This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Baseline

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

This is a copy of my updated hijack log. My computer is very slow and often hangs up. I need help. Your help is appreciated.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:36:23 AM, on 5/19/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Carbonite\Carbonite Backup\carboniteservice.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\iolo\common\lib\ioloServiceManager.exe
C:\Program Files\iolo\System Mechanic Professional\IoloSGCtrl.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Authentium\AntiVirus5\vsedsps.exe
C:\Program Files\Common Files\Authentium\AntiVirus5\vseamps.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\iolo\System Mechanic Professional\System Shield\ioloSSTray.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\hphmon06.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\WINDOWS\ALCMTR.EXE
C:\Program Files\iolo\System Mechanic Professional\SystemGuardAlerter.exe
C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\iolo\Personal Firewall\ioloFW.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
C:\WINDOWS\system32\msdtc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\vssvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.nascar.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [SystemGuardAlerter] "C:\Program Files\iolo\System Mechanic Professional\SystemGuardAlerter.exe"
O4 - HKLM\..\Run: [Carbonite Backup] C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [iolo Personal Firewall] "C:\Program Files\iolo\Personal Firewall\ioloFW.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [Octoshape Streaming Services] "C:\Documents and Settings\HP_Administrator\Application Data\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe" -inv:bootrun
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\iavlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\iavlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\iolo\common\firewall\ifw_xfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\iolo\common\firewall\ifw_xfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\iolo\common\firewall\ifw_xfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\iolo\common\firewall\ifw_xfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\iolo\common\firewall\ifw_xfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\iavlsp.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1271297002906
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadblocker.com/activex/sabspx.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: CarboniteService - Carbonite, Inc. (www.carbonite.com) - C:\Program Files\Carbonite\Carbonite Backup\carboniteservice.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iolo FileInfoList Service (ioloFileInfoList) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe
O23 - Service: iolo System Service (ioloSystemService) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe
O23 - Service: iolo System Guard (IOLO_SRV) - Unknown owner - C:\Program Files\iolo\System Mechanic Professional\IoloSGCtrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: vseamps - Authentium, Inc - C:\Program Files\Common Files\Authentium\AntiVirus5\vseamps.exe
O23 - Service: vsedsps - Authentium, Inc - C:\Program Files\Common Files\Authentium\AntiVirus5\vsedsps.exe
O23 - Service: vseqrts - Authentium, Inc - C:\Program Files\Common Files\Authentium\AntiVirus5\vseqrts.exe

–
End of file - 11273 bytes
Hello, ITLBOK
Welcome to the WhatTheTech Forums. My name is Thomas (Tom is fine), and I will be helping you fixing your problems.



Please take note of some guidelines for this fix:
  • Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
  • If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
  • Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
  • Do not start a new topic. The logs that you post should be pasted directly into the reply. Only attach them if requested or if they do not fit into the post.
  • Please set your system to show all files.
    Click Start, open My Computer, select the Tools menu and click Folder Options.
    Select the View Tab. Under the Hidden files and folders heading, select Show hidden files and folders.
    Uncheck: Hide file extensions for known file types
    Uncheck the Hide protected operating system files (recommended) option.
    Click Yes to confirm.





  • Please download OTL from one of the following mirrors:
    • This is THE Mirror
  • Save it to your desktop.
  • Double click on the [external image: Posted Image] icon on your desktop.
  • Under the Custom Scan box paste this in
    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    /md5stop
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
  • Push the Quick Scan button.
  • Two reports will open, copy and paste them in a reply here:
    • OTL.txt <– Will be opened
    • Extra.txt <– Will be minimized




Download GMER from Here. Note the file's name and save it to your root folder, such as C:\.
  • Disconnect from the Internet and close all running programs.
  • Temporarily disable any real-time active protection so your security program drivers will not conflict with this file.
  • Click on this link to see a list of programs that should be disabled.
  • Double-click on the downloaded file to start the program. (If running Vista, right click on it and select "Run as an Administrator")
  • Allow the driver to load if asked.
  • You may be prompted to scan immediately if it detects rootkit activity.
  • If you are prompted to scan your system click "No", save the log and post back the results.
  • If not prompted, click the "Rootkit/Malware" tab.
  • On the right-side, all items to be scanned should be checked by default except for "Show All". Leave that box unchecked.
  • Select all drives that are connected to your system to be scanned.
  • Click the Scan button to begin. (Please be patient as it can take some time to complete)
  • When the scan is finished, click Save to save the scan results to your Desktop.
  • Save the file as Results.log and copy/paste the contents in your next reply.
  • Exit the program and re-enable all active protection when done.
Hi Tom,
Thank you very much for taking your time to help me. I was having trouble with all sorts of items, so I did a complete hard drive destructive reformat and installed everything again, including all data, programs, and etc. The first time aI ran my registery cleaner (System Mechanic Professional) it said that I had 339 registery errors. I had it fix them. All was well for a while, but then continuing to add programs and etc. things started to change. Hang-ups, very slow operation, and etc. I was just about to try it again, then I found Hijackthis and here I am. I hope that I am doing this right. Let me know if I am doing this incorrectly.
Hopefully you'll be able to make something out of this because it looks confusing to me. I am very much appreciated of your help.
Sincerely,
Richard








OTL logfile created on: 5/20/2010 8:59:30 AM - Run 1
OTL by OldTimer - Version 3.2.5.0 Folder = C:\Documents and Settings\HP_Administrator\My Documents\My Downloads
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 66.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 82.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 179.33 Gb Total Space | 15.13 Gb Free Space | 8.44% Space Free | Partition Type: NTFS
Drive D: | 6.96 Gb Total Space | 1.07 Gb Free Space | 15.43% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive L: | 279.45 Gb Total Space | 42.64 Gb Free Space | 15.26% Space Free | Partition Type: NTFS

Computer Name: YOUR-55E5F9E3D2
Current User Name: HP_Administrator
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan

========== Processes (SafeList) ==========

PRC - [2010/05/20 08:54:07 | 000,571,904 | —- | M] (OldTimer Tools) – C:\Documents and Settings\HP_Administrator\My Documents\My Downloads\OTL.exe
PRC - [2010/05/08 07:00:11 | 002,017,280 | —- | M] (SUPERAntiSpyware.com) – C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
PRC - [2010/04/23 21:42:42 | 000,073,728 | —- | M] (Realtek Semiconductor Corp.) – C:\WINDOWS\ALCFDRTM.EXE
PRC - [2010/04/22 18:31:12 | 000,904,880 | —- | M] () – C:\Program Files\iolo\System Mechanic Professional\System Shield\ioloSSTray.exe
PRC - [2010/04/21 14:54:24 | 000,356,264 | —- | M] () – C:\Program Files\iolo\System Mechanic Professional\IoloSGCtrl.exe
PRC - [2010/04/21 14:54:18 | 000,520,616 | —- | M] () – C:\Program Files\iolo\System Mechanic Professional\SystemGuardAlerter.exe
PRC - [2010/04/21 14:34:14 | 000,704,432 | —- | M] () – C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe
PRC - [2010/04/12 22:05:27 | 000,039,408 | —- | M] (Google Inc.) – C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
PRC - [2010/03/18 14:32:10 | 001,329,568 | —- | M] () – C:\Program Files\iolo\Personal Firewall\ioloFW.exe
PRC - [2010/01/19 18:46:54 | 000,117,288 | R— | M] (Authentium, Inc) – C:\Program Files\Common Files\Authentium\AntiVirus5\vsedsps.exe
PRC - [2010/01/19 18:46:48 | 000,121,384 | R— | M] (Authentium, Inc) – C:\Program Files\Common Files\Authentium\AntiVirus5\vseamps.exe
PRC - [2009/12/03 16:52:32 | 001,980,560 | R— | M] (Carbonite, Inc. (www.carbonite.com)) – C:\Program Files\Carbonite\Carbonite Backup\CarboniteService.exe
PRC - [2009/12/03 16:52:32 | 000,670,864 | R— | M] (Carbonite, Inc.) – C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe
PRC - [2009/03/05 16:07:20 | 002,260,480 | RHS- | M] (Safer-Networking Ltd.) – C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2008/04/13 19:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2007/08/09 02:27:52 | 000,073,728 | —- | M] (HP) – C:\WINDOWS\system32\HPZipm12.exe
PRC - [2005/03/15 21:15:22 | 000,045,056 | —- | M] (Hewlett-Packard) – C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
PRC - [2005/03/15 21:03:28 | 000,180,269 | —- | M] (RealNetworks, Inc.) – C:\Program Files\Common Files\Real\Update_OB\realsched.exe
PRC - [2004/10/13 18:17:06 | 002,742,272 | —- | M] (RealTek Semicoductor Corp.) – C:\WINDOWS\ALCWZRD.EXE
PRC - [2004/10/13 18:00:10 | 000,057,344 | —- | M] (Realtek Semiconductor Corp.) – C:\WINDOWS\ALCMTR.EXE
PRC - [2004/10/13 16:01:50 | 000,077,824 | —- | M] (Realtek Semiconductor Corp.) – C:\WINDOWS\SOUNDMAN.EXE


========== Modules (SafeList) ==========

MOD - [2010/05/20 08:54:07 | 000,571,904 | —- | M] (OldTimer Tools) – C:\Documents and Settings\HP_Administrator\My Documents\My Downloads\OTL.exe
MOD - [2010/04/21 14:55:00 | 000,890,280 | —- | M] () – C:\Program Files\iolo\Common\Lib\sguard.dll
MOD - [2008/04/13 19:10:20 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\msscript.ocx
MOD - [2005/03/15 21:15:22 | 000,024,613 | —- | M] (BackWeb) – C:\Documents and Settings\HP_Administrator\Local Settings\Temp\IadHide5.dll


========== Win32 Services (SafeList) ==========

SRV - [2010/04/21 14:54:24 | 000,356,264 | —- | M] () [Auto | Running] – C:\Program Files\iolo\System Mechanic Professional\IoloSGCtrl.exe – (IOLO_SRV)
SRV - [2010/04/21 14:34:14 | 000,704,432 | —- | M] () [Auto | Running] – C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe – (ioloSystemService)
SRV - [2010/04/21 14:34:14 | 000,704,432 | —- | M] () [Auto | Running] – C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe – (ioloFileInfoList)
SRV - [2010/03/29 08:53:22 | 000,068,000 | —- | M] (NOS Microsystems Ltd.) [On_Demand | Stopped] – C:\Program Files\NOS\bin\getPlus_Helper.dll – (getPlusHelper) getPlus®
SRV - [2010/01/19 18:46:56 | 000,158,248 | —- | M] (Authentium, Inc) [On_Demand | Stopped] – C:\Program Files\Common Files\Authentium\AntiVirus5\vseqrts.exe – (vseqrts)
SRV - [2010/01/19 18:46:54 | 000,117,288 | R— | M] (Authentium, Inc) [Auto | Running] – C:\Program Files\Common Files\Authentium\AntiVirus5\vsedsps.exe – (vsedsps)
SRV - [2010/01/19 18:46:48 | 000,121,384 | R— | M] (Authentium, Inc) [Auto | Running] – C:\Program Files\Common Files\Authentium\AntiVirus5\vseamps.exe – (vseamps)
SRV - [2009/12/03 16:52:32 | 001,980,560 | R— | M] (Carbonite, Inc. (www.carbonite.com)) [Auto | Running] – C:\Program Files\Carbonite\Carbonite Backup\carboniteservice.exe – (CarboniteService)
SRV - [2007/08/09 02:27:52 | 000,073,728 | —- | M] (HP) [Auto | Running] – C:\WINDOWS\system32\HPZipm12.exe – (Pml Driver HPZ12)


========== Driver Services (SafeList) ==========

DRV - [2010/05/08 07:00:10 | 000,068,168 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS – (SASKUTIL)
DRV - [2010/04/16 15:40:17 | 000,012,872 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS – (SASDIFSV)
DRV - [2010/04/16 15:40:16 | 000,012,872 | —- | M] ( SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | On_Demand | Stopped] – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS – (SASENUM)
DRV - [2010/01/19 18:53:46 | 000,127,016 | R— | M] (Authentium, Inc) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\amp.sys – (AMP)
DRV - [2010/01/19 18:53:44 | 001,118,248 | R— | M] (Authentium, Inc) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\ampse.sys – (AMPSE)
DRV - [2009/10/07 17:32:36 | 000,039,424 | —- | M] (iolo technologies, LLC) [Kernel | Boot | Running] – C:\WINDOWS\System32\xpacket.sys – (XPacket)
DRV - [2008/04/13 13:45:34 | 000,046,592 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\irbus.sys – (IrBus)
DRV - [2008/04/13 11:36:05 | 000,144,384 | —- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\hdaudbus.sys – (HDAudBus)
DRV - [2006/07/24 18:51:34 | 000,009,341 | —- | M] (iolo technologies, LLC (based on original work by Bo Brantén)) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\filedisk.sys – (FileDisk)
DRV - [2005/03/21 11:00:24 | 000,004,096 | —- | M] (SuperAdBlocker.com) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\sabprocenum.sys – (SABProcEnum)
DRV - [2004/11/11 17:37:04 | 000,160,256 | —- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\cx88vid.sys – (CX23880)
DRV - [2004/11/11 17:37:02 | 000,031,360 | —- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\cx88tune.sys – (CXTUNE)
DRV - [2004/11/11 17:36:58 | 000,297,344 | —- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\cx88enc.sys – (CX88ENC)
DRV - [2004/11/11 17:36:56 | 000,009,472 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\cxavxbar.sys – (CXAVXBAR)
DRV - [2004/10/13 19:33:20 | 002,287,104 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\RtkHDAud.sys – (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2004/06/29 12:07:18 | 001,268,204 | —- | M] (Agere Systems) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\AGRSM.sys – (AgereSoftModem)
DRV - [2004/03/18 02:10:40 | 000,113,664 | —- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\Hdaudio.sys – (HdAudAddService)
DRV - [2003/12/02 20:23:20 | 000,142,336 | —- | M] (Promise Technology, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\fasttx2k.sys – (fasttx2k)
DRV - [2003/09/19 11:47:00 | 000,010,368 | —- | M] (Padus, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\pfc.sys – (Pfc)
DRV - [2003/09/11 09:36:54 | 000,021,060 | —- | M] (InterVideo, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\iviaspi.sys – (Iviaspi)
DRV - [2002/10/04 12:04:10 | 000,046,976 | —- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\R8139n51.sys – (rtl8139)
DRV - [2001/06/04 08:00:00 | 000,014,112 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\PS2.sys – (Ps2)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.nascar.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.nascar.com/"
FF - prefs.js..extensions.enabledItems: [removed]:1.0

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/05/08 12:43:03 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/05/08 12:43:03 | 000,000,000 | —D | M]

[2010/04/27 22:49:03 | 000,000,000 | —D | M] – C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Extensions
[2010/05/15 08:01:28 | 000,000,000 | —D | M] – C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\lplrqtjt.default\extensions
[2010/05/01 17:51:34 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\lplrqtjt.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/04/27 22:54:38 | 000,000,000 | —D | M] (Adobe DLM (powered by getPlus®)) – C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\lplrqtjt.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2010/04/12 17:03:59 | 000,000,000 | —D | M] – C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\unb7yezh.default\extensions
[2010/04/12 17:04:01 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\unb7yezh.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/04/12 17:03:59 | 000,000,000 | —D | M] – C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\unb7yezh.default\extensions\[removed]
[2010/04/27 22:48:19 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2009/11/19 16:16:28 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
[2009/11/19 16:16:29 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npMozCouponPrinter.dll

O1 HOSTS File: ([2010/05/15 21:14:33 | 000,395,194 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 13648 more lines…
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found.
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (HP view) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll (Hewlett-Packard Company)
O3 - HKCU\..\Toolbar\ShellBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (HP view) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll (Hewlett-Packard Company)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (HP view) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll (Hewlett-Packard Company)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [AlcWzrd] C:\WINDOWS\ALCWZRD.EXE (RealTek Semicoductor Corp.)
O4 - HKLM..\Run: [Carbonite Backup] C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe (Carbonite, Inc.)
O4 - HKLM..\Run: [High Definition Audio Property Page Shortcut] C:\WINDOWS\System32\Hdaudpropshortcut.exe (Windows ® Server 2003 DDK provider)
O4 - HKLM..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe (Hewlett-Packard)
O4 - HKLM..\Run: [iolo Personal Firewall] C:\Program Files\iolo\Personal Firewall\ioloFW.exe ()
O4 - HKLM..\Run: [PS2] C:\WINDOWS\system32\ps2.EXE (Hewlett-Packard Company)
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\Recguard.exe ()
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SystemGuardAlerter] C:\Program Files\iolo\System Mechanic Professional\SystemGuardAlerter.exe ()
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [Octoshape Streaming Services] C:\Documents and Settings\HP_Administrator\Application Data\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe (Octoshape ApS)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe (Hewlett-Packard)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll (Google Inc.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\System32\iavlsp.dll (iolo technologies, LLC)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\System32\iavlsp.dll (iolo technologies, LLC)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\iolo\Common\Firewall\iFW_Xfilter.dll (iolo technologies, LLC)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\iolo\Common\Firewall\iFW_Xfilter.dll (iolo technologies, LLC)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\iolo\Common\Firewall\iFW_Xfilter.dll (iolo technologies, LLC)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\iolo\Common\Firewall\iFW_Xfilter.dll (iolo technologies, LLC)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\iolo\Common\Firewall\iFW_Xfilter.dll (iolo technologies, LLC)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\WINDOWS\System32\iavlsp.dll (iolo technologies, LLC)
O15 - HKLM\..Trusted Domains: localhost ([]http in Local intranet)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1271297002906 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} http://www.superadblocker.com/activex/sabspx.cab (SABScanProcesses Class)
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/03/15 21:44:42 | 000,000,100 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2001/07/28 07:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2010/04/12 10:49:45 | 000,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (50397631582568448)

========== Files/Folders - Created Within 90 Days ==========

[2010/05/19 06:33:12 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010/05/18 19:46:31 | 000,986,266 | —- | C] (Axialis Software) – C:\WINDOWS\System32\JeffGordonScreenSaver_2.scr
[2010/05/18 19:45:50 | 000,000,000 | —D | C] – C:\Program Files\IMG
[2010/05/18 19:45:44 | 001,662,423 | —- | C] (Axialis Software) – C:\WINDOWS\System32\JGScreensaver4.scr
[2010/05/18 19:44:13 | 000,000,000 | —D | C] – C:\Program Files\IMG Media
[2010/05/18 19:44:03 | 003,066,862 | —- | C] (Axialis Software) – C:\WINDOWS\System32\JeffGordonScreensaver.scr
[2010/05/18 19:43:30 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Axialis
[2010/05/16 11:14:39 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\.sv
[2010/05/15 15:56:23 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/05/15 15:56:20 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/05/15 15:56:19 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/05/15 14:36:26 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2010/05/15 14:36:26 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2010/05/15 14:10:56 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\My Documents\Downloads
[2010/05/08 12:43:11 | 000,226,728 | R— | C] (Coupons, Inc.) – C:\WINDOWS\cpnprt2.cid
[2010/05/08 12:43:11 | 000,226,728 | —- | C] (Coupons, Inc.) – C:\WINDOWS\System32\cpnprt2.cid
[2010/05/08 12:43:01 | 000,000,000 | —D | C] – C:\Program Files\Coupons
[2010/05/05 22:09:03 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\wyoHomeInventory Projects
[2010/05/05 22:09:03 | 000,000,000 | —D | C] – C:\Program Files\What You Own
[2010/05/03 10:19:47 | 000,000,000 | —D | C] – C:\Program Files\ACW
[2010/05/02 09:49:43 | 000,000,000 | —D | C] – C:\WINDOWS\System32\NtmsData
[2010/04/30 11:12:51 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\PCHealth
[2010/04/30 06:58:00 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Application Data\HpUpdate
[2010/04/30 06:57:57 | 000,000,000 | —D | C] – C:\WINDOWS\Hewlett-Packard
[2010/04/30 06:33:45 | 000,000,000 | —D | C] – C:\WINDOWS\pss
[2010/04/29 22:14:17 | 000,000,000 | —D | C] – C:\WINDOWS\System32\XPSViewer
[2010/04/29 22:14:05 | 000,000,000 | —D | C] – C:\Program Files\MSBuild
[2010/04/29 22:13:38 | 000,000,000 | —D | C] – C:\Program Files\Reference Assemblies
[2010/04/29 22:12:17 | 000,000,000 | —D | C] – C:\19d4c5ffede28fb7ac78
[2010/04/28 22:27:42 | 000,000,000 | —D | C] – C:\Program Files\Xiph.Org
[2010/04/28 14:54:00 | 000,000,000 | —D | C] – C:\WINDOWS\Performance
[2010/04/28 14:53:45 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft Corporation
[2010/04/28 14:52:57 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Windows 7 Upgrade Advisor
[2010/04/28 11:38:46 | 000,000,000 | RH-D | C] – C:\Documents and Settings\HP_Administrator\Recent
[2010/04/28 06:17:19 | 000,000,000 | —D | C] – C:\WINDOWS\WBEM
[2010/04/28 06:14:47 | 000,000,000 | -H-D | C] – C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$
[2010/04/28 06:14:02 | 000,000,000 | -H-D | C] – C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$
[2010/04/27 22:54:45 | 000,000,000 | —D | C] – C:\Program Files\NOS
[2010/04/27 22:54:45 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\NOS
[2010/04/27 22:48:14 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2010/04/26 10:47:00 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Help
[2010/04/26 10:47:00 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Application Data\Help
[2010/04/25 12:21:10 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sun
[2010/04/25 12:15:13 | 000,000,000 | —D | C] – C:\WINDOWS\Sun
[2010/04/16 15:31:31 | 000,000,000 | —D | C] – C:\Program Files\Windows Media Connect 2
[2010/04/16 15:29:16 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\UMDF
[2010/04/16 15:29:16 | 000,000,000 | —D | C] – C:\WINDOWS\System32\LogFiles
[2010/04/16 09:16:41 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2010/04/16 09:16:31 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2010/04/16 09:15:37 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Wise Installation Wizard
[2010/04/15 22:14:59 | 000,000,000 | —D | C] – C:\WINDOWS\RegisteredPackages
[2010/04/15 22:09:33 | 000,000,000 | —D | C] – C:\981b7146670f8915c3
[2010/04/15 14:06:14 | 000,000,000 | —D | C] – C:\WINDOWS\Prefetch
[2010/04/15 13:31:20 | 000,000,000 | —D | C] – C:\WINDOWS\System32\en-us
[2010/04/15 13:31:18 | 000,000,000 | —D | C] – C:\WINDOWS\System32\scripting
[2010/04/15 13:31:17 | 000,000,000 | —D | C] – C:\WINDOWS\l2schemas
[2010/04/15 13:31:16 | 000,000,000 | —D | C] – C:\WINDOWS\System32\bits
[2010/04/15 13:23:53 | 000,000,000 | —D | C] – C:\WINDOWS\network diagnostic
[2010/04/15 13:17:09 | 000,000,000 | -H-D | C] – C:\WINDOWS\$NtServicePackUninstall$
[2010/04/14 22:15:26 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2010/04/14 21:59:39 | 000,000,000 | —D | C] – C:\WINDOWS\ServicePackFiles
[2010/04/14 21:58:40 | 000,000,000 | —D | C] – C:\Program Files\MSXML 4.0
[2010/04/14 21:37:31 | 000,000,000 | —D | C] – C:\Program Files\Microsoft CAPICOM 2.1.0.2
[2010/04/14 20:40:25 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2010/04/14 17:29:01 | 000,000,000 | —D | C] – C:\Program Files\Windows Installer Clean Up
[2010/04/14 16:27:45 | 000,000,000 | —D | C] – C:\Program Files\TurboTax
[2010/04/14 16:27:23 | 000,000,000 | —D | C] – C:\Program Files\Turbo Tax Audit Support Center
[2010/04/14 16:27:23 | 000,000,000 | —D | C] – C:\Program Files\The Kim Komando Show
[2010/04/14 16:27:22 | 000,000,000 | —D | C] – C:\Program Files\stickies
[2010/04/14 16:26:06 | 000,000,000 | —D | C] – C:\Program Files\Reader's Digest Word Power
[2010/04/14 16:25:27 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/04/14 15:52:26 | 000,000,000 | —D | C] – C:\Program Files\Libronix DLS
[2010/04/14 15:52:25 | 000,000,000 | —D | C] – C:\Program Files\Komando
[2010/04/14 15:37:25 | 000,000,000 | —D | C] – C:\Program Files\ItsDeductible2006
[2010/04/14 15:34:09 | 000,000,000 | —D | C] – C:\Program Files\ItsDeductible2005
[2010/04/14 15:30:40 | 000,000,000 | —D | C] – C:\Program Files\Hasbro Interactive
[2010/04/14 15:28:03 | 000,000,000 | —D | C] – C:\Program Files\Hasbro
[2010/04/14 15:28:02 | 000,000,000 | —D | C] – C:\Program Files\FLV Player
[2010/04/14 15:21:05 | 000,000,000 | —D | C] – C:\Program Files\Family Tree Maker 2005
[2010/04/14 15:21:04 | 000,000,000 | —D | C] – C:\Program Files\EmailStripper
[2010/04/14 15:19:21 | 000,000,000 | —D | C] – C:\Program Files\Driver Robot
[2010/04/14 15:17:54 | 000,000,000 | —D | C] – C:\Program Files\Deluxe 2004
[2010/04/14 15:09:14 | 000,000,000 | —D | C] – C:\Program Files\Atari
[2010/04/14 15:08:58 | 000,000,000 | —D | C] – C:\Program Files\AM-DeadLink
[2010/04/14 15:02:25 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\My Documents\TurboTax
[2010/04/14 12:05:40 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\My Documents\TomTom
[2010/04/14 11:54:56 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\My Documents\Terrie
[2010/04/14 11:54:48 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\My Documents\Templates
[2010/04/14 11:54:44 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\My Documents\Seraphim Angels
[2010/04/14 11:54:40 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Administrator\My Documents\Politics
[2010/04/14 11:54:23 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Administrator\My Documents\Personal Affairs
[2010/04/14 11:54:05 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\My Documents\On line Subscriptions
[2010/04/14 10:53:39 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Administrator\My Documents\My TV Pictures
[2010/04/14 10:53:01 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\My Documents\My Received Files
[2010/04/14 10:53:01 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\My Documents\My Programs
[2010/04/13 01:44:17 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\My Documents\My Master Lists
[2010/04/13 01:43:51 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Administrator\My Documents\My Letters
[2010/04/13 01:43:42 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Administrator\My Documents\My Games
[2010/04/13 01:40:59 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Administrator\My Documents\My Emails' Archives
[2010/04/13 01:38:16 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Administrator\My Documents\My Downloads
[2010/04/13 01:38:14 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Administrator\My Documents\My Data Sources
[2010/04/13 01:36:51 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Administrator\My Documents\My Computer
[2010/04/13 01:26:07 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Administrator\My Documents\Medical Records and Information
[2010/04/13 01:25:12 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\My Documents\Marketplace Meditation
[2010/04/13 01:24:28 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Administrator\My Documents\Manuals
[2010/04/13 01:24:18 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\My Documents\Life Lessons
[2010/04/13 01:24:18 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\My Documents\Libronix DLS
[2010/04/13 01:23:28 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\My Documents\Libraries
[2010/04/13 01:22:46 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Administrator\My Documents\Home
[2010/04/13 01:04:45 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Administrator\My Documents\Financial
[2010/04/13 01:04:44 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Administrator\My Documents\Favorite Bookmarks
[2010/04/13 01:04:06 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Administrator\My Documents\Email Specials
[2010/04/13 01:03:58 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\My Documents\eBay
[2010/04/13 01:02:21 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Administrator\My Documents\Dutton Lainson
[2010/04/13 01:01:39 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Administrator\My Documents\Bandit
[2010/04/13 00:44:18 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\My Documents\Attachments
[2010/04/13 00:40:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\My Documents\Artilces - Religious
[2010/04/13 00:40:18 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\My Documents\Articles - Work
[2010/04/13 00:39:49 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\My Documents\Articles - Misc
[2010/04/13 00:39:40 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\My Documents\Articles - Holidays
[2010/04/13 00:39:09 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\My Documents\Articles - Health
[2010/04/13 00:39:09 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\My Documents\Articles - Finance
[2010/04/13 00:37:31 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\My Documents\Archives
[2010/04/13 00:22:02 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Administrator\My Documents\Addresses
[2010/04/13 00:22:00 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\My Documents\Aaron's File
[2010/04/13 00:21:56 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\TomTom
[2010/04/13 00:21:56 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\MTV Networks
[2010/04/13 00:19:39 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Mozilla
[2010/04/13 00:19:34 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\MicroVision Applications
[2010/04/12 22:10:01 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Temp
[2010/04/12 22:05:49 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2010/04/12 22:05:09 | 000,000,000 | —D | C] – C:\Program Files\Google
[2010/04/12 22:05:09 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Google
[2010/04/12 22:00:34 | 000,000,000 | —D | C] – C:\WINDOWS\System32\PreInstall
[2010/04/12 20:28:12 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Itiva
[2010/04/12 20:28:07 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\IsolatedStorage
[2010/04/12 20:28:07 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Intuit
[2010/04/12 20:00:25 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Identities
[2010/04/12 19:45:49 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Google
[2010/04/12 19:45:48 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Downloaded Installations
[2010/04/12 19:45:47 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\AskToolbar
[2010/04/12 19:24:12 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Administrator\Desktop\DAILY
[2010/04/12 19:24:11 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Application Data\wsInspector
[2010/04/12 19:19:29 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Application Data\Uniblue
[2010/04/12 19:19:23 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Application Data\TuneUp Software
[2010/04/12 19:19:07 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Application Data\TomTom
[2010/04/12 19:16:42 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Application Data\SUPERAntiSpyware.com
[2010/04/12 17:06:04 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Application Data\stickies
[2010/04/12 17:05:57 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Application Data\Sonic
[2010/04/12 17:04:40 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Application Data\Otto
[2010/04/12 17:04:31 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Application Data\Octoshape
[2010/04/12 17:04:30 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Application Data\muvee Technologies
[2010/04/12 17:03:03 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Application Data\Mozilla
[2010/04/12 17:00:46 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Application Data\Move Networks
[2010/04/12 17:00:17 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Application Data\Motive
[2010/04/12 16:54:29 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Application Data\Malwarebytes
[2010/04/12 16:46:57 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Application Data\Libronix DLS
[2010/04/12 16:46:56 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Application Data\Leadertech
[2010/04/12 16:40:28 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Application Data\Intuit
[2010/04/12 16:40:27 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Application Data\Hewlett-Packard
[2010/04/12 16:40:26 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Application Data\GTek
[2010/04/12 16:40:24 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Application Data\Google
[2010/04/12 16:40:23 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010/04/12 16:40:17 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Application Data\CBS Interactive
[2010/04/12 16:22:36 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Adobe
[2010/04/12 16:22:28 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\My Documents\My eBooks
[2010/04/12 16:22:17 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe
[2010/04/12 16:05:53 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Application Data\Blitware
[2010/04/12 16:05:44 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Application Data\Backup MyPC
[2010/04/12 15:47:05 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Application Data\aignes
[2010/04/12 15:47:04 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Application Data\AdobeUM
[2010/04/12 15:22:45 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\.SunDownloadManager
[2010/04/12 15:22:44 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\.jogl_ext
[2010/04/12 15:05:12 | 000,000,000 | —D | C] – C:\Program Files\Carbonite
[2010/04/12 15:05:12 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Carbonite
[2010/04/12 14:51:58 | 000,000,000 | -HSD | C] – C:\Documents and Settings\All Users\Documents\MCE Logs
[2010/04/12 14:41:50 | 000,039,424 | —- | C] (iolo technologies, LLC) – C:\WINDOWS\System32\xpacket.sys
[2010/04/12 14:28:35 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Real
[2010/04/12 14:07:48 | 000,000,000 | —D | C] – C:\Program Files\Microsoft ActiveSync
[2010/04/12 14:07:30 | 000,000,000 | —D | C] – C:\Program Files\Common Files\DESIGNER
[2010/04/12 14:07:07 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Visual Studio
[2010/04/12 13:00:41 | 000,000,000 | —D | C] – C:\WINDOWS\System32\appmgmt
[2010/04/12 12:48:36 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2010/04/12 12:47:43 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Application Data\Adobe
[2010/04/12 12:36:09 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\HP
[2010/04/12 12:07:19 | 000,000,000 | –SD | C] – C:\Documents and Settings\HP_Administrator\UserData
[2010/04/12 12:07:16 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Application Data\Macromedia
[2010/04/12 12:06:12 | 000,000,000 | RHSD | C] – C:\cmdcons
[2010/04/12 12:06:09 | 000,000,000 | —D | C] – C:\WINDOWS\setup.pss
[2010/04/12 12:05:49 | 000,000,000 | —D | C] – C:\WINDOWS\setupupd
[2010/04/12 12:05:33 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\LightScribe
[2010/04/12 12:05:31 | 000,000,000 | —D | C] – C:\WINDOWS\System32\Lang
[2010/04/12 12:04:05 | 000,000,000 | –SD | C] – C:\Documents and Settings\HP_Administrator\Application Data\Microsoft
[2010/04/12 12:04:05 | 000,000,000 | –SD | C] – C:\Documents and Settings\HP_Administrator\Cookies
[2010/04/12 12:04:05 | 000,000,000 | RH-D | C] – C:\Documents and Settings\HP_Administrator\SendTo
[2010/04/12 12:04:05 | 000,000,000 | RH-D | C] – C:\Documents and Settings\HP_Administrator\Application Data
[2010/04/12 12:04:05 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Administrator\My Documents\My Videos
[2010/04/12 12:04:05 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Administrator\My Documents\My Pictures
[2010/04/12 12:04:05 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Administrator\My Documents\My Music
[2010/04/12 12:04:05 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Administrator\My Documents
[2010/04/12 12:04:05 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Administrator\Favorites
[2010/04/12 12:04:05 | 000,000,000 | -H-D | C] – C:\Documents and Settings\HP_Administrator\PrintHood
[2010/04/12 12:04:05 | 000,000,000 | -H-D | C] – C:\Documents and Settings\HP_Administrator\NetHood
[2010/04/12 12:04:05 | 000,000,000 | -H-D | C] – C:\Documents and Settings\HP_Administrator\Local Settings
[2010/04/12 12:04:05 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Application Data\Symantec
[2010/04/12 12:04:05 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Application Data\Sun
[2010/04/12 12:04:05 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Application Data\SampleView
[2010/04/12 12:04:05 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Application Data\Real
[2010/04/12 12:04:05 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft
[2010/04/12 12:04:05 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Application Data\InterMute
[2010/04/12 12:04:05 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Application Data\Identities
[2010/04/12 12:04:05 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Desktop
[2010/04/12 12:04:05 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\ApplicationHistory
[2010/04/12 12:04:05 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Apple Computer
[2010/04/12 12:04:05 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Application Data\Apple Computer
[2010/04/12 12:04:05 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\{7148F0A6-6813-11D6-A77B-00B0D0142030}
[2010/04/12 12:04:04 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Administrator\Start Menu
[2010/04/12 12:04:04 | 000,000,000 | -H-D | C] – C:\Documents and Settings\HP_Administrator\Templates
[2010/04/12 12:04:04 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\WINDOWS
[2010/04/12 12:02:42 | 000,000,000 | —D | C] – C:\Program Files\Common Files\LightScribe
[2010/04/12 12:02:39 | 000,000,000 | —D | C] – C:\WINDOWS\System32\RTCOM
[2010/04/12 11:58:10 | 000,000,000 | —D | C] – C:\WINDOWS\System32\SoftwareDistribution
[2010/04/12 11:53:27 | 000,000,000 | -HSD | C] – C:\System Volume Information
[2010/04/12 10:50:13 | 000,000,000 | —D | C] – C:\WINDOWS\I386
[2010/04/12 10:43:17 | 000,000,000 | RH-D | C] – C:\MSOCache
[2010/04/12 10:43:17 | 000,000,000 | R–D | C] – C:\Documents and Settings\All Users\Start Menu
[2010/04/12 10:43:09 | 000,000,000 | R–D | C] – C:\Documents and Settings\All Users\Documents\My Videos
[2010/04/12 10:43:07 | 000,000,000 | R–D | C] – C:\Documents and Settings\All Users\Documents\My Pictures
[2010/04/12 10:42:55 | 000,000,000 | R–D | C] – C:\Documents and Settings\All Users\Documents\My Music
[2010/04/12 10:42:55 | 000,000,000 | R–D | C] – C:\Documents and Settings\All Users\Documents
[2010/04/12 10:42:53 | 000,000,000 | RH-D | C] – C:\Documents and Settings\All Users\Application Data
[2010/04/12 10:42:06 | 000,000,000 | R-SD | C] – C:\WINDOWS\assembly
[2010/04/12 10:42:03 | 000,000,000 | R–D | C] – C:\WINDOWS\Offline Web Pages
[2010/04/12 10:41:28 | 000,000,000 | RHSD | C] – C:\WINDOWS\System32\dllcache
[2010/04/12 10:17:28 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\iolo
[2010/04/12 10:15:48 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Authentium
[2010/04/12 10:15:28 | 000,000,000 | -H-D | C] – C:\WINDOWS\$MSI31Uninstall_KB893803v2$
[2010/04/12 10:15:03 | 000,118,784 | —- | C] (iolo technologies, LLC) – C:\WINDOWS\System32\iavlsp.dll
[2010/04/12 10:15:01 | 000,093,096 | —- | C] (iolo technologies, LLC) – C:\WINDOWS\System32\IncContxMenu.dll
[2010/04/12 10:15:00 | 000,009,341 | —- | C] (iolo technologies, LLC (based on original work by Bo Brantén)) – C:\WINDOWS\System32\drivers\filedisk.sys
[2010/04/12 10:14:46 | 000,000,000 | —D | C] – C:\Program Files\iolo
[2010/04/12 10:05:56 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Application Data\iolo
[2010/04/12 10:05:56 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\iolo

========== Files - Modified Within 90 Days ==========

[2010/05/20 08:42:01 | 000,000,906 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/05/20 06:51:41 | 008,912,896 | —- | M] () – C:\Documents and Settings\HP_Administrator\NTUSER.DAT
[2010/05/20 00:42:02 | 000,000,902 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/05/19 22:09:35 | 000,000,249 | —- | M] () – C:\WINDOWS\System\hpsysdrv.dat
[2010/05/19 22:08:17 | 000,000,448 | —- | M] () – C:\WINDOWS\System32\iolo.ini
[2010/05/19 22:07:50 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/05/19 22:07:47 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/05/19 22:07:45 | 3212,169,216 | -HS- | M] () – C:\hiberfil.sys
[2010/05/19 22:05:53 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\HP_Administrator\ntuser.ini
[2010/05/19 22:04:57 | 001,578,496 | -H– | M] () – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\IconCache.db
[2010/05/19 09:34:41 | 000,002,469 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\HiJackThis.lnk
[2010/05/18 19:46:36 | 000,000,756 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\JGScreensaver 2 Screensaver.lnk
[2010/05/18 19:46:31 | 000,986,266 | —- | M] (Axialis Software) – C:\WINDOWS\System32\JeffGordonScreenSaver_2.scr
[2010/05/18 19:45:51 | 000,000,709 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\JGScreensaver4 Screensaver.lnk
[2010/05/18 19:45:44 | 001,662,423 | —- | M] (Axialis Software) – C:\WINDOWS\System32\JGScreensaver4.scr
[2010/05/18 19:44:18 | 000,000,762 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\Jeff Gordon Screensaver Screensaver.lnk
[2010/05/18 19:44:07 | 003,066,862 | —- | M] (Axialis Software) – C:\WINDOWS\System32\JeffGordonScreensaver.scr
[2010/05/18 19:17:17 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/05/15 21:14:33 | 000,395,194 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2010/05/11 10:59:25 | 000,060,018 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\Systemsnapshot.zip
[2010/05/09 20:57:09 | 000,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2010/05/09 20:57:09 | 000,001,409 | —- | M] () – C:\WINDOWS\QTFont.for
[2010/05/08 12:43:11 | 000,226,728 | R— | M] (Coupons, Inc.) – C:\WINDOWS\cpnprt2.cid
[2010/05/08 12:43:11 | 000,226,728 | —- | M] (Coupons, Inc.) – C:\WINDOWS\System32\cpnprt2.cid
[2010/05/05 22:09:03 | 000,000,890 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Home Inventory.lnk
[2010/05/05 06:37:56 | 000,044,808 | —- | M] () – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/05/05 06:32:06 | 000,006,144 | —- | M] () – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/05/03 10:38:03 | 000,000,658 | —- | M] () – C:\WINDOWS\win.ini
[2010/05/03 10:38:03 | 000,000,279 | RHS- | M] () – C:\boot.ini
[2010/05/03 10:38:03 | 000,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/05/02 09:49:24 | 000,181,040 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/05/02 09:29:36 | 003,153,920 | —- | M] () – C:\WINDOWS\System32\secsetup.sdb
[2010/04/30 11:02:25 | 000,507,858 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/04/30 11:02:25 | 000,445,700 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/04/30 11:02:25 | 000,072,780 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/04/29 15:39:26 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/04/28 22:42:33 | 000,000,736 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\Computer Wiring Labels.lnk
[2010/04/27 23:51:04 | 000,000,273 | —- | M] () – C:\WINDOWS\SysMech.INI
[2010/04/27 22:48:47 | 000,000,000 | —- | M] () – C:\WINDOWS\nsreg.dat
[2010/04/27 22:48:26 | 000,001,613 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2010/04/23 21:42:43 | 000,940,794 | —- | M] () – C:\WINDOWS\System32\LoopyMusic.wav
[2010/04/23 21:42:43 | 000,146,650 | —- | M] () – C:\WINDOWS\System32\BuzzingBee.wav
[2010/04/21 14:54:36 | 000,093,096 | —- | M] (iolo technologies, LLC) – C:\WINDOWS\System32\IncContxMenu.dll
[2010/04/21 14:54:28 | 002,316,712 | —- | M] () – C:\WINDOWS\System32\Incinerator.dll
[2010/04/16 15:36:32 | 000,023,392 | —- | M] () – C:\WINDOWS\System32\nscompat.tlb
[2010/04/16 15:36:32 | 000,016,832 | —- | M] () – C:\WINDOWS\System32\amcompat.tlb
[2010/04/16 15:29:29 | 000,000,000 | -H– | M] () – C:\WINDOWS\System32\drivers\UMDF\MsftWdf_user_01_00_00.Wdf
[2010/04/15 22:15:35 | 000,316,640 | —- | M] () – C:\WINDOWS\WMSysPr9.prx
[2010/04/15 13:23:20 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/04/13 11:32:13 | 000,103,098 | —- | M] () – C:\Documents and Settings\HP_Administrator\My Documents\h2h.665
[2010/04/12 14:09:35 | 000,000,376 | —- | M] () – C:\WINDOWS\ODBC.INI
[2010/04/12 12:36:08 | 000,000,139 | —- | M] () – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\fusioncache.dat
[2010/04/12 12:16:04 | 000,104,226 | —- | M] () – C:\WINDOWS\hpoins04.dat
[2010/04/12 12:06:00 | 000,001,870 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Updates from HP.lnk
[2010/04/12 12:05:07 | 000,001,922 | RHS- | M] () – C:\WINDOWS\System32\drivers\103C_HP_CPC_PS580AA-ABA M7060N_YC_0Pavi_QMXK516_E52NAsyEPC2_47_IGoldfish3_SASUSTeK Computer INC._V1.xx_B3.21_T050429_WXP2_L409_M3064_J200_7Intel_8Pentium 4_93_#050604_N10EC8139_Z11C1048C_G80862582.MRK
[2010/04/12 12:03:03 | 000,000,993 | —- | M] () – C:\WINDOWS\System32\$winnt$.inf
[2010/04/12 12:03:00 | 000,262,144 | —- | M] () – C:\Documents and Settings\All Users\NTUSER.DAT
[2010/04/12 12:02:48 | 000,002,158 | —- | M] () – C:\WINDOWS\System32\ssmute.ini
[2010/04/12 12:02:16 | 000,000,211 | RHS- | M] () – C:\BOOT.BAK
[2010/04/12 10:18:50 | 000,000,406 | —- | M] () – C:\WINDOWS\System32\ioloBootDefrag.cfg
[2010/04/12 10:13:14 | 000,074,703 | —- | M] () – C:\WINDOWS\System32\mfc45.dll
[2010/03/07 20:46:25 | 000,790,198 | —- | M] () – C:\Documents and Settings\HP_Administrator\My Documents\Branson Map.pdf

========== Files Created - No Company Name ==========

[2010/05/19 22:08:17 | 000,000,448 | —- | C] () – C:\WINDOWS\System32\iolo.ini
[2010/05/19 06:33:13 | 000,002,469 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\HiJackThis.lnk
[2010/05/18 19:46:36 | 000,000,756 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\JGScreensaver 2 Screensaver.lnk
[2010/05/18 19:45:51 | 000,000,709 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\JGScreensaver4 Screensaver.lnk
[2010/05/18 19:44:18 | 000,000,762 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\Jeff Gordon Screensaver Screensaver.lnk
[2010/05/11 10:59:25 | 000,060,018 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\Systemsnapshot.zip
[2010/05/09 20:57:09 | 000,054,156 | -H– | C] () – C:\WINDOWS\QTFont.qfn
[2010/05/09 20:57:09 | 000,001,409 | —- | C] () – C:\WINDOWS\QTFont.for
[2010/05/05 22:09:03 | 000,000,890 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Home Inventory.lnk
[2010/05/02 09:29:32 | 003,153,920 | —- | C] () – C:\WINDOWS\System32\secsetup.sdb
[2010/04/28 22:42:33 | 000,000,736 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\Computer Wiring Labels.lnk
[2010/04/27 22:48:47 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2010/04/27 22:48:26 | 000,001,613 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2010/04/27 16:54:00 | 000,000,273 | —- | C] () – C:\WINDOWS\SysMech.INI
[2010/04/23 21:42:43 | 000,146,650 | —- | C] () – C:\WINDOWS\System32\BuzzingBee.wav
[2010/04/23 21:42:42 | 000,940,794 | —- | C] () – C:\WINDOWS\System32\LoopyMusic.wav
[2010/04/16 15:29:29 | 000,000,000 | -H– | C] () – C:\WINDOWS\System32\drivers\UMDF\MsftWdf_user_01_00_00.Wdf
[2010/04/15 21:19:47 | 001,291,776 | —- | C] () – C:\WINDOWS\System32\dllcache\quartz.dll
[2010/04/15 12:50:34 | 000,067,866 | —- | C] () – C:\WINDOWS\System32\drivers\netwlan5.img
[2010/04/15 12:50:16 | 000,129,045 | —- | C] () – C:\WINDOWS\System32\drivers\cxthsfs2.cty
[2010/04/15 12:48:31 | 000,064,352 | —- | C] () – C:\WINDOWS\System32\drivers\ativmc20.cod
[2010/04/13 11:33:26 | 000,103,098 | —- | C] () – C:\Documents and Settings\HP_Administrator\My Documents\h2h.665
[2010/04/12 22:05:46 | 000,000,906 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/04/12 22:05:45 | 000,000,902 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/04/12 15:40:36 | 000,006,144 | —- | C] () – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/04/12 12:51:28 | 000,000,097 | —- | C] () – C:\Documents and Settings\HP_Administrator\LuResult.txt
[2010/04/12 12:06:22 | 000,000,211 | RHS- | C] () – C:\BOOT.BAK
[2010/04/12 12:06:19 | 000,260,272 | RHS- | C] () – C:\cmldr
[2010/04/12 12:06:00 | 000,001,870 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Updates from HP.lnk
[2010/04/12 12:05:47 | 000,631,188 | —- | C] () – C:\Documents and Settings\HP_Administrator\ProductContext2200.log
[2010/04/12 12:05:02 | 000,001,922 | RHS- | C] () – C:\WINDOWS\System32\drivers\103C_HP_CPC_PS580AA-ABA M7060N_YC_0Pavi_QMXK516_E52NAsyEPC2_47_IGoldfish3_SASUSTeK Computer INC._V1.xx_B3.21_T050429_WXP2_L409_M3064_J200_7Intel_8Pentium 4_93_#050604_N10EC8139_Z11C1048C_G80862582.MRK
[2010/04/12 12:04:52 | 3212,169,216 | -HS- | C] () – C:\hiberfil.sys
[2010/04/12 12:04:08 | 000,000,139 | —- | C] () – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\fusioncache.dat
[2010/04/12 12:04:04 | 008,912,896 | —- | C] () – C:\Documents and Settings\HP_Administrator\NTUSER.DAT
[2010/04/12 12:04:04 | 000,001,024 | -H– | C] () – C:\Documents and Settings\HP_Administrator\ntuser.dat.LOG
[2010/04/12 12:04:04 | 000,000,278 | -HS- | C] () – C:\Documents and Settings\HP_Administrator\ntuser.ini
[2010/04/12 12:03:00 | 000,262,144 | —- | C] () – C:\Documents and Settings\All Users\NTUSER.DAT
[2010/04/12 12:03:00 | 000,001,024 | -H– | C] () – C:\Documents and Settings\All Users\NTUSER.DAT.LOG
[2010/04/12 10:51:15 | 000,000,249 | —- | C] () – C:\WINDOWS\System\hpsysdrv.dat
[2010/04/12 10:18:50 | 000,000,406 | —- | C] () – C:\WINDOWS\System32\ioloBootDefrag.cfg
[2010/04/12 10:15:01 | 002,316,712 | —- | C] () – C:\WINDOWS\System32\Incinerator.dll
[2010/04/12 10:14:48 | 000,030,208 | —- | C] () – C:\WINDOWS\System32\iolobtdfg.exe
[2010/04/12 10:14:48 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\smrgdf.exe
[2010/04/12 10:13:14 | 000,074,703 | —- | C] () – C:\WINDOWS\System32\mfc45.dll
[2010/04/08 16:49:48 | 000,737,280 | —- | C] () – C:\Documents and Settings\HP_Administrator\s-1-5-21-3471819860-1960323850-3924351264-500.rrr
[2010/03/07 20:46:25 | 000,790,198 | —- | C] () – C:\Documents and Settings\HP_Administrator\My Documents\Branson Map.pdf
[2005/08/05 14:01:54 | 000,235,008 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2005/03/15 21:46:30 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/03/15 21:42:56 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2005/03/15 21:42:56 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2005/03/15 21:42:56 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2005/03/15 21:42:56 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2005/03/15 21:42:56 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2005/03/15 21:42:56 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2005/03/15 21:14:41 | 000,015,329 | —- | C] () – C:\WINDOWS\System32\CHODDI.SYS
[2005/03/15 21:14:35 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\hpreg.dll
[2005/03/15 21:14:12 | 000,002,158 | —- | C] () – C:\WINDOWS\System32\ssmute.ini
[2005/03/15 21:10:42 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/03/15 20:46:29 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2005/03/15 20:43:18 | 000,156,672 | —- | C] () – C:\WINDOWS\System32\RTLCPAPI.dll
[2005/03/15 20:33:41 | 000,000,791 | —- | C] () – C:\WINDOWS\orun32.ini
[2005/03/15 20:32:28 | 000,323,584 | —- | C] () – C:\WINDOWS\System32\pythoncom22.dll
[2005/03/15 20:32:28 | 000,094,208 | —- | C] () – C:\WINDOWS\System32\pywintypes22.dll
[2005/03/15 20:32:06 | 000,016,896 | —- | C] () – C:\WINDOWS\System32\bcbmm.dll
[2004/09/13 18:35:56 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2004/08/20 05:14:46 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\PcdrKernelModeServices.dll
[2004/08/20 05:14:46 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\ProgressTrace.dll
[2004/08/10 07:00:00 | 000,755,200 | —- | C] () – C:\WINDOWS\System32\ir50_32.dll
[2004/08/10 07:00:00 | 000,338,432 | —- | C] () – C:\WINDOWS\System32\ir41_qcx.dll
[2004/08/10 07:00:00 | 000,200,192 | —- | C] () – C:\WINDOWS\System32\ir50_qc.dll
[2004/08/10 07:00:00 | 000,183,808 | —- | C] () – C:\WINDOWS\System32\ir50_qcx.dll
[2004/08/10 07:00:00 | 000,120,320 | —- | C] () – C:\WINDOWS\System32\ir41_qc.dll
[2004/07/26 16:51:38 | 000,000,549 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2003/04/11 01:04:00 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\JAWTAccessBridge.dll
[2003/01/07 15:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI

========== LOP Check ==========

[2010/04/12 15:05:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Carbonite
[2010/04/28 06:55:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\iolo

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2004/08/10 13:00:00 | 016,971,599 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2010/04/15 13:17:06 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2004/08/10 07:00:00 | 016,971,599 | —- | M] () .cab file – C:\WINDOWS\I386\sp2.cab:AGP440.sys
[2010/04/15 13:17:06 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 13:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 13:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\drivers\agp440.sys

< MD5 for: ATAPI.SYS >
[2004/08/10 13:00:00 | 016,971,599 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2010/04/15 13:17:06 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2004/08/10 07:00:00 | 016,971,599 | —- | M] () .cab file – C:\WINDOWS\I386\sp2.cab:atapi.sys
[2010/04/15 13:17:06 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/10 07:00:00 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2004/08/10 07:00:00 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\i386\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2008/04/13 19:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 19:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\eventlog.dll
[2004/08/10 07:00:00 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll

< MD5 for: NETLOGON.DLL >
[2008/04/13 19:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 19:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\netlogon.dll
[2009/02/06 13:46:09 | 000,408,064 | —- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 – C:\WINDOWS\SoftwareDistribution\Download\78cf8552430e25a8f24bc1e4dfb1970e\sp2qfe\netlogon.dll
[2009/02/06 13:46:09 | 000,408,064 | —- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 – C:\WINDOWS\SoftwareDistribution\Download\de81b460c3abcfc5b8494c785a5f3944\sp2qfe\netlogon.dll
[2004/08/10 07:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll

< MD5 for: SCECLI.DLL >
[2004/08/10 07:00:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/13 19:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 19:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\scecli.dll

< %systemroot%\*. /mp /s >
< End of report >




OTL Extras logfile created on: 5/20/2010 8:59:30 AM - Run 1
OTL by OldTimer - Version 3.2.5.0 Folder = C:\Documents and Settings\HP_Administrator\My Documents\My Downloads
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 66.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 82.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 179.33 Gb Total Space | 15.13 Gb Free Space | 8.44% Space Free | Partition Type: NTFS
Drive D: | 6.96 Gb Total Space | 1.07 Gb Free Space | 15.43% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive L: | 279.45 Gb Total Space | 42.64 Gb Free Space | 15.26% Space Free | Partition Type: NTFS

Computer Name: YOUR-55E5F9E3D2
Current User Name: HP_Administrator
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%ProgramFiles%\iTunes\iTunes.exe" = %ProgramFiles%\iTunes\iTunes.exe:*:enabled:iTunes – (Apple Computer, Inc.)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Computer, Inc.)
"C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe" = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe:*:Enabled:BackWeb for Pavilion – (Hewlett-Packard)
"C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" = C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink – File not found
"C:\Program Files\iolo\System Mechanic Professional\SysMech.exe" = C:\Program Files\iolo\System Mechanic Professional\SysMech.exe:*:Enabled:iolo System Shield® – ()
"C:\Program Files\iolo\Personal Firewall\ioloFW.exe" = C:\Program Files\iolo\Personal Firewall\ioloFW.exe:*:Enabled:iolo Firewall® – ()


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0C66761E-497A-4BE3-AE0D-8EC30FC9A9AA}" = PC-Doctor for Windows
"{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}" = Microsoft Plus! Photo Story 2 LE
"{14589F05-C658-4594-9429-D437BA688686}" = IntelliMover Data Transfer Demo
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1A103D70-5C9B-4E1A-B306-5106C68F9914}" = Microsoft Plus! Dancer LE
"{1AD5F465-8282-4DAD-B957-E09C0B783D18}" = InstantShare
"{1CF7A444-BEDA-4980-B493-01528F888A8A}" = 21_22_Trb
"{1F63ED0B-EDD2-4037-B6AB-1358C624AF48}" = Scan
"{20FBC0A0-3160-4F14-83ED-3A74BB6B8C31}" = TrayApp
"{21E75254-410E-49C4-8981-2E1A2A2221F2}" = HP Diagnostic Assistant
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{267868CE-6DFF-40F7-9C58-C01119B7B117}" = Fax
"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java™ 6 Update 20
"{272EC8BA-5A08-4ea1-A189-684466A06B02}" = cp_dwShrek2Albums1
"{28CFF19D-B92C-4109-A427-F75505E81688}" = cp_dwSharkTaleAlbums1
"{2C907EF5-FCC6-47A6-8AF7-7A059AAC3D5C}" = 2200_Help
"{2E8428AD-6CD2-4031-916A-3CF9BBF2DEC9}" = Unload
"{2FCE4FC5-6930-40E7-A4F1-F862207424EF}" = InterVideo WinDVD Creator
"{30DBAD4A-BA6D-4F9D-8AB0-2F6C7B0612A4}" = AVSDK5
"{34A59AC3-6C5C-4A09-A7F5-369A37176C8A}" = AiOSoftware
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{36FCD82D-1CED-436d-B33C-874EEC666D68}" = cp_dwSharkTaleCards1
"{3762DB2D-71BD-421F-9E55-C74DA7DF4D07}" = CueTour
"{3AE681E0-4E8D-453F-950A-48534D3C0724}" = Copy
"{3AEF2F6C-F1D3-47CD-BF3B-A327F1FABE58}" = PSPrinters06
"{416D80BA-6F6D-4672-B7CF-F54DA2F80B44}" = Microsoft Works
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4C04DF1B-6A39-4299-9DD1-1FA60000266E}" = HP Photosmart Cameras 4.0
"{4F000DF2-F770-4C9E-A45A-5E9F9398547E}" = 2200Tour
"{55508A44-8225-47AB-9666-1F57A5B5CE2E}" = CP_PLSBusinessFlyers
"{597D73A8-5FDB-4bc1-9893-40B54459F1BC}" = ProductContext
"{5E8D588F-307C-4250-B622-26969027319A}" = PanoStandAlone
"{5EAB5A0E-26FC-484F-B3BD-3C2F3C7056AF}" = 2200
"{644D04A2-C682-4FD5-977D-03B804C4B9C5}" = CreativeProjects
"{646A65DD-23FC-418E-B9F0-E0500FB42CB1}" = PhotoGallery
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Sonic Express Labeler
"{68963635-14A4-48D9-B431-DF3A74D1AAE1}" = Destinations
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6ACC5F14-DE57-4AF3-82A8-49166A78C42C}" = HP Tunes
"{7148F0A8-6813-11D6-A77B-00B0D0142030}" = Java 2 Runtime Environment, SE v1.4.2_03
"{724517BD-1DE1-4986-BFCA-C1DFD379E3BC}" = cp_dwShrek2Cards1
"{725249C3-B94C-4141-8799-0D3BA43D0812}" = CameraDrivers
"{787D1A33-A97B-4245-87C0-7174609A540C}" = HP Update
"{7B98685A-4E21-4A4F-A2D6-DC557042BADA}" = HPIZplus450
"{8105684D-8CA6-440D-8F58-7E5FD67A499D}" = Easy Internet Sign-up
"{84CDF5A8-1D57-4B69-BAB6-1F11D8923375}" = SkinsHP1
"{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver
"{8D0C57BC-4942-4960-BB6D-142456D6F233}" = HP Image Zone for Media Center PC
"{90AD8C11-ED4A-4AE7-BB70-7740C452C999}" = Visual J# .NET Redistributable Package
"{91120409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Standard Edition 2003
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD Player
"{9541FED0-327F-4DF0-8B96-EF57EF622F19}" = Sonic RecordNow!
"{9941F0AA-B903-4AF4-A055-83A9815CC011}" = Sonic Encoders
"{9CB2512B-3EC4-43DF-8002-46BDAB5EDD1B}" = QuickProjects
"{9EEBF8D5-8712-4D1D-88F4-4CDC2D270BC3}" = PrintScreen
"{A1062847-0846-427A-92A1-BB8251A91E91}" = HP PSC & OfficeJet 4.0
"{A2500497-FD32-493e-B8E5-28D6728DBEF5}" = Readme
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A4EA3AB4-E78C-4286-96DF-26035507CE55}" = AiO_Scan
"{A5B9D22C-755A-4AC6-9904-875E80838BB6}" = CP_AtenaShokunin1Config
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}" = Photosmart 320,370,7400,8100,8400 Series
"{AB05F2C8-F608-403b-95E1-FD8ADFACD31E}" = Windows 7 Upgrade Advisor
"{AC76BA86-0000-0000-0000-6028747ADE01}" = Adobe Acrobat - Reader 6.0.2 Update
"{AC76BA86-7AD7-1033-7B44-A00000000001}" = Adobe Reader 6.0.1
"{B103C8A7-D1CC-4B1A-BD41-883F652E097D}" = muvee autoProducer 3.5 magicMoments - HPD
"{B32C75F2-7495-4D01-9431-C11E97D66F8C}" = DocProc
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B56D5B09-C4FB-4EA0-8EAD-7BC3E2715A2D}" = DocumentViewer
"{B911B811-BA3E-46D4-90F8-6F3338359651}" = Director
"{BBD3F66B-1180-4785-B679-3F91572CD3B4}_is1" = iolo technologies' System Mechanic Professional
"{BE20E2F5-1903-4AAE-B1AF-2046E586C925}" = iTunes
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C3F058C0-A21C-452D-8D99-95B1A45F417D}" = InterVideo DiscLabel
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Professional
"{CDFCF124-115F-4976-8BF4-08C89187A146}" = WebReg
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0420D64-8D33-4374-A2B2-9225C7925CA6}" = HP Image Zone Plus 4.5.3
"{D8E4A88B-E35A-4F3B-AB60-42E7DB0EC765}" = muvee autoProducer unPlugged - HPD
"{DB518BA6-CB74-4EB6-9ABD-880B6D6E1F38}" = HpSdpAppCoreApp
"{E0343A4C-2FFD-4CCB-B0EB-5DE9F0E2A083}" = LS_HSI
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{EC8673DA-F96B-497E-B2DB-BC7B029FD680}" = BufferChm
"{F419D20A-7719-4639-8E30-C073A040D878}" = HP Deskjet Preloaded Printer Drivers
"{FC22D020-3005-4715-8DF9-F3EDE81DEB3D}" = CreativeProjectsTemplates
"0C20CAB1-F8BC-4AC1-A796-535B005C1B83" = Super Granny from HP Media Center (remove only)
"0C84A7C5-2762-4932-96BF-44A77202DCC3" = Blasterball 2 Remix from HP Media Center (remove only)
"12133444-BF36-4d4e-B7FB-A3424C645DE4" = GemMaster Mystic
"1FFA88DF-0AC3-4D9E-9139-5FF98813C12C" = Polar Bowler from HP Media Center (remove only)
"24E45CE4-1683-4B71-B8AD-8D7B0A209088" = Orbital from HP Media Center (remove only)
"3D61540E-C88C-4358-B6A1-DC26648F2A3D" = Crystal Maze from HP Media Center (remove only)
"55275778-F7D9-4BA0-95F4-DEFD71ADDFD9" = Polar Golfer from HP Media Center (remove only)
"581538B9-2ED3-45E2-96CB-22AD8F811D2A" = Shrek 2 Ogre Bowler from HP Media Center (remove only)
"5DAA9E44-1B31-41CD-88A8-228EDED6E36E" = Bounce Symphony from HP Media Center (remove only)
"758619C0-7C97-42BB-B1E9-775F72FDAD1E" = Blackhawk Striker 2 from HP Media Center (remove only)
"7D048B8F-76EB-4BFA-9629-2A5881C9F7A3" = Road Ready Streetwise from HP Media Center (remove only)
"A8B63E91-BB8C-41FF-B530-5BB13C915612" = Overball from HP Media Center (remove only)
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Agere Systems Soft Modem" = Agere Systems PCI Soft Modem
"B3EE3001-DC24-4cd1-8743-5692C716659F" = Otto
"B3FF79F4-CDA8-4845-A7C0-9CE017719F36" = Tradewinds from HP Media Center (remove only)
"BackWeb-309731 Uninstaller" = Updates from HP
"BBD3F66B-1180-4785-B679-3F91572CD3B4_is1" = iolo Personal Firewall
"Carbonite Backup" = Carbonite
"Coupon Printer for Windows5.0.0.0" = Coupon Printer for Windows
"D2DACBCD-E1FE-4C32-A49B-1EB0743D1E79" = Blasterball 2 from HP Media Center (remove only)
"Help and Support Additions" = Help and Support Additions
"HijackThis" = HijackThis 2.0.2
"HP Photo & Imaging" = HP Image Zone 4.5.3
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"InstallShield_{0C66761E-497A-4BE3-AE0D-8EC30FC9A9AA}" = PC-Doctor for Windows
"InstallShield_{8105684D-8CA6-440D-8F58-7E5FD67A499D}" = Easy Internet Sign-up
"InstallShield_{BE20E2F5-1903-4AAE-B1AF-2046E586C925}" = iTunes
"Jeff Gordon Screensaver Screensaver" = Jeff Gordon Screensaver Screensaver
"JGScreensaver 2 Screensaver" = JGScreensaver 2 Screensaver
"JGScreensaver4 Screensaver" = JGScreensaver4 Screensaver
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.3)" = Mozilla Firefox (3.6.3)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Ogg Codecs" = Ogg Codecs 0.81.15562
"PS2" = PS2
"Python 2.2.3" = Python 2.2.3
"pywin32-py2.2" = Python 2.2 pywin32 extensions (build 203)
"QuickTime" = QuickTime
"RealPlayer 6.0" = RealPlayer
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"WYO Home Inventory" = WYO Home Inventory 4.12

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Octoshape Streaming Services" = Octoshape Streaming Services

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 5/18/2010 9:49:58 PM | Computer Name = YOUR-55E5F9E3D2 | Source = Application Error | ID = 1000
Description = Faulting application sysmech.exe, version 9.5.8.2, faulting module
unknown, version 0.0.0.0, fault address 0x10001263.

Error - 5/18/2010 9:50:01 PM | Computer Name = YOUR-55E5F9E3D2 | Source = Application Error | ID = 1001
Description = Fault bucket 1833362114.

Error - 5/18/2010 9:50:08 PM | Computer Name = YOUR-55E5F9E3D2 | Source = Application Error | ID = 1000
Description = Faulting application sysmech.exe, version 9.5.8.2, faulting module
kernel32.dll, version 5.1.2600.5781, fault address 0x00012afb.

Error - 5/18/2010 9:50:11 PM | Computer Name = YOUR-55E5F9E3D2 | Source = Application Error | ID = 1001
Description = Fault bucket 1833545160.

Error - 5/19/2010 2:09:26 AM | Computer Name = YOUR-55E5F9E3D2 | Source = Media Center Extender Services | ID = 36864
Description = ERROR: Device Service Initialization - Unable to create or initialize
Device Table. Error code 0x80004005.

Error - 5/19/2010 3:35:42 PM | Computer Name = YOUR-55E5F9E3D2 | Source = Media Center Scheduler | ID = 0
Description =

Error - 5/19/2010 4:31:47 PM | Computer Name = YOUR-55E5F9E3D2 | Source = VSS | ID = 5013
Description = Volume Shadow Copy Service error: Shadow Copy writer RemovableStorageManager
called routine OpenNtmsSessionW which failed with status 0x80070015 (converted
to 0x800423f3).

Error - 5/19/2010 5:45:14 PM | Computer Name = YOUR-55E5F9E3D2 | Source = Google Update | ID = 20
Description =

Error - 5/19/2010 6:45:14 PM | Computer Name = YOUR-55E5F9E3D2 | Source = Google Update | ID = 20
Description =

Error - 5/19/2010 7:45:14 PM | Computer Name = YOUR-55E5F9E3D2 | Source = Google Update | ID = 20
Description =

[ System Events ]
Error - 5/16/2010 1:11:24 PM | Computer Name = YOUR-55E5F9E3D2 | Source = VolSnap | ID = 393228
Description = The shadow copy of volume C: became low on diff area space before
it was properly installed.

Error - 5/17/2010 11:03:20 PM | Computer Name = YOUR-55E5F9E3D2 | Source = DCOM | ID = 10010
Description = The server {0002DF01-0000-0000-C000-000000000046} did not register
with DCOM within the required timeout.

Error - 5/18/2010 6:03:55 AM | Computer Name = YOUR-55E5F9E3D2 | Source = DCOM | ID = 10010
Description = The server {0002DF01-0000-0000-C000-000000000046} did not register
with DCOM within the required timeout.

Error - 5/18/2010 8:13:15 PM | Computer Name = YOUR-55E5F9E3D2 | Source = DCOM | ID = 10010
Description = The server {0002DF01-0000-0000-C000-000000000046} did not register
with DCOM within the required timeout.

Error - 5/19/2010 2:09:18 AM | Computer Name = YOUR-55E5F9E3D2 | Source = NETLOGON | ID = 3095
Description = This computer is configured as a member of a workgroup, not as a member
of a domain. The Netlogon service does not need to run in this configuration.

Error - 5/19/2010 2:09:27 AM | Computer Name = YOUR-55E5F9E3D2 | Source = Service Control Manager | ID = 7024
Description = The Media Center Extender Service service terminated with service-specific
error 2147500037 (0x80004005).

Error - 5/19/2010 11:07:57 PM | Computer Name = YOUR-55E5F9E3D2 | Source = NETLOGON | ID = 3095
Description = This computer is configured as a member of a workgroup, not as a member
of a domain. The Netlogon service does not need to run in this configuration.

Error - 5/19/2010 11:08:07 PM | Computer Name = YOUR-55E5F9E3D2 | Source = Service Control Manager | ID = 7024
Description = The Media Center Extender Service service terminated with service-specific
error 2147500037 (0x80004005).

Error - 5/20/2010 6:42:25 AM | Computer Name = YOUR-55E5F9E3D2 | Source = W32Time | ID = 39452689
Description = Time Provider NtpClient: An error occurred during DNS lookup of the
manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup
again in 15 minutes. The error was: A socket operation was attempted to an unreachable
host. (0x80072751)

Error - 5/20/2010 6:42:25 AM | Computer Name = YOUR-55E5F9E3D2 | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 14 minutes. NtpClient has no source of accurate
time.


< End of report >
Hi, Please uninstall AVSDK5 through Add/Remove Programs. You missed the Gmer step, please run it and post the logfile.
Hi Tom, Yesterday was not a good day. I tried to run the GMER program and my computer kept rebooting by itself (5 times). Then I discovered that I still had the internet hooked up so I disconnected that and then ran GMER and my computer rebooted by itself after 45 minutes, even as the program was collecting quite a few items, I tried it again and the computer rebooted exactly at 45 minutes again. So I had planned on giving up and send you a note about this situation. I tried for over two hours to hookup to the internet. My computer could not find the server. Then my computer started REALLY acting up. i.e. programs not responding on just about everything, hang ups, screen freezing and etc. I was so frustrated that I called a computer technician and he came out this late this morning. After a couple of hours, EVERYTHING is working just fine. All is now well with the world, so to speak. He removed a number of things, checked and unchecked items, uninstalled and installed apps and fixed my internet connection so it could find my server. Now my computer is back to its normal operation. No problems at all. So…. I wanted to let you know what has transpired and that I deeply appreciated all your help. It looks like we won't have to do anymore stuff for my computer. Perhaps, next time you'll be able to help me with any future problems. I plan on keeping in touch with this site as I think what the members are doing is very helpful to people like me. Again, thank you very much. An internet friend, Richard

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI