This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

HJT log to check

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

HP G60 notebook (2009); wired to LAN, network security set to High.

In HJT log, there are two items (in bold) that got red-flagged by an online analyzer:

Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Windows\system32\DllHost.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe
C:\Program Files\HP\HP Software Update\hpwuschd2.exe
C:\Program Files\Privacyware\Privatefirewall 7.0\PFGUI.exe
C:\Windows\system32\igfxsrvc.exe
C:\Users\richtea\AppData\Local\Google\Update\1.3.21.65\GoogleCrashHandler.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\QuoteTracker\stocks.exe
C:\Windows\system32\Taskmgr.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Users\richtea\Downloads\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf=cnnb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf=cnnb
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf=cnnb
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [UpdateLBPShortCut] "C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
O4 - HKLM\..\Run: [UpdatePSTShortCut] "C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [UpdateP2GoShortCut] "C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
O4 - HKLM\..\Run: [UpdatePDIRShortCut] "C:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\PowerDirector" UpdateWithCreateOnce "SOFTWARE\CyberLink\PowerDirector\7.0"
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [Microsoft Default Manager] "C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" UpdateWithCreateOnce "Software\CyberLink\YouCam\2.0"
O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Privatefirewall] C:\Program Files\Privacyware\Privatefirewall 7.0\PFGUI.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\richtea\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://*.secunia.com
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Privacyware network service (PFNet) - Privacyware/PWI, Inc. - C:\Program Files\Privacyware\Privatefirewall 7.0\pfsvc.exe
O23 - Service: Recovery Service for Windows - Unknown owner - C:\Program Files\SMINST\BLService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 6798 bytes

Lately, I have had a series of BSOD incidents, with an IRQL driver less than equal notice on each crash, and mostly Windows Media Player running at the time. RAM checked out as OK. Suspecting Conexant sound driver, I reinstalled & updated, but the problem persists. Also network security drops to Low of its own. Could there be CWS, or even a rootkit?

Any ideas would be appreciated.
Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 3 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

•Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
•If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
•Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
•Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post





Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
      If suspicious objects are found select skip
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)









  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
    %PROGRAMFILES%\PC-Doctor\Downloads\*.*
    %PROGRAMFILES%\Internet Explorer\*.tmp
    %PROGRAMFILES%\Internet Explorer\*.dat
    %USERPROFILE%\My Documents\*.exe
    %USERPROFILE%\*.exe
    %systemroot%\ADDINS\*.*
    %systemroot%\assembly\*.bak2
    %systemroot%\Config\*.*
    %systemroot%\REPAIR\*.bak2
    %systemroot%\SECURITY\Database\*.sdb /x
    %systemroot%\SYSTEM\*.bak2
    %systemroot%\Web\*.bak2
    %systemroot%\Driver Cache\*.*
    %PROGRAMFILES%\Mozilla Firefox\0*.exe
    %ProgramFiles%\Microsoft Common\*.*
    %ProgramFiles%\TinyProxy.
    %USERPROFILE%\Favorites\*.url /x
    %systemroot%\system32\*.bk
    %systemroot%\*.te
    %systemroot%\system32\system32\*.*
    %ALLUSERSPROFILE%\*.dat /x
    %systemroot%\system32\drivers\*.rmv
    dir /b "%systemroot%\system32\*.exe" | find /i " " /c
    dir /b "%systemroot%\*.exe" | find /i " " /c
    %PROGRAMFILES%\Microsoft\*.*
    %systemroot%\System32\Wbem\proquota.exe
    %PROGRAMFILES%\Mozilla Firefox\*.dat
    %USERPROFILE%\Cookies\*.txt /x
    %SystemRoot%\system32\fonts\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
Hello mowman, Thank you for instructions. First, TDSS; it was clean: 2011/08/23 13:44:20.0452 2336 TDSS rootkit removing tool 2.5.17.0 Aug 22 2011 15:46:57 2011/08/23 13:44:22.0464 2336 ================================================================================ 2011/08/23 13:44:22.0464 2336 SystemInfo: 2011/08/23 13:44:22.0464 2336 2011/08/23 13:44:22.0464 2336 OS Version: 6.0.6002 ServicePack: 2.0 2011/08/23 13:44:22.0464 2336 Product type: Workstation 2011/08/23 13:44:22.0464 2336 ComputerName: HP2 2011/08/23 13:44:22.0464 2336 UserName: richtea 2011/08/23 13:44:22.0464 2336 Windows directory: C:\Windows 2011/08/23 13:44:22.0464 2336 System windows directory: C:\Windows 2011/08/23 13:44:22.0464 2336 Processor architecture: Intel x86 2011/08/23 13:44:22.0464 2336 Number of processors: 2 2011/08/23 13:44:22.0464 2336 Page size: 0x1000 2011/08/23 13:44:22.0464 2336 Boot type: Normal boot 2011/08/23 13:44:22.0464 2336 ================================================================================ 2011/08/23 13:44:30.0498 2336 Initialize success 2011/08/23 13:44:40.0732 3920 ================================================================================ 2011/08/23 13:44:40.0732 3920 Scan started 2011/08/23 13:44:40.0732 3920 Mode: Manual; 2011/08/23 13:44:40.0732 3920 ================================================================================ 2011/08/23 13:44:41.0839 3920 ACPI (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys 2011/08/23 13:44:42.0011 3920 adp94xx (04f0fcac69c7c71a3ac4eb97fafc8303) C:\Windows\system32\drivers\adp94xx.sys 2011/08/23 13:44:42.0058 3920 adpahci (60505e0041f7751bdbb80f88bf45c2ce) C:\Windows\system32\drivers\adpahci.sys 2011/08/23 13:44:42.0089 3920 adpu160m (8a42779b02aec986eab64ecfc98f8bd7) C:\Windows\system32\drivers\adpu160m.sys 2011/08/23 13:44:42.0120 3920 adpu320 (241c9e37f8ce45ef51c3de27515ca4e5) C:\Windows\system32\drivers\adpu320.sys 2011/08/23 13:44:42.0183 3920 AFD (3911b972b55fea0478476b2e777b29fa) C:\Windows\system32\drivers\afd.sys 2011/08/23 13:44:42.0245 3920 agp440 (13f9e33747e6b41a3ff305c37db0d360) C:\Windows\system32\drivers\agp440.sys 2011/08/23 13:44:42.0292 3920 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys 2011/08/23 13:44:42.0323 3920 aliide (3d76fda1a10acc3dc84728f55c29b6d4) C:\Windows\system32\drivers\aliide.sys 2011/08/23 13:44:42.0370 3920 amdagp (c47344bc706e5f0b9dce369516661578) C:\Windows\system32\drivers\amdagp.sys 2011/08/23 13:44:42.0401 3920 amdide (5b92e7839f5a1fbc1b39de67758ad6f8) C:\Windows\system32\drivers\amdide.sys 2011/08/23 13:44:42.0432 3920 AmdK7 (18f29b49ad23ecee3d2a826c725c8d48) C:\Windows\system32\drivers\amdk7.sys 2011/08/23 13:44:42.0463 3920 AmdK8 (93ae7f7dd54ab986a6f1a1b37be7442d) C:\Windows\system32\drivers\amdk8.sys 2011/08/23 13:44:42.0510 3920 arc (5d2888182fb46632511acee92fdad522) C:\Windows\system32\drivers\arc.sys 2011/08/23 13:44:42.0557 3920 arcsas (5e2a321bd7c8b3624e41fdec3e244945) C:\Windows\system32\drivers\arcsas.sys 2011/08/23 13:44:42.0635 3920 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys 2011/08/23 13:44:42.0666 3920 atapi (1f05b78ab91c9075565a9d8a4b880bc4) C:\Windows\system32\drivers\atapi.sys 2011/08/23 13:44:42.0838 3920 athr (c8bb2e935a5d195692140e795ea9ac14) C:\Windows\system32\DRIVERS\athr.sys 2011/08/23 13:44:43.0025 3920 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys 2011/08/23 13:44:43.0103 3920 blbdrive (d4df28447741fd3d953526e33a617397) C:\Windows\system32\drivers\blbdrive.sys 2011/08/23 13:44:43.0181 3920 bowser (35f376253f687bde63976ccb3f2108ca) C:\Windows\system32\DRIVERS\bowser.sys 2011/08/23 13:44:43.0243 3920 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys 2011/08/23 13:44:43.0290 3920 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys 2011/08/23 13:44:43.0353 3920 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys 2011/08/23 13:44:43.0384 3920 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys 2011/08/23 13:44:43.0415 3920 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys 2011/08/23 13:44:43.0446 3920 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys 2011/08/23 13:44:43.0493 3920 BTHMODEM (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys 2011/08/23 13:44:43.0524 3920 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys 2011/08/23 13:44:43.0649 3920 cdrom (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys 2011/08/23 13:44:43.0727 3920 circlass (e5d4133f37219dbcfe102bc61072589d) C:\Windows\system32\drivers\circlass.sys 2011/08/23 13:44:43.0789 3920 CLFS (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys 2011/08/23 13:44:43.0883 3920 CmBatt (99afc3795b58cc478fbbbcdc658fcb56) C:\Windows\system32\DRIVERS\CmBatt.sys 2011/08/23 13:44:43.0930 3920 cmdide (d36372a6ea6805efbe8884d10772313f) C:\Windows\system32\drivers\cmdide.sys 2011/08/23 13:44:43.0992 3920 CnxtHdAudService (dda0cb141150fef87419926790cd26c8) C:\Windows\system32\drivers\CHDRT32.sys 2011/08/23 13:44:44.0101 3920 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\DRIVERS\compbatt.sys 2011/08/23 13:44:44.0148 3920 crcdisk (741e9dff4f42d2d8477d0fc1dc0df871) C:\Windows\system32\drivers\crcdisk.sys 2011/08/23 13:44:44.0179 3920 Crusoe (1f07becdca750766a96cda811ba86410) C:\Windows\system32\drivers\crusoe.sys 2011/08/23 13:44:44.0273 3920 DfsC (622c41a07ca7e6dd91770f50d532cb6c) C:\Windows\system32\Drivers\dfsc.sys 2011/08/23 13:44:44.0507 3920 disk (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys 2011/08/23 13:44:44.0632 3920 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys 2011/08/23 13:44:44.0710 3920 DXGKrnl (c68ac676b0ef30cfbb1080adce49eb1f) C:\Windows\System32\drivers\dxgkrnl.sys 2011/08/23 13:44:44.0803 3920 E1G60 (5425f74ac0c1dbd96a1e04f17d63f94c) C:\Windows\system32\DRIVERS\E1G60I32.sys 2011/08/23 13:44:44.0881 3920 Ecache (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys 2011/08/23 13:44:44.0959 3920 elxstor (23b62471681a124889978f6295b3f4c6) C:\Windows\system32\drivers\elxstor.sys 2011/08/23 13:44:45.0006 3920 ErrDev (3db974f3935483555d7148663f726c61) C:\Windows\system32\drivers\errdev.sys 2011/08/23 13:44:45.0084 3920 exfat (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys 2011/08/23 13:44:45.0147 3920 fastfat (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys 2011/08/23 13:44:45.0193 3920 fdc (afe1e8b9782a0dd7fb46bbd88e43f89a) C:\Windows\system32\DRIVERS\fdc.sys 2011/08/23 13:44:45.0271 3920 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys 2011/08/23 13:44:45.0303 3920 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys 2011/08/23 13:44:45.0381 3920 flpydisk (85b7cf99d532820495d68d747fda9ebd) C:\Windows\system32\DRIVERS\flpydisk.sys 2011/08/23 13:44:45.0443 3920 FltMgr (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys 2011/08/23 13:44:45.0552 3920 FSProFilter (3528c9ec493ca524a877d217c7d51600) C:\Windows\system32\Drivers\FSPFltd.sys 2011/08/23 13:44:45.0693 3920 Fs_Rec (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys 2011/08/23 13:44:45.0786 3920 gagp30kx (34582a6e6573d54a07ece5fe24a126b5) C:\Windows\system32\drivers\gagp30kx.sys 2011/08/23 13:44:45.0864 3920 HdAudAddService (3f90e001369a07243763bd5a523d8722) C:\Windows\system32\drivers\HdAudio.sys 2011/08/23 13:44:45.0989 3920 HDAudBus (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys 2011/08/23 13:44:46.0067 3920 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys 2011/08/23 13:44:46.0098 3920 HidIr (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys 2011/08/23 13:44:46.0129 3920 HidUsb (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys 2011/08/23 13:44:46.0145 3920 HpCISSs (16ee7b23a009e00d835cdb79574a91a6) C:\Windows\system32\drivers\hpcisss.sys 2011/08/23 13:44:46.0223 3920 HpqKbFiltr (35956140e686d53bf676cf0c778880fc) C:\Windows\system32\DRIVERS\HpqKbFiltr.sys 2011/08/23 13:44:46.0348 3920 HSF_DPV (cc267848cb3508e72762be65734e764d) C:\Windows\system32\DRIVERS\HSX_DPV.sys 2011/08/23 13:44:46.0410 3920 HSXHWAZL (a2882945cc4b6e3e4e9e825590438888) C:\Windows\system32\DRIVERS\HSXHWAZL.sys 2011/08/23 13:44:46.0457 3920 HTTP (f870aa3e254628ebeafe754108d664de) C:\Windows\system32\drivers\HTTP.sys 2011/08/23 13:44:46.0504 3920 i2omp (c6b032d69650985468160fc9937cf5b4) C:\Windows\system32\drivers\i2omp.sys 2011/08/23 13:44:46.0551 3920 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys 2011/08/23 13:44:46.0629 3920 iaStorV (54155ea1b0df185878e0fc9ec3ac3a14) C:\Windows\system32\drivers\iastorv.sys 2011/08/23 13:44:47.0284 3920 igfx (dce0b53570703cce580d066f89ef58cd) C:\Windows\system32\DRIVERS\igdkmd32.sys 2011/08/23 13:44:47.0627 3920 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys 2011/08/23 13:44:47.0674 3920 IntcHdmiAddService (c7e7e43cbd34d3b0a0156b51b917dfcc) C:\Windows\system32\drivers\IntcHdmi.sys 2011/08/23 13:44:47.0783 3920 intelide (dd512a049bd7b4bce8a83554c5eff2c1) C:\Windows\system32\drivers\intelide.sys 2011/08/23 13:44:47.0830 3920 intelppm (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys 2011/08/23 13:44:47.0877 3920 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys 2011/08/23 13:44:47.0923 3920 IPMIDRV (b25aaf203552b7b3491139d582b39ad1) C:\Windows\system32\drivers\ipmidrv.sys 2011/08/23 13:44:47.0986 3920 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys 2011/08/23 13:44:48.0017 3920 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys 2011/08/23 13:44:48.0079 3920 isapnp (6c70698a3e5c4376c6ab5c7c17fb0614) C:\Windows\system32\drivers\isapnp.sys 2011/08/23 13:44:48.0142 3920 iScsiPrt (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys 2011/08/23 13:44:48.0157 3920 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys 2011/08/23 13:44:48.0189 3920 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys 2011/08/23 13:44:48.0204 3920 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys 2011/08/23 13:44:48.0235 3920 kbdhid (ede59ec70e25c24581add1fbec7325f7) C:\Windows\system32\DRIVERS\kbdhid.sys 2011/08/23 13:44:48.0298 3920 KSecDD (86165728af9bf72d6442a894fdfb4f8b) C:\Windows\system32\Drivers\ksecdd.sys 2011/08/23 13:44:48.0391 3920 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys 2011/08/23 13:44:48.0423 3920 LSI_FC (c7e15e82879bf3235b559563d4185365) C:\Windows\system32\drivers\lsi_fc.sys 2011/08/23 13:44:48.0454 3920 LSI_SAS (ee01ebae8c9bf0fa072e0ff68718920a) C:\Windows\system32\drivers\lsi_sas.sys 2011/08/23 13:44:48.0485 3920 LSI_SCSI (912a04696e9ca30146a62afa1463dd5c) C:\Windows\system32\drivers\lsi_scsi.sys 2011/08/23 13:44:48.0501 3920 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys 2011/08/23 13:44:48.0563 3920 mdmxsdk (0cea2d0d3fa284b85ed5b68365114f76) C:\Windows\system32\DRIVERS\mdmxsdk.sys 2011/08/23 13:44:48.0594 3920 megasas (0001ce609d66632fa17b84705f658879) C:\Windows\system32\drivers\megasas.sys 2011/08/23 13:44:48.0688 3920 MegaSR (c252f32cd9a49dbfc25ecf26ebd51a99) C:\Windows\system32\drivers\megasr.sys 2011/08/23 13:44:48.0781 3920 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys 2011/08/23 13:44:48.0828 3920 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys 2011/08/23 13:44:48.0875 3920 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys 2011/08/23 13:44:48.0906 3920 mouhid (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys 2011/08/23 13:44:48.0937 3920 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys 2011/08/23 13:44:48.0984 3920 MpFilter (fee0baded54222e9f1dae9541212aab1) C:\Windows\system32\DRIVERS\MpFilter.sys 2011/08/23 13:44:49.0062 3920 mpio (511d011289755dd9f9a7579fb0b064e6) C:\Windows\system32\drivers\mpio.sys 2011/08/23 13:44:49.0203 3920 MpKsl96ddd18c (5f53edfead46fa7adb78eee9ecce8fdf) c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{50EAACD5-DF00-484C-9031-2D5A8A5D97A9}\MpKsl96ddd18c.sys 2011/08/23 13:44:49.0327 3920 MpNWMon (2c3489660d4a8d514c123c3f0d67df46) C:\Windows\system32\DRIVERS\MpNWMon.sys 2011/08/23 13:44:49.0437 3920 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys 2011/08/23 13:44:49.0515 3920 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys 2011/08/23 13:44:49.0561 3920 MRxDAV (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys 2011/08/23 13:44:49.0624 3920 mrxsmb (1e94971c4b446ab2290deb71d01cf0c2) C:\Windows\system32\DRIVERS\mrxsmb.sys 2011/08/23 13:44:49.0702 3920 mrxsmb10 (4fccb34d793b116423209c0f8b7a3b03) C:\Windows\system32\DRIVERS\mrxsmb10.sys 2011/08/23 13:44:49.0827 3920 mrxsmb20 (c3cb1b40ad4a0124d617a1199b0b9d7c) C:\Windows\system32\DRIVERS\mrxsmb20.sys 2011/08/23 13:44:49.0889 3920 msahci (5457dcfa7c0da43522f4d9d4049c1472) C:\Windows\system32\drivers\msahci.sys 2011/08/23 13:44:49.0936 3920 msdsm (4468b0f385a86ecddaf8d3ca662ec0e7) C:\Windows\system32\drivers\msdsm.sys 2011/08/23 13:44:49.0998 3920 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys 2011/08/23 13:44:50.0076 3920 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys 2011/08/23 13:44:50.0107 3920 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys 2011/08/23 13:44:50.0154 3920 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys 2011/08/23 13:44:50.0185 3920 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys 2011/08/23 13:44:50.0295 3920 MsRPC (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys 2011/08/23 13:44:50.0357 3920 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys 2011/08/23 13:44:50.0388 3920 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys 2011/08/23 13:44:50.0419 3920 Mup (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys 2011/08/23 13:44:50.0560 3920 NativeWifiP (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys 2011/08/23 13:44:50.0622 3920 NDIS (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys 2011/08/23 13:44:50.0731 3920 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys 2011/08/23 13:44:50.0794 3920 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys 2011/08/23 13:44:50.0825 3920 NdisWan (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys 2011/08/23 13:44:50.0887 3920 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys 2011/08/23 13:44:50.0903 3920 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys 2011/08/23 13:44:50.0950 3920 netbt (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys 2011/08/23 13:44:51.0059 3920 NETw3v32 (35d5458d9a1b26b2005abffbf4c1c5e7) C:\Windows\system32\DRIVERS\NETw3v32.sys 2011/08/23 13:44:51.0184 3920 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys 2011/08/23 13:44:51.0246 3920 NisDrv (7b01c6172cfd0b10116175e09200d4b4) C:\Windows\system32\DRIVERS\NisDrvWFP.sys 2011/08/23 13:44:51.0293 3920 Npfs (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys 2011/08/23 13:44:51.0309 3920 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys 2011/08/23 13:44:51.0418 3920 Ntfs (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys 2011/08/23 13:44:51.0480 3920 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys 2011/08/23 13:44:51.0511 3920 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys 2011/08/23 13:44:51.0527 3920 nvraid (2edf9e7751554b42cbb60116de727101) C:\Windows\system32\drivers\nvraid.sys 2011/08/23 13:44:51.0558 3920 nvstor (abed0c09758d1d97db0042dbb2688177) C:\Windows\system32\drivers\nvstor.sys 2011/08/23 13:44:51.0589 3920 nv_agp (18bbdf913916b71bd54575bdb6eeac0b) C:\Windows\system32\drivers\nv_agp.sys 2011/08/23 13:44:51.0683 3920 ohci1394 (790e27c3db53410b40ff9ef2fd10a1d9) C:\Windows\system32\DRIVERS\ohci1394.sys 2011/08/23 13:44:51.0714 3920 Parport (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys 2011/08/23 13:44:51.0761 3920 partmgr (57389fa59a36d96b3eb09d0cb91e9cdc) C:\Windows\system32\drivers\partmgr.sys 2011/08/23 13:44:51.0823 3920 Parvdm (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys 2011/08/23 13:44:51.0886 3920 pci (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys 2011/08/23 13:44:51.0933 3920 pciide (1d8b3d8df8eb7fcf2f0ac02f9f947802) C:\Windows\system32\drivers\pciide.sys 2011/08/23 13:44:52.0011 3920 pcmcia (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys 2011/08/23 13:44:52.0104 3920 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys 2011/08/23 13:44:52.0198 3920 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys 2011/08/23 13:44:52.0229 3920 Processor (2027293619dd0f047c584cf2e7df4ffd) C:\Windows\system32\drivers\processr.sys 2011/08/23 13:44:52.0291 3920 PSched (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys 2011/08/23 13:44:52.0354 3920 pwipf6 (31759d2f7217cfe436d61612792500c6) C:\Windows\system32\DRIVERS\pwipf6.sys 2011/08/23 13:44:52.0494 3920 ql2300 (0a6db55afb7820c99aa1f3a1d270f4f6) C:\Windows\system32\drivers\ql2300.sys 2011/08/23 13:44:52.0557 3920 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys 2011/08/23 13:44:52.0588 3920 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys 2011/08/23 13:44:52.0619 3920 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys 2011/08/23 13:44:52.0650 3920 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys 2011/08/23 13:44:52.0728 3920 RasPppoe (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys 2011/08/23 13:44:52.0775 3920 RasSstp (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys 2011/08/23 13:44:52.0822 3920 rdbss (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys 2011/08/23 13:44:52.0869 3920 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys 2011/08/23 13:44:52.0931 3920 rdpdr (fbc0bacd9c3d7f6956853f64a66e252d) C:\Windows\system32\drivers\rdpdr.sys 2011/08/23 13:44:52.0962 3920 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys 2011/08/23 13:44:53.0009 3920 RDPWD (30bfbdfb7f95559ede971f9ddb9a00ba) C:\Windows\system32\drivers\RDPWD.sys 2011/08/23 13:44:53.0087 3920 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys 2011/08/23 13:44:53.0196 3920 RTL8169 (a1adc7b4c074744662207da6edcdfbb0) C:\Windows\system32\DRIVERS\Rtlh86.sys 2011/08/23 13:44:53.0227 3920 RTSTOR (d1fb9a678bd6c2b1129fcb09d5feb6dd) C:\Windows\system32\drivers\RTSTOR.SYS 2011/08/23 13:44:53.0274 3920 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys 2011/08/23 13:44:53.0321 3920 sdbus (126ea89bcc413ee45e3004fb0764888f) C:\Windows\system32\DRIVERS\sdbus.sys 2011/08/23 13:44:53.0352 3920 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys 2011/08/23 13:44:53.0383 3920 Serenum (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys 2011/08/23 13:44:53.0415 3920 Serial (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys 2011/08/23 13:44:53.0461 3920 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys 2011/08/23 13:44:53.0508 3920 sffdisk (3efa810bdca87f6ecc24f9832243fe86) C:\Windows\system32\drivers\sffdisk.sys 2011/08/23 13:44:53.0555 3920 sffp_mmc (e95d451f7ea3e583aec75f3b3ee42dc5) C:\Windows\system32\drivers\sffp_mmc.sys 2011/08/23 13:44:53.0602 3920 sffp_sd (3d0ea348784b7ac9ea9bd9f317980979) C:\Windows\system32\drivers\sffp_sd.sys 2011/08/23 13:44:53.0649 3920 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys 2011/08/23 13:44:53.0711 3920 sisagp (1d76624a09a054f682d746b924e2dbc3) C:\Windows\system32\drivers\sisagp.sys 2011/08/23 13:44:53.0727 3920 SiSRaid2 (43cb7aa756c7db280d01da9b676cfde2) C:\Windows\system32\drivers\sisraid2.sys 2011/08/23 13:44:53.0758 3920 SiSRaid4 (a99c6c8b0baa970d8aa59ddc50b57f94) C:\Windows\system32\drivers\sisraid4.sys 2011/08/23 13:44:53.0805 3920 Smb (7b75299a4d201d6a6533603d6914ab04) C:\Windows\system32\DRIVERS\smb.sys 2011/08/23 13:44:53.0836 3920 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys 2011/08/23 13:44:53.0898 3920 srv (41987f9fc0e61adf54f581e15029ad91) C:\Windows\system32\DRIVERS\srv.sys 2011/08/23 13:44:53.0929 3920 srv2 (ff33aff99564b1aa534f58868cbe41ef) C:\Windows\system32\DRIVERS\srv2.sys 2011/08/23 13:44:53.0992 3920 srvnet (7605c0e1d01a08f3ecd743f38b834a44) C:\Windows\system32\DRIVERS\srvnet.sys 2011/08/23 13:44:54.0054 3920 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys 2011/08/23 13:44:54.0101 3920 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys 2011/08/23 13:44:54.0148 3920 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys 2011/08/23 13:44:54.0210 3920 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys 2011/08/23 13:44:54.0257 3920 SynTP (00b19f27858f56181edb58b71a7c67a0) C:\Windows\system32\DRIVERS\SynTP.sys 2011/08/23 13:44:54.0351 3920 Tcpip (6647fce6fc4970daafe5c64c794513d3) C:\Windows\system32\drivers\tcpip.sys 2011/08/23 13:44:54.0507 3920 Tcpip6 (6647fce6fc4970daafe5c64c794513d3) C:\Windows\system32\DRIVERS\tcpip.sys 2011/08/23 13:44:54.0553 3920 tcpipreg (36606b165d04a397bdf613096986d85d) C:\Windows\system32\drivers\tcpipreg.sys 2011/08/23 13:44:54.0631 3920 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys 2011/08/23 13:44:54.0663 3920 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys 2011/08/23 13:44:54.0709 3920 tdx (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys 2011/08/23 13:44:54.0787 3920 TermDD (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys 2011/08/23 13:44:54.0897 3920 truecrypt (be45dad1c73a3216edc8c485916f6594) C:\Windows\system32\drivers\truecrypt.sys 2011/08/23 13:44:55.0723 3920 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys 2011/08/23 13:44:55.0801 3920 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys 2011/08/23 13:44:55.0833 3920 tunnel (300db877ac094feab0be7688c3454a9c) C:\Windows\system32\DRIVERS\tunnel.sys 2011/08/23 13:44:55.0864 3920 uagp35 (7d33c4db2ce363c8518d2dfcf533941f) C:\Windows\system32\drivers\uagp35.sys 2011/08/23 13:44:55.0957 3920 udfs (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys 2011/08/23 13:44:56.0067 3920 uliagpkx (b0acfdc9e4af279e9116c03e014b2b27) C:\Windows\system32\drivers\uliagpkx.sys 2011/08/23 13:44:56.0098 3920 uliahci (9224bb254f591de4ca8d572a5f0d635c) C:\Windows\system32\drivers\uliahci.sys 2011/08/23 13:44:56.0145 3920 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys 2011/08/23 13:44:56.0207 3920 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys 2011/08/23 13:44:56.0223 3920 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys 2011/08/23 13:44:56.0254 3920 usbccgp (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys 2011/08/23 13:44:56.0285 3920 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys 2011/08/23 13:44:56.0332 3920 usbehci (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys 2011/08/23 13:44:56.0363 3920 usbhub (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys 2011/08/23 13:44:56.0394 3920 usbohci (38dbc7dd6cc5a72011f187425384388b) C:\Windows\system32\drivers\usbohci.sys 2011/08/23 13:44:56.0425 3920 usbprint (e75c4b5269091d15a2e7dc0b6d35f2f5) C:\Windows\system32\DRIVERS\usbprint.sys 2011/08/23 13:44:56.0472 3920 usbscan (a508c9bd8724980512136b039bba65e9) C:\Windows\system32\DRIVERS\usbscan.sys 2011/08/23 13:44:56.0488 3920 USBSTOR (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS 2011/08/23 13:44:56.0519 3920 usbuhci (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys 2011/08/23 13:44:56.0581 3920 usbvideo (e67998e8f14cb0627a769f6530bcb352) C:\Windows\system32\Drivers\usbvideo.sys 2011/08/23 13:44:56.0613 3920 vga (87b06e1f30b749a114f74622d013f8d4) C:\Windows\system32\DRIVERS\vgapnp.sys 2011/08/23 13:44:56.0659 3920 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys 2011/08/23 13:44:56.0691 3920 viaagp (5d7159def58a800d5781ba3a879627bc) C:\Windows\system32\drivers\viaagp.sys 2011/08/23 13:44:56.0737 3920 ViaC7 (c4f3a691b5bad343e6249bd8c2d45dee) C:\Windows\system32\drivers\viac7.sys 2011/08/23 13:44:56.0769 3920 viaide (ea1aa6e3abb3c194feba12a46de8cf2c) C:\Windows\system32\drivers\viaide.sys 2011/08/23 13:44:56.0784 3920 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys 2011/08/23 13:44:56.0831 3920 volmgrx (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys 2011/08/23 13:44:56.0878 3920 volsnap (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys 2011/08/23 13:44:56.0909 3920 vsmraid (587253e09325e6bf226b299774b728a9) C:\Windows\system32\drivers\vsmraid.sys 2011/08/23 13:44:56.0940 3920 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys 2011/08/23 13:44:56.0956 3920 Wanarp (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys 2011/08/23 13:44:56.0971 3920 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys 2011/08/23 13:44:57.0018 3920 Wd (78fe9542363f297b18c027b2d7e7c07f) C:\Windows\system32\drivers\wd.sys 2011/08/23 13:44:57.0096 3920 Wdf01000 (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\Windows\system32\drivers\Wdf01000.sys 2011/08/23 13:44:57.0190 3920 winachsf (0acd399f5db3df1b58903cf4949ab5a8) C:\Windows\system32\DRIVERS\HSX_CNXT.sys 2011/08/23 13:44:57.0268 3920 WinUsb (676f4b665bdd8053eaa53ac1695b8074) C:\Windows\system32\DRIVERS\WinUSB.sys 2011/08/23 13:44:57.0346 3920 WmiAcpi (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\DRIVERS\wmiacpi.sys 2011/08/23 13:44:57.0408 3920 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys 2011/08/23 13:44:57.0517 3920 WUDFRd (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys 2011/08/23 13:44:57.0564 3920 XAudio (dab33cfa9dd24251aaa389ff36b64d4b) C:\Windows\system32\DRIVERS\xaudio.sys 2011/08/23 13:44:57.0611 3920 yukonwlh (7d1f3b131d503ef43ee594b5a2b9b427) C:\Windows\system32\DRIVERS\yk60x86.sys 2011/08/23 13:44:57.0658 3920 MBR (0x1B8) (588ae8f0c685c02ba11f30d9cd7e61a0) \Device\Harddisk0\DR0 2011/08/23 13:44:57.0673 3920 Boot (0x1200) (7e7bc497080ed85253eaa5f42ca7a974) \Device\Harddisk0\DR0\Partition0 2011/08/23 13:44:57.0689 3920 Boot (0x1200) (1f1cd4d509f297bdabc1ee0849c180cf) \Device\Harddisk0\DR0\Partition1 2011/08/23 13:44:57.0689 3920 ================================================================================ 2011/08/23 13:44:57.0689 3920 Scan finished 2011/08/23 13:44:57.0689 3920 ================================================================================ 2011/08/23 13:44:57.0705 2828 Detected object count: 0 2011/08/23 13:44:57.0705 2828 Actual detected object count: 0
Second, OTL log:

OTL logfile created on: 8/23/2011 13:57:11 - Run 1
OTL by OldTimer - Version 3.2.26.5 Folder = C:\Users\richtea\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.93 Gb Total Physical Memory | 1.94 Gb Available Physical Memory | 66.07% Memory free
6.06 Gb Paging File | 5.12 Gb Available in Paging File | 84.53% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 287.17 Gb Total Space | 184.18 Gb Free Space | 64.14% Space Free | Partition Type: NTFS
Drive D: | 10.92 Gb Total Space | 1.29 Gb Free Space | 11.85% Space Free | Partition Type: NTFS

Computer Name: HP2 | User Name: richtea | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\richtea\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Users\richtea\AppData\Local\Google\Update\1.3.21.65\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Program Files\Privacyware\Privatefirewall 7.0\PFGUI.exe (Privacyware/PWI, Inc.)
PRC - C:\Program Files\Privacyware\Privatefirewall 7.0\pfsvc.exe (Privacyware/PWI, Inc.)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe (BillP Studios)
PRC - c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\SMINST\BLService.exe ()


========== Modules (No Company Name) ==========

MOD - C:\Program Files\BillP Studios\WinPatrol\sqlite3.dll ()


========== Win32 Services (SafeList) ==========

SRV - (PFNet) – C:\Program Files\Privacyware\Privatefirewall 7.0\pfsvc.exe (Privacyware/PWI, Inc.)
SRV - (MatSvc) – C:\Program Files\Microsoft Fix it Center\Matsvc.exe (Microsoft Corporation)
SRV - (NisSrv) – c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe (Microsoft Corporation)
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV - (BBSvc) – C:\Program Files\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation.)
SRV - (SeaPort) – C:\Program Files\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
SRV - (Recovery Service for Windows) – C:\Program Files\SMINST\BLService.exe ()
SRV - (hpqddsvc) – C:\Program Files\HP\Photosmart R817\Digital Imaging\bin\hpqddsvc.dll (Hewlett-Packard Co.)
SRV - (hpqcxs08) – C:\Program Files\HP\Photosmart R817\Digital Imaging\bin\hpqcxs08.dll (Hewlett-Packard Co.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (MpKsl975e9f3f) – c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{50EAACD5-DF00-484C-9031-2D5A8A5D97A9}\MpKsl975e9f3f.sys (Microsoft Corporation)
DRV - (pwipf6) – C:\Windows\System32\drivers\pwipf6.sys (Privacyware/PWI, Inc.)
DRV - (NisDrv) – C:\Windows\System32\drivers\NisDrvWFP.sys (Microsoft Corporation)
DRV - (MpNWMon) – C:\Windows\System32\drivers\MpNWMon.sys (Microsoft Corporation)
DRV - (truecrypt) – C:\Windows\System32\drivers\truecrypt.sys (TrueCrypt Foundation)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (FSProFilter) – C:\Windows\System32\Drivers\FSPFltd.sys (FSPro Labs)
DRV - (RTL8169) – C:\Windows\System32\drivers\Rtlh86.sys (Realtek )
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (CnxtHdAudService) – C:\Windows\System32\drivers\CHDRT32.sys (Conexant Systems Inc.)
DRV - (IntcHdmiAddService) Intel® – C:\Windows\System32\drivers\IntcHdmi.sys (Intel® Corporation)
DRV - (NETw3v32) Intel® – C:\Windows\System32\drivers\NETw3v32.sys (Intel Corporation)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (HpqKbFiltr) – C:\Windows\System32\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cnnb
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cnnb

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cnnb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Bing"
FF - prefs.js..browser.search.defaulturl: "http://www.bing.com/search?FORM=WLETDF&PC=WLEM&q="
FF - prefs.js..browser.search.selectedEngine: "Ixquick HTTPS"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "https://ixquick.com/do/mypage.pl?prf=b845979a027bafb57da89364487ca393"
FF - prefs.js..extensions.enabledItems: [removed]:1.01
FF - prefs.js..extensions.enabledItems: {888d99e7-e8b5-46a3-851e-1ec45da1e644}:4.0.2
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:[removed]
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..keyword.URL: "http://www.bing.com/search?FORM=WLETDF&PC=WLEM&q="

FF - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\npPDFXCviewNPPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF - HKCU\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\npPDFXCviewNPPlugin.dll File not found
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\richtea\AppData\Local\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\richtea\AppData\Local\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/08/19 23:40:45 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/04/02 22:25:45 | 000,000,000 | —D | M]

[2009/10/05 19:19:47 | 000,000,000 | —D | M] (No name found) – C:\Users\richtea\AppData\Roaming\Mozilla\Extensions
[2011/08/18 22:41:57 | 000,000,000 | —D | M] (No name found) – C:\Users\richtea\AppData\Roaming\Mozilla\Firefox\Profiles\fujsem93.default\extensions
[2010/05/04 15:43:03 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\richtea\AppData\Roaming\Mozilla\Firefox\Profiles\fujsem93.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}(1885)
[2010/05/04 15:43:05 | 000,000,000 | —D | M] (NoScript) – C:\Users\richtea\AppData\Roaming\Mozilla\Firefox\Profiles\fujsem93.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}(1886)
[2011/08/11 21:12:01 | 000,000,000 | —D | M] (FoxyProxy Standard) – C:\Users\richtea\AppData\Roaming\Mozilla\Firefox\Profiles\fujsem93.default\extensions\[removed]
[2010/01/09 18:04:27 | 000,000,000 | —D | M] (No name found) – C:\Users\richtea\AppData\Roaming\Mozilla\Firefox\Profiles\fujsem93.default\extensions\[removed]
[2011/01/09 17:51:49 | 000,001,832 | —- | M] () – C:\Users\richtea\AppData\Roaming\Mozilla\Firefox\Profiles\fujsem93.default\searchplugins\bing.xml
[2010/01/03 01:25:07 | 000,000,939 | —- | M] () – C:\Users\richtea\AppData\Roaming\Mozilla\Firefox\Profiles\fujsem93.default\searchplugins\dictionary.xml
[2010/01/03 01:27:01 | 000,002,060 | —- | M] () – C:\Users\richtea\AppData\Roaming\Mozilla\Firefox\Profiles\fujsem93.default\searchplugins\eccellio-arts.xml
[2010/01/03 01:24:29 | 000,001,710 | —- | M] () – C:\Users\richtea\AppData\Roaming\Mozilla\Firefox\Profiles\fujsem93.default\searchplugins\eccellio-movies.xml
[2010/01/03 01:29:24 | 000,002,443 | —- | M] () – C:\Users\richtea\AppData\Roaming\Mozilla\Firefox\Profiles\fujsem93.default\searchplugins\google-scholar.xml
[2010/01/03 01:22:01 | 000,001,163 | —- | M] () – C:\Users\richtea\AppData\Roaming\Mozilla\Firefox\Profiles\fujsem93.default\searchplugins\hollywoodcom.xml
[2010/01/03 01:22:13 | 000,001,512 | —- | M] () – C:\Users\richtea\AppData\Roaming\Mozilla\Firefox\Profiles\fujsem93.default\searchplugins\imdb.xml
[2011/08/23 13:39:11 | 000,001,597 | —- | M] () – C:\Users\richtea\AppData\Roaming\Mozilla\Firefox\Profiles\fujsem93.default\searchplugins\ixquick-https.xml
[2011/08/19 20:28:58 | 000,001,984 | —- | M] () – C:\Users\richtea\AppData\Roaming\Mozilla\Firefox\Profiles\fujsem93.default\searchplugins\pixmac-search.xml
[2010/01/03 01:30:54 | 000,001,190 | —- | M] () – C:\Users\richtea\AppData\Roaming\Mozilla\Firefox\Profiles\fujsem93.default\searchplugins\urban-dictionary.xml
[2010/01/03 01:22:47 | 000,001,232 | —- | M] () – C:\Users\richtea\AppData\Roaming\Mozilla\Firefox\Profiles\fujsem93.default\searchplugins\yahoo-answers.xml
[2011/08/17 16:41:11 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/08/03 20:22:07 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA}
File not found (No name found) –
() (No name found) – C:\USERS\RICHTEA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FUJSEM93.DEFAULT\EXTENSIONS\{73A6FE31-595D-460B-A920-FCC0F8843232}.XPI
() (No name found) – C:\USERS\RICHTEA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FUJSEM93.DEFAULT\EXTENSIONS\[removed]
[2011/08/19 23:40:45 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/08/03 20:21:36 | 000,611,224 | —- | M] (Oracle Corporation) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[1999/12/31 17:00:00 | 000,165,656 | —- | M] (Tracker Software Products Ltd.) – C:\Program Files\mozilla firefox\plugins\npPDFXCviewNPPlugin.dll
[2010/01/01 10:00:00 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml

O1 HOSTS File: ([2011/06/15 12:19:54 | 000,000,734 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Privatefirewall] C:\Program Files\Privacyware\Privatefirewall 7.0\PFGUI.exe (Privacyware/PWI, Inc.)
O4 - HKLM..\Run: [UpdateLBPShortCut] C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateP2GoShortCut] C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePDIRShortCut] C:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePSTShortCut] C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
O4 - HKCU..\Run: [ccleaner] C:\Program Files\CCleaner\CCleaner.exe (Piriform Ltd)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: secunia.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - Reg Error: Key error. File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\richtea\AppData\Roaming\IrfanView\IrfanView_Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\Users\richtea\AppData\Roaming\IrfanView\IrfanView_Wallpaper.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 23:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:\Windows\System32\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/08/23 13:53:52 | 000,580,096 | —- | C] (OldTimer Tools) – C:\Users\richtea\Desktop\OTL.exe
[2011/08/23 13:42:51 | 000,000,000 | —D | C] – C:\Users\richtea\Desktop\tdsskiller
[2011/08/19 23:28:37 | 000,000,000 | —D | C] – C:\Users\richtea\AppData\Roaming\MusicBee
[2011/08/19 23:25:36 | 000,000,000 | —D | C] – C:\Users\richtea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MusicBee
[2011/08/19 23:25:24 | 000,000,000 | —D | C] – C:\Program Files\MusicBee
[2011/08/19 19:46:53 | 000,122,760 | —- | C] (Privacyware/PWI, Inc.) – C:\Windows\System32\drivers\pwipf6.sys
[2011/08/19 19:46:41 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Privatefirewall 7.0
[2011/08/19 19:46:38 | 000,000,000 | —D | C] – C:\Program Files\Privacyware
[2011/08/18 22:38:19 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Axantum AxCrypt
[2011/08/17 20:51:04 | 000,000,000 | —D | C] – C:\Users\richtea\AppData\Local\{514D5BA7-4648-45FF-86CD-57EA709D1F4B}
[2011/08/17 20:50:05 | 000,000,000 | —D | C] – C:\Users\richtea\AppData\Local\{83739872-229D-48DA-A719-1F487DC48CF0}
[2011/08/17 16:09:32 | 000,000,000 | —D | C] – C:\Program Files\Belarc
[2011/08/16 23:11:47 | 000,000,000 | —D | C] – C:\Users\richtea\AppData\Local\{0789F593-5648-4D69-956B-63A161294387}
[2011/08/13 18:43:32 | 000,000,000 | —D | C] – C:\Users\richtea\AppData\Local\{D1C90109-ED55-4575-B5D3-9C573355EFDB}
[2011/08/12 22:06:30 | 000,000,000 | —D | C] – C:\Users\richtea\AppData\Local\{B7508487-A103-41C8-8331-0DA27B036C07}
[2011/08/12 22:05:31 | 000,000,000 | —D | C] – C:\Users\richtea\AppData\Local\{DB37484D-D6B8-42D9-A6C3-E92EDE5AC1E7}
[2011/08/12 21:09:41 | 000,000,000 | —D | C] – C:\Windows\en
[2011/08/12 21:02:55 | 000,000,000 | —D | C] – C:\Users\richtea\AppData\Local\{B7AE01F0-D696-4072-9DB4-BDF4B69D681A}
[2011/08/12 21:01:55 | 000,000,000 | —D | C] – C:\Users\richtea\AppData\Local\{75B4D495-4A53-48E7-98AC-5717772DE2BB}
[2011/08/09 22:48:49 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2011/08/09 22:48:48 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2011/08/09 22:48:47 | 001,797,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2011/08/09 22:48:47 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2011/08/09 22:48:46 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2011/08/09 22:39:30 | 003,602,832 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2011/08/09 22:39:30 | 003,550,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2011/08/09 22:39:17 | 000,375,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winsrv.dll
[2011/08/08 22:52:24 | 000,000,000 | —D | C] – C:\Users\richtea\AppData\Local\{FDC8FB55-3B2E-45C4-81DE-5B780703F745}
[2011/08/08 22:15:54 | 000,000,000 | —D | C] – C:\Users\richtea\AppData\Local\{74C39A60-BABC-4081-85BD-C55AD70F820C}
[2011/08/08 22:13:40 | 000,000,000 | —D | C] – C:\Users\richtea\AppData\Local\{11383B92-D0B1-4AE7-AF1E-197F4B9FE086}
[2011/08/08 15:09:13 | 000,000,000 | —D | C] – C:\Users\richtea\AppData\Local\{B6E3A6FB-0171-44C2-9C49-1C1D47FDE3DB}
[2011/08/08 15:03:51 | 000,000,000 | —D | C] – C:\Users\richtea\AppData\Local\{74C2BDF4-581B-429D-ABED-0FA0B690BB61}
[2011/08/08 14:53:32 | 000,000,000 | —D | C] – C:\Users\richtea\AppData\Local\{D45FE1FC-B5CE-423D-B31F-2C5C1E9ECBBB}
[2011/08/06 16:28:35 | 000,000,000 | —D | C] – C:\Users\richtea\AppData\Local\{7543926C-42D4-48ED-B55F-9E25F7D0B2EC}
[2011/08/06 16:10:34 | 000,000,000 | —D | C] – C:\Users\richtea\AppData\Local\{50E31EAB-0D00-4CA0-ACB4-A6C04607B6C4}
[2011/08/06 16:04:43 | 000,000,000 | —D | C] – C:\Users\richtea\AppData\Local\{5B9E08DF-7CB2-423F-BE1D-F9CA0A7D24F5}
[2011/08/06 16:01:06 | 000,000,000 | —D | C] – C:\Users\richtea\AppData\Local\{4E8A4E9C-A325-4802-9B73-1F833F63CE02}
[2011/08/06 15:11:45 | 000,000,000 | —D | C] – C:\Users\richtea\AppData\Local\{63583A06-16A5-47D8-B556-6A257F43D7D6}
[2011/08/06 15:10:32 | 000,000,000 | —D | C] – C:\Users\richtea\AppData\Local\{17C68CF1-23C1-4286-BD59-9F840623BE13}
[2011/08/06 14:33:13 | 000,000,000 | —D | C] – C:\Users\richtea\Documents\Roman
[2011/08/05 23:43:03 | 000,000,000 | —D | C] – C:\Users\richtea\AppData\Local\{CEAF02D8-2748-4E2E-849D-5AFE9393A238}
[2011/08/05 23:21:51 | 000,000,000 | —D | C] – C:\Users\richtea\AppData\Local\{3C18FCC0-BFB2-4C42-9B42-F7E5B11877E6}
[2011/08/05 23:20:08 | 000,000,000 | —D | C] – C:\Users\richtea\AppData\Local\{A9EF7BC6-2600-4AA4-860E-27AF9F83D8BD}
[2011/08/05 20:50:43 | 000,000,000 | —D | C] – C:\Users\richtea\AppData\Local\{A9EC6C8F-75A3-4343-9016-CAC5463B6063}
[2011/08/05 20:49:13 | 000,000,000 | —D | C] – C:\Users\richtea\AppData\Local\{1575B6C1-8FC0-4E67-B861-AF54B85C6A61}
[2011/08/04 22:11:58 | 000,000,000 | —D | C] – C:\Users\richtea\AppData\Local\{0030A32F-AF33-48B6-B46D-B9764A18E196}
[2011/08/04 22:11:07 | 000,000,000 | —D | C] – C:\Users\richtea\AppData\Local\{E73BE256-9671-4EA6-A520-E4AB550ECC91}
[2011/08/04 22:09:32 | 000,000,000 | —D | C] – C:\Users\richtea\AppData\Local\{E567DB83-1932-4DD9-9BEF-FF77B03959E5}
[2011/08/03 20:22:05 | 000,214,408 | —- | C] (Oracle Corporation) – C:\Windows\System32\javaws.exe
[2011/08/03 20:22:05 | 000,173,960 | —- | C] (Oracle Corporation) – C:\Windows\System32\javaw.exe
[2011/08/03 20:22:05 | 000,173,960 | —- | C] (Oracle Corporation) – C:\Windows\System32\java.exe
[2011/08/03 14:28:36 | 000,000,000 | —D | C] – C:\Users\richtea\AppData\Local\{47BCDE94-1603-4864-88D5-F48CB991D24E}
[2011/08/02 00:59:47 | 000,000,000 | —D | C] – C:\Users\richtea\AppData\Local\{5ADDE70E-3356-4E2C-80A2-983B0A6C3517}
[2011/02/11 18:40:40 | 000,004,096 | —- | C] ( ) – C:\Windows\System32\IGFXDEVLib.dll
[2009/11/22 23:24:25 | 003,063,561 | —- | C] (Macromedia, Inc.) – C:\ProgramData\MobileTV.exe
[2009/11/22 23:24:24 | 002,989,660 | —- | C] (Macromedia, Inc.) – C:\ProgramData\DVD.exe
[2009/11/22 23:24:24 | 002,864,396 | —- | C] (Macromedia, Inc.) – C:\ProgramData\MPV.exe
[2009/11/22 23:24:24 | 002,331,174 | —- | C] (Macromedia, Inc.) – C:\ProgramData\Karaoke.exe
[2009/11/22 23:24:24 | 002,231,606 | —- | C] (Macromedia, Inc.) – C:\ProgramData\Games.exe
[6 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/08/23 13:59:26 | 000,615,370 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/08/23 13:59:26 | 000,109,196 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/08/23 13:53:55 | 000,580,096 | —- | M] (OldTimer Tools) – C:\Users\richtea\Desktop\OTL.exe
[2011/08/23 13:49:47 | 000,000,284 | —- | M] () – C:\ProgramData\hpqp.ini
[2011/08/23 13:49:31 | 000,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/08/23 13:49:31 | 000,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/08/23 13:49:24 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/08/23 13:49:21 | 3147,010,048 | -HS- | M] () – C:\hiberfil.sys
[2011/08/23 13:34:06 | 000,000,916 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1764177258-2740290987-562837017-1000UA.job
[2011/08/22 23:03:17 | 000,007,728 | —- | M] () – C:\Users\richtea\AppData\Local\d3d9caps.dat
[2011/08/22 22:41:34 | 000,302,093 | —- | M] () – C:\Users\richtea\AppData\Local\census.cache
[2011/08/22 22:41:31 | 000,155,469 | —- | M] () – C:\Users\richtea\AppData\Local\ars.cache
[2011/08/22 21:34:00 | 000,000,864 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1764177258-2740290987-562837017-1000Core.job
[2011/08/19 23:28:26 | 000,000,806 | —- | M] () – C:\Users\richtea\Application Data\Microsoft\Internet Explorer\Quick Launch\MusicBee.lnk
[2011/08/19 19:46:42 | 000,000,146 | —- | M] () – C:\Windows\ODBC.INI
[2011/08/18 18:36:41 | 000,002,401 | —- | M] () – C:\Users\richtea\Application Data\Microsoft\Internet Explorer\Quick Launch\Skype.lnk
[2011/08/17 21:43:25 | 000,004,288 | —- | M] () – C:\Users\richtea\AppData\Roaming\wklnhst.dat
[2011/08/17 16:37:05 | 000,001,845 | —- | M] () – C:\Users\richtea\Application Data\Microsoft\Internet Explorer\Quick Launch\Belarc.lnk
[2011/08/14 20:39:08 | 000,014,184 | —- | M] () – C:\Users\richtea\Desktop\ZHP.zip
[2011/08/10 15:44:43 | 000,339,176 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2011/08/06 08:30:51 | 000,000,330 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForrichtea.job
[2011/08/03 20:21:34 | 000,544,656 | —- | M] (Oracle Corporation) – C:\Windows\System32\deployJava1.dll
[2011/08/03 20:21:34 | 000,214,408 | —- | M] (Oracle Corporation) – C:\Windows\System32\javaws.exe
[2011/08/03 20:21:34 | 000,173,960 | —- | M] (Oracle Corporation) – C:\Windows\System32\javaw.exe
[2011/08/03 20:21:34 | 000,173,960 | —- | M] (Oracle Corporation) – C:\Windows\System32\java.exe
[2011/08/03 19:57:49 | 000,001,945 | —- | M] () – C:\Windows\epplauncher.mif
[6 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/08/22 23:04:17 | 3147,010,048 | -HS- | C] () – C:\hiberfil.sys
[2011/08/19 23:28:26 | 000,000,806 | —- | C] () – C:\Users\richtea\Application Data\Microsoft\Internet Explorer\Quick Launch\MusicBee.lnk
[2011/08/18 23:06:18 | 000,302,093 | —- | C] () – C:\Users\richtea\AppData\Local\census.cache
[2011/08/18 23:05:59 | 000,155,469 | —- | C] () – C:\Users\richtea\AppData\Local\ars.cache
[2011/08/17 17:06:08 | 000,019,501 | —- | C] () – C:\Windows\WISR30B7.CAT
[2011/08/17 16:37:05 | 000,001,845 | —- | C] () – C:\Users\richtea\Application Data\Microsoft\Internet Explorer\Quick Launch\Belarc.lnk
[2011/08/17 16:09:33 | 000,001,857 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Belarc Advisor.lnk
[2011/08/14 20:39:08 | 000,014,184 | —- | C] () – C:\Users\richtea\Desktop\ZHP.zip
[2011/08/10 15:44:07 | 000,339,176 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2011/07/07 16:53:48 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2011/04/17 22:20:23 | 000,000,036 | —- | C] () – C:\Users\richtea\AppData\Local\housecall.guid.cache
[2011/03/19 22:57:43 | 000,000,095 | —- | C] () – C:\Users\richtea\AppData\Local\fusioncache.dat
[2011/03/19 18:07:05 | 000,072,918 | —- | C] () – C:\Windows\hpiins01.dat
[2010/10/01 00:18:20 | 000,000,146 | —- | C] () – C:\Windows\ODBC.INI
[2010/04/21 18:08:14 | 000,982,240 | —- | C] () – C:\Windows\System32\igkrng500.bin
[2010/04/21 18:08:14 | 000,439,308 | —- | C] () – C:\Windows\System32\igcompkrng500.bin
[2010/04/21 18:08:14 | 000,092,356 | —- | C] () – C:\Windows\System32\igfcg500m.bin
[2010/04/21 17:29:46 | 000,000,151 | —- | C] () – C:\Windows\System32\GfxUI.exe.config
[2009/10/31 00:40:00 | 000,161,105 | —- | C] () – C:\Windows\hpqins00.dat
[2009/10/21 20:43:52 | 000,004,288 | —- | C] () – C:\Users\richtea\AppData\Roaming\wklnhst.dat
[2009/10/20 11:14:18 | 000,129,150 | —- | C] () – C:\Windows\hpiins06.dat
[2009/10/20 11:14:18 | 000,000,000 | —- | C] () – C:\Windows\hpimdl06.dat
[2009/10/18 04:48:51 | 000,008,192 | —- | C] () – C:\Users\richtea\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/10/12 18:56:13 | 000,007,728 | —- | C] () – C:\Users\richtea\AppData\Local\d3d9caps.dat
[2009/10/11 18:22:43 | 000,107,612 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2009/10/11 18:22:42 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/09/10 13:08:03 | 000,000,284 | —- | C] () – C:\ProgramData\hpqp.ini
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | —- | C] () – C:\Windows\System32\OGAEXEC.exe
[2009/04/22 16:10:21 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2009/03/05 07:54:58 | 000,073,728 | —- | C] () – C:\Windows\System32\RtNicProp32.dll
[2008/07/06 22:29:46 | 000,147,456 | —- | C] () – C:\Windows\System32\igfxCoIn_v1518.dll
[2008/07/06 22:14:06 | 000,147,172 | —- | C] () – C:\Windows\System32\igfcg550.bin
[2008/06/29 16:52:14 | 000,004,608 | —- | C] () – C:\Windows\System32\HdmiCoin.dll
[2008/03/05 18:38:08 | 001,457,024 | —- | C] () – C:\Windows\System32\SSCProt.dll
[2006/11/02 14:57:28 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 14:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 12:33:01 | 000,615,370 | —- | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 12:33:01 | 000,287,440 | —- | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 12:33:01 | 000,109,196 | —- | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 12:33:01 | 000,030,674 | —- | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 12:23:21 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2006/11/02 10:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/02 10:19:00 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/02 09:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 09:25:31 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2006/03/09 11:58:00 | 001,060,424 | —- | C] () – C:\Windows\System32\WdfCoInstaller01000.dll

========== LOP Check ==========

[2010/01/04 10:34:01 | 000,000,000 | —D | M] – C:\Users\richtea\AppData\Roaming\Auslogics
[2011/03/20 16:15:48 | 000,000,000 | —D | M] – C:\Users\richtea\AppData\Roaming\f-secure
[2011/07/06 16:18:07 | 000,000,000 | —D | M] – C:\Users\richtea\AppData\Roaming\gtk-2.0
[2010/01/24 22:11:19 | 000,000,000 | —D | M] – C:\Users\richtea\AppData\Roaming\InfraRecorder
[2011/08/08 13:17:11 | 000,000,000 | —D | M] – C:\Users\richtea\AppData\Roaming\IrfanView
[2011/08/19 23:33:21 | 000,000,000 | —D | M] – C:\Users\richtea\AppData\Roaming\MusicBee
[2011/08/19 23:53:28 | 000,000,000 | —D | M] – C:\Users\richtea\AppData\Roaming\Notepad++
[2009/10/27 13:58:50 | 000,000,000 | —D | M] – C:\Users\richtea\AppData\Roaming\OpenOffice.org
[2010/05/09 12:06:41 | 000,000,000 | —D | M] – C:\Users\richtea\AppData\Roaming\PhotoFiltre
[2010/04/17 17:59:08 | 000,000,000 | —D | M] – C:\Users\richtea\AppData\Roaming\Picturenaut
[2011/04/12 20:32:02 | 000,000,000 | —D | M] – C:\Users\richtea\AppData\Roaming\QuickScan
[2009/10/21 20:44:05 | 000,000,000 | —D | M] – C:\Users\richtea\AppData\Roaming\Template
[2010/03/16 08:51:03 | 000,000,000 | —D | M] – C:\Users\richtea\AppData\Roaming\Tracker Software
[2010/12/19 23:57:37 | 000,000,000 | —D | M] – C:\Users\richtea\AppData\Roaming\TrueCrypt
[2010/05/30 22:27:18 | 000,000,000 | —D | M] – C:\Users\richtea\AppData\Roaming\WinPatrol
[2011/08/23 13:48:43 | 000,032,604 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2006/09/18 23:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/04/11 08:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2006/09/18 23:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2011/08/23 13:49:21 | 3147,010,048 | -HS- | M] () – C:\hiberfil.sys
[2011/08/23 13:49:20 | 3462,856,704 | -HS- | M] () – C:\pagefile.sys
[2011/08/10 12:46:03 | 000,012,520 | —- | M] () – C:\PureRa.txt
[2010/05/07 23:23:38 | 000,000,184 | —- | M] () – C:\setup.log
[2011/08/23 13:48:10 | 000,061,892 | —- | M] () – C:\TDSSKiller.2.5.17.0_23.08.2011_13.44.20_log.txt

< %systemroot%\Fonts\*.com >
[2006/11/02 14:37:12 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 14:37:12 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 14:37:12 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/10/12 01:21:29 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/09/18 23:37:34 | 000,000,065 | -H– | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2006/11/05 21:00:00 | 000,027,136 | —- | M] (CANON INC.) – C:\Windows\system32\spool\prtprocs\w32x86\CNMPD8O.DLL
[2007/03/18 20:00:00 | 000,027,136 | —- | M] (CANON INC.) – C:\Windows\system32\spool\prtprocs\w32x86\CNMPD8S.DLL
[2010/04/24 06:00:00 | 000,027,648 | —- | M] (CANON INC.) – C:\Windows\system32\spool\prtprocs\w32x86\CNMPD9W.DLL
[2006/11/05 21:00:00 | 000,069,632 | —- | M] (CANON INC.) – C:\Windows\system32\spool\prtprocs\w32x86\CNMPP8O.DLL
[2007/03/18 20:00:00 | 000,069,632 | —- | M] (CANON INC.) – C:\Windows\system32\spool\prtprocs\w32x86\CNMPP8S.DLL
[2010/04/24 06:00:00 | 000,070,656 | —- | M] (CANON INC.) – C:\Windows\system32\spool\prtprocs\w32x86\CNMPP9W.DLL
[2006/11/02 14:35:48 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/27 04:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\msonpppr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2011/05/13 15:42:24 | 000,302,448 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2008/01/21 04:43:21 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2008/01/21 05:14:18 | 016,846,848 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2008/01/21 05:14:08 | 000,106,496 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2008/01/21 05:14:18 | 000,020,480 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 12:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 12:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/04/09 18:39:20 | 000,000,337 | -HS- | M] () – C:\Users\richtea\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/08/23 13:53:55 | 000,580,096 | —- | M] (OldTimer Tools) – C:\Users\richtea\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

< %PROGRAMFILES%\Internet Explorer\*.tmp >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %USERPROFILE%\My Documents\*.exe >

< %USERPROFILE%\*.exe >

< %systemroot%\ADDINS\*.* >

< %systemroot%\assembly\*.bak2 >

< %systemroot%\Config\*.* >

< %systemroot%\REPAIR\*.bak2 >

< %systemroot%\SECURITY\Database\*.sdb /x >
[2011/08/22 22:08:30 | 000,008,192 | —- | M] () – C:\Windows\SECURITY\Database\edb.chk
[2011/08/22 22:08:30 | 001,048,576 | —- | M] () – C:\Windows\SECURITY\Database\edb.log
[2011/08/22 22:02:28 | 001,048,576 | —- | M] () – C:\Windows\SECURITY\Database\edbres00001.jrs
[2011/08/22 22:02:28 | 001,048,576 | —- | M] () – C:\Windows\SECURITY\Database\edbres00002.jrs

< %systemroot%\SYSTEM\*.bak2 >

< %systemroot%\Web\*.bak2 >

< %systemroot%\Driver Cache\*.* >

< %PROGRAMFILES%\Mozilla Firefox\0*.exe >

< %ProgramFiles%\Microsoft Common\*.* >

< %ProgramFiles%\TinyProxy. >

< %USERPROFILE%\Favorites\*.url /x >
[2009/10/05 19:07:30 | 000,000,402 | -HS- | M] () – C:\Users\richtea\Favorites\desktop.ini

< %systemroot%\system32\*.bk >

< %systemroot%\*.te >

< %systemroot%\system32\system32\*.* >

< %ALLUSERSPROFILE%\*.dat /x >
[2009/11/22 23:24:24 | 002,989,660 | —- | M] (Macromedia, Inc.) – C:\ProgramData\DVD.exe
[2009/11/22 23:24:24 | 002,231,606 | —- | M] (Macromedia, Inc.) – C:\ProgramData\Games.exe
[2011/08/23 13:49:47 | 000,000,284 | —- | M] () – C:\ProgramData\hpqp.ini
[2010/01/18 22:59:10 | 000,000,021 | —- | M] () – C:\ProgramData\hpqp.txt
[2011/03/20 01:58:27 | 000,004,820 | —- | M] () – C:\ProgramData\hpzinstall.log
[2009/11/22 23:24:24 | 002,331,174 | —- | M] (Macromedia, Inc.) – C:\ProgramData\Karaoke.exe
[2009/11/22 23:24:25 | 003,063,561 | —- | M] (Macromedia, Inc.) – C:\ProgramData\MobileTV.exe
[2009/11/22 23:24:24 | 002,864,396 | —- | M] (Macromedia, Inc.) – C:\ProgramData\MPV.exe
[2009/09/10 13:11:11 | 000,000,032 | —- | M] () – C:\ProgramData\{051B9612-4D82-42AC-8C63-CD2DCEDC1CB3}.log
[2009/04/22 17:11:38 | 000,000,109 | —- | M] () – C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log
[2009/09/10 13:10:18 | 000,000,032 | —- | M] () – C:\ProgramData\{23F3DA62-2D9E-4A69-B8D5-BE8E9E148092}.log
[2009/04/22 17:06:05 | 000,000,105 | —- | M] () – C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
[2009/09/10 13:08:31 | 000,000,032 | —- | M] () – C:\ProgramData\{4FC670EB-5F02-4B07-90DB-022B86BFEFD0}.log
[2009/09/10 13:10:49 | 000,000,032 | —- | M] () – C:\ProgramData\{9867824A-C86D-4A83-8F3C-E7A86BE0AFD3}.log
[2009/04/22 17:04:25 | 000,000,107 | —- | M] () – C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log
[2009/04/22 17:11:10 | 000,000,110 | —- | M] () – C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log
[2009/09/10 13:11:21 | 000,000,105 | —- | M] () – C:\ProgramData\{d36dd326-7280-11d8-97c8-000129760cbe}.log

< %systemroot%\system32\drivers\*.rmv >

< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >
No captured output from command…

< dir /b "%systemroot%\*.exe" | find /i " " /c >
No captured output from command…

< %PROGRAMFILES%\Microsoft\*.* >

< %systemroot%\System32\Wbem\proquota.exe >

< %PROGRAMFILES%\Mozilla Firefox\*.dat >

< %USERPROFILE%\Cookies\*.txt /x >

< %SystemRoot%\system32\fonts\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-08-17 18:20:46

< End of report >
And, third, OTL extras:

OTL Extras logfile created on: 8/23/2011 13:57:11 - Run 1
OTL by OldTimer - Version 3.2.26.5 Folder = C:\Users\richtea\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.93 Gb Total Physical Memory | 1.94 Gb Available Physical Memory | 66.07% Memory free
6.06 Gb Paging File | 5.12 Gb Available in Paging File | 84.53% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 287.17 Gb Total Space | 184.18 Gb Free Space | 64.14% Space Free | Partition Type: NTFS
Drive D: | 10.92 Gb Total Space | 1.29 Gb Free Space | 11.85% Space Free | Partition Type: NTFS

Computer Name: HP2 | User Name: richtea | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – Reg Error: Key error.
htmlfile [print] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Browse with &IrfanView] – "C:\Program Files\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan)
Directory [Browse with FastStone] – "C:\Program Files\FastStone Image Viewer\FSViewer.exe" "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{3F81B292-D344-40DC-9283-0AE87747C245}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{6C73EA18-E1A1-40AE-8F27-8BAD9BC63158}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0172E333-8527-4A42-B89E-3C4DC7D4EA04}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe |
"{06B2BE5E-70A6-4D45-B6CF-B228548577F9}" = dir=in | app=c:\program files\hp\quickplay\qpservice.exe |
"{6470FB4A-5782-44D3-B8B0-F572E636D271}" = dir=in | app=c:\program files\cyberlink\powerdirector\pdr.exe |
"{CFE4DF1F-4853-452D-881C-60A76D0A2E4F}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{DB7EF027-2BF4-4EA1-B353-0F8162ACBDA4}" = dir=in | app=c:\program files\hp\quickplay\qp.exe |
"{E3A656CA-5C5C-4F23-8EE2-DEE96F4E5A31}" = dir=in | app=c:\program files\windows live\contacts\wlcomm.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{0054A0F6-00C9-4498-B821-B5C9578F433E}" = HP Help and Support
"{007811BF-E310-4285-BFC6-55DB29B3EDDE}" = WinPatrol
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"{0289B35E-DC07-4c7a-9710-BBD686EA4B7D}" = Status
"{05BFB060-4F22-4710-B0A2-2801A1B606C5}" = Microsoft Antimalware
"{082702D5-5DD8-4600-BCE5-48B15174687F}" = HP Doc Viewer
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP250_series" = Canon MP250 series MP Drivers
"{121634B0-2F4B-11D3-ADA3-00C04F52DD52}" = Windows Installer Clean Up
"{154A4184-1A3D-4BF9-A5AE-4FA1660445F3}" = HP Total Care Advisor
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1F4BF9EA-847E-44FB-A728-C456116E6CEF}" = InstantShareDevicesMFC
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{216BB99F-F43D-46E8-BC11-06F2A696675D}" = AxCrypt 1.7.2614.0
"{228C6B46-64E2-404E-898A-EF0830603EF4}" = HPNetworkAssistant
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{26A24AE4-039D-4CA4-87B4-2F83217000FF}" = Java™ 7
"{28EDE5F6-B92A-4EC5-BE47-94B4A7F1CFBE}" = MusicBee
"{29FA38B4-0AE4-4D0D-8A51-6165BB990BB0}" = WebReg
"{2CADCEAB-D5DA-44D6-B5FC-7DEE87AB3C0C}" = Unload
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.40 H2
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{35845E72-E34A-11D4-817D-005004D0F1FA}" = MarketBrowser
"{35A81F0A-A1CA-458D-8FCD-7D838E3D95FF}" = Microsoft WorldWide Telescope
"{36FDBE6E-6684-462B-AE98-9A39A1B200CC}" = HP Product Assistant
"{38058455-8C21-4C2F-B2F6-14ED166039CB}" = HP Total Care Setup
"{3877C901-7B90-4727-A639-B6ED2DD59D43}" = ESU for Microsoft Vista
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3E171899-0175-47CC-84C4-562ACDD4C021}" = OpenOffice.org 3.3
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{415B2719-AD3A-4944-B404-C472DB6085B3}" = Cisco EAP-FAST Module
"{452622B2-CFF1-4373-B773-141FC10A2AB6}" = hpicamDrvQFolder
"{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP DVD Play 3.7
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{543E938C-BDC4-4933-A612-01293996845F}" = UnloadSupport
"{54B6DC7D-8C5B-4DFB-BC15-C010A3326B2B}" = Microsoft Security Client
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{57A5AEC1-97FC-474D-92C4-908FCC2253D4}" = HP Customer Experience Enhancements
"{5DD4FCBD-A3C1-4155-9E17-4161C70AAABA}" = Segoe UI
"{5F26311C-B135-4F7F-B11E-8E650F83651E}" = DeviceFunctionQFolder
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{61BEA823-ECAF-49F1-8378-A59B3B8AD247}" = Microsoft Default Manager
"{665CBCA4-5AB0-414B-A288-3F8F99FEFC45}" = HP User Guides 0118
"{669C7BD8-DAA2-49B6-966C-F1E2AAE6B17E}" = Cisco PEAP Module
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{730837D4-FF5E-48DB-BA49-33E732DFF0B3}" = PanoStandAlone
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77F8A71E-3515-4832-B8B2-2F1EDBD2E0F1}" = Bing Bar
"{7CDCC01F-B4DB-45B2-8CBB-15F0415ADA8D}" = Destinations
"{824D3839-DAA1-4315-A822-7AE3E620E528}" = VideoToolkit01
"{83770D14-21B9-44B3-8689-F7B523F94560}" = Cisco LEAP Module
"{8389382B-53BA-4A87-8854-91E3D80A5AC7}" = HP Photosmart Essential2.01
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 8168 8101E 8102E Ethernet Driver
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8D273DE5-ABFA-4BD0-A9D7-EE9C971438C4}_is1" = PDF-Viewer
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9ADABDDE-9644-461B-9E73-83FA3EFCAB50}" = HP Wireless Assistant
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9C2D4047-0E40-499a-AC7A-C4B9BB12FE03}" = TrayApp
"{9CF4A37B-A8C4-44D7-8C53-13B9D9594BB2}" = Paint.NET v3.5.8
"{A05CF147-BEED-4880-BF9B-4EAF22C77FFD}" = Microsoft Pro Photo Tools
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AA057FD9-0CFC-47e4-8AB4-E0F7EC85631D}" = HP Photosmart Cameras 9.0
"{AA0FB0B5-D853-4F87-9261-A4BC7D503E0D}" = Microsoft Image Composite Editor
"{AD72CFB4-C2BF-424E-9DF0-C7BAD1F30A11}" = Adobe Shockwave Player
"{AEA07F97-9088-497c-8821-0F36BD5DC251}" = HPProductAssistant
"{B0069CFA-5BB9-4C03-B1C6-89CE290E5AFE}" = HP Update
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B48E1711-0132-4f4a-89FC-C231F0C762DE}" = InstantShareDevices
"{B7588D45-AFDC-4C93-9E2E-A100F3554B64}" = Microsoft Fix it Center
"{BCD6CD1A-0DBE-412E-9F25-3B500D1E6BA1}" = SolutionCenter
"{C3A32068-8AB1-4327-BB16-BED9C6219DC7}" = Atheros Driver Installation Program
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{C6150D8A-86ED-41D3-87BB-F3BB51B0B77F}" = Windows Live ID Sign-in Assistant
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CC8E94A2-55C7-4460-953C-2A790180578C}" = LightScribe System Software
"{CD961214-93C9-44FE-9A38-BBE647E98AE9}" = CameraReadme
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE7E3BE0-2DD3-4416-A690-F9E4A99A8CFF}" = HP Active Support Library
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DC24971E-1946-445D-8A82-CE685433FA7D}" = Realtek USB 2.0 Card Reader
"{DD35C328-F115-BEDA-6EEE-E00C5AACCCBC}" = muvee Reveal
"{DEF9CA03-7317-4a01-8111-06996235128E}" = CameraDrivers
"{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1" = Auslogics Disk Defrag
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E503B4BF-F7BB-3D5F-8BC8-F694B1CFF942}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022.218
"{E8EA933E-03A2-4E62-9F52-812C72BE2A6B}" = Privatefirewall 7.0
"{ECEE0279-785F-4CB3-9F28-E69813234BF8}" = SPORE Creature Creator Trial Edition
"{EF1ADA5A-0B1A-4662-8C55-7475A61D8B65}" = DeviceDiscovery
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F72E2DDC-3DB8-4190-A21D-63883D955FE7}" = PSSWCORE
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"7-Zip" = 7-Zip 9.20
"Belarc Advisor" = Belarc Advisor 8.2
"Canon MP250 series User Registration" = Canon MP250 series User Registration
"CanonMyPrinter" = Canon Utilities My Printer
"CanonSolutionMenu" = Canon Utilities Solution Menu
"CCleaner" = CCleaner
"CNXT_AUDIO_HDA" = Conexant HD Audio
"CNXT_MODEM_HDAUDIO_HERMOSA_HSF" = HDAUDIO Soft Data Fax Modem with SmartCP
"FastStone Image Viewer" = FastStone Image Viewer 4.6
"HDMI" = Intel® Graphics Media Accelerator Driver
"HP Imaging Device Functions" = HP Imaging Device Functions 9.0
"HP Photo Creations" = HP Photo Creations
"HP Photosmart Essential" = HP Photosmart Essential 2.01
"HP Solution Center & Imaging Support Tools" = HP Solution Center 9.0
"InfraRecorder" = InfraRecorder
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"IrfanView" = IrfanView (remove only)
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft Security Client" = Microsoft Security Essentials
"Mozilla Firefox 6.0 (x86 en-US)" = Mozilla Firefox 6.0 (x86 en-US)
"MP Navigator EX 3.0" = Canon MP Navigator EX 3.0
"My Lockbox_is1" = My Lockbox 2.5
"Notepad++" = Notepad++
"QuoteTracker_is1" = QuoteTracker
"Recuva" = Recuva
"Revo Uninstaller" = Revo Uninstaller 1.92
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"TrueCrypt" = TrueCrypt
"WildTangent hp Master Uninstall" = My HP Games
"WinGimp-2.0_is1" = GIMP 2.6.8
"WinLiveSuite" = Windows Live Essentials

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
"PhotoFiltre" = PhotoFiltre

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 3/5/2011 12:39:08 | Computer Name = HP2 | Source = Windows Search Service | ID = 3083
Description =

Error - 3/5/2011 12:51:58 | Computer Name = HP2 | Source = Windows Search Service | ID = 3083
Description =

Error - 3/5/2011 12:52:00 | Computer Name = HP2 | Source = Windows Search Service | ID = 3013
Description =

Error - 3/5/2011 12:52:00 | Computer Name = HP2 | Source = Windows Search Service | ID = 3013
Description =

Error - 3/5/2011 12:52:00 | Computer Name = HP2 | Source = Windows Search Service | ID = 3013
Description =

Error - 3/5/2011 12:52:00 | Computer Name = HP2 | Source = Windows Search Service | ID = 3013
Description =

Error - 3/5/2011 12:52:02 | Computer Name = HP2 | Source = Windows Search Service | ID = 3013
Description =

Error - 3/5/2011 12:54:36 | Computer Name = HP2 | Source = Windows Search Service | ID = 3083
Description =

Error - 3/7/2011 16:21:48 | Computer Name = HP2 | Source = Windows Search Service | ID = 3083
Description =

Error - 3/7/2011 16:21:48 | Computer Name = HP2 | Source = WinMgmt | ID = 10
Description =

[ System Events ]
Error - 8/22/2011 16:58:52 | Computer Name = HP2 | Source = Service Control Manager | ID = 7026
Description =

Error - 8/22/2011 17:06:01 | Computer Name = HP2 | Source = Service Control Manager | ID = 7000
Description =

Error - 8/22/2011 17:06:23 | Computer Name = HP2 | Source = Service Control Manager | ID = 7022
Description =

Error - 8/22/2011 17:06:23 | Computer Name = HP2 | Source = Service Control Manager | ID = 7026
Description =

Error - 8/23/2011 7:24:26 | Computer Name = HP2 | Source = Service Control Manager | ID = 7000
Description =

Error - 8/23/2011 7:24:42 | Computer Name = HP2 | Source = Service Control Manager | ID = 7022
Description =

Error - 8/23/2011 7:24:42 | Computer Name = HP2 | Source = Service Control Manager | ID = 7026
Description =

Error - 8/23/2011 7:51:06 | Computer Name = HP2 | Source = Service Control Manager | ID = 7000
Description =

Error - 8/23/2011 7:51:07 | Computer Name = HP2 | Source = Service Control Manager | ID = 7022
Description =

Error - 8/23/2011 7:51:07 | Computer Name = HP2 | Source = Service Control Manager | ID = 7026
Description =


< End of report >
Download Combofix from either of the links below, and save it to your desktop.

Link 1
Link 2



**Note: It is important that it is saved directly to your desktop**

——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
——————————————————————–

Double click on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
Here goes the Combofix report:

ComboFix 11-08-23.05 - richtea 08/23/2011 22:15:50.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3002.1844 [GMT 2:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
FW: Privatefirewall *Disabled* {ADE53067-43C2-2B76-05F6-A92000CC501A}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
.
.
((((((((((((((((((((((((( Files Created from 2011-07-23 to 2011-08-23 )))))))))))))))))))))))))))))))
.
.
2011-08-23 20:22 . 2011-08-23 20:22 ——– d—–w- c:\users\LUA\AppData\Local\temp
2011-08-23 20:22 . 2011-08-23 20:22 ——– d—–w- c:\users\Default\AppData\Local\temp
2011-08-23 17:50 . 2011-08-23 17:50 28752 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C51AD3F3-FFDA-4F71-AC82-24655AF41ACF}\MpKslce3f91c8.sys
2011-08-23 17:50 . 2011-08-12 02:44 7152464 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C51AD3F3-FFDA-4F71-AC82-24655AF41ACF}\mpengine.dll
2011-08-19 21:28 . 2011-08-19 21:33 ——– d—–w- c:\users\richtea\AppData\Roaming\MusicBee
2011-08-19 21:25 . 2011-08-19 21:25 ——– d—–w- c:\program files\MusicBee
2011-08-19 17:46 . 2011-05-10 20:29 122760 —-a-w- c:\windows\system32\drivers\pwipf6.sys
2011-08-19 17:46 . 2011-08-19 17:46 ——– d—–w- c:\program files\Privacyware
2011-08-17 14:09 . 2011-08-17 14:09 ——– d—–w- c:\program files\Belarc
2011-08-12 19:09 . 2011-08-12 19:09 ——– d—–w- c:\windows\en
2011-08-12 19:07 . 2011-08-12 19:07 18328 —-a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-08-12 17:26 . 2011-01-31 21:44 439632 ——w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{91EB18C5-CE5F-42C0-B3E2-5C1379E05A9C}\gapaengine.dll
2011-08-10 11:20 . 2011-08-13 08:25 ——– d—–w- c:\users\LUA\AppData\Roaming\Notepad++
2011-08-09 20:39 . 2011-07-06 15:31 214016 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-08-09 20:39 . 2011-06-20 08:54 3602832 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-08-09 20:39 . 2011-06-20 08:54 3550096 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-08-09 20:39 . 2011-06-06 10:59 2409784 —-a-w- c:\program files\Windows Mail\OESpamFilter.dat
2011-08-09 20:39 . 2011-06-17 16:03 375808 —-a-w- c:\windows\system32\winsrv.dll
2011-08-09 20:38 . 2011-06-17 20:13 913296 —-a-w- c:\windows\system32\drivers\tcpip.sys
2011-08-09 20:38 . 2011-06-17 13:31 31232 —-a-w- c:\windows\system32\drivers\tcpipreg.sys
2011-08-03 17:56 . 2011-07-13 03:39 6881616 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Updates\mpengine.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-08-12 02:44 . 2010-02-09 10:02 7152464 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-08-03 18:21 . 2010-05-06 18:14 544656 —-a-w- c:\windows\system32\deployJava1.dll
2011-06-13 20:09 . 2011-06-13 20:09 65328 —-a-w- c:\windows\apppatch\matsshim.dll
2011-06-08 21:42 . 2011-06-08 21:42 0 —-a-w- c:\windows\system32\REN6DC1.tmp
2011-06-08 21:42 . 2011-06-08 21:42 0 —-a-w- c:\windows\system32\REN6DC0.tmp
2011-06-08 21:42 . 2011-06-08 21:42 0 —-a-w- c:\windows\system32\REN6DB0.tmp
2011-06-02 13:34 . 2011-07-14 15:41 2043392 —-a-w- c:\windows\system32\win32k.sys
2011-08-19 21:40 . 2011-06-23 13:37 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccleaner"="c:\program files\CCleaner\CCleaner.exe" [2011-07-25 2585408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-04-17 1049896]
"UpdateLBPShortCut"="c:\program files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" [2008-06-14 210216]
"UpdatePSTShortCut"="c:\program files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" [2008-10-07 210216]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-08-01 202032]
"UpdateP2GoShortCut"="c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2008-06-14 210216]
"UpdatePDIRShortCut"="c:\program files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" [2008-06-14 210216]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2008-04-15 488752]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-07-17 288080]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2009-03-10 468264]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2008-06-13 210216]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-02-11 137752]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-02-11 172568]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2011-05-15 325512]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2010-06-09 49208]
"Privatefirewall"="c:\program files\Privacyware\Privatefirewall 7.0\PFGUI.exe" [2011-07-18 3039280]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
R1 MpKsl0bcf6af9;MpKsl0bcf6af9;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7E97384B-B7C4-4A36-87BC-A90B9E9554AA}\MpKsl0bcf6af9.sys [x]
R1 MpKsl8cd0be31;MpKsl8cd0be31;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B3DD5DF6-F8C2-4F46-8604-0D6A493C38E1}\MpKsl8cd0be31.sys [x]
R1 MpKsle4fc0860;MpKsle4fc0860;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{475856F8-4FCF-4C38-B191-FB070594F824}\MpKsle4fc0860.sys [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 BBSvc;Bing Bar Update Service;c:\program files\Microsoft\BingBar\BBSvc.EXE [2011-02-28 183560]
R3 MatSvc;Microsoft Automated Troubleshooting Service;c:\program files\Microsoft Fix it Center\Matsvc.exe [2011-06-13 267568]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2011-04-27 65024]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 208944]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S0 FSProFilter;FSPro File Filter;c:\windows\System32\Drivers\FSPFltd.sys [2010-07-22 41912]
S1 MpKslce3f91c8;MpKslce3f91c8;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C51AD3F3-FFDA-4F71-AC82-24655AF41ACF}\MpKslce3f91c8.sys [2011-08-23 28752]
S1 pwipf6;Privacyware Filter Driver;c:\windows\system32\DRIVERS\pwipf6.sys [2011-05-10 122760]
S2 PFNet;Privacyware network service;c:\program files\Privacyware\Privatefirewall 7.0\pfsvc.exe [2011-07-18 377760]
S2 Recovery Service for Windows;Recovery Service for Windows;c:\program files\SMINST\BLService.exe [2008-10-06 365952]
S3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-04-03 193840]
S3 IntcHdmiAddService;Intel® High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [2008-06-29 112128]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2011-04-18 43392]
.
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - MPKSLCE3F91C8
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-08-20 20:24 451872 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
.
2011-08-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1764177258-2740290987-562837017-1000Core.job
- c:\users\richtea\AppData\Local\Google\Update\GoogleUpdate.exe [2009-11-06 22:38]
.
2011-08-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1764177258-2740290987-562837017-1000UA.job
- c:\users\richtea\AppData\Local\Google\Update\GoogleUpdate.exe [2009-11-06 22:38]
.
2011-08-06 c:\windows\Tasks\HPCeeScheduleForrichtea.job
- c:\program files\hewlett-packard\sdp\ceement\HPCEE.exe [2009-04-22 18:34]
.
.
——- Supplementary Scan ——-
.
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Pavilion&pf=cnnb
Trusted Zone: secunia.com
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\users\richtea\AppData\Roaming\Mozilla\Firefox\Profiles\fujsem93.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=WLETDF&PC=WLEM&q=
FF - prefs.js: browser.search.selectedEngine - Ixquick HTTPS
FF - prefs.js: browser.startup.homepage - hxxps://ixquick.com/do/mypage.pl?prf=b845979a027bafb57da89364487ca393
FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?FORM=WLETDF&PC=WLEM&q=
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-08-23 22:23
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2011-08-23 22:25:35
ComboFix-quarantined-files.txt 2011-08-23 20:25
.
Pre-Run: 198,373,580,800 bytes free
Post-Run: 198,306,070,528 bytes free
.
- - End Of File - - B407CCF4EAE47FED1AA9D024BDB15A03
COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    File:: 
    
    c:\windows\system32\REN6DC1.tmp
    c:\windows\system32\REN6DC0.tmp
    c:\windows\system32\REN6DB0.tmp
    
    DirLook::
    C:\Users\richtea\AppData\Local\{514D5BA7-4648-45FF-86CD-57EA709D1F4B}
    C:\Users\richtea\AppData\Local\{83739872-229D-48DA-A719-1F487DC48CF0}
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • If you need help to disable your protection programs see here.
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.










Please download Malwarebytes from Here or Here

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the log please










Next

Run the following scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.
LAN has been down for three days. As of today I am travelling, so will come back to the topic ca Sept. 5th. Please bear with me.
Thanks for waiting; now back to the chase & starting with the ComboFix log:

ComboFix 11-09-05.03 - richtea 09/05/2011 18:53:03.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3002.1877 [GMT 2:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\richtea\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
FW: Privatefirewall *Disabled* {ADE53067-43C2-2B76-05F6-A92000CC501A}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
.
FILE ::
"c:\windows\system32\REN6DB0.tmp"
"c:\windows\system32\REN6DC0.tmp"
"c:\windows\system32\REN6DC1.tmp"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\richtea\AppData\Local\ApplicationHistory
c:\users\richtea\AppData\Local\ApplicationHistory\csc.exe.3e4ac0af.ini
c:\users\richtea\AppData\Local\ApplicationHistory\hpqimvac.exe.eaba0dc5.ini.inuse
c:\users\richtea\AppData\Local\ApplicationHistory\hpqimzone.exe.979fd1e7.ini
c:\users\richtea\AppData\Local\ApplicationHistory\hpqthb08.exe.6aef8ac7.ini
c:\users\richtea\AppData\Local\ApplicationHistory\ngen.exe.2c05686e.ini
c:\windows\system32\REN6DB0.tmp
c:\windows\system32\REN6DC0.tmp
c:\windows\system32\REN6DC1.tmp
.
.
((((((((((((((((((((((((( Files Created from 2011-08-05 to 2011-09-05 )))))))))))))))))))))))))))))))
.
.
2011-09-05 17:03 . 2011-09-05 17:03 ——– d—–w- c:\users\LUA\AppData\Local\temp
2011-09-05 17:03 . 2011-09-05 17:03 ——– d—–w- c:\users\Guest\AppData\Local\temp
2011-09-05 17:03 . 2011-09-05 17:03 ——– d—–w- c:\users\Default\AppData\Local\temp
2011-09-05 16:37 . 2011-09-05 16:37 28752 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{2497FA9D-0674-4221-90C8-C83DC6819FD9}\MpKsl2aed0753.sys
2011-09-05 16:36 . 2011-08-12 02:44 7152464 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{2497FA9D-0674-4221-90C8-C83DC6819FD9}\mpengine.dll
2011-08-19 21:28 . 2011-08-19 21:33 ——– d—–w- c:\users\richtea\AppData\Roaming\MusicBee
2011-08-19 21:25 . 2011-08-19 21:25 ——– d—–w- c:\program files\MusicBee
2011-08-19 17:46 . 2011-05-10 20:29 122760 —-a-w- c:\windows\system32\drivers\pwipf6.sys
2011-08-19 17:46 . 2011-08-19 17:46 ——– d—–w- c:\program files\Privacyware
2011-08-17 14:09 . 2011-08-17 14:09 ——– d—–w- c:\program files\Belarc
2011-08-12 19:09 . 2011-08-12 19:09 ——– d—–w- c:\windows\en
2011-08-12 19:07 . 2011-08-12 19:07 18328 —-a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-08-12 17:26 . 2011-01-31 21:44 439632 ——w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{91EB18C5-CE5F-42C0-B3E2-5C1379E05A9C}\gapaengine.dll
2011-08-10 11:20 . 2011-08-13 08:25 ——– d—–w- c:\users\LUA\AppData\Roaming\Notepad++
2011-08-09 20:39 . 2011-07-06 15:31 214016 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-08-09 20:39 . 2011-06-20 08:54 3602832 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-08-09 20:39 . 2011-06-20 08:54 3550096 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-08-09 20:39 . 2011-06-06 10:59 2409784 —-a-w- c:\program files\Windows Mail\OESpamFilter.dat
2011-08-09 20:39 . 2011-06-17 16:03 375808 —-a-w- c:\windows\system32\winsrv.dll
2011-08-09 20:38 . 2011-06-17 20:13 913296 —-a-w- c:\windows\system32\drivers\tcpip.sys
2011-08-09 20:38 . 2011-06-17 13:31 31232 —-a-w- c:\windows\system32\drivers\tcpipreg.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-08-12 02:44 . 2010-02-09 10:02 7152464 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-08-03 18:21 . 2010-05-06 18:14 544656 —-a-w- c:\windows\system32\deployJava1.dll
2011-07-13 03:39 . 2011-08-03 17:56 6881616 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Updates\mpengine.dll
2011-06-13 20:09 . 2011-06-13 20:09 65328 —-a-w- c:\windows\apppatch\matsshim.dll
2011-08-19 21:40 . 2011-06-23 13:37 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
—- Directory of c:\users\richtea\AppData\Local\{514D5BA7-4648-45FF-86CD-57EA709D1F4B} —-
.
.
—- Directory of c:\users\richtea\AppData\Local\{83739872-229D-48DA-A719-1F487DC48CF0} —-
.
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccleaner"="c:\program files\CCleaner\CCleaner.exe" [2011-07-25 2585408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-04-17 1049896]
"UpdateLBPShortCut"="c:\program files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" [2008-06-14 210216]
"UpdatePSTShortCut"="c:\program files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" [2008-10-07 210216]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-08-01 202032]
"UpdateP2GoShortCut"="c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2008-06-14 210216]
"UpdatePDIRShortCut"="c:\program files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" [2008-06-14 210216]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2008-04-15 488752]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-07-17 288080]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2009-03-10 468264]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2008-06-13 210216]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-02-11 137752]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-02-11 172568]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2011-05-15 325512]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2010-06-09 49208]
"Privatefirewall"="c:\program files\Privacyware\Privatefirewall 7.0\PFGUI.exe" [2011-07-18 3039280]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
R1 MpKsl0bcf6af9;MpKsl0bcf6af9;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7E97384B-B7C4-4A36-87BC-A90B9E9554AA}\MpKsl0bcf6af9.sys [x]
R1 MpKsl8cd0be31;MpKsl8cd0be31;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B3DD5DF6-F8C2-4F46-8604-0D6A493C38E1}\MpKsl8cd0be31.sys [x]
R1 MpKsle4fc0860;MpKsle4fc0860;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{475856F8-4FCF-4C38-B191-FB070594F824}\MpKsle4fc0860.sys [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 BBSvc;Bing Bar Update Service;c:\program files\Microsoft\BingBar\BBSvc.EXE [2011-02-28 183560]
R3 MatSvc;Microsoft Automated Troubleshooting Service;c:\program files\Microsoft Fix it Center\Matsvc.exe [2011-06-13 267568]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2011-04-27 65024]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 208944]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S0 FSProFilter;FSPro File Filter;c:\windows\System32\Drivers\FSPFltd.sys [2010-07-22 41912]
S1 MpKsl2aed0753;MpKsl2aed0753;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{2497FA9D-0674-4221-90C8-C83DC6819FD9}\MpKsl2aed0753.sys [2011-09-05 28752]
S1 pwipf6;Privacyware Filter Driver;c:\windows\system32\DRIVERS\pwipf6.sys [2011-05-10 122760]
S2 PFNet;Privacyware network service;c:\program files\Privacyware\Privatefirewall 7.0\pfsvc.exe [2011-07-18 377760]
S2 Recovery Service for Windows;Recovery Service for Windows;c:\program files\SMINST\BLService.exe [2008-10-06 365952]
S3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-04-03 193840]
S3 IntcHdmiAddService;Intel® High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [2008-06-29 112128]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2011-04-18 43392]
.
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - MPKSL2AED0753
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-08-20 20:24 451872 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
.
2011-09-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1764177258-2740290987-562837017-1000Core.job
- c:\users\richtea\AppData\Local\Google\Update\GoogleUpdate.exe [2009-11-06 22:38]
.
2011-09-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1764177258-2740290987-562837017-1000UA.job
- c:\users\richtea\AppData\Local\Google\Update\GoogleUpdate.exe [2009-11-06 22:38]
.
2011-09-04 c:\windows\Tasks\HPCeeScheduleForrichtea.job
- c:\program files\hewlett-packard\sdp\ceement\HPCEE.exe [2009-04-22 18:34]
.
.
——- Supplementary Scan ——-
.
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Pavilion&pf=cnnb
Trusted Zone: secunia.com
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\users\richtea\AppData\Roaming\Mozilla\Firefox\Profiles\fujsem93.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=WLETDF&PC=WLEM&q=
FF - prefs.js: browser.search.selectedEngine - Ixquick HTTPS
FF - prefs.js: browser.startup.homepage - hxxps://ixquick.com/do/mypage.pl?prf=b845979a027bafb57da89364487ca393
FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?FORM=WLETDF&PC=WLEM&q=
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-09-05 19:03
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2011-09-05 19:12:14
ComboFix-quarantined-files.txt 2011-09-05 17:12
ComboFix2.txt 2011-08-23 20:25
.
Pre-Run: 195,917,053,952 bytes free
Post-Run: 195,879,858,176 bytes free
.
- - End Of File - - 1FD03156EBA1CA5689355AAD95FF8B93


***


MBAM log is clean:

Malwarebytes' Anti-Malware 1.51.1.1800
www.malwarebytes.org

Database version: 7658

Windows 6.0.6002 Service Pack 2
Internet Explorer 9.0.8112.16421

9/5/2011 19:57:13
mbam-log-2011-09-05 (19-57-13).txt

Scan type: Quick scan
Objects scanned: 200784
Time elapsed: 6 minute(s), 48 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

***

Sorry, but no ESET to round up with. I am having trouble to make it run. It fails to update during initialization stage, asking about proxy configuration (same result with IE and FF).
Quick-scanning with F-Secure; all clean: Scanning Report Wednesday, September 7, 2011 10:51:40 - 10:54:50 Computer name: HP2 Scanning type: Quick scan Target: System No malware found Statistics Scanned: Files: 3919 System: 3919 Not scanned: 0 Actions: Disinfected: 0 Renamed: 0 Deleted: 0 Not cleaned: 0 Submitted: 0 Options Scanning engines:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI