This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Desktop has issues, possibly spyware/malware.... [Solved]

94 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

When it turned back on, I had the HP blue screen again. I pressed F8 multiple times, but nothing. I chose F1=setup and selected setup defaults. I now have a black screen with no cursor. I also noticed that I have very little cooling fan operation. The two inside seem to be running a little slower than what I remember. I also had to replace the power supply back in May. The computer is about 8 years old, but we like it.
Here are the scan logs I have. You requested these:

OTL fix log
New OTL log
ComboFix.txt

Buy I only have 2. Which one am I missing and where/what do I do to get it?

ComboFix 13-10-01.03 - HP_Administrator 10/02/2013 11:40:01.9.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.958.265 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((( Files Created from 2013-09-02 to 2013-10-02 )))))))))))))))))))))))))))))))
.
.
2013-10-02 18:04 . 2013-10-02 18:04 ——– dc—-w- C:\_OTL
2013-10-02 18:02 . 2013-09-05 05:02 7328304 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{5718BCD5-6474-4DF9-B7DF-939613AEC91D}\mpengine.dll
2013-09-30 23:49 . 2013-09-05 05:02 7328304 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-09-29 18:50 . 2013-09-29 18:50 ——– d—–w- c:\windows\ERUNT
2013-09-29 18:35 . 2013-09-29 18:40 ——– dc—-w- C:\AdwCleaner
2013-09-03 13:53 . 2013-09-03 13:53 187248 —-a-w- c:\program files\Mozilla Firefox\plugins\nppdf32.dll
2013-09-03 13:53 . 2013-09-03 13:53 187248 —-a-w- c:\program files\Internet Explorer\PLUGINS\nppdf32.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-09-20 23:59 . 2012-08-14 20:37 692616 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2013-09-20 23:59 . 2011-08-10 01:23 71048 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-08-09 01:56 . 2004-08-10 12:00 386560 —-a-w- c:\windows\system32\themeui.dll
2013-08-08 06:05 . 2004-08-10 12:00 920064 —-a-w- c:\windows\system32\wininet.dll
2013-08-08 06:05 . 2004-08-10 12:00 43520 —-a-w- c:\windows\system32\licmgr10.dll
2013-08-08 06:05 . 2004-08-10 12:00 1469440 —-a-w- c:\windows\system32\inetcpl.cpl
2013-08-08 06:05 . 2004-08-10 12:00 18944 —-a-w- c:\windows\system32\corpol.dll
2013-08-08 01:27 . 2004-08-10 12:00 1877760 —-a-w- c:\windows\system32\win32k.sys
2013-08-08 00:02 . 2004-08-10 12:00 385024 —-a-w- c:\windows\system32\html.iec
2013-08-05 13:30 . 2004-08-10 12:00 1289728 —-a-w- c:\windows\system32\ole32.dll
2013-08-03 21:18 . 2006-10-19 05:47 1543680 ——w- c:\windows\system32\wmvdecod.dll
2013-07-10 10:37 . 2004-08-10 12:00 406016 —-a-w- c:\windows\system32\usp10.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Facebook Update"="c:\documents and settings\HP_Administrator\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe" [2012-07-11 138096]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2013-01-08 18705664]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-06 64512]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-06-21 995176]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2011-07-27 434080]
.
c:\documents and settings\Default User\Start Menu\Programs\Startup\
Pin.lnk - c:\hp\bin\CLOAKER.EXE c:\hp\bin\PinToStart.bat [2005-11-10 27136]
.
c:\documents and settings\HP_Administrator.YOUR-4DACD0EA75\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE /tsr [2008-10-25 98696]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-12 282624]
Renaissance Wireless Server.lnk - c:\documents and settings\All Users\Application Data\Renaissance Wireless Server\Renaissance Wireless Server.exe [2007-9-11 6823860]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /r \??\J:\0autocheck autochk *
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Documents and Settings\\All Users\\Application Data\\Renaissance Wireless Server\\Renaissance Wireless Server.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Documents and Settings\\HP_Administrator\\Local Settings\\Application Data\\Facebook\\Video\\Skype\\FacebookVideoCalling.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeEnC2.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeTray.exe"=
"c:\\Program Files\\Rhapsody\\rhapsody.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [8/3/2011 1:31 PM 664064]
R2 DragonUpdater;COMODO Dragon Update Service;c:\program files\COMODO\Dragon\dragon_updater.exe [11/28/2012 4:45 AM 1868432]
R3 AE1000;Linksys AE1000 Driver;c:\windows\system32\drivers\AE1000XP.sys [7/12/2011 8:51 PM 816672]
R3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver;c:\windows\system32\drivers\nx6000.sys [7/13/2011 7:41 PM 30576]
S2 CSUService;COMODO System Utilities Service;c:\program files\COMODO\COMODO System Utilities\CSUService.exe [2/24/2012 6:26 AM 261952]
S2 MotoHelper;MotoHelper Service;c:\program files\Motorola\MotoHelper\MotoHelperService.exe –> c:\program files\Motorola\MotoHelper\MotoHelperService.exe [?]
S2 Skype C2C Service;Skype C2C Service;c:\documents and settings\All Users\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe [10/2/2012 12:13 PM 3064000]
S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [1/8/2013 12:55 PM 161536]
S3 McComponentHostService;McAfee Security Scan Component Host Service;"c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe" –> c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [?]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\DRIVERS\motccgp.sys –> c:\windows\system32\DRIVERS\motccgp.sys [?]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\DRIVERS\motccgpfl.sys –> c:\windows\system32\DRIVERS\motccgpfl.sys [?]
S3 motport;Motorola USB Diagnostic Port;c:\windows\system32\DRIVERS\motport.sys –> c:\windows\system32\DRIVERS\motport.sys [?]
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-09-21 09:21 1177552 —-a-w- c:\program files\Google\Chrome\Application\29.0.1547.76\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2013-10-02 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-14 23:59]
.
2013-09-12 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-02 00:57]
.
2013-09-30 c:\windows\Tasks\CSU Updater.job
- c:\program files\COMODO\COMODO System Utilities\Updater.exe [2012-02-24 13:27]
.
2013-01-13 c:\windows\Tasks\Easy Internet Sign-up.job
- c:\program files\Hewlett-Packard\SDP\HPSdpApp.exe [2005-09-09 03:23]
.
2013-09-30 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-657425056-1587324396-1979525332-1008Core.job
- c:\documents and settings\HP_Administrator\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe [2012-04-13 21:52]
.
2013-10-01 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-657425056-1587324396-1979525332-1008UA.job
- c:\documents and settings\HP_Administrator\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe [2012-04-13 21:52]
.
2013-10-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-12-08 03:45]
.
2013-10-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-12-08 03:45]
.
2013-10-02 c:\windows\Tasks\Microsoft Antimalware Scheduled Scan.job
- c:\program files\Microsoft Security Client\MpCmdRun.exe [2013-06-21 01:05]
.
2013-05-16 c:\windows\Tasks\Microsoft_Hardware_Launch_IcePick_exe.job
- c:\program files\Microsoft LifeCam\IcePick.exe [2010-05-20 22:27]
.
2013-09-30 c:\windows\Tasks\Norton Security Scan for HP_Administrator.job
- c:\program files\Norton Security Scan\Nss.exe [2008-09-19 11:18]
.
2013-10-02 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-657425056-1587324396-1979525332-1008.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2012-07-27 21:27]
.
2013-09-28 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-657425056-1587324396-1979525332-1008.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2012-07-27 21:27]
.
2013-09-04 c:\windows\Tasks\ReclaimerResumeInstall_HP_Administrator.job
- c:\documents and settings\HP_Administrator\Application Data\Real\Update\UpgradeHelper\RealPlayer\10.60\agent\rnupgagent.exe [2013-09-04 15:01]
.
2013-10-02 c:\windows\Tasks\User_Feed_Synchronization-{BF38A124-251E-4DD5-B80F-B1ED348AAA54}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 11:31]
.
.
——- Supplementary Scan ——-
.
uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
uInternet Settings,ProxyOverride = 192.168.*.*
TCP: DhcpNameServer = 75.75.75.75 75.75.76.76
TCP: Interfaces\{4F9665E1-6A11-4972-B941-EB22DFA68FC7}: NameServer = 8.26.56.26,156.154.70.22
TCP: Interfaces\{837C5F68-FB84-414E-8FEC-9FA666C52334}: NameServer = 8.26.56.26,156.154.70.22
FF - ProfilePath - c:\documents and settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ca60dke4.default-1380498043446\
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-10-02 11:52
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_8_800_175_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_8_800_175_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(792)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(3240)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2013-10-02 11:56:51
ComboFix-quarantined-files.txt 2013-10-02 18:56
ComboFix2.txt 2011-11-12 18:03
.
Pre-Run: 147,591,413,760 bytes free
Post-Run: 147,581,644,800 bytes free
.
- - End Of File - - B631C5BB3EEB993B09A00E5DBEC51734
0AC6D996BCE152AED9600E6D6B797E2E
———————————————————————————————————————————————————————

All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully!
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully!
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer| /E : value set successfully!
C:\Program Files\Mozilla Firefox\searchplugins\bing.xml.old moved successfully.
Registry value HKEY_USERS\S-1-5-21-657425056-1587324396-1979525332-1008\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{21FA44EF-376D-4D53-9B0F-8A89D3229068} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{21FA44EF-376D-4D53-9B0F-8A89D3229068}\ not found.
Registry value HKEY_USERS\S-1-5-21-657425056-1587324396-1979525332-1008\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}\ not found.
Registry value HKEY_USERS\S-1-5-21-657425056-1587324396-1979525332-1008\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}\ not found.
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Event Planner Reminders Tray Icon.lnk moved successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Forget Me Not.lnk moved successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk moved successfully.
C:\Documents and Settings\HP_Administrator\Start Menu\Programs\Startup\hc_tray.lnk moved successfully.
C:\Documents and Settings\HP_Administrator\Start Menu\Programs\Startup\Jewell DeskMate.LNK moved successfully.
C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75\Start Menu\Programs\Startup\Registration Silent Hunter III.LNK moved successfully.
Starting removal of ActiveX control {036F8A56-0BC8-4607-8F98-D3231E6FF5ED}
C:\WINDOWS\Downloaded Program Files\CentraUpdaterAx.inf not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{036F8A56-0BC8-4607-8F98-D3231E6FF5ED}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{036F8A56-0BC8-4607-8F98-D3231E6FF5ED}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{036F8A56-0BC8-4607-8F98-D3231E6FF5ED}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{036F8A56-0BC8-4607-8F98-D3231E6FF5ED}\ not found.
========== REGISTRY ==========
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\"AntiVirusOverride"|dword:00000000 /E : value set successfully!
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\"FirewallOverride"|dword:00000000 /E : value set successfully!
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Documents and Settings\HP_Administrator\Desktop\cmd.bat deleted successfully.
C:\Documents and Settings\HP_Administrator\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 160 bytes
->Temporary Internet Files folder emptied: 367562 bytes
->FireFox cache emptied: 20782010 bytes
->Flash cache emptied: 941 bytes

User: All Users

User: Customer
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Flash cache emptied: 300 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->FireFox cache emptied: 3414200 bytes
->Flash cache emptied: 56468 bytes

User: HP_Administrator
->Temp folder emptied: 360793743 bytes
->Temporary Internet Files folder emptied: 8406283 bytes
->Java cache emptied: 32857324 bytes
->FireFox cache emptied: 18586929 bytes
->Google Chrome cache emptied: 488720046 bytes
->Apple Safari cache emptied: 312320 bytes
->Flash cache emptied: 1225538 bytes

User: HP_Administrator.YOUR-4DACD0EA75
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Java cache emptied: 384610 bytes
->FireFox cache emptied: 34225826 bytes
->Flash cache emptied: 2447991 bytes

User: LocalService
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 427 bytes

User: NetworkService
->Temp folder emptied: 2775488 bytes
->Temporary Internet Files folder emptied: 19810927 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 405 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 350434 bytes
%systemroot%\System32 .tmp files removed: 4737041 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 10097322 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 545874309 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 437531 bytes
RecycleBin emptied: 73004840 bytes

Total Files Cleaned = 1,554.00 mb


OTL by OldTimer - Version 3.2.69.0 log created on 10022013_110439

Files\Folders moved on Reboot…
File\Folder C:\Documents and Settings\HP_Administrator\Local Settings\Temp\Perflib_Perfdata_2f8.dat not found!

PendingFileRenameOperations files…

Registry entries deleted on Reboot…
You managed to get the computer up and running to run the scan but don't say how. :unsure:

I also had to replace the power supply back in May.

Your power supply is unlikely to have failed in such a short space of time.

We need further looks and an idea of the current situation.

================================================

Run RogueKiller

IMPORTANT: Please remove any usb or external drives from the computer before you run this scan!

Close all running programs.

Download this version.

.
  • double-click on RogueKiller.exe
  • when the pre-scan is finished, click on Scan
  • click on Report and copy/paste the content in your next post
  • NOTE: DO NOT attempt to remove anything that the scan detects –everything that is reported is not necessarily bad
If the program is blocked, continue to try it several times. If it still doesn’t work, (it could happen), rename it to winlogon.exe.
Please post the contents of the RKreport.txt in your next reply.

================================================

Run Security Check

Download Security Check by screen317 from here or here.
  • save it to your Desktop.
  • double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • a Notepad document should open automatically called checkup.txt; please post the contents of that document.
Can you tell me if there have been any changes since we started and try to explain exactly what problems remain.

Thanks

Satchfan
Satchfan,

I really did not do anything, I just let it sit on the HP page and it booted on it's own. The only issues I see at this time, is when it sits for awhile and goes to screensaver/sleep mode, is when I have issues getting it started again.

Here are the logs:

RogueKiller V8.7.0 [Sep 30 2013] by Tigzy
mail : tigzyRKgmailcom
Feedback : http://www.adlice.com/forum/
Website : http://www.adlice.com/softwares/roguekiller/
Blog : http://tigzyrk.blogspot.com/

Operating System : Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User : HP_Administrator [Admin rights]
Mode : Scan – Date : 10/02/2013 16:12:11
| ARK || FAK || MBR |

¤¤¤ Bad processes : 2 ¤¤¤
[SUSP PATH] arservice.exe – C:\WINDOWS\arservice.exe [-] -> KILLED [TermProc]
[SUSP PATH] Renaissance Wireless Server.exe – C:\Documents and Settings\All Users\Application Data\Renaissance Wireless Server\Renaissance Wireless Server.exe [-] -> KILLED [TermProc]

¤¤¤ Registry Entries : 4 ¤¤¤
[DNS][PUM] HKLM\[…]\CCSet\[…]\{4F9665E1-6A11-4972-B941-EB22DFA68FC7} : NameServer (8.26.56.26,156.154.70.22) -> FOUND
[DNS][PUM] HKLM\[…]\CCSet\[…]\{837C5F68-FB84-414E-8FEC-9FA666C52334} : NameServer (8.26.56.26,156.154.70.22) -> FOUND
[HJ POL][PUM] HKLM\[…]\System : DisableRegistryTools (0) -> FOUND
[HJ DESK][PUM] HKLM\[…]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

¤¤¤ Scheduled tasks : 0 ¤¤¤

¤¤¤ Startup Entries : 1 ¤¤¤
[All Users][SUSP PATH] Renaissance Wireless Server.lnk : C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Renaissance Wireless Server.lnk @C:\DOCUME~1\ALLUSE~1\APPLIC~1\RENAIS~1\RENAIS~1.EXE [-][-] -> FOUND

¤¤¤ Web browsers : 0 ¤¤¤

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver : [LOADED] ¤¤¤
[Inline] EAT @explorer.exe (??_7?$basic_ostringstream@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@6B@) : MSVCP60.dll -> HOOKED (Unknown @ 0x768381A1)
[Inline] EAT @iexplore.exe (?_Ptr_wcout@std@@3PAV?$basic_ostream@GU?$char_traits@G@std@@@1@A) : MSVCP90.dll -> HOOKED (Unknown @ 0x28C8C016)
[Inline] EAT @iexplore.exe (?_Ptr_wcout@std@@3PAV?$basic_ostream@GU?$char_traits@G@std@@@1@A) : MSVCP90.dll -> HOOKED (Unknown @ 0x28C8C016)

¤¤¤ External Hives: ¤¤¤

¤¤¤ Infection : ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
–> %SystemRoot%\System32\drivers\etc\hosts


127.0.0.1 localhost


¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) (Standard disk drives) - ST3200826AS +++++
— User —
[MBR] c726e7a2558a51b8728e98e2a266511c
[BSP] 8a7884da59e414827f91c43dcf324e78 : Toshiba MBR Code
Partition table:
0 - [XXXXXX] FAT32-LBA (0x0c) [VISIBLE] Offset (sectors): 63 | Size: 8714 Mo
1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 17848215 | Size: 182064 Mo
User = LL1 … OK!
User = LL2 … OK!

Finished : << RKreport[0]_S_10022013_161211.txt >>


—————————————————————————————————————————————————————————————-

Results of screen317's Security Check version 0.99.74
Windows XP Service Pack 3 x86
Internet Explorer 8
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Disabled!
Microsoft Security Essentials
Antivirus up to date! (On Access scanning disabled!)
`````````Anti-malware/Other Utilities Check:`````````
Out of date HijackThis installed!
SpyHunter
Malwarebytes Anti-Malware version 1.75.0.1300
HijackThis 2.0.2
Java™ 7 Update 1
Java version out of Date!
Adobe Flash Player 11.8.800.168
Adobe Reader 10.1.8 Adobe Reader out of Date!
Mozilla Firefox 23.0.1 Firefox out of Date!
Google Chrome 29.0.1547.66
Google Chrome 29.0.1547.76
````````Process Check: objlist.exe by Laurent````````
Microsoft Security Essentials MSMpEng.exe
Microsoft Security Essentials msseces.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C:: 9%
````````````````````End of Log``````````````````````
Hello RetiredChief

Your problem related to the display after the system sleeps/hibernates may be due to a glitch in the “turn off display” settings or power options.

It may be worth starting a topic in our Windows forum when we are sure your computer is malware-free. I’ll give you the link when we’re finished.


I see you have Malwarebytes on your computer. Please update and run it then post the log.

=========================================

Run OTL
  • open OTL again, click on Extra Registry -> Use Safelist
  • then click Run Scan
Post back with the 2 logfiles and the Malwarebytes log.

Satchfan
Here ya go:

OTL logfile created on: 10/3/2013 8:37:16 AM - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\HP_Administrator\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

958.48 Mb Total Physical Memory | 106.63 Mb Available Physical Memory | 11.12% Memory free
2.26 Gb Paging File | 1.45 Gb Available in Paging File | 64.34% Paging File free
Paging file location(s): C:\pagefile.sys 1440 2880 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 177.80 Gb Total Space | 137.45 Gb Free Space | 77.31% Space Free | Partition Type: NTFS
Drive D: | 8.50 Gb Total Space | 1.12 Gb Free Space | 13.12% Space Free | Partition Type: FAT32

Computer Name: BLAKLEY | User Name: HP_Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2013/10/02 11:01:33 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\HP_Administrator\Desktop\OTL(1).exe
PRC - [2013/09/16 20:21:30 | 000,829,392 | —- | M] (Google Inc.) – C:\Program Files\Google\Chrome\Application\chrome.exe
PRC - [2013/06/20 18:05:14 | 000,022,208 | —- | M] (Microsoft Corporation) – c:\Program Files\Microsoft Security Client\MsMpEng.exe
PRC - [2013/06/20 17:25:44 | 000,995,176 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2013/04/04 14:50:32 | 000,887,432 | —- | M] (Malwarebytes Corporation) – C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
PRC - [2012/11/28 04:45:16 | 001,868,432 | —- | M] () – C:\Program Files\COMODO\Dragon\dragon_updater.exe
PRC - [2012/10/02 12:13:44 | 003,064,000 | —- | M] (Skype Technologies S.A.) – C:\Documents and Settings\All Users\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe
PRC - [2010/05/20 15:27:24 | 000,139,632 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft LifeCam\MSCamS32.exe
PRC - [2008/04/13 17:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2007/09/11 13:11:00 | 006,823,860 | —- | M] () – C:\Documents and Settings\All Users\Application Data\Renaissance Wireless Server\Renaissance Wireless Server.exe
PRC - [2005/08/03 00:19:16 | 000,058,880 | —- | M] (Microsoft) – C:\WINDOWS\arservice.exe


========== Modules (No Company Name) ==========

MOD - [2013/09/16 20:21:27 | 000,410,576 | —- | M] () – C:\Program Files\Google\Chrome\Application\29.0.1547.76\ppgooglenaclpluginchrome.dll
MOD - [2013/09/16 20:21:26 | 013,611,984 | —- | M] () – C:\Program Files\Google\Chrome\Application\29.0.1547.76\PepperFlash\pepflashplayer.dll
MOD - [2013/09/16 20:21:25 | 004,053,456 | —- | M] () – C:\Program Files\Google\Chrome\Application\29.0.1547.76\pdf.dll
MOD - [2013/09/16 20:20:31 | 001,604,560 | —- | M] () – C:\Program Files\Google\Chrome\Application\29.0.1547.76\ffmpegsumo.dll
MOD - [2013/01/01 23:49:10 | 001,292,288 | —- | M] () – C:\WINDOWS\system32\quartz.dll
MOD - [2012/11/28 04:45:16 | 001,868,432 | —- | M] () – C:\Program Files\COMODO\Dragon\dragon_updater.exe
MOD - [2011/06/24 22:56:36 | 000,087,328 | —- | M] () – C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/06/24 22:56:14 | 001,241,888 | —- | M] () – C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011/02/04 18:48:30 | 000,291,840 | —- | M] () – C:\WINDOWS\system32\sbe.dll
MOD - [2008/04/13 17:11:59 | 000,014,336 | —- | M] () – C:\WINDOWS\system32\msdmo.dll
MOD - [2008/04/13 17:11:51 | 000,059,904 | —- | M] () – C:\WINDOWS\system32\devenum.dll
MOD - [2007/09/11 13:11:00 | 006,823,860 | —- | M] () – C:\Documents and Settings\All Users\Application Data\Renaissance Wireless Server\Renaissance Wireless Server.exe
MOD - [2005/08/03 00:19:16 | 000,050,176 | —- | M] () – C:\WINDOWS\armcex.dll
MOD - [2005/03/15 23:17:28 | 000,204,800 | —- | M] () – c:\Program Files\HP\Digital Imaging\bin\HpqUtil.dll


========== Services (SafeList) ==========

SRV - File not found [Auto | Stopped] – C:\Program Files\Motorola\MotoHelper\MotoHelperService.exe – (MotoHelper)
SRV - File not found [On_Demand | Stopped] – C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe – (McComponentHostService)
SRV - [2013/09/20 16:59:26 | 000,257,416 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe – (AdobeFlashPlayerUpdateSvc)
SRV - [2013/08/20 09:57:43 | 000,117,656 | —- | M] (Mozilla Foundation) [On_Demand | Stopped] – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe – (MozillaMaintenance)
SRV - [2013/06/20 18:05:14 | 000,022,208 | —- | M] (Microsoft Corporation) [Auto | Running] – c:\Program Files\Microsoft Security Client\MsMpEng.exe – (MsMpSvc)
SRV - [2013/01/08 12:55:20 | 000,161,536 | R— | M] (Skype Technologies) [Auto | Stopped] – C:\Program Files\Skype\Updater\Updater.exe – (SkypeUpdate)
SRV - [2012/11/28 04:45:16 | 001,868,432 | —- | M] () [Auto | Running] – C:\Program Files\COMODO\Dragon\dragon_updater.exe – (DragonUpdater)
SRV - [2012/10/02 12:13:44 | 003,064,000 | —- | M] (Skype Technologies S.A.) [Auto | Running] – C:\Documents and Settings\All Users\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe – (Skype C2C Service)
SRV - [2012/02/24 06:26:28 | 000,261,952 | —- | M] (Comodo Security Solutions, Inc.) [Auto | Stopped] – C:\Program Files\COMODO\COMODO System Utilities\CSUService.exe – (CSUService)
SRV - [2010/05/20 15:27:24 | 000,139,632 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Microsoft LifeCam\MSCamS32.exe – (MSCamSvc)
SRV - [2005/08/03 00:19:16 | 000,058,880 | —- | M] (Microsoft) [Auto | Running] – C:\WINDOWS\arservice.exe – (ARSVC)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] – – (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDCOMP)
DRV - File not found [Kernel | System | Stopped] – – (PCIDump)
DRV - File not found [Kernel | On_Demand | Stopped] – system32\DRIVERS\motport.sys – (motport)
DRV - File not found [Kernel | On_Demand | Stopped] – system32\DRIVERS\motmodem.sys – (motmodem)
DRV - File not found [Kernel | On_Demand | Stopped] – system32\DRIVERS\motccgpfl.sys – (motccgpfl)
DRV - File not found [Kernel | On_Demand | Stopped] – system32\DRIVERS\motccgp.sys – (motccgp)
DRV - File not found [Kernel | On_Demand | Stopped] – system32\DRIVERS\mcdbus.sys – (mcdbus)
DRV - File not found [Kernel | System | Stopped] – – (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] – – (i2omgmt)
DRV - File not found [Kernel | System | Stopped] – – (Changer)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\catchme.sys – (catchme)
DRV - [2013/10/03 06:43:40 | 000,040,776 | —- | M] (Malwarebytes Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\mbamswissarmy.sys – (MBAMSwissArmy)
DRV - [2011/08/03 13:54:12 | 000,223,128 | —- | M] (DT Soft Ltd.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\dtscsi.sys – (dtscsi)
DRV - [2011/08/03 13:31:07 | 000,664,064 | —- | M] () [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\sptd.sys – (sptd)
DRV - [2010/05/20 15:27:24 | 000,030,576 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\nx6000.sys – (MSHUSBVideo)
DRV - [2010/04/28 07:44:02 | 000,054,760 | —- | M] (Microsoft Corporation) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\fssfltr_tdi.sys – (fssfltr)
DRV - [2010/03/22 23:53:12 | 000,816,672 | R— | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\AE1000XP.sys – (AE1000)
DRV - [2009/08/19 14:49:22 | 000,049,904 | R— | M] (Avanquest Software) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\BVRPMPR5.SYS – (BVRPMPR5)
DRV - [2005/08/29 15:11:00 | 003,644,928 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ALCXWDM.SYS – (ALCXWDM)
DRV - [2005/08/13 22:35:54 | 001,313,792 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ati2mtag.sys – (ati2mtag)
DRV - [2005/07/04 00:30:34 | 000,026,624 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\PS2.sys – (Ps2)
DRV - [2005/06/30 01:03:18 | 000,175,104 | —- | M] (Promise Technology, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\ftsata2.sys – (ftsata2)
DRV - [2005/03/09 14:53:00 | 000,036,352 | —- | M] (Advanced Micro Devices) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\AmdK8.sys – (AmdK8)
DRV - [2005/03/04 11:10:26 | 000,074,496 | —- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\Rtlnicxp.sys – (RTL8023xp)
DRV - [2004/12/15 15:18:32 | 000,220,928 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HSFHWBS2.sys – (HSFHWBS2)
DRV - [2004/12/15 15:18:28 | 000,703,232 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HSF_CNXT.sys – (winachsf)
DRV - [2004/12/15 15:18:26 | 001,038,208 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HSF_DP.sys – (HSF_DP)
DRV - [2004/08/03 22:31:34 | 000,020,992 | —- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\RTL8139.sys – (rtl8139)
DRV - [2003/11/05 15:45:12 | 000,017,408 | —- | M] (Promise Technology, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\bb-run.sys – (bb-run)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}: "URL" = http://us.yhs.search.yahoo.com/avg/search?…p={searchTerms}


IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:5555

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:5555

IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-657425056-1587324396-1979525332-1008\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKU\S-1-5-21-657425056-1587324396-1979525332-1008\..\SearchScopes,DefaultScope = {CCC7A320-B3CA-4199-B1A6-9F516DD69829}
IE - HKU\S-1-5-21-657425056-1587324396-1979525332-1008\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?FORM=WLETDF&…rc=IE-SearchBox
IE - HKU\S-1-5-21-657425056-1587324396-1979525332-1008\..\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}: "URL" = http://us.search.yahoo.com/search?p={searc…p;fr=chr-comodo
IE - HKU\S-1-5-21-657425056-1587324396-1979525332-1008\..\SearchScopes\{DDC8D966-465C-2856-0BFE-6F4974176253}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;form=ZGAIDF
IE - HKU\S-1-5-21-657425056-1587324396-1979525332-1008\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-657425056-1587324396-1979525332-1008\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 192.168.*.*

========== FireFox ==========

FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:23.0.1
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_8_800_168.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.6.14: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.6.14: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.6.14: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.6.14: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=15.0.6.14: c:\program files\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.1: C:\Documents and Settings\HP_Administrator\Application Data\Facebook\npfbplugin_1_0_1.dll ( )
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.3: C:\Documents and Settings\HP_Administrator\Application Data\Facebook\npfbplugin_1_0_3.dll ( )
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{0153E448-190B-4987-BDE1-F256CADA672F}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012/10/13 08:27:12 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 23.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/08/20 09:56:11 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 23.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/09/19 16:20:14 | 000,000,000 | —D | M]

[2010/02/11 18:35:24 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Extensions
[2013/10/02 11:03:48 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ca60dke4.default-1380498043446\extensions
[2013/08/02 10:40:03 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\op5b9w5g.default\extensions
[2013/08/20 09:56:12 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2013/08/20 09:56:12 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2013/08/20 09:56:14 | 000,000,000 | —D | M] (Skype Click to Call) – C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2013/08/20 09:56:10 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\browser\extensions
[2013/08/20 09:57:45 | 000,000,000 | —D | M] (Default) – C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2011/11/15 22:19:08 | 000,611,224 | —- | M] (Oracle Corporation) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2012/10/13 08:26:53 | 000,129,176 | —- | M] (RealPlayer) – C:\Program Files\mozilla firefox\plugins\nprpplugin.dll

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{g
oogle:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:ins
tantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncodin
g}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyPar
ameter}
CHR - homepage: http://us.yahoo.com?fr=fpc-comodo
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\29.0.1547.76\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 7.0.10.8 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 7 U1 (Enabled) = C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\Microsoft\Office Live\npOLW.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\29.0.1547.76\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\29.0.1547.76\pdf.dll
CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npMozCouponPrinter.dll
CHR - plugin: Facebook Plugin (Enabled) = C:\Documents and Settings\HP_Administrator\Application Data\Facebook\npfbplugin_1_0_1.dll
CHR - plugin: Facebook Plugin (Enabled) = C:\Documents and Settings\HP_Administrator\Application Data\Facebook\npfbplugin_1_0_3.dll
CHR - plugin: Unity Player (Enabled) = C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll
CHR - plugin: CANON iMAGE GATEWAY Album Plugin Utility (Enabled) = C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\
CHR - Extension: Skype Click to Call = C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.9.0.9216_0\
CHR - Extension: Chrome In-App Payments service = C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_0\

O1 HOSTS File: ([2011/11/11 22:40:13 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKU\S-1-5-21-657425056-1587324396-1979525332-1008\..\Toolbar\WebBrowser: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-657425056-1587324396-1979525332-1008..\Run: [Facebook Update] C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Renaissance Wireless Server.lnk = C:\Documents and Settings\All Users\Application Data\Renaissance Wireless Server\Renaissance Wireless Server.exe ()
O4 - Startup: C:\Documents and Settings\Default User\Start Menu\Programs\Startup\Pin.lnk = C:\hp\bin\cloaker.exe (Hewlett-Packard Co.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-657425056-1587324396-1979525332-1008\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-657425056-1587324396-1979525332-1008\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-657425056-1587324396-1979525332-1008\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-657425056-1587324396-1979525332-1008\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ()
O9 - Extra 'Tools' menuitem : Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ()
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_01)
O16 - DPF: {CAFEEFAC-0017-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_01)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_01)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/shock…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4F9665E1-6A11-4972-B941-EB22DFA68FC7}: NameServer = 8.26.56.26,156.154.70.22
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{837C5F68-FB84-414E-8FEC-9FA666C52334}: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{837C5F68-FB84-414E-8FEC-9FA666C52334}: NameServer = 8.26.56.26,156.154.70.22
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EFDC876F-B06E-4EBB-8CF6-7765A6D04335}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/11/10 17:46:21 | 000,000,100 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2010/08/15 11:46:17 | 000,000,000 | R–D | M] - C:\autorun.inf – [ NTFS ]
O32 - AutoRun File - [2001/07/28 05:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O32 - AutoRun File - [2010/08/15 11:46:18 | 000,000,000 | R–D | M] - D:\autorun.inf – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk /r \??\J:)
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2013/10/03 06:43:02 | 000,040,776 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2013/10/02 16:10:03 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Desktop\RK_Quarantine
[2013/10/02 12:04:37 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2013/10/02 11:32:57 | 000,518,144 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2013/10/02 11:32:57 | 000,406,528 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2013/10/02 11:32:57 | 000,060,416 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2013/10/02 11:32:56 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2013/10/02 11:04:39 | 000,000,000 | —D | C] – C:\_OTL
[2013/10/02 11:01:34 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Documents and Settings\HP_Administrator\Desktop\OTL(1).exe
[2013/09/29 16:40:47 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Desktop\Old Firefox Data
[2013/09/29 11:50:10 | 000,000,000 | —D | C] – C:\WINDOWS\ERUNT
[2013/09/29 11:35:27 | 000,000,000 | —D | C] – C:\AdwCleaner
[2013/09/24 16:13:35 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\My Documents\Pictures from Grammy
[2013/09/19 16:18:50 | 000,000,000 | —D | C] – C:\Config.Msi

========== Files - Modified Within 30 Days ==========

[2013/10/03 08:21:03 | 000,000,906 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2013/10/03 07:59:02 | 000,000,830 | —- | M] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2013/10/03 06:46:48 | 000,000,444 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{BF38A124-251E-4DD5-B80F-B1ED348AAA54}.job
[2013/10/03 06:43:40 | 000,040,776 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2013/10/03 06:36:08 | 000,000,384 | -H– | M] () – C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job
[2013/10/03 06:26:10 | 000,000,902 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2013/10/03 06:26:09 | 000,000,300 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-657425056-1587324396-1979525332-1008.job
[2013/10/03 06:25:54 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2013/10/03 06:25:51 | 1005,113,344 | -HS- | M] () – C:\hiberfil.sys
[2013/10/02 16:14:32 | 000,891,167 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\SecurityCheck.exe
[2013/10/02 16:09:00 | 000,948,736 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\RogueKiller.exe
[2013/10/02 11:57:01 | 000,001,042 | —- | M] () – C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-657425056-1587324396-1979525332-1008UA.job
[2013/10/02 11:32:14 | 005,132,885 | R— | M] (Swearware) – C:\Documents and Settings\HP_Administrator\Desktop\ComboFix.exe
[2013/10/02 11:01:33 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\HP_Administrator\Desktop\OTL(1).exe
[2013/10/02 10:50:33 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2013/09/30 14:57:00 | 000,001,020 | —- | M] () – C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-657425056-1587324396-1979525332-1008Core.job
[2013/09/29 21:31:00 | 000,000,484 | —- | M] () – C:\WINDOWS\tasks\CSU Updater.job
[2013/09/29 18:00:00 | 000,000,430 | —- | M] () – C:\WINDOWS\tasks\Norton Security Scan for HP_Administrator.job
[2013/09/29 17:13:31 | 000,000,512 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\MBR.dat
[2013/09/27 17:06:00 | 000,000,308 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-657425056-1587324396-1979525332-1008.job
[2013/09/25 20:58:28 | 000,000,249 | —- | M] () – C:\WINDOWS\System\hpsysdrv.dat
[2013/09/21 02:28:49 | 000,001,824 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2013/09/20 16:59:24 | 000,692,616 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2013/09/20 16:59:23 | 000,071,048 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2013/09/12 12:28:14 | 000,495,456 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2013/09/12 12:09:49 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2013/09/11 21:24:39 | 000,190,398 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\Proof (2).png
[2013/09/11 21:13:13 | 000,159,156 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\Proof (1).png
[2013/09/11 21:12:26 | 000,159,156 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\window cling.png
[2013/09/11 21:06:11 | 000,084,901 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\Proof.png
[2013/09/11 17:44:01 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2013/09/04 08:02:01 | 000,000,454 | —- | M] () – C:\WINDOWS\tasks\ReclaimerResumeInstall_HP_Administrator.job

========== Files Created - No Company Name ==========

[2013/10/02 16:14:30 | 000,891,167 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\SecurityCheck.exe
[2013/10/02 16:08:56 | 000,948,736 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\RogueKiller.exe
[2013/10/02 11:32:57 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2013/10/02 11:32:57 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2013/10/02 11:32:57 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2013/10/02 11:32:57 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2013/10/02 11:32:57 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2013/09/29 17:13:31 | 000,000,512 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\MBR.dat
[2013/09/11 21:24:41 | 000,190,398 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\Proof (2).png
[2013/09/11 21:13:16 | 000,159,156 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\Proof (1).png
[2013/09/11 21:12:39 | 000,159,156 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\window cling.png
[2013/09/11 21:06:18 | 000,084,901 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\Proof.png
[2013/03/28 22:17:19 | 001,474,832 | —- | C] () – C:\WINDOWS\System32\drivers\sfi.dat
[2012/02/14 15:28:51 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2011/11/06 14:58:18 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/10/16 15:14:47 | 000,000,000 | —- | C] () – C:\WINDOWS\DC200_DC210_Updater.INI
[2010/11/23 13:28:10 | 000,138,056 | —- | C] () – C:\Documents and Settings\HP_Administrator\Application Data\PnkBstrK.sys
[2010/09/06 16:05:21 | 000,000,129 | —- | C] () – C:\Documents and Settings\HP_Administrator\jagex_runescape_preferences2.dat
[2010/09/06 16:05:21 | 000,000,000 | —- | C] () – C:\Documents and Settings\HP_Administrator\jagex__preferences3.dat
[2010/04/04 21:48:35 | 000,000,000 | —- | C] () – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\prvlcl.dat
[2010/03/04 16:36:06 | 000,012,130 | -HS- | C] () – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\04lB
[2010/02/11 19:28:30 | 000,000,139 | —- | C] () – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\fusioncache.dat
[2008/08/26 15:30:07 | 000,000,046 | —- | C] () – C:\Documents and Settings\HP_Administrator\jagex_runescape_preferences.dat
[2006/04/04 16:11:55 | 000,031,744 | —- | C] () – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/03/31 22:57:29 | 000,005,336 | —- | C] () – C:\Documents and Settings\HP_Administrator\Application Data\wklnhst.dat

========== ZeroAccess Check ==========

[2005/08/31 04:58:26 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll – [2008/04/13 17:12:05 | 001,499,136 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2009/02/09 05:10:48 | 000,473,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2008/04/13 17:12:08 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

< End of report >

————————————————————————————————————————-

OTL Extras logfile created on: 10/3/2013 8:37:16 AM - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\HP_Administrator\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

958.48 Mb Total Physical Memory | 106.63 Mb Available Physical Memory | 11.12% Memory free
2.26 Gb Paging File | 1.45 Gb Available in Paging File | 64.34% Paging File free
Paging file location(s): C:\pagefile.sys 1440 2880 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 177.80 Gb Total Space | 137.45 Gb Free Space | 77.31% Space Free | Partition Type: NTFS
Drive D: | 8.50 Gb Total Space | 1.12 Gb Free Space | 13.12% Space Free | Partition Type: FAT32

Computer Name: BLAKLEY | User Name: HP_Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = ChromeHTML] – C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l

[HKEY_USERS\S-1-5-21-657425056-1587324396-1979525332-1008\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
https [open] – "C:\Program Files\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" = C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger – (Microsoft Corporation)
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync – (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Documents and Settings\All Users\Application Data\Renaissance Wireless Server\Renaissance Wireless Server.exe" = C:\Documents and Settings\All Users\Application Data\Renaissance Wireless Server\Renaissance Wireless Server.exe:*:Enabled:Renaissance Wireless Server 1.4.5 – ()
"C:\Program Files\Microsoft LifeCam\LifeCam.exe" = C:\Program Files\Microsoft LifeCam\LifeCam.exe:*:Enabled:LifeCam.exe – (Microsoft Corporation)
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" = C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger – (Microsoft Corporation)
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync – (Microsoft Corporation)
"C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Facebook\Video\Skype\FacebookVideoCalling.exe" = C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Facebook\Video\Skype\FacebookVideoCalling.exe:*:Disabled:Facebook Video Calling Plugin – (Skype Limited)
"C:\Program Files\Microsoft LifeCam\LifeEnC2.exe" = C:\Program Files\Microsoft LifeCam\LifeEnC2.exe:*:Disabled:LifeEnC2.exe – (Microsoft Corporation)
"C:\Program Files\Microsoft LifeCam\LifeExp.exe" = C:\Program Files\Microsoft LifeCam\LifeExp.exe:*:Disabled:LifeExp.exe – (Microsoft Corporation)
"C:\Program Files\Microsoft LifeCam\LifeTray.exe" = C:\Program Files\Microsoft LifeCam\LifeTray.exe:*:Disabled:LifeTray.exe – (Microsoft Corporation)
"C:\Program Files\Rhapsody\rhapsody.exe" = C:\Program Files\Rhapsody\rhapsody.exe:*:Disabled:RealNetworks Rhapsody – (Rhapsody International Inc.)
"C:\WINDOWS\system32\sessmgr.exe" = C:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)
"C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe" = C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit – (Apple Inc.)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)
"C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype – (Skype Technologies S.A.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{03B1B42B-F6DE-41d9-8CFF-DC44E895C7A7}" = PhotoGallery
"{03CE1BCB-03F5-4C6A-B37E-69799AA3C544}" = SpyHunter
"{0611BD4E-4FE4-4a62-B0C0-18A4CC463428}" = CP_Package_Variety1
"{069730C2-755A-485B-A205-27A1AAFA836A}" = InstantShareAlert
"{075473F5-846A-448B-BCB3-104AA1760205}" = Sonic RecordNow Data
"{09984AEC-6B9F-4ca7-B78D-CB44D4771DA3}" = Destinations
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG5200_series" = Canon MG5200 series MP Drivers
"{172975EB-9465-4861-95B5-C7BB6D3DE62A}" = DocumentViewer
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{1C139D7D-9FEA-468d-A9C8-2A6E3BDE564A}" = CP_Package_Variety3
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{21657574-BD54-48A2-9450-EB03B2C7FC29}" = Sonic MyDVD Plus
"{21DB3D90-D816-4092-A260-CA3F6B55A6DD}" = Sonic_PrimoSDK
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{23A7B376-BBEC-4e76-BBD7-0F155E70D74B}" = CP_Panorama1Config
"{268278CF-FB69-4D98-B70E-BFEC1CDCA225}" = iTunes
"{26A24AE4-039D-4CA4-87B4-2F83217001FF}" = Java™ 7 Update 1
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2C5D07FB-31A2-4F2D-9FDA-0B24ACD42BD0}" = HP Deskjet Printer Preload
"{2CADCEAB-D5DA-44D6-B5FC-7DEE87AB3C0C}" = Unload
"{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}" = HP Update
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
"{30C19FF2-7FBA-4d09-B9DE-1659977F64F6}" = TrayApp
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{32BDCCB8-9DC8-496d-9DB1-F77510775BDB}" = InstantShareDevices
"{33D6CC28-9F75-4d1b-A11D-98895B3A3729}" = HP Photosmart 330,380,420,470,7800,8000,8200 Series
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{36E47DA1-10E1-45d9-8B19-14D19607CDCF}" = CP_CalendarTemplates1
"{36FDBE6E-6684-462B-AE98-9A39A1B200CC}" = HP Product Assistant
"{382E94C0-6E22-44e4-B003-8EB31DFE296F}" = cp_LightScribeConfig
"{3912A629-0020-0005-3757-2FBA74D4DF0A}" = InterVideo WinDVD Player
"{3BA95526-6AE0-4B87-A62D-17187EF565FC}" = HP Boot Optimizer
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3DADB23F-94E6-4E4D-AFE8-15DE4395E8F3}" = Microsoft Security Client
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{45C56AA7-ED1B-4800-A97F-EDDF3F3520B1}" = Apple Application Support
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype™ 6.1
"{56EE8B17-8274-418d-89AC-C057C5DB251E}" = RandMap
"{56F8AFC3-FA98-4ff1-9673-8A026CBF85BE}" = WebReg
"{5A01C58E-B0EC-49b9-AD71-7C0468688087}" = CP_Package_Basic1
"{5FC7AB5C-61FC-42DF-A923-5139BCF10D42}" = Microsoft LifeCam
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{66BA8C26-AFE4-4408-807B-43E76B57EF53}" = SkinsHP1
"{6BB6627C-694F-4FDC-A3E5-C7F4BED4C724}" = DocProc
"{6F340107-F9AA-47C6-B54C-C3A19F11553F}" = Hewlett-Packard ACLM.NET v1.1.0.0
"{710BF966-43C8-4216-A8EC-BC4E169FF7C1}" = MobileMe Control Panel
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{755EC5E3-FD51-46bd-A57F-7A2D56FBF061}" = PSTAPlugin
"{769A295C-DCF4-41d6-AFBA-7D9394B23AFE}" = PSPrinters08
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7C03270C-4FAB-4F5C-B10D-52FEDA190790}" = DocumentViewerQFolder
"{7E27304E-BAA2-4d90-A34E-76641FAFABB4}" = CP_AtenaShokunin1Config
"{8105684D-8CA6-440D-8F58-7E5FD67A499D}" = Easy Internet Sign-up
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISER_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISER_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISER_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISER_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISER_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{91120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{91120000-0030-0000-0000-0000000FF1CE}_ENTERPRISER_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{91477C6F-EC7C-4BFC-BBE1-E45908019DED}" = LightScribe 1.4.52.1
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD Player
"{94CAC2F1-C856-47F4-AF24-65A1E75AEDB9}" = MotoHelper MergeModules
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95120000-0122-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{96AD3B61-EAE2-11E2-9E72-B8AC6F98CCE3}" = Google Earth
"{A195B13E-A5E3-4BAF-A995-7F70F445CD06}" = ScannerCopy
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A3455242-DAE0-4523-8242-FD82706ABF4B}" = CameraDrivers
"{A436F67F-687E-4736-BD2B-537121A804CF}" = HP Product Detection
"{A5BB5365-EFB4-44c3-A7E2-EB59B7EFD23D}" = CueTour
"{A7DA4247-9F22-4d4a-974A-DD455CCF43B6}" = COMODO System Utilities
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Sonic RecordNow Audio
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.8)
"{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}" = QuickTime
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Sonic RecordNow Copy
"{B3BC9DB1-0B0A-48B0-B86B-EA77CAA7F800}" = Microsoft Corporation
"{B4D279F1-4309-49cc-A4B5-3A0D2E59C7B5}" = PanoStandAlone
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{B824B5C9-849F-4b9e-9EA7-6FD8CD8116DA}" = CP_Package_Variety2
"{B92C5909-1D37-4C51-8397-A28BB28E5DC3}" = Facebook Video Calling 1.2.0.287
"{B996AE66-10DB-4ac5-B151-E8B4BFBC42FC}" = BufferChm
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C104580B-1C79-4d73-9BF0-CA0B184296A4}" = cp_LightScribePlugin
"{C83A12B9-B31B-461A-BBD4-CE9B988094F1}" = HP Photosmart Cameras 5.0
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D518592A-0F1E-40ca-BECB-3D3F026C6B0D}" = CameraDrivers
"{D92FF8EB-BD77-40AE-B68B-A6BFC6F8661D}" = Windows Live Family Safety
"{DB518BA6-CB74-4EB6-9ABD-880B6D6E1F38}" = HpSdpAppCoreApp
"{DFB0FED6-0010-4E9B-A402-E513F2459161}" = muvee autoProducer unPlugged 1.2
"{E14ADE0E-75F3-4A46-87E5-26692DD626EC}" = Apple Mobile Device Support
"{E3F90083-80D4-4b5a-87C7-E97E12F5516D}" = HPProductAssistant
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{E7137AFD-4E43-47A6-BDC7-533808F72B36}" = muvee autoProducer 4.5
"{EA103B64-C0E4-4C0E-A506-751590E1653D}" = SolutionCenter
"{EE39FFBD-544E-49E4-A999-6819828EAE91}" = Windows Live Photo Gallery
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5
"{F4C2E5F5-2970-45f4-ABD3-C180C4D961C4}" = Status
"{F80239D8-7811-4D5E-B033-0D0BBFE32920}" = HP DigitalMedia Archive
"{FDB3B167-F4FA-461D-976F-286304A57B2A}" = Adobe AIR
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"ATI Display Driver" = ATI Display Driver
"AwayMode160" = Microsoft Away Mode
"Canon MG5200 series User Registration" = Canon MG5200 series User Registration
"CanonMyPrinter" = Canon My Printer
"CanonSolutionMenuEX" = Canon Solution Menu EX
"CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200C14F1" = Data Fax SoftModem with SmartCP
"Comodo Dragon" = Comodo Dragon
"Easy-PhotoPrint EX" = Canon Easy-PhotoPrint EX
"Easy-WebPrint EX" = Canon Easy-WebPrint EX
"ENTERPRISER" = Microsoft Office Enterprise 2007
"ESET Online Scanner" = ESET Online Scanner v3
"Google Chrome" = Google Chrome
"Hello Kitty Snap n Share" = Hello Kitty Snap n Share
"HijackThis" = HijackThis 2.0.2
"HP Document Viewer" = HP Document Viewer 5.3
"HP Image Zone for Media Center PC" = HP Image Zone for Media Center PC
"HP Imaging Device Functions" = HP Imaging Device Functions 5.3
"HP Photo & Imaging" = HP Image Zone 5.3
"HP Solution Center & Imaging Support Tools" = HP Solution Center & Imaging Support Tools 5.3
"HPOOVClient-9972322 Uninstaller" = Updates from HP (remove only)
"ie8" = Windows Internet Explorer 8
"InstallShield_{8105684D-8CA6-440D-8F58-7E5FD67A499D}" = Easy Internet Sign-up
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.75.0.1300
"MapsGalaxy_39bar Uninstall Firefox" = MapsGalaxy Firefox Toolbar
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft Security Client" = Microsoft Security Essentials
"Mozilla Firefox 23.0.1 (x86 en-US)" = Mozilla Firefox 23.0.1 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MP Navigator EX 4.0" = Canon MP Navigator EX 4.0
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"RealPlayer 15.0" = RealPlayer
"Rhapsody" = Rhapsody
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-657425056-1587324396-1979525332-1008\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Facebook Plug-In" = Facebook Plug-In

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 9/22/2013 5:10:57 AM | Computer Name = BLAKLEY | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: A connection with the server could not be established

Error - 9/22/2013 5:31:41 AM | Computer Name = BLAKLEY | Source = Application Error | ID = 1000
Description = Faulting application Skype.exe, version 6.1.0.129, faulting module
unknown, version 0.0.0.0, fault address 0x00000200.

Error - 9/24/2013 7:08:27 PM | Computer Name = BLAKLEY | Source = Application Error | ID = 1000
Description = Faulting application photoapp.exe, version 2.3.0.502, faulting module
photoapp.exe, version 2.3.0.502, fault address 0x0006861e.

Error - 9/24/2013 7:08:32 PM | Computer Name = BLAKLEY | Source = Application Error | ID = 1001
Description = Fault bucket 1021164869.

Error - 9/29/2013 4:42:16 AM | Computer Name = BLAKLEY | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

Error - 9/29/2013 4:42:17 AM | Computer Name = BLAKLEY | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: A connection with the server could not be established

Error - 9/29/2013 2:49:35 PM | Computer Name = BLAKLEY | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 unspecified, P2 hardeningtelemetry, P3 hardeningtelemetrydisablertp,
P4 4.3.215.0, P5 unspecified, P6 unspecified, P7 unspecified, P8 NIL, P9 NIL, P10
NIL.

Error - 9/29/2013 3:58:52 PM | Computer Name = BLAKLEY | Source = Application Hang | ID = 1002
Description = Hanging application OTL(1).exe, version 3.2.69.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 9/29/2013 3:59:02 PM | Computer Name = BLAKLEY | Source = Application Hang | ID = 1001
Description = Fault bucket -1102560245.

Error - 9/29/2013 4:03:25 PM | Computer Name = BLAKLEY | Source = Application Hang | ID = 1002
Description = Hanging application OTL(1).exe, version 3.2.69.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

[ OSession Events ]
Error - 1/4/2012 3:08:59 AM | Computer Name = BLAKLEY | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6612.1000, Microsoft Office Version: 12.0.6612.1000. This session lasted 12429
seconds with 1680 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 10/2/2013 2:04:41 PM | Computer Name = BLAKLEY | Source = Service Control Manager | ID = 7034
Description = The LightScribeService Direct Disc Labeling Service service terminated
unexpectedly. It has done this 1 time(s).

Error - 10/2/2013 2:04:41 PM | Computer Name = BLAKLEY | Source = Service Control Manager | ID = 7034
Description = The MSCamSvc service terminated unexpectedly. It has done this 1
time(s).

Error - 10/2/2013 2:04:41 PM | Computer Name = BLAKLEY | Source = Service Control Manager | ID = 7034
Description = The Pml Driver HPZ12 service terminated unexpectedly. It has done
this 1 time(s).

Error - 10/2/2013 2:04:42 PM | Computer Name = BLAKLEY | Source = Service Control Manager | ID = 7034
Description = The Skype C2C Service service terminated unexpectedly. It has done
this 1 time(s).

Error - 10/2/2013 2:15:04 PM | Computer Name = BLAKLEY | Source = Service Control Manager | ID = 7000
Description = The MotoHelper Service service failed to start due to the following
error: %%2

Error - 10/2/2013 2:31:42 PM | Computer Name = BLAKLEY | Source = Service Control Manager | ID = 7034
Description = The Skype C2C Service service terminated unexpectedly. It has done
this 1 time(s).

Error - 10/2/2013 7:04:04 PM | Computer Name = BLAKLEY | Source = Service Control Manager | ID = 7000
Description = The MotoHelper Service service failed to start due to the following
error: %%2

Error - 10/2/2013 7:05:29 PM | Computer Name = BLAKLEY | Source = Service Control Manager | ID = 7022
Description = The MSCamSvc service hung on starting.

Error - 10/2/2013 7:10:08 PM | Computer Name = BLAKLEY | Source = Service Control Manager | ID = 7034
Description = The ARSVC service terminated unexpectedly. It has done this 1 time(s).

Error - 10/3/2013 9:26:09 AM | Computer Name = BLAKLEY | Source = Service Control Manager | ID = 7000
Description = The MotoHelper Service service failed to start due to the following
error: %%2


< End of report >

———————————————————————————————————————————————

Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Database version: v2013.10.03.05

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
HP_Administrator :: BLAKLEY [administrator]

10/3/2013 6:44:06 AM
MBAM-log-2013-10-03 (08-33-59).txt

Scan type: Full scan (C:\|D:\|E:\|G:\|H:\|I:\|J:\|K:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 395606
Time elapsed: 1 hour(s), 42 minute(s), 12 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 4
C:\Documents and Settings\HP_Administrator\Desktop\EmailNotifierSetup.exe (PUP.Optional.Inbox) -> No action taken.
C:\Documents and Settings\HP_Administrator\My Documents\Downloads\EmailNotifierSetup.exe (PUP.Optional.Inbox) -> No action taken.
C:\Documents and Settings\HP_Administrator\My Documents\My Pictures\New Folder\EmailNotifierSetup.exe (PUP.Optional.Inbox) -> No action taken.
C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Extensions\{1FD91A9C-410C-4090-BBCC-55D3450EF433} (PUP.Optional.Searchqu.A) -> No action taken.

(end)
Apologies for the delay but I had a family emergency and am just catching up.

I will check your OTL log as soon as I can.

Meanwhile, you ran Malwarebytes but did’t allow it to remove the files it found. Please run it again
  • when the scan is complete, click OK, then Show Results to view the results.
  • be sure that everything is checked, and click Remove Selected.
  • when removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • the log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • copy and paste the contents of that report in your next reply and exit MBAM.
NOTE: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

===================================================

I noticed that your proxy has been reset – it could be Comodo but I’ll have to check on that.

Meanwhile I’d like to see what an online scan shows.

Run ESET Online Scan

IMPORTANT Please make sure you uncheck the box next to Remove found threats. Eset will detect anything that looks even slightly suspicious, which could include legitimate program files. If you do not uncheck the box, Eset will automatically remove all suspicious files which could leave some of your software inoperable.

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Hold down Control and click on the following link to open ESET OnlineScan in a new window.

ESET OnlineScan
  • click the Eset online Scanner button.
  • for alternate browsers only: (Microsoft Internet Explorer users can skip these steps)


    o click on esetinstaller.exe to download the ESET Smart Installer. Save it to your desktop.
    o double click on the Eset installer icon on your desktop.

  • check Yes, I accept the Terms of Use
  • click the Start button.
  • accept any security warnings from your browser.
  • check Scan archives and Remove found threats.
  • click Advanced settings and select the following:


    o Scan potentially unwanted applications
    o Scan for potentially unsafe applications
    o Enable Anti-Stealth technology

  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • when the scan completes, push List of found threats
  • push Export to Text file and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.

    Note - if ESET doesn't find any threats, no report will be created.
  • push the back button.
  • push Finish
When the scan is complete:

If no threats were found:o put a checkmark in "Uninstall application on close"
o close program
o report to me that nothing was found

If threats were found:o click on "list of threats found"
o click on "export to text file" and save it as ESET results and save to the desktop
o Click on back
o put a checkmark in "Uninstall application on close"
o click on finish
o close program
o copy and paste the report here
Thanks

Satchfan
Here are the scans as directed, Thanks! Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Database version: v2013.10.04.06 Windows XP Service Pack 3 x86 NTFS Internet Explorer 8.0.6001.18702 HP_Administrator :: BLAKLEY [administrator] 10/4/2013 7:33:38 AM mbam-log-2013-10-04 (07-33-38).txt Scan type: Full scan (C:\|D:\|E:\|G:\|H:\|I:\|J:\|K:\|) Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 395645 Time elapsed: 1 hour(s), 42 minute(s), 33 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 4 C:\Documents and Settings\HP_Administrator\Desktop\EmailNotifierSetup.exe (PUP.Optional.Inbox) -> Quarantined and deleted successfully. C:\Documents and Settings\HP_Administrator\My Documents\Downloads\EmailNotifierSetup.exe (PUP.Optional.Inbox) -> Quarantined and deleted successfully. C:\Documents and Settings\HP_Administrator\My Documents\My Pictures\New Folder\EmailNotifierSetup.exe (PUP.Optional.Inbox) -> Quarantined and deleted successfully. C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Extensions\{1FD91A9C-410C-4090-BBCC-55D3450EF433} (PUP.Optional.Searchqu.A) -> Quarantined and deleted successfully. (end) ——————————————————————————————————————————————————————————————————————————————— C:\AdwCleaner\Quarantine\C\Program Files\mapsgalaxy_39\bar\1.bin\39bar.dll.vir a variant of Win32/Toolbar.MyWebSearch.W application C:\AdwCleaner\Quarantine\C\Program Files\mapsgalaxy_39\bar\1.bin\39datact.dll.vir a variant of Win32/Toolbar.MyWebSearch.A application C:\AdwCleaner\Quarantine\C\Program Files\mapsgalaxy_39\bar\1.bin\39htmlmu.dll.vir probably a variant of Win32/Toolbar.MyWebSearch.B application C:\AdwCleaner\Quarantine\C\Program Files\mapsgalaxy_39\bar\1.bin\39impipe.exe.vir Win32/Toolbar.MyWebSearch.W application C:\AdwCleaner\Quarantine\C\Program Files\mapsgalaxy_39\bar\1.bin\39Plugin.dll.vir probably a variant of Win32/Toolbar.MyWebSearch application C:\AdwCleaner\Quarantine\C\Program Files\mapsgalaxy_39\bar\1.bin\39reghk.dll.vir Win32/Toolbar.MyWebSearch.W application C:\AdwCleaner\Quarantine\C\Program Files\mapsgalaxy_39\bar\1.bin\39skin.dll.vir a variant of Win32/Toolbar.MyWebSearch.P application C:\AdwCleaner\Quarantine\C\Program Files\mapsgalaxy_39\bar\1.bin\39skplay.exe.vir Win32/Toolbar.MyWebSearch.W application C:\AdwCleaner\Quarantine\C\Program Files\mapsgalaxy_39\bar\1.bin\39SrchMn.exe.vir Win32/Toolbar.MyWebSearch.W application C:\AdwCleaner\Quarantine\C\Program Files\mapsgalaxy_39\bar\1.bin\AppIntegrator64.exe.vir Win64/Toolbar.MyWebSearch.A application C:\AdwCleaner\Quarantine\C\Program Files\mapsgalaxy_39\bar\1.bin\AppIntegratorStub64.dll.vir Win64/Toolbar.MyWebSearch.A application C:\AdwCleaner\Quarantine\C\Program Files\mapsgalaxy_39\bar\1.bin\CREXT.DLL.vir a variant of Win32/Toolbar.MyWebSearch.W application C:\AdwCleaner\Quarantine\C\Program Files\mapsgalaxy_39\bar\1.bin\Hpg64.dll.vir Win64/Toolbar.MyWebSearch.A application C:\AdwCleaner\Quarantine\C\Program Files\mapsgalaxy_39\bar\1.bin\NP39Stub.dll.vir Win32/Toolbar.MyWebSearch.T application C:\AdwCleaner\Quarantine\C\Program Files\mapsgalaxy_39\bar\1.bin\T8HTML.DLL.vir probably a variant of Win32/Toolbar.MyWebSearch.F application C:\Documents and Settings\HP_Administrator\My Documents\Downloads\DailyBibleGuide.exe a variant of Win32/AdInstaller application
That looks good and most of what Eset found has already been dealt with by AdwCleaner. The ones that have been quarantined will be dealt with when we clean up.

Please copy all text in the code box below and paste it into Notepad:

@echo off
del /f /s /q "C:\Documents and Settings\HP_Administrator\My Documents\Downloads\DailyBibleGuide.exe"
del %0
  • save the Notepad file to your desktop and name it delfiles.bat
  • save type as "All Files"
  • on your desktop, double-click on delfiles.bat to run it, (a black CMD window will flash, then disappear - this is normal).
Can you tell me if there are any remaining problems: if not, I’ll send instructions to tidy up the tools we have used.

Satchfan
Satchfan, I did as directed. The only issue is still the problem when it boots up/goes into sleep or hibernate mode. Sometimes it will sit on the black screen with the flashing cursor, sometimes I get the HP screen where the video looks as if the vertical or horizontal functions are going bad and the letters/words "vibrate" or "oscillate" back and forth like a mirage and sometimes it boots without any issues. I also know there is probably alot of stuff running in the background but I have no idea what to shut off or stop.
SpyHunter may be interfering with the OTL fix because the proxy settings have been reset.

Can you please disable SpyHunter and run another fix.

Note: If you have MalwareBytes Anti-Malware 1.6 or higher installed and are using the Pro version or trial version, please temporarily disable it for the duration of this fix as it may interfere with the successfully execution of the script below.

Run OTL
  • double click on the icon to run it.
  • copy/paste ALL the following text written inside the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
    IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 
    IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:5555
    IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
    IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 
    IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:5555
    
    :Files
    ipconfig /flushdns /c
    
    :Commands
    [purity]
    [emptytemp]
    [Reboot]

  • click the Run Fix button at the top
  • let the program run unhindered, reboot when it is done
  • please post the OTL fix log and new OTL log.
Incidentally, how many times have you run ComboFix?

If you ran it prior to when I asked you, please include the result of the FIRST run.

ComboFix logs are located at c:\combofix.txt, older logs are at c:\qoobox\combofix2.txt, c:\qoobox\ComboFix3.txt etc

Logs to include in the next post:

OTL fix log
New OTL log
ComboFix log (if relevant)


Satchfan
Satchfan,

I ran OTL and it only gave me one report. Here it is. At the bottom is all of the combo fix logs I could find.

All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully!
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully!
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer| /E : value set successfully!
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully!
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully!
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer| /E : value set successfully!
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Documents and Settings\HP_Administrator\Desktop\cmd.bat deleted successfully.
C:\Documents and Settings\HP_Administrator\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 7944 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 856432 bytes
->Flash cache emptied: 0 bytes

User: All Users

User: Customer
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: HP_Administrator
->Temp folder emptied: 1498239 bytes
->Temporary Internet Files folder emptied: 5846780 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 15542211 bytes
->Google Chrome cache emptied: 21243730 bytes
->Apple Safari cache emptied: 0 bytes
->Flash cache emptied: 506 bytes

User: HP_Administrator.YOUR-4DACD0EA75
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: LocalService
->Temp folder emptied: 65748 bytes
->Temporary Internet Files folder emptied: 32902 bytes
->Flash cache emptied: 0 bytes

User: NetworkService
->Temp folder emptied: 9500 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 141034 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 43.00 mb


OTL by OldTimer - Version 3.2.69.0 log created on 10052013_143358

Files\Folders moved on Reboot…

PendingFileRenameOperations files…

Registry entries deleted on Reboot…
—————————————————————————————————————————————————————————————————————————–

ComboFix 13-10-01.03 - HP_Administrator 10/02/2013 11:40:01.9.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.958.265 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((( Files Created from 2013-09-02 to 2013-10-02 )))))))))))))))))))))))))))))))
.
.
2013-10-02 18:04 . 2013-10-02 18:04 ——– dc—-w- C:\_OTL
2013-10-02 18:02 . 2013-09-05 05:02 7328304 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{5718BCD5-6474-4DF9-B7DF-939613AEC91D}\mpengine.dll
2013-09-30 23:49 . 2013-09-05 05:02 7328304 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-09-29 18:50 . 2013-09-29 18:50 ——– d—–w- c:\windows\ERUNT
2013-09-29 18:35 . 2013-09-29 18:40 ——– dc—-w- C:\AdwCleaner
2013-09-03 13:53 . 2013-09-03 13:53 187248 —-a-w- c:\program files\Mozilla Firefox\plugins\nppdf32.dll
2013-09-03 13:53 . 2013-09-03 13:53 187248 —-a-w- c:\program files\Internet Explorer\PLUGINS\nppdf32.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-09-20 23:59 . 2012-08-14 20:37 692616 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2013-09-20 23:59 . 2011-08-10 01:23 71048 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-08-09 01:56 . 2004-08-10 12:00 386560 —-a-w- c:\windows\system32\themeui.dll
2013-08-08 06:05 . 2004-08-10 12:00 920064 —-a-w- c:\windows\system32\wininet.dll
2013-08-08 06:05 . 2004-08-10 12:00 43520 —-a-w- c:\windows\system32\licmgr10.dll
2013-08-08 06:05 . 2004-08-10 12:00 1469440 —-a-w- c:\windows\system32\inetcpl.cpl
2013-08-08 06:05 . 2004-08-10 12:00 18944 —-a-w- c:\windows\system32\corpol.dll
2013-08-08 01:27 . 2004-08-10 12:00 1877760 —-a-w- c:\windows\system32\win32k.sys
2013-08-08 00:02 . 2004-08-10 12:00 385024 —-a-w- c:\windows\system32\html.iec
2013-08-05 13:30 . 2004-08-10 12:00 1289728 —-a-w- c:\windows\system32\ole32.dll
2013-08-03 21:18 . 2006-10-19 05:47 1543680 ——w- c:\windows\system32\wmvdecod.dll
2013-07-10 10:37 . 2004-08-10 12:00 406016 —-a-w- c:\windows\system32\usp10.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Facebook Update"="c:\documents and settings\HP_Administrator\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe" [2012-07-11 138096]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2013-01-08 18705664]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-06 64512]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-06-21 995176]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2011-07-27 434080]
.
c:\documents and settings\Default User\Start Menu\Programs\Startup\
Pin.lnk - c:\hp\bin\CLOAKER.EXE c:\hp\bin\PinToStart.bat [2005-11-10 27136]
.
c:\documents and settings\HP_Administrator.YOUR-4DACD0EA75\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE /tsr [2008-10-25 98696]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-12 282624]
Renaissance Wireless Server.lnk - c:\documents and settings\All Users\Application Data\Renaissance Wireless Server\Renaissance Wireless Server.exe [2007-9-11 6823860]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /r \??\J:\0autocheck autochk *
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Documents and Settings\\All Users\\Application Data\\Renaissance Wireless Server\\Renaissance Wireless Server.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Documents and Settings\\HP_Administrator\\Local Settings\\Application Data\\Facebook\\Video\\Skype\\FacebookVideoCalling.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeEnC2.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeTray.exe"=
"c:\\Program Files\\Rhapsody\\rhapsody.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [8/3/2011 1:31 PM 664064]
R2 DragonUpdater;COMODO Dragon Update Service;c:\program files\COMODO\Dragon\dragon_updater.exe [11/28/2012 4:45 AM 1868432]
R3 AE1000;Linksys AE1000 Driver;c:\windows\system32\drivers\AE1000XP.sys [7/12/2011 8:51 PM 816672]
R3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver;c:\windows\system32\drivers\nx6000.sys [7/13/2011 7:41 PM 30576]
S2 CSUService;COMODO System Utilities Service;c:\program files\COMODO\COMODO System Utilities\CSUService.exe [2/24/2012 6:26 AM 261952]
S2 MotoHelper;MotoHelper Service;c:\program files\Motorola\MotoHelper\MotoHelperService.exe –> c:\program files\Motorola\MotoHelper\MotoHelperService.exe [?]
S2 Skype C2C Service;Skype C2C Service;c:\documents and settings\All Users\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe [10/2/2012 12:13 PM 3064000]
S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [1/8/2013 12:55 PM 161536]
S3 McComponentHostService;McAfee Security Scan Component Host Service;"c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe" –> c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [?]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\DRIVERS\motccgp.sys –> c:\windows\system32\DRIVERS\motccgp.sys [?]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\DRIVERS\motccgpfl.sys –> c:\windows\system32\DRIVERS\motccgpfl.sys [?]
S3 motport;Motorola USB Diagnostic Port;c:\windows\system32\DRIVERS\motport.sys –> c:\windows\system32\DRIVERS\motport.sys [?]
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-09-21 09:21 1177552 —-a-w- c:\program files\Google\Chrome\Application\29.0.1547.76\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2013-10-02 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-14 23:59]
.
2013-09-12 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-02 00:57]
.
2013-09-30 c:\windows\Tasks\CSU Updater.job
- c:\program files\COMODO\COMODO System Utilities\Updater.exe [2012-02-24 13:27]
.
2013-01-13 c:\windows\Tasks\Easy Internet Sign-up.job
- c:\program files\Hewlett-Packard\SDP\HPSdpApp.exe [2005-09-09 03:23]
.
2013-09-30 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-657425056-1587324396-1979525332-1008Core.job
- c:\documents and settings\HP_Administrator\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe [2012-04-13 21:52]
.
2013-10-01 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-657425056-1587324396-1979525332-1008UA.job
- c:\documents and settings\HP_Administrator\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe [2012-04-13 21:52]
.
2013-10-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-12-08 03:45]
.
2013-10-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-12-08 03:45]
.
2013-10-02 c:\windows\Tasks\Microsoft Antimalware Scheduled Scan.job
- c:\program files\Microsoft Security Client\MpCmdRun.exe [2013-06-21 01:05]
.
2013-05-16 c:\windows\Tasks\Microsoft_Hardware_Launch_IcePick_exe.job
- c:\program files\Microsoft LifeCam\IcePick.exe [2010-05-20 22:27]
.
2013-09-30 c:\windows\Tasks\Norton Security Scan for HP_Administrator.job
- c:\program files\Norton Security Scan\Nss.exe [2008-09-19 11:18]
.
2013-10-02 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-657425056-1587324396-1979525332-1008.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2012-07-27 21:27]
.
2013-09-28 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-657425056-1587324396-1979525332-1008.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2012-07-27 21:27]
.
2013-09-04 c:\windows\Tasks\ReclaimerResumeInstall_HP_Administrator.job
- c:\documents and settings\HP_Administrator\Application Data\Real\Update\UpgradeHelper\RealPlayer\10.60\agent\rnupgagent.exe [2013-09-04 15:01]
.
2013-10-02 c:\windows\Tasks\User_Feed_Synchronization-{BF38A124-251E-4DD5-B80F-B1ED348AAA54}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 11:31]
.
.
——- Supplementary Scan ——-
.
uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
uInternet Settings,ProxyOverride = 192.168.*.*
TCP: DhcpNameServer = 75.75.75.75 75.75.76.76
TCP: Interfaces\{4F9665E1-6A11-4972-B941-EB22DFA68FC7}: NameServer = 8.26.56.26,156.154.70.22
TCP: Interfaces\{837C5F68-FB84-414E-8FEC-9FA666C52334}: NameServer = 8.26.56.26,156.154.70.22
FF - ProfilePath - c:\documents and settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ca60dke4.default-1380498043446\
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-10-02 11:52
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_8_800_175_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_8_800_175_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(792)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(3240)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2013-10-02 11:56:51
ComboFix-quarantined-files.txt 2013-10-02 18:56
ComboFix2.txt 2011-11-12 18:03
.
Pre-Run: 147,591,413,760 bytes free
Post-Run: 147,581,644,800 bytes free
.
- - End Of File - - B631C5BB3EEB993B09A00E5DBEC51734
0AC6D996BCE152AED9600E6D6B797E2E

—————————————————————————————————————————————————————————————————————————————————

ComboFix 11-11-12.04 - Administrator 11/12/2011 9:54.8.1 - x86 NETWORK
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.958.691 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Administrator\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
FW: COMODO Firewall *Disabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
.
FILE ::
"c:\documents and settings\all users\application data\privacy.exe"
.
.
((((((((((((((((((((((((( Files Created from 2011-10-12 to 2011-11-12 )))))))))))))))))))))))))))))))
.
.
2011-11-12 17:49 . 2011-11-12 17:49 56200 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{FD52D403-4D9A-42DE-8B70-43D2FFDD0243}\offreg.dll
2011-11-12 02:42 . 2011-10-07 03:48 6668624 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{FD52D403-4D9A-42DE-8B70-43D2FFDD0243}\mpengine.dll
2011-11-09 23:12 . 2011-11-09 23:12 ——– dc—-w- C:\TDSSKiller_Quarantine
2011-11-06 01:37 . 2011-11-06 01:37 ——– d—–w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2011-11-05 00:44 . 2011-03-31 21:53 24064 —-a-w- c:\windows\system32\drivers\motport.sys
2011-11-05 00:44 . 2011-03-31 21:53 24064 —-a-w- c:\windows\system32\drivers\motmodem.sys
2011-11-05 00:44 . 2011-04-04 21:55 20480 —-a-w- c:\windows\system32\drivers\motccgp.sys
2011-11-05 00:44 . 2009-01-30 00:18 8320 —-a-w- c:\windows\system32\drivers\motccgpfl.sys
2011-11-05 00:44 . 2007-11-02 22:51 6400 —-a-w- c:\windows\system32\drivers\motswch.sys
2011-11-05 00:43 . 2011-11-05 00:43 ——– d—–w- c:\program files\Common Files\Motorola Shared
2011-11-05 00:43 . 2011-11-05 00:43 ——– d—–w- c:\program files\Motorola
2011-10-29 17:32 . 2011-10-29 17:33 ——– d—–w- c:\windows\system32\NtmsData
2011-10-29 17:24 . 2001-08-17 20:56 7552 —-a-w- c:\windows\system32\drivers\SONYPVU1.SYS
2011-10-29 17:24 . 2001-08-17 20:56 7552 —-a-w- c:\windows\system32\dllcache\sonypvu1.sys
2011-10-29 17:20 . 2011-10-29 17:20 ——– d–h–w- c:\documents and settings\All Users\Application Data\CanonIJEPPEX
2011-10-24 16:02 . 2011-10-07 17:47 33984 —-a-w- c:\windows\system32\cmdcsr.dll
2011-10-20 03:14 . 2011-10-20 03:14 ——– d—–w- c:\program files\iPod
2011-10-20 03:08 . 2011-10-20 03:08 ——– d—–w- c:\program files\Bonjour
2011-10-20 00:44 . 2011-10-20 00:44 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Coupons.com
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-11 19:22 . 2011-10-11 19:22 398760 —-a-r- c:\windows\system32\cpnprt2.cid
2011-10-10 14:22 . 2004-08-10 12:00 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-10-07 17:48 . 2010-06-02 02:00 97760 —-a-w- c:\windows\system32\drivers\inspect.sys
2011-10-07 17:48 . 2010-06-02 02:00 31704 —-a-w- c:\windows\system32\drivers\cmdhlp.sys
2011-10-07 17:48 . 2010-06-04 18:55 492768 —-a-w- c:\windows\system32\drivers\cmdGuard.sys
2011-10-07 17:47 . 2010-06-02 02:00 18056 —-a-w- c:\windows\system32\drivers\cmderd.sys
2011-10-07 17:47 . 2010-06-02 02:00 300200 —-a-w- c:\windows\system32\guard32.dll
2011-10-07 03:48 . 2011-10-04 22:43 6668624 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-10-03 17:45 . 2011-08-10 01:23 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-09-28 07:06 . 2004-08-10 12:00 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-09-26 18:41 . 2010-03-18 17:09 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 18:41 . 2004-08-10 12:00 220160 —-a-w- c:\windows\system32\oleacc.dll
2011-09-26 18:41 . 2004-08-10 12:00 20480 —-a-w- c:\windows\system32\oleaccrc.dll
2011-09-12 23:14 . 2011-10-05 04:45 7269712 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Updates\mpengine.dll
2011-09-06 13:20 . 2004-08-10 12:00 1858944 —-a-w- c:\windows\system32\win32k.sys
2011-09-01 00:00 . 2011-10-03 23:25 22216 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-08-31 06:05 . 2011-08-31 06:05 83816 —-a-w- c:\windows\system32\dns-sd.exe
2011-08-31 06:05 . 2011-08-31 06:05 73064 —-a-w- c:\windows\system32\dnssd.dll
2011-08-31 06:05 . 2011-08-31 06:05 50536 —-a-w- c:\windows\system32\jdns_sd.dll
2011-08-31 06:05 . 2011-08-31 06:05 178536 —-a-w- c:\windows\system32\dnssdX.dll
2011-08-22 23:48 . 2004-08-10 12:00 916480 —-a-w- c:\windows\system32\wininet.dll
2011-08-22 23:48 . 2004-08-10 12:00 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-08-22 23:48 . 2004-08-10 12:00 1469440 —-a-w- c:\windows\system32\inetcpl.cpl
2011-08-22 11:56 . 2004-08-10 12:00 385024 —-a-w- c:\windows\system32\html.iec
2011-08-17 13:49 . 2004-08-10 12:00 138496 —-a-w- c:\windows\system32\drivers\afd.sys
2011-09-30 17:27 . 2011-05-06 14:29 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-11-10_00.43.47 )))))))))))))))))))))))))))))))))))))))))
.
- 2011-07-14 02:54 . 2011-08-12 20:51 17272 c:\windows\system32\spmsg.dll
+ 2011-07-14 02:54 . 2010-07-05 13:15 17272 c:\windows\system32\spmsg.dll
+ 2010-01-29 15:01 . 2011-10-10 14:22 692736 c:\windows\system32\dllcache\inetcomm.dll
- 2010-01-29 15:01 . 2011-05-02 15:31 692736 c:\windows\system32\dllcache\inetcomm.dll
+ 2011-09-03 10:17 . 2011-09-28 07:06 599040 c:\windows\system32\dllcache\crypt32.dll
- 2011-09-03 10:17 . 2011-09-09 09:12 599040 c:\windows\system32\dllcache\crypt32.dll
+ 2010-02-20 16:57 . 2011-11-10 05:51 50295240 c:\windows\system32\MRT.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-06 64512]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-03 77312]
"HPHUPD08"="c:\program files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-02 49152]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-09-21 1605740]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2011-02-18 49208]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2005-11-11 180269]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-04-20 58656]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2011-10-20 2497352]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2010-05-20 119152]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2010-03-25 2516296]
"CanonSolutionMenuEx"="c:\program files\Canon\Solution Menu EX\CNSEMAIN.EXE" [2010-04-02 1185112]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-07-06 421888]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-10-10 421736]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-09-01 449608]
.
c:\documents and settings\Default User\Start Menu\Programs\Startup\
Pin.lnk - c:\hp\bin\CLOAKER.EXE [2005-11-10 27136]
.
c:\documents and settings\HP_Administrator.YOUR-4DACD0EA75\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2008-10-25 98696]
Registration Silent Hunter III.LNK - c:\program files\Ubisoft\SilentHunterIII\Support\Register\RegistrationReminder.exe [N/A]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Event Planner Reminders Tray Icon.lnk - c:\sierra\Planner\PLNRnote.exe [N/A]
Forget Me Not.lnk - c:\program files\Broderbund\AG CreataCard\agremind.exe [N/A]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-12 282624]
Renaissance Wireless Server.lnk - c:\documents and settings\All Users\Application Data\Renaissance Wireless Server\Renaissance Wireless Server.exe [2007-9-11 6823860]
Updates from HP.lnk - c:\program files\Updates from HP\9972322\Program\Updates from HP.exe [N/A]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /r \??\J:\0autocheck autochk *
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Renaissance Wireless Server\\Renaissance Wireless Server.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\BitTorrent\\BitTorrent.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeEnC2.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeTray.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [8/3/2011 12:31 PM 664064]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [6/1/2010 6:00 PM 31704]
R3 AE1000;Linksys AE1000 Driver;c:\windows\system32\drivers\AE1000XP.sys [7/12/2011 7:51 PM 816672]
S1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [6/4/2010 10:55 AM 492768]
S1 MpKsl0f7c0b36;MpKsl0f7c0b36;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{02636E4D-33B1-4A9D-93F9-D88436CA3D6D}\MpKsl0f7c0b36.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{02636E4D-33B1-4A9D-93F9-D88436CA3D6D}\MpKsl0f7c0b36.sys [?]
S1 MpKsl256912b9;MpKsl256912b9;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{9A0E6A14-A76C-4190-8390-4F85AA171C06}\MpKsl256912b9.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{9A0E6A14-A76C-4190-8390-4F85AA171C06}\MpKsl256912b9.sys [?]
S1 MpKsl5744934b;MpKsl5744934b;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{40394202-2B54-4840-A53F-78E381E1B662}\MpKsl5744934b.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{40394202-2B54-4840-A53F-78E381E1B662}\MpKsl5744934b.sys [?]
S1 MpKsl5ff3be24;MpKsl5ff3be24;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{158E3422-62FB-4074-825C-F251E1501BEC}\MpKsl5ff3be24.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{158E3422-62FB-4074-825C-F251E1501BEC}\MpKsl5ff3be24.sys [?]
S1 MpKsl82c4ff9c;MpKsl82c4ff9c;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7232C367-9761-4A6C-BA0E-49C0DD6AE5C3}\MpKsl82c4ff9c.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7232C367-9761-4A6C-BA0E-49C0DD6AE5C3}\MpKsl82c4ff9c.sys [?]
S1 MpKsl9dd2a4f5;MpKsl9dd2a4f5;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F49F9929-BC03-461B-A787-CC697C91A1BC}\MpKsl9dd2a4f5.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F49F9929-BC03-461B-A787-CC697C91A1BC}\MpKsl9dd2a4f5.sys [?]
S1 MpKsla1025ecb;MpKsla1025ecb;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C179B624-5673-469D-B8BE-7310500DAF9D}\MpKsla1025ecb.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C179B624-5673-469D-B8BE-7310500DAF9D}\MpKsla1025ecb.sys [?]
S1 MpKslb899b9ea;MpKslb899b9ea;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{68003CD4-2DF1-4DF8-B327-C3B29DE74819}\MpKslb899b9ea.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{68003CD4-2DF1-4DF8-B327-C3B29DE74819}\MpKslb899b9ea.sys [?]
S1 MpKslbd4858d2;MpKslbd4858d2;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{422A7366-8CB1-4120-B62B-7E26B6B6F89C}\MpKslbd4858d2.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{422A7366-8CB1-4120-B62B-7E26B6B6F89C}\MpKslbd4858d2.sys [?]
S2 BBUpdate;BBUpdate;c:\program files\Microsoft\BingBar\SeaPort.EXE [6/15/2011 4:33 PM 249648]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 12:16 PM 130384]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [10/3/2011 3:25 PM 366152]
S2 MotoHelper;MotoHelper Service;c:\program files\Motorola\MotoHelper\MotoHelperService.exe [8/10/2011 11:35 AM 227184]
S3 BBSvc;Bing Bar Update Service;c:\program files\Microsoft\BingBar\BBSvc.EXE [7/7/2011 6:31 PM 195336]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [10/3/2011 3:25 PM 22216]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys [11/4/2011 4:44 PM 20480]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys [11/4/2011 4:44 PM 8320]
S3 motport;Motorola USB Diagnostic Port;c:\windows\system32\drivers\motport.sys [11/4/2011 4:44 PM 24064]
S3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver;c:\windows\system32\drivers\nx6000.sys [7/13/2011 6:41 PM 30576]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 12:16 PM 753504]
.
Contents of the 'Scheduled Tasks' folder
.
2011-11-10 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-02 00:57]
.
2011-11-12 c:\windows\Tasks\HPCeeSchedule.job
- c:\program files\Hewlett-Packard\SDP\Ceement\HPCEE.exe [2005-09-09 03:22]
.
2011-11-05 c:\windows\Tasks\MotoHelper MUM.job
- c:\program files\Motorola\MotoHelper\MotoHelperUpdate.exe [2011-08-08 22:11]
.
2011-11-10 c:\windows\Tasks\MotoHelper Routing.job
- c:\program files\Motorola\MotoHelper\MotoHelperUpdate.exe [2011-08-08 22:11]
.
2011-11-05 c:\windows\Tasks\MotoHelper Update.job
- c:\program files\Motorola\MotoHelper\MotoHelperUpdate.exe [2011-08-08 22:11]
.
2011-11-12 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 22:39]
.
2011-11-10 c:\windows\Tasks\Norton Security Scan for HP_Administrator.job
- c:\program files\Norton Security Scan\Nss.exe [2008-09-19 11:18]
.
2011-11-12 c:\windows\Tasks\User_Feed_Synchronization-{BF38A124-251E-4DD5-B80F-B1ED348AAA54}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 11:31]
.
.
——- Supplementary Scan ——-
.
IE: &Google Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html
IE: &Translate English Word - c:\program files\Google\GoogleToolbar1.dll/cmwordtrans.html
IE: Backward Links - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\Google\GoogleToolbar1.dll/cmcache.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Similar Pages - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate Page into English - c:\program files\Google\GoogleToolbar1.dll/cmtrans.html
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{4F9665E1-6A11-4972-B941-EB22DFA68FC7}: NameServer = 156.154.70.22,156.154.71.22
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\op5b9w5g.default\
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-11-12 10:01
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(708)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(600)
c:\windows\system32\WININET.dll
.
Completion time: 2011-11-12 10:03:14
ComboFix-quarantined-files.txt 2011-11-12 18:03
ComboFix2.txt 2011-11-11 20:37
ComboFix3.txt 2010-08-10 04:52
.
Pre-Run: 154,822,512,640 bytes free
Post-Run: 154,820,796,416 bytes free
.
- - End Of File - - EFF5B60AC8BBE6FFABE08D6992CA1DCF
OTL won't automatically send a new log so you'll have to do it manually.
  • open OTL again and click the Quick Scan
  • post the OTL.txt log it produces in your next reply.
Please post back with the log.
Here is the log:

OTL logfile created on: 10/5/2013 7:33:50 PM - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\HP_Administrator\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

958.48 Mb Total Physical Memory | 385.90 Mb Available Physical Memory | 40.26% Memory free
2.26 Gb Paging File | 1.78 Gb Available in Paging File | 79.01% Paging File free
Paging file location(s): C:\pagefile.sys 1440 2880 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 177.80 Gb Total Space | 137.37 Gb Free Space | 77.26% Space Free | Partition Type: NTFS
Drive D: | 8.50 Gb Total Space | 1.12 Gb Free Space | 13.12% Space Free | Partition Type: FAT32

Computer Name: BLAKLEY | User Name: HP_Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2013/10/02 11:01:33 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\HP_Administrator\Desktop\OTL(1).exe
PRC - [2013/09/16 20:21:30 | 000,829,392 | —- | M] (Google Inc.) – C:\Program Files\Google\Chrome\Application\chrome.exe
PRC - [2013/06/20 18:05:14 | 000,022,208 | —- | M] (Microsoft Corporation) – c:\Program Files\Microsoft Security Client\MsMpEng.exe
PRC - [2013/06/20 17:25:44 | 000,995,176 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2012/11/28 04:45:16 | 001,868,432 | —- | M] () – C:\Program Files\COMODO\Dragon\dragon_updater.exe
PRC - [2010/05/20 15:27:24 | 000,139,632 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft LifeCam\MSCamS32.exe
PRC - [2008/04/13 17:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2007/09/11 13:11:00 | 006,823,860 | —- | M] () – C:\Documents and Settings\All Users\Application Data\Renaissance Wireless Server\Renaissance Wireless Server.exe
PRC - [2005/08/03 00:19:16 | 000,058,880 | —- | M] (Microsoft) – C:\WINDOWS\arservice.exe


========== Modules (No Company Name) ==========

MOD - [2013/09/16 20:21:27 | 000,410,576 | —- | M] () – C:\Program Files\Google\Chrome\Application\29.0.1547.76\ppgooglenaclpluginchrome.dll
MOD - [2013/09/16 20:21:26 | 013,611,984 | —- | M] () – C:\Program Files\Google\Chrome\Application\29.0.1547.76\PepperFlash\pepflashplayer.dll
MOD - [2013/09/16 20:21:25 | 004,053,456 | —- | M] () – C:\Program Files\Google\Chrome\Application\29.0.1547.76\pdf.dll
MOD - [2013/09/16 20:20:31 | 001,604,560 | —- | M] () – C:\Program Files\Google\Chrome\Application\29.0.1547.76\ffmpegsumo.dll
MOD - [2013/01/01 23:49:10 | 001,292,288 | —- | M] () – C:\WINDOWS\system32\quartz.dll
MOD - [2012/11/28 04:45:16 | 001,868,432 | —- | M] () – C:\Program Files\COMODO\Dragon\dragon_updater.exe
MOD - [2011/06/24 22:56:36 | 000,087,328 | —- | M] () – C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/06/24 22:56:14 | 001,241,888 | —- | M] () – C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011/02/04 18:48:30 | 000,291,840 | —- | M] () – C:\WINDOWS\system32\sbe.dll
MOD - [2008/04/13 17:11:59 | 000,014,336 | —- | M] () – C:\WINDOWS\system32\msdmo.dll
MOD - [2008/04/13 17:11:51 | 000,059,904 | —- | M] () – C:\WINDOWS\system32\devenum.dll
MOD - [2007/09/11 13:11:00 | 006,823,860 | —- | M] () – C:\Documents and Settings\All Users\Application Data\Renaissance Wireless Server\Renaissance Wireless Server.exe
MOD - [2005/08/03 00:19:16 | 000,050,176 | —- | M] () – C:\WINDOWS\armcex.dll
MOD - [2005/03/15 23:17:28 | 000,204,800 | —- | M] () – c:\Program Files\HP\Digital Imaging\bin\HpqUtil.dll


========== Services (SafeList) ==========

SRV - File not found [Auto | Stopped] – C:\Program Files\Motorola\MotoHelper\MotoHelperService.exe – (MotoHelper)
SRV - File not found [On_Demand | Stopped] – C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe – (McComponentHostService)
SRV - [2013/09/20 16:59:26 | 000,257,416 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe – (AdobeFlashPlayerUpdateSvc)
SRV - [2013/08/20 09:57:43 | 000,117,656 | —- | M] (Mozilla Foundation) [On_Demand | Stopped] – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe – (MozillaMaintenance)
SRV - [2013/06/20 18:05:14 | 000,022,208 | —- | M] (Microsoft Corporation) [Auto | Running] – c:\Program Files\Microsoft Security Client\MsMpEng.exe – (MsMpSvc)
SRV - [2012/11/28 04:45:16 | 001,868,432 | —- | M] () [Auto | Running] – C:\Program Files\COMODO\Dragon\dragon_updater.exe – (DragonUpdater)
SRV - [2012/02/24 06:26:28 | 000,261,952 | —- | M] (Comodo Security Solutions, Inc.) [Auto | Stopped] – C:\Program Files\COMODO\COMODO System Utilities\CSUService.exe – (CSUService)
SRV - [2010/05/20 15:27:24 | 000,139,632 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Microsoft LifeCam\MSCamS32.exe – (MSCamSvc)
SRV - [2005/08/03 00:19:16 | 000,058,880 | —- | M] (Microsoft) [Auto | Running] – C:\WINDOWS\arservice.exe – (ARSVC)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] – – (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDCOMP)
DRV - File not found [Kernel | System | Stopped] – – (PCIDump)
DRV - File not found [Kernel | On_Demand | Stopped] – system32\DRIVERS\motport.sys – (motport)
DRV - File not found [Kernel | On_Demand | Stopped] – system32\DRIVERS\motmodem.sys – (motmodem)
DRV - File not found [Kernel | On_Demand | Stopped] – system32\DRIVERS\motccgpfl.sys – (motccgpfl)
DRV - File not found [Kernel | On_Demand | Stopped] – system32\DRIVERS\motccgp.sys – (motccgp)
DRV - File not found [Kernel | On_Demand | Stopped] – system32\DRIVERS\mcdbus.sys – (mcdbus)
DRV - File not found [Kernel | System | Stopped] – – (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] – – (i2omgmt)
DRV - File not found [Kernel | System | Stopped] – – (Changer)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\catchme.sys – (catchme)
DRV - [2011/08/03 13:54:12 | 000,223,128 | —- | M] (DT Soft Ltd.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\dtscsi.sys – (dtscsi)
DRV - [2011/08/03 13:31:07 | 000,664,064 | —- | M] () [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\sptd.sys – (sptd)
DRV - [2010/05/20 15:27:24 | 000,030,576 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\nx6000.sys – (MSHUSBVideo)
DRV - [2010/04/28 07:44:02 | 000,054,760 | —- | M] (Microsoft Corporation) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\fssfltr_tdi.sys – (fssfltr)
DRV - [2010/03/22 23:53:12 | 000,816,672 | R— | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\AE1000XP.sys – (AE1000)
DRV - [2009/08/19 14:49:22 | 000,049,904 | R— | M] (Avanquest Software) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\BVRPMPR5.SYS – (BVRPMPR5)
DRV - [2005/08/29 15:11:00 | 003,644,928 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ALCXWDM.SYS – (ALCXWDM)
DRV - [2005/08/13 22:35:54 | 001,313,792 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ati2mtag.sys – (ati2mtag)
DRV - [2005/07/04 00:30:34 | 000,026,624 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\PS2.sys – (Ps2)
DRV - [2005/06/30 01:03:18 | 000,175,104 | —- | M] (Promise Technology, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\ftsata2.sys – (ftsata2)
DRV - [2005/03/09 14:53:00 | 000,036,352 | —- | M] (Advanced Micro Devices) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\AmdK8.sys – (AmdK8)
DRV - [2005/03/04 11:10:26 | 000,074,496 | —- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\Rtlnicxp.sys – (RTL8023xp)
DRV - [2004/12/15 15:18:32 | 000,220,928 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HSFHWBS2.sys – (HSFHWBS2)
DRV - [2004/12/15 15:18:28 | 000,703,232 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HSF_CNXT.sys – (winachsf)
DRV - [2004/12/15 15:18:26 | 001,038,208 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HSF_DP.sys – (HSF_DP)
DRV - [2004/08/03 22:31:34 | 000,020,992 | —- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\RTL8139.sys – (rtl8139)
DRV - [2003/11/05 15:45:12 | 000,017,408 | —- | M] (Promise Technology, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\bb-run.sys – (bb-run)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}: "URL" = http://us.yhs.search.yahoo.com/avg/search?…p={searchTerms}


IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:5555

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:5555

IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-657425056-1587324396-1979525332-1008\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\S-1-5-21-657425056-1587324396-1979525332-1008\..\SearchScopes,DefaultScope = {CCC7A320-B3CA-4199-B1A6-9F516DD69829}
IE - HKU\S-1-5-21-657425056-1587324396-1979525332-1008\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?FORM=WLETDF&…rc=IE-SearchBox
IE - HKU\S-1-5-21-657425056-1587324396-1979525332-1008\..\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}: "URL" = http://us.search.yahoo.com/search?p={searc…p;fr=chr-comodo
IE - HKU\S-1-5-21-657425056-1587324396-1979525332-1008\..\SearchScopes\{DDC8D966-465C-2856-0BFE-6F4974176253}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;form=ZGAIDF
IE - HKU\S-1-5-21-657425056-1587324396-1979525332-1008\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-657425056-1587324396-1979525332-1008\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 192.168.*.*

========== FireFox ==========

FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:23.0.1
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_8_800_168.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.6.14: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.6.14: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.6.14: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.6.14: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=15.0.6.14: c:\program files\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.1: C:\Documents and Settings\HP_Administrator\Application Data\Facebook\npfbplugin_1_0_1.dll ( )
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.3: C:\Documents and Settings\HP_Administrator\Application Data\Facebook\npfbplugin_1_0_3.dll ( )

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{0153E448-190B-4987-BDE1-F256CADA672F}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012/10/13 08:27:12 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 23.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/08/20 09:56:11 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 23.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/09/19 16:20:14 | 000,000,000 | —D | M]

[2010/02/11 18:35:24 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Extensions
[2013/10/02 11:03:48 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ca60dke4.default-1380498043446\extensions
[2013/08/02 10:40:03 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\op5b9w5g.default\extensions
[2013/08/20 09:56:12 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2013/08/20 09:56:12 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2013/08/20 09:56:10 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\browser\extensions
[2013/08/20 09:57:45 | 000,000,000 | —D | M] (Default) – C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2011/11/15 22:19:08 | 000,611,224 | —- | M] (Oracle Corporation) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2012/10/13 08:26:53 | 000,129,176 | —- | M] (RealPlayer) – C:\Program Files\mozilla firefox\plugins\nprpplugin.dll

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{g
oogle:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:ins
tantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncodin
g}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyPar
ameter}
CHR - homepage: http://us.yahoo.com?fr=fpc-comodo
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\29.0.1547.76\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 7.0.10.8 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 7 U1 (Enabled) = C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\Microsoft\Office Live\npOLW.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\29.0.1547.76\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\29.0.1547.76\pdf.dll
CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npMozCouponPrinter.dll
CHR - plugin: Facebook Plugin (Enabled) = C:\Documents and Settings\HP_Administrator\Application Data\Facebook\npfbplugin_1_0_1.dll
CHR - plugin: Facebook Plugin (Enabled) = C:\Documents and Settings\HP_Administrator\Application Data\Facebook\npfbplugin_1_0_3.dll
CHR - plugin: Unity Player (Enabled) = C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll
CHR - plugin: CANON iMAGE GATEWAY Album Plugin Utility (Enabled) = C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\
CHR - Extension: Chrome In-App Payments service = C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_0\

O1 HOSTS File: ([2013/10/05 14:13:10 | 000,000,022 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKU\S-1-5-21-657425056-1587324396-1979525332-1008\..\Toolbar\WebBrowser: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Renaissance Wireless Server.lnk = C:\Documents and Settings\All Users\Application Data\Renaissance Wireless Server\Renaissance Wireless Server.exe ()
O4 - Startup: C:\Documents and Settings\Default User\Start Menu\Programs\Startup\Pin.lnk = C:\hp\bin\cloaker.exe (Hewlett-Packard Co.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-657425056-1587324396-1979525332-1008\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-657425056-1587324396-1979525332-1008\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-657425056-1587324396-1979525332-1008\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-657425056-1587324396-1979525332-1008\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ()
O9 - Extra 'Tools' menuitem : Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ()
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_01)
O16 - DPF: {CAFEEFAC-0017-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_01)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_01)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/shock…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4F9665E1-6A11-4972-B941-EB22DFA68FC7}: NameServer = 8.26.56.26,156.154.70.22
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{837C5F68-FB84-414E-8FEC-9FA666C52334}: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{837C5F68-FB84-414E-8FEC-9FA666C52334}: NameServer = 8.26.56.26,156.154.70.22
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EFDC876F-B06E-4EBB-8CF6-7765A6D04335}: DhcpNameServer = 192.168.1.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/11/10 17:46:21 | 000,000,100 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2010/08/15 11:46:17 | 000,000,000 | R–D | M] - C:\autorun.inf – [ NTFS ]
O32 - AutoRun File - [2001/07/28 05:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O32 - AutoRun File - [2010/08/15 11:46:18 | 000,000,000 | R–D | M] - D:\autorun.inf – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk /r \??\J:)
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2013/10/05 13:58:13 | 000,000,000 | —D | C] – C:\WINDOWS\pss
[2013/10/02 16:10:03 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Desktop\RK_Quarantine
[2013/10/02 12:04:37 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2013/10/02 11:32:57 | 000,518,144 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2013/10/02 11:32:57 | 000,406,528 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2013/10/02 11:32:57 | 000,060,416 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2013/10/02 11:32:56 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2013/10/02 11:04:39 | 000,000,000 | —D | C] – C:\_OTL
[2013/10/02 11:01:34 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Documents and Settings\HP_Administrator\Desktop\OTL(1).exe
[2013/09/29 16:40:47 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Desktop\Old Firefox Data
[2013/09/29 11:50:10 | 000,000,000 | —D | C] – C:\WINDOWS\ERUNT
[2013/09/29 11:35:27 | 000,000,000 | —D | C] – C:\AdwCleaner
[2013/09/24 16:13:35 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\My Documents\Pictures from Grammy

========== Files - Modified Within 30 Days ==========

[2013/10/05 19:37:11 | 000,000,384 | -H– | M] () – C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job
[2013/10/05 19:30:37 | 000,000,444 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{BF38A124-251E-4DD5-B80F-B1ED348AAA54}.job
[2013/10/05 19:27:13 | 000,000,902 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2013/10/05 19:27:12 | 000,000,300 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-657425056-1587324396-1979525332-1008.job
[2013/10/05 19:26:57 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2013/10/05 19:26:55 | 1005,113,344 | -HS- | M] () – C:\hiberfil.sys
[2013/10/05 15:21:00 | 000,000,906 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2013/10/05 14:59:15 | 000,000,830 | —- | M] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2013/10/04 07:28:49 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2013/10/02 16:14:32 | 000,891,167 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\SecurityCheck.exe
[2013/10/02 16:09:00 | 000,948,736 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\RogueKiller.exe
[2013/10/02 11:32:14 | 005,132,885 | R— | M] (Swearware) – C:\Documents and Settings\HP_Administrator\Desktop\ComboFix.exe
[2013/10/02 11:01:33 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\HP_Administrator\Desktop\OTL(1).exe
[2013/09/29 21:31:00 | 000,000,484 | —- | M] () – C:\WINDOWS\tasks\CSU Updater.job
[2013/09/29 18:00:00 | 000,000,430 | —- | M] () – C:\WINDOWS\tasks\Norton Security Scan for HP_Administrator.job
[2013/09/29 17:13:31 | 000,000,512 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\MBR.dat
[2013/09/27 17:06:00 | 000,000,308 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-657425056-1587324396-1979525332-1008.job
[2013/09/25 20:58:28 | 000,000,249 | —- | M] () – C:\WINDOWS\System\hpsysdrv.dat
[2013/09/21 02:28:49 | 000,001,824 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2013/09/12 12:28:14 | 000,495,456 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2013/09/12 12:09:49 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2013/09/11 21:24:39 | 000,190,398 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\Proof (2).png
[2013/09/11 21:13:13 | 000,159,156 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\Proof (1).png
[2013/09/11 21:12:26 | 000,159,156 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\window cling.png
[2013/09/11 21:06:11 | 000,084,901 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\Proof.png
[2013/09/11 17:44:01 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job

========== Files Created - No Company Name ==========

[2013/10/05 14:08:13 | 1005,113,344 | -HS- | C] () – C:\hiberfil.sys
[2013/10/02 16:14:30 | 000,891,167 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\SecurityCheck.exe
[2013/10/02 16:08:56 | 000,948,736 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\RogueKiller.exe
[2013/10/02 11:32:57 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2013/10/02 11:32:57 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2013/10/02 11:32:57 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2013/10/02 11:32:57 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2013/10/02 11:32:57 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2013/09/29 17:13:31 | 000,000,512 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\MBR.dat
[2013/09/11 21:24:41 | 000,190,398 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\Proof (2).png
[2013/09/11 21:13:16 | 000,159,156 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\Proof (1).png
[2013/09/11 21:12:39 | 000,159,156 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\window cling.png
[2013/09/11 21:06:18 | 000,084,901 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\Proof.png
[2013/03/28 22:17:19 | 001,474,832 | —- | C] () – C:\WINDOWS\System32\drivers\sfi.dat
[2012/02/14 15:28:51 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2011/11/06 14:58:18 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/10/16 15:14:47 | 000,000,000 | —- | C] () – C:\WINDOWS\DC200_DC210_Updater.INI
[2010/11/23 13:28:10 | 000,138,056 | —- | C] () – C:\Documents and Settings\HP_Administrator\Application Data\PnkBstrK.sys
[2010/09/06 16:05:21 | 000,000,129 | —- | C] () – C:\Documents and Settings\HP_Administrator\jagex_runescape_preferences2.dat
[2010/09/06 16:05:21 | 000,000,000 | —- | C] () – C:\Documents and Settings\HP_Administrator\jagex__preferences3.dat
[2010/04/04 21:48:35 | 000,000,000 | —- | C] () – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\prvlcl.dat
[2010/03/04 16:36:06 | 000,012,130 | -HS- | C] () – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\04lB
[2010/02/11 19:28:30 | 000,000,139 | —- | C] () – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\fusioncache.dat
[2008/08/26 15:30:07 | 000,000,046 | —- | C] () – C:\Documents and Settings\HP_Administrator\jagex_runescape_preferences.dat
[2006/04/04 16:11:55 | 000,031,744 | —- | C] () – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/03/31 22:57:29 | 000,005,336 | —- | C] () – C:\Documents and Settings\HP_Administrator\Application Data\wklnhst.dat

========== ZeroAccess Check ==========

[2005/08/31 04:58:26 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll – [2008/04/13 17:12:05 | 001,499,136 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2009/02/09 05:10:48 | 000,473,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2008/04/13 17:12:08 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2005/11/10 17:30:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Digital Interactive Systems Corporation
[2013/03/06 18:56:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\188F1432-103A-4ffb-80F1-36B633C5C9E1
[2011/03/21 16:30:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AA3DeployClient
[2009/07/13 15:38:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Age of Empires 3
[2008/01/27 16:25:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Broderbund Software
[2011/09/04 11:07:00 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2011/09/04 11:20:15 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonEPP
[2011/09/09 15:22:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJ
[2012/05/05 17:33:42 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJEGV
[2011/10/29 10:20:10 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJEPPEX
[2011/09/04 11:20:15 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJEPPEX2
[2011/09/04 11:12:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJMSetup
[2011/09/04 11:20:13 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJMyPrinter
[2011/09/09 15:20:05 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJScan
[2011/09/04 11:20:16 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJSolutionMenuEX
[2011/09/04 11:11:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJWSpt
[2008/06/21 16:27:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Comcast
[2010/01/25 21:10:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Downloaded Installations
[2008/08/24 11:14:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2013/03/31 10:17:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Hello Kitty Snap n Share
[2013/03/31 10:17:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HelloKittyDC
[2006/06/24 23:14:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\muvee Technologies
[2013/10/05 14:22:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Renaissance Learning
[2010/01/10 22:51:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Renaissance Wireless Server
[2008/09/08 18:38:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\RSE
[2007/09/25 11:37:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SupportSoft
[2010/06/30 19:11:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2005/11/10 17:30:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Customer\Application Data\Digital Interactive Systems Corporation
[2005/11/10 17:30:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Default User\Application Data\Digital Interactive Systems Corporation

========== Purity Check ==========



< End of report >
There are some entries that should have been cleared by OTL but have not, so there is still a need to have a different look with another scan.

I'm also going to ask some of my colleagues to see if they can shed some light on it.


Run DDS

Please download DDS by sUBs from one of the following links and save it to your desktop.

DDS.pif
DDS.com

  • disable any script blocking protection (How to Disable your Security Programs)
  • double click DDS icon to run the tool (may take up to 3 minutes to run)
  • when done, DDS.txt will open.
  • after a few moments, attach.txt will open in a second window.
  • save both reports to your desktop.
  • Post the contents of the DDS.txt and Attach.txt reports in your next reply
Please include the following in your next post :

DDS.txt
Attach.txt


Thanks

Satchfan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI