This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Slow PC refuses to open some AV sites

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I'm helping the daughter of friend. She has a Compaq Persario C300 with Windows XP Home edition sp2, 1.6Ghz processor and 2Gb RAM. She can't find the OS CD/DVD (probably never created it as required by HP for new PCs).

She did have Norton Internet Security but her subscription had never been renewed and someone else removed it using the Norton Removal Tool. She wants to put Kaspersky Internet Security on the notebook.

For over a year it has been getting slower and slower to the point where she feels she can longer put up with it and has asked if I can do something with it.

If I try (in Internet Explorer) to go to some AV sites (such as Kaspersky) IE shuts down without any message but others (such as Norton and Trend Micro) load OK.

If I click on the Strat button and then click on the Run item, nothing happens; however, I can use the Windows key and then tap the R-key to bring up the run dialog. Also there is what looks like a tool tip box across the bottom of the screen reading, "Opens a program, folder, document, or Web site." I can't figure out a way to remove this always on top box. And I cannot click task icons on the task bar to switch between tasks; I have to use Alt+Tab to cycle to the task I want.

From topic 106388, I downloaded the three tools and ran the 1st and 3rd. Hijackthis would only briefly display the licence agreement (I think) and then abruptly shutdown. I tried renaming the file "mike.exe" but had the same result.

Here is the content of OTL.txt:
OTL logfile created on: 15/07/2011 8:29:33 AM - Run 1
OTL by OldTimer - Version 3.2.26.1 Folder = C:\Documents and Settings\Michelle Boag\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

1.99 Gb Total Physical Memory | 1.57 Gb Available Physical Memory | 79.04% Memory free
2.20 Gb Paging File | 1.94 Gb Available in Paging File | 88.11% Paging File free
Paging file location(s): C:\pagefile.sys 372 744 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 48.25 Gb Total Space | 9.19 Gb Free Space | 19.05% Space Free | Partition Type: NTFS
Drive D: | 7.62 Gb Total Space | 1.06 Gb Free Space | 13.90% Space Free | Partition Type: FAT32

Computer Name: PC258271888326 | User Name: Michelle Boag | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Michelle Boag\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Java\jre6\bin\jucheck.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Hotbar\bin\11.0.78.0\HotbarSA.exe (Pinball Corporation.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\HPQ\Shared\HpqToaster.exe ()
PRC - C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
PRC - C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe (Hewlett-Packard Development Company, L.P.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Michelle Boag\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (AppMgmt) – File not found
SRV - (getPlus® Helper) getPlus® – C:\Program Files\NOS\bin\getPlus_HelperSvc.exe (NOS Microsystems Ltd.)
SRV - (AddFiltr) – C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe (Hewlett-Packard Development Company, L.P.)
SRV - (CCALib8) – C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)


========== Driver Services (SafeList) ==========

DRV - (hwdatacard) – C:\WINDOWS\system32\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (Netaapl) – C:\WINDOWS\system32\drivers\netaapl.sys (Apple Inc.)
DRV - (HdAudAddService) – C:\WINDOWS\system32\drivers\CHDAud.sys (Conexant Systems Inc.)
DRV - (RTL8023xp) – C:\WINDOWS\system32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation )
DRV - (BCM43XX) – C:\WINDOWS\system32\drivers\BCMWL5.SYS (Broadcom Corporation)
DRV - (sscdmdm) – C:\WINDOWS\system32\drivers\sscdmdm.sys (MCCI)
DRV - (sscdmdfl) – C:\WINDOWS\system32\drivers\sscdmdfl.sys (MCCI)
DRV - (sscdbus) SAMSUNG USB Composite Device driver (WDM) – C:\WINDOWS\system32\drivers\sscdbus.sys (MCCI)
DRV - (sdcplh) – C:\WINDOWS\system32\drivers\sdcplh.sys (Macrovision Europe Ltd)
DRV - (eabusb) – C:\WINDOWS\system32\drivers\EabUsb.sys (Hewlett-Packard Development Company, L.P.)
DRV - (HBtnKey) – C:\WINDOWS\system32\drivers\CPQBttn.sys (Hewlett-Packard Development Company, L.P.)
DRV - (eabfiltr) – C:\WINDOWS\system32\drivers\eabfiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (HSFHWAZL) – C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (rtl8139) Realtek RTL8139(A/B/C) – C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com.au/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=8: C:\Program Files\Google\Update\1.2.183.39\npGoogleOneClick8.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Hotbar\bin\11.0.78.0\firefox\extensions [2010/02/03 19:32:10 | 000,000,000 | —D | M]


O1 HOSTS File: ([2004/08/05 07:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {1D216076-93C9-477F-9BC7-9C39AD31640B} - No CLSID value found.
O2 - BHO: (ShoppingReport2) - {258C9770-1713-4021-8D7E-1F184A2BD754} - C:\Program Files\ShoppingReport2\Bin\2.7.27\ShoppingReport.dll (SmartShopper Networks)
O2 - BHO: (ALO) - {506CD401-5203-4B27-BB5A-03C97758FD02} - C:\WINDOWS\system32\lastmon.dll ()
O2 - BHO: (Hotbar) - {90B8B761-DF2B-48AC-BBE0-BCC03A819B3B} - C:\Program Files\Hotbar\bin\11.0.78.0\HostIE.dll (Pinball Corporation.)
O2 - BHO: (no name) - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - No CLSID value found.
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll (Google Inc.)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (Hotbar) - {90B8B761-DF2B-48AC-BBE0-BCC03A819B3B} - C:\Program Files\Hotbar\bin\11.0.78.0\HostIE.dll (Pinball Corporation.)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKCU\..\Toolbar\WebBrowser: (Hotbar) - {90B8B761-DF2B-48AC-BBE0-BCC03A819B3B} - C:\Program Files\Hotbar\bin\11.0.78.0\HostIE.dll (Pinball Corporation.)
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O4 - HKLM..\Run: [Cpqset] C:\Program Files\Hewlett-Packard\Default Settings\Cpqset.exe ()
O4 - HKLM..\Run: [High Definition Audio Property Page Shortcut] C:\WINDOWS\System32\CHDAudPropShortcut.exe (Windows ® Server 2003 DDK provider)
O4 - HKLM..\Run: [HotbarSA] C:\Program Files\Hotbar\bin\11.0.78.0\HotbarSA.exe (Pinball Corporation.)
O4 - HKLM..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\imekrmig.exe (Microsoft Corporation)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [RecGuard] C:\WINDOWS\SMINST\Recguard.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\StartUp\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\StartUp\HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Development Company, L.P.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\StartUp\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 91 00 00 00 [binary data]
O9 - Extra Button: ShopperReports - Compare product prices - {DB38E21A-0133-419d-92AD-ECDFD5244D6D} - C:\Program Files\ShoppingReport2\Bin\2.7.27\ShoppingReport.dll (SmartShopper Networks)
O9 - Extra Button: ShopperReports - Compare travel rates - {EB620C54-E229-4942-87CE-E717109FC8C6} - C:\Program Files\ShoppingReport2\Bin\2.7.27\ShoppingReport.dll (SmartShopper Networks)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/Facebo…toUploader5.cab (Facebook Photo Uploader 5)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} http://wwwimages.adobe.com/www.adobe.com/p…obat/nos/gp.cab (get_atlcom Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\abdffcaaf: DllName - C:\WINDOWS\system32\abdffcaaf.dll - C:\WINDOWS\system32\abdffcaaf.dll ()
O20 - Winlogon\Notify\eccafcfaebc: DllName - C:\WINDOWS\system32\eccafcfaebc.dll - C:\WINDOWS\system32\eccafcfaebc.dll ()
O24 - Desktop WallPaper: C:\Documents and Settings\Michelle Boag\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Michelle Boag\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2001/07/27 07:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O32 - AutoRun File - [2004/04/29 23:01:14 | 000,000,053 | -HS- | M] () - D:\Autorun.inf – [ FAT32 ]
O33 - MountPoints2\{c354623e-dbbb-11dd-917f-0014a5dfb7f6}\Shell - "" = AutoRun
O33 - MountPoints2\{c354623e-dbbb-11dd-917f-0014a5dfb7f6}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{c354623e-dbbb-11dd-917f-0014a5dfb7f6}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\m.exe /s
O33 - MountPoints2\{d387e7b4-9443-11de-91b3-0014a5dfb7f6}\Shell\AutoRun\command - "" = F:\StartPortableApps.exe
O33 - MountPoints2\{d75c87a2-be69-11dc-913d-0014a5dfb7f6}\Shell - "" = AutoRun
O33 - MountPoints2\{d75c87a2-be69-11dc-913d-0014a5dfb7f6}\Shell\1\Command - "" = .\RECYCLER\RECYCLER\autorun.exe -autorun
O33 - MountPoints2\{d75c87a2-be69-11dc-913d-0014a5dfb7f6}\Shell\2\Command - "" = .\RECYCLER\RECYCLER\autorun.exe -autorun
O33 - MountPoints2\{d75c87a2-be69-11dc-913d-0014a5dfb7f6}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{d75c87a2-be69-11dc-913d-0014a5dfb7f6}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL .\RECYCLER\RECYCLER\autorun.exe -autorun
O33 - MountPoints2\{ff369203-dfc8-11db-90e1-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{ff369203-dfc8-11db-90e1-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{ff369203-dfc8-11db-90e1-806d6172696f}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivXNetworks, Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.VP60 - C:\WINDOWS\system32\vp6vfw.dll (On2.com)
Drivers32: vidc.VP61 - C:\WINDOWS\system32\vp6vfw.dll (On2.com)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/07/15 08:14:19 | 000,579,584 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Michelle Boag\Desktop\OTL.exe
[2011/07/15 08:14:19 | 000,000,000 | —D | C] – C:\Documents and Settings\Michelle Boag\Desktop\whatthetech
[2011/06/28 11:24:57 | 000,000,000 | —D | C] – C:\Documents and Settings\Michelle Boag\My Documents\backup reg clean
[2011/06/28 11:23:00 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2011/06/28 11:22:03 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Michelle Boag\Recent
[2011/06/28 11:18:45 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2011/06/28 11:18:04 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2011/06/27 22:20:05 | 000,000,000 | —D | C] – C:\WINDOWS\pss
[2011/06/27 22:11:03 | 000,000,000 | —D | C] – C:\TDSSKiller_Quarantine
[2011/06/27 20:34:03 | 000,000,000 | —D | C] – C:\Documents and Settings\Michelle Boag\Desktop\Boag notebook
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/07/15 08:23:00 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/07/15 08:20:16 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/07/15 08:13:01 | 000,000,313 | —- | M] () – C:\hpqp.ini
[2011/07/15 08:12:50 | 000,000,040 | —- | M] () – C:\XP_TV.ini
[2011/07/15 08:12:41 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/07/15 08:12:40 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/07/15 08:12:37 | 2137,116,672 | -HS- | M] () – C:\hiberfil.sys
[2011/07/14 21:56:10 | 000,579,584 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Michelle Boag\Desktop\OTL.exe
[2011/06/28 12:01:00 | 000,000,254 | —- | M] () – C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2011/06/28 11:18:46 | 000,000,682 | —- | M] () – C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/06/28 11:18:46 | 000,000,682 | —- | C] () – C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2011/06/28 11:18:00 | 000,000,886 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/06/28 11:18:00 | 000,000,882 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/09/14 18:28:57 | 000,000,486 | —- | C] () – C:\WINDOWS\eReg.dat
[2010/08/31 20:27:55 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2010/02/10 17:42:28 | 000,207,888 | —- | C] () – C:\WINDOWS\System32\883830944bdf159792b0dde52070a860.exe
[2010/02/10 17:30:52 | 000,193,040 | —- | C] () – C:\WINDOWS\System32\lastmon.dll
[2009/06/16 16:43:29 | 000,000,118 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2009/05/26 23:20:55 | 000,019,520 | —- | C] () – C:\WINDOWS\System32\uacinit.dll
[2009/05/26 23:20:28 | 000,000,194 | —- | C] () – C:\Documents and Settings\Michelle Boag\Application Data\asd.bat
[2008/04/09 16:07:36 | 000,002,584 | —- | C] () – C:\WINDOWS\System32\NSM 7 Student CD.ini
[2007/12/06 14:26:59 | 000,000,036 | —- | C] () – C:\WINDOWS\webica.ini
[2007/07/05 11:17:13 | 000,000,000 | —- | C] () – C:\Documents and Settings\All Users\Application Data\LauncherAccess.dt
[2007/04/16 15:19:28 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2007/04/06 13:16:45 | 000,000,043 | —- | C] () – C:\WINDOWS\popcinfo.dat
[2007/04/01 09:15:41 | 000,000,599 | —- | C] () – C:\WINDOWS\PowerReg.dat
[2007/04/01 09:15:24 | 000,010,240 | —- | C] () – C:\WINDOWS\System32\vidx16.dll
[2007/04/01 08:04:42 | 000,014,848 | —- | C] () – C:\Documents and Settings\Michelle Boag\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/04/01 07:05:35 | 000,000,136 | —- | C] () – C:\Documents and Settings\Michelle Boag\Local Settings\Application Data\fusioncache.dat
[2006/08/18 22:16:44 | 000,028,836 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2006/05/12 14:14:04 | 000,280,079 | —- | C] () – C:\WINDOWS\System32\eccafcfaebc.dll
[2006/05/11 00:23:48 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2006/05/11 00:23:38 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/05/10 23:48:18 | 000,087,268 | —- | C] () – C:\WINDOWS\hpqins69.dat
[2006/05/10 23:46:02 | 000,000,056 | —- | C] () – C:\WINDOWS\WININIT.INI
[2006/05/10 23:42:38 | 000,000,780 | —- | C] () – C:\WINDOWS\orun32.ini
[2006/05/10 23:33:06 | 000,383,822 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2006/05/10 23:33:06 | 000,054,010 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2006/05/10 23:29:10 | 000,386,408 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2006/05/10 23:25:12 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2006/05/10 23:22:48 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2006/05/08 17:07:50 | 000,312,847 | —- | C] () – C:\WINDOWS\System32\abdffcaaf.dll
[2005/12/03 04:11:40 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2004/09/17 06:24:26 | 003,375,104 | —- | C] () – C:\WINDOWS\System32\qt-mt331.dll
[2004/08/05 07:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/05 07:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/05 07:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/05 07:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/05 07:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/05 07:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/05 07:00:00 | 000,001,788 | —- | C] () – C:\WINDOWS\System32\Dcache.bin
[2004/08/05 07:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2002/05/29 07:55:42 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2002/05/29 07:54:40 | 000,004,605 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[1999/01/23 04:46:58 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL

========== LOP Check ==========

[2009/04/14 22:58:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\14623093
[2010/02/03 19:32:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\2ACA5CC3-0F83-453D-A079-1076FE1A8B65
[2009/04/21 21:40:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\614558828
[2011/07/15 08:14:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HotbarSA
[2007/04/02 11:37:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sandlot Games
[2010/05/25 20:42:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/09/19 13:30:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/08/29 12:33:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2007/07/05 12:20:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Michelle Boag\Application Data\ConvertTemp
[2007/11/01 15:36:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Michelle Boag\Application Data\funkitron
[2010/02/07 14:52:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Michelle Boag\Application Data\Hotbar
[2007/12/11 20:32:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Michelle Boag\Application Data\ICAClient
[2007/04/01 12:43:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Michelle Boag\Application Data\Leadertech
[2009/04/23 09:48:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Michelle Boag\Application Data\MSNInstaller
[2010/09/07 16:03:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Michelle Boag\Application Data\My Games
[2007/07/05 11:19:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Michelle Boag\Application Data\SAMSUNG
[2011/05/29 16:57:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Michelle Boag\Application Data\ShoppingReport
[2011/06/28 10:52:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Michelle Boag\Application Data\ShoppingReport2
[2007/07/05 12:20:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Michelle Boag\Application Data\Temporary
[2007/07/05 12:20:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Michelle Boag\Application Data\TransRender
[2011/06/28 12:01:00 | 000,000,254 | —- | M] () – C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2007/04/01 07:04:03 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2011/07/15 08:12:37 | 2137,116,672 | -HS- | M] () – C:\hiberfil.sys
[2011/07/15 08:13:01 | 000,000,313 | —- | M] () – C:\hpqp.ini
[2008/04/09 16:08:22 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2009/09/19 13:24:07 | 000,000,168 | —- | M] () – C:\log.udt
[2008/04/09 16:08:22 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/05 07:00:00 | 000,047,564 | RHS- | M] () – C:\ntdetect.com
[2004/08/05 07:00:00 | 000,250,032 | RHS- | M] () – C:\ntldr
[2011/06/28 11:25:38 | 000,262,144 | —- | M] () – C:\ntuser.dat
[2011/06/28 11:25:38 | 000,001,024 | -H– | M] () – C:\ntuser.dat.LOG
[2011/07/15 08:12:36 | 390,070,272 | -HS- | M] () – C:\pagefile.sys
[2011/06/27 21:36:44 | 000,052,218 | —- | M] () – C:\TDSSKiller.2.4.15.0_27.06.2011_21.35.22_log.txt
[2011/06/27 22:11:11 | 000,052,216 | —- | M] () – C:\TDSSKiller.2.4.15.0_27.06.2011_22.09.58_log.txt
[2011/06/27 22:13:44 | 000,049,030 | —- | M] () – C:\TDSSKiller.2.4.15.0_27.06.2011_22.12.46_log.txt
[2011/06/27 22:15:35 | 000,047,038 | —- | M] () – C:\TDSSKiller.2.4.15.0_27.06.2011_22.14.52_log.txt
[2011/06/28 11:14:01 | 000,047,038 | —- | M] () – C:\TDSSKiller.2.4.15.0_28.06.2011_11.13.41_log.txt
[2011/07/15 08:12:50 | 000,000,040 | —- | M] () – C:\XP_TV.ini

< %systemroot%\Fonts\*.com >

< %systemroot%\Fonts\*.dll >
[2005/09/25 01:49:16 | 000,012,288 | —- | M] (Hewlett-Packard Development Company, L.P.) – C:\WINDOWS\Fonts\RandFont.dll

< %systemroot%\Fonts\*.ini >
[2006/05/10 23:24:58 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >
[2009/08/27 12:50:30 | 000,001,610 | -H– | M] () – C:\Documents and Settings\Michelle Boag\Application Data\Microsoft\LastFlashConfig.WFC

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2006/05/10 16:15:06 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2006/05/10 16:15:04 | 000,634,880 | —- | M] () – C:\WINDOWS\System32\config\software.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2006/05/10 23:25:48 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2007/04/01 07:06:55 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Michelle Boag\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2006/05/10 23:30:02 | 000,000,079 | —- | M] () – C:\Documents and Settings\Michelle Boag\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2009/08/29 12:35:02 | 077,976,864 | —- | M] (Apple Inc.) – C:\Documents and Settings\Michelle Boag\Desktop\iTunesSetup.exe
[2011/07/14 21:56:10 | 000,579,584 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Michelle Boag\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-06-28 02:12:00

< End of report >


And here is the content of Extras.txt:
OTL Extras logfile created on: 15/07/2011 8:29:33 AM - Run 1
OTL by OldTimer - Version 3.2.26.1 Folder = C:\Documents and Settings\Michelle Boag\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

1.99 Gb Total Physical Memory | 1.57 Gb Available Physical Memory | 79.04% Memory free
2.20 Gb Paging File | 1.94 Gb Available in Paging File | 88.11% Paging File free
Paging file location(s): C:\pagefile.sys 372 744 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 48.25 Gb Total Space | 9.19 Gb Free Space | 19.05% Space Free | Partition Type: NTFS
Drive D: | 7.62 Gb Total Space | 1.06 Gb Free Space | 13.90% Space Free | Partition Type: FAT32

Computer Name: PC258271888326 | User Name: Michelle Boag | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 1
"FirewallDisableNotify" = 1
"UpdatesDisableNotify" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Firaxis Games\Sid Meier's Civilization 4\Civilization4.exe" = C:\Program Files\Firaxis Games\Sid Meier's Civilization 4\Civilization4.exe:*:Enabled:Sid Meier's Civilization 4 – (Firaxis Games)
"C:\Program Files\Firaxis Games\Sid Meier's Civilization 4\Warlords\Civ4Warlords.exe" = C:\Program Files\Firaxis Games\Sid Meier's Civilization 4\Warlords\Civ4Warlords.exe:*:Enabled:Sid Meier's Civilization 4 Warlords – (Firaxis Games)
"C:\Program Files\Firaxis Games\Sid Meier's Civilization 4\Warlords\Civ4Warlords_PitBoss.exe" = C:\Program Files\Firaxis Games\Sid Meier's Civilization 4\Warlords\Civ4Warlords_PitBoss.exe:*:Enabled:Sid Meier's Civilization 4 Pitboss – (Firaxis Games)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00000409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 SR-1 Premium
"{06680048-3E21-46D6-9A91-D927BA08F41D}" = Microsoft Encarta Standard 2006
"{075473F5-846A-448B-BCB3-104AA1760205}" = Sonic Data Module
"{0DFB3DE8-65B9-44FF-AA0A-3BECC5A2BFD1}" = Adobe Flash Player 10 Plugin
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1CB34CE9-0E6B-493F-BB66-3425E5DF76E5}" = CP_CalendarTemplates1
"{21657574-BD54-48A2-9450-EB03B2C7FC29}" = Sonic MyDVD Plus
"{23012310-3E05-46A5-88A9-C6CBCABCAC79}" = Customer Experience Enhancement
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{23B35809-5E4A-4F14-8332-1CDEDDFAC089}" = CP_Package_Variety2
"{26A24AE4-039D-4CA4-87B4-2F83216016FF}" = Java™ 6 Update 16
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{2A548002-9042-4083-A270-B67473DE1073}" = SkinsHP1
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.10 A1
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{36D620AD-EEBA-4973-BA86-0C9AE6396620}" = OptionalContentQFolder
"{3E4B349F-10B5-4586-9D99-489A90A8B228}" = Sid Meier's Civilization 4 - Warlords
"{3FE0CFAB-584A-4AA5-B8CD-C32284CFA308}" = RandMap
"{4302B2DD-D958-40E3-BAF3-B07FFE1978CE}" = HP Wireless Assistant 2.00 G2
"{4377F918-E6C9-4ECA-A7F5-754B310B7ED8}" = Sid Meier's Civilization 4
"{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP DVD Play 2.3
"{494D17B5-3369-4905-8C4B-80C972C5E0FF}" = CP_Panorama1Config
"{4DA4012B-39AF-48c2-B23B-A4D570D233A6}" = cp_LightScribeConfig
"{522D1D79-9C0A-4361-91F8-2AFF8EC6C2E1}" = CP_Package_Variety1
"{53EE9E42-CECB-4C92-BF76-9CA65DAF8F1C}" = FullDPAppQFolder
"{54F0998F-73C8-4b51-8286-FE903C231BED}" = cp_PosterPrintConfig
"{552E6DA4-A0F9-41AC-8473-E825D60674EA}" = HP User Guides 0037
"{553255F3-78FD-40F1-A6F8-6882140265FE}" = Apple Application Support
"{5ECB3A3C-980B-4D12-9724-25DCB07A1F47}" = iTunes
"{611BD998-34B9-4DDA-00AE-0CB4632E86FA}" = SimCity 4
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Sonic Express Labeler
"{6815FCDD-401D-481E-BA88-31B4754C2B46}" = Macromedia Flash Player 8
"{6DE13770-01B7-4366-8DA6-48237793F445}" = VoiceOver Kit
"{766633B3-1AFA-44B6-A3FC-1DE991CD9C52}" = CP_Package_Basic1
"{79F8E1D4-36C1-439C-95FA-F695050B5B07}" = Sonic_PrimoSDK
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX
"{80AE27BA-B0ED-4288-A8B9-D8194BCF4115}" = cp_UpdateProjectsConfig
"{838A1BC9-95CA-4880-9BE3-2A7D23600A2B}" = Macromedia Shockwave Player
"{869C3062-4745-4949-B6C9-98AF24D89030}" = PhotoGallery
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{8A253629-0511-4854-8B4E-46E57E66005C}" = Bonjour
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PROR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PROR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_PROR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_PROR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0014-0000-0000-0000000FF1CE}" = Microsoft Office Professional 2007
"{91120000-0014-0000-0000-0000000FF1CE}_PROR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0014-0000-0000-0000000FF1CE}_PROR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{919F3D91-8374-410F-932B-A126F2C85426}" = e-tax 2009
"{9D4ABB0C-F60B-44A6-956C-A4A63D5495C9}" = CueTour
"{9DE1BE03-AFE2-4CDB-BFEB-D06D736CD01A}" = Apple Mobile Device Support
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A93C4E94-1005-489D-BEAA-B873C1AA6CFC}" = HP Help and Support
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Sonic Audio Module
"{AC76BA86-7AD7-1033-7B44-A70500000002}" = Adobe Reader 7.0.5
"{B11E71BA-498C-42D4-9F1A-9D7A89D9DA61}" = CP_AtenaShokunin1Config
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Sonic Copy Module
"{B57F2FF0-5A25-4332-B503-4592B370C02F}" = CP_Package_Variety3
"{BB85ED9C-AFC9-43BD-B8DC-258C3C7DF72E}" = HP Software Update
"{BBD3BF67-5B89-4CBB-BA58-5818ED5F3290}" = cp_OnlineProjectsConfig
"{BC96BBA7-C634-460E-AD18-A0A994213F80}" = HP User Guides–System Recovery
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C4A4722E-79F9-417C-BD72-8D359A090C97}" = Samsung PC Studio
"{C8931F37-DF21-4FD1-8416-10A6FA4259C3}" = Samsung PC Studio
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CF40ACC5-E1BB-4aff-AC72-04C2F616BCA7}" = getPlus® for Adobe
"{CFBCE791-2D53-4FCE-B3FB-D6E01F4112E8}" = Sid Meier's Civilization 4
"{DB518BA6-CB74-4EB6-9ABD-880B6D6E1F38}" = HpSdpAppCoreApp
"{E56D39F8-2A9F-44B4-B068-A72E45A073E6}" = Safari
"{EBA29752-DDD2-4B62-B2E3-9841F92A3E3A}" = Samsung PC Studio 3 USB Driver Installer
"{FC8D25A7-FF1B-41BB-BB3B-9A06C0A60AE0}" = InstantShareDevices
"Adobe Acrobat 4.0" = Adobe Acrobat 4.0
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player
"CAL" = Canon Camera Access Library
"CameraWindowDVC5" = Canon Camera Window DC_DV 5 for ZoomBrowser EX
"CameraWindowDVC6" = Canon Camera Window DC_DV 6 for ZoomBrowser EX
"CameraWindowMC" = Canon Camera Window MC 6 for ZoomBrowser EX
"Canon G.726 WMP-Decoder" = Canon G.726 WMP-Decoder
"CCleaner" = CCleaner
"CNXT_HDAUDIO" = Conexant HD Audio
"CNXT_MODEM_HDAUDIO_CPL30A5m" = HDAUDIO Soft Data Fax Modem with SmartCP
"CSCLIB" = Canon Camera Support Core Library
"EOS Utility" = Canon Utilities EOS Utility
"HotbarSA" = Hotbar
"HP Photo & Imaging" = HP Photosmart Premier Software 6.0
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie8" = Windows Internet Explorer 8
"InstallShield_{23012310-3E05-46A5-88A9-C6CBCABCAC79}" = Customer Experience Enhancement
"MetaFrame Presentation Server Web Client for Win32" = MetaFrame Presentation Server Web Client for Win32
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"MovieEditTask" = Canon MovieEdit Task for ZoomBrowser EX
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSNINST" = ninemsn Internet Software
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"pattern" = pattern Screen Saver
"PhotoStitch" = Canon Utilities PhotoStitch
"Power MP3 WMA Converter 1.14" = Power MP3 WMA Converter 1.14
"PROR" = Microsoft Office Professional 2007
"RAW Image Task" = Canon RAW Image Task for ZoomBrowser EX
"RemoteCaptureTask" = Canon RemoteCapture Task for ZoomBrowser EX
"SAMSUNG CDMA Modem" = SAMSUNG CDMA Modem Driver Set
"Samsung Mobile phone USB driver" = Samsung Mobile phone USB driver Software
"SAMSUNG Mobile USB Modem" = SAMSUNG Mobile USB Modem Software
"SAMSUNG Mobile USB Modem 1.0" = SAMSUNG Mobile USB Modem 1.0 Software
"ShoppingReport" = ShopperReports
"ShoppingReport2" = ShopperReports
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"SysInfo" = Creative System Information
"Virgin Mobile" = Virgin Mobile
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"WGA" = Windows Genuine Advantage Validation Tool
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Xfire" = Xfire (remove only)

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 29/05/2011 2:49:19 AM | Computer Name = PC258271888326 | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 29/05/2011 2:49:19 AM | Computer Name = PC258271888326 | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 1623534050

Error - 29/05/2011 2:49:19 AM | Computer Name = PC258271888326 | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 1623534050

Error - 29/05/2011 2:49:21 AM | Computer Name = PC258271888326 | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 29/05/2011 2:49:21 AM | Computer Name = PC258271888326 | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 1623536581

Error - 29/05/2011 2:49:21 AM | Computer Name = PC258271888326 | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 1623536581

Error - 29/05/2011 2:57:16 AM | Computer Name = PC258271888326 | Source = WinMgmt | ID = 4
Description = Failed to load MOF C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V1.1.4322\ASPNET.MOF
while recovering repository file.

Error - 14/06/2011 8:14:27 AM | Computer Name = PC258271888326 | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module shoppingreport.dll, version 2.7.27.0, fault address 0x000771d6.

Error - 14/06/2011 8:32:19 AM | Computer Name = PC258271888326 | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module shoppingreport.dll, version 2.7.27.0, fault address 0x000771d6.

Error - 14/06/2011 8:45:20 AM | Computer Name = PC258271888326 | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module shoppingreport.dll, version 2.7.27.0, fault address 0x000771d6.

[ OSession Events ]
Error - 26/07/2009 4:20:34 AM | Computer Name = PC258271888326 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6504.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 11
seconds with 0 seconds of active time. This session ended with a crash.

Error - 26/07/2009 4:20:43 AM | Computer Name = PC258271888326 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6504.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 3
seconds with 0 seconds of active time. This session ended with a crash.

Error - 26/07/2009 4:29:56 AM | Computer Name = PC258271888326 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6504.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 549
seconds with 0 seconds of active time. This session ended with a crash.

Error - 26/07/2009 4:30:05 AM | Computer Name = PC258271888326 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6504.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 2
seconds with 0 seconds of active time. This session ended with a crash.

Error - 26/07/2009 4:30:12 AM | Computer Name = PC258271888326 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6504.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 3
seconds with 0 seconds of active time. This session ended with a crash.

Error - 26/07/2009 5:14:49 AM | Computer Name = PC258271888326 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6504.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 2673
seconds with 0 seconds of active time. This session ended with a crash.

Error - 26/07/2009 5:20:33 AM | Computer Name = PC258271888326 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6504.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 340
seconds with 0 seconds of active time. This session ended with a crash.

Error - 26/07/2009 5:34:05 AM | Computer Name = PC258271888326 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6504.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 794
seconds with 0 seconds of active time. This session ended with a crash.

Error - 28/07/2009 8:10:19 AM | Computer Name = PC258271888326 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6504.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 182169
seconds with 0 seconds of active time. This session ended with a crash.

Error - 28/07/2009 8:12:25 AM | Computer Name = PC258271888326 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6504.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 121
seconds with 0 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 27/06/2011 7:16:16 AM | Computer Name = PC258271888326 | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 27/06/2011 7:16:17 AM | Computer Name = PC258271888326 | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 27/06/2011 7:16:17 AM | Computer Name = PC258271888326 | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 27/06/2011 7:16:17 AM | Computer Name = PC258271888326 | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 27/06/2011 7:16:17 AM | Computer Name = PC258271888326 | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 27/06/2011 7:16:17 AM | Computer Name = PC258271888326 | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 27/06/2011 7:16:17 AM | Computer Name = PC258271888326 | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 27/06/2011 8:12:13 AM | Computer Name = PC258271888326 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
AliIde PCIIde Pcmcia ViaIde

Error - 27/06/2011 8:14:36 AM | Computer Name = PC258271888326 | Source = sr | ID = 1
Description = The System Restore filter encountered the unexpected error '0xC0000001'
while processing the file '' on the volume 'HarddiskVolume1'. It has stopped monitoring
the volume.

Error - 27/06/2011 8:14:42 AM | Computer Name = PC258271888326 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
AliIde PCIIde Pcmcia ViaIde


< End of report >


Here is the content of DDS.txt:
(note typing this the letters display one every second with the mouse pointer switching between the egg timer and arrow between each letter)
and Attach.txt is in the attached zip file.
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by [removed] at 12:06:34.53 on Fri 15/07/2011
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2038.1561 [GMT 10:00]
.
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\Hotbar\bin\11.0.78.0\HotbarSA.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\hpq\Shared\HPQTOA~1.EXE
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Documents and Settings\Michelle Boag\Desktop\dds.scr
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com.au/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_AU&c=64&bd=presario&pf=laptop
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: {1D216076-93C9-477F-9BC7-9C39AD31640B} - No File
BHO: ShoppingReport2: {258c9770-1713-4021-8d7e-1f184a2bd754} - c:\program files\shoppingreport2\bin\2.7.27\ShoppingReport.dll
BHO: ALO: {506cd401-5203-4b27-bb5a-03c97758fd02} - c:\windows\system32\lastmon.dll
BHO: Hotbar: {90b8b761-df2b-48ac-bbe0-bcc03a819b3b} - c:\program files\hotbar\bin\11.0.78.0\HostIE.dll
BHO: {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - No File
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.7.6406.1642\swg.dll
BHO: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
TB: Hotbar: {90b8b761-df2b-48ac-bbe0-bcc03a819b3b} - c:\program files\hotbar\bin\11.0.78.0\HostIE.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File
EB: Hotbar Information Window: {2aa2fbf8-9c76-4e97-a226-25c5f4ab6358} - c:\program files\hotbar\bin\11.0.78.0\HostIE.dll
EB: ShopperReports: {bdea95cf-f0e6-41e0-bd3d-b00f39a4e939} - c:\program files\shoppingreport2\bin\2.7.27\ShoppingReport.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
mRun: [hpWirelessAssistant] c:\program files\hpq\hp wireless assistant\HP Wireless Assistant.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [QPService] "c:\program files\hp\quickplay\QPService.exe"
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
mRun: [Cpqset] c:\program files\hewlett-packard\default settings\cpqset.exe
mRun: [RecGuard] c:\windows\sminst\RecGuard.exe
mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [IMEKRMIG6.1] c:\windows\ime\imkr6_1\IMEKRMIG.EXE
mRun: [MSPY2002] c:\windows\system32\ime\pintlgnt\ImScInst.exe /SYNC
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [HotbarSA] "c:\program files\hotbar\bin\11.0.78.0\HotbarSA.exe"
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpphot~1.lnk - c:\program files\hp\digital imaging\bin\hpqthb08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office\OSA9.EXE
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_2EC7709873947E87.dll/cmsidewiki.html
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office12\REFIEBAR.DLL
IE: {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - {552781AF-37E4-4FEE-920A-CED9E648EADD} - c:\program files\common files\microsoft shared\encarta search bar\ENCSBAR.DLL
IE: {DB38E21A-0133-419d-92AD-ECDFD5244D6D} - {3E2DFD6A-4E20-4d4c-AA8B-E1F9DBEF3C80} - c:\program files\shoppingreport2\bin\2.7.27\ShoppingReport.dll
IE: {EB620C54-E229-4942-87CE-E717109FC8C6} - {714E0876-FCEE-49ce-A429-B9AD8AEFCB56} - c:\program files\shoppingreport2\bin\2.7.27\ShoppingReport.dll
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader5.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} - hxxp://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
Notify: abdffcaaf - c:\windows\system32\abdffcaaf.dll
Notify: eccafcfaebc - c:\windows\system32\eccafcfaebc.dll
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
.
============= SERVICES / DRIVERS ===============
.
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-6-28 136176]
S3 988413b7-ba2d-4b26-8f34-5c052fc0b4fe;988413b7-ba2d-4b26-8f34-5c052fc0b4fe;\??\e:\player\cds300.dll –> e:\player\cds300.dll [?]
S3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\drivers\netaapl.sys [2009-8-29 17408]
.
=============== Created Last 30 ================
.
2011-06-28 01:18:45 ——– d—–w- c:\program files\CCleaner
2011-06-27 12:20:05 ——– d—–w- c:\windows\pss
2011-06-27 12:11:03 ——– d—–w- C:\TDSSKiller_Quarantine
.
==================== Find3M ====================
.
.
=================== ROOTKIT ====================
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600
.
CreateFile("\\.\PHYSICALDRIVE0"): The process cannot access the file because it is being used by another process.
device: opened successfully
user: error reading MBR
.
Disk trace:
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll iaStor.sys
c:\windows\system32\drivers\iaStor.sys Intel Corporation Intel Matrix Storage Manager driver
1 ntkrnlpa!IofCallDriver[0x804EE136] -> \Device\Harddisk0\DR0[0x8A3DFAB8]
3 CLASSPNP[0xF74E805B] -> ntkrnlpa!IofCallDriver[0x804EE136] -> \Device\00000078[0x8A38B900]
5 ACPI[0xF735E620] -> ntkrnlpa!IofCallDriver[0x804EE136] -> \Device\Ide\IAAStorageDevice-0[0x8A3DE030]
kernel: MBR read successfully
_asm { XOR DI, DI; MOV SI, 0x200; MOV SS, DI; MOV SP, 0x7a00; MOV BX, 0x7a0; MOV CX, SI; MOV DS, BX; MOV ES, BX; REP MOVSB ; JMP FAR 0x7a0:0x7a; }
user != kernel MBR !!!
.
============= FINISH: 12:06:54.93 ===============

Attachments:

Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 3 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

•Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
•If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
•Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
•Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post











  • Download aswMBR.exe ( 511KB ) to your desktop.
  • Double click the aswMBR.exe to run it
  • Click the Scan button to start scan
  • On completion of the scan click Save Log, save it to your Desktop and post in your next reply










Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
Thanks, Mowman.

I did as you said; a couple of comments: ComboFix did install the MS Recovery Console; during the ComboFix scan I was prompted to remove some folders, I said yes to the first three but then it asked to remove folder WINDOWS. I said no to this before noticing the folder was located in the user folder. Then after a restart, I was again prompted to remove the folder WINDOWS so this time I said yes. The dialogs said they would be in the recycle bin but that is empty.

I can now switch between tasks by clicking on the task bar icons and also I can now access the items on the right-hand column of the Start menu (My Documents down to Run) (when I originally posted teh topic I could only access the pinned and recent programs on the left-hand side of the Start menu)..

Here is the aswMBR log:

aswMBR version 0.9.7.750 Copyright© 2011 AVAST Software
Run date: 2011-07-16 07:26:35
—————————–
07:26:35.718 OS Version: Windows 5.1.2600 Service Pack 2
07:26:35.718 Number of processors: 1 586 0xE08
07:26:35.718 ComputerName: PC258271888326 UserName: Michelle Boag
07:26:35.906 Initialize success
07:27:01.890 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0
07:27:01.906 Disk 0 Vendor: Size: 0MB BusType: 0
07:27:01.953 Disk 0 MBR read successfully
07:27:01.953 Disk 0 MBR scan
07:27:01.968 Disk 0 unknown MBR code
07:27:01.968 Disk 0 MBR hidden
07:27:02.000 Disk 0 scanning C:\WINDOWS\system32\drivers
07:27:14.328 Service scanning
07:27:15.390 Disk 0 trace - called modules:
07:27:15.437 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll iaStor.sys
07:27:15.453 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a3dfab8]
07:27:15.468 3 CLASSPNP.SYS[f74e805b] -> nt!IofCallDriver -> \Device\00000078[0x8a38b900]
07:27:15.468 5 ACPI.sys[f735e620] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-0[0x8a3de030]
07:27:15.484 Scan finished successfully
07:27:27.078 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Michelle Boag\Desktop\MBR.dat"
07:27:27.093 The log file has been saved successfully to "C:\Documents and Settings\Michelle Boag\Desktop\aswMBR.txt"


And here is the ComboFix.txt:

ComboFix 11-07-15.02 - Michelle Boag 16/07/2011 7:36.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2038.1588 [GMT 10:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\2ACA5CC3-0F83-453D-A079-1076FE1A8B65
c:\documents and settings\All Users\Application Data\HotbarSA
c:\documents and settings\All Users\Application Data\HotbarSA\HotbarSA.dat
c:\documents and settings\All Users\Application Data\HotbarSA\HotbarSA_kyf.dat
c:\documents and settings\All Users\Application Data\HotbarSA\HotbarSAAbout.mht
c:\documents and settings\All Users\Application Data\HotbarSA\HotbarSAau.dat
c:\documents and settings\All Users\Application Data\HotbarSA\HotbarSAEULA.mht
c:\documents and settings\All Users\Start Menu\Programs\Hotbar
c:\documents and settings\All Users\Start Menu\Programs\Hotbar\About Hotbar.lnk
c:\documents and settings\All Users\Start Menu\Programs\Hotbar\Hotbar Customer Support Center.lnk
c:\documents and settings\All Users\Start Menu\Programs\Hotbar\Hotbar Games!.lnk
c:\documents and settings\All Users\Start Menu\Programs\Hotbar\Hotbar Uninstall Instructions.lnk
c:\documents and settings\All Users\Start Menu\Programs\Hotbar\Hotbar Videos!.lnk
c:\documents and settings\All Users\Start Menu\Programs\Hotbar\Reset Cursor.lnk
c:\documents and settings\All Users\Start Menu\Programs\Hotbar\Weather.lnk
c:\documents and settings\Michelle Boag\Application Data\Hotbar
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\1.sdf
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\1056052.sdf
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\1057131.sdf
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\1057643.sdf
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\1074941.sdf
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\1140234.sdf
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\1387202.sdf
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\1404489.sdf
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\1504281.sdf
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\1642774.sdf
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\1642777.sdf
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\1840276.sdf
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\2208948.sdf
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\2321133.sdf
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\254545.sdf
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\3404705.sdf
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\3730729.sdf
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\3730773.sdf
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\38151.sdf
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\3852296.sdf
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\471182.sdf
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\559163.sdf
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\600583.sdf
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\805478.sdf
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\831371.sdf
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\832255.sdf
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\890068.sdf
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\977696.sdf
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\domains.txt
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\1000041060
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\12776
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\13119
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\13608
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\14633
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\1491
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\15040
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\164461
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\168167
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\175594
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\180320
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\18721
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\197078
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\198406
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\20213
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\20304
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\205886
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\218712
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\22913
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\243256
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\251440
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\251549
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\25818
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\26664
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\268125
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\277907
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\278975
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\282887
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\28383
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\28396
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\288733
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\288799
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\29115
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\29509
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\30823
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\31262
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\31551
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\32276
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\355971
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\39972
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\40256
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\41215
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\41347
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\41526
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\41641
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\42915
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\43377
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\439932
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\4442
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\449274
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\4501
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\45833
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\460839
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\476910
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\49821
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\526507
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\532492
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\53481
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\547723
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\564375
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\57137
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\60689
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\61194
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\61207
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\61670
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\61837
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\6292
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\63770
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\6458
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\6465
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\64690
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\65429
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\6558
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\66493
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\67215
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\70773
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\73415
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\73595
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\73775
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\73804
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\738272
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\73876
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\744505
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\744881
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\744926
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\745009
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\745144
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\745201
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\745490
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\748405
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\752900
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\753253
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\753333
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\753590
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\753618
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\753635
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\7652
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\78600
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\78788
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\79674
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\79676
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\81093
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\81830
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\82292
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\82959
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\85587
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\86173
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\92930
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\95825
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\96813
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\ustat\3b41.dat
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\dynamic\ustat\3b42.dat
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\ads.cdf
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\btntrans.idx
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\btntrans1.dat
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\business_promo.htm
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\buttondir.txt
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\components.cdf
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\cursors.res
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\d_icons_buttons_1000.res
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\d_icons_buttons_2000.res
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\d_icons_buttons_3000.res
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\d_icons_buttons_bar.res
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\d_icons_buttons_bbar1.res
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\d_icons_buttons_logos.res
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\d_icons_buttons_other.res
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\d_icons_weather.res
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\default.cdf
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_511745-514279.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_bidz.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_bidz1.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_bidz10.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_bidz11.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_bidz12.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_bidz13.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_bidz14.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_bidz15.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_bidz16.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_bidz17.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_bidz18.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_bidz19.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_bidz2.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_bidz20.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_bidz3.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_bidz4.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_bidz5.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_bidz6.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_bidz7.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_bidz8.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_bidz9.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_categorize.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_comparison.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_em_PROFL_CA_flow_b_IEB.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_explorer-Mails.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_explorer-people.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_favorites.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_Games.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_Hide.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_hotbarcom.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_Hotmail.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_hsskin.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_jemster.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_jemsterie.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_jemsteruk.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_jobsearch.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_Mails.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_new.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_premium.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_reun.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_ringtones.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_SearchBoxTrapper.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_searchfor.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_searchgo.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_weather.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_yellowpages.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\editblbuttons.res
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\email-def-511724-548964.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\email-def-511724-9595.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\email-t1-bg.res
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\gamesmenu.cdf
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\gamesMenu.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\hb_ie_menu.res
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\hotbar-premium-hotbar-premium.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\hotbar-premium.cdf
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\hotbar_promo.htm
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\icons2.res
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\ie_games_icon.res
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\ie_video.res
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\keywords.idx
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\keywords1.dat
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\layout.cdf
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\linkpathlegal.txt
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\more.res
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\new_games.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\progress.res
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\s_icons_buttons.res
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\sales_buttons.res
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\sdfmodifier.xml
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\t2_bg.res
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\theweb.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\top7.cdf
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\Top7_theweb.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\tsd_bg.res
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\1\weathericon.res
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\ads.cdf
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\btntrans.idx
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\btntrans1.dat
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\business_promo.htm
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\buttondir.txt
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\components.cdf
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\cursors.res
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\d_icons_buttons_1000.res
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\d_icons_buttons_2000.res
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\d_icons_buttons_3000.res
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\d_icons_buttons_bar.res
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\d_icons_buttons_bbar1.res
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\d_icons_buttons_logos.res
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\d_icons_buttons_other.res
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\d_icons_weather.res
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\default.cdf
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\Default_511745-514279.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\Default_bidz.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\Default_bidz1.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\Default_bidz10.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\Default_bidz11.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\Default_bidz12.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\Default_bidz13.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\Default_bidz14.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\Default_bidz15.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\Default_bidz16.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\Default_bidz17.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\Default_bidz18.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\Default_bidz19.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\Default_bidz2.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\Default_bidz20.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\Default_bidz3.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\Default_bidz4.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\Default_bidz5.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\Default_bidz6.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\Default_bidz7.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\Default_bidz8.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\Default_bidz9.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\Default_categorize.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\Default_comparison.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\Default_em_PROFL_CA_flow_b_IEB.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\Default_explorer-Mails.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\Default_explorer-people.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\Default_favorites.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\Default_Games.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\Default_Hide.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\Default_hotbarcom.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\Default_Hotmail.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\Default_hsskin.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\Default_jemster.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\Default_jemsterie.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\Default_jemsteruk.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\Default_jobsearch.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\Default_Mails.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\Default_new.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\Default_premium.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\Default_reun.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\Default_ringtones.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\Default_SearchBoxTrapper.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\Default_searchfor.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\Default_searchgo.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\Default_weather.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\Default_yellowpages.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\editblbuttons.res
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\email-def-511724-548964.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\email-def-511724-9595.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\email-t1-bg.res
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\gamesmenu.cdf
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\gamesMenu.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\hb_ie_menu.res
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\hotbar-premium-hotbar-premium.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\hotbar-premium.cdf
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\hotbar_promo.htm
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\icons2.res
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\ie_games_icon.res
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\ie_video.res
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\keywords.idx
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\keywords1.dat
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\layout.cdf
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\linkpathlegal.txt
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\more.res
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\new_games.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\progress.res
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\s_icons_buttons.res
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\sales_buttons.res
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\sdfmodifier.xml
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\t2_bg.res
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\theweb.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\top7.cdf
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\Top7_theweb.mnu
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\tsd_bg.res
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\2\weathericon.res
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\ads.xip
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\BtnTrans.xip
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\BtnTrans1.xip
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\business_promo.xip
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\buttondir.xip
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\cursors.xip
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\d_icons_buttons_1000.xip
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\d_icons_buttons_2000.xip
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\d_icons_buttons_3000.xip
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\d_icons_buttons_bar.xip
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\d_icons_buttons_bbar1.xip
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\d_icons_buttons_logos.xip
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\d_icons_buttons_other.xip
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\d_icons_weather.xip
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\default.xip
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\editblbuttons.xip
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\email-t1-bg.xip
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\gamesmenu.xip
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\hb_ie_menu.xip
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\hotbar-premium.xip
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\hotbar_promo.xip
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\icons2.xip
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\ie_games_icon.xip
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\ie_video.xip
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\keywords.xip
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\keywords1.xip
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\layout.xip
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\linkpathlegal.xip
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\more.xip
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\progress.xip
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\s_icons_buttons.xip
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\sales_buttons.xip
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\samplegroups2.txt
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\samplegroups2.xip
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\sdfmodifier.xip
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\t2_bg.xip
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\top7.xip
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\tsd_bg.xip
c:\documents and settings\Michelle Boag\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\weathericon.xip
c:\documents and settings\Michelle Boag\Application Data\ShoppingReport
c:\documents and settings\Michelle Boag\Application Data\ShoppingReport\cs\Config.xml
c:\documents and settings\Michelle Boag\Application Data\ShoppingReport\cs\db\Aliases.dbs
c:\documents and settings\Michelle Boag\Application Data\ShoppingReport\cs\db\Sites.dbs
c:\documents and settings\Michelle Boag\Application Data\ShoppingReport\cs\dwld\WhiteList.xip
c:\documents and settings\Michelle Boag\Application Data\ShoppingReport\cs\report\aggr_storage.xml
c:\documents and settings\Michelle Boag\Application Data\ShoppingReport\cs\report\send_storage.xml
c:\documents and settings\Michelle Boag\Application Data\ShoppingReport\cs\res2\WhiteList.dbs
c:\documents and settings\Michelle Boag\Application Data\ShoppingReport2
c:\documents and settings\Michelle Boag\Application Data\ShoppingReport2\cs\Config.xml
c:\documents and settings\Michelle Boag\Application Data\ShoppingReport2\cs\db\Aliases.dbs
c:\documents and settings\Michelle Boag\Application Data\ShoppingReport2\cs\db\Sites.dbs
c:\documents and settings\Michelle Boag\Application Data\ShoppingReport2\cs\dwld\WhiteList.xip
c:\documents and settings\Michelle Boag\Application Data\ShoppingReport2\cs\report\aggr_storage.xml
c:\documents and settings\Michelle Boag\Application Data\ShoppingReport2\cs\report\send_storage.xml
c:\documents and settings\Michelle Boag\Application Data\ShoppingReport2\cs\res1\WhiteList.dbs
c:\documents and settings\Michelle Boag\WINDOWS
C:\log.udt
c:\program files\Hotbar
c:\program files\Hotbar\bin\11.0.78.0\arrow.ico
c:\program files\Hotbar\bin\11.0.78.0\CntntCntr.dll
c:\program files\Hotbar\bin\11.0.78.0\copyright.txt
c:\program files\Hotbar\bin\11.0.78.0\CoreSrv.dll
c:\program files\Hotbar\bin\11.0.78.0\firefox\extensions\chrome.manifest
c:\program files\Hotbar\bin\11.0.78.0\firefox\extensions\components\npclntax.xpt
c:\program files\Hotbar\bin\11.0.78.0\firefox\extensions\install.rdf
c:\program files\Hotbar\bin\11.0.78.0\firefox\extensions\plugins\npclntax_HotbarSA.dll
c:\program files\Hotbar\bin\11.0.78.0\HostIE.dll
c:\program files\Hotbar\bin\11.0.78.0\HostOL.dll
c:\program files\Hotbar\bin\11.0.78.0\HotbarSA.exe
c:\program files\Hotbar\bin\11.0.78.0\HotbarSAAX.dll
c:\program files\Hotbar\bin\11.0.78.0\HotbarSADF.exe
c:\program files\Hotbar\bin\11.0.78.0\HotbarSAHook.dll
c:\program files\Hotbar\bin\11.0.78.0\HotbarUninstaller.exe
c:\program files\Hotbar\bin\11.0.78.0\Srv.exe
c:\program files\Hotbar\bin\11.0.78.0\Toolbar.dll
c:\program files\Hotbar\bin\11.0.78.0\Weather.exe
c:\program files\Hotbar\bin\11.0.78.0\WeSkin.dll
c:\program files\ShoppingReport
c:\program files\ShoppingReport\Bin\2.6.63\ShoppingReport.dll
c:\program files\ShoppingReport\Uninst.exe
c:\program files\ShoppingReport2
c:\program files\ShoppingReport2\Bin\2.7.27\ShoppingReport.dll
c:\program files\ShoppingReport2\Uninst.exe
c:\windows\system32\abdffcaaf.dll
c:\windows\system32\eccafcfaebc.dll
c:\windows\system32\lastmon.dll
c:\windows\system32\uacinit.dll
D:\Autorun.inf
.
.
((((((((((((((((((((((((( Files Created from 2011-06-15 to 2011-07-15 )))))))))))))))))))))))))))))))
.
.
2011-06-28 01:23 . 2011-06-28 01:23 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2011-06-28 01:18 . 2011-06-28 01:18 ——– d—–w- c:\program files\CCleaner
2011-06-28 01:18 . 2011-06-28 01:18 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Google
2011-06-27 12:11 . 2011-06-27 12:11 ——– d—–w- C:\TDSSKiller_Quarantine
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2009-11-18 07:40 1196936 —-a-w- c:\program files\Ask.com\GenericAskToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-11-18 1196936]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-11-18 1196936]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-09-12 68856]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpWirelessAssistant"="c:\program files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2006-05-04 458752]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2010-02-03 149280]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2006-03-23 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-03-23 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2006-03-23 118784]
"High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" [2006-06-02 61952]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-06-17 794713]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2006-06-23 102400]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-16 49152]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-06-02 135168]
"Cpqset"="c:\program files\Hewlett-Packard\Default Settings\cpqset.exe" [2006-06-19 40960]
"RecGuard"="c:\windows\SMINST\RecGuard.exe" [2005-10-11 1187840]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"IMEKRMIG6.1"="c:\windows\ime\imkr6_1\IMEKRMIG.EXE" [2004-08-04 44032]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-17 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-04-28 142120]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-24 29696]
HP Photosmart Premier Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2005-9-25 73728]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-1-21 65588]
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Warlords\\Civ4Warlords.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Warlords\\Civ4Warlords_PitBoss.exe"=
.
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [28/06/2011 11:17 AM 136176]
S3 988413b7-ba2d-4b26-8f34-5c052fc0b4fe;988413b7-ba2d-4b26-8f34-5c052fc0b4fe;\??\e:\player\cds300.dll –> e:\player\cds300.dll [?]
S3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\drivers\netaapl.sys [29/08/2009 12:32 PM 17408]
.
Contents of the 'Scheduled Tasks' folder
.
2011-07-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-06-28 01:17]
.
2011-07-15 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-06-28 01:17]
.
2011-07-15 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2009-11-18 07:40]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com.au/
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_AU&c=64&bd=presario&pf=laptop
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html
TCP: DhcpNameServer = [removed] [removed]
.
- - - - ORPHANS REMOVED - - - -
.
SafeBoot-klmdb.sys
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-07-16 07:53
Windows 5.1.2600 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = c:\program files\Hewlett-Packard\Default Settings\cpqset.exe????????????L?@? ????\??????`?@?????L?@
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-1056171729-2125890163-539554609-1006\Software\SecuROM\License information*]
"datasecu"=hex:95,0b,eb,c6,79,a3,d7,8f,9e,d2,c4,84,a3,12,8b,dd,d3,a0,a7,c2,b9,
4f,d4,39,91,b9,e3,6e,4b,be,57,53,92,2b,80,47,27,ec,af,6d,14,7a,a9,3e,31,55,\
"rkeysecu"=hex:fa,49,da,9a,2d,6d,74,ff,ae,23,ea,0d,6e,63,eb,0e
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(3544)
c:\windows\system32\WININET.dll
c:\windows\system32\browselc.dll
c:\progra~1\WINDOW~1\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\windows\system32\wscntfy.exe
c:\program files\HP\Digital Imaging\bin\hpqimzone.exe
c:\program files\iPod\bin\iPodService.exe
c:\progra~1\hpq\Shared\HPQTOA~1.EXE
c:\program files\Java\jre6\bin\jucheck.exe
.
**************************************************************************
.
Completion time: 2011-07-16 08:00:52 - machine was rebooted
ComboFix-quarantined-files.txt 2011-07-15 22:00
.
Pre-Run: 9,650,282,496 bytes free
Post-Run: 10,076,884,992 bytes free
.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
.
- - End Of File - - 66628542B6C64D1DB4FC276834006E9B

I await your instructions and thanks again for your help.
Please download Malwarebytes from Here or Here

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the log please

















Next

Run the following scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.
Hi Mowman, Done. During the Eset process I twice got dialogs that a component of MS Office was missing and to insert the CD; I took a screen shot and can send it to you if it would help. Here is the MBAM log: Malwarebytes' Anti-Malware 1.51.1.1800 www.malwarebytes.org Database version: 7160 Windows 5.1.2600 Service Pack 2 Internet Explorer 8.0.6001.18702 16/07/2011 8:21:28 PM mbam-log-2011-07-16 (20-21-28).txt Scan type: Quick scan Objects scanned: 180486 Time elapsed: 3 minute(s), 20 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 5 Registry Values Infected: 0 Registry Data Items Infected: 1 Folders Infected: 33 Files Infected: 283 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CLASSES_ROOT\Typelib\{B035BA6B-57CD-4F72-B545-65BE465FCAF6} (Adware.ShoppingReport2) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{D44FD6F0-9746-484E-B5C4-C66688393872} (Adware.ShoppingReport2) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{0EB3F101-224A-4B2B-9E5B-DF720857529C} (Adware.ShoppingReport2) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A078F691-9C07-4AF2-BF43-35E79EECF8B7} (Adware.Softomate) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EDDBB5EE-BB64-4bfc-9DBE-E7C85941335B} (Adware.Zango) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\StartMenuLogoff (PUM.Hijack.StartMenu) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Folders Infected: c:\documents and settings\all users\application data\14623093 (Rogue.Multiple) -> Quarantined and deleted successfully. c:\documents and settings\all users\application data\614558828 (Rogue.Multiple) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\IESkins (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5 (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\HostOI (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\HostOI\dynamic (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\HostOL (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\HostOL\dynamic (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\dynamic (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\dynamic\tooltipxml (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\dynamic\ustat (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1 (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2 (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\DownLoad (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\Weather (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\Weather\weatherdpa (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\Weather\weatherdpa\weather_xml (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\Weather\weather_xml (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\shoppingreport (Adware.ShopperReports) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\shoppingreport\cs (Adware.ShopperReports) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\shoppingreport\cs\db (Adware.ShopperReports) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\shoppingreport\cs\dwld (Adware.ShopperReports) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\shoppingreport\cs\report (Adware.ShopperReports) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\shoppingreport\cs\res1 (Adware.ShopperReports) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\shoppingreport2 (Adware.ShoppingReport2) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\shoppingreport2\cs (Adware.ShoppingReport2) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\shoppingreport2\cs\db (Adware.ShoppingReport2) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\shoppingreport2\cs\dwld (Adware.ShoppingReport2) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\shoppingreport2\cs\report (Adware.ShoppingReport2) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\weatherdpa (Adware.Hotbar) -> Quarantined and deleted successfully. Files Infected: c:\WINDOWS\system32\419214b5c860768b8f11aa820f491f79.tmp (Worm.AutoRun) -> Quarantined and deleted successfully. c:\WINDOWS\system32\883830944bdf159792b0dde52070a860.exe (Trojan.Dropper) -> Quarantined and deleted successfully. c:\documents and settings\michelle boag\application data\asd.bat (Rogue.WinPCDefender) -> Quarantined and deleted successfully. c:\documents and settings\all users\application data\614558828\pc614558828ins (Rogue.Multiple) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\dynamic\1.sdf (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\dynamic\1057199.sdf (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\dynamic\1057779.sdf (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\dynamic\1075709.sdf (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\dynamic\137979.sdf (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\dynamic\1387202.sdf (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\dynamic\270115.sdf (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\dynamic\3404705.sdf (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\dynamic\3852296.sdf (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\dynamic\600583.sdf (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\dynamic\765025.sdf (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\dynamic\domains.txt (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\dynamic\tooltipxml\1491 (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\dynamic\tooltipxml\161965 (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\dynamic\tooltipxml\180320 (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\dynamic\tooltipxml\23021 (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\dynamic\tooltipxml\243256 (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\dynamic\tooltipxml\278975 (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\dynamic\tooltipxml\35017 (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\dynamic\tooltipxml\41243 (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\dynamic\tooltipxml\53481 (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\dynamic\tooltipxml\585345 (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\dynamic\tooltipxml\61795 (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\dynamic\tooltipxml\6465 (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\dynamic\tooltipxml\6468 (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\dynamic\tooltipxml\72123 (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\dynamic\tooltipxml\745765 (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\dynamic\tooltipxml\750039 (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\dynamic\tooltipxml\79246 (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\dynamic\tooltipxml\81507 (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\dynamic\tooltipxml\90358 (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\dynamic\tooltipxml\96462 (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\dynamic\tooltipxml\98248 (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\dynamic\ustat\396d.dat (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\ads.cdf (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\btntrans.idx (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\btntrans1.dat (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\business_promo.htm (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\buttondir.txt (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\components.cdf (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\cursors.res (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\default_bidz12.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\default_bidz13.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\default_bidz14.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\default_bidz15.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\default_bidz16.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\default_bidz17.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\default_bidz18.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\default_bidz19.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\default_bidz2.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\default_bidz20.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\default_bidz3.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\default_bidz4.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\default_bidz5.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\default_bidz6.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\default_bidz7.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\default_bidz8.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\default_categorize.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\default_comparison.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\default_em_profl_ca_flow_b_ieb.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\default_explorer-mails.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\default_explorer-people.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\default_favorites.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\default_games.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\default_hide.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\default_hotbarcom.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\default_hotmail.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\default_hsskin.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\default_jemster.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\default_jemsterie.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\default_jemsteruk.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\default_jobsearch.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\default.cdf (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\default_511745-514279.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\default_bidz.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\default_bidz1.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\default_bidz10.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\default_new.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\default_premium.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\default_reun.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\default_ringtones.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\default_searchboxtrapper.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\default_searchfor.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\default_searchgo.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\default_weather.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\default_yellowpages.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\d_icons_buttons_1000.res (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\d_icons_buttons_2000.res (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\d_icons_buttons_3000.res (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\d_icons_buttons_bar.res (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\d_icons_buttons_bbar1.res (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\d_icons_buttons_logos.res (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\d_icons_buttons_other.res (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\d_icons_weather.res (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\editblbuttons.res (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\email-def-511724-548964.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\default_bidz11.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\default_bidz9.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\default_mails.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\email-def-511724-9595.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\ie_games_icon.res (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\email-t1-bg.res (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\gamesmenu.cdf (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\gamesmenu.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\hb_ie_menu.res (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\hotbar-premium-hotbar-premium.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\hotbar-premium.cdf (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\hotbar_promo.htm (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\icons2.res (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\ie_video.res (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\keywords.idx (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\keywords1.dat (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\layout.cdf (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\linkpathlegal.txt (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\more.res (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\new_games.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\progress.res (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\sales_buttons.res (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\sdfmodifier.xml (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\s_icons_buttons.res (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\t2_bg.res (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\theweb.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\top7.cdf (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\top7_theweb.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\tsd_bg.res (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\1\weathericon.res (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\ads.cdf (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\btntrans.idx (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\btntrans1.dat (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\business_promo.htm (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\buttondir.txt (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\components.cdf (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\cursors.res (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\default_bidz12.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\default_bidz13.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\default_bidz14.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\default_bidz15.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\default_bidz16.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\default_bidz17.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\default_bidz18.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\default_bidz19.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\default_bidz2.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\default_bidz20.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\default_bidz3.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\default_bidz4.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\default_bidz5.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\default_bidz6.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\default_bidz7.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\default_bidz8.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\default_categorize.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\default_comparison.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\default_em_profl_ca_flow_b_ieb.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\default_explorer-mails.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\default_explorer-people.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\default_favorites.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\default_games.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\default_hide.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\default_hotbarcom.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\default_hotmail.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\default_hsskin.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\default_jemster.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\default_jemsterie.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\default_jemsteruk.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\default_jobsearch.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\default.cdf (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\default_511745-514279.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\default_bidz.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\default_bidz1.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\default_bidz10.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\default_new.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\default_premium.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\default_reun.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\default_ringtones.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\default_searchboxtrapper.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\default_searchfor.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\default_searchgo.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\default_weather.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\default_yellowpages.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\d_icons_buttons_1000.res (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\d_icons_buttons_2000.res (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\d_icons_buttons_3000.res (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\d_icons_buttons_bar.res (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\d_icons_buttons_bbar1.res (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\d_icons_buttons_logos.res (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\d_icons_buttons_other.res (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\d_icons_weather.res (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\editblbuttons.res (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\email-def-511724-548964.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\default_bidz11.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\default_bidz9.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\default_mails.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\email-def-511724-9595.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\ie_games_icon.res (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\email-t1-bg.res (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\gamesmenu.cdf (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\gamesmenu.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\hb_ie_menu.res (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\hotbar-premium-hotbar-premium.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\hotbar-premium.cdf (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\hotbar_promo.htm (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\icons2.res (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\ie_video.res (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\keywords.idx (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\keywords1.dat (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\layout.cdf (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\linkpathlegal.txt (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\more.res (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\new_games.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\progress.res (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\sales_buttons.res (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\sdfmodifier.xml (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\s_icons_buttons.res (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\t2_bg.res (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\theweb.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\top7.cdf (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\top7_theweb.mnu (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\tsd_bg.res (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\2\weathericon.res (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\DownLoad\ads.xip (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\DownLoad\BtnTrans.xip (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\DownLoad\btntrans1.xip (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\DownLoad\business_promo.xip (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\DownLoad\buttondir.xip (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\DownLoad\editblbuttons.xip (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\DownLoad\email-t1-bg.xip (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\DownLoad\progress.xip (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\DownLoad\sales_buttons.xip (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\DownLoad\samplegroups2.txt (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\DownLoad\samplegroups2.xip (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\DownLoad\sdfmodifier.xip (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\DownLoad\s_icons_buttons.xip (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\DownLoad\t2_bg.xip (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\DownLoad\top7.xip (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\DownLoad\tsd_bg.xip (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\DownLoad\weathericon.xip (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\DownLoad\d_icons_buttons_2000.xip (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\DownLoad\d_icons_buttons_3000.xip (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\DownLoad\d_icons_buttons_bar.xip (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\DownLoad\d_icons_buttons_bbar1.xip (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\DownLoad\d_icons_buttons_logos.xip (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\DownLoad\d_icons_buttons_other.xip (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\DownLoad\ie_video.xip (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\DownLoad\keywords.xip (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\DownLoad\keywords1.xip (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\DownLoad\layout.xip (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\DownLoad\linkpathlegal.xip (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\DownLoad\default.xip (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\DownLoad\cursors.xip (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\DownLoad\d_icons_buttons_1000.xip (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\DownLoad\d_icons_weather.xip (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\DownLoad\ie_games_icon.xip (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\DownLoad\more.xip (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\DownLoad\gamesmenu.xip (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\DownLoad\hb_ie_menu.xip (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\DownLoad\hotbar-premium.xip (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\DownLoad\hotbar_promo.xip (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\v3.5\Hotbar\static\DownLoad\icons2.xip (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\Weather\history (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\Weather\weatherstartup.xml (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\Weather\weatherdpa\Links (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\Weather\weatherdpa\weatherpreferences (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\Weather\weatherdpa\weather_xml\Display (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\Weather\weatherdpa\weather_xml\Error (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\Weather\weatherdpa\weather_xml\Loading (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\Weather\weatherdpa\weather_xml\screen2 (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\Weather\weather_xml\Default (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\Weather\weather_xml\Genera1 (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\Hotbar\Weather\weather_xml\General (Adware.Hotbar) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\shoppingreport\cs\Config.xml (Adware.ShopperReports) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\shoppingreport\cs\db\Aliases.dbs (Adware.ShopperReports) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\shoppingreport\cs\db\Sites.dbs (Adware.ShopperReports) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\shoppingreport\cs\dwld\whitelist.xip (Adware.ShopperReports) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\shoppingreport\cs\report\aggr_storage.xml (Adware.ShopperReports) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\shoppingreport\cs\report\send_storage.xml (Adware.ShopperReports) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\shoppingreport\cs\res1\whitelist.dbs (Adware.ShopperReports) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\shoppingreport2\cs\Config.xml (Adware.ShoppingReport2) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\shoppingreport2\cs\db\Aliases.dbs (Adware.ShoppingReport2) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\shoppingreport2\cs\report\aggr_storage.xml (Adware.ShoppingReport2) -> Quarantined and deleted successfully. c:\documents and settings\jaime ratcliffe\application data\shoppingreport2\cs\report\send_storage.xml (Adware.ShoppingReport2) -> Quarantined and deleted successfully. And here is the Eset log: ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK # version=7 # iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339) # OnlineScanner.ocx=1.0.0.6528 # api_version=3.0.2 # EOSSerial=9c1247b777dbfc4eb11f3ab6b54e3d0e # end=finished # remove_checked=true # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2011-07-16 11:41:26 # local_time=2011-07-16 09:41:26 (+1000, AUS Eastern Standard Time) # country="Australia" # lang=1033 # osver=5.1.2600 NT Service Pack 2 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=79873 # found=51 # cleaned=51 # scan_time=2220 C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Start Menu\Programs\Hotbar\About Hotbar.lnk.vir LNK/URL.B trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Start Menu\Programs\Hotbar\Hotbar Customer Support Center.lnk.vir LNK/URL.B trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Start Menu\Programs\Hotbar\Hotbar Games!.lnk.vir LNK/URL.B trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Start Menu\Programs\Hotbar\Hotbar Videos!.lnk.vir LNK/URL.B trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Qoobox\Quarantine\C\Program Files\Hotbar\bin\11.0.78.0\CoreSrv.dll.vir Win32/Adware.HotBar.E application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Qoobox\Quarantine\C\Program Files\Hotbar\bin\11.0.78.0\HostIE.dll.vir Win32/Adware.HotBar.E application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Qoobox\Quarantine\C\Program Files\Hotbar\bin\11.0.78.0\HostOL.dll.vir Win32/Adware.HotBar.E application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Qoobox\Quarantine\C\Program Files\Hotbar\bin\11.0.78.0\HotbarSA.exe.vir probably a variant of Win32/Adware.180Solutions application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Qoobox\Quarantine\C\Program Files\Hotbar\bin\11.0.78.0\HotbarSAAX.dll.vir a variant of Win32/Adware.HotBar.E application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Qoobox\Quarantine\C\Program Files\Hotbar\bin\11.0.78.0\HotbarSADF.exe.vir Win32/Adware.HotBar.E application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Qoobox\Quarantine\C\Program Files\Hotbar\bin\11.0.78.0\HotbarSAHook.dll.vir a variant of Win32/Adware.HotBar.E application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Qoobox\Quarantine\C\Program Files\Hotbar\bin\11.0.78.0\HotbarUninstaller.exe.vir multiple threats (deleted - quarantined) 00000000000000000000000000000000 C C:\Qoobox\Quarantine\C\Program Files\Hotbar\bin\11.0.78.0\Srv.exe.vir Win32/Adware.HotBar.E application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Qoobox\Quarantine\C\Program Files\Hotbar\bin\11.0.78.0\Toolbar.dll.vir Win32/Adware.HotBar.E application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Qoobox\Quarantine\C\Program Files\ShoppingReport\Uninst.exe.vir Win32/Adware.ShopperReports application (deleted - quarantined) 00000000000000000000000000000000 C C:\Qoobox\Quarantine\C\Program Files\ShoppingReport\Bin\2.6.63\ShoppingReport.dll.vir a variant of Win32/Adware.Toolbar.Shopper.AA application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Qoobox\Quarantine\C\Program Files\ShoppingReport2\Bin\2.7.27\ShoppingReport.dll.vir a variant of Win32/Adware.Toolbar.Shopper.AB application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Qoobox\Quarantine\C\WINDOWS\system32\lastmon.dll.vir a variant of Win32/BHO.NYU trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP288\A0057314.dll a variant of Win32/BHO.NKS trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP292\A0088655.lnk LNK/URL.B trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP292\A0088656.lnk LNK/URL.B trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP292\A0088657.lnk LNK/URL.B trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP292\A0088659.lnk LNK/URL.B trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP292\A0088665.dll Win32/Adware.HotBar.E application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP292\A0088668.dll Win32/Adware.HotBar.E application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP292\A0088669.dll Win32/Adware.HotBar.E application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP292\A0088670.exe probably a variant of Win32/Adware.180Solutions application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP292\A0088671.dll a variant of Win32/Adware.HotBar.E application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP292\A0088672.exe Win32/Adware.HotBar.E application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP292\A0088673.dll a variant of Win32/Adware.HotBar.E application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP292\A0088674.exe multiple threats (deleted - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP292\A0088675.exe Win32/Adware.HotBar.E application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP292\A0088676.dll Win32/Adware.HotBar.E application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP292\A0088679.dll a variant of Win32/Adware.Toolbar.Shopper.AA application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP292\A0088680.exe Win32/Adware.ShopperReports application (deleted - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP292\A0088681.dll a variant of Win32/Adware.Toolbar.Shopper.AB application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP292\A0088683.dll a variant of Win32/BHO.NYU trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP292\A0088687.exe probably a variant of Win32/TrojanDownloader.Obfuscated.BTZASGA trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP292\A0088688.ini probably a variant of Win32/BHO.NYU trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP292\A0088690.exe probably a variant of Win32/Agent.LBBERKF trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP292\A0088691.exe probably a variant of Win32/TrojanDownloader.Obfuscated.BTZASGA trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP292\A0088692.ini a variant of Win32/BHO.NYU trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP292\A0088693.ini a variant of Win32/BHO.NYU trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP292\A0088694.ini Win32/BHO.NSD trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP292\A0088696.ini a variant of Win32/BHO.NSD trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP292\A0088699.exe probably a variant of Win32/TrojanDownloader.Agent.NFSQWXJ trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP292\A0088700.exe probably a variant of Win32/Agent.KWBQKY trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP292\A0088701.exe probably a variant of Win32/Agent.LBBERKF trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP292\A0088702.ini Win32/BHO.NSD trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP292\A0088703.ini Win32/BHO.NSD trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\TDSSKiller_Quarantine\27.06.2011_22.09.58\susp0000\svc0000\tsk0000.dta Win32/Rootkit.Agent.NJF trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C Thanks for your help.
Post the screenshot of the error if you are still getting it. Open OTL,click run scan and post the log.Also tell me how the computer is running now.
Hi Mowman,
I originally had the Office dialog when running the eset online scan. I went to the Eset site just now and got the same dialog. I also got it again when I tried to open a Word document from the My Documents folder. Then I opened a couple of Word documents from the desktop and they opened straight into Word 2007. Back to My Documents and this time some documents had the Word 2007 icon and some the Word 2000 icon; opened one with the Word 2007 icon and got a dialog to wait while Word was configured. After that all documents had the Word 2007 icon and everything opens straight into the Office 2007 program (Word, Powerpoint, Excel, Publisher). Back to the Eset site and this time no dialog. Strange but it now seems the PC knows it has Office 2007 Professional installed. In case it helps, I've attached the screen shot (cropped to the dialog box).

Also, it seems to be much more responsive now. Also, I can open the Kaspersky site in Internet Exporer without it shutting down. Can you advise when I could load the Kaspersky Internet Security suite to give protection to this PC?

I ran the OTL scan (as you hadn't mentioned them, I didn't check the LOP and Purity Checks so there is no Extras log. If you need them, I'll gladly rerun the scan. Here is the OTL log:

OTL logfile created on: 17/07/2011 11:52:55 PM - Run 2
OTL by OldTimer - Version 3.2.26.1 Folder = C:\Documents and Settings\Michelle Boag\Desktop\whatthetech\OTL
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

1.99 Gb Total Physical Memory | 1.50 Gb Available Physical Memory | 75.54% Memory free
2.20 Gb Paging File | 1.87 Gb Available in Paging File | 85.08% Paging File free
Paging file location(s): C:\pagefile.sys 372 744 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 48.25 Gb Total Space | 10.65 Gb Free Space | 22.08% Space Free | Partition Type: NTFS
Drive D: | 7.62 Gb Total Space | 1.06 Gb Free Space | 13.91% Space Free | Partition Type: FAT32

Computer Name: PC258271888326 | User Name: Michelle Boag | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Michelle Boag\Desktop\whatthetech\OTL\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Java\jre6\bin\jucheck.exe (Sun Microsystems, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\HPQ\Shared\HpqToaster.exe ()
PRC - C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
PRC - C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe (Hewlett-Packard Development Company, L.P.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Michelle Boag\Desktop\whatthetech\OTL\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (AppMgmt) – File not found
SRV - (getPlus® Helper) getPlus® – C:\Program Files\NOS\bin\getPlus_HelperSvc.exe (NOS Microsystems Ltd.)
SRV - (AddFiltr) – C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe (Hewlett-Packard Development Company, L.P.)
SRV - (CCALib8) – C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)


========== Driver Services (SafeList) ==========

DRV - (MBAMSwissArmy) – C:\WINDOWS\system32\drivers\mbamswissarmy.sys (Malwarebytes Corporation)
DRV - (hwdatacard) – C:\WINDOWS\system32\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (Netaapl) – C:\WINDOWS\system32\drivers\netaapl.sys (Apple Inc.)
DRV - (HdAudAddService) – C:\WINDOWS\system32\drivers\CHDAud.sys (Conexant Systems Inc.)
DRV - (RTL8023xp) – C:\WINDOWS\system32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation )
DRV - (BCM43XX) – C:\WINDOWS\system32\drivers\BCMWL5.SYS (Broadcom Corporation)
DRV - (sscdmdm) – C:\WINDOWS\system32\drivers\sscdmdm.sys (MCCI)
DRV - (sscdmdfl) – C:\WINDOWS\system32\drivers\sscdmdfl.sys (MCCI)
DRV - (sscdbus) SAMSUNG USB Composite Device driver (WDM) – C:\WINDOWS\system32\drivers\sscdbus.sys (MCCI)
DRV - (sdcplh) – C:\WINDOWS\system32\drivers\sdcplh.sys (Macrovision Europe Ltd)
DRV - (eabusb) – C:\WINDOWS\system32\drivers\EabUsb.sys (Hewlett-Packard Development Company, L.P.)
DRV - (HBtnKey) – C:\WINDOWS\system32\drivers\CPQBttn.sys (Hewlett-Packard Development Company, L.P.)
DRV - (eabfiltr) – C:\WINDOWS\system32\drivers\eabfiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (HSFHWAZL) – C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (rtl8139) Realtek RTL8139(A/B/C) – C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com.au/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=8: C:\Program Files\Google\Update\1.2.183.39\npGoogleOneClick8.dll (Google Inc.)



O1 HOSTS File: ([2011/07/16 07:53:34 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - No CLSID value found.
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll (Google Inc.)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O4 - HKLM..\Run: [Cpqset] C:\Program Files\Hewlett-Packard\Default Settings\Cpqset.exe ()
O4 - HKLM..\Run: [High Definition Audio Property Page Shortcut] C:\WINDOWS\System32\CHDAudPropShortcut.exe (Windows ® Server 2003 DDK provider)
O4 - HKLM..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\imekrmig.exe (Microsoft Corporation)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [RecGuard] C:\WINDOWS\SMINST\Recguard.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\StartUp\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\StartUp\HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Development Company, L.P.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\StartUp\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_43C348BC2E93EB2B.dll (Google Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/Facebo…toUploader5.cab (Facebook Photo Uploader 5)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} http://wwwimages.adobe.com/www.adobe.com/p…obat/nos/gp.cab (get_atlcom Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Michelle Boag\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Michelle Boag\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2001/07/27 07:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/07/17 23:46:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Michelle Boag\Application Data\Xfire
[2011/07/16 20:41:22 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2011/07/16 20:01:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Michelle Boag\Application Data\Malwarebytes
[2011/07/16 20:01:51 | 000,041,272 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/07/16 20:01:50 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/07/16 20:01:47 | 000,022,712 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/07/16 20:01:47 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/07/16 08:10:22 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2011/07/16 07:35:25 | 000,000,000 | RHSD | C] – C:\cmdcons
[2011/07/16 07:28:13 | 000,518,144 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2011/07/16 07:28:13 | 000,406,528 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2011/07/16 07:28:13 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2011/07/16 07:28:13 | 000,060,416 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2011/07/16 07:28:05 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2011/07/16 07:28:01 | 000,000,000 | —D | C] – C:\Qoobox
[2011/07/15 08:14:19 | 000,000,000 | —D | C] – C:\Documents and Settings\Michelle Boag\Desktop\whatthetech
[2011/06/28 11:24:57 | 000,000,000 | —D | C] – C:\Documents and Settings\Michelle Boag\My Documents\backup reg clean
[2011/06/28 11:23:00 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2011/06/28 11:22:03 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Michelle Boag\Recent
[2011/06/28 11:18:45 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2011/06/28 11:18:04 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2011/06/27 22:20:05 | 000,000,000 | —D | C] – C:\WINDOWS\pss
[2011/06/27 22:11:03 | 000,000,000 | —D | C] – C:\TDSSKiller_Quarantine
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/07/17 23:33:36 | 000,000,313 | —- | M] () – C:\hpqp.ini
[2011/07/17 23:33:26 | 000,000,040 | —- | M] () – C:\XP_TV.ini
[2011/07/17 23:33:24 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/07/17 23:33:18 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/07/17 23:33:17 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/07/17 23:33:15 | 2137,116,672 | -HS- | M] () – C:\hiberfil.sys
[2011/07/16 22:23:00 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/07/16 22:01:00 | 000,000,254 | —- | M] () – C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2011/07/16 07:53:34 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2011/07/16 07:35:29 | 000,000,327 | RHS- | M] () – C:\boot.ini
[2011/07/16 07:27:27 | 000,000,512 | —- | M] () – C:\Documents and Settings\Michelle Boag\Desktop\MBR.dat
[2011/07/06 19:52:42 | 000,041,272 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/07/06 19:52:42 | 000,022,712 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/06/28 11:18:46 | 000,000,682 | —- | M] () – C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2011/06/26 16:45:56 | 000,256,000 | —- | M] () – C:\WINDOWS\PEV.exe
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/07/16 07:35:29 | 000,000,211 | —- | C] () – C:\Boot.bak
[2011/07/16 07:35:27 | 000,260,272 | RHS- | C] () – C:\cmldr
[2011/07/16 07:28:13 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2011/07/16 07:28:13 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2011/07/16 07:28:13 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2011/07/16 07:28:13 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2011/07/16 07:28:13 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2011/07/16 07:27:27 | 000,000,512 | —- | C] () – C:\Documents and Settings\Michelle Boag\Desktop\MBR.dat
[2011/06/28 11:18:46 | 000,000,682 | —- | C] () – C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2011/06/28 11:18:00 | 000,000,886 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/06/28 11:18:00 | 000,000,882 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/09/14 18:28:57 | 000,000,486 | —- | C] () – C:\WINDOWS\eReg.dat
[2010/08/31 20:27:55 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2009/06/16 16:43:29 | 000,000,118 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2008/04/09 16:07:36 | 000,002,584 | —- | C] () – C:\WINDOWS\System32\NSM 7 Student CD.ini
[2007/12/06 14:26:59 | 000,000,036 | —- | C] () – C:\WINDOWS\webica.ini
[2007/07/05 11:17:13 | 000,000,000 | —- | C] () – C:\Documents and Settings\All Users\Application Data\LauncherAccess.dt
[2007/04/16 15:19:28 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2007/04/06 13:16:45 | 000,000,043 | —- | C] () – C:\WINDOWS\popcinfo.dat
[2007/04/01 09:15:41 | 000,000,599 | —- | C] () – C:\WINDOWS\PowerReg.dat
[2007/04/01 09:15:24 | 000,010,240 | —- | C] () – C:\WINDOWS\System32\vidx16.dll
[2007/04/01 08:04:42 | 000,014,848 | —- | C] () – C:\Documents and Settings\Michelle Boag\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/04/01 07:05:35 | 000,000,136 | —- | C] () – C:\Documents and Settings\Michelle Boag\Local Settings\Application Data\fusioncache.dat
[2006/08/18 22:16:44 | 000,028,836 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2006/05/11 00:23:48 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2006/05/11 00:23:38 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/05/10 23:48:18 | 000,087,268 | —- | C] () – C:\WINDOWS\hpqins69.dat
[2006/05/10 23:46:02 | 000,000,056 | —- | C] () – C:\WINDOWS\WININIT.INI
[2006/05/10 23:42:38 | 000,000,780 | —- | C] () – C:\WINDOWS\orun32.ini
[2006/05/10 23:33:06 | 000,383,822 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2006/05/10 23:33:06 | 000,054,010 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2006/05/10 23:29:10 | 000,386,408 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2006/05/10 23:25:12 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2006/05/10 23:22:48 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2005/12/03 04:11:40 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2004/09/17 06:24:26 | 003,375,104 | —- | C] () – C:\WINDOWS\System32\qt-mt331.dll
[2004/08/05 07:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/05 07:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/05 07:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/05 07:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/05 07:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/05 07:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/05 07:00:00 | 000,001,788 | —- | C] () – C:\WINDOWS\System32\Dcache.bin
[2004/08/05 07:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2002/05/29 07:55:42 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2002/05/29 07:54:40 | 000,004,605 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[1999/01/23 04:46:58 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL

< End of report >
I don't know what is happening with your Microsoft office as I only do malware removal,you should post your problem in our forum dedicated to this product. http://forums.whatthetech.com/index.php?showforum=120

You should install the Antivirus as soon as you have completed the clean up steps below and run a full scan with it.Also you need to update your XP service pack to SP3 so you can get all windows updates.



You appear clean of infections,please do the following.



ComboFix - Cleanup
Time for some housekeeping
  • Click Start…select Run from the menu.
  • Copy and paste the following into the text entry box:
    Combofix /Uninstall
  • Click the OK button. (See image below as reference.)
🖼Click to load external image (Posted Image)









Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.









Clean out your temp files.
Download Attribune's ATF Cleaner and save to your desktop.
Double-click ATF-Cleaner.exe to run the program.
Under Main "Select Files to Delete" choose: Select All.
Click the Empty Selected button.

If you use Firefox or Opera browser click that browser at the top and choose: Select All
Click the Empty Selected button.
If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program
.











[external image: Posted Image]
Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.
  • Download the latest version of Java Runtime Environment (JRE) 26 and save it to your desktop.
  • Scroll down to where it says JDK 6 Update 26 (JDK or JRE)
  • Click the Download JRE button to the right
  • Select the Windows platform from the dropdown menu.
  • Read the License Agreement and then check the box that says: "I agree to the Java SE Runtime Environment 6u26 with JavaFX 1 License Agreement". Click on Continue.The page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel, double-click on Add or Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE or Java™ 6) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u26-windows-i586-p.exe to install the newest version.
  • After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - Leave BOTH CheckedApplications and Applets
      Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.











Here are some recommendations to help you stay clean.


Update your Antivirus programs and other security products regularly to avoid new threats that could infect your system.

Visit Microsoft often to get the latest updates for your computer.
http://www.update.microsoft.com/



Make sure you are running a FIREWALL.The windows firewall is not sufficient to protect your system. It doesn't monitor outgoing traffic and this is a must.
Please read this article 'Safe Computing Practices'.
So how did I get infected in the first place.

please take a moment to read quietman7's excellent prevention tips in post 3 here
Click >>>> Tips to protect yourself against malware and reduce the potential for re-infection:

Preventing Infections in the Future

Please also have a look at the following links, giving some advice and Tips to protect yourself against malware and reduce the potential for re-infection:

  • Avoid gaming sites, underground web pages, pirated software sites, and peer-to-peer (P2P) file sharing programs. They are a security risk which can make your computer susceptible to a smörgåsbord of malware infections, remote attacks, exposure of personal information, and identity theft. Many malicious worms and Trojans spread across P2P file sharing networks, gaming and underground sites. Users visiting such pages may see innocuous-looking banner ads containing code which can trigger pop-up ads and Flash ads that install viruses, Trojans and spyware. Ads are a target for hackers because they offer a stealthy way to distribute malware to a wide range of Internet users. The best way to reduce the risk of infection is to avoid these types of web sites and not use any P2P applications. Read P2P Software User Advisories and Risks of File-Sharing Technology.

Update Non-Microsoft Programs

It is also a good idea to check for the latest versions of commonly installed applications that are regularly patched to fix vulnerabilities. You can check these by visiting Secunia Software Inspector and Calendar of Updates.


Thats it you are good to go.Safe surfing

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI