This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Audio Advertisements Play in the Background of my Computer

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

While trying to download a program I allowed an executable file to run that I obvioulsy shouldn't have. I am now hearing advertisements play in the background of my computer occasionally and it is quite annoying (they are usually for Resolve cleaner but not always). Sometimes they play for a short time and other times they are endless. They seem to turn on and off randomly when I open different programs. My laptop is brand new with Windows 7 and I am using the Norton Anitvirus software that came with the computer. I ran a full scan using that after I got the "virus" and it found and removed 53 issues. This spead my computer back up to it's normal speed but I am still hearing the ads play. I tried downloading the recommended scan programs but got error messages saying they weren't compatible with my OS. I did get Hijackthis and posted the scan below. Please help me! Thanks.

Andy B


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:57:16 AM, on 4/2/2010
Platform: Unknown Windows (WinNT 6.01.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Norton Internet Security\Engine\17.5.0.127\ccSvcHst.exe
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCtrl.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Windows\SysWOW64\regsvr32.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
c:\Program Files (x86)\Hewlett-Packard\Media\Live TV\TVAgent.exe
C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqToaster.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\SysWow64\Macromed\Flash\FlashUtil10e.exe
C:\Program Files (x86)\LimeWire\LimeWire.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT/1
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\17.5.0.127\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\17.5.0.127\IPSBHO.DLL
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~4\Office12\GR469A~1.DLL
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Microsoft Live Search Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0566.0\msneshellx.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (file missing)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: hotrevenue browser enhancer - {EFB5A774-79F8-5037-DC3E-92C6E72F3672} - C:\Windows\SysWow64\rwpviuhukgbfl.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: Microsoft Live Search Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0566.0\msneshellx.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\17.5.0.127\coIEPlg.dll
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (file missing)
O4 - HKLM\..\Run: [HPCam_Menu] "c:\Program Files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe" "c:\Program Files (x86)\Hewlett-Packard\Media\Webcam" UpdateWithCreateOnce "Software\Hewlett-Packard\Media\Webcam"
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [NortonOnlineBackupReminder] "C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [WirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [ezLife] rundll32 "smmqklzn.dll",,Run
O4 - HKLM\..\Run: [ihoefgyztb] C:\Windows\System32\regsvr32.exe /s "C:\Windows\system32\rwpviuhukgbfl.dll"
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [Google Update] "C:\Users\Andrew Brown\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [HPADVISOR] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe view=DOCKVIEW
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O13 - Gopher Prefix:
O16 - DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} (WRC Class) - http://trial.trymicrosoftoffice.com/trialo…osoft/wrc32.ocx
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~2\MICROS~4\Office12\GRA32A~1.DLL
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_d15ed671de43d681\AESTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\Windows\system32\Hpservice.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Norton Internet Security (NIS) - Symantec Corporation - C:\Program Files (x86)\Norton Internet Security\Engine\17.5.0.127\ccSvcHst.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_d15ed671de43d681\STacSV64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 12497 bytes
Hello and Welcome to the forums!

My name is Gringo and I'll be glad to help you with your computer problems.

Somethings to remember while we are working together.

1.Please do not run any other tool untill instructed to do so!
2.Please reply to this thread, do not start another!
3.Please tell me about any problems that have occurred during the fix.
4.Please tell me of any other symptoms you may be having as these can help also.
5.Please try as much as possible not to run anything while executing a fix.

If you follow these instructions, everything should go smoothly.

Please print out or make a copy in notpad of any instructions given, as sometimes it is necessary to go offline and you will lose access to them.

Vista and Win 7 Users please Right Click and run as Admin all programs that I ask you to run

: Malwarebytes' Anti-Malware :

  • Please download Malwarebytes' Anti-Malware to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to
    • Update Malwarebytes' Anti-Malware
    • and Launch Malwarebytes' Anti-Malware
  • then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is Checked (ticked) except items in the C:\System Volume Information folder and click on Remove Selected.
  • When completed, a log will open in Notepad. please copy and paste the log into your next reply
    • If you accidently close it, the log file is saved here and will be named like this:
    • C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt

Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.


Backup the Registry:

Modifying the Registry can create unforeseen problems, so it always wise to create a backup before doing so.

  • Please go here and download ERUNT.
  • ERUNT (Emergency Recovery Utility NT) is a free program that allows you to keep a complete backup of your registry and restore it when needed.
  • Double click on erunt-setup.exe to Install ERUNT by following the prompts.
  • Use the default install settings but say no to the portion that asks you to add ERUNT to the Start-Up folder. You can enable this option later if you wish.
  • Start ERUNT either by double clicking on the desktop icon or choosing to start the program at the end of the setup process.
  • Choose a location for the backup. Note: the default location is C:\WINDOWS\ERDNT which is acceptable.
  • Make sure that at least the first two check boxes are selected.
  • Click on OK
  • Then click on YES to create the folder.

Note: If it is necessary to restore the registry, open the backup folder and start ERDNT.exe

Download and run OTL:

Download OTL by Old Timer and save it to your Desktop.
  • Double click on OTL.exe to run it.
  • Under Output, ensure that Minimal Output is selected.
  • Under Extra Registry section, select Use SafeList.
  • Click the Scan All Users checkbox.
  • Click on Run Scan at the top left hand corner.
  • When done, two Notepad files will open.
    • OTListIt.txt <– Will be opened
    • Extra.txt <– Will be minimized
  • Please post the contents of these 2 Notepad files in your next reply.

"information and logs"

  • In your next post I need the following

  • Log From MBAM
  • The two logs from OTL
  • let me know of any problems you may have had
  • How is the computer doing now?

Gringo
Gringo,

Thanks a lot for helping me. I have done as you recommended in your post and have not heard any advertisements yet. I hope this worked but as I have learned in the past sometimes the problem appears to be gone but it isn't completely. Here are my log files, let me know what to do next. If it appears my computer is clean now I would like to get your recommendation on what software I should use to keep it safe (without causing a loss of performance). I have the trial version of Norton and it seems to be pretty good. I am considering paying to activate it once the trial version is up but let me know what your thoughts are. thanks again.

Andrew

MBAM Log

Malwarebytes' Anti-Malware 1.45
www.malwarebytes.org

Database version: 3947

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

4/2/2010 6:57:48 PM
mbam-log-2010-04-02 (18-57-48).txt

Scan type: Quick scan
Objects scanned: 102805
Time elapsed: 2 minute(s), 33 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 2
Registry Keys Infected: 6
Registry Values Infected: 2
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 8

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
C:\Windows\System32\rwpviuhukgbfl.dll (Adware.Adrotator) -> Delete on reboot.
C:\Windows\SysWOW64\rwpviuhukgbfl.dll (Adware.Adrotator) -> Delete on reboot.

Registry Keys Infected:
HKEY_CLASSES_ROOT\AppID\{38061edc-40bb-4618-a8da-e56353347e6d} (Adware.EZlife) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\{a9722a0d-365f-47d2-b70b-37d046316d99} (Adware.EZlife) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\ezLife (Adware.EzLife) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Smart-Ads-Solutions (Adware.SmartAds) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{efb5a774-79f8-5037-dc3e-92c6e72f3672} (Adware.AdRotator) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{efb5a774-79f8-5037-dc3e-92c6e72f3672} (Adware.AdRotator) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ihoefgyztb (Adware.Adrotator) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ezlife (Adware.EZlife) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Windows\System32\rwpviuhukgbfl.dll (Adware.Adrotator) -> Delete on reboot.
C:\Windows\SysWOW64\rwpviuhukgbfl.dll (Adware.Adrotator) -> Delete on reboot.
C:\Users\Andrew Brown\Documents\downloads\adware-pro-v04.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Windows\System32\qyuapejm.dll (Adware.Adrotator) -> Quarantined and deleted successfully.
C:\Windows\System32\smmqklzn.dll (Adware.Adrotator) -> Quarantined and deleted successfully.
C:\Users\Andrew Brown\AppData\Local\Temp\COM Security Update Level 1 (Adware.Adrotator) -> Quarantined and deleted successfully.
C:\Users\Andrew Brown\AppData\Local\Temp\COM Security Update Level 2 (Adware.Adrotator) -> Quarantined and deleted successfully.
C:\Users\Andrew Brown\AppData\Local\Temp\COM Security Update Level 7 (Adware.Adrotator) -> Quarantined and deleted successfully.


———————————————————————————————————————————————————————————————-

OTList

OTL logfile created on: 4/2/2010 7:05:04 PM - Run 1
OTL by OldTimer - Version 3.1.37.3 Folder = C:\Users\Andrew Brown\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 68.00% Memory free
8.00 Gb Paging File | 6.00 Gb Available in Paging File | 81.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 452.25 Gb Total Space | 329.51 Gb Free Space | 72.86% Space Free | Partition Type: NTFS
Drive D: | 13.21 Gb Total Space | 2.20 Gb Free Space | 16.63% Space Free | Partition Type: NTFS
Drive E: | 99.02 Mb Total Space | 96.46 Mb Free Space | 97.41% Space Free | Partition Type: FAT32
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: ANDREWBROWN-PC
Current User Name: Andrew Brown
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Users\Andrew Brown\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Norton Internet Security\Engine\17.5.0.127\ccsvchst.exe (Symantec Corporation)
PRC - c:\Program Files (x86)\Hewlett-Packard\Media\Live TV\TVAgent.exe (CyberLink Corp.)
PRC - c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe (CyberLink)


========== Modules (SafeList) ==========

MOD - C:\Users\Andrew Brown\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\SysWOW64\comdlg32.dll (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV:64bit: - (STacSV) – C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_d15ed671de43d681\stacsv64.exe (IDT, Inc.)
SRV:64bit: - (WwanSvc) – C:\Windows\SysNative\wwansvc.dll (Microsoft Corporation)
SRV:64bit: - (WbioSrvc) – C:\Windows\SysNative\wbiosrvc.dll (Microsoft Corporation)
SRV:64bit: - (Power) – C:\Windows\SysNative\umpo.dll (Microsoft Corporation)
SRV:64bit: - (Themes) – C:\Windows\SysNative\themeservice.dll (Microsoft Corporation)
SRV:64bit: - (sppuinotify) – C:\Windows\SysNative\sppuinotify.dll (Microsoft Corporation)
SRV:64bit: - (SensrSvc) – C:\Windows\SysNative\sensrsvc.dll (Microsoft Corporation)
SRV:64bit: - (PNRPsvc) – C:\Windows\SysNative\pnrpsvc.dll (Microsoft Corporation)
SRV:64bit: - (p2pimsvc) – C:\Windows\SysNative\pnrpsvc.dll (Microsoft Corporation)
SRV:64bit: - (HomeGroupProvider) – C:\Windows\SysNative\provsvc.dll (Microsoft Corporation)
SRV:64bit: - (RpcEptMapper) – C:\Windows\SysNative\RpcEpMap.dll (Microsoft Corporation)
SRV:64bit: - (PNRPAutoReg) – C:\Windows\SysNative\pnrpauto.dll (Microsoft Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (HomeGroupListener) – C:\Windows\SysNative\ListSvc.dll (Microsoft Corporation)
SRV:64bit: - (FontCache) – C:\Windows\SysNative\FntCache.dll (Microsoft Corporation)
SRV:64bit: - (Dhcp) – C:\Windows\SysNative\dhcpcore.dll (Microsoft Corporation)
SRV:64bit: - (defragsvc) – C:\Windows\SysNative\defragsvc.dll (Microsoft Corporation)
SRV:64bit: - (bthserv) – C:\Windows\SysNative\bthserv.dll (Microsoft Corporation)
SRV:64bit: - (BDESVC) – C:\Windows\SysNative\bdesvc.dll (Microsoft Corporation)
SRV:64bit: - (AxInstSV) – C:\Windows\SysNative\AxInstSv.dll (Microsoft Corporation)
SRV:64bit: - (AppIDSvc) – C:\Windows\SysNative\appidsvc.dll (Microsoft Corporation)
SRV:64bit: - (wbengine) – C:\Windows\SysNative\wbengine.exe (Microsoft Corporation)
SRV:64bit: - (sppsvc) – C:\Windows\SysNative\sppsvc.exe (Microsoft Corporation)
SRV:64bit: - (Fax) – C:\Windows\SysNative\FXSSVC.exe (Microsoft Corporation)
SRV:64bit: - (hpsrv) – C:\Windows\SysNative\hpservice.exe (Hewlett-Packard)
SRV:64bit: - (AESTFilters) – C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_d15ed671de43d681\AESTSr64.exe (Andrea Electronics Corporation)
SRV - (NIS) – C:\Program Files (x86)\Norton Internet Security\Engine\17.5.0.127\ccSvcHst.exe (Symantec Corporation)
SRV - (VSS) – C:\Windows\Vss [2009/07/13 23:20:14 | 000,000,000 | —D | M]
SRV - (MSDTC) – C:\Windows\SysWOW64\Msdtc [2009/07/13 23:20:14 | 000,000,000 | —D | M]
SRV - (HomeGroupProvider) – C:\Windows\SysWOW64\provsvc.dll (Microsoft Corporation)
SRV - (Dhcp) – C:\Windows\SysWOW64\dhcpcore.dll (Microsoft Corporation)
SRV - (vds) – C:\Windows\SysWOW64\wbem\vds.mof ()
SRV - (clr_optimization_v2.0.50727_64) – C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (GameConsoleService) – C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (Microsoft Office Groove Audit Service) – C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (BCM43XX) – C:\Windows\SysNative\drivers\BCMWL664.SYS (Broadcom Corporation)
DRV:64bit: - (SymEvent) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS (Symantec Corporation)
DRV:64bit: - (ccHP) – C:\Windows\SysNative\drivers\NISx64\1105000.07F\cchpx64.sys (Symantec Corporation)
DRV:64bit: - (SRTSP) – C:\Windows\SysNative\drivers\NISx64\1105000.07F\srtsp64.sys (Symantec Corporation)
DRV:64bit: - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\Windows\SysNative\drivers\NISx64\1105000.07F\srtspx64.sys (Symantec Corporation)
DRV:64bit: - (SymEFA) – C:\Windows\SysNative\drivers\NISx64\1105000.07F\symefa64.sys (Symantec Corporation)
DRV:64bit: - (SymIRON) – C:\Windows\SysNative\drivers\NISx64\1105000.07F\ironx64.sys (Symantec Corporation)
DRV:64bit: - (SYMTDIv) – C:\Windows\SysNative\drivers\NISx64\1105000.07F\symtdiv.sys (Symantec Corporation)
DRV:64bit: - (STHDA) – C:\Windows\SysNative\drivers\stwrt64.sys (IDT, Inc.)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (SymDS) – C:\Windows\SysNative\drivers\NISx64\1105000.07F\symds64.sys (Symantec Corporation)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (NVHDA) – C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (JMCR) – C:\Windows\SysNative\drivers\jmcr.sys (JMicron Technology Corporation)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (KSecPkg) – C:\Windows\SysNative\drivers\ksecpkg.sys (Microsoft Corporation)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (hwpolicy) – C:\Windows\SysNative\drivers\hwpolicy.sys (Microsoft Corporation)
DRV:64bit: - (FsDepends) – C:\Windows\SysNative\drivers\fsdepends.sys (Microsoft Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (WIMMount) – C:\Windows\SysNative\drivers\wimmount.sys (Microsoft Corporation)
DRV:64bit: - (vhdmp) – C:\Windows\SysNative\drivers\vhdmp.sys (Microsoft Corporation)
DRV:64bit: - (vdrvroot) – C:\Windows\SysNative\drivers\vdrvroot.sys (Microsoft Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (rdyboost) – C:\Windows\SysNative\drivers\rdyboost.sys (Microsoft Corporation)
DRV:64bit: - (pcw) – C:\Windows\SysNative\drivers\pcw.sys (Microsoft Corporation)
DRV:64bit: - (CNG) – C:\Windows\SysNative\drivers\cng.sys (Microsoft Corporation)
DRV:64bit: - (fvevol) – C:\Windows\SysNative\drivers\fvevol.sys (Microsoft Corporation)
DRV:64bit: - (rdpbus) – C:\Windows\SysNative\drivers\rdpbus.sys (Microsoft Corporation)
DRV:64bit: - (RDPREFMP) – C:\Windows\SysNative\drivers\RDPREFMP.sys (Microsoft Corporation)
DRV:64bit: - (RasAgileVpn) WAN Miniport (IKEv2) – C:\Windows\SysNative\drivers\agilevpn.sys (Microsoft Corporation)
DRV:64bit: - (WfpLwf) – C:\Windows\SysNative\drivers\wfplwf.sys (Microsoft Corporation)
DRV:64bit: - (NdisCap) – C:\Windows\SysNative\drivers\ndiscap.sys (Microsoft Corporation)
DRV:64bit: - (vwifimp) – C:\Windows\SysNative\drivers\vwifimp.sys (Microsoft Corporation)
DRV:64bit: - (vwififlt) – C:\Windows\SysNative\drivers\vwififlt.sys (Microsoft Corporation)
DRV:64bit: - (vwifibus) – C:\Windows\SysNative\drivers\vwifibus.sys (Microsoft Corporation)
DRV:64bit: - (1394ohci) – C:\Windows\SysNative\drivers\1394ohci.sys (Microsoft Corporation)
DRV:64bit: - (HdAudAddService) – C:\Windows\SysNative\drivers\HdAudio.sys (Microsoft Corporation)
DRV:64bit: - (usbvideo) USB Video Device (WDM) – C:\Windows\SysNative\drivers\usbvideo.sys (Microsoft Corporation)
DRV:64bit: - (UmPass) – C:\Windows\SysNative\drivers\umpass.sys (Microsoft Corporation)
DRV:64bit: - (WinUsb) – C:\Windows\SysNative\drivers\winusb.sys (Microsoft Corporation)
DRV:64bit: - (mshidkmdf) – C:\Windows\SysNative\drivers\mshidkmdf.sys (Microsoft Corporation)
DRV:64bit: - (WudfPf) – C:\Windows\SysNative\drivers\WUDFPf.sys (Microsoft Corporation)
DRV:64bit: - (MTConfig) – C:\Windows\SysNative\drivers\MTConfig.sys (Microsoft Corporation)
DRV:64bit: - (CompositeBus) – C:\Windows\SysNative\drivers\CompositeBus.sys (Microsoft Corporation)
DRV:64bit: - (Beep) – C:\Windows\SysNative\drivers\beep.sys (Microsoft Corporation)
DRV:64bit: - (AppID) – C:\Windows\SysNative\drivers\appid.sys (Microsoft Corporation)
DRV:64bit: - (scfilter) – C:\Windows\SysNative\drivers\scfilter.sys (Microsoft Corporation)
DRV:64bit: - (discache) – C:\Windows\SysNative\drivers\discache.sys (Microsoft Corporation)
DRV:64bit: - (sdbus) – C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (HidBatt) – C:\Windows\SysNative\drivers\hidbatt.sys (Microsoft Corporation)
DRV:64bit: - (CmBatt) – C:\Windows\SysNative\drivers\CmBatt.sys (Microsoft Corporation)
DRV:64bit: - (AcpiPmi) – C:\Windows\SysNative\drivers\acpipmi.sys (Microsoft Corporation)
DRV:64bit: - (AmdPPM) – C:\Windows\SysNative\drivers\amdppm.sys (Microsoft Corporation)
DRV:64bit: - (hpdskflt) – C:\Windows\SysNative\drivers\hpdskflt.sys (Hewlett-Packard)
DRV:64bit: - (Accelerometer) – C:\Windows\SysNative\drivers\Accelerometer.sys (Hewlett-Packard)
DRV:64bit: - (enecir) – C:\Windows\SysNative\drivers\enecir.sys (ENE TECHNOLOGY INC.)
DRV:64bit: - (SrvHsfV92) – C:\Windows\SysNative\drivers\VSTDPV6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfWinac) – C:\Windows\SysNative\drivers\VSTCNXT6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfHDA) – C:\Windows\SysNative\drivers\VSTAZL6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (yukonw7) – C:\Windows\SysNative\drivers\yk62x64.sys (Marvell)
DRV:64bit: - (netw5v64) Intel® – C:\Windows\SysNative\drivers\netw5v64.sys (Intel Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (HpqKbFiltr) – C:\Windows\SysNative\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (BHDrvx64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\BASHDefs\20100324.001\BHDrvx64.sys (Symantec Corporation)
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\VirusDefs\20100402.004\EX64.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\VirusDefs\20100402.004\ENG64.SYS (Symantec Corporation)
DRV - (IDSVia64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\20100326.001\IDSviA64.sys (Symantec Corporation)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (WinUsb) – C:\Windows\SysWOW64\winusb.dll (Microsoft Corporation)
DRV - (NetBIOS) – C:\Windows\SysWOW64\netbios.dll (Microsoft Corporation)
DRV - (mpsdrv) – C:\Windows\SysWOW64\wbem\mpsdrv.mof ()
DRV - (Tcpip) – C:\Windows\SysWOW64\wbem\tcpip.mof ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT/1
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT/1


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-4258229573-526587920-623500243-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
IE - HKU\S-1-5-21-4258229573-526587920-623500243-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [Binary data over 100 bytes]
IE - HKU\S-1-5-21-4258229573-526587920-623500243-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKU\S-1-5-21-4258229573-526587920-623500243-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\IPSFFPlgn\ [2010/03/12 19:24:19 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/03/12 19:40:19 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\coFFPlgn\ [2010/03/13 13:22:16 | 000,000,000 | —D | M]

[2010/03/13 15:18:12 | 000,000,000 | —D | M] – C:\Users\Andrew Brown\AppData\Roaming\Mozilla\Extensions
[2010/03/13 15:18:12 | 000,000,000 | —D | M] – C:\Users\Andrew Brown\AppData\Roaming\Mozilla\Extensions\[removed]

O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\17.5.0.127\coieplg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\17.5.0.127\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Microsoft Live Search Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0566.0\msneshellx.dll (Microsoft Corp.)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll File not found
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (Microsoft Live Search Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0566.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\17.5.0.127\coieplg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll File not found
O3 - HKU\S-1-5-21-4258229573-526587920-623500243-1001\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found.
O3 - HKU\S-1-5-21-4258229573-526587920-623500243-1001\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\17.5.0.127\coieplg.dll (Symantec Corporation)
O3 - HKU\S-1-5-21-4258229573-526587920-623500243-1001\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll File not found
O4:64bit: - HKLM..\Run: [NvCplDaemon] C:\Windows\SysNative\NvCpl.DLL (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe ()
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [GrooveMonitor] C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)
O4 - HKLM..\Run: [HPCam_Menu] c:\Program Files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [NortonOnlineBackupReminder] C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe (Symantec Corporation)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\SysWow64\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\SysWow64\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} http://trial.trymicrosoftoffice.com/trialo…osoft/wrc32.ocx (WRC Class)
O16 - DPF: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_19)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18:64bit: - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files (x86)\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (pku2u) - C:\Windows\SysNative\pku2u.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (pku2u) - C:\Windows\SysWow64\pku2u.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/04/02 19:03:35 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2010/04/02 19:02:25 | 000,000,000 | —D | C] – C:\Program Files (x86)\ERUNT
[2010/04/02 18:50:43 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Roaming\Malwarebytes
[2010/04/02 18:50:37 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010/04/02 18:50:35 | 000,024,664 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2010/04/02 18:50:35 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2010/04/02 18:50:35 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/04/02 18:48:41 | 000,555,520 | —- | C] (OldTimer Tools) – C:\Users\Andrew Brown\Desktop\OTL.exe
[2010/04/02 00:57:03 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2010/04/01 21:44:52 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Roaming\Tific
[2010/04/01 21:23:28 | 000,000,000 | —D | C] – C:\ProgramData\Sun
[2010/04/01 21:23:27 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Java
[2010/04/01 21:23:03 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaws.exe
[2010/04/01 21:23:03 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaw.exe
[2010/04/01 21:23:03 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\java.exe
[2010/04/01 20:13:24 | 000,000,000 | —D | C] – C:\Windows\Sun
[2010/04/01 19:21:04 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Local\CrashDumps
[2010/04/01 19:19:47 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2010/03/30 20:50:24 | 001,192,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wininet.dll
[2010/03/30 20:50:24 | 001,026,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mstime.dll
[2010/03/30 20:50:24 | 000,977,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wininet.dll
[2010/03/30 20:50:24 | 000,606,208 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mstime.dll
[2010/03/30 20:50:24 | 000,445,952 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iedkcs32.dll
[2010/03/30 20:50:24 | 000,381,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iedkcs32.dll
[2010/03/30 20:50:24 | 000,082,944 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeedsbs.dll
[2010/03/30 20:50:24 | 000,064,512 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedsbs.dll
[2010/03/29 23:44:15 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\Documents\IUPUI MBA Application
[2010/03/29 19:08:33 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Visual Studio
[2010/03/29 19:06:38 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Visual Studio 8
[2010/03/21 22:38:35 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Local\CutePDF Writer
[2010/03/20 15:31:28 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\Documents\Financial
[2010/03/18 21:39:30 | 000,000,000 | —D | C] – C:\Program Files\HP
[2010/03/18 21:39:25 | 000,127,488 | —- | C] (Zenographics, Inc.) – C:\Windows\SysNative\ZSPOOL.DLL
[2010/03/18 21:39:25 | 000,115,200 | —- | C] (Zenographics, Inc.) – C:\Windows\SysNative\ZLhp1020.DLL
[2010/03/18 21:39:25 | 000,061,952 | —- | C] (Zenographics, Inc.) – C:\Windows\SysNative\ZIMF.DLL
[2010/03/18 21:39:25 | 000,049,664 | —- | C] (Zenographics, Inc.) – C:\Windows\SysNative\ZTAG.DLL
[2010/03/17 18:09:17 | 000,143,360 | R— | C] (Zenographics) – C:\Windows\apptune1020.exe
[2010/03/17 18:09:14 | 000,086,016 | R— | C] (Zenographics, Inc.) – C:\Windows\SysWow64\ZSPOOL.DLL
[2010/03/17 18:09:14 | 000,028,672 | R— | C] (Zenographics, Inc.) – C:\Windows\SysWow64\IMF32.DLL
[2010/03/17 18:09:14 | 000,024,576 | R— | C] (Zenographics, Inc.) – C:\Windows\SysWow64\ZTAG32.DLL
[2010/03/17 18:09:13 | 000,086,016 | R— | C] (Zenographics, Inc.) – C:\Windows\SysWow64\ZLhp1020.dll
[2010/03/17 18:09:13 | 000,028,672 | R— | C] (Zenographics, Inc.) – C:\Windows\SysWow64\zlm.dll
[2010/03/17 18:09:10 | 000,000,000 | -H-D | C] – C:\Program Files (x86)\Zenographics
[2010/03/15 23:40:04 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Local\Adobe
[2010/03/15 22:36:42 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Config
[2010/03/15 22:34:07 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\AnswerWorks 5.0
[2010/03/15 22:34:02 | 004,199,784 | —- | C] (Amyuni Technologies
http://www.amyuni.com) – C:\Windows\SysWow64\cdintf400.dll
[2010/03/15 22:32:59 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Intuit
[2010/03/15 22:32:22 | 000,000,000 | —D | C] – C:\Program Files (x86)\Quicken
[2010/03/15 22:32:22 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Roaming\Intuit
[2010/03/15 22:31:50 | 000,000,000 | —D | C] – C:\ProgramData\Intuit
[2010/03/14 14:05:31 | 000,409,624 | —- | C] (Intel Corporation) – C:\Windows\SysNative\drivers\iaStor.sys
[2010/03/14 14:05:31 | 000,000,000 | —D | C] – C:\Intel
[2010/03/14 14:05:24 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Roaming\InstallShield
[2010/03/14 14:04:23 | 004,239,976 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\NVStWiz.exe
[2010/03/14 14:03:33 | 000,183,912 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcod168.dll
[2010/03/14 12:38:26 | 000,000,000 | —D | C] – C:\ProgramData\{657095DF-DBDB-4B17-8245-B38845C97069}
[2010/03/14 12:25:10 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Roaming\HP Support Assistant
[2010/03/14 01:21:50 | 000,000,000 | -HSD | C] – C:\Users\Andrew Brown\AppData\Roaming\.#
[2010/03/14 01:04:34 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\Documents\TurboTax
[2010/03/14 01:04:26 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\Documents\Quicken
[2010/03/14 01:04:09 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\Documents\Quaestor Stuff
[2010/03/14 01:04:03 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\Documents\Projects
[2010/03/14 01:03:58 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\Documents\Old Masters
[2010/03/14 01:02:52 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\Documents\Musicnotes
[2010/03/14 01:02:18 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\Documents\Internships
[2010/03/14 01:02:12 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\Documents\General Academic Info
[2010/03/14 01:02:06 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\Documents\Games
[2010/03/14 00:43:58 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\Documents\DC Downloads
[2010/03/14 00:41:42 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\Documents\Classes
[2010/03/13 23:47:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\GPLGS
[2010/03/13 23:47:18 | 000,000,000 | —D | C] – C:\Program Files (x86)\Acro Software
[2010/03/13 23:18:18 | 000,000,000 | —D | C] – C:\Program Files (x86)\LightScribe
[2010/03/13 23:05:56 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\Documents\LightScribe
[2010/03/13 23:00:23 | 000,000,000 | —D | C] – C:\ProgramData\LightScribe
[2010/03/13 15:18:16 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\Documents\LimeWire
[2010/03/13 15:18:12 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Roaming\Mozilla
[2010/03/13 15:17:57 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Roaming\LimeWire
[2010/03/13 15:17:04 | 000,000,000 | —D | C] – C:\Program Files (x86)\LimeWire
[2010/03/13 14:59:31 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Roaming\Apple Computer
[2010/03/13 14:59:31 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Local\Apple Computer
[2010/03/13 14:59:25 | 000,126,312 | —- | C] (GEAR Software Inc.) – C:\Windows\SysNative\GEARAspi64.dll
[2010/03/13 14:59:25 | 000,107,368 | —- | C] (GEAR Software Inc.) – C:\Windows\SysWow64\GEARAspi.dll
[2010/03/13 14:59:24 | 000,034,152 | —- | C] (GEAR Software Inc.) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys
[2010/03/13 14:59:23 | 000,000,000 | —D | C] – C:\Windows\SysNative\DRVSTORE
[2010/03/13 14:59:06 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2010/03/13 14:59:06 | 000,000,000 | —D | C] – C:\Program Files (x86)\iTunes
[2010/03/13 14:59:06 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2010/03/13 14:59:06 | 000,000,000 | —D | C] – C:\ProgramData\{0DD0EEEE-2A7C-411C-9243-1AE62F445FC3}
[2010/03/13 14:58:31 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2010/03/13 14:58:31 | 000,000,000 | —D | C] – C:\Program Files (x86)\Bonjour
[2010/03/13 14:58:10 | 000,000,000 | —D | C] – C:\Program Files (x86)\QuickTime
[2010/03/13 14:58:10 | 000,000,000 | —D | C] – C:\ProgramData\Apple Computer
[2010/03/13 14:57:59 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Local\Apple
[2010/03/13 14:57:58 | 000,000,000 | —D | C] – C:\Program Files (x86)\Apple Software Update
[2010/03/13 14:57:45 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Apple
[2010/03/13 14:57:28 | 000,000,000 | —D | C] – C:\ProgramData\Apple
[2010/03/13 14:57:28 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Apple
[2010/03/13 13:52:52 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\Tracing
[2010/03/13 13:26:17 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Roaming\WildTangent
[2010/03/13 13:15:36 | 000,000,000 | —D | C] – C:\Program Files (x86)\MSXML 4.0
[2010/03/13 13:12:55 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Local\Microsoft Help
[2010/03/13 13:02:08 | 014,629,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wmp.dll
[2010/03/13 13:02:08 | 011,406,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wmp.dll
[2010/03/13 13:02:07 | 001,975,296 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\CertEnroll.dll
[2010/03/13 13:02:07 | 001,320,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\CertEnroll.dll
[2010/03/13 13:02:06 | 012,625,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wmploc.DLL
[2010/03/13 13:02:06 | 012,625,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wmploc.DLL
[2010/03/13 13:01:16 | 000,424,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\secproc.dll
[2010/03/13 13:01:16 | 000,422,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\secproc_isv.dll
[2010/03/13 13:01:16 | 000,369,152 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\secproc.dll
[2010/03/13 13:01:16 | 000,365,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\secproc_isv.dll
[2010/03/13 13:01:16 | 000,357,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RMActivate_isv.exe
[2010/03/13 13:01:15 | 000,356,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RMActivate.exe
[2010/03/13 13:01:15 | 000,324,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RMActivate_isv.exe
[2010/03/13 13:01:15 | 000,320,512 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RMActivate.exe
[2010/03/13 13:01:15 | 000,306,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RMActivate_ssp.exe
[2010/03/13 13:01:15 | 000,305,152 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RMActivate_ssp_isv.exe
[2010/03/13 13:01:15 | 000,280,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RMActivate_ssp.exe
[2010/03/13 13:01:15 | 000,277,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RMActivate_ssp_isv.exe
[2010/03/13 13:01:15 | 000,121,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\secproc_ssp_isv.dll
[2010/03/13 13:01:15 | 000,121,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\secproc_ssp.dll
[2010/03/13 13:01:15 | 000,085,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\secproc_ssp_isv.dll
[2010/03/13 13:01:15 | 000,085,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\secproc_ssp.dll
[2010/03/13 13:01:14 | 000,960,512 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\CPFilters.dll
[2010/03/13 13:01:14 | 000,641,536 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\CPFilters.dll
[2010/03/13 13:01:14 | 000,613,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\psisdecd.dll
[2010/03/13 13:01:14 | 000,552,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msdri.dll
[2010/03/13 13:01:14 | 000,465,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\psisdecd.dll
[2010/03/13 13:01:14 | 000,288,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MSNP.ax
[2010/03/13 13:01:14 | 000,204,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MSNP.ax
[2010/03/13 13:01:13 | 000,366,080 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysNative\atmfd.dll
[2010/03/13 13:01:13 | 000,293,888 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\atmfd.dll
[2010/03/13 13:01:13 | 000,148,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\t2embed.dll
[2010/03/13 13:01:13 | 000,108,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\t2embed.dll
[2010/03/13 13:01:13 | 000,100,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\fontsub.dll
[2010/03/13 13:01:13 | 000,070,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\fontsub.dll
[2010/03/13 13:01:03 | 002,870,272 | —- | C] (Microsoft Corporation) – C:\Windows\explorer.exe
[2010/03/13 13:01:03 | 002,614,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\explorer.exe
[2010/03/13 13:01:03 | 000,389,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winlogon.exe
[2010/03/13 13:00:50 | 001,572,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\quartz.dll
[2010/03/13 13:00:50 | 001,328,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\quartz.dll
[2010/03/13 13:00:50 | 000,091,648 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\avifil32.dll
[2010/03/13 13:00:50 | 000,084,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mciavi32.dll
[2010/03/13 13:00:50 | 000,054,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iyuv_32.dll
[2010/03/13 13:00:50 | 000,038,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msvidc32.dll
[2010/03/13 13:00:50 | 000,025,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msyuv.dll
[2010/03/13 13:00:50 | 000,016,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msrle32.dll
[2010/03/13 13:00:50 | 000,014,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\tsbyuv.dll
[2010/03/13 13:00:49 | 000,243,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64.dll
[2010/03/13 13:00:49 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\setup16.exe
[2010/03/13 13:00:49 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntvdm64.dll
[2010/03/13 13:00:49 | 000,007,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\instnm.exe
[2010/03/13 13:00:49 | 000,005,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wow32.dll
[2010/03/13 13:00:49 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\user.exe
[2010/03/13 13:00:44 | 000,852,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2010/03/13 13:00:44 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2010/03/13 13:00:39 | 000,046,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msasn1.dll
[2010/03/13 01:02:48 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\Documents\Downloads
[2010/03/13 00:59:32 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Local\Google
[2010/03/13 00:59:23 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Local\Deployment
[2010/03/13 00:59:23 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Local\Apps
[2010/03/13 00:50:56 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Roaming\CyberLink
[2010/03/13 00:50:55 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Local\CyberLink
[2010/03/13 00:50:54 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Local\PowerCinema
[2010/03/12 23:50:02 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Symantec Shared
[2010/03/12 23:37:58 | 000,000,000 | —D | C] – C:\ProgramData\Recovery
[2010/03/12 19:40:01 | 000,000,000 | —D | C] – C:\ProgramData\HP
[2010/03/12 19:37:01 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Roaming\HpUpdate
[2010/03/12 19:28:56 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Roaming\Macromedia
[2010/03/12 19:28:56 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Roaming\Adobe
[2010/03/12 19:27:48 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Roaming\hpqLog
[2010/03/12 19:24:49 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Local\IsolatedStorage
[2010/03/12 19:24:16 | 000,173,104 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS
[2010/03/12 19:24:15 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Symantec Shared
[2010/03/12 19:24:15 | 000,000,000 | —D | C] – C:\Program Files\Symantec
[2010/03/12 19:22:27 | 000,000,000 | R–D | C] – C:\Users\Andrew Brown\Searches
[2010/03/12 19:22:20 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Roaming\Identities
[2010/03/12 19:22:19 | 000,000,000 | R–D | C] – C:\Users\Andrew Brown\Contacts
[2010/03/12 19:22:17 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Local\VirtualStore
[2010/03/12 19:05:55 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Roaming\Hewlett-Packard
[2010/03/12 19:04:58 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Local\Hewlett-Packard
[2010/03/12 19:04:26 | 000,000,000 | RHSD | C] – C:\Users\Andrew Brown\Documents\My Pictures
[2010/03/12 19:04:26 | 000,000,000 | -HSD | C] – C:\Users\Andrew Brown\AppData\Local\Temporary Internet Files
[2010/03/12 19:04:26 | 000,000,000 | -HSD | C] – C:\Users\Andrew Brown\Templates
[2010/03/12 19:04:26 | 000,000,000 | -HSD | C] – C:\Users\Andrew Brown\Start Menu
[2010/03/12 19:04:26 | 000,000,000 | -HSD | C] – C:\Users\Andrew Brown\SendTo
[2010/03/12 19:04:26 | 000,000,000 | -HSD | C] – C:\Users\Andrew Brown\Recent
[2010/03/12 19:04:26 | 000,000,000 | -HSD | C] – C:\Users\Andrew Brown\PrintHood
[2010/03/12 19:04:26 | 000,000,000 | -HSD | C] – C:\Users\Andrew Brown\NetHood
[2010/03/12 19:04:26 | 000,000,000 | -HSD | C] – C:\Users\Andrew Brown\Documents\My Videos
[2010/03/12 19:04:26 | 000,000,000 | -HSD | C] – C:\Users\Andrew Brown\Documents\My Music
[2010/03/12 19:04:26 | 000,000,000 | -HSD | C] – C:\Users\Andrew Brown\My Documents
[2010/03/12 19:04:26 | 000,000,000 | -HSD | C] – C:\Users\Andrew Brown\Local Settings
[2010/03/12 19:04:26 | 000,000,000 | -HSD | C] – C:\Users\Andrew Brown\AppData\Local\History
[2010/03/12 19:04:26 | 000,000,000 | -HSD | C] – C:\Users\Andrew Brown\Cookies
[2010/03/12 19:04:26 | 000,000,000 | -HSD | C] – C:\Users\Andrew Brown\Application Data
[2010/03/12 19:04:26 | 000,000,000 | -HSD | C] – C:\Users\Andrew Brown\AppData\Local\Application Data
[2010/03/12 19:04:25 | 000,000,000 | –SD | C] – C:\Users\Andrew Brown\AppData\Roaming\Microsoft
[2010/03/12 19:04:25 | 000,000,000 | R–D | C] – C:\Users\Andrew Brown\Videos
[2010/03/12 19:04:25 | 000,000,000 | R–D | C] – C:\Users\Andrew Brown\Saved Games
[2010/03/12 19:04:25 | 000,000,000 | R–D | C] – C:\Users\Andrew Brown\Pictures
[2010/03/12 19:04:25 | 000,000,000 | R–D | C] – C:\Users\Andrew Brown\Music
[2010/03/12 19:04:25 | 000,000,000 | R–D | C] – C:\Users\Andrew Brown\Links
[2010/03/12 19:04:25 | 000,000,000 | R–D | C] – C:\Users\Andrew Brown\Favorites
[2010/03/12 19:04:25 | 000,000,000 | R–D | C] – C:\Users\Andrew Brown\Downloads
[2010/03/12 19:04:25 | 000,000,000 | R–D | C] – C:\Users\Andrew Brown\Documents
[2010/03/12 19:04:25 | 000,000,000 | R–D | C] – C:\Users\Andrew Brown\Desktop
[2010/03/12 19:04:25 | 000,000,000 | -H-D | C] – C:\Users\Andrew Brown\AppData
[2010/03/12 19:04:25 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Local\Temp
[2010/03/12 19:04:25 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Local\Microsoft
[2010/03/12 19:04:25 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Roaming\Media Center Programs
[2010/03/12 19:04:25 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Local\HuluDesktop

========== Files - Modified Within 30 Days ==========

[2010/04/02 19:06:41 | 000,023,024 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/04/02 19:06:41 | 000,023,024 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/04/02 19:03:42 | 001,572,864 | -HS- | M] () – C:\Users\Andrew Brown\NTUSER.DAT
[2010/04/02 19:03:35 | 000,713,888 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010/04/02 19:03:35 | 000,615,360 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010/04/02 19:03:35 | 000,103,702 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010/04/02 19:02:26 | 000,000,905 | —- | M] () – C:\Users\Andrew Brown\Desktop\ERUNT.lnk
[2010/04/02 19:00:06 | 000,000,334 | —- | M] () – C:\Windows\tasks\AdwarePro.job
[2010/04/02 18:59:10 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/04/02 18:59:08 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/04/02 18:59:01 | 3214,045,184 | -HS- | M] () – C:\hiberfil.sys
[2010/04/02 18:58:27 | 002,236,010 | -H– | M] () – C:\Users\Andrew Brown\AppData\Local\IconCache.db
[2010/04/02 18:50:39 | 000,001,009 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/04/02 18:43:36 | 000,555,520 | —- | M] (OldTimer Tools) – C:\Users\Andrew Brown\Desktop\OTL.exe
[2010/04/02 07:12:33 | 000,000,478 | —- | M] () – C:\Windows\win.ini
[2010/04/02 07:11:20 | 001,101,086 | —- | M] () – C:\Windows\SysNative\drivers\NISx64\1105000.07F\Cat.DB
[2010/04/02 07:11:03 | 000,000,936 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4258229573-526587920-623500243-1001UA.job
[2010/04/02 07:11:03 | 000,000,884 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4258229573-526587920-623500243-1001Core.job
[2010/04/02 00:57:04 | 000,002,093 | —- | M] () – C:\Users\Andrew Brown\Desktop\HijackThis.lnk
[2010/03/31 22:47:35 | 000,000,360 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForAndrew Brown.job
[2010/03/31 22:47:30 | 000,435,184 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2010/03/29 23:56:53 | 000,002,611 | —- | M] () – C:\Users\Andrew Brown\Desktop\Microsoft Office Publisher 2007.lnk
[2010/03/29 23:56:47 | 000,002,645 | —- | M] () – C:\Users\Andrew Brown\Desktop\Microsoft Office PowerPoint 2007.lnk
[2010/03/29 23:56:40 | 000,002,693 | —- | M] () – C:\Users\Andrew Brown\Desktop\Microsoft Office Outlook 2007.lnk
[2010/03/29 21:54:31 | 000,115,920 | —- | M] () – C:\Users\Andrew Brown\AppData\Local\GDIPFONTCACHEV1.DAT
[2010/03/29 15:24:58 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010/03/29 15:24:46 | 000,024,664 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2010/03/18 07:03:44 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2010/03/15 22:33:45 | 000,000,126 | —- | M] () – C:\Windows\QUICKEN.INI
[2010/03/15 20:28:16 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2010/03/14 14:03:19 | 000,183,912 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvcod168.dll
[2010/03/14 14:01:04 | 001,047,740 | —- | M] () – C:\Windows\SysNative\oem20.inf
[2010/03/14 14:00:18 | 003,896,832 | —- | M] (Broadcom Corporation) – C:\Windows\SysNative\bcmihvsrv64.dll
[2010/03/14 14:00:18 | 003,561,472 | —- | M] (Broadcom Corporation) – C:\Windows\SysNative\bcmihvui64.dll
[2010/03/14 14:00:18 | 003,053,560 | —- | M] (Broadcom Corporation) – C:\Windows\SysNative\drivers\BCMWL664.SYS
[2010/03/14 14:00:18 | 000,095,472 | —- | M] (Broadcom Corporation) – C:\Windows\SysNative\bcmwlcoi.dll
[2010/03/14 14:00:18 | 000,006,656 | —- | M] () – C:\Windows\SysNative\bcmwlrc.dll
[2010/03/14 12:39:26 | 000,001,097 | —- | M] () – C:\Users\Public\Desktop\HP Support Assistant.lnk
[2010/03/13 13:19:54 | 000,524,288 | -HS- | M] () – C:\Users\Andrew Brown\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
[2010/03/13 13:19:54 | 000,524,288 | -HS- | M] () – C:\Users\Andrew Brown\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
[2010/03/13 13:19:54 | 000,065,536 | -HS- | M] () – C:\Users\Andrew Brown\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
[2010/03/13 03:00:39 | 000,039,219 | —- | M] () – C:\Windows\SysWow64\license.rtf
[2010/03/13 03:00:39 | 000,039,219 | —- | M] () – C:\Windows\SysNative\license.rtf
[2010/03/12 19:40:34 | 000,023,117 | —- | M] () – C:\Windows\hpqins15.dat
[2010/03/12 19:24:15 | 000,173,104 | —- | M] (Symantec Corporation) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS
[2010/03/12 19:24:15 | 000,007,440 | —- | M] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.CAT
[2010/03/12 19:24:15 | 000,000,854 | —- | M] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.INF
[2010/03/12 19:04:41 | 000,000,000 | RHS- | M] () – C:\Windows\SysWow64\drivers\103C_HP_cNB_Pavilion dv6 Notebook PC_Y5335KV_0U_QCNF0065FQP_E587925-003_4A_I3659_SHP_V32.24_F.16_T100122_WU3-0_L409_M4087_J500_7Intel_86E5_91.60_#100210_N14E44357_(WA783UA#ABA)_XMOBILE_CN10
_Z.MRK
[2010/03/12 19:04:41 | 000,000,000 | RHS- | M] () – C:\Windows\SysNative\drivers\103C_HP_cNB_Pavilion dv6 Notebook PC_Y5335KV_0U_QCNF0065FQP_E587925-003_4A_I3659_SHP_V32.24_F.16_T100122_WU3-0_L409_M4087_J500_7Intel_86E5_91.60_#100210_N14E44357_(WA783UA#ABA)_XMOBILE_CN10
_Z.MRK
[2010/03/12 19:04:26 | 000,000,020 | -HS- | M] () – C:\Users\Andrew Brown\ntuser.ini
[2010/03/09 04:28:28 | 000,153,376 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaws.exe
[2010/03/09 04:28:27 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaw.exe
[2010/03/09 04:28:26 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\java.exe
[2010/03/09 04:28:20 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\deploytk.dll

========== Files Created - No Company Name ==========

[2010/04/02 19:02:26 | 000,000,905 | —- | C] () – C:\Users\Andrew Brown\Desktop\ERUNT.lnk
[2010/04/02 18:50:39 | 000,001,009 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/04/02 00:57:04 | 000,002,093 | —- | C] () – C:\Users\Andrew Brown\Desktop\HijackThis.lnk
[2010/04/01 21:36:56 | 000,000,334 | —- | C] () – C:\Windows\tasks\AdwarePro.job
[2010/03/29 23:56:53 | 000,002,611 | —- | C] () – C:\Users\Andrew Brown\Desktop\Microsoft Office Publisher 2007.lnk
[2010/03/29 23:56:47 | 000,002,645 | —- | C] () – C:\Users\Andrew Brown\Desktop\Microsoft Office PowerPoint 2007.lnk
[2010/03/29 23:56:40 | 000,002,693 | —- | C] () – C:\Users\Andrew Brown\Desktop\Microsoft Office Outlook 2007.lnk
[2010/03/18 21:39:25 | 000,574,100 | —- | C] () – C:\Windows\SysNative\hp1022n.img
[2010/03/18 21:39:25 | 000,567,296 | —- | C] () – C:\Windows\SysNative\ZSHP1020.EXE
[2010/03/18 21:39:25 | 000,206,768 | —- | C] () – C:\Windows\SysNative\hp1022.img
[2010/03/18 21:39:25 | 000,128,380 | —- | C] () – C:\Windows\SysNative\hp1020.img
[2010/03/18 21:39:25 | 000,010,632 | —- | C] () – C:\Windows\SysNative\ZSHP1020.CHM
[2010/03/18 07:03:44 | 000,000,000 | -H– | C] () – C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2010/03/17 18:09:13 | 000,574,100 | R— | C] () – C:\Windows\SysWow64\hp1022n.img
[2010/03/17 18:09:13 | 000,206,768 | R— | C] () – C:\Windows\SysWow64\hp1022.img
[2010/03/17 18:09:13 | 000,128,612 | R— | C] () – C:\Windows\SysWow64\hp1020.img
[2010/03/17 18:09:12 | 000,397,312 | R— | C] () – C:\Windows\SysWow64\zshp1020.exe
[2010/03/17 18:09:12 | 000,106,496 | R— | C] () – C:\Windows\SysWow64\vshp1020.dll
[2010/03/17 18:09:12 | 000,007,294 | R— | C] () – C:\Windows\SysWow64\ZSHP1020.HLP
[2010/03/15 22:32:15 | 000,000,126 | —- | C] () – C:\Windows\QUICKEN.INI
[2010/03/15 20:28:16 | 000,000,000 | -H– | C] () – C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2010/03/14 14:01:15 | 001,047,740 | —- | C] () – C:\Windows\SysNative\oem20.inf
[2010/03/14 12:39:26 | 000,001,097 | —- | C] () – C:\Users\Public\Desktop\HP Support Assistant.lnk
[2010/03/13 23:47:18 | 000,085,504 | —- | C] () – C:\Windows\SysNative\cpwmon64.dll
[2010/03/13 18:12:50 | 000,000,360 | —- | C] () – C:\Windows\tasks\HPCeeScheduleForAndrew Brown.job
[2010/03/13 00:59:34 | 000,000,936 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4258229573-526587920-623500243-1001UA.job
[2010/03/13 00:59:34 | 000,000,884 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4258229573-526587920-623500243-1001Core.job
[2010/03/12 19:40:02 | 000,023,117 | —- | C] () – C:\Windows\hpqins15.dat
[2010/03/12 19:40:02 | 000,000,366 | —- | C] () – C:\ProgramData\hpzinstall.log
[2010/03/12 19:24:16 | 000,007,440 | —- | C] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.CAT
[2010/03/12 19:24:16 | 000,000,854 | —- | C] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.INF
[2010/03/12 19:22:49 | 000,000,000 | —- | C] () – C:\Users\Andrew Brown\AppData\Local\QSwitch.txt
[2010/03/12 19:22:49 | 000,000,000 | —- | C] () – C:\Users\Andrew Brown\AppData\Local\DSwitch.txt
[2010/03/12 19:22:49 | 000,000,000 | —- | C] () – C:\Users\Andrew Brown\AppData\Local\AtStart.txt
[2010/03/12 19:22:47 | 000,000,186 | —- | C] () – C:\ProgramData\HPWALog.txt
[2010/03/12 19:04:41 | 000,000,000 | RHS- | C] () – C:\Windows\SysWow64\drivers\103C_HP_cNB_Pavilion dv6 Notebook PC_Y5335KV_0U_QCNF0065FQP_E587925-003_4A_I3659_SHP_V32.24_F.16_T100122_WU3-0_L409_M4087_J500_7Intel_86E5_91.60_#100210_N14E44357_(WA783UA#ABA)_XMOBILE_CN10
_Z.MRK
[2010/03/12 19:04:41 | 000,000,000 | RHS- | C] () – C:\Windows\SysNative\drivers\103C_HP_cNB_Pavilion dv6 Notebook PC_Y5335KV_0U_QCNF0065FQP_E587925-003_4A_I3659_SHP_V32.24_F.16_T100122_WU3-0_L409_M4087_J500_7Intel_86E5_91.60_#100210_N14E44357_(WA783UA#ABA)_XMOBILE_CN10
_Z.MRK
[2010/03/12 19:04:26 | 000,524,288 | -HS- | C] () – C:\Users\Andrew Brown\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
[2010/03/12 19:04:26 | 000,524,288 | -HS- | C] () – C:\Users\Andrew Brown\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
[2010/03/12 19:04:26 | 000,065,536 | -HS- | C] () – C:\Users\Andrew Brown\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
[2010/03/12 19:04:26 | 000,000,020 | -HS- | C] () – C:\Users\Andrew Brown\ntuser.ini
[2010/03/12 19:04:25 | 001,572,864 | -HS- | C] () – C:\Users\Andrew Brown\NTUSER.DAT
[2010/02/10 05:45:11 | 000,000,105 | —- | C] () – C:\ProgramData\{d36dd326-7280-11d8-97c8-000129760cbe}.log
[2010/02/10 05:45:05 | 000,000,032 | —- | C] () – C:\ProgramData\{051B9612-4D82-42AC-8C63-CD2DCEDC1CB3}.log
[2010/02/10 05:44:54 | 000,000,032 | —- | C] () – C:\ProgramData\{9867824A-C86D-4A83-8F3C-E7A86BE0AFD3}.log
[2010/02/10 05:44:35 | 000,000,032 | —- | C] () – C:\ProgramData\{23F3DA62-2D9E-4A69-B8D5-BE8E9E148092}.log
[2010/02/10 05:43:59 | 000,000,032 | —- | C] () – C:\ProgramData\{4FC670EB-5F02-4B07-90DB-022B86BFEFD0}.log
[2010/02/10 05:18:42 | 000,000,283 | —- | C] () – C:\Windows\SysWow64\RStoneLog2.ini
[2010/02/10 05:18:42 | 000,000,224 | —- | C] () – C:\Windows\SysWow64\RStoneLog.ini
[2010/01/09 21:05:19 | 000,000,109 | —- | C] () – C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log
[2010/01/09 21:02:26 | 000,000,110 | —- | C] () – C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log
[2010/01/09 21:01:34 | 000,000,105 | —- | C] () – C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
[2010/01/09 21:01:04 | 000,000,107 | —- | C] () – C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log
[2009/09/29 19:25:16 | 000,013,312 | —- | C] () – C:\Windows\LPRES.DLL
[2009/07/13 19:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 17:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
< End of report >



———————-

OTL Extra

OTL Extras logfile created on: 4/2/2010 7:05:04 PM - Run 1
OTL by OldTimer - Version 3.1.37.3 Folder = C:\Users\Andrew Brown\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 68.00% Memory free
8.00 Gb Paging File | 6.00 Gb Available in Paging File | 81.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 452.25 Gb Total Space | 329.51 Gb Free Space | 72.86% Space Free | Partition Type: NTFS
Drive D: | 13.21 Gb Total Space | 2.20 Gb Free Space | 16.63% Space Free | Partition Type: NTFS
Drive E: | 99.02 Mb Total Space | 96.46 Mb Free Space | 97.41% Space Free | Partition Type: FAT32
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: ANDREWBROWN-PC
Current User Name: Andrew Brown
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
htmlfile – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – C:\PROGRA~2\MICROS~4\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – C:\PROGRA~2\MICROS~4\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{26A24AE4-039D-4CA4-87B4-2F86416015FF}" = Java™ 6 Update 15 (64-bit)
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{64A3A4F4-B792-11D6-A78A-00B0D0160150}" = Java™ SE Development Kit 6 Update 15 (64-bit)
"{84BC87D4-0480-4E10-B15D-1E7886D55180}" = iTunes
"{85A42FF0-F0D0-44A3-B226-C124D6E8B1D5}" = HP 3D DriveGuard
"{88E60521-1E4E-4785-B9F1-1798A4BD0C30}" = HP MediaSmart SmartMenu
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9EFC40E3-5F31-4F75-8445-286273F74D8E}" = Apple Mobile Device Support
"{DAE239CE-EB9D-4EB3-B0D4-528D6BAA48FD}" = Bonjour
"Broadcom 802.11 Wireless LAN Adapter" = Broadcom 802.11 Wireless LAN Adapter
"CutePDF Writer Installation" = CutePDF Writer 2.8
"FFE7D41DF3C645075BB149E21988B63996C34187" = ENE CIR Receiver Driver
"HP Smart Web Printing" = HP Smart Web Printing 4.60
"NVIDIA Drivers" = NVIDIA Drivers
"SynTPDeinstKey" = Synaptics Pointing Device Driver

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = HP MediaSmart Webcam
"{0345CF70-FA00-4F4E-A218-0FA494F465A4}" = LightScribe Template Designs - Business Pack 1
"{07FA4960-B038-49EB-891B-9F95930AA544}" = HP Customer Experience Enhancements
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{1747DF05-6890-440B-B094-2146F5DC50E0}" = HP MediaSmart SlingPlayer
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{17B4760F-334B-475D-829F-1A3E94A6A4E6}" = HP Setup
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{26604C7E-A313-4D12-867F-7C6E7820BE4C}" = JMicron Flash Media Controller Driver
"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java™ 6 Update 19
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{3023EBDA-BF1B-4831-B347-E5018555F26E}" = Movie Theme Pack for HP MediaSmart Video
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons
"{35021DFB-F9CA-402A-89A2-47F91E506465}" = HP MediaSmart/TouchSmart Netflix
"{3877C901-7B90-4727-A639-B6ED2DD59D43}" = ESU for Microsoft Windows 7
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{40FB8D7C-6FF8-4AF2-BC8B-0B1DB32AF04B}" = HP Advisor
"{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}" = Recovery Manager
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{47D7C9B8-BD44-4D2E-9040-E946477B2F9A}" = Microsoft Live Search Toolbar
"{495A8A3C-8FD0-4C46-9979-95C26181A1AB}" = HP Support Assistant
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{54CC7901-804D-4155-B353-21F0CC9112AB}" = HP Wireless Assistant
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{67626E09-5366-4480-8F1E-93FADF50CA15}" = HP MediaSmart Live TV
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{82A213BD-B6AA-4281-A2D3-59D51893CC56}" = HP MediaSmart Software Notebook Demo
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver For Windows Vista and Later
"{88A4002B-BDBA-49A2-927C-D81E8DF32B1B}" = LightScribe Applications
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8FF6F5CA-4E30-4E3B-B951-204CAAA2716A}" = SmartWebPrinting
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{E64BA721-2310-4B55-BE5A-2925F9706192}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002A-0409-1000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0116-0409-1000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{91120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{91120000-0030-0000-0000-0000000FF1CE}_ENTERPRISER_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{AC76BA86-7AD7-FFFF-7B44-A91000000001}" = Adobe Reader 9.1 MUI
"{AF36CE1D-FD2C-4BA0-93FA-1196785DD610}" = Adobe Flash Player 10 Plugin
"{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}" = HP MediaSmart Music/Photo/Video
"{B51605BF-6326-4553-AE96-6D7F1813D5F5}" = HP User Guides 0154
"{C57BCDE1-7CB9-467D-B3BA-7E119916CDC1}" = Norton Online Backup
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CC8E94A2-55C7-4460-953C-2A790180578C}" = LightScribe System Software
"{CCF6F57B-F6B4-4508-BF45-63AAC9DE416A}" = Quicken 2010
"{D46D081B-F60E-467E-A7C4-117B70D76731}" = HP Update
"{D6C75F0B-3BC1-4FC9-B8C5-3F7E8ED059CA}" = Windows Live Photo Gallery
"{D8DFA46A-39F7-4368-810D-18AFCFDDAEAF}" = Adobe Shockwave Player
"{DBCC73BA-C69A-4BF5-B4BF-F07501EE7039}" = AnswerWorks 5.0 English Runtime
"{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"{DF802C05-4660-418c-970C-B988ADB1D316}" = Microsoft Live Search Toolbar
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{E553760D-D7F7-48BF-BD8B-C7E23BA04CB5}" = HP MediaSmart Internet TV
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F1D7AC58-554A-4A58-B784-B61558B1449A}" = QLBCASL
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{FB4BB287-37F9-4E27-9C4D-2D3882E08EFF}" = DVD Menu Pack for HP MediaSmart Video
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"ENTERPRISER" = Microsoft Office Enterprise 2007
"ERUNT_is1" = ERUNT 1.1j
"HijackThis" = HijackThis 2.0.2
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"HP-LaserJet 1020 series" = LaserJet 1020 series
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = HP MediaSmart Webcam
"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
"InstallShield_{3023EBDA-BF1B-4831-B347-E5018555F26E}" = Movie Theme Pack for HP MediaSmart Video
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"InstallShield_{67626E09-5366-4480-8F1E-93FADF50CA15}" = HP MediaSmart Live TV
"InstallShield_{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}" = HP MediaSmart Music/Photo/Video
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"InstallShield_{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"InstallShield_{E553760D-D7F7-48BF-BD8B-C7E23BA04CB5}" = HP MediaSmart Internet TV
"InstallShield_{FB4BB287-37F9-4E27-9C4D-2D3882E08EFF}" = DVD Menu Pack for HP MediaSmart Video
"LimeWire" = LimeWire 5.5.7
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"NIS" = Norton Internet Security
"qwipdrrzgxgdcwghf" = Performance Solution Hotrevenue
"WildTangent hp Master Uninstall" = HP Games
"WinLiveSuite_Wave3" = Windows Live Essentials

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-4258229573-526587920-623500243-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
"HuluDesktop" = Hulu Desktop

========== Last 10 Event Log Errors ==========

[ Hewlett-Packard Events ]
Error - 3/22/2010 7:03:13 PM | Computer Name = AndrewBrown-PC | Source = Hewlett-Packard | ID = 0
Description = en-US Could not find file 'C:\Program Files (x86)\Hewlett-Packard\HP
Support Framework\Logs\SystemInfoAA.xml'. mscorlib at System.IO.__Error.WinIOError(Int32
errorCode, String maybeFullPath) at System.IO.FileStream.Init(String path, FileMode
mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32
bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath,
Boolean bFromProxy) at System.IO.FileStream..ctor(String path, FileMode mode,
FileAccess access, FileShare share, Int32 bufferSize, FileOptions options, String
msgPath, Boolean bFromProxy) at System.IO.FileStream..ctor(String path, FileMode
mode, FileAccess access, FileShare share, Int32 bufferSize, FileOptions options)

at System.IO.StreamReader..ctor(String path, Encoding encoding, Boolean detectEncodingFromByteOrderMarks,
Int32 bufferSize) at System.IO.StreamReader..ctor(String path, Encoding encoding)

at System.IO.File.ReadAllText(String path, Encoding encoding) at n.a(Object
A_0, EventArgs A_1)

Error - 3/22/2010 7:03:14 PM | Computer Name = AndrewBrown-PC | Source = Hewlett-Packard | ID = 0
Description = en-US Could not find file 'C:\Program Files (x86)\Hewlett-Packard\HP
Support Framework\Logs\SystemInfoAA.xml'. mscorlib at System.IO.__Error.WinIOError(Int32
errorCode, String maybeFullPath) at System.IO.FileStream.Init(String path, FileMode
mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32
bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath,
Boolean bFromProxy) at System.IO.FileStream..ctor(String path, FileMode mode,
FileAccess access, FileShare share, Int32 bufferSize, FileOptions options, String
msgPath, Boolean bFromProxy) at System.IO.FileStream..ctor(String path, FileMode
mode, FileAccess access, FileShare share, Int32 bufferSize, FileOptions options)

at System.IO.StreamReader..ctor(String path, Encoding encoding, Boolean detectEncodingFromByteOrderMarks,
Int32 bufferSize) at System.IO.StreamReader..ctor(String path, Encoding encoding)

at System.IO.File.ReadAllText(String path, Encoding encoding) at n.a(Object
A_0, EventArgs A_1)

Error - 3/29/2010 11:57:21 PM | Computer Name = AndrewBrown-PC | Source = Hewlett-Packard | ID = 0
Description = en-US Could not find file 'C:\Program Files (x86)\Hewlett-Packard\HP
Support Framework\Logs\SystemInfoAA.xml'. mscorlib at System.IO.__Error.WinIOError(Int32
errorCode, String maybeFullPath) at System.IO.FileStream.Init(String path, FileMode
mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32
bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath,
Boolean bFromProxy) at System.IO.FileStream..ctor(String path, FileMode mode,
FileAccess access, FileShare share, Int32 bufferSize, FileOptions options, String
msgPath, Boolean bFromProxy) at System.IO.FileStream..ctor(String path, FileMode
mode, FileAccess access, FileShare share, Int32 bufferSize, FileOptions options)

at System.IO.StreamReader..ctor(String path, Encoding encoding, Boolean detectEncodingFromByteOrderMarks,
Int32 bufferSize) at System.IO.StreamReader..ctor(String path, Encoding encoding)

at System.IO.File.ReadAllText(String path, Encoding encoding) at n.a(Object
A_0, EventArgs A_1)

[ System Events ]
Error - 3/13/2010 12:18:25 AM | Computer Name = AndrewBrown-PC | Source = cdrom | ID = 262155
Description = The driver detected a controller error on \Device\CdRom0.

Error - 3/13/2010 12:18:34 AM | Computer Name = AndrewBrown-PC | Source = cdrom | ID = 262155
Description = The driver detected a controller error on \Device\CdRom0.

Error - 3/13/2010 12:18:42 AM | Computer Name = AndrewBrown-PC | Source = cdrom | ID = 262155
Description = The driver detected a controller error on \Device\CdRom0.

Error - 3/13/2010 12:18:51 AM | Computer Name = AndrewBrown-PC | Source = cdrom | ID = 262155
Description = The driver detected a controller error on \Device\CdRom0.

Error - 3/13/2010 12:18:59 AM | Computer Name = AndrewBrown-PC | Source = cdrom | ID = 262155
Description = The driver detected a controller error on \Device\CdRom0.

Error - 3/18/2010 7:03:44 AM | Computer Name = AndrewBrown-PC | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk1\DR1.

Error - 3/18/2010 7:03:44 AM | Computer Name = AndrewBrown-PC | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk1\DR1.

Error - 3/18/2010 7:03:45 AM | Computer Name = AndrewBrown-PC | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk1\DR1.

Error - 3/18/2010 7:03:46 AM | Computer Name = AndrewBrown-PC | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk1\DR1.

Error - 3/18/2010 9:57:34 PM | Computer Name = AndrewBrown-PC | Source = bowser | ID = 8003
Description =


< End of report >
greetings

I have done as you recommended in your post and have not heard any advertisements yet

that is good

TFC(Temp File Cleaner):

  • Please download TFC to your desktop,
  • Save any unsaved work. TFC will close all open application windows.
  • Double-click TFC.exe to run the program.
  • If prompted, click "Yes" to reboot.

Note: Save your work. TFC will automatically close any open programs, let it run uninterrupted. It shouldn't take longer take a couple of minutes, and may only take a few seconds. Only if needed will you be prompted to reboot.

:Kaspersky scan:

  • Important
    Right click on your favourite web browser (Internet Explorer, Firefox, etc) and select Run As Administrator to run it.

    Go to Kaspersky website and perform an online antivirus scan.

    • Read through the requirements and privacy statement and click on Accept button.
    • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
    • When the downloads have finished, click on Settings.
    • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button: Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.

"information and logs"

  • In your next post I need the following

  • log from kaspersky
  • let me know of any problems you may have had
  • How is the computer doing now?

Gringo
Gringo, Everything seems to be working fine. Thanks a bunch for your help. Let me know if there is anything more I should do. The kaspersky scan did not show any problems which I assume is good. Also, let me know what setup is best to protect myself in the future (in terms of software). Thanks. ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Saturday, April 3, 2010 Operating system: Microsoft (build 7600) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Saturday, April 03, 2010 13:40:23 Records in database: 3913863 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: C:\ D:\ E:\ F:\ Scan statistics: Objects scanned: 184511 Threats found: 0 Infected objects found: 0 Suspicious objects found: 0 Scan duration: 03:09:16 No threats found. Scanned area is clean. Selected area has been scanned.
This is my general post for when your logs show no more signs of malware ;)- Please let me know if you still are having problems with your computer and what these problems are.

The following procedure will implement some cleanup procedures. It will also reset your System Restore by flushing out previous restore points and create a new restore point.

:remove tools:
  • Let's clear out the programmes we've been using to clean up your computer, they are not suitable for general malware removal and could cause damage if used inappropriately.


    Please download OTCleanIt and save it to desktop. This tool will remove all the tools we used to clean your pc.
  • Double-click OTCleanIt.exe.
  • Click the CleanUp! button.
  • Select Yes when the "Begin cleanup Process?" prompt appears.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes, if not delete it by yourself.
Note: If you receive a warning from your firewall or other security programs regarding OTCleanIt attempting to contact the internet, please allow it to do so.

:Set correct settings for files:
  • Click Start > My Computer > Tools menu (at top of page) > Folder Options > View tab.
  • Under "Hidden files and folders" if necessary select Do not show hidden files and folders.
  • If unchecked please check Hide protected operating system files (Recommended)
  • If necessary check "Display content of system folders"
  • If necessary Uncheck Hide file extensions for known file types.
  • Click OK

:clear system restore points:
  • This is a good time to clear your existing system restore points and establish a new clean restore point:
  • Go to Start > All Programs > Accessories > System Tools > System Restore
  • Select Create a restore point, and Ok it.
  • Next, go to Start > Run and type in cleanmgr
  • choose your root drive (normally C:)
  • after it calculates how much space you will save it will open up a new window
  • Select the More options tab at the top of the window
  • Choose the option to clean up system restore and OK it.
  • go back to the disk clean up tab
  • put a checkmark in all - except compress old files (leave this unchecked)
  • click Ok then click yes
This will remove all restore points except the new one you just created and clean unneeded files

:Make your Internet Explorer more secure:

please visit this page that gives instructions to do this
http://surfthenetsafely.com/ieseczone8.htm

:Turn On Automatic Updates:

Turn On Automatic Updates
1. Click Start, click Run, type sysdm.cpl, and then press ENTER.
2. Click the Automatic Updates tab, and then click to select one of the following options. We recommend that you select the Automatic (recommended) Automatically download recommended updates for my computer and install them

If you click this setting, click to select the day and time for scheduled updates to occur. You can schedule Automatic Updates for any time of day. Remember, your computer must be on at the scheduled time for updates to be installed. After you set this option, Windows recognizes when you are online and uses your Internet connection to find updates on the Windows Update Web site or on the Microsoft Update Web site that apply to your computer. Updates are downloaded automatically in the background, and you are not notified or interrupted during this process. An icon appears in the notification area of your taskbar when the updates are being downloaded. You can point to the icon to view the download status. To pause or to resume the download, right-click the icon, and then click Pause or Resume. When the download is completed, another message appears in the notification area so that you can review the updates that are scheduled for installation. If you choose not to install at that time, Windows starts the installation on your set schedule.

or visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

:antispyware programs:
  • you have a couple of good antispyware programs on this computer but you still can try some of these others to see if you like them also, They work well together and is low on resources

    I would reccomend the download and installation of some or all of the following programs (all free), and the updating of them regularly:
  • WinPatrol As a robust security monitor, WinPatrol will alert you to hijackings, malware attacks and critical changes made to your computer without your permission. WinPatrol takes snapshot of your critical system resources and alerts you to any changes that may occur without your knowledge.
  • Malwarebytes' Anti-Malware - Malwarebytes' Anti-Malware is a new and powerful anti-malware tool. It is
    totally free but for real-time protection you will have to pay a small one-time fee.
  • Spyware Blaster - By altering your registry, this program stops harmful sites from installing things like ActiveX Controls on your machines.

please read this great article by miekiemoes How to prevent Malware:
and
this great article by Tony Klein So How Did I Get Infected In First Place

Now you have followed my advice - it's time to lodge a complaint against what you have suffered………

Malware Complaints
If you were infected …. Stand Up and be Counted.

I'd be grateful if you could reply to this post so that I know you have read it and, if you've no other questions, the thread can then be closed.

The help you receive here is free, but if you would like to help continue my fight against Malware then:
[external image: Posted Image]

Gringo
Gringo, Thanks for all of your help. Things appear to be working fine now. I am going to look into the software you recommended to protect my computer in the future. Andrew

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI