This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

i think i have a virus

28 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

hello all i think i have a virus on my comp but not sure i have restored to an eairlier time seems to be ok but not sure any help would be great thanks in advance
Hello, maine
Welcome to the WhatTheTech Forums. My name is Thomas (Tom is fine), and I will be helping you fixing your problems.



Please take note of some guidelines for this fix:
  • Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
  • If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
  • Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
  • Do not start a new topic. The logs that you post should be pasted directly into the reply. Only attach them if requested or if they do not fit into the post.
  • Please set your system to show all files.
    Click Start, open My Computer, select the Tools menu and click Folder Options.
    Select the View Tab. Under the Hidden files and folders heading, select Show hidden files and folders.
    Uncheck: Hide file extensions for known file types
    Uncheck the Hide protected operating system files (recommended) option.
    Click Yes to confirm.





  • Please download OTL from one of the following mirrors:
    • This is THE Mirror
  • Save it to your desktop.
  • Double click on the [external image: Posted Image] icon on your desktop.
  • Under the Custom Scan box paste this in
    netsvcs
    %SYSTEMDRIVE%\*.exe
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
  • Push the Quick Scan button.
  • Two reports will open, copy and paste them in a reply here:
    • OTL.txt <– Will be opened
    • Extra.txt <– Will be minimized





Please download Rootkit Unhooker from one of the following links and save it to your desktop. Link 1 (.exe file) Link 2 (zipped file) Link 3 (.rar file)
In order to use this tool if you downloaded from either of the second two links, you will need to extract the RKUnhookerLE.exe file using a program capable of extracing ZIP and RAR compressed files. If you don't have an extraction program, you can downlaod, install and use the free 7-zip utility.
  • Double-click on RKUnhookerLE.exe to start the program. Vista/Windows 7 users right-click and select Run As Administrator.
  • Click the Report tab, then click Scan.
  • Check Drivers, Stealth, and uncheck the rest.
  • Click OK.
  • Wait until it's finished and then go to File > Save Report.
  • Save the report to your Desktop.
  • Copy and paste the contents of the report into your next reply.
– Note: You may get this warning…just ignore it, click OK and continue: "Rootkit Unhooker has detected a parasite inside itself! It is recommended to remove parasite, okay?".
hello tom and ty for helping me i have ran malware byts and it found 181 threats i have removed those this was before i asked for your help :) hear is otl.txt
OTL logfile created on: 2/20/2011 11:58:01 AM - Run 1
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 63.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 91.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 142.96 Gb Total Space | 117.11 Gb Free Space | 81.92% Space Free | Partition Type: NTFS
Drive D: | 6.07 Gb Total Space | 0.72 Gb Free Space | 11.87% Space Free | Partition Type: FAT32
Drive E: | 558.09 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: YOUR-03667082DE | User Name: HP_Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/02/20 11:57:38 | 000,602,624 | —- | M] (OldTimer Tools) – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop\OTL.exe
PRC - [2004/10/21 18:25:36 | 000,045,056 | —- | M] (Hewlett-Packard) – C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
PRC - [2004/10/21 16:27:22 | 000,032,881 | —- | M] () – C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
PRC - [2004/08/04 04:00:00 | 001,032,192 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe


========== Modules (SafeList) ==========

MOD - [2011/02/20 11:57:38 | 000,602,624 | —- | M] (OldTimer Tools) – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop\OTL.exe
MOD - [2004/10/21 18:25:35 | 000,024,613 | —- | M] (BackWeb) – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Local Settings\Temp\IadHide5.dll
MOD - [2004/08/04 11:00:00 | 001,050,624 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] – – (HidServ)
SRV - File not found [On_Demand | Stopped] – – (AppMgmt)


========== Driver Services (SafeList) ==========

DRV - [2005/04/20 11:00:56 | 002,317,696 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ALCXWDM.SYS – (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2005/04/12 11:42:16 | 000,011,904 | —- | M] (Silicon Integrated Systems Corporation) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\srvkp.sys – (SiSkp)
DRV - [2005/04/12 11:08:44 | 000,247,296 | —- | M] (Silicon Integrated Systems Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\sisgrp.sys – (SiS315)
DRV - [2004/05/08 16:21:44 | 000,035,840 | —- | M] (Advanced Micro Devices) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\AmdK8.sys – (AmdK8)
DRV - [2003/12/02 17:23:20 | 000,142,336 | —- | M] (Promise Technology, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\fasttx2k.sys – (fasttx2k)
DRV - [2003/09/19 01:47:00 | 000,010,368 | —- | M] (Padus, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\pfc.sys – (Pfc)
DRV - [2003/09/10 23:36:54 | 000,021,060 | —- | M] (InterVideo, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\iviaspi.sys – (Iviaspi)
DRV - [2003/07/18 15:58:20 | 000,036,992 | —- | M] (Silicon Integrated Systems Corporation) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\SISAGPX.sys – (SISAGP)
DRV - [2003/07/11 21:28:56 | 000,032,768 | —- | M] (SiS Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\sisnic.sys – (SISNIC)
DRV - [2003/07/02 10:42:00 | 000,027,904 | —- | M] (VIA Technologies, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\viaagp1.sys – (viaagp1)
DRV - [2002/10/04 16:04:10 | 000,046,976 | —- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\R8139n51.sys – (rtl8139)
DRV - [2001/08/17 13:28:02 | 000,907,456 | —- | M] (Conexant) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HCF_MSFT.sys – (HCF_MSFT)
DRV - [2001/06/04 13:00:00 | 000,014,112 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\PS2.sys – (Ps2)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?ilc=1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


[2010/12/12 22:26:36 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/12/12 22:26:36 | 000,000,000 | —D | M] (Skype extension) – C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2010/09/14 04:41:12 | 000,002,506 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\BearShareWebSearch.xml

O1 HOSTS File: ([2004/08/04 11:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found.
O3 - HKLM\..\Toolbar: (HP view) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll (Hewlett-Packard Company)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (HP view) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll (Hewlett-Packard Company)
O3 - HKCU\..\Toolbar\WebBrowser: (HP view) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll (Hewlett-Packard Company)
O4 - HKLM..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe (Hewlett-Packard)
O4 - HKLM..\Run: [IS CfgWiz] File not found
O4 - HKLM..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\LSBurnWatcher.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [PS2] C:\WINDOWS\system32\ps2.EXE (Hewlett-Packard Company)
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\Recguard.exe ()
O4 - HKLM..\Run: [Reminder] C:\Windows\Creator\Remind_XP.exe (SoftThinks)
O4 - HKLM..\Run: [SiSPower] C:\WINDOWS\System32\SiSPower.dll (Silicon Integrated Systems Corporation)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe ()
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UpdateManager] C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe (Sonic Solutions)
O4 - HKLM..\Run: [VTTimer] File not found
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe (Hewlett-Packard)
O4 - Startup: C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\Startup\Advanced Registry Optimizer.lnk = File not found
O4 - Startup: C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\Startup\HP Organize.lnk = C:\Program Files\Hewlett-Packard\HP Organize\bin\displayAgent.exe (NeoPlanet)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Add To HP Organize… - C:\PROGRA~1\HEWLET~1\HPORGA~1\bin/module.main/favorites\ie_add_to.html ()
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Reg Error: Key error. File not found
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2_03)
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2_03)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/02/05 12:23:24 | 000,000,050 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2001/07/28 06:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O32 - AutoRun File - [2004/04/30 22:01:14 | 000,000,053 | -HS- | M] () - D:\Autorun.inf – [ FAT32 ]
O32 - AutoRun File - [2010/09/14 14:03:30 | 000,000,067 | RH– | M] () - E:\Autorun.inf – [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (56590081070202880)

========== Files/Folders - Created Within 30 Days ==========

[2011/02/20 11:57:24 | 000,602,624 | —- | C] (OldTimer Tools) – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop\OTL.exe
[2011/02/20 10:42:04 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Malwarebytes
[2011/02/20 10:41:49 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/02/20 10:41:48 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/02/20 10:41:48 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/02/20 10:41:45 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/02/20 10:41:45 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/02/20 10:40:30 | 007,734,208 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop\mbam-setup-1.50.1.1100.exe
[2011/02/19 21:59:59 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Sammsoft
[2011/02/19 21:09:57 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Local Settings\Application Data\OpenCandy
[2011/02/19 21:09:56 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\OpenCandy
[2011/02/19 21:09:54 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Xfire
[2011/02/19 21:09:53 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Xfire
[2011/02/19 21:09:52 | 000,000,000 | —D | C] – C:\Program Files\Xfire
[2011/02/19 16:07:18 | 000,000,000 | —D | C] – C:\9ed20b7a62c8e74031b5087805ec2c
[2011/02/15 15:55:17 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\MysteryChronicles
[2011/02/15 15:54:23 | 000,000,000 | —D | C] – C:\Program Files\Mystery Chronicles - Murder Among Friends
[2011/02/15 15:54:23 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Mystery Chronicles - Murder Among Friends
[2011/02/14 11:35:29 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Local Settings\Application Data\Identities
[2011/02/13 12:09:09 | 000,000,000 | —D | C] – C:\Program Files\Mystery Case Files - Dire Grove
[2011/02/13 12:09:09 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Mystery Case Files - Dire Grove
[2011/02/12 14:59:53 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\ERS G-Studio
[2011/02/12 14:57:57 | 000,000,000 | —D | C] – C:\Program Files\Dark Tales - Edgar Allan Poe`s Murders in the Rue Morgue
[2011/02/12 14:57:57 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Dark Tales - Edgar Allan Poe`s Murders in the Rue Morgue
[2011/02/12 14:50:30 | 000,000,000 | —D | C] – C:\Program Files\Midnight Mysteries - The Edgar Allan Poe Conspiracy
[2011/02/12 14:50:30 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Midnight Mysteries - The Edgar Allan Poe Conspiracy
[2011/02/12 09:22:22 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Friday's games
[2011/02/12 09:20:58 | 000,000,000 | —D | C] – C:\Program Files\Stray Souls - Dollhouse Story Collector's Edition
[2011/02/12 09:20:58 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Stray Souls - Dollhouse Story Collector's Edition
[2011/02/12 09:11:08 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Big Fish Games
[2011/02/11 21:16:55 | 000,000,000 | -HSD | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\IECompatCache
[2011/02/11 21:16:29 | 000,000,000 | -HSD | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\PrivacIE
[2011/02/11 21:11:27 | 000,000,000 | -HSD | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\IETldCache
[2011/02/11 19:53:47 | 000,000,000 | —D | C] – C:\WINDOWS\System32\en-US
[2011/02/06 06:16:02 | 000,000,000 | —D | C] – C:\WINDOWS\System32\CatRoot_bak
[2011/02/05 22:09:26 | 000,000,000 | —D | C] – C:\WINDOWS\System32\PreInstall
[2011/02/05 18:33:09 | 000,000,000 | —D | C] – C:\Program Files\Mystery Case Files - 13th Skull
[2011/02/05 18:33:09 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Mystery Case Files - 13th Skull
[2011/02/05 16:51:32 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Big Fish Games
[2011/02/05 16:51:21 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\TEMP
[2011/02/05 16:38:09 | 000,000,000 | —D | C] – C:\Program Files\bfgclient
[2011/02/05 16:37:22 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\BigFishGamesCache
[2011/02/05 13:04:47 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\My Documents\My eBooks
[2011/02/05 12:35:41 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Adobe
[2011/02/05 12:30:36 | 000,000,000 | –SD | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\UserData
[2011/02/05 12:30:00 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Macromedia
[2011/02/05 12:28:06 | 000,000,000 | RHSD | C] – C:\cmdcons
[2011/02/05 12:27:45 | 000,000,000 | —D | C] – C:\WINDOWS\setupupd
[2011/02/05 12:27:36 | 000,000,000 | RH-D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Recent
[2011/02/05 12:25:19 | 000,000,000 | –SD | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Microsoft
[2011/02/05 12:25:19 | 000,000,000 | RH-D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\SendTo
[2011/02/05 12:25:19 | 000,000,000 | RH-D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data
[2011/02/05 12:25:19 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\Startup
[2011/02/05 12:25:19 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu
[2011/02/05 12:25:19 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\My Documents\My Videos
[2011/02/05 12:25:19 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\My Documents\My Pictures
[2011/02/05 12:25:19 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\My Documents\My Music
[2011/02/05 12:25:19 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\My Documents
[2011/02/05 12:25:19 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Favorites
[2011/02/05 12:25:19 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\Accessories
[2011/02/05 12:25:19 | 000,000,000 | -HSD | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Cookies
[2011/02/05 12:25:19 | 000,000,000 | -H-D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Templates
[2011/02/05 12:25:19 | 000,000,000 | -H-D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\PrintHood
[2011/02/05 12:25:19 | 000,000,000 | -H-D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\NetHood
[2011/02/05 12:25:19 | 000,000,000 | -H-D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Local Settings
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\WINDOWS
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\WeatherBug
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Symantec
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Sun
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\SpySubtract Spyware Manager
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\SpamSubtract Spam Manager
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Sonic
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\SampleView
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Real
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\Quicken
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\PC Help & Tools
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\Online Services
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Local Settings\Application Data\Microsoft
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Identities
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\Games
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Local Settings\Application Data\ApplicationHistory
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Local Settings\Application Data\Apple Computer
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Apple Computer
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Local Settings\Application Data\{7148F0A6-6813-11D6-A77B-00B0D0142030}
[2011/02/05 12:22:59 | 000,021,060 | —- | C] (InterVideo, Inc.) – C:\WINDOWS\System32\drivers\iviaspi.sys
[2011/02/05 12:21:59 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office (60 Day Trial)
[2011/02/05 12:20:10 | 000,000,000 | —D | C] – C:\Program Files\SiS VGA Utilities V3.63
[2011/02/05 12:17:57 | 000,000,000 | —D | C] – C:\WINDOWS\System32\SoftwareDistribution
[2011/02/05 11:11:08 | 000,000,000 | —D | C] – C:\WINDOWS\System32\trayres
[2011/02/05 10:47:05 | 000,000,000 | RHSD | C] – C:\WINDOWS\System32\dllcache
[2011/01/25 13:38:37 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\ConduitEngine
[2011/01/25 13:38:35 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\bearsharemediabartb
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/02/20 11:57:38 | 000,602,624 | —- | M] (OldTimer Tools) – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop\OTL.exe
[2011/02/20 11:56:00 | 000,000,428 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{2B9ABC23-7E4A-4EF3-ACD7-A7C28B953E38}.job
[2011/02/20 11:37:00 | 000,000,396 | —- | M] () – C:\WINDOWS\tasks\At12.job
[2011/02/20 11:16:00 | 000,000,890 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/02/20 11:06:06 | 000,054,016 | —- | M] () – C:\WINDOWS\System32\drivers\bkhded.sys
[2011/02/20 11:01:00 | 000,000,240 | —- | M] () – C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2011/02/20 10:41:49 | 000,000,795 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/02/20 10:41:28 | 007,734,208 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop\mbam-setup-1.50.1.1100.exe
[2011/02/20 10:37:00 | 000,000,396 | —- | M] () – C:\WINDOWS\tasks\At11.job
[2011/02/20 10:14:38 | 000,000,428 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{0C07C01B-5CD2-4771-9302-946C711BE426}.job
[2011/02/20 10:11:47 | 000,003,645 | —- | M] () – C:\WINDOWS\viassary-hp.reg
[2011/02/20 10:11:43 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/02/20 10:11:42 | 000,000,249 | —- | M] () – C:\WINDOWS\System\hpsysdrv.dat
[2011/02/20 10:11:35 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/02/20 10:11:34 | 1475,923,968 | -HS- | M] () – C:\hiberfil.sys
[2011/02/19 21:59:43 | 000,173,080 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/02/19 21:10:34 | 000,000,967 | —- | M] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\Startup\Advanced Registry Optimizer.lnk
[2011/02/19 21:09:53 | 000,000,667 | —- | M] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Microsoft\Internet Explorer\Quick Launch\Xfire.lnk
[2011/02/19 21:09:53 | 000,000,649 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Xfire.lnk
[2011/02/19 16:18:39 | 000,002,229 | —- | M] () – C:\WINDOWS\epplauncher.mif
[2011/02/19 09:37:02 | 000,000,396 | —- | M] () – C:\WINDOWS\tasks\At8.job
[2011/02/19 08:37:00 | 000,000,396 | —- | M] () – C:\WINDOWS\tasks\At7.job
[2011/02/19 07:37:00 | 000,000,396 | —- | M] () – C:\WINDOWS\tasks\At5.job
[2011/02/19 06:37:00 | 000,000,396 | —- | M] () – C:\WINDOWS\tasks\At9.job
[2011/02/19 05:37:00 | 000,000,396 | —- | M] () – C:\WINDOWS\tasks\At4.job
[2011/02/19 04:37:00 | 000,000,396 | —- | M] () – C:\WINDOWS\tasks\At6.job
[2011/02/19 03:37:00 | 000,000,396 | —- | M] () – C:\WINDOWS\tasks\At10.job
[2011/02/19 02:37:00 | 000,000,396 | —- | M] () – C:\WINDOWS\tasks\At2.job
[2011/02/19 01:37:00 | 000,000,396 | —- | M] () – C:\WINDOWS\tasks\At3.job
[2011/02/19 00:37:00 | 000,000,396 | —- | M] () – C:\WINDOWS\tasks\At1.job
[2011/02/16 15:56:45 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/02/15 15:54:34 | 000,001,884 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Play Mystery Chronicles - Murder Among Friends.lnk
[2011/02/13 12:14:18 | 000,001,784 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Play Mystery Case Files - Dire Grove.lnk
[2011/02/12 16:21:11 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/02/12 14:59:06 | 000,002,035 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Play Dark Tales - Edgar Allan Poe`s Murders in the Rue Morgue.lnk
[2011/02/12 14:51:05 | 000,002,034 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Play Midnight Mysteries - The Edgar Allan Poe Conspiracy.lnk
[2011/02/12 09:21:45 | 000,001,942 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Play Stray Souls - Dollhouse Story Collector's Edition.lnk
[2011/02/12 09:11:02 | 000,001,417 | —- | M] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Microsoft\Internet Explorer\Quick Launch\Game Manager.lnk
[2011/02/12 09:11:02 | 000,001,399 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Game Manager.lnk
[2011/02/11 21:11:30 | 000,000,826 | —- | M] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/02/11 12:50:45 | 000,000,815 | —- | M] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2011/02/11 12:50:20 | 000,006,656 | —- | M] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/02/08 12:49:16 | 000,382,022 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/02/08 12:49:16 | 000,053,640 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/02/05 18:34:55 | 000,001,784 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Play Mystery Case Files - 13th Skull.lnk
[2011/02/05 12:30:00 | 000,000,278 | —- | M] () – C:\WINDOWS\tasks\Easy Internet Sign-up.job
[2011/02/05 12:29:53 | 000,000,745 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Easy Internet Sign-up.lnk
[2011/02/05 12:29:36 | 000,001,870 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Updates from HP.lnk
[2011/02/05 12:28:32 | 000,000,283 | RHS- | M] () – C:\boot.ini
[2011/02/05 12:27:29 | 000,000,603 | —- | M] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop\Register with HP.url
[2011/02/05 12:26:08 | 000,001,850 | RHS- | M] () – C:\WINDOWS\System32\drivers\103C_HP_CPC_PP164AA-ABA a810n_YC_0Pavi_QMXM502_E51NAheBLU3_47_ISalmon_SASUSTek Computer INC._V1.04_B3.04_T041029_WXH2_L409_M1408_J160_7AMD_8Athlon 64_92.41_#050223_N10390900_Z14F11036_G10396330.MRK
[2011/02/05 12:23:44 | 000,000,993 | —- | M] () – C:\WINDOWS\System32\$winnt$.inf
[2011/02/05 12:23:24 | 000,000,050 | —- | M] () – C:\AUTOEXEC.BAT
[2011/02/05 12:20:40 | 000,190,524 | —- | M] () – C:\WINDOWS\System32\VGAunistlog.ini
[2011/02/05 12:18:44 | 000,000,213 | RHS- | M] () – C:\BOOT.BAK
[2011/02/01 20:19:05 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/01/28 21:35:19 | 000,000,701 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG 2011.lnk
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/02/20 11:06:06 | 000,054,016 | —- | C] () – C:\WINDOWS\System32\drivers\bkhded.sys
[2011/02/20 10:41:49 | 000,000,795 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/02/19 21:10:33 | 000,000,967 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\Startup\Advanced Registry Optimizer.lnk
[2011/02/19 21:09:53 | 000,000,667 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Microsoft\Internet Explorer\Quick Launch\Xfire.lnk
[2011/02/19 21:09:53 | 000,000,649 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Xfire.lnk
[2011/02/19 16:18:39 | 000,002,229 | —- | C] () – C:\WINDOWS\epplauncher.mif
[2011/02/19 13:40:48 | 000,000,075 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\LuResult.txt
[2011/02/15 15:54:34 | 000,001,884 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Play Mystery Chronicles - Murder Among Friends.lnk
[2011/02/13 12:14:18 | 000,001,784 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Play Mystery Case Files - Dire Grove.lnk
[2011/02/12 14:59:06 | 000,002,035 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Play Dark Tales - Edgar Allan Poe`s Murders in the Rue Morgue.lnk
[2011/02/12 14:51:05 | 000,002,034 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Play Midnight Mysteries - The Edgar Allan Poe Conspiracy.lnk
[2011/02/12 09:21:45 | 000,001,942 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Play Stray Souls - Dollhouse Story Collector's Edition.lnk
[2011/02/11 21:16:54 | 000,000,428 | -H– | C] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{0C07C01B-5CD2-4771-9302-946C711BE426}.job
[2011/02/11 12:50:45 | 000,000,815 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2011/02/11 12:50:05 | 000,006,656 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/02/05 18:34:55 | 000,001,784 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Play Mystery Case Files - 13th Skull.lnk
[2011/02/05 16:38:11 | 000,001,595 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Game Manager.lnk
[2011/02/05 16:38:11 | 000,001,417 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Microsoft\Internet Explorer\Quick Launch\Game Manager.lnk
[2011/02/05 16:38:11 | 000,001,399 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Game Manager.lnk
[2011/02/05 16:38:11 | 000,001,184 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\More Great Games.lnk
[2011/02/05 12:30:04 | 000,001,687 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\Startup\HP Organize.lnk
[2011/02/05 12:30:04 | 000,001,687 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Microsoft\Internet Explorer\Quick Launch\HP Organize.lnk
[2011/02/05 12:29:53 | 000,000,278 | —- | C] () – C:\WINDOWS\tasks\Easy Internet Sign-up.job
[2011/02/05 12:29:36 | 000,001,870 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Updates from HP.lnk
[2011/02/05 12:27:29 | 000,000,603 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop\Register with HP.url
[2011/02/05 12:26:05 | 000,001,850 | RHS- | C] () – C:\WINDOWS\System32\drivers\103C_HP_CPC_PP164AA-ABA a810n_YC_0Pavi_QMXM502_E51NAheBLU3_47_ISalmon_SASUSTek Computer INC._V1.04_B3.04_T041029_WXH2_L409_M1408_J160_7AMD_8Athlon 64_92.41_#050223_N10390900_Z14F11036_G10396330.MRK
[2011/02/05 12:25:59 | 1475,923,968 | -HS- | C] () – C:\hiberfil.sys
[2011/02/05 12:25:23 | 000,002,235 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop\Help and Support.lnk
[2011/02/05 12:25:23 | 000,001,632 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Microsoft\Internet Explorer\Quick Launch\iTunes.lnk
[2011/02/05 12:25:23 | 000,000,915 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Microsoft\Internet Explorer\Quick Launch\RealPlayer.lnk
[2011/02/05 12:25:23 | 000,000,826 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/02/05 12:25:23 | 000,000,742 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Microsoft\Internet Explorer\Quick Launch\QuickTime Player.lnk
[2011/02/05 12:25:23 | 000,000,128 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Local Settings\Application Data\fusioncache.dat
[2011/02/05 12:25:23 | 000,000,079 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
[2011/02/05 12:25:22 | 000,010,326 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\ml1.srt
[2011/02/05 12:25:22 | 000,010,250 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\ml2.srt
[2011/02/05 12:25:20 | 000,009,220 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\tempdiff.txt
[2011/02/05 12:25:20 | 000,001,681 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\Install Microsoft Money 2005.lnk
[2011/02/05 12:25:20 | 000,001,599 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\Remote Assistance.lnk
[2011/02/05 12:25:20 | 000,000,814 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\Internet Explorer.lnk
[2011/02/05 12:25:20 | 000,000,803 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\Windows Media Player.lnk
[2011/02/05 12:25:20 | 000,000,749 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\Outlook Express.lnk
[2011/02/05 12:23:37 | 000,001,943 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AOL® for Broadband.lnk
[2011/02/05 12:23:37 | 000,001,846 | —- | C] () – C:\Documents and Settings\All Users\Desktop\MSN.lnk
[2011/02/05 12:23:37 | 000,001,819 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AOL®.lnk
[2011/02/05 12:23:37 | 000,001,697 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Install Quicken New User Edition.lnk
[2011/02/05 12:23:37 | 000,001,641 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Install Game Channel.lnk
[2011/02/05 12:23:37 | 000,001,564 | —- | C] () – C:\Documents and Settings\All Users\Desktop\H&R; Block.lnk
[2011/02/05 12:23:37 | 000,000,731 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Software Repair Wizard.lnk
[2011/02/05 12:23:29 | 000,000,745 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Easy Internet Sign-up.lnk
[2011/02/05 12:21:59 | 000,000,634 | —- | C] () – C:\Documents and Settings\All Users\Desktop\60 day trial - Office 2003.lnk
[2011/02/05 12:21:41 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2011/02/05 12:21:41 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2011/02/05 12:21:41 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2011/02/05 12:21:41 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2011/02/05 12:21:41 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2011/02/05 12:21:41 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2011/02/05 11:11:05 | 000,190,524 | —- | C] () – C:\WINDOWS\System32\VGAunistlog.ini
[2011/02/04 11:37:02 | 000,015,205 | —- | C] () – C:\Documents and Settings\NetworkService\Application Data\MnVsha.js
[2011/02/04 10:37:02 | 000,015,203 | —- | C] () – C:\Documents and Settings\NetworkService\Application Data\gpNRsCi7X.js
[2011/02/04 09:37:02 | 000,015,202 | —- | C] () – C:\Documents and Settings\NetworkService\Application Data\MlcPFY.js
[2011/02/04 08:37:03 | 000,015,204 | —- | C] () – C:\Documents and Settings\NetworkService\Application Data\uogEq.js
[2011/02/04 07:37:05 | 000,015,204 | —- | C] () – C:\Documents and Settings\NetworkService\Application Data\UwkzqVcyT.js
[2011/02/04 06:37:02 | 000,015,205 | —- | C] () – C:\Documents and Settings\NetworkService\Application Data\ICHjhA.js
[2011/02/04 05:37:02 | 000,015,204 | —- | C] () – C:\Documents and Settings\NetworkService\Application Data\WEFjl.js
[2011/02/04 04:37:03 | 000,015,202 | —- | C] () – C:\Documents and Settings\NetworkService\Application Data\ROnryVn.js
[2011/02/03 03:37:35 | 000,015,204 | —- | C] () – C:\Documents and Settings\NetworkService\Application Data\TvEcE.js
[2010/07/09 11:00:32 | 000,041,872 | —- | C] () – C:\WINDOWS\System32\xfcodec.dll
[2009/12/13 19:36:19 | 000,000,419 | —- | C] () – C:\WINDOWS\BRWMARK.INI
[2009/12/13 19:36:19 | 000,000,027 | —- | C] () – C:\WINDOWS\BRPP2KA.INI
[2009/12/13 19:19:35 | 000,103,579 | —- | C] () – C:\WINDOWS\VGAsetup.ini
[2009/12/13 17:49:45 | 000,000,225 | —- | C] () – C:\WINDOWS\Brpfx04a.ini
[2009/12/13 17:49:45 | 000,000,093 | —- | C] () – C:\WINDOWS\brpcfx.ini
[2004/11/10 16:33:23 | 000,027,440 | —- | C] () – C:\WINDOWS\System32\drivers\secdrv.sys
[2004/11/10 16:32:17 | 000,755,200 | —- | C] () – C:\WINDOWS\System32\ir50_32.dll
[2004/11/10 16:32:17 | 000,338,432 | —- | C] () – C:\WINDOWS\System32\ir41_qcx.dll
[2004/11/10 16:32:17 | 000,200,192 | —- | C] () – C:\WINDOWS\System32\ir50_qc.dll
[2004/11/10 16:32:17 | 000,183,808 | —- | C] () – C:\WINDOWS\System32\ir50_qcx.dll
[2004/11/10 16:32:17 | 000,120,320 | —- | C] () – C:\WINDOWS\System32\ir41_qc.dll
[2004/10/22 13:35:32 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2004/10/21 18:21:50 | 000,014,529 | —- | C] () – C:\WINDOWS\System32\CHODDI.SYS
[2004/10/21 18:21:42 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\hpreg.dll
[2004/10/21 17:55:29 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2004/10/21 17:05:48 | 000,001,444 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2004/10/21 17:00:46 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2004/10/21 16:17:08 | 000,299,073 | —- | C] () – C:\WINDOWS\System32\PythonCOM22.dll
[2004/10/21 16:17:08 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\PyWinTypes22.dll
[2004/10/21 16:15:49 | 000,016,896 | —- | C] () – C:\WINDOWS\System32\bcbmm.dll
[2004/10/21 15:55:39 | 000,000,802 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/10/21 15:36:39 | 000,000,549 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2004/10/21 08:43:28 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2004/09/13 22:35:56 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2004/08/20 02:14:46 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\PcdrKernelModeServices.dll
[2004/08/20 02:14:46 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\ProgressTrace.dll
[2003/04/10 22:04:00 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\JAWTAccessBridge.dll
[2003/01/07 21:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI

========== LOP Check ==========

[2010/12/12 11:41:29 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2011/02/03 03:35:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG10
[2011/02/12 09:11:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Big Fish Games
[2010/12/12 08:22:38 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2010/12/13 17:38:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Control Center for Kodak Webcams
[2010/06/14 17:06:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Driver Mender
[2010/12/25 15:51:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Leapfrog
[2010/12/12 08:20:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2011/02/15 15:55:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MysteryChronicles
[2010/06/14 17:00:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2010/12/12 07:18:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2011/02/19 12:24:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2011/01/08 18:37:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\VTech
[2010/05/09 16:22:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2011/02/19 00:37:00 | 000,000,396 | —- | M] () – C:\WINDOWS\Tasks\At1.job
[2011/02/19 03:37:00 | 000,000,396 | —- | M] () – C:\WINDOWS\Tasks\At10.job
[2011/02/20 10:37:00 | 000,000,396 | —- | M] () – C:\WINDOWS\Tasks\At11.job
[2011/02/20 11:37:00 | 000,000,396 | —- | M] () – C:\WINDOWS\Tasks\At12.job
[2011/02/19 02:37:00 | 000,000,396 | —- | M] () – C:\WINDOWS\Tasks\At2.job
[2011/02/19 01:37:00 | 000,000,396 | —- | M] () – C:\WINDOWS\Tasks\At3.job
[2011/02/19 05:37:00 | 000,000,396 | —- | M] () – C:\WINDOWS\Tasks\At4.job
[2011/02/19 07:37:00 | 000,000,396 | —- | M] () – C:\WINDOWS\Tasks\At5.job
[2011/02/19 04:37:00 | 000,000,396 | —- | M] () – C:\WINDOWS\Tasks\At6.job
[2011/02/19 08:37:00 | 000,000,396 | —- | M] () – C:\WINDOWS\Tasks\At7.job
[2011/02/19 09:37:02 | 000,000,396 | —- | M] () – C:\WINDOWS\Tasks\At8.job
[2011/02/19 06:37:00 | 000,000,396 | —- | M] () – C:\WINDOWS\Tasks\At9.job
[2011/02/05 12:30:00 | 000,000,278 | —- | M] () – C:\WINDOWS\Tasks\Easy Internet Sign-up.job
[2011/02/20 11:01:00 | 000,000,240 | —- | M] () – C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job
[2011/02/20 10:14:38 | 000,000,428 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{0C07C01B-5CD2-4771-9302-946C711BE426}.job
[2011/02/20 11:56:00 | 000,000,428 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{2B9ABC23-7E4A-4EF3-ACD7-A7C28B953E38}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >
[2010/02/26 17:45:09 | 000,000,385 | —- | M] () – C:\5bvlbr.exe
[2007/11/07 08:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe

< %systemroot%\*. /mp /s >

========== Alternate Data Streams ==========

@Alternate Data Stream - 231 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:9BAC4211
@Alternate Data Stream - 217 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:71612023
@Alternate Data Stream - 176 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:561B1D2B
@Alternate Data Stream - 173 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A02025CE
@Alternate Data Stream - 131 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A5241382
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E91ADC66

< End of report >
and here is extras.txt

OTL Extras logfile created on: 2/20/2011 11:58:01 AM - Run 1
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 63.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 91.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 142.96 Gb Total Space | 117.11 Gb Free Space | 81.92% Space Free | Partition Type: NTFS
Drive D: | 6.07 Gb Total Space | 0.72 Gb Free Space | 11.87% Space Free | Partition Type: FAT32
Drive E: | 558.09 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: YOUR-03667082DE | User Name: HP_Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%ProgramFiles%\iTunes\iTunes.exe" = %ProgramFiles%\iTunes\iTunes.exe:*:enabled:iTunes – (Apple Computer, Inc.)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Computer, Inc.)
"C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe" = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe:*:Enabled:BackWeb for Pavilion – (Hewlett-Packard)
"C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" = C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00FC6799-866E-44A1-A60C-DCF394CF56FD}" = iTunes
"{09DA4F91-2A09-4232-AB8C-6BC740096DE3}" = Sonic Update Manager
"{0D182A5E-AEE0-42ca-BD1D-4EEB2FFA256D}" = HP Image Zone Plus 4.2.3
"{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}" = Microsoft Plus! Photo Story 2 LE
"{14589F05-C658-4594-9429-D437BA688686}" = IntelliMover Data Transfer Demo
"{1F63ED0B-EDD2-4037-B6AB-1358C624AF48}" = Scan
"{21E75254-410E-49C4-8981-2E1A2A2221F2}" = HP Diagnostic Assistant
"{267868CE-6DFF-40F7-9C58-C01119B7B117}" = Fax
"{2BBC9458-07CA-4843-848B-5C8146E5EFA8}" = CreativeProjects
"{2FCE4FC5-6930-40E7-A4F1-F862207424EF}" = InterVideo WinDVD Creator
"{34A59AC3-6C5C-4A09-A7F5-369A37176C8A}" = AiOSoftware
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3AE681E0-4E8D-453F-950A-48534D3C0724}" = Copy
"{3AEF2F6C-F1D3-47CD-BF3B-A327F1FABE58}" = PSPrinters06
"{3BD0196C-6553-460c-A0C4-90D8AE5D60D2}" = Norton Personal Firewall
"{41254D7B-EADF-4078-AE4A-BD73B300EE86}" = Unload
"{416D80BA-6F6D-4672-B7CF-F54DA2F80B44}" = Microsoft Works
"{457791C5-D702-4143-A7B2-2744BE9573F2}" = HP Software Update
"{4C04DF1B-6A39-4299-9DD1-1FA60000266E}" = HP Photosmart Cameras 4.0
"{561A9B4E-2E48-4149-B977-59C7AFF62B52}" = HPIZ423
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Sonic Express Labeler
"{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}" = Microsoft Plus! Digital Media Edition Installer
"{7148F0A8-6813-11D6-A77B-00B0D0142030}" = Java 2 Runtime Environment, SE v1.4.2_03
"{725249C3-B94C-4141-8799-0D3BA43D0812}" = CameraDrivers
"{8105684D-8CA6-440D-8F58-7E5FD67A499D}" = Easy Internet Sign-up
"{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" =
"{91120409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Standard Edition 2003
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD Player
"{9541FED0-327F-4DF0-8B96-EF57EF622F19}" = Sonic RecordNow!
"{981FB376-8418-4EA8-BBED-9DE5AA63E7D5}" = SkinsHP1
"{9CB2512B-3EC4-43DF-8002-46BDAB5EDD1B}" = QuickProjects
"{9EEBF8D5-8712-4D1D-88F4-4CDC2D270BC3}" = PrintScreen
"{A1062847-0846-427A-92A1-BB8251A91E91}" = HP PSC & OfficeJet 4.0
"{A1DCC235-DACC-4E1F-8D11-D630634B4AEF}" = PhotoGallery
"{A2500497-FD32-493e-B8E5-28D6728DBEF5}" = Readme
"{A4EA3AB4-E78C-4286-96DF-26035507CE55}" = AiO_Scan
"{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}" = Photosmart 320,370,7400,8100,8400 Series
"{AC76BA86-0000-0000-0000-6028747ADE01}" = Adobe Acrobat - Reader 6.0.2 Update
"{AC76BA86-7AD7-1033-7B44-A00000000001}" = Adobe Reader 6.0.1
"{B103C8A7-D1CC-4B1A-BD41-883F652E097D}" = muvee autoProducer 3.5 magicMoments - HPD
"{B32C75F2-7495-4D01-9431-C11E97D66F8C}" = DocProc
"{B3D5D4E0-E965-41C4-ABFD-A7B1AD0663C2}" = Director
"{B45D9FEE-1AF4-46F3-9A83-2545F81547F5}" = CreativeProjectsTemplates
"{B56D5B09-C4FB-4EA0-8EAD-7BC3E2715A2D}" = DocumentViewer
"{BCC992E5-5C81-4066-9B55-03DC10B24D21}" = InstantShare
"{BF018D2F-C788-4AB1-AB95-1280EAB8F13E}" = TrayApp
"{C3F058C0-A21C-452D-8D99-95B1A45F417D}" = InterVideo DiscLabel
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{D0122362-6333-4DE4-93F6-A5A2F3CC101A}" = HP Organize
"{DB518BA6-CB74-4EB6-9ABD-880B6D6E1F38}" = HpSdpAppCoreApp
"{EC8673DA-F96B-497E-B2DB-BC7B029FD680}" = BufferChm
"{F419D20A-7719-4639-8E30-C073A040D878}" = HP Deskjet Preloaded Printer Drivers
"{F4F47155-5B4D-42AA-97F8-490BC52EA7F3}" = Destinations
"{F65787F3-B356-45EC-8DD0-0E6758EDBCEE}" = WebReg
"{FF26F7EA-BCEE-478C-9A1B-6B4F88717D73}" = CueTour
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"BackWeb-309731 Uninstaller" = Updates from HP
"BFGC" = Big Fish Games: Game Manager
"BFG-Dark Tales - Edgar Allan Poe`s Murders in the Rue Morgue" = Dark Tales: Edgar Allan Poe`s Murders in the Rue Morgue
"BFG-Midnight Mysteries - The Edgar Allan Poe Conspiracy" = Midnight Mysteries: The Edgar Allan Poe Conspiracy
"BFG-Mystery Case Files - 13th Skull" = Mystery Case Files ®: 13th Skull ™
"BFG-Mystery Case Files - Dire Grove" = Mystery Case Files ®: Dire Grove ™
"BFG-Mystery Chronicles - Murder Among Friends" = Mystery Chronicles: Murder Among Friends
"BFG-Stray Souls - Dollhouse Story Collector's Edition" = Stray Souls: Dollhouse Story Collector's Edition
"Help and Support Additions" = Help and Support Additions
"HP Photo & Imaging" = HP Image Zone 4.2.3
"ie8" = Windows Internet Explorer 8
"InstallShield_{00FC6799-866E-44A1-A60C-DCF394CF56FD}" = iTunes
"InstallShield_{8105684D-8CA6-440D-8F58-7E5FD67A499D}" = Easy Internet Sign-up
"LiveReg" = LiveReg (Symantec Corporation)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"PS2" = PS2
"Python 2.2 combined Win32 extensions" = Python 2.2 combined Win32 extensions
"Python 2.2.1" = Python 2.2.1
"QuickTime" = QuickTime
"RealPlayer 6.0" = RealPlayer
"SiS VGA Driver" = SiS VGA Utilities
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows Media Player" = Windows Media Player 10
"Xfire" = Xfire (remove only)

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 2/5/2011 5:07:09 PM | Computer Name = YOUR-03667082DE | Source = Application Hang | ID = 1002
Description = Hanging application IEXPLORE.EXE, version 6.0.2900.2180, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 2/5/2011 8:20:27 PM | Computer Name = YOUR-03667082DE | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.2180, faulting
module unknown, version 0.0.0.0, fault address 0x62ef4d70.

Error - 2/5/2011 8:31:56 PM | Computer Name = YOUR-03667082DE | Source = Application Hang | ID = 1002
Description = Hanging application IEXPLORE.EXE, version 6.0.2900.2180, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 2/8/2011 8:18:02 PM | Computer Name = YOUR-03667082DE | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.2180, faulting
module flash10l.ocx, version 10.1.102.64, fault address 0x00380ec8.

Error - 2/8/2011 8:18:34 PM | Computer Name = YOUR-03667082DE | Source = Application Hang | ID = 1002
Description = Hanging application IEXPLORE.EXE, version 6.0.2900.2180, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 2/9/2011 4:43:09 PM | Computer Name = YOUR-03667082DE | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.2180, faulting
module mshtml.dll, version 6.0.2900.3698, fault address 0x001dbae7.

Error - 2/11/2011 7:14:51 PM | Computer Name = YOUR-03667082DE | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.2180, faulting
module mshtml.dll, version 6.0.2900.3698, fault address 0x001dbae7.

Error - 2/11/2011 7:58:08 PM | Computer Name = YOUR-03667082DE | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.2180, faulting
module mshtml.dll, version 6.0.2900.3698, fault address 0x001dbae7.

Error - 2/11/2011 7:58:28 PM | Computer Name = YOUR-03667082DE | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.2180, faulting
module mshtml.dll, version 6.0.2900.3698, fault address 0x001dbae7.

Error - 2/11/2011 8:02:31 PM | Computer Name = YOUR-03667082DE | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.2180, faulting
module mshtml.dll, version 6.0.2900.3698, fault address 0x001dbae7.

[ System Events ]
Error - 2/19/2011 8:24:18 PM | Computer Name = YOUR-03667082DE | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 2/19/2011 8:24:18 PM | Computer Name = YOUR-03667082DE | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 2/19/2011 8:24:18 PM | Computer Name = YOUR-03667082DE | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 2/19/2011 8:24:18 PM | Computer Name = YOUR-03667082DE | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 2/19/2011 8:24:19 PM | Computer Name = YOUR-03667082DE | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 2/19/2011 8:24:19 PM | Computer Name = YOUR-03667082DE | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 2/19/2011 8:24:19 PM | Computer Name = YOUR-03667082DE | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 2/19/2011 8:24:19 PM | Computer Name = YOUR-03667082DE | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 2/19/2011 8:24:19 PM | Computer Name = YOUR-03667082DE | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 2/19/2011 8:24:19 PM | Computer Name = YOUR-03667082DE | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126


< End of report >
hello tom and here is rootkit log RkU Version: 3.8.388.590, Type LE (SR2) ============================================== OS Name: Windows XP Version 5.1.2600 (Service Pack 2) Number of processors #1 ============================================== >Drivers ============================================== 0xB93B1000 C:\WINDOWS\system32\drivers\ALCXWDM.SYS 2318336 bytes (Realtek Semiconductor Corp., Realtek AC'97 Audio Driver (WDM)) 0x804D7000 C:\WINDOWS\system32\ntkrnlpa.exe 2058368 bytes (Microsoft Corporation, NT Kernel & System) 0x804D7000 PnpManager 2058368 bytes 0x804D7000 RAW 2058368 bytes 0x804D7000 WMIxWDM 2058368 bytes 0xBF800000 Win32k 1851392 bytes 0xBF800000 C:\WINDOWS\System32\win32k.sys 1851392 bytes (Microsoft Corporation, Multi-User Win32 Driver) 0xBF012000 C:\WINDOWS\System32\SiSGRV.dll 1236992 bytes (Silicon Integrated Systems Corporation, SiS Compatible Super VGA Driver) 0xB928F000 C:\WINDOWS\system32\DRIVERS\HCF_MSFT.sys 909312 bytes (Conexant, Modem) 0xB9E20000 Ntfs.sys 577536 bytes (Microsoft Corporation, NT File System Driver) 0xAFD76000 C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 454656 bytes (Microsoft Corporation, Windows NT SMB Minirdr) 0xAFE5B000 C:\WINDOWS\system32\DRIVERS\tcpip.sys 360448 bytes (Microsoft Corporation, TCP/IP Protocol Driver) 0xAF866000 C:\WINDOWS\system32\DRIVERS\srv.sys 356352 bytes (Microsoft Corporation, Server driver) 0xAF183000 C:\WINDOWS\System32\Drivers\HTTP.sys 266240 bytes (Microsoft Corporation, HTTP Protocol Stack) 0xB9662000 C:\WINDOWS\system32\DRIVERS\sisgrp.sys 266240 bytes (Silicon Integrated Systems Corporation, SiS Compatible Super VGA Driver) 0xB921F000 C:\WINDOWS\system32\DRIVERS\update.sys 212992 bytes (Microsoft Corporation, Update Driver) 0xB9F79000 ACPI.sys 188416 bytes (Microsoft Corporation, ACPI Driver for NT) 0xAF90D000 C:\WINDOWS\system32\DRIVERS\mrxdav.sys 184320 bytes (Microsoft Corporation, Windows NT WebDav Minirdr) 0xB9DF3000 NDIS.sys 184320 bytes (Microsoft Corporation, NDIS 5.1 wrapper driver) 0xAFDE5000 C:\WINDOWS\system32\DRIVERS\rdbss.sys 180224 bytes (Microsoft Corporation, Redirected Drive Buffering SubSystem Driver) 0xAECD5000 C:\WINDOWS\system32\drivers\kmixer.sys 172032 bytes (Microsoft Corporation, Kernel Mode Audio Mixer) 0xAFE33000 C:\WINDOWS\system32\DRIVERS\netbt.sys 163840 bytes (Microsoft Corporation, MBT Transport driver) 0xAFCBA000 C:\WINDOWS\System32\Drivers\Fastfat.SYS 143360 bytes (Microsoft Corporation, Fast FAT File System Driver) 0xB9F0E000 fasttx2k.sys 143360 bytes (Promise Technology, Inc., Promise FastTrak Series Driver for WindowsXP) 0xB95E7000 C:\WINDOWS\system32\DRIVERS\ks.sys 143360 bytes (Microsoft Corporation, Kernel CSA Library) 0xB936D000 C:\WINDOWS\system32\DRIVERS\USBPORT.SYS 143360 bytes (Microsoft Corporation, USB 1.1 & 2.0 Port Driver) 0xAFE11000 C:\WINDOWS\System32\drivers\afd.sys 139264 bytes (Microsoft Corporation, Ancillary Function Driver for WinSock) 0xAFD55000 C:\WINDOWS\system32\DRIVERS\ipnat.sys 135168 bytes (Microsoft Corporation, IP Network Address Translator) 0xB9390000 C:\WINDOWS\system32\drivers\portcls.sys 135168 bytes (Microsoft Corporation, Port Class (Class Driver for Port/Miniport Devices)) 0x806CE000 ACPI_HAL 131968 bytes 0x806CE000 C:\WINDOWS\system32\hal.dll 131968 bytes (Microsoft Corporation, Hardware Abstraction Layer DLL) 0xB9ED6000 fltMgr.sys 131072 bytes (Microsoft Corporation, Microsoft Filesystem Filter Manager) 0xB9F49000 ftdisk.sys 126976 bytes (Microsoft Corporation, FT Disk Driver) 0xB9DD8000 Mup.sys 110592 bytes (Microsoft Corporation, Multiple UNC Provider driver) 0xB9F31000 atapi.sys 98304 bytes (Microsoft Corporation, IDE/ATAPI Port Driver) 0xAFCA2000 C:\WINDOWS\System32\Drivers\dump_atapi.sys 98304 bytes 0xB9EF6000 C:\WINDOWS\system32\DRIVERS\SCSIPORT.SYS 98304 bytes (Microsoft Corporation, SCSI Port Driver) 0xB9EAD000 KSecDD.sys 94208 bytes (Microsoft Corporation, Kernel Security Support Provider Interface) 0xB9264000 C:\WINDOWS\system32\DRIVERS\ndiswan.sys 94208 bytes (Microsoft Corporation, MS PPP Framing Driver (Strong Encryption)) 0xAF5D1000 C:\WINDOWS\system32\drivers\wdmaud.sys 86016 bytes (Microsoft Corporation, MMSYSTEM Wave/Midi API mapper) 0xB927B000 C:\WINDOWS\system32\DRIVERS\parport.sys 81920 bytes (Microsoft Corporation, Parallel Port Driver) 0xB960A000 C:\WINDOWS\system32\DRIVERS\VIDEOPRT.SYS 81920 bytes (Microsoft Corporation, Video Port Driver) 0xAFEB3000 C:\WINDOWS\system32\DRIVERS\ipsec.sys 77824 bytes (Microsoft Corporation, IPSec Driver) 0xBF000000 C:\WINDOWS\System32\drivers\dxg.sys 73728 bytes (Microsoft Corporation, DirectX Graphics Driver) 0xB9EC4000 sr.sys 73728 bytes (Microsoft Corporation, System Restore Filesystem Filter Driver) 0xB9F68000 pci.sys 69632 bytes (Microsoft Corporation, NT Plug and Play PCI Enumerator) 0xB9253000 C:\WINDOWS\system32\DRIVERS\psched.sys 69632 bytes (Microsoft Corporation, MS QoS Packet Scheduler) 0xB974E000 C:\WINDOWS\System32\Drivers\Cdfs.SYS 65536 bytes (Microsoft Corporation, CD-ROM File System Driver) 0xBA1E8000 C:\WINDOWS\system32\DRIVERS\nic1394.sys 65536 bytes (Microsoft Corporation, IEEE1394 Ndis Miniport and Call Manager) 0xBA178000 C:\WINDOWS\system32\DRIVERS\serial.sys 65536 bytes (Microsoft Corporation, Serial Device Driver) 0xBA2F8000 C:\WINDOWS\system32\DRIVERS\arp1394.sys 61440 bytes (Microsoft Corporation, IP/1394 Arp Client) 0xBA168000 C:\WINDOWS\system32\drivers\drmk.sys 61440 bytes (Microsoft Corporation, Microsoft Kernel DRM Descrambler Filter) 0xBA108000 ohci1394.sys 61440 bytes (Microsoft Corporation, 1394 OpenHCI Port Driver) 0xBA158000 C:\WINDOWS\system32\DRIVERS\redbook.sys 61440 bytes (Microsoft Corporation, Redbook Audio Filter Driver) 0xAF716000 C:\WINDOWS\system32\drivers\sysaudio.sys 61440 bytes (Microsoft Corporation, System Audio WDM Filter) 0xBA248000 C:\WINDOWS\system32\DRIVERS\usbhub.sys 61440 bytes (Microsoft Corporation, Default Hub Driver for USB) 0xB971E000 C:\WINDOWS\system32\DRIVERS\AmdK8.sys 57344 bytes (Advanced Micro Devices, AMD Processor Driver) 0xBA118000 C:\WINDOWS\system32\DRIVERS\1394BUS.SYS 53248 bytes (Microsoft Corporation, 1394 Bus Device Driver) 0xBA148000 C:\WINDOWS\system32\DRIVERS\cdrom.sys 53248 bytes (Microsoft Corporation, SCSI CD-ROM Driver) 0xBA0E8000 C:\WINDOWS\system32\DRIVERS\CLASSPNP.SYS 53248 bytes (Microsoft Corporation, SCSI Class System Dll) 0xBA188000 C:\WINDOWS\system32\DRIVERS\i8042prt.sys 53248 bytes (Microsoft Corporation, i8042 Port Driver) 0xBA198000 C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 53248 bytes (Microsoft Corporation, RAS L2TP mini-port/call-manager driver) 0xBA0C8000 VolSnap.sys 53248 bytes (Microsoft Corporation, Volume Shadow Copy Driver) 0xBA1B8000 C:\WINDOWS\system32\DRIVERS\raspptp.sys 49152 bytes (Microsoft Corporation, Peer-to-Peer Tunneling Protocol) 0xB970E000 C:\WINDOWS\system32\DRIVERS\imapi.sys 45056 bytes (Microsoft Corporation, IMAPI Kernel Driver) 0xBA0B8000 MountMgr.sys 45056 bytes (Microsoft Corporation, Mount Manager) 0xBA1A8000 C:\WINDOWS\system32\DRIVERS\raspppoe.sys 45056 bytes (Microsoft Corporation, RAS PPPoE mini-port/call-manager driver) 0xBA1F8000 C:\WINDOWS\System32\Drivers\NDProxy.SYS 40960 bytes (Microsoft Corporation, NDIS Proxy) 0xBA0F8000 SISAGPX.sys 40960 bytes (Silicon Integrated Systems Corporation, SiS AGPv3.5 Filter) 0xBA1D8000 C:\WINDOWS\system32\DRIVERS\termdd.sys 40960 bytes (Microsoft Corporation, Terminal Server Driver) 0xBA0D8000 disk.sys 36864 bytes (Microsoft Corporation, PnP Disk Driver) 0xBA2D8000 C:\WINDOWS\System32\Drivers\Fips.SYS 36864 bytes (Microsoft Corporation, FIPS Crypto Driver) 0xBA0A8000 isapnp.sys 36864 bytes (Microsoft Corporation, PNP ISA Bus Driver) 0xBA1C8000 C:\WINDOWS\system32\DRIVERS\msgpc.sys 36864 bytes (Microsoft Corporation, MS General Packet Classifier) 0xBA2A8000 C:\WINDOWS\system32\DRIVERS\netbios.sys 36864 bytes (Microsoft Corporation, NetBIOS interface driver) 0xAFBE2000 C:\WINDOWS\System32\Drivers\Normandy.SYS 36864 bytes (RKU Driver) 0xBA2E8000 C:\WINDOWS\system32\DRIVERS\wanarp.sys 36864 bytes (Microsoft Corporation, MS Remote Access and Routing ARP Driver) 0xBA468000 C:\WINDOWS\System32\Drivers\Modem.SYS 32768 bytes (Microsoft Corporation, Modem Device Driver) 0xBA3C8000 C:\WINDOWS\System32\Drivers\Npfs.SYS 32768 bytes (Microsoft Corporation, NPFS Driver) 0xBA460000 C:\WINDOWS\system32\DRIVERS\sisnic.sys 32768 bytes (SiS Corporation, SiS PCI Fast Ethernet Adapter Driver) 0xBA448000 C:\WINDOWS\SYSTEM32\DRIVERS\GEARAspiWDM.sys 28672 bytes (GEAR Software Inc., CDRom Class Filter Driver) 0xBA328000 C:\WINDOWS\system32\DRIVERS\PCIIDEX.SYS 28672 bytes (Microsoft Corporation, PCI IDE Bus Driver Extension) 0xBA458000 C:\WINDOWS\system32\DRIVERS\usbehci.sys 28672 bytes (Microsoft Corporation, EHCI eUSB Miniport Driver) 0xBA3F0000 C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 28672 bytes (Microsoft Corporation, USB Mass Storage Class Driver) 0xBA340000 viaagp1.sys 28672 bytes (VIA Technologies, Inc., VIA NT AGP Filter) 0xBA440000 C:\WINDOWS\system32\drivers\iviaspi.sys 24576 bytes (InterVideo, Inc., InterVideo ASPI Shell) 0xBA478000 C:\WINDOWS\system32\DRIVERS\kbdclass.sys 24576 bytes (Microsoft Corporation, Keyboard Class Driver) 0xBA470000 C:\WINDOWS\system32\DRIVERS\mouclass.sys 24576 bytes (Microsoft Corporation, Mouse Class Driver) 0xBA3B8000 C:\WINDOWS\System32\drivers\vga.sys 24576 bytes (Microsoft Corporation, VGA/Super VGA Video Driver) 0xBA3C0000 C:\WINDOWS\System32\Drivers\Msfs.SYS 20480 bytes (Microsoft Corporation, Mailslot driver) 0xBA330000 PartMgr.sys 20480 bytes (Microsoft Corporation, Partition Manager) 0xBA488000 C:\WINDOWS\system32\DRIVERS\ptilink.sys 20480 bytes (Parallel Technologies, Inc., Parallel Technologies DirectParallel IO Library) 0xBA338000 PxHelp20.sys 20480 bytes (Sonic Solutions, Px Engine Device Driver for Windows 2000/XP) 0xBA490000 C:\WINDOWS\system32\DRIVERS\raspti.sys 20480 bytes (Microsoft Corporation, PTI DirectParallel® mini-port/call-manager driver) 0xBA480000 C:\WINDOWS\system32\DRIVERS\TDI.SYS 20480 bytes (Microsoft Corporation, TDI Wrapper) 0xBA450000 C:\WINDOWS\system32\DRIVERS\usbohci.sys 20480 bytes (Microsoft Corporation, OHCI USB Miniport Driver) 0xBA430000 C:\WINDOWS\System32\watchdog.sys 20480 bytes (Microsoft Corporation, Watchdog Driver) 0xB96A3000 C:\WINDOWS\system32\DRIVERS\mssmbios.sys 16384 bytes (Microsoft Corporation, System Management BIOS Driver) 0xAFB76000 C:\WINDOWS\system32\DRIVERS\ndisuio.sys 16384 bytes (Microsoft Corporation, NDIS User mode I/O Driver) 0xB96B7000 C:\WINDOWS\system32\DRIVERS\PS2.sys 16384 bytes (Hewlett-Packard Company, PS2 SYS) 0xB96BB000 C:\WINDOWS\system32\DRIVERS\serenum.sys 16384 bytes (Microsoft Corporation, Serial Port Enumerator) 0xBA4B8000 C:\WINDOWS\system32\BOOTVID.dll 12288 bytes (Microsoft Corporation, VGA Boot Driver) 0xBA554000 C:\WINDOWS\System32\drivers\Dxapi.sys 12288 bytes (Microsoft Corporation, DirectX API Driver) 0xB96B3000 C:\WINDOWS\system32\DRIVERS\ndistapi.sys 12288 bytes (Microsoft Corporation, NDIS 3.0 connection wrapper driver) 0xB96C7000 C:\WINDOWS\system32\drivers\pfc.sys 12288 bytes (Padus, Inc., Padus® ASPI Shell) 0xBA590000 C:\WINDOWS\system32\DRIVERS\rasacd.sys 12288 bytes (Microsoft Corporation, RAS Automatic Connection Driver) 0xBA598000 C:\WINDOWS\system32\DRIVERS\srvkp.sys 12288 bytes (Silicon Integrated Systems Corporation, SiS VGA Driver Manager) 0xBA62E000 C:\WINDOWS\System32\Drivers\Beep.SYS 8192 bytes (Microsoft Corporation, BEEP Driver) 0xBA65C000 C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS 8192 bytes 0xBA62C000 C:\WINDOWS\System32\Drivers\Fs_Rec.SYS 8192 bytes (Microsoft Corporation, File System Recognizer Driver) 0xBA5A8000 C:\WINDOWS\system32\KDCOM.DLL 8192 bytes (Microsoft Corporation, Kernel Debugger HW Extension DLL) 0xBA630000 C:\WINDOWS\System32\Drivers\mnmdd.SYS 8192 bytes (Microsoft Corporation, Frame buffer simulator) 0xBA632000 C:\WINDOWS\System32\DRIVERS\RDPCDD.sys 8192 bytes (Microsoft Corporation, RDP Miniport) 0xBA5FA000 C:\WINDOWS\system32\DRIVERS\swenum.sys 8192 bytes (Microsoft Corporation, Plug and Play Software Device Enumerator) 0xBA5FE000 C:\WINDOWS\system32\DRIVERS\USBD.SYS 8192 bytes (Microsoft Corporation, Universal Serial Bus Driver) 0xBA5AA000 C:\WINDOWS\system32\DRIVERS\WMILIB.SYS 8192 bytes (Microsoft Corporation, WMILIB WMI support library Dll) 0xBA767000 C:\WINDOWS\system32\DRIVERS\audstub.sys 4096 bytes (Microsoft Corporation, AudStub Driver) 0xBA6BE000 C:\WINDOWS\System32\drivers\dxgthk.sys 4096 bytes (Microsoft Corporation, DirectX Graphics Driver Thunk) 0xBA7F3000 C:\WINDOWS\System32\Drivers\Null.SYS 4096 bytes (Microsoft Corporation, NULL Driver) 0xBA670000 pciide.sys 4096 bytes (Microsoft Corporation, Generic PCI IDE Bus Driver) ============================================== >Stealth ==============================================
Hi,

Please open Malwarebytes, under the Log tab you will see the logfile from your scan, please post it in your next reply.



Please go here and have a look how you can disable your security software.

Download Combofix from any of the links below but rename it to before saving it to your desktop.

Link 1
Link 2



——————————————————————–

Double click on the renamed Combofix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it will produce a log for you. Please include the C:\ComboFix.txt in your next reply.

This tool is not a toy and not for everyday use.
ComboFix SHOULD NOT be used unless requested by a forum helper


If you need help, see this link:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix
hello tom here is malware bytes log Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 5822 Windows 5.1.2600 Service Pack 2 Internet Explorer 8.0.6001.18702 2/20/2011 11:03:24 AM mbam-log-2011-02-20 (11-03-24).txt Scan type: Quick scan Objects scanned: 188883 Time elapsed: 19 minute(s), 9 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 20 Files Infected: 161 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: c:\program files\funwebproducts (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\funwebproducts\screensaver (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\funwebproducts\screensaver\Cache (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\funwebproducts\screensaver\Images (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\funwebproducts\Shared (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\funwebproducts\Shared\Cache (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\1.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Avatar (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Cache (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Game (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\History (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\icons (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Message (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Message\COMMON (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Notifier (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Settings (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\relevantknowledge (Spyware.MarketScore) -> Quarantined and deleted successfully. c:\program files\relevantknowledge\components (Spyware.MarketScore) -> Quarantined and deleted successfully. Files Infected: c:\documents and settings\networkservice\application data\aveydrxso2.exe (Trojan.FakeAlert.Gen) -> Quarantined and deleted successfully. c:\documents and settings\networkservice\application data\dfq8jkhr0.exe (Trojan.FakeAlert.Gen) -> Quarantined and deleted successfully. c:\documents and settings\networkservice\application data\qp8s3bwtl.exe (Trojan.FakeAlert.Gen) -> Quarantined and deleted successfully. c:\documents and settings\networkservice\application data\XyK4dSE.exe (Trojan.FakeAlert.Gen) -> Quarantined and deleted successfully. c:\documents and settings\networkservice\application data\y5uwj6orl.exe (Trojan.FakeAlert.Gen) -> Quarantined and deleted successfully. c:\program files\mozilla firefox\plugins\NPMyWebS.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\documents and settings\HP_Owner\local settings\Temp\fjsY.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully. c:\WINDOWS\Temp\15.tmp (Trojan.FakeAlert.Gen) -> Quarantined and deleted successfully. c:\WINDOWS\Temp\3kUOC17u.sys (Rootkit.Agent) -> Quarantined and deleted successfully. c:\documents and settings\HP_Owner\local settings\temporary internet files\Content.IE5\8HIJ8DAJ\ehf7f9a715v03008f35002r65eba8a1102tbc7e5308q0000028b901806f002d000aj1000060 1l0409k3d4d394b3180[1] (Trojan.FakeAlert) -> Quarantined and deleted successfully. c:\documents and settings\HP_Owner\local settings\temporary internet files\Content.IE5\WJSUUEJE\ehf7f9a715v03008f35002r65eba8a1102tbc7e5308q0000028b901806f002d000aj1000060 1l0409k3d4d394b3181[1] (Rootkit.Agent) -> Quarantined and deleted successfully. c:\documents and settings\networkservice\local settings\temporary internet files\Content.IE5\5ON7ZNWJ\dm11[1].exe (Trojan.Downloader) -> Quarantined and deleted successfully. c:\program files\funwebproducts\screensaver\Cache\0008EE8F.jpg (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\funwebproducts\screensaver\Cache\00090EB9.jpg (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\funwebproducts\screensaver\Cache\00092D5D.jpg (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\funwebproducts\screensaver\Cache\0009448F.jpg (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\funwebproducts\screensaver\Cache\000958D2.jpg (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\funwebproducts\screensaver\Cache\files.ini (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\funwebproducts\screensaver\Images\000846D5.urr (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\funwebproducts\screensaver\Images\0008E095.urr (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\funwebproducts\screensaver\Images\000901B9.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\funwebproducts\screensaver\Images\00092CE0.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\funwebproducts\screensaver\Images\00094460.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\funwebproducts\screensaver\Images\00095884.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\funwebproducts\screensaver\Images\00096778.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\funwebproducts\screensaver\Images\00097FF2.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\funwebproducts\screensaver\Images\000986D7.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\funwebproducts\screensaver\Images\00098D7E.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\funwebproducts\screensaver\Images\0009AFDB.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\funwebproducts\screensaver\Images\0009B951.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\funwebproducts\screensaver\Images\0009C085.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\funwebproducts\screensaver\Images\0009C661.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\funwebproducts\screensaver\Images\0009CC1E.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\funwebproducts\screensaver\Images\000A05DB.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\funwebproducts\screensaver\Images\000A0D6C.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\funwebproducts\screensaver\Images\000A25E6.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\funwebproducts\screensaver\Images\000A322B.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\funwebproducts\screensaver\Images\000A4FF4.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\funwebproducts\screensaver\Images\f3wallpp.bmp (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\funwebproducts\screensaver\Images\wrkparam.lst (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\funwebproducts\Shared\Cache\cursormaniabtn.html (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\funwebproducts\Shared\Cache\myfuncardsimbtn.html (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\funwebproducts\Shared\Cache\smileycentralbtn.html (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\funwebproducts\Shared\Cache\webfettibtn.html (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\1.bin\F3WPHOOK.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\1.bin\F3BKGERR.JPG (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\1.bin\F3CJPEG.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\1.bin\F3DTACTL.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\1.bin\F3HISTSW.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\1.bin\F3HKSTUB.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\1.bin\F3HTMLMU.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\1.bin\F3HTTPCT.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\1.bin\F3POPSWT.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\1.bin\F3PSSAVR.SCR (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\1.bin\F3REGHK.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\1.bin\F3REPROX.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\1.bin\F3RESTUB.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\1.bin\F3SCHMON.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\1.bin\F3SCRCTR.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\1.bin\F3SPACER.WMV (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\1.bin\F3WALLPP.DAT (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\1.bin\FWPBUDDY.PNG (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\1.bin\M3AUXSTB.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\1.bin\M3DLGHK.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\1.bin\M3FFXTBR.JAR (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\1.bin\m3ffxtbr.manifest (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\1.bin\M3HIGHIN.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\1.bin\M3HTML.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\1.bin\M3IDLE.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\1.bin\M3IMPIPE.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\1.bin\M3MEDINT.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\1.bin\M3MSG.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\1.bin\M3NTSTBR.JAR (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\1.bin\m3ntstbr.manifest (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\1.bin\M3OUTLCN.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\1.bin\M3PLUGIN.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\1.bin\M3SKIN.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\1.bin\M3SKPLAY.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\1.bin\M3SLSRCH.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\1.bin\MWSBAR.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\1.bin\MWSOEPLG.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\1.bin\MWSOESTB.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\1.bin\MWSSRCAS.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\1.bin\MWSSVC.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\1.bin\NPMYWEBS.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Avatar\COMMON.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Cache\00039982.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Cache\00039D6A.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Cache\0003AA1C.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Cache\0003AB35.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Cache\0008308E (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Cache\0008386E (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Cache\00083A81.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Cache\00083CB4.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Cache\0008400F.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Cache\00084399.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Cache\002A8909.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Cache\00624614 (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Cache\files.ini (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Game\CHECKERS.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Game\CHESS.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Game\REVERSI.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\History\search3 (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\icons\CM.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\icons\MFC.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\icons\PSS.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\icons\SMILEY.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\icons\WB.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\icons\ZWINKY.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Message\COMMON.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Message\COMMON\8_step1.gif (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Message\COMMON\ask_logo.gif (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Message\COMMON\autoup.gif (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Message\COMMON\autoup.htm (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Message\COMMON\bkwebfet.jpg (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Message\COMMON\bkzwinky.jpg (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Message\COMMON\blubtn2d.png (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Message\COMMON\blubtn2r.png (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Message\COMMON\blubtn3d.png (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Message\COMMON\blubtn3r.png (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Message\COMMON\center.htm (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Message\COMMON\index.htm (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Message\COMMON\logo_ZJ.png (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Message\COMMON\logo_ZR.png (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Message\COMMON\mid_dots.gif (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Message\COMMON\mws_logo.gif (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Message\COMMON\protect.htm (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Message\COMMON\rebbtnbg.png (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Message\COMMON\rebbtnn1.png (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Message\COMMON\rebbtnn2.png (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Message\COMMON\rebbtny1.png (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Message\COMMON\rebbtny2.png (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Message\COMMON\rebclose.png (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Message\COMMON\rebut.htm (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Message\COMMON\rebut2.htm (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Message\COMMON\rebut3.htm (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Message\COMMON\rebut3b.htm (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Message\COMMON\reb_bg.png (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Message\COMMON\repmidsm.png (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Message\COMMON\shield.png (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Message\COMMON\shocked.gif (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Message\COMMON\stop.gif (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Message\COMMON\systray.htm (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Message\COMMON\systrayp.htm (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Message\COMMON\tp_grad.gif (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Message\COMMON\warn.gif (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Notifier\COMMON.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Notifier\DOG.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Notifier\FISH.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Notifier\KUNGFU.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Notifier\LIFEGARD.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Notifier\MAID.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Notifier\MAILBOX.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Notifier\OPERA.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Notifier\ROBOT.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Notifier\SEDUCT.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Notifier\SURFER.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Settings\prevcfg2.htm (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Settings\setting2.htm (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Settings\settings.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Settings\s_pid.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
hello tom here is log from combofix


ComboFix 11-02-24.01 - HP_Owner 02/24/2011 10:02:18.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1407.904 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\docume~1\HP_OWN~1.000\LOCALS~1\Temp\IadHide5.dll
c:\documents and settings\HP_Owner.YOUR-03667082DE.000\Local Settings\Temp\IadHide5.dll
c:\documents and settings\HP_Owner.YOUR-03667082DE\Application Data\uid_pal
c:\documents and settings\HP_Owner.YOUR-03667082DE\Desktop\Internet Explorer.lnk
C:\Install.exe
c:\windows\Downloaded Program Files\f3initialsetup1.0.1.1.inf
c:\windows\Tasks\At1.job
c:\windows\Tasks\At10.job
c:\windows\Tasks\At11.job
c:\windows\Tasks\At12.job
c:\windows\Tasks\At2.job
c:\windows\Tasks\At3.job
c:\windows\Tasks\At4.job
c:\windows\Tasks\At5.job
c:\windows\Tasks\At6.job
c:\windows\Tasks\At7.job
c:\windows\Tasks\At8.job
c:\windows\Tasks\At9.job
c:\windows\viassary-hp.reg
D:\Autorun.inf

.
((((((((((((((((((((((((( Files Created from 2011-01-24 to 2011-02-24 )))))))))))))))))))))))))))))))
.

2011-02-23 22:15 . 2011-02-23 22:15 ——– d—–w- c:\documents and settings\NetworkService\Application Data\Xfire
2011-02-23 20:19 . 2011-01-13 09:41 5890896 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{0572F3C1-C35F-423B-B8BF-8AC56D6B21CA}\mpengine.dll
2011-02-22 15:23 . 2010-08-26 12:52 5120 —-a-w- c:\windows\system32\xpsp4res.dll
2011-02-22 13:17 . 2011-02-22 13:17 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2011-02-22 13:07 . 2011-02-22 13:07 ——– d—–w- c:\windows\system32\scripting
2011-02-22 13:07 . 2011-02-22 13:07 ——– d—–w- c:\windows\system32\bits
2011-02-21 21:17 . 2009-08-07 03:23 274288 —-a-w- c:\windows\system32\mucltui.dll
2011-02-21 21:17 . 2009-08-07 03:23 215920 —-a-w- c:\windows\system32\muweb.dll
2011-02-21 15:19 . 2011-01-13 09:41 5890896 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-02-21 15:18 . 2011-02-03 01:11 222080 ——w- c:\windows\system32\MpSigStub.exe
2011-02-21 15:16 . 2011-02-21 15:16 ——– d—–w- c:\program files\Microsoft Security Client
2011-02-20 18:41 . 2011-02-20 18:41 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-02-20 18:41 . 2010-12-21 02:09 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-02-20 18:41 . 2011-02-20 18:41 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-02-20 18:41 . 2010-12-21 02:08 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-02-20 05:09 . 2011-02-23 22:16 ——– d—–w- c:\program files\Xfire
2011-02-20 00:07 . 2011-02-20 00:18 ——– d—–w- C:\9ed20b7a62c8e74031b5087805ec2c
2011-02-15 23:55 . 2011-02-15 23:55 ——– d—–w- c:\documents and settings\All Users\Application Data\MysteryChronicles
2011-02-15 23:54 . 2011-02-15 23:54 ——– d—–w- c:\program files\Mystery Chronicles - Murder Among Friends
2011-02-13 20:09 . 2011-02-13 20:14 ——– d—–w- c:\program files\Mystery Case Files - Dire Grove
2011-02-12 22:57 . 2011-02-12 22:59 ——– d—–w- c:\program files\Dark Tales - Edgar Allan Poe`s Murders in the Rue Morgue
2011-02-12 22:50 . 2011-02-12 22:51 ——– d—–w- c:\program files\Midnight Mysteries - The Edgar Allan Poe Conspiracy
2011-02-12 17:20 . 2011-02-12 17:21 ——– d—–w- c:\program files\Stray Souls - Dollhouse Story Collector's Edition
2011-02-12 17:11 . 2011-02-12 17:11 ——– d—–w- c:\documents and settings\All Users\Application Data\Big Fish Games
2011-02-11 20:48 . 2001-08-18 06:36 5632 —-a-w- c:\windows\system32\ptpusb.dll
2011-02-11 20:48 . 2008-04-13 18:45 15104 —-a-w- c:\windows\system32\drivers\usbscan.sys
2011-02-11 20:48 . 2004-08-04 08:56 159232 —-a-w- c:\windows\system32\ptpusd.dll
2011-02-06 14:14 . 2008-04-14 00:12 30208 ——w- c:\windows\system32\napipsec.dll
2011-02-06 14:13 . 2008-04-14 00:11 233472 ——w- c:\windows\system32\azroles.dll
2011-02-06 14:06 . 2008-06-13 11:05 272128 ——w- c:\windows\system32\drivers\bthport.sys
2011-02-06 06:09 . 2009-01-08 02:21 26144 —-a-w- c:\windows\system32\spupdsvc.exe
2011-02-06 02:33 . 2011-02-06 02:34 ——– d—–w- c:\program files\Mystery Case Files - 13th Skull
2011-02-06 00:51 . 2011-02-19 20:24 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2011-02-06 00:38 . 2011-02-12 17:11 ——– d—–w- c:\program files\bfgclient
2011-02-06 00:37 . 2011-02-18 19:28 ——– d—–w- c:\documents and settings\All Users\Application Data\BigFishGamesCache
2011-02-05 20:26 . 2004-08-04 12:00 221184 —-a-w- c:\windows\system32\wmpns.dll
2011-02-05 20:25 . 2011-02-20 06:10 ——– d—–w- c:\documents and settings\HP_Owner.YOUR-03667082DE.000
2011-02-05 20:23 . 2004-10-22 01:59 ——– d—–w- c:\windows\system32\config\systemprofile\WINDOWS
2011-02-05 20:23 . 2003-09-19 09:47 10368 ——w- c:\windows\system32\drivers\pfc.sys
2011-02-05 20:22 . 2003-09-11 07:36 21060 ——w- c:\windows\system32\drivers\iviaspi.sys
2011-02-05 20:22 . 2004-04-16 19:24 61440 —-a-w- c:\windows\system32\ISUSPM.cpl
2011-02-05 20:21 . 2004-09-27 22:09 204800 —-a-w- c:\windows\system32\IVIresizeW7.dll
2011-02-05 20:21 . 2004-09-27 22:09 20480 —-a-w- c:\windows\system32\IVIresize.dll
2011-02-05 20:21 . 2004-09-27 22:09 200704 —-a-w- c:\windows\system32\IVIresizeA6.dll
2011-02-05 20:21 . 2004-09-27 22:09 192512 —-a-w- c:\windows\system32\IVIresizeP6.dll
2011-02-05 20:21 . 2004-09-27 22:09 192512 —-a-w- c:\windows\system32\IVIresizeM6.dll
2011-02-05 20:21 . 2004-09-27 22:09 188416 —-a-w- c:\windows\system32\IVIresizePX.dll
2011-02-05 20:20 . 2011-02-05 20:20 ——– d—–w- c:\program files\SiS VGA Utilities V3.63
2011-02-05 19:11 . 2001-08-17 21:28 907456 —-a-w- c:\windows\system32\drivers\HCF_MSFT.sys
2011-02-05 19:11 . 2008-04-13 18:46 61696 —-a-w- c:\windows\system32\drivers\ohci1394.sys
2011-02-05 19:11 . 2001-08-17 21:46 6400 —-a-w- c:\windows\system32\drivers\enum1394.sys
2011-02-05 19:11 . 2008-04-13 18:46 53376 —-a-w- c:\windows\system32\drivers\1394bus.sys
2011-02-05 19:11 . 2004-09-24 16:49 110592 ——w- c:\windows\system32\TVMode.dll
2011-02-05 19:11 . 2004-09-24 16:44 184320 ——w- c:\windows\system32\SiSApCom.dll
2011-02-05 19:11 . 2011-02-05 20:20 ——– d—–w- c:\windows\system32\trayres
2011-02-05 19:11 . 2004-09-24 10:47 331776 —-a-w- c:\windows\system32\sistray.exe
2011-02-05 19:11 . 2004-09-24 16:49 49152 —-a-w- c:\windows\system32\SiSPower.dll
2011-02-05 18:47 . 2011-02-22 20:01 ——– dcsh–r- c:\windows\system32\dllcache
2011-02-04 19:37 . 2011-02-04 19:37 15205 —-a-w- c:\documents and settings\NetworkService\Application Data\MnVsha.js
2011-02-04 18:37 . 2011-02-04 18:37 15203 —-a-w- c:\documents and settings\NetworkService\Application Data\gpNRsCi7X.js
2011-02-04 17:37 . 2011-02-04 17:37 15202 —-a-w- c:\documents and settings\NetworkService\Application Data\MlcPFY.js
2011-02-04 16:37 . 2011-02-04 16:37 15204 —-a-w- c:\documents and settings\NetworkService\Application Data\uogEq.js
2011-02-04 15:37 . 2011-02-04 15:37 15204 —-a-w- c:\documents and settings\NetworkService\Application Data\UwkzqVcyT.js
2011-02-04 14:37 . 2011-02-04 14:37 15205 —-a-w- c:\documents and settings\NetworkService\Application Data\ICHjhA.js
2011-02-04 13:37 . 2011-02-04 13:37 15204 —-a-w- c:\documents and settings\NetworkService\Application Data\WEFjl.js
2011-02-04 12:37 . 2011-02-04 12:37 15202 —-a-w- c:\documents and settings\NetworkService\Application Data\ROnryVn.js
2011-02-03 11:37 . 2011-02-03 11:37 15204 —-a-w- c:\documents and settings\NetworkService\Application Data\TvEcE.js
2011-01-25 21:38 . 2011-01-25 21:38 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\ConduitEngine
2011-01-25 21:38 . 2011-01-27 20:37 ——– d—–w- c:\documents and settings\NetworkService\Application Data\bearsharemediabartb

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-22 13:10 . 2011-02-22 13:10 44032 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\LocalContent\Attachments\devcon.exe
2011-02-22 13:10 . 2011-02-22 13:10 307200 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\pchnotify.exe
2011-02-22 13:10 . 2011-02-22 13:10 3072 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\pchealthde.exe
2011-02-22 13:10 . 2011-02-22 13:10 159744 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\PCHButton.exe
2011-02-22 13:10 . 2011-02-22 13:10 77824 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\FDIWrapper.dll
2011-02-22 13:10 . 2011-02-22 13:10 26572 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\INV16.dll
2011-02-22 13:10 . 2011-02-22 13:10 69632 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\msxmlwrapper.dll
2011-02-22 13:10 . 2011-02-22 13:10 40960 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\ScDmi.dll
2011-02-22 13:09 . 2011-02-22 13:09 49152 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\PCHI18N.dll
2011-02-22 13:09 . 2011-02-22 13:09 139264 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\ContentUpdater.exe
2011-02-22 13:09 . 2011-02-22 13:09 110592 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\DSAPI4.dll
2011-02-22 13:09 . 2011-02-22 13:09 98304 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\PluginCtrl.dll
2011-02-22 13:09 . 2011-02-22 13:09 287310 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\HPBasicDetection.dll
2011-02-22 13:09 . 2011-02-22 13:09 69632 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\msxmlwrapper.dll
2011-02-22 13:09 . 2011-02-22 13:09 114688 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\ZipLib.dll
2011-02-22 13:09 . 2011-02-22 13:09 5632 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\GUI.dll
2011-02-22 13:09 . 2011-02-22 13:09 32768 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\pchapi.dll
2011-02-22 13:09 . 2011-02-22 13:09 434176 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\motivede.dll
2011-02-22 13:09 . 2011-02-22 13:09 315392 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\pchmsxml.dll
2011-02-22 13:09 . 2011-02-22 13:09 77824 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\WinVerifyTrust.dll
2011-02-22 13:09 . 2011-02-22 13:09 344064 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\api.dll
2011-02-22 13:09 . 2011-02-22 13:09 24576 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\pcdapi.dll
2011-02-22 13:09 . 2011-02-22 13:09 45056 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\util.dll
2011-02-22 13:09 . 2011-02-22 13:09 356352 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\client_motkt.dll
2011-02-22 13:09 . 2011-02-22 13:09 282624 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\clientutil52.dll
2011-02-22 13:09 . 2011-02-22 13:09 28672 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\InetWrap.dll
2011-02-22 13:09 . 2011-02-22 13:09 102400 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\PCDrAccess.dll
2011-02-22 13:09 . 2011-02-22 13:09 114688 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\asst_ui.dll
2011-02-22 13:09 . 2011-02-22 13:09 49152 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\hwinv.dll
2011-02-22 13:09 . 2011-02-22 13:09 315392 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\pchmsxml.dll
2011-02-22 13:09 . 2011-02-22 13:09 36864 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\gnu.dll
2011-02-22 13:09 . 2011-02-22 13:09 126976 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\SearchCtrl.dll
2011-02-22 13:09 . 2011-02-22 13:09 4096 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\winverifytrustwrapper.dll
2011-02-22 13:09 . 2011-02-22 13:09 212992 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\jsharpinterp.dll
2011-02-22 13:09 . 2011-02-22 13:09 307200 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\pchealthplugin.dll
2011-01-21 14:44 . 2004-11-11 00:33 439296 —-a-w- c:\windows\system32\shimgvw.dll
2011-01-07 14:09 . 2004-11-11 01:21 290048 —-a-w- c:\windows\system32\atmfd.dll
2010-12-31 13:10 . 2004-11-11 00:34 1854976 —-a-w- c:\windows\system32\win32k.sys
2010-12-22 12:34 . 2004-11-11 00:32 301568 —-a-w- c:\windows\system32\kerberos.dll
2010-12-20 23:59 . 2004-11-11 00:34 916480 —-a-w- c:\windows\system32\wininet.dll
2010-12-20 23:59 . 2004-11-11 00:32 43520 —-a-w- c:\windows\system32\licmgr10.dll
2010-12-20 23:59 . 2004-11-11 00:32 1469440 ——w- c:\windows\system32\inetcpl.cpl
2010-12-20 17:26 . 2004-11-11 00:32 730112 —-a-w- c:\windows\system32\lsasrv.dll
2010-12-20 12:55 . 2004-11-11 00:32 385024 —-a-w- c:\windows\system32\html.iec
2010-12-09 15:15 . 2004-10-21 23:35 718336 —-a-w- c:\windows\system32\ntdll.dll
2010-12-09 14:30 . 2004-11-11 00:31 33280 —-a-w- c:\windows\system32\csrsrv.dll
2010-12-09 13:38 . 2004-11-11 00:32 2192768 —-a-w- c:\windows\system32\ntoskrnl.exe
2010-12-09 13:07 . 2004-08-04 05:59 2069376 —-a-w- c:\windows\system32\ntkrnlpa.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\j2re1.4.2_03\bin\jusched.exe" [2004-10-22 32881]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-08-21 155648]
"HPHUPD06"="c:\program files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe" [2004-06-08 49152]
"HPHmon06"="c:\windows\system32\hphmon06.exe" [2004-06-08 659456]
"KBD"="c:\hp\KBD\KBD.EXE" [2003-02-12 61440]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2004-10-22 180269]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2004-06-05 286720]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2004-04-15 233472]
"SiSPower"="SiSPower.dll" [2004-09-24 49152]
"PS2"="c:\windows\system32\ps2.exe" [2002-10-16 81920]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-15 253952]
"Reminder"="c:\windows\Creator\Remind_XP.exe" [2003-12-18 118784]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 57344]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2004-10-22 98304]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 997408]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]

c:\documents and settings\HP_Owner\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [N/A]
Picture Motion Browser Media Check Tool.lnk - c:\program files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe [2009-12-20 385024]

c:\documents and settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\Startup\
Advanced Registry Optimizer.lnk - c:\program files\Advanced Registry Optimizer\ARO.exe [N/A]
HP Organize.lnk - c:\program files\Hewlett-Packard\HP Organize\bin\displayAgent.exe [2004-10-21 36864]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2004-5-29 241664]
Updates from HP.lnk - c:\program files\Updates from HP\309731\Program\Updates from HP.exe [2004-10-21 45056]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Updates from HP\\309731\\Program\\Updates from HP.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Xfire\\Xfire.exe"=

.
Contents of the 'Scheduled Tasks' folder

2011-02-02 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 18:50]

2011-02-05 c:\windows\Tasks\Easy Internet Sign-up.job
- c:\program files\Easy Internet signup\HPSdpApp.exe [2004-08-13 15:50]

2011-02-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-05 05:06]

2011-02-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-05 05:06]

2011-02-24 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2010-11-11 20:26]

2011-02-24 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2010-03-28 20:11]

2011-02-24 c:\windows\Tasks\User_Feed_Synchronization-{0C07C01B-5CD2-4771-9302-946C711BE426}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 12:31]

2011-02-24 c:\windows\Tasks\User_Feed_Synchronization-{2B9ABC23-7E4A-4EF3-ACD7-A7C28B953E38}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 12:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/?ilc=1
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
IE: Add To HP Organize… - c:\progra~1\HEWLET~1\HPORGA~1\bin/module.main/favorites\ie_add_to.html
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-VTTimer - VTTimer.exe
HKLM-Run-IS CfgWiz - c:\program files\Common Files\Symantec Shared\cfgwiz.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-02-24 10:12
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(3360)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
———————— Other Running Processes ————————
.
c:\program files\Microsoft Security Client\Antimalware\MsMpEng.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\wdfmgr.exe
c:\windows\system32\wscntfy.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\ALCXMNTR.EXE
.
**************************************************************************
.
Completion time: 2011-02-24 10:19:52 - machine was rebooted
ComboFix-quarantined-files.txt 2011-02-24 18:19

Pre-Run: 128,973,221,888 bytes free
Post-Run: 129,677,336,576 bytes free

- - End Of File - - 7B2E48D19446B65F90231CC821F5E5EE
Hi,


1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

File::
c:\documents and settings\NetworkService\Application Data\MnVsha.js
c:\documents and settings\NetworkService\Application Data\gpNRsCi7X.js
c:\documents and settings\NetworkService\Application Data\MlcPFY.js
c:\documents and settings\NetworkService\Application Data\uogEq.js
c:\documents and settings\NetworkService\Application Data\UwkzqVcyT.js
c:\documents and settings\NetworkService\Application Data\ICHjhA.js
c:\documents and settings\NetworkService\Application Data\WEFjl.js
c:\documents and settings\NetworkService\Application Data\ROnryVn.js
c:\documents and settings\NetworkService\Application Data\TvEcE.js


Save this as CFScript.txt, in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.





Please update your version of Malwarebytes and run a quick scan, post back with the content of the logfile.




Please run a free online scan with the ESET Online Scanner
Note: You will need to use Internet Explorer for this scan
  • Tick the box next to YES, I accept the Terms of Use
  • Click Start
  • When asked, allow the ActiveX control to install
  • Click Start
  • Make sure that the options Remove found threats and the option Scan unwanted applications is checked
  • Click Scan (This scan can take several hours, so please be patient)
  • Once the scan is completed, you may close the window
  • Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  • Copy and paste that log as a reply to this topic





Please open OTL, set the extra registry tab to use safe list and hit the run scan button, post back with the 2 logfiles. How is it running now?
here log for 2nd combofix

ComboFix 11-02-25.01 - HP_Owner 02/26/2011 3:48.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1407.989 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\HP_Owner.YOUR-03667082DE.000\Desktop\cfscript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}

FILE ::
"c:\documents and settings\NetworkService\Application Data\gpNRsCi7X.js"
"c:\documents and settings\NetworkService\Application Data\ICHjhA.js"
"c:\documents and settings\NetworkService\Application Data\MlcPFY.js"
"c:\documents and settings\NetworkService\Application Data\MnVsha.js"
"c:\documents and settings\NetworkService\Application Data\ROnryVn.js"
"c:\documents and settings\NetworkService\Application Data\TvEcE.js"
"c:\documents and settings\NetworkService\Application Data\uogEq.js"
"c:\documents and settings\NetworkService\Application Data\UwkzqVcyT.js"
"c:\documents and settings\NetworkService\Application Data\WEFjl.js"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\docume~1\HP_OWN~1.000\LOCALS~1\Temp\IadHide5.dll
c:\documents and settings\HP_Owner.YOUR-03667082DE.000\Local Settings\Temp\IadHide5.dll
c:\documents and settings\NetworkService\Application Data\gpNRsCi7X.js
c:\documents and settings\NetworkService\Application Data\ICHjhA.js
c:\documents and settings\NetworkService\Application Data\MlcPFY.js
c:\documents and settings\NetworkService\Application Data\MnVsha.js
c:\documents and settings\NetworkService\Application Data\ROnryVn.js
c:\documents and settings\NetworkService\Application Data\TvEcE.js
c:\documents and settings\NetworkService\Application Data\uogEq.js
c:\documents and settings\NetworkService\Application Data\UwkzqVcyT.js
c:\documents and settings\NetworkService\Application Data\WEFjl.js
c:\windows\viassary-hp.reg

.
((((((((((((((((((((((((( Files Created from 2011-01-26 to 2011-02-26 )))))))))))))))))))))))))))))))
.

2011-02-25 19:57 . 2011-02-11 06:54 5943120 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{6B4200D8-8C8C-4579-83C7-82A3574B5FE8}\mpengine.dll
2011-02-23 22:15 . 2011-02-23 22:15 ——– d—–w- c:\documents and settings\NetworkService\Application Data\Xfire
2011-02-22 15:23 . 2010-08-26 12:52 5120 —-a-w- c:\windows\system32\xpsp4res.dll
2011-02-22 13:17 . 2011-02-22 13:17 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2011-02-22 13:07 . 2011-02-22 13:07 ——– d—–w- c:\windows\system32\scripting
2011-02-22 13:07 . 2011-02-22 13:07 ——– d—–w- c:\windows\system32\bits
2011-02-21 21:17 . 2009-08-07 03:23 274288 —-a-w- c:\windows\system32\mucltui.dll
2011-02-21 21:17 . 2009-08-07 03:23 215920 —-a-w- c:\windows\system32\muweb.dll
2011-02-21 15:19 . 2011-02-11 06:54 5943120 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-02-21 15:18 . 2011-02-03 01:11 222080 ——w- c:\windows\system32\MpSigStub.exe
2011-02-21 15:16 . 2011-02-21 15:16 ——– d—–w- c:\program files\Microsoft Security Client
2011-02-20 18:41 . 2011-02-20 18:41 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-02-20 18:41 . 2010-12-21 02:09 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-02-20 18:41 . 2011-02-20 18:41 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-02-20 18:41 . 2010-12-21 02:08 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-02-20 05:09 . 2011-02-23 22:16 ——– d—–w- c:\program files\Xfire
2011-02-20 00:07 . 2011-02-20 00:18 ——– d—–w- C:\9ed20b7a62c8e74031b5087805ec2c
2011-02-15 23:55 . 2011-02-15 23:55 ——– d—–w- c:\documents and settings\All Users\Application Data\MysteryChronicles
2011-02-15 23:54 . 2011-02-15 23:54 ——– d—–w- c:\program files\Mystery Chronicles - Murder Among Friends
2011-02-13 20:09 . 2011-02-13 20:14 ——– d—–w- c:\program files\Mystery Case Files - Dire Grove
2011-02-12 22:57 . 2011-02-12 22:59 ——– d—–w- c:\program files\Dark Tales - Edgar Allan Poe`s Murders in the Rue Morgue
2011-02-12 22:50 . 2011-02-12 22:51 ——– d—–w- c:\program files\Midnight Mysteries - The Edgar Allan Poe Conspiracy
2011-02-12 17:20 . 2011-02-12 17:21 ——– d—–w- c:\program files\Stray Souls - Dollhouse Story Collector's Edition
2011-02-12 17:11 . 2011-02-12 17:11 ——– d—–w- c:\documents and settings\All Users\Application Data\Big Fish Games
2011-02-11 20:48 . 2001-08-18 06:36 5632 —-a-w- c:\windows\system32\ptpusb.dll
2011-02-11 20:48 . 2008-04-13 18:45 15104 —-a-w- c:\windows\system32\drivers\usbscan.sys
2011-02-11 20:48 . 2004-08-04 08:56 159232 —-a-w- c:\windows\system32\ptpusd.dll
2011-02-06 14:14 . 2008-04-14 00:12 30208 ——w- c:\windows\system32\napipsec.dll
2011-02-06 14:13 . 2008-04-14 00:11 233472 ——w- c:\windows\system32\azroles.dll
2011-02-06 14:06 . 2008-06-13 11:05 272128 ——w- c:\windows\system32\drivers\bthport.sys
2011-02-06 06:09 . 2009-01-08 02:21 26144 —-a-w- c:\windows\system32\spupdsvc.exe
2011-02-06 02:33 . 2011-02-06 02:34 ——– d—–w- c:\program files\Mystery Case Files - 13th Skull
2011-02-06 00:51 . 2011-02-19 20:24 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2011-02-06 00:38 . 2011-02-12 17:11 ——– d—–w- c:\program files\bfgclient
2011-02-06 00:37 . 2011-02-18 19:28 ——– d—–w- c:\documents and settings\All Users\Application Data\BigFishGamesCache
2011-02-05 20:26 . 2004-08-04 12:00 221184 —-a-w- c:\windows\system32\wmpns.dll
2011-02-05 20:25 . 2011-02-20 06:10 ——– d—–w- c:\documents and settings\HP_Owner.YOUR-03667082DE.000
2011-02-05 20:23 . 2004-10-22 01:59 ——– d—–w- c:\windows\system32\config\systemprofile\WINDOWS
2011-02-05 20:23 . 2003-09-19 09:47 10368 ——w- c:\windows\system32\drivers\pfc.sys
2011-02-05 20:22 . 2003-09-11 07:36 21060 ——w- c:\windows\system32\drivers\iviaspi.sys
2011-02-05 20:22 . 2004-04-16 19:24 61440 —-a-w- c:\windows\system32\ISUSPM.cpl
2011-02-05 20:21 . 2004-09-27 22:09 204800 —-a-w- c:\windows\system32\IVIresizeW7.dll
2011-02-05 20:21 . 2004-09-27 22:09 20480 —-a-w- c:\windows\system32\IVIresize.dll
2011-02-05 20:21 . 2004-09-27 22:09 200704 —-a-w- c:\windows\system32\IVIresizeA6.dll
2011-02-05 20:21 . 2004-09-27 22:09 192512 —-a-w- c:\windows\system32\IVIresizeP6.dll
2011-02-05 20:21 . 2004-09-27 22:09 192512 —-a-w- c:\windows\system32\IVIresizeM6.dll
2011-02-05 20:21 . 2004-09-27 22:09 188416 —-a-w- c:\windows\system32\IVIresizePX.dll
2011-02-05 20:20 . 2011-02-05 20:20 ——– d—–w- c:\program files\SiS VGA Utilities V3.63
2011-02-05 19:11 . 2001-08-17 21:28 907456 —-a-w- c:\windows\system32\drivers\HCF_MSFT.sys
2011-02-05 19:11 . 2008-04-13 18:46 61696 —-a-w- c:\windows\system32\drivers\ohci1394.sys
2011-02-05 19:11 . 2001-08-17 21:46 6400 —-a-w- c:\windows\system32\drivers\enum1394.sys
2011-02-05 19:11 . 2008-04-13 18:46 53376 —-a-w- c:\windows\system32\drivers\1394bus.sys
2011-02-05 19:11 . 2004-09-24 16:49 110592 ——w- c:\windows\system32\TVMode.dll
2011-02-05 19:11 . 2004-09-24 16:44 184320 ——w- c:\windows\system32\SiSApCom.dll
2011-02-05 19:11 . 2011-02-05 20:20 ——– d—–w- c:\windows\system32\trayres
2011-02-05 19:11 . 2004-09-24 10:47 331776 —-a-w- c:\windows\system32\sistray.exe
2011-02-05 19:11 . 2004-09-24 16:49 49152 —-a-w- c:\windows\system32\SiSPower.dll
2011-02-05 18:47 . 2011-02-22 20:01 ——– dcsh–r- c:\windows\system32\dllcache

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-22 13:10 . 2011-02-22 13:10 44032 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\LocalContent\Attachments\devcon.exe
2011-02-22 13:10 . 2011-02-22 13:10 307200 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\pchnotify.exe
2011-02-22 13:10 . 2011-02-22 13:10 3072 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\pchealthde.exe
2011-02-22 13:10 . 2011-02-22 13:10 159744 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\PCHButton.exe
2011-02-22 13:10 . 2011-02-22 13:10 77824 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\FDIWrapper.dll
2011-02-22 13:10 . 2011-02-22 13:10 26572 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\INV16.dll
2011-02-22 13:10 . 2011-02-22 13:10 69632 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\msxmlwrapper.dll
2011-02-22 13:10 . 2011-02-22 13:10 40960 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\ScDmi.dll
2011-02-22 13:09 . 2011-02-22 13:09 49152 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\PCHI18N.dll
2011-02-22 13:09 . 2011-02-22 13:09 139264 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\ContentUpdater.exe
2011-02-22 13:09 . 2011-02-22 13:09 110592 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\DSAPI4.dll
2011-02-22 13:09 . 2011-02-22 13:09 98304 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\PluginCtrl.dll
2011-02-22 13:09 . 2011-02-22 13:09 287310 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\HPBasicDetection.dll
2011-02-22 13:09 . 2011-02-22 13:09 69632 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\msxmlwrapper.dll
2011-02-22 13:09 . 2011-02-22 13:09 114688 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\ZipLib.dll
2011-02-22 13:09 . 2011-02-22 13:09 5632 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\GUI.dll
2011-02-22 13:09 . 2011-02-22 13:09 32768 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\pchapi.dll
2011-02-22 13:09 . 2011-02-22 13:09 434176 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\motivede.dll
2011-02-22 13:09 . 2011-02-22 13:09 315392 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\pchmsxml.dll
2011-02-22 13:09 . 2011-02-22 13:09 77824 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\WinVerifyTrust.dll
2011-02-22 13:09 . 2011-02-22 13:09 344064 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\api.dll
2011-02-22 13:09 . 2011-02-22 13:09 24576 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\pcdapi.dll
2011-02-22 13:09 . 2011-02-22 13:09 45056 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\util.dll
2011-02-22 13:09 . 2011-02-22 13:09 356352 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\client_motkt.dll
2011-02-22 13:09 . 2011-02-22 13:09 282624 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\clientutil52.dll
2011-02-22 13:09 . 2011-02-22 13:09 28672 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\InetWrap.dll
2011-02-22 13:09 . 2011-02-22 13:09 102400 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\PCDrAccess.dll
2011-02-22 13:09 . 2011-02-22 13:09 114688 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\asst_ui.dll
2011-02-22 13:09 . 2011-02-22 13:09 49152 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\hwinv.dll
2011-02-22 13:09 . 2011-02-22 13:09 315392 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\pchmsxml.dll
2011-02-22 13:09 . 2011-02-22 13:09 36864 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\gnu.dll
2011-02-22 13:09 . 2011-02-22 13:09 126976 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\SearchCtrl.dll
2011-02-22 13:09 . 2011-02-22 13:09 4096 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\winverifytrustwrapper.dll
2011-02-22 13:09 . 2011-02-22 13:09 212992 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\jsharpinterp.dll
2011-02-22 13:09 . 2011-02-22 13:09 307200 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\pchealthplugin.dll
2011-01-21 14:44 . 2004-11-11 00:33 439296 —-a-w- c:\windows\system32\shimgvw.dll
2011-01-07 14:09 . 2004-11-11 01:21 290048 —-a-w- c:\windows\system32\atmfd.dll
2010-12-31 13:10 . 2004-11-11 00:34 1854976 —-a-w- c:\windows\system32\win32k.sys
2010-12-22 12:34 . 2004-11-11 00:32 301568 —-a-w- c:\windows\system32\kerberos.dll
2010-12-20 23:59 . 2004-11-11 00:34 916480 —-a-w- c:\windows\system32\wininet.dll
2010-12-20 23:59 . 2004-11-11 00:32 43520 —-a-w- c:\windows\system32\licmgr10.dll
2010-12-20 23:59 . 2004-11-11 00:32 1469440 ——w- c:\windows\system32\inetcpl.cpl
2010-12-20 17:26 . 2004-11-11 00:32 730112 —-a-w- c:\windows\system32\lsasrv.dll
2010-12-20 12:55 . 2004-11-11 00:32 385024 —-a-w- c:\windows\system32\html.iec
2010-12-09 15:15 . 2004-10-21 23:35 718336 —-a-w- c:\windows\system32\ntdll.dll
2010-12-09 14:30 . 2004-11-11 00:31 33280 —-a-w- c:\windows\system32\csrsrv.dll
2010-12-09 13:38 . 2004-11-11 00:32 2192768 —-a-w- c:\windows\system32\ntoskrnl.exe
2010-12-09 13:07 . 2004-08-04 05:59 2069376 —-a-w- c:\windows\system32\ntkrnlpa.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\j2re1.4.2_03\bin\jusched.exe" [2004-10-22 32881]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-08-21 155648]
"HPHUPD06"="c:\program files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe" [2004-06-08 49152]
"HPHmon06"="c:\windows\system32\hphmon06.exe" [2004-06-08 659456]
"KBD"="c:\hp\KBD\KBD.EXE" [2003-02-12 61440]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2004-10-22 180269]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2004-06-05 286720]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2004-04-15 233472]
"SiSPower"="SiSPower.dll" [2004-09-24 49152]
"PS2"="c:\windows\system32\ps2.exe" [2002-10-16 81920]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-15 253952]
"Reminder"="c:\windows\Creator\Remind_XP.exe" [2003-12-18 118784]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 57344]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2004-10-22 98304]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 997408]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]

c:\documents and settings\HP_Owner\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [N/A]
Picture Motion Browser Media Check Tool.lnk - c:\program files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe [2009-12-20 385024]

c:\documents and settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\Startup\
Advanced Registry Optimizer.lnk - c:\program files\Advanced Registry Optimizer\ARO.exe [N/A]
HP Organize.lnk - c:\program files\Hewlett-Packard\HP Organize\bin\displayAgent.exe [2004-10-21 36864]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2004-5-29 241664]
Updates from HP.lnk - c:\program files\Updates from HP\309731\Program\Updates from HP.exe [2004-10-21 45056]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Updates from HP\\309731\\Program\\Updates from HP.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Xfire\\Xfire.exe"=

.
Contents of the 'Scheduled Tasks' folder

2011-02-02 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 18:50]

2011-02-05 c:\windows\Tasks\Easy Internet Sign-up.job
- c:\program files\Easy Internet signup\HPSdpApp.exe [2004-08-13 15:50]

2011-02-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-05 05:06]

2011-02-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-05 05:06]

2011-02-26 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2010-11-11 20:26]

2011-02-26 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2010-03-28 20:11]

2011-02-26 c:\windows\Tasks\User_Feed_Synchronization-{0C07C01B-5CD2-4771-9302-946C711BE426}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 12:31]

2011-02-26 c:\windows\Tasks\User_Feed_Synchronization-{2B9ABC23-7E4A-4EF3-ACD7-A7C28B953E38}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 12:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/?ilc=1
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
IE: Add To HP Organize… - c:\progra~1\HEWLET~1\HPORGA~1\bin/module.main/favorites\ie_add_to.html
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-02-26 03:55
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(236)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
———————— Other Running Processes ————————
.
c:\program files\Microsoft Security Client\Antimalware\MsMpEng.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\wdfmgr.exe
c:\windows\system32\wscntfy.exe
c:\windows\ALCXMNTR.EXE
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2011-02-26 04:02:58 - machine was rebooted
ComboFix-quarantined-files.txt 2011-02-26 12:02
ComboFix2.txt 2011-02-24 18:19

Pre-Run: 129,496,776,704 bytes free
Post-Run: 129,673,396,224 bytes free

- - End Of File - - 1155464DC8801D8FDAFB304C7FC5E769
hello here is malware log Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 5881 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 2/26/2011 4:14:58 AM mbam-log-2011-02-26 (04-14-58).txt Scan type: Quick scan Objects scanned: 162105 Time elapsed: 4 minute(s), 47 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
here is eset log


ESETSmartInstaller@High as CAB hook log:
OnlineScanner.ocx - registred OK
# version=7
# iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
# OnlineScanner.ocx=1.0.0.6425
# api_version=3.0.2
# EOSSerial=6e578d84167593448e87fbf8e5d96f95
# end=finished
# remove_checked=true
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2011-02-26 01:03:35
# local_time=2011-02-26 05:03:35 (-0800, Pacific Standard Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=5891 16776869 42 87 0 9816933 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=92841
# found=13
# cleaned=13
# scan_time=2546
C:\Documents and Settings\HP_Owner\Local Settings\Application Data\dcavni\evtpsftav.exe a variant of Win32/Adware.SpyProtector.Q application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\1ekutghq.default\Cache\DD56727Fd01 JS/Exploit.Pdfka.NTY trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\HP_Owner.YOUR-03667082DE\Application Data\Sun\Java\Deployment\cache\6.0\8\62e60948-47ed1ecf a variant of Win32/TrojanDropper.Agent.PDB trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\gpNRsCi7X.js.vir JS/TrojanDownloader.Agent.NWG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\ICHjhA.js.vir JS/TrojanDownloader.Agent.NWG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\MlcPFY.js.vir JS/TrojanDownloader.Agent.NWG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\MnVsha.js.vir JS/TrojanDownloader.Agent.NWG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\ROnryVn.js.vir JS/TrojanDownloader.Agent.NWG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\TvEcE.js.vir JS/TrojanDownloader.Agent.NWG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\uogEq.js.vir JS/TrojanDownloader.Agent.NWG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\UwkzqVcyT.js.vir JS/TrojanDownloader.Agent.NWG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\WEFjl.js.vir JS/TrojanDownloader.Agent.NWG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{8F7A5040-9305-4BDA-A5EE-E7EE68E6A93B}\RP30\A0008461.exe a variant of Win32/Adware.SpyProtector.Q application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C


here is otl log and seems to be running ok

OTL logfile created on: 2/26/2011 5:14:00 AM - Run 2
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 64.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 88.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 142.96 Gb Total Space | 120.68 Gb Free Space | 84.41% Space Free | Partition Type: NTFS
Drive D: | 6.07 Gb Total Space | 0.72 Gb Free Space | 11.87% Space Free | Partition Type: FAT32
Drive E: | 558.09 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: YOUR-03667082DE | User Name: HP_Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/02/20 11:57:38 | 000,602,624 | —- | M] (OldTimer Tools) – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop\OTL.exe
PRC - [2010/11/30 13:20:36 | 000,997,408 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2010/11/11 12:26:40 | 000,011,736 | —- | M] (Microsoft Corporation) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
PRC - [2008/04/13 16:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2004/10/21 18:25:36 | 000,045,056 | —- | M] (Hewlett-Packard) – C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
PRC - [2004/10/21 16:27:22 | 000,032,881 | —- | M] () – C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe


========== Modules (SafeList) ==========

MOD - [2011/02/20 11:57:38 | 000,602,624 | —- | M] (OldTimer Tools) – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop\OTL.exe
MOD - [2010/08/23 08:12:02 | 001,054,208 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] – – (HidServ)
SRV - File not found [On_Demand | Stopped] – – (AppMgmt)
SRV - [2010/11/11 12:26:40 | 000,011,736 | —- | M] (Microsoft Corporation) [Auto | Running] – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe – (MsMpSvc)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Running] – – (catchme)
DRV - [2005/04/20 11:00:56 | 002,317,696 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ALCXWDM.SYS – (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2005/04/12 11:42:16 | 000,011,904 | —- | M] (Silicon Integrated Systems Corporation) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\srvkp.sys – (SiSkp)
DRV - [2005/04/12 11:08:44 | 000,247,296 | —- | M] (Silicon Integrated Systems Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\sisgrp.sys – (SiS315)
DRV - [2004/05/08 16:21:44 | 000,035,840 | —- | M] (Advanced Micro Devices) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\AmdK8.sys – (AmdK8)
DRV - [2003/12/02 17:23:20 | 000,142,336 | —- | M] (Promise Technology, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\fasttx2k.sys – (fasttx2k)
DRV - [2003/09/19 01:47:00 | 000,010,368 | —- | M] (Padus, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\pfc.sys – (Pfc)
DRV - [2003/09/10 23:36:54 | 000,021,060 | —- | M] (InterVideo, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\iviaspi.sys – (Iviaspi)
DRV - [2003/07/18 15:58:20 | 000,036,992 | —- | M] (Silicon Integrated Systems Corporation) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\SISAGPX.sys – (SISAGP)
DRV - [2003/07/11 21:28:56 | 000,032,768 | —- | M] (SiS Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\sisnic.sys – (SISNIC)
DRV - [2003/07/02 10:42:00 | 000,027,904 | —- | M] (VIA Technologies, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\viaagp1.sys – (viaagp1)
DRV - [2002/10/04 16:04:10 | 000,046,976 | —- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\R8139n51.sys – (rtl8139)
DRV - [2001/08/17 13:28:02 | 000,907,456 | —- | M] (Conexant) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HCF_MSFT.sys – (HCF_MSFT)
DRV - [2001/06/04 13:00:00 | 000,014,112 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\PS2.sys – (Ps2)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?ilc=1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


[2010/12/12 22:26:36 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/12/12 22:26:36 | 000,000,000 | —D | M] (Skype extension) – C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2010/09/14 04:41:12 | 000,002,506 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\BearShareWebSearch.xml

O1 HOSTS File: ([2011/02/26 03:55:40 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found.
O3 - HKLM\..\Toolbar: (HP view) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll (Hewlett-Packard Company)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (HP view) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll (Hewlett-Packard Company)
O3 - HKCU\..\Toolbar\WebBrowser: (HP view) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll (Hewlett-Packard Company)
O4 - HKLM..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe (Hewlett-Packard)
O4 - HKLM..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\LSBurnWatcher.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [PS2] C:\WINDOWS\system32\ps2.EXE (Hewlett-Packard Company)
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\Recguard.exe ()
O4 - HKLM..\Run: [Reminder] C:\Windows\Creator\Remind_XP.exe (SoftThinks)
O4 - HKLM..\Run: [SiSPower] C:\WINDOWS\System32\SiSPower.dll (Silicon Integrated Systems Corporation)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe ()
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UpdateManager] C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe (Sonic Solutions)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe (Hewlett-Packard)
O4 - Startup: C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\Startup\Advanced Registry Optimizer.lnk = File not found
O4 - Startup: C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\Startup\HP Organize.lnk = C:\Program Files\Hewlett-Packard\HP Organize\bin\displayAgent.exe (NeoPlanet)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add To HP Organize… - C:\PROGRA~1\HEWLET~1\HPORGA~1\bin/module.main/favorites\ie_add_to.html ()
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Reg Error: Key error. File not found
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2_03)
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2_03)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/02/05 12:23:24 | 000,000,050 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2001/07/28 06:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O32 - AutoRun File - [2010/09/14 14:03:30 | 000,000,067 | RH– | M] () - E:\Autorun.inf – [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/02/26 04:17:50 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2011/02/26 04:03:00 | 000,000,000 | —D | C] – C:\WINDOWS\temp
[2011/02/24 09:58:44 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2011/02/24 09:58:44 | 000,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2011/02/24 09:58:44 | 000,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2011/02/24 09:58:44 | 000,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2011/02/24 09:58:37 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2011/02/23 14:15:53 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Xfire
[2011/02/22 10:47:37 | 000,000,000 | —D | C] – C:\Qoobox
[2011/02/22 07:27:16 | 000,953,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mfc40u.dll
[2011/02/22 07:27:15 | 000,974,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mfc42.dll
[2011/02/22 07:27:06 | 000,357,248 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\srv.sys
[2011/02/22 07:26:48 | 000,617,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\comctl32.dll
[2011/02/22 07:26:09 | 000,040,960 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ndproxy.sys
[2011/02/22 07:23:43 | 000,180,224 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\scrobj.dll
[2011/02/22 07:23:43 | 000,172,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\scrrun.dll
[2011/02/22 07:23:43 | 000,155,648 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wscript.exe
[2011/02/22 07:23:43 | 000,135,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wshom.ocx
[2011/02/22 07:23:43 | 000,090,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wshext.dll
[2011/02/22 07:23:42 | 000,135,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cscript.exe
[2011/02/22 07:23:20 | 000,045,568 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wab.exe
[2011/02/22 07:23:16 | 000,590,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rpcrt4.dll
[2011/02/22 05:25:23 | 000,048,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iyuv_32.dll
[2011/02/22 05:25:13 | 000,265,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\http.sys
[2011/02/22 05:24:16 | 000,272,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\bthport.sys
[2011/02/22 05:23:54 | 000,471,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\aclayers.dll
[2011/02/22 05:23:29 | 000,119,808 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\t2embed.dll
[2011/02/22 05:23:29 | 000,081,920 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fontsub.dll
[2011/02/22 05:23:07 | 000,017,920 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msyuv.dll
[2011/02/22 05:22:57 | 000,203,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rmcast.sys
[2011/02/22 05:22:20 | 000,337,408 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\netapi32.dll
[2011/02/22 05:21:26 | 000,136,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msv1_0.dll
[2011/02/22 05:17:33 | 000,000,000 | —D | C] – C:\WINDOWS\Prefetch
[2011/02/22 05:07:15 | 000,000,000 | —D | C] – C:\WINDOWS\System32\scripting
[2011/02/22 05:07:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\bits
[2011/02/21 13:17:24 | 000,274,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mucltui.dll
[2011/02/21 13:17:24 | 000,016,736 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mucltui.dll.mui
[2011/02/21 07:18:24 | 000,222,080 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\MpSigStub.exe
[2011/02/21 07:16:24 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Security Client
[2011/02/20 11:57:24 | 000,602,624 | —- | C] (OldTimer Tools) – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop\OTL.exe
[2011/02/20 10:42:04 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Malwarebytes
[2011/02/20 10:41:49 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/02/20 10:41:48 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/02/20 10:41:48 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/02/20 10:41:45 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/02/20 10:41:45 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/02/20 10:40:30 | 007,734,208 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop\mbam-setup-1.50.1.1100.exe
[2011/02/19 21:59:59 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Sammsoft
[2011/02/19 21:09:57 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Local Settings\Application Data\OpenCandy
[2011/02/19 21:09:54 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Xfire
[2011/02/19 21:09:53 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Xfire
[2011/02/19 21:09:52 | 000,000,000 | —D | C] – C:\Program Files\Xfire
[2011/02/19 16:07:18 | 000,000,000 | —D | C] – C:\9ed20b7a62c8e74031b5087805ec2c
[2011/02/15 15:55:17 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\MysteryChronicles
[2011/02/15 15:54:23 | 000,000,000 | —D | C] – C:\Program Files\Mystery Chronicles - Murder Among Friends
[2011/02/15 15:54:23 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Mystery Chronicles - Murder Among Friends
[2011/02/14 11:35:29 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Local Settings\Application Data\Identities
[2011/02/13 12:09:09 | 000,000,000 | —D | C] – C:\Program Files\Mystery Case Files - Dire Grove
[2011/02/13 12:09:09 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Mystery Case Files - Dire Grove
[2011/02/12 14:59:53 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\ERS G-Studio
[2011/02/12 14:57:57 | 000,000,000 | —D | C] – C:\Program Files\Dark Tales - Edgar Allan Poe`s Murders in the Rue Morgue
[2011/02/12 14:57:57 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Dark Tales - Edgar Allan Poe`s Murders in the Rue Morgue
[2011/02/12 14:50:30 | 000,000,000 | —D | C] – C:\Program Files\Midnight Mysteries - The Edgar Allan Poe Conspiracy
[2011/02/12 14:50:30 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Midnight Mysteries - The Edgar Allan Poe Conspiracy
[2011/02/12 09:22:22 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Friday's games
[2011/02/12 09:20:58 | 000,000,000 | —D | C] – C:\Program Files\Stray Souls - Dollhouse Story Collector's Edition
[2011/02/12 09:20:58 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Stray Souls - Dollhouse Story Collector's Edition
[2011/02/12 09:11:08 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Big Fish Games
[2011/02/11 21:16:55 | 000,000,000 | -HSD | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\IECompatCache
[2011/02/11 21:16:29 | 000,000,000 | -HSD | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\PrivacIE
[2011/02/11 21:11:27 | 000,000,000 | -HSD | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\IETldCache
[2011/02/11 19:53:47 | 000,000,000 | —D | C] – C:\WINDOWS\System32\en-US
[2011/02/11 19:50:54 | 000,602,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfeeds.dll
[2011/02/11 19:50:54 | 000,055,296 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfeedsbs.dll
[2011/02/11 19:50:53 | 000,743,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iedvtool.dll
[2011/02/11 19:50:52 | 001,991,680 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iertutil.dll
[2011/02/11 19:50:50 | 011,080,704 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieframe.dll
[2011/02/11 12:48:45 | 000,005,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ptpusb.dll
[2011/02/11 12:48:43 | 000,159,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ptpusd.dll
[2011/02/06 06:24:31 | 002,148,864 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntkrnlmp.exe
[2011/02/06 06:24:29 | 002,069,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntkrnlpa.exe
[2011/02/06 06:24:29 | 002,027,008 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntkrpamp.exe
[2011/02/06 06:24:21 | 000,455,680 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mrxsmb.sys
[2011/02/06 06:24:14 | 000,744,448 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\helpsvc.exe
[2011/02/06 06:15:57 | 000,276,992 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wmphoto.dll
[2011/02/06 06:15:55 | 000,069,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wlanapi.dll
[2011/02/06 06:15:53 | 000,712,704 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\windowscodecs.dll
[2011/02/06 06:15:53 | 000,346,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\windowscodecsext.dll
[2011/02/06 06:15:51 | 000,025,471 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\watv10nt.sys
[2011/02/06 06:15:51 | 000,022,271 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\watv06nt.sys
[2011/02/06 06:15:51 | 000,011,935 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\wadv11nt.sys
[2011/02/06 06:15:51 | 000,011,871 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\wadv09nt.sys
[2011/02/06 06:15:50 | 000,011,807 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\wadv07nt.sys
[2011/02/06 06:15:50 | 000,011,295 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\wadv08nt.sys
[2011/02/06 06:15:49 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\vidcap.ax
[2011/02/06 06:15:49 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\verclsid.exe
[2011/02/06 06:15:49 | 000,011,325 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\vchnt5.dll
[2011/02/06 06:15:44 | 000,053,248 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\tsgqec.dll
[2011/02/06 06:15:37 | 000,020,992 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\spupdwxp.exe
[2011/02/06 06:15:36 | 000,007,680 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\spdwnwxp.exe
[2011/02/06 06:15:29 | 000,404,990 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\slntamr.sys
[2011/02/06 06:15:29 | 000,286,792 | —- | C] (Smart Link) – C:\WINDOWS\System32\slextspk.dll
[2011/02/06 06:15:29 | 000,188,508 | —- | C] (Smart Link) – C:\WINDOWS\System32\slgen.dll
[2011/02/06 06:15:29 | 000,129,535 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\slnt7554.sys
[2011/02/06 06:15:29 | 000,095,424 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\slnthal.sys
[2011/02/06 06:15:29 | 000,073,832 | —- | C] (Smart Link) – C:\WINDOWS\System32\slcoinst.dll
[2011/02/06 06:15:29 | 000,073,796 | —- | C] (Smart Link) – C:\WINDOWS\System32\slserv.exe
[2011/02/06 06:15:29 | 000,032,866 | —- | C] (Smart Link) – C:\WINDOWS\System32\slrundll.exe
[2011/02/06 06:15:29 | 000,013,240 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\slwdmsup.sys
[2011/02/06 06:15:29 | 000,005,888 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\smbali.sys
[2011/02/06 06:15:28 | 000,040,960 | —- | C] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\drivers\sisagp.sys
[2011/02/06 06:15:28 | 000,003,901 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\siint5.dll
[2011/02/06 06:15:25 | 000,032,768 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\setupn.exe
[2011/02/06 06:15:22 | 000,397,056 | —- | C] (S3 Graphics, Inc.) – C:\WINDOWS\System32\s3gnb.dll
[2011/02/06 06:15:22 | 000,166,912 | —- | C] (S3 Graphics, Inc.) – C:\WINDOWS\System32\drivers\s3gnbm.sys
[2011/02/06 06:15:21 | 000,030,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\rndismpx.sys
[2011/02/06 06:15:20 | 000,290,304 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\rhttpaa.dll
[2011/02/06 06:15:20 | 000,013,776 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\recagent.sys
[2011/02/06 06:15:19 | 000,061,952 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\rasqec.dll
[2011/02/06 06:15:17 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\qutil.dll
[2011/02/06 06:15:16 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\qagent.dll
[2011/02/06 06:15:16 | 000,062,464 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\qcliprov.dll
[2011/02/06 06:15:15 | 000,412,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\photometadatahandler.dll
[2011/02/06 06:15:12 | 000,144,384 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\onex.dll
[2011/02/06 06:15:06 | 000,180,360 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\ntmtlfax.sys
[2011/02/06 06:15:00 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\napstat.exe
[2011/02/06 06:14:59 | 001,737,856 | —- | C] (Matrox Graphics Inc.) – C:\WINDOWS\System32\mtxparhd.dll
[2011/02/06 06:14:59 | 000,452,736 | —- | C] (Matrox Graphics Inc.) – C:\WINDOWS\System32\drivers\mtxparhm.sys
[2011/02/06 06:14:59 | 000,193,024 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\napmontr.dll
[2011/02/06 06:14:59 | 000,030,208 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\napipsec.dll
[2011/02/06 06:14:59 | 000,012,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\mutohpen.sys
[2011/02/06 06:14:58 | 001,309,184 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\mtlstrm.sys
[2011/02/06 06:14:58 | 000,126,686 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\mtlmnt5.sys
[2011/02/06 06:14:58 | 000,079,872 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msxml6r.dll
[2011/02/06 06:14:58 | 000,079,872 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msxml6r.dll
[2011/02/06 06:14:57 | 001,372,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msxml6.dll
[2011/02/06 06:14:55 | 000,155,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mssha.dll
[2011/02/06 06:14:55 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msshavmsg.dll
[2011/02/06 06:14:42 | 000,397,312 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mmcex.dll
[2011/02/06 06:14:42 | 000,106,496 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mmcfxcommon.dll
[2011/02/06 06:14:42 | 000,033,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mmcperf.exe
[2011/02/06 06:14:41 | 000,184,320 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\microsoft.managementconsole.dll
[2011/02/06 06:14:39 | 000,086,016 | —- | C] (Conexant) – C:\WINDOWS\System32\mdmxsdk.dll
[2011/02/06 06:14:36 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\l2gpstore.dll
[2011/02/06 06:14:35 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdpash.dll
[2011/02/06 06:14:35 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdnepr.dll
[2011/02/06 06:14:34 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdiultn.dll
[2011/02/06 06:14:34 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdbhc.dll
[2011/02/06 06:14:30 | 000,081,920 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ieencode.dll
[2011/02/06 06:14:25 | 000,032,285 | —- | C] (Conexant Systems, Inc.) – C:\WINDOWS\System32\hsfcisp2.dll
[2011/02/06 06:14:18 | 000,020,992 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\faxpatch.exe
[2011/02/06 06:14:16 | 000,184,832 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eapp3hst.dll
[2011/02/06 06:14:16 | 000,180,224 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eapphost.dll
[2011/02/06 06:14:16 | 000,126,976 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eappcfg.dll
[2011/02/06 06:14:16 | 000,094,208 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eappgnui.dll
[2011/02/06 06:14:16 | 000,059,392 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eapqec.dll
[2011/02/06 06:14:16 | 000,040,960 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eappprxy.dll
[2011/02/06 06:14:15 | 000,030,720 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eapolqec.dll
[2011/02/06 06:14:12 | 000,650,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3ui.dll
[2011/02/06 06:14:12 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3cfg.dll
[2011/02/06 06:14:12 | 000,056,320 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3msm.dll
[2011/02/06 06:14:12 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3gpclnt.dll
[2011/02/06 06:14:12 | 000,026,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3api.dll
[2011/02/06 06:14:12 | 000,009,216 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3dlg.dll
[2011/02/06 06:14:10 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dhcpqec.dll
[2011/02/06 06:14:10 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dimsroam.dll
[2011/02/06 06:14:01 | 000,015,423 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\ch7xxnt5.dll
[2011/02/06 06:14:00 | 000,036,480 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\bthprint.sys
[2011/02/06 06:13:59 | 000,233,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\azroles.dll
[2011/02/06 06:13:59 | 000,007,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\bitsprx4.dll
[2011/02/06 06:13:58 | 000,025,471 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\atv04nt5.dll
[2011/02/06 06:13:58 | 000,021,183 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\atv01nt5.dll
[2011/02/06 06:13:58 | 000,017,279 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\atv10nt5.dll
[2011/02/06 06:13:58 | 000,014,143 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\atv06nt5.dll
[2011/02/06 06:13:58 | 000,011,359 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\atv02nt5.dll
[2011/02/06 06:13:57 | 000,516,768 | —- | C] (ATI Technologies Inc. ) – C:\WINDOWS\System32\ativvaxx.dll
[2011/02/06 06:13:57 | 000,104,960 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinrvxx.sys
[2011/02/06 06:13:57 | 000,073,216 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atintuxx.sys
[2011/02/06 06:13:57 | 000,063,488 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinxsxx.sys
[2011/02/06 06:13:57 | 000,052,224 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinraxx.sys
[2011/02/06 06:13:57 | 000,032,768 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\ativtmxx.dll
[2011/02/06 06:13:57 | 000,031,744 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinxbxx.sys
[2011/02/06 06:13:57 | 000,028,672 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinsnxx.sys
[2011/02/06 06:13:57 | 000,023,040 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\ativmvxx.ax
[2011/02/06 06:13:57 | 000,014,336 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinpdxx.sys
[2011/02/06 06:13:57 | 000,013,824 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinttxx.sys
[2011/02/06 06:13:57 | 000,013,824 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinmdxx.sys
[2011/02/06 06:13:57 | 000,009,728 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\ativdaxx.ax
[2011/02/06 06:13:56 | 001,888,992 | —- | C] (ATI Technologies Inc. ) – C:\WINDOWS\System32\ati3duag.dll
[2011/02/06 06:13:56 | 000,057,856 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinbtxx.sys
[2011/02/06 06:13:55 | 000,870,784 | —- | C] (ATI Technologies Inc. ) – C:\WINDOWS\System32\ati3d1ag.dll
[2011/02/06 06:13:55 | 000,701,440 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati2mtag.sys
[2011/02/06 06:13:55 | 000,377,984 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\ati2dvaa.dll
[2011/02/06 06:13:55 | 000,327,040 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati2mtaa.sys
[2011/02/06 06:13:55 | 000,229,376 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\ati2cqag.dll
[2011/02/06 06:13:55 | 000,201,728 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\ati2dvag.dll
[2011/02/06 06:13:55 | 000,034,735 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1xsxx.sys
[2011/02/06 06:13:54 | 000,063,663 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1rvxx.sys
[2011/02/06 06:13:54 | 000,056,623 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1btxx.sys
[2011/02/06 06:13:54 | 000,036,463 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1tuxx.sys
[2011/02/06 06:13:54 | 000,030,671 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1raxx.sys
[2011/02/06 06:13:54 | 000,029,455 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1xbxx.sys
[2011/02/06 06:13:54 | 000,026,367 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1snxx.sys
[2011/02/06 06:13:54 | 000,021,343 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1ttxx.sys
[2011/02/06 06:13:54 | 000,012,047 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1pdxx.sys
[2011/02/06 06:13:54 | 000,011,615 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1mdxx.sys
[2011/02/06 06:13:51 | 000,043,008 | —- | C] (Advanced Micro Devices, Inc.) – C:\WINDOWS\System32\drivers\amdagp.sys
[2011/02/06 06:13:47 | 000,003,775 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv11nt5.dll
[2011/02/06 06:13:47 | 000,003,711 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv09nt5.dll
[2011/02/06 06:13:47 | 000,003,647 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv07nt5.dll
[2011/02/06 06:13:47 | 000,003,135 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv08nt5.dll
[2011/02/06 06:13:46 | 000,004,255 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv01nt5.dll
[2011/02/06 06:13:46 | 000,003,967 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv02nt5.dll
[2011/02/06 06:13:46 | 000,003,615 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv05nt5.dll
[2011/02/06 06:13:40 | 000,136,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\aaclient.dll
[2011/02/06 06:08:21 | 000,008,704 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\tsbyuv.dll
[2011/02/05 22:09:26 | 000,026,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\spupdsvc.exe
[2011/02/05 22:09:26 | 000,000,000 | —D | C] – C:\WINDOWS\System32\PreInstall
[2011/02/05 18:33:09 | 000,000,000 | —D | C] – C:\Program Files\Mystery Case Files - 13th Skull
[2011/02/05 18:33:09 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Mystery Case Files - 13th Skull
[2011/02/05 16:51:32 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Big Fish Games
[2011/02/05 16:51:21 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\TEMP
[2011/02/05 16:38:09 | 000,000,000 | —D | C] – C:\Program Files\bfgclient
[2011/02/05 16:37:22 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\BigFishGamesCache
[2011/02/05 13:04:47 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\My Documents\My eBooks
[2011/02/05 12:35:41 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Adobe
[2011/02/05 12:30:36 | 000,000,000 | -HSD | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\UserData
[2011/02/05 12:30:00 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Macromedia
[2011/02/05 12:28:09 | 000,689,152 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xpsp3res.dll
[2011/02/05 12:28:06 | 000,000,000 | RHSD | C] – C:\cmdcons
[2011/02/05 12:27:45 | 000,000,000 | —D | C] – C:\WINDOWS\setupupd
[2011/02/05 12:27:36 | 000,000,000 | RH-D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Recent
[2011/02/05 12:25:19 | 000,000,000 | –SD | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Microsoft
[2011/02/05 12:25:19 | 000,000,000 | RH-D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\SendTo
[2011/02/05 12:25:19 | 000,000,000 | RH-D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data
[2011/02/05 12:25:19 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\Startup
[2011/02/05 12:25:19 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu
[2011/02/05 12:25:19 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\My Documents\My Videos
[2011/02/05 12:25:19 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\My Documents\My Pictures
[2011/02/05 12:25:19 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\My Documents\My Music
[2011/02/05 12:25:19 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\My Documents
[2011/02/05 12:25:19 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Favorites
[2011/02/05 12:25:19 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\Accessories
[2011/02/05 12:25:19 | 000,000,000 | -HSD | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Cookies
[2011/02/05 12:25:19 | 000,000,000 | -H-D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Templates
[2011/02/05 12:25:19 | 000,000,000 | -H-D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\PrintHood
[2011/02/05 12:25:19 | 000,000,000 | -H-D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\NetHood
[2011/02/05 12:25:19 | 000,000,000 | -H-D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Local Settings
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\WINDOWS
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\WeatherBug
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Symantec
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Sun
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\SpySubtract Spyware Manager
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\SpamSubtract Spam Manager
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Sonic
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\SampleView
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Real
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\Quicken
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\PC Help & Tools
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\Online Services
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Local Settings\Application Data\Microsoft
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Identities
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\Games
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Local Settings\Application Data\ApplicationHistory
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Local Settings\Application Data\Apple Computer
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Apple Computer
[2011/02/05 12:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Local Settings\Application Data\{7148F0A6-6813-11D6-A77B-00B0D0142030}
[2011/02/05 12:23:00 | 000,010,368 | —- | C] (Padus, Inc.) – C:\WINDOWS\System32\drivers\pfc.sys
[2011/02/05 12:22:59 | 000,021,060 | —- | C] (InterVideo, Inc.) – C:\WINDOWS\System32\drivers\iviaspi.sys
[2011/02/05 12:22:44 | 000,061,440 | —- | C] (InstallShield Software Corporation) – C:\WINDOWS\System32\ISUSPM.cpl
[2011/02/05 12:21:59 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office (60 Day Trial)
[2011/02/05 12:20:10 | 000,000,000 | —D | C] – C:\Program Files\SiS VGA Utilities V3.63
[2011/02/05 12:17:57 | 000,000,000 | —D | C] – C:\WINDOWS\System32\SoftwareDistribution
[2011/02/05 11:11:40 | 000,907,456 | —- | C] (Conexant) – C:\WINDOWS\System32\drivers\HCF_MSFT.sys
[2011/02/05 11:11:38 | 000,006,400 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\enum1394.sys
[2011/02/05 11:11:37 | 000,053,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\1394bus.sys
[2011/02/05 11:11:23 | 000,184,320 | —- | C] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\SiSApCom.dll
[2011/02/05 11:11:23 | 000,110,592 | —- | C] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\TVMode.dll
[2011/02/05 11:11:08 | 000,331,776 | —- | C] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\sistray.exe
[2011/02/05 11:11:08 | 000,000,000 | —D | C] – C:\WINDOWS\System32\trayres
[2011/02/05 11:11:04 | 000,049,152 | —- | C] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\SiSPower.dll
[2011/02/05 10:47:05 | 000,000,000 | RHSD | C] – C:\WINDOWS\System32\dllcache
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/02/26 05:11:00 | 000,000,428 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{2B9ABC23-7E4A-4EF3-ACD7-A7C28B953E38}.job
[2011/02/26 05:01:00 | 000,000,240 | —- | M] () – C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2011/02/26 04:16:00 | 000,000,890 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/02/26 04:01:06 | 000,000,424 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/02/26 03:55:54 | 000,000,249 | —- | M] () – C:\WINDOWS\System\hpsysdrv.dat
[2011/02/26 03:55:40 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2011/02/26 03:55:28 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/02/26 03:55:22 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/02/26 03:55:21 | 1475,923,968 | -HS- | M] () – C:\hiberfil.sys
[2011/02/26 03:44:49 | 004,274,990 | R— | M] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop\ComboFix.exe
[2011/02/26 03:42:04 | 000,000,428 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{0C07C01B-5CD2-4771-9302-946C711BE426}.job
[2011/02/25 09:07:05 | 000,014,340 | —- | M] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop\JONATHAN.htm
[2011/02/25 09:06:28 | 000,018,924 | —- | M] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop\popups.zip
[2011/02/22 12:05:53 | 000,174,672 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/02/22 12:01:46 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/02/22 11:03:22 | 000,022,005 | —- | M] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop\schrauber.htm
[2011/02/22 07:51:56 | 000,382,022 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/02/22 07:51:56 | 000,053,640 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/02/22 05:18:27 | 000,316,640 | —- | M] () – C:\WINDOWS\WMSysPr9.prx
[2011/02/22 05:18:08 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/02/22 05:04:11 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/02/21 07:16:53 | 000,001,945 | —- | M] () – C:\WINDOWS\epplauncher.mif
[2011/02/20 12:12:20 | 000,133,632 | —- | M] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop\RKUnhookerLE.EXE
[2011/02/20 11:57:38 | 000,602,624 | —- | M] (OldTimer Tools) – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop\OTL.exe
[2011/02/20 10:41:49 | 000,000,795 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/02/20 10:41:28 | 007,734,208 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop\mbam-setup-1.50.1.1100.exe
[2011/02/19 21:10:34 | 000,000,967 | —- | M] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\Startup\Advanced Registry Optimizer.lnk
[2011/02/19 21:09:53 | 000,000,667 | —- | M] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Microsoft\Internet Explorer\Quick Launch\Xfire.lnk
[2011/02/19 21:09:53 | 000,000,649 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Xfire.lnk
[2011/02/15 15:54:34 | 000,001,884 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Play Mystery Chronicles - Murder Among Friends.lnk
[2011/02/13 12:14:18 | 000,001,784 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Play Mystery Case Files - Dire Grove.lnk
[2011/02/12 14:59:06 | 000,002,035 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Play Dark Tales - Edgar Allan Poe`s Murders in the Rue Morgue.lnk
[2011/02/12 14:51:05 | 000,002,034 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Play Midnight Mysteries - The Edgar Allan Poe Conspiracy.lnk
[2011/02/12 09:21:45 | 000,001,942 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Play Stray Souls - Dollhouse Story Collector's Edition.lnk
[2011/02/12 09:11:02 | 000,001,417 | —- | M] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Microsoft\Internet Explorer\Quick Launch\Game Manager.lnk
[2011/02/12 09:11:02 | 000,001,399 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Game Manager.lnk
[2011/02/11 21:11:30 | 000,000,826 | —- | M] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/02/11 12:50:45 | 000,000,815 | —- | M] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2011/02/11 12:50:20 | 000,006,656 | —- | M] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/02/05 18:34:55 | 000,001,784 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Play Mystery Case Files - 13th Skull.lnk
[2011/02/05 12:30:00 | 000,000,278 | —- | M] () – C:\WINDOWS\tasks\Easy Internet Sign-up.job
[2011/02/05 12:29:53 | 000,000,745 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Easy Internet Sign-up.lnk
[2011/02/05 12:29:36 | 000,001,870 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Updates from HP.lnk
[2011/02/05 12:28:32 | 000,000,283 | RHS- | M] () – C:\boot.ini
[2011/02/05 12:27:29 | 000,000,603 | —- | M] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop\Register with HP.url
[2011/02/05 12:26:08 | 000,001,850 | RHS- | M] () – C:\WINDOWS\System32\drivers\103C_HP_CPC_PP164AA-ABA a810n_YC_0Pavi_QMXM502_E51NAheBLU3_47_ISalmon_SASUSTek Computer INC._V1.04_B3.04_T041029_WXH2_L409_M1408_J160_7AMD_8Athlon 64_92.41_#050223_N10390900_Z14F11036_G10396330.MRK
[2011/02/05 12:23:44 | 000,000,993 | —- | M] () – C:\WINDOWS\System32\$winnt$.inf
[2011/02/05 12:23:24 | 000,000,050 | —- | M] () – C:\AUTOEXEC.BAT
[2011/02/05 12:20:40 | 000,190,524 | —- | M] () – C:\WINDOWS\System32\VGAunistlog.ini
[2011/02/05 12:18:44 | 000,000,213 | RHS- | M] () – C:\BOOT.BAK
[2011/02/02 17:11:20 | 000,222,080 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MpSigStub.exe
[2011/02/01 20:19:05 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/02/25 09:07:04 | 000,014,340 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop\JONATHAN.htm
[2011/02/25 09:06:26 | 000,018,924 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop\popups.zip
[2011/02/24 09:58:44 | 000,256,512 | —- | C] () – C:\WINDOWS\PEV.exe
[2011/02/24 09:58:44 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2011/02/24 09:58:44 | 000,089,088 | —- | C] () – C:\WINDOWS\MBR.exe
[2011/02/24 09:58:44 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2011/02/24 09:58:44 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2011/02/24 09:57:03 | 004,274,990 | R— | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop\ComboFix.exe
[2011/02/22 11:03:19 | 000,022,005 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop\schrauber.htm
[2011/02/21 07:21:46 | 000,000,424 | -H– | C] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/02/21 07:16:33 | 000,001,691 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Security Essentials.lnk
[2011/02/20 12:12:17 | 000,133,632 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop\RKUnhookerLE.EXE
[2011/02/20 10:41:49 | 000,000,795 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/02/19 21:10:33 | 000,000,967 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\Startup\Advanced Registry Optimizer.lnk
[2011/02/19 21:09:53 | 000,000,667 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Microsoft\Internet Explorer\Quick Launch\Xfire.lnk
[2011/02/19 21:09:53 | 000,000,649 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Xfire.lnk
[2011/02/19 16:18:39 | 000,001,945 | —- | C] () – C:\WINDOWS\epplauncher.mif
[2011/02/19 13:40:48 | 000,000,075 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\LuResult.txt
[2011/02/15 15:54:34 | 000,001,884 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Play Mystery Chronicles - Murder Among Friends.lnk
[2011/02/13 12:14:18 | 000,001,784 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Play Mystery Case Files - Dire Grove.lnk
[2011/02/12 14:59:06 | 000,002,035 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Play Dark Tales - Edgar Allan Poe`s Murders in the Rue Morgue.lnk
[2011/02/12 14:51:05 | 000,002,034 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Play Midnight Mysteries - The Edgar Allan Poe Conspiracy.lnk
[2011/02/12 09:21:45 | 000,001,942 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Play Stray Souls - Dollhouse Story Collector's Edition.lnk
[2011/02/11 21:16:54 | 000,000,428 | -H– | C] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{0C07C01B-5CD2-4771-9302-946C711BE426}.job
[2011/02/11 12:50:45 | 000,000,815 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2011/02/11 12:50:05 | 000,006,656 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/02/06 06:15:02 | 000,067,866 | —- | C] () – C:\WINDOWS\System32\drivers\netwlan5.img
[2011/02/06 06:14:28 | 000,001,261 | —- | C] () – C:\WINDOWS\System32\pid.inf
[2011/02/06 06:14:07 | 000,129,045 | —- | C] () – C:\WINDOWS\System32\drivers\cxthsfs2.cty
[2011/02/06 06:13:57 | 000,064,352 | —- | C] () – C:\WINDOWS\System32\drivers\ativmc20.cod
[2011/02/05 18:34:55 | 000,001,784 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Play Mystery Case Files - 13th Skull.lnk
[2011/02/05 16:38:11 | 000,001,595 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Game Manager.lnk
[2011/02/05 16:38:11 | 000,001,417 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Microsoft\Internet Explorer\Quick Launch\Game Manager.lnk
[2011/02/05 16:38:11 | 000,001,399 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Game Manager.lnk
[2011/02/05 16:38:11 | 000,001,184 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\More Great Games.lnk
[2011/02/05 12:30:04 | 000,001,687 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\Startup\HP Organize.lnk
[2011/02/05 12:30:04 | 000,001,687 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Microsoft\Internet Explorer\Quick Launch\HP Organize.lnk
[2011/02/05 12:29:53 | 000,000,278 | —- | C] () – C:\WINDOWS\tasks\Easy Internet Sign-up.job
[2011/02/05 12:29:36 | 000,001,870 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Updates from HP.lnk
[2011/02/05 12:27:29 | 000,000,603 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop\Register with HP.url
[2011/02/05 12:26:05 | 000,001,850 | RHS- | C] () – C:\WINDOWS\System32\drivers\103C_HP_CPC_PP164AA-ABA a810n_YC_0Pavi_QMXM502_E51NAheBLU3_47_ISalmon_SASUSTek Computer INC._V1.04_B3.04_T041029_WXH2_L409_M1408_J160_7AMD_8Athlon 64_92.41_#050223_N10390900_Z14F11036_G10396330.MRK
[2011/02/05 12:25:59 | 1475,923,968 | -HS- | C] () – C:\hiberfil.sys
[2011/02/05 12:25:23 | 000,002,235 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop\Help and Support.lnk
[2011/02/05 12:25:23 | 000,001,632 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Microsoft\Internet Explorer\Quick Launch\iTunes.lnk
[2011/02/05 12:25:23 | 000,000,915 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Microsoft\Internet Explorer\Quick Launch\RealPlayer.lnk
[2011/02/05 12:25:23 | 000,000,826 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/02/05 12:25:23 | 000,000,742 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Microsoft\Internet Explorer\Quick Launch\QuickTime Player.lnk
[2011/02/05 12:25:23 | 000,000,128 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Local Settings\Application Data\fusioncache.dat
[2011/02/05 12:25:23 | 000,000,079 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
[2011/02/05 12:25:22 | 000,010,326 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\ml1.srt
[2011/02/05 12:25:22 | 000,010,250 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\ml2.srt
[2011/02/05 12:25:20 | 000,009,220 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\tempdiff.txt
[2011/02/05 12:25:20 | 000,001,681 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\Install Microsoft Money 2005.lnk
[2011/02/05 12:25:20 | 000,001,599 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\Remote Assistance.lnk
[2011/02/05 12:25:20 | 000,000,814 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\Internet Explorer.lnk
[2011/02/05 12:25:20 | 000,000,803 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\Windows Media Player.lnk
[2011/02/05 12:25:20 | 000,000,749 | —- | C] () – C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Start Menu\Programs\Outlook Express.lnk
[2011/02/05 12:23:37 | 000,001,943 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AOL® for Broadband.lnk
[2011/02/05 12:23:37 | 000,001,846 | —- | C] () – C:\Documents and Settings\All Users\Desktop\MSN.lnk
[2011/02/05 12:23:37 | 000,001,819 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AOL®.lnk
[2011/02/05 12:23:37 | 000,001,697 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Install Quicken New User Edition.lnk
[2011/02/05 12:23:37 | 000,001,641 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Install Game Channel.lnk
[2011/02/05 12:23:37 | 000,001,564 | —- | C] () – C:\Documents and Settings\All Users\Desktop\H&R Block.lnk
[2011/02/05 12:23:37 | 000,000,731 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Software Repair Wizard.lnk
[2011/02/05 12:23:29 | 000,000,745 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Easy Internet Sign-up.lnk
[2011/02/05 12:21:59 | 000,000,634 | —- | C] () – C:\Documents and Settings\All Users\Desktop\60 day trial - Office 2003.lnk
[2011/02/05 12:21:41 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2011/02/05 12:21:41 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2011/02/05 12:21:41 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2011/02/05 12:21:41 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2011/02/05 12:21:41 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2011/02/05 12:21:41 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2011/02/05 11:11:05 | 000,190,524 | —- | C] () – C:\WINDOWS\System32\VGAunistlog.ini
[2010/07/09 11:00:32 | 000,041,872 | —- | C] () – C:\WINDOWS\System32\xfcodec.dll
[2009/12/13 19:36:19 | 000,000,419 | —- | C] () – C:\WINDOWS\BRWMARK.INI
[2009/12/13 19:36:19 | 000,000,027 | —- | C] () – C:\WINDOWS\BRPP2KA.INI
[2009/12/13 19:19:35 | 000,103,579 | —- | C] () – C:\WINDOWS\VGAsetup.ini
[2009/12/13 17:49:45 | 000,000,225 | —- | C] () – C:\WINDOWS\Brpfx04a.ini
[2009/12/13 17:49:45 | 000,000,093 | —- | C] () – C:\WINDOWS\brpcfx.ini
[2004/10/22 13:35:32 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2004/10/21 18:21:50 | 000,014,529 | —- | C] () – C:\WINDOWS\System32\CHODDI.SYS
[2004/10/21 18:21:42 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\hpreg.dll
[2004/10/21 17:55:29 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2004/10/21 17:05:48 | 000,001,444 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2004/10/21 17:00:46 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2004/10/21 16:17:08 | 000,299,073 | —- | C] () – C:\WINDOWS\System32\PythonCOM22.dll
[2004/10/21 16:17:08 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\PyWinTypes22.dll
[2004/10/21 16:15:49 | 000,016,896 | —- | C] () – C:\WINDOWS\System32\bcbmm.dll
[2004/10/21 15:55:39 | 000,000,802 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/10/21 15:36:39 | 000,000,549 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2004/10/21 08:43:28 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2004/09/13 22:35:56 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2004/08/20 02:14:46 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\PcdrKernelModeServices.dll
[2004/08/20 02:14:46 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\ProgressTrace.dll
[2003/04/10 22:04:00 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\JAWTAccessBridge.dll
[2003/01/07 21:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI

========== Alternate Data Streams ==========

@Alternate Data Stream - 231 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:9BAC4211
@Alternate Data Stream - 217 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:71612023
@Alternate Data Stream - 176 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:561B1D2B
@Alternate Data Stream - 173 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A02025CE
@Alternate Data Stream - 131 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A5241382
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E91ADC66

< End of report >
here is extras for otl srry


OTL Extras logfile created on: 2/26/2011 5:14:00 AM - Run 2
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Documents and Settings\HP_Owner.YOUR-03667082DE.000\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 64.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 88.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 142.96 Gb Total Space | 120.68 Gb Free Space | 84.41% Space Free | Partition Type: NTFS
Drive D: | 6.07 Gb Total Space | 0.72 Gb Free Space | 11.87% Space Free | Partition Type: FAT32
Drive E: | 558.09 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: YOUR-03667082DE | User Name: HP_Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%ProgramFiles%\iTunes\iTunes.exe" = %ProgramFiles%\iTunes\iTunes.exe:*:enabled:iTunes – (Apple Computer, Inc.)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Computer, Inc.)
"C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe" = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe:*:Enabled:BackWeb for Pavilion – (Hewlett-Packard)
"C:\Program Files\Xfire\Xfire.exe" = C:\Program Files\Xfire\Xfire.exe:*:Enabled:Xfire – (Xfire Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00FC6799-866E-44A1-A60C-DCF394CF56FD}" = iTunes
"{09DA4F91-2A09-4232-AB8C-6BC740096DE3}" = Sonic Update Manager
"{0D182A5E-AEE0-42ca-BD1D-4EEB2FFA256D}" = HP Image Zone Plus 4.2.3
"{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}" = Microsoft Plus! Photo Story 2 LE
"{14589F05-C658-4594-9429-D437BA688686}" = IntelliMover Data Transfer Demo
"{1F63ED0B-EDD2-4037-B6AB-1358C624AF48}" = Scan
"{21E75254-410E-49C4-8981-2E1A2A2221F2}" = HP Diagnostic Assistant
"{267868CE-6DFF-40F7-9C58-C01119B7B117}" = Fax
"{2BBC9458-07CA-4843-848B-5C8146E5EFA8}" = CreativeProjects
"{2FCE4FC5-6930-40E7-A4F1-F862207424EF}" = InterVideo WinDVD Creator
"{34A59AC3-6C5C-4A09-A7F5-369A37176C8A}" = AiOSoftware
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3AE681E0-4E8D-453F-950A-48534D3C0724}" = Copy
"{3AEF2F6C-F1D3-47CD-BF3B-A327F1FABE58}" = PSPrinters06
"{3BD0196C-6553-460c-A0C4-90D8AE5D60D2}" = Norton Personal Firewall
"{41254D7B-EADF-4078-AE4A-BD73B300EE86}" = Unload
"{416D80BA-6F6D-4672-B7CF-F54DA2F80B44}" = Microsoft Works
"{457791C5-D702-4143-A7B2-2744BE9573F2}" = HP Software Update
"{4C04DF1B-6A39-4299-9DD1-1FA60000266E}" = HP Photosmart Cameras 4.0
"{561A9B4E-2E48-4149-B977-59C7AFF62B52}" = HPIZ423
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Sonic Express Labeler
"{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}" = Microsoft Plus! Digital Media Edition Installer
"{7148F0A8-6813-11D6-A77B-00B0D0142030}" = Java 2 Runtime Environment, SE v1.4.2_03
"{725249C3-B94C-4141-8799-0D3BA43D0812}" = CameraDrivers
"{774088D4-0777-4D78-904D-E435B318F5D2}" = Microsoft Antimalware
"{77A776C4-D10F-416D-88F0-53F2D9DCD9B3}" = Microsoft Security Client
"{8105684D-8CA6-440D-8F58-7E5FD67A499D}" = Easy Internet Sign-up
"{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" =
"{91120409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Standard Edition 2003
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD Player
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9541FED0-327F-4DF0-8B96-EF57EF622F19}" = Sonic RecordNow!
"{981FB376-8418-4EA8-BBED-9DE5AA63E7D5}" = SkinsHP1
"{9CB2512B-3EC4-43DF-8002-46BDAB5EDD1B}" = QuickProjects
"{9EEBF8D5-8712-4D1D-88F4-4CDC2D270BC3}" = PrintScreen
"{A1062847-0846-427A-92A1-BB8251A91E91}" = HP PSC & OfficeJet 4.0
"{A1DCC235-DACC-4E1F-8D11-D630634B4AEF}" = PhotoGallery
"{A2500497-FD32-493e-B8E5-28D6728DBEF5}" = Readme
"{A4EA3AB4-E78C-4286-96DF-26035507CE55}" = AiO_Scan
"{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}" = Photosmart 320,370,7400,8100,8400 Series
"{AC76BA86-0000-0000-0000-6028747ADE01}" = Adobe Acrobat - Reader 6.0.2 Update
"{AC76BA86-7AD7-1033-7B44-A00000000001}" = Adobe Reader 6.0.1
"{B103C8A7-D1CC-4B1A-BD41-883F652E097D}" = muvee autoProducer 3.5 magicMoments - HPD
"{B32C75F2-7495-4D01-9431-C11E97D66F8C}" = DocProc
"{B3D5D4E0-E965-41C4-ABFD-A7B1AD0663C2}" = Director
"{B45D9FEE-1AF4-46F3-9A83-2545F81547F5}" = CreativeProjectsTemplates
"{B56D5B09-C4FB-4EA0-8EAD-7BC3E2715A2D}" = DocumentViewer
"{BCC992E5-5C81-4066-9B55-03DC10B24D21}" = InstantShare
"{BF018D2F-C788-4AB1-AB95-1280EAB8F13E}" = TrayApp
"{C3F058C0-A21C-452D-8D99-95B1A45F417D}" = InterVideo DiscLabel
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{D0122362-6333-4DE4-93F6-A5A2F3CC101A}" = HP Organize
"{DB518BA6-CB74-4EB6-9ABD-880B6D6E1F38}" = HpSdpAppCoreApp
"{EC8673DA-F96B-497E-B2DB-BC7B029FD680}" = BufferChm
"{F419D20A-7719-4639-8E30-C073A040D878}" = HP Deskjet Preloaded Printer Drivers
"{F4F47155-5B4D-42AA-97F8-490BC52EA7F3}" = Destinations
"{F65787F3-B356-45EC-8DD0-0E6758EDBCEE}" = WebReg
"{FF26F7EA-BCEE-478C-9A1B-6B4F88717D73}" = CueTour
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"BackWeb-309731 Uninstaller" = Updates from HP
"BFGC" = Big Fish Games: Game Manager
"BFG-Dark Tales - Edgar Allan Poe`s Murders in the Rue Morgue" = Dark Tales: Edgar Allan Poe`s Murders in the Rue Morgue
"BFG-Midnight Mysteries - The Edgar Allan Poe Conspiracy" = Midnight Mysteries: The Edgar Allan Poe Conspiracy
"BFG-Mystery Case Files - 13th Skull" = Mystery Case Files ®: 13th Skull ™
"BFG-Mystery Case Files - Dire Grove" = Mystery Case Files ®: Dire Grove ™
"BFG-Mystery Chronicles - Murder Among Friends" = Mystery Chronicles: Murder Among Friends
"BFG-Stray Souls - Dollhouse Story Collector's Edition" = Stray Souls: Dollhouse Story Collector's Edition
"ESET Online Scanner" = ESET Online Scanner v3
"Help and Support Additions" = Help and Support Additions
"HP Photo & Imaging" = HP Image Zone 4.2.3
"ie8" = Windows Internet Explorer 8
"InstallShield_{00FC6799-866E-44A1-A60C-DCF394CF56FD}" = iTunes
"InstallShield_{8105684D-8CA6-440D-8F58-7E5FD67A499D}" = Easy Internet Sign-up
"LiveReg" = LiveReg (Symantec Corporation)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft Security Client" = Microsoft Security Essentials
"PS2" = PS2
"Python 2.2 combined Win32 extensions" = Python 2.2 combined Win32 extensions
"Python 2.2.1" = Python 2.2.1
"QuickTime" = QuickTime
"RealPlayer 6.0" = RealPlayer
"SiS VGA Driver" = SiS VGA Utilities
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows Media Player" = Windows Media Player 10
"Windows XP Service Pack" = Windows XP Service Pack 3
"Xfire" = Xfire (remove only)

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 2/11/2011 7:58:08 PM | Computer Name = YOUR-03667082DE | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.2180, faulting
module mshtml.dll, version 6.0.2900.3698, fault address 0x001dbae7.

Error - 2/11/2011 7:58:28 PM | Computer Name = YOUR-03667082DE | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.2180, faulting
module mshtml.dll, version 6.0.2900.3698, fault address 0x001dbae7.

Error - 2/11/2011 8:02:31 PM | Computer Name = YOUR-03667082DE | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.2180, faulting
module mshtml.dll, version 6.0.2900.3698, fault address 0x001dbae7.

Error - 2/21/2011 11:16:44 AM | Computer Name = YOUR-03667082DE | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 0x80070003, P2 moac, P3 cachereset, P4 3.0.8107.0,
P5 unspecified, P6 unspecified, P7 unspecified, P8 NIL, P9 NIL, P10 NIL.

Error - 2/21/2011 11:18:59 AM | Computer Name = YOUR-03667082DE | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 0x8050800c, P2 mpupdateengine, P3 am delta,
P4 10.3.1781.0, P5 mpsigstub.exe, P6 3.0.8107.0, P7 microsoft security essentials,
P8 NIL, P9 NIL, P10 NIL.

Error - 2/21/2011 11:33:44 AM | Computer Name = YOUR-03667082DE | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 0, P2 moaccapability, P3 3.0.8107.0, P4
0, P5 0, P6 unspecified, P7 unspecified, P8 NIL, P9 NIL, P10 NIL.

Error - 2/21/2011 2:44:20 PM | Computer Name = YOUR-03667082DE | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 2/21/2011 3:20:52 PM | Computer Name = YOUR-03667082DE | Source = Application Hang | ID = 1001
Description = Fault bucket 1180947459.

Error - 2/24/2011 2:02:08 PM | Computer Name = YOUR-03667082DE | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting
module unknown, version 0.0.0.0, fault address 0x715b9e59.

Error - 2/24/2011 2:02:39 PM | Computer Name = YOUR-03667082DE | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting
module unknown, version 0.0.0.0, fault address 0x715b9e59.

[ System Events ]
Error - 2/19/2011 8:24:15 PM | Computer Name = YOUR-03667082DE | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 2/19/2011 8:24:16 PM | Computer Name = YOUR-03667082DE | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 2/19/2011 8:24:16 PM | Computer Name = YOUR-03667082DE | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 2/19/2011 8:24:16 PM | Computer Name = YOUR-03667082DE | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 2/19/2011 8:24:16 PM | Computer Name = YOUR-03667082DE | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 2/19/2011 8:24:16 PM | Computer Name = YOUR-03667082DE | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 2/19/2011 8:24:16 PM | Computer Name = YOUR-03667082DE | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 2/19/2011 8:24:16 PM | Computer Name = YOUR-03667082DE | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 2/19/2011 8:24:16 PM | Computer Name = YOUR-03667082DE | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 2/19/2011 8:24:16 PM | Computer Name = YOUR-03667082DE | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126


< End of report >

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI