This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Computer Freezes after IE opens and starts opening random windows

25 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello once again to you fine folk at Tom Coyote!

My desktop has been havng several issues over past several months, and just lst month I decided to do a full system restoe after other attempts to fix the corrupt files failed. The compter was running fine for a bit, but then IE woul cease to function, or it would open random windows to random sites while browsing.

I've run OTL, DDS and HJT; you can see the logs below.

I would greatly appreciate somehelp in solving the issue.

OTL Log:
OTL logfile created on: 1/2/2011 2:24:08 PM - Run 1
OTL by OldTimer - Version 3.2.20.1 Folder = C:\Documents and Settings\HP_Administrator\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

503.00 Mb Total Physical Memory | 169.00 Mb Available Physical Memory | 34.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 72.00% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 178.29 Gb Total Space | 153.67 Gb Free Space | 86.19% Space Free | Partition Type: NTFS
Drive D: | 8.00 Gb Total Space | 0.90 Gb Free Space | 11.24% Space Free | Partition Type: FAT32

Computer Name: GFERGUSON | User Name: HP_Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\HP_Administrator\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe (Hewlett-Packard)
PRC - C:\WINDOWS\ALCWZRD.EXE (RealTek Semicoductor Corp.)
PRC - C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
PRC - C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.)
PRC - C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe (Hewlett-Packard Company)
PRC - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe (Symantec Corporation)
PRC - C:\Program Files\NETGEAR\MA111 Configuration Utility\wlancfg4.exe ()


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\HP_Administrator\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\eziborovomasiv.dll ()
MOD - C:\WINDOWS\system32\ddraw.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\dciman32.dll (Microsoft Corporation)
MOD - C:\Documents and Settings\HP_Administrator\Local Settings\Temp\IadHide5.dll (BackWeb)


========== Win32 Services (SafeList) ==========

SRV - (nosGetPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper_3004.dll File not found
SRV - (HidServ) – C:\WINDOWS\System32\hidserv.dll File not found
SRV - (6to4) – C:\WINDOWS\system32\6to4v32.dll ()
SRV - (McComponentHostService) – C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (SymWSC) – c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe (Symantec Corporation)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)


========== Driver Services (SafeList) ==========

DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (ftsata2) – C:\WINDOWS\system32\DRIVERS\ftsata2.sys (Promise Technology, Inc.)
DRV - (iaStor) – C:\WINDOWS\system32\DRIVERS\iaStor.sys (Intel Corporation)
DRV - (RTL8023xp) – C:\WINDOWS\system32\drivers\Rtlnicxp.sys (Realtek Semiconductor Corporation )
DRV - (HdAudAddService) – C:\WINDOWS\system32\drivers\Hdaudio.sys (Windows ® Server 2003 DDK provider)
DRV - (HSFHWBS2) – C:\WINDOWS\system32\drivers\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) – C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (ltmodem5) – C:\WINDOWS\system32\drivers\ltmdmnt.sys (LT)
DRV - (rtl8139) Realtek RTL8139(A/B/C) – C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)
DRV - (bb-run) – C:\WINDOWS\system32\DRIVERS\bb-run.sys (Promise Technology, Inc.)
DRV - (Ps2) – C:\WINDOWS\system32\drivers\PS2.sys (Hewlett-Packard Company)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…arm1=seconduser

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…arm1=seconduser
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…arm1=seconduser
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…arm1=seconduser
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com/?pc=Z007&form=ZGAPHP
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://cnn.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\software\mozilla\Firefox\extensions\\{B283FB04-2444-407B-B462-E2A89D0466BE}: C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\{B283FB04-2444-407B-B462-E2A89D0466BE} [2010/12/01 07:34:51 | 000,000,000 | —D | M]


O1 HOSTS File: ([2004/08/10 19:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O4 - HKLM..\Run: [High Definition Audio Property Page Shortcut] C:\WINDOWS\System32\HdAShCut.exe (Windows ® Server 2003 DDK provider)
O4 - HKLM..\Run: [HPBootOp] C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe (Hewlett-Packard)
O4 - HKLM..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\LSBurnWatcher.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [PCDrProfiler] File not found
O4 - HKLM..\Run: [Rluhoy] C:\WINDOWS\eziborovomasiv.DLL ()
O4 - HKLM..\Run: [SSC_UserPrompt] c:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe (Symantec Corporation)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [Osoturej] C:\WINDOWS\lgmflbc.DLL ()
O4 - HKCU..\Run: [skypedllxx.exe] C:\skypedllxx.exe\skypedllxx.exe (Scwm2)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe (Autodesk, Inc)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\MA111 Configuration Utility.lnk = C:\Program Files\NETGEAR\MA111 Configuration Utility\wlancfg.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Updates from HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe (Hewlett-Packard)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &Google Search - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Backward Links - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Cached Snapshot of Page - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Similar Pages - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Translate into English - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O9 - Extra Button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ()
O9 - Extra 'Tools' menuitem : Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ()
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/09/16 23:04:28 | 000,000,100 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2001/07/28 05:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O32 - AutoRun File - [2004/04/30 21:01:14 | 000,000,053 | -HS- | M] () - D:\Autorun.inf – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - C:\WINDOWS\system32\6to4v32.dll ()
NetSvcs: HidServ - C:\WINDOWS\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.LEAD - C:\WINDOWS\System32\LCodcCMP.dll (LEAD Technologies, Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (69819404975603712)

========== Files/Folders - Created Within 30 Days ==========

[2011/01/02 14:19:40 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Documents and Settings\HP_Administrator\Desktop\OTL.exe
[2011/01/02 14:19:10 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\HP_Administrator\Desktop\HiJackThis.exe
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\HP_Administrator\My Documents\*.tmp files -> C:\Documents and Settings\HP_Administrator\My Documents\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/01/02 14:30:00 | 000,000,444 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{3510D38C-31BB-4DF7-8E98-02CA6F10487A}.job
[2011/01/02 14:29:46 | 000,760,320 | —- | M] () – C:\WINDOWS\System32\drivers\ffcbj.sys
[2011/01/02 14:29:00 | 000,000,366 | —- | M] () – C:\WINDOWS\tasks\Symantec NetDetect.job
[2011/01/02 14:22:44 | 000,000,248 | —- | M] () – C:\WINDOWS\System\hpsysdrv.dat
[2011/01/02 14:19:42 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\HP_Administrator\Desktop\OTL.exe
[2011/01/02 14:19:29 | 000,359,929 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\dds.scr
[2011/01/02 14:19:11 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\HP_Administrator\Desktop\HiJackThis.exe
[2011/01/02 14:17:55 | 000,000,000 | —- | M] () – C:\WINDOWS\Lvosiwedok.bin
[2011/01/02 14:15:16 | 000,000,902 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/01/02 14:15:01 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/01/02 14:14:47 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/01/02 14:14:41 | 527,814,656 | -HS- | M] () – C:\hiberfil.sys
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\HP_Administrator\My Documents\*.tmp files -> C:\Documents and Settings\HP_Administrator\My Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/01/02 14:19:28 | 000,359,929 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\dds.scr
[2010/12/01 07:57:09 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\6to4v32.dll
[2010/12/01 07:28:36 | 000,760,320 | —- | C] () – C:\WINDOWS\System32\drivers\ffcbj.sys
[2010/11/30 12:13:19 | 000,030,000 | —- | C] () – C:\WINDOWS\System32\tayznwhx7.dll
[2010/11/30 12:13:17 | 000,030,000 | —- | C] () – C:\WINDOWS\System32\out5u796bm.dll
[2010/09/26 13:49:35 | 000,000,139 | —- | C] () – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\fusioncache.dat
[2010/09/26 10:59:52 | 000,000,000 | —- | C] () – C:\Documents and Settings\HP_Administrator\Application Data\wklnhst.dat
[2009/12/18 18:05:01 | 000,000,008 | —- | C] () – C:\Documents and Settings\All Users\Application Data\sysReserve.ini
[2009/10/06 08:19:47 | 000,000,477 | —- | C] () – C:\Documents and Settings\HP_Administrator\Application Data\Hewlett-PackardHP PSC 1400 series1148959385_PROTOCOL.log
[2009/10/06 08:19:47 | 000,000,000 | —- | C] () – C:\Documents and Settings\HP_Administrator\Application Data\Hewlett-PackardHP PSC 1400 series1148959385_API.log
[2009/10/06 08:19:46 | 000,000,658 | —- | C] () – C:\Documents and Settings\HP_Administrator\Application Data\Hewlett-PackardHP PSC 1400 series1148959385_UI.log
[2009/10/06 08:19:46 | 000,000,221 | —- | C] () – C:\WINDOWS\NCLogConfig.ini
[2009/07/31 21:15:22 | 000,000,022 | —- | C] () – C:\WINDOWS\kodakpcd.HP_Administrator.ini
[2008/04/21 19:24:15 | 000,000,032 | —- | C] () – C:\Documents and Settings\All Users\Application Data\ezsid.dat
[2006/09/10 19:19:19 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2006/06/01 20:20:30 | 000,006,144 | —- | C] () – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005/09/16 23:33:24 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/09/16 23:07:50 | 000,014,289 | —- | C] () – C:\WINDOWS\System32\CHODDI.SYS
[2005/09/16 23:07:43 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\hpreg.dll
[2005/09/16 23:05:16 | 000,000,180 | —- | C] () – C:\WINDOWS\Quicken.ini
[2005/09/16 23:00:26 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/09/16 22:54:40 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2005/09/16 22:54:40 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2005/09/16 22:54:40 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2005/09/16 22:54:40 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2005/09/16 22:54:40 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2005/09/16 22:54:40 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2005/09/16 22:46:25 | 000,000,059 | —- | C] () – C:\WINDOWS\WININIT.INI
[2005/09/16 22:32:13 | 000,002,811 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2005/09/16 22:31:19 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2005/09/16 22:15:03 | 000,000,036 | —- | C] () – C:\WINDOWS\wwwbatch.ini
[2005/09/16 22:11:31 | 000,000,791 | —- | C] () – C:\WINDOWS\orun32.ini
[2005/09/16 22:07:27 | 000,323,584 | —- | C] () – C:\WINDOWS\System32\pythoncom22.dll
[2005/09/16 22:07:27 | 000,094,208 | —- | C] () – C:\WINDOWS\System32\pywintypes22.dll
[2005/09/16 22:07:02 | 000,016,896 | —- | C] () – C:\WINDOWS\System32\bcbmm.dll
[2005/07/07 13:07:24 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2005/05/09 23:52:32 | 000,022,396 | —- | C] () – C:\WINDOWS\System32\drivers\USBkey.sys
[2004/11/17 04:32:20 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2004/08/10 12:00:00 | 000,188,928 | —- | C] () – C:\WINDOWS\eziborovomasiv.dll
[2004/08/10 12:00:00 | 000,087,040 | —- | C] () – C:\WINDOWS\lgmflbc.dll
[2004/07/26 22:51:38 | 000,000,560 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2003/01/07 22:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2001/07/06 22:30:00 | 000,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini

========== LOP Check ==========

[2010/09/26 10:12:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Autodesk
[2007/08/15 20:42:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2008/02/19 20:47:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2007/10/21 15:01:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2011/01/02 14:30:00 | 000,000,444 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{3510D38C-31BB-4DF7-8E98-02CA6F10487A}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2005/09/16 23:04:28 | 000,000,100 | —- | M] () – C:\AUTOEXEC.BAT
[2010/09/26 13:46:09 | 000,000,211 | RHS- | M] () – C:\BOOT.BAK
[2010/09/26 14:18:53 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2004/08/10 05:00:00 | 000,260,272 | RHS- | M] () – C:\cmldr
[2004/11/17 04:32:46 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2006/04/25 16:37:06 | 000,002,498 | —- | M] () – C:\FINAL.BAT
[2011/01/02 14:14:41 | 527,814,656 | -HS- | M] () – C:\hiberfil.sys
[2010/08/22 18:04:29 | 000,025,311 | —- | M] () – C:\hpcmerr.log
[2004/11/17 04:32:46 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2007/10/21 15:02:06 | 000,000,542 | -H– | M] () – C:\IPH.PH
[2008/04/20 15:05:44 | 000,000,090 | —- | M] () – C:\LogiSetup.log
[2008/04/20 20:59:49 | 000,010,583 | —- | M] () – C:\lvcoinst.log
[2004/11/17 04:32:46 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/10 05:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2010/09/26 18:15:22 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/01/02 14:14:39 | 792,723,456 | -HS- | M] () – C:\pagefile.sys
[2006/05/08 16:33:10 | 045,454,728 | —- | M] (Hewlett Packard ) – C:\PCDR54060.exe
[2008/02/20 22:29:17 | 000,002,804 | —- | M] () – C:\rapport-after.txt
[2008/02/20 22:27:07 | 000,002,804 | —- | M] () – C:\rapport.txt
[2007/07/06 07:33:26 | 000,001,753 | —- | M] () – C:\rollback.ini
[2010/09/25 20:21:20 | 000,000,512 | —- | M] () – C:\ScanSectorLog.dat
[2008/06/22 15:06:25 | 000,034,930 | —- | M] () – C:\VETlog.dmp
[2008/06/22 15:06:25 | 000,142,347 | —- | M] () – C:\VETlog.txt

< %systemroot%\Fonts\*.com >

< %systemroot%\Fonts\*.dll >
[2005/05/12 06:36:48 | 000,012,288 | —- | M] (Hewlett-Packard Co.) – C:\WINDOWS\Fonts\RandFont.dll

< %systemroot%\Fonts\*.ini >
[2004/11/17 04:31:48 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2003/06/19 00:31:48 | 000,018,944 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2004/11/16 20:20:24 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2004/11/16 20:20:24 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2004/11/16 20:20:24 | 000,876,544 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2010/09/26 18:26:04 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2007/01/02 21:23:39 | 000,000,170 | -HS- | M] () – C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2004/11/17 04:37:56 | 000,000,079 | —- | M] () – C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2011/01/02 14:19:11 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\HP_Administrator\Desktop\HiJackThis.exe
[2008/05/24 15:40:29 | 001,649,976 | —- | M] (Malwarebytes ) – C:\Documents and Settings\HP_Administrator\Desktop\mbam-setup.exe
[2011/01/02 14:19:42 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\HP_Administrator\Desktop\OTL.exe
[2009/07/15 11:19:18 | 016,409,960 | —- | M] (Safer Networking Limited ) – C:\Documents and Settings\HP_Administrator\Desktop\setup-spybotsd162.exe
[2008/11/19 20:22:17 | 000,266,128 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\zapSetup_en.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-11-13 10:01:54

< >

========== Alternate Data Streams ==========

@Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A11F741D

< End of report >


OTL EXTRAS:
OTL Extras logfile created on: 1/2/2011 2:24:08 PM - Run 1
OTL by OldTimer - Version 3.2.20.1 Folder = C:\Documents and Settings\HP_Administrator\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

503.00 Mb Total Physical Memory | 169.00 Mb Available Physical Memory | 34.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 72.00% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 178.29 Gb Total Space | 153.67 Gb Free Space | 86.19% Space Free | Partition Type: NTFS
Drive D: | 8.00 Gb Total Space | 0.90 Gb Free Space | 11.24% Space Free | Partition Type: FAT32

Computer Name: GFERGUSON | User Name: HP_Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%ProgramFiles%\iTunes\iTunes.exe" = %ProgramFiles%\iTunes\iTunes.exe:*:enabled:iTunes – (Apple Computer, Inc.)
"C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe" = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe:*:Enabled:Updates from HP – (Hewlett-Packard)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe" = C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe – ()
"C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe – ( )
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe – (Hewlett-Packard Co.)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Computer, Inc.)
"C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe" = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe:*:Enabled:Updates from HP – (Hewlett-Packard)
"C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" = C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink – File not found


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{03B1B42B-F6DE-41d9-8CFF-DC44E895C7A7}" = PhotoGallery
"{044146E4-A924-458A-9948-4B9C7C7D9321}" = LightScribe [removed]
"{0611BD4E-4FE4-4a62-B0C0-18A4CC463428}" = CP_Package_Variety1
"{075473F5-846A-448B-BCB3-104AA1760205}" = Sonic RecordNow Data
"{09984AEC-6B9F-4ca7-B78D-CB44D4771DA3}" = Destinations
"{0B33B738-AD79-4E32-90C5-E67BFB10BBFF}" = AiO_Scan
"{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}" = Microsoft Plus! Photo Story 2 LE
"{14589F05-C658-4594-9429-D437BA688686}" = IntelliMover Data Transfer Demo
"{172975EB-9465-4861-95B5-C7BB6D3DE62A}" = DocumentViewer
"{193DB24F-9A66-4896-8404-22D53EA89075}" = 1400_Help
"{1A103D70-5C9B-4E1A-B306-5106C68F9914}" = Microsoft Plus! Dancer LE
"{1C139D7D-9FEA-468d-A9C8-2A6E3BDE564A}" = CP_Package_Variety3
"{21657574-BD54-48A2-9450-EB03B2C7FC29}" = Sonic MyDVD Plus
"{21DB3D90-D816-4092-A260-CA3F6B55A6DD}" = Sonic_PrimoSDK
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{23A7B376-BBEC-4e76-BBD7-0F155E70D74B}" = CP_Panorama1Config
"{266959FA-0AEE-41D0-A88E-F1EAC10A7C14}" = 1400
"{26A24AE4-039D-4CA4-87B4-2F83216021FF}" = Java™ 6 Update 21
"{2C3D719A-92C7-4323-89CC-C937D0267B84}" = muvee autoProducer 4.0
"{2C5D07FB-31A2-4F2D-9FDA-0B24ACD42BD0}" = HP Deskjet Printer Preload
"{2CADCEAB-D5DA-44D6-B5FC-7DEE87AB3C0C}" = Unload
"{2DBE41DD-2129-4C65-A3D3-5647236A60F3}" = Quicken 2005
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
"{3076D235-59F2-448E-889F-D04F985B4CF1}" = HP Tunes
"{30C19FF2-7FBA-4d09-B9DE-1659977F64F6}" = TrayApp
"{3248F0A8-6813-11D6-A77B-00B0D0150000}" = J2SE Runtime Environment 5.0
"{32BDCCB8-9DC8-496d-9DB1-F77510775BDB}" = InstantShareDevices
"{33D6CC28-9F75-4d1b-A11D-98895B3A3729}" = HP Photosmart 330,380,420,470,7800,8000,8200 Series
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{36E47DA1-10E1-45d9-8B19-14D19607CDCF}" = CP_CalendarTemplates1
"{3912A629-0020-0005-3757-2FBA74D4DF0A}" = InterVideo WinDVD Player
"{3BA95526-6AE0-4B87-A62D-17187EF565FC}" = HP Boot Optimizer
"{416D80BA-6F6D-4672-B7CF-F54DA2F80B44}" = Microsoft Works
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{503AA035-41E2-4858-B31F-1E49AC66C309}" = Norton Security Center
"{523E6F2A-2D59-4D91-90E8-6C49931C9F50}" = iTunes
"{54E3707F-808E-4fd4-95C9-15D1AB077E5D}" = NewCopy
"{56EE8B17-8274-418d-89AC-C057C5DB251E}" = RandMap
"{56F8AFC3-FA98-4ff1-9673-8A026CBF85BE}" = WebReg
"{5A01C58E-B0EC-49b9-AD71-7C0468688087}" = CP_Package_Basic1
"{5B79CFD1-6845-4158-9D7D-6BE89DF2C135}" = HP PSC & OfficeJet 5.3.B
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Sonic Express Labeler
"{66BA8C26-AFE4-4408-807B-43E76B57EF53}" = SkinsHP1
"{6BB6627C-694F-4FDC-A3E5-C7F4BED4C724}" = DocProc
"{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}" = Microsoft Plus! Digital Media Edition Installer
"{755EC5E3-FD51-46bd-A57F-7A2D56FBF061}" = PSTAPlugin
"{769A295C-DCF4-41d6-AFBA-7D9394B23AFE}" = PSPrinters08
"{7850A6D2-CBEA-4728-9877-F1BEDEA9F619}" = AiOSoftware
"{7C03270C-4FAB-4F5C-B10D-52FEDA190790}" = DocumentViewerQFolder
"{7C9B95B7-B598-4398-B30F-7F6827192E6C}" = ProductContext
"{7E27304E-BAA2-4d90-A34E-76641FAFABB4}" = CP_AtenaShokunin1Config
"{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver
"{8D0C57BC-4942-4960-BB6D-142456D6F233}" = HP Image Zone for Media Center PC
"{90110409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional
"{91120409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Standard Edition 2003
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD Player
"{923A7F5A-1E8C-4FBE-8DF6-85940A60A79F}" = Readme
"{9941F0AA-B903-4AF4-A055-83A9815CC011}" = Sonic Encoders
"{A195B13E-A5E3-4BAF-A995-7F70F445CD06}" = ScannerCopy
"{A3455242-DAE0-4523-8242-FD82706ABF4B}" = CameraDrivers
"{A5BB5365-EFB4-44c3-A7E2-EB59B7EFD23D}" = CueTour
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AB61A692-5543-4C48-979B-8CEA1C52FE9C}" = PC-Doctor 5 for Windows
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Sonic RecordNow Audio
"{AC76BA86-7AD7-1033-7B44-A70000000000}" = Adobe Reader 7.0
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Sonic RecordNow Copy
"{B1931B3A-29E9-4F91-9B61-BE2CF05E84F1}" = muvee autoProducer unPlugged 1.1 - HPD
"{B4D279F1-4309-49cc-A4B5-3A0D2E59C7B5}" = PanoStandAlone
"{B824B5C9-849F-4b9e-9EA7-6FD8CD8116DA}" = CP_Package_Variety2
"{B996AE66-10DB-4ac5-B151-E8B4BFBC42FC}" = BufferChm
"{BE9FEFBA-F2F8-468B-A108-4356F73A3E9C}" = Office 2003 Tour
"{C506A18C-1469-4678-B094-F4EC9DAE6DB7}" = Scan
"{C510CA36-98D6-4F07-8AFF-81E7399A075B}" = 1400Trb
"{C83A12B9-B31B-461A-BBD4-CE9B988094F1}" = HP Photosmart Cameras 5.0
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE24344F-DFD8-40C8-8FD8-C9740B5F25AC}" = Fax
"{D518592A-0F1E-40ca-BECB-3D3F026C6B0D}" = CameraDrivers
"{DB518BA6-CB74-4EB6-9ABD-880B6D6E1F38}" = HpSdpAppCoreApp
"{E3F90083-80D4-4b5a-87C7-E97E12F5516D}" = HPProductAssistant
"{EA103B64-C0E4-4C0E-A506-751590E1653D}" = SolutionCenter
"{ECFDD6BD-E0C0-41CC-A171-E6D6AF4C0E93}" = HP Software Update
"{F4C2E5F5-2970-45f4-ABD3-C180C4D961C4}" = Status
"{F80239D8-7811-4D5E-B033-0D0BBFE32920}" = HP DigitalMedia Archive
"12133444-BF36-4d4e-B7FB-A3424C645DE4" = GemMaster Mystic
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Photoshop Elements 2.0" = Adobe Photoshop Elements 2.0
"B3EE3001-DC24-4cd1-8743-5692C716659F" = Otto
"CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200C14F1" = Data Fax SoftModem with SmartCP
"Coupon Printer for Windows5.0.0.0" = Coupon Printer for Windows
"HP Document Viewer" = HP Document Viewer 5.3
"HP Imaging Device Functions" = HP Imaging Device Functions 5.3
"HP Photo & Imaging" = HP Image Zone 5.3
"HP Solution Center & Imaging Support Tools" = HP Solution Center & Imaging Support Tools 5.3
"HPOOVClient-9972322 Uninstaller" = Updates from HP (remove only)
"ie8" = Windows Internet Explorer 8
"InstallShield_{2DBE41DD-2129-4C65-A3D3-5647236A60F3}" = Quicken 2005
"InstallShield_{523E6F2A-2D59-4D91-90E8-6C49931C9F50}" = iTunes
"InstallShield_{AB61A692-5543-4C48-979B-8CEA1C52FE9C}" = PC-Doctor 5 for Windows
"McAfee Security Scan" = McAfee Security Scan Plus
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Money2005b" = Microsoft Money 2005
"PS2" = PS2
"Python 2.2.3" = Python 2.2.3
"pywin32-py2.2" = Python 2.2 pywin32 extensions (build 203)
"QuickTime" = QuickTime
"RealPlayer 6.0" = RealPlayer
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows XP Service Pack" = Windows XP Service Pack 3

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 10/24/2010 11:35:32 PM | Computer Name = GFERGUSON | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module mshtml.dll, version 8.0.6001.18975, fault address 0x000b9d78.

Error - 11/15/2010 5:09:34 PM | Computer Name = GFERGUSON | Source = Application Hang | ID = 1002
Description = Hanging application QuickTimePlayer.exe, version 6.5.2.10, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 11/30/2010 1:01:14 PM | Computer Name = GFERGUSON | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.5512, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x00023845.

Error - 11/30/2010 1:25:56 PM | Computer Name = GFERGUSON | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.5512, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x00023845.

Error - 12/1/2010 10:35:22 AM | Computer Name = GFERGUSON | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The connection with the server was terminated abnormally

Error - 12/1/2010 10:35:23 AM | Computer Name = GFERGUSON | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 12/1/2010 11:04:39 AM | Computer Name = GFERGUSON | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.5512, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x00023845.

Error - 12/5/2010 11:05:20 PM | Computer Name = GFERGUSON | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting
module eziborovomasiv.dll, version 0.0.0.0, fault address 0x000126de.

Error - 12/5/2010 11:05:49 PM | Computer Name = GFERGUSON | Source = EventSystem | ID = 4609
Description = The COM+ Event System detected a bad return code during its internal
processing. HRESULT was 8007041D from line 44 of d:\comxp_sp3\com\com1x\src\events\tier1\eventsystemobj.cpp.
Please contact Microsoft Product Support Services to report this erro

Error - 12/5/2010 11:08:49 PM | Computer Name = GFERGUSON | Source = EventSystem | ID = 4609
Description = The COM+ Event System detected a bad return code during its internal
processing. HRESULT was 8007041D from line 44 of d:\comxp_sp3\com\com1x\src\events\tier1\eventsystemobj.cpp.
Please contact Microsoft Product Support Services to report this erro

[ System Events ]
Error - 10/5/2010 11:16:22 PM | Computer Name = GFERGUSON | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.2.4 for the Network Card with network
address 0011D8C84A21 has been denied by the DHCP server 192.168.2.1 (The DHCP Server
sent a DHCPNACK message).

Error - 10/7/2010 10:01:15 PM | Computer Name = GFERGUSON | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.2.2 for the Network Card with network
address 0011D8C84A21 has been denied by the DHCP server 192.168.2.1 (The DHCP Server
sent a DHCPNACK message).

Error - 10/10/2010 4:55:57 PM | Computer Name = GFERGUSON | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the Netman service.

Error - 10/15/2010 4:01:46 PM | Computer Name = GFERGUSON | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.2.3 for the Network Card with network
address 0011D8C84A21 has been denied by the DHCP server 192.168.2.1 (The DHCP Server
sent a DHCPNACK message).

Error - 11/17/2010 5:07:51 PM | Computer Name = GFERGUSON | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.2.3 for the Network Card with network
address 0011D8C84A21 has been denied by the DHCP server 192.168.2.1 (The DHCP Server
sent a DHCPNACK message).

Error - 11/30/2010 1:05:18 PM | Computer Name = GFERGUSON | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.2.3 for the Network Card with network
address 0011D8C84A21 has been denied by the DHCP server 192.168.2.1 (The DHCP Server
sent a DHCPNACK message).


< End of report >
Hijack This Log:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 2:21:12 PM, on 1/2/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\NETGEAR\MA111 Configuration Utility\wlancfg4.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
c:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Documents and Settings\HP_Administrator\Desktop\HiJackThis.exe
C:\WINDOWS\ALCMTR.EXE
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…arm1=seconduser
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…arm1=seconduser
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…arm1=seconduser
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…arm1=seconduser
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com/?pc=Z007&form=ZGAPHP
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…arm1=seconduser
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…arm1=seconduser
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
O4 - HKLM\..\Run: [SSC_UserPrompt] c:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Rluhoy] rundll32.exe "C:\WINDOWS\eziborovomasiv.dll",Startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Osoturej] rundll32.exe "C:\WINDOWS\lgmflbc.dll",Startup
O4 - HKCU\..\Run: [skypedllxx.exe] C:\skypedllxx.exe\skypedllxx.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: MA111 Configuration Utility.lnk = C:\Program Files\NETGEAR\MA111 Configuration Utility\wlancfg.exe
O4 - Global Startup: McAfee Security Scan Plus.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

–
End of file - 9414 bytes
DDS: DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 14:37:11.04 on Sun 01/02/2011 Internet Explorer: 8.0.6001.18702 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.503.88 [GMT -7:00] ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch C:\WINDOWS\system32\svchost -k rpcss C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k NetworkService C:\WINDOWS\system32\svchost.exe -k LocalService C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\svchost.exe -k LocalService C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\ehome\ehtray.exe C:\WINDOWS\system32\igfxpers.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe C:\Program Files\HP\HP Software Update\HPwuSchd2.exe C:\Program Files\QuickTime\qttask.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\NETGEAR\MA111 Configuration Utility\wlancfg4.EXE C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE "C:\WINDOWS\System32\svchost.exe" "C:\WINDOWS\System32\svchost.exe" C:\WINDOWS\system32\svchost.exe -k imgsvc c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe c:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\System32\alg.exe C:\WINDOWS\eHome\ehmsas.exe C:\HP\KBD\KBD.EXE C:\WINDOWS\SOUNDMAN.EXE C:\WINDOWS\ALCMTR.EXE C:\WINDOWS\ALCWZRD.EXE C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Internet Explorer\IEXPLORE.EXE c:\windows\system\hpsysdrv.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\Common Files\Java\Java Update\jucheck.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\HP_Administrator\Desktop\dds.scr C:\WINDOWS\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uStart Page = hxxp://www.bing.com/?pc=Z007&form=ZGAPHP uSearch Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=pavilion&pf=desktop&parm1=seconduser uSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=pavilion&pf=desktop&parm1=seconduser uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q405&bd=pavilion&pf=desktop&parm1=seconduser uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=pavilion&pf=desktop&parm1=seconduser mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=pavilion&pf=desktop&parm1=seconduser uSearchURL,(Default) = hxxp://www.google.com/keyword/%s mSearchAssistant = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=pavilion&pf=desktop&parm1=seconduser BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar1.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar1.dll TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [Osoturej] rundll32.exe "c:\windows\lgmflbc.dll",Startup uRun: [skypedllxx.exe] c:\skypedllxx.exe\skypedllxx.exe mRun: [ehTray] c:\windows\ehome\ehtray.exe mRun: [High Definition Audio Property Page Shortcut] HDAShCut.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [HPHUPD08] c:\program files\hp\digital imaging\{33d6cc28-9f75-4d1b-a11d-98895b3a3729}\hphupd08.exe mRun: [PCDrProfiler] mRun: [SSC_UserPrompt] c:\program files\common files\symantec shared\security center\UsrPrmpt.exe mRun: [HPBootOp] "c:\program files\hewlett-packard\hp boot optimizer\HPBootOp.exe" /run mRun: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe mRun: [HP Software Update] c:\program files\hp\hp software update\HPwuSchd2.exe mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [Rluhoy] rundll32.exe "c:\windows\eziborovomasiv.dll",Startup StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\autoca~1.lnk - c:\program files\common files\autodesk shared\acstart16.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\ma111c~1.lnk - c:\program files\netgear\ma111 configuration utility\wlancfg.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\mcafee~1.lnk - c:\program files\mcafee security scan\2.0.181\SSScheduler.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\update~1.lnk - c:\program files\updates from hp\9972322\program\Updates from HP.exe IE: &Google Search - c:\program files\google\GoogleToolbar1.dll/cmsearch.html IE: Backward Links - c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html IE: Cached Snapshot of Page - c:\program files\google\GoogleToolbar1.dll/cmcache.html IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office10\EXCEL.EXE/3000 IE: Similar Pages - c:\program files\google\GoogleToolbar1.dll/cmsimilar.html IE: Translate into English - c:\program files\google\GoogleToolbar1.dll/cmtrans.html IE: {E2D4D26B-0180-43a4-B05F-462D6D54C789} - c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\iebutton\support.htm IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office11\REFIEBAR.DLL DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL Notify: igfxcui - igfxdev.dll ============= SERVICES / DRIVERS =============== S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\mcafee security scan\2.0.181\McCHSvc.exe [2010-1-15 227232] S3 nosGetPlusHelper;getPlus® Helper 3004;c:\windows\system32\svchost.exe -k nosGetPlusHelper [2004-8-10 14336] =============== Created Last 30 ================ ==================== Find3M ==================== 2011-01-02 14:37 760,320 a——- c:\windows\system32\drivers\ffcbj.sys 2010-12-01 07:57 53,248 a——- c:\windows\system32\6to4v32.dll 2010-11-30 12:13 760,320 a——- c:\windows\system32\drivers\knblxf.sys 2010-11-30 12:13 30,000 a——- c:\windows\system32\tayznwhx7.dll 2010-11-30 12:13 30,000 a——- c:\windows\system32\out5u796bm.dll 2010-11-01 13:21 50,664 a——- c:\docume~1\hp_adm~1\applic~1\GDIPFONTCACHEV1.DAT 2010-10-23 20:27 112,044 a——- c:\windows\hpoins07.dat 2010-09-26 10:59 0 a——- c:\docume~1\hp_adm~1\applic~1\wklnhst.dat 2008-04-21 19:24 32 a——- c:\docume~1\alluse~1\applic~1\ezsid.dat 2010-09-26 20:03 245,760 a–sh— c:\windows\system32\config\systemprofile\ietldcache\index.dat 2008-02-20 22:27 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008022020080221\index.dat ============= FINISH: 14:38:27.90 ===============
Hi bergferg, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

What are you using for an antivirus program?


Next, Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:OTL
O4 - HKLM..\Run: [Rluhoy] C:\WINDOWS\eziborovomasiv.DLL ()
O4 - HKCU..\Run: [Osoturej] C:\WINDOWS\lgmflbc.DLL ()
[2011/01/02 14:17:55 | 000,000,000 | —- | M] () – C:\WINDOWS\Lvosiwedok.bin
2010/11/30 12:13:19 | 000,030,000 | —- | C] () – C:\WINDOWS\System32\tayznwhx7.dll
[2010/11/30 12:13:17 | 000,030,000 | —- | C] () – C:\WINDOWS\System32\out5u796bm.dll
[2010/12/01 07:57:09 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\6to4v32.dll
[2010/12/01 07:28:36 | 000,760,320 | —- | C] () – C:\WINDOWS\System32\drivers\ffcbj.sys
O4 - HKCU\..\Run: [skypedllxx.exe] C:\skypedllxx.exe\skypedllxx.exe

:Commands
[emptytemp]
[createrestorepoint]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
Please post the OTL log.


Next

Go HERE to get a randomly named copy of GMER. Scroll down to the Download section and click Download EXE. Save it to your desktop.

Before scanning with GMER, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

  • Double click on the file you downloaded. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


If GMER will not run in normal windows, please run it in Safe Mode


Next

  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • UnCheck the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open a notepad windows. OTL.Txt, no Extra.txt this time.


Please post back with
  • OTL fix log
  • GMER log
  • new OTL.txt
How's the computer?

Thanks
Mr. Oldman,

I greatly appreciate you looking at this post, and for the direction you've provided so far.

It appears that when I did the system restore, I did not reinstall any firewall or AV programs, and I'm guessing that is how this occurred. My old software was out of date anyway(Zone Alarm).

Do you have any suggestions for good AV and firewall programs? Malware detction programs?

So, first off, the OTL Fix Log:
All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Rluhoy deleted successfully.
C:\WINDOWS\eziborovomasiv.dll moved successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Osoturej deleted successfully.
C:\WINDOWS\lgmflbc.dll moved successfully.
C:\WINDOWS\Lvosiwedok.bin moved successfully.
C:\WINDOWS\system32\out5u796bm.dll moved successfully.
C:\WINDOWS\system32\6to4v32.dll moved successfully.
C:\WINDOWS\System32\drivers\ffcbj.sys moved successfully.
Registry key HKEY_CURRENT_USER\\Software\Microsoft\Windows\CurrentVersion\Run not found.
File move failed. C:\skypedllxx.exe\skypedllxx.exe scheduled to be moved on reboot.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: HP_Administrator
->Temp folder emptied: 23301764 bytes
->Temporary Internet Files folder emptied: 24068120 bytes
->Java cache emptied: 830231 bytes
->Flash cache emptied: 1417867 bytes

User: LocalService
->Temp folder emptied: 65716 bytes
->Temporary Internet Files folder emptied: 1402654 bytes

User: NetworkService
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 43043598 bytes
->Flash cache emptied: 17609 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 39138 bytes
%systemroot%\System32 .tmp files removed: 2577 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 21440079 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 18714 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 110.00 mb

Unable to start service SrService!

OTL by OldTimer - Version 3.2.20.1 log created on 01032011_083617

Files\Folders moved on Reboot…
C:\skypedllxx.exe\skypedllxx.exe moved successfully.
File\Folder C:\Documents and Settings\HP_Administrator\Local Settings\Temp\Temporary Internet Files\Content.IE5\L5RLX79K\Type=click&FlightID=69403&AdID=93647&TargetID=913&Segments=730,2259,2743,3030,3285,3800,4635,4960,5855,6298,6520,6582,7215,733
3,8463,8796,9125,9276,9496,9505,9632,9742,9[2] not found!
File\Folder C:\Documents and Settings\HP_Administrator\Local Settings\Temp\Temporary Internet Files\Content.IE5\KKA7TCEW\Type=click&FlightID=68571&AdID=92049&TargetID=14665&Segments=730,2743,3030,3285,4960,6298,6520,6582,7333,8463,8796,8808,9496,977
9,9781,9784,9853,9958,10381&Targets=14665[1].htm not found!
C:\Documents and Settings\HP_Administrator\Local Settings\Temp\IadHide5.dll moved successfully.
File\Folder C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\YQGABIMR\bestofyoutube_mevio_com[1].txt not found!
File\Folder C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\YQGABIMR\jquery-1.4.2.min[1].js not found!
File\Folder C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\YQGABIMR\reset[1].css not found!
File\Folder C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\YQGABIMR\sync-min[1].htm not found!
File\Folder C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\MJIRQUVX\fw-nonplayer-banner[1].htm not found!
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\MJIRQUVX\Y7YCBKX-HZn[1].swf moved successfully.
File\Folder C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\GJCHJBRA\quant[2].js not found!
File\Folder C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\2OU4QN63\bizo[1].html not found!
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\2OU4QN63\fw-nonplayer-banner[1].htm moved successfully.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\2OU4QN63\home_facebook[1].css moved successfully.
File\Folder C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\2OU4QN63\jquery.cookie_1.0[1].js not found!
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\2OU4QN63\mycs-widget[1].js moved successfully.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\2OU4QN63\play-random-game[1].txt moved successfully.
File\Folder C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\2OU4QN63\pushup[1].css not found!
File\Folder C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\2OU4QN63\search[1].txt not found!
File\Folder C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\2OU4QN63\user_bar[1].js not found!
File\Folder C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\2OU4QN63\xd_receiver[1].htm not found!

Registry entries deleted on Reboot…

GMER Log:
GMER 1.0.15.15530 - http://www.gmer.net
Rootkit scan 2011-01-03 12:53:45
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdePort2 Maxtor_6L200M0 rev.BANC1G10
Running: rt6ye558.exe; Driver: C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\kftdipog.sys


—- User code sections - GMER 1.0.15 —-

.text C:\WINDOWS\System32\svchost.exe[936] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00CB000A
.text C:\WINDOWS\System32\svchost.exe[936] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00CC000A
.text C:\WINDOWS\System32\svchost.exe[936] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 00CA000C
.text C:\WINDOWS\System32\svchost.exe[936] ole32.dll!CoCreateInstance 774FF1AC 5 Bytes JMP 00D8000A
.text C:\WINDOWS\Explorer.EXE[1304] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00BD000A
.text C:\WINDOWS\Explorer.EXE[1304] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00BE000A
.text C:\WINDOWS\Explorer.EXE[1304] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 00B7000C
.text C:\WINDOWS\system32\wuauclt.exe[2008] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00E2000A
.text C:\WINDOWS\system32\wuauclt.exe[2008] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00E3000A
.text C:\WINDOWS\system32\wuauclt.exe[2008] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 00E1000C

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs bb-run.sys (Promise Disk Accelerator/Promise Technology, Inc.)

Device \Driver\atapi -> DriverStartIo \Device\Ide\IdeDeviceP0T0L0-3 82AE73B2
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort0 82AE73B2
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort1 82AE73B2
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort2 82AE73B2
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort3 82AE73B2

AttachedDevice \FileSystem\Fastfat \Fat bb-run.sys (Promise Disk Accelerator/Promise Technology, Inc.)

Device \Device\Ide\IdeDeviceP2T1L0-e -> \??\IDE#DiskMaxtor_6L200M0__________________________BANC1G10#344c51305635473320
2020202020202020202020#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found

—- Disk sectors - GMER 1.0.15 —-

Disk \Device\Harddisk0\DR0 sector 00 (MBR): rootkit-like behavior; TDL4 <– ROOTKIT !!!
Disk \Device\Harddisk0\DR0 sector 32: rootkit-like behavior;
Disk \Device\Harddisk0\DR0 sector 63: rootkit-like behavior;
Disk \Device\Harddisk0\DR0 sectors 390721712 (+255): rootkit-like behavior;

—- EOF - GMER 1.0.15 —-


New OTL Log:
OTL logfile created on: 1/3/2011 12:55:09 PM - Run 2
OTL by OldTimer - Version 3.2.20.1 Folder = C:\Documents and Settings\HP_Administrator\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

503.00 Mb Total Physical Memory | 110.00 Mb Available Physical Memory | 22.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 68.00% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 178.29 Gb Total Space | 155.99 Gb Free Space | 87.49% Space Free | Partition Type: NTFS
Drive D: | 8.00 Gb Total Space | 0.90 Gb Free Space | 11.24% Space Free | Partition Type: FAT32
Drive F: | 14.17 Mb Total Space | 13.66 Mb Free Space | 96.36% Space Free | Partition Type: FAT

Computer Name: GFERGUSON | User Name: HP_Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\WINDOWS\install .exe ()
PRC - C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe ()
PRC - C:\WINDOWS\wininst .exe ()
PRC - C:\WINDOWS\install .exe ()
PRC - C:\WINDOWS\wininst .exe ()
PRC - C:\WINDOWS\taskmgr .exe ()
PRC - C:\Program Files\QuickTime\qttask .exe ()
PRC - C:\WINDOWS\install .exe ()
PRC - C:\WINDOWS\hexdump .exe ()
PRC - C:\WINDOWS\drweb .exe ()
PRC - C:\WINDOWS\install .exe ()
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe ()
PRC - C:\WINDOWS\system32\HDAShCut.exe ()
PRC - C:\Documents and Settings\HP_Administrator\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe (Hewlett-Packard)
PRC - C:\Program Files\HP\HP Software Update\HPwuSchd2 .exe (Hewlett-Packard Co.)
PRC - C:\hp\drivers\hplsbwatcher\lsburnwatcher .exe (Hewlett-Packard Company)
PRC - C:\WINDOWS\ALCWZRD.EXE (RealTek Semicoductor Corp.)
PRC - C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
PRC - C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.)
PRC - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe (Symantec Corporation)
PRC - C:\Program Files\NETGEAR\MA111 Configuration Utility\wlancfg4.exe ()


========== Modules (SafeList) ==========

MOD - C:\WINDOWS\system32\gfbccb.dll ()
MOD - C:\Documents and Settings\HP_Administrator\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\wsock32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\opengl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\glu32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\ddraw.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\dciman32.dll (Microsoft Corporation)
MOD - C:\Documents and Settings\HP_Administrator\Local Settings\Temp\IadHide5.dll (BackWeb)


========== Win32 Services (SafeList) ==========

SRV - (nosGetPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper_3004.dll File not found
SRV - (HidServ) – C:\WINDOWS\System32\hidserv.dll File not found
SRV - (6to4) – C:\WINDOWS\System32\6to4v32.dll File not found
SRV - (McComponentHostService) – C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (SymWSC) – c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe (Symantec Corporation)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)


========== Driver Services (SafeList) ==========

DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (ftsata2) – C:\WINDOWS\system32\DRIVERS\ftsata2.sys (Promise Technology, Inc.)
DRV - (iaStor) – C:\WINDOWS\system32\DRIVERS\iaStor.sys (Intel Corporation)
DRV - (RTL8023xp) – C:\WINDOWS\system32\drivers\Rtlnicxp.sys (Realtek Semiconductor Corporation )
DRV - (HdAudAddService) – C:\WINDOWS\system32\drivers\Hdaudio.sys (Windows ® Server 2003 DDK provider)
DRV - (HSFHWBS2) – C:\WINDOWS\system32\drivers\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) – C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (ltmodem5) – C:\WINDOWS\system32\drivers\ltmdmnt.sys (LT)
DRV - (rtl8139) Realtek RTL8139(A/B/C) – C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)
DRV - (bb-run) – C:\WINDOWS\system32\DRIVERS\bb-run.sys (Promise Technology, Inc.)
DRV - (Ps2) – C:\WINDOWS\system32\drivers\PS2.sys (Hewlett-Packard Company)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…arm1=seconduser

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…arm1=seconduser
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…arm1=seconduser
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…arm1=seconduser
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com/?pc=ZUGO&form=ZGAPHP
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://cnn.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:8074

FF - HKLM\software\mozilla\Firefox\extensions\\{B283FB04-2444-407B-B462-E2A89D0466BE}: C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\{B283FB04-2444-407B-B462-E2A89D0466BE} [2010/12/01 07:34:51 | 000,000,000 | —D | M]


O1 HOSTS File: ([2004/08/10 19:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (C:\WINDOWS\system32\gfbccb.dll) - {B2B220C1-A503-59BD-F413-01B53A2C8953} - C:\WINDOWS\system32\gfbccb.dll ()
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Search Toolbar) - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files\Search Toolbar\SearchToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O4 - HKLM..\Run: [High Definition Audio Property Page Shortcut] C:\WINDOWS\System32\HDAShCut.exe ()
O4 - HKLM..\Run: [HNUOQOXRme] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\avp.exe File not found
O4 - HKLM..\Run: [HNUOQOXRnsc] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\drweb.exe File not found
O4 - HKLM..\Run: [HNUOQOXRoMc] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\gdi32.exe File not found
O4 - HKLM..\Run: [HNUOQOXRouqc] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\iexplarer.exe File not found
O4 - HKLM..\Run: [HNUOQOXRrrb] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\taskmgr.exe File not found
O4 - HKLM..\Run: [HNUOQOXRsPc] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\win16.exe File not found
O4 - HKLM..\Run: [HNUOQOXRsuO] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\xxfjrt0f.exe File not found
O4 - HKLM..\Run: [HPBootOp] C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe ()
O4 - HKLM..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe ()
O4 - HKLM..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe ()
O4 - HKLM..\Run: [MKas0] C:\WINDOWS\drweb .exe ()
O4 - HKLM..\Run: [MKasc] C:\WINDOWS\drweb.exe ()
O4 - HKLM..\Run: [MKasK] C:\WINDOWS\drweb .exe ()
O4 - HKLM..\Run: [MKbta] C:\WINDOWS\install.exe ()
O4 - HKLM..\Run: [MKbtala/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/533.9 (KHTML, like Gecko) Chrome/6.0.401.1 Safari/533.9] C:\WINDOWS\install.exe ()
O4 - HKLM..\Run: [MKbtc] C:\WINDOWS\hexdump.exe ()
O4 - HKLM..\Run: [MKbtG0] C:\WINDOWS\install .exe ()
O4 - HKLM..\Run: [MKbtGc] C:\WINDOWS\install .exe ()
O4 - HKLM..\Run: [MKbtGgc] C:\WINDOWS\install .exe ()
O4 - HKLM..\Run: [MKbtGgK] C:\WINDOWS\install .exe ()
O4 - HKLM..\Run: [MKbtGj] C:\WINDOWS\install .exe ()
O4 - HKLM..\Run: [MKbtHc] C:\WINDOWS\hexdump .exe ()
O4 - HKLM..\Run: [MKbtJ] C:\WINDOWS\install .exe ()
O4 - HKLM..\Run: [MKbtK] C:\WINDOWS\hexdump .exe ()
O4 - HKLM..\Run: [MKerb] C:\WINDOWS\taskmgr.exe ()
O4 - HKLM..\Run: [MKerGc] C:\WINDOWS\taskmgr .exe ()
O4 - HKLM..\Run: [MKerJ] C:\WINDOWS\taskmgr .exe ()
O4 - HKLM..\Run: [MKfre] C:\WINDOWS\wininst.exe ()
O4 - HKLM..\Run: [MKfrJc] C:\WINDOWS\wininst .exe ()
O4 - HKLM..\Run: [MKfrJK] C:\WINDOWS\wininst .exe ()
O4 - HKLM..\Run: [MKfrN] C:\WINDOWS\wininst .exe ()
O4 - HKLM..\Run: [PCDrProfiler] File not found
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask .exe ()
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe ()
O4 - HKLM..\Run: [uPc+MV0NbabJsiv] C:\WINDOWS\System32\vk1a6mgve.DLL ()
O4 - HKCU..\Run: [HNUOQOXRme] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\avp.exe File not found
O4 - HKCU..\Run: [HNUOQOXRnsc] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\drweb.exe File not found
O4 - HKCU..\Run: [HNUOQOXRoMc] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\gdi32.exe File not found
O4 - HKCU..\Run: [HNUOQOXRouqc] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\iexplarer.exe File not found
O4 - HKCU..\Run: [HNUOQOXRrrb] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\taskmgr.exe File not found
O4 - HKCU..\Run: [HNUOQOXRsPc] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\win16.exe File not found
O4 - HKCU..\Run: [HNUOQOXRsuO] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\xxfjrt0f.exe File not found
O4 - HKCU..\Run: [MKas0] C:\WINDOWS\drweb .exe ()
O4 - HKCU..\Run: [MKasc] C:\WINDOWS\drweb.exe ()
O4 - HKCU..\Run: [MKasK] C:\WINDOWS\drweb .exe ()
O4 - HKCU..\Run: [MKbta] C:\WINDOWS\install.exe ()
O4 - HKCU..\Run: [MKbtala/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/533.9 (KHTML, like Gecko) Chrome/6.0.401.1 Safari/533.9] C:\WINDOWS\install.exe ()
O4 - HKCU..\Run: [MKbtc] C:\WINDOWS\hexdump.exe ()
O4 - HKCU..\Run: [MKbtG0] C:\WINDOWS\install .exe ()
O4 - HKCU..\Run: [MKbtGc] C:\WINDOWS\install .exe ()
O4 - HKCU..\Run: [MKbtGgc] C:\WINDOWS\install .exe ()
O4 - HKCU..\Run: [MKbtGgK] C:\WINDOWS\install .exe ()
O4 - HKCU..\Run: [MKbtGj] C:\WINDOWS\install .exe ()
O4 - HKCU..\Run: [MKbtHc] C:\WINDOWS\hexdump .exe ()
O4 - HKCU..\Run: [MKbtJ] C:\WINDOWS\install .exe ()
O4 - HKCU..\Run: [MKbtK] C:\WINDOWS\hexdump .exe ()
O4 - HKCU..\Run: [MKerb] C:\WINDOWS\taskmgr.exe ()
O4 - HKCU..\Run: [MKerGc] C:\WINDOWS\taskmgr .exe ()
O4 - HKCU..\Run: [MKerJ] C:\WINDOWS\taskmgr .exe ()
O4 - HKCU..\Run: [MKfre] C:\WINDOWS\wininst.exe ()
O4 - HKCU..\Run: [MKfrJc] C:\WINDOWS\wininst .exe ()
O4 - HKCU..\Run: [MKfrJK] C:\WINDOWS\wininst .exe ()
O4 - HKCU..\Run: [MKfrN] C:\WINDOWS\wininst .exe ()
O4 - HKCU..\Run: [oqkifoik] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\teopgxwpq\lnhkxhylajb.exe File not found
O4 - HKCU..\Run: [Osoturej] C:\WINDOWS\lgmflbc.DLL File not found
O4 - HKCU..\Run: [skypedllxx.exe] C:\skypedllxx.exe\skypedllxx.exe File not found
O4 - HKCU..\Run: [uPc+MV0NbabJsiv] C:\WINDOWS\System32\vk1a6mgve.DLL ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe (Autodesk, Inc)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\MA111 Configuration Utility.lnk = C:\Program Files\NETGEAR\MA111 Configuration Utility\wlancfg.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Updates from HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe (Hewlett-Packard)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFolderOptions = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1
O8 - Extra context menu item: &Google Search - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Backward Links - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Cached Snapshot of Page - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Similar Pages - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Translate into English - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O9 - Extra Button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ()
O9 - Extra 'Tools' menuitem : Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ()
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O22 - SharedTaskScheduler: {B2B220C1-A503-59BD-F413-01B53A2C8953} - iwuiahf87sfy8ushfijsjgfgf - C:\WINDOWS\system32\gfbccb.dll ()
O24 - Desktop WallPaper: C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/09/16 23:04:28 | 000,000,100 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2001/07/28 05:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O32 - AutoRun File - [2004/04/30 21:01:14 | 000,000,053 | -HS- | M] () - D:\Autorun.inf – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/01/03 08:36:17 | 000,000,000 | —D | C] – C:\_OTL
[2011/01/02 14:59:43 | 000,000,000 | —D | C] – C:\Program Files\Search Toolbar
[2011/01/02 14:19:40 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Documents and Settings\HP_Administrator\Desktop\OTL.exe
[2011/01/02 14:19:10 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\HP_Administrator\Desktop\HiJackThis.exe
[1 C:\Documents and Settings\HP_Administrator\My Documents\*.tmp files -> C:\Documents and Settings\HP_Administrator\My Documents\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/01/03 12:59:01 | 000,000,366 | —- | M] () – C:\WINDOWS\tasks\Symantec NetDetect.job
[2011/01/03 12:59:00 | 000,000,906 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/01/03 12:55:00 | 000,000,444 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{3510D38C-31BB-4DF7-8E98-02CA6F10487A}.job
[2011/01/03 12:53:55 | 000,037,392 | —- | M] () – C:\WINDOWS\install .exe
[2011/01/03 12:53:30 | 000,037,384 | —- | M] () – C:\WINDOWS\wininst .exe
[2011/01/03 12:53:30 | 000,037,384 | —- | M] () – C:\WINDOWS\install .exe
[2011/01/03 12:52:56 | 000,000,248 | —- | M] () – C:\WINDOWS\System\hpsysdrv.dat
[2011/01/03 12:44:47 | 000,037,396 | —- | M] () – C:\WINDOWS\wininst .exe
[2011/01/03 12:44:47 | 000,037,396 | —- | M] () – C:\WINDOWS\taskmgr .exe
[2011/01/03 12:44:47 | 000,037,396 | —- | M] () – C:\WINDOWS\install .exe
[2011/01/03 12:44:47 | 000,037,396 | —- | M] () – C:\WINDOWS\hexdump .exe
[2011/01/03 12:44:47 | 000,037,396 | —- | M] () – C:\WINDOWS\drweb .exe
[2011/01/03 12:43:16 | 000,000,902 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/01/03 12:43:08 | 527,814,656 | -HS- | M] () – C:\hiberfil.sys
[2011/01/03 12:43:08 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/01/03 09:27:36 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/01/03 09:18:49 | 000,037,392 | —- | M] () – C:\WINDOWS\install .exe
[2011/01/03 09:18:27 | 000,037,384 | —- | M] () – C:\WINDOWS\wininst .exe
[2011/01/03 09:18:27 | 000,037,384 | —- | M] () – C:\WINDOWS\taskmgr .exe
[2011/01/03 09:18:27 | 000,037,384 | —- | M] () – C:\WINDOWS\install .exe
[2011/01/03 09:18:27 | 000,037,384 | —- | M] () – C:\WINDOWS\hexdump .exe
[2011/01/03 09:18:27 | 000,037,384 | —- | M] () – C:\WINDOWS\drweb .exe
[2011/01/03 08:48:30 | 000,296,448 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\rt6ye558.exe
[2011/01/03 08:47:14 | 000,037,392 | —- | M] () – C:\WINDOWS\install .exe
[2011/01/03 08:46:53 | 000,037,384 | —- | M] () – C:\WINDOWS\wininst.exe
[2011/01/03 08:46:53 | 000,037,384 | —- | M] () – C:\WINDOWS\taskmgr.exe
[2011/01/03 08:46:53 | 000,037,384 | —- | M] () – C:\WINDOWS\install.exe
[2011/01/03 08:46:53 | 000,037,384 | —- | M] () – C:\WINDOWS\hexdump.exe
[2011/01/03 08:46:53 | 000,037,384 | —- | M] () – C:\WINDOWS\drweb.exe
[2011/01/03 08:26:13 | 000,003,007 | —- | M] () – C:\WINDOWS\isadoruvozer.dll
[2011/01/03 08:25:15 | 000,021,092 | -H– | M] () – C:\WINDOWS\drweb .exe
[2011/01/03 08:22:08 | 000,003,007 | —- | M] () – C:\WINDOWS\ebiyerid.dll
[2011/01/02 19:51:00 | 000,000,338 | —- | M] () – C:\WINDOWS\tasks\HP Usg Daily.job
[2011/01/02 15:00:47 | 000,021,092 | -H– | M] () – C:\WINDOWS\hexdump .exe
[2011/01/02 15:00:30 | 000,060,004 | -H– | M] () – C:\WINDOWS\wininst .exe
[2011/01/02 15:00:28 | 000,060,004 | -H– | M] () – C:\WINDOWS\taskmgr .exe
[2011/01/02 15:00:27 | 000,060,004 | -H– | M] () – C:\WINDOWS\install .exe
[2011/01/02 15:00:16 | 000,030,000 | —- | M] () – C:\WINDOWS\System32\vk1a6mgve.dll
[2011/01/02 15:00:16 | 000,030,000 | —- | M] () – C:\WINDOWS\System32\gfbccb.dll
[2011/01/02 14:58:22 | 000,037,380 | —- | M] () – C:\WINDOWS\System32\HDAShCut.exe
[2011/01/02 14:19:42 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\HP_Administrator\Desktop\OTL.exe
[2011/01/02 14:19:29 | 000,359,929 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\dds.scr
[2011/01/02 14:19:11 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\HP_Administrator\Desktop\HiJackThis.exe
[2011/01/02 14:15:01 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[1 C:\Documents and Settings\HP_Administrator\My Documents\*.tmp files -> C:\Documents and Settings\HP_Administrator\My Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/01/03 08:49:58 | 000,296,448 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\rt6ye558.exe
[2011/01/03 08:26:13 | 000,003,007 | —- | C] () – C:\WINDOWS\isadoruvozer.dll
[2011/01/03 08:25:15 | 000,037,396 | —- | C] () – C:\WINDOWS\drweb .exe
[2011/01/03 08:25:15 | 000,037,384 | —- | C] () – C:\WINDOWS\drweb.exe
[2011/01/03 08:25:15 | 000,037,384 | —- | C] () – C:\WINDOWS\drweb .exe
[2011/01/03 08:25:15 | 000,021,092 | -H– | C] () – C:\WINDOWS\drweb .exe
[2011/01/03 08:22:08 | 000,003,007 | —- | C] () – C:\WINDOWS\ebiyerid.dll
[2011/01/02 15:00:47 | 000,037,396 | —- | C] () – C:\WINDOWS\hexdump .exe
[2011/01/02 15:00:47 | 000,037,384 | —- | C] () – C:\WINDOWS\hexdump.exe
[2011/01/02 15:00:47 | 000,037,384 | —- | C] () – C:\WINDOWS\hexdump .exe
[2011/01/02 15:00:47 | 000,021,092 | -H– | C] () – C:\WINDOWS\hexdump .exe
[2011/01/02 15:00:30 | 000,060,004 | -H– | C] () – C:\WINDOWS\wininst .exe
[2011/01/02 15:00:30 | 000,037,396 | —- | C] () – C:\WINDOWS\wininst .exe
[2011/01/02 15:00:30 | 000,037,384 | —- | C] () – C:\WINDOWS\wininst.exe
[2011/01/02 15:00:30 | 000,037,384 | —- | C] () – C:\WINDOWS\wininst .exe
[2011/01/02 15:00:30 | 000,037,384 | —- | C] () – C:\WINDOWS\wininst .exe
[2011/01/02 15:00:28 | 000,060,004 | -H– | C] () – C:\WINDOWS\taskmgr .exe
[2011/01/02 15:00:28 | 000,037,396 | —- | C] () – C:\WINDOWS\taskmgr .exe
[2011/01/02 15:00:28 | 000,037,384 | —- | C] () – C:\WINDOWS\taskmgr.exe
[2011/01/02 15:00:28 | 000,037,384 | —- | C] () – C:\WINDOWS\taskmgr .exe
[2011/01/02 15:00:27 | 000,060,004 | -H– | C] () – C:\WINDOWS\install .exe
[2011/01/02 15:00:27 | 000,037,396 | —- | C] () – C:\WINDOWS\install .exe
[2011/01/02 15:00:27 | 000,037,392 | —- | C] () – C:\WINDOWS\install .exe
[2011/01/02 15:00:27 | 000,037,392 | —- | C] () – C:\WINDOWS\install .exe
[2011/01/02 15:00:27 | 000,037,392 | —- | C] () – C:\WINDOWS\install .exe
[2011/01/02 15:00:27 | 000,037,384 | —- | C] () – C:\WINDOWS\install.exe
[2011/01/02 15:00:27 | 000,037,384 | —- | C] () – C:\WINDOWS\install .exe
[2011/01/02 15:00:27 | 000,037,384 | —- | C] () – C:\WINDOWS\install .exe
[2011/01/02 15:00:16 | 000,030,000 | —- | C] () – C:\WINDOWS\System32\vk1a6mgve.dll
[2011/01/02 15:00:16 | 000,030,000 | —- | C] () – C:\WINDOWS\System32\gfbccb.dll
[2011/01/02 14:19:28 | 000,359,929 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\dds.scr
[2010/11/30 12:13:19 | 000,030,000 | —- | C] () – C:\WINDOWS\System32\tayznwhx7.dll
[2010/09/26 13:49:35 | 000,000,139 | —- | C] () – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\fusioncache.dat
[2010/09/26 10:59:52 | 000,000,000 | —- | C] () – C:\Documents and Settings\HP_Administrator\Application Data\wklnhst.dat
[2009/12/18 18:05:01 | 000,000,008 | —- | C] () – C:\Documents and Settings\All Users\Application Data\sysReserve.ini
[2009/10/06 08:19:47 | 000,000,477 | —- | C] () – C:\Documents and Settings\HP_Administrator\Application Data\Hewlett-PackardHP PSC 1400 series1148959385_PROTOCOL.log
[2009/10/06 08:19:47 | 000,000,000 | —- | C] () – C:\Documents and Settings\HP_Administrator\Application Data\Hewlett-PackardHP PSC 1400 series1148959385_API.log
[2009/10/06 08:19:46 | 000,000,658 | —- | C] () – C:\Documents and Settings\HP_Administrator\Application Data\Hewlett-PackardHP PSC 1400 series1148959385_UI.log
[2009/10/06 08:19:46 | 000,000,221 | —- | C] () – C:\WINDOWS\NCLogConfig.ini
[2009/07/31 21:15:22 | 000,000,022 | —- | C] () – C:\WINDOWS\kodakpcd.HP_Administrator.ini
[2008/04/21 19:24:15 | 000,000,032 | —- | C] () – C:\Documents and Settings\All Users\Application Data\ezsid.dat
[2006/09/10 19:19:19 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2006/06/01 20:20:30 | 000,006,144 | —- | C] () – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005/09/16 23:33:24 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/09/16 23:07:50 | 000,014,289 | —- | C] () – C:\WINDOWS\System32\CHODDI.SYS
[2005/09/16 23:07:43 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\hpreg.dll
[2005/09/16 23:05:16 | 000,000,180 | —- | C] () – C:\WINDOWS\Quicken.ini
[2005/09/16 23:00:26 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/09/16 22:54:40 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2005/09/16 22:54:40 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2005/09/16 22:54:40 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2005/09/16 22:54:40 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2005/09/16 22:54:40 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2005/09/16 22:54:40 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2005/09/16 22:46:25 | 000,000,059 | —- | C] () – C:\WINDOWS\WININIT.INI
[2005/09/16 22:32:13 | 000,002,811 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2005/09/16 22:31:19 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2005/09/16 22:15:03 | 000,000,036 | —- | C] () – C:\WINDOWS\wwwbatch.ini
[2005/09/16 22:11:31 | 000,000,791 | —- | C] () – C:\WINDOWS\orun32.ini
[2005/09/16 22:07:27 | 000,323,584 | —- | C] () – C:\WINDOWS\System32\pythoncom22.dll
[2005/09/16 22:07:27 | 000,094,208 | —- | C] () – C:\WINDOWS\System32\pywintypes22.dll
[2005/09/16 22:07:02 | 000,016,896 | —- | C] () – C:\WINDOWS\System32\bcbmm.dll
[2005/07/07 13:07:24 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2005/05/09 23:52:32 | 000,022,396 | —- | C] () – C:\WINDOWS\System32\drivers\USBkey.sys
[2004/11/17 04:32:20 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2004/07/26 22:51:38 | 000,000,560 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2003/01/07 22:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2001/07/06 22:30:00 | 000,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini

========== Alternate Data Streams ==========

@Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A11F741D

< End of report >


I await further instruction!
Hi bergferg,

You seem to have picked up some other malware since you last posted. I'll give you some links to some very good free programs once we get this computer cleaned up a bit.

You have also picked up a nasty RootKit. Given the amount of infections on this computer you may want to reformat and reinstall Windows.

I strongly suggest you do the following immediately:
  • From a clean computer, change *all* your online passwords – for email, for banks, financial accounts, PayPal, eBay, online companies, any online forums or groups you belong to.
  • DO NOT change passwords or do any transactions while using the infected computer because the attacker will get the new passwords and transaction information.

If, however, you decide that the computer is not used for any sensitive work, or if you do not wish to reformat at this time, I can help you clean your computer to the best of my abilities. I must remind you that i cannot guarantee that your computer will be completely clean afterwards since we have no way of knowing what has been done to it.

If you wish to reformat and reinstall Windows this topic will assist in doing it correctly and safely.

When should I re-format? How should I reinstall?

Should you wish to clean this machine please follow these instructions.

Please do not use this machine on line for anything besides downloading tools and posting in this topic. We will clean the most serious infections then install some security programs.

Next, Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:OTL
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:8074
FF - HKLM\software\mozilla\Firefox\extensions\\{B283FB04-2444-407B-B462-E2A89D0466BE}: C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\{B283FB04-2444-407B-B462-E2A89D0466BE} [2010/12/01 07:34:51 | 000,000,000 | —D | M]
O2 - BHO: (C:\WINDOWS\system32\gfbccb.dll) - {B2B220C1-A503-59BD-F413-01B53A2C8953} - C:\WINDOWS\system32\gfbccb.dll ()
O4 - HKLM..\Run: [HNUOQOXRme] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\avp.exe File not found
O4 - HKLM..\Run: [HNUOQOXRnsc] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\drweb.exe File not found
O4 - HKLM..\Run: [HNUOQOXRoMc] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\gdi32.exe File not found
O4 - HKLM..\Run: [HNUOQOXRouqc] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\iexplarer.exe File not found
O4 - HKLM..\Run: [HNUOQOXRrrb] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\taskmgr.exe File not found
O4 - HKLM..\Run: [HNUOQOXRsPc] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\win16.exe File not found
O4 - HKLM..\Run: [HNUOQOXRsuO] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\xxfjrt0f.exe File not found
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFolderOptions = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1
O4 - HKLM..\Run: [uPc+MV0NbabJsiv] C:\WINDOWS\System32\vk1a6mgve.DLL ()
O4 - HKCU..\Run: [HNUOQOXRme] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\avp.exe File not found
O4 - HKCU..\Run: [HNUOQOXRnsc] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\drweb.exe File not found
O4 - HKCU..\Run: [HNUOQOXRoMc] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\gdi32.exe File not found
O4 - HKCU..\Run: [HNUOQOXRouqc] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\iexplarer.exe File not found
O4 - HKCU..\Run: [HNUOQOXRrrb] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\taskmgr.exe File not found
O4 - HKCU..\Run: [HNUOQOXRsPc] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\win16.exe File not found
O4 - HKCU..\Run: [HNUOQOXRsuO] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\xxfjrt0f.exe File not found
O4 - HKCU..\Run: [oqkifoik] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\teopgxwpq\lnhkxhylajb.exe File not found
O4 - HKCU..\Run: [Osoturej] C:\WINDOWS\lgmflbc.DLL File not found
O4 - HKCU..\Run: [skypedllxx.exe] C:\skypedllxx.exe\skypedllxx.exe File not found
O4 - HKCU..\Run: [uPc+MV0NbabJsiv] C:\WINDOWS\System32\vk1a6mgve.DLL ()
O22 - SharedTaskScheduler: {B2B220C1-A503-59BD-F413-01B53A2C8953} - iwuiahf87sfy8ushfijsjgfgf - C:\WINDOWS\system32\gfbccb.dll ()
O4 - HKLM..\Run: [MKas0] C:\WINDOWS\drweb .exe ()
O4 - HKLM..\Run: [MKasc] C:\WINDOWS\drweb.exe ()
O4 - HKLM..\Run: [MKasK] C:\WINDOWS\drweb .exe ()
O4 - HKLM..\Run: [MKbta] C:\WINDOWS\install.exe ()
O4 - HKLM..\Run: [MKbtala/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/533.9 (KHTML, like Gecko) Chrome/6.0.401.1 Safari/533.9] C:\WINDOWS\install.exe ()
O4 - HKLM..\Run: [MKbtc] C:\WINDOWS\hexdump.exe ()
O4 - HKLM..\Run: [MKbtG0] C:\WINDOWS\install .exe ()
O4 - HKLM..\Run: [MKbtGc] C:\WINDOWS\install .exe ()
O4 - HKLM..\Run: [MKbtGgc] C:\WINDOWS\install .exe ()
O4 - HKLM..\Run: [MKbtGgK] C:\WINDOWS\install .exe ()
O4 - HKLM..\Run: [MKbtGj] C:\WINDOWS\install .exe ()
O4 - HKLM..\Run: [MKbtHc] C:\WINDOWS\hexdump .exe ()
O4 - HKLM..\Run: [MKbtJ] C:\WINDOWS\install .exe ()
O4 - HKLM..\Run: [MKbtK] C:\WINDOWS\hexdump .exe ()
O4 - HKLM..\Run: [MKerb] C:\WINDOWS\taskmgr.exe ()
O4 - HKLM..\Run: [MKerGc] C:\WINDOWS\taskmgr .exe ()
O4 - HKLM..\Run: [MKerJ] C:\WINDOWS\taskmgr .exe ()
O4 - HKLM..\Run: [MKfre] C:\WINDOWS\wininst.exe ()
O4 - HKLM..\Run: [MKfrJc] C:\WINDOWS\wininst .exe ()
O4 - HKLM..\Run: [MKfrJK] C:\WINDOWS\wininst .exe ()
O4 - HKLM..\Run: [MKfrN] C:\WINDOWS\wininst .exe ()
O4 - HKCU..\Run: [MKas0] C:\WINDOWS\drweb .exe ()
O4 - HKCU..\Run: [MKasc] C:\WINDOWS\drweb.exe ()
O4 - HKCU..\Run: [MKasK] C:\WINDOWS\drweb .exe ()
O4 - HKCU..\Run: [MKbta] C:\WINDOWS\install.exe ()
O4 - HKCU..\Run: [MKbtala/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/533.9 (KHTML, like Gecko) Chrome/6.0.401.1 Safari/533.9] C:\WINDOWS\install.exe ()
O4 - HKCU..\Run: [MKbtc] C:\WINDOWS\hexdump.exe ()
O4 - HKCU..\Run: [MKbtG0] C:\WINDOWS\install .exe ()
O4 - HKCU..\Run: [MKbtGc] C:\WINDOWS\install .exe ()
O4 - HKCU..\Run: [MKbtGgc] C:\WINDOWS\install .exe ()
O4 - HKCU..\Run: [MKbtGgK] C:\WINDOWS\install .exe ()
O4 - HKCU..\Run: [MKbtGj] C:\WINDOWS\install .exe ()
O4 - HKCU..\Run: [MKbtHc] C:\WINDOWS\hexdump .exe ()
O4 - HKCU..\Run: [MKbtJ] C:\WINDOWS\install .exe ()
O4 - HKCU..\Run: [MKbtK] C:\WINDOWS\hexdump .exe ()
O4 - HKCU..\Run: [MKerb] C:\WINDOWS\taskmgr.exe ()
O4 - HKCU..\Run: [MKerGc] C:\WINDOWS\taskmgr .exe ()
O4 - HKCU..\Run: [MKerJ] C:\WINDOWS\taskmgr .exe ()
O4 - HKCU..\Run: [MKfre] C:\WINDOWS\wininst.exe ()
O4 - HKCU..\Run: [MKfrJc] C:\WINDOWS\wininst .exe ()
O4 - HKCU..\Run: [MKfrJK] C:\WINDOWS\wininst .exe ()
O4 - HKCU..\Run: [MKfrN] C:\WINDOWS\wininst .exe ()

:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe"
[-HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]

:Files
C:\skypedllxx.exe
C:\Program Files\QuickTime\qttask .exe 

:Commands
[emptytemp]
[createrestorepoint]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
Please post the OTL fix log


Next

Please read carefully and follow these steps.


Next

  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • UnCheck the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open a notepad windows. OTL.Txt, no Extra.txt this time.

Please post back with
  • OTL fix log
  • TDSKiller log
  • new OTL.txt
How's the computer?

Thanks
Mr. Oldman, Give the extent of the issues on this computer, and your suggestion, I think I will reformat and reinstall windows. I will follow the advice and direction given in the link you provided; would you still be able to direct me to some AV/Firewall/Malware programs? Additionally, do you think it will be necessary to run any of the scans after reinstallation to make sure everything has been removed, or is that the entire purpose of reformatting? I currently have the problem computer disconnected from the internet, but can still transfer files back and forth via jumpdrive or SD card. Thank you for the help. Gavin
Hi bergferg,

Additionally, do you think it will be necessary to run any of the scans after reinstallation to make sure everything has been removed, or is that the entire purpose of reformatting?

You can post a new OTL log here if you wish after you have it up and running (with security programs in place ;) ) .

The reformat should remove everything on the computer. Are you using a full Windows XP disk or is it an OEM disk from the computer manufacturer? They both do basically the same thing but if it's an OEM it will restore the computer back to factory settings. This is OK as it will then be in the same condition as it was when you bought it. Please note if it's an OEM it most likely came with a trial virsion of an antivirus program. This will need to be uninstalled before installing your new antivirus program.


Before you transfer any files to the USB jump drive I suggest you protect it the best you can.

On the clean computer

Download Flash_Disinfector.exe by sUBs and save it to your desktop.
  • Attach the jumpdrive to the computer while holding down the shift key
  • Double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.
  • The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.
  • Wait until it has finished scanning and then exit the program.
Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder…it will help protect your drives from future infection.


Here is a step by step guide you can follow along with the other guide to help you.

How to Reformat and Reinstall your Operating System

To be sure your back up are clean once you have backed up what ever you want to save from the infected computer I suggest you scan the jumpdrive (containing your data) with an online scanner. ESET is pretty good and you can select just the jumpdrive for scanning unless you want to scan the entire clean computer just to be sure.

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



Go here to run an online scannner from
ESET

(Note: You can use either Internet Exploer or FireFox for this scan. If you use FireFox you will be asked to install an additional package. Do so.)

  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Disable your Antivirus software. You can usually do this with its Notfication Tray icon near the clock
  • Click Start
  • Make sure that the option "Remove found threats" is Unchecked, and the option "Scan unwanted applications" is Checked.
    If you only wish to scan the only the flashdrive
    • Click Advanced settings
    • Beside "Current scan target: Oerating memory. local drives" click change
    • Make sure the jumpdrive drive letter is checked and any other drive you do not want to scan are unchecked
    • Click ok
  • Click Start.
  • Wait for the scan to finish.
  • Re-enable your Antivirus software.
  • A logfile is created and located at C:\Program Files\EsetOnlineScanner\log.txt. or C:\Program Files\ESET\log.txt
If you have any concerns over anything the scanner may find you can post the ESET log here for review.

Programs you willl need

Please install these programs after the reinstall and before connecting to the internet. You can download them to your clean computer and transfer them over.

If your Windows disk is less than XP Service Pack 3 you can get a copy from here. This page will say that this installation package is intended for IT professionals and developers. However, you can safely download this file. Install this if you need to before you install your security programs.


Basic security consists of 1 antivirus program, 1 resident antispyware program, 1 on demand antispyware program and a firewall.

* If you are behind a router Windows firewall should be fine. Otherwise a 3rd party firewall with outbound monitoring is recommended.

Click FIREWALL for tips, reviews and links to good, free and paid for firewalls. (Note: Zone Alarm is becoming bloatware,IMO)

For a free antivirus program you can download and install one of these

Avast
Help and support can be found here Avast Forum
AVG
Help and support can be found here AVG Forum
Antivir PersonalEditionClassic
Help and support can be found here Avira Personal Support Forum
MicroSoft Security Essentials
Help and Support


Resident antispyware (there are others)

Windows Defender OR Winpatrol


On demand antimalware (this one is very good)

Malwarebytes Anti-Malware

Finally reinstall any programs that you backed up.

-More tips and programs can be found HERE

Post back if you have any questions or problems.

Good luck.
Mr. Oldman,

I did a "destructive system restore" per my PC Troubleshooting Guide for this computer(HP Pav. A1221N).

I then installed AVG Firewall and AV via a secure jumpdrive. I also installed Windows Defender and MBAM.

I then ran the OTL, HJT and DDS scans and the logs reports are below.

Of note, the MBAM scan came back with trojans and other malware already, and when I opened a window to post the logs, a separate web page opened titled "Registry Virus Scanner" from the website pcspeedmaximizer.s3.amazonaws.com/index.html. With this page appeared an error box saying that errors had been foudn and I should download the cleaner. The problem computer is now diconnected from the internet again.

Please review the logs and let me know what I need to do.

Thank you,
G

OTL Log:
OTL logfile created on: 1/4/2011 6:12:10 PM - Run 1
OTL by OldTimer - Version 3.2.20.1 Folder = C:\Documents and Settings\HP_Administrator\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

503.00 Mb Total Physical Memory | 107.00 Mb Available Physical Memory | 21.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 71.00% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 178.29 Gb Total Space | 166.70 Gb Free Space | 93.50% Space Free | Partition Type: NTFS
Drive D: | 8.00 Gb Total Space | 0.90 Gb Free Space | 11.24% Space Free | Partition Type: FAT32

Computer Name: FERGUSONHOME | User Name: HP_Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\HP_Administrator\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgfws.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgam.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe (Hewlett-Packard Company)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\HP_Administrator\Desktop\OTL.exe (OldTimer Tools)


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – C:\WINDOWS\System32\hidserv.dll File not found
SRV - (6to4) – C:\WINDOWS\System32\6to4v32.dll File not found
SRV - (AVG Security Toolbar Service) – C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe ()
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgfws) – C:\Program Files\AVG\AVG10\avgfws.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) – C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)


========== Driver Services (SafeList) ==========

DRV - (Avgldx86) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgtdix) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSEH) – C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgmfx86) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) – C:\WINDOWS\system32\DRIVERS\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSFilter) – C:\WINDOWS\system32\drivers\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSDriver) – C:\WINDOWS\system32\drivers\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSShim) – C:\WINDOWS\system32\drivers\AVGIDSShim.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgfwfd) – C:\WINDOWS\system32\drivers\avgfwdx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgfwdx) – C:\WINDOWS\system32\drivers\avgfwdx.sys (AVG Technologies CZ, s.r.o.)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (ftsata2) – C:\WINDOWS\system32\DRIVERS\ftsata2.sys (Promise Technology, Inc.)
DRV - (iaStor) – C:\WINDOWS\system32\DRIVERS\iaStor.sys (Intel Corporation)
DRV - (RTL8023xp) – C:\WINDOWS\system32\drivers\Rtlnicxp.sys (Realtek Semiconductor Corporation )
DRV - (HdAudAddService) – C:\WINDOWS\system32\drivers\Hdaudio.sys (Windows ® Server 2003 DDK provider)
DRV - (HSFHWBS2) – C:\WINDOWS\system32\drivers\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) – C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (ltmodem5) – C:\WINDOWS\system32\drivers\ltmdmnt.sys (LT)
DRV - (rtl8139) Realtek RTL8139(A/B/C) – C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)
DRV - (bb-run) – C:\WINDOWS\system32\DRIVERS\bb-run.sys (Promise Technology, Inc.)
DRV - (Ps2) – C:\WINDOWS\system32\drivers\PS2.sys (Hewlett-Packard Company)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…arm1=seconduser
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…arm1=seconduser
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…arm1=seconduser
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…arm1=seconduser
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…arm1=seconduser

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…arm1=seconduser
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…arm1=seconduser
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…arm1=seconduser
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…arm1=seconduser
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG10\Firefox\ [2011/01/04 14:31:34 | 000,000,000 | —D | M]


O1 HOSTS File: ([2004/08/10 19:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (&Google;) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (&Google;) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [High Definition Audio Property Page Shortcut] C:\WINDOWS\System32\HdAShCut.exe (Windows ® Server 2003 DDK provider)
O4 - HKLM..\Run: [HPBootOp] C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe (Hewlett-Packard)
O4 - HKLM..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\LSBurnWatcher.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [PCDrProfiler] File not found
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &Google; Search - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Backward Links - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Cached Snapshot of Page - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Similar Pages - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Translate into English - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\NPJPI150.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ()
O9 - Extra 'Tools' menuitem : Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ()
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0)
O16 - DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/09/16 23:04:28 | 000,000,100 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2001/07/28 05:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O32 - AutoRun File - [2004/04/30 21:01:14 | 000,000,053 | -HS- | M] () - D:\Autorun.inf – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync) - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart) - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - C:\WINDOWS\System32\6to4v32.dll File not found
NetSvcs: HidServ - C:\WINDOWS\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.LEAD - C:\WINDOWS\System32\LCodcCMP.dll (LEAD Technologies, Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (17465059307421696)

========== Files/Folders - Created Within 30 Days ==========

[2011/01/04 18:07:41 | 000,000,000 | -H-D | C] – C:\$AVG
[2011/01/04 17:40:18 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Application Data\Malwarebytes
[2011/01/04 17:39:58 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/01/04 17:39:58 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/01/04 17:39:57 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/01/04 17:39:49 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/01/04 17:39:49 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/01/04 15:00:42 | 000,000,000 | —D | C] – C:\Program Files\Windows Defender
[2011/01/04 15:00:14 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2011/01/04 14:43:46 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Application Data\AVG10
[2011/01/04 14:37:33 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2011/01/04 14:36:09 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2011/01/04 14:36:08 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2011/01/04 14:35:23 | 000,000,000 | —D | C] – C:\WINDOWS\Sun
[2011/01/04 14:35:21 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Sun
[2011/01/04 14:34:00 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\Common Files
[2011/01/04 14:33:37 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2011/01/04 14:33:01 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\AVG 2011
[2011/01/04 14:31:23 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\AVG10
[2011/01/04 14:31:23 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\AVG
[2011/01/04 14:31:02 | 000,000,000 | —D | C] – C:\Program Files\AVG
[2011/01/04 14:25:35 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\MFAData
[2011/01/04 14:23:43 | 000,000,000 | —D | C] – C:\WINDOWS\Prefetch
[2011/01/04 14:14:13 | 001,306,624 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msxml6.dll
[2011/01/04 14:14:13 | 000,079,872 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msxml6r.dll
[2011/01/04 14:14:12 | 000,079,872 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msxml6r.dll
[2011/01/04 14:14:02 | 000,046,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\irbus.sys
[2011/01/04 14:14:02 | 000,010,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\smtpapi.dll
[2011/01/04 14:14:02 | 000,009,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\rwnh.dll
[2011/01/04 14:14:02 | 000,009,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\comsdupd.exe
[2011/01/04 14:13:59 | 000,136,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\aaclient.dll
[2011/01/04 14:13:58 | 001,888,992 | —- | C] (ATI Technologies Inc. ) – C:\WINDOWS\System32\ati3duag.dll
[2011/01/04 14:13:58 | 000,870,784 | —- | C] (ATI Technologies Inc. ) – C:\WINDOWS\System32\ati3d1ag.dll
[2011/01/04 14:13:58 | 000,516,768 | —- | C] (ATI Technologies Inc. ) – C:\WINDOWS\System32\ativvaxx.dll
[2011/01/04 14:13:58 | 000,377,984 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\ati2dvaa.dll
[2011/01/04 14:13:58 | 000,233,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\azroles.dll
[2011/01/04 14:13:58 | 000,229,376 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\ati2cqag.dll
[2011/01/04 14:13:58 | 000,201,728 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\ati2dvag.dll
[2011/01/04 14:13:58 | 000,032,768 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\ativtmxx.dll
[2011/01/04 14:13:58 | 000,023,040 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\ativmvxx.ax
[2011/01/04 14:13:58 | 000,009,728 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\ativdaxx.ax
[2011/01/04 14:13:58 | 000,007,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\bitsprx4.dll
[2011/01/04 14:13:57 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3cfg.dll
[2011/01/04 14:13:57 | 000,056,320 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3msm.dll
[2011/01/04 14:13:57 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dhcpqec.dll
[2011/01/04 14:13:57 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3gpclnt.dll
[2011/01/04 14:13:57 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dimsroam.dll
[2011/01/04 14:13:57 | 000,026,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3api.dll
[2011/01/04 14:13:57 | 000,009,216 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3dlg.dll
[2011/01/04 14:13:56 | 000,650,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3ui.dll
[2011/01/04 14:13:56 | 000,184,832 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eapp3hst.dll
[2011/01/04 14:13:56 | 000,180,224 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eapphost.dll
[2011/01/04 14:13:56 | 000,126,976 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eappcfg.dll
[2011/01/04 14:13:56 | 000,094,208 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eappgnui.dll
[2011/01/04 14:13:56 | 000,059,392 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eapqec.dll
[2011/01/04 14:13:56 | 000,040,960 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eappprxy.dll
[2011/01/04 14:13:56 | 000,030,720 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eapolqec.dll
[2011/01/04 14:13:55 | 000,032,285 | —- | C] (Conexant Systems, Inc.) – C:\WINDOWS\System32\hsfcisp2.dll
[2011/01/04 14:13:54 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdiultn.dll
[2011/01/04 14:13:54 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdbhc.dll
[2011/01/04 14:13:53 | 000,397,312 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mmcex.dll
[2011/01/04 14:13:53 | 000,184,320 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\microsoft.managementconsole.dll
[2011/01/04 14:13:53 | 000,106,496 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mmcfxcommon.dll
[2011/01/04 14:13:53 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\l2gpstore.dll
[2011/01/04 14:13:53 | 000,033,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mmcperf.exe
[2011/01/04 14:13:53 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdpash.dll
[2011/01/04 14:13:53 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdnepr.dll
[2011/01/04 14:13:52 | 004,274,816 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nv4_disp.dll
[2011/01/04 14:13:52 | 001,737,856 | —- | C] (Matrox Graphics Inc.) – C:\WINDOWS\System32\mtxparhd.dll
[2011/01/04 14:13:52 | 000,193,024 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\napmontr.dll
[2011/01/04 14:13:52 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\napstat.exe
[2011/01/04 14:13:52 | 000,155,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mssha.dll
[2011/01/04 14:13:52 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msshavmsg.dll
[2011/01/04 14:13:52 | 000,030,208 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\napipsec.dll
[2011/01/04 14:13:51 | 000,412,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\photometadatahandler.dll
[2011/01/04 14:13:51 | 000,397,056 | —- | C] (S3 Graphics, Inc.) – C:\WINDOWS\System32\s3gnb.dll
[2011/01/04 14:13:51 | 000,290,304 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\rhttpaa.dll
[2011/01/04 14:13:51 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\qagent.dll
[2011/01/04 14:13:51 | 000,144,384 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\onex.dll
[2011/01/04 14:13:51 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\qutil.dll
[2011/01/04 14:13:51 | 000,062,464 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\qcliprov.dll
[2011/01/04 14:13:51 | 000,061,952 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\rasqec.dll
[2011/01/04 14:13:50 | 000,712,704 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\windowscodecs.dll
[2011/01/04 14:13:50 | 000,346,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\windowscodecsext.dll
[2011/01/04 14:13:50 | 000,286,792 | —- | C] (Smart Link) – C:\WINDOWS\System32\slextspk.dll
[2011/01/04 14:13:50 | 000,188,508 | —- | C] (Smart Link) – C:\WINDOWS\System32\slgen.dll
[2011/01/04 14:13:50 | 000,073,832 | —- | C] (Smart Link) – C:\WINDOWS\System32\slcoinst.dll
[2011/01/04 14:13:50 | 000,073,796 | —- | C] (Smart Link) – C:\WINDOWS\System32\slserv.exe
[2011/01/04 14:13:50 | 000,053,248 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\tsgqec.dll
[2011/01/04 14:13:50 | 000,032,866 | —- | C] (Smart Link) – C:\WINDOWS\System32\slrundll.exe
[2011/01/04 14:13:50 | 000,032,768 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\setupn.exe
[2011/01/04 14:13:50 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\vidcap.ax
[2011/01/04 14:13:50 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\verclsid.exe
[2011/01/04 14:13:49 | 000,276,992 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wmphoto.dll
[2011/01/04 14:13:49 | 000,069,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wlanapi.dll
[2011/01/04 14:13:47 | 000,689,152 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xpsp3res.dll
[2011/01/04 14:13:47 | 000,032,866 | —- | C] (Smart Link) – C:\WINDOWS\slrundll.exe
[2011/01/04 14:13:47 | 000,000,000 | —D | C] – C:\WINDOWS\System32\en-us
[2011/01/04 14:13:46 | 000,000,000 | —D | C] – C:\WINDOWS\System32\scripting
[2011/01/04 14:13:45 | 000,000,000 | —D | C] – C:\WINDOWS\l2schemas
[2011/01/04 14:13:45 | 000,000,000 | —D | C] – C:\WINDOWS\System32\en
[2011/01/04 14:13:44 | 000,000,000 | —D | C] – C:\WINDOWS\System32\bits
[2011/01/04 14:11:22 | 000,000,000 | —D | C] – C:\WINDOWS\ServicePackFiles
[2011/01/04 14:09:12 | 000,043,008 | —- | C] (Advanced Micro Devices, Inc.) – C:\WINDOWS\System32\drivers\amdagp.sys
[2011/01/04 14:09:12 | 000,004,255 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv01nt5.dll
[2011/01/04 14:09:12 | 000,003,967 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv02nt5.dll
[2011/01/04 14:09:12 | 000,003,775 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv11nt5.dll
[2011/01/04 14:09:12 | 000,003,711 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv09nt5.dll
[2011/01/04 14:09:12 | 000,003,647 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv07nt5.dll
[2011/01/04 14:09:12 | 000,003,615 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv05nt5.dll
[2011/01/04 14:09:12 | 000,003,135 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv08nt5.dll
[2011/01/04 14:09:12 | 000,000,000 | —D | C] – C:\WINDOWS\network diagnostic
[2011/01/04 14:09:11 | 000,701,440 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati2mtag.sys
[2011/01/04 14:09:11 | 000,327,040 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati2mtaa.sys
[2011/01/04 14:09:11 | 000,104,960 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinrvxx.sys
[2011/01/04 14:09:11 | 000,073,216 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atintuxx.sys
[2011/01/04 14:09:11 | 000,063,663 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1rvxx.sys
[2011/01/04 14:09:11 | 000,063,488 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinxsxx.sys
[2011/01/04 14:09:11 | 000,057,856 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinbtxx.sys
[2011/01/04 14:09:11 | 000,056,623 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1btxx.sys
[2011/01/04 14:09:11 | 000,052,224 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinraxx.sys
[2011/01/04 14:09:11 | 000,036,463 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1tuxx.sys
[2011/01/04 14:09:11 | 000,034,735 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1xsxx.sys
[2011/01/04 14:09:11 | 000,031,744 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinxbxx.sys
[2011/01/04 14:09:11 | 000,030,671 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1raxx.sys
[2011/01/04 14:09:11 | 000,029,455 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1xbxx.sys
[2011/01/04 14:09:11 | 000,028,672 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinsnxx.sys
[2011/01/04 14:09:11 | 000,026,367 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1snxx.sys
[2011/01/04 14:09:11 | 000,025,471 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\atv04nt5.dll
[2011/01/04 14:09:11 | 000,021,343 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1ttxx.sys
[2011/01/04 14:09:11 | 000,021,183 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\atv01nt5.dll
[2011/01/04 14:09:11 | 000,014,336 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinpdxx.sys
[2011/01/04 14:09:11 | 000,014,143 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\atv06nt5.dll
[2011/01/04 14:09:11 | 000,013,824 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinttxx.sys
[2011/01/04 14:09:11 | 000,013,824 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinmdxx.sys
[2011/01/04 14:09:11 | 000,012,047 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1pdxx.sys
[2011/01/04 14:09:11 | 000,011,615 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1mdxx.sys
[2011/01/04 14:09:11 | 000,011,359 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\atv02nt5.dll
[2011/01/04 14:09:10 | 000,036,480 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\bthprint.sys
[2011/01/04 14:09:10 | 000,017,279 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\atv10nt5.dll
[2011/01/04 14:09:10 | 000,015,423 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\ch7xxnt5.dll
[2011/01/04 14:09:08 | 001,897,408 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\drivers\nv4_mini.sys
[2011/01/04 14:09:08 | 001,309,184 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\mtlstrm.sys
[2011/01/04 14:09:08 | 000,452,736 | —- | C] (Matrox Graphics Inc.) – C:\WINDOWS\System32\drivers\mtxparhm.sys
[2011/01/04 14:09:08 | 000,180,360 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\ntmtlfax.sys
[2011/01/04 14:09:08 | 000,166,912 | —- | C] (S3 Graphics, Inc.) – C:\WINDOWS\System32\drivers\s3gnbm.sys
[2011/01/04 14:09:08 | 000,126,686 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\mtlmnt5.sys
[2011/01/04 14:09:08 | 000,030,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\rndismpx.sys
[2011/01/04 14:09:08 | 000,013,776 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\recagent.sys
[2011/01/04 14:09:08 | 000,012,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\mutohpen.sys
[2011/01/04 14:09:07 | 000,404,990 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\slntamr.sys
[2011/01/04 14:09:07 | 000,129,535 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\slnt7554.sys
[2011/01/04 14:09:07 | 000,095,424 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\slnthal.sys
[2011/01/04 14:09:07 | 000,040,960 | —- | C] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\drivers\sisagp.sys
[2011/01/04 14:09:07 | 000,025,471 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\watv10nt.sys
[2011/01/04 14:09:07 | 000,022,271 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\watv06nt.sys
[2011/01/04 14:09:07 | 000,013,240 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\slwdmsup.sys
[2011/01/04 14:09:07 | 000,011,935 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\wadv11nt.sys
[2011/01/04 14:09:07 | 000,011,871 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\wadv09nt.sys
[2011/01/04 14:09:07 | 000,011,807 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\wadv07nt.sys
[2011/01/04 14:09:07 | 000,011,325 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\vchnt5.dll
[2011/01/04 14:09:07 | 000,011,295 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\wadv08nt.sys
[2011/01/04 14:09:07 | 000,005,888 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\smbali.sys
[2011/01/04 14:09:07 | 000,003,901 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\siint5.dll
[2011/01/04 14:03:43 | 000,000,000 | -H-D | C] – C:\WINDOWS\$NtServicePackUninstall$
[2011/01/04 13:58:39 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Documents and Settings\HP_Administrator\Desktop\OTL.exe
[2011/01/04 13:58:39 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\HP_Administrator\Desktop\HiJackThis.exe
[2011/01/04 13:58:37 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Desktop\A1221N
[2011/01/04 13:20:33 | 000,000,000 | RHSD | C] – C:\cmdcons
[2011/01/04 13:20:30 | 000,000,000 | —D | C] – C:\WINDOWS\setup.pss
[2011/01/04 13:20:17 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2011/01/04 13:20:02 | 000,000,000 | RH-D | C] – C:\Documents and Settings\HP_Administrator\Recent
[2011/01/04 13:16:49 | 000,000,000 | —D | C] – C:\WINDOWS\System32\appmgmt
[2011/01/04 13:07:16 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office (60 Day Trial)
[2011/01/04 13:07:06 | 000,000,000 | —D | C] – C:\Program Files\Microsoft
[2011/01/04 13:06:12 | 000,090,112 | —- | C] (Hewlett-Packard Company) – C:\WINDOWS\System32\ps2.EXE
[2011/01/04 13:04:35 | 000,000,000 | –SD | C] – C:\Documents and Settings\HP_Administrator\Application Data\Microsoft
[2011/01/04 13:04:35 | 000,000,000 | –SD | C] – C:\Documents and Settings\HP_Administrator\Cookies
[2011/01/04 13:04:35 | 000,000,000 | RH-D | C] – C:\Documents and Settings\HP_Administrator\Application Data
[2011/01/04 13:04:35 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Administrator\Favorites
[2011/01/04 13:04:35 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Application Data\Symantec
[2011/01/04 13:04:35 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Application Data\SampleView
[2011/01/04 13:04:35 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Application Data\Real
[2011/01/04 13:04:35 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Application Data\Intuit
[2011/01/04 13:04:35 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Application Data\Identities
[2011/01/04 13:04:35 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Google
[2011/01/04 13:04:35 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Desktop
[2011/01/04 13:04:35 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\ApplicationHistory
[2011/01/04 13:04:35 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Apple Computer
[2011/01/04 13:04:35 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Application Data\Apple Computer
[2011/01/04 13:04:34 | 000,000,000 | RH-D | C] – C:\Documents and Settings\HP_Administrator\SendTo
[2011/01/04 13:04:34 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Administrator\Start Menu\Programs\Startup
[2011/01/04 13:04:34 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Administrator\Start Menu
[2011/01/04 13:04:34 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Administrator\My Documents\My Videos
[2011/01/04 13:04:34 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Administrator\My Documents\My Pictures
[2011/01/04 13:04:34 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Administrator\My Documents\My Music
[2011/01/04 13:04:34 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Administrator\My Documents
[2011/01/04 13:04:34 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Administrator\Start Menu\Programs\Accessories
[2011/01/04 13:04:34 | 000,000,000 | -H-D | C] – C:\Documents and Settings\HP_Administrator\Templates
[2011/01/04 13:04:34 | 000,000,000 | -H-D | C] – C:\Documents and Settings\HP_Administrator\PrintHood
[2011/01/04 13:04:34 | 000,000,000 | -H-D | C] – C:\Documents and Settings\HP_Administrator\NetHood
[2011/01/04 13:04:34 | 000,000,000 | -H-D | C] – C:\Documents and Settings\HP_Administrator\Local Settings
[2011/01/04 13:04:34 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\WINDOWS
[2011/01/04 13:04:34 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Start Menu\Programs\Online Services
[2011/01/04 13:04:34 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft
[2011/01/04 13:04:34 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\{3248F0A6-6813-11D6-A77B-00B0D0150000}
[2011/01/04 11:47:56 | 000,000,000 | -HSD | C] – C:\System Volume Information
[2011/01/04 11:25:06 | 000,000,000 | —D | C] – C:\WINDOWS\I386
[2011/01/04 11:18:17 | 000,000,000 | RH-D | C] – C:\MSOCache
[2011/01/04 11:18:17 | 000,000,000 | R–D | C] – C:\Documents and Settings\All Users\Desktop\User's Guides
[2011/01/04 11:18:17 | 000,000,000 | R–D | C] – C:\Documents and Settings\All Users\Start Menu
[2011/01/04 11:18:17 | 000,000,000 | R–D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Games
[2011/01/04 11:18:17 | 000,000,000 | R–D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools
[2011/01/04 11:18:17 | 000,000,000 | R–D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Accessories
[2011/01/04 11:18:10 | 000,000,000 | R–D | C] – C:\Documents and Settings\All Users\Documents\My Videos
[2011/01/04 11:18:07 | 000,000,000 | R–D | C] – C:\Documents and Settings\All Users\Documents\My Pictures
[2011/01/04 11:17:57 | 000,000,000 | R–D | C] – C:\Documents and Settings\All Users\Documents\My Music
[2011/01/04 11:17:57 | 000,000,000 | R–D | C] – C:\Documents and Settings\All Users\Documents
[2011/01/04 11:17:50 | 000,000,000 | RH-D | C] – C:\Documents and Settings\All Users\Application Data
[2011/01/04 11:17:04 | 000,000,000 | R-SD | C] – C:\WINDOWS\assembly
[2011/01/04 11:17:00 | 000,000,000 | R–D | C] – C:\WINDOWS\Offline Web Pages
[2011/01/04 11:15:49 | 000,000,000 | RHSD | C] – C:\WINDOWS\System32\dllcache
[2010/12/08 04:12:38 | 000,251,728 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/01/04 18:10:48 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/01/04 18:10:47 | 527,814,656 | -HS- | M] () – C:\hiberfil.sys
[2011/01/04 18:09:23 | 000,000,248 | —- | M] () – C:\WINDOWS\System\hpsysdrv.dat
[2011/01/04 17:40:07 | 000,000,795 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/01/04 15:00:14 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/01/04 14:57:47 | 103,382,694 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2011/01/04 14:57:47 | 000,641,053 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\iavifw.avm
[2011/01/04 14:54:28 | 000,192,184 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/01/04 14:33:11 | 000,000,701 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG 2011.lnk
[2011/01/04 14:25:57 | 000,382,022 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/01/04 14:25:57 | 000,053,640 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/01/04 14:25:54 | 000,316,640 | —- | M] () – C:\WINDOWS\WMSysPr9.prx
[2011/01/04 14:24:18 | 000,000,790 | —- | M] () – C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/01/04 14:08:50 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/01/04 13:53:42 | 000,359,929 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\dds.scr
[2011/01/04 13:53:34 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\HP_Administrator\Desktop\HiJackThis.exe
[2011/01/04 13:50:46 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\HP_Administrator\Desktop\OTL.exe
[2011/01/04 13:21:28 | 000,003,584 | —- | M] () – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/01/04 13:21:02 | 000,001,891 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/01/04 13:20:43 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2011/01/04 13:07:07 | 000,002,054 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\Microsoft Office 2003 Edition 60 Days Trial Welcome Tour.lnk
[2011/01/04 13:07:03 | 000,000,603 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\Register with HP.url
[2011/01/04 13:05:45 | 000,000,338 | —- | M] () – C:\WINDOWS\tasks\Easy Internet Sign-up.job
[2011/01/04 13:05:44 | 000,000,745 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Easy Internet Sign-up.lnk
[2011/01/04 13:03:43 | 000,001,063 | —- | M] () – C:\WINDOWS\System32\$winnt$.inf
[2011/01/04 13:02:50 | 000,000,211 | RHS- | M] () – C:\BOOT.BAK
[2010/12/20 18:09:00 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/12/20 18:08:40 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/12/08 04:12:38 | 000,251,728 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/01/04 17:40:07 | 000,000,795 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/01/04 14:57:47 | 103,382,694 | —- | C] () – C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2011/01/04 14:57:47 | 000,641,053 | —- | C] () – C:\WINDOWS\System32\drivers\AVG\iavifw.avm
[2011/01/04 14:33:11 | 000,000,701 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AVG 2011.lnk
[2011/01/04 14:09:11 | 000,064,352 | —- | C] () – C:\WINDOWS\System32\drivers\ativmc20.cod
[2011/01/04 14:09:10 | 000,129,045 | —- | C] () – C:\WINDOWS\System32\drivers\cxthsfs2.cty
[2011/01/04 14:09:08 | 000,067,866 | —- | C] () – C:\WINDOWS\System32\drivers\netwlan5.img
[2011/01/04 13:58:39 | 000,359,929 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\dds.scr
[2011/01/04 13:21:28 | 000,003,584 | —- | C] () – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/01/04 13:20:41 | 000,000,211 | RHS- | C] () – C:\BOOT.BAK
[2011/01/04 13:20:40 | 000,260,272 | RHS- | C] () – C:\cmldr
[2011/01/04 13:13:33 | 000,000,075 | —- | C] () – C:\Documents and Settings\HP_Administrator\LuResult.txt
[2011/01/04 13:07:07 | 000,002,054 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\Microsoft Office 2003 Edition 60 Days Trial Welcome Tour.lnk
[2011/01/04 13:07:03 | 000,000,603 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\Register with HP.url
[2011/01/04 13:06:13 | 527,814,656 | -HS- | C] () – C:\hiberfil.sys
[2011/01/04 13:05:44 | 000,000,338 | —- | C] () – C:\WINDOWS\tasks\Easy Internet Sign-up.job
[2011/01/04 13:04:38 | 000,002,892 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\Help and Support.lnk
[2011/01/04 13:04:38 | 000,001,643 | —- | C] () – C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\iTunes.lnk
[2011/01/04 13:04:38 | 000,000,926 | —- | C] () – C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\RealPlayer.lnk
[2011/01/04 13:04:38 | 000,000,790 | —- | C] () – C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/01/04 13:04:38 | 000,000,753 | —- | C] () – C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\QuickTime Player.lnk
[2011/01/04 13:04:38 | 000,000,136 | —- | C] () – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\fusioncache.dat
[2011/01/04 13:04:38 | 000,000,079 | —- | C] () – C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
[2011/01/04 13:03:26 | 000,002,197 | —- | C] () – C:\Documents and Settings\All Users\Desktop\BLOCKBUSTER Online.lnk
[2011/01/04 13:03:26 | 000,002,088 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AOL Latino 3 Meses Incluidos.lnk
[2011/01/04 13:03:26 | 000,001,944 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AOL 3 Months Included.lnk
[2011/01/04 13:03:26 | 000,001,857 | —- | C] () – C:\Documents and Settings\All Users\Desktop\MSN.lnk
[2011/01/04 13:03:26 | 000,001,625 | —- | C] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2011/01/04 13:03:26 | 000,001,540 | —- | C] () – C:\Documents and Settings\All Users\Desktop\HP Extended Service Plans.lnk
[2011/01/04 13:03:26 | 000,001,486 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Quicken 2005.lnk
[2011/01/04 13:03:26 | 000,000,908 | —- | C] () – C:\Documents and Settings\All Users\Desktop\RealPlayer.lnk
[2011/01/04 13:03:18 | 000,000,745 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Easy Internet Sign-up.lnk
[2011/01/04 11:26:08 | 000,000,248 | —- | C] () – C:\WINDOWS\System\hpsysdrv.dat
[2005/09/16 23:33:24 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/09/16 23:07:50 | 000,014,289 | —- | C] () – C:\WINDOWS\System32\CHODDI.SYS
[2005/09/16 23:07:43 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\hpreg.dll
[2005/09/16 23:05:16 | 000,000,180 | —- | C] () – C:\WINDOWS\Quicken.ini
[2005/09/16 23:00:26 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/09/16 22:54:40 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2005/09/16 22:54:40 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2005/09/16 22:54:40 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2005/09/16 22:54:40 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2005/09/16 22:54:40 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2005/09/16 22:54:40 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2005/09/16 22:46:25 | 000,000,059 | —- | C] () – C:\WINDOWS\WININIT.INI
[2005/09/16 22:32:13 | 000,000,972 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2005/09/16 22:31:19 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2005/09/16 22:15:03 | 000,000,036 | —- | C] () – C:\WINDOWS\wwwbatch.ini
[2005/09/16 22:11:31 | 000,000,791 | —- | C] () – C:\WINDOWS\orun32.ini
[2005/09/16 22:07:27 | 000,323,584 | —- | C] () – C:\WINDOWS\System32\pythoncom22.dll
[2005/09/16 22:07:27 | 000,094,208 | —- | C] () – C:\WINDOWS\System32\pywintypes22.dll
[2005/09/16 22:07:02 | 000,016,896 | —- | C] () – C:\WINDOWS\System32\bcbmm.dll
[2005/07/07 13:07:24 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2005/05/09 23:52:32 | 000,022,396 | —- | C] () – C:\WINDOWS\System32\drivers\USBkey.sys
[2004/11/17 04:32:20 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2004/07/26 22:51:38 | 000,000,560 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2003/01/07 22:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2001/07/06 22:30:00 | 000,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini

========== LOP Check ==========

[2011/01/04 14:33:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2011/01/04 14:34:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG10
[2011/01/04 14:34:00 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2011/01/04 14:31:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2011/01/04 13:05:45 | 000,000,338 | —- | M] () – C:\WINDOWS\Tasks\Easy Internet Sign-up.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2005/09/16 23:04:28 | 000,000,100 | —- | M] () – C:\AUTOEXEC.BAT
[2011/01/04 13:02:50 | 000,000,211 | RHS- | M] () – C:\BOOT.BAK
[2011/01/04 13:20:43 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2004/08/10 05:00:00 | 000,260,272 | RHS- | M] () – C:\cmldr
[2004/11/17 04:32:46 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2011/01/04 18:10:47 | 527,814,656 | -HS- | M] () – C:\hiberfil.sys
[2004/11/17 04:32:46 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2004/11/17 04:32:46 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/10 05:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2011/01/04 14:08:50 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/01/04 18:10:46 | 792,723,456 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >

< %systemroot%\Fonts\*.dll >
[2005/05/12 06:36:48 | 000,012,288 | —- | M] (Hewlett-Packard Co.) – C:\WINDOWS\Fonts\RandFont.dll

< %systemroot%\Fonts\*.ini >
[2004/11/17 04:31:48 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2003/06/19 00:31:48 | 000,018,944 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2004/11/16 20:20:24 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2004/11/16 20:20:24 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2004/11/16 20:20:24 | 000,876,544 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2011/01/04 14:14:45 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/01/04 14:24:28 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2004/11/17 04:37:56 | 000,000,079 | —- | M] () – C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2011/01/04 13:53:34 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\HP_Administrator\Desktop\HiJackThis.exe
[2011/01/04 13:50:46 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\HP_Administrator\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< End of report >


OTL Extras:
OTL Extras logfile created on: 1/4/2011 6:12:10 PM - Run 1
OTL by OldTimer - Version 3.2.20.1 Folder = C:\Documents and Settings\HP_Administrator\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

503.00 Mb Total Physical Memory | 107.00 Mb Available Physical Memory | 21.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 71.00% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 178.29 Gb Total Space | 166.70 Gb Free Space | 93.50% Space Free | Partition Type: NTFS
Drive D: | 8.00 Gb Total Space | 0.90 Gb Free Space | 11.24% Space Free | Partition Type: FAT32

Computer Name: FERGUSONHOME | User Name: HP_Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%ProgramFiles%\iTunes\iTunes.exe" = %ProgramFiles%\iTunes\iTunes.exe:*:enabled:iTunes – (Apple Computer, Inc.)
"C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe" = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe:*:Enabled:Updates from HP – (Hewlett-Packard)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe" = C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe – ()
"C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe – ( )
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe – (Hewlett-Packard Co.)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Computer, Inc.)
"C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe" = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe:*:Enabled:Updates from HP – (Hewlett-Packard)
"C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" = C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink – File not found
"C:\Program Files\AVG\AVG10\avgdiagex.exe" = C:\Program Files\AVG\AVG10\avgdiagex.exe:*:Enabled:AVG Diagnostics 2011 – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG10\avgnsx.exe" = C:\Program Files\AVG\AVG10\avgnsx.exe:*:Enabled:Online Shield – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG10\avgmfapx.exe" = C:\Program Files\AVG\AVG10\avgmfapx.exe:*:Enabled:AVG Installer – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG10\avgam.exe" = C:\Program Files\AVG\AVG10\avgam.exe:*:Enabled:AVG Alert manager – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG10\avgemcx.exe" = C:\Program Files\AVG\AVG10\avgemcx.exe:*:Enabled:Personal E-mail Scanner – (AVG Technologies CZ, s.r.o.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{03B1B42B-F6DE-41d9-8CFF-DC44E895C7A7}" = PhotoGallery
"{044146E4-A924-458A-9948-4B9C7C7D9321}" = LightScribe 1.4.31.1
"{04E7A3BB-DB38-481C-A809-35FA60C78EDF}" = AVG 2011
"{0611BD4E-4FE4-4a62-B0C0-18A4CC463428}" = CP_Package_Variety1
"{075473F5-846A-448B-BCB3-104AA1760205}" = Sonic RecordNow Data
"{09984AEC-6B9F-4ca7-B78D-CB44D4771DA3}" = Destinations
"{0B33B738-AD79-4E32-90C5-E67BFB10BBFF}" = AiO_Scan
"{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}" = Microsoft Plus! Photo Story 2 LE
"{14589F05-C658-4594-9429-D437BA688686}" = IntelliMover Data Transfer Demo
"{172975EB-9465-4861-95B5-C7BB6D3DE62A}" = DocumentViewer
"{1A103D70-5C9B-4E1A-B306-5106C68F9914}" = Microsoft Plus! Dancer LE
"{1C139D7D-9FEA-468d-A9C8-2A6E3BDE564A}" = CP_Package_Variety3
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{21657574-BD54-48A2-9450-EB03B2C7FC29}" = Sonic MyDVD Plus
"{21DB3D90-D816-4092-A260-CA3F6B55A6DD}" = Sonic_PrimoSDK
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{23A7B376-BBEC-4e76-BBD7-0F155E70D74B}" = CP_Panorama1Config
"{2C3D719A-92C7-4323-89CC-C937D0267B84}" = muvee autoProducer 4.0
"{2C5D07FB-31A2-4F2D-9FDA-0B24ACD42BD0}" = HP Deskjet Printer Preload
"{2CADCEAB-D5DA-44D6-B5FC-7DEE87AB3C0C}" = Unload
"{2DBE41DD-2129-4C65-A3D3-5647236A60F3}" = Quicken 2005
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
"{3076D235-59F2-448E-889F-D04F985B4CF1}" = HP Tunes
"{30C19FF2-7FBA-4d09-B9DE-1659977F64F6}" = TrayApp
"{3248F0A8-6813-11D6-A77B-00B0D0150000}" = J2SE Runtime Environment 5.0
"{32BDCCB8-9DC8-496d-9DB1-F77510775BDB}" = InstantShareDevices
"{33D6CC28-9F75-4d1b-A11D-98895B3A3729}" = HP Photosmart 330,380,420,470,7800,8000,8200 Series
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{36E47DA1-10E1-45d9-8B19-14D19607CDCF}" = CP_CalendarTemplates1
"{3912A629-0020-0005-3757-2FBA74D4DF0A}" = InterVideo WinDVD Player
"{3BA95526-6AE0-4B87-A62D-17187EF565FC}" = HP Boot Optimizer
"{416D80BA-6F6D-4672-B7CF-F54DA2F80B44}" = Microsoft Works
"{523E6F2A-2D59-4D91-90E8-6C49931C9F50}" = iTunes
"{54E3707F-808E-4fd4-95C9-15D1AB077E5D}" = NewCopy
"{56EE8B17-8274-418d-89AC-C057C5DB251E}" = RandMap
"{56F8AFC3-FA98-4ff1-9673-8A026CBF85BE}" = WebReg
"{5A01C58E-B0EC-49b9-AD71-7C0468688087}" = CP_Package_Basic1
"{5B79CFD1-6845-4158-9D7D-6BE89DF2C135}" = HP PSC & OfficeJet 5.3.B
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Sonic Express Labeler
"{66BA8C26-AFE4-4408-807B-43E76B57EF53}" = SkinsHP1
"{6BB6627C-694F-4FDC-A3E5-C7F4BED4C724}" = DocProc
"{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}" = Microsoft Plus! Digital Media Edition Installer
"{755EC5E3-FD51-46bd-A57F-7A2D56FBF061}" = PSTAPlugin
"{769A295C-DCF4-41d6-AFBA-7D9394B23AFE}" = PSPrinters08
"{7850A6D2-CBEA-4728-9877-F1BEDEA9F619}" = AiOSoftware
"{7C03270C-4FAB-4F5C-B10D-52FEDA190790}" = DocumentViewerQFolder
"{7E27304E-BAA2-4d90-A34E-76641FAFABB4}" = CP_AtenaShokunin1Config
"{8105684D-8CA6-440D-8F58-7E5FD67A499D}" = Easy Internet Sign-up
"{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver
"{8D0C57BC-4942-4960-BB6D-142456D6F233}" = HP Image Zone for Media Center PC
"{91120409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Standard Edition 2003
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD Player
"{923A7F5A-1E8C-4FBE-8DF6-85940A60A79F}" = Readme
"{9941F0AA-B903-4AF4-A055-83A9815CC011}" = Sonic Encoders
"{A06275F4-324B-4E85-95E6-87B2CD729401}" = Windows Defender
"{A195B13E-A5E3-4BAF-A995-7F70F445CD06}" = ScannerCopy
"{A3455242-DAE0-4523-8242-FD82706ABF4B}" = CameraDrivers
"{A5BB5365-EFB4-44c3-A7E2-EB59B7EFD23D}" = CueTour
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AB61A692-5543-4C48-979B-8CEA1C52FE9C}" = PC-Doctor 5 for Windows
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Sonic RecordNow Audio
"{AC76BA86-7AD7-1033-7B44-A70000000000}" = Adobe Reader 7.0
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Sonic RecordNow Copy
"{B1931B3A-29E9-4F91-9B61-BE2CF05E84F1}" = muvee autoProducer unPlugged 1.1 - HPD
"{B4D279F1-4309-49cc-A4B5-3A0D2E59C7B5}" = PanoStandAlone
"{B824B5C9-849F-4b9e-9EA7-6FD8CD8116DA}" = CP_Package_Variety2
"{B996AE66-10DB-4ac5-B151-E8B4BFBC42FC}" = BufferChm
"{BE9FEFBA-F2F8-468B-A108-4356F73A3E9C}" = Office 2003 Tour
"{C506A18C-1469-4678-B094-F4EC9DAE6DB7}" = Scan
"{C83A12B9-B31B-461A-BBD4-CE9B988094F1}" = HP Photosmart Cameras 5.0
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE24344F-DFD8-40C8-8FD8-C9740B5F25AC}" = Fax
"{D518592A-0F1E-40ca-BECB-3D3F026C6B0D}" = CameraDrivers
"{DB518BA6-CB74-4EB6-9ABD-880B6D6E1F38}" = HpSdpAppCoreApp
"{E3F90083-80D4-4b5a-87C7-E97E12F5516D}" = HPProductAssistant
"{EA103B64-C0E4-4C0E-A506-751590E1653D}" = SolutionCenter
"{ECFDD6BD-E0C0-41CC-A171-E6D6AF4C0E93}" = HP Software Update
"{F4C2E5F5-2970-45f4-ABD3-C180C4D961C4}" = Status
"{F4C68898-EBA5-46A9-82B3-2D30426086BF}" = AVG 2011
"{F80239D8-7811-4D5E-B033-0D0BBFE32920}" = HP DigitalMedia Archive
"AVG" = AVG 2011
"B3EE3001-DC24-4cd1-8743-5692C716659F" = Otto
"CNXT_MODEM_PCI_VEN_14F1&DEV;_2F20&SUBSYS;_200C14F1" = Data Fax SoftModem with SmartCP
"HP Document Viewer" = HP Document Viewer 5.3
"HP Imaging Device Functions" = HP Imaging Device Functions 5.3
"HP Photo & Imaging" = HP Image Zone 5.3
"HP Solution Center & Imaging Support Tools" = HP Solution Center & Imaging Support Tools 5.3
"HPOOVClient-9972322 Uninstaller" = Updates from HP (remove only)
"InstallShield_{2DBE41DD-2129-4C65-A3D3-5647236A60F3}" = Quicken 2005
"InstallShield_{523E6F2A-2D59-4D91-90E8-6C49931C9F50}" = iTunes
"InstallShield_{8105684D-8CA6-440D-8F58-7E5FD67A499D}" = Easy Internet Sign-up
"InstallShield_{AB61A692-5543-4C48-979B-8CEA1C52FE9C}" = PC-Doctor 5 for Windows
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Money2005b" = Microsoft Money 2005
"PS2" = PS2
"Python 2.2.3" = Python 2.2.3
"pywin32-py2.2" = Python 2.2 pywin32 extensions (build 203)
"QuickTime" = QuickTime
"RealPlayer 6.0" = RealPlayer
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows XP Service Pack" = Windows XP Service Pack 3

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 1/4/2011 5:26:48 PM | Computer Name = FERGUSONHOME | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The connection with the server was terminated abnormally

Error - 1/4/2011 5:26:49 PM | Computer Name = FERGUSONHOME | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 1/4/2011 5:26:49 PM | Computer Name = FERGUSONHOME | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 1/4/2011 6:11:36 PM | Computer Name = FERGUSONHOME | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 80004002, P2 cocreateinstance(updateservicemanager),
P3 fallbackcheck, P4 1.1.1593.0, P5 mpsigdwn.dll, P6 1.1.1593.0, P7 windows defender,
P8 NIL, P9 NIL, P10 NIL.

Error - 1/4/2011 6:35:52 PM | Computer Name = FERGUSONHOME | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.5512, faulting
module ntdll.dll, version 5.1.2600.5512, fault address 0x00023825.

Error - 1/4/2011 8:17:56 PM | Computer Name = FERGUSONHOME | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.5512, faulting
module ntdll.dll, version 5.1.2600.5512, fault address 0x00023825.

[ System Events ]
Error - 1/4/2011 9:12:20 PM | Computer Name = FERGUSONHOME | Source = Service Control Manager | ID = 7023
Description = The Network Security service terminated with the following error:
%%126

Error - 1/4/2011 9:12:20 PM | Computer Name = FERGUSONHOME | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
iaStor PCIIde ViaIde


< End of report >


HJT Log:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 6:45:05 PM, on 1/4/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\PROGRA~1\AVG\AVG10\avgchsvx.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\Program Files\AVG\AVG10\avgtray.exe
C:\Program Files\AVG\AVG10\avgfws.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\AVG\AVG10\avgwdsvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\Program Files\AVG\AVG10\avgam.exe
C:\Program Files\AVG\AVG10\avgnsx.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCMTR.EXE
C:\WINDOWS\ALCWZRD.EXE
c:\windows\system\hpsysdrv.exe
C:\Program Files\Java\jre1.5.0\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\AVG\AVG10\avgcsrvx.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\AVG\AVG10\avgrsx.exe
C:\Program Files\AVG\AVG10\avgcsrvx.exe
C:\Documents and Settings\HP_Administrator\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…arm1=seconduser
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…arm1=seconduser
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…arm1=seconduser
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…arm1=seconduser
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…arm1=seconduser
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…arm1=seconduser
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…arm1=seconduser
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…arm1=seconduser
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…arm1=seconduser
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…arm1=seconduser
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…arm1=seconduser
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…arm1=seconduser
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: &Google; Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: AVG Security Toolbar Service - Unknown owner - C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe
O23 - Service: AVG Firewall (avgfws) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10\avgfws.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10\avgwdsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe

–
End of file - 9181 bytes


DDS Log:

DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 18:46:58.79 on Tue 01/04/2011
Internet Explorer: 6.0.2900.5512
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.503.49 [GMT -7:00]

AV: AVG Internet Security 2011 *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: AVG Firewall *enabled* {8decf618-9569-4340-b34a-d78d28969b66}

============== Running Processes ===============

C:\PROGRA~1\AVG\AVG10\avgchsvx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\Program Files\AVG\AVG10\avgtray.exe
C:\Program Files\AVG\AVG10\avgfws.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\AVG\AVG10\avgwdsvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\Program Files\AVG\AVG10\avgam.exe
C:\Program Files\AVG\AVG10\avgnsx.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCMTR.EXE
C:\WINDOWS\ALCWZRD.EXE
c:\windows\system\hpsysdrv.exe
C:\Program Files\Java\jre1.5.0\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\AVG\AVG10\avgcsrvx.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\AVG\AVG10\avgrsx.exe
C:\Program Files\AVG\AVG10\avgcsrvx.exe
C:\Documents and Settings\HP_Administrator\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iehome&locale;=EN_US&c;=Q405&bd;=pavilion&pf;=desktop&parm1;=seconduser
uSearch Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iesearch&locale;=EN_US&c;=Q405&bd;=pavilion&pf;=desktop&parm1;=seconduser
uSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iesearch&locale;=EN_US&c;=Q405&bd;=pavilion&pf;=desktop&parm1;=seconduser
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iehome&locale;=EN_US&c;=Q405&bd;=pavilion&pf;=desktop&parm1;=seconduser
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iesearch&locale;=EN_US&c;=Q405&bd;=pavilion&pf;=desktop&parm1;=seconduser
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iehome&locale;=EN_US&c;=Q405&bd;=pavilion&pf;=desktop&parm1;=seconduser
mDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iesearch&locale;=EN_US&c;=Q405&bd;=pavilion&pf;=desktop&parm1;=seconduser
mSearch Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iesearch&locale;=EN_US&c;=Q405&bd;=pavilion&pf;=desktop&parm1;=seconduser
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iehome&locale;=EN_US&c;=Q405&bd;=pavilion&pf;=desktop&parm1;=seconduser
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iesearch&locale;=EN_US&c;=Q405&bd;=pavilion&pf;=desktop&parm1;=seconduser
uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iehome&locale;=EN_US&c;=Q405&bd;=pavilion&pf;=desktop&parm1;=seconduser
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
mSearchAssistant = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iesearch&locale;=EN_US&c;=Q405&bd;=pavilion&pf;=desktop&parm1;=seconduser
mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg10\toolbar\IEToolbar.dll
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg10\avgssie.dll
BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg10\toolbar\IEToolbar.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar1.dll
TB: &Google;: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar1.dll
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg10\toolbar\IEToolbar.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [High Definition Audio Property Page Shortcut] HDAShCut.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [HPHUPD08] c:\program files\hp\digital imaging\{33d6cc28-9f75-4d1b-a11d-98895b3a3729}\hphupd08.exe
mRun: [PCDrProfiler]
mRun: [HPBootOp] "c:\program files\hewlett-packard\hp boot optimizer\HPBootOp.exe" /run
mRun: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPwuSchd2.exe
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [AVG_TRAY] c:\program files\avg\avg10\avgtray.exe
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
IE: &Google; Search - c:\program files\google\GoogleToolbar1.dll/cmsearch.html
IE: Backward Links - c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\google\GoogleToolbar1.dll/cmcache.html
IE: E&xport; to Microsoft Excel - c:\progra~1\mi1933~1\office11\EXCEL.EXE/3000
IE: Similar Pages - c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate into English - c:\program files\google\GoogleToolbar1.dll/cmtrans.html
IE: {E2D4D26B-0180-43a4-B05F-462D6D54C789} - c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\iebutton\support.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBC} - c:\program files\java\jre1.5.0\bin\npjpi150.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office11\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\avg\avg10\toolbar\IEToolbar.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg10\avgpp.dll
Notify: igfxcui - igfxdev.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll

============= SERVICES / DRIVERS ===============

R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2010-9-13 25680]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2010-9-7 26064]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2010-12-8 251728]
R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2010-9-7 34384]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2010-11-12 299984]
R2 avgfws;AVG Firewall;c:\program files\avg\avg10\avgfws.exe [2010-11-22 3226632]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg10\identity protection\agent\bin\AVGIDSAgent.exe [2010-11-23 6128208]
R2 avgwd;AVG WatchDog;c:\program files\avg\avg10\avgwdsvc.exe [2010-10-22 265400]
R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [2010-7-12 30432]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2010-8-19 123472]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2010-8-19 30288]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2010-8-19 26192]
S2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\avg\avg10\toolbar\ToolbarBroker.exe [2011-1-4 517448]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [2010-7-12 30432]

=============== Created Last 30 ================

2011-01-04 18:07 –d-h— C:\$AVG
2011-01-04 17:40 –d—– c:\docume~1\hp_adm~1\applic~1\Malwarebytes
2011-01-04 17:39 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2011-01-04 17:39 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2011-01-04 17:39 20,952 a——- c:\windows\system32\drivers\mbam.sys
2011-01-04 17:39 –d—– c:\program files\Malwarebytes' Anti-Malware
2011-01-04 14:43 –d—– c:\docume~1\hp_adm~1\applic~1\AVG10
2011-01-04 14:34 –d-h— c:\docume~1\alluse~1\applic~1\Common Files
2011-01-04 14:33 –d—– c:\docume~1\alluse~1\applic~1\AVG Security Toolbar
2011-01-04 14:31 –d—– c:\windows\system32\drivers\AVG
2011-01-04 14:31 –d—– c:\docume~1\alluse~1\applic~1\AVG10
2011-01-04 14:31 –d—– c:\program files\AVG
2011-01-04 14:25 –d—– c:\docume~1\alluse~1\applic~1\MFAData
2011-01-04 14:14 1,306,624 ——– c:\windows\system32\dllcache\msxml6.dll
2011-01-04 14:14 79,872 ——– c:\windows\system32\dllcache\msxml6r.dll
2011-01-04 14:14 1,306,624 ——– c:\windows\system32\msxml6.dll
2011-01-04 14:14 79,872 ——– c:\windows\system32\msxml6r.dll
2011-01-04 14:14 46,592 ——– c:\windows\system32\drivers\irbus.sys
2011-01-04 14:14 10,752 ——– c:\windows\system32\smtpapi.dll
2011-01-04 14:14 9,728 ——– c:\windows\system32\rwnh.dll
2011-01-04 14:14 9,728 ——– c:\windows\system32\comsdupd.exe
2011-01-04 14:14 3,990 ——– c:\windows\system32\wbem\napclientschema.mof
2011-01-04 14:14 638 ——– c:\windows\system32\wbem\napclientprov.mof
2011-01-04 14:11 –d—– c:\windows\ServicePackFiles
2011-01-04 14:07 19,569 a——- c:\windows\002992_.tmp
2011-01-04 13:20 –dshr– C:\cmdcons
2011-01-04 13:20 –d—– c:\windows\setup.pss
2011-01-04 13:16 –d—– c:\windows\system32\appmgmt
2011-01-04 13:07 –d—– c:\program files\Microsoft
2011-01-04 13:06 90,112 a——- c:\windows\system32\ps2.EXE
2011-01-04 13:04 –d—– c:\docume~1\hp_adm~1\applic~1\Symantec
2011-01-04 13:04 –d—– c:\docume~1\hp_adm~1\applic~1\Intuit
2011-01-04 13:04 –d—– c:\documents and settings\hp_administrator\WINDOWS
2011-01-04 13:04 –d—– c:\documents and settings\HP_Administrator
2011-01-04 11:26 248 a——- c:\windows\system\hpsysdrv.dat
2011-01-04 11:25 –d—– c:\windows\I386
2011-01-04 11:17 –d–r– c:\documents and settings\all users\Documents
2011-01-04 11:17 –d–r– c:\windows\Offline Web Pages
2011-01-04 11:15 –dshr– c:\windows\system32\dllcache
2010-12-08 04:12 251,728 a——- c:\windows\system32\drivers\avgldx86.sys

==================== Find3M ====================

2011-01-04 14:17 92,191 a——- c:\windows\pchealth\helpctr\offlinecache\index.dat
2011-01-04 14:16 287,310 a——- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\HPBasicDetection.dll
2011-01-04 14:16 163,840 a——- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\modemcheck.dll
2011-01-04 14:16 61,440 a——- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\modemutil.dll
2011-01-04 14:16 45,056 a——- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\uninstallui\eHelpSetup.exe
2011-01-04 14:16 44,032 a——- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\scripts\devcon.exe
2011-01-04 14:16 40,960 a——- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\ScDmi.dll
2011-01-04 14:16 32,768 a——- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\uploadHSC.dll
2011-01-04 14:16 32,768 a——- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\Scom.dll
2010-11-12 13:19 299,984 a——- c:\windows\system32\drivers\avgtdix.sys

============= FINISH: 18:47:53.51 ===============
Hi bergferg,

Don't panic yet, the popup may have just been a drive by. Did you reinstall any of your backed up data?

Please post the MBAM log. You can find it by opening MBAM and clicking on the Logs tab.
  • Locate the log and click on it
  • Click open

Should you recieve another popup like that just click the X to close it.

Thanks
Here is the MBAM Log: Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 5461 Windows 5.1.2600 Service Pack 3 Internet Explorer 6.0.2900.5512 1/4/2011 6:08:40 PM mbam-log-2011-01-04 (18-08-40).txt Scan type: Quick scan Objects scanned: 147331 Time elapsed: 7 minute(s), 26 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 1 Registry Data Items Infected: 1 Folders Infected: 0 Files Infected: 8 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\JP595IR86O (Trojan.FraudPack) -> Value: JP595IR86O -> Quarantined and deleted successfully. Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: c:\WINDOWS\Temp\Wri.exe (Trojan.FraudPack) -> Quarantined and deleted successfully. c:\WINDOWS\Temp\Wrh.exe (Trojan.FraudPack) -> Quarantined and deleted successfully. c:\WINDOWS\Temp\Wrj.exe (Trojan.FraudPack) -> Quarantined and deleted successfully. c:\WINDOWS\system32\6to4v32.dll (Trojan.Agent) -> Quarantined and deleted successfully. c:\WINDOWS\system32\certstore.dat (Trojan.Agent) -> Quarantined and deleted successfully. c:\WINDOWS\Tasks\{22116563-108c-42c0-a7ce-60161b75e508}.job (Trojan.Downloader) -> Quarantined and deleted successfully. c:\WINDOWS\Tasks\{62c40aa6-4406-467a-a5a5-dfdf1b559b7a}.job (Trojan.FakeAlert) -> Quarantined and deleted successfully. c:\WINDOWS\Tasks\{bbaeaeaf-1275-40e2-bd6c-bc8f88bd114a}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
I came back from work today and AVG had run a full system scan while I was away. It came back with a threat identified as "Adware Generic2.TQI" I've not done anything with the results from that sacn such as quarantine the file it was associated with, so I will wait to hear back from you. Thanks.
Hi bergferg,

Did AVG identify the file and it's location? Is please post the entire file path. It will be something like C:\folder\filename

Some of those infections are the same as you had previously. It will be interesting to see where this came from. Did you restore any of your backed up data to the computer and were you on line prior to the MBAM scan?

Let's see if there is anything else.

Go HERE to get a randomly named copy of GMER. Scroll down to the Download section and click Download EXE. Save it to your desktop.

Before scanning with GMER, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

  • Double click on the file you downloaded. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


If GMER will not run in normal windows, please run it in Safe Mode

Please post back with the GMER log.

Thanks
The file path names are: c:\System Volume Information\_restore{D7BD54B8-C977-4903-8CE7-9415B851EC71}\RP7\A0006681.exe c:\System Volume Information\_restore{D7BD54B8-C977-4903-8CE7-9415B851EC71}\RP7\A0006681.exe
Also, I have not re-installed any old files or information, just the AV and protection items you listed above.

Here is the GMER Log:
GMER 1.0.15.15530 - http://www.gmer.net
Rootkit scan 2011-01-06 13:31:54
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdePort2 Maxtor_6L200M0 rev.BANC1G10
Running: m67lrhvv.exe; Driver: C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\kwtcypow.sys


—- System - GMER 1.0.15 —-

SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwOpenProcess [0xF87156C0]
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateProcess [0xF8715770]
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateThread [0xF8715810]
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwWriteVirtualMemory [0xF87158B0]

—- User code sections - GMER 1.0.15 —-

.text C:\WINDOWS\System32\svchost.exe[1496] ntdll.dll!NtProtectVirtualMemory 7C90D6D0 5 Bytes JMP 007F000A
.text C:\WINDOWS\System32\svchost.exe[1496] ntdll.dll!NtWriteVirtualMemory 7C90DF90 5 Bytes JMP 0080000A
.text C:\WINDOWS\System32\svchost.exe[1496] ntdll.dll!KiUserExceptionDispatcher 7C90E45C 5 Bytes JMP 007E000C
.text C:\WINDOWS\System32\svchost.exe[1496] USER32.dll!GetCursorPos 7E42974E 5 Bytes JMP 0175000A
.text C:\WINDOWS\System32\svchost.exe[1496] ole32.dll!CoCreateInstance 7750057E 5 Bytes JMP 00CF000A
.text C:\WINDOWS\Explorer.EXE[1956] ntdll.dll!NtProtectVirtualMemory 7C90D6D0 5 Bytes JMP 00A8000A
.text C:\WINDOWS\Explorer.EXE[1956] ntdll.dll!NtWriteVirtualMemory 7C90DF90 5 Bytes JMP 00A9000A
.text C:\WINDOWS\Explorer.EXE[1956] ntdll.dll!KiUserExceptionDispatcher 7C90E45C 5 Bytes JMP 00A2000C

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs bb-run.sys (Promise Disk Accelerator/Promise Technology, Inc.)
AttachedDevice \FileSystem\Ntfs \Ntfs AVGIDSFilter.Sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. )
AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \Driver\atapi -> DriverStartIo \Device\Ide\IdeDeviceP0T0L0-3 829123B2
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort0 829123B2
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort1 829123B2
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort2 829123B2
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort3 829123B2

AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \FileSystem\Fastfat \Fat bb-run.sys (Promise Disk Accelerator/Promise Technology, Inc.)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat AVGIDSFilter.Sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. )

Device \Device\Ide\IdeDeviceP2T1L0-e -> \??\IDE#DiskMaxtor_6L200M0__________________________BANC1G10#344c51305635473320
2020202020202020202020#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found

—- Disk sectors - GMER 1.0.15 —-

Disk \Device\Harddisk0\DR0 sector 00 (MBR): rootkit-like behavior; TDL4 <– ROOTKIT !!!
Disk \Device\Harddisk0\DR0 sector 32: rootkit-like behavior;
Disk \Device\Harddisk0\DR0 sector 63: rootkit-like behavior;
Disk \Device\Harddisk0\DR0 sectors 390721712 (+255): rootkit-like behavior;

—- EOF - GMER 1.0.15 —-

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI