This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

searchqu 406 help me please

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have searchqu 406 and it will not go away please help me.


OTL log

OTL logfile created on: 7/9/2011 2:55:31 AM - Run 1
OTL by OldTimer - Version 3.2.26.1 Folder = C:\Documents and Settings\Rogelio_1986\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

503.30 Mb Total Physical Memory | 101.43 Mb Available Physical Memory | 20.15% Memory free
1.20 Gb Paging File | 0.72 Gb Available in Paging File | 60.40% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 142.96 Gb Total Space | 44.36 Gb Free Space | 31.03% Space Free | Partition Type: NTFS
Drive D: | 6.07 Gb Total Space | 0.48 Gb Free Space | 7.84% Space Free | Partition Type: FAT32
Drive E: | 612.92 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF

Computer Name: YOUR-03667082DE | User Name: Rogelio_1986 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/07/09 02:55:23 | 000,579,584 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Rogelio_1986\My Documents\Downloads\OTL.exe
PRC - [2011/05/31 02:12:18 | 000,912,344 | —- | M] (Mozilla Corporation) – C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2010/04/16 11:04:38 | 001,809,680 | —- | M] (Orbitdownloader.com) – C:\Program Files\Orbitdownloader\orbitdm.exe
PRC - [2010/01/15 06:49:20 | 000,255,536 | —- | M] (McAfee, Inc.) – C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
PRC - [2009/12/03 09:54:40 | 000,557,056 | —- | M] (Orbitdownloader.com) – C:\Program Files\Orbitdownloader\orbitnet.exe
PRC - [2009/04/23 06:29:18 | 007,418,368 | —- | M] (OpenOffice.org) – C:\Program Files\OpenOffice.org 3\program\soffice.bin
PRC - [2009/04/23 06:29:14 | 007,424,000 | —- | M] (OpenOffice.org) – C:\Program Files\OpenOffice.org 3\program\soffice.exe
PRC - [2008/12/12 12:41:06 | 000,157,312 | —- | M] (Microsoft Corporation) – C:\Program Files\Zune\ZuneLauncher.exe
PRC - [2008/12/12 12:41:02 | 000,060,032 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\ZuneBusEnum.exe
PRC - [2008/11/09 14:48:14 | 000,602,392 | —- | M] (Yahoo! Inc.) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
PRC - [2008/04/13 18:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2007/11/02 19:00:00 | 000,032,768 | —- | M] (Creative Technology Ltd.) – C:\WINDOWS\V0500Mon.exe
PRC - [2007/06/21 22:56:14 | 000,282,624 | —- | M] (Eastman Kodak Company) – C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
PRC - [2004/10/21 20:25:36 | 000,045,056 | —- | M] (Hewlett-Packard) – C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
PRC - [2004/10/21 19:39:48 | 000,180,269 | —- | M] (RealNetworks, Inc.) – C:\Program Files\Common Files\Real\Update_OB\realsched.exe
PRC - [2004/08/18 08:44:36 | 000,176,768 | —- | M] (Symantec Corporation) – c:\Program Files\Norton AntiVirus\navapsvc.exe
PRC - [2004/08/13 21:17:48 | 000,164,984 | —- | M] (Symantec Corporation) – c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
PRC - [2004/08/13 21:17:40 | 000,197,752 | —- | M] (Symantec Corporation) – c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
PRC - [2004/08/13 21:17:38 | 000,058,488 | —- | M] (Symantec Corporation) – C:\Program Files\Common Files\Symantec Shared\ccApp.exe
PRC - [2004/08/13 20:00:44 | 000,206,048 | —- | M] (Symantec Corporation) – c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
PRC - [2004/08/06 01:23:10 | 000,308,352 | —- | M] (Symantec Corporation) – c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
PRC - [2004/07/29 02:34:22 | 002,551,808 | —- | M] (RealTek Semicoductor Corp.) – C:\WINDOWS\ALCWZRD.EXE
PRC - [2004/07/29 01:40:18 | 000,077,824 | —- | M] (Realtek Semiconductor Corp.) – C:\WINDOWS\SOUNDMAN.EXE
PRC - [2004/03/04 09:46:24 | 000,172,032 | —- | M] (HP) – C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
PRC - [2003/12/22 09:38:40 | 000,135,168 | —- | M] (Hewlett-Packard Company) – C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
PRC - [2003/12/09 00:18:40 | 000,218,232 | —- | M] (Symantec Corporation) – c:\Program Files\Common Files\Symantec Shared\ccProxy.exe


========== Modules (SafeList) ==========

MOD - [2011/07/09 02:55:23 | 000,579,584 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Rogelio_1986\My Documents\Downloads\OTL.exe
MOD - [2008/04/13 18:12:51 | 001,054,208 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll
MOD - [2004/10/21 20:25:35 | 000,024,613 | —- | M] (BackWeb) – C:\Documents and Settings\Rogelio_1986\Local Settings\temp\IadHide5.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] – – (HidServ)
SRV - File not found [On_Demand | Stopped] – – (AppMgmt)
SRV - [2010/01/15 06:49:20 | 000,227,232 | —- | M] (McAfee, Inc.) [On_Demand | Stopped] – C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe – (McComponentHostService)
SRV - [2008/12/12 12:41:18 | 005,117,568 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – c:\Program Files\Zune\ZuneNss.exe – (ZuneNetworkSvc)
SRV - [2008/12/12 12:41:08 | 000,243,840 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\system32\ZuneWlanCfgSvc.exe – (ZuneWlanCfgSvc)
SRV - [2008/12/12 12:41:02 | 000,060,032 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\ZuneBusEnum.exe – (ZuneBusEnum)
SRV - [2008/11/09 14:48:14 | 000,602,392 | —- | M] (Yahoo! Inc.) [Auto | Running] – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe – (YahooAUService)
SRV - [2004/08/18 08:44:56 | 000,046,208 | —- | M] (Symantec Corporation) [Auto | Stopped] – c:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe – (NPFMntor)
SRV - [2004/08/18 08:44:36 | 000,176,768 | —- | M] (Symantec Corporation) [Auto | Running] – c:\Program Files\Norton AntiVirus\navapsvc.exe – (navapsvc)
SRV - [2004/08/13 21:17:48 | 000,164,984 | —- | M] (Symantec Corporation) [Auto | Running] – c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe – (ccSetMgr)
SRV - [2004/08/13 21:17:46 | 000,078,968 | —- | M] (Symantec Corporation) [On_Demand | Stopped] – c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe – (ccPwdSvc)
SRV - [2004/08/13 21:17:40 | 000,197,752 | —- | M] (Symantec Corporation) [Auto | Running] – c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe – (ccEvtMgr)
SRV - [2004/08/13 20:00:44 | 000,206,048 | —- | M] (Symantec Corporation) [On_Demand | Running] – c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe – (SNDSrvc)
SRV - [2004/08/06 01:23:10 | 000,308,352 | —- | M] (Symantec Corporation) [Auto | Running] – c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe – (SymWSC)
SRV - [2004/07/23 20:47:22 | 000,197,864 | —- | M] (Symantec Corporation) [On_Demand | Stopped] – c:\Program Files\Norton AntiVirus\SAVScan.exe – (SAVScan)
SRV - [2004/07/21 17:24:04 | 000,173,160 | —- | M] (Symantec Corporation) [On_Demand | Stopped] – c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe – (SPBBCSvc)
SRV - [2003/12/09 00:18:40 | 000,218,232 | —- | M] (Symantec Corporation) [Auto | Running] – c:\Program Files\Common Files\Symantec Shared\ccProxy.exe – (ccProxy)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Running] – – (catchme)
DRV - [2009/08/28 07:20:02 | 000,103,552 | R— | M] (QUALCOMM Incorporated) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\qscnusb.sys – (MobileAdapter)
DRV - [2007/10/31 19:00:00 | 000,251,264 | R— | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\V0500Vid.sys – (V0500Dev)
DRV - [2006/11/02 07:00:08 | 000,039,368 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\winusb.sys – (WinUSB)
DRV - [2004/10/22 15:23:19 | 000,261,912 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] – C:\Program Files\Common Files\Symantec Shared\SymcData\idsdefs\20040813.178\SymIDSCo.sys – (SYMIDSCO)
DRV - [2004/10/06 10:00:00 | 000,617,288 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20041006.020\NAVEX15.SYS – (NAVEX15)
DRV - [2004/10/06 10:00:00 | 000,068,168 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20041006.020\NAVENG.SYS – (NAVENG)
DRV - [2004/10/01 18:24:02 | 002,279,424 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\ALCXWDM.SYS – (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2004/09/29 23:55:50 | 000,229,888 | —- | M] (Silicon Integrated Systems Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\sisgrp.sys – (SiS315)
DRV - [2004/09/24 11:38:40 | 000,012,928 | —- | M] (Silicon Integrated Systems Corporation) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\srvkp.sys – (SiSkp)
DRV - [2004/08/13 20:00:24 | 000,266,368 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\WINDOWS\System32\Drivers\SYMTDI.SYS – (SYMTDI)
DRV - [2004/08/13 20:00:22 | 000,025,824 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\Drivers\SYMREDRV.SYS – (SYMREDRV)
DRV - [2004/08/13 20:00:20 | 000,034,496 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\System32\Drivers\SYMIDS.SYS – (SYMIDS)
DRV - [2004/08/13 20:00:18 | 000,046,208 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\System32\Drivers\SYMNDIS.SYS – (SYMNDIS)
DRV - [2004/08/13 20:00:16 | 000,171,424 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\System32\Drivers\SYMFW.SYS – (SYMFW)
DRV - [2004/08/13 20:00:12 | 000,011,040 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\System32\Drivers\SYMDNS.SYS – (SYMDNS)
DRV - [2004/08/09 20:59:32 | 000,103,952 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Program Files\Symantec\SYMEVENT.SYS – (SymEvent)
DRV - [2004/07/29 21:04:26 | 002,216,128 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\RtkHDAud.sys – (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2004/07/23 20:47:24 | 000,049,808 | —- | M] (Symantec Corporation) [Kernel | Auto | Running] – c:\Program Files\Norton AntiVirus\Savrtpel.sys – (SAVRTPEL)
DRV - [2004/07/23 20:47:22 | 000,335,504 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – c:\Program Files\Norton AntiVirus\savrt.sys – (SAVRT)
DRV - [2004/07/21 17:24:02 | 000,341,096 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys – (SPBBCDrv)
DRV - [2004/06/29 18:07:18 | 001,268,204 | —- | M] (Agere Systems) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\AGRSM.sys – (AgereSoftModem)
DRV - [2003/12/02 19:23:20 | 000,142,336 | —- | M] (Promise Technology, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\fasttx2k.sys – (fasttx2k)
DRV - [2003/09/19 01:47:00 | 000,010,368 | —- | M] (Padus, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\pfc.sys – (Pfc)
DRV - [2003/07/18 17:58:20 | 000,036,992 | —- | M] (Silicon Integrated Systems Corporation) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\SISAGPX.sys – (SISAGP)
DRV - [2003/07/02 12:42:00 | 000,027,904 | —- | M] (VIA Technologies, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\viaagp1.sys – (viaagp1)
DRV - [2002/10/04 18:04:10 | 000,046,976 | —- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\R8139n51.sys – (rtl8139)
DRV - [2001/06/04 15:00:00 | 000,014,112 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\PS2.sys – (Ps2)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Search Results"
FF - prefs.js..browser.search.order.1: "Search Results"
FF - prefs.js..browser.search.selectedEngine: "Search Results"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.searchqu.com/406"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {35379F86-8CCB-4724-AE33-4278DE266C70}:1.0.5
FF - prefs.js..extensions.enabledItems: [removed]:3.11.3.15590
FF - prefs.js..extensions.enabledItems: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.1.94
FF - prefs.js..extensions.enabledItems: {6904342A-8307-11DF-A508-4AE2DFD72085}:2.1.1.94
FF - prefs.js..keyword.URL: "http://dts.search-results.com/sr?src=ffb&appid;=102&systemid;=406&q;="


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60310.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Documents and Settings\Rogelio_1986\Application Data\Move Networks\plugins\071803000001\npqmp071803000001.dll (Move Networks)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.1879: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.2.1939: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.872: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.57\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.57\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Documents and Settings\Rogelio_1986\Application Data\Move Networks\plugins\071803000001\npqmp071803000001.dll (Move Networks)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.17\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/05/31 02:12:26 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.17\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/07/06 22:19:52 | 000,000,000 | —D | M]

[2011/07/07 23:35:23 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Rogelio_1986\Application Data\Mozilla\Extensions
[2010/10/17 23:09:29 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Rogelio_1986\Application Data\Mozilla\Extensions\[removed]
[2011/07/09 02:42:02 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Rogelio_1986\Application Data\Mozilla\Firefox\Profiles\8u81h8pd.default\extensions
[2010/12/05 14:49:27 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Rogelio_1986\Application Data\Mozilla\Firefox\Profiles\8u81h8pd.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/05/19 11:04:12 | 000,002,561 | —- | M] () – C:\Documents and Settings\Rogelio_1986\Application Data\Mozilla\Firefox\Profiles\8u81h8pd.default\searchplugins\askcom.xml
[2011/07/07 23:06:32 | 000,002,501 | —- | M] () – C:\Documents and Settings\Rogelio_1986\Application Data\Mozilla\Firefox\Profiles\8u81h8pd.default\searchplugins\SearchResults.xml
[2011/07/07 23:35:23 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/07/09 02:32:10 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2011/07/09 01:39:37 | 000,001,211 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\Mp3Tube.xml
[2011/07/07 23:06:32 | 000,002,501 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\SearchResults.xml

O1 HOSTS File: ([2011/07/09 02:19:02 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Octh Class) - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll (Orbitdownloader.com)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (CNisExtBho Class) - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - c:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll (Symantec Corporation)
O2 - BHO: (CNavExtBho Class) - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NAVShExt.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found.
O3 - HKLM\..\Toolbar: (Norton AntiVirus) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NAVShExt.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll ()
O3 - HKCU\..\Toolbar\ShellBrowser: (Norton AntiVirus) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NAVShExt.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll ()
O4 - HKLM..\Run: [AlcWzrd] C:\WINDOWS\ALCWZRD.EXE (RealTek Semicoductor Corp.)
O4 - HKLM..\Run: [ccApp] c:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe (HP)
O4 - HKLM..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe (Hewlett-Packard)
O4 - HKLM..\Run: [IS CfgWiz] c:\Program Files\Common Files\Symantec Shared\cfgwiz.exe (Symantec Corporation)
O4 - HKLM..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\LSBurnWatcher.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [NAV CfgWiz] c:\Program Files\Norton AntiVirus\CfgWiz.exe (Symantec Corporation)
O4 - HKLM..\Run: [PS2] C:\WINDOWS\system32\ps2.EXE (Hewlett-Packard Company)
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\Recguard.exe ()
O4 - HKLM..\Run: [Reminder] C:\Windows\Creator\Remind_XP.exe (SoftThinks)
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SSC_UserPrompt] c:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe (Symantec Corporation)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UpdateManager] C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe (Sonic Solutions)
O4 - HKLM..\Run: [V0500Mon.exe] C:\WINDOWS\V0500Mon.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [Zune Launcher] c:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe (Eastman Kodak Company)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Orbit.lnk = C:\Program Files\Orbitdownloader\orbitdm.exe (Orbitdownloader.com)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe (Hewlett-Packard)
O4 - Startup: C:\Documents and Settings\Rogelio_1986\Start Menu\Programs\Startup\OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &Download; by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: &Grab; video by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Do&wnload; selected by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Down&load; all by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/C/0…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {8FA2192F-B95D-40E3-898F-8D7ABB8E00D0} http://download-games.pogo.com/online2/pog…mesLauncher.cab (SpinTop Games Launcher)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Rogelio_1986\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Rogelio_1986\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/07/06 03:22:12 | 000,000,050 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2001/07/28 06:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O32 - AutoRun File - [2008/10/11 17:47:17 | 000,662,592 | R— | M] (Electronic Arts Inc.) - E:\AutoRunGUI.dll – [ UDF ]
O32 - AutoRun File - [2008/10/22 08:19:21 | 000,000,000 | R–D | M] - E:\AutoRun – [ UDF ]
O32 - AutoRun File - [2008/10/11 17:47:17 | 000,703,552 | R— | M] (Electronic Arts Inc.) - E:\AutoRun.exe – [ UDF ]
O32 - AutoRun File - [2008/10/11 17:47:12 | 000,000,166 | R— | M] () - E:\autorun.inf – [ UDF ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/07/09 02:00:26 | 000,518,144 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2011/07/09 02:00:26 | 000,406,528 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2011/07/09 02:00:26 | 000,060,416 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2011/07/09 02:00:25 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2011/07/09 02:00:15 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2011/07/09 01:59:31 | 000,000,000 | —D | C] – C:\Qoobox
[2011/07/09 01:59:16 | 000,000,000 | R–D | C] – C:\Documents and Settings\Rogelio_1986\Start Menu\Programs\Administrative Tools
[2011/07/08 23:39:48 | 000,000,000 | —D | C] – C:\WINDOWS\Prefetch
[2011/07/08 23:21:32 | 000,000,000 | —D | C] – C:\WINDOWS\System32\scripting
[2011/07/08 23:21:30 | 000,000,000 | —D | C] – C:\WINDOWS\l2schemas
[2011/07/08 23:21:29 | 000,000,000 | —D | C] – C:\Program Files\msn
[2011/07/08 23:21:29 | 000,000,000 | —D | C] – C:\WINDOWS\System32\bits
[2011/07/08 23:16:44 | 000,000,000 | —D | C] – C:\WINDOWS\network diagnostic
[2011/07/08 23:12:08 | 000,000,000 | -H-D | C] – C:\WINDOWS\$NtServicePackUninstall$
[2011/07/08 23:12:04 | 000,000,000 | —D | C] – C:\WINDOWS\EHome
[2011/07/07 23:17:51 | 000,000,000 | —D | C] – C:\Documents and Settings\Rogelio_1986\Local Settings\Application Data\Ilivid Player
[2011/07/07 23:17:45 | 000,000,000 | —D | C] – C:\Documents and Settings\Rogelio_1986\AppData
[2011/07/07 23:17:44 | 000,000,000 | —D | C] – C:\Documents and Settings\Rogelio_1986\Application Data\searchquband
[2011/07/07 23:06:34 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\boost_interprocess
[2011/07/07 23:05:38 | 000,000,000 | —D | C] – C:\Documents and Settings\Rogelio_1986\Local Settings\Application Data\PackageAware
[2011/07/07 21:47:35 | 000,000,000 | —D | C] – C:\Documents and Settings\Rogelio_1986\My Documents\FrostWire
[2011/07/07 21:47:17 | 000,000,000 | —D | C] – C:\Documents and Settings\Rogelio_1986\Application Data\FrostWire
[2011/07/07 21:47:17 | 000,000,000 | —D | C] – C:\Documents and Settings\Rogelio_1986\.frostwire4.20
[2011/07/06 21:41:29 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe AIR
[2011/07/06 21:17:24 | 000,000,000 | —D | C] – C:\Documents and Settings\Rogelio_1986\My Documents\My eBooks
[2011/06/29 23:32:33 | 000,000,000 | -H-D | C] – C:\WINDOWS\ie8
[2011/06/29 00:18:55 | 000,000,000 | —D | C] – C:\Documents and Settings\Rogelio_1986\Application Data\Malwarebytes
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/07/09 02:47:03 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/07/09 02:31:26 | 000,940,910 | —- | M] () – C:\logfile
[2011/07/09 02:21:31 | 000,001,565 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Orbit.lnk
[2011/07/09 02:19:28 | 000,000,248 | —- | M] () – C:\WINDOWS\System\hpsysdrv.dat
[2011/07/09 02:19:02 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2011/07/09 02:18:59 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/07/09 02:18:21 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/07/09 02:18:20 | 527,814,656 | -HS- | M] () – C:\hiberfil.sys
[2011/07/09 01:00:29 | 000,001,324 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/07/08 23:42:38 | 000,442,796 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/07/08 23:42:38 | 000,071,936 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/07/08 23:39:52 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/07/08 23:39:16 | 000,183,424 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/07/08 23:16:24 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/07/08 03:58:54 | 000,013,246 | —- | M] () – C:\Documents and Settings\Rogelio_1986\My Documents\The Many Lives of Bridgette Yorke.odt
[2011/07/06 21:52:41 | 000,001,745 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader X.lnk
[2011/07/06 19:43:24 | 000,107,125 | —- | M] () – C:\Documents and Settings\Rogelio_1986\My Documents\Beijing Brownie Points Outfits.jpg
[2011/06/29 23:50:41 | 000,001,824 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2011/06/29 23:37:46 | 000,000,826 | —- | M] () – C:\Documents and Settings\Rogelio_1986\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/06/26 00:45:56 | 000,256,000 | —- | M] () – C:\WINDOWS\PEV.exe
[2011/06/12 08:27:48 | 000,120,467 | —- | M] () – C:\Documents and Settings\Rogelio_1986\My Documents\jb111.jpg
[2011/06/12 08:26:18 | 000,033,518 | —- | M] () – C:\Documents and Settings\Rogelio_1986\My Documents\ad.jpg
[2011/06/12 08:25:55 | 000,036,619 | —- | M] () – C:\Documents and Settings\Rogelio_1986\My Documents\shurugby_4.jpg
[2011/06/12 08:25:50 | 000,047,521 | —- | M] () – C:\Documents and Settings\Rogelio_1986\My Documents\shurugby18.jpg
[2011/06/12 08:25:36 | 000,054,089 | —- | M] () – C:\Documents and Settings\Rogelio_1986\My Documents\10.jpg
[2011/06/12 08:25:10 | 000,144,064 | —- | M] () – C:\Documents and Settings\Rogelio_1986\My Documents\gm.jpg
[2011/06/09 03:34:52 | 000,105,984 | —- | M] () – C:\Documents and Settings\Rogelio_1986\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/07/09 02:00:26 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2011/07/09 02:00:26 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2011/07/09 02:00:26 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2011/07/09 02:00:26 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2011/07/09 02:00:26 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2011/07/09 01:37:39 | 527,814,656 | -HS- | C] () – C:\hiberfil.sys
[2011/07/06 21:52:40 | 000,001,804 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader X.lnk
[2011/07/06 21:52:40 | 000,001,745 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader X.lnk
[2011/07/06 19:44:08 | 000,107,125 | —- | C] () – C:\Documents and Settings\Rogelio_1986\My Documents\Beijing Brownie Points Outfits.jpg
[2011/06/17 01:25:49 | 000,013,246 | —- | C] () – C:\Documents and Settings\Rogelio_1986\My Documents\The Many Lives of Bridgette Yorke.odt
[2011/06/12 08:27:50 | 000,120,467 | —- | C] () – C:\Documents and Settings\Rogelio_1986\My Documents\jb111.jpg
[2011/06/12 08:26:20 | 000,033,518 | —- | C] () – C:\Documents and Settings\Rogelio_1986\My Documents\ad.jpg
[2011/06/12 08:25:56 | 000,036,619 | —- | C] () – C:\Documents and Settings\Rogelio_1986\My Documents\shurugby_4.jpg
[2011/06/12 08:25:52 | 000,047,521 | —- | C] () – C:\Documents and Settings\Rogelio_1986\My Documents\shurugby18.jpg
[2011/06/12 08:25:40 | 000,054,089 | —- | C] () – C:\Documents and Settings\Rogelio_1986\My Documents\10.jpg
[2011/06/12 08:25:24 | 000,144,064 | —- | C] () – C:\Documents and Settings\Rogelio_1986\My Documents\gm.jpg
[2010/11/08 17:25:21 | 000,180,168 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/11/04 16:26:14 | 000,230,752 | —- | C] () – C:\WINDOWS\patchw32.dll
[2010/11/04 16:26:14 | 000,118,176 | —- | C] () – C:\WINDOWS\patchw.dll
[2010/04/23 16:50:19 | 000,105,984 | —- | C] () – C:\Documents and Settings\Rogelio_1986\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/04/23 16:13:50 | 000,000,128 | —- | C] () – C:\Documents and Settings\Rogelio_1986\Local Settings\Application Data\fusioncache.dat
[2010/02/12 20:46:39 | 000,004,978 | —- | C] () – C:\Documents and Settings\All Users\Application Data\kbkwknay.ayh
[2010/01/17 16:27:06 | 000,001,324 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2009/09/12 02:04:44 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2009/09/06 00:09:41 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2009/07/16 16:42:44 | 000,010,051 | —- | C] () – C:\WINDOWS\hpdj3840.ini
[2009/07/16 00:16:42 | 000,000,025 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2009/07/06 03:20:25 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2009/07/06 03:20:25 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2009/07/06 03:20:25 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2009/07/06 03:20:25 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2009/07/06 03:20:25 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2009/07/06 03:20:25 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2004/11/10 18:33:09 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/11/10 18:33:09 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/11/10 18:33:05 | 000,004,490 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/11/10 18:33:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2004/11/10 18:32:54 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2004/11/10 18:32:26 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/11/10 18:32:25 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/11/10 18:31:49 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/11/10 18:31:17 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/10/22 15:35:32 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2004/10/21 20:25:36 | 000,118,784 | R— | C] () – C:\WINDOWS\bwUnin-6.3.2.62.exe
[2004/10/21 20:21:50 | 000,014,529 | —- | C] () – C:\WINDOWS\System32\CHODDI.SYS
[2004/10/21 20:21:42 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\hpreg.dll
[2004/10/21 19:55:29 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2004/10/21 19:26:39 | 000,094,364 | —- | C] () – C:\WINDOWS\HPHins03.dat
[2004/10/21 19:26:39 | 000,002,655 | —- | C] () – C:\WINDOWS\hphmdl03.dat
[2004/10/21 19:19:52 | 000,104,140 | —- | C] () – C:\WINDOWS\hpoins04.dat
[2004/10/21 19:19:52 | 000,016,939 | —- | C] () – C:\WINDOWS\hpomdl04.dat
[2004/10/21 19:12:22 | 000,089,019 | —- | C] () – C:\WINDOWS\hpdins03.dat
[2004/10/21 19:05:47 | 000,086,562 | —- | C] () – C:\WINDOWS\hpiins01.dat
[2004/10/21 19:05:47 | 000,000,000 | —- | C] () – C:\WINDOWS\hpimdl01.dat
[2004/10/21 19:00:46 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2004/10/21 18:51:33 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\RTCOMDLL.dll
[2004/10/21 18:51:33 | 000,156,160 | —- | C] () – C:\WINDOWS\System32\RTLCPAPI.dll
[2004/10/21 18:45:57 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\sis760.bin
[2004/10/21 18:45:57 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\sis741.bin
[2004/10/21 18:45:57 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\sis660.bin
[2004/10/21 18:39:34 | 000,000,552 | —- | C] () – C:\WINDOWS\System32\d3d8caps.dat
[2004/10/21 18:17:08 | 000,299,073 | —- | C] () – C:\WINDOWS\System32\PythonCOM22.dll
[2004/10/21 18:17:08 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\PyWinTypes22.dll
[2004/10/21 18:15:49 | 000,016,896 | —- | C] () – C:\WINDOWS\System32\bcbmm.dll
[2004/10/21 17:55:39 | 000,000,802 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/10/21 17:53:52 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2004/10/21 17:49:07 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2004/10/21 17:36:39 | 000,000,549 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2004/10/21 17:35:59 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/10/21 17:35:56 | 000,442,796 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/10/21 17:35:56 | 000,071,936 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/10/21 10:43:28 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2004/10/21 10:42:31 | 000,183,424 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/20 04:14:46 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\PcdrKernelModeServices.dll
[2004/08/20 04:14:46 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\ProgressTrace.dll
[2004/06/07 19:32:52 | 000,009,505 | —- | C] () – C:\WINDOWS\System32\hphmon06.dat
[2004/03/03 01:50:56 | 000,004,460 | —- | C] () – C:\WINDOWS\hpfmdl_s04_main.dat
[2004/02/11 12:39:07 | 000,000,316 | —- | C] () – C:\WINDOWS\hpfins_s04_main.dat
[2003/04/11 00:04:00 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\JAWTAccessBridge.dll

========== Alternate Data Streams ==========

@Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2

< End of report >
sorry forgot this as well

OTL Extras logfile created on: 7/9/2011 2:55:31 AM - Run 1
OTL by OldTimer - Version 3.2.26.1 Folder = C:\Documents and Settings\Rogelio_1986\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

503.30 Mb Total Physical Memory | 101.43 Mb Available Physical Memory | 20.15% Memory free
1.20 Gb Paging File | 0.72 Gb Available in Paging File | 60.40% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 142.96 Gb Total Space | 44.36 Gb Free Space | 31.03% Space Free | Partition Type: NTFS
Drive D: | 6.07 Gb Total Space | 0.48 Gb Free Space | 7.84% Space Free | Partition Type: FAT32
Drive E: | 612.92 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF

Computer Name: YOUR-03667082DE | User Name: Rogelio_1986 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – C:\Program Files\VideoLAN\VLC\vlc.exe –started-from-file –playlist-enqueue "%1" ()
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – C:\Program Files\VideoLAN\VLC\vlc.exe –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe" = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe:*:Enabled:BackWeb for Pavilion – (Hewlett-Packard)
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger – (Yahoo! Inc.)
"C:\Program Files\Orbitdownloader\orbitdm.exe" = C:\Program Files\Orbitdownloader\orbitdm.exe:*:Enabled:Orbit – (Orbitdownloader.com)
"C:\Program Files\Orbitdownloader\orbitnet.exe" = C:\Program Files\Orbitdownloader\orbitnet.exe:*:Enabled:Orbit – (Orbitdownloader.com)
"C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe" = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe:*:Enabled:EasyShare – (Eastman Kodak Company)
"C:\Program Files\Java\jre6\bin\java.exe" = C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)
"C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe" = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe:*:Enabled:Kodak Software Updater – ()
"C:\Program Files\VideoLAN\VLC\vlc.exe" = C:\Program Files\VideoLAN\VLC\vlc.exe:*:Enabled:VLC media player – ()
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox – (Mozilla Corporation)
"C:\Program Files\Google\Google Earth\client\googleearth.exe" = C:\Program Files\Google\Google Earth\client\googleearth.exe:*:Enabled:Google Earth – (Google)
"C:\Program Files\FrostWire\FrostWire.exe" = C:\Program Files\FrostWire\FrostWire.exe:*:Enabled:FrostWire – (FrostWire Group)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0008546E-DF6E-4CC1-AFD0-2CB8E16C95A2}" = Notifier
"{0076E1AC-9E7B-4B9F-A62A-4CC9511AD8E3}" = Zune Language Pack (FR)
"{009435FA-9011-4C36-AE7C-CCC9669E7875}" = Windows Media Format 11 SDK
"{00FC6799-866E-44A1-A60C-DCF394CF56FD}" = iTunes
"{03EDED24-8375-407D-A721-4643D9768BE1}" = kgchlwn
"{073F22CE-9A5B-4A40-A604-C7270AC6BF34}" = ESSSONIC
"{09DA4F91-2A09-4232-AB8C-6BC740096DE3}" = Sonic Update Manager
"{0C66761E-497A-4BE3-AE0D-8EC30FC9A9AA}" = PC-Doctor for Windows
"{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}" = Microsoft Plus! Photo Story 2 LE
"{11F3F858-4131-4FFA-A560-3FE282933B6E}" = kgchday
"{12E2B9E9-05B1-407d-B0FD-B5F350535125}" = Norton Internet Security
"{14589F05-C658-4594-9429-D437BA688686}" = IntelliMover Data Transfer Demo
"{14D4ED84-6A9A-45A0-96F6-1753768C3CB5}" = ESSPCD
"{1A2A15C2-6780-49c1-B296-503230E9DE00}" = The Sims™ 2 Mansion and Garden Stuff
"{1F63ED0B-EDD2-4037-B6AB-1358C624AF48}" = Scan
"{21E75254-410E-49C4-8981-2E1A2A2221F2}" = HP Diagnostic Assistant
"{228F6876-A313-40A3-91C0-C3CBE6997D09}" = Symantec
"{267868CE-6DFF-40F7-9C58-C01119B7B117}" = Fax
"{26A24AE4-039D-4CA4-87B4-2F83216014FF}" = Java™ 6 Update 14
"{2908F0CB-C1D4-447F-97A2-CFC135C9F8D4}" = Internet Worm Protection
"{2D03B6F8-DF36-4980-B7B6-5B93D5BA3A8F}" = essvatgt
"{2DA85B02-13C0-4E6D-9A76-22E6B3DD0CB2}" = SymNet
"{2FCE4FC5-6930-40E7-A4F1-F862207424EF}" = InterVideo WinDVD Creator
"{3192A00C-7336-48C6-8BD7-54B9CFA6F7C1}" = Windows Rights Management Client
"{34A59AC3-6C5C-4A09-A7F5-369A37176C8A}" = AiOSoftware
"{34EEB1F5-E939-40A1-A6BA-957282A4B2C8}" = Norton AntiVirus Help
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3AEF2F6C-F1D3-47CD-BF3B-A327F1FABE58}" = PSPrinters06
"{3BD0196C-6553-460c-A0C4-90D8AE5D60D2}" = Norton Personal Firewall
"{416D80BA-6F6D-4672-B7CF-F54DA2F80B44}" = Microsoft Works
"{42938595-0D83-404D-9F73-F8177FDD531A}" = ESScore
"{4537EA4B-F603-4181-89FB-2953FC695AB1}" = netbrdg
"{457791C5-D702-4143-A7B2-2744BE9573F2}" = HP Software Update
"{4817189D-1785-4627-A33C-39FD90919300}" = The Sims 2 Pets
"{48185814-A224-447a-81DA-71BD20580E1B}" = Norton Internet Security
"{4C04DF1B-6A39-4299-9DD1-1FA60000266E}" = HP Photosmart Cameras 4.0
"{503AA035-41E2-4858-B31F-1E49AC66C309}" = Norton Security Center
"{526AD5DC-CFC4-4f2a-8442-C84CC91D6C7F}" = Norton Internet Security
"{5316DFC9-CE99-4458-9AB3-E8726EDE0210}" = skin0001
"{541DEAC0-5F3D-45E6-B7CB-94ECF3B96748}" = Skype web features
"{5C648FDB-0138-4619-B66E-230EF53E8E2C}" = The Sims™ 2 Teen Style Stuff
"{605A4E39-613C-4A12-B56F-DEFBE6757237}" = SHASTA
"{608D2A3C-6889-4C11-9B54-A42F45ACBFDB}" = fflink
"{643EAE81-920C-4931-9F0B-4B343B225CA6}" = ESSBrwr
"{6522C636-B04C-4333-9BEB-9E0C0B6350D6}" = The Sims™ 2 Kitchen & Bath Interior Design Stuff
"{693C08A7-9E76-43FF-B11E-9A58175474C4}" = kgckids
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6BDD9CE6-D0A6-478A-BAD3-BA6945E89EB0}" = The Sims 2 Family Fun Stuff
"{6E17F9751-F056-4335-B718-8AF1B1092AFB}" = The Sims™ 2 IKEA® Home Stuff
"{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}" = Microsoft Plus! Digital Media Edition Installer
"{7148F0A8-6813-11D6-A77B-00B0D0142030}" = Java 2 Runtime Environment, SE v1.4.2_03
"{725249C3-B94C-4141-8799-0D3BA43D0812}" = CameraDrivers
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{77772678-817F-4401-9301-ED1D01A8DA56}" = SPBBC
"{7B3577F5-1D82-4C9B-008B-69D026FD8BCA}" = The Sims 2 Open For Business
"{84031A18-BA9A-4156-A74F-E05B52DDFCE2}" = DING!
"{84DDE556-43EF-43ed-B2DF-37AF9E5DDD75}" = The Sims™ 2 H&M® Fashion Stuff
"{87F6C83D-F949-4d14-B5CB-DC8C75F8932D}" = The Sims™ 2 FreeTime
"{8943CE61-53BD-475E-90E1-A580869E98A2}" = staticcr
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A502E38-29C9-49FA-BCFA-D727CA062589}" = ESSTOOLS
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver
"{8A8664E1-84C8-4936-891C-BC1F07797549}" = kgcvday
"{8AB8D458-939E-403F-0097-9BA1C1F013D5}" = The Sims 2
"{8E92D746-CD9F-4B90-9668-42B74C14F765}" = ESSini
"{8FD3F4BA-A4A6-4380-00A6-CC6853AB2DC2}" = The Sims 2 University
"{91517631-A9F3-4B7C-B482-43E0068FD55A}" = ESSgui
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD Player
"{91AA4B1F-B918-4e0b-A304-F8D4EC5D7726}" = Norton Internet Security
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{999D43F4-9709-4887-9B1A-83EBB15A8370}" = VPRINTOL
"{9BD54685-1496-46A5-AB62-357CD140ED8B}" = kgcinvt
"{9CDBC303-3EED-40b0-8E41-A7C65AA96C26}" = The Sims 2 Glamour Life Stuff
"{A1062847-0846-427A-92A1-BB8251A91E91}" = HP PSC & OfficeJet 4.0
"{A1588373-1D86-4D44-86C9-78ABD190F9CC}" = kgcmove
"{A2500497-FD32-493e-B8E5-28D6728DBEF5}" = Readme
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A398F2DC-D706-4bb2-AC38-5532CD229D08}" = CC_ccProxyMSI
"{A4EA3AB4-E78C-4286-96DF-26035507CE55}" = AiO_Scan
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}" = Photosmart 320,370,7400,8100,8400 Series
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.0)
"{AE1FA02D-E6A4-4EA0-8E58-6483CAC016DD}" = ESSCDBK
"{B103C8A7-D1CC-4B1A-BD41-883F652E097D}" = muvee autoProducer 3.5 magicMoments - HPD
"{B1591C79-1C35-4E09-AA15-F7D6923AFB96}" = HP Deskjet 3840
"{B162D0A6-9A1D-4B7C-91A5-88FB48113C45}" = OfotoXMI
"{B3FED300-806C-11E0-A0D0-B8AC6F97B88E}" = Google Earth
"{B4B44FE7-41FF-4DAD-8C0A-E406DDA72992}" = CCScore
"{B6F5B704-06D3-4687-90F3-6195304AD755}" = The Sims™ 2 Apartment Life
"{B997C2A0-4383-41BF-B76E-9B8B7ECFB267}" = KSU
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C3F058C0-A21C-452D-8D99-95B1A45F417D}" = InterVideo DiscLabel
"{C6F5B6CF-609C-428E-876F-CA83176C021B}" = Norton AntiVirus 2005
"{C78EAC6F-7A73-452E-8134-DBB2165C5A68}" = QuickTime
"{C9D599E1-6B68-4a1f-8A4F-A1DB433DB1BF}" = Norton Internet Security
"{CA256FA1-4CF9-492C-98A6-6E451F83AEC3}" = Youda Farmer
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0122362-6333-4DE4-93F6-A5A2F3CC101A}" = HP Organize
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1
"{D32470A1-B10C-4059-BA53-CF0486F68EBC}" = Kodak EasyShare software
"{D6414CC7-F215-467F-88B1-546ED863F35B}" = CC_ccStart
"{DB02F716-6275-42E9-B8D2-83BA2BF5100B}" = SFR
"{DB518BA6-CB74-4EB6-9ABD-880B6D6E1F38}" = HpSdpAppCoreApp
"{DC367608-64A7-4BF7-92F4-8BAA25BA02DB}" = ccCommon
"{DFEF49D9-FC95-4301-99B9-2FB91C6ABA06}" = The Sims™ 2 Seasons
"{E18B549C-5D15-45DA-8D8F-8FD2BD946344}" = kgcbaby
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E47EE8FB-ACC0-4608-859C-4E2851B18A6A}" = Norton Internet Security
"{E5EE9939-259F-4DE2-8023-5C49E16A4F43}" = Norton AntiVirus Parent MSI
"{E6B87DC4-2B3D-4483-ADFF-E483BF718991}" = OpenOffice.org 3.1
"{E79987F0-0E34-42CC-B8FF-6C860AEEB26A}" = tooltips
"{EAA38532-7AD0-4f78-918A-4F4F02096ECE}" = The Sims™ 2 Celebration! Stuff
"{EC905264-BCFE-423B-9C42-C3A106266790}" = Windows Rights Management Client Backwards Compatibility
"{EE4ACABF-531E-419A-9225-B8E0FA4955AF}" = Zune Language Pack (ES)
"{F22C222C-3CE2-4A4B-A83F-AF4681371ABE}" = kgcbase
"{F248ADFA-64E0-4b03-8A83-059078BED6A0}" = The Sims™ 2 Bon Voyage
"{F419D20A-7719-4639-8E30-C073A040D878}" = HP Deskjet Preloaded Printer Drivers
"{F4A2E7CC-60CA-4AFA-B67F-AD5E58173C3F}" = SKINXSDK
"{F64306A5-4C32-41bb-B153-53986527FAB4}" = Norton WMI Update
"{F7529650-B9DB-481B-0089-A2AC3C2821C1}" = The Sims 2 Nightlife
"{F9593CFB-D836-49BC-BFF1-0E669A411D9F}" = WIRELESS
"{FC2C0536-583C-46c0-844A-62CECAE01F22}" = Norton Internet Security
"{FC37ABD0-2108-4beb-B010-1254E0662B5A}" = MSRedist
"{FCDB1C92-03C6-4C76-8625-371224256091}" = ESSPDock
"{FDB3B167-F4FA-461D-976F-286304A57B2A}" = Adobe AIR
"{FF70513F-E3A7-402F-84FB-B7810A064BE2}" = Zune
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Agere Systems Soft Modem" = Agere Systems PCI Soft Modem
"BackWeb-309731 Uninstaller" = Updates from HP
"BN_DesktopReader" = NOOK for PC
"Dynex VF0500" = Dynex 1.3MP Webcam Driver (1.00.03.0000)
"Dynex Webcam User's Guide" = Dynex Webcam User's Guide
"Google Chrome" = Google Chrome
"Help and Support Additions" = Help and Support Additions
"ie8" = Windows Internet Explorer 8
"InstallShield_{00FC6799-866E-44A1-A60C-DCF394CF56FD}" = iTunes
"InstallShield_{0C66761E-497A-4BE3-AE0D-8EC30FC9A9AA}" = PC-Doctor for Windows
"Live! Cam Center" = Live! Cam Center
"LiveReg" = LiveReg (Symantec Corporation)
"LiveUpdate" = LiveUpdate 2.5 (Symantec Corporation)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"McAfee Security Scan" = McAfee Security Scan Plus
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.17)" = Mozilla Firefox (3.6.17)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NVIDIA Drivers" = NVIDIA Drivers
"Orbit_is1" = Orbit Downloader
"Picasa 3" = Picasa 3
"PS2" = PS2
"Python 2.2 combined Win32 extensions" = Python 2.2 combined Win32 extensions
"Python 2.2.1" = Python 2.2.1
"RealPlayer 6.0" = RealPlayer
"SymSetup.{3BD0196C-6553-460c-A0C4-90D8AE5D60D2}" = Norton Personal Firewall (Symantec Corporation)
"SymSetup.{C6F5B6CF-609C-428E-876F-CA83176C021B}" = Norton AntiVirus 2005 (Symantec Corporation)
"SystemRequirementsLab" = System Requirements Lab
"VLC media player" = VLC media player 0.9.8a
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"winusb0100" = Microsoft WinUsb 1.0
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01007" = Microsoft User-Mode Driver Framework Feature Pack 1.7
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Search Defender" = Yahoo! Search Protection
"Yahoo! Software Update" = Yahoo! Software Update
"Zune" = Zune

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Move Media Player" = Move Media Player

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 7/1/2011 12:13:51 AM | Computer Name = YOUR-03667082DE | Source = WPDMTPDriver | ID = 80836
Description =

Error - 7/6/2011 7:45:55 AM | Computer Name = YOUR-03667082DE | Source = Application Hang | ID = 1002
Description = Hanging application wmplayer.exe, version 11.0.5721.5145, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 7/6/2011 7:50:15 AM | Computer Name = YOUR-03667082DE | Source = Application Hang | ID = 1002
Description = Hanging application wmplayer.exe, version 11.0.5721.5145, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 7/6/2011 7:50:20 AM | Computer Name = YOUR-03667082DE | Source = Application Hang | ID = 1001
Description = Fault bucket 337816799.

Error - 7/7/2011 1:24:01 AM | Computer Name = YOUR-03667082DE | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 7/7/2011 1:24:01 AM | Computer Name = YOUR-03667082DE | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 7/8/2011 12:29:18 AM | Computer Name = YOUR-03667082DE | Source = WPDMTPDriver | ID = 80836
Description =

Error - 7/9/2011 2:00:47 AM | Computer Name = YOUR-03667082DE | Source = Application Hang | ID = 1002
Description = Hanging application mbam.exe, version 1.44.0.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 7/9/2011 2:31:29 AM | Computer Name = YOUR-03667082DE | Source = Application Error | ID = 1000
Description = Faulting application chrome.exe, version 0.0.0.0, faulting module
chrome.dll, version 12.0.742.112, fault address 0x005a6a6c.

Error - 7/9/2011 2:31:29 AM | Computer Name = YOUR-03667082DE | Source = Application Error | ID = 1000
Description = Faulting application chrome.exe, version 0.0.0.0, faulting module
chrome.dll, version 12.0.742.112, fault address 0x005a6a6c.

[ System Events ]
Error - 7/9/2011 3:10:10 AM | Computer Name = YOUR-03667082DE | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service McComponentHostService
with arguments "" in order to run the server: {CC6F4D12-8575-4CFF-9455-CF5774AEB13B}

Error - 7/9/2011 3:10:20 AM | Computer Name = YOUR-03667082DE | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service McComponentHostService
with arguments "" in order to run the server: {CC6F4D12-8575-4CFF-9455-CF5774AEB13B}

Error - 7/9/2011 3:10:25 AM | Computer Name = YOUR-03667082DE | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service MDM with arguments
"" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064}

Error - 7/9/2011 3:10:49 AM | Computer Name = YOUR-03667082DE | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service MDM with arguments
"" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064}

Error - 7/9/2011 3:11:00 AM | Computer Name = YOUR-03667082DE | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service MDM with arguments
"" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064}

Error - 7/9/2011 3:11:05 AM | Computer Name = YOUR-03667082DE | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service McComponentHostService
with arguments "" in order to run the server: {CC6F4D12-8575-4CFF-9455-CF5774AEB13B}

Error - 7/9/2011 3:11:05 AM | Computer Name = YOUR-03667082DE | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service McComponentHostService
with arguments "" in order to run the server: {CC6F4D12-8575-4CFF-9455-CF5774AEB13B}

Error - 7/9/2011 3:36:30 AM | Computer Name = YOUR-03667082DE | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 7/9/2011 3:41:44 AM | Computer Name = YOUR-03667082DE | Source = Service Control Manager | ID = 7022
Description = The Windows Firewall/Internet Connection Sharing (ICS) service hung
on starting.

Error - 7/9/2011 4:04:35 AM | Computer Name = YOUR-03667082DE | Source = Service Control Manager | ID = 7034
Description = The Mp3Tube Toolbar Updater Service service terminated unexpectedly.
It has done this 1 time(s).


< End of report >
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 3:32:50 AM, on 7/9/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Norton AntiVirus\navapsvc.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\WINDOWS\system32\ZuneBusEnum.exe
c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\hphmon06.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\WINDOWS\V0500Mon.exe
C:\Program Files\Zune\ZuneLauncher.exe
C:\Program Files\QuickTime\QTTask.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\igfxtray.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
C:\Program Files\Orbitdownloader\orbitdm.exe
C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
C:\Program Files\Orbitdownloader\orbitnet.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - c:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] c:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [NAV CfgWiz] "c:\Program Files\Norton AntiVirus\CfgWiz.exe" /GUID {0D7956A2-5A08-4ec2-A72C-DF8495A66016} /MODE CfgWiz /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [IS CfgWiz] c:\Program Files\Common Files\Symantec Shared\cfgwiz.exe /GUID NIS /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
O4 - HKLM\..\Run: [V0500Mon.exe] C:\WINDOWS\V0500Mon.exe
O4 - HKLM\..\Run: [Zune Launcher] "c:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - Startup: OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: McAfee Security Scan Plus.lnk = ?
O4 - Global Startup: Orbit.lnk = C:\Program Files\Orbitdownloader\orbitdm.exe
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {8FA2192F-B95D-40E3-898F-8D7ABB8E00D0} (SpinTop Games Launcher) - http://download-games.pogo.com/online2/pog…mesLauncher.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Google Update Service (gupdate1ca012caa06ed90) (gupdate1ca012caa06ed90) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - c:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

–
End of file - 11323 bytes
Hi Bookworm1986, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

I see you have ran combofix. This is a very powerful tool that should not be used without supervision.

A log should have been created, you will find it at C:\combofix.txt. Please post the contents of that log.

Next

Next, Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:OTL
FF - prefs.js..browser.search.defaultenginename: "Search Results"
FF - prefs.js..browser.search.order.1: "Search Results"
FF - prefs.js..browser.search.selectedEngine: "Search Results"
FF - prefs.js..browser.startup.homepage: "http://www.searchqu.com/406"
FF - prefs.js..keyword.URL: "http://dts.search-results.com/sr?src=ffb&appid=102&systemid=406&q="
[2011/07/07 23:06:32 | 000,002,501 | —- | M] () – C:\Documents and Settings\Rogelio_1986\Application Data\Mozilla\Firefox\Profiles\8u81h8pd.default\searchplugins\SearchResults.xml
[2011/07/07 23:06:32 | 000,002,501 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\SearchResults.xml
O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found.
[2011/07/07 23:17:44 | 000,000,000 | —D | C] – C:\Documents and Settings\Rogelio_1986\Application Data\searchquband

:Files
ipconfig /flushdns /c

:Commands
[createrestorepoint]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
  • Reboot your computer
Please post the OTL fix log .

Next

Please open OTL if it is not opened.

  • Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, click the None button near the top (it may looked greyed out)
  • In the window under Custom Scans/Fixes copy and paste the following


    c:|Bandoo;true;true;true; /FP
    c:|Searchqu;true;true;true; /FP
    c:|iLivid;true;true;true; /FP
    %USERPROFILE%\..|smtmp;true;true;true /FP


  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open a notepad window, OTL.Txt. Please post this log.

Please post back with
  • combofix log
  • OTL fix log
  • OTL.txt
How is the computer? Please describe any symptoms you may be experiencing.

Thanks
OTL logfile created on: 7/9/2011 4:02:55 AM - Run 2
OTL by OldTimer - Version 3.2.26.1 Folder = C:\Documents and Settings\Rogelio_1986\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

503.30 Mb Total Physical Memory | 137.36 Mb Available Physical Memory | 27.29% Memory free
1.20 Gb Paging File | 0.83 Gb Available in Paging File | 69.39% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 142.96 Gb Total Space | 44.33 Gb Free Space | 31.01% Space Free | Partition Type: NTFS
Drive D: | 6.07 Gb Total Space | 0.48 Gb Free Space | 7.84% Space Free | Partition Type: FAT32
Drive E: | 612.92 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF

Computer Name: YOUR-03667082DE | User Name: Rogelio_1986 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days

========== Custom Scans ==========


< c:|Bandoo;true;true;true; /FP >

< c:|Searchqu;true;true;true; /FP >
[2011/07/07 23:17:44 | 000,000,000 | —D | M] – c:\_OTL\MovedFiles\07092011_035204\C_Documents and Settings\Rogelio_1986\Application Data\searchquband

< c:|iLivid;true;true;true; /FP >
[2011/07/07 23:18:13 | 000,000,000 | —D | M] – c:\Documents and Settings\Rogelio_1986\Local Settings\Application Data\Ilivid Player

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< End of report >


Error: Unable to interpret in the current context!
Error: Unable to interpret in the current context!
Error: Unable to interpret in the current context!
Error: Unable to interpret in the current context!
Error: Unable to interpret in the current context!
Error: Unable to interpret in the current context!
Error: Unable to interpret in the current context!
Error: Unable to interpret in the current context!
Error: Unable to interpret in the current context!
Error: Unable to interpret in the current context!
Error: Unable to interpret in the current context!
Error: Unable to interpret <[X]> in the current context!
Error: Unable to interpret in the current context!
Error: Unable to interpret in the current context!
Error: Unable to interpret in the current context!
Error: Unable to interpret <(Message will auto close in 2 seconds)> in the current context!
Error: Unable to interpret in the current context!
Error: Unable to interpret < My Topics · My Controls · View New Posts · My Assistant> in the current context!
Error: Unable to interpret <> What the Tech > Spyware / Malware / Virus Removal > Virus, Spyware & Malware Removal> in the current context!
Error: Unable to interpret <> Guidelines> in the current context!
Error: Unable to interpret in the current context!
Error: Unable to interpret in the current context!
Error: Unable to interpret in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret < Reply to this topicStart new topic> in the current context!
Error: Unable to interpret <> searchqu 406 help me please> in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret in the current context!
Error: Unable to interpret in the current context!
Error: Unable to interpret in the current context!
Error: Unable to interpret in the current context!
Error: Unable to interpret in the current context!
Error: Unable to interpret in the current context!
Error: Unable to interpret in the current context!
Error: Unable to interpret in the current context!
Error: Unable to interpret in the current context!
Error: Unable to interpret in the current context!
Error: Unable to interpret in the current context!
Error: Unable to interpret in the current context!
Error: Unable to interpret
Hi Bookworm1986,

It looks like you may have pasted the entire page into OTL when you ran the fix.

  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • UNCheck the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open a notepad windows. OTL.Txt, no Extras.Txt this time.

Please post back with
  • OTL.txt
Thanks
OTL logfile created on: 7/9/2011 12:30:12 PM - Run 3
OTL by OldTimer - Version 3.2.26.1 Folder = C:\Documents and Settings\Rogelio_1986\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

503.30 Mb Total Physical Memory | 73.16 Mb Available Physical Memory | 14.54% Memory free
1.20 Gb Paging File | 0.79 Gb Available in Paging File | 65.72% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 142.96 Gb Total Space | 44.25 Gb Free Space | 30.95% Space Free | Partition Type: NTFS
Drive D: | 6.07 Gb Total Space | 0.48 Gb Free Space | 7.84% Space Free | Partition Type: FAT32
Drive E: | 612.92 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF

Computer Name: YOUR-03667082DE | User Name: Rogelio_1986 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Rogelio_1986\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Orbitdownloader\orbitdm.exe (Orbitdownloader.com)
PRC - C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
PRC - C:\Program Files\Orbitdownloader\orbitnet.exe (Orbitdownloader.com)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\ZuneBusEnum.exe (Microsoft Corporation)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\V0500Mon.exe (Creative Technology Ltd.)
PRC - C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe (Eastman Kodak Company)
PRC - C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe (Hewlett-Packard)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - c:\Program Files\Norton AntiVirus\navapsvc.exe (Symantec Corporation)
PRC - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
PRC - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
PRC - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (Symantec Corporation)
PRC - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe (Symantec Corporation)
PRC - C:\WINDOWS\ALCWZRD.EXE (RealTek Semicoductor Corp.)
PRC - C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
PRC - C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe (HP)
PRC - C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe ()
PRC - C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe (Hewlett-Packard Company)
PRC - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe (Sonic Solutions)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Rogelio_1986\My Documents\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll (Microsoft Corporation)
MOD - C:\Documents and Settings\Rogelio_1986\Local Settings\temp\IadHide5.dll (BackWeb)


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – File not found
SRV - (AppMgmt) – File not found
SRV - (McComponentHostService) – C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (ZuneNetworkSvc) – c:\Program Files\Zune\ZuneNss.exe (Microsoft Corporation)
SRV - (ZuneWlanCfgSvc) – C:\WINDOWS\system32\ZuneWlanCfgSvc.exe (Microsoft Corporation)
SRV - (ZuneBusEnum) – C:\WINDOWS\system32\ZuneBusEnum.exe (Microsoft Corporation)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (NPFMntor) – c:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe (Symantec Corporation)
SRV - (navapsvc) – c:\Program Files\Norton AntiVirus\navapsvc.exe (Symantec Corporation)
SRV - (ccSetMgr) – c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
SRV - (ccPwdSvc) – c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe (Symantec Corporation)
SRV - (ccEvtMgr) – c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
SRV - (SNDSrvc) – c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (Symantec Corporation)
SRV - (SymWSC) – c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe (Symantec Corporation)
SRV - (SAVScan) – c:\Program Files\Norton AntiVirus\SAVScan.exe (Symantec Corporation)
SRV - (SPBBCSvc) – c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe (Symantec Corporation)
SRV - (ccProxy) – c:\Program Files\Common Files\Symantec Shared\ccProxy.exe (Symantec Corporation)


========== Driver Services (SafeList) ==========

DRV - (MobileAdapter) – C:\WINDOWS\system32\drivers\qscnusb.sys (QUALCOMM Incorporated)
DRV - (V0500Dev) – C:\WINDOWS\system32\drivers\V0500Vid.sys (Creative Technology Ltd.)
DRV - (WinUSB) – C:\WINDOWS\system32\drivers\winusb.sys (Microsoft Corporation)
DRV - (SYMIDSCO) – C:\Program Files\Common Files\Symantec Shared\SymcData\idsdefs\20040813.178\SymIDSCo.sys (Symantec Corporation)
DRV - (NAVEX15) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20041006.020\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20041006.020\NAVENG.SYS (Symantec Corporation)
DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (SiS315) – C:\WINDOWS\system32\drivers\sisgrp.sys (Silicon Integrated Systems Corporation)
DRV - (SiSkp) – C:\WINDOWS\system32\drivers\srvkp.sys (Silicon Integrated Systems Corporation)
DRV - (SYMTDI) – C:\WINDOWS\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (SYMREDRV) – C:\WINDOWS\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (SYMIDS) – C:\WINDOWS\System32\Drivers\SYMIDS.SYS (Symantec Corporation)
DRV - (SYMNDIS) – C:\WINDOWS\System32\Drivers\SYMNDIS.SYS (Symantec Corporation)
DRV - (SYMFW) – C:\WINDOWS\System32\Drivers\SYMFW.SYS (Symantec Corporation)
DRV - (SYMDNS) – C:\WINDOWS\System32\Drivers\SYMDNS.SYS (Symantec Corporation)
DRV - (SymEvent) – C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (SAVRTPEL) – c:\Program Files\Norton AntiVirus\Savrtpel.sys (Symantec Corporation)
DRV - (SAVRT) – c:\Program Files\Norton AntiVirus\savrt.sys (Symantec Corporation)
DRV - (SPBBCDrv) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (AgereSoftModem) – C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (fasttx2k) – C:\WINDOWS\system32\DRIVERS\fasttx2k.sys (Promise Technology, Inc.)
DRV - (Pfc) – C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
DRV - (SISAGP) – C:\WINDOWS\system32\DRIVERS\SISAGPX.sys (Silicon Integrated Systems Corporation)
DRV - (viaagp1) – C:\WINDOWS\system32\DRIVERS\viaagp1.sys (VIA Technologies, Inc.)
DRV - (rtl8139) – C:\WINDOWS\system32\drivers\R8139n51.sys (Realtek Semiconductor Corporation )
DRV - (Ps2) – C:\WINDOWS\system32\drivers\PS2.sys (Hewlett-Packard Company)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: ""
FF - prefs.js..browser.search.order.1: ""
FF - prefs.js..browser.search.selectedEngine: ""
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {35379F86-8CCB-4724-AE33-4278DE266C70}:1.0.5
FF - prefs.js..extensions.enabledItems: [removed]:3.11.3.15590
FF - prefs.js..extensions.enabledItems: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.1.94
FF - prefs.js..extensions.enabledItems: {6904342A-8307-11DF-A508-4AE2DFD72085}:2.1.1.94


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60310.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Documents and Settings\Rogelio_1986\Application Data\Move Networks\plugins\071803000001\npqmp071803000001.dll (Move Networks)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.1879: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.2.1939: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.872: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.57\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.57\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Documents and Settings\Rogelio_1986\Application Data\Move Networks\plugins\071803000001\npqmp071803000001.dll (Move Networks)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.18\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/07/09 04:02:22 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.18\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/07/09 03:18:00 | 000,000,000 | —D | M]

[2011/07/07 23:35:23 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Rogelio_1986\Application Data\Mozilla\Extensions
[2010/10/17 23:09:29 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Rogelio_1986\Application Data\Mozilla\Extensions\[removed]
[2011/07/09 04:29:22 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Rogelio_1986\Application Data\Mozilla\Firefox\Profiles\8u81h8pd.default\extensions
[2010/12/05 14:49:27 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Rogelio_1986\Application Data\Mozilla\Firefox\Profiles\8u81h8pd.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/05/19 11:04:12 | 000,002,561 | —- | M] () – C:\Documents and Settings\Rogelio_1986\Application Data\Mozilla\Firefox\Profiles\8u81h8pd.default\searchplugins\askcom.xml
[2011/07/09 02:32:10 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/07/09 02:32:10 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2011/07/09 01:39:37 | 000,001,211 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\Mp3Tube.xml

O1 HOSTS File: ([2011/07/09 02:19:02 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Octh Class) - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll (Orbitdownloader.com)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (CNisExtBho Class) - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - c:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll (Symantec Corporation)
O2 - BHO: (CNavExtBho Class) - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NAVShExt.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Norton AntiVirus) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NAVShExt.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll ()
O3 - HKCU\..\Toolbar\ShellBrowser: (Norton AntiVirus) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NAVShExt.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll ()
O4 - HKLM..\Run: [AlcWzrd] C:\WINDOWS\ALCWZRD.EXE (RealTek Semicoductor Corp.)
O4 - HKLM..\Run: [ccApp] c:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe (HP)
O4 - HKLM..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe (Hewlett-Packard)
O4 - HKLM..\Run: [IS CfgWiz] c:\Program Files\Common Files\Symantec Shared\cfgwiz.exe (Symantec Corporation)
O4 - HKLM..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\LSBurnWatcher.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [NAV CfgWiz] c:\Program Files\Norton AntiVirus\CfgWiz.exe (Symantec Corporation)
O4 - HKLM..\Run: [PS2] C:\WINDOWS\system32\ps2.EXE (Hewlett-Packard Company)
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\Recguard.exe ()
O4 - HKLM..\Run: [Reminder] C:\Windows\Creator\Remind_XP.exe (SoftThinks)
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SSC_UserPrompt] c:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe (Symantec Corporation)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UpdateManager] C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe (Sonic Solutions)
O4 - HKLM..\Run: [V0500Mon.exe] C:\WINDOWS\V0500Mon.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [Zune Launcher] c:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe (Eastman Kodak Company)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Orbit.lnk = C:\Program Files\Orbitdownloader\orbitdm.exe (Orbitdownloader.com)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe (Hewlett-Packard)
O4 - Startup: C:\Documents and Settings\Rogelio_1986\Start Menu\Programs\Startup\OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &Download; by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: &Grab; video by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Do&wnload; selected by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Down&load; all by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/C/0…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {8FA2192F-B95D-40E3-898F-8D7ABB8E00D0} http://download-games.pogo.com/online2/pog…mesLauncher.cab (SpinTop Games Launcher)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Rogelio_1986\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Rogelio_1986\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/07/06 03:22:12 | 000,000,050 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2001/07/28 06:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O32 - AutoRun File - [2008/10/11 17:47:17 | 000,662,592 | R— | M] (Electronic Arts Inc.) - E:\AutoRunGUI.dll – [ UDF ]
O32 - AutoRun File - [2008/10/22 08:19:21 | 000,000,000 | R–D | M] - E:\AutoRun – [ UDF ]
O32 - AutoRun File - [2008/10/11 17:47:17 | 000,703,552 | R— | M] (Electronic Arts Inc.) - E:\AutoRun.exe – [ UDF ]
O32 - AutoRun File - [2008/10/11 17:47:12 | 000,000,166 | R— | M] () - E:\autorun.inf – [ UDF ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/07/09 03:52:04 | 000,000,000 | —D | C] – C:\_OTL
[2011/07/09 03:32:06 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2011/07/09 03:32:06 | 000,000,000 | —D | C] – C:\Documents and Settings\Rogelio_1986\Start Menu\Programs\HiJackThis
[2011/07/09 02:00:26 | 000,518,144 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2011/07/09 02:00:26 | 000,406,528 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2011/07/09 02:00:26 | 000,060,416 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2011/07/09 02:00:25 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2011/07/09 02:00:15 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2011/07/09 01:59:31 | 000,000,000 | —D | C] – C:\Qoobox
[2011/07/09 01:59:16 | 000,000,000 | R–D | C] – C:\Documents and Settings\Rogelio_1986\Start Menu\Programs\Administrative Tools
[2011/07/08 23:39:48 | 000,000,000 | —D | C] – C:\WINDOWS\Prefetch
[2011/07/08 23:21:32 | 000,000,000 | —D | C] – C:\WINDOWS\System32\scripting
[2011/07/08 23:21:30 | 000,000,000 | —D | C] – C:\WINDOWS\l2schemas
[2011/07/08 23:21:29 | 000,000,000 | —D | C] – C:\Program Files\msn
[2011/07/08 23:21:29 | 000,000,000 | —D | C] – C:\WINDOWS\System32\bits
[2011/07/08 23:16:44 | 000,000,000 | —D | C] – C:\WINDOWS\network diagnostic
[2011/07/08 23:12:08 | 000,000,000 | -H-D | C] – C:\WINDOWS\$NtServicePackUninstall$
[2011/07/08 23:12:04 | 000,000,000 | —D | C] – C:\WINDOWS\EHome
[2011/07/07 23:17:51 | 000,000,000 | —D | C] – C:\Documents and Settings\Rogelio_1986\Local Settings\Application Data\Ilivid Player
[2011/07/07 23:17:45 | 000,000,000 | —D | C] – C:\Documents and Settings\Rogelio_1986\AppData
[2011/07/07 23:06:34 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\boost_interprocess
[2011/07/07 23:05:38 | 000,000,000 | —D | C] – C:\Documents and Settings\Rogelio_1986\Local Settings\Application Data\PackageAware
[2011/07/07 21:47:35 | 000,000,000 | —D | C] – C:\Documents and Settings\Rogelio_1986\My Documents\FrostWire
[2011/07/07 21:47:17 | 000,000,000 | —D | C] – C:\Documents and Settings\Rogelio_1986\Application Data\FrostWire
[2011/07/07 21:47:17 | 000,000,000 | —D | C] – C:\Documents and Settings\Rogelio_1986\.frostwire4.20
[2011/07/06 21:41:29 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe AIR
[2011/07/06 21:17:24 | 000,000,000 | —D | C] – C:\Documents and Settings\Rogelio_1986\My Documents\My eBooks
[2011/06/29 23:32:33 | 000,000,000 | -H-D | C] – C:\WINDOWS\ie8
[2011/06/29 00:18:55 | 000,000,000 | —D | C] – C:\Documents and Settings\Rogelio_1986\Application Data\Malwarebytes
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/07/09 12:32:23 | 000,944,600 | —- | M] () – C:\logfile
[2011/07/09 12:25:49 | 000,001,565 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Orbit.lnk
[2011/07/09 12:25:20 | 000,000,248 | —- | M] () – C:\WINDOWS\System\hpsysdrv.dat
[2011/07/09 12:25:19 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/07/09 12:24:56 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/07/09 12:24:55 | 527,814,656 | -HS- | M] () – C:\hiberfil.sys
[2011/07/09 06:47:11 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/07/09 03:32:06 | 000,001,998 | —- | M] () – C:\Documents and Settings\Rogelio_1986\Desktop\HiJackThis.lnk
[2011/07/09 02:19:02 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2011/07/09 01:00:29 | 000,001,324 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/07/08 23:42:38 | 000,442,796 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/07/08 23:42:38 | 000,071,936 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/07/08 23:39:52 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/07/08 23:39:16 | 000,183,424 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/07/08 23:16:24 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/07/08 03:58:54 | 000,013,246 | —- | M] () – C:\Documents and Settings\Rogelio_1986\My Documents\The Many Lives of Bridgette Yorke.odt
[2011/07/06 21:52:41 | 000,001,745 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader X.lnk
[2011/07/06 19:43:24 | 000,107,125 | —- | M] () – C:\Documents and Settings\Rogelio_1986\My Documents\Beijing Brownie Points Outfits.jpg
[2011/06/29 23:50:41 | 000,001,824 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2011/06/29 23:37:46 | 000,000,826 | —- | M] () – C:\Documents and Settings\Rogelio_1986\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/06/26 00:45:56 | 000,256,000 | —- | M] () – C:\WINDOWS\PEV.exe
[2011/06/12 08:27:48 | 000,120,467 | —- | M] () – C:\Documents and Settings\Rogelio_1986\My Documents\jb111.jpg
[2011/06/12 08:26:18 | 000,033,518 | —- | M] () – C:\Documents and Settings\Rogelio_1986\My Documents\ad.jpg
[2011/06/12 08:25:55 | 000,036,619 | —- | M] () – C:\Documents and Settings\Rogelio_1986\My Documents\shurugby_4.jpg
[2011/06/12 08:25:50 | 000,047,521 | —- | M] () – C:\Documents and Settings\Rogelio_1986\My Documents\shurugby18.jpg
[2011/06/12 08:25:36 | 000,054,089 | —- | M] () – C:\Documents and Settings\Rogelio_1986\My Documents\10.jpg
[2011/06/12 08:25:10 | 000,144,064 | —- | M] () – C:\Documents and Settings\Rogelio_1986\My Documents\gm.jpg
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/07/09 03:32:06 | 000,001,998 | —- | C] () – C:\Documents and Settings\Rogelio_1986\Desktop\HiJackThis.lnk
[2011/07/09 02:00:26 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2011/07/09 02:00:26 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2011/07/09 02:00:26 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2011/07/09 02:00:26 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2011/07/09 02:00:26 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2011/07/09 01:37:39 | 527,814,656 | -HS- | C] () – C:\hiberfil.sys
[2011/07/06 21:52:40 | 000,001,804 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader X.lnk
[2011/07/06 21:52:40 | 000,001,745 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader X.lnk
[2011/07/06 19:44:08 | 000,107,125 | —- | C] () – C:\Documents and Settings\Rogelio_1986\My Documents\Beijing Brownie Points Outfits.jpg
[2011/06/17 01:25:49 | 000,013,246 | —- | C] () – C:\Documents and Settings\Rogelio_1986\My Documents\The Many Lives of Bridgette Yorke.odt
[2011/06/12 08:27:50 | 000,120,467 | —- | C] () – C:\Documents and Settings\Rogelio_1986\My Documents\jb111.jpg
[2011/06/12 08:26:20 | 000,033,518 | —- | C] () – C:\Documents and Settings\Rogelio_1986\My Documents\ad.jpg
[2011/06/12 08:25:56 | 000,036,619 | —- | C] () – C:\Documents and Settings\Rogelio_1986\My Documents\shurugby_4.jpg
[2011/06/12 08:25:52 | 000,047,521 | —- | C] () – C:\Documents and Settings\Rogelio_1986\My Documents\shurugby18.jpg
[2011/06/12 08:25:40 | 000,054,089 | —- | C] () – C:\Documents and Settings\Rogelio_1986\My Documents\10.jpg
[2011/06/12 08:25:24 | 000,144,064 | —- | C] () – C:\Documents and Settings\Rogelio_1986\My Documents\gm.jpg
[2010/11/08 17:25:21 | 000,180,168 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/11/04 16:26:14 | 000,230,752 | —- | C] () – C:\WINDOWS\patchw32.dll
[2010/11/04 16:26:14 | 000,118,176 | —- | C] () – C:\WINDOWS\patchw.dll
[2010/04/23 16:50:19 | 000,105,984 | —- | C] () – C:\Documents and Settings\Rogelio_1986\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/04/23 16:13:50 | 000,000,128 | —- | C] () – C:\Documents and Settings\Rogelio_1986\Local Settings\Application Data\fusioncache.dat
[2010/02/12 20:46:39 | 000,004,978 | —- | C] () – C:\Documents and Settings\All Users\Application Data\kbkwknay.ayh
[2010/01/17 16:27:06 | 000,001,324 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2009/09/12 02:04:44 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2009/09/06 00:09:41 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2009/07/16 16:42:44 | 000,010,051 | —- | C] () – C:\WINDOWS\hpdj3840.ini
[2009/07/16 00:16:42 | 000,000,025 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2009/07/06 03:20:25 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2009/07/06 03:20:25 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2009/07/06 03:20:25 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2009/07/06 03:20:25 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2009/07/06 03:20:25 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2009/07/06 03:20:25 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2004/11/10 18:33:09 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/11/10 18:33:09 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/11/10 18:33:05 | 000,004,490 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/11/10 18:33:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2004/11/10 18:32:54 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2004/11/10 18:32:26 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/11/10 18:32:25 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/11/10 18:31:49 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/11/10 18:31:17 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/10/22 15:35:32 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2004/10/21 20:25:36 | 000,118,784 | R— | C] () – C:\WINDOWS\bwUnin-6.3.2.62.exe
[2004/10/21 20:21:50 | 000,014,529 | —- | C] () – C:\WINDOWS\System32\CHODDI.SYS
[2004/10/21 20:21:42 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\hpreg.dll
[2004/10/21 19:55:29 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2004/10/21 19:26:39 | 000,094,364 | —- | C] () – C:\WINDOWS\HPHins03.dat
[2004/10/21 19:26:39 | 000,002,655 | —- | C] () – C:\WINDOWS\hphmdl03.dat
[2004/10/21 19:19:52 | 000,104,140 | —- | C] () – C:\WINDOWS\hpoins04.dat
[2004/10/21 19:19:52 | 000,016,939 | —- | C] () – C:\WINDOWS\hpomdl04.dat
[2004/10/21 19:12:22 | 000,089,019 | —- | C] () – C:\WINDOWS\hpdins03.dat
[2004/10/21 19:05:47 | 000,086,562 | —- | C] () – C:\WINDOWS\hpiins01.dat
[2004/10/21 19:05:47 | 000,000,000 | —- | C] () – C:\WINDOWS\hpimdl01.dat
[2004/10/21 19:00:46 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2004/10/21 18:51:33 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\RTCOMDLL.dll
[2004/10/21 18:51:33 | 000,156,160 | —- | C] () – C:\WINDOWS\System32\RTLCPAPI.dll
[2004/10/21 18:45:57 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\sis760.bin
[2004/10/21 18:45:57 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\sis741.bin
[2004/10/21 18:45:57 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\sis660.bin
[2004/10/21 18:39:34 | 000,000,552 | —- | C] () – C:\WINDOWS\System32\d3d8caps.dat
[2004/10/21 18:17:08 | 000,299,073 | —- | C] () – C:\WINDOWS\System32\PythonCOM22.dll
[2004/10/21 18:17:08 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\PyWinTypes22.dll
[2004/10/21 18:15:49 | 000,016,896 | —- | C] () – C:\WINDOWS\System32\bcbmm.dll
[2004/10/21 17:55:39 | 000,000,802 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/10/21 17:53:52 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2004/10/21 17:49:07 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2004/10/21 17:36:39 | 000,000,549 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2004/10/21 17:35:59 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/10/21 17:35:56 | 000,442,796 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/10/21 17:35:56 | 000,071,936 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/10/21 10:43:28 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2004/10/21 10:42:31 | 000,183,424 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/20 04:14:46 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\PcdrKernelModeServices.dll
[2004/08/20 04:14:46 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\ProgressTrace.dll
[2004/06/07 19:32:52 | 000,009,505 | —- | C] () – C:\WINDOWS\System32\hphmon06.dat
[2004/03/03 01:50:56 | 000,004,460 | —- | C] () – C:\WINDOWS\hpfmdl_s04_main.dat
[2004/02/11 12:39:07 | 000,000,316 | —- | C] () – C:\WINDOWS\hpfins_s04_main.dat
[2003/04/11 00:04:00 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\JAWTAccessBridge.dll

========== Alternate Data Streams ==========

@Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2

< End of report >
Hi Bookworm1986,

Let's clear a few thing out and see if it will help with Google Chrome.

Please go to start > control panel > add/remove programs and uninstall


Java 2 Runtime Environment, SE v1.4.2_03


Do not uninstall Java™ 6 Update 14

Reboot your computer.

Click start > run > Control panel.
  • Locate the Java icon (it looks like a coffee cup)
  • double click it to open it
  • click the Update tab
  • Click update now


Next, Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:Files
C:\Documents and Settings\Rogelio_1986\Local Settings\Application Data\Ilivid Player

:Commands
[emptytemp]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
  • Reboot your computer
Please post the OTL fix log .


Next

You have this program installed, Malwarebytes' Anti-Malware (MBAM). Please update it and run a scan.

Open MBAM

  • Click the Update tab
  • Click Check for Updates
  • If an update is found, it will download and install the latest version.
  • The program will close to update and reopen.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

Please post back with
  • OTL fix log
  • MBAM log
How is Google Chrome now? Any other problems?

Thanks
Malwarebytes' Anti-Malware 1.44 Database version: 3510 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 7/9/2011 7:09:03 PM mbam-log-2011-07-09 (19-09-03).txt Scan type: Quick Scan Objects scanned: 136701 Time elapsed: 7 minute(s), 0 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) All processes killed ========== SERVICES/DRIVERS ========== ========== FILES ========== C:\Documents and Settings\Rogelio_1986\Local Settings\Application Data\Ilivid Player folder moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Alma_1950 ->Temp folder emptied: 384760 bytes ->Temporary Internet Files folder emptied: 1138183503 bytes ->Java cache emptied: 3635429 bytes ->FireFox cache emptied: 3394153 bytes ->Google Chrome cache emptied: 11268209 bytes ->Flash cache emptied: 24792 bytes User: Default User ->Temp folder emptied: 77979 bytes ->Temporary Internet Files folder emptied: 32902 bytes ->Flash cache emptied: 56509 bytes User: HP_Owner ->Temp folder emptied: 648047771 bytes ->Temporary Internet Files folder emptied: 106143867 bytes ->Java cache emptied: 54010931 bytes ->FireFox cache emptied: 98004127 bytes ->Google Chrome cache emptied: 6304961 bytes ->Flash cache emptied: 233748 bytes User: LocalService ->Temp folder emptied: 65748 bytes ->Temporary Internet Files folder emptied: 16786 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes User: Rogelio_1986 ->Temp folder emptied: 11147590 bytes ->Temporary Internet Files folder emptied: 3508475 bytes ->Java cache emptied: 33997568 bytes ->FireFox cache emptied: 103503003 bytes ->Google Chrome cache emptied: 420641049 bytes ->Flash cache emptied: 245349 bytes User: Roger ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 294871 bytes ->Java cache emptied: 672530 bytes ->Google Chrome cache emptied: 351346184 bytes ->Flash cache emptied: 34096 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 19569 bytes %systemroot%\System32 .tmp files removed: 2577 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 16384 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes RecycleBin emptied: 247918 bytes Total Files Cleaned = 2,857.00 mb OTL by OldTimer - Version 3.2.26.1 log created on 07092011_184112 Files\Folders moved on Reboot… Registry entries deleted on Reboot… Here are the logs, but Google still the same. my computer works great and so do foxfire and internet explorer.
whenever I put a search in the engine it takes me to the searchup engine and not google chrome, but it has google as it's homepage like the other browsers, but the search is still searchup.
quick question i tried to update and have been having trouble downloading it, i keep getting the message Error 1721. There is a problem with this Windows Installer package. A program required for this install to complete could not be run. Contact your support or package vendor. what should i do?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI