[2005/12/02 19:55:33 | 000,000,099 | —- | C] () – C:\WINDOWS\Quicken.ini
[2005/12/02 19:52:27 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/12/02 19:48:06 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2005/12/02 19:48:06 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2005/12/02 19:48:06 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2005/12/02 19:48:06 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2005/12/02 19:48:06 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2005/12/02 19:48:06 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2005/12/02 19:42:51 | 000,000,108 | —- | C] () – C:\WINDOWS\WININIT.INI
[2005/12/02 19:41:57 | 000,000,698 | —- | C] () – C:\WINDOWS\NSSetDefaultBrowser.ini
[2005/12/02 19:31:59 | 000,005,466 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2005/12/02 19:16:15 | 000,000,791 | —- | C] () – C:\WINDOWS\orun32.ini
[2005/12/02 19:09:57 | 000,323,584 | —- | C] () – C:\WINDOWS\System32\pythoncom22.dll
[2005/12/02 19:09:57 | 000,094,208 | —- | C] () – C:\WINDOWS\System32\pywintypes22.dll
[2005/12/02 19:09:42 | 000,016,896 | —- | C] () – C:\WINDOWS\System32\bcbmm.dll
[2005/10/05 16:50:52 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2005/08/06 01:01:54 | 000,235,008 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2005/08/03 03:19:16 | 000,050,176 | —- | C] () – C:\WINDOWS\armcex.dll
[2004/09/16 14:26:40 | 000,012,634 | —- | C] () – C:\WINDOWS\System32\drivers\ADFUUD.SYS
[2004/07/26 18:51:38 | 000,000,560 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2003/01/08 02:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2001/07/07 02:30:00 | 000,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini
[1998/08/16 06:00:00 | 000,004,096 | —- | C] () – C:\WINDOWS\System32\sysres.dll

========== LOP Check ==========

[2008/07/05 17:38:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\acccore
[2010/02/26 13:14:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2008/01/27 20:51:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Broderbund Software
[2008/12/09 16:32:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\COMMON FILES
[2006/04/12 11:43:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Digital Interactive Systems Corporation
[2006/05/03 15:59:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\espionServerData
[2009/07/22 20:52:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Leapfrog
[2007/06/29 14:10:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\muvee Technologies
[2006/03/07 12:50:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Napster
[2009/03/23 19:30:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2009/07/29 22:19:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\RoboForm
[2007/08/01 15:24:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SpinTop Games
[2008/12/10 21:47:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SQL Anywhere 10
[2010/03/13 23:29:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Tarma Installer
[2009/01/18 21:23:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/08/02 10:42:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2009/06/15 15:06:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/09/29 11:17:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/04/06 15:05:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2009/03/18 20:46:39 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{92E7A367-8E12-4830-AA70-29C32E331A81}

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 96 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3F2F06F2
@Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CB16385F
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:588B60C7
@Alternate Data Stream - 111 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7B212553
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:52B72A7C
@Alternate Data Stream - 102 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:EA34E08F
< End of report >
Hi, We're no longer seeing any infections on your machine. The infections found by Kaspersky are all false positives. How is your computer?
I haven't been on my computer much other than to run the scans requested and I tried to defrag yesterday… I defraged in normal mode with windows defrag overnight but it left a really big cluster of fragmented files. I restarted in safe mode and tried again. After 4 hours it got to 15% and stopped saying that some files cannot be defraged. I have another defrag program JK defrag. Should I attempt it with JK? Also my Firewall ZoneAlarm subscription is over. I have switched back to Windows firewall. Are there any good freeware firewalls you recommend? When I get home tonight I'll run some programs and do some browsing and let you know how things seem to be running. *** Things seem to be running smoother. *Start up is still slower than I think it should be… I'm gonna time it one of these days when I think about it *Programs seem to be more responsive not quite so draggy *Firefox is definitely smoother don't seem to be any more known good links that don't want to load or take several clicks and lots of waiting to get them to load… a bit laggy still on occasion but overall fairly good
Hi,

You can use StartUpLite, this may help your computer boot up faster.

If your computer problem still persist, it would be best if you could create a new topic at the Microsoft Windows section of the forum.
Please read this article before creating a new topic as it would greatly help our Tech Team in determining your problem. Also, please provide a link to your new topic back here in order for the team there to review your logs. Thank you.

Your computer now looks clean! :thumbup:

Let's do a little clean up:

Please delete GMER, RootRepeal and all the logs we've created.

–Next–

Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.
You can keep TFC and use it to clean your computer of some junk atleast once a week. You can also keep Malwarebytes, it is an excellent malware removal tool. Update atleast once a week then run a complete scan.

–Next–

You need to create a new Clean restore point.
Click Start Menu > Run > copy and paste

%SystemRoot%\System32\restore\rstrui.exe

Press OK. Choose Create a Restore Point then click Next. Name it (something you'll remember) and click Create, when the confirmation screen shows the restore point has been created click Close.

Remove all previous Restore Points
Click Start Menu > Run > copy and paste

cleanmgr

At top, click on More Options tab. Click Clean up… button in the System Restore box. Click on Yes button. When finished, click on Cancel button to exit.

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Check "Hide file extensions for known file types."
Under the "Hidden files" folder, Uncheck "Show hidden files and folders."
Check "Hide protected operating system files."
Click Apply, and then click OK.

–Next–

To keep your operating system up to date visit
  • Secunia Software inspector to check your program update status.
  • Microsoft Windows Update .

Here are some tips to reduce the potential for spyware infection in the future:

1. It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
Strong passwords: How to create and use them

Then consider a password keeper, to keep all your passwords safe.

2. Make your Internet Explorer More Secure
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab.
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.

    • Change the Download signed ActiveX controls to Prompt.
    • Change the Download unsigned ActiveX controls to Disable.
    • Change the Initialise and script ActiveX controls not marked as safe to Disable.
    • Change the Installation of desktop items to Prompt.
    • Change the Launching programs and files in an IFRAME to Prompt.
    • Change the Navigate sub-frames across different domains to Prompt.
    • When all these settings have been made, click on the OK button.
    • If it prompts you as to whether or not you want to save the settings, press the Yes button.
  • Next press the Apply button and then the OK to exit the Internet Properties page.
3. Update your Anti-Virus Software - I can not overemphasize the need for you to update your Anti-virus application on a regular basis. With the ever increasing number of new variants of malware arriving on the scene daily, you become very susceptible to an attack without updated protection.

4. Make sure you keep your Windows OS current by visiting Windows update regularly to download and install any critical updates and service packs. Without these you are leaving the back door open.

5. Consider a custom hosts file such as MVPS HOSTS. This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers.
For information on how to download and install, please read this tutorial by WinHelp2002
Note: Be sure to follow the instructions to disable the DNS Client service before installing a custom hosts file.

6. Download and install the free version of WinPatrol. This program protects your computer in a variety of ways and will work well with your existing security software. Have a look at this tutorial to help you get started with the program.

7. SpywareBlaster - Download and install SpywareBlaster. This program prevents the installation of ActiveX-based spyware and other potentially unwanted programs.

8. Protect your computer from internet threats with SandboxIE. This program isolates Internet Explorer from the rest of your operating system, 'sandboxing' it away - so malicious websites can't do damage to the rest of your system. There is a Getting Started guide on their website.

9. Some excellent free firewalls. Note: Use only one firewall at a time.
Agnitum Outpost Firewall
Comodo Firewall - If you are installing this and already have an anti spyware then please do not install Comodo's anti spyware program.
Online Armor Personal Firewall

10. And finally, please read these excellent articles:
Malware: Help prevent the Infection by Sandi Hardmeier,
Preventing Malware - Tools and Practices for Safe Computing

For more safe computing tips please read the guide by Rorschach112 on how to prevent malware and about safe computing here.



Good luck, happy computing and stay clean! ^_^
Thank You inzanity Allmost finished with the suggestions I chose Online Armor Personal Firewall thank you for the suggestion. I do have one question. Will SandboxIE slow down browsing speed? I guess two questions I think it does but does it work with Firefox as well? I may have to take your suggestion and move to the windows help forum. My wife was frustrated today saying IE was not loading anything… I mostly use Firefox, but I'm using IE now and everything seems to be working very well… We'll see how it goes. I'm going to try JK defrag to see if I can complete the process. I've got some more reading to do, but nearly done… Again Thank You Amebeo BTW I removed a couple thing in msconfig from startup one of them being zonealarm, and startup seems to be faster and smoother now.
Hi, Sandboxie does not slow down browsing speed and is compatible with Firefox. When you installed Online Armor Personal Firewall, did you remove Zone alarm? Running more than one firewall at the same time does not only slow down your computer but provides less protection than they are programmed to do, due to the fact that they will be conflicting with each other rather than providing sufficient protection for your computer. Please uninstall Zone Alarm as you've chosen to use OA, uninstalling it would also remove it from your start up list.
Thank you inzanity I did remove ZA before installing OA, and windows firewall is turned off. JK defrag is still running; if it is done this afternoon I will give sandboxie a try. Thank you Amebeo

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI