This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Spyware.IEMonster Infected Computer

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have a windows XP operating system. I can't execute anything. I tried running exeHelper and can't stop the spyware. Computer has no anti-virus software on hard drive. The computer has small business files on the hard drive. Yes, I know I'm screwed. Is there anything I can do to stop this virus?
Hi,

:welcome:

My name is NoodleTech. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
As I'm still in training at What The Tech, all my posts needs to be checked by an expert first. This may cause a delay, but I will do my best to keep it as short as possible.
Hi T.C.,

Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments,  attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scrolling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.

    ===================================================

    [external image: Posted Image]
    Download GMER Rootkit Scanner from here or here.
    • Extract the contents of the zipped file to desktop.
    • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
    • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

      [external image: Posted Image]
      Click the image to enlarge it
    • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries

DDS (Ver_10-12-12.02) - NTFSx86 Run by [removed] at 12:51:32.29 on 02/27/2011 Internet Explorer: 6.0.2900.2180 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.503.196 [GMT -5:00] AV: AntiVir Desktop *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Avira\AntiVir Desktop\sched.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\igfxpers.exe C:\Program Files\Avira\AntiVir Desktop\avgnt.exe C:\Program Files\Avira\AntiVir Desktop\avguard.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\HPZipm12.exe C:\Program Files\Avira\AntiVir Desktop\avshadow.exe C:\WINDOWS\system32\wscntfy.exe C:\HP\KBD\KBD.EXE C:\WINDOWS\SOUNDMAN.EXE C:\WINDOWS\ALCMTR.EXE C:\WINDOWS\ALCWZRD.EXE C:\WINDOWS\AGRSMMSG.exe c:\windows\system\hpsysdrv.exe C:\WINDOWS\system32\hphmon06.exe C:\Program Files\Java\jre1.5.0\bin\jusched.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\iPod\bin\iPodService.exe c:\program files\avira\antivir desktop\avcenter.exe C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\system32\dllhost.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\HP_Owner\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=pavilion&pf=desktop uSearch Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=pavilion&pf=desktop uSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=pavilion&pf=desktop uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=pavilion&pf=desktop uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=pavilion&pf=desktop mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=pavilion&pf=desktop mDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=pavilion&pf=desktop mSearch Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=pavilion&pf=desktop mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=pavilion&pf=desktop mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=pavilion&pf=desktop uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=pavilion&pf=desktop uSearchURL,(Default) = hxxp://www.google.com/keyword/%s mSearchAssistant = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=pavilion&pf=desktop BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 6.0\reader\activex\AcroIEHelper.dll TB: {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - No File TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [HPBootOp] "c:\program files\hewlett-packard\hp boot optimizer\HPBootOp.exe" /run mRun: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot mRun: [AutoTBar] c:\program files\hp\digital imaging\bin\AUTOTBAR.EXE mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\spysub~1.lnk - c:\program files\intermute\spysubtract\sslaunch.exe IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office10\EXCEL.EXE/3000 IE: {E2D4D26B-0180-43a4-B05F-462D6D54C789} - c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\iebutton\support.htm IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBC} - c:\program files\java\jre1.5.0\bin\npjpi150.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office11\REFIEBAR.DLL DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL Notify: igfxcui - igfxdev.dll SEH: {FA010552-4A27-4cb1-A1BB-3E2D697F1639} - No File ============= SERVICES / DRIVERS =============== R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2011-2-27 11608] R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2011-2-27 135336] R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2011-2-27 267432] R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2011-2-27 60936] S2 Parclass;Parclass;c:\windows\system32\drivers\parclass.sys [2011-2-27 19824] =============== Created Last 30 ================ 2011-02-27 16:56:30 ——– d—–w- c:\windows\system32\NtmsData 2011-02-27 16:56:07 ——– d—–w- c:\docume~1\hp_owner\applic~1\Avira 2011-02-27 16:55:35 14848 —-a-w- c:\windows\system32\drivers\kbdhid.sys 2011-02-27 16:55:35 14848 —-a-w- c:\windows\system32\dllcache\kbdhid.sys 2011-02-27 16:54:26 9600 —-a-w- c:\windows\system32\drivers\hidusb.sys 2011-02-27 16:54:26 9600 —-a-w- c:\windows\system32\dllcache\hidusb.sys 2011-02-27 09:25:59 166600 —-a-w- c:\windows\system32\Msmask32.ocx 2011-02-27 09:12:50 ——– d—–w- C:\Tim3 2011-02-27 08:48:01 ——– d-sh–r- C:\cmdcons 2011-02-27 08:28:54 ——– d—–w- c:\windows\system32\Lang 2011-02-27 08:28:21 221184 —-a-w- c:\windows\system32\wmpns.dll 2011-02-27 08:26:04 ——– d—–w- c:\windows\system32\RTCOM 2011-02-27 08:07:30 ——– d-sh–r- c:\windows\system32\dllcache 2011-02-27 07:32:53 60936 —-a-w- c:\windows\system32\drivers\avgntflt.sys 2011-02-27 07:32:52 ——– d—–w- c:\program files\Avira 2011-02-27 07:32:52 ——– d—–w- c:\docume~1\alluse~1\applic~1\Avira 2011-02-27 04:37:18 ——– d—–w- c:\program files\common files\Mcafee 2011-02-27 04:37:17 ——– d—–w- c:\program files\McAfee.com 2011-02-27 04:37:07 ——– d—–w- c:\program files\McAfee 2011-02-27 03:26:54 ——– d—–w- c:\windows\pss 2011-02-26 23:54:01 ——– d—–w- c:\docume~1\alluse~1\applic~1\gJlNlJm06300 ==================== Find3M ==================== ============= FINISH: 12:51:54.82 ===============

Attachments:

GMER 1.0.15.15530 - http://www.gmer.net
Rootkit scan 2011-02-27 12:58:26
Windows 5.1.2600 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-17 ST380013AS rev.3.43
Running: gmer.exe; Driver: C:\DOCUME~1\HP_Owner\LOCALS~1\Temp\awgdypod.sys


—- System - GMER 1.0.15 —-

SSDT F8A8CE16 ZwCreateKey
SSDT F8A8CE0C ZwCreateThread
SSDT F8A8CE1B ZwDeleteKey
SSDT F8A8CE25 ZwDeleteValueKey
SSDT F8A8CE2A ZwLoadKey
SSDT F8A8CDF8 ZwOpenProcess
SSDT F8A8CDFD ZwOpenThread
SSDT F8A8CE34 ZwReplaceKey
SSDT F8A8CE2F ZwRestoreKey
SSDT F8A8CE20 ZwSetValueKey

—- Kernel code sections - GMER 1.0.15 —-

? C:\DOCUME~1\HP_Owner\LOCALS~1\Temp\mbr.sys The system cannot find the file specified. !

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

—- EOF - GMER 1.0.15 —-
Hi T.C.,

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    dir:
    c:\docume~1\alluse~1\applic~1\gJlNlJm06300 /s
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

===================================================

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.

Also please describe how your computer behaves at the moment.

===================================================

I need you to run the following scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Do Not place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\Program Files\ESET\log.txt into your next reply.
SystemLook 04.09.10 by jpshortstuff Log created at 16:37 on 27/02/2011 by HP_Owner Administrator - Elevation successful No Context: dir: No Context: c:\docume~1\alluse~1\applic~1\gJlNlJm06300 /s -= EOF =-
Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 5897 Windows 5.1.2600 Service Pack 2 Internet Explorer 6.0.2900.2180 02/27/2011 04:49:32 PM mbam-log-2011-02-27 (16-49-32).txt Scan type: Quick scan Objects scanned: 146981 Time elapsed: 6 minute(s), 17 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
FROM ESET ONLINE SCANNER C:\WINDOWS\mfgdexb.dll Win32/Cimag.DU trojan D:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP2\A0002085.exe probably a variant of Win32/Agent.HVEUCPZ trojan
Hi T.C.,
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    drivers32
    c:\docume~1\alluse~1\applic~1\gJlNlJm06300\*.*
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
    %PROGRAMFILES%\PC-Doctor\Downloads\*.*
    %PROGRAMFILES%\Internet Explorer\*.tmp
    %PROGRAMFILES%\Internet Explorer\*.dat
    %USERPROFILE%\My Documents\*.exe
    %USERPROFILE%\*.exe
    %systemroot%\ADDINS\*.*
    %systemroot%\assembly\*.bak2
    %systemroot%\Config\*.*
    %systemroot%\REPAIR\*.bak2
    %systemroot%\SECURITY\Database\*.sdb /x
    %systemroot%\SYSTEM\*.bak2
    %systemroot%\Web\*.bak2
    %systemroot%\Driver Cache\*.*
    %PROGRAMFILES%\Mozilla Firefox\0*.exe
    %ProgramFiles%\Microsoft Common\*.*
    %ProgramFiles%\TinyProxy.
    %USERPROFILE%\Favorites\*.url /x
    %systemroot%\system32\*.bk
    %systemroot%\*.te
    %systemroot%\system32\system32\*.*
    %ALLUSERSPROFILE%\*.dat /x
    %systemroot%\system32\drivers\*.rmv
    dir /b "%systemroot%\system32\*.exe" | find /i " " /c
    dir /b "%systemroot%\*.exe" | find /i " " /c
    %PROGRAMFILES%\Microsoft\*.*
    %systemroot%\System32\Wbem\proquota.exe
    %PROGRAMFILES%\Mozilla Firefox\*.dat
    %USERPROFILE%\Cookies\*.txt /x
    %SystemRoot%\system32\fonts\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
OTL LOG

OTL logfile created on: 03/04/2011 10:11:28 AM - Run 1
OTL by OldTimer - Version 3.2.22.2 Folder = C:\Documents and Settings\HP_Owner\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: MM/dd/yyyy

503.00 Mb Total Physical Memory | 216.00 Mb Available Physical Memory | 43.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 75.00% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 67.55 Gb Total Space | 58.21 Gb Free Space | 86.18% Space Free | Partition Type: NTFS
Drive D: | 6.96 Gb Total Space | 1.94 Gb Free Space | 27.89% Space Free | Partition Type: FAT32

Computer Name: YOUR-F78BF48CE2 | User Name: HP_Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\HP_Owner\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH)
PRC - C:\WINDOWS\system32\EloSrvce.exe (Elo Touchsystems)
PRC - C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.)
PRC - C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
PRC - C:\WINDOWS\ALCWZRD.EXE (RealTek Semicoductor Corp.)
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\HP_Owner\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – File not found
SRV - (AppMgmt) – File not found
SRV - (AntiVirSchedulerService) – C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (AntiVirService) – C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (EloSystemService) – C:\WINDOWS\system32\EloSrvce.exe (Elo Touchsystems)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)


========== Driver Services (SafeList) ==========

DRV - (NmPar) – C:\WINDOWS\system32\drivers\NmPar.sys (Windows ® Codename Longhorn DDK provider)
DRV - (nmserial) – C:\WINDOWS\system32\drivers\NmSerial.sys (Windows ® Codename Longhorn DDK provider)
DRV - (avipbb) – C:\WINDOWS\system32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) – C:\WINDOWS\system32\drivers\avgntflt.sys (Avira GmbH)
DRV - (ssmdrv) – C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (avgio) – C:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (EloUsb) – C:\WINDOWS\system32\drivers\EloUsb.Sys (Elo Touchsystems )
DRV - (elomoufiltr) – C:\WINDOWS\system32\drivers\EloFiltr.sys (Elo Touchsystems )
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (RTL8023xp) – C:\WINDOWS\system32\drivers\Rtlnicxp.sys (Realtek Semiconductor Corporation )
DRV - (mf) – C:\WINDOWS\system32\drivers\mf.sys (Microsoft Corporation)
DRV - (rtl8139) Realtek RTL8139(A/B/C) – C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)
DRV - (AgereSoftModem) – C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (HdAudAddService) – C:\WINDOWS\system32\drivers\Hdaudio.sys (Windows ® Server 2003 DDK provider)
DRV - (fasttx2k) – C:\WINDOWS\system32\DRIVERS\fasttx2k.sys (Promise Technology, Inc.)
DRV - (Ps2) – C:\WINDOWS\system32\drivers\PS2.sys (Hewlett-Packard Company)
DRV - (Parclass) – C:\WINDOWS\System32\Drivers\Parclass.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



O1 HOSTS File: ([2004/08/04 13:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - No CLSID value found.
O4 - HKLM..\Run: [AutoTBar] File not found
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [High Definition Audio Property Page Shortcut] C:\WINDOWS\System32\Hdaudpropshortcut.exe (Windows ® Server 2003 DDK provider)
O4 - HKLM..\Run: [HPBootOp] C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\LSBurnWatcher.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ()
O9 - Extra 'Tools' menuitem : Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ()
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1298930891125 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/01/26 23:53:38 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2001/07/28 07:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O32 - Unable to obtain root file information for disk D:\
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (54619756233228288)

========== Files/Folders - Created Within 30 Days ==========

[2011/03/03 17:25:00 | 000,581,120 | —- | C] (OldTimer Tools) – C:\Documents and Settings\HP_Owner\Desktop\OTL.exe
[2011/03/01 13:46:05 | 000,000,000 | —D | C] – C:\WINDOWS\System32\NtmsData
[2011/03/01 13:29:48 | 000,520,192 | —- | C] (Elo Touchsystems) – C:\WINDOWS\System32\EloVA25p.exe
[2011/03/01 13:29:48 | 000,466,944 | —- | C] (Elo Touchsystems) – C:\WINDOWS\System32\EloVA.EXE
[2011/03/01 13:29:48 | 000,348,160 | —- | C] (Elo Touchsystems) – C:\WINDOWS\System32\EloProp.dll
[2011/03/01 13:29:48 | 000,307,200 | —- | C] (Elo Touchsystems) – C:\WINDOWS\System32\EloTouch.Cpl
[2011/03/01 13:29:48 | 000,294,912 | —- | C] (Elo Touchsystems) – C:\WINDOWS\System32\EloDkMon.exe
[2011/03/01 13:29:48 | 000,229,376 | —- | C] (Elo Touchsystems) – C:\WINDOWS\System32\EloIntf.dll
[2011/03/01 13:29:48 | 000,110,592 | —- | C] (Elo Touchsystems) – C:\WINDOWS\System32\EloTTray.exe
[2011/03/01 13:29:48 | 000,106,496 | —- | C] (Elo Touchsystems) – C:\WINDOWS\System32\EloStrings_ENG.dll
[2011/03/01 13:29:48 | 000,098,304 | —- | C] (Elo Touchsystems) – C:\WINDOWS\System32\EloRtBtn.exe
[2011/03/01 13:29:48 | 000,073,728 | —- | C] (Elo Touchsystems) – C:\WINDOWS\System32\EloSrvce.exe
[2011/03/01 13:29:48 | 000,065,536 | —- | C] (Elo Touchsystems) – C:\WINDOWS\System32\EloPubIf.dll
[2011/03/01 13:29:48 | 000,049,152 | —- | C] (Elo Touchsystems) – C:\WINDOWS\System32\EloSrvCt.exe
[2011/03/01 13:29:48 | 000,049,152 | —- | C] (Elo Touchsystems) – C:\WINDOWS\System32\EloLnchr.exe
[2011/03/01 13:29:48 | 000,049,152 | —- | C] (Elo Touchsystems) – C:\WINDOWS\System32\BeamMon.dll
[2011/03/01 13:29:48 | 000,037,376 | —- | C] (Elo Touchsystems) – C:\WINDOWS\System32\EloAlMon.exe
[2011/03/01 13:29:45 | 000,055,680 | —- | C] (Elo Touchsystems ) – C:\WINDOWS\System32\drivers\EloUsb.Sys
[2011/03/01 13:29:45 | 000,048,640 | —- | C] (Elo Touchsystems ) – C:\WINDOWS\System32\drivers\EloFiltr.sys
[2011/03/01 13:29:32 | 000,000,000 | —D | C] – C:\Program Files\EloTouchSystems
[2011/03/01 13:13:54 | 000,012,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mouhid.sys
[2011/03/01 13:07:54 | 000,000,000 | —D | C] – C:\Tim3
[2011/03/01 12:58:14 | 000,016,928 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\spmsgXP_2k3.dll
[2011/03/01 12:56:27 | 001,461,992 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\WdfCoInstaller01009.dll
[2011/03/01 12:56:27 | 000,000,000 | —D | C] – C:\Program Files\Elo TouchSystems
[2011/03/01 12:56:09 | 000,000,000 | —D | C] – C:\temp
[2011/03/01 11:49:27 | 000,039,936 | —- | C] (Windows ® 2000 DDK provider) – C:\WINDOWS\System32\pnpports.dll
[2011/03/01 11:49:26 | 000,081,920 | —- | C] (Windows ® Codename Longhorn DDK provider) – C:\WINDOWS\System32\drivers\NmPar.sys
[2011/03/01 11:49:26 | 000,070,656 | —- | C] (Windows ® Codename Longhorn DDK provider) – C:\WINDOWS\System32\drivers\NmSerial.sys
[2011/03/01 11:49:26 | 000,000,000 | —D | C] – C:\Program Files\NMSERIES
[2011/03/01 11:48:13 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner\Application Data\AdobeUM
[2011/03/01 11:48:13 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Adobe
[2011/03/01 11:48:09 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner\My Documents\My eBooks
[2011/03/01 11:48:04 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe
[2011/03/01 11:30:02 | 000,014,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kbdhid.sys
[2011/03/01 11:29:20 | 000,009,600 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hidusb.sys
[2011/03/01 02:25:10 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2011/03/01 02:24:22 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office Tools
[2011/03/01 02:14:30 | 001,089,536 | —- | C] (IDI) – C:\WINDOWS\System32\rmast.exe
[2011/03/01 02:14:30 | 001,089,536 | —- | C] (IDI) – C:\WINDOWS\rmast.exe
[2011/03/01 02:14:30 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner\Start Menu\Programs\SunTouch Plus
[2011/03/01 02:14:28 | 000,326,656 | —- | C] (Bits Per Second Ltd) – C:\WINDOWS\System32\GRAPH32.OCX
[2011/03/01 02:14:28 | 000,323,408 | —- | C] (Xceed Software Inc [removed] [removed] www.xceedsoft.com) – C:\WINDOWS\System32\XceedZip.dll
[2011/03/01 02:14:28 | 000,304,256 | —- | C] (FarPoint Technologies, Inc.) – C:\WINDOWS\System32\MEM32X30.OCX
[2011/03/01 02:14:28 | 000,165,680 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\Autmgr32.exe
[2011/03/01 02:14:28 | 000,140,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\Autprx32.dll
[2011/03/01 02:14:28 | 000,107,530 | —- | C] (Xceed Software Inc. [removed] [removed] www.xceedsoft.com) – C:\WINDOWS\System32\xcdsfx32.bin
[2011/03/01 02:14:28 | 000,061,440 | —- | C] ( Microsoft Corporation) – C:\WINDOWS\System32\Racmgr32.exe
[2011/03/01 02:14:28 | 000,032,768 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\Racreg32.dll
[2011/03/01 02:14:28 | 000,016,896 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\Odkob32.dll
[2011/03/01 02:14:25 | 000,495,616 | —- | C] (Transym Computer Services Ltd) – C:\WINDOWS\System32\TOCRRService.exe
[2011/03/01 02:14:25 | 000,086,016 | —- | C] (Transym Computer Services Ltd) – C:\WINDOWS\System32\TOCRRdll.dll
[2011/03/01 02:14:24 | 001,077,248 | —- | C] (Home) – C:\WINDOWS\System32\OCR_PreProc.dll
[2011/03/01 02:14:24 | 001,060,864 | —- | C] (Card Scanning Solutions (LLC)) – C:\WINDOWS\System32\SLib.dll
[2011/03/01 02:14:24 | 000,472,064 | —- | C] (Ursus Computing Pty. Ltd.) – C:\WINDOWS\System32\imgForm.DLL
[2011/03/01 02:14:24 | 000,069,632 | —- | C] (Card Scanning Solutions (LLC)) – C:\WINDOWS\System32\ScanW.dll
[2011/03/01 02:14:24 | 000,040,960 | —- | C] (Card Scanning Solutions (LLC)) – C:\WINDOWS\System32\ImageCtrl.dll
[2011/03/01 02:14:24 | 000,032,768 | —- | C] (Card Scanning Solutions (LLC)) – C:\WINDOWS\System32\SOCRdll.dll
[2011/03/01 02:14:23 | 000,217,088 | —- | C] (Card Scanning Solutions (LLC)) – C:\WINDOWS\System32\IdCard.dll
[2011/03/01 02:14:23 | 000,019,824 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\PARCLASS.SYS
[2011/03/01 02:14:23 | 000,019,824 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\parclass.sys
[2011/03/01 02:14:18 | 000,069,632 | —- | C] (Bits Per Second Ltd) – C:\WINDOWS\System32\Gswdll32.dll
[2011/03/01 02:14:17 | 005,550,080 | —- | C] (Seagate Software, Inc.) – C:\WINDOWS\System32\craxdrt.dll
[2011/03/01 02:14:16 | 008,880,128 | —- | C] (Seagate Software, Inc.) – C:\WINDOWS\System32\craxddt.dll
[2011/03/01 02:14:16 | 001,184,896 | —- | C] (FarPoint Technologies, Inc.) – C:\WINDOWS\System32\Edt32x30.ocx
[2011/03/01 02:14:16 | 000,664,576 | —- | C] (Seagate Software) – C:\WINDOWS\System32\crviewer.dll
[2011/03/01 02:14:16 | 000,647,872 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\Mscomct2.ocx
[2011/03/01 02:14:16 | 000,118,976 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\Msadodc.ocx
[2011/03/01 02:14:16 | 000,103,744 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\Mscomm32.ocx
[2011/03/01 02:14:16 | 000,092,160 | —- | C] (Mabry Software, Inc.) – C:\WINDOWS\System32\barcod32.ocx
[2011/03/01 02:14:16 | 000,087,040 | —- | C] (Seagate Software, Information Management Group) – C:\WINDOWS\System32\cselexpt.ocx
[2011/03/01 02:14:16 | 000,049,152 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\Mscdrun.dll
[2011/03/01 02:14:15 | 000,992,944 | —- | C] (FarPoint Technologies, Inc.) – C:\WINDOWS\System32\SPR32X30.ocx
[2011/03/01 02:14:15 | 000,974,848 | —- | C] (Three |D| Graphics, Inc.) – C:\WINDOWS\System32\Sscsdk80.dll
[2011/03/01 02:14:15 | 000,484,128 | —- | C] (Sheridan Software Systems, Inc.) – C:\WINDOWS\System32\Sscala32.ocx
[2011/03/01 02:14:15 | 000,166,600 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\Msmask32.ocx
[2011/03/01 02:14:15 | 000,076,288 | —- | C] (Sheridan Software Systems, Inc) – C:\WINDOWS\System32\Ssfm1032.dll
[2011/03/01 02:14:14 | 000,415,176 | —- | C] (Microsoft Corporation ) – C:\WINDOWS\System32\Comct332.ocx
[2011/03/01 02:14:14 | 000,300,088 | —- | C] (Sheridan Software Systems, Inc.) – C:\WINDOWS\System32\Threed20.ocx
[2011/03/01 02:14:14 | 000,262,328 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\Msdatgrd.ocx
[2011/03/01 02:14:14 | 000,258,840 | —- | C] (Sheridan Software Systems, Inc.) – C:\WINDOWS\System32\SSLstBar.ocx
[2011/03/01 02:14:14 | 000,209,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\Tabctl32.ocx
[2011/03/01 02:14:14 | 000,116,938 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\Vshelp.dll
[2011/03/01 02:14:14 | 000,093,184 | —- | C] (Microsoft Corporation) – C:\WINDOWS\Cardfile.exe
[2011/03/01 02:14:14 | 000,071,136 | —- | C] (Sheridan) – C:\WINDOWS\System32\SSPng2.dll
[2011/03/01 02:14:06 | 000,245,760 | —- | C] (Seagate Software, Inc.) – C:\WINDOWS\System32\p2ixbse.dll
[2011/03/01 02:14:06 | 000,212,992 | —- | C] (Seagate Software, Inc.) – C:\WINDOWS\System32\u2fxls.dll
[2011/03/01 02:14:06 | 000,204,800 | —- | C] (Seagate Software, Inc) – C:\WINDOWS\System32\p2soledb.dll
[2011/03/01 02:14:06 | 000,168,000 | —- | C] (Seagate Software Information Management Group, Inc.) – C:\WINDOWS\System32\p2ssql.dll
[2011/03/01 02:14:06 | 000,167,936 | —- | C] (Seagate Software, Information Management Group, Inc.) – C:\WINDOWS\System32\p2sifmx.dll
[2011/03/01 02:14:06 | 000,167,936 | —- | C] (Seagate Software Information Management Group, Inc.) – C:\WINDOWS\System32\p2sora7.dll
[2011/03/01 02:14:06 | 000,167,936 | —- | C] (Seagate Software Information Management Group, Inc.) – C:\WINDOWS\System32\p2sdb2.dll
[2011/03/01 02:14:06 | 000,159,744 | —- | C] (Seagate Software Inc.) – C:\WINDOWS\System32\p2ssyb10.dll
[2011/03/01 02:14:06 | 000,131,072 | —- | C] (Seagate Software, Inc.) – C:\WINDOWS\System32\p2lodbc.dll
[2011/03/01 02:14:06 | 000,122,880 | —- | C] (Seagate Software Information Management Group, Inc.) – C:\WINDOWS\System32\u2frtf.dll
[2011/03/01 02:14:06 | 000,106,496 | —- | C] (Seagate Software, Inc.) – C:\WINDOWS\System32\u2fwordw.dll
[2011/03/01 02:14:06 | 000,102,400 | —- | C] (Seagate Software Information Management Group, Inc.) – C:\WINDOWS\System32\u2dpost.dll
[2011/03/01 02:14:06 | 000,090,112 | —- | C] (Seagate Software, Inc.) – C:\WINDOWS\System32\u2ftext.dll
[2011/03/01 02:14:06 | 000,077,824 | —- | C] (Seagate Software, Inc) – C:\WINDOWS\System32\p2sfs.dll
[2011/03/01 02:14:06 | 000,065,536 | —- | C] (Seagate Software Information Management Group, Inc.) – C:\WINDOWS\System32\u2frdef.dll
[2011/03/01 02:14:06 | 000,057,344 | —- | C] (Seagate Software Information Management Group, Inc.) – C:\WINDOWS\System32\u2dvim.dll
[2011/03/01 02:14:06 | 000,053,248 | —- | C] (Seagate Software Information Management Group, Inc.) – C:\WINDOWS\System32\u2dnotes.dll
[2011/03/01 02:14:06 | 000,049,152 | —- | C] (Seagate Software, Inc.) – C:\WINDOWS\System32\u2fodbc.dll
[2011/03/01 02:14:06 | 000,049,152 | —- | C] (Seagate Software Information Management Group, Inc.) – C:\WINDOWS\System32\u2lfinra.dll
[2011/03/01 02:14:06 | 000,045,056 | —- | C] (Seagate Software, Inc.) – C:\WINDOWS\System32\u2fhtml.dll
[2011/03/01 02:14:06 | 000,045,056 | —- | C] (Seagate Software, Inc) – C:\WINDOWS\System32\u2lcom.dll
[2011/03/01 02:14:06 | 000,040,960 | —- | C] (Seagate Software Information Management Group, Inc.) – C:\WINDOWS\System32\u2fwks.dll
[2011/03/01 02:14:06 | 000,040,960 | —- | C] (Seagate Software Information Management Group, Inc.) – C:\WINDOWS\System32\u2dmapi.dll
[2011/03/01 02:14:06 | 000,036,864 | —- | C] (Seagate Software, Inc.) – C:\WINDOWS\System32\u2frec.dll
[2011/03/01 02:14:06 | 000,036,864 | —- | C] (Seagate Software, Inc.) – C:\WINDOWS\System32\u2fdif.dll
[2011/03/01 02:14:06 | 000,036,864 | —- | C] (Seagate Software Information Management Group, Inc.) – C:\WINDOWS\System32\u2fsepv.dll
[2011/03/01 02:14:06 | 000,028,672 | —- | C] (Seagate Software, Inc.) – C:\WINDOWS\System32\u2lexch.dll
[2011/03/01 02:14:06 | 000,028,672 | —- | C] (Seagate Software, Inc.) – C:\WINDOWS\System32\u2fcr.dll
[2011/03/01 02:14:06 | 000,028,672 | —- | C] (Seagate Software, Inc.) – C:\WINDOWS\System32\u2ddisk.dll
[2011/03/01 02:14:06 | 000,028,672 | —- | C] (Seagate Software Information Management Group, Inc.) – C:\WINDOWS\System32\u2dapp.dll
[2011/03/01 02:14:06 | 000,024,576 | —- | C] (Seagate Software, Inc.) – C:\WINDOWS\System32\u2lsamp1.dll
[2011/03/01 02:14:06 | 000,024,576 | —- | C] (Seagate Software, Inc.) – C:\WINDOWS\System32\u2ldts.dll
[2011/03/01 02:14:06 | 000,024,576 | —- | C] (Seagate Software, Inc.) – C:\WINDOWS\System32\u2l2000.dll
[2011/03/01 02:14:06 | 000,024,576 | —- | C] (Seagate Software, Inc.) – C:\WINDOWS\System32\u25dts.dll
[2011/03/01 02:14:06 | 000,024,576 | —- | C] (Seagate Software, Inc.) – C:\WINDOWS\System32\u252000.dll
[2011/03/01 02:14:05 | 000,249,856 | —- | C] (Seagate Software, Inc.) – C:\WINDOWS\System32\p2bxbse.dll
[2011/03/01 02:14:05 | 000,077,824 | —- | C] (Seagate Software Information Management Group, Inc.) – C:\WINDOWS\System32\p2bbtrv.dll
[2011/03/01 02:14:05 | 000,053,248 | —- | C] (Seagate Software Information Management Group, Inc.) – C:\WINDOWS\System32\p2ctbtrv.dll
[2011/03/01 02:14:05 | 000,024,576 | —- | C] (Seagate Software, Inc.) – C:\WINDOWS\System32\crxlat32.dll
[2011/03/01 02:14:04 | 000,663,609 | —- | C] (Seagate Software, Inc.) – C:\WINDOWS\System32\EXLATE32.dll
[2011/03/01 02:14:04 | 000,618,496 | —- | C] (Seagate Software) – C:\WINDOWS\System32\CRPAIG80.DLL
[2011/03/01 02:14:04 | 000,066,560 | —- | C] (Seagate Software, Inc.) – C:\WINDOWS\System32\CRWRAP32.DLL
[2011/03/01 02:14:02 | 000,979,456 | —- | C] (Three D Graphics) – C:\WINDOWS\System32\Pg32.dll
[2011/03/01 02:14:02 | 000,286,720 | —- | C] (Seagate Software Information Management Group, Inc.) – C:\WINDOWS\System32\P2sodbc.dll
[2011/03/01 02:14:02 | 000,163,840 | —- | C] (Seagate Software, Inc) – C:\WINDOWS\System32\P2SMON.dll
[2011/03/01 02:14:02 | 000,094,208 | —- | C] (Seagate Software Information Management Group, Inc.) – C:\WINDOWS\System32\P2bdao.dll
[2011/03/01 02:14:02 | 000,065,536 | —- | C] (Seagate Software Information Management Group, Inc.) – C:\WINDOWS\System32\P2irdao.dll
[2011/03/01 02:14:02 | 000,053,248 | —- | C] (Seagate Software Information Management Group, Inc.) – C:\WINDOWS\System32\P2ctdao.dll
[2011/03/01 02:14:02 | 000,018,944 | —- | C] ( ) – C:\WINDOWS\System32\Implode.dll
[2011/03/01 02:14:02 | 000,000,000 | —D | C] – C:\WINDOWS\CRYSTAL
[2011/03/01 02:14:01 | 004,587,577 | —- | C] (Seagate Software, Inc.) – C:\WINDOWS\System32\Crpe32.dll
[2011/03/01 02:14:01 | 000,847,324 | —- | C] (Seagate Software, Inc.) – C:\WINDOWS\System32\Crystl32.ocx
[2011/03/01 02:14:01 | 000,525,352 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dbgrid32.ocx
[2011/03/01 02:14:01 | 000,508,928 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msde.dll
[2011/03/01 02:14:01 | 000,077,824 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msbind.dll
[2011/03/01 02:14:00 | 001,046,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msjet35.dll
[2011/03/01 02:14:00 | 000,415,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msrepl35.dll
[2011/03/01 02:14:00 | 000,368,912 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\vbar332.dll
[2011/03/01 02:14:00 | 000,252,176 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\Msrd2x35.dll
[2011/03/01 02:14:00 | 000,123,664 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\MSJINT35.DLL
[2011/03/01 02:14:00 | 000,089,360 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\Vb5db.dll
[2011/03/01 02:14:00 | 000,000,000 | —D | C] – C:\SUNPLUS
[2011/03/01 02:13:58 | 000,024,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\MSJTER35.DLL
[2011/03/01 02:09:21 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sun
[2011/03/01 02:09:20 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2011/03/01 02:09:09 | 000,472,808 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2011/03/01 02:09:09 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/03/01 02:09:09 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/03/01 02:09:09 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2011/03/01 02:09:09 | 000,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2011/03/01 02:08:56 | 000,000,000 | —D | C] – C:\Program Files\Java
[2011/03/01 02:08:49 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\McAfee
[2011/03/01 02:02:39 | 000,000,000 | —D | C] – C:\WINDOWS\System32\Adobe
[2011/03/01 02:02:15 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner\Application Data\Adobe
[2011/03/01 02:00:11 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner\Application Data\Avira
[2011/03/01 01:54:48 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Avira
[2011/03/01 01:54:37 | 000,028,520 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\ssmdrv.sys
[2011/03/01 01:54:36 | 000,135,096 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\avipbb.sys
[2011/03/01 01:54:36 | 000,061,960 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\avgntflt.sys
[2011/03/01 01:54:36 | 000,045,416 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\avgntdd.sys
[2011/03/01 01:54:36 | 000,022,360 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\avgntmgr.sys
[2011/03/01 01:54:35 | 000,000,000 | —D | C] – C:\Program Files\Avira
[2011/03/01 01:54:35 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Avira
[2011/02/28 18:01:42 | 000,000,000 | —D | C] – C:\Program Files\MSXML 4.0
[2011/02/28 18:01:12 | 000,000,000 | —D | C] – C:\WINDOWS\ie8updates
[2011/02/28 18:00:46 | 000,000,000 | —D | C] – C:\WINDOWS\ServicePackFiles
[2011/02/28 17:48:31 | 000,599,040 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfeeds.dll
[2011/02/28 17:48:31 | 000,055,296 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfeedsbs.dll
[2011/02/28 17:48:30 | 000,743,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iedvtool.dll
[2011/02/28 17:48:29 | 001,985,536 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iertutil.dll
[2011/02/28 17:48:28 | 011,076,096 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieframe.dll
[2011/02/28 17:39:17 | 000,454,016 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mrxsmb.sys
[2011/02/28 17:20:23 | 002,137,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntkrnlmp.exe
[2011/02/28 17:20:22 | 002,181,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntoskrnl.exe
[2011/02/28 17:20:22 | 002,016,768 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntkrpamp.exe
[2011/02/28 17:20:21 | 002,058,368 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntkrnlpa.exe
[2011/02/28 17:19:08 | 000,351,744 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xpsp3res.dll
[2011/02/28 17:15:37 | 000,000,000 | RHSD | C] – C:\cmdcons
[2011/02/28 17:15:34 | 000,000,000 | —D | C] – C:\WINDOWS\setup.pss
[2011/02/28 17:15:16 | 000,272,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\bthport.sys
[2011/02/28 17:13:43 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2011/02/28 17:11:57 | 000,000,000 | —D | C] – C:\WINDOWS\System32\PreInstall
[2011/02/28 17:11:34 | 000,000,000 | -H-D | C] – C:\WINDOWS\$MSI31Uninstall_KB893803v2$
[2011/02/28 17:08:58 | 000,044,768 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wups2.dll
[2011/02/28 17:08:58 | 000,021,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wucltui.dll.mui
[2011/02/28 17:08:58 | 000,015,064 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wuapi.dll.mui
[2011/02/28 17:08:58 | 000,000,000 | —D | C] – C:\WINDOWS\System32\SoftwareDistribution
[2011/02/28 17:06:00 | 000,000,000 | -HSD | C] – C:\Documents and Settings\HP_Owner\PrivacIE
[2011/02/28 17:05:31 | 000,000,000 | -HSD | C] – C:\Documents and Settings\HP_Owner\IETldCache
[2011/02/28 17:01:53 | 000,000,000 | RH-D | C] – C:\Documents and Settings\HP_Owner\Recent
[2011/02/28 17:01:48 | 000,000,000 | —D | C] – C:\WINDOWS\System32\Lang
[2011/02/28 17:01:29 | 000,000,000 | —D | C] – C:\WINDOWS\WBEM
[2011/02/28 17:01:12 | 000,026,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\spupdsvc.exe
[2011/02/28 17:00:53 | 000,000,000 | –SD | C] – C:\Documents and Settings\HP_Owner\Application Data\Microsoft
[2011/02/28 17:00:53 | 000,000,000 | RH-D | C] – C:\Documents and Settings\HP_Owner\SendTo
[2011/02/28 17:00:53 | 000,000,000 | RH-D | C] – C:\Documents and Settings\HP_Owner\Application Data
[2011/02/28 17:00:53 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Owner\Start Menu\Programs\Startup
[2011/02/28 17:00:53 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Owner\Start Menu
[2011/02/28 17:00:53 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Owner\My Documents\My Videos
[2011/02/28 17:00:53 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Owner\My Documents\My Pictures
[2011/02/28 17:00:53 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Owner\My Documents\My Music
[2011/02/28 17:00:53 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Owner\My Documents
[2011/02/28 17:00:53 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Owner\Favorites
[2011/02/28 17:00:53 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Owner\Start Menu\Programs\Accessories
[2011/02/28 17:00:53 | 000,000,000 | -HSD | C] – C:\Documents and Settings\HP_Owner\Cookies
[2011/02/28 17:00:53 | 000,000,000 | -H-D | C] – C:\Documents and Settings\HP_Owner\Templates
[2011/02/28 17:00:53 | 000,000,000 | -H-D | C] – C:\Documents and Settings\HP_Owner\PrintHood
[2011/02/28 17:00:53 | 000,000,000 | -H-D | C] – C:\Documents and Settings\HP_Owner\NetHood
[2011/02/28 17:00:53 | 000,000,000 | -H-D | C] – C:\Documents and Settings\HP_Owner\Local Settings
[2011/02/28 17:00:53 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner\WINDOWS
[2011/02/28 17:00:53 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner\Application Data\Symantec
[2011/02/28 17:00:53 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner\Application Data\SampleView
[2011/02/28 17:00:53 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner\Application Data\Real
[2011/02/28 17:00:53 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner\Start Menu\Programs\Quicken
[2011/02/28 17:00:53 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner\Start Menu\Programs\Online Services
[2011/02/28 17:00:53 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Microsoft
[2011/02/28 17:00:53 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner\Application Data\InterMute
[2011/02/28 17:00:53 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner\Application Data\Identities
[2011/02/28 17:00:53 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Google
[2011/02/28 17:00:53 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner\Desktop
[2011/02/28 17:00:53 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner\Local Settings\Application Data\ApplicationHistory
[2011/02/28 17:00:53 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Apple Computer
[2011/02/28 17:00:53 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner\Application Data\Apple Computer
[2011/02/28 17:00:53 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner\Local Settings\Application Data\{3248F0A6-6813-11D6-A77B-00B0D0150000}
[2011/02/28 17:00:35 | 000,000,000 | -H-D | C] – C:\WINDOWS\ie8
[2011/02/28 17:00:35 | 000,000,000 | —D | C] – C:\WINDOWS\System32\en-US
[2011/02/28 16:59:37 | 000,000,000 | —D | C] – C:\WINDOWS\System32\RTCOM
[2011/02/28 16:58:04 | 000,000,000 | —D | C] – C:\WINDOWS\Prefetch
[2011/02/28 16:55:59 | 000,000,000 | -HSD | C] – C:\System Volume Information
[2011/02/28 16:52:49 | 000,000,000 | —D | C] – C:\WINDOWS\I386
[2011/02/28 16:47:19 | 000,000,000 | -HSD | C] – C:\Documents and Settings\HP_Owner\UserData
[2011/02/28 16:47:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner\Application Data\Macromedia
[2011/02/28 16:46:14 | 000,000,000 | RH-D | C] – C:\MSOCache
[2011/02/28 16:46:11 | 000,000,000 | R–D | C] – C:\Documents and Settings\All Users\Start Menu
[2011/02/28 16:46:11 | 000,000,000 | R–D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Games
[2011/02/28 16:46:11 | 000,000,000 | R–D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools
[2011/02/28 16:46:11 | 000,000,000 | R–D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Accessories
[2011/02/28 16:46:10 | 000,000,000 | R–D | C] – C:\Documents and Settings\All Users\Documents\My Pictures
[2011/02/28 16:46:10 | 000,000,000 | R–D | C] – C:\Documents and Settings\All Users\Documents\My Music
[2011/02/28 16:46:10 | 000,000,000 | R–D | C] – C:\Documents and Settings\All Users\Documents
[2011/02/28 16:46:09 | 000,000,000 | RH-D | C] – C:\Documents and Settings\All Users\Application Data
[2011/02/28 16:45:54 | 000,000,000 | R-SD | C] – C:\WINDOWS\assembly
[2011/02/28 16:45:50 | 000,000,000 | R–D | C] – C:\WINDOWS\Offline Web Pages
[2011/02/28 16:45:25 | 000,000,000 | RHSD | C] – C:\WINDOWS\System32\dllcache
[2011/02/28 16:40:21 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Owner\Application Data\Sun
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/03/04 10:04:25 | 000,000,248 | —- | M] () – C:\WINDOWS\System\hpsysdrv.dat
[2011/03/04 10:02:56 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/03/04 10:02:55 | 527,814,656 | -HS- | M] () – C:\hiberfil.sys
[2011/03/03 21:03:21 | 000,001,688 | —- | M] () – C:\WINDOWS\SUNTOUCH.INI
[2011/03/03 17:25:04 | 000,581,120 | —- | M] (OldTimer Tools) – C:\Documents and Settings\HP_Owner\Desktop\OTL.exe
[2011/03/01 13:33:01 | 000,381,692 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/03/01 13:33:01 | 000,053,436 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/03/01 13:18:16 | 009,261,960 | —- | M] () – C:\Documents and Settings\HP_Owner\My Documents\SW601379_TETouch_5.2.0.exe
[2011/03/01 12:58:20 | 000,000,000 | -H– | M] () – C:\WINDOWS\System32\drivers\Msft_Kernel_EloUsbG2_01009.Wdf
[2011/03/01 12:58:19 | 000,000,000 | -H– | M] () – C:\WINDOWS\System32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
[2011/03/01 11:47:50 | 000,245,760 | —- | M] () – C:\WINDOWS\System32\NmUninst.exe
[2011/03/01 11:47:50 | 000,081,920 | —- | M] (Windows ® Codename Longhorn DDK provider) – C:\WINDOWS\System32\drivers\NmPar.sys
[2011/03/01 11:47:50 | 000,070,656 | —- | M] (Windows ® Codename Longhorn DDK provider) – C:\WINDOWS\System32\drivers\NmSerial.sys
[2011/03/01 11:47:50 | 000,039,936 | —- | M] (Windows ® 2000 DDK provider) – C:\WINDOWS\System32\pnpports.dll
[2011/03/01 11:31:18 | 000,155,648 | —- | M] () – C:\WsView.mdb
[2011/03/01 11:28:22 | 000,155,568 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/03/01 02:24:53 | 000,000,376 | —- | M] () – C:\WINDOWS\ODBC.INI
[2011/03/01 02:24:23 | 000,001,741 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
[2011/03/01 02:14:46 | 000,023,392 | —- | M] () – C:\WINDOWS\System32\nscompat.tlb
[2011/03/01 02:14:46 | 000,016,832 | —- | M] () – C:\WINDOWS\System32\amcompat.tlb
[2011/03/01 02:13:58 | 000,000,061 | —- | M] () – C:\WINDOWS\CUSTDATA.INI
[2011/03/01 02:08:59 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2011/03/01 02:08:59 | 000,157,472 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/03/01 02:08:59 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/03/01 02:08:59 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2011/03/01 02:08:59 | 000,073,728 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2011/03/01 01:54:48 | 000,001,718 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Avira AntiVir Control Center.lnk
[2011/02/28 18:04:41 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/02/28 17:15:41 | 000,000,283 | RHS- | M] () – C:\boot.ini
[2011/02/28 17:13:43 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/02/28 17:05:34 | 000,000,826 | —- | M] () – C:\Documents and Settings\HP_Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/02/28 17:03:21 | 000,002,158 | —- | M] () – C:\WINDOWS\System32\ssmute.ini
[2011/02/28 17:01:52 | 000,000,603 | —- | M] () – C:\Documents and Settings\HP_Owner\Desktop\Register with HP.url
[2011/02/28 17:01:21 | 000,001,761 | RHS- | M] () – C:\WINDOWS\System32\drivers\103C_HP_CPC_PU131AV-ABA a1050y_YC_0Pavi_QMXG530_E53NAheBLU5_47_IGrouper_SASUSTeK Computer INC._V1.xx_B3.20_T050331_WXH2_L409_M504_J80_7Intel_8Pentium 4_93_#050806_N10EC8139_Z11C1048C_G80862582.MRK
[2011/02/28 17:00:04 | 000,000,993 | —- | M] () – C:\WINDOWS\System32\$winnt$.inf
[2011/02/28 16:59:48 | 000,001,635 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Easy Internet Sign-up.lnk
[2011/02/28 16:59:14 | 000,000,213 | RHS- | M] () – C:\BOOT.BAK
[2011/02/28 16:45:47 | 000,000,375 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts.ics
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/03/01 13:29:48 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\EloSetOptions.exe
[2011/03/01 13:29:48 | 000,005,548 | —- | C] () – C:\WINDOWS\EloVA25.cfg
[2011/03/01 13:18:07 | 009,261,960 | —- | C] () – C:\Documents and Settings\HP_Owner\My Documents\SW601379_TETouch_5.2.0.exe
[2011/03/01 12:58:20 | 000,000,000 | -H– | C] () – C:\WINDOWS\System32\drivers\Msft_Kernel_EloUsbG2_01009.Wdf
[2011/03/01 12:58:19 | 000,000,000 | -H– | C] () – C:\WINDOWS\System32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
[2011/03/01 11:49:26 | 000,245,760 | —- | C] () – C:\WINDOWS\System32\NmUninst.exe
[2011/03/01 02:24:23 | 000,002,489 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Word.lnk
[2011/03/01 02:24:23 | 000,001,741 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
[2011/03/01 02:24:22 | 000,002,030 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Excel.lnk
[2011/03/01 02:24:22 | 000,001,998 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft FrontPage.lnk
[2011/03/01 02:14:25 | 001,274,620 | —- | C] () – C:\WINDOWS\System32\test5.teh
[2011/03/01 02:14:25 | 001,272,394 | —- | C] () – C:\WINDOWS\System32\UsaIDs.bin
[2011/03/01 02:14:25 | 000,200,024 | —- | C] () – C:\WINDOWS\System32\test5.qnp
[2011/03/01 02:14:25 | 000,000,128 | —- | C] () – C:\WINDOWS\System32\TOCRR.ini
[2011/03/01 02:14:24 | 005,471,684 | —- | C] () – C:\WINDOWS\System32\test5.gar
[2011/03/01 02:14:24 | 000,874,404 | —- | C] () – C:\WINDOWS\System32\test5.n3s
[2011/03/01 02:14:24 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\Parser.dll
[2011/03/01 02:14:23 | 000,093,206 | —- | C] () – C:\WINDOWS\System32\EngRotDB.bin
[2011/03/01 02:14:23 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\NWKL2_32.DLL
[2011/03/01 02:14:23 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\BarCode.dll
[2011/03/01 02:14:23 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\KL2DLL32.DLL
[2011/03/01 02:14:23 | 000,012,048 | —- | C] () – C:\WINDOWS\System32\ppmon.exe
[2011/03/01 02:14:23 | 000,007,440 | —- | C] () – C:\WINDOWS\System32\PPMON.DLL
[2011/03/01 02:14:16 | 000,051,200 | —- | C] () – C:\WINDOWS\System32\dfinfo32.ocx
[2011/03/01 02:14:11 | 000,155,648 | —- | C] () – C:\WsView.mdb
[2011/03/01 02:14:06 | 000,299,008 | —- | C] () – C:\WINDOWS\System32\p2smcube.dll
[2011/03/01 02:14:06 | 000,282,624 | —- | C] () – C:\WINDOWS\System32\p2molap.dll
[2011/03/01 02:14:06 | 000,270,336 | —- | C] () – C:\WINDOWS\System32\p2solap.dll
[2011/03/01 02:14:02 | 000,748,160 | —- | C] () – C:\WINDOWS\System32\Co2c40en.dll
[2011/03/01 02:14:02 | 000,036,352 | —- | C] () – C:\WINDOWS\System32\P2bbnd.dll
[2011/03/01 02:13:58 | 000,001,688 | —- | C] () – C:\WINDOWS\SUNTOUCH.INI
[2011/03/01 02:13:58 | 000,000,061 | —- | C] () – C:\WINDOWS\CUSTDATA.INI
[2011/03/01 01:54:48 | 000,001,718 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Avira AntiVir Control Center.lnk
[2011/02/28 17:15:40 | 000,000,213 | RHS- | C] () – C:\BOOT.BAK
[2011/02/28 17:15:39 | 000,260,272 | RHS- | C] () – C:\cmldr
[2011/02/28 17:01:52 | 000,000,603 | —- | C] () – C:\Documents and Settings\HP_Owner\Desktop\Register with HP.url
[2011/02/28 17:01:17 | 000,001,761 | RHS- | C] () – C:\WINDOWS\System32\drivers\103C_HP_CPC_PU131AV-ABA a1050y_YC_0Pavi_QMXG530_E53NAheBLU5_47_IGrouper_SASUSTeK Computer INC._V1.xx_B3.20_T050331_WXH2_L409_M504_J80_7Intel_8Pentium 4_93_#050806_N10EC8139_Z11C1048C_G80862582.MRK
[2011/02/28 17:01:13 | 527,814,656 | -HS- | C] () – C:\hiberfil.sys
[2011/02/28 17:00:56 | 000,001,643 | —- | C] () – C:\Documents and Settings\HP_Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\iTunes.lnk
[2011/02/28 17:00:56 | 000,001,135 | —- | C] () – C:\Documents and Settings\HP_Owner\Desktop\Help and Support.lnk
[2011/02/28 17:00:56 | 000,000,926 | —- | C] () – C:\Documents and Settings\HP_Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\RealPlayer.lnk
[2011/02/28 17:00:56 | 000,000,826 | —- | C] () – C:\Documents and Settings\HP_Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/02/28 17:00:56 | 000,000,753 | —- | C] () – C:\Documents and Settings\HP_Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\QuickTime Player.lnk
[2011/02/28 17:00:56 | 000,000,079 | —- | C] () – C:\Documents and Settings\HP_Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
[2011/02/28 17:00:54 | 000,001,692 | —- | C] () – C:\Documents and Settings\HP_Owner\Start Menu\Programs\Install Microsoft Money 2005.lnk
[2011/02/28 17:00:54 | 000,000,814 | —- | C] () – C:\Documents and Settings\HP_Owner\Start Menu\Programs\Internet Explorer.lnk
[2011/02/28 17:00:53 | 000,001,599 | —- | C] () – C:\Documents and Settings\HP_Owner\Start Menu\Programs\Remote Assistance.lnk
[2011/02/28 17:00:53 | 000,000,803 | —- | C] () – C:\Documents and Settings\HP_Owner\Start Menu\Programs\Windows Media Player.lnk
[2011/02/28 17:00:53 | 000,000,749 | —- | C] () – C:\Documents and Settings\HP_Owner\Start Menu\Programs\Outlook Express.lnk
[2011/02/28 16:59:58 | 000,002,097 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Play WildGames.lnk
[2011/02/28 16:59:58 | 000,001,954 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AOL® for Broadband.lnk
[2011/02/28 16:59:58 | 000,001,857 | —- | C] () – C:\Documents and Settings\All Users\Desktop\MSN.lnk
[2011/02/28 16:59:58 | 000,001,830 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AOL®.lnk
[2011/02/28 16:59:58 | 000,001,708 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Install Quicken New User Edition.lnk
[2011/02/28 16:59:58 | 000,001,540 | —- | C] () – C:\Documents and Settings\All Users\Desktop\HP Extended Service Plans.lnk
[2011/02/28 16:59:58 | 000,000,908 | —- | C] () – C:\Documents and Settings\All Users\Desktop\RealPlayer.lnk
[2011/02/28 16:59:58 | 000,000,731 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Software Repair Wizard.lnk
[2011/02/28 16:59:48 | 000,001,635 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Easy Internet Sign-up.lnk
[2011/02/28 16:53:49 | 000,000,248 | —- | C] () – C:\WINDOWS\System\hpsysdrv.dat
[2005/07/28 21:52:09 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/07/28 21:22:10 | 000,118,784 | R— | C] () – C:\WINDOWS\bwUnin-6.3.2.62.exe
[2005/07/28 21:20:58 | 000,014,555 | —- | C] () – C:\WINDOWS\System32\CHODDI.SYS
[2005/07/28 21:20:51 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\hpreg.dll
[2005/07/28 21:20:30 | 000,002,158 | —- | C] () – C:\WINDOWS\System32\ssmute.ini
[2005/07/28 21:17:44 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/07/28 15:12:36 | 000,047,832 | —- | C] () – C:\WINDOWS\hpiins01.dat
[2005/07/28 15:11:17 | 000,094,364 | —- | C] () – C:\WINDOWS\HPHins03.dat
[2005/07/28 15:11:17 | 000,002,655 | —- | C] () – C:\WINDOWS\hphmdl03.dat
[2005/07/28 15:05:38 | 000,050,500 | —- | C] () – C:\WINDOWS\hpdins05.dat
[2005/07/28 15:04:19 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2005/07/28 14:59:52 | 000,156,672 | —- | C] () – C:\WINDOWS\System32\RTLCPAPI.dll
[2005/07/28 14:49:27 | 000,000,780 | —- | C] () – C:\WINDOWS\orun32.ini
[2005/07/28 14:48:19 | 000,323,584 | —- | C] () – C:\WINDOWS\System32\pythoncom22.dll
[2005/07/28 14:48:19 | 000,094,208 | —- | C] () – C:\WINDOWS\System32\pywintypes22.dll
[2005/07/28 14:47:58 | 000,016,896 | —- | C] () – C:\WINDOWS\System32\bcbmm.dll
[2005/04/01 13:34:56 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2005/01/28 04:12:02 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2005/01/26 23:58:08 | 000,381,692 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2005/01/26 23:58:08 | 000,053,436 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2005/01/26 23:56:22 | 000,155,568 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2005/01/26 23:53:16 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2005/01/26 23:51:30 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2004/08/04 13:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/04 07:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/04 07:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/04 07:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/04 07:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/04 07:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/04 07:00:00 | 000,027,440 | —- | C] () – C:\WINDOWS\System32\drivers\secdrv.sys
[2004/08/04 07:00:00 | 000,001,788 | —- | C] () – C:\WINDOWS\System32\Dcache.bin
[2004/08/04 07:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2004/06/15 23:38:00 | 000,000,560 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2003/04/11 00:04:00 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\JAWTAccessBridge.dll
[2003/01/08 00:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2001/08/23 18:12:28 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2001/08/23 18:11:02 | 000,004,490 | —- | C] () – C:\WINDOWS\System32\oembios.dat

========== LOP Check ==========


========== Purity Check ==========



========== Custom Scans ==========


< c:\docume~1\alluse~1\applic~1\gJlNlJm06300\*.* >

< %SYSTEMDRIVE%\*.* >
[2005/01/26 23:53:38 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2011/02/28 16:59:14 | 000,000,213 | RHS- | M] () – C:\BOOT.BAK
[2011/02/28 17:15:41 | 000,000,283 | RHS- | M] () – C:\boot.ini
[2004/08/04 07:00:00 | 000,260,272 | RHS- | M] () – C:\cmldr
[2005/01/26 23:53:38 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2011/03/04 10:02:55 | 527,814,656 | -HS- | M] () – C:\hiberfil.sys
[2005/01/26 23:53:38 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2005/01/26 23:53:38 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/04 07:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2004/08/04 07:00:00 | 000,250,032 | RHS- | M] () – C:\ntldr
[2011/03/04 10:02:54 | 792,723,456 | -HS- | M] () – C:\pagefile.sys
[2011/03/01 11:31:18 | 000,155,648 | —- | M] () – C:\WsView.mdb

< %systemroot%\Fonts\*.com >

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2005/01/26 23:53:06 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2003/06/19 02:31:48 | 000,018,944 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2005/01/26 15:45:52 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2005/01/26 15:45:52 | 000,634,880 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2005/01/26 15:45:52 | 000,872,448 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2005/01/26 23:53:42 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/02/28 17:01:32 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\HP_Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2005/01/26 23:57:04 | 000,000,079 | —- | M] () – C:\Documents and Settings\HP_Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2011/03/03 17:25:04 | 000,581,120 | —- | M] (OldTimer Tools) – C:\Documents and Settings\HP_Owner\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

< %PROGRAMFILES%\Internet Explorer\*.tmp >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %USERPROFILE%\My Documents\*.exe >
[2011/03/01 13:18:16 | 009,261,960 | —- | M] () – C:\Documents and Settings\HP_Owner\My Documents\SW601379_TETouch_5.2.0.exe

< %USERPROFILE%\*.exe >

< %systemroot%\ADDINS\*.* >
[2004/08/04 07:00:00 | 000,000,791 | —- | M] () – C:\WINDOWS\addins\fxsext.ecf

< %systemroot%\assembly\*.bak2 >

< %systemroot%\Config\*.* >

< %systemroot%\REPAIR\*.bak2 >

< %systemroot%\SECURITY\Database\*.sdb /x >

< %systemroot%\SYSTEM\*.bak2 >

< %systemroot%\Web\*.bak2 >

< %systemroot%\Driver Cache\*.* >

< %PROGRAMFILES%\Mozilla Firefox\0*.exe >

< %ProgramFiles%\Microsoft Common\*.* >

< %ProgramFiles%\TinyProxy. >

< %USERPROFILE%\Favorites\*.url /x >
[2011/02/28 17:01:31 | 000,000,122 | -HS- | M] () – C:\Documents and Settings\HP_Owner\Favorites\Desktop.ini

< %systemroot%\system32\*.bk >

< %systemroot%\*.te >

< %systemroot%\system32\system32\*.* >

< %ALLUSERSPROFILE%\*.dat /x >

< %systemroot%\system32\drivers\*.rmv >

< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >

< dir /b "%systemroot%\*.exe" | find /i " " /c >

< %PROGRAMFILES%\Microsoft\*.* >

< %systemroot%\System32\Wbem\proquota.exe >

< %PROGRAMFILES%\Mozilla Firefox\*.dat >

< %USERPROFILE%\Cookies\*.txt /x >
[2011/03/04 10:08:46 | 000,081,920 | —- | M] () – C:\Documents and Settings\HP_Owner\Cookies\index.dat

< %SystemRoot%\system32\fonts\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< End of report >



EXTRAS


OTL Extras logfile created on: 03/04/2011 10:11:28 AM - Run 1
OTL by OldTimer - Version 3.2.22.2 Folder = C:\Documents and Settings\HP_Owner\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: MM/dd/yyyy

503.00 Mb Total Physical Memory | 216.00 Mb Available Physical Memory | 43.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 75.00% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 67.55 Gb Total Space | 58.21 Gb Free Space | 86.18% Space Free | Partition Type: NTFS
Drive D: | 6.96 Gb Total Space | 1.94 Gb Free Space | 27.89% Space Free | Partition Type: FAT32

Computer Name: YOUR-F78BF48CE2 | User Name: HP_Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe" = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe:*:Enabled:BackWeb for Pavilion – (Hewlett-Packard)
"C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" = C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{075473F5-846A-448B-BCB3-104AA1760205}" = Sonic RecordNow Data
"{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}" = Microsoft Plus! Photo Story 2 LE
"{14589F05-C658-4594-9429-D437BA688686}" = IntelliMover Data Transfer Demo
"{1A103D70-5C9B-4E1A-B306-5106C68F9914}" = Microsoft Plus! Dancer LE
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{26A24AE4-039D-4CA4-87B4-2F83216024FF}" = Java™ 6 Update 24
"{2C5D07FB-31A2-4F2D-9FDA-0B24ACD42BD0}" = HP Deskjet Printer Preload
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3BA95526-6AE0-4B87-A62D-17187EF565FC}" = HP Boot Optimizer
"{416D80BA-6F6D-4672-B7CF-F54DA2F80B44}" = Microsoft Works
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{64FC0C98-B035-4530-B15D-3D30610B6DF1}" = HP Software Update
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Sonic Express Labeler
"{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}" = Microsoft Plus! Digital Media Edition Installer
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver
"{90280409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional with FrontPage
"{91120409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Standard Edition 2003
"{A93C4E94-1005-489D-BEAA-B873C1AA6CFC}" = HP Help and Support 4.0
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Sonic RecordNow Audio
"{AC76BA86-0000-0000-0000-6028747ADE01}" = Adobe Acrobat - Reader 6.0.2 Update
"{AC76BA86-7AD7-1033-7B44-A00000000001}" = Adobe Reader 6.0.1
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Sonic RecordNow Copy
"{BE20E2F5-1903-4AAE-B1AF-2046E586C925}" = iTunes
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{D0122362-6333-4DE4-93F6-A5A2F3CC101A}" = HP Organize
"{DB518BA6-CB74-4EB6-9ABD-880B6D6E1F38}" = HpSdpAppCoreApp
"14DD9322-0AAE-4DA4-90A9-EB42CF296127" = Shooting Stars Pool from Hewlett-Packard Desktops (remove only)
"36317AE4-57EC-4F3E-B828-009A3DD96BE8" = Polar Bowler from Hewlett-Packard Desktops (remove only)
"3F34F72F-9BB0-4B73-8312-558953ACF56F" = Super Granny from Hewlett-Packard Desktops (remove only)
"58D1A004-6D3C-480A-9E0D-FAA58F3C2A62" = Blackhawk Striker 2 from Hewlett-Packard Desktops (remove only)
"6723E59E-322A-417A-8E03-27A61E18253C" = Overball from Hewlett-Packard Desktops (remove only)
"741C4983-B139-407A-AD4E-3D6C7B29704B" = Final Drive Nitro from Hewlett-Packard Desktops (remove only)
"7CEF0F00-BA1B-4861-A102-38CC86CA622B" = Phoenix Assault from Hewlett-Packard Desktops (remove only)
"8C4E79CC-03E1-43AA-9910-9A5113F24603" = Blasterball 2 from Hewlett-Packard Desktops (remove only)
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Agere Systems Soft Modem" = Agere Systems PCI Soft Modem
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"B151D9AC-5E4E-4AD0-96C9-5A6C9EC23502" = Blasterball 2 Remix from Hewlett-Packard Desktops (remove only)
"B2D3332F-EA2D-42B3-8E4A-F74D052BCBC1" = Polar Golfer from Hewlett-Packard Desktops (remove only)
"B41503CB-5FE0-47E0-87C1-47BA8E660BCC" = Blasterball 2 Holidays from Hewlett-Packard Desktops (remove only)
"BackWeb-309731 Uninstaller" = Updates from HP
"C2C3C2DB-7D8A-4E20-B527-E3149FAECC3A" = Slyder from Hewlett-Packard Desktops (remove only)
"D11F7128-8CBD-408B-8BF8-034604DEDD42" = Bounce Symphony from Hewlett-Packard Desktops (remove only)
"DAE7A92A-BAC7-42FA-AC62-53DEF1DC4292" = Crystal Maze from Hewlett-Packard Desktops (remove only)
"E2A4EA31-80A1-4460-9510-631AF4D6A636" = Lexibox Deluxe from Hewlett-Packard Desktops (remove only)
"EloTouchscreen" = Elo Universal Driver 4.8.7
"F5215F01-DFC0-475D-A910-6F1AF94E807E" = Tradewinds from Hewlett-Packard Desktops (remove only)
"Help and Support Additions" = Help and Support Additions
"ie8" = Windows Internet Explorer 8
"InstallShield_{BE20E2F5-1903-4AAE-B1AF-2046E586C925}" = iTunes
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Money" = Remove Microsoft Money 2005 installer
"MosChip Technology" = PCI Multi-IO Controller
"Python 2.2.3" = Python 2.2.3
"pywin32-py2.2" = Python 2.2 pywin32 extensions (build 203)
"Quicken_NUE" = Remove Quicken New User Edition installer
"QuickTime" = QuickTime
"RealPlayer 6.0" = RealPlayer
"SunTouch Plus version 1.50.17" = SunTouch Plus version 1.50.17
"Wdf01009" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows Media Player" = Windows Media Player 10

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 03/01/2011 02:55:29 AM | Computer Name = YOUR-F78BF48CE2 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.

Error - 03/01/2011 02:59:43 AM | Computer Name = YOUR-F78BF48CE2 | Source = Application Hang | ID = 1002
Description = Hanging application avscan.exe, version 10.0.3.5, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 03/01/2011 03:10:59 AM | Computer Name = YOUR-F78BF48CE2 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.

[ System Events ]
Error - 03/01/2011 01:23:14 PM | Computer Name = YOUR-F78BF48CE2 | Source = Parclass | ID = 458754
Description = Unable to get device object pointer for parallel port object.

Error - 03/01/2011 02:10:02 PM | Computer Name = YOUR-F78BF48CE2 | Source = Parclass | ID = 458754
Description = Unable to get device object pointer for parallel port object.

Error - 03/01/2011 02:20:58 PM | Computer Name = YOUR-F78BF48CE2 | Source = Parclass | ID = 458754
Description = Unable to get device object pointer for parallel port object.

Error - 03/01/2011 02:31:45 PM | Computer Name = YOUR-F78BF48CE2 | Source = Parclass | ID = 458754
Description = Unable to get device object pointer for parallel port object.

Error - 03/01/2011 02:32:30 PM | Computer Name = YOUR-F78BF48CE2 | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the EloSystemService service.

Error - 03/01/2011 02:35:48 PM | Computer Name = YOUR-F78BF48CE2 | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the EloSystemService service.

Error - 03/02/2011 10:45:08 AM | Computer Name = YOUR-F78BF48CE2 | Source = Parclass | ID = 458754
Description = Unable to get device object pointer for parallel port object.

Error - 03/03/2011 10:58:47 AM | Computer Name = YOUR-F78BF48CE2 | Source = Parclass | ID = 458754
Description = Unable to get device object pointer for parallel port object.

Error - 03/04/2011 11:00:08 AM | Computer Name = YOUR-F78BF48CE2 | Source = Parclass | ID = 458754
Description = Unable to get device object pointer for parallel port object.

Error - 03/04/2011 11:03:20 AM | Computer Name = YOUR-F78BF48CE2 | Source = Parclass | ID = 458754
Description = Unable to get device object pointer for parallel port object.


< End of report >
Hi T.C.,

Run OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    :Files
    C:\WINDOWS\mfgdexb.dll
    
    :Commands
    [createrestorepoint]
    [purity]
    [emptytemp]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
How is your computer running now?
All processes killed ========== FILES ========== File\Folder C:\WINDOWS\mfgdexb.dll not found. ========== COMMANDS ========== Restore point Set: OTL Restore Point (0) [EMPTYTEMP] User: All Users User: Default User ->Temp folder emptied: 19218 bytes ->Temporary Internet Files folder emptied: 32768 bytes User: HP_Owner ->Temp folder emptied: 35287138 bytes ->Temporary Internet Files folder emptied: 18344719 bytes ->Java cache emptied: 0 bytes ->Flash cache emptied: 4153 bytes User: LocalService ->Temp folder emptied: 65984 bytes ->Temporary Internet Files folder emptied: 32902 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 2577 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 92494 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 19218 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 51.00 mb OTL by OldTimer - Version 3.2.22.3 log created on 03082011_104806 Files\Folders moved on Reboot… File\Folder C:\Documents and Settings\HP_Owner\Local Settings\Temp\~DF6657.tmp not found! File\Folder C:\Documents and Settings\HP_Owner\Local Settings\Temp\~DF7128.tmp not found! File\Folder C:\Documents and Settings\HP_Owner\Local Settings\Temp\~DFE28F.tmp not found! File\Folder C:\Documents and Settings\HP_Owner\Local Settings\Temp\~DFE2A7.tmp not found! File\Folder C:\Documents and Settings\HP_Owner\Local Settings\Temp\~DFE320.tmp not found! File\Folder C:\Documents and Settings\HP_Owner\Local Settings\Temp\~DFE33A.tmp not found! File\Folder C:\Documents and Settings\HP_Owner\Local Settings\Temp\~DFE380.tmp not found! File\Folder C:\Documents and Settings\HP_Owner\Local Settings\Temp\~DFE398.tmp not found! C:\Documents and Settings\HP_Owner\Local Settings\Temporary Internet Files\Content.IE5\SJ2L052V\index[1].htm moved successfully. C:\Documents and Settings\HP_Owner\Local Settings\Temporary Internet Files\Content.IE5\14GM1BW7\iframe[1].htm moved successfully. C:\Documents and Settings\HP_Owner\Local Settings\Temporary Internet Files\Content.IE5\0O5466ZA\like[1].htm moved successfully. Registry entries deleted on Reboot…
Hi T.C.,

Glad to hear that!

We need to address a couple more things.

Windows is out of date
You are currently running Windows XP Home Service Pack 2. The latest service pack is service pack 3. Download service pack 3 here and install it.

===================================================

Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.

Updating Java:
  • Download the latest version of Java Runtime Environment (JRE) 6 Update 23.
  • Scroll down to where it says "The Java SE Runtime Environment (JRE) allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • In the pull down menu next to Platform select Windows
  • Check the box that says: "I agree to the Java SE Runtime Environment 6 License Agreement"
  • Click Continue
  • Click on the link to download Windows Offline Installation and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u23-windows-i586-p.exe to install the newest version.
Now to Clean out the Java cache:

Go into the Control Panel and double-click the Java Icon. [external image: Posted Image]
  • Under Temporary Internet Files, click the Settings… button
  • click the Delete Files button.
  • There are three options in the window to clear the cache - Leave all 3 Checked
    • Downloaded Applets
      Downloaded Applications
      Other Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Settings
  • Click OK to leave the Java Control Panel.
===================================================

Update Adobe Reader
Earlier versions of Adobe Reader have known security flaws so it is recommended that you update your copy
  • Go to Start > Control Panel > Add/Remove Programs
  • Remove ALL instances of Adobe Reader
  • Re-boot your computer as required.
  • Once ALL versions of Adobe Reader have been uninstalled, visit: <> and download the latest version of Adobe Reader
Alternative Option: after uninstalling Adobe Reader, you could try installing Foxit Reader from >here< Foxit Reader has fewer add-ons therefore loads more quickly.

===================================================

Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.
===================================================

Now Set a New Restore Point to prevent possible reinfection from an old one. Some of the malware you picked up could have been saved in System Restore. Since System Restore is a protected directory, your tools can not access it to delete these bad files which sometimes can reinfect your system. Setting a new restore point AFTER cleaning your system will help prevent this and enable your computer to "roll-back" to a clean working state.  

The easiest and safest way to do this is:
  • Go to Start > Programs > Accessories > System Tools and click "System Restore".
  • Choose the radio button marked "Create a Restore Point" on the first screen then click "Next". Give the R.P. a name then click "Create". The new point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
  • Then go to Start > Run and type: Cleanmgr
  • Click "OK".
  • Click the "More Options" Tab.
  • Click "Clean Up" in the System Restore section to remove all previous restore points except the newly created one.
Here are some tips to reduce the potential for spyware infection in the future:

1. Make your Internet Explorer More Secure
  • Click Start > Run
  • Type Inetcpl.cpl and click OK
  • Click on the Security tab
  • Click Reset all zones to default level
  • Make sure the Internet Zone is selected and Click Custom level
  • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to Prompt, and ("Initialize and Script ActiveX controls not marked as safe") to Disable.
  • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
2. Update your Anti-Virus Software - I can not overemphasize the need for you to update your Anti-virus application on a regular basis.  With the ever increasing number of new variants of malware arriving on the scene daily, you become very susceptible to an attack without updated protection.

3. Make sure you keep your Windows OS current by visiting Windows update   regularly to download and install any critical updates and service packs. Without these you are leaving the back door open.

4. Consider a custom hosts file such as MVPS HOSTS. This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers.
For information on how to download and install, please read this tutorial by WinHelp2002
Note: Be sure to follow the instructions to disable the DNS Client service before installing a custom hosts file.

5. Finally, I strongly recommend that you read TonyKlein's good advice So how did I get infected in the first place?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI