I'm trying to help a friend whose desktop PC running Windows XP SP3 is infected with Win32/heur.dropper. AVG has found two instances:
D:\System Volume Information\_restore{A2578CBA-012A-4EE9-9E3D-27D3F494A2B6}\RP101\A0041288.exe:\$JJ\5253F22E-D4B6-49B7-9106-28D9C5395F22.exe";"Virus found Win32/Heur.dropper";"Infected"
D:\I386\Apps\APP03031\src\install\Worldwide-HP\games\{5253F22E-D4B6-49B7-9106-28D9C5395F22}.exe:\$JJ\5253F22E-D4B6-49B7-9106-28D9C5395F22.exe";"Virus found Win32/Heur.dropper";"Infected"
I've run OTL following the posted instructions but it doesn't produce the Extras.txt file. I've also run HJT. The log files are posted below. I can't see that either scan looks at the D: partition.
Any help getting rid of this would be greatly appreciated.
Thank You.
The OTL.txt file contains:
OTL logfile created on: 3/14/2011 12:19:18 PM - Run 3
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Wendy.YOUR-27E1513D96\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
958.00 Mb Total Physical Memory | 214.00 Mb Available Physical Memory | 22.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 70.00% Paging File free
Paging file location(s): C:\pagefile.sys 1440 2880 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 225.36 Gb Total Space | 160.92 Gb Free Space | 71.40% Space Free | Partition Type: NTFS
Drive D: | 7.50 Gb Total Space | 1.65 Gb Free Space | 22.05% Space Free | Partition Type: FAT32
Computer Name: YOUR-27E1513D96 | User Name: Wendy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Wendy.YOUR-27E1513D96\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Real\realplayer\Update\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Soluto\SolutoService.exe (Soluto)
PRC - C:\Program Files\Soluto\Soluto.exe (Soluto)
PRC - C:\Program Files\AVG\AVG10\avgui.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Common Files\Portrait Displays\Shared\HookManager.exe (Portrait Displays Inc.)
PRC - C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe ()
PRC - C:\Program Files\Acer Display\eDisplay Management\dthtml.exe (Portrait Displays, Inc)
PRC - C:\Program Files\Common Files\Portrait Displays\Drivers\pdisrvc.exe (Portrait Displays, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Portrait Displays\Pivot Software\Floater.exe ()
PRC - C:\Program Files\Portrait Displays\Pivot Software\wpCtrl.exe ()
PRC - C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
PRC - C:\Program Files\Java\jre1.5.0\bin\jucheck.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Java\jre1.5.0\bin\jusched.exe (Sun Microsystems, Inc.)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Wendy.YOUR-27E1513D96\My Documents\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchromebrowserrecordhelper.dll (RealNetworks, Inc.)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcr90.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcp90.dll (Microsoft Corporation)
MOD - C:\Program Files\Portrait Displays\Pivot Software\Winphook.dll ()
========== Win32 Services (SafeList) ==========
SRV - (HidServ) – File not found
SRV - (AppMgmt) – File not found
SRV - (SolutoService) – C:\Program Files\Soluto\SolutoService.exe (Soluto)
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) – C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (DTSRVC) – C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe ()
SRV - (PdiService) – C:\Program Files\Common Files\Portrait Displays\Drivers\pdisrvc.exe (Portrait Displays, Inc.)
SRV - (CCALib8) – C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
========== Driver Services (SafeList) ==========
DRV - (Soluto) – C:\WINDOWS\system32\DRIVERS\Soluto.sys (Soluto LTD.)
DRV - (Avgldx86) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgtdix) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSEH) – C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgmfx86) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) – C:\WINDOWS\system32\DRIVERS\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSShim) – C:\WINDOWS\system32\drivers\AVGIDSShim.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSDriver) – C:\WINDOWS\system32\drivers\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSFilter) – C:\WINDOWS\system32\drivers\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV - (PdiPorts) – C:\WINDOWS\system32\drivers\PdiPorts.sys (Portrait Displays, Inc.)
DRV - (Pivot) – C:\WINDOWS\system32\drivers\pivot.sys (Portrait Displays, Inc.)
DRV - (pivotmou) – C:\WINDOWS\system32\drivers\pivotmou.sys (Portrait Displays, Inc.)
DRV - (Ps2) – C:\WINDOWS\system32\drivers\PS2.sys (Hewlett-Packard Company)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (ftsata2) – C:\WINDOWS\system32\DRIVERS\ftsata2.sys (Promise Technology, Inc.)
DRV - (AmdK8) – C:\WINDOWS\system32\drivers\AmdK8.sys (Advanced Micro Devices)
DRV - (RTL8023xp) – C:\WINDOWS\system32\drivers\Rtlnicxp.sys (Realtek Semiconductor Corporation )
DRV - (smserial) – C:\WINDOWS\system32\drivers\smserial.sys (Motorola Inc.)
DRV - (rtl8139) Realtek RTL8139(A/B/C) – C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)
DRV - (bb-run) – C:\WINDOWS\system32\DRIVERS\bb-run.sys (Promise Technology, Inc.)
DRV - (crlscsi) – C:\WINDOWS\System32\drivers\crlscsi.sys (Corel Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…arm1=seconduser
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.sympatico.ca/
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://www.sympatico.ca/"
FF - prefs.js..extensions.enabledItems: {D6D05E6F-D5C1-4e03-8E33-73F92B05E262}:10.2
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:10.0.0.1178
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.2
FF - prefs.js..network.proxy.type: 0
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/09/04 22:42:03 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG10\Firefox\ [2011/01/24 12:22:26 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/02/16 22:27:14 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/02/16 22:27:06 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/02/16 22:27:30 | 000,000,000 | —D | M]
[2010/12/31 18:37:19 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Application Data\Mozilla\Extensions
[2011/03/13 21:52:57 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Application Data\Mozilla\Firefox\Profiles\5a8x4pk8.default\extensions
[2011/03/13 21:52:57 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Application Data\Mozilla\Firefox\Profiles\5a8x4pk8.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/03/05 15:01:42 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2009/04/05 22:35:55 | 000,000,000 | —D | M] (SMART Notebook Extension) – C:\Program Files\Mozilla Firefox\extensions\{D6D05E6F-D5C1-4e03-8E33-73F92B05E262}
[2011/02/16 22:27:14 | 000,000,000 | —D | M] (RealPlayer Browser Record Plugin) – C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
[2011/01/24 12:22:26 | 000,000,000 | —D | M] (AVG Safe Search) – C:\PROGRAM FILES\AVG\AVG10\FIREFOX
[2010/12/30 23:00:24 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2009/11/06 11:37:19 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
[2005/12/05 23:31:00 | 000,114,688 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\npmozax.dll
[2009/11/06 11:37:20 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npMozCouponPrinter.dll
O1 HOSTS File: ([2004/08/04 15:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [DT ACR] C:\Program Files\Common Files\Portrait Displays\Shared\DT_startup.exe ()
O4 - HKLM..\Run: [HPBootOp] C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [PivotSoftware] C:\Program Files\Portrait Displays\Pivot Software\wpctrl.exe ()
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &Google Search - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Backward Links - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Cached Snapshot of Page - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O8 - Extra context menu item: Similar Pages - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Translate into English - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ()
O9 - Extra 'Tools' menuitem : Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ()
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\intu-tt2010 {97A0575E-2309-4e75-8509-B1F9390C4DE7} - C:\Program Files\TurboTax 2010\ic2010pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Program Files\Soluto\soluto.exe /userinit) - C:\Program Files\Soluto\soluto.exe (Soluto)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Wendy.YOUR-27E1513D96\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Wendy.YOUR-27E1513D96\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/10/07 08:09:40 | 000,000,050 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2001/07/28 07:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O33 - MountPoints2\{2d435b36-e506-11d9-9b78-e6b009352ae7}\Shell - "" = AutoRun
O33 - MountPoints2\{2d435b36-e506-11d9-9b78-e6b009352ae7}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{2d435b36-e506-11d9-9b78-e6b009352ae7}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync) - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart) - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.LEAD - C:\WINDOWS\System32\LCodcCMP.dll (LEAD Technologies, Inc.)
Drivers32: wave1 - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)
Drivers32: wave2 - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)
========== Files/Folders - Created Within 30 Days ==========
[2011/03/13 22:04:04 | 000,000,000 | —D | C] – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Application Data\Malwarebytes
[2011/03/13 22:03:54 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/03/13 22:03:37 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/03/13 22:02:33 | 000,000,000 | —D | C] – C:\Documents and Settings\Wendy.YOUR-27E1513D96\My Documents\Downloads
[2011/03/07 13:35:38 | 000,236,032 | —- | C] (CANON INC.) – C:\WINDOWS\System32\CNMLM9R.DLL
[2011/03/07 13:35:35 | 000,000,000 | -H-D | C] – C:\WINDOWS\System32\CanonIJ Uninstaller Information
[2011/03/07 13:35:35 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Canon JX510P series
[2011/03/07 13:35:31 | 000,178,176 | —- | C] (CANON INC.) – C:\WINDOWS\System32\CNMIU9R.DLL
[2011/03/07 13:35:17 | 000,000,000 | -H-D | C] – C:\Program Files\CanonBJ
[2011/03/06 23:41:54 | 000,000,000 | —D | C] – C:\Documents and Settings\Wendy.YOUR-27E1513D96\My Documents\TurboTax
[2011/03/06 20:59:52 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\TurboTax
[2011/03/06 20:59:35 | 000,000,000 | —D | C] – C:\Program Files\TurboTax 2010
[2011/02/24 18:57:28 | 000,051,144 | —- | C] (Soluto LTD.) – C:\WINDOWS\System32\drivers\Soluto.sys
[2011/02/24 18:57:15 | 000,000,000 | —D | C] – C:\Program Files\Soluto
[2011/02/24 18:57:15 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Soluto
[2011/02/24 18:55:45 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Soluto
[2011/02/18 10:37:19 | 000,012,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mouhid.sys
[2011/02/18 10:37:06 | 000,010,368 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hidusb.sys
[2011/02/16 22:27:18 | 000,000,000 | —D | C] – C:\Program Files\Common Files\xing shared
[2011/02/16 22:27:05 | 000,198,848 | —- | C] (RealNetworks, Inc.) – C:\WINDOWS\System32\rmoc3260.dll
[2011/02/16 22:26:55 | 000,006,656 | —- | C] (RealNetworks, Inc.) – C:\WINDOWS\System32\pndx5016.dll
[2011/02/16 22:26:55 | 000,005,632 | —- | C] (RealNetworks, Inc.) – C:\WINDOWS\System32\pndx5032.dll
[2011/02/16 22:26:54 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Real
[2011/02/16 22:26:14 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Real
[2011/02/16 22:20:39 | 000,602,464 | —- | C] (RealNetworks, Inc.) – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Desktop\RealPlayer.exe
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/03/14 12:20:00 | 000,000,422 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{1A14DDC3-D4C6-4955-A8DD-1C9C60364BFE}.job
[2011/03/14 12:08:20 | 000,000,286 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-3131796442-2609879388-2480220986-1010.job
[2011/03/14 12:08:20 | 000,000,278 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-3131796442-2609879388-2480220986-1010.job
[2011/03/14 11:35:05 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/03/14 09:57:25 | 108,637,145 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2011/03/13 22:03:55 | 000,000,795 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/03/13 21:53:52 | 000,000,248 | —- | M] () – C:\WINDOWS\System\hpsysdrv.dat
[2011/03/13 21:53:15 | 000,446,338 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/03/13 21:53:15 | 000,073,100 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/03/13 21:50:44 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/03/13 21:50:33 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/03/13 21:50:30 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/03/13 21:50:27 | 1005,113,344 | -HS- | M] () – C:\hiberfil.sys
[2011/03/13 21:38:51 | 000,006,674 | —- | M] () – C:\Documents and Settings\Wendy.YOUR-27E1513D96\My Documents\WP_pcAVGscan.csv
[2011/03/09 15:37:15 | 000,001,355 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/03/09 14:49:00 | 000,049,842 | —- | M] () – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Desktop\Orillia Deck Project Materials List - Final Pricing.pdf
[2011/03/07 09:25:32 | 000,358,544 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/03/06 20:59:52 | 000,001,662 | —- | M] () – C:\Documents and Settings\All Users\Desktop\TurboTax Canada 2010.lnk
[2011/03/05 14:49:35 | 000,002,501 | —- | M] () – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Desktop\Microsoft Word 2010.lnk
[2011/03/01 18:22:23 | 000,193,113 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\iavichjg.avm
[2011/02/28 18:20:00 | 000,000,322 | —- | M] () – C:\WINDOWS\tasks\Easy Internet Sign-up.job
[2011/02/26 12:00:03 | 000,173,347 | —- | M] () – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Desktop\Gawel v Meloche Monnex.pdf
[2011/02/26 11:59:47 | 000,708,258 | —- | M] () – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Desktop\Stewart v New Brunswick.pdf
[2011/02/24 18:59:50 | 000,000,098 | —- | M] () – C:\Documents and Settings\All Users\Application Data\Microsoft.SqlServer.Compact.351.32.bc
[2011/02/22 11:52:31 | 000,003,584 | —- | M] () – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/02/22 10:20:39 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/02/16 22:28:36 | 000,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2011/02/16 22:28:36 | 000,001,409 | —- | M] () – C:\WINDOWS\QTFont.for
[2011/02/16 22:27:24 | 000,000,747 | —- | M] () – C:\Documents and Settings\All Users\Desktop\RealPlayer.lnk
[2011/02/16 22:27:05 | 000,198,848 | —- | M] (RealNetworks, Inc.) – C:\WINDOWS\System32\rmoc3260.dll
[2011/02/16 22:26:55 | 000,006,656 | —- | M] (RealNetworks, Inc.) – C:\WINDOWS\System32\pndx5016.dll
[2011/02/16 22:26:55 | 000,005,632 | —- | M] (RealNetworks, Inc.) – C:\WINDOWS\System32\pndx5032.dll
[2011/02/16 22:26:54 | 000,272,896 | —- | M] (Progressive Networks) – C:\WINDOWS\System32\pncrt.dll
[2011/02/16 22:20:39 | 000,602,464 | —- | M] (RealNetworks, Inc.) – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Desktop\RealPlayer.exe
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/03/13 22:03:55 | 000,000,795 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/03/13 21:38:50 | 000,006,674 | —- | C] () – C:\Documents and Settings\Wendy.YOUR-27E1513D96\My Documents\WP_pcAVGscan.csv
[2011/03/09 14:49:00 | 000,049,842 | —- | C] () – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Desktop\Orillia Deck Project Materials List - Final Pricing.pdf
[2011/03/06 20:59:51 | 000,001,662 | —- | C] () – C:\Documents and Settings\All Users\Desktop\TurboTax Canada 2010.lnk
[2011/02/26 11:59:55 | 000,173,347 | —- | C] () – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Desktop\Gawel v Meloche Monnex.pdf
[2011/02/26 11:59:46 | 000,708,258 | —- | C] () – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Desktop\Stewart v New Brunswick.pdf
[2011/02/24 19:01:20 | 001,115,872 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2011/02/24 18:59:50 | 000,000,098 | —- | C] () – C:\Documents and Settings\All Users\Application Data\Microsoft.SqlServer.Compact.351.32.bc
[2011/02/22 11:52:31 | 000,003,584 | —- | C] () – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/02/16 22:28:36 | 000,054,156 | -H– | C] () – C:\WINDOWS\QTFont.qfn
[2011/02/16 22:28:36 | 000,001,409 | —- | C] () – C:\WINDOWS\QTFont.for
[2011/02/16 22:27:56 | 000,000,278 | —- | C] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-3131796442-2609879388-2480220986-1010.job
[2011/02/16 22:27:51 | 000,000,286 | —- | C] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-3131796442-2609879388-2480220986-1010.job
[2011/02/16 22:27:24 | 000,000,747 | —- | C] () – C:\Documents and Settings\All Users\Desktop\RealPlayer.lnk
[2010/12/31 16:12:13 | 001,371,436 | R— | C] () – C:\WINDOWS\System32\VBAR2132.DLL
[2010/12/31 12:18:29 | 000,002,304 | —- | C] () – C:\WINDOWS\System32\Machnm32.sys
[2010/12/31 10:36:58 | 000,000,016 | —- | C] () – C:\WINDOWS\System32\asdict.dat
[2010/12/31 10:36:58 | 000,000,004 | —- | C] () – C:\WINDOWS\System32\aspdict-en.dat
[2010/12/31 01:20:23 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\wsbl.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\phar_unmip.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\phar_histprot.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\ph_white.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\ph_summ.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\ph_black.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pcwords2.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pcwords.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_webproxy.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_video.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_tabloids.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_socialnetworks.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_searchengines.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_regionaltlds.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_pornography.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_onlineshop.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_onlinepay.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_onlinedating.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_news.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_im.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_illegal.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_hate.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_games.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_gambling.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_drugs.dat
[2010/12/30 23:06:25 | 000,118,784 | —- | C] () – C:\WINDOWS\System32\hpocnt05.dll
[2010/12/30 23:06:25 | 000,000,970 | —- | C] () – C:\WINDOWS\hpoio05.ini
[2010/12/30 23:06:25 | 000,000,065 | —- | C] () – C:\WINDOWS\opleinst.ini
[2010/12/30 19:54:55 | 000,168,557 | —- | C] () – C:\WINDOWS\hphins33.dat.temp
[2010/12/30 19:54:55 | 000,000,512 | —- | C] () – C:\WINDOWS\hphmdl33.dat.temp
[2010/12/30 19:50:48 | 000,000,156 | —- | C] () – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Application Data\wklnhst.dat
[2010/09/04 22:32:09 | 000,168,470 | —- | C] () – C:\WINDOWS\hphins33.dat
[2010/09/04 22:32:09 | 000,000,512 | —- | C] () – C:\WINDOWS\hphmdl33.dat
[2010/03/29 19:40:20 | 000,100,256 | —- | C] () – C:\Program Files\Common Files\LinkInstaller.exe
[2009/02/06 21:07:32 | 000,000,004 | —- | C] () – C:\Program Files\Common Files\Cvtaqlog.dat
[2008/11/12 15:24:59 | 000,000,100 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2007/11/30 11:02:09 | 000,001,891 | —- | C] () – C:\WINDOWS\mozver.dat
[2007/11/30 11:00:07 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2007/11/19 23:52:47 | 000,000,234 | —- | C] () – C:\WINDOWS\LEXSTAT.INI
[2007/01/31 15:50:32 | 000,913,408 | —- | C] () – C:\WINDOWS\System32\xreglib.dll
[2006/08/04 10:28:10 | 000,000,010 | —- | C] () – C:\WINDOWS\SIERRA.INI
[2006/05/19 07:10:50 | 000,000,214 | —- | C] () – C:\WINDOWS\HP_InstantSHareJPG.ini
[2006/05/19 07:09:03 | 000,000,206 | —- | C] () – C:\WINDOWS\HPGdiPlus.ini
[2006/04/18 23:00:00 | 000,000,227 | —- | C] () – C:\WINDOWS\HP_CounterReport_Update_HPSU.ini
[2006/04/18 22:59:49 | 000,000,214 | —- | C] () – C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2006/04/18 22:59:38 | 000,000,217 | —- | C] () – C:\WINDOWS\HP_IZClosingDiscErrorPatch.ini
[2006/04/18 22:57:46 | 000,000,221 | —- | C] () – C:\WINDOWS\HP_RedboxHprblog_HPSU.ini
[2005/11/25 13:24:10 | 000,000,000 | —- | C] () – C:\WINDOWS\longfile.INI
[2005/11/25 13:17:39 | 000,000,102 | —- | C] () – C:\WINDOWS\texture.ini
[2005/11/24 23:12:18 | 000,039,125 | —- | C] () – C:\WINDOWS\iccsigs.dat
[2005/10/07 08:36:45 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/10/07 08:13:47 | 000,118,842 | R— | C] () – C:\WINDOWS\HPCPCUninstaller-6.3.2.116-9972322.exe
[2005/10/07 08:12:37 | 000,013,543 | —- | C] () – C:\WINDOWS\System32\CHODDI.SYS
[2005/10/07 08:12:32 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\hpreg.dll
[2005/10/07 08:10:21 | 000,000,172 | —- | C] () – C:\WINDOWS\Quicken.ini
[2005/10/07 08:06:07 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/10/07 08:01:42 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2005/10/07 08:01:42 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2005/10/07 08:01:42 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2005/10/07 08:01:42 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2005/10/07 08:01:42 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2005/10/07 08:01:41 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2005/10/07 07:56:41 | 000,000,056 | —- | C] () – C:\WINDOWS\WININIT.INI
[2005/10/07 07:51:25 | 000,112,873 | —- | C] () – C:\WINDOWS\hpoins07.dat
[2005/10/07 07:51:25 | 000,021,124 | —- | C] () – C:\WINDOWS\hpomdl07.dat
[2005/10/07 07:46:50 | 000,080,418 | —- | C] () – C:\WINDOWS\HPHins08.dat
[2005/10/07 07:46:50 | 000,004,011 | —- | C] () – C:\WINDOWS\hphmdl08.dat
[2005/10/07 07:44:51 | 000,072,881 | —- | C] () – C:\WINDOWS\hpiins01.dat
[2005/10/07 07:44:51 | 000,000,000 | —- | C] () – C:\WINDOWS\hpimdl01.dat
[2005/10/07 07:43:58 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2005/10/07 07:41:38 | 000,065,536 | —- | C] () – C:\WINDOWS\sm56spn.dll
[2005/10/07 07:41:38 | 000,065,536 | —- | C] () – C:\WINDOWS\sm56spn(2).dll
[2005/10/07 07:41:38 | 000,065,536 | —- | C] () – C:\WINDOWS\sm56itl.dll
[2005/10/07 07:41:38 | 000,065,536 | —- | C] () – C:\WINDOWS\sm56itl(2).dll
[2005/10/07 07:41:38 | 000,065,536 | —- | C] () – C:\WINDOWS\sm56ger.dll
[2005/10/07 07:41:38 | 000,065,536 | —- | C] () – C:\WINDOWS\sm56ger(2).dll
[2005/10/07 07:41:38 | 000,065,536 | —- | C] () – C:\WINDOWS\sm56fra.dll
[2005/10/07 07:41:38 | 000,065,536 | —- | C] () – C:\WINDOWS\sm56fra(2).dll
[2005/10/07 07:41:38 | 000,065,536 | —- | C] () – C:\WINDOWS\sm56eng.dll
[2005/10/07 07:41:38 | 000,065,536 | —- | C] () – C:\WINDOWS\sm56eng(2).dll
[2005/10/07 07:41:38 | 000,065,536 | —- | C] () – C:\WINDOWS\sm56brz.dll
[2005/10/07 07:41:38 | 000,065,536 | —- | C] () – C:\WINDOWS\sm56brz(2).dll
[2005/10/07 07:41:38 | 000,049,152 | —- | C] () – C:\WINDOWS\sm56jpn.dll
[2005/10/07 07:41:38 | 000,049,152 | —- | C] () – C:\WINDOWS\sm56jpn(2).dll
[2005/10/07 07:41:38 | 000,045,056 | —- | C] () – C:\WINDOWS\sm56cht.dll
[2005/10/07 07:41:38 | 000,045,056 | —- | C] () – C:\WINDOWS\sm56cht(2).dll
[2005/10/07 07:41:38 | 000,045,056 | —- | C] () – C:\WINDOWS\sm56chs.dll
[2005/10/07 07:41:38 | 000,045,056 | —- | C] () – C:\WINDOWS\sm56chs(2).dll
[2005/10/07 07:40:36 | 000,001,040 | —- | C] () – C:\WINDOWS\System32\drivers\alcxinit.dat
[2005/10/07 07:40:34 | 000,026,625 | —- | C] () – C:\WINDOWS\System32\sxsttsu.dll
[2005/10/07 07:40:14 | 000,094,574 | —- | C] () – C:\WINDOWS\System32\atiicdxx.dat
[2005/10/07 07:31:11 | 000,000,780 | —- | C] () – C:\WINDOWS\orun32.ini
[2005/10/07 07:27:48 | 000,323,584 | —- | C] () – C:\WINDOWS\System32\pythoncom22.dll
[2005/10/07 07:27:48 | 000,094,208 | —- | C] () – C:\WINDOWS\System32\pywintypes22.dll
[2005/10/07 07:27:30 | 000,016,896 | —- | C] () – C:\WINDOWS\System32\bcbmm.dll
[2005/07/07 16:07:24 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2005/06/25 02:29:32 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2005/06/25 01:43:44 | 000,446,338 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2005/06/25 01:43:44 | 000,073,100 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2005/06/25 01:42:06 | 000,358,544 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2005/06/25 01:31:46 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2005/06/25 01:30:20 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2005/05/10 02:52:32 | 000,022,396 | —- | C] () – C:\WINDOWS\System32\drivers\USBkey.sys
[2004/08/04 15:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/04 08:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/04 08:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/04 08:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/04 08:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/04 08:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/04 08:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/08/04 08:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2004/06/16 01:38:02 | 000,000,537 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2001/08/23 19:12:28 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2001/08/23 19:11:02 | 000,004,490 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2001/07/07 01:30:00 | 000,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini
========== LOP Check ==========
[2007/12/01 21:18:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Avery
[2011/01/24 14:00:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG
[2011/03/13 21:44:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG10
[2010/03/30 18:01:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Bell
[2008/03/06 14:37:03 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2011/01/24 12:24:06 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2011/01/24 12:21:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2010/10/03 09:15:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Radialpoint
[2009/04/05 23:27:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SMART Technologies
[2011/02/24 19:06:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Soluto
[2011/01/24 23:58:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2011/01/24 13:58:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Application Data\AVG
[2011/01/24 12:28:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Application Data\AVG10
[2010/12/30 19:50:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Application Data\Bell
[2010/12/30 19:51:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Application Data\Canon
[2010/12/31 15:22:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Application Data\DisplayTune
[2010/12/30 19:51:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Application Data\FileMaker
[2010/12/30 19:51:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Application Data\InterVideo
[2010/12/30 19:51:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Application Data\Leadertech
[2010/12/30 19:51:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Application Data\PDF reDirect
[2010/12/30 19:51:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Application Data\QuickScan
[2005/10/07 08:11:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Application Data\SampleView
[2010/12/30 19:51:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Application Data\SMART Technologies
[2010/12/30 19:51:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Application Data\SMART Technologies Inc
[2010/12/30 19:51:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Application Data\Template
[2010/12/30 19:51:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Application Data\WinBatch
[2010/12/30 19:51:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Application Data\Xerox
[2011/02/28 18:20:00 | 000,000,322 | —- | M] () – C:\WINDOWS\Tasks\Easy Internet Sign-up.job
[2011/03/14 12:20:00 | 000,000,422 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{1A14DDC3-D4C6-4955-A8DD-1C9C60364BFE}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2005/10/07 08:09:40 | 000,000,050 | —- | M] () – C:\AUTOEXEC.BAT
[2011/01/24 11:59:49 | 000,041,323 | —- | M] () – C:\bdlog.txt
[2010/12/30 18:45:33 | 000,000,213 | RHS- | M] () – C:\BOOT.BAK
[2010/12/30 19:07:51 | 000,000,283 | RHS- | M] () – C:\boot.ini
[2004/08/04 08:00:00 | 000,260,272 | RHS- | M] () – C:\cmldr
[2005/06/25 01:32:00 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2007/04/01 22:46:13 | 000,030,208 | —- | M] () – C:\Fax Lease agreement KingstonJosanne Parret 2007.doc
[2011/03/13 21:50:27 | 1005,113,344 | -HS- | M] () – C:\hiberfil.sys
[2005/06/25 01:32:00 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/05/11 19:31:24 | 000,000,000 | —- | M] () – C:\Log.txt
[2005/06/25 01:32:00 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/04 08:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2010/12/30 21:12:21 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/03/13 21:50:21 | 1509,949,440 | -HS- | M] () – C:\pagefile.sys
[2010/12/31 12:17:58 | 000,000,173 | —- | M] () – C:\pdisdk.log
[2010/12/31 12:18:53 | 000,000,184 | —- | M] () – C:\pivot.log
[2007/04/30 07:10:58 | 000,001,990 | —- | M] () – C:\xPos.txt
[1 C:\*.tmp files -> C:\*.tmp -> ]
< %systemroot%\Fonts\*.com >
[2006/04/18 16:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 15:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 16:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 15:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
[2005/05/12 09:36:48 | 000,012,288 | —- | M] (Hewlett-Packard Co.) – C:\WINDOWS\Fonts\RandFont.dll
< %systemroot%\Fonts\*.ini >
[2005/06/25 01:31:38 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/10/07 06:00:00 | 000,027,136 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD9R.DLL
[2008/10/07 06:00:00 | 000,069,632 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP9R.DLL
[2008/07/06 08:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2009/04/16 15:08:20 | 000,312,832 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpfpp70v.dll
[2003/06/19 03:31:48 | 000,018,944 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 06:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2005/06/24 18:25:14 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2005/06/24 18:25:14 | 000,634,880 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2005/06/24 18:25:14 | 000,884,736 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2010/12/30 22:50:18 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2005/11/26 00:50:59 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2005/06/25 01:42:40 | 000,000,079 | —- | M] () – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2006/11/20 10:18:28 | 000,077,824 | —- | M] (WinTronTechnologies) – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Desktop\conversion.exe
[2011/02/16 22:20:39 | 000,602,464 | —- | M] (RealNetworks, Inc.) – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Desktop\RealPlayer.exe
< %PROGRAMFILES%\Common Files\*.* >
[2009/02/06 21:07:32 | 000,000,004 | —- | M] () – C:\Program Files\Common Files\Cvtaqlog.dat
[2010/03/29 19:40:20 | 000,100,256 | —- | M] () – C:\Program Files\Common Files\LinkInstaller.exe
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-03-09 19:37:48
========== Alternate Data Streams ==========
@Alternate Data Stream - 146 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4
< End of report >
Here is the HJT log:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:24:35 PM, on 3/14/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Soluto\soluto.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AVG\AVG10\avgwdsvc.exe
C:\Program Files\Common Files\Portrait Displays\Shared\dtsrvc.exe
C:\Program Files\Common Files\Portrait Displays\Drivers\pdisrvc.exe
C:\Program Files\Soluto\SolutoService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Portrait Displays\Pivot Software\wpctrl.exe
C:\Program Files\AVG\AVG10\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Portrait Displays\Pivot Software\floater.exe
C:\Program Files\Acer Display\eDisplay Management\DTHtml.exe
C:\Program Files\Common Files\Portrait Displays\Shared\HookManager.exe
C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
C:\WINDOWS\system32\wuauclt.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
c:\windows\system\hpsysdrv.exe
C:\Program Files\Java\jre1.5.0\bin\jusched.exe
C:\Program Files\Java\jre1.5.0\bin\jucheck.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\program files\real\realplayer\update\realsched.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\AVG\AVG10\avgui.exe
C:\Documents and Settings\Wendy.YOUR-27E1513D96\My Documents\Downloads\OTL.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\Wendy.YOUR-27E1513D96\My Documents\Downloads\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…arm1=seconduser
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sympatico.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…arm1=seconduser
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…arm1=seconduser
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\Program Files\Soluto\soluto.exe /userinit
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MI1933~1\Office14\URLREDIR.DLL
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [PivotSoftware] "C:\Program Files\Portrait Displays\Pivot Software\wpctrl.exe"
O4 - HKLM\..\Run: [DT ACR] C:\Program Files\Common Files\Portrait Displays\Shared\DT_startup.exe -ACR
O4 - HKLM\..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MI1933~1\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: intu-tt2010 - {97A0575E-2309-4E75-8509-B1F9390C4DE7} - C:\Program Files\TurboTax 2010\ic2010pp.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10\avgwdsvc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Portrait Displays Display Tune Service (DTSRVC) - Unknown owner - C:\Program Files\Common Files\Portrait Displays\Shared\dtsrvc.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Portrait Displays SDK Service (PdiService) - Portrait Displays, Inc. - C:\Program Files\Common Files\Portrait Displays\Drivers\pdisrvc.exe
O23 - Service: Soluto PCGenome Core Service (SolutoService) - Soluto - C:\Program Files\Soluto\SolutoService.exe
–
End of file - 10125 bytes