This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Mozilla Firefox won't open Yahoo email.

25 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello.

A couple of weeks ago I started having a lot of problems with my Firefox browser (the one I always use). I don't seem to have the same problems with IE. I think the problem is virus or malware related. Also, I have gotten several notices from Yahoo that indicate someone is trying to change my password.

When I log in to my Yahoo email account, I get a blank page. I can get to the log-in page, but after logging in, I keep getting a blank page. Also, Firefox will not update anymore. I get this message; "UPDATE FAILED!, Something is trying to trick Firefox into accepting an insecure update."

Firefox will not open many of the websites I visit anymore.

I have run Malwarebytes and Hitman Pro to try and fix the problem, but no luck. I have also tried the search engines, but I can't seem to find much information about this problem.

Here is my HiJack This scan;



Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 2:26:42 PM, on 5/3/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\PROGRA~1\AVG\AVG10\avgchsvx.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AVG\AVG10\avgwdsvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\Program Files\AVG\AVG10\avgnsx.exe
C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\DISC\DISCover.exe
C:\Program Files\DISC\DiscUpdateMgr.exe
C:\Program Files\Sonic\DigitalMedia Plus\DigitalMedia Archive\DMAScheduler.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe
C:\Program Files\AVG\AVG10\avgtray.exe
C:\program files\real\realplayer\update\realsched.exe
C:\Program Files\DISC\DiscGui.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\DISC\DiscStreamHub.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\HP\KBD\KBD.EXE
c:\windows\system\hpsysdrv.exe
C:\PROGRA~1\AVG\AVG10\avgrsx.exe
C:\Program Files\AVG\AVG10\avgcsrvx.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
O1 - Hosts: 255.255.255.255 hcurltest5
O1 - Hosts: 255.255.255.255 vnsjs1.1stworks.com
O1 - Hosts: 74.208.77.54 hcurltest1
O1 - Hosts: 74.208.223.76 hcurltest2
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
O4 - HKLM\..\Run: [DISCover] C:\Program Files\DISC\DISCover.exe
O4 - HKLM\..\Run: [DiscUpdateManager] C:\Program Files\DISC\DiscUpdateMgr.exe
O4 - HKLM\..\Run: [DMAScheduler] c:\Program Files\Sonic\DigitalMedia Plus\DigitalMedia Archive\DMAScheduler.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [MaxMenuMgr] "C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe"
O4 - HKLM\..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\program files\real\realplayer\update\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [cdloader] "C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Application Data\mjusbsp\cdloader2.exe" MAGICJACK
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - S-1-5-18 Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'SYSTEM')
O4 - .DEFAULT Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Startup: OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Startup: Seagate 2GEXM0JE Product Registration.lnk = C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Application Data\Leadertech\PowerRegister\Seagate 2GEXM0JE Product Registration.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Updates From HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.trymedia.com (HKLM)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10\avgwdsvc.exe
O23 - Service: Intel® Quick Resume Technology Drivers (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
O23 - Service: Seagate Service (FreeAgentGoNext Service) - Seagate Technology LLC - C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE

–
End of file - 14059 bytes



Thanks for your help,
Hello baldingeagle and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:
• Please follow all instructions in the order posted
• Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
• If you don't understand something, please don't hesitate to ask for clarification before proceeding
• The fixes are specific to your problem and should only be used for this issue on this machine.
• Please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

I am looking at your log now and will reply with instructions shortly

Satchfan
Hello again baldingeagle

Did you modify your Hosts file and added these:

O1 - Hosts: 255.255.255.255 hcurltest5
O1 - Hosts: 255.255.255.255 vnsjs1.1stworks.com
O1 - Hosts: 74.208.77.54 hcurltest1
O1 - Hosts: 74.208.223.76 hcurltest2


If not, do the following:

RunHostsXpert

Download HostsXpert and then follow the steps below:* Unzip HostsXpert.zip
* It will create a folder named HostsXpert in whatever folder you extract it to.
* Run HostsXpert.exe by double clicking on it (Vista and Windows 7 users, right click and click "Run As Administrator").
* click Restore MS Hosts File and then click OK.
* Click the X to exit the program
Note: If you were using a custom Hosts file you will need to replace any of those entries yourself.

Restart your computer.


Download and run OTL
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in


    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %PROGRAMFILES%\Internet Explorer\*.dat
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
===================================================

Download the GMER Rootkit Scanner

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • All drives/partitions except C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


Logs to include with next post:

OTL.txt
Extras.txt
Gmer.txt


Thanks

Satchfan
Hello Satchfan.

I ran HostsXpert as you instructed.

I then ran OTL. It only opened one notepad window.

Attached is my OTL.txt scan; My favorites make the file far too large to paste or upload via attachement (I tried several times). I am going to leave out the "favorites" and post the scan. If you need them, please let me know what to do.

OTL logfile created on: 5/6/2011 3:13:36 PM - Run 2
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 62.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 85.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 270.76 Gb Total Space | 26.55 Gb Free Space | 9.81% Space Free | Partition Type: NTFS
Drive D: | 8.68 Gb Total Space | 0.49 Gb Free Space | 5.61% Space Free | Partition Type: FAT32

Computer Name: YOUR-4DACD0EA75 | User Name: HP_Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe (Siber Systems)
PRC - C:\Program Files\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe (Seagate Technology LLC)
PRC - C:\Program Files\Seagate\SeagateManager\FreeAgent Status\stxmenumgr.exe (Seagate LLC)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe (Hewlett-Packard)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Intel Corporation)
PRC - C:\Program Files\DISC\DiscGui.exe (Digital Interactive Systems Corporation, Inc.)
PRC - C:\Program Files\DISC\DISCover.exe (Digital Interactive Systems Corporation)
PRC - C:\Program Files\DISC\DISCUpdateMgr.exe (Digital Interactive Systems Corporation, Inc.)
PRC - C:\Program Files\DISC\DiscStreamHub.exe (Digital Interactive Systems Corporation, Inc.)
PRC - C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe (Intel Corporation)
PRC - C:\Program Files\Sonic\DigitalMedia Plus\DigitalMedia Archive\DMAScheduler.exe (Sonic Solutions)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchrome10browserrecordhelper.dll (RealNetworks, Inc.)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcr90.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcp90.dll (Microsoft Corporation)
MOD - C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Local Settings\Temp\IadHide5.dll (BackWeb)


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – File not found
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) – C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (FreeAgentGoNext Service) – C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe (Seagate Technology LLC)
SRV - (IAANTMON) Intel® – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Intel Corporation)
SRV - (ELService) – C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe (Intel Corporation)


========== Driver Services (SafeList) ==========

DRV - (F-Secure Standalone Minifilter) – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Local Settings\Temp\OnlineScanner\Anti-Virus\fsgk.sys ()
DRV - (Avgldx86) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgtdix) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSEH) – C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgmfx86) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) – C:\WINDOWS\system32\DRIVERS\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSFilter) – C:\WINDOWS\system32\drivers\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSDriver) – C:\WINDOWS\system32\drivers\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSShim) – C:\WINDOWS\system32\drivers\AVGIDSShim.sys (AVG Technologies CZ, s.r.o. )
DRV - (RTL8192su) – C:\WINDOWS\system32\drivers\RTL8192su.sys (Realtek Semiconductor Corporation )
DRV - (NPF) – C:\WINDOWS\system32\drivers\npf.sys (CACE Technologies, Inc.)
DRV - (mf) – C:\WINDOWS\system32\drivers\mf.sys (Microsoft Corporation)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (Ps2) – C:\WINDOWS\system32\drivers\PS2.sys (Hewlett-Packard Company)
DRV - (ELacpi) – C:\WINDOWS\system32\drivers\ELacpi.sys (Intel Corporation)
DRV - (ELmon) – C:\WINDOWS\system32\drivers\ELmon.sys (Intel Corporation)
DRV - (ELkbd) – C:\WINDOWS\system32\drivers\ELkbd.sys (Intel Corporation)
DRV - (ELmou) – C:\WINDOWS\system32\drivers\ELmou.sys (Intel Corporation)
DRV - (ELhid) – C:\WINDOWS\system32\drivers\ELhid.sys (Intel Corporation)
DRV - (AgereSoftModem) – C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (hcwPP2) – C:\WINDOWS\system32\drivers\hcwPP2.sys (Hauppauge Computer Works, Inc.)
DRV - (ftsata2) – C:\WINDOWS\system32\DRIVERS\ftsata2.sys (Promise Technology, Inc.)
DRV - (rtl8139) Realtek RTL8139(A/B/C) – C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)
DRV - (bb-run) – C:\WINDOWS\system32\DRIVERS\bb-run.sys (Promise Technology, Inc.)
DRV - (BrUsbScn) – C:\WINDOWS\system32\drivers\BrUsbScn.sys (Brother Industries Ltd.)
DRV - (brfilt) – C:\WINDOWS\system32\drivers\BrFilt.sys (Brother Industries Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:10.0.0.1178
FF - prefs.js..extensions.enabledItems: {3e0e7d2a-070f-4a47-b019-91fe5385ba79}:3.1.0
FF - prefs.js..extensions.enabledItems: vshare@toolbar:1.0.0
FF - prefs.js..network.proxy.type: 0

FF - HKLM\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG10\Firefox4\ [2011/03/30 10:25:22 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/04/16 10:13:58 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{22119944-ED35-4ab1-910B-E619EA06A115}: C:\Program Files\Siber Systems\AI RoboForm\Firefox [2011/03/25 13:43:14 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/04/23 14:47:48 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/04/16 10:14:34 | 000,000,000 | —D | M]

[2010/11/22 23:31:31 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Application Data\Mozilla\Extensions
[2011/04/25 10:02:40 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Application Data\Mozilla\Firefox\Profiles\05kfcsd2.default\extensions
[2011/03/24 20:37:37 | 000,000,000 | —D | M] (AddThis) – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Application Data\Mozilla\Firefox\Profiles\05kfcsd2.default\extensions\{3e0e7d2a-070f-4a47-b019-91fe5385ba79}
[2010/11/28 14:09:46 | 000,000,000 | —D | M] (vShare) – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Application Data\Mozilla\Firefox\Profiles\05kfcsd2.default\extensions\vshare@toolbar
[2011/04/23 14:47:47 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/04/19 09:35:54 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/19 09:38:58 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/10/19 09:33:47 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/04/12 09:39:01 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/04/23 14:47:47 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\distribution\extensions
[2011/04/23 14:47:48 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Program Files\Mozilla Firefox\distribution\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
File not found (No name found) –
[2011/04/16 10:13:58 | 000,000,000 | —D | M] (RealPlayer Browser Record Plugin) – C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
() (No name found) – C:\DOCUMENTS AND SETTINGS\HP_ADMINISTRATOR.YOUR-4DACD0EA75.000\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\05KFCSD2.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
[2011/03/30 10:25:22 | 000,000,000 | —D | M] (AVG Safe Search) – C:\PROGRAM FILES\AVG\AVG10\FIREFOX4
[2010/11/23 02:49:39 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/03/25 13:43:14 | 000,000,000 | —D | M] (AI Roboform Toolbar for Firefox) – C:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\FIREFOX
[2010/01/01 04:00:00 | 000,135,168 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2011/04/14 17:18:26 | 000,289,592 | —- | M] (Cisco WebEx LLC) – C:\Program Files\Mozilla Firefox\plugins\ieatgpc.dll
[2011/04/14 17:17:53 | 000,172,344 | —- | M] (Cisco WebEx LLC) – C:\Program Files\Mozilla Firefox\plugins\npatgpc.dll
[2011/02/02 21:40:24 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/01/01 04:00:00 | 000,002,252 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\bing.xml

O1 HOSTS File: ([2011/05/06 10:52:34 | 000,000,698 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (&RoboForm) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&RoboForm) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [DISCover] C:\Program Files\DISC\DISCover.exe (Digital Interactive Systems Corporation)
O4 - HKLM..\Run: [DiscUpdateManager] C:\Program Files\DISC\DISCUpdateMgr.exe (Digital Interactive Systems Corporation, Inc.)
O4 - HKLM..\Run: [DMAScheduler] c:\Program Files\Sonic\DigitalMedia Plus\DigitalMedia Archive\DMAScheduler.exe (Sonic Solutions)
O4 - HKLM..\Run: [HPBootOp] C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe (Hewlett-Packard)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [MaxMenuMgr] C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe (Seagate LLC)
O4 - HKLM..\Run: [PCDrProfiler] File not found
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\Recguard.exe ()
O4 - HKLM..\Run: [Reminder] C:\Windows\Creator\Remind_XP.exe (SoftThinks)
O4 - HKLM..\Run: [TkBellExe] C:\program files\real\realplayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [RoboForm] C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (Siber Systems)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Updates From HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe (Hewlett-Packard)
O4 - Startup: C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Start Menu\Programs\Startup\OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O4 - Startup: C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Start Menu\Programs\Startup\Seagate 2GEXM0JE Product Registration.lnk = C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Application Data\Leadertech\PowerRegister\Seagate 2GEXM0JE Product Registration.exe (Leader Technologies/Seagate)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &Google Search - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: &Translate English Word - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Backward Links - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Cached Snapshot of Page - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Customize Menu - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html ()
O8 - Extra context menu item: Fill Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O8 - Extra context menu item: RoboForm Toolbar - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O8 - Extra context menu item: Save Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O8 - Extra context menu item: Similar Pages - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Translate Page into English - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O9 - Extra Button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra 'Tools' menuitem : Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra Button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra 'Tools' menuitem : Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra 'Tools' menuitem : RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra Button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ()
O9 - Extra 'Tools' menuitem : Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ()
O15 - HKLM\..Trusted Domains: trymedia.com ([]http in Trusted sites)
O15 - HKLM\..Trusted Domains: trymedia.com ([]https in Trusted sites)
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/e/2…78f/wvc1dmo.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/03/12 10:04:40 | 000,000,100 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2001/07/27 15:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync) - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart) - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.LEAD - C:\WINDOWS\System32\LCodcCMP.dll (LEAD Technologies, Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)

========== Files/Folders - Created Within 30 Days ==========

[2011/05/06 11:15:17 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\OTL.exe
[2011/05/06 10:51:57 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\HostsXpert
[2011/05/03 14:26:01 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\HiJackThis.exe
[2011/04/28 10:49:48 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\AI RoboForm
[2011/04/24 14:19:42 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Application Data\f-secure
[2011/04/24 14:19:16 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\F-Secure
[2011/04/23 15:07:50 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2011/04/23 15:07:50 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Start Menu\Programs\HiJackThis
[2011/04/23 15:04:48 | 000,173,456 | —- | C] (Symantec Corporation) – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\FixVundo.exe
[2011/04/21 16:27:19 | 000,947,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msjava.bak
[2011/04/16 10:14:04 | 000,000,000 | —D | C] – C:\Program Files\Common Files\xing shared
[2011/04/16 10:13:44 | 000,198,848 | —- | C] (RealNetworks, Inc.) – C:\WINDOWS\System32\rmoc3260.dll
[2011/04/16 10:13:26 | 000,006,656 | —- | C] (RealNetworks, Inc.) – C:\WINDOWS\System32\pndx5016.dll
[2011/04/16 10:13:26 | 000,005,632 | —- | C] (RealNetworks, Inc.) – C:\WINDOWS\System32\pndx5032.dll
[2011/04/15 16:50:28 | 000,000,000 | —D | C] – C:\WINDOWS\System32\Registry Patrol
[2011/04/15 16:49:59 | 000,000,000 | —D | C] – C:\Program Files\Registry Patrol
[2011/04/15 15:01:04 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Local Settings\Application Data\PackageAware
[2011/04/15 13:56:59 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Start Menu\Programs\RT-Alerts
[2011/04/15 13:50:09 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Application Data\RT-Alerts
[2011/04/14 17:18:57 | 000,000,000 | -HSD | C] – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\My Documents\cache
[2011/04/14 17:18:57 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Application Data\webex
[2011/04/12 09:38:59 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/04/12 09:38:59 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/04/12 09:38:59 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2011/04/11 11:18:37 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Application Data\HpUpdate
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/05/06 15:12:53 | 000,000,308 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-1747380976-3469703338-1627799412-1008.job
[2011/05/06 15:12:53 | 000,000,300 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1747380976-3469703338-1627799412-1008.job
[2011/05/06 14:59:45 | 000,014,296 | —- | M] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\letter to eyebuydirect.odt
[2011/05/06 14:20:00 | 000,001,062 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1747380976-3469703338-1627799412-1008UA.job
[2011/05/06 14:20:00 | 000,001,010 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1747380976-3469703338-1627799412-1008Core.job
[2011/05/06 13:58:37 | 000,000,248 | —- | M] () – C:\WINDOWS\System\hpsysdrv.dat
[2011/05/06 13:56:18 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/05/06 13:56:14 | 2145,865,728 | -HS- | M] () – C:\hiberfil.sys
[2011/05/06 13:44:26 | 000,217,088 | —- | M] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/05/06 11:15:32 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\OTL.exe
[2011/05/06 10:51:47 | 000,353,485 | —- | M] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\HostsXpert.zip
[2011/05/06 10:14:31 | 114,275,020 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2011/05/05 21:54:52 | 000,870,128 | —- | M] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Application Data\mcs.rma
[2011/05/05 21:54:52 | 000,000,004 | —- | M] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Application Data\25A1A5
[2011/05/05 14:46:33 | 000,002,653 | —- | M] () – C:\WINDOWS\BRMFBIDI.INI
[2011/05/04 19:08:08 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/05/03 14:26:02 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\HiJackThis.exe
[2011/05/01 10:26:34 | 000,016,968 | —- | M] () – C:\WINDOWS\System32\drivers\hitmanpro35.sys
[2011/04/28 10:32:18 | 003,017,304 | —- | M] (Siber Systems) – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\AiRoboForm.exe
[2011/04/27 16:11:15 | 000,001,782 | —- | M] () – C:\Documents and Settings\All Users\Desktop\hotCommCL.lnk
[2011/04/27 16:11:15 | 000,001,140 | —- | M] () – C:\Documents and Settings\All Users\Desktop\hotCommCL Transcripts.lnk
[2011/04/27 16:11:15 | 000,001,116 | —- | M] () – C:\Documents and Settings\All Users\Desktop\hotCommCL Uploads.lnk
[2011/04/25 11:36:55 | 000,180,759 | —- | M] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\Faye Bragg eye exam 2.JPG
[2011/04/25 11:35:37 | 000,424,184 | —- | M] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\Faye Bragg eye exam 1.JPG
[2011/04/23 16:31:19 | 000,639,741 | —- | M] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\Ken Bragg's Eye Exam 2.JPG
[2011/04/23 16:29:36 | 000,001,471 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Media Center.lnk
[2011/04/23 16:29:19 | 000,290,908 | —- | M] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\Ken Bragg's Eye Exam 1.JPG
[2011/04/23 15:32:51 | 000,000,000 | —- | M] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\My Documents\firefox352.exe
[2011/04/23 15:06:50 | 001,402,880 | —- | M] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\HijackThis.msi
[2011/04/23 15:04:59 | 000,173,456 | —- | M] (Symantec Corporation) – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\FixVundo.exe
[2011/04/23 14:47:54 | 000,000,753 | —- | M] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/04/23 14:47:54 | 000,000,735 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/04/23 14:24:52 | 000,001,425 | —- | M] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Start Menu\Programs\Startup\Seagate 2GEXM0JE Product Registration.lnk
[2011/04/23 13:53:27 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/04/18 18:29:00 | 000,196,968 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\iavichjg.avm
[2011/04/16 10:14:23 | 000,000,747 | —- | M] () – C:\Documents and Settings\All Users\Desktop\RealPlayer.lnk
[2011/04/16 10:13:44 | 000,198,848 | —- | M] (RealNetworks, Inc.) – C:\WINDOWS\System32\rmoc3260.dll
[2011/04/16 10:13:26 | 000,006,656 | —- | M] (RealNetworks, Inc.) – C:\WINDOWS\System32\pndx5016.dll
[2011/04/16 10:13:26 | 000,005,632 | —- | M] (RealNetworks, Inc.) – C:\WINDOWS\System32\pndx5032.dll
[2011/04/16 10:13:24 | 000,272,896 | —- | M] (Progressive Networks) – C:\WINDOWS\System32\pncrt.dll
[2011/04/15 13:56:59 | 000,159,519 | —- | M] () – C:\WINDOWS\RT-Alerts Uninstaller.exe
[2011/04/15 13:56:59 | 000,000,651 | —- | M] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\RT-Alerts.lnk
[2011/04/15 13:56:33 | 000,303,285 | —- | M] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\Install-RT-Alerts.exe
[2011/04/14 11:18:09 | 000,216,064 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/04/14 01:09:08 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/05/06 14:59:44 | 000,014,296 | —- | C] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\letter to eyebuydirect.odt
[2011/05/06 10:51:41 | 000,353,485 | —- | C] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\HostsXpert.zip
[2011/04/25 11:36:55 | 000,180,759 | —- | C] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\Faye Bragg eye exam 2.JPG
[2011/04/25 11:35:37 | 000,424,184 | —- | C] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\Faye Bragg eye exam 1.JPG
[2011/04/23 16:31:18 | 000,639,741 | —- | C] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\Ken Bragg's Eye Exam 2.JPG
[2011/04/23 16:29:18 | 000,290,908 | —- | C] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\Ken Bragg's Eye Exam 1.JPG
[2011/04/23 15:33:25 | 000,000,000 | —- | C] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\My Documents\firefox352.exe
[2011/04/23 15:06:49 | 001,402,880 | —- | C] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\HijackThis.msi
[2011/04/23 14:15:41 | 000,001,062 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1747380976-3469703338-1627799412-1008UA.job
[2011/04/23 14:15:40 | 000,001,010 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1747380976-3469703338-1627799412-1008Core.job
[2011/04/16 10:15:03 | 000,000,300 | —- | C] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1747380976-3469703338-1627799412-1008.job
[2011/04/16 10:15:01 | 000,000,308 | —- | C] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-1747380976-3469703338-1627799412-1008.job
[2011/04/16 10:14:23 | 000,000,747 | —- | C] () – C:\Documents and Settings\All Users\Desktop\RealPlayer.lnk
[2011/04/15 13:56:59 | 000,159,519 | —- | C] () – C:\WINDOWS\RT-Alerts Uninstaller.exe
[2011/04/15 13:56:59 | 000,000,651 | —- | C] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\RT-Alerts.lnk
[2011/04/15 13:56:33 | 000,303,285 | —- | C] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\Install-RT-Alerts.exe
[2010/11/28 00:37:54 | 000,000,004 | —- | C] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Application Data\25A1A5
[2010/11/28 00:37:53 | 000,870,128 | —- | C] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Application Data\mcs.rma
[2010/11/24 11:02:47 | 000,520,192 | —- | C] () – C:\WINDOWS\System32\ati2sgag.exe
[2010/11/23 22:36:24 | 000,651,264 | —- | C] () – C:\WINDOWS\System32\brfxdial.dll
[2010/11/23 19:24:24 | 000,000,256 | R— | C] () – C:\WINDOWS\System32\brmsl05f.bin
[2010/11/23 11:55:50 | 000,217,088 | —- | C] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/11/23 00:27:18 | 000,016,968 | —- | C] () – C:\WINDOWS\System32\drivers\hitmanpro35.sys
[2010/11/22 23:03:32 | 000,000,159 | —- | C] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Local Settings\Application Data\fusioncache.dat
[2010/10/21 02:42:41 | 000,137,088 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/09/10 10:25:16 | 000,000,107 | —- | C] () – C:\Documents and Settings\All Users\Application Data\Microsoft.SqlServer.Compact.351.32.bc
[2010/08/27 11:31:46 | 000,002,161 | —- | C] () – C:\WINDOWS\StockNeuroMaster.INI
[2010/07/04 18:09:02 | 000,256,512 | —- | C] () – C:\WINDOWS\PEV.exe
[2010/04/16 18:25:14 | 000,077,312 | —- | C] () – C:\WINDOWS\MBR.exe
[2010/04/04 14:19:46 | 000,002,042 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\8s32
[2010/04/02 16:12:13 | 000,002,270 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\LK2mfPE2j
[2010/03/03 10:58:32 | 000,160,032 | —- | C] () – C:\WINDOWS\RampRT Uninstaller.exe.bak
[2009/12/12 17:21:02 | 000,000,000 | —- | C] () – C:\WINDOWS\Opefeyesu.bin
[2009/12/12 17:21:01 | 000,000,120 | —- | C] () – C:\WINDOWS\Cnarusi.dat
[2009/11/02 11:04:16 | 000,000,323 | —- | C] () – C:\WINDOWS\MessorAnalytics_RegressionChannel_uninstall.ini
[2009/11/02 11:03:47 | 000,000,303 | —- | C] () – C:\WINDOWS\MessorAnalytics_Ergodic_uninstall.ini
[2009/10/20 14:19:30 | 000,053,299 | —- | C] () – C:\WINDOWS\System32\pthreadVC.dll
[2009/10/02 03:04:30 | 000,000,034 | —- | C] () – C:\WINDOWS\AuthMgr.INI
[2009/09/04 15:49:05 | 000,001,469 | —- | C] () – C:\WINDOWS\w59_prmf.dat
[2009/08/31 14:00:22 | 000,021,504 | —- | C] () – C:\WINDOWS\System32\WBCustomizer.dll
[2009/08/31 14:00:21 | 000,185,344 | —- | C] () – C:\WINDOWS\System32\MemWarp.dll
[2009/08/06 16:03:26 | 000,000,053 | —- | C] () – C:\WINDOWS\wowserver.ini
[2009/07/02 00:40:52 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2009/07/02 00:40:52 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2009/07/02 00:40:52 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2008/04/11 09:27:40 | 000,000,032 | —- | C] () – C:\Documents and Settings\All Users\Application Data\ezsid.dat
[2007/09/17 11:34:00 | 000,001,352 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/08/31 15:46:00 | 000,004,048 | —- | C] () – C:\WINDOWS\WinSig.Ini
[2007/08/31 15:46:00 | 000,000,046 | —- | C] () – C:\WINDOWS\Reader.Ini
[2007/08/31 15:43:51 | 000,002,191 | —- | C] () – C:\WINDOWS\WinRos.Ini
[2007/08/24 15:25:34 | 000,000,000 | —- | C] () – C:\WINDOWS\AIQvRpts.ini
[2007/08/13 01:08:41 | 000,001,838 | —- | C] () – C:\WINDOWS\rtalerts.INI
[2007/08/12 00:41:57 | 000,001,580 | —- | C] () – C:\WINDOWS\aiqeds.INI
[2007/08/12 00:27:41 | 000,000,000 | —- | C] () – C:\WINDOWS\Buildmtl.INI
[2007/08/12 00:27:34 | 000,001,215 | —- | C] () – C:\WINDOWS\rtcom.ini
[2007/08/12 00:27:33 | 000,002,118 | —- | C] () – C:\WINDOWS\aiqch32.ini
[2007/08/12 00:27:30 | 000,001,039 | —- | C] () – C:\WINDOWS\aiq32.ini
[2007/04/04 16:12:52 | 000,000,000 | —- | C] () – C:\WINDOWS\Poker.com
[2007/01/30 00:49:50 | 000,397,312 | —- | C] () – C:\WINDOWS\iwexec.exe
[2007/01/12 15:56:50 | 000,000,033 | —- | C] () – C:\WINDOWS\dshowaudio.ini
[2006/12/11 01:51:15 | 000,000,071 | —- | C] () – C:\WINDOWS\hotComm.INI
[2006/10/18 15:51:37 | 000,684,032 | —- | C] () – C:\WINDOWS\libeay32.dll
[2006/10/18 15:51:37 | 000,155,648 | —- | C] () – C:\WINDOWS\ssleay32.dll
[2006/10/06 22:24:40 | 000,000,227 | —- | C] () – C:\WINDOWS\HP_CounterReport_Update_HPSU.ini
[2006/10/06 22:24:28 | 000,000,214 | —- | C] () – C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2006/09/28 19:15:13 | 000,000,040 | —- | C] () – C:\WINDOWS\opt_2460.ini
[2006/09/27 11:10:35 | 000,000,051 | —- | C] () – C:\WINDOWS\brmx2001.ini
[2006/09/27 11:06:43 | 000,000,291 | —- | C] () – C:\WINDOWS\Brpcfx.ini
[2006/09/27 11:06:39 | 000,000,052 | —- | C] () – C:\WINDOWS\BRPP2KA.INI
[2006/09/27 11:06:39 | 000,000,000 | —- | C] () – C:\WINDOWS\brwmark.ini
[2006/09/27 10:39:36 | 000,002,326 | —- | C] () – C:\WINDOWS\MAXLINK.INI
[2006/09/27 10:39:36 | 000,000,090 | —- | C] () – C:\WINDOWS\calera.ini
[2006/09/15 17:22:43 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2006/09/08 17:19:15 | 000,000,558 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2006/09/08 12:02:18 | 000,000,043 | —- | C] () – C:\WINDOWS\WALLSTRT.INI
[2006/09/07 11:29:16 | 000,000,032 | —- | C] () – C:\WINDOWS\BrmfXCh1.ini
[2006/09/07 11:17:13 | 000,002,653 | —- | C] () – C:\WINDOWS\BRMFBIDI.INI
[2006/09/07 00:36:49 | 000,005,108 | —- | C] () – C:\WINDOWS\mozver.dat
[2006/09/06 21:09:07 | 000,000,206 | —- | C] () – C:\WINDOWS\HPGdiPlus.ini
[2006/09/06 21:06:55 | 000,000,221 | —- | C] () – C:\WINDOWS\HP_RedboxHprblog_HPSU.ini
[2006/03/12 10:30:53 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/03/12 10:10:24 | 000,028,848 | —- | C] () – C:\WINDOWS\System32\drivers\USBkey.sys
[2006/03/12 10:08:18 | 000,118,842 | R— | C] () – C:\WINDOWS\HPCPCUninstaller-6.3.2.116-9972322.exe
[2006/03/12 10:07:35 | 000,014,316 | —- | C] () – C:\WINDOWS\System32\CHODDI.SYS
[2006/03/12 10:07:25 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\hpreg.dll
[2006/03/12 10:05:07 | 000,000,031 | —- | C] () – C:\WINDOWS\Quicken.ini
[2006/03/12 10:02:56 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/03/12 09:54:08 | 000,000,108 | —- | C] () – C:\WINDOWS\WININIT.INI
[2006/03/12 09:53:03 | 000,045,929 | —- | C] () – C:\WINDOWS\NSSetDefaultBrowser.EXE
[2006/03/12 09:53:03 | 000,000,698 | —- | C] () – C:\WINDOWS\NSSetDefaultBrowser.ini
[2006/03/12 09:48:19 | 000,080,417 | —- | C] () – C:\WINDOWS\HPHins08.dat
[2006/03/12 09:48:18 | 000,004,011 | —- | C] () – C:\WINDOWS\hphmdl08.dat
[2006/03/12 09:47:39 | 000,072,881 | —- | C] () – C:\WINDOWS\hpiins01.dat
[2006/03/12 09:47:39 | 000,000,000 | —- | C] () – C:\WINDOWS\hpimdl01.dat
[2006/03/12 09:45:32 | 000,087,276 | —- | C] () – C:\WINDOWS\hpqins69.dat
[2006/03/12 09:44:20 | 000,112,873 | —- | C] () – C:\WINDOWS\hpoins07.dat
[2006/03/12 09:44:20 | 000,021,124 | —- | C] () – C:\WINDOWS\hpomdl07.dat
[2006/03/12 09:42:13 | 000,088,403 | —- | C] () – C:\WINDOWS\hpoins06.dat
[2006/03/12 09:42:12 | 000,005,389 | —- | C] () – C:\WINDOWS\hpomdl06.dat
[2006/03/12 09:41:27 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2006/03/12 09:38:44 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\hcwXDS.dll
[2006/03/12 09:37:16 | 000,129,084 | —- | C] () – C:\WINDOWS\System32\atiicdxx.dat
[2006/03/12 09:36:14 | 000,000,791 | —- | C] () – C:\WINDOWS\orun32.ini
[2006/03/12 09:17:09 | 000,323,584 | —- | C] () – C:\WINDOWS\System32\pythoncom22.dll
[2006/03/12 09:17:09 | 000,094,208 | —- | C] () – C:\WINDOWS\System32\pywintypes22.dll
[2006/03/12 09:16:52 | 000,016,896 | —- | C] () – C:\WINDOWS\System32\bcbmm.dll
[2005/12/09 17:03:52 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2005/08/31 00:17:40 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2005/08/31 00:07:46 | 000,381,692 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2005/08/31 00:07:46 | 000,053,436 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2005/08/31 00:05:30 | 000,216,064 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2005/08/31 00:01:42 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2005/08/30 23:58:02 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2005/08/06 01:01:54 | 000,239,104 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2004/08/10 07:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/10 00:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/10 00:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/10 00:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/10 00:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/10 00:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/10 00:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/08/10 00:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2004/07/26 10:51:38 | 000,000,560 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2003/11/16 05:48:02 | 000,909,312 | —- | C] () – C:\WINDOWS\System32\vorbisenc.dll
[2003/11/16 05:48:00 | 001,060,864 | —- | C] () – C:\WINDOWS\System32\vorbis.dll
[2003/11/15 12:54:18 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\ogg.dll
[2003/01/08 02:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2002/10/06 18:42:58 | 000,237,568 | —- | C] () – C:\WINDOWS\System32\OggDS.dll
[2001/08/23 11:12:28 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2001/08/23 11:11:02 | 000,004,490 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2001/07/07 02:30:00 | 000,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini

========== LOP Check ==========

[2009/05/21 11:09:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\1stWorks
[2010/10/21 18:58:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\93x8GFadd0YlOkwddBp3
[2010/11/23 17:06:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG10
[2010/07/01 21:41:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2009/02/22 17:16:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Azureus
[2010/11/22 23:48:44 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2006/03/12 09:52:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Digital Interactive Systems Corporation
[2009/01/14 14:16:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Downloaded Installations
[2010/09/14 01:14:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DriverCure
[2011/04/24 14:19:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\F-Secure
[2010/02/21 15:15:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GoodSync
[2008/07/04 15:14:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2010/09/21 23:48:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Hitman Pro
[2010/11/23 12:04:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\magicJack
[2011/04/09 12:40:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2009/06/23 09:48:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PCPitstop
[2006/09/07 00:33:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\RoboForm
[2010/01/12 18:52:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Seagate
[2009/05/18 20:43:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SITEguard
[2010/07/16 08:51:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2010/01/16 17:40:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/12/04 12:54:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TS Support
[2010/09/18 17:20:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Update
[2010/03/12 11:36:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2007/09/19 22:21:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ZILLAbar
[2009/02/22 15:04:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2009/04/12 21:51:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{63A9FDE6-FCC7-4E26-A4CF-552A08431B32}
[2010/02/07 21:32:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2006/09/07 01:39:00 | 000,004,833 | —- | M] () – C:\adp_inst.log
[2006/03/12 10:04:40 | 000,000,100 | —- | M] () – C:\AUTOEXEC.BAT
[2010/11/22 23:01:10 | 000,000,211 | RHS- | M] () – C:\Boot.bak
[2010/11/22 23:15:34 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2006/09/27 01:40:40 | 000,032,620 | —- | M] () – C:\candle.txt
[2004/08/09 17:00:00 | 000,260,272 | RHS- | M] () – C:\cmldr
[2010/09/20 18:22:01 | 000,026,863 | —- | M] () – C:\ComboFix.txt
[2005/08/31 00:02:02 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2007/11/07 11:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 11:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 11:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 11:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 11:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 11:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 11:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/07 11:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 11:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2006/10/20 15:27:40 | 000,000,087 | —- | M] () – C:\Export.txt
[2006/10/14 16:22:48 | 002,064,384 | —- | M] () – C:\ffastunT.ffl
[2007/11/07 11:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2009/02/11 15:56:14 | 000,000,262 | —- | M] () – C:\HCFRAME.HCD
[2011/05/06 13:56:14 | 2145,865,728 | -HS- | M] () – C:\hiberfil.sys
[2011/03/16 15:17:43 | 000,115,469 | —- | M] () – C:\hpWebHelper.log
[2007/11/07 11:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2007/11/07 11:03:18 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 11:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 11:03:18 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 11:03:18 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 11:03:18 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 11:03:18 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 11:03:18 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 11:03:18 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 11:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2005/08/31 00:02:02 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/04/29 17:39:17 | 000,000,109 | —- | M] () – C:\mbam-error.txt
[2005/08/31 00:02:02 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/09 17:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2010/12/07 15:46:57 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/05/06 13:56:10 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
[2006/10/31 09:58:00 | 000,000,000 | —- | M] () – C:\palsound.txt
[2010/09/21 21:34:41 | 000,003,180 | —- | M] () – C:\rapport.txt
[2010/07/07 01:52:04 | 000,000,279 | —- | M] () – C:\rkill.log
[2005/12/27 03:21:54 | 007,477,561 | —- | M] (Intel Corporation ) – C:\setup_all.exe
[2011/04/24 13:31:16 | 000,000,414 | —- | M] () – C:\TDSSKiller.2.4.18.0_24.04.2011_13.31.12_log.txt
[2011/04/24 13:32:34 | 000,041,410 | —- | M] () – C:\TDSSKiller.2.4.21.0_24.04.2011_13.32.05_log.txt
[2007/11/07 11:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 11:09:22 | 001,442,522 | —- | M] () – C:\VC_RED.cab
[2007/11/07 11:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI
[2008/08/03 10:20:19 | 000,000,156 | —- | M] () – C:\YServer.txt

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >
[2005/09/24 11:49:16 | 000,012,288 | —- | M] (Hewlett-Packard Development Company, L.P.) – C:\WINDOWS\Fonts\RandFont.dll

< %systemroot%\Fonts\*.ini >
[2005/08/31 00:01:20 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2006/10/14 17:43:18 | 000,027,648 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2007/04/09 14:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2006/10/14 17:44:44 | 000,671,744 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\PrintFilterPipelineSvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >
[2007/07/04 20:37:54 | 000,000,198 | —- | M] () – C:\Documents and Settings\All Users\Favorites\ Popups!.url
Here is the rest of the scan information after the "favorites";


[2007/06/15 10:29:02 | 000,000,182 | —- | M] () – C:\Documents and Settings\All Users\Favorites\“The Newbie Secret” - Private Pre Launch.url

< %APPDATA%\Microsoft\*.* >
[2011/02/14 12:48:00 | 000,001,714 | -H– | M] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Application Data\Microsoft\LastFlashConfig.WFC

< %PROGRAMFILES%\*.* >
[2009/07/02 02:47:51 | 000,000,528 | —- | M] () – C:\Program Files\cwdqd.txt

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2005/08/30 16:51:10 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2005/08/30 16:51:10 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2010/12/07 15:54:28 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/11/22 23:13:55 | 000,000,170 | -HS- | M] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2005/08/31 00:06:40 | 000,000,079 | —- | M] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2011/04/28 10:32:18 | 003,017,304 | —- | M] (Siber Systems) – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\AiRoboForm.exe
[2011/03/24 20:33:49 | 012,580,112 | —- | M] (Mozilla) – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\Firefox Setup 4.0(2).exe
[2011/04/23 15:04:59 | 000,173,456 | —- | M] (Symantec Corporation) – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\FixVundo.exe
[2011/03/29 16:15:29 | 005,862,296 | —- | M] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\hclsetup.exe
[2011/05/03 14:26:02 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\HiJackThis.exe
[2011/04/15 13:56:33 | 000,303,285 | —- | M] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\Install-RT-Alerts.exe
[2011/04/05 18:05:02 | 002,833,568 | —- | M] (Adobe Systems, Inc.) – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\install_flash_player(1).exe
[2009/10/03 00:03:32 | 005,689,344 | —- | M] (Gabest) – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\mplayerc.exe
[2011/03/13 19:25:28 | 000,520,397 | —- | M] (Nova Code Trader) – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\novachart.exe
[2011/05/06 11:15:32 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-04-28 06:02:27

========== Alternate Data Streams ==========

@Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8
@Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2

< End of report >
baldingeagle

The OTL log you sent was the result of the second time it was run. The first OTL scan and Extras file will be found on your desktop..

Don't worry about the first OTL log but please locate Extras.txt and copy/paste that in the next post together with the result of the Gmer scan.

Can you also let me know if there is any change since running Hostxpert.

Thanks

Satchfan
Hi Satchfan. I can not find the first OTL scan and Extras file on my Desktop. The first time I ran OTL, I got this message; "Access violation of address 0040295B in module 'OTL.exe' Read of address 0020D000" The scan just stopped so I ran it again and it completed the scan the second time I tried it, but I don't see any Extras file on my Desktop. I apologize if I should have stopped and contacted you after the first scan. I am attaching the GMER scan which took a very long time. I was hoping to get that to you sooner. After running HostXpert, I rebooted my computer, but nothing had changed as far as the problems I am having. Thanks for your help, baldingeagle

Attachments:

Hi baldingeagle
• run OTL again, click on Extra Registry -> Use Safelist
• then click Run Scan
Post back with the 2 logfiles

===================================================

Download aswMBR.exe ( 511KB ) to your desktop.

Double click the aswMBR.exe to run it

Click the "Scan" button to start scan
[external image: Posted Image]

On completion of the scan click save log, save it to your desktop and post in your next reply
[external image: Posted Image]

Satchfan
Hi Satchfan.

I will post the OTL.txt and the Extras.txt separately. I will leave out the Users/Favorites because it is so long. If you need them, please let me know.



OTL logfile created on: 5/7/2011 10:16:46 AM - Run 3
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 62.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 85.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 270.76 Gb Total Space | 26.51 Gb Free Space | 9.79% Space Free | Partition Type: NTFS
Drive D: | 8.68 Gb Total Space | 0.49 Gb Free Space | 5.61% Space Free | Partition Type: FAT32

Computer Name: YOUR-4DACD0EA75 | User Name: HP_Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe (Siber Systems)
PRC - C:\Program Files\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe (Seagate Technology LLC)
PRC - C:\Program Files\Seagate\SeagateManager\FreeAgent Status\stxmenumgr.exe (Seagate LLC)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe (Hewlett-Packard)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Intel Corporation)
PRC - C:\Program Files\DISC\DiscGui.exe (Digital Interactive Systems Corporation, Inc.)
PRC - C:\Program Files\DISC\DISCover.exe (Digital Interactive Systems Corporation)
PRC - C:\Program Files\DISC\DISCUpdateMgr.exe (Digital Interactive Systems Corporation, Inc.)
PRC - C:\Program Files\DISC\DiscStreamHub.exe (Digital Interactive Systems Corporation, Inc.)
PRC - C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe (Intel Corporation)
PRC - C:\Program Files\Sonic\DigitalMedia Plus\DigitalMedia Archive\DMAScheduler.exe (Sonic Solutions)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchrome10browserrecordhelper.dll (RealNetworks, Inc.)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcr90.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcp90.dll (Microsoft Corporation)
MOD - C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Local Settings\Temp\IadHide5.dll (BackWeb)


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – File not found
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) – C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (FreeAgentGoNext Service) – C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe (Seagate Technology LLC)
SRV - (IAANTMON) Intel® – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Intel Corporation)
SRV - (ELService) – C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe (Intel Corporation)


========== Driver Services (SafeList) ==========

DRV - (F-Secure Standalone Minifilter) – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Local Settings\Temp\OnlineScanner\Anti-Virus\fsgk.sys ()
DRV - (Avgldx86) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgtdix) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSEH) – C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgmfx86) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) – C:\WINDOWS\system32\DRIVERS\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSFilter) – C:\WINDOWS\system32\drivers\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSDriver) – C:\WINDOWS\system32\drivers\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSShim) – C:\WINDOWS\system32\drivers\AVGIDSShim.sys (AVG Technologies CZ, s.r.o. )
DRV - (RTL8192su) – C:\WINDOWS\system32\drivers\RTL8192su.sys (Realtek Semiconductor Corporation )
DRV - (NPF) – C:\WINDOWS\system32\drivers\npf.sys (CACE Technologies, Inc.)
DRV - (mf) – C:\WINDOWS\system32\drivers\mf.sys (Microsoft Corporation)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (Ps2) – C:\WINDOWS\system32\drivers\PS2.sys (Hewlett-Packard Company)
DRV - (ELacpi) – C:\WINDOWS\system32\drivers\ELacpi.sys (Intel Corporation)
DRV - (ELmon) – C:\WINDOWS\system32\drivers\ELmon.sys (Intel Corporation)
DRV - (ELkbd) – C:\WINDOWS\system32\drivers\ELkbd.sys (Intel Corporation)
DRV - (ELmou) – C:\WINDOWS\system32\drivers\ELmou.sys (Intel Corporation)
DRV - (ELhid) – C:\WINDOWS\system32\drivers\ELhid.sys (Intel Corporation)
DRV - (AgereSoftModem) – C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (hcwPP2) – C:\WINDOWS\system32\drivers\hcwPP2.sys (Hauppauge Computer Works, Inc.)
DRV - (ftsata2) – C:\WINDOWS\system32\DRIVERS\ftsata2.sys (Promise Technology, Inc.)
DRV - (rtl8139) Realtek RTL8139(A/B/C) – C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)
DRV - (bb-run) – C:\WINDOWS\system32\DRIVERS\bb-run.sys (Promise Technology, Inc.)
DRV - (BrUsbScn) – C:\WINDOWS\system32\drivers\BrUsbScn.sys (Brother Industries Ltd.)
DRV - (brfilt) – C:\WINDOWS\system32\drivers\BrFilt.sys (Brother Industries Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:10.0.0.1178
FF - prefs.js..extensions.enabledItems: {3e0e7d2a-070f-4a47-b019-91fe5385ba79}:3.1.0
FF - prefs.js..extensions.enabledItems: vshare@toolbar:1.0.0
FF - prefs.js..network.proxy.type: 0

FF - HKLM\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG10\Firefox4\ [2011/03/30 10:25:22 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/04/16 10:13:58 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{22119944-ED35-4ab1-910B-E619EA06A115}: C:\Program Files\Siber Systems\AI RoboForm\Firefox [2011/03/25 13:43:14 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/04/23 14:47:48 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/04/16 10:14:34 | 000,000,000 | —D | M]

[2010/11/22 23:31:31 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Application Data\Mozilla\Extensions
[2011/04/25 10:02:40 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Application Data\Mozilla\Firefox\Profiles\05kfcsd2.default\extensions
[2011/03/24 20:37:37 | 000,000,000 | —D | M] (AddThis) – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Application Data\Mozilla\Firefox\Profiles\05kfcsd2.default\extensions\{3e0e7d2a-070f-4a47-b019-91fe5385ba79}
[2010/11/28 14:09:46 | 000,000,000 | —D | M] (vShare) – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Application Data\Mozilla\Firefox\Profiles\05kfcsd2.default\extensions\vshare@toolbar
[2011/04/23 14:47:47 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/04/19 09:35:54 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/19 09:38:58 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/10/19 09:33:47 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/04/12 09:39:01 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/04/23 14:47:47 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\distribution\extensions
[2011/04/23 14:47:48 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Program Files\Mozilla Firefox\distribution\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
File not found (No name found) –
[2011/04/16 10:13:58 | 000,000,000 | —D | M] (RealPlayer Browser Record Plugin) – C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
() (No name found) – C:\DOCUMENTS AND SETTINGS\HP_ADMINISTRATOR.YOUR-4DACD0EA75.000\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\05KFCSD2.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
[2011/03/30 10:25:22 | 000,000,000 | —D | M] (AVG Safe Search) – C:\PROGRAM FILES\AVG\AVG10\FIREFOX4
[2010/11/23 02:49:39 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/03/25 13:43:14 | 000,000,000 | —D | M] (AI Roboform Toolbar for Firefox) – C:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\FIREFOX
[2010/01/01 04:00:00 | 000,135,168 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2011/04/14 17:18:26 | 000,289,592 | —- | M] (Cisco WebEx LLC) – C:\Program Files\Mozilla Firefox\plugins\ieatgpc.dll
[2011/04/14 17:17:53 | 000,172,344 | —- | M] (Cisco WebEx LLC) – C:\Program Files\Mozilla Firefox\plugins\npatgpc.dll
[2011/02/02 21:40:24 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/01/01 04:00:00 | 000,002,252 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\bing.xml

O1 HOSTS File: ([2011/05/06 10:52:34 | 000,000,698 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (&Google;) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (&RoboForm;) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&Google;) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&RoboForm;) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [DISCover] C:\Program Files\DISC\DISCover.exe (Digital Interactive Systems Corporation)
O4 - HKLM..\Run: [DiscUpdateManager] C:\Program Files\DISC\DISCUpdateMgr.exe (Digital Interactive Systems Corporation, Inc.)
O4 - HKLM..\Run: [DMAScheduler] c:\Program Files\Sonic\DigitalMedia Plus\DigitalMedia Archive\DMAScheduler.exe (Sonic Solutions)
O4 - HKLM..\Run: [HPBootOp] C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe (Hewlett-Packard)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [MaxMenuMgr] C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe (Seagate LLC)
O4 - HKLM..\Run: [PCDrProfiler] File not found
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\Recguard.exe ()
O4 - HKLM..\Run: [Reminder] C:\Windows\Creator\Remind_XP.exe (SoftThinks)
O4 - HKLM..\Run: [TkBellExe] C:\program files\real\realplayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [RoboForm] C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (Siber Systems)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Updates From HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe (Hewlett-Packard)
O4 - Startup: C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Start Menu\Programs\Startup\OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O4 - Startup: C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Start Menu\Programs\Startup\Seagate 2GEXM0JE Product Registration.lnk = C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Application Data\Leadertech\PowerRegister\Seagate 2GEXM0JE Product Registration.exe (Leader Technologies/Seagate)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &Google; Search - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: &Translate; English Word - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Backward Links - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Cached Snapshot of Page - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Customize Menu - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html ()
O8 - Extra context menu item: Fill Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O8 - Extra context menu item: RoboForm Toolbar - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O8 - Extra context menu item: Save Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O8 - Extra context menu item: Similar Pages - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Translate Page into English - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O9 - Extra Button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra 'Tools' menuitem : Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra Button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra 'Tools' menuitem : Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra 'Tools' menuitem : RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra Button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ()
O9 - Extra 'Tools' menuitem : Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ()
O15 - HKLM\..Trusted Domains: trymedia.com ([]http in Trusted sites)
O15 - HKLM\..Trusted Domains: trymedia.com ([]https in Trusted sites)
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/e/2…78f/wvc1dmo.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/03/12 10:04:40 | 000,000,100 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2001/07/27 15:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync) - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart) - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.LEAD - C:\WINDOWS\System32\LCodcCMP.dll (LEAD Technologies, Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)

========== Files/Folders - Created Within 30 Days ==========

[2011/05/06 11:15:17 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\OTL.exe
[2011/05/06 10:51:57 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\HostsXpert
[2011/05/03 14:26:01 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\HiJackThis.exe
[2011/04/28 10:49:48 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\AI RoboForm
[2011/04/24 14:19:42 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Application Data\f-secure
[2011/04/24 14:19:16 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\F-Secure
[2011/04/23 15:07:50 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2011/04/23 15:07:50 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Start Menu\Programs\HiJackThis
[2011/04/23 15:04:48 | 000,173,456 | —- | C] (Symantec Corporation) – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\FixVundo.exe
[2011/04/21 16:27:19 | 000,947,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msjava.bak
[2011/04/16 10:14:04 | 000,000,000 | —D | C] – C:\Program Files\Common Files\xing shared
[2011/04/16 10:13:44 | 000,198,848 | —- | C] (RealNetworks, Inc.) – C:\WINDOWS\System32\rmoc3260.dll
[2011/04/16 10:13:26 | 000,006,656 | —- | C] (RealNetworks, Inc.) – C:\WINDOWS\System32\pndx5016.dll
[2011/04/16 10:13:26 | 000,005,632 | —- | C] (RealNetworks, Inc.) – C:\WINDOWS\System32\pndx5032.dll
[2011/04/15 16:50:28 | 000,000,000 | —D | C] – C:\WINDOWS\System32\Registry Patrol
[2011/04/15 16:49:59 | 000,000,000 | —D | C] – C:\Program Files\Registry Patrol
[2011/04/15 15:01:04 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Local Settings\Application Data\PackageAware
[2011/04/15 13:56:59 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Start Menu\Programs\RT-Alerts
[2011/04/15 13:50:09 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Application Data\RT-Alerts
[2011/04/14 17:18:57 | 000,000,000 | -HSD | C] – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\My Documents\cache
[2011/04/14 17:18:57 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Application Data\webex
[2011/04/12 09:38:59 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/04/12 09:38:59 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/04/12 09:38:59 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2011/04/11 11:18:37 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Application Data\HpUpdate
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/05/07 10:20:00 | 000,001,062 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1747380976-3469703338-1627799412-1008UA.job
[2011/05/07 10:16:41 | 000,000,300 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1747380976-3469703338-1627799412-1008.job
[2011/05/07 10:16:39 | 000,000,308 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-1747380976-3469703338-1627799412-1008.job
[2011/05/07 09:42:27 | 114,392,365 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2011/05/07 09:40:10 | 000,000,248 | —- | M] () – C:\WINDOWS\System\hpsysdrv.dat
[2011/05/07 09:36:44 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/05/07 09:36:40 | 2145,865,728 | -HS- | M] () – C:\hiberfil.sys
[2011/05/06 15:55:50 | 000,293,775 | —- | M] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\gmer.zip
[2011/05/06 14:59:45 | 000,014,296 | —- | M] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\letter to eyebuydirect.odt
[2011/05/06 14:20:00 | 000,001,010 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1747380976-3469703338-1627799412-1008Core.job
[2011/05/06 13:44:26 | 000,217,088 | —- | M] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/05/06 11:15:32 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\OTL.exe
[2011/05/06 10:51:47 | 000,353,485 | —- | M] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\HostsXpert.zip
[2011/05/05 21:54:52 | 000,870,128 | —- | M] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Application Data\mcs.rma
[2011/05/05 21:54:52 | 000,000,004 | —- | M] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Application Data\25A1A5
[2011/05/05 14:46:33 | 000,002,653 | —- | M] () – C:\WINDOWS\BRMFBIDI.INI
[2011/05/04 19:08:08 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/05/03 14:26:02 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\HiJackThis.exe
[2011/05/01 10:26:34 | 000,016,968 | —- | M] () – C:\WINDOWS\System32\drivers\hitmanpro35.sys
[2011/04/28 10:32:18 | 003,017,304 | —- | M] (Siber Systems) – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\AiRoboForm.exe
[2011/04/27 16:11:15 | 000,001,782 | —- | M] () – C:\Documents and Settings\All Users\Desktop\hotCommCL.lnk
[2011/04/27 16:11:15 | 000,001,140 | —- | M] () – C:\Documents and Settings\All Users\Desktop\hotCommCL Transcripts.lnk
[2011/04/27 16:11:15 | 000,001,116 | —- | M] () – C:\Documents and Settings\All Users\Desktop\hotCommCL Uploads.lnk
[2011/04/25 11:36:55 | 000,180,759 | —- | M] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\Faye Bragg eye exam 2.JPG
[2011/04/25 11:35:37 | 000,424,184 | —- | M] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\Faye Bragg eye exam 1.JPG
[2011/04/23 16:31:19 | 000,639,741 | —- | M] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\Ken Bragg's Eye Exam 2.JPG
[2011/04/23 16:29:36 | 000,001,471 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Media Center.lnk
[2011/04/23 16:29:19 | 000,290,908 | —- | M] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\Ken Bragg's Eye Exam 1.JPG
[2011/04/23 15:32:51 | 000,000,000 | —- | M] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\My Documents\firefox352.exe
[2011/04/23 15:06:50 | 001,402,880 | —- | M] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\HijackThis.msi
[2011/04/23 15:04:59 | 000,173,456 | —- | M] (Symantec Corporation) – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\FixVundo.exe
[2011/04/23 14:47:54 | 000,000,753 | —- | M] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/04/23 14:47:54 | 000,000,735 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/04/23 14:24:52 | 000,001,425 | —- | M] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Start Menu\Programs\Startup\Seagate 2GEXM0JE Product Registration.lnk
[2011/04/23 13:53:27 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/04/18 18:29:00 | 000,196,968 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\iavichjg.avm
[2011/04/16 10:14:23 | 000,000,747 | —- | M] () – C:\Documents and Settings\All Users\Desktop\RealPlayer.lnk
[2011/04/16 10:13:44 | 000,198,848 | —- | M] (RealNetworks, Inc.) – C:\WINDOWS\System32\rmoc3260.dll
[2011/04/16 10:13:26 | 000,006,656 | —- | M] (RealNetworks, Inc.) – C:\WINDOWS\System32\pndx5016.dll
[2011/04/16 10:13:26 | 000,005,632 | —- | M] (RealNetworks, Inc.) – C:\WINDOWS\System32\pndx5032.dll
[2011/04/16 10:13:24 | 000,272,896 | —- | M] (Progressive Networks) – C:\WINDOWS\System32\pncrt.dll
[2011/04/15 13:56:59 | 000,159,519 | —- | M] () – C:\WINDOWS\RT-Alerts Uninstaller.exe
[2011/04/15 13:56:59 | 000,000,651 | —- | M] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\RT-Alerts.lnk
[2011/04/15 13:56:33 | 000,303,285 | —- | M] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\Install-RT-Alerts.exe
[2011/04/14 11:18:09 | 000,216,064 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/04/14 01:09:08 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/05/06 15:55:50 | 000,293,775 | —- | C] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\gmer.zip
[2011/05/06 14:59:44 | 000,014,296 | —- | C] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\letter to eyebuydirect.odt
[2011/05/06 10:51:41 | 000,353,485 | —- | C] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\HostsXpert.zip
[2011/04/25 11:36:55 | 000,180,759 | —- | C] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\Faye Bragg eye exam 2.JPG
[2011/04/25 11:35:37 | 000,424,184 | —- | C] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\Faye Bragg eye exam 1.JPG
[2011/04/23 16:31:18 | 000,639,741 | —- | C] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\Ken Bragg's Eye Exam 2.JPG
[2011/04/23 16:29:18 | 000,290,908 | —- | C] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\Ken Bragg's Eye Exam 1.JPG
[2011/04/23 15:33:25 | 000,000,000 | —- | C] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\My Documents\firefox352.exe
[2011/04/23 15:06:49 | 001,402,880 | —- | C] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\HijackThis.msi
[2011/04/23 14:15:41 | 000,001,062 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1747380976-3469703338-1627799412-1008UA.job
[2011/04/23 14:15:40 | 000,001,010 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1747380976-3469703338-1627799412-1008Core.job
[2011/04/16 10:15:03 | 000,000,300 | —- | C] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1747380976-3469703338-1627799412-1008.job
[2011/04/16 10:15:01 | 000,000,308 | —- | C] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-1747380976-3469703338-1627799412-1008.job
[2011/04/16 10:14:23 | 000,000,747 | —- | C] () – C:\Documents and Settings\All Users\Desktop\RealPlayer.lnk
[2011/04/15 13:56:59 | 000,159,519 | —- | C] () – C:\WINDOWS\RT-Alerts Uninstaller.exe
[2011/04/15 13:56:59 | 000,000,651 | —- | C] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\RT-Alerts.lnk
[2011/04/15 13:56:33 | 000,303,285 | —- | C] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\Install-RT-Alerts.exe
[2010/11/28 00:37:54 | 000,000,004 | —- | C] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Application Data\25A1A5
[2010/11/28 00:37:53 | 000,870,128 | —- | C] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Application Data\mcs.rma
[2010/11/24 11:02:47 | 000,520,192 | —- | C] () – C:\WINDOWS\System32\ati2sgag.exe
[2010/11/23 22:36:24 | 000,651,264 | —- | C] () – C:\WINDOWS\System32\brfxdial.dll
[2010/11/23 19:24:24 | 000,000,256 | R— | C] () – C:\WINDOWS\System32\brmsl05f.bin
[2010/11/23 11:55:50 | 000,217,088 | —- | C] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/11/23 00:27:18 | 000,016,968 | —- | C] () – C:\WINDOWS\System32\drivers\hitmanpro35.sys
[2010/11/22 23:03:32 | 000,000,159 | —- | C] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Local Settings\Application Data\fusioncache.dat
[2010/10/21 02:42:41 | 000,137,088 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/09/10 10:25:16 | 000,000,107 | —- | C] () – C:\Documents and Settings\All Users\Application Data\Microsoft.SqlServer.Compact.351.32.bc
[2010/08/27 11:31:46 | 000,002,161 | —- | C] () – C:\WINDOWS\StockNeuroMaster.INI
[2010/07/04 18:09:02 | 000,256,512 | —- | C] () – C:\WINDOWS\PEV.exe
[2010/04/16 18:25:14 | 000,077,312 | —- | C] () – C:\WINDOWS\MBR.exe
[2010/04/04 14:19:46 | 000,002,042 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\8s32
[2010/04/02 16:12:13 | 000,002,270 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\LK2mfPE2j
[2010/03/03 10:58:32 | 000,160,032 | —- | C] () – C:\WINDOWS\RampRT Uninstaller.exe.bak
[2009/12/12 17:21:02 | 000,000,000 | —- | C] () – C:\WINDOWS\Opefeyesu.bin
[2009/12/12 17:21:01 | 000,000,120 | —- | C] () – C:\WINDOWS\Cnarusi.dat
[2009/11/02 11:04:16 | 000,000,323 | —- | C] () – C:\WINDOWS\MessorAnalytics_RegressionChannel_uninstall.ini
[2009/11/02 11:03:47 | 000,000,303 | —- | C] () – C:\WINDOWS\MessorAnalytics_Ergodic_uninstall.ini
[2009/10/20 14:19:30 | 000,053,299 | —- | C] () – C:\WINDOWS\System32\pthreadVC.dll
[2009/10/02 03:04:30 | 000,000,034 | —- | C] () – C:\WINDOWS\AuthMgr.INI
[2009/09/04 15:49:05 | 000,001,469 | —- | C] () – C:\WINDOWS\w59_prmf.dat
[2009/08/31 14:00:22 | 000,021,504 | —- | C] () – C:\WINDOWS\System32\WBCustomizer.dll
[2009/08/31 14:00:21 | 000,185,344 | —- | C] () – C:\WINDOWS\System32\MemWarp.dll
[2009/08/06 16:03:26 | 000,000,053 | —- | C] () – C:\WINDOWS\wowserver.ini
[2009/07/02 00:40:52 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2009/07/02 00:40:52 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2009/07/02 00:40:52 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2008/04/11 09:27:40 | 000,000,032 | —- | C] () – C:\Documents and Settings\All Users\Application Data\ezsid.dat
[2007/09/17 11:34:00 | 000,001,352 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/08/31 15:46:00 | 000,004,048 | —- | C] () – C:\WINDOWS\WinSig.Ini
[2007/08/31 15:46:00 | 000,000,046 | —- | C] () – C:\WINDOWS\Reader.Ini
[2007/08/31 15:43:51 | 000,002,191 | —- | C] () – C:\WINDOWS\WinRos.Ini
[2007/08/24 15:25:34 | 000,000,000 | —- | C] () – C:\WINDOWS\AIQvRpts.ini
[2007/08/13 01:08:41 | 000,001,838 | —- | C] () – C:\WINDOWS\rtalerts.INI
[2007/08/12 00:41:57 | 000,001,580 | —- | C] () – C:\WINDOWS\aiqeds.INI
[2007/08/12 00:27:41 | 000,000,000 | —- | C] () – C:\WINDOWS\Buildmtl.INI
[2007/08/12 00:27:34 | 000,001,215 | —- | C] () – C:\WINDOWS\rtcom.ini
[2007/08/12 00:27:33 | 000,002,118 | —- | C] () – C:\WINDOWS\aiqch32.ini
[2007/08/12 00:27:30 | 000,001,039 | —- | C] () – C:\WINDOWS\aiq32.ini
[2007/04/04 16:12:52 | 000,000,000 | —- | C] () – C:\WINDOWS\Poker.com
[2007/01/30 00:49:50 | 000,397,312 | —- | C] () – C:\WINDOWS\iwexec.exe
[2007/01/12 15:56:50 | 000,000,033 | —- | C] () – C:\WINDOWS\dshowaudio.ini
[2006/12/11 01:51:15 | 000,000,071 | —- | C] () – C:\WINDOWS\hotComm.INI
[2006/10/18 15:51:37 | 000,684,032 | —- | C] () – C:\WINDOWS\libeay32.dll
[2006/10/18 15:51:37 | 000,155,648 | —- | C] () – C:\WINDOWS\ssleay32.dll
[2006/10/06 22:24:40 | 000,000,227 | —- | C] () – C:\WINDOWS\HP_CounterReport_Update_HPSU.ini
[2006/10/06 22:24:28 | 000,000,214 | —- | C] () – C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2006/09/28 19:15:13 | 000,000,040 | —- | C] () – C:\WINDOWS\opt_2460.ini
[2006/09/27 11:10:35 | 000,000,051 | —- | C] () – C:\WINDOWS\brmx2001.ini
[2006/09/27 11:06:43 | 000,000,291 | —- | C] () – C:\WINDOWS\Brpcfx.ini
[2006/09/27 11:06:39 | 000,000,052 | —- | C] () – C:\WINDOWS\BRPP2KA.INI
[2006/09/27 11:06:39 | 000,000,000 | —- | C] () – C:\WINDOWS\brwmark.ini
[2006/09/27 10:39:36 | 000,002,326 | —- | C] () – C:\WINDOWS\MAXLINK.INI
[2006/09/27 10:39:36 | 000,000,090 | —- | C] () – C:\WINDOWS\calera.ini
[2006/09/15 17:22:43 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2006/09/08 17:19:15 | 000,000,558 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2006/09/08 12:02:18 | 000,000,043 | —- | C] () – C:\WINDOWS\WALLSTRT.INI
[2006/09/07 11:29:16 | 000,000,032 | —- | C] () – C:\WINDOWS\BrmfXCh1.ini
[2006/09/07 11:17:13 | 000,002,653 | —- | C] () – C:\WINDOWS\BRMFBIDI.INI
[2006/09/07 00:36:49 | 000,005,108 | —- | C] () – C:\WINDOWS\mozver.dat
[2006/09/06 21:09:07 | 000,000,206 | —- | C] () – C:\WINDOWS\HPGdiPlus.ini
[2006/09/06 21:06:55 | 000,000,221 | —- | C] () – C:\WINDOWS\HP_RedboxHprblog_HPSU.ini
[2006/03/12 10:30:53 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/03/12 10:10:24 | 000,028,848 | —- | C] () – C:\WINDOWS\System32\drivers\USBkey.sys
[2006/03/12 10:08:18 | 000,118,842 | R— | C] () – C:\WINDOWS\HPCPCUninstaller-6.3.2.116-9972322.exe
[2006/03/12 10:07:35 | 000,014,316 | —- | C] () – C:\WINDOWS\System32\CHODDI.SYS
[2006/03/12 10:07:25 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\hpreg.dll
[2006/03/12 10:05:07 | 000,000,031 | —- | C] () – C:\WINDOWS\Quicken.ini
[2006/03/12 10:02:56 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/03/12 09:54:08 | 000,000,108 | —- | C] () – C:\WINDOWS\WININIT.INI
[2006/03/12 09:53:03 | 000,045,929 | —- | C] () – C:\WINDOWS\NSSetDefaultBrowser.EXE
[2006/03/12 09:53:03 | 000,000,698 | —- | C] () – C:\WINDOWS\NSSetDefaultBrowser.ini
[2006/03/12 09:48:19 | 000,080,417 | —- | C] () – C:\WINDOWS\HPHins08.dat
[2006/03/12 09:48:18 | 000,004,011 | —- | C] () – C:\WINDOWS\hphmdl08.dat
[2006/03/12 09:47:39 | 000,072,881 | —- | C] () – C:\WINDOWS\hpiins01.dat
[2006/03/12 09:47:39 | 000,000,000 | —- | C] () – C:\WINDOWS\hpimdl01.dat
[2006/03/12 09:45:32 | 000,087,276 | —- | C] () – C:\WINDOWS\hpqins69.dat
[2006/03/12 09:44:20 | 000,112,873 | —- | C] () – C:\WINDOWS\hpoins07.dat
[2006/03/12 09:44:20 | 000,021,124 | —- | C] () – C:\WINDOWS\hpomdl07.dat
[2006/03/12 09:42:13 | 000,088,403 | —- | C] () – C:\WINDOWS\hpoins06.dat
[2006/03/12 09:42:12 | 000,005,389 | —- | C] () – C:\WINDOWS\hpomdl06.dat
[2006/03/12 09:41:27 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2006/03/12 09:38:44 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\hcwXDS.dll
[2006/03/12 09:37:16 | 000,129,084 | —- | C] () – C:\WINDOWS\System32\atiicdxx.dat
[2006/03/12 09:36:14 | 000,000,791 | —- | C] () – C:\WINDOWS\orun32.ini
[2006/03/12 09:17:09 | 000,323,584 | —- | C] () – C:\WINDOWS\System32\pythoncom22.dll
[2006/03/12 09:17:09 | 000,094,208 | —- | C] () – C:\WINDOWS\System32\pywintypes22.dll
[2006/03/12 09:16:52 | 000,016,896 | —- | C] () – C:\WINDOWS\System32\bcbmm.dll
[2005/12/09 17:03:52 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2005/08/31 00:17:40 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2005/08/31 00:07:46 | 000,381,692 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2005/08/31 00:07:46 | 000,053,436 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2005/08/31 00:05:30 | 000,216,064 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2005/08/31 00:01:42 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2005/08/30 23:58:02 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2005/08/06 01:01:54 | 000,239,104 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2004/08/10 07:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/10 00:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/10 00:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/10 00:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/10 00:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/10 00:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/10 00:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/08/10 00:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2004/07/26 10:51:38 | 000,000,560 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2003/11/16 05:48:02 | 000,909,312 | —- | C] () – C:\WINDOWS\System32\vorbisenc.dll
[2003/11/16 05:48:00 | 001,060,864 | —- | C] () – C:\WINDOWS\System32\vorbis.dll
[2003/11/15 12:54:18 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\ogg.dll
[2003/01/08 02:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2002/10/06 18:42:58 | 000,237,568 | —- | C] () – C:\WINDOWS\System32\OggDS.dll
[2001/08/23 11:12:28 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2001/08/23 11:11:02 | 000,004,490 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2001/07/07 02:30:00 | 000,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini

========== LOP Check ==========

[2009/05/21 11:09:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\1stWorks
[2010/10/21 18:58:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\93x8GFadd0YlOkwddBp3
[2010/11/23 17:06:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG10
[2010/07/01 21:41:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2009/02/22 17:16:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Azureus
[2010/11/22 23:48:44 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2006/03/12 09:52:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Digital Interactive Systems Corporation
[2009/01/14 14:16:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Downloaded Installations
[2010/09/14 01:14:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DriverCure
[2011/04/24 14:19:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\F-Secure
[2010/02/21 15:15:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GoodSync
[2008/07/04 15:14:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2010/09/21 23:48:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Hitman Pro
[2010/11/23 12:04:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\magicJack
[2011/04/09 12:40:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2009/06/23 09:48:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PCPitstop
[2006/09/07 00:33:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\RoboForm
[2010/01/12 18:52:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Seagate
[2009/05/18 20:43:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SITEguard
[2010/07/16 08:51:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2010/01/16 17:40:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/12/04 12:54:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TS Support
[2010/09/18 17:20:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Update
[2010/03/12 11:36:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2007/09/19 22:21:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ZILLAbar
[2009/02/22 15:04:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2009/04/12 21:51:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{63A9FDE6-FCC7-4E26-A4CF-552A08431B32}
[2010/02/07 21:32:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2006/09/07 01:39:00 | 000,004,833 | —- | M] () – C:\adp_inst.log
[2006/03/12 10:04:40 | 000,000,100 | —- | M] () – C:\AUTOEXEC.BAT
[2010/11/22 23:01:10 | 000,000,211 | RHS- | M] () – C:\Boot.bak
[2010/11/22 23:15:34 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2006/09/27 01:40:40 | 000,032,620 | —- | M] () – C:\candle.txt
[2004/08/09 17:00:00 | 000,260,272 | RHS- | M] () – C:\cmldr
[2010/09/20 18:22:01 | 000,026,863 | —- | M] () – C:\ComboFix.txt
[2005/08/31 00:02:02 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2007/11/07 11:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 11:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 11:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 11:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 11:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 11:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 11:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/07 11:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 11:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2006/10/20 15:27:40 | 000,000,087 | —- | M] () – C:\Export.txt
[2006/10/14 16:22:48 | 002,064,384 | —- | M] () – C:\ffastunT.ffl
[2007/11/07 11:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2009/02/11 15:56:14 | 000,000,262 | —- | M] () – C:\HCFRAME.HCD
[2011/05/07 09:36:40 | 2145,865,728 | -HS- | M] () – C:\hiberfil.sys
[2011/03/16 15:17:43 | 000,115,469 | —- | M] () – C:\hpWebHelper.log
[2007/11/07 11:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2007/11/07 11:03:18 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 11:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 11:03:18 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 11:03:18 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 11:03:18 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 11:03:18 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 11:03:18 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 11:03:18 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 11:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2005/08/31 00:02:02 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/04/29 17:39:17 | 000,000,109 | —- | M] () – C:\mbam-error.txt
[2005/08/31 00:02:02 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/09 17:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2010/12/07 15:46:57 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/05/07 09:36:35 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
[2006/10/31 09:58:00 | 000,000,000 | —- | M] () – C:\palsound.txt
[2010/09/21 21:34:41 | 000,003,180 | —- | M] () – C:\rapport.txt
[2010/07/07 01:52:04 | 000,000,279 | —- | M] () – C:\rkill.log
[2005/12/27 03:21:54 | 007,477,561 | —- | M] (Intel Corporation ) – C:\setup_all.exe
[2011/04/24 13:31:16 | 000,000,414 | —- | M] () – C:\TDSSKiller.2.4.18.0_24.04.2011_13.31.12_log.txt
[2011/04/24 13:32:34 | 000,041,410 | —- | M] () – C:\TDSSKiller.2.4.21.0_24.04.2011_13.32.05_log.txt
[2007/11/07 11:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 11:09:22 | 001,442,522 | —- | M] () – C:\VC_RED.cab
[2007/11/07 11:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI
[2008/08/03 10:20:19 | 000,000,156 | —- | M] () – C:\YServer.txt

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >
[2005/09/24 11:49:16 | 000,012,288 | —- | M] (Hewlett-Packard Development Company, L.P.) – C:\WINDOWS\Fonts\RandFont.dll

< %systemroot%\Fonts\*.ini >
[2005/08/31 00:01:20 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2006/10/14 17:43:18 | 000,027,648 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2007/04/09 14:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2006/10/14 17:44:44 | 000,671,744 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\PrintFilterPipelineSvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >
[2007/07/04 20:37:54 | 000,000,198 | —- | M] () – C:\Documents and Settings\All Users\Favorites\ Popups!.url





[2007/06/15 10:29:02 | 000,000,182 | —- | M] () – C:\Documents and Settings\All Users\Favorites\“The Newbie Secret” - Private Pre Launch.url

< %APPDATA%\Microsoft\*.* >
[2011/02/14 12:48:00 | 000,001,714 | -H– | M] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Application Data\Microsoft\LastFlashConfig.WFC

< %PROGRAMFILES%\*.* >
[2009/07/02 02:47:51 | 000,000,528 | —- | M] () – C:\Program Files\cwdqd.txt

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2005/08/30 16:51:10 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2005/08/30 16:51:10 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2010/12/07 15:54:28 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/11/22 23:13:55 | 000,000,170 | -HS- | M] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2005/08/31 00:06:40 | 000,000,079 | —- | M] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2011/04/28 10:32:18 | 003,017,304 | —- | M] (Siber Systems) – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\AiRoboForm.exe
[2011/03/24 20:33:49 | 012,580,112 | —- | M] (Mozilla) – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\Firefox Setup 4.0(2).exe
[2011/04/23 15:04:59 | 000,173,456 | —- | M] (Symantec Corporation) – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\FixVundo.exe
[2011/03/29 16:15:29 | 005,862,296 | —- | M] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\hclsetup.exe
[2011/05/03 14:26:02 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\HiJackThis.exe
[2011/04/15 13:56:33 | 000,303,285 | —- | M] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\Install-RT-Alerts.exe
[2011/04/05 18:05:02 | 002,833,568 | —- | M] (Adobe Systems, Inc.) – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\install_flash_player(1).exe
[2009/10/03 00:03:32 | 005,689,344 | —- | M] (Gabest) – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\mplayerc.exe
[2011/03/13 19:25:28 | 000,520,397 | —- | M] (Nova Code Trader) – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\novachart.exe
[2011/05/06 11:15:32 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-04-28 06:02:27

========== Alternate Data Streams ==========

@Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8
@Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2

< End of report >
Extras.txt



OTL Extras logfile created on: 5/7/2011 10:16:46 AM - Run 3
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 62.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 85.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 270.76 Gb Total Space | 26.51 Gb Free Space | 9.79% Space Free | Partition Type: NTFS
Drive D: | 8.68 Gb Total Space | 0.49 Gb Free Space | 5.61% Space Free | Partition Type: FAT32

Computer Name: YOUR-4DACD0EA75 | User Name: HP_Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – "C:\Program Files\File Type Assistant\tsassist.exe" "%1" (Trusted Software ApS)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe" = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe:*:Enabled:Updates from HP – (Hewlett-Packard)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe" = C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe – ()
"C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe – ( )
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe – (Hewlett-Packard Co.)
"C:\Program Files\DISC\DISCover.exe" = C:\Program Files\DISC\DISCover.exe:*:Enabled:DISCover Drop & Play System – (Digital Interactive Systems Corporation)
"C:\Program Files\DISC\DiscStreamHub.exe" = C:\Program Files\DISC\DiscStreamHub.exe:*:Enabled:DISCover Stream Hub – (Digital Interactive Systems Corporation, Inc.)
"C:\Program Files\DISC\myFTP.exe" = C:\Program Files\DISC\myFTP.exe:*:Enabled:DISCover FTP – (Digital Interactive Systems Corporation, Inc.)
"C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe" = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe:*:Enabled:Updates from HP – (Hewlett-Packard)
"C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" = C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink – (EarthLink, Inc.)
"C:\Program Files\AVG\AVG10\avgmfapx.exe" = C:\Program Files\AVG\AVG10\avgmfapx.exe:*:Enabled:AVG Installer – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox – (Mozilla Corporation)
"C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Application Data\mjusbsp\magicJack.exe" = C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Application Data\mjusbsp\magicJack.exe:*:Enabled:magicJack – (magicJack L.P.)
"C:\Program Files\1stWORKS\hotCommCL\BIN\HotComm.exe" = C:\Program Files\1stWORKS\hotCommCL\BIN\HotComm.exe:*:Enabled:hotComm CL Client – (1stWorks Corporation)
"C:\Program Files\AVG\AVG10\avgdiagex.exe" = C:\Program Files\AVG\AVG10\avgdiagex.exe:*:Enabled:AVG Diagnostics 2011 – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG10\avgnsx.exe" = C:\Program Files\AVG\AVG10\avgnsx.exe:*:Enabled:Online Shield – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG10\avgemcx.exe" = C:\Program Files\AVG\AVG10\avgemcx.exe:*:Enabled:Personal E-mail Scanner – (AVG Technologies CZ, s.r.o.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{02850087-A59F-4782-B8AF-40674752D5F1}" = ATI Catalyst Control Center
"{075473F5-846A-448B-BCB3-104AA1760205}" = Sonic RecordNow Data
"{0B33B738-AD79-4E32-90C5-E67BFB10BBFF}" = AiO_Scan
"{0C3FCE48-6984-11D5-90F8-00E029591716}" = Brother MFL Pro Suite
"{172975EB-9465-4861-95B5-C7BB6D3DE62A}" = DocumentViewer
"{1CB34CE9-0E6B-493F-BB66-3425E5DF76E5}" = CP_CalendarTemplates1
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{21657574-BD54-48A2-9450-EB03B2C7FC29}" = Sonic MyDVD Plus
"{23012310-3E05-46A5-88A9-C6CBCABCAC79}" = Customer Experience Enhancement
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{23B35809-5E4A-4F14-8332-1CDEDDFAC089}" = CP_Package_Variety2
"{24BEBF2E-73F3-4599-840B-EDC612CCDD0D}" = Destinations
"{26A24AE4-039D-4CA4-87B4-2F83216016F0}" = Java™ 6 Update 16
"{26A24AE4-039D-4CA4-87B4-2F83216022FF}" = Java™ 6 Update 24
"{27E395E5-EB04-4BFD-96C3-C9A102E97E1B}" = Intel® Viiv™ Software
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2A30052B-831C-41D3-8044-3C0388066350}" = Seagate Manager Installer
"{2A548002-9042-4083-A270-B67473DE1073}" = SkinsHP1
"{2C5D07FB-31A2-4F2D-9FDA-0B24ACD42BD0}" = HP Deskjet Printer Preload
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
"{30C19FF2-7FBA-4d09-B9DE-1659977F64F6}" = TrayApp
"{3248F0A8-6813-11D6-A77B-00B0D0150050}" = J2SE Runtime Environment 5.0 Update 5
"{33D6CC28-9F75-4d1b-A11D-98895B3A3729}" = HP Photosmart 330,380,420,470,7800,8000,8200 Series
"{34F3FCF1-817B-4D61-B6AF-19D9486AFEA0}" = Unload
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35DD9A1D-B340-4F41-A8B0-6EEBFB119280}" = muvee autoProducer unPlugged 1.2
"{36D620AD-EEBA-4973-BA86-0C9AE6396620}" = OptionalContentQFolder
"{36FDBE6E-6684-462B-AE98-9A39A1B200CC}" = HP Product Assistant
"{3BA95526-6AE0-4B87-A62D-17187EF565FC}" = HP Boot Optimizer
"{3E386744-10FA-44b2-98C9-DF7A270DECB3}" = HP PSC & OfficeJet 5.3.A
"{3FE0CFAB-584A-4AA5-B8CD-C32284CFA308}" = RandMap
"{4041C245-7099-4C96-9738-5EBC23827B3C}" = BufferChm
"{416D80BA-6F6D-4672-B7CF-F54DA2F80B44}" = Microsoft Works
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP DVD Play 1.0
"{46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB}" = Adobe AIR
"{494D17B5-3369-4905-8C4B-80C972C5E0FF}" = CP_Panorama1Config
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4DA4012B-39AF-48c2-B23B-A4D570D233A6}" = cp_LightScribeConfig
"{522D1D79-9C0A-4361-91F8-2AFF8EC6C2E1}" = CP_Package_Variety1
"{53EE9E42-CECB-4C92-BF76-9CA65DAF8F1C}" = FullDPAppQFolder
"{54E3707F-808E-4fd4-95C9-15D1AB077E5D}" = NewCopy
"{54F0998F-73C8-4b51-8286-FE903C231BED}" = cp_PosterPrintConfig
"{567C23E1-7580-4185-B8C2-30805677297C}" = NewCopy_CDA
"{56F8AFC3-FA98-4ff1-9673-8A026CBF85BE}" = WebReg
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5B79CFD1-6845-4158-9D7D-6BE89DF2C135}" = HP PSC & OfficeJet 5.3.B
"{612F4E20-3661-4D44-AD79-823F1B613FB3}" = HP Update
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Sonic Express Labeler
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6BB6627C-694F-4FDC-A3E5-C7F4BED4C724}" = DocProc
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{755EC5E3-FD51-46bd-A57F-7A2D56FBF061}" = PSTAPlugin
"{766633B3-1AFA-44B6-A3FC-1DE991CD9C52}" = CP_Package_Basic1
"{769A295C-DCF4-41d6-AFBA-7D9394B23AFE}" = PSPrinters08
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{7850A6D2-CBEA-4728-9877-F1BEDEA9F619}" = AiOSoftware
"{78E9A751-5616-233F-1249-16AC5758C646}" = muvee Reveal Seagate Edition
"{79F8E1D4-36C1-439C-95FA-F695050B5B07}" = Sonic_PrimoSDK
"{7C03270C-4FAB-4F5C-B10D-52FEDA190790}" = DocumentViewerQFolder
"{80AE27BA-B0ED-4288-A8B9-D8194BCF4115}" = cp_UpdateProjectsConfig
"{869C3062-4745-4949-B6C9-98AF24D89030}" = PhotoGallery
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C22F265-DE76-44D1-8A79-A71D819137DA}" = Intel® Quick Resume Technology Drivers
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{91120409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Standard Edition 2003
"{923A7F5A-1E8C-4FBE-8DF6-85940A60A79F}" = Readme
"{9D4ABB0C-F60B-44A6-956C-A4A63D5495C9}" = CueTour
"{A01FC76F-CC09-4658-9E37-5C2F635EE708}" = Microsoft Office 2003 Edition 60 Days Trial Welcome Tour
"{A195B13E-A5E3-4BAF-A995-7F70F445CD06}" = ScannerCopy
"{A3455242-DAE0-4523-8242-FD82706ABF4B}" = CameraDrivers
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Sonic RecordNow Audio
"{ABB2901A-3D0A-4F21-8324-2F13C3EFE163}" = LightScribe [removed]
"{AC76BA86-7AD7-1033-7B44-AA0000000001}" = Adobe Reader X (10.0.1)
"{AFD89880-C544-4777-B645-FBF6D3391B11}" = Belkin F7D1101 Basic Wireless USB Adapter
"{B11E71BA-498C-42D4-9F1A-9D7A89D9DA61}" = CP_AtenaShokunin1Config
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Sonic RecordNow Copy
"{B26B00DA-2E5D-4CF2-83C5-911198C0F009}" = GoodSync
"{B276997E-4367-4b1b-A39C-4CAE7464337A}" = AiO_Scan_CDA
"{B3AEF776-7FFF-4C50-A402-9119E3849EE0}" = AVG 2011
"{B4D279F1-4309-49cc-A4B5-3A0D2E59C7B5}" = PanoStandAlone
"{B57F2FF0-5A25-4332-B503-4592B370C02F}" = CP_Package_Variety3
"{B60E7826-F117-4d26-8165-D2DC5A494AB0}" = Fax_CDA
"{B64E3AFC-59EF-4f18-BF11-E751462450D3}" = AiOSoftwareNPI
"{BBD3BF67-5B89-4CBB-BA58-5818ED5F3290}" = cp_OnlineProjectsConfig
"{C506A18C-1469-4678-B094-F4EC9DAE6DB7}" = Scan
"{C83A12B9-B31B-461A-BBD4-CE9B988094F1}" = HP Photosmart Cameras 5.0
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE24344F-DFD8-40C8-8FD8-C9740B5F25AC}" = Fax
"{D4E53304-1F6C-4111-9872-1BCD2CF5B642}" = AVG 2011
"{D518592A-0F1E-40ca-BECB-3D3F026C6B0D}" = CameraDrivers
"{DAAD5187-62C5-4AD6-A526-803C18C4944D}" = HP Web Helper
"{DB518BA6-CB74-4EB6-9ABD-880B6D6E1F38}" = HpSdpAppCoreApp
"{E073D315-3C54-44BF-A1B2-B5583AEA618C}" = muvee autoProducer 4.5
"{E3F90083-80D4-4b5a-87C7-E97E12F5516D}" = HPProductAssistant
"{E6B87DC4-2B3D-4483-ADFF-E483BF718991}" = OpenOffice.org 3.1
"{EA103B64-C0E4-4C0E-A506-751590E1653D}" = SolutionCenter
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F4C2E5F5-2970-45f4-ABD3-C180C4D961C4}" = Status
"{F80239D8-7811-4D5E-B033-0D0BBFE32920}" = HP DigitalMedia Archive
"{FC8D25A7-FF1B-41BB-BB3B-9A06C0A60AE0}" = InstantShareDevices
"12133444-BF36-4d4e-B7FB-A3424C645DE4" = GemMaster Mystic
"ActiveTouchMeetingClient" = WebEx
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Agere Systems Soft Modem" = Agere Systems PCI Soft Modem
"AI RoboForm" = AI RoboForm (All Users)
"ATI Display Driver" = ATI Display Driver
"AVG" = AVG 2011
"B3EE3001-DC24-4cd1-8743-5692C716659F" = Otto
"DISCover" = DISCover
"HaaliMkx" = Haali Media Splitter
"hotComm® CL" = hotComm® CL
"HP Document Viewer" = HP Document Viewer 5.3
"HP Imaging Device Functions" = HP Imaging Device Functions 6.0
"HP Photo & Imaging" = HP Photosmart Premier Software 6.0
"HP Photosmart for Media Center PC" = HP Photosmart for Media Center PC
"HP Rhapsody" = HP Rhapsody
"HP Solution Center & Imaging Support Tools" = HP Solution Center & Imaging Support Tools 5.3
"HPOOVClient-9972322 Uninstaller" = Updates from HP (remove only)
"ie8" = Windows Internet Explorer 8
"InstallShield_{23012310-3E05-46A5-88A9-C6CBCABCAC79}" = Customer Experience Enhancement
"InstallShield_{2A30052B-831C-41D3-8044-3C0388066350}" = Seagate Manager Installer
"InstallShield_{AFD89880-C544-4777-B645-FBF6D3391B11}" = Belkin F7D1101 Basic Wireless USB Adapter
"Intel® Quick Resume Technology" = Intel® Quick Resume Technology Drivers
"IntelliMover Data Transfer Demo" = Remove IntelliMover Demo
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Mozilla Firefox 4.0 (x86 en-US)" = Mozilla Firefox 4.0 (x86 en-US)
"PROSet" = Intel® PRO Network Connections Drivers
"PS2" = PS2
"Python 2.2.3" = Python 2.2.3
"pywin32-py2.2" = Python 2.2 pywin32 extensions (build 203)
"RealPlayer 12.0" = RealPlayer
"RT-Alerts" = RT-Alerts
"Trusted Software Assistant_is1" = File Type Assistant
"Veetle TV" = Veetle TV 0.9.18
"WIC" = Windows Imaging Component
"WildTangent CDA" = WildTangent Web Driver
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinPcapInst" = WinPcap 4.1.1
"WMFDist11" = Windows Media Format 11 runtime
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"GoToMeeting" = GoToMeeting 4.5.0.457
"magicJack" = magicJack

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 5/4/2011 4:04:20 PM | Computer Name = YOUR-4DACD0EA75 | Source = MsiInstaller | ID = 10005
Description = Product: Microsoft .NET Framework 2.0 Service Pack 2 – There is a
problem with this Windows Installer package. Please refer to the setup log for
more information.

Error - 5/4/2011 4:04:37 PM | Computer Name = YOUR-4DACD0EA75 | Source = MsiInstaller | ID = 1023
Description = Product: Microsoft .NET Framework 2.0 Service Pack 2 - Update '.NET
Framework CLR' could not be installed. Error code 1603. Additional information
is available in the log file C:\DOCUME~1\HP_ADM~1.000\LOCALS~1\Temp\dd_NET_Framework20_Setup1D20.txt.

Error - 5/4/2011 4:04:37 PM | Computer Name = YOUR-4DACD0EA75 | Source = MsiInstaller | ID = 1023
Description = Product: Microsoft .NET Framework 2.0 Service Pack 2 - Update '.NET
Framework CA' could not be installed. Error code 1603. Additional information is
available in the log file C:\DOCUME~1\HP_ADM~1.000\LOCALS~1\Temp\dd_NET_Framework20_Setup1D20.txt.

Error - 5/4/2011 4:04:37 PM | Computer Name = YOUR-4DACD0EA75 | Source = MsiInstaller | ID = 1023
Description = Product: Microsoft .NET Framework 2.0 Service Pack 2 - Update '.NET
Framework CRT' could not be installed. Error code 1603. Additional information
is available in the log file C:\DOCUME~1\HP_ADM~1.000\LOCALS~1\Temp\dd_NET_Framework20_Setup1D20.txt.

Error - 5/4/2011 4:04:37 PM | Computer Name = YOUR-4DACD0EA75 | Source = MsiInstaller | ID = 1023
Description = Product: Microsoft .NET Framework 2.0 Service Pack 2 - Update '.NET
Framework PreXP' could not be installed. Error code 1603. Additional information
is available in the log file C:\DOCUME~1\HP_ADM~1.000\LOCALS~1\Temp\dd_NET_Framework20_Setup1D20.txt.

Error - 5/4/2011 4:04:37 PM | Computer Name = YOUR-4DACD0EA75 | Source = MsiInstaller | ID = 1023
Description = Product: Microsoft .NET Framework 2.0 Service Pack 2 - Update 'Dr.
Watson' could not be installed. Error code 1603. Additional information is available
in the log file C:\DOCUME~1\HP_ADM~1.000\LOCALS~1\Temp\dd_NET_Framework20_Setup1D20.txt.

Error - 5/4/2011 4:04:37 PM | Computer Name = YOUR-4DACD0EA75 | Source = MsiInstaller | ID = 1023
Description = Product: Microsoft .NET Framework 2.0 Service Pack 2 - Update '.NET
Framework 1' could not be installed. Error code 1603. Additional information is
available in the log file C:\DOCUME~1\HP_ADM~1.000\LOCALS~1\Temp\dd_NET_Framework20_Setup1D20.txt.

Error - 5/4/2011 4:04:37 PM | Computer Name = YOUR-4DACD0EA75 | Source = MsiInstaller | ID = 1023
Description = Product: Microsoft .NET Framework 2.0 Service Pack 2 - Update '.NET
Framework 2' could not be installed. Error code 1603. Additional information is
available in the log file C:\DOCUME~1\HP_ADM~1.000\LOCALS~1\Temp\dd_NET_Framework20_Setup1D20.txt.

Error - 5/4/2011 4:04:37 PM | Computer Name = YOUR-4DACD0EA75 | Source = MsiInstaller | ID = 1023
Description = Product: Microsoft .NET Framework 2.0 Service Pack 2 - Update '.NET
Framework ASP .NET' could not be installed. Error code 1603. Additional information
is available in the log file C:\DOCUME~1\HP_ADM~1.000\LOCALS~1\Temp\dd_NET_Framework20_Setup1D20.txt.

Error - 5/4/2011 4:04:37 PM | Computer Name = YOUR-4DACD0EA75 | Source = MsiInstaller | ID = 1023
Description = Product: Microsoft .NET Framework 2.0 Service Pack 2 - Update '.NET
Framework WinForms' could not be installed. Error code 1603. Additional information
is available in the log file C:\DOCUME~1\HP_ADM~1.000\LOCALS~1\Temp\dd_NET_Framework20_Setup1D20.txt.

[ System Events ]
Error - 5/3/2011 10:20:23 PM | Computer Name = YOUR-4DACD0EA75 | Source = Service Control Manager | ID = 7000
Description = The MCSTRM service failed to start due to the following error: %%2

Error - 5/4/2011 10:18:29 AM | Computer Name = YOUR-4DACD0EA75 | Source = Service Control Manager | ID = 7000
Description = The MCSTRM service failed to start due to the following error: %%2

Error - 5/5/2011 9:54:13 AM | Computer Name = YOUR-4DACD0EA75 | Source = Service Control Manager | ID = 7000
Description = The MCSTRM service failed to start due to the following error: %%2

Error - 5/5/2011 9:55:50 AM | Computer Name = YOUR-4DACD0EA75 | Source = Service Control Manager | ID = 7022
Description = The AVGIDSAgent service hung on starting.

Error - 5/5/2011 3:11:29 PM | Computer Name = YOUR-4DACD0EA75 | Source = Service Control Manager | ID = 7000
Description = The MCSTRM service failed to start due to the following error: %%2

Error - 5/6/2011 10:09:03 AM | Computer Name = YOUR-4DACD0EA75 | Source = Service Control Manager | ID = 7000
Description = The MCSTRM service failed to start due to the following error: %%2

Error - 5/6/2011 10:10:38 AM | Computer Name = YOUR-4DACD0EA75 | Source = Service Control Manager | ID = 7022
Description = The AVGIDSAgent service hung on starting.

Error - 5/6/2011 10:57:15 AM | Computer Name = YOUR-4DACD0EA75 | Source = Service Control Manager | ID = 7000
Description = The MCSTRM service failed to start due to the following error: %%2

Error - 5/6/2011 1:56:34 PM | Computer Name = YOUR-4DACD0EA75 | Source = Service Control Manager | ID = 7000
Description = The MCSTRM service failed to start due to the following error: %%2

Error - 5/7/2011 9:37:01 AM | Computer Name = YOUR-4DACD0EA75 | Source = Service Control Manager | ID = 7000
Description = The MCSTRM service failed to start due to the following error: %%2


< End of report >
Hi Satchfan. Here is the aswMBR.exe scan; aswMBR version 0.9.5.256 Copyright© 2011 AVAST Software Run date: 2011-05-07 10:40:17 —————————– 10:40:17.703 OS Version: Windows 5.1.2600 Service Pack 3 10:40:17.703 Number of processors: 2 586 0x602 10:40:17.703 ComputerName: YOUR-4DACD0EA75 UserName: 10:40:18.890 Initialize success 10:40:25.656 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 10:40:25.656 Disk 0 Vendor: WDC_WD30 21.0 Size: 286168MB BusType: 3 10:40:25.671 Disk 0 MBR read successfully 10:40:25.671 Disk 0 MBR scan 10:40:25.671 Disk 0 unknown MBR code 10:40:25.671 Disk 0 malicious Win32:MBRoot code @ sector 61 ! 10:40:25.703 Disk 0 PE file @ sector 586067290 ! 10:40:25.703 Disk 0 scanning C:\WINDOWS\system32\drivers 10:40:35.593 Service scanning 10:40:37.500 Disk 0 trace - called modules: 10:40:37.531 ntkrnlpa.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll 10:40:37.531 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a55bab8] 10:40:37.531 3 CLASSPNP.SYS[ba108fd7] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-0[0x8a005030] 10:40:37.531 Scan finished successfully 10:41:10.625 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\MBR.dat" 10:41:10.640 The log file has been saved successfully to "C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\aswMBR.txt"
Hi baldingeagle

P2P - I see you have P2P software, (Azureus), installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infection. If your computer is infected, it almost certainly contributed to your current situation.

Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are more often than not, infected. The bad guys use P2P file-sharing as a major conduit to spread their wares.

Please see this topic for more information:

Perils of P2P File Sharing.

I would strongly recommend that you uninstall it now. You can do so via Control Panel, Programs, and then Programs and Features.

Should you decide to keep it, please don’t use it until we have finished up here.

===================================================

Run OTL

  • Double click on the icon to run it.
  • Copy/paste ALL the following text written inside the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    O4 - HKLM..\Run: [PCDrProfiler] File not found
    O15 - HKLM\..Trusted Domains: trymedia.com ([]http in Trusted sites)
    O15 - HKLM\..Trusted Domains: trymedia.com ([]https in Trusted sites)
    O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/e/2…78f/wvc1dmo.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
    [2011/04/23 15:32:51 | 000,000,000 | —- | M] () – C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\My Documents\firefox352.exe
    @Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1
    @Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8
    @Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
    
    :Reg
    
    :Files
    C:\ComboFix.txt
    
    :Commands
    [purity]
    [emptytemp]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log (don't check the boxes beside LOP Check or Purity this time)


Uninstall AVG 10

AVG interferes with some of the tools we use so we need to uninstall it for now. Please don’t use the Internet except to download tools that I request until I give the all clear to re-install it.
  • click Start, Settings, Control Panel,
  • double-click Add/Remove Programs
  • click on AVG 10 and then Uninstall.
If you are prompted for an administrator password or confirmation, type the password or provide confirmation.

Run AVG removal tool

There will still be some remnants of AVG on your computer even after the uninstall so please download and run AVG Removal Tool from here


Download and run ComboFix

Download Combofix from either of the links below. You must rename it to 123 before saving it.
Save it to your desktop. Change the save as file type to "all files"

**Note: In the event you already have Combofix, delete it, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**
  • If you are using Firefox, make sure that your download settings are as follows:
  • Tools->Options->Main tab
  • Set to "Always ask me where to Save the files".

Link 1
Link 2

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
  • NOTE: If ComboFix asks to install the Recovery Console, please ALLOW it to do so.
  • Double click on the renamed ComboFix.exe & follow the prompts.
When finished, it will produce a report for you. Please post the C:\ComboFix.txt in your next reply.

===================================================

Can you please copy the contents of :\TDSSKiller.2.4.18.0_24.04.2011_13.31.12_log.txt and paste it in your next reply

===================================================

Do you have Wireless Zero Configuration service installed?

===================================================

Do you know what this is?:

C:\Documents and Settings\All Users\Application Data\93x8GFadd0YlOkwddBp3

Thanks

Satchfan
Hi Satchfan. I was not aware that I had P2P/Azureus on my computer. I have not knowingly participated in a file sharing program. I think I have deleted it. The OTL scan is below. I am running into problems trying to delete AVG. I have run the AVG removal tool multiple times, but ComboFix keeps sending me this message; "ComboFix cannot run when AVG is installed. This is due to AVG's targeting of ComboFix's files/processes. It would be dangerous to continue. Please uninstall AVG or use another tool." I can't find any traces of AVG, so I don't know what to do? Thanks. All processes killed ========== SERVICES/DRIVERS ========== ========== OTL ========== Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\PCDrProfiler deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\trymedia.com\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\trymedia.com\ not found. Starting removal of ActiveX control {31435657-9980-0010-8000-00AA00389B71} C:\WINDOWS\Downloaded Program Files\wvc1dmo.inf moved successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{31435657-9980-0010-8000-00AA00389B71}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{31435657-9980-0010-8000-00AA00389B71}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{31435657-9980-0010-8000-00AA00389B71}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{31435657-9980-0010-8000-00AA00389B71}\ not found. Starting removal of ActiveX control {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA}\ not found. Starting removal of ActiveX control {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}\ not found. Starting removal of ActiveX control {E2883E8F-472F-4FB0-9522-AC9BF37916A7} C:\WINDOWS\Downloaded Program Files\gp.inf not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found. C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75.000\My Documents\firefox352.exe moved successfully. ADS C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1 deleted successfully. ADS C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8 deleted successfully. ADS C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2 deleted successfully. ========== REGISTRY ========== ========== FILES ========== C:\ComboFix.txt moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 31285 bytes ->Temporary Internet Files folder emptied: 32835 bytes User: All Users User: Default User ->Temp folder emptied: 31285 bytes ->Temporary Internet Files folder emptied: 32835 bytes ->Flash cache emptied: 56502 bytes User: HelpAssistant ->Temp folder emptied: 31285 bytes ->Temporary Internet Files folder emptied: 32768 bytes ->Java cache emptied: 12229280 bytes ->Flash cache emptied: 393454 bytes User: HP_Administrator ->Temp folder emptied: 376527914 bytes ->Temporary Internet Files folder emptied: 475091524 bytes ->Java cache emptied: 57733843 bytes ->FireFox cache emptied: 84369810 bytes ->Google Chrome cache emptied: 273074096 bytes ->Flash cache emptied: 5283550 bytes User: HP_Administrator.YOUR-4DACD0EA75 ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 1514595 bytes ->Java cache emptied: 723383 bytes ->FireFox cache emptied: 48482687 bytes ->Google Chrome cache emptied: 100119034 bytes ->Apple Safari cache emptied: 12102656 bytes ->Flash cache emptied: 4458 bytes User: HP_Administrator.YOUR-4DACD0EA75.000 ->Temp folder emptied: 1355999594 bytes ->Temporary Internet Files folder emptied: 153982219 bytes ->Java cache emptied: 2106857 bytes ->FireFox cache emptied: 48772806 bytes ->Google Chrome cache emptied: 1905008 bytes ->Flash cache emptied: 19846 bytes User: LocalService ->Temp folder emptied: 65748 bytes ->Temporary Internet Files folder emptied: 32902 bytes ->Flash cache emptied: 456 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 143113854 bytes ->Java cache emptied: 2187573 bytes ->Flash cache emptied: 83340 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 148819 bytes %systemroot%\System32 .tmp files removed: 2577 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 15238630 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 31285 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 3,025.00 mb OTL by OldTimer - Version 3.2.22.3 log created on 05082011_114135 Files\Folders moved on Reboot… File\Folder C:\WINDOWS\temp\Perflib_Perfdata_b7c.dat not found! Registry entries deleted on Reboot…
Hi Satchfan.

I tried manually running a search for all AVG files both hidden and not hidden. I then manually deleted all that were found. I then ran ComboFix again and it ran successfully this time.

Below is my scan result for ComboFix. Below that is the contents of :\TDSSKiller.2.4.18.0_24.04.2011_13.31.12_log.txt.

I do not have Wireless Zero Configuration service installed.

I do not know what this is……………… C:\Documents and Settings\All Users\Application Data\93x8GFadd0YlOkwddBp3 ?????



Thanks so much for your help.





ComboFix 11-05-08.02 - HP_Administrator 05/08/2011 15:16:27.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1447 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\123.exe
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\docume~1\HP_ADM~1.000\LOCALS~1\Temp\IadHide5.dll
c:\documents and settings\Administrator\WINDOWS
c:\documents and settings\Default User\WINDOWS
c:\documents and settings\HelpAssistant\WINDOWS
c:\documents and settings\HP_Administrator.YOUR-4DACD0EA75.000\Desktop\install_flash_player(1).exe
c:\documents and settings\HP_Administrator.YOUR-4DACD0EA75.000\g2mdlhlpx.exe
c:\documents and settings\HP_Administrator.YOUR-4DACD0EA75.000\Local Settings\Temp\IadHide5.dll
c:\documents and settings\HP_Administrator.YOUR-4DACD0EA75.000\WINDOWS
c:\documents and settings\HP_Administrator.YOUR-4DACD0EA75\Desktop\Setup.exe
c:\documents and settings\HP_Administrator.YOUR-4DACD0EA75\WINDOWS
c:\documents and settings\HP_Administrator\g2mdlhlpx.exe
c:\documents and settings\HP_Administrator\WINDOWS
c:\program files\Search Toolbar
c:\program files\Search Toolbar\icon.ico
c:\program files\Search Toolbar\SearchToolbar.dll
c:\program files\Search Toolbar\SearchToolbarUninstall.exe
c:\program files\Search Toolbar\SearchToolbarUpdater.exe
C:\RECYCLER(2)
c:\recycler(2)\S-1-5-21-1835656616-1007078278-4199080885-1008(2)\INFO2
c:\windows\system32\config\systemprofile\WINDOWS
c:\windows\system32vbscript.dll
c:\windows\system32vbscript.dll\vbscript.dll
.
.
((((((((((((((((((((((((( Files Created from 2011-04-08 to 2011-05-08 )))))))))))))))))))))))))))))))
.
.
2011-05-08 15:41 . 2011-05-08 15:41 ——– d—–w- C:\_OTL
2011-04-24 18:19 . 2011-04-24 18:19 ——– d—–w- c:\documents and settings\HP_Administrator.YOUR-4DACD0EA75.000\Application Data\f-secure
2011-04-24 18:19 . 2011-04-24 18:19 ——– d—–w- c:\documents and settings\All Users\Application Data\F-Secure
2011-04-23 19:07 . 2011-04-23 19:07 388096 —-a-r- c:\documents and settings\HP_Administrator.YOUR-4DACD0EA75.000\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-04-23 19:07 . 2011-04-23 19:07 ——– d—–w- c:\program files\Trend Micro
2011-04-23 18:47 . 2011-03-08 23:37 49152 —-a-w- c:\program files\Mozilla Firefox\distribution\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}\components\XPATLCOM.dll
2011-04-23 18:21 . 2011-04-23 18:21 ——– d—–w- c:\windows\system32\wbem\Repository
2011-04-21 20:27 . 2003-02-28 21:26 947472 —-a-w- c:\windows\system32\msjava.bak
2011-04-16 14:14 . 2011-04-16 14:14 11776 —-a-w- c:\program files\Mozilla Firefox\plugins\nprjplug.dll
2011-04-16 14:14 . 2011-04-16 14:14 ——– d—–w- c:\program files\Common Files\xing shared
2011-04-16 14:13 . 2011-04-16 14:13 150712 —-a-w- c:\program files\Mozilla Firefox\plugins\nppl3260.dll
2011-04-16 14:13 . 2011-04-16 14:13 105472 —-a-w- c:\program files\Mozilla Firefox\plugins\nprpjplug.dll
2011-04-15 20:50 . 2011-04-15 20:50 ——– d—–w- c:\windows\system32\Registry Patrol
2011-04-15 20:49 . 2011-04-15 20:56 ——– d—–w- c:\program files\Registry Patrol
2011-04-15 19:01 . 2011-04-15 19:01 ——– d—–w- c:\documents and settings\HP_Administrator.YOUR-4DACD0EA75.000\Local Settings\Application Data\PackageAware
2011-04-15 17:56 . 2011-04-15 17:56 159519 —-a-w- c:\windows\RT-Alerts Uninstaller.exe
2011-04-15 17:50 . 2011-04-28 13:09 ——– d—–w- c:\documents and settings\HP_Administrator.YOUR-4DACD0EA75.000\Application Data\RT-Alerts
2011-04-14 21:36 . 2011-04-14 21:36 80384 —-a-w- c:\program files\Mozilla Firefox\plugins\WebEx\1126\mticket.dll
2011-04-14 21:36 . 2011-04-14 21:36 1094144 —-a-w- c:\program files\Mozilla Firefox\plugins\WebEx\1126\mac.dll
2011-04-14 21:36 . 2011-04-14 21:36 316928 —-a-w- c:\program files\Mozilla Firefox\plugins\WebEx\1126\msess.dll
2011-04-14 21:36 . 2011-04-14 21:36 710144 —-a-w- c:\program files\Mozilla Firefox\plugins\WebEx\1126\mutiltpd.dll
2011-04-14 21:17 . 2011-04-14 21:17 449848 —-a-w- c:\program files\Mozilla Firefox\plugins\WebEx\1126\atgpcext.dll
2011-04-14 21:17 . 2011-04-14 21:17 113976 —-a-w- c:\program files\Mozilla Firefox\plugins\WebEx\1126\atgpcdec.dll
2011-04-14 21:17 . 2011-04-14 21:17 172344 —-a-w- c:\program files\Mozilla Firefox\plugins\npatgpc.dll
2011-04-11 15:18 . 2011-04-30 19:08 ——– d—–w- c:\documents and settings\HP_Administrator.YOUR-4DACD0EA75.000\Application Data\HpUpdate
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-05-01 14:26 . 2010-11-23 04:27 16968 —-a-w- c:\windows\system32\drivers\hitmanpro35.sys
2011-03-07 05:33 . 2004-08-10 04:00 692736 ——w- c:\windows\system32\inetcomm.dll
2011-03-04 06:37 . 2004-08-10 04:00 420864 —-a-w- c:\windows\system32\vbscript.dll
2011-03-03 13:21 . 2004-08-10 04:00 1857920 —-a-w- c:\windows\system32\win32k.sys
2011-02-22 23:06 . 2004-08-10 04:00 916480 —-a-w- c:\windows\system32\wininet.dll
2011-02-22 23:06 . 2004-08-10 04:00 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-02-22 23:06 . 2004-08-10 04:00 1469440 ——w- c:\windows\system32\inetcpl.cpl
2011-02-22 11:41 . 2004-08-10 04:00 385024 —-a-w- c:\windows\system32\html.iec
2011-02-17 13:18 . 2004-08-10 04:00 455936 ——w- c:\windows\system32\drivers\mrxsmb.sys
2011-02-17 13:18 . 2004-08-10 04:00 357888 ——w- c:\windows\system32\drivers\srv.sys
2011-02-17 12:32 . 2010-12-08 03:04 5120 —-a-w- c:\windows\system32\xpsp4res.dll
2011-02-15 12:56 . 2004-08-10 04:00 290432 —-a-w- c:\windows\system32\atmfd.dll
2011-02-11 13:25 . 2006-03-12 13:41 229888 —-a-w- c:\windows\system32\fxscover.exe
2011-02-08 13:33 . 2004-08-10 04:00 978944 —-a-w- c:\windows\system32\mfc42.dll
2011-02-08 13:33 . 2004-08-10 04:00 974848 —-a-w- c:\windows\system32\mfc42u.dll
2011-04-14 21:18 . 2011-04-14 21:18 289592 —-a-w- c:\program files\mozilla firefox\plugins\ieatgpc.dll
2010-01-01 08:00 . 2011-03-25 00:34 135168 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
——- Sigcheck ——-
.
[7] 2010-09-16 14:12 . A26898623D61508C2FA3F5672C11FA5D . 910296 . . [1.9.2.10] . . c:\windows\ERDNT\cache\firefox.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"cdloader"="c:\documents and settings\HP_Administrator.YOUR-4DACD0EA75.000\Application Data\mjusbsp\cdloader2.exe" [2010-12-03 50592]
"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2011-04-28 160328]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-06 64512]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2006-02-21 143360]
"RTHDCPL"="RTHDCPL.EXE" [2006-01-12 15961088]
"HPHUPD08"="c:\program files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-02 49152]
"DISCover"="c:\program files\DISC\DISCover.exe" [2005-11-12 1064960]
"DiscUpdateManager"="c:\program files\DISC\DiscUpdateMgr.exe" [2005-11-12 61440]
"DMAScheduler"="c:\program files\Sonic\DigitalMedia Plus\DigitalMedia Archive\DMAScheduler.exe" [2005-11-01 90112]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2005-07-23 237568]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-11-10 249856]
"Reminder"="c:\windows\Creator\Remind_XP.exe" [2004-12-14 663552]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2011-02-18 49208]
"MaxMenuMgr"="c:\program files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe" [2009-09-26 185640]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-01-30 35736]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-10 932288]
"TkBellExe"="c:\program files\real\realplayer\update\realsched.exe" [2011-04-16 273544]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-29 421888]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-28 221184]
.
c:\documents and settings\Default User\Start Menu\Programs\Startup\
Pin.lnk - c:\hp\bin\CLOAKER.EXE [2006-3-12 27136]
.
c:\documents and settings\HP_Administrator\Start Menu\Programs\Startup\
Check for ContinuumClient Updates.lnk - c:\program files\Quote.com\ContinuumClient\UNWISE.EXE [2009-9-3 164864]
OpenOffice.org 2.4.lnk - c:\program files\OpenOffice.org 2.4\program\quickstart.exe [2008-1-21 393216]
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-8-18 384000]
.
c:\documents and settings\HP_Administrator.YOUR-4DACD0EA75\Start Menu\Programs\Startup\
OpenOffice.org 2.4.lnk - c:\program files\OpenOffice.org 2.4\program\quickstart.exe [2008-1-21 393216]
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-8-18 384000]
.
c:\documents and settings\HP_Administrator.YOUR-4DACD0EA75.000\Start Menu\Programs\Startup\
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-8-18 384000]
Seagate 2GEXM0JE Product Registration.lnk - c:\documents and settings\HP_Administrator.YOUR-4DACD0EA75.000\Application Data\Leadertech\PowerRegister\Seagate 2GEXM0JE Product Registration.exe [2010-11-22 1731736]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-12 282624]
Updates From HP.lnk - c:\program files\Updates from HP\9972322\Program\Updates from HP.exe [2006-3-12 36903]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\DISC\\DISCover.exe"=
"c:\\Program Files\\DISC\\DiscStreamHub.exe"=
"c:\\Program Files\\DISC\\myFTP.exe"=
"c:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
"c:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Documents and Settings\\HP_Administrator.YOUR-4DACD0EA75.000\\Application Data\\mjusbsp\\magicJack.exe"=
"c:\\Program Files\\1stWORKS\\hotCommCL\\BIN\\HotComm.exe"=
.
R2 FreeAgentGoNext Service;Seagate Service;c:\program files\Seagate\SeagateManager\Sync\FreeAgentService.exe [9/26/2009 12:32 AM 189736]
R2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [10/20/2009 2:19 PM 50704]
R3 RTL8192su;%RTL8192su.DeviceDesc.DispName%;c:\windows\system32\drivers\RTL8192su.sys [2/14/2011 11:54 AM 594048]
S3 brfilt;Brother MFC Filter Driver;c:\windows\system32\drivers\BrFilt.sys [11/23/2010 7:53 PM 2944]
S3 BrSerWDM;Brother Serial driver;c:\windows\system32\drivers\BrSerWdm.sys [11/23/2010 7:53 PM 60416]
S3 BrUsbMdm;Brother MFC USB Fax Only Modem;c:\windows\system32\drivers\BrUsbMdm.sys [11/23/2010 7:53 PM 11008]
S3 BrUsbScn;Brother MFC USB Scanner driver;c:\windows\system32\drivers\BrUsbScn.sys [11/23/2010 7:01 PM 10368]
.
Contents of the 'Scheduled Tasks' folder
.
2011-05-04 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 20:34]
.
2011-05-08 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1747380976-3469703338-1627799412-1008.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 14:47]
.
2011-05-08 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1747380976-3469703338-1627799412-1008.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 14:47]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
IE: &Google Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html
IE: &Translate English Word - c:\program files\Google\GoogleToolbar1.dll/cmwordtrans.html
IE: Backward Links - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\Google\GoogleToolbar1.dll/cmcache.html
IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: RoboForm Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
IE: Similar Pages - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate Page into English - c:\program files\Google\GoogleToolbar1.dll/cmtrans.html
FF - ProfilePath - c:\documents and settings\HP_Administrator.YOUR-4DACD0EA75.000\Application Data\Mozilla\Firefox\Profiles\05kfcsd2.default\
FF - prefs.js: network.proxy.type - 0
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-05-08 15:23
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(968)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(3696)
c:\windows\system32\WININET.dll
c:\docume~1\HP_ADM~1.000\LOCALS~1\Temp\IadHide5.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\System32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE
c:\windows\ehome\mcrdsvc.exe
c:\program files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wscntfy.exe
c:\windows\RTHDCPL.EXE
c:\windows\eHome\ehmsas.exe
c:\program files\DISC\DiscGui.exe
c:\program files\OpenOffice.org 3\program\soffice.exe
c:\program files\OpenOffice.org 3\program\soffice.bin
c:\program files\DISC\DiscStreamHub.exe
.
**************************************************************************
.
Completion time: 2011-05-08 15:32:18 - machine was rebooted
ComboFix-quarantined-files.txt 2011-05-08 19:32
ComboFix2.txt 2010-09-18 21:32
ComboFix3.txt 2010-09-12 23:09
ComboFix4.txt 2010-08-31 04:03
ComboFix5.txt 2010-09-20 21:40
.
Pre-Run: 32,671,952,896 bytes free
Post-Run: 32,644,837,376 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect
.
- - End Of File - - 9B05AE9F11CD8595D79DB66E19353D86













contents of :\TDSSKiller.2.4.18.0_24.04.2011_13.31.12_log.txt

2011/04/24 13:31:12.0843 5540 TDSS rootkit removing tool 2.4.18.0 Feb 21 2011 11:08:08
2011/04/24 13:31:16.0890 5540 Perform update action was selected
2011/04/24 13:31:16.0890 2992 Deinitialize success
Baldingeagle

Run Security Check

Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
Can you also tell me if there is any improvement and exactly what problems remain.

Thanks

Satchfan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI