This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

ping.exe, iexplore.exe high cpu usage [Solved]

29 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello:

I recently was infected with the VISTA 2012 on my two computers. I was able to kind of clean them. My HP Pavillion a6130n, which is the reason for this posting, runs really slow AND many times a website opens up unrequested. Ping.exe and iexplore.exe run really high.

I am pasting the OTL and Extras files for your review. Thanks for the help!


OTL logfile created on: 12/24/2011 1:21:58 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\HP_Administrator\Desktop
Windows XP Media Center Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.94 Gb Total Physical Memory | 1.45 Gb Available Physical Memory | 74.79% Memory free
3.78 Gb Paging File | 3.31 Gb Available in Paging File | 87.54% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 224.03 Gb Total Space | 104.36 Gb Free Space | 46.58% Space Free | Partition Type: NTFS
Drive D: | 8.84 Gb Total Space | 0.93 Gb Free Space | 10.50% Space Free | Partition Type: FAT32
Drive K: | 298.09 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: NTFS

Computer Name: OFFICE | User Name: HP_Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/12/24 13:19:28 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\HP_Administrator\Desktop\OTL.exe
PRC - [2011/10/25 09:59:16 | 000,244,960 | —- | M] () – C:\Program Files\StartNow Toolbar\ToolbarUpdaterService.exe
PRC - [2011/09/08 14:15:09 | 000,161,664 | —- | M] (Oracle Corporation) – C:\Program Files\Java\jre7\bin\jqs.exe
PRC - [2011/08/31 17:00:48 | 000,449,608 | —- | M] (Malwarebytes Corporation) – C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2011/08/31 17:00:48 | 000,366,152 | —- | M] (Malwarebytes Corporation) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2009/09/25 23:32:18 | 000,189,736 | —- | M] (Seagate Technology LLC) – C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
PRC - [2009/09/25 23:31:32 | 000,185,640 | —- | M] (Seagate LLC) – C:\Program Files\Seagate\SeagateManager\FreeAgent Status\stxmenumgr.exe
PRC - [2006/11/19 00:38:26 | 000,036,903 | —- | M] (Hewlett-Packard) – C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
PRC - [2006/04/13 12:05:00 | 000,090,112 | —- | M] (Sonic Solutions) – C:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe
PRC - [2006/04/07 03:51:18 | 001,073,152 | —- | M] (Digital Interactive Systems Corporation) – C:\Program Files\DISC\DISCover.exe
PRC - [2006/04/07 03:50:22 | 000,065,536 | —- | M] (Digital Interactive Systems Corporation, Inc.) – C:\Program Files\DISC\DISCUpdMgr.exe
PRC - [2006/04/07 03:50:22 | 000,057,344 | —- | M] (Digital Interactive Systems Corporation, Inc.) – C:\Program Files\DISC\DiscStreamHub.exe
PRC - [2006/03/01 16:06:22 | 000,069,632 | —- | M] (Brother Industries, Ltd.) – C:\Program Files\Brother\Brmfcmon\BrMfcMon.exe
PRC - [2005/09/24 08:02:20 | 000,065,536 | —- | M] (Adobe Systems Incorporated) – C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
PRC - [2005/08/03 02:19:16 | 000,058,880 | —- | M] (Microsoft) – C:\WINDOWS\arservice.exe
PRC - [2004/08/09 23:00:00 | 001,032,192 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe


========== Modules (No Company Name) ==========

MOD - [2011/12/17 12:27:13 | 000,037,888 | —- | M] () – C:\WINDOWS\system32\xmlrpw32.dll
MOD - [2011/10/25 09:59:16 | 000,244,960 | —- | M] () – C:\Program Files\StartNow Toolbar\ToolbarUpdaterService.exe
MOD - [2011/09/27 06:23:00 | 000,087,912 | —- | M] () – C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/09/27 06:22:40 | 001,242,472 | —- | M] () – C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011/07/09 11:28:49 | 003,391,488 | —- | M] () – c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_dbf6c5b0\mscorlib.dll
MOD - [2011/07/09 11:28:46 | 000,835,584 | —- | M] () – c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_fc7fe484\system.drawing.dll
MOD - [2011/07/09 11:28:42 | 002,088,960 | —- | M] () – c:\windows\assembly\nativeimages1_v1.1.4322\system.xml\1.0.5000.0__b77a5c561934e089_b9fa2a8d\system.xml.dll
MOD - [2011/07/09 11:28:37 | 003,018,752 | —- | M] () – c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_3fb12b53\system.windows.forms.dll
MOD - [2011/07/09 11:28:31 | 001,966,080 | —- | M] () – c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_7e0e8d70\system.dll
MOD - [2011/07/09 11:28:26 | 001,265,664 | —- | M] () – c:\windows\assembly\gac\system.web\1.0.5000.0__b03f5f7f11d50a3a\system.web.dll
MOD - [2011/07/09 11:28:26 | 001,232,896 | —- | M] () – c:\windows\assembly\gac\system\1.0.5000.0__b77a5c561934e089\system.dll
MOD - [2011/02/04 16:48:30 | 000,291,840 | —- | M] () – C:\WINDOWS\system32\sbe.dll
MOD - [2010/02/05 13:14:43 | 001,291,776 | —- | M] () – C:\WINDOWS\system32\quartz.dll
MOD - [2008/06/20 12:41:10 | 000,245,248 | —- | M] () – \\?\globalroot\systemroot\system32\mswsock.dll
MOD - [2008/06/20 12:41:10 | 000,245,248 | —- | M] () – \\.\globalroot\systemroot\system32\mswsock.dll
MOD - [2006/11/19 00:38:24 | 000,151,589 | —- | M] () – C:\Program Files\Updates from HP\9972322\6.3.2.116-9972322\Program\bwfiles.dll
MOD - [2006/11/19 00:38:24 | 000,098,339 | —- | M] () – C:\Program Files\Updates from HP\9972322\6.3.2.116-9972322\Program\FrExt.dll
MOD - [2006/11/19 00:38:24 | 000,061,496 | —- | M] () – C:\Program Files\Updates from HP\9972322\6.3.2.116-9972322\Program\clntutil.dll
MOD - [2006/11/18 23:54:34 | 001,339,392 | —- | M] () – c:\windows\assembly\gac\system.xml\1.0.5000.0__b77a5c561934e089\system.xml.dll
MOD - [2006/11/18 23:54:33 | 002,052,096 | —- | M] () – c:\windows\assembly\gac\system.windows.forms\1.0.5000.0__b77a5c561934e089\system.windows.forms.dll
MOD - [2006/11/18 23:54:33 | 000,466,944 | —- | M] () – c:\windows\assembly\gac\system.drawing\1.0.5000.0__b03f5f7f11d50a3a\system.drawing.dll
MOD - [2006/11/18 23:54:32 | 000,573,440 | —- | M] () – c:\windows\assembly\gac\system.web.services\1.0.5000.0__b03f5f7f11d50a3a\system.web.services.dll
MOD - [2006/11/18 23:54:32 | 000,299,008 | —- | M] () – c:\windows\assembly\gac\microsoft.visualbasic\7.0.5000.0__b03f5f7f11d50a3a\microsoft.visualbasic.dll
MOD - [2006/11/18 23:54:32 | 000,241,664 | —- | M] () – c:\windows\assembly\gac\system.enterpriseservices\1.0.5000.0__b03f5f7f11d50a3a\system.enterpriseservices.dll
MOD - [2005/12/15 15:34:04 | 000,126,976 | —- | M] () – C:\Program Files\Updates from HP\9972322\Program\HPClientExt.dll
MOD - [2005/08/03 02:19:16 | 000,050,176 | —- | M] () – C:\WINDOWS\armcex.dll
MOD - [2004/08/09 23:00:00 | 000,059,904 | —- | M] () – C:\WINDOWS\system32\devenum.dll
MOD - [2004/08/09 23:00:00 | 000,014,336 | —- | M] () – C:\WINDOWS\system32\msdmo.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Auto | Stopped] – – (XMLProvS)
SRV - [2011/10/25 09:59:16 | 000,244,960 | —- | M] () [Auto | Running] – C:\Program Files\StartNow Toolbar\ToolbarUpdaterService.exe – (Updater Service for StartNow Toolbar)
SRV - [2011/09/08 14:15:09 | 000,161,664 | —- | M] (Oracle Corporation) [Auto | Running] – C:\Program Files\Java\jre7\bin\jqs.exe – (JavaQuickStarterService)
SRV - [2011/08/31 17:00:48 | 000,366,152 | —- | M] (Malwarebytes Corporation) [Auto | Running] – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe – (MBAMService)
SRV - [2009/09/25 23:32:18 | 000,189,736 | —- | M] (Seagate Technology LLC) [Auto | Running] – C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe – (FreeAgentGoNext Service)
SRV - [2005/08/03 02:19:16 | 000,058,880 | —- | M] (Microsoft) [Auto | Running] – C:\WINDOWS\arservice.exe – (ARSVC)


========== Driver Services (SafeList) ==========

DRV - [2011/08/31 17:00:50 | 000,022,216 | —- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] – C:\WINDOWS\system32\drivers\mbam.sys – (MBAMProtector)
DRV - [2006/06/14 13:04:12 | 004,299,264 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\RtkHDAud.sys – (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2006/03/03 17:31:04 | 000,013,056 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\nvnetbus.sys – (nvnetbus)
DRV - [2006/03/03 17:31:02 | 000,034,176 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\NVENETFD.sys – (NVENETFD)
DRV - [2005/12/12 19:27:00 | 000,019,072 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\PS2.sys – (Ps2)
DRV - [2005/12/06 13:20:50 | 000,241,664 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HSXHWBS2.sys – (HSXHWBS2)
DRV - [2005/12/06 13:20:40 | 000,936,448 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HSX_DP.sys – (HSX_DP)
DRV - [2005/06/29 19:03:18 | 000,175,104 | —- | M] (Promise Technology, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\ftsata2.sys – (ftsata2)
DRV - [2005/03/09 16:53:00 | 000,036,352 | —- | M] (Advanced Micro Devices) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\AmdK8.sys – (AmdK8)
DRV - [2004/08/09 23:00:00 | 000,074,752 | —- | M] () [Kernel | System | Running] – C:\WINDOWS\System32\drivers\ipsec.sys – (IPSec)
DRV - [2004/08/03 16:31:34 | 000,020,992 | —- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\RTL8139.sys – (rtl8139) Realtek RTL8139(A/B/C)
DRV - [2003/11/05 09:45:12 | 000,017,408 | —- | M] (Promise Technology, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\bb-run.sys – (bb-run)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://search.msn.com/spbasic.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.msn.com/?ocid=OIE8HP&PC;=B8DF
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?ocid=OIE8HP&PC;=B8DF
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2321: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.2.2379: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1483: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Netscape Browser 8.0.4.0\Extensions\\Components: C:\Program Files\Netscape\Netscape Browser\Components [2011/10/20 19:29:50 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Netscape Browser 8.0.4.0\Extensions\\Plugins: C:\Program Files\Netscape\Netscape Browser\Plugins [2011/10/20 19:30:17 | 000,000,000 | —D | M]


O1 HOSTS File: ([2011/12/24 12:40:22 | 000,439,132 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 127.0.0.1 123fporn.info
O1 - Hosts: 15125 more lines…
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (StartNow Toolbar Helper) - {6E13D095-45C3-4271-9475-F3B48227DD9F} - C:\Program Files\StartNow Toolbar\Toolbar32.dll ()
O2 - BHO: (hpWebHelper Class) - {AAAE832A-5FFF-4661-9C8F-369692D1DCB9} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\WebHelper.dll (Hewlett-Packard)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7018.1622\swg.dll (Google Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (StartNow Toolbar) - {5911488E-9D1E-40ec-8CBB-06B231CC153F} - C:\Program Files\StartNow Toolbar\Toolbar32.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [AlwaysReady Power Message APP] C:\WINDOWS\arpwrmsg.exe (Microsoft)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [DMAScheduler] c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe (Sonic Solutions)
O4 - HKLM..\Run: [ftutil2] C:\WINDOWS\System32\ftutil2.dll (Promise Technology, Inc.)
O4 - HKLM..\Run: [HPBootOp] C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [MaxMenuMgr] C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe (Seagate LLC)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [PCDrProfiler] File not found
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\Recguard.exe ()
O4 - HKLM..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl06a\BrStDvPt.exe (Brother Industories, Ltd.)
O4 - HKLM..\RunOnce: [SpybotDeletingA1104] C:\WINDOWS\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingA1117] C:\WINDOWS\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingA1231] C:\WINDOWS\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingA2232] C:\WINDOWS\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingA2457] C:\WINDOWS\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingA2813] C:\WINDOWS\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingA2845] C:\WINDOWS\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingA2867] C:\WINDOWS\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingA3031] C:\WINDOWS\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingA3074] C:\WINDOWS\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingA3089] C:\WINDOWS\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingA3173] C:\WINDOWS\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingA3342] C:\WINDOWS\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingA3390] C:\WINDOWS\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingA3557] C:\WINDOWS\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingA3943] C:\WINDOWS\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingA4166] C:\WINDOWS\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingA4341] C:\WINDOWS\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingA4350] C:\WINDOWS\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingA4390] C:\WINDOWS\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingA4449] C:\WINDOWS\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingA4816] C:\WINDOWS\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingA4918] C:\WINDOWS\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingA4950] C:\WINDOWS\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingA5233] C:\WINDOWS\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingA5347] C:\WINDOWS\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingA5449] C:\WINDOWS\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingA573] C:\WINDOWS\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingA6144] C:\WINDOWS\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingA6659] C:\WINDOWS\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingA681] C:\WINDOWS\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingA6813] C:\WINDOWS\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingA7066] C:\WINDOWS\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingA7086] C:\WINDOWS\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingA7170] C:\WINDOWS\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingA7179] C:\WINDOWS\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingA7306] C:\WINDOWS\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingA7314] C:\WINDOWS\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingA7583] C:\WINDOWS\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingA7627] C:\WINDOWS\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingA7735] C:\WINDOWS\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingA7759] C:\WINDOWS\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingA781] C:\WINDOWS\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingA7964] C:\WINDOWS\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingA8002] C:\WINDOWS\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingA8122] C:\WINDOWS\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingA839] C:\WINDOWS\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingA8447] C:\WINDOWS\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingA8471] C:\WINDOWS\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingA8621] C:\WINDOWS\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingA8659] C:\WINDOWS\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingA8751] C:\WINDOWS\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingA9015] C:\WINDOWS\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingA9256] C:\WINDOWS\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingA9554] C:\WINDOWS\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingA9688] C:\WINDOWS\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingA9713] C:\WINDOWS\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingA975] C:\WINDOWS\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingA9850] C:\WINDOWS\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingC1375] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC1690] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC1777] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC1804] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC1837] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC1848] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC1928] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC2366] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC255] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC258] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC2675] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC2704] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC2733] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC276] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC2863] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC3078] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC3117] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC3204] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC3216] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC3447] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC3564] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC383] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC3852] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC3995] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC412] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC4124] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC4269] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC4325] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC4573] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC4605] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC4765] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC4794] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC5147] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC5281] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC5294] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC5395] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC5397] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC5531] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC5574] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC5671] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC6106] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC6129] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC645] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC6689] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC6788] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC7002] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC730] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC7308] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC7689] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC8065] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC8159] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC8446] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC8470] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC9026] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC9129] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC959] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC9630] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC9631] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC9840] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [SpybotDeletingB1431] C:\WINDOWS\System32\command.com ()
O4 - HKCU..\RunOnce: [SpybotDeletingB1514] C:\WINDOWS\System32\command.com ()
O4 - HKCU..\RunOnce: [SpybotDeletingB1672] C:\WINDOWS\System32\command.com ()
O4 - HKCU..\RunOnce: [SpybotDeletingB1800] C:\WINDOWS\System32\command.com ()
O4 - HKCU..\RunOnce: [SpybotDeletingB1873] C:\WINDOWS\System32\command.com ()
O4 - HKCU..\RunOnce: [SpybotDeletingB2014] C:\WINDOWS\System32\command.com ()
O4 - HKCU..\RunOnce: [SpybotDeletingB2017] C:\WINDOWS\System32\command.com ()
O4 - HKCU..\RunOnce: [SpybotDeletingB2201] C:\WINDOWS\System32\command.com ()
O4 - HKCU..\RunOnce: [SpybotDeletingB2313] C:\WINDOWS\System32\command.com ()
O4 - HKCU..\RunOnce: [SpybotDeletingB2535] C:\WINDOWS\System32\command.com ()
O4 - HKCU..\RunOnce: [SpybotDeletingB2596] C:\WINDOWS\System32\command.com ()
O4 - HKCU..\RunOnce: [SpybotDeletingB262] C:\WINDOWS\System32\command.com ()
O4 - HKCU..\RunOnce: [SpybotDeletingB3000] C:\WINDOWS\System32\command.com ()
O4 - HKCU..\RunOnce: [SpybotDeletingB3075] C:\WINDOWS\System32\command.com ()
O4 - HKCU..\RunOnce: [SpybotDeletingB3225] C:\WINDOWS\System32\command.com ()
O4 - HKCU..\RunOnce: [SpybotDeletingB3286] C:\WINDOWS\System32\command.com ()
O4 - HKCU..\RunOnce: [SpybotDeletingB3383] C:\WINDOWS\System32\command.com ()
O4 - HKCU..\RunOnce: [SpybotDeletingB3389] C:\WINDOWS\System32\command.com ()
O4 - HKCU..\RunOnce: [SpybotDeletingB3583] C:\WINDOWS\System32\command.com ()
O4 - HKCU..\RunOnce: [SpybotDeletingB3592] C:\WINDOWS\System32\command.com ()
O4 - HKCU..\RunOnce: [SpybotDeletingB3796] C:\WINDOWS\System32\command.com ()
O4 - HKCU..\RunOnce: [SpybotDeletingB3883] C:\WINDOWS\System32\command.com ()
O4 - HKCU..\RunOnce: [SpybotDeletingB4183] C:\WINDOWS\System32\command.com ()
O4 - HKCU..\RunOnce: [SpybotDeletingB4305] C:\WINDOWS\System32\command.com ()
O4 - HKCU..\RunOnce: [SpybotDeletingB4400] C:\WINDOWS\System32\command.com ()
O4 - HKCU..\RunOnce: [SpybotDeletingB4519] C:\WINDOWS\System32\command.com ()
O4 - HKCU..\RunOnce: [SpybotDeletingB454] C:\WINDOWS\System32\command.com ()
O4 - HKCU..\RunOnce: [SpybotDeletingB4563] C:\WINDOWS\System32\command.com ()
O4 - HKCU..\RunOnce: [SpybotDeletingB4798] C:\WINDOWS\System32\command.com ()
O4 - HKCU..\RunOnce: [SpybotDeletingB4917] C:\WINDOWS\System32\command.com ()
O4 - HKCU..\RunOnce: [SpybotDeletingB5009] C:\WINDOWS\System32\command.com ()
O4 - HKCU..\RunOnce: [SpybotDeletingB5053] C:\WINDOWS\System32\command.com ()
O4 - HKCU..\RunOnce: [SpybotDeletingB5054] C:\WINDOWS\System32\command.com ()
O4 - HKCU..\RunOnce: [SpybotDeletingB513] C:\WINDOWS\System32\command.com ()
O4 - HKCU..\RunOnce: [SpybotDeletingB5351] C:\WINDOWS\System32\command.com ()
O4 - HKCU..\RunOnce: [SpybotDeletingB5650] C:\WINDOWS\System32\command.com ()
O4 - HKCU..\RunOnce: [SpybotDeletingB6366] C:\WINDOWS\System32\command.com ()
O4 - HKCU..\RunOnce: [SpybotDeletingB6423] C:\WINDOWS\System32\command.com ()
O4 - HKCU..\RunOnce: [SpybotDeletingB6434] C:\WINDOWS\System32\command.com ()
O4 - HKCU..\RunOnce: [SpybotDeletingB6454] C:\WINDOWS\System32\command.com ()
O4 - HKCU..\RunOnce: [SpybotDeletingB6701] C:\WINDOWS\System32\command.com ()
O4 - HKCU..\RunOnce: [SpybotDeletingB6816] C:\WINDOWS\System32\command.com ()
O4 - HKCU..\RunOnce: [SpybotDeletingB6817] C:\WINDOWS\System32\command.com ()
O4 - HKCU..\RunOnce: [SpybotDeletingB7178] C:\WINDOWS\System32\command.com ()
O4 - HKCU..\RunOnce: [SpybotDeletingB7241] C:\WINDOWS\System32\command.com ()
O4 - HKCU..\RunOnce: [SpybotDeletingB7390] C:\WINDOWS\System32\command.com ()
O4 - HKCU..\RunOnce: [SpybotDeletingB7481] C:\WINDOWS\System32\command.com ()
O4 - HKCU..\RunOnce: [SpybotDeletingB7885] C:\WINDOWS\System32\command.com ()
O4 - HKCU..\RunOnce: [SpybotDeletingB821] C:\WINDOWS\System32\command.com ()
O4 - HKCU..\RunOnce: [SpybotDeletingB8273] C:\WINDOWS\System32\command.com ()
O4 - HKCU..\RunOnce: [SpybotDeletingB8418] C:\WINDOWS\System32\command.com ()
O4 - HKCU..\RunOnce: [SpybotDeletingB8435] C:\WINDOWS\System32\command.com ()
O4 - HKCU..\RunOnce: [SpybotDeletingB8644] C:\WINDOWS\System32\command.com ()
O4 - HKCU..\RunOnce: [SpybotDeletingB8740] C:\WINDOWS\System32\command.com ()
O4 - HKCU..\RunOnce: [SpybotDeletingB8771] C:\WINDOWS\System32\command.com ()
O4 - HKCU..\RunOnce: [SpybotDeletingB8793] C:\WINDOWS\System32\command.com ()
O4 - HKCU..\RunOnce: [SpybotDeletingB939] C:\WINDOWS\System32\command.com ()
O4 - HKCU..\RunOnce: [SpybotDeletingB9407] C:\WINDOWS\System32\command.com ()
O4 - HKCU..\RunOnce: [SpybotDeletingB9795] C:\WINDOWS\System32\command.com ()
O4 - HKCU..\RunOnce: [SpybotDeletingD1295] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [SpybotDeletingD1532] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [SpybotDeletingD1616] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [SpybotDeletingD1669] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [SpybotDeletingD1752] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [SpybotDeletingD1925] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [SpybotDeletingD1942] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [SpybotDeletingD2021] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [SpybotDeletingD213] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [SpybotDeletingD2287] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [SpybotDeletingD2411] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [SpybotDeletingD2487] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [SpybotDeletingD2758] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [SpybotDeletingD2760] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [SpybotDeletingD315] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [SpybotDeletingD3339] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [SpybotDeletingD3507] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [SpybotDeletingD3712] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [SpybotDeletingD3758] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [SpybotDeletingD3915] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [SpybotDeletingD3970] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [SpybotDeletingD3991] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [SpybotDeletingD4026] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [SpybotDeletingD4288] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [SpybotDeletingD4382] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [SpybotDeletingD4478] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [SpybotDeletingD4614] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [SpybotDeletingD4743] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [SpybotDeletingD4885] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [SpybotDeletingD5000] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [SpybotDeletingD5297] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [SpybotDeletingD5515] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [SpybotDeletingD5690] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [SpybotDeletingD5762] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [SpybotDeletingD5861] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [SpybotDeletingD5986] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [SpybotDeletingD6100] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [SpybotDeletingD6370] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [SpybotDeletingD6377] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [SpybotDeletingD6453] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [SpybotDeletingD6522] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [SpybotDeletingD6683] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [SpybotDeletingD674] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [SpybotDeletingD6775] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [SpybotDeletingD6863] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [SpybotDeletingD7830] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [SpybotDeletingD7926] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [SpybotDeletingD8007] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [SpybotDeletingD8017] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [SpybotDeletingD8021] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [SpybotDeletingD808] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [SpybotDeletingD8268] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [SpybotDeletingD8674] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [SpybotDeletingD8945] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [SpybotDeletingD9033] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [SpybotDeletingD9088] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [SpybotDeletingD9103] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [SpybotDeletingD9472] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [SpybotDeletingD9984] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Updates From HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe (Hewlett-Packard)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ()
O9 - Extra 'Tools' menuitem : Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O15 - HKLM\..Trusted Domains: trymedia.com ([]http in Trusted sites)
O15 - HKLM\..Trusted Domains: trymedia.com ([]https in Trusted sites)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{892900FC-9814-4488-99C0-81491C1EE93D}: DhcpNameServer = [removed] [removed] [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AC282281-329A-4328-BB9B-677B1D041BDC}: DhcpNameServer = [removed] [removed]
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\xmlproservice: DllName - (xmlrpw32.dll) - C:\WINDOWS\System32\xmlrpw32.dll ()
O20 - Winlogon\Notify\xmlrpw32: DllName - (xmlrpw32.dll) - C:\WINDOWS\System32\xmlrpw32.dll ()
O24 - Desktop WallPaper: C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/11/19 00:34:17 | 000,000,100 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2001/07/27 15:07:38 | 000,000,000 | -HS- | M] () - D:\Autoexec.bat – [ FAT32 ]
O32 - AutoRun File - [2004/04/30 07:01:14 | 000,000,053 | -HS- | M] () - D:\Autorun.inf – [ FAT32 ]
O32 - AutoRun File - [2011/11/22 21:39:24 | 000,000,062 | —- | M] () - K:\Autorun.inf – [ NTFS ]
O33 - MountPoints2\{c4575899-d70e-11e0-a8cc-0018f3ddd6b4}\Shell\AutoRun\command - "" = M:\RunClubSanDisk.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found

========== Files/Folders - Created Within 30 Days ==========

[2011/12/24 13:19:42 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\HP_Administrator\Desktop\HiJackThis.exe
[2011/12/24 13:19:27 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\HP_Administrator\Desktop\OTL.exe
[2011/12/24 12:33:52 | 016,409,960 | —- | C] (Safer Networking Limited ) – C:\Documents and Settings\HP_Administrator\Desktop\setup-spybotsd162.exe
[2011/12/24 12:28:14 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Spybot - Search & Destroy
[2011/12/24 12:28:05 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2011/12/24 12:28:05 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2011/12/24 12:25:33 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Google
[2011/12/24 12:17:35 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Seagate
[2011/12/22 15:04:40 | 000,041,272 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/12/20 21:25:37 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2011/12/20 01:59:37 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Real
[2011/12/18 18:10:12 | 000,000,000 | R–D | C] – C:\Documents and Settings\HP_Administrator\Start Menu\Programs\Administrative Tools
[2011/12/17 20:17:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Threat Expert
[2011/12/17 17:59:54 | 000,000,000 | —D | C] – C:\Program Files\PC Tools
[2011/12/17 17:56:55 | 000,185,560 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\PCTSD.sys
[2011/12/17 17:56:55 | 000,000,000 | —D | C] – C:\Program Files\Common Files\PC Tools
[2011/12/17 17:53:00 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\TEMP
[2011/12/17 17:52:56 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\PC Tools
[2011/12/17 17:52:55 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Application Data\TestApp
[2011/12/15 14:15:02 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple Computer
[2011/12/15 12:30:14 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Sun
[2011/12/15 12:30:14 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Sun
[2011/12/15 12:14:30 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2011/12/15 12:13:57 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2011/12/10 18:07:59 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\My Documents\Pendrive-Nando
[2011/12/05 19:24:42 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\My Documents\dvd
[2011/12/05 19:20:34 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Application Data\DVD Flick
[2011/12/05 19:20:01 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\DVD Flick
[2011/12/05 19:19:58 | 000,040,960 | —- | C] (vbAccelerator) – C:\WINDOWS\System32\ssubtmr6.dll
[2011/12/05 19:19:58 | 000,036,864 | —- | C] (Robdogg Inc.) – C:\WINDOWS\System32\trayicon_handler.ocx
[2011/12/05 19:19:57 | 000,662,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mscomct2.ocx
[2011/12/05 19:19:57 | 000,212,240 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\richtx32.ocx
[2011/12/05 19:19:57 | 000,164,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\comct232.ocx
[2011/12/05 19:19:57 | 000,028,672 | —- | C] (-) – C:\WINDOWS\System32\mousewheel.ocx
[2011/12/05 19:19:57 | 000,000,000 | —D | C] – C:\Program Files\DVD Flick
[2011/12/05 18:42:31 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Start Menu\Programs\FoxTab Video Converter
[2011/12/05 18:42:30 | 000,000,000 | —D | C] – C:\Program Files\FoxTabVideoConverter
[2011/12/05 18:42:29 | 000,000,000 | —D | C] – C:\Program Files\StartNow Toolbar
[2011/12/04 17:51:31 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Desktop\New Folder
[2011/12/04 16:04:58 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Google Chrome
[2011/12/03 08:41:48 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Cucusoft Video Converter
[2011/12/03 08:41:47 | 000,060,273 | —- | C] (Open Source Software community project) – C:\WINDOWS\System32\pthreadGC2.dll
[2011/12/03 08:41:47 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Cucusoft
[2011/12/03 08:41:45 | 001,017,208 | —- | C] (CyberLink Corp.) – C:\WINDOWS\System32\CLVSD.ax
[2011/12/03 08:41:45 | 000,274,432 | —- | C] (Cucusoft Inc.) – C:\WINDOWS\System32\cdg.dll
[2011/12/03 08:41:45 | 000,110,592 | —- | C] (Cucusoft Inc.) – C:\WINDOWS\System32\PropListCtrl.ocx
[2011/12/03 08:41:44 | 000,000,000 | —D | C] – C:\Program Files\Cucusoft
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/12/24 13:24:53 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/12/24 13:19:43 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\HP_Administrator\Desktop\HiJackThis.exe
[2011/12/24 13:19:28 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\HP_Administrator\Desktop\OTL.exe
[2011/12/24 13:19:00 | 000,000,906 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/12/24 13:03:59 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At25.job
[2011/12/24 12:59:25 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At26.job
[2011/12/24 12:58:24 | 000,004,541 | —- | M] () – C:\WINDOWS\WININIT.INI
[2011/12/24 12:43:37 | 000,000,944 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\Spybot - Search & Destroy.lnk
[2011/12/24 12:42:00 | 016,409,960 | —- | M] (Safer Networking Limited ) – C:\Documents and Settings\HP_Administrator\Desktop\setup-spybotsd162.exe
[2011/12/24 12:40:22 | 000,439,132 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2011/12/24 12:17:36 | 000,001,874 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Seagate Manager.lnk
[2011/12/24 11:59:25 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At24.job
[2011/12/24 11:59:25 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At23.job
[2011/12/24 10:59:25 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At22.job
[2011/12/24 10:59:25 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At21.job
[2011/12/24 09:59:25 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At20.job
[2011/12/24 09:59:25 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At19.job
[2011/12/24 09:42:15 | 000,015,866 | -HS- | M] () – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\a6dd58p3yb2qyt
[2011/12/24 09:42:15 | 000,015,866 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\a6dd58p3yb2qyt
[2011/12/24 08:59:20 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At18.job
[2011/12/24 08:59:20 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At17.job
[2011/12/24 07:59:25 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At16.job
[2011/12/24 07:59:25 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At15.job
[2011/12/24 07:21:38 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At14.job
[2011/12/24 07:21:38 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At13.job
[2011/12/24 06:29:26 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At12.job
[2011/12/24 06:29:21 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At11.job
[2011/12/24 05:29:21 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At10.job
[2011/12/24 04:59:00 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At9.job
[2011/12/24 04:31:59 | 000,000,112 | —- | M] () – C:\Documents and Settings\All Users\Application Data\hgTGm6Gd.dat
[2011/12/24 04:31:58 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\mO8P6.com.b
[2011/12/24 04:31:57 | 000,079,872 | —- | M] () – C:\WINDOWS\System32\mO8P6.com_
[2011/12/24 04:25:18 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At8.job
[2011/12/24 04:25:18 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At6.job
[2011/12/24 04:25:18 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At48.job
[2011/12/24 04:25:18 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At46.job
[2011/12/24 04:25:18 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At44.job
[2011/12/24 04:25:18 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At42.job
[2011/12/24 04:25:18 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At40.job
[2011/12/24 04:25:18 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At4.job
[2011/12/24 04:25:18 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At38.job
[2011/12/24 04:25:18 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At36.job
[2011/12/24 04:25:18 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At34.job
[2011/12/24 04:25:18 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At32.job
[2011/12/24 04:25:18 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At30.job
[2011/12/24 04:25:18 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At28.job
[2011/12/24 04:25:18 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At2.job
[2011/12/24 04:25:18 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At7.job
[2011/12/24 04:25:18 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At5.job
[2011/12/24 04:25:18 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At47.job
[2011/12/24 04:25:18 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At45.job
[2011/12/24 04:25:18 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At43.job
[2011/12/24 04:25:18 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At41.job
[2011/12/24 04:25:18 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At39.job
[2011/12/24 04:25:18 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At37.job
[2011/12/24 04:25:18 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At35.job
[2011/12/24 04:25:18 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At33.job
[2011/12/24 04:25:18 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At31.job
[2011/12/24 04:25:18 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At3.job
[2011/12/24 04:25:18 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At29.job
[2011/12/24 04:25:18 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At27.job
[2011/12/24 04:25:18 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At1.job
[2011/12/23 21:46:23 | 000,000,183 | —- | M] () – C:\WINDOWS\System\hpsysdrv.DAT
[2011/12/23 21:45:07 | 000,043,531 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2011/12/23 21:45:06 | 000,000,902 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/12/23 21:45:04 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/12/23 21:45:02 | 2078,855,168 | -HS- | M] () – C:\hiberfil.sys
[2011/12/23 12:04:13 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/12/22 15:04:40 | 000,041,272 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/12/20 19:25:23 | 001,516,970 | —- | M] () – C:\WINDOWS\System32\drivers\Cat.DB
[2011/12/17 17:52:56 | 000,002,131 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\sdsetup[1].exe.lnk
[2011/12/17 17:36:11 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/12/17 12:31:15 | 000,103,365 | —- | M] () – C:\WINDOWS\System32\itusbcore.dat
[2011/12/17 12:31:15 | 000,000,197 | —- | M] () – C:\WINDOWS\System32\itlsvc.dat
[2011/12/17 12:27:13 | 000,037,888 | —- | M] () – C:\WINDOWS\System32\xmlrpw32.dll
[2011/12/15 12:20:35 | 000,001,824 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2011/12/05 19:20:01 | 000,001,588 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\DVD Flick.lnk
[2011/12/05 18:42:31 | 000,000,809 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\FoxTab Video Converter.lnk
[2011/12/04 16:04:59 | 000,001,802 | —- | M] () – C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/12/03 08:41:48 | 000,000,917 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Cucusoft DVD Ripper + Video Converter Ultimate.lnk
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/12/24 12:28:15 | 000,000,944 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\Spybot - Search & Destroy.lnk
[2011/12/24 12:17:36 | 000,001,874 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Seagate Manager.lnk
[2011/12/24 04:31:58 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\mO8P6.com.b
[2011/12/24 04:25:21 | 000,000,112 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hgTGm6Gd.dat
[2011/12/24 04:25:18 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At48.job
[2011/12/24 04:25:18 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At46.job
[2011/12/24 04:25:18 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At44.job
[2011/12/24 04:25:18 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At42.job
[2011/12/24 04:25:18 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At40.job
[2011/12/24 04:25:18 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At38.job
[2011/12/24 04:25:18 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At36.job
[2011/12/24 04:25:18 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At34.job
[2011/12/24 04:25:18 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At32.job
[2011/12/24 04:25:18 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At30.job
[2011/12/24 04:25:18 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At28.job
[2011/12/24 04:25:18 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At26.job
[2011/12/24 04:25:18 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At24.job
[2011/12/24 04:25:18 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At22.job
[2011/12/24 04:25:18 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At20.job
[2011/12/24 04:25:18 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At18.job
[2011/12/24 04:25:18 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At16.job
[2011/12/24 04:25:18 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At47.job
[2011/12/24 04:25:18 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At45.job
[2011/12/24 04:25:18 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At43.job
[2011/12/24 04:25:18 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At41.job
[2011/12/24 04:25:18 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At39.job
[2011/12/24 04:25:18 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At37.job
[2011/12/24 04:25:18 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At35.job
[2011/12/24 04:25:18 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At33.job
[2011/12/24 04:25:18 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At31.job
[2011/12/24 04:25:18 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At29.job
[2011/12/24 04:25:18 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At27.job
[2011/12/24 04:25:18 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At25.job
[2011/12/24 04:25:18 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At23.job
[2011/12/24 04:25:18 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At21.job
[2011/12/24 04:25:18 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At19.job
[2011/12/24 04:25:18 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At17.job
[2011/12/24 04:25:17 | 000,079,872 | —- | C] () – C:\WINDOWS\System32\mO8P6.com_
[2011/12/24 04:25:17 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At8.job
[2011/12/24 04:25:17 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At6.job
[2011/12/24 04:25:17 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At4.job
[2011/12/24 04:25:17 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At2.job
[2011/12/24 04:25:17 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At14.job
[2011/12/24 04:25:17 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At12.job
[2011/12/24 04:25:17 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At10.job
[2011/12/24 04:25:17 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At9.job
[2011/12/24 04:25:17 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At7.job
[2011/12/24 04:25:17 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At5.job
[2011/12/24 04:25:17 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At3.job
[2011/12/24 04:25:17 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At15.job
[2011/12/24 04:25:17 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At13.job
[2011/12/24 04:25:17 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At11.job
[2011/12/24 04:25:17 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At1.job
[2011/12/20 21:11:58 | 2078,855,168 | -HS- | C] () – C:\hiberfil.sys
[2011/12/17 17:57:02 | 001,516,970 | —- | C] () – C:\WINDOWS\System32\drivers\Cat.DB
[2011/12/17 17:52:56 | 000,002,131 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\sdsetup[1].exe.lnk
[2011/12/17 12:31:15 | 000,103,365 | —- | C] () – C:\WINDOWS\System32\itusbcore.dat
[2011/12/17 12:31:15 | 000,000,197 | —- | C] () – C:\WINDOWS\System32\itlsvc.dat
[2011/12/17 12:27:13 | 000,037,888 | —- | C] () – C:\WINDOWS\System32\xmlrpw32.dll
[2011/12/14 20:28:15 | 000,015,866 | -HS- | C] () – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\a6dd58p3yb2qyt
[2011/12/14 20:28:15 | 000,015,866 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\a6dd58p3yb2qyt
[2011/12/05 19:20:01 | 000,001,588 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\DVD Flick.lnk
[2011/12/05 18:42:31 | 000,000,809 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\FoxTab Video Converter.lnk
[2011/12/04 16:04:59 | 000,001,824 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2011/12/04 16:04:59 | 000,001,802 | —- | C] () – C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/12/03 08:41:48 | 000,000,917 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Cucusoft DVD Ripper + Video Converter Ultimate.lnk
[2011/12/03 08:41:47 | 000,094,854 | —- | C] () – C:\WINDOWS\System32\HKCU_GNU.reg
[2011/12/03 08:41:47 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2011/12/03 08:41:47 | 000,006,144 | —- | C] () – C:\WINDOWS\System32\ff_acm.acm
[2011/12/03 08:41:47 | 000,002,004 | —- | C] () – C:\WINDOWS\System32\HKLM_GNU.reg
[2011/12/03 08:41:45 | 000,372,736 | —- | C] () – C:\WINDOWS\System32\xvid.ax
[2011/12/03 08:41:45 | 000,348,160 | —- | C] () – C:\WINDOWS\System32\cdga.dll
[2011/12/03 08:41:45 | 000,014,909 | —- | C] () – C:\WINDOWS\System32\A_reg.reg
[2011/11/18 19:24:26 | 000,000,225 | —- | C] () – C:\WINDOWS\Brpfx04a.ini
[2011/11/18 19:24:26 | 000,000,093 | —- | C] () – C:\WINDOWS\brpcfx.ini
[2011/11/18 19:24:26 | 000,000,050 | —- | C] () – C:\WINDOWS\System32\bridf06a.dat
[2011/11/18 19:22:56 | 000,000,000 | —- | C] () – C:\WINDOWS\brdfxspd.dat
[2011/11/18 19:22:55 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\BrMuSNMP.dll
[2011/11/18 19:19:55 | 000,027,019 | —- | C] () – C:\WINDOWS\maxlink.ini
[2011/11/11 20:08:46 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/07/03 13:00:50 | 000,234,496 | —- | C] () – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/07/03 12:05:53 | 000,000,419 | —- | C] () – C:\WINDOWS\BRWMARK.INI
[2011/07/03 12:05:53 | 000,000,027 | —- | C] () – C:\WINDOWS\BRPP2KA.INI
[2011/07/03 11:50:47 | 000,000,139 | —- | C] () – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\fusioncache.dat
[2006/11/19 01:02:05 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/11/19 00:42:25 | 000,028,848 | —- | C] () – C:\WINDOWS\System32\drivers\USBkey.sys
[2006/11/19 00:38:24 | 000,118,842 | R— | C] () – C:\WINDOWS\HPCPCUninstaller-6.3.2.116-9972322.exe
[2006/11/19 00:37:35 | 000,014,318 | —- | C] () – C:\WINDOWS\System32\CHODDI.SYS
[2006/11/19 00:37:29 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\hpreg.dll
[2006/11/19 00:34:29 | 000,000,031 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2006/11/19 00:23:36 | 000,004,541 | —- | C] () – C:\WINDOWS\WININIT.INI
[2006/11/19 00:22:58 | 000,045,929 | —- | C] () – C:\WINDOWS\NSSetDefaultBrowser.EXE
[2006/11/19 00:22:58 | 000,000,698 | —- | C] () – C:\WINDOWS\NSSetDefaultBrowser.ini
[2006/11/19 00:18:15 | 000,095,822 | —- | C] () – C:\WINDOWS\hpqins69.dat
[2006/11/19 00:17:18 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2006/11/19 00:14:19 | 001,662,976 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2006/11/19 00:14:19 | 001,519,616 | —- | C] () – C:\WINDOWS\System32\nwiz.exe
[2006/11/19 00:14:19 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2006/11/19 00:14:18 | 001,466,368 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2006/11/19 00:14:18 | 001,339,392 | —- | C] () – C:\WINDOWS\System32\nvdspsch.exe
[2006/11/19 00:14:18 | 000,573,440 | —- | C] () – C:\WINDOWS\System32\nvhwvid.dll
[2006/11/19 00:14:18 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2006/11/19 00:14:18 | 000,442,368 | —- | C] () – C:\WINDOWS\System32\nvappbar.exe
[2006/11/19 00:14:18 | 000,425,984 | —- | C] () – C:\WINDOWS\System32\keystone.exe
[2006/11/19 00:14:18 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2006/11/19 00:14:18 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\nvapi.dll
[2006/11/19 00:13:08 | 000,000,791 | —- | C] () – C:\WINDOWS\orun32.ini
[2006/11/18 23:52:20 | 000,323,584 | —- | C] () – C:\WINDOWS\System32\pythoncom22.dll
[2006/11/18 23:52:20 | 000,094,208 | —- | C] () – C:\WINDOWS\System32\pywintypes22.dll
[2006/11/18 23:52:04 | 000,016,896 | —- | C] () – C:\WINDOWS\System32\bcbmm.dll
[2006/06/16 13:58:18 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2005/08/30 23:17:40 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2005/08/30 23:07:46 | 000,382,022 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2005/08/30 23:07:46 | 000,053,640 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2005/08/30 23:05:30 | 000,221,632 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2005/08/30 23:01:42 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2005/08/30 22:58:02 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2005/08/06 00:01:54 | 000,235,008 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2005/08/03 02:19:16 | 000,050,176 | —- | C] () – C:\WINDOWS\armcex.dll
[2004/09/16 22:24:26 | 003,375,104 | —- | C] () – C:\WINDOWS\System32\qt-mt331.dll
[2004/08/10 06:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/09 23:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/09 23:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/09 23:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/09 23:00:00 | 000,074,752 | —- | C] () – C:\WINDOWS\System32\drivers\ipsec.sys
[2004/08/09 23:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/09 23:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/09 23:00:00 | 000,027,440 | —- | C] () – C:\WINDOWS\System32\drivers\secdrv.sys
[2004/08/09 23:00:00 | 000,001,788 | —- | C] () – C:\WINDOWS\System32\Dcache.bin
[2004/08/09 23:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2004/07/26 09:51:38 | 000,000,560 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2002/03/04 10:16:34 | 000,110,592 | R— | C] () – C:\WINDOWS\System32\Jpeg32.dll
[2001/08/23 10:12:28 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2001/08/23 10:11:02 | 000,004,490 | —- | C] () – C:\WINDOWS\System32\oembios.dat

========== Alternate Data Streams ==========

@Alternate Data Stream - 155 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 133 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:430C6D84

< End of report >


OTL Extras logfile created on: 12/24/2011 1:21:58 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\HP_Administrator\Desktop
Windows XP Media Center Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.94 Gb Total Physical Memory | 1.45 Gb Available Physical Memory | 74.79% Memory free
3.78 Gb Paging File | 3.31 Gb Available in Paging File | 87.54% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 224.03 Gb Total Space | 104.36 Gb Free Space | 46.58% Space Free | Partition Type: NTFS
Drive D: | 8.84 Gb Total Space | 0.93 Gb Free Space | 10.50% Space Free | Partition Type: FAT32
Drive K: | 298.09 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: NTFS

Computer Name: OFFICE | User Name: HP_Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.exe [@ = exefile] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe" = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe:*:Enabled:Updates from HP – (Hewlett-Packard)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\DISC\DISCover.exe" = C:\Program Files\DISC\DISCover.exe:*:Enabled:DISCover Drop & Play System – (Digital Interactive Systems Corporation)
"C:\Program Files\DISC\DiscStreamHub.exe" = C:\Program Files\DISC\DiscStreamHub.exe:*:Enabled:DISCover Stream Hub – (Digital Interactive Systems Corporation, Inc.)
"C:\Program Files\DISC\myFTP.exe" = C:\Program Files\DISC\myFTP.exe:*:Enabled:DISCover FTP – (Digital Interactive Systems Corporation, Inc.)
"C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe" = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe:*:Enabled:Updates from HP – (Hewlett-Packard)
"C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" = C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink
"C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe" = C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit – (Apple Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{069730C2-755A-485B-A205-27A1AAFA836A}" = InstantShareAlert
"{075473F5-846A-448B-BCB3-104AA1760205}" = Sonic RecordNow Data
"{0A65A3BD-54B5-4d0d-B084-7688507813F5}" = SlideShow
"{1341D838-719C-4A05-B50F-49420CA1B4BB}" = HP Boot Optimizer
"{15C0AF59-4877-49B6-B8C6-A61CE54515F5}" = cp_OnlineProjectsConfig
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{21657574-BD54-48A2-9450-EB03B2C7FC29}" = Sonic MyDVD Plus
"{23012310-3E05-46A5-88A9-C6CBCABCAC79}" = Customer Experience Enhancement
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2376813B-2E5A-4641-B7B3-A0D5ADB55229}" = HPPhotoSmartExpress
"{26A24AE4-039D-4CA4-87B4-2F83217000FF}" = Java™ 7
"{29ED20C9-5E15-4969-9279-25BF3727A3DA}" = iTunes
"{2A30052B-831C-41D3-8044-3C0388066350}" = Seagate Manager Installer
"{2AEABBDC-89E6-4AE2-BF99-DA6D188D6F7C}" = LightScribe [removed]
"{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}" = HP Update
"{2F58D60D-2BFD-4467-9B4D-64E7355C329D}" = Sonic_PrimoSDK
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{32A3A4F4-B792-11D6-A78A-00B0D0170000}" = Java™ SE Development Kit 7
"{33BF0960-DBA3-4187-B6CC-C969FCFA2D25}" = SkinsHP1
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{36D620AD-EEBA-4973-BA86-0C9AE6396620}" = OptionalContentQFolder
"{3E4153AF-3D74-4062-8812-B1FDCE6B1F37}" = LEGO® MINDSTORMS® NXT - English Language Pack
"{416D80BA-6F6D-4672-B7CF-F54DA2F80B44}" = Microsoft Works
"{41E776A5-9B12-416D-9A12-B4F7B044EBED}" = CP_Package_Basic1
"{4246326C-E861-43CA-B47D-2357454385F9}" = LEGO® MINDSTORMS® NXT Software v1.0
"{45B8A76B-57EC-4242-B019-066400CD8428}" = BufferChm
"{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP DVD Play 2.1
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{53EE9E42-CECB-4C92-BF76-9CA65DAF8F1C}" = FullDPAppQFolder
"{5FDD0538-C67A-4F67-B3F8-09D1AAF04D99}" = muvee autoProducer unPlugged 2.0
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Sonic Express Labeler
"{6696D9A4-28A8-4F5A-8E9A-2E8974C8C39C}" = RandMap
"{71C97545-E547-4A8B-B0C8-61FF853270AC}" = PaperPort
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX
"{8105684D-8CA6-440D-8F58-7E5FD67A499D}" = Easy Internet Sign-up
"{82081779-4175-4666-A457-AB711CD37EF0}" = cp_LightScribeConfig
"{829DAAD6-BB11-4BB7-921B-07FFB703F944}" = CP_Package_Variety3
"{82E55892-6FFD-403F-AA97-D726846768AA}" = CP_AtenaShokunin1Config
"{866A0078-DEA7-4348-9C9A-999AF2991EAA}" = SlideShowMusic
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A534F71-3202-4464-A422-B767295E67B9}" = CP_Package_Variety2
"{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}" = Unload
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{93E5A317-24EC-4744-812C-16FECFE86E6A}" = CP_Package_Variety1
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}" = Brother MFL-Pro Suite
"{A00B9A50-3090-4CFF-9CDA-82DA0BEDAA21}" = Apple Mobile Device Support
"{A29800BA-0BF1-4E63-9F31-DF05A87F4104}" = InstantShareDevices
"{A83279FD-CA4B-4206-9535-90974DE76654}" = Apple Application Support
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Sonic RecordNow Audio
"{AC76BA86-7AD7-1033-7B44-A70500000002}" = Adobe Reader 7.0.5
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Sonic RecordNow Copy
"{B2157760-AA3C-4E2E-BFE6-D20BC52495D9}" = cp_PosterPrintConfig
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B6286A44-7505-471A-A72B-04EC2DB2F442}" = CueTour
"{B69CFE29-FD03-4E0A-87A7-6ED97F98E5B3}" = CP_Panorama1Config
"{B6EC7388-E277-4A5B-8C8F-71067A41BA64}" = TextPad 5
"{C1C6767D-B395-43CB-BF99-051B58B86DA6}" = PhotoGallery
"{C3FAA091-B278-44A7-BF48-190811C5F9F7}" = cp_UpdateProjectsConfig
"{C6579A65-9CAE-4B31-8B6B-3306E0630A66}" = Apple Software Update
"{C9E14402-3631-4182-B377-6B0DFB1C0339}" = QuickTime
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{DAAD5187-62C5-4AD6-A526-803C18C4944D}" = HP Web Helper
"{DB518BA6-CB74-4EB6-9ABD-880B6D6E1F38}" = HpSdpAppCoreApp
"{E14D4E88-DBBF-4AEE-A8EB-C4744E95EEEA}" = LEGO® MINDSTORMS® NXT Driver
"{ED2C557E-9C18-41FF-B58E-A05EEF0B3B5F}" = CP_CalendarTemplates1
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F80239D8-7811-4D5E-B033-0D0BBFE32920}" = HP DigitalMedia Archive
"{FB15E224-67C3-491F-9F5C-F257BC418412}" = Destinations
"{FB4740B3-2530-452D-A825-F7AB246CA7DF}" = muvee autoProducer 5.0
"12133444-BF36-4d4e-B7FB-A3424C645DE4" = GemMaster Mystic
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"AwayMode160" = Microsoft Away Mode
"B3EE3001-DC24-4cd1-8743-5692C716659F" = Otto
"CNXT_MODEM_PCI_VEN_14F1&DEV;_2F20&SUBSYS;_200C14F1" = Data Fax SoftModem with SmartCP
"Cucusoft Ultimate DVD + Video Converter Suite_is1" = Cucusoft Ultimate DVD + Video Converter Suite [removed]
"DISCover" = DISCover
"DVD Flick_is1" = DVD Flick 1.3.0.7
"Google Chrome" = Google Chrome
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"HP Imaging Device Functions" = HP Imaging Device Functions 7.0
"HP Photo & Imaging" = HP Photosmart Premier Software 6.5
"HP Photosmart for Media Center PC" = HP Photosmart for Media Center PC
"HPOOVClient-9972322 Uninstaller" = Updates from HP (remove only)
"ie8" = Windows Internet Explorer 8
"Install WeatherBug" = Remove WeatherBug Installer
"InstallShield_{23012310-3E05-46A5-88A9-C6CBCABCAC79}" = Customer Experience Enhancement
"InstallShield_{2A30052B-831C-41D3-8044-3C0388066350}" = Seagate Manager Installer
"InstallShield_{8105684D-8CA6-440D-8F58-7E5FD67A499D}" = Easy Internet Sign-up
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Money2006b" = Microsoft Money 2006
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Netscape Browser" = Netscape Browser (remove only)
"NVIDIA Drivers" = NVIDIA Drivers
"OfficeTrial" = Microsoft Office Standard Edition 2003 60 days trial
"PC-Doctor 5 for Windows" = PC-Doctor 5 for Windows
"Python 2.2.3" = Python 2.2.3
"pywin32-py2.2" = Python 2.2 pywin32 extensions (build 203)
"RealPlayer 6.0" = RealPlayer
"Rhapsody" = Rhapsody
"StartNow Toolbar" = StartNow Toolbar
"WildTangent hpmedia Master Uninstall" = My HP Games
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"FoxTab Video Converter" = FoxTab Video Converter

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 10/23/2011 3:43:39 AM | Computer Name = OFFICE | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 3922

Error - 10/23/2011 3:43:39 AM | Computer Name = OFFICE | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 3922

Error - 10/23/2011 4:04:40 AM | Computer Name = OFFICE | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 10/23/2011 4:04:40 AM | Computer Name = OFFICE | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 1264547

Error - 10/23/2011 4:04:40 AM | Computer Name = OFFICE | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 1264547

Error - 10/23/2011 4:04:42 AM | Computer Name = OFFICE | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 10/23/2011 4:04:42 AM | Computer Name = OFFICE | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 1266531

Error - 10/23/2011 4:04:42 AM | Computer Name = OFFICE | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 1266531

Error - 10/23/2011 4:24:53 AM | Computer Name = OFFICE | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 10/23/2011 4:24:53 AM | Computer Name = OFFICE | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 1953

[ System Events ]
Error - 12/23/2011 10:07:39 PM | Computer Name = OFFICE | Source = Service Control Manager | ID = 7023
Description = The Network ProService service terminated with the following error:
%%126

Error - 12/23/2011 10:07:41 PM | Computer Name = OFFICE | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 12/23/2011 10:07:49 PM | Computer Name = OFFICE | Source = Service Control Manager | ID = 7023
Description = The Network ProService service terminated with the following error:
%%126

Error - 12/23/2011 10:07:59 PM | Computer Name = OFFICE | Source = Service Control Manager | ID = 7023
Description = The Network ProService service terminated with the following error:
%%126

Error - 12/23/2011 10:10:09 PM | Computer Name = OFFICE | Source = Service Control Manager | ID = 7023
Description = The Network ProService service terminated with the following error:
%%126

Error - 12/23/2011 10:11:59 PM | Computer Name = OFFICE | Source = Service Control Manager | ID = 7023
Description = The Network ProService service terminated with the following error:
%%126

Error - 12/23/2011 10:22:59 PM | Computer Name = OFFICE | Source = Service Control Manager | ID = 7023
Description = The Network ProService service terminated with the following error:
%%126

Error - 12/23/2011 10:31:39 PM | Computer Name = OFFICE | Source = Service Control Manager | ID = 7023
Description = The Network ProService service terminated with the following error:
%%126

Error - 12/23/2011 10:33:09 PM | Computer Name = OFFICE | Source = Service Control Manager | ID = 7023
Description = The Network ProService service terminated with the following error:
%%126

Error - 12/23/2011 10:33:19 PM | Computer Name = OFFICE | Source = Service Control Manager | ID = 7023
Description = The Network ProService service terminated with the following error:
%%126


< End of report >
Hi fernipascual,

:welcome:

My name is NoodleTech. I would be glad to assist you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • Please be aware that removing malware is not without risk and while unrecoverable damage to systems is rare, it can happen and may require a re-format and re-install of your operating system. Because of this it is a good idea to back-up anything important saved on your computer.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Do not delete anything unless instructed to.
  • DO NOT use tools such as ComboFix without supervision.
  • Please continue to review my answers until I tell you your machine appears to be clean. Absence of symptoms does not mean that everything is clean.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
  • Failure to respond within 3 days will result in this topic being closed - If you need more time to complete the steps required, please let me know.
===================================================

Please download aswMBR.exe and save it to your desktop. 

Double click aswMBR.exe to start the tool. (Vista/Windows 7 users - right click to run as administrator)

Click Scan
  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review.
  • Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat.
  • Right click that file and select Send To>Compressed (zipped) file.
  • Attach that zipped file in your next reply as well.
===================================================

Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan.
    • If Malicious objects are found, DO NOT cure them.
    • Choose Skip then click on Continue.
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)
Thanks for your help! Just so you know my computer has been acting up and I did not see your response until today. I was looking for an e-mail alert in my e-mail account but I never received one. Other forums I belong to send e-mail alerts that somebody has responded. Between the time I posted the initial logs and today I've downloaded and installed Spybot Rearch & Destroy as well as AVG in hopes to be able to use the computer. It's been chaotic and I am hoping I can get it back to working to normal speed and that the unsolicited websites stop popping up! aswMBR version 0.9.9.1120 Copyright© 2011 AVAST Software Run date: 2011-12-26 16:46:55 —————————– 16:46:55.000 OS Version: Windows 5.1.2600 Service Pack 2 16:46:55.000 Number of processors: 2 586 0x4B02 16:46:55.000 ComputerName: OFFICE UserName: 16:46:58.984 Initialize success 16:47:36.406 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-e 16:47:36.406 Disk 0 Vendor: SAMSUNG_SP2504C VT100-49 Size: 238475MB BusType: 3 16:47:38.453 Disk 0 MBR read successfully 16:47:38.453 Disk 0 MBR scan 16:47:38.453 Disk 0 unknown MBR code 16:47:38.453 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 229404 MB offset 63 16:47:38.484 Disk 0 Partition 2 00 0C FAT32 LBA RECOVERY 9067 MB offset 469820925 16:47:38.484 Disk 0 scanning sectors +488392065 16:47:38.546 Disk 0 scanning C:\WINDOWS\system32\drivers 16:47:51.359 Service scanning 16:47:52.531 Modules scanning 16:47:56.281 Module: C:\WINDOWS\System32\Drivers\IPSec.SYS **SUSPICIOUS** 16:48:01.500 Disk 0 trace - called modules: 16:48:01.531 ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x894e5f10]<< 16:48:01.859 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a534ab8] 16:48:01.859 3 CLASSPNP.SYS[ba10905b] -> nt!IofCallDriver -> [0x8a081ea0] 16:48:01.859 \Driver\00001209[0x89566620] -> IRP_MJ_CREATE -> 0x894e5f10 16:48:01.859 Scan finished successfully 16:48:20.453 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\HP_Administrator\Desktop\MBR.dat" 16:48:20.453 The log file has been saved successfully to "C:\Documents and Settings\HP_Administrator\Desktop\aswMBR.txt" 16:50:09.0703 0316 TDSS rootkit removing tool 2.6.25.0 Dec 23 2011 14:51:16 16:50:10.0093 0316 ============================================================ 16:50:10.0093 0316 Current date / time: 2011/12/26 16:50:10.0093 16:50:10.0093 0316 SystemInfo: 16:50:10.0093 0316 16:50:10.0093 0316 OS Version: 5.1.2600 ServicePack: 2.0 16:50:10.0093 0316 Product type: Workstation 16:50:10.0093 0316 ComputerName: OFFICE 16:50:10.0093 0316 UserName: HP_Administrator 16:50:10.0093 0316 Windows directory: C:\WINDOWS 16:50:10.0093 0316 System windows directory: C:\WINDOWS 16:50:10.0093 0316 Processor architecture: Intel x86 16:50:10.0093 0316 Number of processors: 2 16:50:10.0093 0316 Page size: 0x1000 16:50:10.0093 0316 Boot type: Normal boot 16:50:10.0093 0316 ============================================================ 16:50:17.0531 0316 Initialize success 16:50:21.0984 3300 ============================================================ 16:50:21.0984 3300 Scan started 16:50:21.0984 3300 Mode: Manual; 16:50:21.0984 3300 ============================================================ 16:50:24.0609 3300 Abiosdsk - ok 16:50:24.0640 3300 abp480n5 - ok 16:50:24.0703 3300 ACPI (a10c7534f7223f4a73a948967d00e69b) C:\WINDOWS\system32\DRIVERS\ACPI.sys 16:50:24.0703 3300 ACPI - ok 16:50:24.0750 3300 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys 16:50:24.0750 3300 ACPIEC - ok 16:50:24.0765 3300 adpu160m - ok 16:50:24.0828 3300 aec (841f385c6cfaf66b58fbd898722bb4f0) C:\WINDOWS\system32\drivers\aec.sys 16:50:24.0859 3300 aec - ok 16:50:24.0906 3300 AFD (55e6e1c51b6d30e54335750955453702) C:\WINDOWS\System32\drivers\afd.sys 16:50:24.0906 3300 AFD - ok 16:50:24.0921 3300 Aha154x - ok 16:50:24.0937 3300 aic78u2 - ok 16:50:24.0953 3300 aic78xx - ok 16:50:24.0984 3300 AliIde - ok 16:50:25.0000 3300 AmdK8 (59301936898ae62245a6f09c0aba9475) C:\WINDOWS\system32\DRIVERS\AmdK8.sys 16:50:25.0000 3300 AmdK8 - ok 16:50:25.0015 3300 amsint - ok 16:50:25.0046 3300 aracpi (00523019e3579c8f8a94457fe25f0f24) C:\WINDOWS\system32\DRIVERS\aracpi.sys 16:50:25.0046 3300 aracpi - ok 16:50:25.0062 3300 arhidfltr (9fedaa46eb1a572ac4d9ee6b5f123cf2) C:\WINDOWS\system32\DRIVERS\arhidfltr.sys 16:50:25.0062 3300 arhidfltr - ok 16:50:25.0078 3300 arkbcfltr (82969576093cd983dd559f5a86f382b4) C:\WINDOWS\system32\DRIVERS\arkbcfltr.sys 16:50:25.0078 3300 arkbcfltr - ok 16:50:25.0187 3300 armoucfltr (9b21791d8a78faece999fadbebda6c22) C:\WINDOWS\system32\DRIVERS\armoucfltr.sys 16:50:25.0187 3300 armoucfltr - ok 16:50:25.0281 3300 Arp1394 (f0d692b0bffb46e30eb3cea168bbc49f) C:\WINDOWS\system32\DRIVERS\arp1394.sys 16:50:25.0281 3300 Arp1394 - ok 16:50:25.0296 3300 ARPolicy (7a2da7c7b0c524ef26a79f17a5c69fde) C:\WINDOWS\system32\DRIVERS\arpolicy.sys 16:50:25.0296 3300 ARPolicy - ok 16:50:25.0312 3300 asc - ok 16:50:25.0343 3300 asc3350p - ok 16:50:25.0359 3300 asc3550 - ok 16:50:25.0406 3300 AsyncMac (02000abf34af4c218c35d257024807d6) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 16:50:25.0421 3300 AsyncMac - ok 16:50:25.0453 3300 atapi (cdfe4411a69c224bd1d11b2da92dac51) C:\WINDOWS\system32\DRIVERS\atapi.sys 16:50:25.0453 3300 atapi - ok 16:50:25.0468 3300 Atdisk - ok 16:50:25.0515 3300 Atmarpc (ec88da854ab7d7752ec8be11a741bb7f) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 16:50:25.0515 3300 Atmarpc - ok 16:50:25.0531 3300 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 16:50:25.0531 3300 audstub - ok 16:50:25.0593 3300 AVGIDSDriver (4fa401b33c1b50c816486f6951244a14) C:\WINDOWS\system32\DRIVERS\AVGIDSDriver.Sys 16:50:25.0593 3300 AVGIDSDriver - ok 16:50:25.0625 3300 AVGIDSEH (69578bc9d43d614c6b3455db4af19762) C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys 16:50:25.0625 3300 AVGIDSEH - ok 16:50:25.0640 3300 AVGIDSFilter (6df528406aa22201f392b9b19121cd6f) C:\WINDOWS\system32\DRIVERS\AVGIDSFilter.Sys 16:50:25.0640 3300 AVGIDSFilter - ok 16:50:25.0671 3300 AVGIDSShim (1e01c2166b5599802bcd61b9691f7476) C:\WINDOWS\system32\DRIVERS\AVGIDSShim.Sys 16:50:25.0671 3300 AVGIDSShim - ok 16:50:25.0687 3300 Avgldx86 (bf8118cd5e2255387b715b534d64acd1) C:\WINDOWS\system32\DRIVERS\avgldx86.sys 16:50:25.0703 3300 Avgldx86 - ok 16:50:25.0734 3300 Avgmfx86 (1c77ef67f196466adc9924cb288afe87) C:\WINDOWS\system32\DRIVERS\avgmfx86.sys 16:50:25.0734 3300 Avgmfx86 - ok 16:50:25.0781 3300 Avgrkx86 (f2038ed7284b79dcef581468121192a9) C:\WINDOWS\system32\DRIVERS\avgrkx86.sys 16:50:25.0781 3300 Avgrkx86 - ok 16:50:25.0812 3300 Avgtdix (a6d562b612216d8d02a35ebeb92366bd) C:\WINDOWS\system32\DRIVERS\avgtdix.sys 16:50:25.0812 3300 Avgtdix - ok 16:50:25.0843 3300 bb-run (7270d070173b20ac9487ea16bb08b45f) C:\WINDOWS\system32\DRIVERS\bb-run.sys 16:50:25.0843 3300 bb-run - ok 16:50:25.0875 3300 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 16:50:25.0875 3300 Beep - ok 16:50:25.0937 3300 BrScnUsb (92a964547b96d697e5e9ed43b4297f5a) C:\WINDOWS\system32\DRIVERS\BrScnUsb.sys 16:50:25.0953 3300 BrScnUsb - ok 16:50:25.0984 3300 BrSerIf (d48c13f4a409aee8dafaddac81e34557) C:\WINDOWS\system32\Drivers\BrSerIf.sys 16:50:25.0984 3300 BrSerIf - ok 16:50:26.0000 3300 BrUsbSer (8fa0ac830a8312912a3aa0c0431cba0d) C:\WINDOWS\system32\Drivers\BrUsbSer.sys 16:50:26.0000 3300 BrUsbSer - ok 16:50:26.0031 3300 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 16:50:26.0031 3300 cbidf2k - ok 16:50:26.0062 3300 CCDECODE (6163ed60b684bab19d3352ab22fc48b2) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys 16:50:26.0062 3300 CCDECODE - ok 16:50:26.0078 3300 cd20xrnt - ok 16:50:26.0093 3300 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 16:50:26.0093 3300 Cdaudio - ok 16:50:26.0109 3300 Cdfs (cd7d5152df32b47f4e36f710b35aae02) C:\WINDOWS\system32\drivers\Cdfs.sys 16:50:26.0109 3300 Cdfs - ok 16:50:26.0156 3300 Cdrom (af9c19b3100fe010496b1a27181fbf72) C:\WINDOWS\system32\DRIVERS\cdrom.sys 16:50:26.0156 3300 Cdrom - ok 16:50:26.0171 3300 Changer - ok 16:50:26.0203 3300 CmdIde - ok 16:50:26.0234 3300 Cpqarray - ok 16:50:26.0250 3300 dac2w2k - ok 16:50:26.0265 3300 dac960nt - ok 16:50:26.0296 3300 Disk (00ca44e4534865f8a3b64f7c0984bff0) C:\WINDOWS\system32\DRIVERS\disk.sys 16:50:26.0296 3300 Disk - ok 16:50:26.0375 3300 dmboot (c0fbb516e06e243f0cf31f597e7ebf7d) C:\WINDOWS\system32\drivers\dmboot.sys 16:50:26.0390 3300 dmboot - ok 16:50:26.0421 3300 dmio (f5e7b358a732d09f4bcf2824b88b9e28) C:\WINDOWS\system32\drivers\dmio.sys 16:50:26.0421 3300 dmio - ok 16:50:26.0421 3300 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 16:50:26.0437 3300 dmload - ok 16:50:26.0453 3300 DMusic (a6f881284ac1150e37d9ae47ff601267) C:\WINDOWS\system32\drivers\DMusic.sys 16:50:26.0453 3300 DMusic - ok 16:50:26.0468 3300 dpti2o - ok 16:50:26.0515 3300 drmkaud (1ed4dbbae9f5d558dbba4cc450e3eb2e) C:\WINDOWS\system32\drivers\drmkaud.sys 16:50:26.0515 3300 drmkaud - ok 16:50:26.0531 3300 Fastfat (3117f595e9615e04f05a54fc15a03b20) C:\WINDOWS\system32\drivers\Fastfat.sys 16:50:26.0531 3300 Fastfat - ok 16:50:26.0546 3300 Fdc (ced2e8396a8838e59d8fd529c680e02c) C:\WINDOWS\system32\drivers\Fdc.sys 16:50:26.0546 3300 Fdc - ok 16:50:26.0562 3300 Fips (e153ab8a11de5452bcf5ac7652dbf3ed) C:\WINDOWS\system32\drivers\Fips.sys 16:50:26.0562 3300 Fips - ok 16:50:26.0578 3300 Flpydisk (0dd1de43115b93f4d85e889d7a86f548) C:\WINDOWS\system32\drivers\Flpydisk.sys 16:50:26.0578 3300 Flpydisk - ok 16:50:26.0593 3300 FltMgr (157754f0df355a9e0a6f54721914f9c6) C:\WINDOWS\system32\DRIVERS\fltMgr.sys 16:50:26.0593 3300 FltMgr - ok 16:50:26.0609 3300 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 16:50:26.0609 3300 Fs_Rec - ok 16:50:26.0625 3300 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 16:50:26.0625 3300 Ftdisk - ok 16:50:26.0640 3300 ftsata2 (22399d3ce5840c6082844679cca5d2fc) C:\WINDOWS\system32\DRIVERS\ftsata2.sys 16:50:26.0640 3300 ftsata2 - ok 16:50:26.0671 3300 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys 16:50:26.0671 3300 GEARAspiWDM - ok 16:50:26.0703 3300 Gpc (c0f1d4a21de5a415df8170616703debf) C:\WINDOWS\system32\DRIVERS\msgpc.sys 16:50:26.0703 3300 Gpc - ok 16:50:26.0718 3300 HDAudBus (3fcc124b6e08ee0e9351f717dd136939) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 16:50:26.0734 3300 HDAudBus - ok 16:50:26.0781 3300 HidUsb (1de6783b918f540149aa69943bdfeba8) C:\WINDOWS\system32\DRIVERS\hidusb.sys 16:50:26.0781 3300 HidUsb - ok 16:50:26.0812 3300 hpn - ok 16:50:26.0859 3300 HSXHWBS2 (1f5c64b0c6b2e2f48735a77ae714ccb8) C:\WINDOWS\system32\DRIVERS\HSXHWBS2.sys 16:50:26.0859 3300 HSXHWBS2 - ok 16:50:26.0890 3300 HSX_DP (a7f8c9228898a1e871d2ae7082f50ac3) C:\WINDOWS\system32\DRIVERS\HSX_DP.sys 16:50:26.0906 3300 HSX_DP - ok 16:50:26.0968 3300 HTTP (9f8b0f4276f618964fd118be4289b7cd) C:\WINDOWS\system32\Drivers\HTTP.sys 16:50:26.0968 3300 HTTP - ok 16:50:26.0984 3300 i2omgmt - ok 16:50:26.0984 3300 i2omp - ok 16:50:27.0062 3300 i8042prt (5502b58eef7486ee6f93f3f164dcb808) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 16:50:27.0062 3300 i8042prt - ok 16:50:27.0109 3300 Imapi (f8aa320c6a0409c0380e5d8a99d76ec6) C:\WINDOWS\system32\DRIVERS\imapi.sys 16:50:27.0125 3300 Imapi - ok 16:50:27.0125 3300 ini910u - ok 16:50:27.0265 3300 IntcAzAudAddService (ab2fe0faa519880bd16e4a0792d633d2) C:\WINDOWS\system32\drivers\RtkHDAud.sys 16:50:27.0359 3300 IntcAzAudAddService - ok 16:50:27.0390 3300 IntelIde (2d722b2b54ab55b2fa475eb58d7b2aad) C:\WINDOWS\system32\DRIVERS\intelide.sys 16:50:27.0390 3300 IntelIde - ok 16:50:27.0406 3300 intelppm - ok 16:50:27.0437 3300 Ip6Fw (4448006b6bc60e6c027932cfc38d6855) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys 16:50:27.0437 3300 Ip6Fw - ok 16:50:27.0468 3300 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 16:50:27.0468 3300 IpFilterDriver - ok 16:50:27.0468 3300 IpInIp (e1ec7f5da720b640cd8fb8424f1b14bb) C:\WINDOWS\system32\DRIVERS\ipinip.sys 16:50:27.0468 3300 IpInIp - ok 16:50:27.0500 3300 IpNat (b5a8e215ac29d24d60b4d1250ef05ace) C:\WINDOWS\system32\DRIVERS\ipnat.sys 16:50:27.0500 3300 IpNat - ok 16:50:27.0546 3300 IPSec (ea66d9a13e73b54f7e9ae34a0d835114) C:\WINDOWS\system32\drivers\IPSec.sys 16:50:27.0562 3300 IPSec - ok 16:50:27.0593 3300 IRENUM (50708daa1b1cbb7d6ac1cf8f56a24410) C:\WINDOWS\system32\DRIVERS\irenum.sys 16:50:27.0593 3300 IRENUM - ok 16:50:27.0609 3300 isapnp (e504f706ccb699c2596e9a3da1596e87) C:\WINDOWS\system32\DRIVERS\isapnp.sys 16:50:27.0609 3300 isapnp - ok 16:50:27.0656 3300 Kbdclass (ebdee8a2ee5393890a1acee971c4c246) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 16:50:27.0656 3300 Kbdclass - ok 16:50:27.0703 3300 kbdhid (e182fa8e49e8ee41b4adc53093f3c7e6) C:\WINDOWS\system32\DRIVERS\kbdhid.sys 16:50:27.0703 3300 kbdhid - ok 16:50:27.0734 3300 kmixer (d93cad07c5683db066b0b2d2d3790ead) C:\WINDOWS\system32\drivers\kmixer.sys 16:50:27.0734 3300 kmixer - ok 16:50:27.0765 3300 KSecDD (674d3e5a593475915dc6643317192403) C:\WINDOWS\system32\drivers\KSecDD.sys 16:50:27.0765 3300 KSecDD - ok 16:50:27.0781 3300 lbrtfdc - ok 16:50:27.0812 3300 MBAMProtector (69a6268d7f81e53d568ab4e7e991caf3) C:\WINDOWS\system32\drivers\mbam.sys 16:50:27.0812 3300 MBAMProtector - ok 16:50:27.0843 3300 MBAMSwissArmy - ok 16:50:27.0875 3300 mdmxsdk (e246a32c445056996074a397da56e815) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys 16:50:27.0875 3300 mdmxsdk - ok 16:50:27.0906 3300 MHNDRV (7f2f1d2815a6449d346fcccbc569fbd6) C:\WINDOWS\system32\DRIVERS\mhndrv.sys 16:50:27.0906 3300 MHNDRV - ok 16:50:27.0921 3300 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 16:50:27.0921 3300 mnmdd - ok 16:50:27.0953 3300 Modem (6fc6f9d7acc36dca9b914565a3aeda05) C:\WINDOWS\system32\drivers\Modem.sys 16:50:27.0953 3300 Modem - ok 16:50:27.0968 3300 Mouclass (34e1f0031153e491910e12551400192c) C:\WINDOWS\system32\DRIVERS\mouclass.sys 16:50:27.0968 3300 Mouclass - ok 16:50:28.0000 3300 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys 16:50:28.0000 3300 mouhid - ok 16:50:28.0000 3300 MountMgr (65653f3b4477f3c63e68a9659f85ee2e) C:\WINDOWS\system32\drivers\MountMgr.sys 16:50:28.0000 3300 MountMgr - ok 16:50:28.0015 3300 mraid35x - ok 16:50:28.0046 3300 MRxDAV (46edcc8f2db2f322c24f48785cb46366) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 16:50:28.0062 3300 MRxDAV - ok 16:50:28.0109 3300 MRxSmb (fb6c89bb3ce282b08bdb1e3c179e1c39) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 16:50:28.0125 3300 MRxSmb - ok 16:50:28.0125 3300 Msfs (561b3a4333ca2dbdba28b5b956822519) C:\WINDOWS\system32\drivers\Msfs.sys 16:50:28.0125 3300 Msfs - ok 16:50:28.0171 3300 MSKSSRV (ae431a8dd3c1d0d0610cdbac16057ad0) C:\WINDOWS\system32\drivers\MSKSSRV.sys 16:50:28.0171 3300 MSKSSRV - ok 16:50:28.0187 3300 MSPCLOCK (13e75fef9dfeb08eeded9d0246e1f448) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 16:50:28.0187 3300 MSPCLOCK - ok 16:50:28.0203 3300 MSPQM (1988a33ff19242576c3d0ef9ce785da7) C:\WINDOWS\system32\drivers\MSPQM.sys 16:50:28.0203 3300 MSPQM - ok 16:50:28.0234 3300 mssmbios (469541f8bfd2b32659d5d463a6714bce) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 16:50:28.0234 3300 mssmbios - ok 16:50:28.0281 3300 MSTEE (bf13612142995096ab084f2db7f40f77) C:\WINDOWS\system32\drivers\MSTEE.sys 16:50:28.0281 3300 MSTEE - ok 16:50:28.0296 3300 Mup (82035e0f41c2dd05ae41d27fe6cf7de1) C:\WINDOWS\system32\drivers\Mup.sys 16:50:28.0296 3300 Mup - ok 16:50:28.0312 3300 NABTSFEC (5c8dc6429c43dc6177c1fa5b76290d1a) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys 16:50:28.0312 3300 NABTSFEC - ok 16:50:28.0328 3300 NDIS (558635d3af1c7546d26067d5d9b6959e) C:\WINDOWS\system32\drivers\NDIS.sys 16:50:28.0328 3300 NDIS - ok 16:50:28.0343 3300 NdisIP (520ce427a8b298f54112857bcf6bde15) C:\WINDOWS\system32\DRIVERS\NdisIP.sys 16:50:28.0343 3300 NdisIP - ok 16:50:28.0375 3300 NdisTapi (08d43bbdacdf23f34d79e44ed35c1b4c) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 16:50:28.0375 3300 NdisTapi - ok 16:50:28.0406 3300 Ndisuio (eefa1ce63805d2145978621be5c6d955) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 16:50:28.0406 3300 Ndisuio - ok 16:50:28.0421 3300 NdisWan (0b90e255a9490166ab368cd55a529893) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 16:50:28.0421 3300 NdisWan - ok 16:50:28.0437 3300 NDProxy (59fc3fb44d2669bc144fd87826bb571f) C:\WINDOWS\system32\drivers\NDProxy.sys 16:50:28.0437 3300 NDProxy - ok 16:50:28.0453 3300 NetBIOS (3a2aca8fc1d7786902ca434998d7ceb4) C:\WINDOWS\system32\DRIVERS\netbios.sys 16:50:28.0453 3300 NetBIOS - ok 16:50:28.0484 3300 NetBT (0c80e410cd2f47134407ee7dd19cc86b) C:\WINDOWS\system32\DRIVERS\netbt.sys 16:50:28.0484 3300 NetBT - ok 16:50:28.0515 3300 NIC1394 (5c5c53db4fef16cf87b9911c7e8c6fbc) C:\WINDOWS\system32\DRIVERS\nic1394.sys 16:50:28.0515 3300 NIC1394 - ok 16:50:28.0531 3300 Npfs (4f601bcb8f64ea3ac0994f98fed03f8e) C:\WINDOWS\system32\drivers\Npfs.sys 16:50:28.0531 3300 Npfs - ok 16:50:28.0562 3300 Ntfs (b78be402c3f63dd55521f73876951cdd) C:\WINDOWS\system32\drivers\Ntfs.sys 16:50:28.0578 3300 Ntfs - ok 16:50:28.0625 3300 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 16:50:28.0640 3300 Null - ok 16:50:28.0734 3300 nv (642a87877f83313eb5302749cd479024) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 16:50:28.0796 3300 nv - ok 16:50:28.0812 3300 NVENETFD (22eedb34c4d7613a25b10c347c6c4c21) C:\WINDOWS\system32\DRIVERS\NVENETFD.sys 16:50:28.0812 3300 NVENETFD - ok 16:50:28.0843 3300 nvnetbus (5e3f6ad5cad0f12d3cccd06fd964087a) C:\WINDOWS\system32\DRIVERS\nvnetbus.sys 16:50:28.0843 3300 nvnetbus - ok 16:50:28.0890 3300 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 16:50:28.0890 3300 NwlnkFlt - ok 16:50:28.0890 3300 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 16:50:28.0890 3300 NwlnkFwd - ok 16:50:28.0953 3300 ohci1394 (0951db8e5823ea366b0e408d71e1ba2a) C:\WINDOWS\system32\DRIVERS\ohci1394.sys 16:50:28.0953 3300 ohci1394 - ok 16:50:29.0015 3300 Parport (29744eb4ce659dfe3b4122deb45bc478) C:\WINDOWS\system32\DRIVERS\parport.sys 16:50:29.0015 3300 Parport - ok 16:50:29.0031 3300 PartMgr (3334430c29dc338092f79c38ef7b4cd0) C:\WINDOWS\system32\drivers\PartMgr.sys 16:50:29.0046 3300 PartMgr - ok 16:50:29.0078 3300 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 16:50:29.0078 3300 ParVdm - ok 16:50:29.0078 3300 PCI (8086d9979234b603ad5bc2f5d890b234) C:\WINDOWS\system32\DRIVERS\pci.sys 16:50:29.0093 3300 PCI - ok 16:50:29.0093 3300 PCIDump - ok 16:50:29.0109 3300 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys 16:50:29.0109 3300 PCIIde - ok 16:50:29.0125 3300 Pcmcia (82a087207decec8456fbe8537947d579) C:\WINDOWS\system32\drivers\Pcmcia.sys 16:50:29.0125 3300 Pcmcia - ok 16:50:29.0156 3300 PDCOMP - ok 16:50:29.0156 3300 PDFRAME - ok 16:50:29.0171 3300 PDRELI - ok 16:50:29.0187 3300 PDRFRAME - ok 16:50:29.0203 3300 perc2 - ok 16:50:29.0203 3300 perc2hib - ok 16:50:29.0265 3300 PptpMiniport (1c5cc65aac0783c344f16353e60b72ac) C:\WINDOWS\system32\DRIVERS\raspptp.sys 16:50:29.0265 3300 PptpMiniport - ok 16:50:29.0281 3300 Processor (0d97d88720a4087ec93af7dbb303b30a) C:\WINDOWS\system32\DRIVERS\processr.sys 16:50:29.0281 3300 Processor - ok 16:50:29.0328 3300 Ps2 (390c204ced3785609ab24e9c52054a84) C:\WINDOWS\system32\DRIVERS\PS2.sys 16:50:29.0328 3300 Ps2 - ok 16:50:29.0328 3300 PSched (48671f327553dcf1d27f6197f622a668) C:\WINDOWS\system32\DRIVERS\psched.sys 16:50:29.0328 3300 PSched - ok 16:50:29.0343 3300 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 16:50:29.0343 3300 Ptilink - ok 16:50:29.0359 3300 PxHelp20 (97b735de4e3cd44c71c8cb09bdbf07b7) C:\WINDOWS\system32\Drivers\PxHelp20.sys 16:50:29.0359 3300 PxHelp20 - ok 16:50:29.0375 3300 ql1080 - ok 16:50:29.0390 3300 Ql10wnt - ok 16:50:29.0406 3300 ql12160 - ok 16:50:29.0421 3300 ql1240 - ok 16:50:29.0437 3300 ql1280 - ok 16:50:29.0468 3300 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 16:50:29.0468 3300 RasAcd - ok 16:50:29.0484 3300 Rasl2tp (98faeb4a4dcf812ba1c6fca4aa3e115c) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 16:50:29.0484 3300 Rasl2tp - ok 16:50:29.0500 3300 RasPppoe (7306eeed8895454cbed4669be9f79faa) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 16:50:29.0500 3300 RasPppoe - ok 16:50:29.0515 3300 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 16:50:29.0515 3300 Raspti - ok 16:50:29.0531 3300 Rdbss (809ca45caa9072b3176ad44579d7f688) C:\WINDOWS\system32\DRIVERS\rdbss.sys 16:50:29.0546 3300 Rdbss - ok 16:50:29.0562 3300 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 16:50:29.0562 3300 RDPCDD - ok 16:50:29.0578 3300 rdpdr (a2cae2c60bc37e0751ef9dda7ceaf4ad) C:\WINDOWS\system32\DRIVERS\rdpdr.sys 16:50:29.0593 3300 rdpdr - ok 16:50:29.0625 3300 RDPWD (d4f5643d7714ef499ae9527fdcd50894) C:\WINDOWS\system32\drivers\RDPWD.sys 16:50:29.0625 3300 RDPWD - ok 16:50:29.0671 3300 redbook (b31b4588e4086d8d84adbf9845c2402b) C:\WINDOWS\system32\DRIVERS\redbook.sys 16:50:29.0671 3300 redbook - ok 16:50:29.0718 3300 rtl8139 (d507c1400284176573224903819ffda3) C:\WINDOWS\system32\DRIVERS\RTL8139.SYS 16:50:29.0718 3300 rtl8139 - ok 16:50:29.0734 3300 Secdrv (d26e26ea516450af9d072635c60387f4) C:\WINDOWS\system32\DRIVERS\secdrv.sys 16:50:29.0734 3300 Secdrv - ok 16:50:29.0781 3300 Serial (cd9404d115a00d249f70a371b46d5a26) C:\WINDOWS\system32\drivers\Serial.sys 16:50:29.0781 3300 Serial - ok 16:50:29.0796 3300 Sfloppy (0d13b6df6e9e101013a7afb0ce629fe0) C:\WINDOWS\system32\drivers\Sfloppy.sys 16:50:29.0796 3300 Sfloppy - ok 16:50:29.0812 3300 Simbad - ok 16:50:29.0859 3300 SLIP (5caeed86821fa2c6139e32e9e05ccdc9) C:\WINDOWS\system32\DRIVERS\SLIP.sys 16:50:29.0859 3300 SLIP - ok 16:50:29.0875 3300 Sparrow - ok 16:50:29.0906 3300 splitter (8e186b8f23295d1e42c573b82b80d548) C:\WINDOWS\system32\drivers\splitter.sys 16:50:29.0906 3300 splitter - ok 16:50:29.0921 3300 sr (e41b6d037d6cd08461470af04500dc24) C:\WINDOWS\system32\DRIVERS\sr.sys 16:50:29.0937 3300 sr - ok 16:50:29.0984 3300 Srv (7a4f147cc6b133f905f6e65e2f8669fb) C:\WINDOWS\system32\DRIVERS\srv.sys 16:50:30.0000 3300 Srv - ok 16:50:30.0031 3300 streamip (284c57df5dc7abca656bc2b96a667afb) C:\WINDOWS\system32\DRIVERS\StreamIP.sys 16:50:30.0031 3300 streamip - ok 16:50:30.0062 3300 swenum (03c1bae4766e2450219d20b993d6e046) C:\WINDOWS\system32\DRIVERS\swenum.sys 16:50:30.0062 3300 swenum - ok 16:50:30.0078 3300 swmidi (94abc808fc4b6d7d2bbf42b85e25bb4d) C:\WINDOWS\system32\drivers\swmidi.sys 16:50:30.0078 3300 swmidi - ok 16:50:30.0093 3300 symc810 - ok 16:50:30.0109 3300 symc8xx - ok 16:50:30.0109 3300 sym_hi - ok 16:50:30.0125 3300 sym_u3 - ok 16:50:30.0140 3300 sysaudio (650ad082d46bac0e64c9c0e0928492fd) C:\WINDOWS\system32\drivers\sysaudio.sys 16:50:30.0140 3300 sysaudio - ok 16:50:30.0203 3300 Tcpip (2a5554fc5b1e04e131230e3ce035c3f9) C:\WINDOWS\system32\DRIVERS\tcpip.sys 16:50:30.0218 3300 Tcpip - ok 16:50:30.0250 3300 TDPIPE (38d437cf2d98965f239b0abcd66dcb0f) C:\WINDOWS\system32\drivers\TDPIPE.sys 16:50:30.0250 3300 TDPIPE - ok 16:50:30.0265 3300 TDTCP (ed0580af02502d00ad8c4c066b156be9) C:\WINDOWS\system32\drivers\TDTCP.sys 16:50:30.0265 3300 TDTCP - ok 16:50:30.0281 3300 TermDD (a540a99c281d933f3d69d55e48727f47) C:\WINDOWS\system32\DRIVERS\termdd.sys 16:50:30.0281 3300 TermDD - ok 16:50:30.0281 3300 TfFsMon - ok 16:50:30.0296 3300 TfNetMon - ok 16:50:30.0312 3300 TFSysMon - ok 16:50:30.0328 3300 TosIde - ok 16:50:30.0359 3300 Udfs (12f70256f140cd7d52c58c7048fde657) C:\WINDOWS\system32\drivers\Udfs.sys 16:50:30.0359 3300 Udfs - ok 16:50:30.0375 3300 ultra - ok 16:50:30.0390 3300 Update (aff2e5045961bbc0a602bb6f95eb1345) C:\WINDOWS\system32\DRIVERS\update.sys 16:50:30.0390 3300 Update - ok 16:50:30.0453 3300 USBAAPL (83cafcb53201bbac04d822f32438e244) C:\WINDOWS\system32\Drivers\usbaapl.sys 16:50:30.0453 3300 USBAAPL - ok 16:50:30.0531 3300 usbaudio (45a0d14b26c35497ad93bce7e15c9941) C:\WINDOWS\system32\drivers\usbaudio.sys 16:50:30.0531 3300 usbaudio - ok 16:50:30.0546 3300 usbccgp (bffd9f120cc63bcbaa3d840f3eef9f79) C:\WINDOWS\system32\DRIVERS\usbccgp.sys 16:50:30.0562 3300 usbccgp - ok 16:50:30.0578 3300 usbehci (7481d843e672b51039b7e8a161b746b8) C:\WINDOWS\system32\DRIVERS\usbehci.sys 16:50:30.0578 3300 usbehci - ok 16:50:30.0593 3300 usbhub (c72f40947f92cea56a8fb532edf025f1) C:\WINDOWS\system32\DRIVERS\usbhub.sys 16:50:30.0593 3300 usbhub - ok 16:50:30.0609 3300 usbohci (bdfe799a8531bad8a5a985821fe78760) C:\WINDOWS\system32\DRIVERS\usbohci.sys 16:50:30.0609 3300 usbohci - ok 16:50:30.0625 3300 usbprint (a42369b7cd8886cd7c70f33da6fcbcf5) C:\WINDOWS\system32\DRIVERS\usbprint.sys 16:50:30.0625 3300 usbprint - ok 16:50:30.0656 3300 usbscan (a6bc71402f4f7dd5b77fd7f4a8ddba85) C:\WINDOWS\system32\DRIVERS\usbscan.sys 16:50:30.0656 3300 usbscan - ok 16:50:30.0671 3300 usbstor (6cd7b22193718f1d17a47a1cd6d37e75) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 16:50:30.0671 3300 usbstor - ok 16:50:30.0687 3300 usbuhci (f8fd1400092e23c8f2f31406ef06167b) C:\WINDOWS\system32\DRIVERS\usbuhci.sys 16:50:30.0687 3300 usbuhci - ok 16:50:30.0703 3300 usbvideo (8968ff3973a883c49e8b564200f565b9) C:\WINDOWS\system32\Drivers\usbvideo.sys 16:50:30.0703 3300 usbvideo - ok 16:50:30.0734 3300 VgaSave (8a60edd72b4ea5aea8202daf0e427925) C:\WINDOWS\System32\drivers\vga.sys 16:50:30.0734 3300 VgaSave - ok 16:50:30.0750 3300 ViaIde (59cb1338ad3654417bea49636457f65d) C:\WINDOWS\system32\DRIVERS\viaide.sys 16:50:30.0750 3300 ViaIde - ok 16:50:30.0765 3300 VolSnap (ee4660083deba849ff6c485d944b379b) C:\WINDOWS\system32\drivers\VolSnap.sys 16:50:30.0765 3300 VolSnap - ok 16:50:30.0796 3300 Wanarp (984ef0b9788abf89974cfed4bfbaacbc) C:\WINDOWS\system32\DRIVERS\wanarp.sys 16:50:30.0796 3300 Wanarp - ok 16:50:30.0812 3300 WDICA - ok 16:50:30.0843 3300 wdmaud (2797f33ebf50466020c430ee4f037933) C:\WINDOWS\system32\drivers\wdmaud.sys 16:50:30.0843 3300 wdmaud - ok 16:50:30.0875 3300 winachsx (11ec1afceb5c917ce73d3c301ff4291e) C:\WINDOWS\system32\DRIVERS\HSX_CNXT.sys 16:50:30.0890 3300 winachsx - ok 16:50:30.0937 3300 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys 16:50:30.0937 3300 WS2IFSL - ok 16:50:30.0968 3300 WSTCODEC (d5842484f05e12121c511aa93f6439ec) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS 16:50:30.0968 3300 WSTCODEC - ok 16:50:31.0000 3300 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys 16:50:31.0000 3300 WudfPf - ok 16:50:31.0031 3300 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys 16:50:31.0031 3300 WudfRd - ok 16:50:31.0062 3300 MBR (0x1B8) (d11c727e03bb7318dcda069b06e652f0) \Device\Harddisk0\DR0 16:50:31.0109 3300 \Device\Harddisk0\DR0 - ok 16:50:31.0125 3300 MBR (0x1B8) (5fb38429d5d77768867c76dcbdb35194) \Device\Harddisk1\DR3 16:50:31.0125 3300 \Device\Harddisk1\DR3 - ok 16:50:31.0140 3300 Boot (0x1200) (58ca19a01360261197492d6f4579b419) \Device\Harddisk0\DR0\Partition0 16:50:31.0140 3300 \Device\Harddisk0\DR0\Partition0 - ok 16:50:31.0140 3300 Boot (0x1200) (dc84b485ed600b68b38eb0ba56352687) \Device\Harddisk0\DR0\Partition1 16:50:31.0140 3300 \Device\Harddisk0\DR0\Partition1 - ok 16:50:31.0156 3300 Boot (0x1200) (e9d795123a5e2ac7670169335ebe5c33) \Device\Harddisk1\DR3\Partition0 16:50:31.0156 3300 \Device\Harddisk1\DR3\Partition0 - ok 16:50:31.0156 3300 ============================================================ 16:50:31.0156 3300 Scan finished 16:50:31.0156 3300 ============================================================ 16:50:31.0171 1440 Detected object count: 0 16:50:31.0171 1440 Actual detected object count: 0 16:50:40.0734 2904 ============================================================ 16:50:40.0734 2904 Scan started 16:50:40.0734 2904 Mode: Manual; 16:50:40.0734 2904 ============================================================ 16:50:41.0203 2904 Abiosdsk - ok 16:50:41.0203 2904 abp480n5 - ok 16:50:41.0234 2904 ACPI (a10c7534f7223f4a73a948967d00e69b) C:\WINDOWS\system32\DRIVERS\ACPI.sys 16:50:41.0250 2904 ACPI - ok 16:50:41.0281 2904 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys 16:50:41.0281 2904 ACPIEC - ok 16:50:41.0281 2904 adpu160m - ok 16:50:41.0328 2904 aec (841f385c6cfaf66b58fbd898722bb4f0) C:\WINDOWS\system32\drivers\aec.sys 16:50:41.0328 2904 aec - ok 16:50:41.0375 2904 AFD (55e6e1c51b6d30e54335750955453702) C:\WINDOWS\System32\drivers\afd.sys 16:50:41.0375 2904 AFD - ok 16:50:41.0390 2904 Aha154x - ok 16:50:41.0406 2904 aic78u2 - ok 16:50:41.0406 2904 aic78xx - ok 16:50:41.0421 2904 AliIde - ok 16:50:41.0453 2904 AmdK8 (59301936898ae62245a6f09c0aba9475) C:\WINDOWS\system32\DRIVERS\AmdK8.sys 16:50:41.0453 2904 AmdK8 - ok 16:50:41.0453 2904 amsint - ok 16:50:41.0500 2904 aracpi (00523019e3579c8f8a94457fe25f0f24) C:\WINDOWS\system32\DRIVERS\aracpi.sys 16:50:41.0500 2904 aracpi - ok 16:50:41.0531 2904 arhidfltr (9fedaa46eb1a572ac4d9ee6b5f123cf2) C:\WINDOWS\system32\DRIVERS\arhidfltr.sys 16:50:41.0531 2904 arhidfltr - ok 16:50:41.0546 2904 arkbcfltr (82969576093cd983dd559f5a86f382b4) C:\WINDOWS\system32\DRIVERS\arkbcfltr.sys 16:50:41.0546 2904 arkbcfltr - ok 16:50:41.0562 2904 armoucfltr (9b21791d8a78faece999fadbebda6c22) C:\WINDOWS\system32\DRIVERS\armoucfltr.sys 16:50:41.0562 2904 armoucfltr - ok 16:50:41.0593 2904 Arp1394 (f0d692b0bffb46e30eb3cea168bbc49f) C:\WINDOWS\system32\DRIVERS\arp1394.sys 16:50:41.0593 2904 Arp1394 - ok 16:50:41.0656 2904 ARPolicy (7a2da7c7b0c524ef26a79f17a5c69fde) C:\WINDOWS\system32\DRIVERS\arpolicy.sys 16:50:41.0656 2904 ARPolicy - ok 16:50:41.0687 2904 asc - ok 16:50:41.0703 2904 asc3350p - ok 16:50:41.0718 2904 asc3550 - ok 16:50:41.0765 2904 AsyncMac (02000abf34af4c218c35d257024807d6) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 16:50:41.0765 2904 AsyncMac - ok 16:50:41.0781 2904 atapi (cdfe4411a69c224bd1d11b2da92dac51) C:\WINDOWS\system32\DRIVERS\atapi.sys 16:50:41.0796 2904 atapi - ok 16:50:41.0796 2904 Atdisk - ok 16:50:41.0828 2904 Atmarpc (ec88da854ab7d7752ec8be11a741bb7f) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 16:50:41.0828 2904 Atmarpc - ok 16:50:41.0843 2904 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 16:50:41.0843 2904 audstub - ok 16:50:41.0890 2904 AVGIDSDriver (4fa401b33c1b50c816486f6951244a14) C:\WINDOWS\system32\DRIVERS\AVGIDSDriver.Sys 16:50:41.0906 2904 AVGIDSDriver - ok 16:50:41.0921 2904 AVGIDSEH (69578bc9d43d614c6b3455db4af19762) C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys 16:50:41.0921 2904 AVGIDSEH - ok 16:50:41.0937 2904 AVGIDSFilter (6df528406aa22201f392b9b19121cd6f) C:\WINDOWS\system32\DRIVERS\AVGIDSFilter.Sys 16:50:41.0937 2904 AVGIDSFilter - ok 16:50:41.0953 2904 AVGIDSShim (1e01c2166b5599802bcd61b9691f7476) C:\WINDOWS\system32\DRIVERS\AVGIDSShim.Sys 16:50:41.0953 2904 AVGIDSShim - ok 16:50:42.0015 2904 Avgldx86 (bf8118cd5e2255387b715b534d64acd1) C:\WINDOWS\system32\DRIVERS\avgldx86.sys 16:50:42.0015 2904 Avgldx86 - ok 16:50:42.0015 2904 Avgmfx86 (1c77ef67f196466adc9924cb288afe87) C:\WINDOWS\system32\DRIVERS\avgmfx86.sys 16:50:42.0015 2904 Avgmfx86 - ok 16:50:42.0046 2904 Avgrkx86 (f2038ed7284b79dcef581468121192a9) C:\WINDOWS\system32\DRIVERS\avgrkx86.sys 16:50:42.0046 2904 Avgrkx86 - ok 16:50:42.0093 2904 Avgtdix (a6d562b612216d8d02a35ebeb92366bd) C:\WINDOWS\system32\DRIVERS\avgtdix.sys 16:50:42.0093 2904 Avgtdix - ok 16:50:42.0109 2904 bb-run (7270d070173b20ac9487ea16bb08b45f) C:\WINDOWS\system32\DRIVERS\bb-run.sys 16:50:42.0109 2904 bb-run - ok 16:50:42.0125 2904 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 16:50:42.0125 2904 Beep - ok 16:50:42.0187 2904 BrScnUsb (92a964547b96d697e5e9ed43b4297f5a) C:\WINDOWS\system32\DRIVERS\BrScnUsb.sys 16:50:42.0187 2904 BrScnUsb - ok 16:50:42.0218 2904 BrSerIf (d48c13f4a409aee8dafaddac81e34557) C:\WINDOWS\system32\Drivers\BrSerIf.sys 16:50:42.0218 2904 BrSerIf - ok 16:50:42.0250 2904 BrUsbSer (8fa0ac830a8312912a3aa0c0431cba0d) C:\WINDOWS\system32\Drivers\BrUsbSer.sys 16:50:42.0250 2904 BrUsbSer - ok 16:50:42.0265 2904 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 16:50:42.0265 2904 cbidf2k - ok 16:50:42.0296 2904 CCDECODE (6163ed60b684bab19d3352ab22fc48b2) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys 16:50:42.0296 2904 CCDECODE - ok 16:50:42.0296 2904 cd20xrnt - ok 16:50:42.0312 2904 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 16:50:42.0312 2904 Cdaudio - ok 16:50:42.0359 2904 Cdfs (cd7d5152df32b47f4e36f710b35aae02) C:\WINDOWS\system32\drivers\Cdfs.sys 16:50:42.0359 2904 Cdfs - ok 16:50:42.0375 2904 Cdrom (af9c19b3100fe010496b1a27181fbf72) C:\WINDOWS\system32\DRIVERS\cdrom.sys 16:50:42.0375 2904 Cdrom - ok 16:50:42.0453 2904 Changer - ok 16:50:42.0484 2904 CmdIde - ok 16:50:42.0531 2904 Cpqarray - ok 16:50:42.0546 2904 dac2w2k - ok 16:50:42.0562 2904 dac960nt - ok 16:50:42.0578 2904 Disk (00ca44e4534865f8a3b64f7c0984bff0) C:\WINDOWS\system32\DRIVERS\disk.sys 16:50:42.0578 2904 Disk - ok 16:50:42.0640 2904 dmboot (c0fbb516e06e243f0cf31f597e7ebf7d) C:\WINDOWS\system32\drivers\dmboot.sys 16:50:42.0640 2904 dmboot - ok 16:50:42.0671 2904 dmio (f5e7b358a732d09f4bcf2824b88b9e28) C:\WINDOWS\system32\drivers\dmio.sys 16:50:42.0671 2904 dmio - ok 16:50:42.0687 2904 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 16:50:42.0687 2904 dmload - ok 16:50:42.0718 2904 DMusic (a6f881284ac1150e37d9ae47ff601267) C:\WINDOWS\system32\drivers\DMusic.sys 16:50:42.0718 2904 DMusic - ok 16:50:42.0734 2904 dpti2o - ok 16:50:42.0781 2904 drmkaud (1ed4dbbae9f5d558dbba4cc450e3eb2e) C:\WINDOWS\system32\drivers\drmkaud.sys 16:50:42.0781 2904 drmkaud - ok 16:50:42.0796 2904 Fastfat (3117f595e9615e04f05a54fc15a03b20) C:\WINDOWS\system32\drivers\Fastfat.sys 16:50:42.0796 2904 Fastfat - ok 16:50:42.0828 2904 Fdc (ced2e8396a8838e59d8fd529c680e02c) C:\WINDOWS\system32\drivers\Fdc.sys 16:50:42.0828 2904 Fdc - ok 16:50:42.0843 2904 Fips (e153ab8a11de5452bcf5ac7652dbf3ed) C:\WINDOWS\system32\drivers\Fips.sys 16:50:42.0843 2904 Fips - ok 16:50:42.0859 2904 Flpydisk (0dd1de43115b93f4d85e889d7a86f548) C:\WINDOWS\system32\drivers\Flpydisk.sys 16:50:42.0859 2904 Flpydisk - ok 16:50:42.0875 2904 FltMgr (157754f0df355a9e0a6f54721914f9c6) C:\WINDOWS\system32\DRIVERS\fltMgr.sys 16:50:42.0875 2904 FltMgr - ok 16:50:42.0890 2904 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 16:50:42.0890 2904 Fs_Rec - ok 16:50:42.0906 2904 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 16:50:42.0921 2904 Ftdisk - ok 16:50:42.0921 2904 ftsata2 (22399d3ce5840c6082844679cca5d2fc) C:\WINDOWS\system32\DRIVERS\ftsata2.sys 16:50:42.0937 2904 ftsata2 - ok 16:50:42.0984 2904 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys 16:50:42.0984 2904 GEARAspiWDM - ok 16:50:43.0000 2904 Gpc (c0f1d4a21de5a415df8170616703debf) C:\WINDOWS\system32\DRIVERS\msgpc.sys 16:50:43.0000 2904 Gpc - ok 16:50:43.0078 2904 HDAudBus (3fcc124b6e08ee0e9351f717dd136939) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 16:50:43.0078 2904 HDAudBus - ok 16:50:43.0125 2904 HidUsb (1de6783b918f540149aa69943bdfeba8) C:\WINDOWS\system32\DRIVERS\hidusb.sys 16:50:43.0125 2904 HidUsb - ok 16:50:43.0140 2904 hpn - ok 16:50:43.0171 2904 HSXHWBS2 (1f5c64b0c6b2e2f48735a77ae714ccb8) C:\WINDOWS\system32\DRIVERS\HSXHWBS2.sys 16:50:43.0171 2904 HSXHWBS2 - ok 16:50:43.0203 2904 HSX_DP (a7f8c9228898a1e871d2ae7082f50ac3) C:\WINDOWS\system32\DRIVERS\HSX_DP.sys 16:50:43.0218 2904 HSX_DP - ok 16:50:43.0265 2904 HTTP (9f8b0f4276f618964fd118be4289b7cd) C:\WINDOWS\system32\Drivers\HTTP.sys 16:50:43.0265 2904 HTTP - ok 16:50:43.0281 2904 i2omgmt - ok 16:50:43.0296 2904 i2omp - ok 16:50:43.0359 2904 i8042prt (5502b58eef7486ee6f93f3f164dcb808) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 16:50:43.0359 2904 i8042prt - ok 16:50:43.0390 2904 Imapi (f8aa320c6a0409c0380e5d8a99d76ec6) C:\WINDOWS\system32\DRIVERS\imapi.sys 16:50:43.0390 2904 Imapi - ok 16:50:43.0421 2904 ini910u - ok 16:50:43.0578 2904 IntcAzAudAddService (ab2fe0faa519880bd16e4a0792d633d2) C:\WINDOWS\system32\drivers\RtkHDAud.sys 16:50:43.0609 2904 IntcAzAudAddService - ok 16:50:43.0625 2904 IntelIde (2d722b2b54ab55b2fa475eb58d7b2aad) C:\WINDOWS\system32\DRIVERS\intelide.sys 16:50:43.0625 2904 IntelIde - ok 16:50:43.0640 2904 intelppm - ok 16:50:43.0671 2904 Ip6Fw (4448006b6bc60e6c027932cfc38d6855) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys 16:50:43.0671 2904 Ip6Fw - ok 16:50:43.0718 2904 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 16:50:43.0718 2904 IpFilterDriver - ok 16:50:43.0718 2904 IpInIp (e1ec7f5da720b640cd8fb8424f1b14bb) C:\WINDOWS\system32\DRIVERS\ipinip.sys 16:50:43.0718 2904 IpInIp - ok 16:50:43.0750 2904 IpNat (b5a8e215ac29d24d60b4d1250ef05ace) C:\WINDOWS\system32\DRIVERS\ipnat.sys 16:50:43.0750 2904 IpNat - ok 16:50:43.0812 2904 IPSec (ea66d9a13e73b54f7e9ae34a0d835114) C:\WINDOWS\system32\drivers\IPSec.sys 16:50:43.0875 2904 IPSec - ok 16:50:43.0906 2904 IRENUM (50708daa1b1cbb7d6ac1cf8f56a24410) C:\WINDOWS\system32\DRIVERS\irenum.sys 16:50:43.0906 2904 IRENUM - ok 16:50:43.0921 2904 isapnp (e504f706ccb699c2596e9a3da1596e87) C:\WINDOWS\system32\DRIVERS\isapnp.sys 16:50:43.0921 2904 isapnp - ok 16:50:43.0968 2904 Kbdclass (ebdee8a2ee5393890a1acee971c4c246) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 16:50:43.0968 2904 Kbdclass - ok 16:50:44.0015 2904 kbdhid (e182fa8e49e8ee41b4adc53093f3c7e6) C:\WINDOWS\system32\DRIVERS\kbdhid.sys 16:50:44.0015 2904 kbdhid - ok 16:50:44.0046 2904 kmixer (d93cad07c5683db066b0b2d2d3790ead) C:\WINDOWS\system32\drivers\kmixer.sys 16:50:44.0046 2904 kmixer - ok 16:50:44.0078 2904 KSecDD (674d3e5a593475915dc6643317192403) C:\WINDOWS\system32\drivers\KSecDD.sys 16:50:44.0078 2904 KSecDD - ok 16:50:44.0093 2904 lbrtfdc - ok 16:50:44.0125 2904 MBAMProtector (69a6268d7f81e53d568ab4e7e991caf3) C:\WINDOWS\system32\drivers\mbam.sys 16:50:44.0125 2904 MBAMProtector - ok 16:50:44.0140 2904 MBAMSwissArmy - ok 16:50:44.0187 2904 mdmxsdk (e246a32c445056996074a397da56e815) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys 16:50:44.0187 2904 mdmxsdk - ok 16:50:44.0218 2904 MHNDRV (7f2f1d2815a6449d346fcccbc569fbd6) C:\WINDOWS\system32\DRIVERS\mhndrv.sys 16:50:44.0234 2904 MHNDRV - ok 16:50:44.0250 2904 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 16:50:44.0250 2904 mnmdd - ok 16:50:44.0281 2904 Modem (6fc6f9d7acc36dca9b914565a3aeda05) C:\WINDOWS\system32\drivers\Modem.sys 16:50:44.0281 2904 Modem - ok 16:50:44.0343 2904 Mouclass (34e1f0031153e491910e12551400192c) C:\WINDOWS\system32\DRIVERS\mouclass.sys 16:50:44.0343 2904 Mouclass - ok 16:50:44.0375 2904 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys 16:50:44.0375 2904 mouhid - ok 16:50:44.0390 2904 MountMgr (65653f3b4477f3c63e68a9659f85ee2e) C:\WINDOWS\system32\drivers\MountMgr.sys 16:50:44.0390 2904 MountMgr - ok 16:50:44.0406 2904 mraid35x - ok 16:50:44.0437 2904 MRxDAV (46edcc8f2db2f322c24f48785cb46366) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 16:50:44.0437 2904 MRxDAV - ok 16:50:44.0500 2904 MRxSmb (fb6c89bb3ce282b08bdb1e3c179e1c39) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 16:50:44.0500 2904 MRxSmb - ok 16:50:44.0515 2904 Msfs (561b3a4333ca2dbdba28b5b956822519) C:\WINDOWS\system32\drivers\Msfs.sys 16:50:44.0515 2904 Msfs - ok 16:50:44.0546 2904 MSKSSRV (ae431a8dd3c1d0d0610cdbac16057ad0) C:\WINDOWS\system32\drivers\MSKSSRV.sys 16:50:44.0546 2904 MSKSSRV - ok 16:50:44.0562 2904 MSPCLOCK (13e75fef9dfeb08eeded9d0246e1f448) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 16:50:44.0578 2904 MSPCLOCK - ok 16:50:44.0578 2904 MSPQM (1988a33ff19242576c3d0ef9ce785da7) C:\WINDOWS\system32\drivers\MSPQM.sys 16:50:44.0578 2904 MSPQM - ok 16:50:44.0593 2904 mssmbios (469541f8bfd2b32659d5d463a6714bce) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 16:50:44.0593 2904 mssmbios - ok 16:50:44.0640 2904 MSTEE (bf13612142995096ab084f2db7f40f77) C:\WINDOWS\system32\drivers\MSTEE.sys 16:50:44.0640 2904 MSTEE - ok 16:50:44.0656 2904 Mup (82035e0f41c2dd05ae41d27fe6cf7de1) C:\WINDOWS\system32\drivers\Mup.sys 16:50:44.0656 2904 Mup - ok 16:50:44.0671 2904 NABTSFEC (5c8dc6429c43dc6177c1fa5b76290d1a) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys 16:50:44.0671 2904 NABTSFEC - ok 16:50:44.0687 2904 NDIS (558635d3af1c7546d26067d5d9b6959e) C:\WINDOWS\system32\drivers\NDIS.sys 16:50:44.0687 2904 NDIS - ok 16:50:44.0703 2904 NdisIP (520ce427a8b298f54112857bcf6bde15) C:\WINDOWS\system32\DRIVERS\NdisIP.sys 16:50:44.0703 2904 NdisIP - ok 16:50:44.0734 2904 NdisTapi (08d43bbdacdf23f34d79e44ed35c1b4c) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 16:50:44.0734 2904 NdisTapi - ok 16:50:44.0750 2904 Ndisuio (eefa1ce63805d2145978621be5c6d955) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 16:50:44.0750 2904 Ndisuio - ok 16:50:44.0765 2904 NdisWan (0b90e255a9490166ab368cd55a529893) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 16:50:44.0765 2904 NdisWan - ok 16:50:44.0796 2904 NDProxy (59fc3fb44d2669bc144fd87826bb571f) C:\WINDOWS\system32\drivers\NDProxy.sys 16:50:44.0796 2904 NDProxy - ok 16:50:44.0796 2904 NetBIOS (3a2aca8fc1d7786902ca434998d7ceb4) C:\WINDOWS\system32\DRIVERS\netbios.sys 16:50:44.0812 2904 NetBIOS - ok 16:50:44.0828 2904 NetBT (0c80e410cd2f47134407ee7dd19cc86b) C:\WINDOWS\system32\DRIVERS\netbt.sys 16:50:44.0828 2904 NetBT - ok 16:50:44.0859 2904 NIC1394 (5c5c53db4fef16cf87b9911c7e8c6fbc) C:\WINDOWS\system32\DRIVERS\nic1394.sys 16:50:44.0859 2904 NIC1394 - ok 16:50:44.0875 2904 Npfs (4f601bcb8f64ea3ac0994f98fed03f8e) C:\WINDOWS\system32\drivers\Npfs.sys 16:50:44.0875 2904 Npfs - ok 16:50:44.0906 2904 Ntfs (b78be402c3f63dd55521f73876951cdd) C:\WINDOWS\system32\drivers\Ntfs.sys 16:50:44.0906 2904 Ntfs - ok 16:50:44.0921 2904 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 16:50:44.0937 2904 Null - ok 16:50:45.0031 2904 nv (642a87877f83313eb5302749cd479024) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 16:50:45.0062 2904 nv - ok 16:50:45.0078 2904 NVENETFD (22eedb34c4d7613a25b10c347c6c4c21) C:\WINDOWS\system32\DRIVERS\NVENETFD.sys 16:50:45.0078 2904 NVENETFD - ok 16:50:45.0093 2904 nvnetbus (5e3f6ad5cad0f12d3cccd06fd964087a) C:\WINDOWS\system32\DRIVERS\nvnetbus.sys 16:50:45.0093 2904 nvnetbus - ok 16:50:45.0125 2904 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 16:50:45.0125 2904 NwlnkFlt - ok 16:50:45.0140 2904 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 16:50:45.0140 2904 NwlnkFwd - ok 16:50:45.0171 2904 ohci1394 (0951db8e5823ea366b0e408d71e1ba2a) C:\WINDOWS\system32\DRIVERS\ohci1394.sys 16:50:45.0171 2904 ohci1394 - ok 16:50:45.0203 2904 Parport (29744eb4ce659dfe3b4122deb45bc478) C:\WINDOWS\system32\DRIVERS\parport.sys 16:50:45.0203 2904 Parport - ok 16:50:45.0234 2904 PartMgr (3334430c29dc338092f79c38ef7b4cd0) C:\WINDOWS\system32\drivers\PartMgr.sys 16:50:45.0234 2904 PartMgr - ok 16:50:45.0234 2904 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 16:50:45.0234 2904 ParVdm - ok 16:50:45.0250 2904 PCI (8086d9979234b603ad5bc2f5d890b234) C:\WINDOWS\system32\DRIVERS\pci.sys 16:50:45.0250 2904 PCI - ok 16:50:45.0265 2904 PCIDump - ok 16:50:45.0281 2904 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys 16:50:45.0281 2904 PCIIde - ok 16:50:45.0296 2904 Pcmcia (82a087207decec8456fbe8537947d579) C:\WINDOWS\system32\drivers\Pcmcia.sys 16:50:45.0296 2904 Pcmcia - ok 16:50:45.0312 2904 PDCOMP - ok 16:50:45.0312 2904 PDFRAME - ok 16:50:45.0328 2904 PDRELI - ok 16:50:45.0343 2904 PDRFRAME - ok 16:50:45.0359 2904 perc2 - ok 16:50:45.0359 2904 perc2hib - ok 16:50:45.0421 2904 PptpMiniport (1c5cc65aac0783c344f16353e60b72ac) C:\WINDOWS\system32\DRIVERS\raspptp.sys 16:50:45.0421 2904 PptpMiniport - ok 16:50:45.0437 2904 Processor (0d97d88720a4087ec93af7dbb303b30a) C:\WINDOWS\system32\DRIVERS\processr.sys 16:50:45.0437 2904 Processor - ok 16:50:45.0484 2904 Ps2 (390c204ced3785609ab24e9c52054a84) C:\WINDOWS\system32\DRIVERS\PS2.sys 16:50:45.0484 2904 Ps2 - ok 16:50:45.0484 2904 PSched (48671f327553dcf1d27f6197f622a668) C:\WINDOWS\system32\DRIVERS\psched.sys 16:50:45.0500 2904 PSched - ok 16:50:45.0500 2904 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 16:50:45.0500 2904 Ptilink - ok 16:50:45.0515 2904 PxHelp20 (97b735de4e3cd44c71c8cb09bdbf07b7) C:\WINDOWS\system32\Drivers\PxHelp20.sys 16:50:45.0515 2904 PxHelp20 - ok 16:50:45.0531 2904 ql1080 - ok 16:50:45.0546 2904 Ql10wnt - ok 16:50:45.0562 2904 ql12160 - ok 16:50:45.0562 2904 ql1240 - ok 16:50:45.0578 2904 ql1280 - ok 16:50:45.0609 2904 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 16:50:45.0609 2904 RasAcd - ok 16:50:45.0640 2904 Rasl2tp (98faeb4a4dcf812ba1c6fca4aa3e115c) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 16:50:45.0640 2904 Rasl2tp - ok 16:50:45.0656 2904 RasPppoe (7306eeed8895454cbed4669be9f79faa) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 16:50:45.0656 2904 RasPppoe - ok 16:50:45.0671 2904 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 16:50:45.0671 2904 Raspti - ok 16:50:45.0687 2904 Rdbss (809ca45caa9072b3176ad44579d7f688) C:\WINDOWS\system32\DRIVERS\rdbss.sys 16:50:45.0687 2904 Rdbss - ok 16:50:45.0703 2904 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 16:50:45.0703 2904 RDPCDD - ok 16:50:45.0718 2904 rdpdr (a2cae2c60bc37e0751ef9dda7ceaf4ad) C:\WINDOWS\system32\DRIVERS\rdpdr.sys 16:50:45.0718 2904 rdpdr - ok 16:50:45.0765 2904 RDPWD (d4f5643d7714ef499ae9527fdcd50894) C:\WINDOWS\system32\drivers\RDPWD.sys 16:50:45.0765 2904 RDPWD - ok 16:50:45.0796 2904 redbook (b31b4588e4086d8d84adbf9845c2402b) C:\WINDOWS\system32\DRIVERS\redbook.sys 16:50:45.0812 2904 redbook - ok 16:50:45.0859 2904 rtl8139 (d507c1400284176573224903819ffda3) C:\WINDOWS\system32\DRIVERS\RTL8139.SYS 16:50:45.0859 2904 rtl8139 - ok 16:50:45.0875 2904 Secdrv (d26e26ea516450af9d072635c60387f4) C:\WINDOWS\system32\DRIVERS\secdrv.sys 16:50:45.0875 2904 Secdrv - ok 16:50:45.0906 2904 Serial (cd9404d115a00d249f70a371b46d5a26) C:\WINDOWS\system32\drivers\Serial.sys 16:50:45.0906 2904 Serial - ok 16:50:45.0921 2904 Sfloppy (0d13b6df6e9e101013a7afb0ce629fe0) C:\WINDOWS\system32\drivers\Sfloppy.sys 16:50:45.0921 2904 Sfloppy - ok 16:50:45.0937 2904 Simbad - ok 16:50:45.0984 2904 SLIP (5caeed86821fa2c6139e32e9e05ccdc9) C:\WINDOWS\system32\DRIVERS\SLIP.sys 16:50:45.0984 2904 SLIP - ok 16:50:46.0000 2904 Sparrow - ok 16:50:46.0031 2904 splitter (8e186b8f23295d1e42c573b82b80d548) C:\WINDOWS\system32\drivers\splitter.sys 16:50:46.0031 2904 splitter - ok 16:50:46.0078 2904 sr (e41b6d037d6cd08461470af04500dc24) C:\WINDOWS\system32\DRIVERS\sr.sys 16:50:46.0093 2904 sr - ok 16:50:46.0156 2904 Srv (7a4f147cc6b133f905f6e65e2f8669fb) C:\WINDOWS\system32\DRIVERS\srv.sys 16:50:46.0156 2904 Srv - ok 16:50:46.0234 2904 streamip (284c57df5dc7abca656bc2b96a667afb) C:\WINDOWS\system32\DRIVERS\StreamIP.sys 16:50:46.0234 2904 streamip - ok 16:50:46.0265 2904 swenum (03c1bae4766e2450219d20b993d6e046) C:\WINDOWS\system32\DRIVERS\swenum.sys 16:50:46.0265 2904 swenum - ok 16:50:46.0281 2904 swmidi (94abc808fc4b6d7d2bbf42b85e25bb4d) C:\WINDOWS\system32\drivers\swmidi.sys 16:50:46.0281 2904 swmidi - ok 16:50:46.0296 2904 symc810 - ok 16:50:46.0312 2904 symc8xx - ok 16:50:46.0328 2904 sym_hi - ok 16:50:46.0343 2904 sym_u3 - ok 16:50:46.0375 2904 sysaudio (650ad082d46bac0e64c9c0e0928492fd) C:\WINDOWS\system32\drivers\sysaudio.sys 16:50:46.0375 2904 sysaudio - ok 16:50:46.0453 2904 Tcpip (2a5554fc5b1e04e131230e3ce035c3f9) C:\WINDOWS\system32\DRIVERS\tcpip.sys 16:50:46.0453 2904 Tcpip - ok 16:50:46.0500 2904 TDPIPE (38d437cf2d98965f239b0abcd66dcb0f) C:\WINDOWS\system32\drivers\TDPIPE.sys 16:50:46.0500 2904 TDPIPE - ok 16:50:46.0515 2904 TDTCP (ed0580af02502d00ad8c4c066b156be9) C:\WINDOWS\system32\drivers\TDTCP.sys 16:50:46.0515 2904 TDTCP - ok 16:50:46.0546 2904 TermDD (a540a99c281d933f3d69d55e48727f47) C:\WINDOWS\system32\DRIVERS\termdd.sys 16:50:46.0546 2904 TermDD - ok 16:50:46.0578 2904 TfFsMon - ok 16:50:46.0593 2904 TfNetMon - ok 16:50:46.0609 2904 TFSysMon - ok 16:50:46.0625 2904 TosIde - ok 16:50:46.0656 2904 Udfs (12f70256f140cd7d52c58c7048fde657) C:\WINDOWS\system32\drivers\Udfs.sys 16:50:46.0656 2904 Udfs - ok 16:50:46.0671 2904 ultra - ok 16:50:46.0687 2904 Update (aff2e5045961bbc0a602bb6f95eb1345) C:\WINDOWS\system32\DRIVERS\update.sys 16:50:46.0687 2904 Update - ok 16:50:46.0750 2904 USBAAPL (83cafcb53201bbac04d822f32438e244) C:\WINDOWS\system32\Drivers\usbaapl.sys 16:50:46.0750 2904 USBAAPL - ok 16:50:46.0796 2904 usbaudio (45a0d14b26c35497ad93bce7e15c9941) C:\WINDOWS\system32\drivers\usbaudio.sys 16:50:46.0796 2904 usbaudio - ok 16:50:46.0812 2904 usbccgp (bffd9f120cc63bcbaa3d840f3eef9f79) C:\WINDOWS\system32\DRIVERS\usbccgp.sys 16:50:46.0812 2904 usbccgp - ok 16:50:46.0843 2904 usbehci (7481d843e672b51039b7e8a161b746b8) C:\WINDOWS\system32\DRIVERS\usbehci.sys 16:50:46.0843 2904 usbehci - ok 16:50:46.0890 2904 usbhub (c72f40947f92cea56a8fb532edf025f1) C:\WINDOWS\system32\DRIVERS\usbhub.sys 16:50:46.0890 2904 usbhub - ok 16:50:46.0906 2904 usbohci (bdfe799a8531bad8a5a985821fe78760) C:\WINDOWS\system32\DRIVERS\usbohci.sys 16:50:46.0906 2904 usbohci - ok 16:50:46.0921 2904 usbprint (a42369b7cd8886cd7c70f33da6fcbcf5) C:\WINDOWS\system32\DRIVERS\usbprint.sys 16:50:46.0921 2904 usbprint - ok 16:50:46.0953 2904 usbscan (a6bc71402f4f7dd5b77fd7f4a8ddba85) C:\WINDOWS\system32\DRIVERS\usbscan.sys 16:50:46.0953 2904 usbscan - ok 16:50:46.0968 2904 usbstor (6cd7b22193718f1d17a47a1cd6d37e75) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 16:50:46.0968 2904 usbstor - ok 16:50:46.0984 2904 usbuhci (f8fd1400092e23c8f2f31406ef06167b) C:\WINDOWS\system32\DRIVERS\usbuhci.sys 16:50:46.0984 2904 usbuhci - ok 16:50:47.0000 2904 usbvideo (8968ff3973a883c49e8b564200f565b9) C:\WINDOWS\system32\Drivers\usbvideo.sys 16:50:47.0000 2904 usbvideo - ok 16:50:47.0031 2904 VgaSave (8a60edd72b4ea5aea8202daf0e427925) C:\WINDOWS\System32\drivers\vga.sys 16:50:47.0031 2904 VgaSave - ok 16:50:47.0046 2904 ViaIde (59cb1338ad3654417bea49636457f65d) C:\WINDOWS\system32\DRIVERS\viaide.sys 16:50:47.0046 2904 ViaIde - ok 16:50:47.0062 2904 VolSnap (ee4660083deba849ff6c485d944b379b) C:\WINDOWS\system32\drivers\VolSnap.sys 16:50:47.0062 2904 VolSnap - ok 16:50:47.0093 2904 Wanarp (984ef0b9788abf89974cfed4bfbaacbc) C:\WINDOWS\system32\DRIVERS\wanarp.sys 16:50:47.0093 2904 Wanarp - ok 16:50:47.0109 2904 WDICA - ok 16:50:47.0140 2904 wdmaud (2797f33ebf50466020c430ee4f037933) C:\WINDOWS\system32\drivers\wdmaud.sys 16:50:47.0140 2904 wdmaud - ok 16:50:47.0296 2904 winachsx (11ec1afceb5c917ce73d3c301ff4291e) C:\WINDOWS\system32\DRIVERS\HSX_CNXT.sys 16:50:47.0296 2904 winachsx - ok 16:50:47.0359 2904 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys 16:50:47.0359 2904 WS2IFSL - ok 16:50:47.0406 2904 WSTCODEC (d5842484f05e12121c511aa93f6439ec) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS 16:50:47.0406 2904 WSTCODEC - ok 16:50:47.0453 2904 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys 16:50:47.0453 2904 WudfPf - ok 16:50:47.0468 2904 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys 16:50:47.0468 2904 WudfRd - ok 16:50:47.0515 2904 MBR (0x1B8) (d11c727e03bb7318dcda069b06e652f0) \Device\Harddisk0\DR0 16:50:47.0546 2904 \Device\Harddisk0\DR0 - ok 16:50:47.0562 2904 MBR (0x1B8) (5fb38429d5d77768867c76dcbdb35194) \Device\Harddisk1\DR3 16:50:47.0562 2904 \Device\Harddisk1\DR3 - ok 16:50:47.0562 2904 Boot (0x1200) (58ca19a01360261197492d6f4579b419) \Device\Harddisk0\DR0\Partition0 16:50:47.0562 2904 \Device\Harddisk0\DR0\Partition0 - ok 16:50:47.0578 2904 Boot (0x1200) (dc84b485ed600b68b38eb0ba56352687) \Device\Harddisk0\DR0\Partition1 16:50:47.0578 2904 \Device\Harddisk0\DR0\Partition1 - ok 16:50:47.0578 2904 Boot (0x1200) (e9d795123a5e2ac7670169335ebe5c33) \Device\Harddisk1\DR3\Partition0 16:50:47.0578 2904 \Device\Harddisk1\DR3\Partition0 - ok 16:50:47.0578 2904 ============================================================ 16:50:47.0578 2904 Scan finished 16:50:47.0578 2904 ============================================================ 16:50:47.0593 5172 Detected object count: 0 16:50:47.0593 5172 Actual detected object count: 0

Attachments:

Thanks for your help! Just so you know my computer has been acting up and I did not see your response until today. I was looking for an e-mail alert in my e-mail account but I never received one. Other forums I belong to send e-mail alerts that somebody has responded. Between the time I posted the initial logs and today I've downloaded and installed Spybot Rearch & Destroy as well as AVG in hopes to be able to use the computer. It's been chaotic and I am hoping I can get it back to working to normal speed and that the unsolicited websites stop popping up!

No problem :). Hmm, it should have automatically subscribed you to this thread. Check your subscription settings to make sure. Let's try to get your computer fixed.

I'll need you to disable Spybot S&D and uninstall AVG temporarily so we can run some tools.

Next, Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT- Save ComboFix.exe to your Desktop

====================================================


Disable your AntiVirus and AntiSpyware applications as they will interfere with our tools and the removal. If you are unsure how to do this, please refer to our sticky topic How to disable your security applications

====================================================


Double click on ComboFix.exe & follow the prompts.


  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:


[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply for further review.
I am replying from a different computer. Combofix said that it needed to reboot the machine and to let it do it, that I should not intitiate the reboot. But now I have a blank screen, no icons or anything else for the last five minutes. The only thing I can bring up is Task Manager. What should I do?
Here's the Combofix log.

ComboFix 11-12-26.03 - HP_Administrator 12/26/2011 22:42:41.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1982.1586 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Administrator\WINDOWS
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\All Users\Application Data\TEMP\430C6D84.TMP
c:\documents and settings\Default User\WINDOWS
c:\documents and settings\HP_Administrator\WINDOWS
c:\program files\StartNow Toolbar
c:\program files\StartNow Toolbar\ReactivateIE.exe
c:\program files\StartNow Toolbar\Resources\images\engine_images.png
c:\program files\StartNow Toolbar\Resources\images\engine_maps.png
c:\program files\StartNow Toolbar\Resources\images\engine_news.png
c:\program files\StartNow Toolbar\Resources\images\engine_videos.png
c:\program files\StartNow Toolbar\Resources\images\engine_web.png
c:\program files\StartNow Toolbar\Resources\images\icon_amazon.png
c:\program files\StartNow Toolbar\Resources\images\icon_ebay.png
c:\program files\StartNow Toolbar\Resources\images\icon_facebook.png
c:\program files\StartNow Toolbar\Resources\images\icon_games.png
c:\program files\StartNow Toolbar\Resources\images\icon_msn.png
c:\program files\StartNow Toolbar\Resources\images\icon_shopping.png
c:\program files\StartNow Toolbar\Resources\images\icon_travel.png
c:\program files\StartNow Toolbar\Resources\images\icon_twitter.png
c:\program files\StartNow Toolbar\Resources\images\startnow_logo.png
c:\program files\StartNow Toolbar\Resources\installer.xml
c:\program files\StartNow Toolbar\Resources\skin\chevron_button.png
c:\program files\StartNow Toolbar\Resources\skin\searchbox_button_hover.png
c:\program files\StartNow Toolbar\Resources\skin\searchbox_button_normal.png
c:\program files\StartNow Toolbar\Resources\skin\searchbox_dropdown_button_normal.png
c:\program files\StartNow Toolbar\Resources\skin\searchbox_input_background.png
c:\program files\StartNow Toolbar\Resources\skin\searchbox_input_left.png
c:\program files\StartNow Toolbar\Resources\skin\searchbox_input_middle.png
c:\program files\StartNow Toolbar\Resources\skin\separator.png
c:\program files\StartNow Toolbar\Resources\skin\splitter.png
c:\program files\StartNow Toolbar\Resources\skin\toolbarbutton_ff_hover_c.png
c:\program files\StartNow Toolbar\Resources\skin\toolbarbutton_ie_hover_c.png
c:\program files\StartNow Toolbar\Resources\skin\toolbarbutton_ie_hover_l.png
c:\program files\StartNow Toolbar\Resources\skin\toolbarbutton_ie_hover_r.png
c:\program files\StartNow Toolbar\Resources\skin\toolbarbutton_ie_normal_c.png
c:\program files\StartNow Toolbar\Resources\skin\toolbarbutton_ie_normal_l.png
c:\program files\StartNow Toolbar\Resources\skin\toolbarbutton_ie_normal_r.png
c:\program files\StartNow Toolbar\Resources\toolbar.xml
c:\program files\StartNow Toolbar\Resources\update.xml
c:\program files\StartNow Toolbar\StartNowToolbarUninstall.exe
c:\program files\StartNow Toolbar\Toolbar32.dll
c:\program files\StartNow Toolbar\ToolbarBroker.exe
c:\program files\StartNow Toolbar\ToolbarUpdaterService.exe
c:\program files\StartNow Toolbar\uninstall.dat
c:\windows\$NtUninstallKB6978$
c:\windows\$NtUninstallKB6978$\1718319446
c:\windows\$NtUninstallKB6978$\674116460\@
c:\windows\$NtUninstallKB6978$\674116460\bckfg.tmp
c:\windows\$NtUninstallKB6978$\674116460\cfg.ini
c:\windows\$NtUninstallKB6978$\674116460\Desktop.ini
c:\windows\$NtUninstallKB6978$\674116460\keywords
c:\windows\$NtUninstallKB6978$\674116460\kwrd.dll
c:\windows\$NtUninstallKB6978$\674116460\L\aqaeidou
c:\windows\$NtUninstallKB6978$\674116460\lsflt7.ver
c:\windows\$NtUninstallKB6978$\674116460\U\00000001.@
c:\windows\$NtUninstallKB6978$\674116460\U\00000002.@
c:\windows\$NtUninstallKB6978$\674116460\U\00000004.@
c:\windows\$NtUninstallKB6978$\674116460\U\80000000.@
c:\windows\$NtUninstallKB6978$\674116460\U\80000004.@
c:\windows\$NtUninstallKB6978$\674116460\U\80000032.@
c:\windows\HPCPCUninstaller-6.3.2.116-9972322.exe
c:\windows\kb913800.exe
c:\windows\system32\config\systemprofile\WINDOWS
c:\windows\system32\SET55A.tmp
c:\windows\system32\SET5A5.tmp
c:\windows\system32\SET5B1.tmp
c:\windows\system32\SET5F4.tmp
c:\windows\system32\SET5F9.tmp
D:\Autorun.inf
K:\Autorun.inf
K:\Setup.exe
.
Infected copy of c:\windows\system32\drivers\ipsec.sys was found and disinfected
Restored copy from - The cat found it :)
c:\windows\system32\drivers\intelppm.sys . . . is missing!!
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Legacy_6TO4
——-\Service_6to4
——-\Legacy_Updater_Service_for_StartNow_Toolbar
——-\Legacy_Updater_Service_for_StartNow_Toolbar
——-\Service_Updater Service for StartNow Toolbar
——-\Service_Updater Service for StartNow Toolbar
.
.
((((((((((((((((((((((((( Files Created from 2011-11-27 to 2011-12-27 )))))))))))))))))))))))))))))))
.
.
2011-12-27 03:49 . 2011-12-27 03:49 ——– d—–w- c:\windows\LastGood.Tmp
2011-12-27 03:45 . 2011-12-27 03:45 ——– d-sh–w- c:\documents and settings\Default User\IETldCache
2011-12-27 02:05 . 2004-08-10 04:00 74752 —-a-w- c:\windows\system32\drivers\ipsec.sys
2011-12-27 02:05 . 2004-08-10 04:00 74752 —-a-w- c:\windows\system32\dllcache\ipsec.sys
2011-12-26 14:53 . 2011-12-26 14:53 ——– d–h–w- c:\documents and settings\All Users\Application Data\Common Files
2011-12-26 14:47 . 2011-12-27 01:46 ——– d—–w- c:\documents and settings\All Users\Application Data\MFAData
2011-12-24 19:26 . 2011-12-24 19:26 ——– d-sh–w- c:\documents and settings\LocalService\IETldCache
2011-12-24 17:28 . 2011-12-24 19:26 ——– d—–w- c:\program files\Spybot - Search & Destroy
2011-12-24 17:28 . 2011-12-24 17:39 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2011-12-15 17:15 . 2011-12-15 17:15 ——– d-sh–w- c:\documents and settings\NetworkService\IETldCache
2011-12-06 00:20 . 2011-12-06 02:37 ——– d—–w- c:\documents and settings\HP_Administrator\Application Data\DVD Flick
2011-12-06 00:19 . 2007-08-31 23:36 36864 —-a-w- c:\windows\system32\trayicon_handler.ocx
2011-12-06 00:19 . 2003-01-26 18:41 40960 —-a-w- c:\windows\system32\ssubtmr6.dll
2011-12-06 00:19 . 2011-12-06 00:20 ——– d—–w- c:\program files\DVD Flick
2011-12-06 00:19 . 2008-08-31 18:27 28672 —-a-w- c:\windows\system32\mousewheel.ocx
2011-12-06 00:19 . 2004-03-09 05:00 662288 —-a-w- c:\windows\system32\mscomct2.ocx
2011-12-06 00:19 . 2004-03-09 05:00 212240 —-a-w- c:\windows\system32\richtx32.ocx
2011-12-06 00:19 . 1998-06-24 05:00 164144 —-a-w- c:\windows\system32\comct232.ocx
2011-12-05 23:42 . 2011-12-05 23:42 ——– d—–w- c:\program files\FoxTabVideoConverter
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-19 01:10 . 2011-07-17 16:09 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-14 22:38 . 2004-08-10 04:00 456192 ——w- c:\windows\system32\encdec.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-07-03 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-30 67584]
"ftutil2"="ftutil2.dll" [2004-06-07 106496]
"RTHDCPL"="RTHDCPL.EXE" [2006-06-14 16239616]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-03 77312]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-05-09 7311360]
"nwiz"="nwiz.exe" [2006-05-09 1519616]
"DMAScheduler"="c:\program files\HP DigitalMedia Archive\DMAScheduler.exe" [2006-04-13 90112]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2005-07-23 237568]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2006-02-16 249856]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-05-04 252136]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2011-05-10 49208]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2011-07-05 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-10-09 421736]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-08-31 449608]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 155648]
"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2005-03-17 57393]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2005-03-17 40960]
"BrMfcWnd"="c:\program files\Brother\Brmfcmon\BrMfcWnd.exe" [2006-06-28 622592]
"SetDefPrt"="c:\program files\Brother\Brmfl06a\BrStDvPt.exe" [2005-01-26 49152]
"ControlCenter3"="c:\program files\Brother\ControlCenter3\brctrcen.exe" [2006-06-29 77824]
"MaxMenuMgr"="c:\program files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe" [2009-09-26 185640]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Updates From HP.lnk - c:\program files\Updates from HP\9972322\Program\Updates from HP.exe [2006-11-19 36903]
.
c:\documents and settings\Default User\Start Menu\Programs\Startup\
Pin.lnk - c:\hp\bin\CLOAKER.EXE [2006-11-18 27136]
PinMcLnk.lnk - c:\hp\bin\cloaker.exe [2006-11-18 27136]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\DISC\\DISCover.exe"=
"c:\\Program Files\\DISC\\DiscStreamHub.exe"=
"c:\\Program Files\\DISC\\myFTP.exe"=
"c:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
R2 FreeAgentGoNext Service;Seagate Service;c:\program files\Seagate\SeagateManager\Sync\FreeAgentService.exe [9/25/2009 11:32 PM 189736]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [11/11/2011 9:51 PM 366152]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [11/11/2011 9:51 PM 22216]
S0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys –> c:\windows\system32\drivers\TfFsMon.sys [?]
S0 TFSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys –> c:\windows\system32\drivers\TfSysMon.sys [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [7/3/2011 4:59 PM 136176]
S2 XMLProvS;Network ProService;c:\windows\System32\svchost.exe -k xmlpros [8/9/2004 11:00 PM 14336]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [7/3/2011 4:59 PM 136176]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys –> c:\windows\system32\drivers\mbamswissarmy.sys [?]
S3 TfNetMon;TfNetMon;\??\c:\windows\system32\drivers\TfNetMon.sys –> c:\windows\system32\drivers\TfNetMon.sys [?]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - EHRECVR
*NewlyCreated* - EHSCHED
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
xmlpros REG_MULTI_SZ XMLProvS
.
Contents of the 'Scheduled Tasks' folder
.
2011-12-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 21:57]
.
2011-12-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-07-03 21:59]
.
2011-12-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-07-03 21:59]
.
.
——- Supplementary Scan ——-
.
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iesearch&locale;=EN_US&c;=64&bd;=PAVILION&pf;=desktop
uInternet Settings,ProxyOverride = *.local
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
Trusted Zone: trymedia.com
TCP: DhcpNameServer = [removed] [removed]
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - (no file)
HKLM-Run-PCDrProfiler - (no file)
AddRemove-StartNow Toolbar - c:\program files\StartNow Toolbar\StartNowToolbarUninstall.exe
AddRemove-FoxTab Video Converter - c:\program files\FoxTabVideoConverter\Uninstall\Uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-26 23:05
Windows 5.1.2600 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,ef,34,95,bc,1b,74,be,47,b9,f6,00,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,ef,34,95,bc,1b,74,be,47,b9,f6,00,\
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(496)
c:\windows\system32\WININET.dll
c:\docume~1\HP_ADM~1\LOCALS~1\Temp\IadHide5.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\windows\arservice.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre7\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\nvsvc32.exe
c:\windows\RTHDCPL.EXE
c:\windows\ARPWRMSG.EXE
c:\program files\Seagate\SeagateManager\Sync\MaxSync.exe
c:\windows\ehome\mcrdsvc.exe
c:\program files\Brother\Brmfcmon\BrMfcmon.exe
c:\windows\system32\wscntfy.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\windows\eHome\ehmsas.exe
c:\windows\system32\dllhost.exe
c:\hp\KBD\KBD.EXE
c:\windows\system\hpsysdrv.exe
c:\program files\DISC\DISCover.exe
c:\program files\DISC\DiscUpdMgr.exe
c:\program files\DISC\DiscStreamHub.exe
.
**************************************************************************
.
Completion time: 2011-12-26 23:08:57 - machine was rebooted
ComboFix-quarantined-files.txt 2011-12-27 04:08
.
Pre-Run: 111,309,512,704 bytes free
Post-Run: 112,656,764,928 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect
.
- - End Of File - - BEF888387F72CEE21662536E4EFB5039
Hi fernipascual,

You're infected with the Zero Access Rootkit. This rootkit has some backdoor functionality , which means it has the capability to steal banking account numbers, credit card numbers and passwords, I would strongly urge you to use a known clean computer and change all your passwords to any banking and shopping sites that you use.

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2
64 Bit Version

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :filefind
    intelppm.sys
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
SystemLook 30.07.11 by jpshortstuff Log created at 23:26 on 26/12/2011 by HP_Administrator Administrator - Elevation successful ========== filefind ========== Searching for "intelppm.sys" C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\intelppm.sys –a—- 36352 bytes [18:31 13/04/2008] [18:31 13/04/2008] 8C953733D8F36EB2133F5BB58808B66B -= EOF =-
Hi fernipascual, I see you have Malwarebytes Antimalware installed. Can you open it, update it, run a quick scan, remove anything found, then post the log?
Hello NoodleTech: Malwarebytes' Anti-Malware 1.51.2.1300 www.malwarebytes.org Database version: 911122701 Windows 5.1.2600 Service Pack 2 Internet Explorer 8.0.6001.18702 12/27/2011 9:09:10 AM mbam-log-2011-12-27 (09-09-10).txt Scan type: Quick scan Objects scanned: 183227 Time elapsed: 1 minute(s), 32 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Hi fernipascual,

Update Adobe Reader
Earlier versions of Adobe Reader have known security flaws so it is recommended that you update your copy
  • Go to Start > Control Panel > Add/Remove Programs
  • Remove ALL instances of Adobe Reader
  • Re-boot your computer if required.
  • Once ALL versions of Adobe Reader have been uninstalled, visit: <> and download the latest version of Adobe Reader.
  • Make sure you uncheck Yes, install McAfee Security Scan Plus - optional if prompted.
Alternative Option: after uninstalling Adobe Reader, you could try downloading and installing SlimPDF Reader from >here< SlimPDF Reader comes with no bloatware and loads extremely quickly.

===================================================

Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.

Updating Java:
  • Download the latest version of Java Runtime Environment (JRE) 7 Update 2.
  • Click on jre-7u2-windows-i586.exe if you are running 32-bit Windows or jre-7u2-windows-x64.exe if you are running 64-bit Windows.
  • After the download completes, close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Double click the Java setup file you just downloaded and follow the prompts to begin the installation.
Now to Clean out the Java cache:

Go into the Control Panel and double-click the Java Icon. [external image: Posted Image]
  • Under Temporary Internet Files, click the Settings… button
  • click the Delete Files button.
  • There are three options in the window to clear the cache - Leave all 3 Checked
    • Downloaded Applets
      Downloaded Applications
      Other Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Settings
  • Click OK to leave the Java Control Panel.
Hello NoodleTech: I've completed all the steps. Are there additional steps to be completed? The computer has been running much quicker since yesterday and the CPU usage is back to normal. My wife spends a lot of time on Sims and MallWorld. Are these places where malware can be picked up? Thanks

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI