i think i have a virus
28 min read
Welcome to the WhatTheTech Forums. My name is Thomas (Tom is fine), and I will be helping you fixing your problems.
Please take note of some guidelines for this fix:
- Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
- If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
- Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
- Do not start a new topic. The logs that you post should be pasted directly into the reply. Only attach them if requested or if they do not fit into the post.
- Please set your system to show all files.
Click Start, open My Computer, select the Tools menu and click Folder Options.
Select the View Tab. Under the Hidden files and folders heading, select Show hidden files and folders.
Uncheck: Hide file extensions for known file types
Uncheck the Hide protected operating system files (recommended) option.
Click Yes to confirm.
- Please download OTL from one of the following mirrors:
- This is THE Mirror
- Save it to your desktop.
- Double click on the [external image: Posted Image] icon on your desktop.
- Under the Custom Scan box paste this in
netsvcs
%SYSTEMDRIVE%\*.exe
%systemroot%\*. /mp /s
CREATERESTOREPOINT - Push the Quick Scan button.
- Two reports will open, copy and paste them in a reply here:
- OTL.txt <– Will be opened
- Extra.txt <– Will be minimized
Please download Rootkit Unhooker from one of the following links and save it to your desktop. Link 1 (.exe file) Link 2 (zipped file) Link 3 (.rar file)
In order to use this tool if you downloaded from either of the second two links, you will need to extract the RKUnhookerLE.exe file using a program capable of extracing ZIP and RAR compressed files. If you don't have an extraction program, you can downlaod, install and use the free 7-zip utility.
- Double-click on RKUnhookerLE.exe to start the program. Vista/Windows 7 users right-click and select Run As Administrator.
- Click the Report tab, then click Scan.
- Check Drivers, Stealth, and uncheck the rest.
- Click OK.
- Wait until it's finished and then go to File > Save Report.
- Save the report to your Desktop.
- Copy and paste the contents of the report into your next reply.
OTL logfile created on: 2/20/2011 11:58:01 AM - Run 1
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 63.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 91.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 142.96 Gb Total Space | 117.11 Gb Free Space | 81.92% Space Free | Partition Type: NTFS
Drive D: | 6.07 Gb Total Space | 0.72 Gb Free Space | 11.87% Space Free | Partition Type: FAT32
Drive E: | 558.09 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: YOUR-03667082DE | User Name: HP_Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/02/20 11:57:38 | 000,602,624 | —- | M] (OldTimer Tools) – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop\OTL.exe
PRC - [2004/10/21 18:25:36 | 000,045,056 | —- | M] (Hewlett-Packard) – C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
PRC - [2004/10/21 16:27:22 | 000,032,881 | —- | M] () – C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
PRC - [2004/08/04 04:00:00 | 001,032,192 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
========== Modules (SafeList) ==========
MOD - [2011/02/20 11:57:38 | 000,602,624 | —- | M] (OldTimer Tools) – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop\OTL.exe
MOD - [2004/10/21 18:25:35 | 000,024,613 | —- | M] (BackWeb) – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Local Settings\Temp\IadHide5.dll
MOD - [2004/08/04 11:00:00 | 001,050,624 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [Disabled | Stopped] – – (HidServ)
SRV - File not found [On_Demand | Stopped] – – (AppMgmt)
========== Driver Services (SafeList) ==========
DRV - [2005/04/20 11:00:56 | 002,317,696 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ALCXWDM.SYS – (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2005/04/12 11:42:16 | 000,011,904 | —- | M] (Silicon Integrated Systems Corporation) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\srvkp.sys – (SiSkp)
DRV - [2005/04/12 11:08:44 | 000,247,296 | —- | M] (Silicon Integrated Systems Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\sisgrp.sys – (SiS315)
DRV - [2004/05/08 16:21:44 | 000,035,840 | —- | M] (Advanced Micro Devices) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\AmdK8.sys – (AmdK8)
DRV - [2003/12/02 17:23:20 | 000,142,336 | —- | M] (Promise Technology, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\fasttx2k.sys – (fasttx2k)
DRV - [2003/09/19 01:47:00 | 000,010,368 | —- | M] (Padus, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\pfc.sys – (Pfc)
DRV - [2003/09/10 23:36:54 | 000,021,060 | —- | M] (InterVideo, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\iviaspi.sys – (Iviaspi)
DRV - [2003/07/18 15:58:20 | 000,036,992 | —- | M] (Silicon Integrated Systems Corporation) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\SISAGPX.sys – (SISAGP)
DRV - [2003/07/11 21:28:56 | 000,032,768 | —- | M] (SiS Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\sisnic.sys – (SISNIC)
DRV - [2003/07/02 10:42:00 | 000,027,904 | —- | M] (VIA Technologies, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\viaagp1.sys – (viaagp1)
DRV - [2002/10/04 16:04:10 | 000,046,976 | —- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\R8139n51.sys – (rtl8139)
DRV - [2001/08/17 13:28:02 | 000,907,456 | —- | M] (Conexant) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HCF_MSFT.sys – (HCF_MSFT)
DRV - [2001/06/04 13:00:00 | 000,014,112 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\PS2.sys – (Ps2)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?ilc=1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
[2010/12/12 22:26:36 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/12/12 22:26:36 | 000,000,000 | —D | M] (Skype extension) – C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2010/09/14 04:41:12 | 000,002,506 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\BearShareWebSearch.xml
O1 HOSTS File: ([2004/08/04 11:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found.
O3 - HKLM\..\Toolbar: (HP view) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll (Hewlett-Packard Company)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (HP view) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll (Hewlett-Packard Company)
O3 - HKCU\..\Toolbar\WebBrowser: (HP view) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll (Hewlett-Packard Company)
O4 - HKLM..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe (Hewlett-Packard)
O4 - HKLM..\Run: [IS CfgWiz] File not found
O4 - HKLM..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\LSBurnWatcher.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [PS2] C:\WINDOWS\system32\ps2.EXE (Hewlett-Packard Company)
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\Recguard.exe ()
O4 - HKLM..\Run: [Reminder] C:\Windows\Creator\Remind_XP.exe (SoftThinks)
O4 - HKLM..\Run: [SiSPower] C:\WINDOWS\System32\SiSPower.dll (Silicon Integrated Systems Corporation)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe ()
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UpdateManager] C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe (Sonic Solutions)
O4 - HKLM..\Run: [VTTimer] File not found
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe (Hewlett-Packard)
O4 - Startup: C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\Startup\Advanced Registry Optimizer.lnk = File not found
O4 - Startup: C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\Startup\HP Organize.lnk = C:\Program Files\Hewlett-Packard\HP Organize\bin\displayAgent.exe (NeoPlanet)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Add To HP Organize… - C:\PROGRA~1\HEWLET~1\HPORGA~1\bin/module.main/favorites\ie_add_to.html ()
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Reg Error: Key error. File not found
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2_03)
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2_03)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/02/05 12:23:24 | 000,000,050 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2001/07/28 06:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O32 - AutoRun File - [2004/04/30 22:01:14 | 000,000,053 | -HS- | M] () - D:\Autorun.inf – [ FAT32 ]
O32 - AutoRun File - [2010/09/14 14:03:30 | 000,000,067 | RH– | M] () - E:\Autorun.inf – [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (56590081070202880)
========== Files/Folders - Created Within 30 Days ==========
[2011/02/20 11:57:24 | 000,602,624 | —- | C] (OldTimer Tools) – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop\OTL.exe
[2011/02/20 10:42:04 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Malwarebytes
[2011/02/20 10:41:49 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/02/20 10:41:48 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/02/20 10:41:48 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/02/20 10:41:45 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/02/20 10:41:45 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/02/20 10:40:30 | 007,734,208 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop\mbam-setup-1.50.1.1100.exe
[2011/02/19 21:59:59 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Sammsoft
[2011/02/19 21:09:57 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Local Settings\Application Data\OpenCandy
[2011/02/19 21:09:56 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\OpenCandy
[2011/02/19 21:09:54 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Xfire
[2011/02/19 21:09:53 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Xfire
[2011/02/19 21:09:52 | 000,000,000 | —D | C] – C:\Program Files\Xfire
[2011/02/19 16:07:18 | 000,000,000 | —D | C] – C:\9ed20b7a62c8e74031b5087805ec2c
[2011/02/15 15:55:17 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\MysteryChronicles
[2011/02/15 15:54:23 | 000,000,000 | —D | C] – C:\Program Files\Mystery Chronicles - Murder Among Friends
[2011/02/15 15:54:23 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Mystery Chronicles - Murder Among Friends
[2011/02/14 11:35:29 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Local Settings\Application Data\Identities
[2011/02/13 12:09:09 | 000,000,000 | —D | C] – C:\Program Files\Mystery Case Files - Dire Grove
[2011/02/13 12:09:09 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Mystery Case Files - Dire Grove
[2011/02/12 14:59:53 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\ERS G-Studio
[2011/02/12 14:57:57 | 000,000,000 | —D | C] – C:\Program Files\Dark Tales - Edgar Allan Poe`s Murders in the Rue Morgue
[2011/02/12 14:57:57 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Dark Tales - Edgar Allan Poe`s Murders in the Rue Morgue
[2011/02/12 14:50:30 | 000,000,000 | —D | C] – C:\Program Files\Midnight Mysteries - The Edgar Allan Poe Conspiracy
[2011/02/12 14:50:30 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Midnight Mysteries - The Edgar Allan Poe Conspiracy
[2011/02/12 09:22:22 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Friday's games
[2011/02/12 09:20:58 | 000,000,000 | —D | C] – C:\Program Files\Stray Souls - Dollhouse Story Collector's Edition
[2011/02/12 09:20:58 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Stray Souls - Dollhouse Story Collector's Edition
[2011/02/12 09:11:08 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Big Fish Games
[2011/02/11 21:16:55 | 000,000,000 | -HSD | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\IECompatCache
[2011/02/11 21:16:29 | 000,000,000 | -HSD | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\PrivacIE
[2011/02/11 21:11:27 | 000,000,000 | -HSD | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\IETldCache
[2011/02/11 19:53:47 | 000,000,000 | —D | C] – C:\WINDOWS\System32\en-US
[2011/02/06 06:16:02 | 000,000,000 | —D | C] – C:\WINDOWS\System32\CatRoot_bak
[2011/02/05 22:09:26 | 000,000,000 | —D | C] – C:\WINDOWS\System32\PreInstall
[2011/02/05 18:33:09 | 000,000,000 | —D | C] – C:\Program Files\Mystery Case Files - 13th Skull
[2011/02/05 18:33:09 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Mystery Case Files - 13th Skull
[2011/02/05 16:51:32 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Big Fish Games
[2011/02/05 16:51:21 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\TEMP
[2011/02/05 16:38:09 | 000,000,000 | —D | C] – C:\Program Files\bfgclient
[2011/02/05 16:37:22 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\BigFishGamesCache
[2011/02/05 13:04:47 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\My Documents\My eBooks
[2011/02/05 12:35:41 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Adobe
[2011/02/05 12:30:36 | 000,000,000 | –SD | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\UserData
[2011/02/05 12:30:00 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Macromedia
[2011/02/05 12:28:06 | 000,000,000 | RHSD | C] – C:\cmdcons
[2011/02/05 12:27:45 | 000,000,000 | —D | C] – C:\WINDOWS\setupupd
[2011/02/05 12:27:36 | 000,000,000 | RH-D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Recent
[2011/02/05 12:25:19 | 000,000,000 | –SD | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Microsoft
[2011/02/05 12:25:19 | 000,000,000 | RH-D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\SendTo
[2011/02/05 12:25:19 | 000,000,000 | RH-D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data
[2011/02/05 12:25:19 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\Startup
[2011/02/05 12:25:19 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu
[2011/02/05 12:25:19 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\My Documents\My Videos
[2011/02/05 12:25:19 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\My Documents\My Pictures
[2011/02/05 12:25:19 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\My Documents\My Music
[2011/02/05 12:25:19 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\My Documents
[2011/02/05 12:25:19 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Favorites
[2011/02/05 12:25:19 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\Accessories
[2011/02/05 12:25:19 | 000,000,000 | -HSD | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Cookies
[2011/02/05 12:25:19 | 000,000,000 | -H-D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Templates
[2011/02/05 12:25:19 | 000,000,000 | -H-D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\PrintHood
[2011/02/05 12:25:19 | 000,000,000 | -H-D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\NetHood
[2011/02/05 12:25:19 | 000,000,000 | -H-D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Local Settings
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\WINDOWS
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\WeatherBug
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Symantec
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Sun
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\SpySubtract Spyware Manager
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\SpamSubtract Spam Manager
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Sonic
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\SampleView
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Real
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\Quicken
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\PC Help & Tools
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\Online Services
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Local Settings\Application Data\Microsoft
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Identities
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\Games
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Local Settings\Application Data\ApplicationHistory
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Local Settings\Application Data\Apple Computer
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Apple Computer
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Local Settings\Application Data\{7148F0A6-6813-11D6-A77B-00B0D0142030}
[2011/02/05 12:22:59 | 000,021,060 | —- | C] (InterVideo, Inc.) – C:\WINDOWS\System32\drivers\iviaspi.sys
[2011/02/05 12:21:59 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office (60 Day Trial)
[2011/02/05 12:20:10 | 000,000,000 | —D | C] – C:\Program Files\SiS VGA Utilities V3.63
[2011/02/05 12:17:57 | 000,000,000 | —D | C] – C:\WINDOWS\System32\SoftwareDistribution
[2011/02/05 11:11:08 | 000,000,000 | —D | C] – C:\WINDOWS\System32\trayres
[2011/02/05 10:47:05 | 000,000,000 | RHSD | C] – C:\WINDOWS\System32\dllcache
[2011/01/25 13:38:37 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\ConduitEngine
[2011/01/25 13:38:35 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\bearsharemediabartb
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/02/20 11:57:38 | 000,602,624 | —- | M] (OldTimer Tools) – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop\OTL.exe
[2011/02/20 11:56:00 | 000,000,428 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{2B9ABC23-7E4A-4EF3-ACD7-A7C28B953E38}.job
[2011/02/20 11:37:00 | 000,000,396 | —- | M] () – C:\WINDOWS\tasks\At12.job
[2011/02/20 11:16:00 | 000,000,890 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/02/20 11:06:06 | 000,054,016 | —- | M] () – C:\WINDOWS\System32\drivers\bkhded.sys
[2011/02/20 11:01:00 | 000,000,240 | —- | M] () – C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2011/02/20 10:41:49 | 000,000,795 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/02/20 10:41:28 | 007,734,208 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop\mbam-setup-1.50.1.1100.exe
[2011/02/20 10:37:00 | 000,000,396 | —- | M] () – C:\WINDOWS\tasks\At11.job
[2011/02/20 10:14:38 | 000,000,428 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{0C07C01B-5CD2-4771-9302-946C711BE426}.job
[2011/02/20 10:11:47 | 000,003,645 | —- | M] () – C:\WINDOWS\viassary-hp.reg
[2011/02/20 10:11:43 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/02/20 10:11:42 | 000,000,249 | —- | M] () – C:\WINDOWS\System\hpsysdrv.dat
[2011/02/20 10:11:35 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/02/20 10:11:34 | 1475,923,968 | -HS- | M] () – C:\hiberfil.sys
[2011/02/19 21:59:43 | 000,173,080 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/02/19 21:10:34 | 000,000,967 | —- | M] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\Startup\Advanced Registry Optimizer.lnk
[2011/02/19 21:09:53 | 000,000,667 | —- | M] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Microsoft\Internet Explorer\Quick Launch\Xfire.lnk
[2011/02/19 21:09:53 | 000,000,649 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Xfire.lnk
[2011/02/19 16:18:39 | 000,002,229 | —- | M] () – C:\WINDOWS\epplauncher.mif
[2011/02/19 09:37:02 | 000,000,396 | —- | M] () – C:\WINDOWS\tasks\At8.job
[2011/02/19 08:37:00 | 000,000,396 | —- | M] () – C:\WINDOWS\tasks\At7.job
[2011/02/19 07:37:00 | 000,000,396 | —- | M] () – C:\WINDOWS\tasks\At5.job
[2011/02/19 06:37:00 | 000,000,396 | —- | M] () – C:\WINDOWS\tasks\At9.job
[2011/02/19 05:37:00 | 000,000,396 | —- | M] () – C:\WINDOWS\tasks\At4.job
[2011/02/19 04:37:00 | 000,000,396 | —- | M] () – C:\WINDOWS\tasks\At6.job
[2011/02/19 03:37:00 | 000,000,396 | —- | M] () – C:\WINDOWS\tasks\At10.job
[2011/02/19 02:37:00 | 000,000,396 | —- | M] () – C:\WINDOWS\tasks\At2.job
[2011/02/19 01:37:00 | 000,000,396 | —- | M] () – C:\WINDOWS\tasks\At3.job
[2011/02/19 00:37:00 | 000,000,396 | —- | M] () – C:\WINDOWS\tasks\At1.job
[2011/02/16 15:56:45 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/02/15 15:54:34 | 000,001,884 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Play Mystery Chronicles - Murder Among Friends.lnk
[2011/02/13 12:14:18 | 000,001,784 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Play Mystery Case Files - Dire Grove.lnk
[2011/02/12 16:21:11 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/02/12 14:59:06 | 000,002,035 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Play Dark Tales - Edgar Allan Poe`s Murders in the Rue Morgue.lnk
[2011/02/12 14:51:05 | 000,002,034 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Play Midnight Mysteries - The Edgar Allan Poe Conspiracy.lnk
[2011/02/12 09:21:45 | 000,001,942 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Play Stray Souls - Dollhouse Story Collector's Edition.lnk
[2011/02/12 09:11:02 | 000,001,417 | —- | M] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Microsoft\Internet Explorer\Quick Launch\Game Manager.lnk
[2011/02/12 09:11:02 | 000,001,399 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Game Manager.lnk
[2011/02/11 21:11:30 | 000,000,826 | —- | M] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/02/11 12:50:45 | 000,000,815 | —- | M] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2011/02/11 12:50:20 | 000,006,656 | —- | M] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/02/08 12:49:16 | 000,382,022 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/02/08 12:49:16 | 000,053,640 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/02/05 18:34:55 | 000,001,784 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Play Mystery Case Files - 13th Skull.lnk
[2011/02/05 12:30:00 | 000,000,278 | —- | M] () – C:\WINDOWS\tasks\Easy Internet Sign-up.job
[2011/02/05 12:29:53 | 000,000,745 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Easy Internet Sign-up.lnk
[2011/02/05 12:29:36 | 000,001,870 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Updates from HP.lnk
[2011/02/05 12:28:32 | 000,000,283 | RHS- | M] () – C:\boot.ini
[2011/02/05 12:27:29 | 000,000,603 | —- | M] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop\Register with HP.url
[2011/02/05 12:26:08 | 000,001,850 | RHS- | M] () – C:\WINDOWS\System32\drivers\103C_HP_CPC_PP164AA-ABA a810n_YC_0Pavi_QMXM502_E51NAheBLU3_47_ISalmon_SASUSTek Computer INC._V1.04_B3.04_T041029_WXH2_L409_M1408_J160_7AMD_8Athlon 64_92.41_#050223_N10390900_Z14F11036_G10396330.MRK
[2011/02/05 12:23:44 | 000,000,993 | —- | M] () – C:\WINDOWS\System32\$winnt$.inf
[2011/02/05 12:23:24 | 000,000,050 | —- | M] () – C:\AUTOEXEC.BAT
[2011/02/05 12:20:40 | 000,190,524 | —- | M] () – C:\WINDOWS\System32\VGAunistlog.ini
[2011/02/05 12:18:44 | 000,000,213 | RHS- | M] () – C:\BOOT.BAK
[2011/02/01 20:19:05 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/01/28 21:35:19 | 000,000,701 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG 2011.lnk
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/02/20 11:06:06 | 000,054,016 | —- | C] () – C:\WINDOWS\System32\drivers\bkhded.sys
[2011/02/20 10:41:49 | 000,000,795 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/02/19 21:10:33 | 000,000,967 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\Startup\Advanced Registry Optimizer.lnk
[2011/02/19 21:09:53 | 000,000,667 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Microsoft\Internet Explorer\Quick Launch\Xfire.lnk
[2011/02/19 21:09:53 | 000,000,649 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Xfire.lnk
[2011/02/19 16:18:39 | 000,002,229 | —- | C] () – C:\WINDOWS\epplauncher.mif
[2011/02/19 13:40:48 | 000,000,075 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\LuResult.txt
[2011/02/15 15:54:34 | 000,001,884 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Play Mystery Chronicles - Murder Among Friends.lnk
[2011/02/13 12:14:18 | 000,001,784 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Play Mystery Case Files - Dire Grove.lnk
[2011/02/12 14:59:06 | 000,002,035 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Play Dark Tales - Edgar Allan Poe`s Murders in the Rue Morgue.lnk
[2011/02/12 14:51:05 | 000,002,034 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Play Midnight Mysteries - The Edgar Allan Poe Conspiracy.lnk
[2011/02/12 09:21:45 | 000,001,942 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Play Stray Souls - Dollhouse Story Collector's Edition.lnk
[2011/02/11 21:16:54 | 000,000,428 | -H– | C] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{0C07C01B-5CD2-4771-9302-946C711BE426}.job
[2011/02/11 12:50:45 | 000,000,815 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2011/02/11 12:50:05 | 000,006,656 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/02/05 18:34:55 | 000,001,784 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Play Mystery Case Files - 13th Skull.lnk
[2011/02/05 16:38:11 | 000,001,595 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Game Manager.lnk
[2011/02/05 16:38:11 | 000,001,417 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Microsoft\Internet Explorer\Quick Launch\Game Manager.lnk
[2011/02/05 16:38:11 | 000,001,399 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Game Manager.lnk
[2011/02/05 16:38:11 | 000,001,184 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\More Great Games.lnk
[2011/02/05 12:30:04 | 000,001,687 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\Startup\HP Organize.lnk
[2011/02/05 12:30:04 | 000,001,687 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Microsoft\Internet Explorer\Quick Launch\HP Organize.lnk
[2011/02/05 12:29:53 | 000,000,278 | —- | C] () – C:\WINDOWS\tasks\Easy Internet Sign-up.job
[2011/02/05 12:29:36 | 000,001,870 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Updates from HP.lnk
[2011/02/05 12:27:29 | 000,000,603 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop\Register with HP.url
[2011/02/05 12:26:05 | 000,001,850 | RHS- | C] () – C:\WINDOWS\System32\drivers\103C_HP_CPC_PP164AA-ABA a810n_YC_0Pavi_QMXM502_E51NAheBLU3_47_ISalmon_SASUSTek Computer INC._V1.04_B3.04_T041029_WXH2_L409_M1408_J160_7AMD_8Athlon 64_92.41_#050223_N10390900_Z14F11036_G10396330.MRK
[2011/02/05 12:25:59 | 1475,923,968 | -HS- | C] () – C:\hiberfil.sys
[2011/02/05 12:25:23 | 000,002,235 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop\Help and Support.lnk
[2011/02/05 12:25:23 | 000,001,632 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Microsoft\Internet Explorer\Quick Launch\iTunes.lnk
[2011/02/05 12:25:23 | 000,000,915 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Microsoft\Internet Explorer\Quick Launch\RealPlayer.lnk
[2011/02/05 12:25:23 | 000,000,826 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/02/05 12:25:23 | 000,000,742 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Microsoft\Internet Explorer\Quick Launch\QuickTime Player.lnk
[2011/02/05 12:25:23 | 000,000,128 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Local Settings\Application Data\fusioncache.dat
[2011/02/05 12:25:23 | 000,000,079 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
[2011/02/05 12:25:22 | 000,010,326 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\ml1.srt
[2011/02/05 12:25:22 | 000,010,250 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\ml2.srt
[2011/02/05 12:25:20 | 000,009,220 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\tempdiff.txt
[2011/02/05 12:25:20 | 000,001,681 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\Install Microsoft Money 2005.lnk
[2011/02/05 12:25:20 | 000,001,599 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\Remote Assistance.lnk
[2011/02/05 12:25:20 | 000,000,814 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\Internet Explorer.lnk
[2011/02/05 12:25:20 | 000,000,803 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\Windows Media Player.lnk
[2011/02/05 12:25:20 | 000,000,749 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\Outlook Express.lnk
[2011/02/05 12:23:37 | 000,001,943 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AOL® for Broadband.lnk
[2011/02/05 12:23:37 | 000,001,846 | —- | C] () – C:\Documents and Settings\All Users\Desktop\MSN.lnk
[2011/02/05 12:23:37 | 000,001,819 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AOL®.lnk
[2011/02/05 12:23:37 | 000,001,697 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Install Quicken New User Edition.lnk
[2011/02/05 12:23:37 | 000,001,641 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Install Game Channel.lnk
[2011/02/05 12:23:37 | 000,001,564 | —- | C] () – C:\Documents and Settings\All Users\Desktop\H&R; Block.lnk
[2011/02/05 12:23:37 | 000,000,731 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Software Repair Wizard.lnk
[2011/02/05 12:23:29 | 000,000,745 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Easy Internet Sign-up.lnk
[2011/02/05 12:21:59 | 000,000,634 | —- | C] () – C:\Documents and Settings\All Users\Desktop\60 day trial - Office 2003.lnk
[2011/02/05 12:21:41 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2011/02/05 12:21:41 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2011/02/05 12:21:41 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2011/02/05 12:21:41 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2011/02/05 12:21:41 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2011/02/05 12:21:41 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2011/02/05 11:11:05 | 000,190,524 | —- | C] () – C:\WINDOWS\System32\VGAunistlog.ini
[2011/02/04 11:37:02 | 000,015,205 | —- | C] () – C:\Documents and Settings\NetworkService\Application Data\MnVsha.js
[2011/02/04 10:37:02 | 000,015,203 | —- | C] () – C:\Documents and Settings\NetworkService\Application Data\gpNRsCi7X.js
[2011/02/04 09:37:02 | 000,015,202 | —- | C] () – C:\Documents and Settings\NetworkService\Application Data\MlcPFY.js
[2011/02/04 08:37:03 | 000,015,204 | —- | C] () – C:\Documents and Settings\NetworkService\Application Data\uogEq.js
[2011/02/04 07:37:05 | 000,015,204 | —- | C] () – C:\Documents and Settings\NetworkService\Application Data\UwkzqVcyT.js
[2011/02/04 06:37:02 | 000,015,205 | —- | C] () – C:\Documents and Settings\NetworkService\Application Data\ICHjhA.js
[2011/02/04 05:37:02 | 000,015,204 | —- | C] () – C:\Documents and Settings\NetworkService\Application Data\WEFjl.js
[2011/02/04 04:37:03 | 000,015,202 | —- | C] () – C:\Documents and Settings\NetworkService\Application Data\ROnryVn.js
[2011/02/03 03:37:35 | 000,015,204 | —- | C] () – C:\Documents and Settings\NetworkService\Application Data\TvEcE.js
[2010/07/09 11:00:32 | 000,041,872 | —- | C] () – C:\WINDOWS\System32\xfcodec.dll
[2009/12/13 19:36:19 | 000,000,419 | —- | C] () – C:\WINDOWS\BRWMARK.INI
[2009/12/13 19:36:19 | 000,000,027 | —- | C] () – C:\WINDOWS\BRPP2KA.INI
[2009/12/13 19:19:35 | 000,103,579 | —- | C] () – C:\WINDOWS\VGAsetup.ini
[2009/12/13 17:49:45 | 000,000,225 | —- | C] () – C:\WINDOWS\Brpfx04a.ini
[2009/12/13 17:49:45 | 000,000,093 | —- | C] () – C:\WINDOWS\brpcfx.ini
[2004/11/10 16:33:23 | 000,027,440 | —- | C] () – C:\WINDOWS\System32\drivers\secdrv.sys
[2004/11/10 16:32:17 | 000,755,200 | —- | C] () – C:\WINDOWS\System32\ir50_32.dll
[2004/11/10 16:32:17 | 000,338,432 | —- | C] () – C:\WINDOWS\System32\ir41_qcx.dll
[2004/11/10 16:32:17 | 000,200,192 | —- | C] () – C:\WINDOWS\System32\ir50_qc.dll
[2004/11/10 16:32:17 | 000,183,808 | —- | C] () – C:\WINDOWS\System32\ir50_qcx.dll
[2004/11/10 16:32:17 | 000,120,320 | —- | C] () – C:\WINDOWS\System32\ir41_qc.dll
[2004/10/22 13:35:32 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2004/10/21 18:21:50 | 000,014,529 | —- | C] () – C:\WINDOWS\System32\CHODDI.SYS
[2004/10/21 18:21:42 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\hpreg.dll
[2004/10/21 17:55:29 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2004/10/21 17:05:48 | 000,001,444 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2004/10/21 17:00:46 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2004/10/21 16:17:08 | 000,299,073 | —- | C] () – C:\WINDOWS\System32\PythonCOM22.dll
[2004/10/21 16:17:08 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\PyWinTypes22.dll
[2004/10/21 16:15:49 | 000,016,896 | —- | C] () – C:\WINDOWS\System32\bcbmm.dll
[2004/10/21 15:55:39 | 000,000,802 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/10/21 15:36:39 | 000,000,549 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2004/10/21 08:43:28 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2004/09/13 22:35:56 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2004/08/20 02:14:46 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\PcdrKernelModeServices.dll
[2004/08/20 02:14:46 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\ProgressTrace.dll
[2003/04/10 22:04:00 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\JAWTAccessBridge.dll
[2003/01/07 21:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
========== LOP Check ==========
[2010/12/12 11:41:29 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2011/02/03 03:35:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG10
[2011/02/12 09:11:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Big Fish Games
[2010/12/12 08:22:38 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2010/12/13 17:38:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Control Center for Kodak Webcams
[2010/06/14 17:06:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Driver Mender
[2010/12/25 15:51:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Leapfrog
[2010/12/12 08:20:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2011/02/15 15:55:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MysteryChronicles
[2010/06/14 17:00:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2010/12/12 07:18:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2011/02/19 12:24:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2011/01/08 18:37:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\VTech
[2010/05/09 16:22:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2011/02/19 00:37:00 | 000,000,396 | —- | M] () – C:\WINDOWS\Tasks\At1.job
[2011/02/19 03:37:00 | 000,000,396 | —- | M] () – C:\WINDOWS\Tasks\At10.job
[2011/02/20 10:37:00 | 000,000,396 | —- | M] () – C:\WINDOWS\Tasks\At11.job
[2011/02/20 11:37:00 | 000,000,396 | —- | M] () – C:\WINDOWS\Tasks\At12.job
[2011/02/19 02:37:00 | 000,000,396 | —- | M] () – C:\WINDOWS\Tasks\At2.job
[2011/02/19 01:37:00 | 000,000,396 | —- | M] () – C:\WINDOWS\Tasks\At3.job
[2011/02/19 05:37:00 | 000,000,396 | —- | M] () – C:\WINDOWS\Tasks\At4.job
[2011/02/19 07:37:00 | 000,000,396 | —- | M] () – C:\WINDOWS\Tasks\At5.job
[2011/02/19 04:37:00 | 000,000,396 | —- | M] () – C:\WINDOWS\Tasks\At6.job
[2011/02/19 08:37:00 | 000,000,396 | —- | M] () – C:\WINDOWS\Tasks\At7.job
[2011/02/19 09:37:02 | 000,000,396 | —- | M] () – C:\WINDOWS\Tasks\At8.job
[2011/02/19 06:37:00 | 000,000,396 | —- | M] () – C:\WINDOWS\Tasks\At9.job
[2011/02/05 12:30:00 | 000,000,278 | —- | M] () – C:\WINDOWS\Tasks\Easy Internet Sign-up.job
[2011/02/20 11:01:00 | 000,000,240 | —- | M] () – C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job
[2011/02/20 10:14:38 | 000,000,428 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{0C07C01B-5CD2-4771-9302-946C711BE426}.job
[2011/02/20 11:56:00 | 000,000,428 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{2B9ABC23-7E4A-4EF3-ACD7-A7C28B953E38}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
[2010/02/26 17:45:09 | 000,000,385 | —- | M] () – C:\5bvlbr.exe
[2007/11/07 08:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe
< %systemroot%\*. /mp /s >
========== Alternate Data Streams ==========
@Alternate Data Stream - 231 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:9BAC4211
@Alternate Data Stream - 217 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:71612023
@Alternate Data Stream - 176 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:561B1D2B
@Alternate Data Stream - 173 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A02025CE
@Alternate Data Stream - 131 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A5241382
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E91ADC66
< End of report >
OTL Extras logfile created on: 2/20/2011 11:58:01 AM - Run 1
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 63.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 91.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 142.96 Gb Total Space | 117.11 Gb Free Space | 81.92% Space Free | Partition Type: NTFS
Drive D: | 6.07 Gb Total Space | 0.72 Gb Free Space | 11.87% Space Free | Partition Type: FAT32
Drive E: | 558.09 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: YOUR-03667082DE | User Name: HP_Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%ProgramFiles%\iTunes\iTunes.exe" = %ProgramFiles%\iTunes\iTunes.exe:*:enabled:iTunes – (Apple Computer, Inc.)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Computer, Inc.)
"C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe" = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe:*:Enabled:BackWeb for Pavilion – (Hewlett-Packard)
"C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" = C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00FC6799-866E-44A1-A60C-DCF394CF56FD}" = iTunes
"{09DA4F91-2A09-4232-AB8C-6BC740096DE3}" = Sonic Update Manager
"{0D182A5E-AEE0-42ca-BD1D-4EEB2FFA256D}" = HP Image Zone Plus 4.2.3
"{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}" = Microsoft Plus! Photo Story 2 LE
"{14589F05-C658-4594-9429-D437BA688686}" = IntelliMover Data Transfer Demo
"{1F63ED0B-EDD2-4037-B6AB-1358C624AF48}" = Scan
"{21E75254-410E-49C4-8981-2E1A2A2221F2}" = HP Diagnostic Assistant
"{267868CE-6DFF-40F7-9C58-C01119B7B117}" = Fax
"{2BBC9458-07CA-4843-848B-5C8146E5EFA8}" = CreativeProjects
"{2FCE4FC5-6930-40E7-A4F1-F862207424EF}" = InterVideo WinDVD Creator
"{34A59AC3-6C5C-4A09-A7F5-369A37176C8A}" = AiOSoftware
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3AE681E0-4E8D-453F-950A-48534D3C0724}" = Copy
"{3AEF2F6C-F1D3-47CD-BF3B-A327F1FABE58}" = PSPrinters06
"{3BD0196C-6553-460c-A0C4-90D8AE5D60D2}" = Norton Personal Firewall
"{41254D7B-EADF-4078-AE4A-BD73B300EE86}" = Unload
"{416D80BA-6F6D-4672-B7CF-F54DA2F80B44}" = Microsoft Works
"{457791C5-D702-4143-A7B2-2744BE9573F2}" = HP Software Update
"{4C04DF1B-6A39-4299-9DD1-1FA60000266E}" = HP Photosmart Cameras 4.0
"{561A9B4E-2E48-4149-B977-59C7AFF62B52}" = HPIZ423
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Sonic Express Labeler
"{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}" = Microsoft Plus! Digital Media Edition Installer
"{7148F0A8-6813-11D6-A77B-00B0D0142030}" = Java 2 Runtime Environment, SE v1.4.2_03
"{725249C3-B94C-4141-8799-0D3BA43D0812}" = CameraDrivers
"{8105684D-8CA6-440D-8F58-7E5FD67A499D}" = Easy Internet Sign-up
"{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" =
"{91120409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Standard Edition 2003
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD Player
"{9541FED0-327F-4DF0-8B96-EF57EF622F19}" = Sonic RecordNow!
"{981FB376-8418-4EA8-BBED-9DE5AA63E7D5}" = SkinsHP1
"{9CB2512B-3EC4-43DF-8002-46BDAB5EDD1B}" = QuickProjects
"{9EEBF8D5-8712-4D1D-88F4-4CDC2D270BC3}" = PrintScreen
"{A1062847-0846-427A-92A1-BB8251A91E91}" = HP PSC & OfficeJet 4.0
"{A1DCC235-DACC-4E1F-8D11-D630634B4AEF}" = PhotoGallery
"{A2500497-FD32-493e-B8E5-28D6728DBEF5}" = Readme
"{A4EA3AB4-E78C-4286-96DF-26035507CE55}" = AiO_Scan
"{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}" = Photosmart 320,370,7400,8100,8400 Series
"{AC76BA86-0000-0000-0000-6028747ADE01}" = Adobe Acrobat - Reader 6.0.2 Update
"{AC76BA86-7AD7-1033-7B44-A00000000001}" = Adobe Reader 6.0.1
"{B103C8A7-D1CC-4B1A-BD41-883F652E097D}" = muvee autoProducer 3.5 magicMoments - HPD
"{B32C75F2-7495-4D01-9431-C11E97D66F8C}" = DocProc
"{B3D5D4E0-E965-41C4-ABFD-A7B1AD0663C2}" = Director
"{B45D9FEE-1AF4-46F3-9A83-2545F81547F5}" = CreativeProjectsTemplates
"{B56D5B09-C4FB-4EA0-8EAD-7BC3E2715A2D}" = DocumentViewer
"{BCC992E5-5C81-4066-9B55-03DC10B24D21}" = InstantShare
"{BF018D2F-C788-4AB1-AB95-1280EAB8F13E}" = TrayApp
"{C3F058C0-A21C-452D-8D99-95B1A45F417D}" = InterVideo DiscLabel
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{D0122362-6333-4DE4-93F6-A5A2F3CC101A}" = HP Organize
"{DB518BA6-CB74-4EB6-9ABD-880B6D6E1F38}" = HpSdpAppCoreApp
"{EC8673DA-F96B-497E-B2DB-BC7B029FD680}" = BufferChm
"{F419D20A-7719-4639-8E30-C073A040D878}" = HP Deskjet Preloaded Printer Drivers
"{F4F47155-5B4D-42AA-97F8-490BC52EA7F3}" = Destinations
"{F65787F3-B356-45EC-8DD0-0E6758EDBCEE}" = WebReg
"{FF26F7EA-BCEE-478C-9A1B-6B4F88717D73}" = CueTour
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"BackWeb-309731 Uninstaller" = Updates from HP
"BFGC" = Big Fish Games: Game Manager
"BFG-Dark Tales - Edgar Allan Poe`s Murders in the Rue Morgue" = Dark Tales: Edgar Allan Poe`s Murders in the Rue Morgue
"BFG-Midnight Mysteries - The Edgar Allan Poe Conspiracy" = Midnight Mysteries: The Edgar Allan Poe Conspiracy
"BFG-Mystery Case Files - 13th Skull" = Mystery Case Files ®: 13th Skull ™
"BFG-Mystery Case Files - Dire Grove" = Mystery Case Files ®: Dire Grove ™
"BFG-Mystery Chronicles - Murder Among Friends" = Mystery Chronicles: Murder Among Friends
"BFG-Stray Souls - Dollhouse Story Collector's Edition" = Stray Souls: Dollhouse Story Collector's Edition
"Help and Support Additions" = Help and Support Additions
"HP Photo & Imaging" = HP Image Zone 4.2.3
"ie8" = Windows Internet Explorer 8
"InstallShield_{00FC6799-866E-44A1-A60C-DCF394CF56FD}" = iTunes
"InstallShield_{8105684D-8CA6-440D-8F58-7E5FD67A499D}" = Easy Internet Sign-up
"LiveReg" = LiveReg (Symantec Corporation)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"PS2" = PS2
"Python 2.2 combined Win32 extensions" = Python 2.2 combined Win32 extensions
"Python 2.2.1" = Python 2.2.1
"QuickTime" = QuickTime
"RealPlayer 6.0" = RealPlayer
"SiS VGA Driver" = SiS VGA Utilities
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows Media Player" = Windows Media Player 10
"Xfire" = Xfire (remove only)
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 2/5/2011 5:07:09 PM | Computer Name = YOUR-03667082DE | Source = Application Hang | ID = 1002
Description = Hanging application IEXPLORE.EXE, version 6.0.2900.2180, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 2/5/2011 8:20:27 PM | Computer Name = YOUR-03667082DE | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.2180, faulting
module unknown, version 0.0.0.0, fault address 0x62ef4d70.
Error - 2/5/2011 8:31:56 PM | Computer Name = YOUR-03667082DE | Source = Application Hang | ID = 1002
Description = Hanging application IEXPLORE.EXE, version 6.0.2900.2180, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 2/8/2011 8:18:02 PM | Computer Name = YOUR-03667082DE | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.2180, faulting
module flash10l.ocx, version 10.1.102.64, fault address 0x00380ec8.
Error - 2/8/2011 8:18:34 PM | Computer Name = YOUR-03667082DE | Source = Application Hang | ID = 1002
Description = Hanging application IEXPLORE.EXE, version 6.0.2900.2180, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 2/9/2011 4:43:09 PM | Computer Name = YOUR-03667082DE | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.2180, faulting
module mshtml.dll, version 6.0.2900.3698, fault address 0x001dbae7.
Error - 2/11/2011 7:14:51 PM | Computer Name = YOUR-03667082DE | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.2180, faulting
module mshtml.dll, version 6.0.2900.3698, fault address 0x001dbae7.
Error - 2/11/2011 7:58:08 PM | Computer Name = YOUR-03667082DE | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.2180, faulting
module mshtml.dll, version 6.0.2900.3698, fault address 0x001dbae7.
Error - 2/11/2011 7:58:28 PM | Computer Name = YOUR-03667082DE | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.2180, faulting
module mshtml.dll, version 6.0.2900.3698, fault address 0x001dbae7.
Error - 2/11/2011 8:02:31 PM | Computer Name = YOUR-03667082DE | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.2180, faulting
module mshtml.dll, version 6.0.2900.3698, fault address 0x001dbae7.
[ System Events ]
Error - 2/19/2011 8:24:18 PM | Computer Name = YOUR-03667082DE | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 2/19/2011 8:24:18 PM | Computer Name = YOUR-03667082DE | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 2/19/2011 8:24:18 PM | Computer Name = YOUR-03667082DE | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 2/19/2011 8:24:18 PM | Computer Name = YOUR-03667082DE | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 2/19/2011 8:24:19 PM | Computer Name = YOUR-03667082DE | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 2/19/2011 8:24:19 PM | Computer Name = YOUR-03667082DE | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 2/19/2011 8:24:19 PM | Computer Name = YOUR-03667082DE | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 2/19/2011 8:24:19 PM | Computer Name = YOUR-03667082DE | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 2/19/2011 8:24:19 PM | Computer Name = YOUR-03667082DE | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 2/19/2011 8:24:19 PM | Computer Name = YOUR-03667082DE | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
< End of report >
Please open Malwarebytes, under the Log tab you will see the logfile from your scan, please post it in your next reply.
Please go here and have a look how you can disable your security software.
Download Combofix from any of the links below but rename it to before saving it to your desktop.
Link 1
Link 2
——————————————————————–
Double click on the renamed Combofix.exe & follow the prompts.
- When finished, it will produce a report for you.
- As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
- Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
[external image: Posted Image]
Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
[external image: Posted Image]
Click on Yes, to continue scanning for malware.
When finished, it will produce a log for you. Please include the C:\ComboFix.txt in your next reply.
This tool is not a toy and not for everyday use.
ComboFix SHOULD NOT be used unless requested by a forum helper
If you need help, see this link:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix
ComboFix 11-02-24.01 - HP_Owner 02/24/2011 10:02:18.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1407.904 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\HP_OWN~1.000\LOCALS~1\Temp\IadHide5.dll
c:\documents and settings\HP_Owner.YOUR-03667082DE.000\Local Settings\Temp\IadHide5.dll
c:\documents and settings\HP_Owner.YOUR-03667082DE\Application Data\uid_pal
c:\documents and settings\HP_Owner.YOUR-03667082DE\Desktop\Internet Explorer.lnk
C:\Install.exe
c:\windows\Downloaded Program Files\f3initialsetup1.0.1.1.inf
c:\windows\Tasks\At1.job
c:\windows\Tasks\At10.job
c:\windows\Tasks\At11.job
c:\windows\Tasks\At12.job
c:\windows\Tasks\At2.job
c:\windows\Tasks\At3.job
c:\windows\Tasks\At4.job
c:\windows\Tasks\At5.job
c:\windows\Tasks\At6.job
c:\windows\Tasks\At7.job
c:\windows\Tasks\At8.job
c:\windows\Tasks\At9.job
c:\windows\viassary-hp.reg
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2011-01-24 to 2011-02-24 )))))))))))))))))))))))))))))))
.
2011-02-23 22:15 . 2011-02-23 22:15 ——– d—–w- c:\documents and settings\NetworkService\Application Data\Xfire
2011-02-23 20:19 . 2011-01-13 09:41 5890896 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{0572F3C1-C35F-423B-B8BF-8AC56D6B21CA}\mpengine.dll
2011-02-22 15:23 . 2010-08-26 12:52 5120 —-a-w- c:\windows\system32\xpsp4res.dll
2011-02-22 13:17 . 2011-02-22 13:17 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2011-02-22 13:07 . 2011-02-22 13:07 ——– d—–w- c:\windows\system32\scripting
2011-02-22 13:07 . 2011-02-22 13:07 ——– d—–w- c:\windows\system32\bits
2011-02-21 21:17 . 2009-08-07 03:23 274288 —-a-w- c:\windows\system32\mucltui.dll
2011-02-21 21:17 . 2009-08-07 03:23 215920 —-a-w- c:\windows\system32\muweb.dll
2011-02-21 15:19 . 2011-01-13 09:41 5890896 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-02-21 15:18 . 2011-02-03 01:11 222080 ——w- c:\windows\system32\MpSigStub.exe
2011-02-21 15:16 . 2011-02-21 15:16 ——– d—–w- c:\program files\Microsoft Security Client
2011-02-20 18:41 . 2011-02-20 18:41 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-02-20 18:41 . 2010-12-21 02:09 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-02-20 18:41 . 2011-02-20 18:41 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-02-20 18:41 . 2010-12-21 02:08 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-02-20 05:09 . 2011-02-23 22:16 ——– d—–w- c:\program files\Xfire
2011-02-20 00:07 . 2011-02-20 00:18 ——– d—–w- C:\9ed20b7a62c8e74031b5087805ec2c
2011-02-15 23:55 . 2011-02-15 23:55 ——– d—–w- c:\documents and settings\All Users\Application Data\MysteryChronicles
2011-02-15 23:54 . 2011-02-15 23:54 ——– d—–w- c:\program files\Mystery Chronicles - Murder Among Friends
2011-02-13 20:09 . 2011-02-13 20:14 ——– d—–w- c:\program files\Mystery Case Files - Dire Grove
2011-02-12 22:57 . 2011-02-12 22:59 ——– d—–w- c:\program files\Dark Tales - Edgar Allan Poe`s Murders in the Rue Morgue
2011-02-12 22:50 . 2011-02-12 22:51 ——– d—–w- c:\program files\Midnight Mysteries - The Edgar Allan Poe Conspiracy
2011-02-12 17:20 . 2011-02-12 17:21 ——– d—–w- c:\program files\Stray Souls - Dollhouse Story Collector's Edition
2011-02-12 17:11 . 2011-02-12 17:11 ——– d—–w- c:\documents and settings\All Users\Application Data\Big Fish Games
2011-02-11 20:48 . 2001-08-18 06:36 5632 —-a-w- c:\windows\system32\ptpusb.dll
2011-02-11 20:48 . 2008-04-13 18:45 15104 —-a-w- c:\windows\system32\drivers\usbscan.sys
2011-02-11 20:48 . 2004-08-04 08:56 159232 —-a-w- c:\windows\system32\ptpusd.dll
2011-02-06 14:14 . 2008-04-14 00:12 30208 ——w- c:\windows\system32\napipsec.dll
2011-02-06 14:13 . 2008-04-14 00:11 233472 ——w- c:\windows\system32\azroles.dll
2011-02-06 14:06 . 2008-06-13 11:05 272128 ——w- c:\windows\system32\drivers\bthport.sys
2011-02-06 06:09 . 2009-01-08 02:21 26144 —-a-w- c:\windows\system32\spupdsvc.exe
2011-02-06 02:33 . 2011-02-06 02:34 ——– d—–w- c:\program files\Mystery Case Files - 13th Skull
2011-02-06 00:51 . 2011-02-19 20:24 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2011-02-06 00:38 . 2011-02-12 17:11 ——– d—–w- c:\program files\bfgclient
2011-02-06 00:37 . 2011-02-18 19:28 ——– d—–w- c:\documents and settings\All Users\Application Data\BigFishGamesCache
2011-02-05 20:26 . 2004-08-04 12:00 221184 —-a-w- c:\windows\system32\wmpns.dll
2011-02-05 20:25 . 2011-02-20 06:10 ——– d—–w- c:\documents and settings\HP_Owner.YOUR-03667082DE.000
2011-02-05 20:23 . 2004-10-22 01:59 ——– d—–w- c:\windows\system32\config\systemprofile\WINDOWS
2011-02-05 20:23 . 2003-09-19 09:47 10368 ——w- c:\windows\system32\drivers\pfc.sys
2011-02-05 20:22 . 2003-09-11 07:36 21060 ——w- c:\windows\system32\drivers\iviaspi.sys
2011-02-05 20:22 . 2004-04-16 19:24 61440 —-a-w- c:\windows\system32\ISUSPM.cpl
2011-02-05 20:21 . 2004-09-27 22:09 204800 —-a-w- c:\windows\system32\IVIresizeW7.dll
2011-02-05 20:21 . 2004-09-27 22:09 20480 —-a-w- c:\windows\system32\IVIresize.dll
2011-02-05 20:21 . 2004-09-27 22:09 200704 —-a-w- c:\windows\system32\IVIresizeA6.dll
2011-02-05 20:21 . 2004-09-27 22:09 192512 —-a-w- c:\windows\system32\IVIresizeP6.dll
2011-02-05 20:21 . 2004-09-27 22:09 192512 —-a-w- c:\windows\system32\IVIresizeM6.dll
2011-02-05 20:21 . 2004-09-27 22:09 188416 —-a-w- c:\windows\system32\IVIresizePX.dll
2011-02-05 20:20 . 2011-02-05 20:20 ——– d—–w- c:\program files\SiS VGA Utilities V3.63
2011-02-05 19:11 . 2001-08-17 21:28 907456 —-a-w- c:\windows\system32\drivers\HCF_MSFT.sys
2011-02-05 19:11 . 2008-04-13 18:46 61696 —-a-w- c:\windows\system32\drivers\ohci1394.sys
2011-02-05 19:11 . 2001-08-17 21:46 6400 —-a-w- c:\windows\system32\drivers\enum1394.sys
2011-02-05 19:11 . 2008-04-13 18:46 53376 —-a-w- c:\windows\system32\drivers\1394bus.sys
2011-02-05 19:11 . 2004-09-24 16:49 110592 ——w- c:\windows\system32\TVMode.dll
2011-02-05 19:11 . 2004-09-24 16:44 184320 ——w- c:\windows\system32\SiSApCom.dll
2011-02-05 19:11 . 2011-02-05 20:20 ——– d—–w- c:\windows\system32\trayres
2011-02-05 19:11 . 2004-09-24 10:47 331776 —-a-w- c:\windows\system32\sistray.exe
2011-02-05 19:11 . 2004-09-24 16:49 49152 —-a-w- c:\windows\system32\SiSPower.dll
2011-02-05 18:47 . 2011-02-22 20:01 ——– dcsh–r- c:\windows\system32\dllcache
2011-02-04 19:37 . 2011-02-04 19:37 15205 —-a-w- c:\documents and settings\NetworkService\Application Data\MnVsha.js
2011-02-04 18:37 . 2011-02-04 18:37 15203 —-a-w- c:\documents and settings\NetworkService\Application Data\gpNRsCi7X.js
2011-02-04 17:37 . 2011-02-04 17:37 15202 —-a-w- c:\documents and settings\NetworkService\Application Data\MlcPFY.js
2011-02-04 16:37 . 2011-02-04 16:37 15204 —-a-w- c:\documents and settings\NetworkService\Application Data\uogEq.js
2011-02-04 15:37 . 2011-02-04 15:37 15204 —-a-w- c:\documents and settings\NetworkService\Application Data\UwkzqVcyT.js
2011-02-04 14:37 . 2011-02-04 14:37 15205 —-a-w- c:\documents and settings\NetworkService\Application Data\ICHjhA.js
2011-02-04 13:37 . 2011-02-04 13:37 15204 —-a-w- c:\documents and settings\NetworkService\Application Data\WEFjl.js
2011-02-04 12:37 . 2011-02-04 12:37 15202 —-a-w- c:\documents and settings\NetworkService\Application Data\ROnryVn.js
2011-02-03 11:37 . 2011-02-03 11:37 15204 —-a-w- c:\documents and settings\NetworkService\Application Data\TvEcE.js
2011-01-25 21:38 . 2011-01-25 21:38 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\ConduitEngine
2011-01-25 21:38 . 2011-01-27 20:37 ——– d—–w- c:\documents and settings\NetworkService\Application Data\bearsharemediabartb
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-22 13:10 . 2011-02-22 13:10 44032 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\LocalContent\Attachments\devcon.exe
2011-02-22 13:10 . 2011-02-22 13:10 307200 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\pchnotify.exe
2011-02-22 13:10 . 2011-02-22 13:10 3072 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\pchealthde.exe
2011-02-22 13:10 . 2011-02-22 13:10 159744 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\PCHButton.exe
2011-02-22 13:10 . 2011-02-22 13:10 77824 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\FDIWrapper.dll
2011-02-22 13:10 . 2011-02-22 13:10 26572 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\INV16.dll
2011-02-22 13:10 . 2011-02-22 13:10 69632 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\msxmlwrapper.dll
2011-02-22 13:10 . 2011-02-22 13:10 40960 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\ScDmi.dll
2011-02-22 13:09 . 2011-02-22 13:09 49152 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\PCHI18N.dll
2011-02-22 13:09 . 2011-02-22 13:09 139264 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\ContentUpdater.exe
2011-02-22 13:09 . 2011-02-22 13:09 110592 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\DSAPI4.dll
2011-02-22 13:09 . 2011-02-22 13:09 98304 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\PluginCtrl.dll
2011-02-22 13:09 . 2011-02-22 13:09 287310 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\HPBasicDetection.dll
2011-02-22 13:09 . 2011-02-22 13:09 69632 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\msxmlwrapper.dll
2011-02-22 13:09 . 2011-02-22 13:09 114688 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\ZipLib.dll
2011-02-22 13:09 . 2011-02-22 13:09 5632 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\GUI.dll
2011-02-22 13:09 . 2011-02-22 13:09 32768 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\pchapi.dll
2011-02-22 13:09 . 2011-02-22 13:09 434176 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\motivede.dll
2011-02-22 13:09 . 2011-02-22 13:09 315392 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\pchmsxml.dll
2011-02-22 13:09 . 2011-02-22 13:09 77824 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\WinVerifyTrust.dll
2011-02-22 13:09 . 2011-02-22 13:09 344064 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\api.dll
2011-02-22 13:09 . 2011-02-22 13:09 24576 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\pcdapi.dll
2011-02-22 13:09 . 2011-02-22 13:09 45056 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\util.dll
2011-02-22 13:09 . 2011-02-22 13:09 356352 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\client_motkt.dll
2011-02-22 13:09 . 2011-02-22 13:09 282624 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\clientutil52.dll
2011-02-22 13:09 . 2011-02-22 13:09 28672 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\InetWrap.dll
2011-02-22 13:09 . 2011-02-22 13:09 102400 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\PCDrAccess.dll
2011-02-22 13:09 . 2011-02-22 13:09 114688 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\asst_ui.dll
2011-02-22 13:09 . 2011-02-22 13:09 49152 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\hwinv.dll
2011-02-22 13:09 . 2011-02-22 13:09 315392 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\pchmsxml.dll
2011-02-22 13:09 . 2011-02-22 13:09 36864 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\gnu.dll
2011-02-22 13:09 . 2011-02-22 13:09 126976 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\SearchCtrl.dll
2011-02-22 13:09 . 2011-02-22 13:09 4096 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\winverifytrustwrapper.dll
2011-02-22 13:09 . 2011-02-22 13:09 212992 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\jsharpinterp.dll
2011-02-22 13:09 . 2011-02-22 13:09 307200 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\pchealthplugin.dll
2011-01-21 14:44 . 2004-11-11 00:33 439296 —-a-w- c:\windows\system32\shimgvw.dll
2011-01-07 14:09 . 2004-11-11 01:21 290048 —-a-w- c:\windows\system32\atmfd.dll
2010-12-31 13:10 . 2004-11-11 00:34 1854976 —-a-w- c:\windows\system32\win32k.sys
2010-12-22 12:34 . 2004-11-11 00:32 301568 —-a-w- c:\windows\system32\kerberos.dll
2010-12-20 23:59 . 2004-11-11 00:34 916480 —-a-w- c:\windows\system32\wininet.dll
2010-12-20 23:59 . 2004-11-11 00:32 43520 —-a-w- c:\windows\system32\licmgr10.dll
2010-12-20 23:59 . 2004-11-11 00:32 1469440 ——w- c:\windows\system32\inetcpl.cpl
2010-12-20 17:26 . 2004-11-11 00:32 730112 —-a-w- c:\windows\system32\lsasrv.dll
2010-12-20 12:55 . 2004-11-11 00:32 385024 —-a-w- c:\windows\system32\html.iec
2010-12-09 15:15 . 2004-10-21 23:35 718336 —-a-w- c:\windows\system32\ntdll.dll
2010-12-09 14:30 . 2004-11-11 00:31 33280 —-a-w- c:\windows\system32\csrsrv.dll
2010-12-09 13:38 . 2004-11-11 00:32 2192768 —-a-w- c:\windows\system32\ntoskrnl.exe
2010-12-09 13:07 . 2004-08-04 05:59 2069376 —-a-w- c:\windows\system32\ntkrnlpa.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\j2re1.4.2_03\bin\jusched.exe" [2004-10-22 32881]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-08-21 155648]
"HPHUPD06"="c:\program files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe" [2004-06-08 49152]
"HPHmon06"="c:\windows\system32\hphmon06.exe" [2004-06-08 659456]
"KBD"="c:\hp\KBD\KBD.EXE" [2003-02-12 61440]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2004-10-22 180269]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2004-06-05 286720]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2004-04-15 233472]
"SiSPower"="SiSPower.dll" [2004-09-24 49152]
"PS2"="c:\windows\system32\ps2.exe" [2002-10-16 81920]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-15 253952]
"Reminder"="c:\windows\Creator\Remind_XP.exe" [2003-12-18 118784]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 57344]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2004-10-22 98304]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 997408]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]
c:\documents and settings\HP_Owner\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [N/A]
Picture Motion Browser Media Check Tool.lnk - c:\program files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe [2009-12-20 385024]
c:\documents and settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\Startup\
Advanced Registry Optimizer.lnk - c:\program files\Advanced Registry Optimizer\ARO.exe [N/A]
HP Organize.lnk - c:\program files\Hewlett-Packard\HP Organize\bin\displayAgent.exe [2004-10-21 36864]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2004-5-29 241664]
Updates from HP.lnk - c:\program files\Updates from HP\309731\Program\Updates from HP.exe [2004-10-21 45056]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Updates from HP\\309731\\Program\\Updates from HP.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Xfire\\Xfire.exe"=
.
Contents of the 'Scheduled Tasks' folder
2011-02-02 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 18:50]
2011-02-05 c:\windows\Tasks\Easy Internet Sign-up.job
- c:\program files\Easy Internet signup\HPSdpApp.exe [2004-08-13 15:50]
2011-02-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-05 05:06]
2011-02-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-05 05:06]
2011-02-24 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2010-11-11 20:26]
2011-02-24 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2010-03-28 20:11]
2011-02-24 c:\windows\Tasks\User_Feed_Synchronization-{0C07C01B-5CD2-4771-9302-946C711BE426}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 12:31]
2011-02-24 c:\windows\Tasks\User_Feed_Synchronization-{2B9ABC23-7E4A-4EF3-ACD7-A7C28B953E38}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 12:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/?ilc=1
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
IE: Add To HP Organize… - c:\progra~1\HEWLET~1\HPORGA~1\bin/module.main/favorites\ie_add_to.html
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-VTTimer - VTTimer.exe
HKLM-Run-IS CfgWiz - c:\program files\Common Files\Symantec Shared\cfgwiz.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-02-24 10:12
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'explorer.exe'(3360)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
———————— Other Running Processes ————————
.
c:\program files\Microsoft Security Client\Antimalware\MsMpEng.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\wdfmgr.exe
c:\windows\system32\wscntfy.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\ALCXMNTR.EXE
.
**************************************************************************
.
Completion time: 2011-02-24 10:19:52 - machine was rebooted
ComboFix-quarantined-files.txt 2011-02-24 18:19
Pre-Run: 128,973,221,888 bytes free
Post-Run: 129,677,336,576 bytes free
- - End Of File - - 7B2E48D19446B65F90231CC821F5E5EE
1. Close any open browsers.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
3. Open notepad and copy/paste the text in the quotebox below into it:
File::
c:\documents and settings\NetworkService\Application Data\MnVsha.js
c:\documents and settings\NetworkService\Application Data\gpNRsCi7X.js
c:\documents and settings\NetworkService\Application Data\MlcPFY.js
c:\documents and settings\NetworkService\Application Data\uogEq.js
c:\documents and settings\NetworkService\Application Data\UwkzqVcyT.js
c:\documents and settings\NetworkService\Application Data\ICHjhA.js
c:\documents and settings\NetworkService\Application Data\WEFjl.js
c:\documents and settings\NetworkService\Application Data\ROnryVn.js
c:\documents and settings\NetworkService\Application Data\TvEcE.js
Save this as CFScript.txt, in the same location as ComboFix.exe
[external image: Posted Image]
Refering to the picture above, drag CFScript into ComboFix.exe
When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
Please update your version of Malwarebytes and run a quick scan, post back with the content of the logfile.
Please run a free online scan with the ESET Online Scanner
Note: You will need to use Internet Explorer for this scan
- Tick the box next to YES, I accept the Terms of Use
- Click Start
- When asked, allow the ActiveX control to install
- Click Start
- Make sure that the options Remove found threats and the option Scan unwanted applications is checked
- Click Scan (This scan can take several hours, so please be patient)
- Once the scan is completed, you may close the window
- Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
- Copy and paste that log as a reply to this topic
Please open OTL, set the extra registry tab to use safe list and hit the run scan button, post back with the 2 logfiles. How is it running now?
ComboFix 11-02-25.01 - HP_Owner 02/26/2011 3:48.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1407.989 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\HP_Owner.YOUR-03667082DE.000\Desktop\cfscript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
FILE ::
"c:\documents and settings\NetworkService\Application Data\gpNRsCi7X.js"
"c:\documents and settings\NetworkService\Application Data\ICHjhA.js"
"c:\documents and settings\NetworkService\Application Data\MlcPFY.js"
"c:\documents and settings\NetworkService\Application Data\MnVsha.js"
"c:\documents and settings\NetworkService\Application Data\ROnryVn.js"
"c:\documents and settings\NetworkService\Application Data\TvEcE.js"
"c:\documents and settings\NetworkService\Application Data\uogEq.js"
"c:\documents and settings\NetworkService\Application Data\UwkzqVcyT.js"
"c:\documents and settings\NetworkService\Application Data\WEFjl.js"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\HP_OWN~1.000\LOCALS~1\Temp\IadHide5.dll
c:\documents and settings\HP_Owner.YOUR-03667082DE.000\Local Settings\Temp\IadHide5.dll
c:\documents and settings\NetworkService\Application Data\gpNRsCi7X.js
c:\documents and settings\NetworkService\Application Data\ICHjhA.js
c:\documents and settings\NetworkService\Application Data\MlcPFY.js
c:\documents and settings\NetworkService\Application Data\MnVsha.js
c:\documents and settings\NetworkService\Application Data\ROnryVn.js
c:\documents and settings\NetworkService\Application Data\TvEcE.js
c:\documents and settings\NetworkService\Application Data\uogEq.js
c:\documents and settings\NetworkService\Application Data\UwkzqVcyT.js
c:\documents and settings\NetworkService\Application Data\WEFjl.js
c:\windows\viassary-hp.reg
.
((((((((((((((((((((((((( Files Created from 2011-01-26 to 2011-02-26 )))))))))))))))))))))))))))))))
.
2011-02-25 19:57 . 2011-02-11 06:54 5943120 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{6B4200D8-8C8C-4579-83C7-82A3574B5FE8}\mpengine.dll
2011-02-23 22:15 . 2011-02-23 22:15 ——– d—–w- c:\documents and settings\NetworkService\Application Data\Xfire
2011-02-22 15:23 . 2010-08-26 12:52 5120 —-a-w- c:\windows\system32\xpsp4res.dll
2011-02-22 13:17 . 2011-02-22 13:17 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2011-02-22 13:07 . 2011-02-22 13:07 ——– d—–w- c:\windows\system32\scripting
2011-02-22 13:07 . 2011-02-22 13:07 ——– d—–w- c:\windows\system32\bits
2011-02-21 21:17 . 2009-08-07 03:23 274288 —-a-w- c:\windows\system32\mucltui.dll
2011-02-21 21:17 . 2009-08-07 03:23 215920 —-a-w- c:\windows\system32\muweb.dll
2011-02-21 15:19 . 2011-02-11 06:54 5943120 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-02-21 15:18 . 2011-02-03 01:11 222080 ——w- c:\windows\system32\MpSigStub.exe
2011-02-21 15:16 . 2011-02-21 15:16 ——– d—–w- c:\program files\Microsoft Security Client
2011-02-20 18:41 . 2011-02-20 18:41 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-02-20 18:41 . 2010-12-21 02:09 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-02-20 18:41 . 2011-02-20 18:41 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-02-20 18:41 . 2010-12-21 02:08 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-02-20 05:09 . 2011-02-23 22:16 ——– d—–w- c:\program files\Xfire
2011-02-20 00:07 . 2011-02-20 00:18 ——– d—–w- C:\9ed20b7a62c8e74031b5087805ec2c
2011-02-15 23:55 . 2011-02-15 23:55 ——– d—–w- c:\documents and settings\All Users\Application Data\MysteryChronicles
2011-02-15 23:54 . 2011-02-15 23:54 ——– d—–w- c:\program files\Mystery Chronicles - Murder Among Friends
2011-02-13 20:09 . 2011-02-13 20:14 ——– d—–w- c:\program files\Mystery Case Files - Dire Grove
2011-02-12 22:57 . 2011-02-12 22:59 ——– d—–w- c:\program files\Dark Tales - Edgar Allan Poe`s Murders in the Rue Morgue
2011-02-12 22:50 . 2011-02-12 22:51 ——– d—–w- c:\program files\Midnight Mysteries - The Edgar Allan Poe Conspiracy
2011-02-12 17:20 . 2011-02-12 17:21 ——– d—–w- c:\program files\Stray Souls - Dollhouse Story Collector's Edition
2011-02-12 17:11 . 2011-02-12 17:11 ——– d—–w- c:\documents and settings\All Users\Application Data\Big Fish Games
2011-02-11 20:48 . 2001-08-18 06:36 5632 —-a-w- c:\windows\system32\ptpusb.dll
2011-02-11 20:48 . 2008-04-13 18:45 15104 —-a-w- c:\windows\system32\drivers\usbscan.sys
2011-02-11 20:48 . 2004-08-04 08:56 159232 —-a-w- c:\windows\system32\ptpusd.dll
2011-02-06 14:14 . 2008-04-14 00:12 30208 ——w- c:\windows\system32\napipsec.dll
2011-02-06 14:13 . 2008-04-14 00:11 233472 ——w- c:\windows\system32\azroles.dll
2011-02-06 14:06 . 2008-06-13 11:05 272128 ——w- c:\windows\system32\drivers\bthport.sys
2011-02-06 06:09 . 2009-01-08 02:21 26144 —-a-w- c:\windows\system32\spupdsvc.exe
2011-02-06 02:33 . 2011-02-06 02:34 ——– d—–w- c:\program files\Mystery Case Files - 13th Skull
2011-02-06 00:51 . 2011-02-19 20:24 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2011-02-06 00:38 . 2011-02-12 17:11 ——– d—–w- c:\program files\bfgclient
2011-02-06 00:37 . 2011-02-18 19:28 ——– d—–w- c:\documents and settings\All Users\Application Data\BigFishGamesCache
2011-02-05 20:26 . 2004-08-04 12:00 221184 —-a-w- c:\windows\system32\wmpns.dll
2011-02-05 20:25 . 2011-02-20 06:10 ——– d—–w- c:\documents and settings\HP_Owner.YOUR-03667082DE.000
2011-02-05 20:23 . 2004-10-22 01:59 ——– d—–w- c:\windows\system32\config\systemprofile\WINDOWS
2011-02-05 20:23 . 2003-09-19 09:47 10368 ——w- c:\windows\system32\drivers\pfc.sys
2011-02-05 20:22 . 2003-09-11 07:36 21060 ——w- c:\windows\system32\drivers\iviaspi.sys
2011-02-05 20:22 . 2004-04-16 19:24 61440 —-a-w- c:\windows\system32\ISUSPM.cpl
2011-02-05 20:21 . 2004-09-27 22:09 204800 —-a-w- c:\windows\system32\IVIresizeW7.dll
2011-02-05 20:21 . 2004-09-27 22:09 20480 —-a-w- c:\windows\system32\IVIresize.dll
2011-02-05 20:21 . 2004-09-27 22:09 200704 —-a-w- c:\windows\system32\IVIresizeA6.dll
2011-02-05 20:21 . 2004-09-27 22:09 192512 —-a-w- c:\windows\system32\IVIresizeP6.dll
2011-02-05 20:21 . 2004-09-27 22:09 192512 —-a-w- c:\windows\system32\IVIresizeM6.dll
2011-02-05 20:21 . 2004-09-27 22:09 188416 —-a-w- c:\windows\system32\IVIresizePX.dll
2011-02-05 20:20 . 2011-02-05 20:20 ——– d—–w- c:\program files\SiS VGA Utilities V3.63
2011-02-05 19:11 . 2001-08-17 21:28 907456 —-a-w- c:\windows\system32\drivers\HCF_MSFT.sys
2011-02-05 19:11 . 2008-04-13 18:46 61696 —-a-w- c:\windows\system32\drivers\ohci1394.sys
2011-02-05 19:11 . 2001-08-17 21:46 6400 —-a-w- c:\windows\system32\drivers\enum1394.sys
2011-02-05 19:11 . 2008-04-13 18:46 53376 —-a-w- c:\windows\system32\drivers\1394bus.sys
2011-02-05 19:11 . 2004-09-24 16:49 110592 ——w- c:\windows\system32\TVMode.dll
2011-02-05 19:11 . 2004-09-24 16:44 184320 ——w- c:\windows\system32\SiSApCom.dll
2011-02-05 19:11 . 2011-02-05 20:20 ——– d—–w- c:\windows\system32\trayres
2011-02-05 19:11 . 2004-09-24 10:47 331776 —-a-w- c:\windows\system32\sistray.exe
2011-02-05 19:11 . 2004-09-24 16:49 49152 —-a-w- c:\windows\system32\SiSPower.dll
2011-02-05 18:47 . 2011-02-22 20:01 ——– dcsh–r- c:\windows\system32\dllcache
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-22 13:10 . 2011-02-22 13:10 44032 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\LocalContent\Attachments\devcon.exe
2011-02-22 13:10 . 2011-02-22 13:10 307200 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\pchnotify.exe
2011-02-22 13:10 . 2011-02-22 13:10 3072 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\pchealthde.exe
2011-02-22 13:10 . 2011-02-22 13:10 159744 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\PCHButton.exe
2011-02-22 13:10 . 2011-02-22 13:10 77824 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\FDIWrapper.dll
2011-02-22 13:10 . 2011-02-22 13:10 26572 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\INV16.dll
2011-02-22 13:10 . 2011-02-22 13:10 69632 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\msxmlwrapper.dll
2011-02-22 13:10 . 2011-02-22 13:10 40960 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\ScDmi.dll
2011-02-22 13:09 . 2011-02-22 13:09 49152 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\PCHI18N.dll
2011-02-22 13:09 . 2011-02-22 13:09 139264 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\ContentUpdater.exe
2011-02-22 13:09 . 2011-02-22 13:09 110592 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\DSAPI4.dll
2011-02-22 13:09 . 2011-02-22 13:09 98304 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\PluginCtrl.dll
2011-02-22 13:09 . 2011-02-22 13:09 287310 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\HPBasicDetection.dll
2011-02-22 13:09 . 2011-02-22 13:09 69632 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\msxmlwrapper.dll
2011-02-22 13:09 . 2011-02-22 13:09 114688 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\ZipLib.dll
2011-02-22 13:09 . 2011-02-22 13:09 5632 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\GUI.dll
2011-02-22 13:09 . 2011-02-22 13:09 32768 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\pchapi.dll
2011-02-22 13:09 . 2011-02-22 13:09 434176 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\motivede.dll
2011-02-22 13:09 . 2011-02-22 13:09 315392 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\pchmsxml.dll
2011-02-22 13:09 . 2011-02-22 13:09 77824 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\WinVerifyTrust.dll
2011-02-22 13:09 . 2011-02-22 13:09 344064 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\api.dll
2011-02-22 13:09 . 2011-02-22 13:09 24576 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\pcdapi.dll
2011-02-22 13:09 . 2011-02-22 13:09 45056 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\util.dll
2011-02-22 13:09 . 2011-02-22 13:09 356352 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\client_motkt.dll
2011-02-22 13:09 . 2011-02-22 13:09 282624 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\clientutil52.dll
2011-02-22 13:09 . 2011-02-22 13:09 28672 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\InetWrap.dll
2011-02-22 13:09 . 2011-02-22 13:09 102400 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\PCDrAccess.dll
2011-02-22 13:09 . 2011-02-22 13:09 114688 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\asst_ui.dll
2011-02-22 13:09 . 2011-02-22 13:09 49152 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\hwinv.dll
2011-02-22 13:09 . 2011-02-22 13:09 315392 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\pchmsxml.dll
2011-02-22 13:09 . 2011-02-22 13:09 36864 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\gnu.dll
2011-02-22 13:09 . 2011-02-22 13:09 126976 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\SearchCtrl.dll
2011-02-22 13:09 . 2011-02-22 13:09 4096 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\winverifytrustwrapper.dll
2011-02-22 13:09 . 2011-02-22 13:09 212992 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\jsharpinterp.dll
2011-02-22 13:09 . 2011-02-22 13:09 307200 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\pchealthplugin.dll
2011-01-21 14:44 . 2004-11-11 00:33 439296 —-a-w- c:\windows\system32\shimgvw.dll
2011-01-07 14:09 . 2004-11-11 01:21 290048 —-a-w- c:\windows\system32\atmfd.dll
2010-12-31 13:10 . 2004-11-11 00:34 1854976 —-a-w- c:\windows\system32\win32k.sys
2010-12-22 12:34 . 2004-11-11 00:32 301568 —-a-w- c:\windows\system32\kerberos.dll
2010-12-20 23:59 . 2004-11-11 00:34 916480 —-a-w- c:\windows\system32\wininet.dll
2010-12-20 23:59 . 2004-11-11 00:32 43520 —-a-w- c:\windows\system32\licmgr10.dll
2010-12-20 23:59 . 2004-11-11 00:32 1469440 ——w- c:\windows\system32\inetcpl.cpl
2010-12-20 17:26 . 2004-11-11 00:32 730112 —-a-w- c:\windows\system32\lsasrv.dll
2010-12-20 12:55 . 2004-11-11 00:32 385024 —-a-w- c:\windows\system32\html.iec
2010-12-09 15:15 . 2004-10-21 23:35 718336 —-a-w- c:\windows\system32\ntdll.dll
2010-12-09 14:30 . 2004-11-11 00:31 33280 —-a-w- c:\windows\system32\csrsrv.dll
2010-12-09 13:38 . 2004-11-11 00:32 2192768 —-a-w- c:\windows\system32\ntoskrnl.exe
2010-12-09 13:07 . 2004-08-04 05:59 2069376 —-a-w- c:\windows\system32\ntkrnlpa.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\j2re1.4.2_03\bin\jusched.exe" [2004-10-22 32881]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-08-21 155648]
"HPHUPD06"="c:\program files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe" [2004-06-08 49152]
"HPHmon06"="c:\windows\system32\hphmon06.exe" [2004-06-08 659456]
"KBD"="c:\hp\KBD\KBD.EXE" [2003-02-12 61440]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2004-10-22 180269]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2004-06-05 286720]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2004-04-15 233472]
"SiSPower"="SiSPower.dll" [2004-09-24 49152]
"PS2"="c:\windows\system32\ps2.exe" [2002-10-16 81920]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-15 253952]
"Reminder"="c:\windows\Creator\Remind_XP.exe" [2003-12-18 118784]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 57344]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2004-10-22 98304]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 997408]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]
c:\documents and settings\HP_Owner\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [N/A]
Picture Motion Browser Media Check Tool.lnk - c:\program files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe [2009-12-20 385024]
c:\documents and settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\Startup\
Advanced Registry Optimizer.lnk - c:\program files\Advanced Registry Optimizer\ARO.exe [N/A]
HP Organize.lnk - c:\program files\Hewlett-Packard\HP Organize\bin\displayAgent.exe [2004-10-21 36864]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2004-5-29 241664]
Updates from HP.lnk - c:\program files\Updates from HP\309731\Program\Updates from HP.exe [2004-10-21 45056]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Updates from HP\\309731\\Program\\Updates from HP.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Xfire\\Xfire.exe"=
.
Contents of the 'Scheduled Tasks' folder
2011-02-02 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 18:50]
2011-02-05 c:\windows\Tasks\Easy Internet Sign-up.job
- c:\program files\Easy Internet signup\HPSdpApp.exe [2004-08-13 15:50]
2011-02-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-05 05:06]
2011-02-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-05 05:06]
2011-02-26 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2010-11-11 20:26]
2011-02-26 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2010-03-28 20:11]
2011-02-26 c:\windows\Tasks\User_Feed_Synchronization-{0C07C01B-5CD2-4771-9302-946C711BE426}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 12:31]
2011-02-26 c:\windows\Tasks\User_Feed_Synchronization-{2B9ABC23-7E4A-4EF3-ACD7-A7C28B953E38}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 12:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/?ilc=1
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
IE: Add To HP Organize… - c:\progra~1\HEWLET~1\HPORGA~1\bin/module.main/favorites\ie_add_to.html
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-02-26 03:55
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'explorer.exe'(236)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
———————— Other Running Processes ————————
.
c:\program files\Microsoft Security Client\Antimalware\MsMpEng.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\wdfmgr.exe
c:\windows\system32\wscntfy.exe
c:\windows\ALCXMNTR.EXE
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2011-02-26 04:02:58 - machine was rebooted
ComboFix-quarantined-files.txt 2011-02-26 12:02
ComboFix2.txt 2011-02-24 18:19
Pre-Run: 129,496,776,704 bytes free
Post-Run: 129,673,396,224 bytes free
- - End Of File - - 1155464DC8801D8FDAFB304C7FC5E769
ESETSmartInstaller@High as CAB hook log:
OnlineScanner.ocx - registred OK
# version=7
# iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
# OnlineScanner.ocx=1.0.0.6425
# api_version=3.0.2
# EOSSerial=6e578d84167593448e87fbf8e5d96f95
# end=finished
# remove_checked=true
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2011-02-26 01:03:35
# local_time=2011-02-26 05:03:35 (-0800, Pacific Standard Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=5891 16776869 42 87 0 9816933 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=92841
# found=13
# cleaned=13
# scan_time=2546
C:\Documents and Settings\HP_Owner\Local Settings\Application Data\dcavni\evtpsftav.exe a variant of Win32/Adware.SpyProtector.Q application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\1ekutghq.default\Cache\DD56727Fd01 JS/Exploit.Pdfka.NTY trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\HP_Owner.YOUR-03667082DE\Application Data\Sun\Java\Deployment\cache\6.0\8\62e60948-47ed1ecf a variant of Win32/TrojanDropper.Agent.PDB trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\gpNRsCi7X.js.vir JS/TrojanDownloader.Agent.NWG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\ICHjhA.js.vir JS/TrojanDownloader.Agent.NWG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\MlcPFY.js.vir JS/TrojanDownloader.Agent.NWG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\MnVsha.js.vir JS/TrojanDownloader.Agent.NWG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\ROnryVn.js.vir JS/TrojanDownloader.Agent.NWG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\TvEcE.js.vir JS/TrojanDownloader.Agent.NWG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\uogEq.js.vir JS/TrojanDownloader.Agent.NWG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\UwkzqVcyT.js.vir JS/TrojanDownloader.Agent.NWG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\WEFjl.js.vir JS/TrojanDownloader.Agent.NWG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{8F7A5040-9305-4BDA-A5EE-E7EE68E6A93B}\RP30\A0008461.exe a variant of Win32/Adware.SpyProtector.Q application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
here is otl log and seems to be running ok
OTL logfile created on: 2/26/2011 5:14:00 AM - Run 2
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 64.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 88.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 142.96 Gb Total Space | 120.68 Gb Free Space | 84.41% Space Free | Partition Type: NTFS
Drive D: | 6.07 Gb Total Space | 0.72 Gb Free Space | 11.87% Space Free | Partition Type: FAT32
Drive E: | 558.09 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: YOUR-03667082DE | User Name: HP_Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/02/20 11:57:38 | 000,602,624 | —- | M] (OldTimer Tools) – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop\OTL.exe
PRC - [2010/11/30 13:20:36 | 000,997,408 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2010/11/11 12:26:40 | 000,011,736 | —- | M] (Microsoft Corporation) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
PRC - [2008/04/13 16:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2004/10/21 18:25:36 | 000,045,056 | —- | M] (Hewlett-Packard) – C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
PRC - [2004/10/21 16:27:22 | 000,032,881 | —- | M] () – C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
========== Modules (SafeList) ==========
MOD - [2011/02/20 11:57:38 | 000,602,624 | —- | M] (OldTimer Tools) – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop\OTL.exe
MOD - [2010/08/23 08:12:02 | 001,054,208 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [Disabled | Stopped] – – (HidServ)
SRV - File not found [On_Demand | Stopped] – – (AppMgmt)
SRV - [2010/11/11 12:26:40 | 000,011,736 | —- | M] (Microsoft Corporation) [Auto | Running] – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe – (MsMpSvc)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Running] – – (catchme)
DRV - [2005/04/20 11:00:56 | 002,317,696 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ALCXWDM.SYS – (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2005/04/12 11:42:16 | 000,011,904 | —- | M] (Silicon Integrated Systems Corporation) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\srvkp.sys – (SiSkp)
DRV - [2005/04/12 11:08:44 | 000,247,296 | —- | M] (Silicon Integrated Systems Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\sisgrp.sys – (SiS315)
DRV - [2004/05/08 16:21:44 | 000,035,840 | —- | M] (Advanced Micro Devices) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\AmdK8.sys – (AmdK8)
DRV - [2003/12/02 17:23:20 | 000,142,336 | —- | M] (Promise Technology, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\fasttx2k.sys – (fasttx2k)
DRV - [2003/09/19 01:47:00 | 000,010,368 | —- | M] (Padus, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\pfc.sys – (Pfc)
DRV - [2003/09/10 23:36:54 | 000,021,060 | —- | M] (InterVideo, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\iviaspi.sys – (Iviaspi)
DRV - [2003/07/18 15:58:20 | 000,036,992 | —- | M] (Silicon Integrated Systems Corporation) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\SISAGPX.sys – (SISAGP)
DRV - [2003/07/11 21:28:56 | 000,032,768 | —- | M] (SiS Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\sisnic.sys – (SISNIC)
DRV - [2003/07/02 10:42:00 | 000,027,904 | —- | M] (VIA Technologies, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\viaagp1.sys – (viaagp1)
DRV - [2002/10/04 16:04:10 | 000,046,976 | —- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\R8139n51.sys – (rtl8139)
DRV - [2001/08/17 13:28:02 | 000,907,456 | —- | M] (Conexant) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HCF_MSFT.sys – (HCF_MSFT)
DRV - [2001/06/04 13:00:00 | 000,014,112 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\PS2.sys – (Ps2)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?ilc=1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
[2010/12/12 22:26:36 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/12/12 22:26:36 | 000,000,000 | —D | M] (Skype extension) – C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2010/09/14 04:41:12 | 000,002,506 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\BearShareWebSearch.xml
O1 HOSTS File: ([2011/02/26 03:55:40 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found.
O3 - HKLM\..\Toolbar: (HP view) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll (Hewlett-Packard Company)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (HP view) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll (Hewlett-Packard Company)
O3 - HKCU\..\Toolbar\WebBrowser: (HP view) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll (Hewlett-Packard Company)
O4 - HKLM..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe (Hewlett-Packard)
O4 - HKLM..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\LSBurnWatcher.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [PS2] C:\WINDOWS\system32\ps2.EXE (Hewlett-Packard Company)
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\Recguard.exe ()
O4 - HKLM..\Run: [Reminder] C:\Windows\Creator\Remind_XP.exe (SoftThinks)
O4 - HKLM..\Run: [SiSPower] C:\WINDOWS\System32\SiSPower.dll (Silicon Integrated Systems Corporation)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe ()
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UpdateManager] C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe (Sonic Solutions)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe (Hewlett-Packard)
O4 - Startup: C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\Startup\Advanced Registry Optimizer.lnk = File not found
O4 - Startup: C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\Startup\HP Organize.lnk = C:\Program Files\Hewlett-Packard\HP Organize\bin\displayAgent.exe (NeoPlanet)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add To HP Organize… - C:\PROGRA~1\HEWLET~1\HPORGA~1\bin/module.main/favorites\ie_add_to.html ()
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Reg Error: Key error. File not found
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2_03)
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2_03)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/02/05 12:23:24 | 000,000,050 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2001/07/28 06:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O32 - AutoRun File - [2010/09/14 14:03:30 | 000,000,067 | RH– | M] () - E:\Autorun.inf – [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/02/26 04:17:50 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2011/02/26 04:03:00 | 000,000,000 | —D | C] – C:\WINDOWS\temp
[2011/02/24 09:58:44 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2011/02/24 09:58:44 | 000,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2011/02/24 09:58:44 | 000,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2011/02/24 09:58:44 | 000,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2011/02/24 09:58:37 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2011/02/23 14:15:53 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Xfire
[2011/02/22 10:47:37 | 000,000,000 | —D | C] – C:\Qoobox
[2011/02/22 07:27:16 | 000,953,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mfc40u.dll
[2011/02/22 07:27:15 | 000,974,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mfc42.dll
[2011/02/22 07:27:06 | 000,357,248 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\srv.sys
[2011/02/22 07:26:48 | 000,617,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\comctl32.dll
[2011/02/22 07:26:09 | 000,040,960 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ndproxy.sys
[2011/02/22 07:23:43 | 000,180,224 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\scrobj.dll
[2011/02/22 07:23:43 | 000,172,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\scrrun.dll
[2011/02/22 07:23:43 | 000,155,648 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wscript.exe
[2011/02/22 07:23:43 | 000,135,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wshom.ocx
[2011/02/22 07:23:43 | 000,090,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wshext.dll
[2011/02/22 07:23:42 | 000,135,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cscript.exe
[2011/02/22 07:23:20 | 000,045,568 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wab.exe
[2011/02/22 07:23:16 | 000,590,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rpcrt4.dll
[2011/02/22 05:25:23 | 000,048,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iyuv_32.dll
[2011/02/22 05:25:13 | 000,265,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\http.sys
[2011/02/22 05:24:16 | 000,272,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\bthport.sys
[2011/02/22 05:23:54 | 000,471,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\aclayers.dll
[2011/02/22 05:23:29 | 000,119,808 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\t2embed.dll
[2011/02/22 05:23:29 | 000,081,920 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fontsub.dll
[2011/02/22 05:23:07 | 000,017,920 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msyuv.dll
[2011/02/22 05:22:57 | 000,203,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rmcast.sys
[2011/02/22 05:22:20 | 000,337,408 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\netapi32.dll
[2011/02/22 05:21:26 | 000,136,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msv1_0.dll
[2011/02/22 05:17:33 | 000,000,000 | —D | C] – C:\WINDOWS\Prefetch
[2011/02/22 05:07:15 | 000,000,000 | —D | C] – C:\WINDOWS\System32\scripting
[2011/02/22 05:07:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\bits
[2011/02/21 13:17:24 | 000,274,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mucltui.dll
[2011/02/21 13:17:24 | 000,016,736 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mucltui.dll.mui
[2011/02/21 07:18:24 | 000,222,080 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\MpSigStub.exe
[2011/02/21 07:16:24 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Security Client
[2011/02/20 11:57:24 | 000,602,624 | —- | C] (OldTimer Tools) – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop\OTL.exe
[2011/02/20 10:42:04 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Malwarebytes
[2011/02/20 10:41:49 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/02/20 10:41:48 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/02/20 10:41:48 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/02/20 10:41:45 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/02/20 10:41:45 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/02/20 10:40:30 | 007,734,208 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop\mbam-setup-1.50.1.1100.exe
[2011/02/19 21:59:59 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Sammsoft
[2011/02/19 21:09:57 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Local Settings\Application Data\OpenCandy
[2011/02/19 21:09:54 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Xfire
[2011/02/19 21:09:53 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Xfire
[2011/02/19 21:09:52 | 000,000,000 | —D | C] – C:\Program Files\Xfire
[2011/02/19 16:07:18 | 000,000,000 | —D | C] – C:\9ed20b7a62c8e74031b5087805ec2c
[2011/02/15 15:55:17 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\MysteryChronicles
[2011/02/15 15:54:23 | 000,000,000 | —D | C] – C:\Program Files\Mystery Chronicles - Murder Among Friends
[2011/02/15 15:54:23 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Mystery Chronicles - Murder Among Friends
[2011/02/14 11:35:29 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Local Settings\Application Data\Identities
[2011/02/13 12:09:09 | 000,000,000 | —D | C] – C:\Program Files\Mystery Case Files - Dire Grove
[2011/02/13 12:09:09 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Mystery Case Files - Dire Grove
[2011/02/12 14:59:53 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\ERS G-Studio
[2011/02/12 14:57:57 | 000,000,000 | —D | C] – C:\Program Files\Dark Tales - Edgar Allan Poe`s Murders in the Rue Morgue
[2011/02/12 14:57:57 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Dark Tales - Edgar Allan Poe`s Murders in the Rue Morgue
[2011/02/12 14:50:30 | 000,000,000 | —D | C] – C:\Program Files\Midnight Mysteries - The Edgar Allan Poe Conspiracy
[2011/02/12 14:50:30 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Midnight Mysteries - The Edgar Allan Poe Conspiracy
[2011/02/12 09:22:22 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Friday's games
[2011/02/12 09:20:58 | 000,000,000 | —D | C] – C:\Program Files\Stray Souls - Dollhouse Story Collector's Edition
[2011/02/12 09:20:58 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Stray Souls - Dollhouse Story Collector's Edition
[2011/02/12 09:11:08 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Big Fish Games
[2011/02/11 21:16:55 | 000,000,000 | -HSD | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\IECompatCache
[2011/02/11 21:16:29 | 000,000,000 | -HSD | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\PrivacIE
[2011/02/11 21:11:27 | 000,000,000 | -HSD | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\IETldCache
[2011/02/11 19:53:47 | 000,000,000 | —D | C] – C:\WINDOWS\System32\en-US
[2011/02/11 19:50:54 | 000,602,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfeeds.dll
[2011/02/11 19:50:54 | 000,055,296 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfeedsbs.dll
[2011/02/11 19:50:53 | 000,743,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iedvtool.dll
[2011/02/11 19:50:52 | 001,991,680 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iertutil.dll
[2011/02/11 19:50:50 | 011,080,704 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieframe.dll
[2011/02/11 12:48:45 | 000,005,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ptpusb.dll
[2011/02/11 12:48:43 | 000,159,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ptpusd.dll
[2011/02/06 06:24:31 | 002,148,864 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntkrnlmp.exe
[2011/02/06 06:24:29 | 002,069,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntkrnlpa.exe
[2011/02/06 06:24:29 | 002,027,008 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntkrpamp.exe
[2011/02/06 06:24:21 | 000,455,680 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mrxsmb.sys
[2011/02/06 06:24:14 | 000,744,448 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\helpsvc.exe
[2011/02/06 06:15:57 | 000,276,992 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wmphoto.dll
[2011/02/06 06:15:55 | 000,069,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wlanapi.dll
[2011/02/06 06:15:53 | 000,712,704 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\windowscodecs.dll
[2011/02/06 06:15:53 | 000,346,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\windowscodecsext.dll
[2011/02/06 06:15:51 | 000,025,471 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\watv10nt.sys
[2011/02/06 06:15:51 | 000,022,271 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\watv06nt.sys
[2011/02/06 06:15:51 | 000,011,935 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\wadv11nt.sys
[2011/02/06 06:15:51 | 000,011,871 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\wadv09nt.sys
[2011/02/06 06:15:50 | 000,011,807 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\wadv07nt.sys
[2011/02/06 06:15:50 | 000,011,295 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\wadv08nt.sys
[2011/02/06 06:15:49 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\vidcap.ax
[2011/02/06 06:15:49 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\verclsid.exe
[2011/02/06 06:15:49 | 000,011,325 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\vchnt5.dll
[2011/02/06 06:15:44 | 000,053,248 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\tsgqec.dll
[2011/02/06 06:15:37 | 000,020,992 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\spupdwxp.exe
[2011/02/06 06:15:36 | 000,007,680 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\spdwnwxp.exe
[2011/02/06 06:15:29 | 000,404,990 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\slntamr.sys
[2011/02/06 06:15:29 | 000,286,792 | —- | C] (Smart Link) – C:\WINDOWS\System32\slextspk.dll
[2011/02/06 06:15:29 | 000,188,508 | —- | C] (Smart Link) – C:\WINDOWS\System32\slgen.dll
[2011/02/06 06:15:29 | 000,129,535 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\slnt7554.sys
[2011/02/06 06:15:29 | 000,095,424 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\slnthal.sys
[2011/02/06 06:15:29 | 000,073,832 | —- | C] (Smart Link) – C:\WINDOWS\System32\slcoinst.dll
[2011/02/06 06:15:29 | 000,073,796 | —- | C] (Smart Link) – C:\WINDOWS\System32\slserv.exe
[2011/02/06 06:15:29 | 000,032,866 | —- | C] (Smart Link) – C:\WINDOWS\System32\slrundll.exe
[2011/02/06 06:15:29 | 000,013,240 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\slwdmsup.sys
[2011/02/06 06:15:29 | 000,005,888 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\smbali.sys
[2011/02/06 06:15:28 | 000,040,960 | —- | C] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\drivers\sisagp.sys
[2011/02/06 06:15:28 | 000,003,901 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\siint5.dll
[2011/02/06 06:15:25 | 000,032,768 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\setupn.exe
[2011/02/06 06:15:22 | 000,397,056 | —- | C] (S3 Graphics, Inc.) – C:\WINDOWS\System32\s3gnb.dll
[2011/02/06 06:15:22 | 000,166,912 | —- | C] (S3 Graphics, Inc.) – C:\WINDOWS\System32\drivers\s3gnbm.sys
[2011/02/06 06:15:21 | 000,030,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\rndismpx.sys
[2011/02/06 06:15:20 | 000,290,304 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\rhttpaa.dll
[2011/02/06 06:15:20 | 000,013,776 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\recagent.sys
[2011/02/06 06:15:19 | 000,061,952 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\rasqec.dll
[2011/02/06 06:15:17 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\qutil.dll
[2011/02/06 06:15:16 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\qagent.dll
[2011/02/06 06:15:16 | 000,062,464 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\qcliprov.dll
[2011/02/06 06:15:15 | 000,412,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\photometadatahandler.dll
[2011/02/06 06:15:12 | 000,144,384 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\onex.dll
[2011/02/06 06:15:06 | 000,180,360 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\ntmtlfax.sys
[2011/02/06 06:15:00 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\napstat.exe
[2011/02/06 06:14:59 | 001,737,856 | —- | C] (Matrox Graphics Inc.) – C:\WINDOWS\System32\mtxparhd.dll
[2011/02/06 06:14:59 | 000,452,736 | —- | C] (Matrox Graphics Inc.) – C:\WINDOWS\System32\drivers\mtxparhm.sys
[2011/02/06 06:14:59 | 000,193,024 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\napmontr.dll
[2011/02/06 06:14:59 | 000,030,208 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\napipsec.dll
[2011/02/06 06:14:59 | 000,012,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\mutohpen.sys
[2011/02/06 06:14:58 | 001,309,184 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\mtlstrm.sys
[2011/02/06 06:14:58 | 000,126,686 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\mtlmnt5.sys
[2011/02/06 06:14:58 | 000,079,872 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msxml6r.dll
[2011/02/06 06:14:58 | 000,079,872 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msxml6r.dll
[2011/02/06 06:14:57 | 001,372,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msxml6.dll
[2011/02/06 06:14:55 | 000,155,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mssha.dll
[2011/02/06 06:14:55 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msshavmsg.dll
[2011/02/06 06:14:42 | 000,397,312 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mmcex.dll
[2011/02/06 06:14:42 | 000,106,496 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mmcfxcommon.dll
[2011/02/06 06:14:42 | 000,033,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mmcperf.exe
[2011/02/06 06:14:41 | 000,184,320 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\microsoft.managementconsole.dll
[2011/02/06 06:14:39 | 000,086,016 | —- | C] (Conexant) – C:\WINDOWS\System32\mdmxsdk.dll
[2011/02/06 06:14:36 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\l2gpstore.dll
[2011/02/06 06:14:35 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdpash.dll
[2011/02/06 06:14:35 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdnepr.dll
[2011/02/06 06:14:34 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdiultn.dll
[2011/02/06 06:14:34 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdbhc.dll
[2011/02/06 06:14:30 | 000,081,920 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ieencode.dll
[2011/02/06 06:14:25 | 000,032,285 | —- | C] (Conexant Systems, Inc.) – C:\WINDOWS\System32\hsfcisp2.dll
[2011/02/06 06:14:18 | 000,020,992 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\faxpatch.exe
[2011/02/06 06:14:16 | 000,184,832 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eapp3hst.dll
[2011/02/06 06:14:16 | 000,180,224 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eapphost.dll
[2011/02/06 06:14:16 | 000,126,976 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eappcfg.dll
[2011/02/06 06:14:16 | 000,094,208 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eappgnui.dll
[2011/02/06 06:14:16 | 000,059,392 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eapqec.dll
[2011/02/06 06:14:16 | 000,040,960 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eappprxy.dll
[2011/02/06 06:14:15 | 000,030,720 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eapolqec.dll
[2011/02/06 06:14:12 | 000,650,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3ui.dll
[2011/02/06 06:14:12 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3cfg.dll
[2011/02/06 06:14:12 | 000,056,320 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3msm.dll
[2011/02/06 06:14:12 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3gpclnt.dll
[2011/02/06 06:14:12 | 000,026,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3api.dll
[2011/02/06 06:14:12 | 000,009,216 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3dlg.dll
[2011/02/06 06:14:10 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dhcpqec.dll
[2011/02/06 06:14:10 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dimsroam.dll
[2011/02/06 06:14:01 | 000,015,423 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\ch7xxnt5.dll
[2011/02/06 06:14:00 | 000,036,480 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\bthprint.sys
[2011/02/06 06:13:59 | 000,233,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\azroles.dll
[2011/02/06 06:13:59 | 000,007,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\bitsprx4.dll
[2011/02/06 06:13:58 | 000,025,471 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\atv04nt5.dll
[2011/02/06 06:13:58 | 000,021,183 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\atv01nt5.dll
[2011/02/06 06:13:58 | 000,017,279 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\atv10nt5.dll
[2011/02/06 06:13:58 | 000,014,143 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\atv06nt5.dll
[2011/02/06 06:13:58 | 000,011,359 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\atv02nt5.dll
[2011/02/06 06:13:57 | 000,516,768 | —- | C] (ATI Technologies Inc. ) – C:\WINDOWS\System32\ativvaxx.dll
[2011/02/06 06:13:57 | 000,104,960 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinrvxx.sys
[2011/02/06 06:13:57 | 000,073,216 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atintuxx.sys
[2011/02/06 06:13:57 | 000,063,488 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinxsxx.sys
[2011/02/06 06:13:57 | 000,052,224 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinraxx.sys
[2011/02/06 06:13:57 | 000,032,768 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\ativtmxx.dll
[2011/02/06 06:13:57 | 000,031,744 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinxbxx.sys
[2011/02/06 06:13:57 | 000,028,672 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinsnxx.sys
[2011/02/06 06:13:57 | 000,023,040 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\ativmvxx.ax
[2011/02/06 06:13:57 | 000,014,336 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinpdxx.sys
[2011/02/06 06:13:57 | 000,013,824 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinttxx.sys
[2011/02/06 06:13:57 | 000,013,824 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinmdxx.sys
[2011/02/06 06:13:57 | 000,009,728 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\ativdaxx.ax
[2011/02/06 06:13:56 | 001,888,992 | —- | C] (ATI Technologies Inc. ) – C:\WINDOWS\System32\ati3duag.dll
[2011/02/06 06:13:56 | 000,057,856 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinbtxx.sys
[2011/02/06 06:13:55 | 000,870,784 | —- | C] (ATI Technologies Inc. ) – C:\WINDOWS\System32\ati3d1ag.dll
[2011/02/06 06:13:55 | 000,701,440 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati2mtag.sys
[2011/02/06 06:13:55 | 000,377,984 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\ati2dvaa.dll
[2011/02/06 06:13:55 | 000,327,040 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati2mtaa.sys
[2011/02/06 06:13:55 | 000,229,376 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\ati2cqag.dll
[2011/02/06 06:13:55 | 000,201,728 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\ati2dvag.dll
[2011/02/06 06:13:55 | 000,034,735 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1xsxx.sys
[2011/02/06 06:13:54 | 000,063,663 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1rvxx.sys
[2011/02/06 06:13:54 | 000,056,623 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1btxx.sys
[2011/02/06 06:13:54 | 000,036,463 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1tuxx.sys
[2011/02/06 06:13:54 | 000,030,671 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1raxx.sys
[2011/02/06 06:13:54 | 000,029,455 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1xbxx.sys
[2011/02/06 06:13:54 | 000,026,367 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1snxx.sys
[2011/02/06 06:13:54 | 000,021,343 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1ttxx.sys
[2011/02/06 06:13:54 | 000,012,047 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1pdxx.sys
[2011/02/06 06:13:54 | 000,011,615 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1mdxx.sys
[2011/02/06 06:13:51 | 000,043,008 | —- | C] (Advanced Micro Devices, Inc.) – C:\WINDOWS\System32\drivers\amdagp.sys
[2011/02/06 06:13:47 | 000,003,775 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv11nt5.dll
[2011/02/06 06:13:47 | 000,003,711 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv09nt5.dll
[2011/02/06 06:13:47 | 000,003,647 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv07nt5.dll
[2011/02/06 06:13:47 | 000,003,135 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv08nt5.dll
[2011/02/06 06:13:46 | 000,004,255 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv01nt5.dll
[2011/02/06 06:13:46 | 000,003,967 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv02nt5.dll
[2011/02/06 06:13:46 | 000,003,615 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv05nt5.dll
[2011/02/06 06:13:40 | 000,136,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\aaclient.dll
[2011/02/06 06:08:21 | 000,008,704 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\tsbyuv.dll
[2011/02/05 22:09:26 | 000,026,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\spupdsvc.exe
[2011/02/05 22:09:26 | 000,000,000 | —D | C] – C:\WINDOWS\System32\PreInstall
[2011/02/05 18:33:09 | 000,000,000 | —D | C] – C:\Program Files\Mystery Case Files - 13th Skull
[2011/02/05 18:33:09 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Mystery Case Files - 13th Skull
[2011/02/05 16:51:32 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Big Fish Games
[2011/02/05 16:51:21 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\TEMP
[2011/02/05 16:38:09 | 000,000,000 | —D | C] – C:\Program Files\bfgclient
[2011/02/05 16:37:22 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\BigFishGamesCache
[2011/02/05 13:04:47 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\My Documents\My eBooks
[2011/02/05 12:35:41 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Adobe
[2011/02/05 12:30:36 | 000,000,000 | -HSD | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\UserData
[2011/02/05 12:30:00 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Macromedia
[2011/02/05 12:28:09 | 000,689,152 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xpsp3res.dll
[2011/02/05 12:28:06 | 000,000,000 | RHSD | C] – C:\cmdcons
[2011/02/05 12:27:45 | 000,000,000 | —D | C] – C:\WINDOWS\setupupd
[2011/02/05 12:27:36 | 000,000,000 | RH-D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Recent
[2011/02/05 12:25:19 | 000,000,000 | –SD | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Microsoft
[2011/02/05 12:25:19 | 000,000,000 | RH-D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\SendTo
[2011/02/05 12:25:19 | 000,000,000 | RH-D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data
[2011/02/05 12:25:19 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\Startup
[2011/02/05 12:25:19 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu
[2011/02/05 12:25:19 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\My Documents\My Videos
[2011/02/05 12:25:19 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\My Documents\My Pictures
[2011/02/05 12:25:19 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\My Documents\My Music
[2011/02/05 12:25:19 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\My Documents
[2011/02/05 12:25:19 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Favorites
[2011/02/05 12:25:19 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\Accessories
[2011/02/05 12:25:19 | 000,000,000 | -HSD | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Cookies
[2011/02/05 12:25:19 | 000,000,000 | -H-D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Templates
[2011/02/05 12:25:19 | 000,000,000 | -H-D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\PrintHood
[2011/02/05 12:25:19 | 000,000,000 | -H-D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\NetHood
[2011/02/05 12:25:19 | 000,000,000 | -H-D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Local Settings
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\WINDOWS
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\WeatherBug
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Symantec
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Sun
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\SpySubtract Spyware Manager
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\SpamSubtract Spam Manager
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Sonic
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\SampleView
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Real
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\Quicken
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\PC Help & Tools
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\Online Services
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Local Settings\Application Data\Microsoft
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Identities
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\Games
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Local Settings\Application Data\ApplicationHistory
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Local Settings\Application Data\Apple Computer
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Apple Computer
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Local Settings\Application Data\{7148F0A6-6813-11D6-A77B-00B0D0142030}
[2011/02/05 12:23:00 | 000,010,368 | —- | C] (Padus, Inc.) – C:\WINDOWS\System32\drivers\pfc.sys
[2011/02/05 12:22:59 | 000,021,060 | —- | C] (InterVideo, Inc.) – C:\WINDOWS\System32\drivers\iviaspi.sys
[2011/02/05 12:22:44 | 000,061,440 | —- | C] (InstallShield Software Corporation) – C:\WINDOWS\System32\ISUSPM.cpl
[2011/02/05 12:21:59 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office (60 Day Trial)
[2011/02/05 12:20:10 | 000,000,000 | —D | C] – C:\Program Files\SiS VGA Utilities V3.63
[2011/02/05 12:17:57 | 000,000,000 | —D | C] – C:\WINDOWS\System32\SoftwareDistribution
[2011/02/05 11:11:40 | 000,907,456 | —- | C] (Conexant) – C:\WINDOWS\System32\drivers\HCF_MSFT.sys
[2011/02/05 11:11:38 | 000,006,400 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\enum1394.sys
[2011/02/05 11:11:37 | 000,053,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\1394bus.sys
[2011/02/05 11:11:23 | 000,184,320 | —- | C] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\SiSApCom.dll
[2011/02/05 11:11:23 | 000,110,592 | —- | C] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\TVMode.dll
[2011/02/05 11:11:08 | 000,331,776 | —- | C] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\sistray.exe
[2011/02/05 11:11:08 | 000,000,000 | —D | C] – C:\WINDOWS\System32\trayres
[2011/02/05 11:11:04 | 000,049,152 | —- | C] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\SiSPower.dll
[2011/02/05 10:47:05 | 000,000,000 | RHSD | C] – C:\WINDOWS\System32\dllcache
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/02/26 05:11:00 | 000,000,428 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{2B9ABC23-7E4A-4EF3-ACD7-A7C28B953E38}.job
[2011/02/26 05:01:00 | 000,000,240 | —- | M] () – C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2011/02/26 04:16:00 | 000,000,890 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/02/26 04:01:06 | 000,000,424 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/02/26 03:55:54 | 000,000,249 | —- | M] () – C:\WINDOWS\System\hpsysdrv.dat
[2011/02/26 03:55:40 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2011/02/26 03:55:28 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/02/26 03:55:22 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/02/26 03:55:21 | 1475,923,968 | -HS- | M] () – C:\hiberfil.sys
[2011/02/26 03:44:49 | 004,274,990 | R— | M] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop\ComboFix.exe
[2011/02/26 03:42:04 | 000,000,428 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{0C07C01B-5CD2-4771-9302-946C711BE426}.job
[2011/02/25 09:07:05 | 000,014,340 | —- | M] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop\JONATHAN.htm
[2011/02/25 09:06:28 | 000,018,924 | —- | M] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop\popups.zip
[2011/02/22 12:05:53 | 000,174,672 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/02/22 12:01:46 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/02/22 11:03:22 | 000,022,005 | —- | M] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop\schrauber.htm
[2011/02/22 07:51:56 | 000,382,022 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/02/22 07:51:56 | 000,053,640 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/02/22 05:18:27 | 000,316,640 | —- | M] () – C:\WINDOWS\WMSysPr9.prx
[2011/02/22 05:18:08 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/02/22 05:04:11 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/02/21 07:16:53 | 000,001,945 | —- | M] () – C:\WINDOWS\epplauncher.mif
[2011/02/20 12:12:20 | 000,133,632 | —- | M] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop\RKUnhookerLE.EXE
[2011/02/20 11:57:38 | 000,602,624 | —- | M] (OldTimer Tools) – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop\OTL.exe
[2011/02/20 10:41:49 | 000,000,795 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/02/20 10:41:28 | 007,734,208 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop\mbam-setup-1.50.1.1100.exe
[2011/02/19 21:10:34 | 000,000,967 | —- | M] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\Startup\Advanced Registry Optimizer.lnk
[2011/02/19 21:09:53 | 000,000,667 | —- | M] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Microsoft\Internet Explorer\Quick Launch\Xfire.lnk
[2011/02/19 21:09:53 | 000,000,649 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Xfire.lnk
[2011/02/15 15:54:34 | 000,001,884 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Play Mystery Chronicles - Murder Among Friends.lnk
[2011/02/13 12:14:18 | 000,001,784 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Play Mystery Case Files - Dire Grove.lnk
[2011/02/12 14:59:06 | 000,002,035 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Play Dark Tales - Edgar Allan Poe`s Murders in the Rue Morgue.lnk
[2011/02/12 14:51:05 | 000,002,034 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Play Midnight Mysteries - The Edgar Allan Poe Conspiracy.lnk
[2011/02/12 09:21:45 | 000,001,942 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Play Stray Souls - Dollhouse Story Collector's Edition.lnk
[2011/02/12 09:11:02 | 000,001,417 | —- | M] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Microsoft\Internet Explorer\Quick Launch\Game Manager.lnk
[2011/02/12 09:11:02 | 000,001,399 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Game Manager.lnk
[2011/02/11 21:11:30 | 000,000,826 | —- | M] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/02/11 12:50:45 | 000,000,815 | —- | M] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2011/02/11 12:50:20 | 000,006,656 | —- | M] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/02/05 18:34:55 | 000,001,784 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Play Mystery Case Files - 13th Skull.lnk
[2011/02/05 12:30:00 | 000,000,278 | —- | M] () – C:\WINDOWS\tasks\Easy Internet Sign-up.job
[2011/02/05 12:29:53 | 000,000,745 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Easy Internet Sign-up.lnk
[2011/02/05 12:29:36 | 000,001,870 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Updates from HP.lnk
[2011/02/05 12:28:32 | 000,000,283 | RHS- | M] () – C:\boot.ini
[2011/02/05 12:27:29 | 000,000,603 | —- | M] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop\Register with HP.url
[2011/02/05 12:26:08 | 000,001,850 | RHS- | M] () – C:\WINDOWS\System32\drivers\103C_HP_CPC_PP164AA-ABA a810n_YC_0Pavi_QMXM502_E51NAheBLU3_47_ISalmon_SASUSTek Computer INC._V1.04_B3.04_T041029_WXH2_L409_M1408_J160_7AMD_8Athlon 64_92.41_#050223_N10390900_Z14F11036_G10396330.MRK
[2011/02/05 12:23:44 | 000,000,993 | —- | M] () – C:\WINDOWS\System32\$winnt$.inf
[2011/02/05 12:23:24 | 000,000,050 | —- | M] () – C:\AUTOEXEC.BAT
[2011/02/05 12:20:40 | 000,190,524 | —- | M] () – C:\WINDOWS\System32\VGAunistlog.ini
[2011/02/05 12:18:44 | 000,000,213 | RHS- | M] () – C:\BOOT.BAK
[2011/02/02 17:11:20 | 000,222,080 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MpSigStub.exe
[2011/02/01 20:19:05 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/02/25 09:07:04 | 000,014,340 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop\JONATHAN.htm
[2011/02/25 09:06:26 | 000,018,924 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop\popups.zip
[2011/02/24 09:58:44 | 000,256,512 | —- | C] () – C:\WINDOWS\PEV.exe
[2011/02/24 09:58:44 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2011/02/24 09:58:44 | 000,089,088 | —- | C] () – C:\WINDOWS\MBR.exe
[2011/02/24 09:58:44 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2011/02/24 09:58:44 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2011/02/24 09:57:03 | 004,274,990 | R— | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop\ComboFix.exe
[2011/02/22 11:03:19 | 000,022,005 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop\schrauber.htm
[2011/02/21 07:21:46 | 000,000,424 | -H– | C] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/02/21 07:16:33 | 000,001,691 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Security Essentials.lnk
[2011/02/20 12:12:17 | 000,133,632 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop\RKUnhookerLE.EXE
[2011/02/20 10:41:49 | 000,000,795 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/02/19 21:10:33 | 000,000,967 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\Startup\Advanced Registry Optimizer.lnk
[2011/02/19 21:09:53 | 000,000,667 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Microsoft\Internet Explorer\Quick Launch\Xfire.lnk
[2011/02/19 21:09:53 | 000,000,649 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Xfire.lnk
[2011/02/19 16:18:39 | 000,001,945 | —- | C] () – C:\WINDOWS\epplauncher.mif
[2011/02/19 13:40:48 | 000,000,075 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\LuResult.txt
[2011/02/15 15:54:34 | 000,001,884 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Play Mystery Chronicles - Murder Among Friends.lnk
[2011/02/13 12:14:18 | 000,001,784 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Play Mystery Case Files - Dire Grove.lnk
[2011/02/12 14:59:06 | 000,002,035 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Play Dark Tales - Edgar Allan Poe`s Murders in the Rue Morgue.lnk
[2011/02/12 14:51:05 | 000,002,034 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Play Midnight Mysteries - The Edgar Allan Poe Conspiracy.lnk
[2011/02/12 09:21:45 | 000,001,942 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Play Stray Souls - Dollhouse Story Collector's Edition.lnk
[2011/02/11 21:16:54 | 000,000,428 | -H– | C] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{0C07C01B-5CD2-4771-9302-946C711BE426}.job
[2011/02/11 12:50:45 | 000,000,815 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2011/02/11 12:50:05 | 000,006,656 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/02/06 06:15:02 | 000,067,866 | —- | C] () – C:\WINDOWS\System32\drivers\netwlan5.img
[2011/02/06 06:14:28 | 000,001,261 | —- | C] () – C:\WINDOWS\System32\pid.inf
[2011/02/06 06:14:07 | 000,129,045 | —- | C] () – C:\WINDOWS\System32\drivers\cxthsfs2.cty
[2011/02/06 06:13:57 | 000,064,352 | —- | C] () – C:\WINDOWS\System32\drivers\ativmc20.cod
[2011/02/05 18:34:55 | 000,001,784 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Play Mystery Case Files - 13th Skull.lnk
[2011/02/05 16:38:11 | 000,001,595 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Game Manager.lnk
[2011/02/05 16:38:11 | 000,001,417 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Microsoft\Internet Explorer\Quick Launch\Game Manager.lnk
[2011/02/05 16:38:11 | 000,001,399 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Game Manager.lnk
[2011/02/05 16:38:11 | 000,001,184 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\More Great Games.lnk
[2011/02/05 12:30:04 | 000,001,687 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\Startup\HP Organize.lnk
[2011/02/05 12:30:04 | 000,001,687 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Microsoft\Internet Explorer\Quick Launch\HP Organize.lnk
[2011/02/05 12:29:53 | 000,000,278 | —- | C] () – C:\WINDOWS\tasks\Easy Internet Sign-up.job
[2011/02/05 12:29:36 | 000,001,870 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Updates from HP.lnk
[2011/02/05 12:27:29 | 000,000,603 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop\Register with HP.url
[2011/02/05 12:26:05 | 000,001,850 | RHS- | C] () – C:\WINDOWS\System32\drivers\103C_HP_CPC_PP164AA-ABA a810n_YC_0Pavi_QMXM502_E51NAheBLU3_47_ISalmon_SASUSTek Computer INC._V1.04_B3.04_T041029_WXH2_L409_M1408_J160_7AMD_8Athlon 64_92.41_#050223_N10390900_Z14F11036_G10396330.MRK
[2011/02/05 12:25:59 | 1475,923,968 | -HS- | C] () – C:\hiberfil.sys
[2011/02/05 12:25:23 | 000,002,235 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop\Help and Support.lnk
[2011/02/05 12:25:23 | 000,001,632 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Microsoft\Internet Explorer\Quick Launch\iTunes.lnk
[2011/02/05 12:25:23 | 000,000,915 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Microsoft\Internet Explorer\Quick Launch\RealPlayer.lnk
[2011/02/05 12:25:23 | 000,000,826 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/02/05 12:25:23 | 000,000,742 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Microsoft\Internet Explorer\Quick Launch\QuickTime Player.lnk
[2011/02/05 12:25:23 | 000,000,128 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Local Settings\Application Data\fusioncache.dat
[2011/02/05 12:25:23 | 000,000,079 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
[2011/02/05 12:25:22 | 000,010,326 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\ml1.srt
[2011/02/05 12:25:22 | 000,010,250 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\ml2.srt
[2011/02/05 12:25:20 | 000,009,220 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\tempdiff.txt
[2011/02/05 12:25:20 | 000,001,681 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\Install Microsoft Money 2005.lnk
[2011/02/05 12:25:20 | 000,001,599 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\Remote Assistance.lnk
[2011/02/05 12:25:20 | 000,000,814 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\Internet Explorer.lnk
[2011/02/05 12:25:20 | 000,000,803 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\Windows Media Player.lnk
[2011/02/05 12:25:20 | 000,000,749 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\Outlook Express.lnk
[2011/02/05 12:23:37 | 000,001,943 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AOL® for Broadband.lnk
[2011/02/05 12:23:37 | 000,001,846 | —- | C] () – C:\Documents and Settings\All Users\Desktop\MSN.lnk
[2011/02/05 12:23:37 | 000,001,819 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AOL®.lnk
[2011/02/05 12:23:37 | 000,001,697 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Install Quicken New User Edition.lnk
[2011/02/05 12:23:37 | 000,001,641 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Install Game Channel.lnk
[2011/02/05 12:23:37 | 000,001,564 | —- | C] () – C:\Documents and Settings\All Users\Desktop\H&R Block.lnk
[2011/02/05 12:23:37 | 000,000,731 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Software Repair Wizard.lnk
[2011/02/05 12:23:29 | 000,000,745 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Easy Internet Sign-up.lnk
[2011/02/05 12:21:59 | 000,000,634 | —- | C] () – C:\Documents and Settings\All Users\Desktop\60 day trial - Office 2003.lnk
[2011/02/05 12:21:41 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2011/02/05 12:21:41 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2011/02/05 12:21:41 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2011/02/05 12:21:41 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2011/02/05 12:21:41 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2011/02/05 12:21:41 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2011/02/05 11:11:05 | 000,190,524 | —- | C] () – C:\WINDOWS\System32\VGAunistlog.ini
[2010/07/09 11:00:32 | 000,041,872 | —- | C] () – C:\WINDOWS\System32\xfcodec.dll
[2009/12/13 19:36:19 | 000,000,419 | —- | C] () – C:\WINDOWS\BRWMARK.INI
[2009/12/13 19:36:19 | 000,000,027 | —- | C] () – C:\WINDOWS\BRPP2KA.INI
[2009/12/13 19:19:35 | 000,103,579 | —- | C] () – C:\WINDOWS\VGAsetup.ini
[2009/12/13 17:49:45 | 000,000,225 | —- | C] () – C:\WINDOWS\Brpfx04a.ini
[2009/12/13 17:49:45 | 000,000,093 | —- | C] () – C:\WINDOWS\brpcfx.ini
[2004/10/22 13:35:32 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2004/10/21 18:21:50 | 000,014,529 | —- | C] () – C:\WINDOWS\System32\CHODDI.SYS
[2004/10/21 18:21:42 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\hpreg.dll
[2004/10/21 17:55:29 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2004/10/21 17:05:48 | 000,001,444 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2004/10/21 17:00:46 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2004/10/21 16:17:08 | 000,299,073 | —- | C] () – C:\WINDOWS\System32\PythonCOM22.dll
[2004/10/21 16:17:08 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\PyWinTypes22.dll
[2004/10/21 16:15:49 | 000,016,896 | —- | C] () – C:\WINDOWS\System32\bcbmm.dll
[2004/10/21 15:55:39 | 000,000,802 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/10/21 15:36:39 | 000,000,549 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2004/10/21 08:43:28 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2004/09/13 22:35:56 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2004/08/20 02:14:46 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\PcdrKernelModeServices.dll
[2004/08/20 02:14:46 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\ProgressTrace.dll
[2003/04/10 22:04:00 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\JAWTAccessBridge.dll
[2003/01/07 21:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
========== Alternate Data Streams ==========
@Alternate Data Stream - 231 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:9BAC4211
@Alternate Data Stream - 217 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:71612023
@Alternate Data Stream - 176 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:561B1D2B
@Alternate Data Stream - 173 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A02025CE
@Alternate Data Stream - 131 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A5241382
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E91ADC66
< End of report >
OTL Extras logfile created on: 2/26/2011 5:14:00 AM - Run 2
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 64.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 88.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 142.96 Gb Total Space | 120.68 Gb Free Space | 84.41% Space Free | Partition Type: NTFS
Drive D: | 6.07 Gb Total Space | 0.72 Gb Free Space | 11.87% Space Free | Partition Type: FAT32
Drive E: | 558.09 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: YOUR-03667082DE | User Name: HP_Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%ProgramFiles%\iTunes\iTunes.exe" = %ProgramFiles%\iTunes\iTunes.exe:*:enabled:iTunes – (Apple Computer, Inc.)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Computer, Inc.)
"C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe" = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe:*:Enabled:BackWeb for Pavilion – (Hewlett-Packard)
"C:\Program Files\Xfire\Xfire.exe" = C:\Program Files\Xfire\Xfire.exe:*:Enabled:Xfire – (Xfire Inc.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00FC6799-866E-44A1-A60C-DCF394CF56FD}" = iTunes
"{09DA4F91-2A09-4232-AB8C-6BC740096DE3}" = Sonic Update Manager
"{0D182A5E-AEE0-42ca-BD1D-4EEB2FFA256D}" = HP Image Zone Plus 4.2.3
"{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}" = Microsoft Plus! Photo Story 2 LE
"{14589F05-C658-4594-9429-D437BA688686}" = IntelliMover Data Transfer Demo
"{1F63ED0B-EDD2-4037-B6AB-1358C624AF48}" = Scan
"{21E75254-410E-49C4-8981-2E1A2A2221F2}" = HP Diagnostic Assistant
"{267868CE-6DFF-40F7-9C58-C01119B7B117}" = Fax
"{2BBC9458-07CA-4843-848B-5C8146E5EFA8}" = CreativeProjects
"{2FCE4FC5-6930-40E7-A4F1-F862207424EF}" = InterVideo WinDVD Creator
"{34A59AC3-6C5C-4A09-A7F5-369A37176C8A}" = AiOSoftware
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3AE681E0-4E8D-453F-950A-48534D3C0724}" = Copy
"{3AEF2F6C-F1D3-47CD-BF3B-A327F1FABE58}" = PSPrinters06
"{3BD0196C-6553-460c-A0C4-90D8AE5D60D2}" = Norton Personal Firewall
"{41254D7B-EADF-4078-AE4A-BD73B300EE86}" = Unload
"{416D80BA-6F6D-4672-B7CF-F54DA2F80B44}" = Microsoft Works
"{457791C5-D702-4143-A7B2-2744BE9573F2}" = HP Software Update
"{4C04DF1B-6A39-4299-9DD1-1FA60000266E}" = HP Photosmart Cameras 4.0
"{561A9B4E-2E48-4149-B977-59C7AFF62B52}" = HPIZ423
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Sonic Express Labeler
"{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}" = Microsoft Plus! Digital Media Edition Installer
"{7148F0A8-6813-11D6-A77B-00B0D0142030}" = Java 2 Runtime Environment, SE v1.4.2_03
"{725249C3-B94C-4141-8799-0D3BA43D0812}" = CameraDrivers
"{774088D4-0777-4D78-904D-E435B318F5D2}" = Microsoft Antimalware
"{77A776C4-D10F-416D-88F0-53F2D9DCD9B3}" = Microsoft Security Client
"{8105684D-8CA6-440D-8F58-7E5FD67A499D}" = Easy Internet Sign-up
"{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" =
"{91120409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Standard Edition 2003
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD Player
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9541FED0-327F-4DF0-8B96-EF57EF622F19}" = Sonic RecordNow!
"{981FB376-8418-4EA8-BBED-9DE5AA63E7D5}" = SkinsHP1
"{9CB2512B-3EC4-43DF-8002-46BDAB5EDD1B}" = QuickProjects
"{9EEBF8D5-8712-4D1D-88F4-4CDC2D270BC3}" = PrintScreen
"{A1062847-0846-427A-92A1-BB8251A91E91}" = HP PSC & OfficeJet 4.0
"{A1DCC235-DACC-4E1F-8D11-D630634B4AEF}" = PhotoGallery
"{A2500497-FD32-493e-B8E5-28D6728DBEF5}" = Readme
"{A4EA3AB4-E78C-4286-96DF-26035507CE55}" = AiO_Scan
"{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}" = Photosmart 320,370,7400,8100,8400 Series
"{AC76BA86-0000-0000-0000-6028747ADE01}" = Adobe Acrobat - Reader 6.0.2 Update
"{AC76BA86-7AD7-1033-7B44-A00000000001}" = Adobe Reader 6.0.1
"{B103C8A7-D1CC-4B1A-BD41-883F652E097D}" = muvee autoProducer 3.5 magicMoments - HPD
"{B32C75F2-7495-4D01-9431-C11E97D66F8C}" = DocProc
"{B3D5D4E0-E965-41C4-ABFD-A7B1AD0663C2}" = Director
"{B45D9FEE-1AF4-46F3-9A83-2545F81547F5}" = CreativeProjectsTemplates
"{B56D5B09-C4FB-4EA0-8EAD-7BC3E2715A2D}" = DocumentViewer
"{BCC992E5-5C81-4066-9B55-03DC10B24D21}" = InstantShare
"{BF018D2F-C788-4AB1-AB95-1280EAB8F13E}" = TrayApp
"{C3F058C0-A21C-452D-8D99-95B1A45F417D}" = InterVideo DiscLabel
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{D0122362-6333-4DE4-93F6-A5A2F3CC101A}" = HP Organize
"{DB518BA6-CB74-4EB6-9ABD-880B6D6E1F38}" = HpSdpAppCoreApp
"{EC8673DA-F96B-497E-B2DB-BC7B029FD680}" = BufferChm
"{F419D20A-7719-4639-8E30-C073A040D878}" = HP Deskjet Preloaded Printer Drivers
"{F4F47155-5B4D-42AA-97F8-490BC52EA7F3}" = Destinations
"{F65787F3-B356-45EC-8DD0-0E6758EDBCEE}" = WebReg
"{FF26F7EA-BCEE-478C-9A1B-6B4F88717D73}" = CueTour
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"BackWeb-309731 Uninstaller" = Updates from HP
"BFGC" = Big Fish Games: Game Manager
"BFG-Dark Tales - Edgar Allan Poe`s Murders in the Rue Morgue" = Dark Tales: Edgar Allan Poe`s Murders in the Rue Morgue
"BFG-Midnight Mysteries - The Edgar Allan Poe Conspiracy" = Midnight Mysteries: The Edgar Allan Poe Conspiracy
"BFG-Mystery Case Files - 13th Skull" = Mystery Case Files ®: 13th Skull ™
"BFG-Mystery Case Files - Dire Grove" = Mystery Case Files ®: Dire Grove ™
"BFG-Mystery Chronicles - Murder Among Friends" = Mystery Chronicles: Murder Among Friends
"BFG-Stray Souls - Dollhouse Story Collector's Edition" = Stray Souls: Dollhouse Story Collector's Edition
"ESET Online Scanner" = ESET Online Scanner v3
"Help and Support Additions" = Help and Support Additions
"HP Photo & Imaging" = HP Image Zone 4.2.3
"ie8" = Windows Internet Explorer 8
"InstallShield_{00FC6799-866E-44A1-A60C-DCF394CF56FD}" = iTunes
"InstallShield_{8105684D-8CA6-440D-8F58-7E5FD67A499D}" = Easy Internet Sign-up
"LiveReg" = LiveReg (Symantec Corporation)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft Security Client" = Microsoft Security Essentials
"PS2" = PS2
"Python 2.2 combined Win32 extensions" = Python 2.2 combined Win32 extensions
"Python 2.2.1" = Python 2.2.1
"QuickTime" = QuickTime
"RealPlayer 6.0" = RealPlayer
"SiS VGA Driver" = SiS VGA Utilities
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows Media Player" = Windows Media Player 10
"Windows XP Service Pack" = Windows XP Service Pack 3
"Xfire" = Xfire (remove only)
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 2/11/2011 7:58:08 PM | Computer Name = YOUR-03667082DE | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.2180, faulting
module mshtml.dll, version 6.0.2900.3698, fault address 0x001dbae7.
Error - 2/11/2011 7:58:28 PM | Computer Name = YOUR-03667082DE | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.2180, faulting
module mshtml.dll, version 6.0.2900.3698, fault address 0x001dbae7.
Error - 2/11/2011 8:02:31 PM | Computer Name = YOUR-03667082DE | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.2180, faulting
module mshtml.dll, version 6.0.2900.3698, fault address 0x001dbae7.
Error - 2/21/2011 11:16:44 AM | Computer Name = YOUR-03667082DE | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 0x80070003, P2 moac, P3 cachereset, P4 3.0.8107.0,
P5 unspecified, P6 unspecified, P7 unspecified, P8 NIL, P9 NIL, P10 NIL.
Error - 2/21/2011 11:18:59 AM | Computer Name = YOUR-03667082DE | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 0x8050800c, P2 mpupdateengine, P3 am delta,
P4 10.3.1781.0, P5 mpsigstub.exe, P6 3.0.8107.0, P7 microsoft security essentials,
P8 NIL, P9 NIL, P10 NIL.
Error - 2/21/2011 11:33:44 AM | Computer Name = YOUR-03667082DE | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 0, P2 moaccapability, P3 3.0.8107.0, P4
0, P5 0, P6 unspecified, P7 unspecified, P8 NIL, P9 NIL, P10 NIL.
Error - 2/21/2011 2:44:20 PM | Computer Name = YOUR-03667082DE | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 2/21/2011 3:20:52 PM | Computer Name = YOUR-03667082DE | Source = Application Hang | ID = 1001
Description = Fault bucket 1180947459.
Error - 2/24/2011 2:02:08 PM | Computer Name = YOUR-03667082DE | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting
module unknown, version 0.0.0.0, fault address 0x715b9e59.
Error - 2/24/2011 2:02:39 PM | Computer Name = YOUR-03667082DE | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting
module unknown, version 0.0.0.0, fault address 0x715b9e59.
[ System Events ]
Error - 2/19/2011 8:24:15 PM | Computer Name = YOUR-03667082DE | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 2/19/2011 8:24:16 PM | Computer Name = YOUR-03667082DE | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 2/19/2011 8:24:16 PM | Computer Name = YOUR-03667082DE | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 2/19/2011 8:24:16 PM | Computer Name = YOUR-03667082DE | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 2/19/2011 8:24:16 PM | Computer Name = YOUR-03667082DE | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 2/19/2011 8:24:16 PM | Computer Name = YOUR-03667082DE | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 2/19/2011 8:24:16 PM | Computer Name = YOUR-03667082DE | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 2/19/2011 8:24:16 PM | Computer Name = YOUR-03667082DE | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 2/19/2011 8:24:16 PM | Computer Name = YOUR-03667082DE | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 2/19/2011 8:24:16 PM | Computer Name = YOUR-03667082DE | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
< End of report >
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI