This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Infected with Win32/heur.dropper

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

I'm trying to help a friend whose desktop PC running Windows XP SP3 is infected with Win32/heur.dropper. AVG has found two instances:

D:\System Volume Information\_restore{A2578CBA-012A-4EE9-9E3D-27D3F494A2B6}\RP101\A0041288.exe:\$JJ\5253F22E-D4B6-49B7-9106-28D9C5395F22.exe";"Virus found Win32/Heur.dropper";"Infected"

D:\I386\Apps\APP03031\src\install\Worldwide-HP\games\{5253F22E-D4B6-49B7-9106-28D9C5395F22}.exe:\$JJ\5253F22E-D4B6-49B7-9106-28D9C5395F22.exe";"Virus found Win32/Heur.dropper";"Infected"

I've run OTL following the posted instructions but it doesn't produce the Extras.txt file. I've also run HJT. The log files are posted below. I can't see that either scan looks at the D: partition.

Any help getting rid of this would be greatly appreciated.

Thank You.



The OTL.txt file contains:

OTL logfile created on: 3/14/2011 12:19:18 PM - Run 3
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Wendy.YOUR-27E1513D96\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

958.00 Mb Total Physical Memory | 214.00 Mb Available Physical Memory | 22.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 70.00% Paging File free
Paging file location(s): C:\pagefile.sys 1440 2880 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 225.36 Gb Total Space | 160.92 Gb Free Space | 71.40% Space Free | Partition Type: NTFS
Drive D: | 7.50 Gb Total Space | 1.65 Gb Free Space | 22.05% Space Free | Partition Type: FAT32

Computer Name: YOUR-27E1513D96 | User Name: Wendy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Wendy.YOUR-27E1513D96\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Real\realplayer\Update\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Soluto\SolutoService.exe (Soluto)
PRC - C:\Program Files\Soluto\Soluto.exe (Soluto)
PRC - C:\Program Files\AVG\AVG10\avgui.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Common Files\Portrait Displays\Shared\HookManager.exe (Portrait Displays Inc.)
PRC - C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe ()
PRC - C:\Program Files\Acer Display\eDisplay Management\dthtml.exe (Portrait Displays, Inc)
PRC - C:\Program Files\Common Files\Portrait Displays\Drivers\pdisrvc.exe (Portrait Displays, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Portrait Displays\Pivot Software\Floater.exe ()
PRC - C:\Program Files\Portrait Displays\Pivot Software\wpCtrl.exe ()
PRC - C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
PRC - C:\Program Files\Java\jre1.5.0\bin\jucheck.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Java\jre1.5.0\bin\jusched.exe (Sun Microsystems, Inc.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Wendy.YOUR-27E1513D96\My Documents\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchromebrowserrecordhelper.dll (RealNetworks, Inc.)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcr90.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcp90.dll (Microsoft Corporation)
MOD - C:\Program Files\Portrait Displays\Pivot Software\Winphook.dll ()


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – File not found
SRV - (AppMgmt) – File not found
SRV - (SolutoService) – C:\Program Files\Soluto\SolutoService.exe (Soluto)
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) – C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (DTSRVC) – C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe ()
SRV - (PdiService) – C:\Program Files\Common Files\Portrait Displays\Drivers\pdisrvc.exe (Portrait Displays, Inc.)
SRV - (CCALib8) – C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)


========== Driver Services (SafeList) ==========

DRV - (Soluto) – C:\WINDOWS\system32\DRIVERS\Soluto.sys (Soluto LTD.)
DRV - (Avgldx86) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgtdix) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSEH) – C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgmfx86) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) – C:\WINDOWS\system32\DRIVERS\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSShim) – C:\WINDOWS\system32\drivers\AVGIDSShim.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSDriver) – C:\WINDOWS\system32\drivers\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSFilter) – C:\WINDOWS\system32\drivers\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV - (PdiPorts) – C:\WINDOWS\system32\drivers\PdiPorts.sys (Portrait Displays, Inc.)
DRV - (Pivot) – C:\WINDOWS\system32\drivers\pivot.sys (Portrait Displays, Inc.)
DRV - (pivotmou) – C:\WINDOWS\system32\drivers\pivotmou.sys (Portrait Displays, Inc.)
DRV - (Ps2) – C:\WINDOWS\system32\drivers\PS2.sys (Hewlett-Packard Company)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (ftsata2) – C:\WINDOWS\system32\DRIVERS\ftsata2.sys (Promise Technology, Inc.)
DRV - (AmdK8) – C:\WINDOWS\system32\drivers\AmdK8.sys (Advanced Micro Devices)
DRV - (RTL8023xp) – C:\WINDOWS\system32\drivers\Rtlnicxp.sys (Realtek Semiconductor Corporation )
DRV - (smserial) – C:\WINDOWS\system32\drivers\smserial.sys (Motorola Inc.)
DRV - (rtl8139) Realtek RTL8139(A/B/C) – C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)
DRV - (bb-run) – C:\WINDOWS\system32\DRIVERS\bb-run.sys (Promise Technology, Inc.)
DRV - (crlscsi) – C:\WINDOWS\System32\drivers\crlscsi.sys (Corel Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…arm1=seconduser

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.sympatico.ca/
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.sympatico.ca/"
FF - prefs.js..extensions.enabledItems: {D6D05E6F-D5C1-4e03-8E33-73F92B05E262}:10.2
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:10.0.0.1178
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.2
FF - prefs.js..network.proxy.type: 0

FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/09/04 22:42:03 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG10\Firefox\ [2011/01/24 12:22:26 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/02/16 22:27:14 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/02/16 22:27:06 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/02/16 22:27:30 | 000,000,000 | —D | M]

[2010/12/31 18:37:19 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Application Data\Mozilla\Extensions
[2011/03/13 21:52:57 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Application Data\Mozilla\Firefox\Profiles\5a8x4pk8.default\extensions
[2011/03/13 21:52:57 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Application Data\Mozilla\Firefox\Profiles\5a8x4pk8.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/03/05 15:01:42 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2009/04/05 22:35:55 | 000,000,000 | —D | M] (SMART Notebook Extension) – C:\Program Files\Mozilla Firefox\extensions\{D6D05E6F-D5C1-4e03-8E33-73F92B05E262}
[2011/02/16 22:27:14 | 000,000,000 | —D | M] (RealPlayer Browser Record Plugin) – C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
[2011/01/24 12:22:26 | 000,000,000 | —D | M] (AVG Safe Search) – C:\PROGRAM FILES\AVG\AVG10\FIREFOX
[2010/12/30 23:00:24 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2009/11/06 11:37:19 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
[2005/12/05 23:31:00 | 000,114,688 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\npmozax.dll
[2009/11/06 11:37:20 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npMozCouponPrinter.dll

O1 HOSTS File: ([2004/08/04 15:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [DT ACR] C:\Program Files\Common Files\Portrait Displays\Shared\DT_startup.exe ()
O4 - HKLM..\Run: [HPBootOp] C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [PivotSoftware] C:\Program Files\Portrait Displays\Pivot Software\wpctrl.exe ()
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &Google Search - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Backward Links - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Cached Snapshot of Page - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O8 - Extra context menu item: Similar Pages - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Translate into English - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ()
O9 - Extra 'Tools' menuitem : Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ()
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\intu-tt2010 {97A0575E-2309-4e75-8509-B1F9390C4DE7} - C:\Program Files\TurboTax 2010\ic2010pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Program Files\Soluto\soluto.exe /userinit) - C:\Program Files\Soluto\soluto.exe (Soluto)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Wendy.YOUR-27E1513D96\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Wendy.YOUR-27E1513D96\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/10/07 08:09:40 | 000,000,050 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2001/07/28 07:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O33 - MountPoints2\{2d435b36-e506-11d9-9b78-e6b009352ae7}\Shell - "" = AutoRun
O33 - MountPoints2\{2d435b36-e506-11d9-9b78-e6b009352ae7}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{2d435b36-e506-11d9-9b78-e6b009352ae7}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync) - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart) - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.LEAD - C:\WINDOWS\System32\LCodcCMP.dll (LEAD Technologies, Inc.)
Drivers32: wave1 - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)
Drivers32: wave2 - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)

========== Files/Folders - Created Within 30 Days ==========

[2011/03/13 22:04:04 | 000,000,000 | —D | C] – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Application Data\Malwarebytes
[2011/03/13 22:03:54 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/03/13 22:03:37 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/03/13 22:02:33 | 000,000,000 | —D | C] – C:\Documents and Settings\Wendy.YOUR-27E1513D96\My Documents\Downloads
[2011/03/07 13:35:38 | 000,236,032 | —- | C] (CANON INC.) – C:\WINDOWS\System32\CNMLM9R.DLL
[2011/03/07 13:35:35 | 000,000,000 | -H-D | C] – C:\WINDOWS\System32\CanonIJ Uninstaller Information
[2011/03/07 13:35:35 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Canon JX510P series
[2011/03/07 13:35:31 | 000,178,176 | —- | C] (CANON INC.) – C:\WINDOWS\System32\CNMIU9R.DLL
[2011/03/07 13:35:17 | 000,000,000 | -H-D | C] – C:\Program Files\CanonBJ
[2011/03/06 23:41:54 | 000,000,000 | —D | C] – C:\Documents and Settings\Wendy.YOUR-27E1513D96\My Documents\TurboTax
[2011/03/06 20:59:52 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\TurboTax
[2011/03/06 20:59:35 | 000,000,000 | —D | C] – C:\Program Files\TurboTax 2010
[2011/02/24 18:57:28 | 000,051,144 | —- | C] (Soluto LTD.) – C:\WINDOWS\System32\drivers\Soluto.sys
[2011/02/24 18:57:15 | 000,000,000 | —D | C] – C:\Program Files\Soluto
[2011/02/24 18:57:15 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Soluto
[2011/02/24 18:55:45 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Soluto
[2011/02/18 10:37:19 | 000,012,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mouhid.sys
[2011/02/18 10:37:06 | 000,010,368 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hidusb.sys
[2011/02/16 22:27:18 | 000,000,000 | —D | C] – C:\Program Files\Common Files\xing shared
[2011/02/16 22:27:05 | 000,198,848 | —- | C] (RealNetworks, Inc.) – C:\WINDOWS\System32\rmoc3260.dll
[2011/02/16 22:26:55 | 000,006,656 | —- | C] (RealNetworks, Inc.) – C:\WINDOWS\System32\pndx5016.dll
[2011/02/16 22:26:55 | 000,005,632 | —- | C] (RealNetworks, Inc.) – C:\WINDOWS\System32\pndx5032.dll
[2011/02/16 22:26:54 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Real
[2011/02/16 22:26:14 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Real
[2011/02/16 22:20:39 | 000,602,464 | —- | C] (RealNetworks, Inc.) – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Desktop\RealPlayer.exe
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/03/14 12:20:00 | 000,000,422 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{1A14DDC3-D4C6-4955-A8DD-1C9C60364BFE}.job
[2011/03/14 12:08:20 | 000,000,286 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-3131796442-2609879388-2480220986-1010.job
[2011/03/14 12:08:20 | 000,000,278 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-3131796442-2609879388-2480220986-1010.job
[2011/03/14 11:35:05 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/03/14 09:57:25 | 108,637,145 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2011/03/13 22:03:55 | 000,000,795 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/03/13 21:53:52 | 000,000,248 | —- | M] () – C:\WINDOWS\System\hpsysdrv.dat
[2011/03/13 21:53:15 | 000,446,338 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/03/13 21:53:15 | 000,073,100 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/03/13 21:50:44 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/03/13 21:50:33 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/03/13 21:50:30 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/03/13 21:50:27 | 1005,113,344 | -HS- | M] () – C:\hiberfil.sys
[2011/03/13 21:38:51 | 000,006,674 | —- | M] () – C:\Documents and Settings\Wendy.YOUR-27E1513D96\My Documents\WP_pcAVGscan.csv
[2011/03/09 15:37:15 | 000,001,355 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/03/09 14:49:00 | 000,049,842 | —- | M] () – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Desktop\Orillia Deck Project Materials List - Final Pricing.pdf
[2011/03/07 09:25:32 | 000,358,544 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/03/06 20:59:52 | 000,001,662 | —- | M] () – C:\Documents and Settings\All Users\Desktop\TurboTax Canada 2010.lnk
[2011/03/05 14:49:35 | 000,002,501 | —- | M] () – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Desktop\Microsoft Word 2010.lnk
[2011/03/01 18:22:23 | 000,193,113 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\iavichjg.avm
[2011/02/28 18:20:00 | 000,000,322 | —- | M] () – C:\WINDOWS\tasks\Easy Internet Sign-up.job
[2011/02/26 12:00:03 | 000,173,347 | —- | M] () – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Desktop\Gawel v Meloche Monnex.pdf
[2011/02/26 11:59:47 | 000,708,258 | —- | M] () – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Desktop\Stewart v New Brunswick.pdf
[2011/02/24 18:59:50 | 000,000,098 | —- | M] () – C:\Documents and Settings\All Users\Application Data\Microsoft.SqlServer.Compact.351.32.bc
[2011/02/22 11:52:31 | 000,003,584 | —- | M] () – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/02/22 10:20:39 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/02/16 22:28:36 | 000,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2011/02/16 22:28:36 | 000,001,409 | —- | M] () – C:\WINDOWS\QTFont.for
[2011/02/16 22:27:24 | 000,000,747 | —- | M] () – C:\Documents and Settings\All Users\Desktop\RealPlayer.lnk
[2011/02/16 22:27:05 | 000,198,848 | —- | M] (RealNetworks, Inc.) – C:\WINDOWS\System32\rmoc3260.dll
[2011/02/16 22:26:55 | 000,006,656 | —- | M] (RealNetworks, Inc.) – C:\WINDOWS\System32\pndx5016.dll
[2011/02/16 22:26:55 | 000,005,632 | —- | M] (RealNetworks, Inc.) – C:\WINDOWS\System32\pndx5032.dll
[2011/02/16 22:26:54 | 000,272,896 | —- | M] (Progressive Networks) – C:\WINDOWS\System32\pncrt.dll
[2011/02/16 22:20:39 | 000,602,464 | —- | M] (RealNetworks, Inc.) – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Desktop\RealPlayer.exe
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/03/13 22:03:55 | 000,000,795 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/03/13 21:38:50 | 000,006,674 | —- | C] () – C:\Documents and Settings\Wendy.YOUR-27E1513D96\My Documents\WP_pcAVGscan.csv
[2011/03/09 14:49:00 | 000,049,842 | —- | C] () – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Desktop\Orillia Deck Project Materials List - Final Pricing.pdf
[2011/03/06 20:59:51 | 000,001,662 | —- | C] () – C:\Documents and Settings\All Users\Desktop\TurboTax Canada 2010.lnk
[2011/02/26 11:59:55 | 000,173,347 | —- | C] () – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Desktop\Gawel v Meloche Monnex.pdf
[2011/02/26 11:59:46 | 000,708,258 | —- | C] () – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Desktop\Stewart v New Brunswick.pdf
[2011/02/24 19:01:20 | 001,115,872 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2011/02/24 18:59:50 | 000,000,098 | —- | C] () – C:\Documents and Settings\All Users\Application Data\Microsoft.SqlServer.Compact.351.32.bc
[2011/02/22 11:52:31 | 000,003,584 | —- | C] () – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/02/16 22:28:36 | 000,054,156 | -H– | C] () – C:\WINDOWS\QTFont.qfn
[2011/02/16 22:28:36 | 000,001,409 | —- | C] () – C:\WINDOWS\QTFont.for
[2011/02/16 22:27:56 | 000,000,278 | —- | C] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-3131796442-2609879388-2480220986-1010.job
[2011/02/16 22:27:51 | 000,000,286 | —- | C] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-3131796442-2609879388-2480220986-1010.job
[2011/02/16 22:27:24 | 000,000,747 | —- | C] () – C:\Documents and Settings\All Users\Desktop\RealPlayer.lnk
[2010/12/31 16:12:13 | 001,371,436 | R— | C] () – C:\WINDOWS\System32\VBAR2132.DLL
[2010/12/31 12:18:29 | 000,002,304 | —- | C] () – C:\WINDOWS\System32\Machnm32.sys
[2010/12/31 10:36:58 | 000,000,016 | —- | C] () – C:\WINDOWS\System32\asdict.dat
[2010/12/31 10:36:58 | 000,000,004 | —- | C] () – C:\WINDOWS\System32\aspdict-en.dat
[2010/12/31 01:20:23 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\wsbl.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\phar_unmip.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\phar_histprot.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\ph_white.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\ph_summ.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\ph_black.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pcwords2.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pcwords.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_webproxy.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_video.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_tabloids.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_socialnetworks.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_searchengines.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_regionaltlds.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_pornography.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_onlineshop.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_onlinepay.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_onlinedating.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_news.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_im.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_illegal.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_hate.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_games.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_gambling.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_drugs.dat
[2010/12/30 23:06:25 | 000,118,784 | —- | C] () – C:\WINDOWS\System32\hpocnt05.dll
[2010/12/30 23:06:25 | 000,000,970 | —- | C] () – C:\WINDOWS\hpoio05.ini
[2010/12/30 23:06:25 | 000,000,065 | —- | C] () – C:\WINDOWS\opleinst.ini
[2010/12/30 19:54:55 | 000,168,557 | —- | C] () – C:\WINDOWS\hphins33.dat.temp
[2010/12/30 19:54:55 | 000,000,512 | —- | C] () – C:\WINDOWS\hphmdl33.dat.temp
[2010/12/30 19:50:48 | 000,000,156 | —- | C] () – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Application Data\wklnhst.dat
[2010/09/04 22:32:09 | 000,168,470 | —- | C] () – C:\WINDOWS\hphins33.dat
[2010/09/04 22:32:09 | 000,000,512 | —- | C] () – C:\WINDOWS\hphmdl33.dat
[2010/03/29 19:40:20 | 000,100,256 | —- | C] () – C:\Program Files\Common Files\LinkInstaller.exe
[2009/02/06 21:07:32 | 000,000,004 | —- | C] () – C:\Program Files\Common Files\Cvtaqlog.dat
[2008/11/12 15:24:59 | 000,000,100 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2007/11/30 11:02:09 | 000,001,891 | —- | C] () – C:\WINDOWS\mozver.dat
[2007/11/30 11:00:07 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2007/11/19 23:52:47 | 000,000,234 | —- | C] () – C:\WINDOWS\LEXSTAT.INI
[2007/01/31 15:50:32 | 000,913,408 | —- | C] () – C:\WINDOWS\System32\xreglib.dll
[2006/08/04 10:28:10 | 000,000,010 | —- | C] () – C:\WINDOWS\SIERRA.INI
[2006/05/19 07:10:50 | 000,000,214 | —- | C] () – C:\WINDOWS\HP_InstantSHareJPG.ini
[2006/05/19 07:09:03 | 000,000,206 | —- | C] () – C:\WINDOWS\HPGdiPlus.ini
[2006/04/18 23:00:00 | 000,000,227 | —- | C] () – C:\WINDOWS\HP_CounterReport_Update_HPSU.ini
[2006/04/18 22:59:49 | 000,000,214 | —- | C] () – C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2006/04/18 22:59:38 | 000,000,217 | —- | C] () – C:\WINDOWS\HP_IZClosingDiscErrorPatch.ini
[2006/04/18 22:57:46 | 000,000,221 | —- | C] () – C:\WINDOWS\HP_RedboxHprblog_HPSU.ini
[2005/11/25 13:24:10 | 000,000,000 | —- | C] () – C:\WINDOWS\longfile.INI
[2005/11/25 13:17:39 | 000,000,102 | —- | C] () – C:\WINDOWS\texture.ini
[2005/11/24 23:12:18 | 000,039,125 | —- | C] () – C:\WINDOWS\iccsigs.dat
[2005/10/07 08:36:45 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/10/07 08:13:47 | 000,118,842 | R— | C] () – C:\WINDOWS\HPCPCUninstaller-6.3.2.116-9972322.exe
[2005/10/07 08:12:37 | 000,013,543 | —- | C] () – C:\WINDOWS\System32\CHODDI.SYS
[2005/10/07 08:12:32 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\hpreg.dll
[2005/10/07 08:10:21 | 000,000,172 | —- | C] () – C:\WINDOWS\Quicken.ini
[2005/10/07 08:06:07 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/10/07 08:01:42 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2005/10/07 08:01:42 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2005/10/07 08:01:42 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2005/10/07 08:01:42 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2005/10/07 08:01:42 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2005/10/07 08:01:41 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2005/10/07 07:56:41 | 000,000,056 | —- | C] () – C:\WINDOWS\WININIT.INI
[2005/10/07 07:51:25 | 000,112,873 | —- | C] () – C:\WINDOWS\hpoins07.dat
[2005/10/07 07:51:25 | 000,021,124 | —- | C] () – C:\WINDOWS\hpomdl07.dat
[2005/10/07 07:46:50 | 000,080,418 | —- | C] () – C:\WINDOWS\HPHins08.dat
[2005/10/07 07:46:50 | 000,004,011 | —- | C] () – C:\WINDOWS\hphmdl08.dat
[2005/10/07 07:44:51 | 000,072,881 | —- | C] () – C:\WINDOWS\hpiins01.dat
[2005/10/07 07:44:51 | 000,000,000 | —- | C] () – C:\WINDOWS\hpimdl01.dat
[2005/10/07 07:43:58 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2005/10/07 07:41:38 | 000,065,536 | —- | C] () – C:\WINDOWS\sm56spn.dll
[2005/10/07 07:41:38 | 000,065,536 | —- | C] () – C:\WINDOWS\sm56spn(2).dll
[2005/10/07 07:41:38 | 000,065,536 | —- | C] () – C:\WINDOWS\sm56itl.dll
[2005/10/07 07:41:38 | 000,065,536 | —- | C] () – C:\WINDOWS\sm56itl(2).dll
[2005/10/07 07:41:38 | 000,065,536 | —- | C] () – C:\WINDOWS\sm56ger.dll
[2005/10/07 07:41:38 | 000,065,536 | —- | C] () – C:\WINDOWS\sm56ger(2).dll
[2005/10/07 07:41:38 | 000,065,536 | —- | C] () – C:\WINDOWS\sm56fra.dll
[2005/10/07 07:41:38 | 000,065,536 | —- | C] () – C:\WINDOWS\sm56fra(2).dll
[2005/10/07 07:41:38 | 000,065,536 | —- | C] () – C:\WINDOWS\sm56eng.dll
[2005/10/07 07:41:38 | 000,065,536 | —- | C] () – C:\WINDOWS\sm56eng(2).dll
[2005/10/07 07:41:38 | 000,065,536 | —- | C] () – C:\WINDOWS\sm56brz.dll
[2005/10/07 07:41:38 | 000,065,536 | —- | C] () – C:\WINDOWS\sm56brz(2).dll
[2005/10/07 07:41:38 | 000,049,152 | —- | C] () – C:\WINDOWS\sm56jpn.dll
[2005/10/07 07:41:38 | 000,049,152 | —- | C] () – C:\WINDOWS\sm56jpn(2).dll
[2005/10/07 07:41:38 | 000,045,056 | —- | C] () – C:\WINDOWS\sm56cht.dll
[2005/10/07 07:41:38 | 000,045,056 | —- | C] () – C:\WINDOWS\sm56cht(2).dll
[2005/10/07 07:41:38 | 000,045,056 | —- | C] () – C:\WINDOWS\sm56chs.dll
[2005/10/07 07:41:38 | 000,045,056 | —- | C] () – C:\WINDOWS\sm56chs(2).dll
[2005/10/07 07:40:36 | 000,001,040 | —- | C] () – C:\WINDOWS\System32\drivers\alcxinit.dat
[2005/10/07 07:40:34 | 000,026,625 | —- | C] () – C:\WINDOWS\System32\sxsttsu.dll
[2005/10/07 07:40:14 | 000,094,574 | —- | C] () – C:\WINDOWS\System32\atiicdxx.dat
[2005/10/07 07:31:11 | 000,000,780 | —- | C] () – C:\WINDOWS\orun32.ini
[2005/10/07 07:27:48 | 000,323,584 | —- | C] () – C:\WINDOWS\System32\pythoncom22.dll
[2005/10/07 07:27:48 | 000,094,208 | —- | C] () – C:\WINDOWS\System32\pywintypes22.dll
[2005/10/07 07:27:30 | 000,016,896 | —- | C] () – C:\WINDOWS\System32\bcbmm.dll
[2005/07/07 16:07:24 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2005/06/25 02:29:32 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2005/06/25 01:43:44 | 000,446,338 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2005/06/25 01:43:44 | 000,073,100 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2005/06/25 01:42:06 | 000,358,544 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2005/06/25 01:31:46 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2005/06/25 01:30:20 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2005/05/10 02:52:32 | 000,022,396 | —- | C] () – C:\WINDOWS\System32\drivers\USBkey.sys
[2004/08/04 15:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/04 08:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/04 08:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/04 08:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/04 08:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/04 08:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/04 08:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/08/04 08:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2004/06/16 01:38:02 | 000,000,537 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2001/08/23 19:12:28 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2001/08/23 19:11:02 | 000,004,490 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2001/07/07 01:30:00 | 000,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini

========== LOP Check ==========

[2007/12/01 21:18:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Avery
[2011/01/24 14:00:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG
[2011/03/13 21:44:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG10
[2010/03/30 18:01:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Bell
[2008/03/06 14:37:03 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2011/01/24 12:24:06 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2011/01/24 12:21:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2010/10/03 09:15:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Radialpoint
[2009/04/05 23:27:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SMART Technologies
[2011/02/24 19:06:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Soluto
[2011/01/24 23:58:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2011/01/24 13:58:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Application Data\AVG
[2011/01/24 12:28:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Application Data\AVG10
[2010/12/30 19:50:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Application Data\Bell
[2010/12/30 19:51:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Application Data\Canon
[2010/12/31 15:22:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Application Data\DisplayTune
[2010/12/30 19:51:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Application Data\FileMaker
[2010/12/30 19:51:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Application Data\InterVideo
[2010/12/30 19:51:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Application Data\Leadertech
[2010/12/30 19:51:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Application Data\PDF reDirect
[2010/12/30 19:51:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Application Data\QuickScan
[2005/10/07 08:11:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Application Data\SampleView
[2010/12/30 19:51:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Application Data\SMART Technologies
[2010/12/30 19:51:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Application Data\SMART Technologies Inc
[2010/12/30 19:51:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Application Data\Template
[2010/12/30 19:51:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Application Data\WinBatch
[2010/12/30 19:51:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Application Data\Xerox
[2011/02/28 18:20:00 | 000,000,322 | —- | M] () – C:\WINDOWS\Tasks\Easy Internet Sign-up.job
[2011/03/14 12:20:00 | 000,000,422 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{1A14DDC3-D4C6-4955-A8DD-1C9C60364BFE}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2005/10/07 08:09:40 | 000,000,050 | —- | M] () – C:\AUTOEXEC.BAT
[2011/01/24 11:59:49 | 000,041,323 | —- | M] () – C:\bdlog.txt
[2010/12/30 18:45:33 | 000,000,213 | RHS- | M] () – C:\BOOT.BAK
[2010/12/30 19:07:51 | 000,000,283 | RHS- | M] () – C:\boot.ini
[2004/08/04 08:00:00 | 000,260,272 | RHS- | M] () – C:\cmldr
[2005/06/25 01:32:00 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2007/04/01 22:46:13 | 000,030,208 | —- | M] () – C:\Fax Lease agreement KingstonJosanne Parret 2007.doc
[2011/03/13 21:50:27 | 1005,113,344 | -HS- | M] () – C:\hiberfil.sys
[2005/06/25 01:32:00 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/05/11 19:31:24 | 000,000,000 | —- | M] () – C:\Log.txt
[2005/06/25 01:32:00 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/04 08:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2010/12/30 21:12:21 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/03/13 21:50:21 | 1509,949,440 | -HS- | M] () – C:\pagefile.sys
[2010/12/31 12:17:58 | 000,000,173 | —- | M] () – C:\pdisdk.log
[2010/12/31 12:18:53 | 000,000,184 | —- | M] () – C:\pivot.log
[2007/04/30 07:10:58 | 000,001,990 | —- | M] () – C:\xPos.txt
[1 C:\*.tmp files -> C:\*.tmp -> ]

< %systemroot%\Fonts\*.com >
[2006/04/18 16:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 15:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 16:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 15:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >
[2005/05/12 09:36:48 | 000,012,288 | —- | M] (Hewlett-Packard Co.) – C:\WINDOWS\Fonts\RandFont.dll

< %systemroot%\Fonts\*.ini >
[2005/06/25 01:31:38 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/10/07 06:00:00 | 000,027,136 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD9R.DLL
[2008/10/07 06:00:00 | 000,069,632 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP9R.DLL
[2008/07/06 08:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2009/04/16 15:08:20 | 000,312,832 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpfpp70v.dll
[2003/06/19 03:31:48 | 000,018,944 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 06:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2005/06/24 18:25:14 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2005/06/24 18:25:14 | 000,634,880 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2005/06/24 18:25:14 | 000,884,736 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2010/12/30 22:50:18 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2005/11/26 00:50:59 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2005/06/25 01:42:40 | 000,000,079 | —- | M] () – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2006/11/20 10:18:28 | 000,077,824 | —- | M] (WinTronTechnologies) – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Desktop\conversion.exe
[2011/02/16 22:20:39 | 000,602,464 | —- | M] (RealNetworks, Inc.) – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Desktop\RealPlayer.exe

< %PROGRAMFILES%\Common Files\*.* >
[2009/02/06 21:07:32 | 000,000,004 | —- | M] () – C:\Program Files\Common Files\Cvtaqlog.dat
[2010/03/29 19:40:20 | 000,100,256 | —- | M] () – C:\Program Files\Common Files\LinkInstaller.exe

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-03-09 19:37:48

========== Alternate Data Streams ==========

@Alternate Data Stream - 146 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4

< End of report >


Here is the HJT log:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:24:35 PM, on 3/14/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Soluto\soluto.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AVG\AVG10\avgwdsvc.exe
C:\Program Files\Common Files\Portrait Displays\Shared\dtsrvc.exe
C:\Program Files\Common Files\Portrait Displays\Drivers\pdisrvc.exe
C:\Program Files\Soluto\SolutoService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Portrait Displays\Pivot Software\wpctrl.exe
C:\Program Files\AVG\AVG10\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Portrait Displays\Pivot Software\floater.exe
C:\Program Files\Acer Display\eDisplay Management\DTHtml.exe
C:\Program Files\Common Files\Portrait Displays\Shared\HookManager.exe
C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
C:\WINDOWS\system32\wuauclt.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
c:\windows\system\hpsysdrv.exe
C:\Program Files\Java\jre1.5.0\bin\jusched.exe
C:\Program Files\Java\jre1.5.0\bin\jucheck.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\program files\real\realplayer\update\realsched.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\AVG\AVG10\avgui.exe
C:\Documents and Settings\Wendy.YOUR-27E1513D96\My Documents\Downloads\OTL.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\Wendy.YOUR-27E1513D96\My Documents\Downloads\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…arm1=seconduser
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sympatico.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…arm1=seconduser
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…arm1=seconduser
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\Program Files\Soluto\soluto.exe /userinit
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MI1933~1\Office14\URLREDIR.DLL
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [PivotSoftware] "C:\Program Files\Portrait Displays\Pivot Software\wpctrl.exe"
O4 - HKLM\..\Run: [DT ACR] C:\Program Files\Common Files\Portrait Displays\Shared\DT_startup.exe -ACR
O4 - HKLM\..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MI1933~1\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: intu-tt2010 - {97A0575E-2309-4E75-8509-B1F9390C4DE7} - C:\Program Files\TurboTax 2010\ic2010pp.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10\avgwdsvc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Portrait Displays Display Tune Service (DTSRVC) - Unknown owner - C:\Program Files\Common Files\Portrait Displays\Shared\dtsrvc.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Portrait Displays SDK Service (PdiService) - Portrait Displays, Inc. - C:\Program Files\Common Files\Portrait Displays\Drivers\pdisrvc.exe
O23 - Service: Soluto PCGenome Core Service (SolutoService) - Soluto - C:\Program Files\Soluto\SolutoService.exe

–
End of file - 10125 bytes
Hello and Welcome to the forums!

My name is Carolyn and I'll be glad to help you with your computer problems.

Please do not run any other tool untill instructed to do so!
Please reply to this thread, do not start another!
Please tell me about any problems that have occurred during the fix.
Please tell me of any other symptoms you may be having as these can help also.
Please try as much as possible not to run anything while executing a fix.

If you follow these instructions, everything should go smoothly.

Step 1

ESET online scannner

Note: You can use either Internet Explorer or Mozilla FireFox for this scan.

Note: If you are using Windows Vista or Windows 7, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

  • Hold down Control then click on the following link to open a new window to ESET online scannner
  • Then click on: [external image: Posted Image]

    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.

  • Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: [external image: Posted Image]
  • The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on: [external image: Posted Image]
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.

—————————————————–

Step 2

[external image: Posted Image]
Download DDS and save it to your desktop from here or here or here.
Disable any script blocker, and then double click dds.scr to run the tool.
  • When done, DDS will open two (2) logs:
    • DDS.txt
    • Attach.txt
  • Save both reports to your desktop.

—————————————————–

Please include the following logs in your next reply (post all logs as text, no attachments please):
  • DDS.txt
  • Attach.txt
  • log.txt
Hi Carolyn,

AVG picked up the infection but, when I tried deleting the infected files through AVG and rebooting the video went to some minimal VGA 4 colour scheme and could not be changed. I reverted the system back to the restore point from March 12.

I then ran MalwareBytes but found nothing.

I've run ESET and DDS today the log results are:

ESET log

ESETSmartInstaller@High as CAB hook log:
OnlineScanner.ocx - delete file error:The process cannot access the file because it is being used by another process.

OnlineScanner.ocx - copy file error :The process cannot access the file because it is being used by another process.

OnlineScanner.ocx - registred OK
# version=7
# iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
# OnlineScanner.ocx=1.0.0.6425
# api_version=3.0.2
# EOSSerial=d6d29977efefc64fb1ec04715b76b79d
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2011-03-16 06:39:13
# local_time=2011-03-16 02:39:13 (-0500, Eastern Daylight Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=512 16777215 100 0 0 0 0 0
# compatibility_mode=1032 16777189 100 96 0 43347898 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=230742
# found=11
# cleaned=0
# scan_time=9002
C:\Old PC C Drive recovery\Cdrive loose Files\Info_sex4.cab Win32/Dialer.T trojan (unable to clean) 00000000000000000000000000000000 I
C:\Program Files\Java\jre1.5.0\lib\rt.jar a variant of Java/Agent.AG trojan (unable to clean) 00000000000000000000000000000000 I
C:\Program Files\Java\jre1.5.0_06\lib\rt.jar a variant of Java/Agent.AG trojan (unable to clean) 00000000000000000000000000000000 I
C:\Program Files\Java\jre1.5.0_10\lib\rt.jar a variant of Java/Agent.AG trojan (unable to clean) 00000000000000000000000000000000 I
C:\Program Files\Java\jre1.5.0_11\lib\rt.jar a variant of Java/Agent.AG trojan (unable to clean) 00000000000000000000000000000000 I
C:\Program Files\Java\jre1.6.0_01\lib\rt.jar a variant of Java/Agent.AG trojan (unable to clean) 00000000000000000000000000000000 I
C:\Program Files\Java\jre1.6.0_03\lib\rt.jar a variant of Java/Agent.AG trojan (unable to clean) 00000000000000000000000000000000 I
C:\Program Files\Java\jre1.6.0_05\lib\rt.jar a variant of Java/Agent.AG trojan (unable to clean) 00000000000000000000000000000000 I
C:\Program Files\Java\jre1.6.0_07\lib\rt.jar a variant of Java/Agent.AG trojan (unable to clean) 00000000000000000000000000000000 I
C:\Program Files\Java\jre6\lib\rt.jar a variant of Java/Agent.AG trojan (unable to clean) 00000000000000000000000000000000 I
D:\I386\Apps\APP15351\src\HPSummer2005.exe a variant of Win32/AdInstaller application (unable to clean) 00000000000000000000000000000000 I


The DDS results were:

.
DDS (Ver_11-03-05.01) - NTFSx86
Run by [removed] at 14:53:02.57 on Wed 03/16/2011
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.958.284 [GMT -4:00]
.
AV: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\AVG\AVG10\avgwdsvc.exe
C:\Program Files\Common Files\Portrait Displays\Shared\dtsrvc.exe
C:\Program Files\Common Files\Portrait Displays\Drivers\pdisrvc.exe
C:\Program Files\Soluto\SolutoService.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Soluto\soluto.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Portrait Displays\Pivot Software\wpctrl.exe
C:\Program Files\AVG\AVG10\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Acer Display\eDisplay Management\DTHtml.exe
C:\Program Files\Portrait Displays\Pivot Software\floater.exe
C:\Program Files\Common Files\Portrait Displays\Shared\HookManager.exe
C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
C:\WINDOWS\system32\wuauclt.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
c:\windows\system\hpsysdrv.exe
C:\Program Files\Java\jre1.5.0\bin\jusched.exe
C:\Program Files\Java\jre1.5.0\bin\jucheck.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\program files\real\realplayer\update\realsched.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\AVG\AVG10\avgui.exe
C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\Program Files\AVG\AVG10\avgnsx.exe
C:\Program Files\AVG\AVG10\avgchsvx.exe
C:\Program Files\AVG\AVG10\avgrsx.exe
C:\Program Files\AVG\AVG10\avgcsrvx.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Wendy.YOUR-27E1513D96\Desktop\dds.scr
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.sympatico.ca/
uSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_CA&c=Q405&bd=pavilion&pf=desktop&parm1=seconduser
mStart Page = about:blank
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_CA&c=Q405&bd=pavilion&pf=desktop&parm1=seconduser
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
mSearchAssistant = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_CA&c=Q405&bd=pavilion&pf=desktop&parm1=seconduser
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn1\yt.dll
mWinlogon: Userinit=c:\windows\system32\userinit.exe,c:\program files\soluto\soluto.exe /userinit
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn1\yt.dll
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg10\avgssie.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar1.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\mi1933~1\office14\URLREDIR.DLL
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn1\YTSingleInstance.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar1.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn1\yt.dll
EB: HP Smart Web Printing: {555d4d79-4bd2-4094-a395-cfc534424a05} - c:\program files\hp\digital imaging\smart web printing\hpswp_bho.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [HPBootOp] "c:\program files\hewlett-packard\hp boot optimizer\HPBootOp.exe" /run
mRun: [PivotSoftware] "c:\program files\portrait displays\pivot software\wpctrl.exe"
mRun: [DT ACR] c:\program files\common files\portrait displays\shared\DT_startup.exe -ACR
mRun: [AVG_TRAY] c:\program files\avg\avg10\avgtray.exe
IE: &Google Search - c:\program files\google\GoogleToolbar1.dll/cmsearch.html
IE: Backward Links - c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\google\GoogleToolbar1.dll/cmcache.html
IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\mi1933~1\office14\ONBttnIE.dll/105
IE: Similar Pages - c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate into English - c:\program files\google\GoogleToolbar1.dll/cmtrans.html
IE: {E2D4D26B-0180-43a4-B05F-462D6D54C789} - c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\iebutton\support.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
Handler: intu-tt2010 - {97A0575E-2309-4e75-8509-B1F9390C4DE7} - c:\program files\turbotax 2010\ic2010pp.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg10\avgpp.dll
Notify: AtiExtEvent - Ati2evxx.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\docume~1\wendy~1.you\applic~1\mozilla\firefox\profiles\5a8x4pk8.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.sympatico.ca/
FF - prefs.js: network.proxy.type - 0
FF - component: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\firefox\ext\components\nprpffbrowserrecordext.dll
FF - component: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\firefox\ext\components\nprpffbrowserrecordlegacyext.dll
FF - component: c:\program files\avg\avg10\firefox\components\avgssff.dll
FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
FF - plugin: c:\progra~1\mi1933~1\office14\NPAUTHZ.DLL
FF - plugin: c:\progra~1\mi1933~1\office14\NPSPWRAP.DLL
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npmozax.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npMozCouponPrinter.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - Ext: SMART Notebook Extension: {D6D05E6F-D5C1-4e03-8E33-73F92B05E262} - c:\program files\mozilla firefox\extensions\{D6D05E6F-D5C1-4e03-8E33-73F92B05E262}
FF - Ext: Java Quick Starter: [removed] - c:\program files\java\jre6\lib\deploy\jqs\ff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
FF - Ext: AVG Safe Search: {3f963a5b-e555-4543-90e2-c3908898db71} - c:\program files\avg\avg10\Firefox
FF - Ext: RealPlayer Browser Record Plugin: {ABDE892B-13A8-4d1b-88E6-365A6E755758} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\firefox\Ext
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2010-9-13 25680]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2010-9-7 26064]
R0 Soluto;Soluto;c:\windows\system32\drivers\Soluto.sys [2011-2-24 51144]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2010-12-8 251728]
R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2010-9-7 34384]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2010-11-12 299984]
R1 crlscsi;crlscsi;c:\windows\system32\drivers\crlscsi.sys [2010-12-31 6144]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg10\identity protection\agent\bin\AVGIDSAgent.exe [2011-1-6 6128720]
R2 avgwd;AVG WatchDog;c:\program files\avg\avg10\avgwdsvc.exe [2010-10-22 265400]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2010-8-3 123472]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2010-8-3 30288]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2010-8-3 26192]
S3 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-2-7 135664]
S3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000]
.
=============== Created Last 30 ================
.
2011-03-16 15:10:17 ——– d—–w- c:\program files\ESET
2011-03-14 02:04:04 ——– d—–w- c:\docume~1\wendy~1.you\applic~1\Malwarebytes
2011-03-14 02:03:54 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-03-14 02:03:37 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-03-14 01:53:15 4900 —-a-w- c:\windows\system32\PerfStringBackup.TMP
2011-03-14 01:48:47 ——– d—–w- c:\windows\system32\wbem\repository\FS
2011-03-14 01:48:47 ——– d—–w- c:\windows\system32\wbem\Repository
2011-03-07 17:35:39 69632 —-a-w- c:\windows\system32\spool\prtprocs\w32x86\CNMPP9R.DLL
2011-03-07 17:35:39 27136 —-a-w- c:\windows\system32\spool\prtprocs\w32x86\CNMPD9R.DLL
2011-03-07 17:35:38 236032 —-a-w- c:\windows\system32\CNMLM9R.DLL
2011-03-07 17:35:31 178176 —-a-w- c:\windows\system32\CNMIU9R.DLL
2011-03-07 00:59:35 ——– d—–w- c:\program files\TurboTax 2010
2011-02-24 22:57:28 51144 —-a-w- c:\windows\system32\drivers\Soluto.sys
2011-02-24 22:57:15 ——– d—–w- c:\program files\Soluto
2011-02-24 22:55:45 ——– d—–w- c:\docume~1\alluse~1\applic~1\Soluto
2011-02-18 14:37:19 12160 —-a-w- c:\windows\system32\drivers\mouhid.sys
2011-02-18 14:37:19 12160 —-a-w- c:\windows\system32\dllcache\mouhid.sys
2011-02-18 14:37:06 10368 —-a-w- c:\windows\system32\drivers\hidusb.sys
2011-02-18 14:37:06 10368 —-a-w- c:\windows\system32\dllcache\hidusb.sys
2011-02-17 02:28:36 1409 —-a-w- c:\windows\QTFont.for
2011-02-17 02:27:30 11776 —-a-w- c:\program files\mozilla firefox\plugins\nprjplug.dll
2011-02-17 02:27:18 ——– d—–w- c:\program files\common files\xing shared
2011-02-17 02:27:05 150712 —-a-w- c:\program files\mozilla firefox\plugins\nppl3260.dll
2011-02-17 02:26:58 100864 —-a-w- c:\program files\mozilla firefox\plugins\nprpjplug.dll
.
==================== Find3M ====================
.
2011-02-09 13:53:52 270848 —-a-w- c:\windows\system32\sbe.dll
2011-02-09 13:53:52 186880 —-a-w- c:\windows\system32\encdec.dll
2011-02-02 07:58:35 2067456 —-a-w- c:\windows\system32\mstscax.dll
2011-01-27 11:57:06 677888 —-a-w- c:\windows\system32\mstsc.exe
2011-01-21 14:44:37 439296 —-a-w- c:\windows\system32\shimgvw.dll
2011-01-07 14:09:02 290048 —-a-w- c:\windows\system32\atmfd.dll
2010-12-31 16:18:41 62009 —-a-w- c:\windows\system32\wpfb_ati2dvag.dll
2010-12-31 13:10:33 1854976 —-a-w- c:\windows\system32\win32k.sys
2010-12-31 03:00:22 73728 —-a-w- c:\windows\system32\javacpl.cpl
2010-12-31 03:00:21 472808 —-a-w- c:\windows\system32\deployJava1.dll
2010-12-31 01:17:27 61440 —-a-w- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\modemutil.dll
2010-12-31 01:17:27 45056 —-a-w- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\uninstallui\eHelpSetup.exe
2010-12-31 01:17:27 44032 —-a-w- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\scripts\devcon.exe
2010-12-31 01:17:27 40960 —-a-w- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\ScDmi.dll
2010-12-31 01:17:27 32768 —-a-w- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\uploadHSC.dll
2010-12-31 01:17:27 32768 —-a-w- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\Scom.dll
2010-12-31 01:17:27 287310 —-a-w- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\HPBasicDetection.dll
2010-12-31 01:17:27 163840 —-a-w- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\modemcheck.dll
2010-12-22 12:34:28 301568 —-a-w- c:\windows\system32\kerberos.dll
2010-12-20 23:59:20 916480 —-a-w- c:\windows\system32\wininet.dll
2010-12-20 23:59:19 43520 —-a-w- c:\windows\system32\licmgr10.dll
2010-12-20 23:59:19 1469440 —-a-w- c:\windows\system32\inetcpl.cpl
2010-12-20 17:26:00 730112 —-a-w- c:\windows\system32\lsasrv.dll
2010-12-20 12:55:26 385024 —-a-w- c:\windows\system32\html.iec
2010-03-29 23:40:20 100256 —-a-w- c:\program files\common files\LinkInstaller.exe
.
============= FINISH: 14:54:44.68 ===============

Attach.txt
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_11-03-05.01)
.
Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume2
Install Date: 12/30/2010 5:46:19 PM
System Uptime: 3/16/2011 9:40:52 AM (5 hours ago)
.
Motherboard: ASUSTek Computer INC. | | Amberine M
Processor: AMD Athlon™ 64 Processor 3500+ | Socket 939 | 2188/200mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 225 GiB total, 160.525 GiB free.
D: is FIXED (FAT32) - 8 GiB total, 1.653 GiB free.
E: is CDROM ()
F: is CDROM ()
G: is Removable
H: is Removable
I: is Removable
J: is Removable
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP1: 12/30/2010 6:14:43 PM - Removed Norton Security Center
RP2: 12/30/2010 6:32:38 PM - Software Distribution Service 3.0
RP3: 12/30/2010 6:39:42 PM - Unsigned printer driver HP Deskjet D1600 series installed.
RP4: 12/30/2010 6:58:28 PM - Removed WebReg
RP5: 12/30/2010 6:59:26 PM - Removed BufferChm
RP6: 12/30/2010 7:00:50 PM - Removed TrayApp
RP7: 12/30/2010 7:01:55 PM - Removed Status
RP8: 12/30/2010 7:03:16 PM - Removed SolutionCenter
RP9: 12/30/2010 7:04:00 PM - Removed HPProductAssistant
RP10: 12/30/2010 7:07:17 PM - Removed HP Software Update
RP11: 12/30/2010 7:48:29 PM - Software Distribution Service 3.0
RP12: 12/30/2010 7:52:28 PM - Installed Windows Internet Explorer 8.
RP13: 12/30/2010 7:53:23 PM - Software Distribution Service 3.0
RP14: 12/30/2010 8:11:08 PM - Installed Windows XP Service Pack 3.
RP15: 12/30/2010 8:20:56 PM - Installed Windows XP KB951072-v2.
RP16: 12/30/2010 8:36:34 PM - Restore Operation
RP17: 12/30/2010 9:27:16 PM - Pre SP3
RP18: 12/30/2010 9:44:12 PM - Installed Windows XP Service Pack 3.
RP19: 12/30/2010 9:53:46 PM - Installed Windows XP KB951072-v2.
RP20: 12/30/2010 10:00:10 PM - Installed Java™ 6 Update 22
RP21: 12/30/2010 10:10:21 PM - Unsigned printer driver HP OfficeJet Series 700 Prin installed.
RP22: 12/30/2010 10:18:39 PM - Unsigned printer driver HP OfficeJet Series 700 Prin installed.
RP23: 12/30/2010 11:14:47 PM - Installed Microsoft Office Home and Student 2010
RP24: 12/31/2010 3:00:35 AM - Software Distribution Service 3.0
RP25: 12/31/2010 11:16:45 AM - Installed Acer eDisplay Management
RP26: 12/31/2010 11:16:49 AM - Installed Acer eDisplay Management
RP27: 12/31/2010 11:17:29 AM - Installed SDK
RP28: 12/31/2010 11:18:24 AM - Installed Pivot Software
RP29: 12/31/2010 11:18:27 AM - Installed Pivot Software
RP30: 12/31/2010 11:33:23 AM - Software Distribution Service 3.0
RP31: 12/31/2010 2:31:30 PM - Software Distribution Service 3.0
RP32: 12/31/2010 5:53:31 PM - Configured Acer eDisplay Management
RP33: 12/31/2010 5:53:35 PM - Configured Acer eDisplay Management
RP34: 1/1/2011 8:56:33 PM - System Checkpoint
RP35: 1/3/2011 3:56:56 PM - System Checkpoint
RP36: 1/4/2011 5:03:52 PM - System Checkpoint
RP37: 1/5/2011 5:11:53 PM - System Checkpoint
RP38: 1/6/2011 12:41:14 AM - Software Distribution Service 3.0
RP39: 1/6/2011 10:12:57 AM - Software Distribution Service 3.0
RP40: 1/6/2011 8:01:15 PM - Printer Driver Microsoft XPS Document Writer Installed
RP41: 1/7/2011 8:06:59 PM - System Checkpoint
RP42: 1/8/2011 9:12:22 AM - Software Distribution Service 3.0
RP43: 1/9/2011 10:18:37 AM - System Checkpoint
RP44: 1/10/2011 10:23:36 AM - System Checkpoint
RP45: 1/11/2011 11:10:20 AM - System Checkpoint
RP46: 1/12/2011 11:45:12 AM - System Checkpoint
RP47: 1/12/2011 11:20:50 PM - Software Distribution Service 3.0
RP48: 1/13/2011 11:27:41 PM - System Checkpoint
RP49: 1/15/2011 10:05:51 AM - System Checkpoint
RP50: 1/16/2011 10:16:44 AM - System Checkpoint
RP51: 1/17/2011 10:17:30 AM - System Checkpoint
RP52: 1/18/2011 1:35:54 PM - System Checkpoint
RP53: 1/19/2011 2:35:13 PM - System Checkpoint
RP54: 1/20/2011 3:16:42 PM - System Checkpoint
RP55: 1/21/2011 4:10:06 PM - System Checkpoint
RP56: 1/23/2011 12:25:59 PM - System Checkpoint
RP57: 1/24/2011 11:21:27 AM - Installed Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
RP58: 1/24/2011 11:21:39 AM - Installed AVG 2011
RP59: 1/24/2011 11:22:00 AM - Installed AVG 2011
RP60: 1/25/2011 12:10:16 PM - System Checkpoint
RP61: 1/26/2011 3:00:20 AM - Software Distribution Service 3.0
RP62: 1/26/2011 12:17:09 PM - Software Distribution Service 3.0
RP63: 1/26/2011 10:37:51 PM - Software Distribution Service 3.0
RP64: 1/30/2011 2:59:06 PM - System Checkpoint
RP65: 1/31/2011 3:08:36 PM - System Checkpoint
RP66: 2/1/2011 10:30:33 PM - System Checkpoint
RP67: 2/2/2011 11:20:05 PM - System Checkpoint
RP68: 2/3/2011 11:39:01 PM - System Checkpoint
RP69: 2/4/2011 11:57:01 PM - System Checkpoint
RP70: 2/6/2011 8:51:17 AM - System Checkpoint
RP71: 2/7/2011 8:59:04 AM - System Checkpoint
RP72: 2/8/2011 10:41:06 AM - System Checkpoint
RP73: 2/9/2011 10:56:21 AM - System Checkpoint
RP74: 2/9/2011 1:47:43 PM - Software Distribution Service 3.0
RP75: 2/12/2011 11:37:05 AM - System Checkpoint
RP76: 2/14/2011 11:17:26 AM - System Checkpoint
RP77: 2/15/2011 12:02:21 PM - System Checkpoint
RP78: 2/16/2011 12:53:17 PM - System Checkpoint
RP79: 2/17/2011 7:40:10 PM - System Checkpoint
RP80: 2/18/2011 8:35:13 PM - System Checkpoint
RP81: 2/19/2011 9:12:41 PM - System Checkpoint
RP82: 2/22/2011 10:18:32 AM - System Checkpoint
RP83: 2/23/2011 10:49:00 AM - System Checkpoint
RP84: 2/24/2011 11:32:24 AM - System Checkpoint
RP85: 2/24/2011 5:56:08 PM - Soluto
RP86: 2/25/2011 6:44:45 PM - System Checkpoint
RP87: 2/27/2011 7:13:06 PM - System Checkpoint
RP88: 2/28/2011 7:36:45 PM - System Checkpoint
RP89: 3/1/2011 8:23:43 PM - System Checkpoint
RP90: 3/2/2011 9:03:11 PM - System Checkpoint
RP91: 3/3/2011 9:58:27 PM - System Checkpoint
RP92: 3/4/2011 10:12:15 PM - System Checkpoint
RP93: 3/6/2011 11:12:18 AM - System Checkpoint
RP94: 3/6/2011 7:59:33 PM - Installed TurboTax 2010.
RP95: 3/7/2011 8:47:03 PM - System Checkpoint
RP96: 3/8/2011 8:57:43 PM - System Checkpoint
RP97: 3/9/2011 2:34:49 PM - Software Distribution Service 3.0
RP98: 3/10/2011 5:49:57 PM - System Checkpoint
RP99: 3/11/2011 5:54:40 PM - System Checkpoint
RP100: 3/12/2011 5:58:01 PM - System Checkpoint
RP101: 3/13/2011 8:19:53 PM - System Checkpoint
RP102: 3/13/2011 9:47:48 PM - Restore Operation
RP103: 3/14/2011 12:19:45 PM - OTL Restore Point
RP104: 3/15/2011 1:00:46 PM - System Checkpoint
RP105: 3/15/2011 11:43:04 PM - Software Distribution Service 3.0
.
==== Installed Programs ======================
.
32 Bit HP CIO Components Installer
Acer eDisplay Management
Adobe Flash Player 10 ActiveX
Adobe Photoshop 7.0
Adobe Reader 7.0
AiO_Scan
AiOSoftware
ATI Control Panel
ATI Display Driver
AVG 2011
AVG PC Tuneup 2011
Barnyard Invasion from Hewlett-Packard Desktops (remove only)
Bejeweled 2 Deluxe from Hewlett-Packard Desktops (remove only)
Big Kahuna Reef from Hewlett-Packard Desktops (remove only)
Blackhawk Striker 2 from Hewlett-Packard Desktops (remove only)
Blasterball 2 from Hewlett-Packard Desktops (remove only)
Blasterball 2 Holidays from Hewlett-Packard Desktops (remove only)
Boggle Supreme from Hewlett-Packard Desktops (remove only)
Bookworm Deluxe from Hewlett-Packard Desktops (remove only)
Bounce Symphony from Hewlett-Packard Desktops (remove only)
BufferChm
CameraDrivers
Canon Camera Access Library
Canon Camera Support Core Library
Canon G.726 WMP-Decoder
Canon JX510P series Printer Driver
Canon MovieEdit Task for ZoomBrowser EX
Canon RAW Image Task for ZoomBrowser EX
Canon Utilities CameraWindow
Canon Utilities CameraWindow DC
Canon Utilities CameraWindow DC_DV 5 for ZoomBrowser EX
Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX
Canon Utilities EOS Utility
Canon Utilities MyCamera
Canon Utilities MyCamera DC
Canon Utilities PhotoStitch
Canon Utilities RemoteCapture Task for ZoomBrowser EX
Canon Utilities ZoomBrowser EX
Canon ZoomBrowser EX Memory Card Utility
Corel Applications
Coupon Printer for Windows
CP_AtenaShokunin1Config
CP_CalendarTemplates1
CP_Package_Basic1
CP_Package_Variety1
CP_Package_Variety2
CP_Package_Variety3
CP_Panorama1Config
Crystal Maze from Hewlett-Packard Desktops (remove only)
CueTour
D1600
Definition update for Microsoft Office 2010 (KB982726)
Destinations
DeviceDiscovery
DeviceManagementQFolder
Digby's Donuts from Hewlett-Packard Desktops (remove only)
DJ_SF_06_D1600_SW_Min
DocProc
DocumentViewer
DocumentViewerQFolder
Easy Internet Sign-up
ESET Online Scanner v3
FATE Demo from Hewlett-Packard Desktops (remove only)
Fax
Flip Words from Hewlett-Packard Desktops (remove only)
Free Window Registry Repair
Google Earth
Google Toolbar for Internet Explorer
Google Update Helper
GPBaseService2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
HP Boot Optimizer
HP Customer Participation Program 14.0
HP Deskjet D1600 Printer Driver Software 14.0 Rel. 6
HP Deskjet Printer Preload
HP Document Viewer 5.3
HP Game Console and games
HP Image Zone 5.3
HP Imaging Device Functions 14.0
HP Multimedia Keyboard Software
HP OfficeJet Series 700 (Remove Only)
HP Organize
HP Photo Creations
HP Photosmart 330,380,420,470,7800,8000,8200 Series
HP Photosmart Cameras 5.0
HP PSC & OfficeJet 5.3.B
HP Smart Web Printing 4.60
HP Solution Center 14.0
HP Update
HPProductAssistant
HpSdpAppCoreApp
HPSSupply
Insaniquarium Deluxe from Hewlett-Packard Desktops (remove only)
InstantShareDevices
IntelliMover Data Transfer Demo
InterVideo WinDVD Player
iTunes
J2SE Runtime Environment 5.0
Java Auto Updater
Java™ 6 Update 22
Jewel Quest from Hewlett-Packard Desktops (remove only)
LightScribe 1.4.42.1
Mah Jong Quest from Hewlett-Packard Desktops (remove only)
Malwarebytes' Anti-Malware
MarketResearch
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB2416447)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Money 2005
Microsoft Office Access MUI (English) 2010
Microsoft Office Access Setup Metadata MUI (English) 2010
Microsoft Office Excel MUI (English) 2010
Microsoft Office Home and Student 2010
Microsoft Office OneNote MUI (English) 2010
Microsoft Office Outlook MUI (English) 2010
Microsoft Office PowerPoint MUI (English) 2010
Microsoft Office Proof (English) 2010
Microsoft Office Proof (French) 2010
Microsoft Office Proof (Spanish) 2010
Microsoft Office Proofing (English) 2010
Microsoft Office Publisher MUI (English) 2010
Microsoft Office Shared MUI (English) 2010
Microsoft Office Shared Setup Metadata MUI (English) 2010
Microsoft Office Single Image 2010
Microsoft Office Word MUI (English) 2010
Microsoft Plus! Dancer LE
Microsoft Plus! Digital Media Edition Installer
Microsoft Plus! Photo Story 2 LE
Microsoft Software Update for Web Folders (English) 14
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Works
Motorola SM56 Speakerphone Modem
Mozilla Firefox (3.6.15)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
muvee autoProducer 4.0
NewCopy
Office 2003 Tour
PanoStandAlone
PC-Doctor 5 for Windows
PhotoGallery
Pivot Software
Polar Bowler from Hewlett-Packard Desktops (remove only)
Polar Golfer from Hewlett-Packard Desktops (remove only)
PS2
PSPrinters08
PSTAPlugin
Puzzle Express from Hewlett-Packard Desktops (remove only)
Python 2.2 pywin32 extensions (build 203)
Python 2.2.3
QFolder
Quicken 2005
QuickTime
RandMap
Readme
RealNetworks - Microsoft Visual C++ 2008 Runtime
RealPlayer
RealUpgrade 1.1
Remove WeatherBug Installer
Ricochet Lost Worlds from Hewlett-Packard Desktops (remove only)
Scan
ScannerCopy
SCRABBLE Blast from Hewlett-Packard Desktops (remove only)
SCRABBLE from Hewlett-Packard Desktops (remove only)
SCRABBLE Rack Attack from Hewlett-Packard Desktops (remove only)
SDK
Security Update for CAPICOM (KB931906)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Microsoft Office 2010 (KB2289078)
Security Update for Microsoft Office 2010 (KB2289161)
Security Update for Microsoft Publisher 2010 (KB2409055)
Security Update for Microsoft Word 2010 (KB2345000)
Security Update for Windows Internet Explorer 8 (KB2360131)
Security Update for Windows Internet Explorer 8 (KB2416400)
Security Update for Windows Internet Explorer 8 (KB2482017)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB981332)
Security Update for Windows XP (KB2393802)
Security Update for Windows XP (KB2476687)
Security Update for Windows XP (KB2478960)
Security Update for Windows XP (KB2478971)
Security Update for Windows XP (KB2479628)
Security Update for Windows XP (KB2479943)
Security Update for Windows XP (KB2481109)
Security Update for Windows XP (KB2483185)
Security Update for Windows XP (KB2485376)
Shop for HP Supplies
Shrek 2 Ogre Bowler from Hewlett-Packard Desktops (remove only)
SkinsHP1
Slingo Deluxe from Hewlett-Packard Desktops (remove only)
Slyder from Hewlett-Packard Desktops (remove only)
SmartWebPrinting
SolutionCenter
Soluto
Sonic Express Labeler
Sonic MyDVD Plus
Sonic RecordNow Audio
Sonic RecordNow Copy
Sonic RecordNow Data
Sonic Update Manager
Sonic_PrimoSDK
Status
Super Granny from Hewlett-Packard Desktops (remove only)
Swarm from Hewlett-Packard Desktops (remove only)
Toolbox
Tradewinds from Hewlett-Packard Desktops (remove only)
TrayApp
TurboTax 2010
Unload
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Office 2010 (KB2202188)
Update for Microsoft Office 2010 (KB2413186)
Update for Microsoft OneNote 2010 (KB2493983)
Update for Microsoft Outlook Social Connector (KB2289116)
Update for Windows Internet Explorer 8 (KB976662)
Update for Windows XP (KB971029)
Updates from HP (remove only)
WebFldrs XP
WebReg
Windows Media Format Runtime
Windows Media Player 10
Windows XP Service Pack 3
Yahoo! Toolbar
.
==== End Of File ===========================

While running ESET, AVG popped up a warning about Win32/heur.dropper in the D: partition in BardYardInvasion. Unfortunately I did'nt get all of the details.

Appreciate the help,
G
Hello,

I can't see that either scan looks at the D: partition.


The D: partition is the "Recovery Partition". It is not usually scanned and should not be used for anything other than the factory installed recovery software. Further, it is not uncommon to see "False Positives" result from such scans.

I do not know of any malware that targets the Recovery Partition. If your system drive, C:, is clean, then it is even more unlikely that D: is infected.

=======================

D:\System Volume Information\_restore{A2578CBA-012A-4EE9-9E3D-27D3F494A2B6}\RP101\A0041288.exe

That is a System Restore Point. There should not be any restore points in the Recovery Partition.

Disable System Restore on a Non-system Drive
Drive letters are listed in the following order:
  • The system drive is listed first, followed by the remaining drives in alphabetical order.
  • The system drive is the drive in which Windows is installed or from which Windows runs. The system drive is listed first because it cannot be excluded without disabling the System Restore utility. Non-system drives can be individually configured and excluded from the System Restore utility.
To exclude drive D: from the System Restore utility, perform the following steps:
  • Click Start and click Control Panel.
  • In Control Panel, click System or click Performance and Maintenance, and then click System.
  • Click the System Restore tab, and then select the drive that you want to exclude.
  • Click the Settings button and make make certain that drive D: is excluded.
=======================

Registry Cleaners

I notice the presence of AVG PC Tuneup 2011 Registry Cleaner on your pc.

I don't personally recommend the use of ANY registry cleaners.
Here is an excerpt from a discussion on regcleaners

Most reg cleaners aren't "bad" as such, but they aren't perfect and even the best have been known to cause problems.
The point we are trying to make is that the risk of using one far outweighs any benefit.
If it does work perfectly you will not see any difference
If it doesn't work properly you may end up with an expensive doorstop.


http://miekiemoes.blogspot.com/2008/02/reg…weaking_13.html
http://forums.whatthetech.com/Regcleaner_t42862.html

=======================

Remove Outdated Programs
Current versions can be installed after we know that your computer is clean.

Please Click Start > Control Panel > Add/Remove Programs
Remove these programs by clicking Remove

Adobe Reader 7.0
J2SE Runtime Environment 5.0
Java Auto Updater
Java™ 6 Update 22


=======================

I see you already have Malwarebytes Anti-Malware installed:

  • Launch the application, Check for Updates >> Perform Quick Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Check all items except items in the C:\System Volume Information folder… and click Remove Selected.
    Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.
  • When completed, a log will open in Notepad. please copy and paste the log into your next reply.
  • The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt

=======================

I would like to see fresh OTL logs
  • Double click on OTL.exe to run it.
  • Under Extra Registry section, select Use SafeList.
  • Click the Scan All Users checkbox.
  • Click on Run Scan at the top left hand corner.
  • When done, two Notepad files will open.
    • OTL.txt <– Will be opened
    • Extras.txt <– Will be minimized
  • Please post the contents of these 2 Notepad files in your next reply.

=======================

Please post the following in your next reply:
  • The Malwarebytes' log
  • OTL.txt
  • Extra.txt
  • Any questions you might have about System Restore or the Recovery Partition
  • A description of how your computer is behaving now
Hi Carolyn,

I've done the following:

1- removed D: from the system restore list

2 - removed: Adobe Reader 7.0
J2SE Runtime Environment 5.0
Java 6 Update 22
Java Auto Updater does not appear in the list for Add/Remove Programs

3 - Restarted the computer

4 - Ran MBAM and it found nothing (Log below)

While runnimg MBAM, Avg Resident Shield popped up with two warnings:
c:\Program Files\WildTangent\Apps\GameChannel\Games\5253F22E-D4B6-49B7-9106-28D29C5395F22\BarnyardInvasion-WT. exe - False alarm - Virus Found Win32/Heur.dropper

c\System Volume Information\_restore{A2578CBA-012A-4EE9-9E3D-27D3F494A2B6}\RP96\A0040916.exe - False alarm - Virus Found Win32/Heur.dropper

Both appear to be False Alarms but I'm not sure what that means in this case.

5 - Ran OTL as specified. I did not include the script that you had me include the first time.



MBAM Log

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 6093

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

3/17/2011 11:31:36 PM
mbam-log-2011-03-17 (23-31-36).txt

Scan type: Quick scan
Objects scanned: 303332
Time elapsed: 27 minute(s), 17 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


OTL Log



OTL logfile created on: 3/17/2011 11:34:49 PM - Run 4
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Wendy.YOUR-27E1513D96\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

958.00 Mb Total Physical Memory | 563.00 Mb Available Physical Memory | 59.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 76.00% Paging File free
Paging file location(s): C:\pagefile.sys 1440 2880 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 225.36 Gb Total Space | 160.58 Gb Free Space | 71.25% Space Free | Partition Type: NTFS
Drive D: | 7.50 Gb Total Space | 1.66 Gb Free Space | 22.18% Space Free | Partition Type: FAT32

Computer Name: YOUR-27E1513D96 | User Name: Wendy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Wendy.YOUR-27E1513D96\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Real\realplayer\Update\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Soluto\SolutoService.exe (Soluto)
PRC - C:\Program Files\Soluto\Soluto.exe (Soluto)
PRC - C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Common Files\Portrait Displays\Shared\HookManager.exe (Portrait Displays Inc.)
PRC - C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe ()
PRC - C:\Program Files\Acer Display\eDisplay Management\dthtml.exe (Portrait Displays, Inc)
PRC - C:\Program Files\Common Files\Portrait Displays\Drivers\pdisrvc.exe (Portrait Displays, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Portrait Displays\Pivot Software\Floater.exe ()
PRC - C:\Program Files\Portrait Displays\Pivot Software\wpCtrl.exe ()
PRC - C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Wendy.YOUR-27E1513D96\My Documents\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\Portrait Displays\Pivot Software\Winphook.dll ()


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – File not found
SRV - (AppMgmt) – File not found
SRV - (SolutoService) – C:\Program Files\Soluto\SolutoService.exe (Soluto)
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) – C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (DTSRVC) – C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe ()
SRV - (PdiService) – C:\Program Files\Common Files\Portrait Displays\Drivers\pdisrvc.exe (Portrait Displays, Inc.)
SRV - (CCALib8) – C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)


========== Driver Services (SafeList) ==========

DRV - (Soluto) – C:\WINDOWS\system32\DRIVERS\Soluto.sys (Soluto LTD.)
DRV - (Avgldx86) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgtdix) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSEH) – C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgmfx86) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) – C:\WINDOWS\system32\DRIVERS\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSShim) – C:\WINDOWS\system32\drivers\AVGIDSShim.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSDriver) – C:\WINDOWS\system32\drivers\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSFilter) – C:\WINDOWS\system32\drivers\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV - (PdiPorts) – C:\WINDOWS\system32\drivers\PdiPorts.sys (Portrait Displays, Inc.)
DRV - (Pivot) – C:\WINDOWS\system32\drivers\pivot.sys (Portrait Displays, Inc.)
DRV - (pivotmou) – C:\WINDOWS\system32\drivers\pivotmou.sys (Portrait Displays, Inc.)
DRV - (Ps2) – C:\WINDOWS\system32\drivers\PS2.sys (Hewlett-Packard Company)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (ftsata2) – C:\WINDOWS\system32\DRIVERS\ftsata2.sys (Promise Technology, Inc.)
DRV - (AmdK8) – C:\WINDOWS\system32\drivers\AmdK8.sys (Advanced Micro Devices)
DRV - (RTL8023xp) – C:\WINDOWS\system32\drivers\Rtlnicxp.sys (Realtek Semiconductor Corporation )
DRV - (smserial) – C:\WINDOWS\system32\drivers\smserial.sys (Motorola Inc.)
DRV - (rtl8139) Realtek RTL8139(A/B/C) – C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)
DRV - (bb-run) – C:\WINDOWS\system32\DRIVERS\bb-run.sys (Promise Technology, Inc.)
DRV - (crlscsi) – C:\WINDOWS\System32\drivers\crlscsi.sys (Corel Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…arm1=seconduser


IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-3131796442-2609879388-2480220986-1010\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.sympatico.ca/
IE - HKU\S-1-5-21-3131796442-2609879388-2480220986-1010\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
IE - HKU\S-1-5-21-3131796442-2609879388-2480220986-1010\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.sympatico.ca/"
FF - prefs.js..extensions.enabledItems: {D6D05E6F-D5C1-4e03-8E33-73F92B05E262}:10.2
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:10.0.0.1178
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.2
FF - prefs.js..network.proxy.type: 0

FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/09/04 22:42:03 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG10\Firefox\ [2011/01/24 12:22:26 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/02/16 22:27:14 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.15\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/03/16 09:44:58 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.15\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/03/16 09:44:58 | 000,000,000 | —D | M]

[2010/12/31 18:37:19 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Application Data\Mozilla\Extensions
[2011/03/13 21:52:57 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Application Data\Mozilla\Firefox\Profiles\5a8x4pk8.default\extensions
[2011/03/13 21:52:57 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Application Data\Mozilla\Firefox\Profiles\5a8x4pk8.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/03/05 15:01:42 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2009/04/05 22:35:55 | 000,000,000 | —D | M] (SMART Notebook Extension) – C:\Program Files\Mozilla Firefox\extensions\{D6D05E6F-D5C1-4e03-8E33-73F92B05E262}
[2011/02/16 22:27:14 | 000,000,000 | —D | M] (RealPlayer Browser Record Plugin) – C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
[2011/01/24 12:22:26 | 000,000,000 | —D | M] (AVG Safe Search) – C:\PROGRAM FILES\AVG\AVG10\FIREFOX
[2010/12/30 23:00:24 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2009/11/06 11:37:19 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
[2005/12/05 23:31:00 | 000,114,688 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\npmozax.dll
[2009/11/06 11:37:20 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npMozCouponPrinter.dll

O1 HOSTS File: ([2004/08/04 15:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (&Google;) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
O3 - HKU\S-1-5-21-3131796442-2609879388-2480220986-1010\..\Toolbar\WebBrowser: (&Google;) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKU\S-1-5-21-3131796442-2609879388-2480220986-1010\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [DT ACR] C:\Program Files\Common Files\Portrait Displays\Shared\DT_startup.exe ()
O4 - HKLM..\Run: [HPBootOp] C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [PivotSoftware] C:\Program Files\Portrait Displays\Pivot Software\wpctrl.exe ()
O4 - Startup: C:\Documents and Settings\Kimberly\Start Menu\Programs\Startup\Calendar Creator Scheduler.lnk = C:\Program Files\SoftKey\Calendar Creator 4.0\CCSCHED.EXE ()
O4 - Startup: C:\Documents and Settings\Wendy\Start Menu\Programs\Startup\HP Organize.lnk = C:\Program Files\Hewlett-Packard\HP Organize\bin\displayAgent.exe (NeoPlanet)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-3131796442-2609879388-2480220986-1010\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &Google; Search - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Backward Links - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Cached Snapshot of Page - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Se&nd; to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O8 - Extra context menu item: Similar Pages - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Translate into English - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ()
O9 - Extra 'Tools' menuitem : Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ()
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\intu-tt2010 {97A0575E-2309-4e75-8509-B1F9390C4DE7} - C:\Program Files\TurboTax 2010\ic2010pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Program Files\Soluto\soluto.exe /userinit) - C:\Program Files\Soluto\soluto.exe (Soluto)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Wendy.YOUR-27E1513D96\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Wendy.YOUR-27E1513D96\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/10/07 08:09:40 | 000,000,050 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2001/07/28 07:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O33 - MountPoints2\{2d435b36-e506-11d9-9b78-e6b009352ae7}\Shell - "" = AutoRun
O33 - MountPoints2\{2d435b36-e506-11d9-9b78-e6b009352ae7}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{2d435b36-e506-11d9-9b78-e6b009352ae7}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync) - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart) - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/03/16 11:10:17 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2011/03/13 22:04:04 | 000,000,000 | —D | C] – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Application Data\Malwarebytes
[2011/03/13 22:03:54 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/03/13 22:03:37 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/03/13 22:02:33 | 000,000,000 | —D | C] – C:\Documents and Settings\Wendy.YOUR-27E1513D96\My Documents\Downloads
[2011/03/07 13:35:38 | 000,236,032 | —- | C] (CANON INC.) – C:\WINDOWS\System32\CNMLM9R.DLL
[2011/03/07 13:35:35 | 000,000,000 | -H-D | C] – C:\WINDOWS\System32\CanonIJ Uninstaller Information
[2011/03/07 13:35:35 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Canon JX510P series
[2011/03/07 13:35:31 | 000,178,176 | —- | C] (CANON INC.) – C:\WINDOWS\System32\CNMIU9R.DLL
[2011/03/07 13:35:17 | 000,000,000 | -H-D | C] – C:\Program Files\CanonBJ
[2011/03/06 23:41:54 | 000,000,000 | —D | C] – C:\Documents and Settings\Wendy.YOUR-27E1513D96\My Documents\TurboTax
[2011/03/06 20:59:52 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\TurboTax
[2011/03/06 20:59:35 | 000,000,000 | —D | C] – C:\Program Files\TurboTax 2010
[2011/02/24 18:57:28 | 000,051,144 | —- | C] (Soluto LTD.) – C:\WINDOWS\System32\drivers\Soluto.sys
[2011/02/24 18:57:15 | 000,000,000 | —D | C] – C:\Program Files\Soluto
[2011/02/24 18:57:15 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Soluto
[2011/02/24 18:55:45 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Soluto
[2011/02/18 10:37:19 | 000,012,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mouhid.sys
[2011/02/18 10:37:06 | 000,010,368 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hidusb.sys
[2011/02/16 22:27:18 | 000,000,000 | —D | C] – C:\Program Files\Common Files\xing shared
[2011/02/16 22:27:05 | 000,198,848 | —- | C] (RealNetworks, Inc.) – C:\WINDOWS\System32\rmoc3260.dll
[2011/02/16 22:26:55 | 000,006,656 | —- | C] (RealNetworks, Inc.) – C:\WINDOWS\System32\pndx5016.dll
[2011/02/16 22:26:55 | 000,005,632 | —- | C] (RealNetworks, Inc.) – C:\WINDOWS\System32\pndx5032.dll
[2011/02/16 22:26:54 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Real
[2011/02/16 22:26:14 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Real
[2011/02/16 22:20:39 | 000,602,464 | —- | C] (RealNetworks, Inc.) – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Desktop\RealPlayer.exe
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/03/17 23:35:02 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/03/17 23:35:00 | 000,000,422 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{1A14DDC3-D4C6-4955-A8DD-1C9C60364BFE}.job
[2011/03/17 23:03:54 | 000,000,248 | —- | M] () – C:\WINDOWS\System\hpsysdrv.dat
[2011/03/17 23:01:49 | 000,000,278 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-3131796442-2609879388-2480220986-1010.job
[2011/03/17 23:01:48 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/03/17 23:01:38 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/03/17 23:01:35 | 1005,113,344 | -HS- | M] () – C:\hiberfil.sys
[2011/03/17 23:00:11 | 000,000,286 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-3131796442-2609879388-2480220986-1010.job
[2011/03/17 22:50:03 | 109,010,314 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2011/03/17 22:44:44 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/03/16 11:59:59 | 000,625,664 | —- | M] () – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Desktop\dds.scr
[2011/03/13 22:03:55 | 000,000,795 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/03/13 21:53:15 | 000,446,338 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/03/13 21:53:15 | 000,073,100 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/03/13 21:38:51 | 000,006,674 | —- | M] () – C:\Documents and Settings\Wendy.YOUR-27E1513D96\My Documents\WP_pcAVGscan.csv
[2011/03/09 15:37:24 | 000,001,355 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/03/09 14:49:00 | 000,049,842 | —- | M] () – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Desktop\Orillia Deck Project Materials List - Final Pricing.pdf
[2011/03/07 09:25:32 | 000,358,544 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/03/06 20:59:52 | 000,001,662 | —- | M] () – C:\Documents and Settings\All Users\Desktop\TurboTax Canada 2010.lnk
[2011/03/05 14:49:35 | 000,002,501 | —- | M] () – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Desktop\Microsoft Word 2010.lnk
[2011/03/01 18:22:23 | 000,193,113 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\iavichjg.avm
[2011/02/28 18:20:00 | 000,000,322 | —- | M] () – C:\WINDOWS\tasks\Easy Internet Sign-up.job
[2011/02/26 12:00:03 | 000,173,347 | —- | M] () – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Desktop\Gawel v Meloche Monnex.pdf
[2011/02/26 11:59:47 | 000,708,258 | —- | M] () – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Desktop\Stewart v New Brunswick.pdf
[2011/02/24 18:59:50 | 000,000,098 | —- | M] () – C:\Documents and Settings\All Users\Application Data\Microsoft.SqlServer.Compact.351.32.bc
[2011/02/22 11:52:31 | 000,003,584 | —- | M] () – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/02/22 10:20:39 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/02/16 22:28:36 | 000,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2011/02/16 22:28:36 | 000,001,409 | —- | M] () – C:\WINDOWS\QTFont.for
[2011/02/16 22:27:24 | 000,000,747 | —- | M] () – C:\Documents and Settings\All Users\Desktop\RealPlayer.lnk
[2011/02/16 22:27:05 | 000,198,848 | —- | M] (RealNetworks, Inc.) – C:\WINDOWS\System32\rmoc3260.dll
[2011/02/16 22:26:55 | 000,006,656 | —- | M] (RealNetworks, Inc.) – C:\WINDOWS\System32\pndx5016.dll
[2011/02/16 22:26:55 | 000,005,632 | —- | M] (RealNetworks, Inc.) – C:\WINDOWS\System32\pndx5032.dll
[2011/02/16 22:26:54 | 000,272,896 | —- | M] (Progressive Networks) – C:\WINDOWS\System32\pncrt.dll
[2011/02/16 22:20:39 | 000,602,464 | —- | M] (RealNetworks, Inc.) – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Desktop\RealPlayer.exe
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/03/16 11:59:58 | 000,625,664 | —- | C] () – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Desktop\dds.scr
[2011/03/13 22:03:55 | 000,000,795 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/03/13 21:38:50 | 000,006,674 | —- | C] () – C:\Documents and Settings\Wendy.YOUR-27E1513D96\My Documents\WP_pcAVGscan.csv
[2011/03/09 14:49:00 | 000,049,842 | —- | C] () – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Desktop\Orillia Deck Project Materials List - Final Pricing.pdf
[2011/03/06 20:59:51 | 000,001,662 | —- | C] () – C:\Documents and Settings\All Users\Desktop\TurboTax Canada 2010.lnk
[2011/02/26 11:59:55 | 000,173,347 | —- | C] () – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Desktop\Gawel v Meloche Monnex.pdf
[2011/02/26 11:59:46 | 000,708,258 | —- | C] () – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Desktop\Stewart v New Brunswick.pdf
[2011/02/24 19:01:20 | 001,115,872 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2011/02/24 18:59:50 | 000,000,098 | —- | C] () – C:\Documents and Settings\All Users\Application Data\Microsoft.SqlServer.Compact.351.32.bc
[2011/02/22 11:52:31 | 000,003,584 | —- | C] () – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/02/16 22:28:36 | 000,054,156 | -H– | C] () – C:\WINDOWS\QTFont.qfn
[2011/02/16 22:28:36 | 000,001,409 | —- | C] () – C:\WINDOWS\QTFont.for
[2011/02/16 22:27:56 | 000,000,278 | —- | C] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-3131796442-2609879388-2480220986-1010.job
[2011/02/16 22:27:51 | 000,000,286 | —- | C] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-3131796442-2609879388-2480220986-1010.job
[2011/02/16 22:27:24 | 000,000,747 | —- | C] () – C:\Documents and Settings\All Users\Desktop\RealPlayer.lnk
[2010/12/31 16:12:13 | 001,371,436 | R— | C] () – C:\WINDOWS\System32\VBAR2132.DLL
[2010/12/31 12:18:29 | 000,002,304 | —- | C] () – C:\WINDOWS\System32\Machnm32.sys
[2010/12/31 10:36:58 | 000,000,016 | —- | C] () – C:\WINDOWS\System32\asdict.dat
[2010/12/31 10:36:58 | 000,000,004 | —- | C] () – C:\WINDOWS\System32\aspdict-en.dat
[2010/12/31 01:20:23 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\wsbl.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\phar_unmip.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\phar_histprot.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\ph_white.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\ph_summ.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\ph_black.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pcwords2.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pcwords.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_webproxy.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_video.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_tabloids.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_socialnetworks.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_searchengines.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_regionaltlds.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_pornography.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_onlineshop.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_onlinepay.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_onlinedating.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_news.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_im.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_illegal.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_hate.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_games.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_gambling.dat
[2010/12/31 00:35:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\pc_drugs.dat
[2010/12/30 23:06:25 | 000,118,784 | —- | C] () – C:\WINDOWS\System32\hpocnt05.dll
[2010/12/30 23:06:25 | 000,000,970 | —- | C] () – C:\WINDOWS\hpoio05.ini
[2010/12/30 23:06:25 | 000,000,065 | —- | C] () – C:\WINDOWS\opleinst.ini
[2010/12/30 19:54:55 | 000,168,557 | —- | C] () – C:\WINDOWS\hphins33.dat.temp
[2010/12/30 19:54:55 | 000,000,512 | —- | C] () – C:\WINDOWS\hphmdl33.dat.temp
[2010/12/30 19:50:48 | 000,000,156 | —- | C] () – C:\Documents and Settings\Wendy.YOUR-27E1513D96\Application Data\wklnhst.dat
[2010/09/04 22:32:09 | 000,168,470 | —- | C] () – C:\WINDOWS\hphins33.dat
[2010/09/04 22:32:09 | 000,000,512 | —- | C] () – C:\WINDOWS\hphmdl33.dat
[2010/03/29 19:40:20 | 000,100,256 | —- | C] () – C:\Program Files\Common Files\LinkInstaller.exe
[2009/02/06 21:07:32 | 000,000,004 | —- | C] () – C:\Program Files\Common Files\Cvtaqlog.dat
[2008/11/12 15:24:59 | 000,000,100 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2007/11/30 11:02:09 | 000,001,891 | —- | C] () – C:\WINDOWS\mozver.dat
[2007/11/30 11:00:07 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2007/11/19 23:52:47 | 000,000,234 | —- | C] () – C:\WINDOWS\LEXSTAT.INI
[2007/01/31 15:50:32 | 000,913,408 | —- | C] () – C:\WINDOWS\System32\xreglib.dll
[2006/08/04 10:28:10 | 000,000,010 | —- | C] () – C:\WINDOWS\SIERRA.INI
[2006/05/19 07:10:50 | 000,000,214 | —- | C] () – C:\WINDOWS\HP_InstantSHareJPG.ini
[2006/05/19 07:09:03 | 000,000,206 | —- | C] () – C:\WINDOWS\HPGdiPlus.ini
[2006/04/18 23:00:00 | 000,000,227 | —- | C] () – C:\WINDOWS\HP_CounterReport_Update_HPSU.ini
[2006/04/18 22:59:49 | 000,000,214 | —- | C] () – C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2006/04/18 22:59:38 | 000,000,217 | —- | C] () – C:\WINDOWS\HP_IZClosingDiscErrorPatch.ini
[2006/04/18 22:57:46 | 000,000,221 | —- | C] () – C:\WINDOWS\HP_RedboxHprblog_HPSU.ini
[2005/11/25 13:24:10 | 000,000,000 | —- | C] () – C:\WINDOWS\longfile.INI
[2005/11/25 13:17:39 | 000,000,102 | —- | C] () – C:\WINDOWS\texture.ini
[2005/11/24 23:12:18 | 000,039,125 | —- | C] () – C:\WINDOWS\iccsigs.dat
[2005/10/07 08:36:45 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/10/07 08:13:47 | 000,118,842 | R— | C] () – C:\WINDOWS\HPCPCUninstaller-6.3.2.116-9972322.exe
[2005/10/07 08:12:37 | 000,013,543 | —- | C] () – C:\WINDOWS\System32\CHODDI.SYS
[2005/10/07 08:12:32 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\hpreg.dll
[2005/10/07 08:10:21 | 000,000,172 | —- | C] () – C:\WINDOWS\Quicken.ini
[2005/10/07 08:06:07 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/10/07 08:01:42 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2005/10/07 08:01:42 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2005/10/07 08:01:42 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2005/10/07 08:01:42 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2005/10/07 08:01:42 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2005/10/07 08:01:41 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2005/10/07 07:56:41 | 000,000,056 | —- | C] () – C:\WINDOWS\WININIT.INI
[2005/10/07 07:51:25 | 000,112,873 | —- | C] () – C:\WINDOWS\hpoins07.dat
[2005/10/07 07:51:25 | 000,021,124 | —- | C] () – C:\WINDOWS\hpomdl07.dat
[2005/10/07 07:46:50 | 000,080,418 | —- | C] () – C:\WINDOWS\HPHins08.dat
[2005/10/07 07:46:50 | 000,004,011 | —- | C] () – C:\WINDOWS\hphmdl08.dat
[2005/10/07 07:44:51 | 000,072,881 | —- | C] () – C:\WINDOWS\hpiins01.dat
[2005/10/07 07:44:51 | 000,000,000 | —- | C] () – C:\WINDOWS\hpimdl01.dat
[2005/10/07 07:43:58 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2005/10/07 07:41:38 | 000,065,536 | —- | C] () – C:\WINDOWS\sm56spn.dll
[2005/10/07 07:41:38 | 000,065,536 | —- | C] () – C:\WINDOWS\sm56spn(2).dll
[2005/10/07 07:41:38 | 000,065,536 | —- | C] () – C:\WINDOWS\sm56itl.dll
[2005/10/07 07:41:38 | 000,065,536 | —- | C] () – C:\WINDOWS\sm56itl(2).dll
[2005/10/07 07:41:38 | 000,065,536 | —- | C] () – C:\WINDOWS\sm56ger.dll
[2005/10/07 07:41:38 | 000,065,536 | —- | C] () – C:\WINDOWS\sm56ger(2).dll
[2005/10/07 07:41:38 | 000,065,536 | —- | C] () – C:\WINDOWS\sm56fra.dll
[2005/10/07 07:41:38 | 000,065,536 | —- | C] () – C:\WINDOWS\sm56fra(2).dll
[2005/10/07 07:41:38 | 000,065,536 | —- | C] () – C:\WINDOWS\sm56eng.dll
[2005/10/07 07:41:38 | 000,065,536 | —- | C] () – C:\WINDOWS\sm56eng(2).dll
[2005/10/07 07:41:38 | 000,065,536 | —- | C] () – C:\WINDOWS\sm56brz.dll
[2005/10/07 07:41:38 | 000,065,536 | —- | C] () – C:\WINDOWS\sm56brz(2).dll
[2005/10/07 07:41:38 | 000,049,152 | —- | C] () – C:\WINDOWS\sm56jpn.dll
[2005/10/07 07:41:38 | 000,049,152 | —- | C] () – C:\WINDOWS\sm56jpn(2).dll
[2005/10/07 07:41:38 | 000,045,056 | —- | C] () – C:\WINDOWS\sm56cht.dll
[2005/10/07 07:41:38 | 000,045,056 | —- | C] () – C:\WINDOWS\sm56cht(2).dll
[2005/10/07 07:41:38 | 000,045,056 | —- | C] () – C:\WINDOWS\sm56chs.dll
[2005/10/07 07:41:38 | 000,045,056 | —- | C] () – C:\WINDOWS\sm56chs(2).dll
[2005/10/07 07:40:36 | 000,001,040 | —- | C] () – C:\WINDOWS\System32\drivers\alcxinit.dat
[2005/10/07 07:40:34 | 000,026,625 | —- | C] () – C:\WINDOWS\System32\sxsttsu.dll
[2005/10/07 07:40:14 | 000,094,574 | —- | C] () – C:\WINDOWS\System32\atiicdxx.dat
[2005/10/07 07:31:11 | 000,000,780 | —- | C] () – C:\WINDOWS\orun32.ini
[2005/10/07 07:27:48 | 000,323,584 | —- | C] () – C:\WINDOWS\System32\pythoncom22.dll
[2005/10/07 07:27:48 | 000,094,208 | —- | C] () – C:\WINDOWS\System32\pywintypes22.dll
[2005/10/07 07:27:30 | 000,016,896 | —- | C] () – C:\WINDOWS\System32\bcbmm.dll
[2005/07/07 16:07:24 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2005/06/25 02:29:32 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2005/06/25 01:43:44 | 000,446,338 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2005/06/25 01:43:44 | 000,073,100 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2005/06/25 01:42:06 | 000,358,544 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2005/06/25 01:31:46 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2005/06/25 01:30:20 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2005/05/10 02:52:32 | 000,022,396 | —- | C] () – C:\WINDOWS\System32\drivers\USBkey.sys
[2004/08/04 15:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/04 08:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/04 08:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/04 08:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/04 08:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/04 08:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/04 08:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/08/04 08:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2004/06/16 01:38:02 | 000,000,537 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2001/08/23 19:12:28 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2001/08/23 19:11:02 | 000,004,490 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2001/07/07 01:30:00 | 000,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini

========== Alternate Data Streams ==========

@Alternate Data Stream - 146 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4

< End of report >


OTL Extras
OTL Extras logfile created on: 3/17/2011 11:34:49 PM - Run 4
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Wendy.YOUR-27E1513D96\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

958.00 Mb Total Physical Memory | 563.00 Mb Available Physical Memory | 59.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 76.00% Paging File free
Paging file location(s): C:\pagefile.sys 1440 2880 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 225.36 Gb Total Space | 160.58 Gb Free Space | 71.25% Space Free | Partition Type: NTFS
Drive D: | 7.50 Gb Total Space | 1.66 Gb Free Space | 22.18% Space Free | Partition Type: FAT32

Computer Name: YOUR-27E1513D96 | User Name: Wendy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe" = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe:*:Enabled:Updates from HP – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe" = C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpofxs08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpofxs08.exe:*:Enabled:hpofxs08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe:*:Enabled:hpqgplgtupl.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe:*:Enabled:hpqusgm.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe:*:Enabled:hpqusgh.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\HP Software Update\hpwucli.exe" = C:\Program Files\HP\HP Software Update\hpwucli.exe:*:Enabled:hpwucli.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\smart web printing\SmartWebPrintExe.exe" = C:\Program Files\HP\Digital Imaging\smart web printing\SmartWebPrintExe.exe:*:Enabled:smartwebprintexe.exe – (Hewlett-Packard Co.)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe – ()
"C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe – ( )
"C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe" = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe:*:Enabled:Updates from HP – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe" = C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpofxs08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpofxs08.exe:*:Enabled:hpofxs08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe:*:Enabled:hpqgplgtupl.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe:*:Enabled:hpqusgm.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe:*:Enabled:hpqusgh.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\HP Software Update\hpwucli.exe" = C:\Program Files\HP\HP Software Update\hpwucli.exe:*:Enabled:hpwucli.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\smart web printing\SmartWebPrintExe.exe" = C:\Program Files\HP\Digital Imaging\smart web printing\SmartWebPrintExe.exe:*:Enabled:smartwebprintexe.exe – (Hewlett-Packard Co.)
"C:\Program Files\Microsoft Office\Office14\ONENOTE.EXE" = C:\Program Files\Microsoft Office\Office14\ONENOTE.EXE:*:Enabled:Microsoft OneNote – (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE" = C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook – (Microsoft Corporation)
"C:\Program Files\AVG\AVG10\avgmfapx.exe" = C:\Program Files\AVG\AVG10\avgmfapx.exe:*:Enabled:AVG Installer – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG10\avgdiagex.exe" = C:\Program Files\AVG\AVG10\avgdiagex.exe:*:Enabled:AVG Diagnostics 2011 – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG10\avgnsx.exe" = C:\Program Files\AVG\AVG10\avgnsx.exe:*:Enabled:Online Shield – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG10\avgemcx.exe" = C:\Program Files\AVG\AVG10\avgemcx.exe:*:Enabled:Personal E-mail Scanner – (AVG Technologies CZ, s.r.o.)
"K:\solutoinstaller.exe" = K:\solutoinstaller.exe:*:Enabled:SolutoInstaller
"C:\Program Files\Soluto\Soluto.exe" = C:\Program Files\Soluto\Soluto.exe:*:Enabled:Soluto Tray – (Soluto)
"C:\Program Files\Soluto\SolutoService.exe" = C:\Program Files\Soluto\SolutoService.exe:*:Enabled:Soluto Service – (Soluto)
"C:\Program Files\Soluto\SolutoConsole.exe" = C:\Program Files\Soluto\SolutoConsole.exe:*:Enabled:Soluto Console – (Soluto)
"C:\Program Files\Soluto\SolutoUpdateService.exe" = C:\Program Files\Soluto\SolutoUpdateService.exe:*:Enabled:Soluto Update Service – (Soluto)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0217E1D1-BCEF-4A61-AF6D-F7740F65A066}" = Pivot Software
"{03B1B42B-F6DE-41d9-8CFF-DC44E895C7A7}" = PhotoGallery
"{0611BD4E-4FE4-4a62-B0C0-18A4CC463428}" = CP_Package_Variety1
"{075473F5-846A-448B-BCB3-104AA1760205}" = Sonic RecordNow Data
"{09984AEC-6B9F-4ca7-B78D-CB44D4771DA3}" = Destinations
"{0B33B738-AD79-4E32-90C5-E67BFB10BBFF}" = AiO_Scan
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{0DEA342C-15CB-4F52-97B6-06A9C4B9C06F}" = SDK
"{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}" = Microsoft Plus! Photo Story 2 LE
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_JX510P_series" = Canon JX510P series Printer Driver
"{14589F05-C658-4594-9429-D437BA688686}" = IntelliMover Data Transfer Demo
"{1458BB78-1DC5-4BC0-B9A3-2B644F5A8105}" = DeviceDiscovery
"{150B6201-E9E6-4DFB-960E-CCBD53FBDDED}" = HPProductAssistant
"{172975EB-9465-4861-95B5-C7BB6D3DE62A}" = DocumentViewer
"{1A103D70-5C9B-4E1A-B306-5106C68F9914}" = Microsoft Plus! Dancer LE
"{1C139D7D-9FEA-468d-A9C8-2A6E3BDE564A}" = CP_Package_Variety3
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{21657574-BD54-48A2-9450-EB03B2C7FC29}" = Sonic MyDVD Plus
"{21DB3D90-D816-4092-A260-CA3F6B55A6DD}" = Sonic_PrimoSDK
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{23A7B376-BBEC-4e76-BBD7-0F155E70D74B}" = CP_Panorama1Config
"{24AE6B5B-3D5A-488C-9224-1BEE11F75DD9}" = TurboTax 2010
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{292F0F52-B62D-4E71-921B-89A682402201}" = Toolbox
"{2C3D719A-92C7-4323-89CC-C937D0267B84}" = muvee autoProducer 4.0
"{2C5D07FB-31A2-4F2D-9FDA-0B24ACD42BD0}" = HP Deskjet Printer Preload
"{2CADCEAB-D5DA-44D6-B5FC-7DEE87AB3C0C}" = Unload
"{2DBE41DD-2129-4C65-A3D3-5647236A60F3}" = Quicken 2005
"{2FB9EA69-51D4-4913-9AD5-762C034DE811}" = Status
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
"{32BDCCB8-9DC8-496d-9DB1-F77510775BDB}" = InstantShareDevices
"{33D6CC28-9F75-4d1b-A11D-98895B3A3729}" = HP Photosmart 330,380,420,470,7800,8000,8200 Series
"{343A1706-26A4-45EA-88CF-37CA172B0F27}" = D1600
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{36E47DA1-10E1-45d9-8B19-14D19607CDCF}" = CP_CalendarTemplates1
"{3BA95526-6AE0-4B87-A62D-17187EF565FC}" = HP Boot Optimizer
"{416D80BA-6F6D-4672-B7CF-F54DA2F80B44}" = Microsoft Works
"{50316C0A-CC2A-460A-9EA5-F486E54AC17D}_is1" = AVG PC Tuneup 2011
"{523E6F2A-2D59-4D91-90E8-6C49931C9F50}" = iTunes
"{54E3707F-808E-4fd4-95C9-15D1AB077E5D}" = NewCopy
"{56EE8B17-8274-418d-89AC-C057C5DB251E}" = RandMap
"{5A01C58E-B0EC-49b9-AD71-7C0468688087}" = CP_Package_Basic1
"{5B79CFD1-6845-4158-9D7D-6BE89DF2C135}" = HP PSC & OfficeJet 5.3.B
"{5DCF0E4B-F8EA-4229-A0BD-5CA6D4AFB749}" = SolutionCenter
"{60FFB3E0-6D5B-4D73-AE5B-07E58B83AF0C}" = 32 Bit HP CIO Components Installer
"{64D5E9DE-7890-4FB0-8865-8B24BE1773F7}" = LightScribe [removed]
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Sonic Express Labeler
"{66BA8C26-AFE4-4408-807B-43E76B57EF53}" = SkinsHP1
"{6BB6627C-694F-4FDC-A3E5-C7F4BED4C724}" = DocProc
"{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}" = Microsoft Plus! Digital Media Edition Installer
"{74DC0593-6BC6-4001-AD5F-D810AFB68D86}" = HP Update
"{755EC5E3-FD51-46bd-A57F-7A2D56FBF061}" = PSTAPlugin
"{769A295C-DCF4-41d6-AFBA-7D9394B23AFE}" = PSPrinters08
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{7850A6D2-CBEA-4728-9877-F1BEDEA9F619}" = AiOSoftware
"{7C03270C-4FAB-4F5C-B10D-52FEDA190790}" = DocumentViewerQFolder
"{7E27304E-BAA2-4d90-A34E-76641FAFABB4}" = CP_AtenaShokunin1Config
"{8105684D-8CA6-440D-8F58-7E5FD67A499D}" = Easy Internet Sign-up
"{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder
"{8EE94FD8-5F52-4463-A340-185D16328158}" = WebReg
"{8FF6F5CA-4E30-4E3B-B951-204CAAA2716A}" = SmartWebPrinting
"{90140000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 14
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-003D-0000-0000-0000000FF1CE}" = Microsoft Office Single Image 2010
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD Player
"{923A7F5A-1E8C-4FBE-8DF6-85940A60A79F}" = Readme
"{96178C0A-BAF9-4E49-A2A5-CDE76722105B}" = HP Deskjet D1600 Printer Driver Software 14.0 Rel. 6
"{A195B13E-A5E3-4BAF-A995-7F70F445CD06}" = ScannerCopy
"{A276502A-8979-44FB-8090-90CF72F22ABC}" = AVG 2011
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A3455242-DAE0-4523-8242-FD82706ABF4B}" = CameraDrivers
"{A586DC50-B18D-48FB-B7CC-A598200457C2}" = Acer eDisplay Management
"{A5BB5365-EFB4-44c3-A7E2-EB59B7EFD23D}" = CueTour
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AB61A692-5543-4C48-979B-8CEA1C52FE9C}" = PC-Doctor 5 for Windows
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Sonic RecordNow Audio
"{AC35A885-0F8F-4857-B7DA-6E8DFB43E6B3}" = HPSSupply
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Sonic RecordNow Copy
"{B4D279F1-4309-49cc-A4B5-3A0D2E59C7B5}" = PanoStandAlone
"{B594B13B-0395-411D-AE09-C86E7304C749}" = Soluto
"{B824B5C9-849F-4b9e-9EA7-6FD8CD8116DA}" = CP_Package_Variety2
"{BB3447F6-9553-4AA9-960E-0DB5310C5779}" = GPBaseService2
"{BE9FEFBA-F2F8-468B-A108-4356F73A3E9C}" = Office 2003 Tour
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C506A18C-1469-4678-B094-F4EC9DAE6DB7}" = Scan
"{C768790F-04FB-11E0-9B2C-001AA037B01E}" = Google Earth
"{C83A12B9-B31B-461A-BBD4-CE9B988094F1}" = HP Photosmart Cameras 5.0
"{C9B2F671-870B-43A0-8B9D-7DB30CEBD87E}" = DJ_SF_06_D1600_SW_Min
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CD31E63D-47FD-491C-8117-CF201D0AFAB5}" = TrayApp
"{CE24344F-DFD8-40C8-8FD8-C9740B5F25AC}" = Fax
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0122362-6333-4DE4-93F6-A5A2F3CC101A}" = HP Organize
"{D360FA88-17C8-4F14-B67F-13AAF9607B12}" = MarketResearch
"{D518592A-0F1E-40ca-BECB-3D3F026C6B0D}" = CameraDrivers
"{DB518BA6-CB74-4EB6-9ABD-880B6D6E1F38}" = HpSdpAppCoreApp
"{E35AF511-B618-4D02-B559-0F2147341D3B}" = AVG 2011
"{FA0FF682-CC70-4C57-93CD-E276F3E7537E}" = BufferChm
"010D7E30-8019-4477-AE7C-BFBBDE570CB9" = Insaniquarium Deluxe from Hewlett-Packard Desktops (remove only)
"0B99A43B-A792-4003-9295-604BC687B6F6" = Big Kahuna Reef from Hewlett-Packard Desktops (remove only)
"1E728F26-D920-45F1-9E97-4A5690B07A7F" = Jewel Quest from Hewlett-Packard Desktops (remove only)
"27C7083E-4ECB-4C88-ACC1-0EDA88C00257" = Ricochet Lost Worlds from Hewlett-Packard Desktops (remove only)
"3295A049-B970-4CC5-847C-7ABF14B9F8F1" = Mah Jong Quest from Hewlett-Packard Desktops (remove only)
"36317AE4-57EC-4F3E-B828-009A3DD96BE8" = Polar Bowler from Hewlett-Packard Desktops (remove only)
"3F34F72F-9BB0-4B73-8312-558953ACF56F" = Super Granny from Hewlett-Packard Desktops (remove only)
"46CD7AAB-D3C9-41DB-8AEC-5BD24169B0E1" = Flip Words from Hewlett-Packard Desktops (remove only)
"47298745-7194-4142-AFDA-8BE2EDFDF82E" = Bookworm Deluxe from Hewlett-Packard Desktops (remove only)
"5253F22E-D4B6-49B7-9106-28D9C5395F22" = Barnyard Invasion from Hewlett-Packard Desktops (remove only)
"58D1A004-6D3C-480A-9E0D-FAA58F3C2A62" = Blackhawk Striker 2 from Hewlett-Packard Desktops (remove only)
"5F5B2E2A-5924-4DAB-825A-10BEA50A4DA1" = Boggle Supreme from Hewlett-Packard Desktops (remove only)
"663A22CB-3C2B-4302-9A14-BC5DAFAB2071" = FATE Demo from Hewlett-Packard Desktops (remove only)
"6E4D87E1-83A3-4029-A9E4-2F360442E1FC" = SCRABBLE Rack Attack from Hewlett-Packard Desktops (remove only)
"703E3900-69DA-47C9-9768-C6514098F149" = Shrek 2 Ogre Bowler from Hewlett-Packard Desktops (remove only)
"7978E9A8-5A11-4406-BA8F-866E120352DF" = Bejeweled 2 Deluxe from Hewlett-Packard Desktops (remove only)
"8C4E79CC-03E1-43AA-9910-9A5113F24603" = Blasterball 2 from Hewlett-Packard Desktops (remove only)
"95A4B97A-C363-41DD-B907-BD4AB9E4FF16" = SCRABBLE Blast from Hewlett-Packard Desktops (remove only)
"A9C7B4D4-A866-4696-B115-77B65D0A641A" = Swarm from Hewlett-Packard Desktops (remove only)
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Photoshop 7.0" = Adobe Photoshop 7.0
"ATI Display Driver" = ATI Display Driver
"AVG" = AVG 2011
"B2D3332F-EA2D-42B3-8E4A-F74D052BCBC1" = Polar Golfer from Hewlett-Packard Desktops (remove only)
"B41503CB-5FE0-47E0-87C1-47BA8E660BCC" = Blasterball 2 Holidays from Hewlett-Packard Desktops (remove only)
"BA910432-2C22-4BB8-9D13-46170F52C5AC" = Puzzle Express from Hewlett-Packard Desktops (remove only)
"C1241092-7183-480A-A289-B5920C7C56D0" = Slingo Deluxe from Hewlett-Packard Desktops (remove only)
"C2C3C2DB-7D8A-4E20-B527-E3149FAECC3A" = Slyder from Hewlett-Packard Desktops (remove only)
"CAL" = Canon Camera Access Library
"CameraWindowDC" = Canon Utilities CameraWindow DC
"CameraWindowDVC5" = Canon Utilities CameraWindow DC_DV 5 for ZoomBrowser EX
"CameraWindowDVC6" = Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX
"CameraWindowLauncher" = Canon Utilities CameraWindow
"Canon G.726 WMP-Decoder" = Canon G.726 WMP-Decoder
"Corel Applications" = Corel Applications
"Coupon Printer for Windows5.0.0.0" = Coupon Printer for Windows
"CSCLIB" = Canon Camera Support Core Library
"D11F7128-8CBD-408B-8BF8-034604DEDD42" = Bounce Symphony from Hewlett-Packard Desktops (remove only)
"D3203C96-6C76-43D6-A3D0-5DD6A0732E83" = SCRABBLE from Hewlett-Packard Desktops (remove only)
"DAE7A92A-BAC7-42FA-AC62-53DEF1DC4292" = Crystal Maze from Hewlett-Packard Desktops (remove only)
"ED8E7ECA-9D6A-46BA-BF46-D97774AA7117" = Digby's Donuts from Hewlett-Packard Desktops (remove only)
"EOS Utility" = Canon Utilities EOS Utility
"ESET Online Scanner" = ESET Online Scanner v3
"F5215F01-DFC0-475D-A910-6F1AF94E807E" = Tradewinds from Hewlett-Packard Desktops (remove only)
"Free Window Registry Repair" = Free Window Registry Repair
"HP Document Viewer" = HP Document Viewer 5.3
"HP Game Console" = HP Game Console and games
"HP Imaging Device Functions" = HP Imaging Device Functions 14.0
"HP OfficeJet Series 700" = HP OfficeJet Series 700 (Remove Only)
"HP Photo & Imaging" = HP Image Zone 5.3
"HP Photo Creations" = HP Photo Creations
"HP Smart Web Printing" = HP Smart Web Printing 4.60
"HP Solution Center & Imaging Support Tools" = HP Solution Center 14.0
"HPExtendedCapabilities" = HP Customer Participation Program 14.0
"HPOOVClient-9972322 Uninstaller" = Updates from HP (remove only)
"Install WeatherBug" = Remove WeatherBug Installer
"InstallShield_{2DBE41DD-2129-4C65-A3D3-5647236A60F3}" = Quicken 2005
"InstallShield_{523E6F2A-2D59-4D91-90E8-6C49931C9F50}" = iTunes
"InstallShield_{8105684D-8CA6-440D-8F58-7E5FD67A499D}" = Easy Internet Sign-up
"InstallShield_{AB61A692-5543-4C48-979B-8CEA1C52FE9C}" = PC-Doctor 5 for Windows
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Money2005b" = Microsoft Money 2005
"MovieEditTask" = Canon MovieEdit Task for ZoomBrowser EX
"Mozilla Firefox (3.6.15)" = Mozilla Firefox (3.6.15)
"MyCamera" = Canon Utilities MyCamera
"MyCameraDC" = Canon Utilities MyCamera DC
"Office14.SingleImage" = Microsoft Office Home and Student 2010
"PhotoStitch" = Canon Utilities PhotoStitch
"PS2" = PS2
"Python 2.2.3" = Python 2.2.3
"pywin32-py2.2" = Python 2.2 pywin32 extensions (build 203)
"QuickTime" = QuickTime
"RAW Image Task" = Canon RAW Image Task for ZoomBrowser EX
"RealPlayer 12.0" = RealPlayer
"RemoteCaptureTask" = Canon Utilities RemoteCapture Task for ZoomBrowser EX
"Shop for HP Supplies" = Shop for HP Supplies
"SMSERIAL" = Motorola SM56 Speakerphone Modem
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows Media Player" = Windows Media Player 10
"Windows XP Service Pack" = Windows XP Service Pack 3
"Yahoo! Companion" = Yahoo! Toolbar
"ZoomBrowser EX" = Canon Utilities ZoomBrowser EX
"ZoomBrowser EX Memory Card Utility" = Canon ZoomBrowser EX Memory Card Utility

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-3131796442-2609879388-2480220986-1010\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 12/31/2010 7:03:39 PM | Computer Name = YOUR-27E1513D96 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 1/4/2011 12:32:37 AM | Computer Name = YOUR-27E1513D96 | Source = Application Error | ID = 1000
Description = Faulting application , version 0.0.0.0, faulting module unknown, version
0.0.0.0, fault address 0x00000000.

Error - 1/11/2011 11:34:37 PM | Computer Name = YOUR-27E1513D96 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 1/11/2011 11:34:48 PM | Computer Name = YOUR-27E1513D96 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

[ System Events ]
Error - 3/17/2011 10:50:14 PM | Computer Name = YOUR-27E1513D96 | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 3/17/2011 10:50:14 PM | Computer Name = YOUR-27E1513D96 | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 3/17/2011 10:50:14 PM | Computer Name = YOUR-27E1513D96 | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 3/17/2011 10:50:14 PM | Computer Name = YOUR-27E1513D96 | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 3/17/2011 10:50:14 PM | Computer Name = YOUR-27E1513D96 | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 3/17/2011 10:50:14 PM | Computer Name = YOUR-27E1513D96 | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 3/17/2011 10:50:14 PM | Computer Name = YOUR-27E1513D96 | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 3/17/2011 10:50:15 PM | Computer Name = YOUR-27E1513D96 | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 3/17/2011 10:50:15 PM | Computer Name = YOUR-27E1513D96 | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 3/17/2011 10:50:15 PM | Computer Name = YOUR-27E1513D96 | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126


< End of report >

Thanks Again,

G
I missed another Registry Cleaner that is installed on your computer

Free Window Registry Repair

I strongly recommend that you uninstall that program as well.

========================

c:\Program Files\WildTangent\Apps\GameChannel\Games\5253F22E-D4B6-49B7-9106-28D29C5395F22\BarnyardInvasion-WT. exe - False alarm - Virus Found Win32/Heur.dropper

This is likely to be a false positive but let's test it so you will be certain…

Upload File/Files for testing

Please go to jotti.org or Virustotal

Copy/paste this file and path into the white box at the top:

c:\Program Files\WildTangent\Apps\GameChannel\Games\5253F22E-D4B6-49B7-9106-28D29C5395F22\BarnyardInvasion-WT. exe

Press Submit - this will submit the file for testing.
Please wait for all the scanners to finish then copy and paste the permalink (web address) in your next response.
Example of web address :
[external image: Posted Image]

========================

I see you are using Wild Tangent. It is not malware, but is sometimes thought to bring malware along. Wild Tangent is a video game software company specializing in online games. It has even made a partnership with AOL to include itself as part of the AOL Instant Messenger for their AIM games section. The WildTangent Web Driver is their technology that allows you to play 3D games over the Internet. Although it's not technically considered spyware, it does have built in components to update itself and gather information about the computer system including
  • Operating System Version
  • CPU Type and Speed
  • Memory Amount
    Video Card type and Driver Version
  • Sound Card type and Driver Version
  • DirectX Version
    Location that the Web Driver was installed from
  • It is also a MAJOR resource hog.
For more information, see WildTangent Removal Instructions and Help and Inside Wild Tangent-Delivering High-End 3-D Content To A Web Site Near You.
Unless you are an extremely avid games player, I recommend you uninstall Wild Tangent: To uninstall Wild Tangent:
  • Click Start, point to Settings, and then click Control Panel.
  • In Control Panel, double-click Add or Remove Programs.
  • In Add or Remove Programs, highlight Wild Tangent, click Remove.
  • Close the Add or Remove Programs and the Control Panel windows.

========================

c\System Volume Information\_restore{A2578CBA-012A-4EE9-9E3D-27D3F494A2B6}\RP96\A0040916.exe - False alarm - Virus Found Win32/Heur.dropper

That is a System Restore Point. If it is infected, it is of no consequence as long as you do not use it to restore the system. We will create a new Restore Point and purge the old ones once we are confident that your computer is clean.

========================

Backup Your Registry with ERUNT
  • Please use the following link and scroll down to ERUNT and download it.
    http://aumha.org/freeware/freeware.php
  • For version with the Installer:
    Use the setup program to install ERUNT on your computer
  • For the zipped version:
    Unzip all the files into a folder of your choice.
Click Erunt.exe to backup your registry to the folder of your choice.

Note:to restore your registry, go to the folder and start ERUNT.exe

========================

Disable AVG

  • Please open the AVG Control Center, by right clicking on the AVG icon on task bar.
  • Click on Open AVG User Interface.
  • On the Menu Bar, click on Tools.
  • Click Advanced Settings.
  • In the new screen which opens, scroll down to Temporarily disable AVG protection. Click on it to highlight it.
  • In the right hand pane, tick the box for Temporarily disable AVG protection.
  • Click Apply.
  • In the next screen which opens, select 180 minutes from the drop down menu, then click the Disable real time protection button.
  • Click OK.
  • Note: Don't forget to re-enable it after the fix.

========================

Run a Custom OTL Script
  • Double-click OTL.exe to start the program.
  • Copy and Paste the following code into the [external image: Posted Image] textbox. Do not include the word Code
    :Reg
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
    "K:\solutoinstaller.exe" =-
    :Commands
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top.
  • Click [external image: Posted Image].
  • OTL may ask to reboot the machine. Please do so if asked.
  • The report should appear in Notepad after the reboot.Copy and Paste that report in your next reply.

========================

Please post the following in your next reply:
  • The VirusTotal or Jotti results
  • The OTL report
  • A description of how the computer is behaving. Any problems?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI