This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Malware using Windows Installer

60 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

HI,

I have a virus that tries to install something when I start a probram from the Start Menu of recently used programs. When I try to start one of the programs, I get a dialog box that says Windows Installer is trying to install the program but cannot find a part of the program. If I continually click the Cancel button in this doalog box, then after about 4 or 5 times it appears, the program I wanted to start will come up.

Here is the HiJackThis log. Please help if possible. Thanks

————————————————————————–

Logfile of HijackThis v1.99.1
Scan saved at 1:31:06 PM, on 12/8/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\Common Files\AOL\1125684819\ee\AOLSoftware.exe
C:\WINDOWS\System32\WDBtnMgr.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe
C:\Program Files\WinZip\WZQKPICK.EXE
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Insight Development\Zip Up The Web Pro\ZUTWTray.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\American Systems\Print Screen Deluxe\psdeluxe.exe
C:\Program Files\American Systems\EZ Macros\EZMacros.exe
c:\program files\common files\aol\1125684819\ee\services\antiSpywareApp\ver2_0_32_1\AOLSP Scheduler.exe
c:\program files\common files\aol\1125684819\ee\aolsoftware.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\Dantz\Retrospect\retrorun.exe
C:\WINDOWS\System32\wuauclt.exe
C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\GBCS Software\URL Address Book\Urlbook.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\Program Files\Hijack This\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus8.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://news.myway.com/index/id/top%7Cap.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://qus8.hpwis.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: (no name) - {02DCA195-602B-4B1F-83FF-381B7E804BDB} - C:\WINDOWS\system32\HDBHO.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptcl.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1125684819\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [WD Button Manager] WDBtnMgr.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [AOLAspSunset2] C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\updates\aspapp\sunsetAsp2.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\AOL 9.0b\AOL.EXE" -b
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: Print Screen Deluxe.lnk = C:\Program Files\American Systems\Print Screen Deluxe\psdeluxe.exe
O4 - Startup: Shortcut to EZMacros.lnk = C:\Program Files\American Systems\EZ Macros\EZMacros.exe
O4 - Startup: URL Address Book.lnk = C:\Program Files\GBCS Software\URL Address Book\Urlbook.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O4 - Global Startup: Zip Up The Web Tray Icon.lnk = C:\Program Files\Insight Development\Zip Up The Web Pro\ZUTWTray.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://www.lizardtech.com/download/files/w…ntrol_en_US.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.snapfish.com/SnapfishActivia.cab
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://www.tscmaps.com/shared/viewer/mgaxctrl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1189980911625
O16 - DPF: {6BF35011-3AE5-44D3-A8BB-73ED462A0BC0} (EZUploader Control) - http://www.ezprints.com/software/ezuploader.cab
O16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} - http://toolbar.google.com/data/GoogleActivate.cab
O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - http://www.rentmanager.com/demo/msrdp.cab
O16 - DPF: {A93B47FD-9BF6-4DA8-97FC-9270B9D64A6C} (VaPgCtrl Class) - http://www.dlink.com/products/livedemo/plugin/h263ctrl.cab
O16 - DPF: {BAC01377-73DD-4796-854D-2A8997E3D68A} (Yahoo! Photos Easy Upload Tool Class) - http://us.dl1.yimg.com/download.yahoo.com/…ropper1_6us.cab
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://download.toontown.com/sv1.0.13.16/ttinst.cab
O16 - DPF: {D53A9247-2FEA-4E93-8EEE-9A9B07E8D760} (EZPCropFit Class) - http://www.ezprints.com/software/cropfit.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Retrospect Launcher (RetroLauncher) - Dantz Development Corporation - C:\Program Files\Dantz\Retrospect\retrorun.exe
O23 - Service: Retrospect Helper - Dantz Development Corporation - C:\Program Files\Dantz\Retrospect\rthlpsvc.exe
O23 - Service: Retrospect WD Service (RetroWDSvc) - Dantz Development Corporation - C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
Hello and welcome to the forum.

Sorry about the delay in responding

If you still need help, Scan again with HijackThis, and "copy/paste" a new log file into this thread.

Please make a uninstall list using HijackThis
To access the Uninstall Manager you would do the following:

1. Start HijackThis
2. Click on the Config button
3. Click on the Misc Tools button
4. Click on the Open Uninstall Manager button.
5. Click on the Save list… button and specify where you would like to save this file. When you press Save button a notepad will open with the contents of that file. Simply copy and paste the contents of that notepad here in a reply.


Also please describe how your computer behaves at the moment.
Here is the latest JiJackThis log:

Logfile of HijackThis v1.99.1
Scan saved at 9:00:52 PM, on 12/20/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\Program Files\Dantz\Retrospect\retrorun.exe
C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Common Files\AOL\1125684819\ee\AOLSoftware.exe
C:\WINDOWS\System32\WDBtnMgr.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Insight Development\Zip Up The Web Pro\ZUTWTray.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\American Systems\Print Screen Deluxe\psdeluxe.exe
C:\Program Files\American Systems\EZ Macros\EZMacros.exe
c:\program files\common files\aol\1125684819\ee\services\antiSpywareApp\ver2_0_32_1\AOLSP Scheduler.exe
c:\program files\common files\aol\1125684819\ee\aolsoftware.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\taskmgr.exe
c:\program files\common files\aol\1125684819\ee\anotify.exe
C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\GBCS Software\URL Address Book\Urlbook.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Hijack This\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus8.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://news.myway.com/index/id/top%7Cap.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://qus8.hpwis.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: (no name) - {02DCA195-602B-4B1F-83FF-381B7E804BDB} - C:\WINDOWS\system32\HDBHO.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptcl.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1125684819\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [WD Button Manager] WDBtnMgr.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [AOLAspSunset2] C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\updates\aspapp\sunsetAsp2.exe
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\AOL 9.0b\AOL.EXE" -b
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: Print Screen Deluxe.lnk = C:\Program Files\American Systems\Print Screen Deluxe\psdeluxe.exe
O4 - Startup: Shortcut to EZMacros.lnk = C:\Program Files\American Systems\EZ Macros\EZMacros.exe
O4 - Startup: URL Address Book.lnk = C:\Program Files\GBCS Software\URL Address Book\Urlbook.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O4 - Global Startup: Zip Up The Web Tray Icon.lnk = C:\Program Files\Insight Development\Zip Up The Web Pro\ZUTWTray.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra button: URLBook - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files\GBCS Software\URL Address Book\Urlbook.exe (HKCU)
O9 - Extra 'Tools' menuitem: URL Address Book - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files\GBCS Software\URL Address Book\Urlbook.exe (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://www.lizardtech.com/download/files/w…ntrol_en_US.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.snapfish.com/SnapfishActivia.cab
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://www.tscmaps.com/shared/viewer/mgaxctrl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1189980911625
O16 - DPF: {6BF35011-3AE5-44D3-A8BB-73ED462A0BC0} (EZUploader Control) - http://www.ezprints.com/software/ezuploader.cab
O16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} - http://toolbar.google.com/data/GoogleActivate.cab
O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - http://www.rentmanager.com/demo/msrdp.cab
O16 - DPF: {A93B47FD-9BF6-4DA8-97FC-9270B9D64A6C} (VaPgCtrl Class) - http://www.dlink.com/products/livedemo/plugin/h263ctrl.cab
O16 - DPF: {BAC01377-73DD-4796-854D-2A8997E3D68A} (Yahoo! Photos Easy Upload Tool Class) - http://us.dl1.yimg.com/download.yahoo.com/…ropper1_6us.cab
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://download.toontown.com/sv1.0.13.16/ttinst.cab
O16 - DPF: {D53A9247-2FEA-4E93-8EEE-9A9B07E8D760} (EZPCropFit Class) - http://www.ezprints.com/software/cropfit.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Retrospect Launcher (RetroLauncher) - Dantz Development Corporation - C:\Program Files\Dantz\Retrospect\retrorun.exe
O23 - Service: Retrospect Helper - Dantz Development Corporation - C:\Program Files\Dantz\Retrospect\rthlpsvc.exe
O23 - Service: Retrospect WD Service (RetroWDSvc) - Dantz Development Corporation - C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

Here is the Uninstall List:

Adobe Acrobat 5.0
Adobe Download Manager 2.0 (Remove Only)
Adobe Flash Player ActiveX
Adobe Reader 7.0.9
AFPL Ghostscript 8.51
AFPL Ghostscript Fonts
Album Express Trial (Remove only)
AOL Coach Version 1.0(Build:20030807.3)
AOL Coach Version 2.0(Build:20041026.5 en)
AOL Toolbar
AOL Uninstaller (Choose which Products to Remove)
AOL You've Got Pictures Screensaver
Argali White & Yellow
Audacity 1.2.3
AutoIt v3.2.0.1
BroadJump Client Foundation
Citrix ICA Web Client
Command & Conquer Red Alert 2
Compaq Connections
ePreserver
ESRI ArcExplorer 2.0
Google Earth
Google Toolbar for Internet Explorer
Google Toolbar for Internet Explorer
Google Updater
HijackThis 1.99.1
HP Deskjet printer preloaded drivers
HP Image Zone 4.7
HP PSC & OfficeJet 4.7
HP Software Update
Image2PDF OCR v3.2
Instant Support
Intel® Extreme Graphics Driver
IrfanView (remove only)
ItalianNow!
ItsDeductible Express
Java™ 6 Update 3
KBD
Learn2 Player (Uninstall Only)
Lexmark X83
McAfee SecurityCenter
Microsoft .NET Framework (English) v1.0.3705
Microsoft .NET Framework 1.1
Microsoft Office 97, Professional Edition
Microsoft Works 7.0
MinuteMan
MyDVD
PaperPort 9.0
PC-Doctor for Windows
PDFCreator 0.7.1}
Picasa 2
PowerDVD
PrimoPDF
PrimoPDF
PrimoPDF Redistribution Package
Print Screen Deluxe
PS2
Pure Networks Port Magic
Python 2.2 combined Win32 extensions
Python 2.2.1
Quicken 2006
QuickTime
RealOne Player
Retrospect 6.5
S3Display
S3Gamma2
S3Info2
S3Overlay
SafeCast Shared Components
Self-help Subliminals
ShowBiz
Skype™ 3.5
Social Security Benefit Calculator
Spybot - Search & Destroy 1.4
Spyware Doctor 5.1
TurboTax 2005
TurboTax Basic 2003
TurboTax Basic 2004
TurboTax Basic 2006
TurboTax ItsDeductible 2005
TurboTax ItsDeductible 2006
Ultimate Paint 2.88
Update for Windows XP (KB898461)
URL Address Book 6.08
VERITAS RecordNow DX
VERITAS RecordNow DX Update Manager
VERITAS Simple Backup
VeryPDF PDF2Word v2.0
Viewpoint Media Player
WackGet (remove only)
WayneReavesCar
WexTech AnswerWorks
Windows Installer 3.1 (KB893803)
Windows XP Hotfix - KB822603
Windows XP Hotfix - KB823980
Windows XP Hotfix - KB842773
Windows XP Hotfix (SP2) [See q329256 for more information]
Windows XP Hotfix (SP2) Q327979
Windows XP Hotfix (SP2) Q329909
Windows XP Hotfix (SP2) Q331958
Windows XP Hotfix (SP2) Q811789
WinRAR archiver
WinZip
Yahoo! Photos Easy Upload Tool 1v6
Zip Up The Web Pro

Thanks for taking a look at this!

Ron Cobb
Here is how the computer is behaving now. Most programs run fine. There are about 3 or 4 programs that have become infected with this malware. When I try to start them, the Windows Installer shows up to do something - I know not what. If I click on the cancel button in this dialog box, and continue clicking for the several times it shows up, then finally the program I am trying to select will come up and run. If I don't click cancel in the Installer dialog box, the program will not ever come up. I believe I concluded that the infected programs were all at one time in the list of recently used programs of the Start list. So, I have now set this list to maximum length 0, hoping to avoid any further infection. Also, this Windows Installer Diaglog Box comes up after reboot. If I cancel at each appearance, the system will boot up and again most programs run OK. When this first started happening I checked my own Hijackthis log and found two sites in the O15 Trusted Site list. Whataboutadog.com and whataboutarabit.com. I removed these straght away, but it did not seem to help. Ron
Hi

Let's start here.

Please download FindAWF here:
http://noahdfear.geekstogo.com/FindAWF.exe
Save to desktop and run
The output is awf.txt, save the text file to your desktop.
Hi, I downloaded FINDAWF.exe and ran it. After 6 hours it is still running. I selected option 1 to check for bak files. Did this at 10:am this morning, and it is still running now at 4:00 pm this afternoon. No output from the program at all, only a blue screen stating it is "checking for duplicate files, please wait" which came up right away. Is this normal - six hours in execution without any notice to the user? I have three hard drives on this computer, but only C: is the system drive, the others are storage and backup. It does seem like the program is still searching one of the other hard drives. Thanks Ron Cobb
No, it shouldnt take that long. The following tool also checks for AWF, so stop FindAWF and follow the instructions. :thumbup:

If you already have Combofix, please delete this copy and download it again as it's being updated regularly.

Please Download and Save Combofix from Bleeping Computer. Save it to your desktop.

If you can't download it, please try these 2 alternative sites:

Forospyware
Geeks to Go
  • Save it to your Desktop.
  • Disconnect from the Internet, than disable your anti-virus and any real-time anti-spyware monitors that are running.
  • Click Start>Run copy/paste or type "%userprofile%\desktop\combofix.exe" /killall into the Run box and click OK.
  • When finished, it shall produce a log for you. Post that log in your next reply with a new HijackThis log.
Note 1: Do not mouseclick combofix's window whilst it's running. That may cause it to stall
Note 2:Remember to re-enable your anti-virus and anti-spyware before reconnecting to the Internet.

Combofix should never take more that 20 minutes including the reboot if malware is detected.
If it does, open Task-Manager use the Processes tab (press ctrl alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
If that happened we want to know, and also what process you had to end.

In your next reply post:
ComboFix.txt
New HijackThis log taken after the above scan has run
Scotty, Finally I have an AWF.txt file. The program ran for over 8 hours, but finally finished. Below is the file. Here is why I think it took so long. I have two USB Hard Drives that I use to automaically back up the C:drive on a regular basis. These drives have various backups, many of which I should toss out, but have not done so, since I never (amost) access them. So you will see in the log a lot of reference to G: and H; drives. I expect we should disragard any duplicte files on those drives, and just concentrate on C: Anyway, because of my wierd configuration and how I backup, this might be a horrendus clean-up task. Basically what I do is an incremental backup of my C: drive each night at 2:00 am on to the H:drive. (But, note that I never create a backup file with a .bak extenseion.) The G: drive is not written anymore, and I just keep it around because it has some very old files I did n ot want to trash. Please take a look, and if you think I am beyond help, let me know. I could disconnect the G: and H; drives and redo the AWF.txt, if that would simplify this analysis. Thanks, I really appreciate your help. Ron Cobb ——————————– Find AWF report by noahdfear ©2006 Version 1.40 The current date is: Fri 12/21/2007 The current time is: 9:46:46.43 bak folders found ~~~~~~~~~~~ Directory of C:\HP\KBD\BAK 02/11/2003 11:02 PM 61,440 KBD.EXE 1 File(s) 61,440 bytes Directory of C:\PROGRA~1\AMERIC~1.0A\BAK 07/12/2005 01:17 AM 50,776 AOL.EXE 09/19/2007 09:27 PM 24 shellmon.ph 2 File(s) 50,800 bytes Directory of C:\PROGRA~1\AOL9~1.0B\BAK 04/18/2007 02:49 AM 50,736 AOL.EXE 11/19/2007 09:12 AM 24 shellmon.ph 2 File(s) 50,760 bytes Directory of C:\PROGRA~1\LEXMAR~1\BAK 06/14/2001 12:42 PM 53,248 AcBtnMgr_X83.exe 10/18/2001 10:25 AM 40,960 ACMonitor_X83.exe 2 File(s) 94,208 bytes Directory of C:\PROGRA~1\MESSEN~1\BAK 0 File(s) 0 bytes Directory of C:\PROGRA~1\PICASA2\BAK 12/11/2006 08:36 PM 366,400 PicasaMediaDetector.exe 1 File(s) 366,400 bytes Directory of C:\PROGRA~1\QUICKT~1\BAK 09/02/2005 02:16 PM 98,304 qttask.exe 1 File(s) 98,304 bytes Directory of C:\WINDOWS\SMINST\BAK 09/14/2002 12:42 AM 212,992 RECGUARD.EXE 1 File(s) 212,992 bytes Directory of C:\WINDOWS\SYSTEM\BAK 11/26/2007 08:47 AM 183 hpsysdrv.DAT 05/07/1998 07:04 PM 52,736 hpsysdrv.exe 2 File(s) 52,919 bytes Directory of C:\WINDOWS\SYSTEM32\BAK 03/11/2003 08:11 PM 114,688 hkcmd.exe 07/31/2002 11:28 PM 81,920 ps2.exe 2 File(s) 196,608 bytes Directory of C:\PROGRA~1\BROADJ~1\CLIENT~1\BAK 0 File(s) 0 bytes Directory of C:\PROGRA~1\GOOGLE\GOOGLE~2\BAK 07/12/2007 10:13 PM 68,856 GoogleToolbarNotifier.exe 1 File(s) 68,856 bytes Directory of C:\PROGRA~1\HP\HPSOFT~1\BAK 09/13/2004 04:49 PM 49,152 HPWuSchd2.exe 1 File(s) 49,152 bytes Directory of C:\PROGRA~1\MCAFEE.COM\PERSON~1\BAK 04/12/2005 04:44 PM 1,187,899 MpfTray.exe 1 File(s) 1,187,899 bytes Directory of C:\PROGRA~1\PURENE~1\PORTMA~1\BAK 04/05/2004 05:33 PM 99,480 PortAOL.exe 1 File(s) 99,480 bytes Directory of C:\PROGRA~1\REAL\REALON~1\BAK 05/26/2006 08:21 AM 1,003,520 realplay.exe 1 File(s) 1,003,520 bytes Directory of C:\PROGRA~1\SCANSOFT\PAPERP~1\BAK 02/27/2003 02:40 AM 40,960 IndexSearch.exe 02/27/2003 02:12 AM 57,393 pptd40nt.exe 2 File(s) 98,353 bytes Directory of C:\PROGRA~1\SKYPE\PHONE\BAK 08/17/2007 03:45 AM 23,120,680 Skype.exe 1 File(s) 23,120,680 bytes Directory of C:\PROGRA~1\VERITA~1\UPDATE~1\BAK 06/18/2002 01:01 AM 155,648 sgtray.exe 1 File(s) 155,648 bytes Directory of C:\PROGRA~1\COMMON~1\AOL\ACS\BAK 10/23/2006 08:50 AM 71,216 AOLDial.exe 1 File(s) 71,216 bytes Directory of C:\PROGRA~1\COMMON~1\REAL\UPDATE~1\BAK 04/26/2003 02:30 AM 151,597 realsched.exe 1 File(s) 151,597 bytes Directory of C:\PROGRA~1\COMMON~1\AOL\112568~1\EE\BAK 09/25/2006 08:52 PM 50,736 AOLSoftware.exe 1 File(s) 50,736 bytes Directory of C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\BAK 10/25/2001 02:20 PM 36,864 printray.exe 1 File(s) 36,864 bytes Directory of G:\CDRIVE~1\HP\KBD\BAK 02/11/2003 11:02 PM 61,440 KBD.EXE 1 File(s) 61,440 bytes Directory of G:\CDRIVE~1\PROGRA~1\AMERIC~1.0A\BAK 07/12/2005 01:17 AM 50,776 AOL.EXE 09/19/2007 09:27 PM 24 shellmon.ph 2 File(s) 50,800 bytes Directory of G:\CDRIVE~1\PROGRA~1\AOL9~1.0B\BAK 04/18/2007 02:49 AM 50,736 AOL.EXE 11/19/2007 09:12 AM 24 shellmon.ph 2 File(s) 50,760 bytes Directory of G:\CDRIVE~1\PROGRA~1\LEXMAR~1\BAK 06/14/2001 12:42 PM 53,248 AcBtnMgr_X83.exe 10/18/2001 10:25 AM 40,960 ACMonitor_X83.exe 2 File(s) 94,208 bytes Directory of G:\CDRIVE~1\PROGRA~1\MESSEN~1\BAK 0 File(s) 0 bytes Directory of G:\CDRIVE~1\PROGRA~1\PICASA2\BAK 12/11/2006 08:36 PM 366,400 PicasaMediaDetector.exe 1 File(s) 366,400 bytes Directory of G:\CDRIVE~1\PROGRA~1\QUICKT~1\BAK 09/02/2005 02:16 PM 98,304 qttask.exe 1 File(s) 98,304 bytes Directory of G:\CDRIVE~1\WINDOWS\SMINST\BAK 09/14/2002 12:42 AM 212,992 RECGUARD.EXE 1 File(s) 212,992 bytes Directory of G:\CDRIVE~1\WINDOWS\SYSTEM\BAK 11/26/2007 08:47 AM 183 hpsysdrv.DAT 05/07/1998 07:04 PM 52,736 hpsysdrv.exe 2 File(s) 52,919 bytes Directory of G:\CDRIVE~1\WINDOWS\SYSTEM32\BAK 03/11/2003 08:11 PM 114,688 hkcmd.exe 07/31/2002 11:28 PM 81,920 ps2.exe 2 File(s) 196,608 bytes Directory of G:\CDRIVE~1\PROGRA~1\BROADJ~1\CLIENT~1\BAK 0 File(s) 0 bytes Directory of G:\CDRIVE~1\PROGRA~1\GOOGLE\GOOGLE~2\BAK 07/12/2007 10:13 PM 68,856 GoogleToolbarNotifier.exe 1 File(s) 68,856 bytes Directory of G:\CDRIVE~1\PROGRA~1\HP\HPSOFT~1\BAK 09/13/2004 04:49 PM 49,152 HPWuSchd2.exe 1 File(s) 49,152 bytes Directory of G:\CDRIVE~1\PROGRA~1\MCAFEE.COM\PERSON~1\BAK 04/12/2005 04:44 PM 1,187,899 MpfTray.exe 1 File(s) 1,187,899 bytes Directory of G:\CDRIVE~1\PROGRA~1\PURENE~1\PORTMA~1\BAK 04/05/2004 05:33 PM 99,480 PortAOL.exe 1 File(s) 99,480 bytes Directory of G:\CDRIVE~1\PROGRA~1\REAL\REALON~1\BAK 05/26/2006 08:21 AM 1,003,520 realplay.exe 1 File(s) 1,003,520 bytes Directory of G:\CDRIVE~1\PROGRA~1\SCANSOFT\PAPERP~1\BAK 02/27/2003 02:40 AM 40,960 IndexSearch.exe 02/27/2003 02:12 AM 57,393 pptd40nt.exe 2 File(s) 98,353 bytes Directory of G:\CDRIVE~1\PROGRA~1\SKYPE\PHONE\BAK 08/17/2007 03:45 AM 23,120,680 Skype.exe 1 File(s) 23,120,680 bytes Directory of G:\CDRIVE~1\PROGRA~1\VERITA~1\UPDATE~1\BAK 06/18/2002 01:01 AM 155,648 sgtray.exe 1 File(s) 155,648 bytes Directory of G:\CDRIVE~1\PROGRA~1\COMMON~1\AOL\ACS\BAK 10/23/2006 08:50 AM 71,216 AOLDial.exe 1 File(s) 71,216 bytes Directory of G:\CDRIVE~1\PROGRA~1\COMMON~1\REAL\UPDATE~1\BAK 04/26/2003 02:30 AM 151,597 realsched.exe 1 File(s) 151,597 bytes Directory of G:\CDRIVE~1\PROGRA~1\COMMON~1\AOL\112568~1\EE\BAK 09/25/2006 08:52 PM 50,736 AOLSoftware.exe 1 File(s) 50,736 bytes Directory of G:\FHCOBB~1.JPG\HPOMNI~1\PROGRA~1\SUPPORT.COM\BACKUP\PH\PHONEITL.BAK 11/14/2001 01:10 PM 542,231 1779648_5abe1c3b1_ 1 File(s) 542,231 bytes Directory of G:\CDRIVE~1\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\BAK 10/25/2001 02:20 PM 36,864 printray.exe 1 File(s) 36,864 bytes Directory of H:\RESTOR~1\HPOMNI~1\PROGRA~1\SUPPORT.COM\BACKUP\PH\PHONEITL.BAK 11/14/2001 12:10 PM 542,231 1779648_5abe1c3b1_ 1 File(s) 542,231 bytes Duplicate files of bak directory contents ~~~~~~~~~~~~~~~~~~~~~~~ 61440 Feb 11 2003 "C:\hp\KBD\bak\KBD.EXE" 61440 Feb 11 2003 "G:\C Drive Duplicate\hp\KBD\bak\KBD.EXE" 45125 Dec 18 2002 "C:\Program Files\America Online 8.0\aol.exe" 45140 Sep 24 2003 "C:\Program Files\America Online 9.0\aol.exe" 24576 Aug 27 1999 "C:\Program Files\America Online 5.0\aol.exe" 50736 Apr 18 2007 "C:\Program Files\AOL 9.0a\aol.exe" 50776 Jul 12 2005 "C:\Program Files\America Online 9.0a\bak\AOL.EXE" 50736 Apr 18 2007 "C:\Program Files\AOL 9.0b\bak\AOL.EXE" 45125 Dec 18 2002 "G:\C Drive Duplicate\Program Files\America Online 8.0\aol.exe" 45140 Sep 24 2003 "G:\C Drive Duplicate\Program Files\America Online 9.0\aol.exe" 24576 Aug 27 1999 "G:\C Drive Duplicate\Program Files\America Online 5.0\aol.exe" 50736 Apr 18 2007 "G:\C Drive Duplicate\Program Files\AOL 9.0a\aol.exe" 24576 Aug 27 1999 "G:\Old G Drive Restored Partial\May 19 Copy ofPavillion Drive C\America Online 5.0\aol.exe" 50776 Jul 12 2005 "G:\C Drive Duplicate\Program Files\America Online 9.0a\bak\AOL.EXE" 50736 Apr 18 2007 "G:\C Drive Duplicate\Program Files\AOL 9.0b\bak\AOL.EXE" 24576 Aug 27 1999 "G:\Backup Set A - C and G-1\1 Pavilion Backup Combined\May 19 Copy ofPavillion Drive C\America Online 5.0\aol.exe" 74 Sep 16 2007 "C:\Program Files\America Online 8.0\shellmon.ph" 24 Sep 11 2007 "C:\Program Files\America Online 9.0a\shellmon.ph" 24 Sep 19 2007 "C:\Program Files\America Online 9.0\shellmon.ph" 24 Sep 16 2007 "C:\Program Files\AOL 9.0a\shellmon.ph" 24 Sep 16 2007 "C:\Program Files\AOL 9.0b\shellmon.ph" 24 Sep 19 2007 "C:\Program Files\America Online 9.0a\bak\shellmon.ph" 24 Nov 19 2007 "C:\Program Files\AOL 9.0b\bak\shellmon.ph" 1693 Oct 21 2007 "C:\Documents and Settings\All Users\Application Data\AOL\C_America Online 9.0\shellmon.ph" 1646 Sep 26 2007 "C:\Documents and Settings\All Users\Application Data\AOL\C_America Online 9.0a\shellmon.ph" 1634 Sep 24 2007 "C:\Documents and Settings\All Users\Application Data\AOL\C_AOL 9.0a\shellmon.ph" 2402 Dec 14 2007 "C:\Documents and Settings\All Users\Application Data\AOL\C_AOL 9.0b\shellmon.ph" 74 Sep 16 2007 "G:\C Drive Duplicate\Program Files\America Online 8.0\shellmon.ph" 24 Sep 11 2007 "G:\C Drive Duplicate\Program Files\America Online 9.0a\shellmon.ph" 24 Sep 19 2007 "G:\C Drive Duplicate\Program Files\America Online 9.0\shellmon.ph" 24 Sep 16 2007 "G:\C Drive Duplicate\Program Files\AOL 9.0a\shellmon.ph" 24 Sep 16 2007 "G:\C Drive Duplicate\Program Files\AOL 9.0b\shellmon.ph" 24 Sep 19 2007 "G:\C Drive Duplicate\Program Files\America Online 9.0a\bak\shellmon.ph" 24 Nov 19 2007 "G:\C Drive Duplicate\Program Files\AOL 9.0b\bak\shellmon.ph" 1693 Oct 21 2007 "G:\C Drive Duplicate\Documents and Settings\All Users\Application Data\AOL\C_America Online 9.0\shellmon.ph" 1646 Sep 26 2007 "G:\C Drive Duplicate\Documents and Settings\All Users\Application Data\AOL\C_America Online 9.0a\shellmon.ph" 1634 Sep 24 2007 "G:\C Drive Duplicate\Documents and Settings\All Users\Application Data\AOL\C_AOL 9.0a\shellmon.ph" 4800 Dec 6 2007 "G:\C Drive Duplicate\Documents and Settings\All Users\Application Data\AOL\C_AOL 9.0b\shellmon.ph" 45125 Dec 18 2002 "C:\Program Files\America Online 8.0\aol.exe" 45140 Sep 24 2003 "C:\Program Files\America Online 9.0\aol.exe" 24576 Aug 27 1999 "C:\Program Files\America Online 5.0\aol.exe" 50736 Apr 18 2007 "C:\Program Files\AOL 9.0a\aol.exe" 50776 Jul 12 2005 "C:\Program Files\America Online 9.0a\bak\AOL.EXE" 50736 Apr 18 2007 "C:\Program Files\AOL 9.0b\bak\AOL.EXE" 45125 Dec 18 2002 "G:\C Drive Duplicate\Program Files\America Online 8.0\aol.exe" 45140 Sep 24 2003 "G:\C Drive Duplicate\Program Files\America Online 9.0\aol.exe" 24576 Aug 27 1999 "G:\C Drive Duplicate\Program Files\America Online 5.0\aol.exe" 50736 Apr 18 2007 "G:\C Drive Duplicate\Program Files\AOL 9.0a\aol.exe" 24576 Aug 27 1999 "G:\Old G Drive Restored Partial\May 19 Copy ofPavillion Drive C\America Online 5.0\aol.exe" 50776 Jul 12 2005 "G:\C Drive Duplicate\Program Files\America Online 9.0a\bak\AOL.EXE" 50736 Apr 18 2007 "G:\C Drive Duplicate\Program Files\AOL 9.0b\bak\AOL.EXE" 24576 Aug 27 1999 "G:\Backup Set A - C and G-1\1 Pavilion Backup Combined\May 19 Copy ofPavillion Drive C\America Online 5.0\aol.exe" 74 Sep 16 2007 "C:\Program Files\America Online 8.0\shellmon.ph" 24 Sep 11 2007 "C:\Program Files\America Online 9.0a\shellmon.ph" 24 Sep 19 2007 "C:\Program Files\America Online 9.0\shellmon.ph" 24 Sep 16 2007 "C:\Program Files\AOL 9.0a\shellmon.ph" 24 Sep 16 2007 "C:\Program Files\AOL 9.0b\shellmon.ph" 24 Sep 19 2007 "C:\Program Files\America Online 9.0a\bak\shellmon.ph" 24 Nov 19 2007 "C:\Program Files\AOL 9.0b\bak\shellmon.ph" 1693 Oct 21 2007 "C:\Documents and Settings\All Users\Application Data\AOL\C_America Online 9.0\shellmon.ph" 1646 Sep 26 2007 "C:\Documents and Settings\All Users\Application Data\AOL\C_America Online 9.0a\shellmon.ph" 1634 Sep 24 2007 "C:\Documents and Settings\All Users\Application Data\AOL\C_AOL 9.0a\shellmon.ph" 2402 Dec 14 2007 "C:\Documents and Settings\All Users\Application Data\AOL\C_AOL 9.0b\shellmon.ph" 74 Sep 16 2007 "G:\C Drive Duplicate\Program Files\America Online 8.0\shellmon.ph" 24 Sep 11 2007 "G:\C Drive Duplicate\Program Files\America Online 9.0a\shellmon.ph" 24 Sep 19 2007 "G:\C Drive Duplicate\Program Files\America Online 9.0\shellmon.ph" 24 Sep 16 2007 "G:\C Drive Duplicate\Program Files\AOL 9.0a\shellmon.ph" 24 Sep 16 2007 "G:\C Drive Duplicate\Program Files\AOL 9.0b\shellmon.ph" 24 Sep 19 2007 "G:\C Drive Duplicate\Program Files\America Online 9.0a\bak\shellmon.ph" 24 Nov 19 2007 "G:\C Drive Duplicate\Program Files\AOL 9.0b\bak\shellmon.ph" 1693 Oct 21 2007 "G:\C Drive Duplicate\Documents and Settings\All Users\Application Data\AOL\C_America Online 9.0\shellmon.ph" 1646 Sep 26 2007 "G:\C Drive Duplicate\Documents and Settings\All Users\Application Data\AOL\C_America Online 9.0a\shellmon.ph" 1634 Sep 24 2007 "G:\C Drive Duplicate\Documents and Settings\All Users\Application Data\AOL\C_AOL 9.0a\shellmon.ph" 4800 Dec 6 2007 "G:\C Drive Duplicate\Documents and Settings\All Users\Application Data\AOL\C_AOL 9.0b\shellmon.ph" 53248 Jun 14 2001 "C:\Program Files\LexmarkX83\bak\AcBtnMgr_X83.exe" 53248 Jun 14 2001 "G:\C Drive Duplicate\Program Files\LexmarkX83\bak\AcBtnMgr_X83.exe" 40960 Oct 18 2001 "C:\Program Files\LexmarkX83\bak\ACMonitor_X83.exe" 40960 Oct 18 2001 "G:\C Drive Duplicate\Program Files\LexmarkX83\bak\ACMonitor_X83.exe" 591416 Sep 27 2007 "C:\Program Files\Picasa2\PicasaUpdate.exe" 366400 Dec 11 2006 "C:\Program Files\Picasa2\bak\PicasaMediaDetector.exe" 665160 Sep 27 2007 "C:\Program Files\Picasa2\cdautorun\PicasaRestore.exe" 591416 Sep 27 2007 "G:\C Drive Duplicate\Program Files\Picasa2\PicasaUpdate.exe" 366400 Dec 11 2006 "G:\C Drive Duplicate\Program Files\Picasa2\bak\PicasaMediaDetector.exe" 665160 Sep 27 2007 "G:\C Drive Duplicate\Program Files\Picasa2\cdautorun\PicasaRestore.exe" 98304 Sep 2 2005 "C:\Program Files\QuickTime\bak\qttask.exe" 98304 Sep 2 2005 "G:\C Drive Duplicate\Program Files\QuickTime\bak\qttask.exe" 212992 Sep 14 2002 "C:\WINDOWS\SMINST\bak\RECGUARD.EXE" 212992 Sep 14 2002 "G:\C Drive Duplicate\WINDOWS\SMINST\bak\RECGUARD.EXE" 199 Sep 16 2003 "C:\WINDOWS\system\hpsysdrv.DAT" 183 Nov 26 2007 "C:\WINDOWS\system\bak\hpsysdrv.DAT" 199 Sep 16 2003 "G:\C Drive Duplicate\WINDOWS\system\hpsysdrv.DAT" 183 Nov 26 2007 "G:\C Drive Duplicate\WINDOWS\system\bak\hpsysdrv.DAT" 52736 May 7 1998 "C:\WINDOWS\system\bak\hpsysdrv.exe" 52736 May 7 1998 "G:\C Drive Duplicate\WINDOWS\system\bak\hpsysdrv.exe" 114688 Mar 11 2003 "C:\WINDOWS\system32\bak\hkcmd.exe" 114688 Mar 11 2003 "C:\hp\drivers\video\865\hkcmd.exe" 114688 Mar 11 2003 "C:\WINDOWS\system32\ReinstallBackups\0002\DriverFiles\hkcmd.exe" 114688 Mar 11 2003 "G:\C Drive Duplicate\WINDOWS\system32\bak\hkcmd.exe" 114688 Mar 11 2003 "G:\C Drive Duplicate\hp\drivers\video\865\hkcmd.exe" 114688 Mar 11 2003 "G:\C Drive Duplicate\WINDOWS\system32\ReinstallBackups\0002\DriverFiles\hkcmd.exe" 81920 Jul 31 2002 "C:\hp\drivers\keyboard\PS2.EXE" 81920 Jul 31 2002 "C:\WINDOWS\system32\bak\ps2.exe" 81920 Jul 31 2002 "G:\C Drive Duplicate\hp\drivers\keyboard\PS2.EXE" 81920 Jul 31 2002 "G:\C Drive Duplicate\WINDOWS\system32\bak\ps2.exe" 52272 Nov 16 2007 "C:\Program Files\Google\googletoolbar1user.exe" 441088 Nov 17 2003 "C:\Program Files\America Online 5.0\download\GoogleToolbarInstaller.exe" 69632 May 24 2007 "C:\Program Files\Google\Google Earth\googleearth.exe" 126136 Nov 16 2007 "C:\Program Files\Google\Google Updater\GoogleUpdater.exe" 138680 Nov 16 2007 "C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe" 68856 Jul 12 2007 "C:\Program Files\Google\GoogleToolbarNotifier\bak\GoogleToolbarNotifier.exe" 126136 Nov 16 2007 "C:\Program Files\Google\Google Updater\2.2.969.23408\GoogleUpdaterRestartManager.exe" 26694 Jul 15 2007 "C:\Documents and Settings\Owner\Application Data\Microsoft\Installer\{407B9B5C-DAC5-4F44-A756-B57CAB4E6A8B}\googleearth.exe_407B9B5CDAC54F44A756B57CAB4E6A8B.exe" 52272 Nov 16 2007 "G:\C Drive Duplicate\Program Files\Google\googletoolbar1user.exe" 441088 Nov 17 2003 "G:\C Drive Duplicate\Program Files\America Online 5.0\download\GoogleToolbarInstaller.exe" 69632 May 24 2007 "G:\C Drive Duplicate\Program Files\Google\Google Earth\googleearth.exe" 126136 Nov 16 2007 "G:\C Drive Duplicate\Program Files\Google\Google Updater\GoogleUpdater.exe" 441088 Nov 17 2003 "G:\Old G Drive Restored Partial\May 19 Copy ofPavillion Drive C\America Online 5.0\download\GoogleToolbarInstaller.exe" 138680 Nov 16 2007 "G:\C Drive Duplicate\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe" 68856 Jul 12 2007 "G:\C Drive Duplicate\Program Files\Google\GoogleToolbarNotifier\bak\GoogleToolbarNotifier.exe" 126136 Nov 16 2007 "G:\C Drive Duplicate\Program Files\Google\Google Updater\2.2.969.23408\GoogleUpdaterRestartManager.exe" 441088 Nov 17 2003 "G:\Backup Set A - C and G-1\1 Pavilion Backup Combined\May 19 Copy ofPavillion Drive C\America Online 5.0\download\GoogleToolbarInstaller.exe" 3832231 Sep 28 2002 "G:\Old G Drive Restored Partial\May 19 Copy ofPavillion Drive C\My Documents\Daniel\2002 Season\Google News 092802.EXE" 3832231 Sep 28 2002 "G:\Backup Set A - C and G-1\1 Pavilion Backup Combined\May 19 Copy ofPavillion Drive C\My Documents\Daniel\2002 Season\Google News 092802.EXE" 26694 Jul 15 2007 "G:\C Drive Duplicate\Documents and Settings\Owner\Application Data\Microsoft\Installer\{407B9B5C-DAC5-4F44-A756-B57CAB4E6A8B}\googleearth.exe_407B9B5CDAC54F44A756B57CAB4E6A8B.exe" 882512 Nov 16 2007 "G:\C Drive Duplicate\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\OR5BEI7P\Google Updater[1].exe" 49152 Sep 13 2004 "C:\Program Files\HP\HP Software Update\bak\HPWuSchd2.exe" 49152 Sep 13 2004 "G:\C Drive Duplicate\Program Files\HP\HP Software Update\bak\HPWuSchd2.exe" 1187899 Apr 12 2005 "C:\Program Files\McAfee.com\Personal Firewall\bak\MpfTray.exe" 1187899 Apr 12 2005 "G:\C Drive Duplicate\Program Files\McAfee.com\Personal Firewall\bak\MpfTray.exe" 99480 Apr 5 2004 "C:\Program Files\Pure Networks\Port Magic\bak\PortAOL.exe" 99480 Apr 5 2004 "G:\C Drive Duplicate\Program Files\Pure Networks\Port Magic\bak\PortAOL.exe" 1003520 May 26 2006 "C:\Program Files\Real\RealOne Player\bak\realplay.exe" 1003520 May 26 2006 "G:\C Drive Duplicate\Program Files\Real\RealOne Player\bak\realplay.exe" 19456 Sep 4 2001 "G:\Old G Drive Restored Partial\May 19 Copy ofPavillion Drive C\Program Files\Real\RealPlayer\realplay.exe" 19456 Sep 4 2001 "G:\Backup Set A - C and G-1\1 Pavilion Backup Combined\May 19 Copy ofPavillion Drive C\Program Files\Real\RealPlayer\realplay.exe" 40960 Feb 27 2003 "C:\Program Files\ScanSoft\PaperPort\bak\IndexSearch.exe" 40960 Feb 27 2003 "G:\C Drive Duplicate\Program Files\ScanSoft\PaperPort\bak\IndexSearch.exe" 57393 Feb 27 2003 "C:\Program Files\ScanSoft\PaperPort\bak\pptd40nt.exe" 57393 Feb 27 2003 "G:\C Drive Duplicate\Program Files\ScanSoft\PaperPort\bak\pptd40nt.exe" 29184 Apr 13 1999 "G:\Old G Drive Restored Partial\May 19 Copy ofPavillion Drive C\Program Files\Visioneer\PaperPort\Pptd40nt.exe" 29184 Apr 13 1999 "G:\Backup Set A - C and G-1\1 Pavilion Backup Combined\May 19 Copy ofPavillion Drive C\Program Files\Visioneer\PaperPort\Pptd40nt.exe" 23120680 Aug 17 2007 "C:\Program Files\Skype\Phone\bak\Skype.exe" 23120680 Aug 17 2007 "G:\C Drive Duplicate\Program Files\Skype\Phone\bak\Skype.exe" 155648 Jun 18 2002 "C:\Program Files\VERITAS Software\Update Manager\bak\sgtray.exe" 155648 Jun 18 2002 "G:\C Drive Duplicate\Program Files\VERITAS Software\Update Manager\bak\sgtray.exe" 71216 Oct 23 2006 "C:\Program Files\Common Files\AOL\ACS\bak\AOLDial.exe" 71216 Oct 23 2006 "G:\C Drive Duplicate\Program Files\Common Files\AOL\ACS\bak\AOLDial.exe" 151597 Apr 26 2003 "C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe" 151597 Apr 26 2003 "G:\C Drive Duplicate\Program Files\Common Files\Real\Update_OB\bak\realsched.exe" 50736 Sep 25 2006 "C:\Program Files\Common Files\AOL\1125684819\EE\AOLSoftware.exe1189973455" 50736 Sep 25 2006 "C:\Program Files\Common Files\AOL\1125684819\EE\bak\AOLSoftware.exe" 50736 Sep 25 2006 "G:\C Drive Duplicate\Program Files\Common Files\AOL\1125684819\EE\AOLSoftware.exe1189973455" 50736 Sep 25 2006 "G:\C Drive Duplicate\Program Files\Common Files\AOL\1125684819\EE\bak\AOLSoftware.exe" 36864 Oct 25 2001 "C:\WINDOWS\system32\spool\drivers\w32x86\lexmarklexmark_x83d8e5\printray.exe" 36864 Oct 25 2001 "C:\WINDOWS\system32\spool\drivers\w32x86\3\bak\printray.exe" 36864 Oct 25 2001 "G:\C Drive Duplicate\WINDOWS\system32\spool\drivers\w32x86\lexmarklexmark_x83d8e5\printray.exe" 36864 Oct 25 2001 "G:\C Drive Duplicate\WINDOWS\system32\spool\drivers\w32x86\3\bak\printray.exe" 61440 Feb 11 2003 "C:\hp\KBD\bak\KBD.EXE" 61440 Feb 11 2003 "G:\C Drive Duplicate\hp\KBD\bak\KBD.EXE" 45125 Dec 18 2002 "C:\Program Files\America Online 8.0\aol.exe" 45140 Sep 24 2003 "C:\Program Files\America Online 9.0\aol.exe" 24576 Aug 27 1999 "C:\Program Files\America Online 5.0\aol.exe" 50736 Apr 18 2007 "C:\Program Files\AOL 9.0a\aol.exe" 50776 Jul 12 2005 "C:\Program Files\America Online 9.0a\bak\AOL.EXE" 50736 Apr 18 2007 "C:\Program Files\AOL 9.0b\bak\AOL.EXE" 45125 Dec 18 2002 "G:\C Drive Duplicate\Program Files\America Online 8.0\aol.exe" 45140 Sep 24 2003 "G:\C Drive Duplicate\Program Files\America Online 9.0\aol.exe" 24576 Aug 27 1999 "G:\C Drive Duplicate\Program Files\America Online 5.0\aol.exe" 50736 Apr 18 2007 "G:\C Drive Duplicate\Program Files\AOL 9.0a\aol.exe" 24576 Aug 27 1999 "G:\Old G Drive Restored Partial\May 19 Copy ofPavillion Drive C\America Online 5.0\aol.exe" 50776 Jul 12 2005 "G:\C Drive Duplicate\Program Files\America Online 9.0a\bak\AOL.EXE" 50736 Apr 18 2007 "G:\C Drive Duplicate\Program Files\AOL 9.0b\bak\AOL.EXE" 24576 Aug 27 1999 "G:\Backup Set A - C and G-1\1 Pavilion Backup Combined\May 19 Copy ofPavillion Drive C\America Online 5.0\aol.exe" 74 Sep 16 2007 "C:\Program Files\America Online 8.0\shellmon.ph" 24 Sep 11 2007 "C:\Program Files\America Online 9.0a\shellmon.ph" 24 Sep 19 2007 "C:\Program Files\America Online 9.0\shellmon.ph" 24 Sep 16 2007 "C:\Program Files\AOL 9.0a\shellmon.ph" 24 Sep 16 2007 "C:\Program Files\AOL 9.0b\shellmon.ph" 24 Sep 19 2007 "C:\Program Files\America Online 9.0a\bak\shellmon.ph" 24 Nov 19 2007 "C:\Program Files\AOL 9.0b\bak\shellmon.ph" 1693 Oct 21 2007 "C:\Documents and Settings\All Users\Application Data\AOL\C_America Online 9.0\shellmon.ph" 1646 Sep 26 2007 "C:\Documents and Settings\All Users\Application Data\AOL\C_America Online 9.0a\shellmon.ph" 1634 Sep 24 2007 "C:\Documents and Settings\All Users\Application Data\AOL\C_AOL 9.0a\shellmon.ph" 2402 Dec 14 2007 "C:\Documents and Settings\All Users\Application Data\AOL\C_AOL 9.0b\shellmon.ph" 74 Sep 16 2007 "G:\C Drive Duplicate\Program Files\America Online 8.0\shellmon.ph" 24 Sep 11 2007 "G:\C Drive Duplicate\Program Files\America Online 9.0a\shellmon.ph" 24 Sep 19 2007 "G:\C Drive Duplicate\Program Files\America Online 9.0\shellmon.ph" 24 Sep 16 2007 "G:\C Drive Duplicate\Program Files\AOL 9.0a\shellmon.ph" 24 Sep 16 2007 "G:\C Drive Duplicate\Program Files\AOL 9.0b\shellmon.ph" 24 Sep 19 2007 "G:\C Drive Duplicate\Program Files\America Online 9.0a\bak\shellmon.ph" 24 Nov 19 2007 "G:\C Drive Duplicate\Program Files\AOL 9.0b\bak\shellmon.ph" 1693 Oct 21 2007 "G:\C Drive Duplicate\Documents and Settings\All Users\Application Data\AOL\C_America Online 9.0\shellmon.ph" 1646 Sep 26 2007 "G:\C Drive Duplicate\Documents and Settings\All Users\Application Data\AOL\C_America Online 9.0a\shellmon.ph" 1634 Sep 24 2007 "G:\C Drive Duplicate\Documents and Settings\All Users\Application Data\AOL\C_AOL 9.0a\shellmon.ph" 4800 Dec 6 2007 "G:\C Drive Duplicate\Documents and Settings\All Users\Application Data\AOL\C_AOL 9.0b\shellmon.ph" 45125 Dec 18 2002 "C:\Program Files\America Online 8.0\aol.exe" 45140 Sep 24 2003 "C:\Program Files\America Online 9.0\aol.exe" 24576 Aug 27 1999 "C:\Program Files\America Online 5.0\aol.exe" 50736 Apr 18 2007 "C:\Program Files\AOL 9.0a\aol.exe" 50776 Jul 12 2005 "C:\Program Files\America Online 9.0a\bak\AOL.EXE" 50736 Apr 18 2007 "C:\Program Files\AOL 9.0b\bak\AOL.EXE" 45125 Dec 18 2002 "G:\C Drive Duplicate\Program Files\America Online 8.0\aol.exe" 45140 Sep 24 2003 "G:\C Drive Duplicate\Program Files\America Online 9.0\aol.exe" 24576 Aug 27 1999 "G:\C Drive Duplicate\Program Files\America Online 5.0\aol.exe" 50736 Apr 18 2007 "G:\C Drive Duplicate\Program Files\AOL 9.0a\aol.exe" 24576 Aug 27 1999 "G:\Old G Drive Restored Partial\May 19 Copy ofPavillion Drive C\America Online 5.0\aol.exe" 50776 Jul 12 2005 "G:\C Drive Duplicate\Program Files\America Online 9.0a\bak\AOL.EXE" 50736 Apr 18 2007 "G:\C Drive Duplicate\Program Files\AOL 9.0b\bak\AOL.EXE" 24576 Aug 27 1999 "G:\Backup Set A - C and G-1\1 Pavilion Backup Combined\May 19 Copy ofPavillion Drive C\America Online 5.0\aol.exe" 74 Sep 16 2007 "C:\Program Files\America Online 8.0\shellmon.ph" 24 Sep 11 2007 "C:\Program Files\America Online 9.0a\shellmon.ph" 24 Sep 19 2007 "C:\Program Files\America Online 9.0\shellmon.ph" 24 Sep 16 2007 "C:\Program Files\AOL 9.0a\shellmon.ph" 24 Sep 16 2007 "C:\Program Files\AOL 9.0b\shellmon.ph" 24 Sep 19 2007 "C:\Program Files\America Online 9.0a\bak\shellmon.ph" 24 Nov 19 2007 "C:\Program Files\AOL 9.0b\bak\shellmon.ph" 1693 Oct 21 2007 "C:\Documents and Settings\All Users\Application Data\AOL\C_America Online 9.0\shellmon.ph" 1646 Sep 26 2007 "C:\Documents and Settings\All Users\Application Data\AOL\C_America Online 9.0a\shellmon.ph" 1634 Sep 24 2007 "C:\Documents and Settings\All Users\Application Data\AOL\C_AOL 9.0a\shellmon.ph" 2402 Dec 14 2007 "C:\Documents and Settings\All Users\Application Data\AOL\C_AOL 9.0b\shellmon.ph" 74 Sep 16 2007 "G:\C Drive Duplicate\Program Files\America Online 8.0\shellmon.ph" 24 Sep 11 2007 "G:\C Drive Duplicate\Program Files\America Online 9.0a\shellmon.ph" 24 Sep 19 2007 "G:\C Drive Duplicate\Program Files\America Online 9.0\shellmon.ph" 24 Sep 16 2007 "G:\C Drive Duplicate\Program Files\AOL 9.0a\shellmon.ph" 24 Sep 16 2007 "G:\C Drive Duplicate\Program Files\AOL 9.0b\shellmon.ph" 24 Sep 19 2007 "G:\C Drive Duplicate\Program Files\America Online 9.0a\bak\shellmon.ph" 24 Nov 19 2007 "G:\C Drive Duplicate\Program Files\AOL 9.0b\bak\shellmon.ph" 1693 Oct 21 2007 "G:\C Drive Duplicate\Documents and Settings\All Users\Application Data\AOL\C_America Online 9.0\shellmon.ph" 1646 Sep 26 2007 "G:\C Drive Duplicate\Documents and Settings\All Users\Application Data\AOL\C_America Online 9.0a\shellmon.ph" 1634 Sep 24 2007 "G:\C Drive Duplicate\Documents and Settings\All Users\Application Data\AOL\C_AOL 9.0a\shellmon.ph" 4800 Dec 6 2007 "G:\C Drive Duplicate\Documents and Settings\All Users\Application Data\AOL\C_AOL 9.0b\shellmon.ph" 53248 Jun 14 2001 "C:\Program Files\LexmarkX83\bak\AcBtnMgr_X83.exe" 53248 Jun 14 2001 "G:\C Drive Duplicate\Program Files\LexmarkX83\bak\AcBtnMgr_X83.exe" 40960 Oct 18 2001 "C:\Program Files\LexmarkX83\bak\ACMonitor_X83.exe" 40960 Oct 18 2001 "G:\C Drive Duplicate\Program Files\LexmarkX83\bak\ACMonitor_X83.exe" 591416 Sep 27 2007 "C:\Program Files\Picasa2\PicasaUpdate.exe" 366400 Dec 11 2006 "C:\Program Files\Picasa2\bak\PicasaMediaDetector.exe" 665160 Sep 27 2007 "C:\Program Files\Picasa2\cdautorun\PicasaRestore.exe" 591416 Sep 27 2007 "G:\C Drive Duplicate\Program Files\Picasa2\PicasaUpdate.exe" 366400 Dec 11 2006 "G:\C Drive Duplicate\Program Files\Picasa2\bak\PicasaMediaDetector.exe" 665160 Sep 27 2007 "G:\C Drive Duplicate\Program Files\Picasa2\cdautorun\PicasaRestore.exe" 98304 Sep 2 2005 "C:\Program Files\QuickTime\bak\qttask.exe" 98304 Sep 2 2005 "G:\C Drive Duplicate\Program Files\QuickTime\bak\qttask.exe" 212992 Sep 14 2002 "C:\WINDOWS\SMINST\bak\RECGUARD.EXE" 212992 Sep 14 2002 "G:\C Drive Duplicate\WINDOWS\SMINST\bak\RECGUARD.EXE" 199 Sep 16 2003 "C:\WINDOWS\system\hpsysdrv.DAT" 183 Nov 26 2007 "C:\WINDOWS\system\bak\hpsysdrv.DAT" 199 Sep 16 2003 "G:\C Drive Duplicate\WINDOWS\system\hpsysdrv.DAT" 183 Nov 26 2007 "G:\C Drive Duplicate\WINDOWS\system\bak\hpsysdrv.DAT" 52736 May 7 1998 "C:\WINDOWS\system\bak\hpsysdrv.exe" 52736 May 7 1998 "G:\C Drive Duplicate\WINDOWS\system\bak\hpsysdrv.exe" 114688 Mar 11 2003 "C:\WINDOWS\system32\bak\hkcmd.exe" 114688 Mar 11 2003 "C:\hp\drivers\video\865\hkcmd.exe" 114688 Mar 11 2003 "C:\WINDOWS\system32\ReinstallBackups\0002\DriverFiles\hkcmd.exe" 114688 Mar 11 2003 "G:\C Drive Duplicate\WINDOWS\system32\bak\hkcmd.exe" 114688 Mar 11 2003 "G:\C Drive Duplicate\hp\drivers\video\865\hkcmd.exe" 114688 Mar 11 2003 "G:\C Drive Duplicate\WINDOWS\system32\ReinstallBackups\0002\DriverFiles\hkcmd.exe" 81920 Jul 31 2002 "C:\hp\drivers\keyboard\PS2.EXE" 81920 Jul 31 2002 "C:\WINDOWS\system32\bak\ps2.exe" 81920 Jul 31 2002 "G:\C Drive Duplicate\hp\drivers\keyboard\PS2.EXE" 81920 Jul 31 2002 "G:\C Drive Duplicate\WINDOWS\system32\bak\ps2.exe" 52272 Nov 16 2007 "C:\Program Files\Google\googletoolbar1user.exe" 441088 Nov 17 2003 "C:\Program Files\America Online 5.0\download\GoogleToolbarInstaller.exe" 69632 May 24 2007 "C:\Program Files\Google\Google Earth\googleearth.exe" 126136 Nov 16 2007 "C:\Program Files\Google\Google Updater\GoogleUpdater.exe" 138680 Nov 16 2007 "C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe" 68856 Jul 12 2007 "C:\Program Files\Google\GoogleToolbarNotifier\bak\GoogleToolbarNotifier.exe" 126136 Nov 16 2007 "C:\Program Files\Google\Google Updater\2.2.969.23408\GoogleUpdaterRestartManager.exe" 26694 Jul 15 2007 "C:\Documents and Settings\Owner\Application Data\Microsoft\Installer\{407B9B5C-DAC5-4F44-A756-B57CAB4E6A8B}\googleearth.exe_407B9B5CDAC54F44A756B57CAB4E6A8B.exe" 52272 Nov 16 2007 "G:\C Drive Duplicate\Program Files\Google\googletoolbar1user.exe" 441088 Nov 17 2003 "G:\C Drive Duplicate\Program Files\America Online 5.0\download\GoogleToolbarInstaller.exe" 69632 May 24 2007 "G:\C Drive Duplicate\Program Files\Google\Google Earth\googleearth.exe" 126136 Nov 16 2007 "G:\C Drive Duplicate\Program Files\Google\Google Updater\GoogleUpdater.exe" 441088 Nov 17 2003 "G:\Old G Drive Restored Partial\May 19 Copy ofPavillion Drive C\America Online 5.0\download\GoogleToolbarInstaller.exe" 138680 Nov 16 2007 "G:\C Drive Duplicate\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe" 68856 Jul 12 2007 "G:\C Drive Duplicate\Program Files\Google\GoogleToolbarNotifier\bak\GoogleToolbarNotifier.exe" 126136 Nov 16 2007 "G:\C Drive Duplicate\Program Files\Google\Google Updater\2.2.969.23408\GoogleUpdaterRestartManager.exe" 441088 Nov 17 2003 "G:\Backup Set A - C and G-1\1 Pavilion Backup Combined\May 19 Copy ofPavillion Drive C\America Online 5.0\download\GoogleToolbarInstaller.exe" 3832231 Sep 28 2002 "G:\Old G Drive Restored Partial\May 19 Copy ofPavillion Drive C\My Documents\Daniel\2002 Season\Google News 092802.EXE" 3832231 Sep 28 2002 "G:\Backup Set A - C and G-1\1 Pavilion Backup Combined\May 19 Copy ofPavillion Drive C\My Documents\Daniel\2002 Season\Google News 092802.EXE" 26694 Jul 15 2007 "G:\C Drive Duplicate\Documents and Settings\Owner\Application Data\Microsoft\Installer\{407B9B5C-DAC5-4F44-A756-B57CAB4E6A8B}\googleearth.exe_407B9B5CDAC54F44A756B57CAB4E6A8B.exe" 882512 Nov 16 2007 "G:\C Drive Duplicate\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\OR5BEI7P\Google Updater[1].exe" 49152 Sep 13 2004 "C:\Program Files\HP\HP Software Update\bak\HPWuSchd2.exe" 49152 Sep 13 2004 "G:\C Drive Duplicate\Program Files\HP\HP Software Update\bak\HPWuSchd2.exe" 1187899 Apr 12 2005 "C:\Program Files\McAfee.com\Personal Firewall\bak\MpfTray.exe" 1187899 Apr 12 2005 "G:\C Drive Duplicate\Program Files\McAfee.com\Personal Firewall\bak\MpfTray.exe" 99480 Apr 5 2004 "C:\Program Files\Pure Networks\Port Magic\bak\PortAOL.exe" 99480 Apr 5 2004 "G:\C Drive Duplicate\Program Files\Pure Networks\Port Magic\bak\PortAOL.exe" 1003520 May 26 2006 "C:\Program Files\Real\RealOne Player\bak\realplay.exe" 1003520 May 26 2006 "G:\C Drive Duplicate\Program Files\Real\RealOne Player\bak\realplay.exe" 19456 Sep 4 2001 "G:\Old G Drive Restored Partial\May 19 Copy ofPavillion Drive C\Program Files\Real\RealPlayer\realplay.exe" 19456 Sep 4 2001 "G:\Backup Set A - C and G-1\1 Pavilion Backup Combined\May 19 Copy ofPavillion Drive C\Program Files\Real\RealPlayer\realplay.exe" 40960 Feb 27 2003 "C:\Program Files\ScanSoft\PaperPort\bak\IndexSearch.exe" 40960 Feb 27 2003 "G:\C Drive Duplicate\Program Files\ScanSoft\PaperPort\bak\IndexSearch.exe" 57393 Feb 27 2003 "C:\Program Files\ScanSoft\PaperPort\bak\pptd40nt.exe" 57393 Feb 27 2003 "G:\C Drive Duplicate\Program Files\ScanSoft\PaperPort\bak\pptd40nt.exe" 29184 Apr 13 1999 "G:\Old G Drive Restored Partial\May 19 Copy ofPavillion Drive C\Program Files\Visioneer\PaperPort\Pptd40nt.exe" 29184 Apr 13 1999 "G:\Backup Set A - C and G-1\1 Pavilion Backup Combined\May 19 Copy ofPavillion Drive C\Program Files\Visioneer\PaperPort\Pptd40nt.exe" 23120680 Aug 17 2007 "C:\Program Files\Skype\Phone\bak\Skype.exe" 23120680 Aug 17 2007 "G:\C Drive Duplicate\Program Files\Skype\Phone\bak\Skype.exe" 155648 Jun 18 2002 "C:\Program Files\VERITAS Software\Update Manager\bak\sgtray.exe" 155648 Jun 18 2002 "G:\C Drive Duplicate\Program Files\VERITAS Software\Update Manager\bak\sgtray.exe" 71216 Oct 23 2006 "C:\Program Files\Common Files\AOL\ACS\bak\AOLDial.exe" 71216 Oct 23 2006 "G:\C Drive Duplicate\Program Files\Common Files\AOL\ACS\bak\AOLDial.exe" 151597 Apr 26 2003 "C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe" 151597 Apr 26 2003 "G:\C Drive Duplicate\Program Files\Common Files\Real\Update_OB\bak\realsched.exe" 50736 Sep 25 2006 "C:\Program Files\Common Files\AOL\1125684819\EE\AOLSoftware.exe1189973455" 50736 Sep 25 2006 "C:\Program Files\Common Files\AOL\1125684819\EE\bak\AOLSoftware.exe" 50736 Sep 25 2006 "G:\C Drive Duplicate\Program Files\Common Files\AOL\1125684819\EE\AOLSoftware.exe1189973455" 50736 Sep 25 2006 "G:\C Drive Duplicate\Program Files\Common Files\AOL\1125684819\EE\bak\AOLSoftware.exe" 542231 Nov 14 2001 "G:\Backup Set A - C and G-1\HP Omnibook Files\Program Files\Support.com\backup\PH\phoneitl.bak\1779648_5abe1c3b1_" 542231 Nov 14 2001 "G:\Backup Set A - C and G-1\HP Omnibook Files\Program Files\Support.com\backup\PH\phoneitl.dms\1779648_5abe1c3b1_" 542231 Nov 14 2001 "H:\Restored Drive G partial\HP Omnibook Files\Program Files\Support.com\backup\PH\phoneitl.bak\1779648_5abe1c3b1_" 542231 Nov 14 2001 "H:\Restored Drive G partial\HP Omnibook Files\Program Files\Support.com\backup\PH\phoneitl.dms\1779648_5abe1c3b1_" 36864 Oct 25 2001 "C:\WINDOWS\system32\spool\drivers\w32x86\lexmarklexmark_x83d8e5\printray.exe" 36864 Oct 25 2001 "C:\WINDOWS\system32\spool\drivers\w32x86\3\bak\printray.exe" 36864 Oct 25 2001 "G:\C Drive Duplicate\WINDOWS\system32\spool\drivers\w32x86\lexmarklexmark_x83d8e5\printray.exe" 36864 Oct 25 2001 "G:\C Drive Duplicate\WINDOWS\system32\spool\drivers\w32x86\3\bak\printray.exe" 542231 Nov 14 2001 "G:\Backup Set A - C and G-1\HP Omnibook Files\Program Files\Support.com\backup\PH\phoneitl.bak\1779648_5abe1c3b1_" 542231 Nov 14 2001 "G:\Backup Set A - C and G-1\HP Omnibook Files\Program Files\Support.com\backup\PH\phoneitl.dms\1779648_5abe1c3b1_" 542231 Nov 14 2001 "H:\Restored Drive G partial\HP Omnibook Files\Program Files\Support.com\backup\PH\phoneitl.bak\1779648_5abe1c3b1_" 542231 Nov 14 2001 "H:\Restored Drive G partial\HP Omnibook Files\Program Files\Support.com\backup\PH\phoneitl.dms\1779648_5abe1c3b1_" end of report ————————————————————— Latest HiJackThis log: Find AWF report by noahdfear ©2006 Version 1.40 The current date is: Fri 12/21/2007 The current time is: 9:46:46.43 bak folders found ~~~~~~~~~~~ Directory of C:\HP\KBD\BAK 02/11/2003 11:02 PM 61,440 KBD.EXE 1 File(s) 61,440 bytes Directory of C:\PROGRA~1\AMERIC~1.0A\BAK 07/12/2005 01:17 AM 50,776 AOL.EXE 09/19/2007 09:27 PM 24 shellmon.ph 2 File(s) 50,800 bytes Directory of C:\PROGRA~1\AOL9~1.0B\BAK 04/18/2007 02:49 AM 50,736 AOL.EXE 11/19/2007 09:12 AM 24 shellmon.ph 2 File(s) 50,760 bytes Directory of C:\PROGRA~1\LEXMAR~1\BAK 06/14/2001 12:42 PM 53,248 AcBtnMgr_X83.exe 10/18/2001 10:25 AM 40,960 ACMonitor_X83.exe 2 File(s) 94,208 bytes Directory of C:\PROGRA~1\MESSEN~1\BAK 0 File(s) 0 bytes Directory of C:\PROGRA~1\PICASA2\BAK 12/11/2006 08:36 PM 366,400 PicasaMediaDetector.exe 1 File(s) 366,400 bytes Directory of C:\PROGRA~1\QUICKT~1\BAK 09/02/2005 02:16 PM 98,304 qttask.exe 1 File(s) 98,304 bytes Directory of C:\WINDOWS\SMINST\BAK 09/14/2002 12:42 AM 212,992 RECGUARD.EXE 1 File(s) 212,992 bytes Directory of C:\WINDOWS\SYSTEM\BAK 11/26/2007 08:47 AM 183 hpsysdrv.DAT 05/07/1998 07:04 PM 52,736 hpsysdrv.exe 2 File(s) 52,919 bytes Directory of C:\WINDOWS\SYSTEM32\BAK 03/11/2003 08:11 PM 114,688 hkcmd.exe 07/31/2002 11:28 PM 81,920 ps2.exe 2 File(s) 196,608 bytes Directory of C:\PROGRA~1\BROADJ~1\CLIENT~1\BAK 0 File(s) 0 bytes Directory of C:\PROGRA~1\GOOGLE\GOOGLE~2\BAK 07/12/2007 10:13 PM 68,856 GoogleToolbarNotifier.exe 1 File(s) 68,856 bytes Directory of C:\PROGRA~1\HP\HPSOFT~1\BAK 09/13/2004 04:49 PM 49,152 HPWuSchd2.exe 1 File(s) 49,152 bytes Directory of C:\PROGRA~1\MCAFEE.COM\PERSON~1\BAK 04/12/2005 04:44 PM 1,187,899 MpfTray.exe 1 File(s) 1,187,899 bytes Directory of C:\PROGRA~1\PURENE~1\PORTMA~1\BAK 04/05/2004 05:33 PM 99,480 PortAOL.exe 1 File(s) 99,480 bytes Directory of C:\PROGRA~1\REAL\REALON~1\BAK 05/26/2006 08:21 AM 1,003,520 realplay.exe 1 File(s) 1,003,520 bytes Directory of C:\PROGRA~1\SCANSOFT\PAPERP~1\BAK 02/27/2003 02:40 AM 40,960 IndexSearch.exe 02/27/2003 02:12 AM 57,393 pptd40nt.exe 2 File(s) 98,353 bytes Directory of C:\PROGRA~1\SKYPE\PHONE\BAK 08/17/2007 03:45 AM 23,120,680 Skype.exe 1 File(s) 23,120,680 bytes Directory of C:\PROGRA~1\VERITA~1\UPDATE~1\BAK 06/18/2002 01:01 AM 155,648 sgtray.exe 1 File(s) 155,648 bytes Directory of C:\PROGRA~1\COMMON~1\AOL\ACS\BAK 10/23/2006 08:50 AM 71,216 AOLDial.exe 1 File(s) 71,216 bytes Directory of C:\PROGRA~1\COMMON~1\REAL\UPDATE~1\BAK 04/26/2003 02:30 AM 151,597 realsched.exe 1 File(s) 151,597 bytes Directory of C:\PROGRA~1\COMMON~1\AOL\112568~1\EE\BAK 09/25/2006 08:52 PM 50,736 AOLSoftware.exe 1 File(s) 50,736 bytes Directory of C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\BAK 10/25/2001 02:20 PM 36,864 printray.exe 1 File(s) 36,864 bytes Directory of G:\CDRIVE~1\HP\KBD\BAK 02/11/2003 11:02 PM 61,440 KBD.EXE 1 File(s) 61,440 bytes Directory of G:\CDRIVE~1\PROGRA~1\AMERIC~1.0A\BAK 07/12/2005 01:17 AM 50,776 AOL.EXE 09/19/2007 09:27 PM 24 shellmon.ph 2 File(s) 50,800 bytes Directory of G:\CDRIVE~1\PROGRA~1\AOL9~1.0B\BAK 04/18/2007 02:49 AM 50,736 AOL.EXE 11/19/2007 09:12 AM 24 shellmon.ph 2 File(s) 50,760 bytes Directory of G:\CDRIVE~1\PROGRA~1\LEXMAR~1\BAK 06/14/2001 12:42 PM 53,248 AcBtnMgr_X83.exe 10/18/2001 10:25 AM 40,960 ACMonitor_X83.exe 2 File(s) 94,208 bytes Directory of G:\CDRIVE~1\PROGRA~1\MESSEN~1\BAK 0 File(s) 0 bytes Directory of G:\CDRIVE~1\PROGRA~1\PICASA2\BAK 12/11/2006 08:36 PM 366,400 PicasaMediaDetector.exe 1 File(s) 366,400 bytes Directory of G:\CDRIVE~1\PROGRA~1\QUICKT~1\BAK 09/02/2005 02:16 PM 98,304 qttask.exe 1 File(s) 98,304 bytes Directory of G:\CDRIVE~1\WINDOWS\SMINST\BAK 09/14/2002 12:42 AM 212,992 RECGUARD.EXE 1 File(s) 212,992 bytes Directory of G:\CDRIVE~1\WINDOWS\SYSTEM\BAK 11/26/2007 08:47 AM 183 hpsysdrv.DAT 05/07/1998 07:04 PM 52,736 hpsysdrv.exe 2 File(s) 52,919 bytes Directory of G:\CDRIVE~1\WINDOWS\SYSTEM32\BAK 03/11/2003 08:11 PM 114,688 hkcmd.exe 07/31/2002 11:28 PM 81,920 ps2.exe 2 File(s) 196,608 bytes Directory of G:\CDRIVE~1\PROGRA~1\BROADJ~1\CLIENT~1\BAK 0 File(s) 0 bytes Directory of G:\CDRIVE~1\PROGRA~1\GOOGLE\GOOGLE~2\BAK 07/12/2007 10:13 PM 68,856 GoogleToolbarNotifier.exe 1 File(s) 68,856 bytes Directory of G:\CDRIVE~1\PROGRA~1\HP\HPSOFT~1\BAK 09/13/2004 04:49 PM 49,152 HPWuSchd2.exe 1 File(s) 49,152 bytes Directory of G:\CDRIVE~1\PROGRA~1\MCAFEE.COM\PERSON~1\BAK 04/12/2005 04:44 PM 1,187,899 MpfTray.exe 1 File(s) 1,187,899 bytes Directory of G:\CDRIVE~1\PROGRA~1\PURENE~1\PORTMA~1\BAK 04/05/2004 05:33 PM 99,480 PortAOL.exe 1 File(s) 99,480 bytes Directory of G:\CDRIVE~1\PROGRA~1\REAL\REALON~1\BAK 05/26/2006 08:21 AM 1,003,520 realplay.exe 1 File(s) 1,003,520 bytes Directory of G:\CDRIVE~1\PROGRA~1\SCANSOFT\PAPERP~1\BAK 02/27/2003 02:40 AM 40,960 IndexSearch.exe 02/27/2003 02:12 AM 57,393 pptd40nt.exe 2 File(s) 98,353 bytes Directory of G:\CDRIVE~1\PROGRA~1\SKYPE\PHONE\BAK 08/17/2007 03:45 AM 23,120,680 Skype.exe 1 File(s) 23,120,680 bytes Directory of G:\CDRIVE~1\PROGRA~1\VERITA~1\UPDATE~1\BAK 06/18/2002 01:01 AM 155,648 sgtray.exe 1 File(s) 155,648 bytes Directory of G:\CDRIVE~1\PROGRA~1\COMMON~1\AOL\ACS\BAK 10/23/2006 08:50 AM 71,216 AOLDial.exe 1 File(s) 71,216 bytes Directory of G:\CDRIVE~1\PROGRA~1\COMMON~1\REAL\UPDATE~1\BAK 04/26/2003 02:30 AM 151,597 realsched.exe 1 File(s) 151,597 bytes Directory of G:\CDRIVE~1\PROGRA~1\COMMON~1\AOL\112568~1\EE\BAK 09/25/2006 08:52 PM 50,736 AOLSoftware.exe 1 File(s) 50,736 bytes Directory of G:\FHCOBB~1.JPG\HPOMNI~1\PROGRA~1\SUPPORT.COM\BACKUP\PH\PHONEITL.BAK 11/14/2001 01:10 PM 542,231 1779648_5abe1c3b1_ 1 File(s) 542,231 bytes Directory of G:\CDRIVE~1\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\BAK 10/25/2001 02:20 PM 36,864 printray.exe 1 File(s) 36,864 bytes Directory of H:\RESTOR~1\HPOMNI~1\PROGRA~1\SUPPORT.COM\BACKUP\PH\PHONEITL.BAK 11/14/2001 12:10 PM 542,231 1779648_5abe1c3b1_ 1 File(s) 542,231 bytes Duplicate files of bak directory contents ~~~~~~~~~~~~~~~~~~~~~~~ 61440 Feb 11 2003 "C:\hp\KBD\bak\KBD.EXE" 61440 Feb 11 2003 "G:\C Drive Duplicate\hp\KBD\bak\KBD.EXE" 45125 Dec 18 2002 "C:\Program Files\America Online 8.0\aol.exe" 45140 Sep 24 2003 "C:\Program Files\America Online 9.0\aol.exe" 24576 Aug 27 1999 "C:\Program Files\America Online 5.0\aol.exe" 50736 Apr 18 2007 "C:\Program Files\AOL 9.0a\aol.exe" 50776 Jul 12 2005 "C:\Program Files\America Online 9.0a\bak\AOL.EXE" 50736 Apr 18 2007 "C:\Program Files\AOL 9.0b\bak\AOL.EXE" 45125 Dec 18 2002 "G:\C Drive Duplicate\Program Files\America Online 8.0\aol.exe" 45140 Sep 24 2003 "G:\C Drive Duplicate\Program Files\America Online 9.0\aol.exe" 24576 Aug 27 1999 "G:\C Drive Duplicate\Program Files\America Online 5.0\aol.exe" 50736 Apr 18 2007 "G:\C Drive Duplicate\Program Files\AOL 9.0a\aol.exe" 24576 Aug 27 1999 "G:\Old G Drive Restored Partial\May 19 Copy ofPavillion Drive C\America Online 5.0\aol.exe" 50776 Jul 12 2005 "G:\C Drive Duplicate\Program Files\America Online 9.0a\bak\AOL.EXE" 50736 Apr 18 2007 "G:\C Drive Duplicate\Program Files\AOL 9.0b\bak\AOL.EXE" 24576 Aug 27 1999 "G:\Backup Set A - C and G-1\1 Pavilion Backup Combined\May 19 Copy ofPavillion Drive C\America Online 5.0\aol.exe" 74 Sep 16 2007 "C:\Program Files\America Online 8.0\shellmon.ph" 24 Sep 11 2007 "C:\Program Files\America Online 9.0a\shellmon.ph" 24 Sep 19 2007 "C:\Program Files\America Online 9.0\shellmon.ph" 24 Sep 16 2007 "C:\Program Files\AOL 9.0a\shellmon.ph" 24 Sep 16 2007 "C:\Program Files\AOL 9.0b\shellmon.ph" 24 Sep 19 2007 "C:\Program Files\America Online 9.0a\bak\shellmon.ph" 24 Nov 19 2007 "C:\Program Files\AOL 9.0b\bak\shellmon.ph" 1693 Oct 21 2007 "C:\Documents and Settings\All Users\Application Data\AOL\C_America Online 9.0\shellmon.ph" 1646 Sep 26 2007 "C:\Documents and Settings\All Users\Application Data\AOL\C_America Online 9.0a\shellmon.ph" 1634 Sep 24 2007 "C:\Documents and Settings\All Users\Application Data\AOL\C_AOL 9.0a\shellmon.ph" 2402 Dec 14 2007 "C:\Documents and Settings\All Users\Application Data\AOL\C_AOL 9.0b\shellmon.ph" 74 Sep 16 2007 "G:\C Drive Duplicate\Program Files\America Online 8.0\shellmon.ph" 24 Sep 11 2007 "G:\C Drive Duplicate\Program Files\America Online 9.0a\shellmon.ph" 24 Sep 19 2007 "G:\C Drive Duplicate\Program Files\America Online 9.0\shellmon.ph" 24 Sep 16 2007 "G:\C Drive Duplicate\Program Files\AOL 9.0a\shellmon.ph" 24 Sep 16 2007 "G:\C Drive Duplicate\Program Files\AOL 9.0b\shellmon.ph" 24 Sep 19 2007 "G:\C Drive Duplicate\Program Files\America Online 9.0a\bak\shellmon.ph" 24 Nov 19 2007 "G:\C Drive Duplicate\Program Files\AOL 9.0b\bak\shellmon.ph" 1693 Oct 21 2007 "G:\C Drive Duplicate\Documents and Settings\All Users\Application Data\AOL\C_America Online 9.0\shellmon.ph" 1646 Sep 26 2007 "G:\C Drive Duplicate\Documents and Settings\All Users\Application Data\AOL\C_America Online 9.0a\shellmon.ph" 1634 Sep 24 2007 "G:\C Drive Duplicate\Documents and Settings\All Users\Application Data\AOL\C_AOL 9.0a\shellmon.ph" 4800 Dec 6 2007 "G:\C Drive Duplicate\Documents and Settings\All Users\Application Data\AOL\C_AOL 9.0b\shellmon.ph" 45125 Dec 18 2002 "C:\Program Files\America Online 8.0\aol.exe" 45140 Sep 24 2003 "C:\Program Files\America Online 9.0\aol.exe" 24576 Aug 27 1999 "C:\Program Files\America Online 5.0\aol.exe" 50736 Apr 18 2007 "C:\Program Files\AOL 9.0a\aol.exe" 50776 Jul 12 2005 "C:\Program Files\America Online 9.0a\bak\AOL.EXE" 50736 Apr 18 2007 "C:\Program Files\AOL 9.0b\bak\AOL.EXE" 45125 Dec 18 2002 "G:\C Drive Duplicate\Program Files\America Online 8.0\aol.exe" 45140 Sep 24 2003 "G:\C Drive Duplicate\Program Files\America Online 9.0\aol.exe" 24576 Aug 27 1999 "G:\C Drive Duplicate\Program Files\America Online 5.0\aol.exe" 50736 Apr 18 2007 "G:\C Drive Duplicate\Program Files\AOL 9.0a\aol.exe" 24576 Aug 27 1999 "G:\Old G Drive Restored Partial\May 19 Copy ofPavillion Drive C\America Online 5.0\aol.exe" 50776 Jul 12 2005 "G:\C Drive Duplicate\Program Files\America Online 9.0a\bak\AOL.EXE" 50736 Apr 18 2007 "G:\C Drive Duplicate\Program Files\AOL 9.0b\bak\AOL.EXE" 24576 Aug 27 1999 "G:\Backup Set A - C and G-1\1 Pavilion Backup Combined\May 19 Copy ofPavillion Drive C\America Online 5.0\aol.exe" 74 Sep 16 2007 "C:\Program Files\America Online 8.0\shellmon.ph" 24 Sep 11 2007 "C:\Program Files\America Online 9.0a\shellmon.ph" 24 Sep 19 2007 "C:\Program Files\America Online 9.0\shellmon.ph" 24 Sep 16 2007 "C:\Program Files\AOL 9.0a\shellmon.ph" 24 Sep 16 2007 "C:\Program Files\AOL 9.0b\shellmon.ph" 24 Sep 19 2007 "C:\Program Files\America Online 9.0a\bak\shellmon.ph" 24 Nov 19 2007 "C:\Program Files\AOL 9.0b\bak\shellmon.ph" 1693 Oct 21 2007 "C:\Documents and Settings\All Users\Application Data\AOL\C_America Online 9.0\shellmon.ph" 1646 Sep 26 2007 "C:\Documents and Settings\All Users\Application Data\AOL\C_America Online 9.0a\shellmon.ph" 1634 Sep 24 2007 "C:\Documents and Settings\All Users\Application Data\AOL\C_AOL 9.0a\shellmon.ph" 2402 Dec 14 2007 "C:\Documents and Settings\All Users\Application Data\AOL\C_AOL 9.0b\shellmon.ph" 74 Sep 16 2007 "G:\C Drive Duplicate\Program Files\America Online 8.0\shellmon.ph" 24 Sep 11 2007 "G:\C Drive Duplicate\Program Files\America Online 9.0a\shellmon.ph" 24 Sep 19 2007 "G:\C Drive Duplicate\Program Files\America Online 9.0\shellmon.ph" 24 Sep 16 2007 "G:\C Drive Duplicate\Program Files\AOL 9.0a\shellmon.ph" 24 Sep 16 2007 "G:\C Drive Duplicate\Program Files\AOL 9.0b\shellmon.ph" 24 Sep 19 2007 "G:\C Drive Duplicate\Program Files\America Online 9.0a\bak\shellmon.ph" 24 Nov 19 2007 "G:\C Drive Duplicate\Program Files\AOL 9.0b\bak\shellmon.ph" 1693 Oct 21 2007 "G:\C Drive Duplicate\Documents and Settings\All Users\Application Data\AOL\C_America Online 9.0\shellmon.ph" 1646 Sep 26 2007 "G:\C Drive Duplicate\Documents and Settings\All Users\Application Data\AOL\C_America Online 9.0a\shellmon.ph" 1634 Sep 24 2007 "G:\C Drive Duplicate\Documents and Settings\All Users\Application Data\AOL\C_AOL 9.0a\shellmon.ph" 4800 Dec 6 2007 "G:\C Drive Duplicate\Documents and Settings\All Users\Application Data\AOL\C_AOL 9.0b\shellmon.ph" 53248 Jun 14 2001 "C:\Program Files\LexmarkX83\bak\AcBtnMgr_X83.exe" 53248 Jun 14 2001 "G:\C Drive Duplicate\Program Files\LexmarkX83\bak\AcBtnMgr_X83.exe" 40960 Oct 18 2001 "C:\Program Files\LexmarkX83\bak\ACMonitor_X83.exe" 40960 Oct 18 2001 "G:\C Drive Duplicate\Program Files\LexmarkX83\bak\ACMonitor_X83.exe" 591416 Sep 27 2007 "C:\Program Files\Picasa2\PicasaUpdate.exe" 366400 Dec 11 2006 "C:\Program Files\Picasa2\bak\PicasaMediaDetector.exe" 665160 Sep 27 2007 "C:\Program Files\Picasa2\cdautorun\PicasaRestore.exe" 591416 Sep 27 2007 "G:\C Drive Duplicate\Program Files\Picasa2\PicasaUpdate.exe" 366400 Dec 11 2006 "G:\C Drive Duplicate\Program Files\Picasa2\bak\PicasaMediaDetector.exe" 665160 Sep 27 2007 "G:\C Drive Duplicate\Program Files\Picasa2\cdautorun\PicasaRestore.exe" 98304 Sep 2 2005 "C:\Program Files\QuickTime\bak\qttask.exe" 98304 Sep 2 2005 "G:\C Drive Duplicate\Program Files\QuickTime\bak\qttask.exe" 212992 Sep 14 2002 "C:\WINDOWS\SMINST\bak\RECGUARD.EXE" 212992 Sep 14 2002 "G:\C Drive Duplicate\WINDOWS\SMINST\bak\RECGUARD.EXE" 199 Sep 16 2003 "C:\WINDOWS\system\hpsysdrv.DAT" 183 Nov 26 2007 "C:\WINDOWS\system\bak\hpsysdrv.DAT" 199 Sep 16 2003 "G:\C Drive Duplicate\WINDOWS\system\hpsysdrv.DAT" 183 Nov 26 2007 "G:\C Drive Duplicate\WINDOWS\system\bak\hpsysdrv.DAT" 52736 May 7 1998 "C:\WINDOWS\system\bak\hpsysdrv.exe" 52736 May 7 1998 "G:\C Drive Duplicate\WINDOWS\system\bak\hpsysdrv.exe" 114688 Mar 11 2003 "C:\WINDOWS\system32\bak\hkcmd.exe" 114688 Mar 11 2003 "C:\hp\drivers\video\865\hkcmd.exe" 114688 Mar 11 2003 "C:\WINDOWS\system32\ReinstallBackups\0002\DriverFiles\hkcmd.exe" 114688 Mar 11 2003 "G:\C Drive Duplicate\WINDOWS\system32\bak\hkcmd.exe" 114688 Mar 11 2003 "G:\C Drive Duplicate\hp\drivers\video\865\hkcmd.exe" 114688 Mar 11 2003 "G:\C Drive Duplicate\WINDOWS\system32\ReinstallBackups\0002\DriverFiles\hkcmd.exe" 81920 Jul 31 2002 "C:\hp\drivers\keyboard\PS2.EXE" 81920 Jul 31 2002 "C:\WINDOWS\system32\bak\ps2.exe" 81920 Jul 31 2002 "G:\C Drive Duplicate\hp\drivers\keyboard\PS2.EXE" 81920 Jul 31 2002 "G:\C Drive Duplicate\WINDOWS\system32\bak\ps2.exe" 52272 Nov 16 2007 "C:\Program Files\Google\googletoolbar1user.exe" 441088 Nov 17 2003 "C:\Program Files\America Online 5.0\download\GoogleToolbarInstaller.exe" 69632 May 24 2007 "C:\Program Files\Google\Google Earth\googleearth.exe" 126136 Nov 16 2007 "C:\Program Files\Google\Google Updater\GoogleUpdater.exe" 138680 Nov 16 2007 "C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe" 68856 Jul 12 2007 "C:\Program Files\Google\GoogleToolbarNotifier\bak\GoogleToolbarNotifier.exe" 126136 Nov 16 2007 "C:\Program Files\Google\Google Updater\2.2.969.23408\GoogleUpdaterRestartManager.exe" 26694 Jul 15 2007 "C:\Documents and Settings\Owner\Application Data\Microsoft\Installer\{407B9B5C-DAC5-4F44-A756-B57CAB4E6A8B}\googleearth.exe_407B9B5CDAC54F44A756B57CAB4E6A8B.exe" 52272 Nov 16 2007 "G:\C Drive Duplicate\Program Files\Google\googletoolbar1user.exe" 441088 Nov 17 2003 "G:\C Drive Duplicate\Program Files\America Online 5.0\download\GoogleToolbarInstaller.exe" 69632 May 24 2007 "G:\C Drive Duplicate\Program Files\Google\Google Earth\googleearth.exe" 126136 Nov 16 2007 "G:\C Drive Duplicate\Program Files\Google\Google Updater\GoogleUpdater.exe" 441088 Nov 17 2003 "G:\Old G Drive Restored Partial\May 19 Copy ofPavillion Drive C\America Online 5.0\download\GoogleToolbarInstaller.exe" 138680 Nov 16 2007 "G:\C Drive Duplicate\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe" 68856 Jul 12 2007 "G:\C Drive Duplicate\Program Files\Google\GoogleToolbarNotifier\bak\GoogleToolbarNotifier.exe" 126136 Nov 16 2007 "G:\C Drive Duplicate\Program Files\Google\Google Updater\2.2.969.23408\GoogleUpdaterRestartManager.exe" 441088 Nov 17 2003 "G:\Backup Set A - C and G-1\1 Pavilion Backup Combined\May 19 Copy ofPavillion Drive C\America Online 5.0\download\GoogleToolbarInstaller.exe" 3832231 Sep 28 2002 "G:\Old G Drive Restored Partial\May 19 Copy ofPavillion Drive C\My Documents\Daniel\2002 Season\Google News 092802.EXE" 3832231 Sep 28 2002 "G:\Backup Set A - C and G-1\1 Pavilion Backup Combined\May 19 Copy ofPavillion Drive C\My Documents\Daniel\2002 Season\Google News 092802.EXE" 26694 Jul 15 2007 "G:\C Drive Duplicate\Documents and Settings\Owner\Application Data\Microsoft\Installer\{407B9B5C-DAC5-4F44-A756-B57CAB4E6A8B}\googleearth.exe_407B9B5CDAC54F44A756B57CAB4E6A8B.exe" 882512 Nov 16 2007 "G:\C Drive Duplicate\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\OR5BEI7P\Google Updater[1].exe" 49152 Sep 13 2004 "C:\Program Files\HP\HP Software Update\bak\HPWuSchd2.exe" 49152 Sep 13 2004 "G:\C Drive Duplicate\Program Files\HP\HP Software Update\bak\HPWuSchd2.exe" 1187899 Apr 12 2005 "C:\Program Files\McAfee.com\Personal Firewall\bak\MpfTray.exe" 1187899 Apr 12 2005 "G:\C Drive Duplicate\Program Files\McAfee.com\Personal Firewall\bak\MpfTray.exe" 99480 Apr 5 2004 "C:\Program Files\Pure Networks\Port Magic\bak\PortAOL.exe" 99480 Apr 5 2004 "G:\C Drive Duplicate\Program Files\Pure Networks\Port Magic\bak\PortAOL.exe" 1003520 May 26 2006 "C:\Program Files\Real\RealOne Player\bak\realplay.exe" 1003520 May 26 2006 "G:\C Drive Duplicate\Program Files\Real\RealOne Player\bak\realplay.exe" 19456 Sep 4 2001 "G:\Old G Drive Restored Partial\May 19 Copy ofPavillion Drive C\Program Files\Real\RealPlayer\realplay.exe" 19456 Sep 4 2001 "G:\Backup Set A - C and G-1\1 Pavilion Backup Combined\May 19 Copy ofPavillion Drive C\Program Files\Real\RealPlayer\realplay.exe" 40960 Feb 27 2003 "C:\Program Files\ScanSoft\PaperPort\bak\IndexSearch.exe" 40960 Feb 27 2003 "G:\C Drive Duplicate\Program Files\ScanSoft\PaperPort\bak\IndexSearch.exe" 57393 Feb 27 2003 "C:\Program Files\ScanSoft\PaperPort\bak\pptd40nt.exe" 57393 Feb 27 2003 "G:\C Drive Duplicate\Program Files\ScanSoft\PaperPort\bak\pptd40nt.exe" 29184 Apr 13 1999 "G:\Old G Drive Restored Partial\May 19 Copy ofPavillion Drive C\Program Files\Visioneer\PaperPort\Pptd40nt.exe" 29184 Apr 13 1999 "G:\Backup Set A - C and G-1\1 Pavilion Backup Combined\May 19 Copy ofPavillion Drive C\Program Files\Visioneer\PaperPort\Pptd40nt.exe" 23120680 Aug 17 2007 "C:\Program Files\Skype\Phone\bak\Skype.exe" 23120680 Aug 17 2007 "G:\C Drive Duplicate\Program Files\Skype\Phone\bak\Skype.exe" 155648 Jun 18 2002 "C:\Program Files\VERITAS Software\Update Manager\bak\sgtray.exe" 155648 Jun 18 2002 "G:\C Drive Duplicate\Program Files\VERITAS Software\Update Manager\bak\sgtray.exe" 71216 Oct 23 2006 "C:\Program Files\Common Files\AOL\ACS\bak\AOLDial.exe" 71216 Oct 23 2006 "G:\C Drive Duplicate\Program Files\Common Files\AOL\ACS\bak\AOLDial.exe" 151597 Apr 26 2003 "C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe" 151597 Apr 26 2003 "G:\C Drive Duplicate\Program Files\Common Files\Real\Update_OB\bak\realsched.exe" 50736 Sep 25 2006 "C:\Program Files\Common Files\AOL\1125684819\EE\AOLSoftware.exe1189973455" 50736 Sep 25 2006 "C:\Program Files\Common Files\AOL\1125684819\EE\bak\AOLSoftware.exe" 50736 Sep 25 2006 "G:\C Drive Duplicate\Program Files\Common Files\AOL\1125684819\EE\AOLSoftware.exe1189973455" 50736 Sep 25 2006 "G:\C Drive Duplicate\Program Files\Common Files\AOL\1125684819\EE\bak\AOLSoftware.exe" 36864 Oct 25 2001 "C:\WINDOWS\system32\spool\drivers\w32x86\lexmarklexmark_x83d8e5\printray.exe" 36864 Oct 25 2001 "C:\WINDOWS\system32\spool\drivers\w32x86\3\bak\printray.exe" 36864 Oct 25 2001 "G:\C Drive Duplicate\WINDOWS\system32\spool\drivers\w32x86\lexmarklexmark_x83d8e5\printray.exe" 36864 Oct 25 2001 "G:\C Drive Duplicate\WINDOWS\system32\spool\drivers\w32x86\3\bak\printray.exe" 61440 Feb 11 2003 "C:\hp\KBD\bak\KBD.EXE" 61440 Feb 11 2003 "G:\C Drive Duplicate\hp\KBD\bak\KBD.EXE" 45125 Dec 18 2002 "C:\Program Files\America Online 8.0\aol.exe" 45140 Sep 24 2003 "C:\Program Files\America Online 9.0\aol.exe" 24576 Aug 27 1999 "C:\Program Files\America Online 5.0\aol.exe" 50736 Apr 18 2007 "C:\Program Files\AOL 9.0a\aol.exe" 50776 Jul 12 2005 "C:\Program Files\America Online 9.0a\bak\AOL.EXE" 50736 Apr 18 2007 "C:\Program Files\AOL 9.0b\bak\AOL.EXE" 45125 Dec 18 2002 "G:\C Drive Duplicate\Program Files\America Online 8.0\aol.exe" 45140 Sep 24 2003 "G:\C Drive Duplicate\Program Files\America Online 9.0\aol.exe" 24576 Aug 27 1999 "G:\C Drive Duplicate\Program Files\America Online 5.0\aol.exe" 50736 Apr 18 2007 "G:\C Drive Duplicate\Program Files\AOL 9.0a\aol.exe" 24576 Aug 27 1999 "G:\Old G Drive Restored Partial\May 19 Copy ofPavillion Drive C\America Online 5.0\aol.exe" 50776 Jul 12 2005 "G:\C Drive Duplicate\Program Files\America Online 9.0a\bak\AOL.EXE" 50736 Apr 18 2007 "G:\C Drive Duplicate\Program Files\AOL 9.0b\bak\AOL.EXE" 24576 Aug 27 1999 "G:\Backup Set A - C and G-1\1 Pavilion Backup Combined\May 19 Copy ofPavillion Drive C\America Online 5.0\aol.exe" 74 Sep 16 2007 "C:\Program Files\America Online 8.0\shellmon.ph" 24 Sep 11 2007 "C:\Program Files\America Online 9.0a\shellmon.ph" 24 Sep 19 2007 "C:\Program Files\America Online 9.0\shellmon.ph" 24 Sep 16 2007 "C:\Program Files\AOL 9.0a\shellmon.ph" 24 Sep 16 2007 "C:\Program Files\AOL 9.0b\shellmon.ph" 24 Sep 19 2007 "C:\Program Files\America Online 9.0a\bak\shellmon.ph" 24 Nov 19 2007 "C:\Program Files\AOL 9.0b\bak\shellmon.ph" 1693 Oct 21 2007 "C:\Documents and Settings\All Users\Application Data\AOL\C_America Online 9.0\shellmon.ph" 1646 Sep 26 2007 "C:\Documents and Settings\All Users\Application Data\AOL\C_America Online 9.0a\shellmon.ph" 1634 Sep 24 2007 "C:\Documents and Settings\All Users\Application Data\AOL\C_AOL 9.0a\shellmon.ph" 2402 Dec 14 2007 "C:\Documents and Settings\All Users\Application Data\AOL\C_AOL 9.0b\shellmon.ph" 74 Sep 16 2007 "G:\C Drive Duplicate\Program Files\America Online 8.0\shellmon.ph" 24 Sep 11 2007 "G:\C Drive Duplicate\Program Files\America Online 9.0a\shellmon.ph" 24 Sep 19 2007 "G:\C Drive Duplicate\Program Files\America Online 9.0\shellmon.ph" 24 Sep 16 2007 "G:\C Drive Duplicate\Program Files\AOL 9.0a\shellmon.ph" 24 Sep 16 2007 "G:\C Drive Duplicate\Program Files\AOL 9.0b\shellmon.ph" 24 Sep 19 2007 "G:\C Drive Duplicate\Program Files\America Online 9.0a\bak\shellmon.ph" 24 Nov 19 2007 "G:\C Drive Duplicate\Program Files\AOL 9.0b\bak\shellmon.ph" 1693 Oct 21 2007 "G:\C Drive Duplicate\Documents and Settings\All Users\Application Data\AOL\C_America Online 9.0\shellmon.ph" 1646 Sep 26 2007 "G:\C Drive Duplicate\Documents and Settings\All Users\Application Data\AOL\C_America Online 9.0a\shellmon.ph" 1634 Sep 24 2007 "G:\C Drive Duplicate\Documents and Settings\All Users\Application Data\AOL\C_AOL 9.0a\shellmon.ph" 4800 Dec 6 2007 "G:\C Drive Duplicate\Documents and Settings\All Users\Application Data\AOL\C_AOL 9.0b\shellmon.ph" 45125 Dec 18 2002 "C:\Program Files\America Online 8.0\aol.exe" 45140 Sep 24 2003 "C:\Program Files\America Online 9.0\aol.exe" 24576 Aug 27 1999 "C:\Program Files\America Online 5.0\aol.exe" 50736 Apr 18 2007 "C:\Program Files\AOL 9.0a\aol.exe" 50776 Jul 12 2005 "C:\Program Files\America Online 9.0a\bak\AOL.EXE" 50736 Apr 18 2007 "C:\Program Files\AOL 9.0b\bak\AOL.EXE" 45125 Dec 18 2002 "G:\C Drive Duplicate\Program Files\America Online 8.0\aol.exe" 45140 Sep 24 2003 "G:\C Drive Duplicate\Program Files\America Online 9.0\aol.exe" 24576 Aug 27 1999 "G:\C Drive Duplicate\Program Files\America Online 5.0\aol.exe" 50736 Apr 18 2007 "G:\C Drive Duplicate\Program Files\AOL 9.0a\aol.exe" 24576 Aug 27 1999 "G:\Old G Drive Restored Partial\May 19 Copy ofPavillion Drive C\America Online 5.0\aol.exe" 50776 Jul 12 2005 "G:\C Drive Duplicate\Program Files\America Online 9.0a\bak\AOL.EXE" 50736 Apr 18 2007 "G:\C Drive Duplicate\Program Files\AOL 9.0b\bak\AOL.EXE" 24576 Aug 27 1999 "G:\Backup Set A - C and G-1\1 Pavilion Backup Combined\May 19 Copy ofPavillion Drive C\America Online 5.0\aol.exe" 74 Sep 16 2007 "C:\Program Files\America Online 8.0\shellmon.ph" 24 Sep 11 2007 "C:\Program Files\America Online 9.0a\shellmon.ph" 24 Sep 19 2007 "C:\Program Files\America Online 9.0\shellmon.ph" 24 Sep 16 2007 "C:\Program Files\AOL 9.0a\shellmon.ph" 24 Sep 16 2007 "C:\Program Files\AOL 9.0b\shellmon.ph" 24 Sep 19 2007 "C:\Program Files\America Online 9.0a\bak\shellmon.ph" 24 Nov 19 2007 "C:\Program Files\AOL 9.0b\bak\shellmon.ph" 1693 Oct 21 2007 "C:\Documents and Settings\All Users\Application Data\AOL\C_America Online 9.0\shellmon.ph" 1646 Sep 26 2007 "C:\Documents and Settings\All Users\Application Data\AOL\C_America Online 9.0a\shellmon.ph" 1634 Sep 24 2007 "C:\Documents and Settings\All Users\Application Data\AOL\C_AOL 9.0a\shellmon.ph" 2402 Dec 14 2007 "C:\Documents and Settings\All Users\Application Data\AOL\C_AOL 9.0b\shellmon.ph" 74 Sep 16 2007 "G:\C Drive Duplicate\Program Files\America Online 8.0\shellmon.ph" 24 Sep 11 2007 "G:\C Drive Duplicate\Program Files\America Online 9.0a\shellmon.ph" 24 Sep 19 2007 "G:\C Drive Duplicate\Program Files\America Online 9.0\shellmon.ph" 24 Sep 16 2007 "G:\C Drive Duplicate\Program Files\AOL 9.0a\shellmon.ph" 24 Sep 16 2007 "G:\C Drive Duplicate\Program Files\AOL 9.0b\shellmon.ph" 24 Sep 19 2007 "G:\C Drive Duplicate\Program Files\America Online 9.0a\bak\shellmon.ph" 24 Nov 19 2007 "G:\C Drive Duplicate\Program Files\AOL 9.0b\bak\shellmon.ph" 1693 Oct 21 2007 "G:\C Drive Duplicate\Documents and Settings\All Users\Application Data\AOL\C_America Online 9.0\shellmon.ph" 1646 Sep 26 2007 "G:\C Drive Duplicate\Documents and Settings\All Users\Application Data\AOL\C_America Online 9.0a\shellmon.ph" 1634 Sep 24 2007 "G:\C Drive Duplicate\Documents and Settings\All Users\Application Data\AOL\C_AOL 9.0a\shellmon.ph" 4800 Dec 6 2007 "G:\C Drive Duplicate\Documents and Settings\All Users\Application Data\AOL\C_AOL 9.0b\shellmon.ph" 53248 Jun 14 2001 "C:\Program Files\LexmarkX83\bak\AcBtnMgr_X83.exe" 53248 Jun 14 2001 "G:\C Drive Duplicate\Program Files\LexmarkX83\bak\AcBtnMgr_X83.exe" 40960 Oct 18 2001 "C:\Program Files\LexmarkX83\bak\ACMonitor_X83.exe" 40960 Oct 18 2001 "G:\C Drive Duplicate\Program Files\LexmarkX83\bak\ACMonitor_X83.exe" 591416 Sep 27 2007 "C:\Program Files\Picasa2\PicasaUpdate.exe" 366400 Dec 11 2006 "C:\Program Files\Picasa2\bak\PicasaMediaDetector.exe" 665160 Sep 27 2007 "C:\Program Files\Picasa2\cdautorun\PicasaRestore.exe" 591416 Sep 27 2007 "G:\C Drive Duplicate\Program Files\Picasa2\PicasaUpdate.exe" 366400 Dec 11 2006 "G:\C Drive Duplicate\Program Files\Picasa2\bak\PicasaMediaDetector.exe" 665160 Sep 27 2007 "G:\C Drive Duplicate\Program Files\Picasa2\cdautorun\PicasaRestore.exe" 98304 Sep 2 2005 "C:\Program Files\QuickTime\bak\qttask.exe" 98304 Sep 2 2005 "G:\C Drive Duplicate\Program Files\QuickTime\bak\qttask.exe" 212992 Sep 14 2002 "C:\WINDOWS\SMINST\bak\RECGUARD.EXE" 212992 Sep 14 2002 "G:\C Drive Duplicate\WINDOWS\SMINST\bak\RECGUARD.EXE" 199 Sep 16 2003 "C:\WINDOWS\system\hpsysdrv.DAT" 183 Nov 26 2007 "C:\WINDOWS\system\bak\hpsysdrv.DAT" 199 Sep 16 2003 "G:\C Drive Duplicate\WINDOWS\system\hpsysdrv.DAT" 183 Nov 26 2007 "G:\C Drive Duplicate\WINDOWS\system\bak\hpsysdrv.DAT" 52736 May 7 1998 "C:\WINDOWS\system\bak\hpsysdrv.exe" 52736 May 7 1998 "G:\C Drive Duplicate\WINDOWS\system\bak\hpsysdrv.exe" 114688 Mar 11 2003 "C:\WINDOWS\system32\bak\hkcmd.exe" 114688 Mar 11 2003 "C:\hp\drivers\video\865\hkcmd.exe" 114688 Mar 11 2003 "C:\WINDOWS\system32\ReinstallBackups\0002\DriverFiles\hkcmd.exe" 114688 Mar 11 2003 "G:\C Drive Duplicate\WINDOWS\system32\bak\hkcmd.exe" 114688 Mar 11 2003 "G:\C Drive Duplicate\hp\drivers\video\865\hkcmd.exe" 114688 Mar 11 2003 "G:\C Drive Duplicate\WINDOWS\system32\ReinstallBackups\0002\DriverFiles\hkcmd.exe" 81920 Jul 31 2002 "C:\hp\drivers\keyboard\PS2.EXE" 81920 Jul 31 2002 "C:\WINDOWS\system32\bak\ps2.exe" 81920 Jul 31 2002 "G:\C Drive Duplicate\hp\drivers\keyboard\PS2.EXE" 81920 Jul 31 2002 "G:\C Drive Duplicate\WINDOWS\system32\bak\ps2.exe" 52272 Nov 16 2007 "C:\Program Files\Google\googletoolbar1user.exe" 441088 Nov 17 2003 "C:\Program Files\America Online 5.0\download\GoogleToolbarInstaller.exe" 69632 May 24 2007 "C:\Program Files\Google\Google Earth\googleearth.exe" 126136 Nov 16 2007 "C:\Program Files\Google\Google Updater\GoogleUpdater.exe" 138680 Nov 16 2007 "C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe" 68856 Jul 12 2007 "C:\Program Files\Google\GoogleToolbarNotifier\bak\GoogleToolbarNotifier.exe" 126136 Nov 16 2007 "C:\Program Files\Google\Google Updater\2.2.969.23408\GoogleUpdaterRestartManager.exe" 26694 Jul 15 2007 "C:\Documents and Settings\Owner\Application Data\Microsoft\Installer\{407B9B5C-DAC5-4F44-A756-B57CAB4E6A8B}\googleearth.exe_407B9B5CDAC54F44A756B57CAB4E6A8B.exe" 52272 Nov 16 2007 "G:\C Drive Duplicate\Program Files\Google\googletoolbar1user.exe" 441088 Nov 17 2003 "G:\C Drive Duplicate\Program Files\America Online 5.0\download\GoogleToolbarInstaller.exe" 69632 May 24 2007 "G:\C Drive Duplicate\Program Files\Google\Google Earth\googleearth.exe" 126136 Nov 16 2007 "G:\C Drive Duplicate\Program Files\Google\Google Updater\GoogleUpdater.exe" 441088 Nov 17 2003 "G:\Old G Drive Restored Partial\May 19 Copy ofPavillion Drive C\America Online 5.0\download\GoogleToolbarInstaller.exe" 138680 Nov 16 2007 "G:\C Drive Duplicate\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe" 68856 Jul 12 2007 "G:\C Drive Duplicate\Program Files\Google\GoogleToolbarNotifier\bak\GoogleToolbarNotifier.exe" 126136 Nov 16 2007 "G:\C Drive Duplicate\Program Files\Google\Google Updater\2.2.969.23408\GoogleUpdaterRestartManager.exe" 441088 Nov 17 2003 "G:\Backup Set A - C and G-1\1 Pavilion Backup Combined\May 19 Copy ofPavillion Drive C\America Online 5.0\download\GoogleToolbarInstaller.exe" 3832231 Sep 28 2002 "G:\Old G Drive Restored Partial\May 19 Copy ofPavillion Drive C\My Documents\Daniel\2002 Season\Google News 092802.EXE" 3832231 Sep 28 2002 "G:\Backup Set A - C and G-1\1 Pavilion Backup Combined\May 19 Copy ofPavillion Drive C\My Documents\Daniel\2002 Season\Google News 092802.EXE" 26694 Jul 15 2007 "G:\C Drive Duplicate\Documents and Settings\Owner\Application Data\Microsoft\Installer\{407B9B5C-DAC5-4F44-A756-B57CAB4E6A8B}\googleearth.exe_407B9B5CDAC54F44A756B57CAB4E6A8B.exe" 882512 Nov 16 2007 "G:\C Drive Duplicate\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\OR5BEI7P\Google Updater[1].exe" 49152 Sep 13 2004 "C:\Program Files\HP\HP Software Update\bak\HPWuSchd2.exe" 49152 Sep 13 2004 "G:\C Drive Duplicate\Program Files\HP\HP Software Update\bak\HPWuSchd2.exe" 1187899 Apr 12 2005 "C:\Program Files\McAfee.com\Personal Firewall\bak\MpfTray.exe" 1187899 Apr 12 2005 "G:\C Drive Duplicate\Program Files\McAfee.com\Personal Firewall\bak\MpfTray.exe" 99480 Apr 5 2004 "C:\Program Files\Pure Networks\Port Magic\bak\PortAOL.exe" 99480 Apr 5 2004 "G:\C Drive Duplicate\Program Files\Pure Networks\Port Magic\bak\PortAOL.exe" 1003520 May 26 2006 "C:\Program Files\Real\RealOne Player\bak\realplay.exe" 1003520 May 26 2006 "G:\C Drive Duplicate\Program Files\Real\RealOne Player\bak\realplay.exe" 19456 Sep 4 2001 "G:\Old G Drive Restored Partial\May 19 Copy ofPavillion Drive C\Program Files\Real\RealPlayer\realplay.exe" 19456 Sep 4 2001 "G:\Backup Set A - C and G-1\1 Pavilion Backup Combined\May 19 Copy ofPavillion Drive C\Program Files\Real\RealPlayer\realplay.exe" 40960 Feb 27 2003 "C:\Program Files\ScanSoft\PaperPort\bak\IndexSearch.exe" 40960 Feb 27 2003 "G:\C Drive Duplicate\Program Files\ScanSoft\PaperPort\bak\IndexSearch.exe" 57393 Feb 27 2003 "C:\Program Files\ScanSoft\PaperPort\bak\pptd40nt.exe" 57393 Feb 27 2003 "G:\C Drive Duplicate\Program Files\ScanSoft\PaperPort\bak\pptd40nt.exe" 29184 Apr 13 1999 "G:\Old G Drive Restored Partial\May 19 Copy ofPavillion Drive C\Program Files\Visioneer\PaperPort\Pptd40nt.exe" 29184 Apr 13 1999 "G:\Backup Set A - C and G-1\1 Pavilion Backup Combined\May 19 Copy ofPavillion Drive C\Program Files\Visioneer\PaperPort\Pptd40nt.exe" 23120680 Aug 17 2007 "C:\Program Files\Skype\Phone\bak\Skype.exe" 23120680 Aug 17 2007 "G:\C Drive Duplicate\Program Files\Skype\Phone\bak\Skype.exe" 155648 Jun 18 2002 "C:\Program Files\VERITAS Software\Update Manager\bak\sgtray.exe" 155648 Jun 18 2002 "G:\C Drive Duplicate\Program Files\VERITAS Software\Update Manager\bak\sgtray.exe" 71216 Oct 23 2006 "C:\Program Files\Common Files\AOL\ACS\bak\AOLDial.exe" 71216 Oct 23 2006 "G:\C Drive Duplicate\Program Files\Common Files\AOL\ACS\bak\AOLDial.exe" 151597 Apr 26 2003 "C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe" 151597 Apr 26 2003 "G:\C Drive Duplicate\Program Files\Common Files\Real\Update_OB\bak\realsched.exe" 50736 Sep 25 2006 "C:\Program Files\Common Files\AOL\1125684819\EE\AOLSoftware.exe1189973455" 50736 Sep 25 2006 "C:\Program Files\Common Files\AOL\1125684819\EE\bak\AOLSoftware.exe" 50736 Sep 25 2006 "G:\C Drive Duplicate\Program Files\Common Files\AOL\1125684819\EE\AOLSoftware.exe1189973455" 50736 Sep 25 2006 "G:\C Drive Duplicate\Program Files\Common Files\AOL\1125684819\EE\bak\AOLSoftware.exe" 542231 Nov 14 2001 "G:\Backup Set A - C and G-1\HP Omnibook Files\Program Files\Support.com\backup\PH\phoneitl.bak\1779648_5abe1c3b1_" 542231 Nov 14 2001 "G:\Backup Set A - C and G-1\HP Omnibook Files\Program Files\Support.com\backup\PH\phoneitl.dms\1779648_5abe1c3b1_" 542231 Nov 14 2001 "H:\Restored Drive G partial\HP Omnibook Files\Program Files\Support.com\backup\PH\phoneitl.bak\1779648_5abe1c3b1_" 542231 Nov 14 2001 "H:\Restored Drive G partial\HP Omnibook Files\Program Files\Support.com\backup\PH\phoneitl.dms\1779648_5abe1c3b1_" 36864 Oct 25 2001 "C:\WINDOWS\system32\spool\drivers\w32x86\lexmarklexmark_x83d8e5\printray.exe" 36864 Oct 25 2001 "C:\WINDOWS\system32\spool\drivers\w32x86\3\bak\printray.exe" 36864 Oct 25 2001 "G:\C Drive Duplicate\WINDOWS\system32\spool\drivers\w32x86\lexmarklexmark_x83d8e5\printray.exe" 36864 Oct 25 2001 "G:\C Drive Duplicate\WINDOWS\system32\spool\drivers\w32x86\3\bak\printray.exe" 542231 Nov 14 2001 "G:\Backup Set A - C and G-1\HP Omnibook Files\Program Files\Support.com\backup\PH\phoneitl.bak\1779648_5abe1c3b1_" 542231 Nov 14 2001 "G:\Backup Set A - C and G-1\HP Omnibook Files\Program Files\Support.com\backup\PH\phoneitl.dms\1779648_5abe1c3b1_" 542231 Nov 14 2001 "H:\Restored Drive G partial\HP Omnibook Files\Program Files\Support.com\backup\PH\phoneitl.bak\1779648_5abe1c3b1_" 542231 Nov 14 2001 "H:\Restored Drive G partial\HP Omnibook Files\Program Files\Support.com\backup\PH\phoneitl.dms\1779648_5abe1c3b1_" end of report
Oops, I posted the AWF log twice, and not the HIJackThis log. Here it is:

Logfile of HijackThis v1.99.1
Scan saved at 7:53:42 PM, on 12/21/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\Program Files\Dantz\Retrospect\retrorun.exe
C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Common Files\AOL\1125684819\ee\AOLSoftware.exe
C:\WINDOWS\System32\WDBtnMgr.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Insight Development\Zip Up The Web Pro\ZUTWTray.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\American Systems\Print Screen Deluxe\psdeluxe.exe
C:\Program Files\American Systems\EZ Macros\EZMacros.exe
c:\program files\common files\aol\1125684819\ee\services\antiSpywareApp\ver2_0_32_1\AOLSP Scheduler.exe
c:\program files\common files\aol\1125684819\ee\aolsoftware.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\WINDOWS\System32\wuauclt.exe
c:\program files\common files\aol\1125684819\ee\anotify.exe
C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
C:\Program Files\GBCS Software\URL Address Book\Urlbook.exe
C:\WINDOWS\System32\taskmgr.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijack This\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus8.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://news.myway.com/index/id/top%7Cap.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://qus8.hpwis.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: (no name) - {02DCA195-602B-4B1F-83FF-381B7E804BDB} - C:\WINDOWS\system32\HDBHO.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptcl.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1125684819\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [WD Button Manager] WDBtnMgr.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [AOLAspSunset2] C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\updates\aspapp\sunsetAsp2.exe
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\AOL 9.0b\AOL.EXE" -b
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: Print Screen Deluxe.lnk = C:\Program Files\American Systems\Print Screen Deluxe\psdeluxe.exe
O4 - Startup: Shortcut to EZMacros.lnk = C:\Program Files\American Systems\EZ Macros\EZMacros.exe
O4 - Startup: URL Address Book.lnk = C:\Program Files\GBCS Software\URL Address Book\Urlbook.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O4 - Global Startup: Zip Up The Web Tray Icon.lnk = C:\Program Files\Insight Development\Zip Up The Web Pro\ZUTWTray.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra button: URLBook - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files\GBCS Software\URL Address Book\Urlbook.exe (HKCU)
O9 - Extra 'Tools' menuitem: URL Address Book - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files\GBCS Software\URL Address Book\Urlbook.exe (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://www.lizardtech.com/download/files/w…ntrol_en_US.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.snapfish.com/SnapfishActivia.cab
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://www.tscmaps.com/shared/viewer/mgaxctrl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1189980911625
O16 - DPF: {6BF35011-3AE5-44D3-A8BB-73ED462A0BC0} (EZUploader Control) - http://www.ezprints.com/software/ezuploader.cab
O16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} - http://toolbar.google.com/data/GoogleActivate.cab
O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - http://www.rentmanager.com/demo/msrdp.cab
O16 - DPF: {A93B47FD-9BF6-4DA8-97FC-9270B9D64A6C} (VaPgCtrl Class) - http://www.dlink.com/products/livedemo/plugin/h263ctrl.cab
O16 - DPF: {BAC01377-73DD-4796-854D-2A8997E3D68A} (Yahoo! Photos Easy Upload Tool Class) - http://us.dl1.yimg.com/download.yahoo.com/…ropper1_6us.cab
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://download.toontown.com/sv1.0.13.16/ttinst.cab
O16 - DPF: {D53A9247-2FEA-4E93-8EEE-9A9B07E8D760} (EZPCropFit Class) - http://www.ezprints.com/software/cropfit.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Retrospect Launcher (RetroLauncher) - Dantz Development Corporation - C:\Program Files\Dantz\Retrospect\retrorun.exe
O23 - Service: Retrospect Helper - Dantz Development Corporation - C:\Program Files\Dantz\Retrospect\rthlpsvc.exe
O23 - Service: Retrospect WD Service (RetroWDSvc) - Dantz Development Corporation - C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
Hmm…! Im trying to think of the best way to play this, to save on running time. How about a back up on one drive, format the other then clean up C. Once it is clean, back it up? That's how we work Restore Points. It's always better to have an infected backup than no backup at all.
Scotty,

I turned off the G; and G; drives, and reran FindAWF. It only took a short while. The results are below, with a new HiJackThis log. If I can get this problem solved, I will deal with the backup disks then. I need to spend a good deal of time straightening them out anyway, so I will likely just start over with a new full backup, and then do incrementals from then on.

I did notice in the AWF log that a couple of the programs with .bak files were the ones I was having the most problem with - Scansoft and Veritas.

Also, when I first discovered this problem, I tried to do a recovery to a state from a few weeks earlier, and could not do so. Can't remember what the error message was now. I haven't tried this again since, but I decided at that time that this Malware had somehow infected that process as well.

Thanks,

Ron Cobb

———————————


Find AWF report by noahdfear ©2006
Version 1.40

The current date is: Sat 12/22/2007
The current time is: 8:28:15.28


bak folders found
~~~~~~~~~~~


Directory of C:\HP\KBD\BAK

02/11/2003 11:02 PM 61,440 KBD.EXE
1 File(s) 61,440 bytes

Directory of C:\PROGRA~1\AMERIC~1.0A\BAK

07/12/2005 01:17 AM 50,776 AOL.EXE
09/19/2007 09:27 PM 24 shellmon.ph
2 File(s) 50,800 bytes

Directory of C:\PROGRA~1\AOL9~1.0B\BAK

04/18/2007 02:49 AM 50,736 AOL.EXE
11/19/2007 09:12 AM 24 shellmon.ph
2 File(s) 50,760 bytes

Directory of C:\PROGRA~1\LEXMAR~1\BAK

06/14/2001 12:42 PM 53,248 AcBtnMgr_X83.exe
10/18/2001 10:25 AM 40,960 ACMonitor_X83.exe
2 File(s) 94,208 bytes

Directory of C:\PROGRA~1\MESSEN~1\BAK

0 File(s) 0 bytes

Directory of C:\PROGRA~1\PICASA2\BAK

12/11/2006 08:36 PM 366,400 PicasaMediaDetector.exe
1 File(s) 366,400 bytes

Directory of C:\PROGRA~1\QUICKT~1\BAK

09/02/2005 02:16 PM 98,304 qttask.exe
1 File(s) 98,304 bytes

Directory of C:\WINDOWS\SMINST\BAK

09/14/2002 12:42 AM 212,992 RECGUARD.EXE
1 File(s) 212,992 bytes

Directory of C:\WINDOWS\SYSTEM\BAK

11/26/2007 08:47 AM 183 hpsysdrv.DAT
05/07/1998 07:04 PM 52,736 hpsysdrv.exe
2 File(s) 52,919 bytes

Directory of C:\WINDOWS\SYSTEM32\BAK

03/11/2003 08:11 PM 114,688 hkcmd.exe
07/31/2002 11:28 PM 81,920 ps2.exe
2 File(s) 196,608 bytes

Directory of C:\PROGRA~1\BROADJ~1\CLIENT~1\BAK

0 File(s) 0 bytes

Directory of C:\PROGRA~1\GOOGLE\GOOGLE~2\BAK

07/12/2007 10:13 PM 68,856 GoogleToolbarNotifier.exe
1 File(s) 68,856 bytes

Directory of C:\PROGRA~1\HP\HPSOFT~1\BAK

09/13/2004 04:49 PM 49,152 HPWuSchd2.exe
1 File(s) 49,152 bytes

Directory of C:\PROGRA~1\MCAFEE.COM\PERSON~1\BAK

04/12/2005 04:44 PM 1,187,899 MpfTray.exe
1 File(s) 1,187,899 bytes

Directory of C:\PROGRA~1\PURENE~1\PORTMA~1\BAK

04/05/2004 05:33 PM 99,480 PortAOL.exe
1 File(s) 99,480 bytes

Directory of C:\PROGRA~1\REAL\REALON~1\BAK

05/26/2006 08:21 AM 1,003,520 realplay.exe
1 File(s) 1,003,520 bytes

Directory of C:\PROGRA~1\SCANSOFT\PAPERP~1\BAK

02/27/2003 02:40 AM 40,960 IndexSearch.exe
02/27/2003 02:12 AM 57,393 pptd40nt.exe
2 File(s) 98,353 bytes

Directory of C:\PROGRA~1\SKYPE\PHONE\BAK

08/17/2007 03:45 AM 23,120,680 Skype.exe
1 File(s) 23,120,680 bytes

Directory of C:\PROGRA~1\VERITA~1\UPDATE~1\BAK

06/18/2002 01:01 AM 155,648 sgtray.exe
1 File(s) 155,648 bytes

Directory of C:\PROGRA~1\COMMON~1\AOL\ACS\BAK

10/23/2006 08:50 AM 71,216 AOLDial.exe
1 File(s) 71,216 bytes

Directory of C:\PROGRA~1\COMMON~1\REAL\UPDATE~1\BAK

04/26/2003 02:30 AM 151,597 realsched.exe
1 File(s) 151,597 bytes

Directory of C:\PROGRA~1\COMMON~1\AOL\112568~1\EE\BAK

09/25/2006 08:52 PM 50,736 AOLSoftware.exe
1 File(s) 50,736 bytes

Directory of C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\BAK

10/25/2001 02:20 PM 36,864 printray.exe
1 File(s) 36,864 bytes


Duplicate files of bak directory contents
~~~~~~~~~~~~~~~~~~~~~~~

61440 Feb 11 2003 "C:\hp\KBD\bak\KBD.EXE"
45125 Dec 18 2002 "C:\Program Files\America Online 8.0\aol.exe"
45140 Sep 24 2003 "C:\Program Files\America Online 9.0\aol.exe"
24576 Aug 27 1999 "C:\Program Files\America Online 5.0\aol.exe"
50736 Apr 18 2007 "C:\Program Files\AOL 9.0a\aol.exe"
50776 Jul 12 2005 "C:\Program Files\America Online 9.0a\bak\AOL.EXE"
50736 Apr 18 2007 "C:\Program Files\AOL 9.0b\bak\AOL.EXE"
74 Sep 16 2007 "C:\Program Files\America Online 8.0\shellmon.ph"
24 Sep 11 2007 "C:\Program Files\America Online 9.0a\shellmon.ph"
24 Sep 19 2007 "C:\Program Files\America Online 9.0\shellmon.ph"
24 Sep 16 2007 "C:\Program Files\AOL 9.0a\shellmon.ph"
24 Sep 16 2007 "C:\Program Files\AOL 9.0b\shellmon.ph"
24 Sep 19 2007 "C:\Program Files\America Online 9.0a\bak\shellmon.ph"
24 Nov 19 2007 "C:\Program Files\AOL 9.0b\bak\shellmon.ph"
1693 Oct 21 2007 "C:\Documents and Settings\All Users\Application Data\AOL\C_America Online 9.0\shellmon.ph"
1646 Sep 26 2007 "C:\Documents and Settings\All Users\Application Data\AOL\C_America Online 9.0a\shellmon.ph"
1634 Sep 24 2007 "C:\Documents and Settings\All Users\Application Data\AOL\C_AOL 9.0a\shellmon.ph"
2402 Dec 14 2007 "C:\Documents and Settings\All Users\Application Data\AOL\C_AOL 9.0b\shellmon.ph"
45125 Dec 18 2002 "C:\Program Files\America Online 8.0\aol.exe"
45140 Sep 24 2003 "C:\Program Files\America Online 9.0\aol.exe"
24576 Aug 27 1999 "C:\Program Files\America Online 5.0\aol.exe"
50736 Apr 18 2007 "C:\Program Files\AOL 9.0a\aol.exe"
50776 Jul 12 2005 "C:\Program Files\America Online 9.0a\bak\AOL.EXE"
50736 Apr 18 2007 "C:\Program Files\AOL 9.0b\bak\AOL.EXE"
74 Sep 16 2007 "C:\Program Files\America Online 8.0\shellmon.ph"
24 Sep 11 2007 "C:\Program Files\America Online 9.0a\shellmon.ph"
24 Sep 19 2007 "C:\Program Files\America Online 9.0\shellmon.ph"
24 Sep 16 2007 "C:\Program Files\AOL 9.0a\shellmon.ph"
24 Sep 16 2007 "C:\Program Files\AOL 9.0b\shellmon.ph"
24 Sep 19 2007 "C:\Program Files\America Online 9.0a\bak\shellmon.ph"
24 Nov 19 2007 "C:\Program Files\AOL 9.0b\bak\shellmon.ph"
1693 Oct 21 2007 "C:\Documents and Settings\All Users\Application Data\AOL\C_America Online 9.0\shellmon.ph"
1646 Sep 26 2007 "C:\Documents and Settings\All Users\Application Data\AOL\C_America Online 9.0a\shellmon.ph"
1634 Sep 24 2007 "C:\Documents and Settings\All Users\Application Data\AOL\C_AOL 9.0a\shellmon.ph"
2402 Dec 14 2007 "C:\Documents and Settings\All Users\Application Data\AOL\C_AOL 9.0b\shellmon.ph"
53248 Jun 14 2001 "C:\Program Files\LexmarkX83\bak\AcBtnMgr_X83.exe"
40960 Oct 18 2001 "C:\Program Files\LexmarkX83\bak\ACMonitor_X83.exe"
591416 Sep 27 2007 "C:\Program Files\Picasa2\PicasaUpdate.exe"
366400 Dec 11 2006 "C:\Program Files\Picasa2\bak\PicasaMediaDetector.exe"
665160 Sep 27 2007 "C:\Program Files\Picasa2\cdautorun\PicasaRestore.exe"
98304 Sep 2 2005 "C:\Program Files\QuickTime\bak\qttask.exe"
212992 Sep 14 2002 "C:\WINDOWS\SMINST\bak\RECGUARD.EXE"
199 Sep 16 2003 "C:\WINDOWS\system\hpsysdrv.DAT"
183 Nov 26 2007 "C:\WINDOWS\system\bak\hpsysdrv.DAT"
52736 May 7 1998 "C:\WINDOWS\system\bak\hpsysdrv.exe"
114688 Mar 11 2003 "C:\WINDOWS\system32\bak\hkcmd.exe"
114688 Mar 11 2003 "C:\hp\drivers\video\865\hkcmd.exe"
114688 Mar 11 2003 "C:\WINDOWS\system32\ReinstallBackups\0002\DriverFiles\hkcmd.exe"
81920 Jul 31 2002 "C:\hp\drivers\keyboard\PS2.EXE"
81920 Jul 31 2002 "C:\WINDOWS\system32\bak\ps2.exe"
52272 Nov 16 2007 "C:\Program Files\Google\googletoolbar1user.exe"
441088 Nov 17 2003 "C:\Program Files\America Online 5.0\download\GoogleToolbarInstaller.exe"
69632 May 24 2007 "C:\Program Files\Google\Google Earth\googleearth.exe"
126136 Nov 16 2007 "C:\Program Files\Google\Google Updater\GoogleUpdater.exe"
138680 Nov 16 2007 "C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"
68856 Jul 12 2007 "C:\Program Files\Google\GoogleToolbarNotifier\bak\GoogleToolbarNotifier.exe"
126136 Nov 16 2007 "C:\Program Files\Google\Google Updater\2.2.969.23408\GoogleUpdaterRestartManager.exe"
26694 Jul 15 2007 "C:\Documents and Settings\Owner\Application Data\Microsoft\Installer\{407B9B5C-DAC5-4F44-A756-B57CAB4E6A8B}\googleearth.exe_407B9B5CDAC54F44A756B57CAB4E6A8B.exe"
49152 Sep 13 2004 "C:\Program Files\HP\HP Software Update\bak\HPWuSchd2.exe"
1187899 Apr 12 2005 "C:\Program Files\McAfee.com\Personal Firewall\bak\MpfTray.exe"
99480 Apr 5 2004 "C:\Program Files\Pure Networks\Port Magic\bak\PortAOL.exe"
1003520 May 26 2006 "C:\Program Files\Real\RealOne Player\bak\realplay.exe"
40960 Feb 27 2003 "C:\Program Files\ScanSoft\PaperPort\bak\IndexSearch.exe"
57393 Feb 27 2003 "C:\Program Files\ScanSoft\PaperPort\bak\pptd40nt.exe"
23120680 Aug 17 2007 "C:\Program Files\Skype\Phone\bak\Skype.exe"
155648 Jun 18 2002 "C:\Program Files\VERITAS Software\Update Manager\bak\sgtray.exe"
71216 Oct 23 2006 "C:\Program Files\Common Files\AOL\ACS\bak\AOLDial.exe"
151597 Apr 26 2003 "C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe"
50736 Sep 25 2006 "C:\Program Files\Common Files\AOL\1125684819\EE\AOLSoftware.exe1189973455"
50736 Sep 25 2006 "C:\Program Files\Common Files\AOL\1125684819\EE\bak\AOLSoftware.exe"
36864 Oct 25 2001 "C:\WINDOWS\system32\spool\drivers\w32x86\lexmarklexmark_x83d8e5\printray.exe"
36864 Oct 25 2001 "C:\WINDOWS\system32\spool\drivers\w32x86\3\bak\printray.exe"


end of report
——————————————

Logfile of HijackThis v1.99.1
Scan saved at 12:11:13 PM, on 12/22/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\Program Files\Dantz\Retrospect\retrorun.exe
C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Common Files\AOL\1125684819\ee\AOLSoftware.exe
C:\WINDOWS\System32\WDBtnMgr.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Insight Development\Zip Up The Web Pro\ZUTWTray.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\American Systems\Print Screen Deluxe\psdeluxe.exe
C:\Program Files\American Systems\EZ Macros\EZMacros.exe
c:\program files\common files\aol\1125684819\ee\services\antiSpywareApp\ver2_0_32_1\AOLSP Scheduler.exe
c:\program files\common files\aol\1125684819\ee\aolsoftware.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\WINDOWS\System32\wuauclt.exe
c:\program files\common files\aol\1125684819\ee\anotify.exe
C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
C:\Program Files\GBCS Software\URL Address Book\Urlbook.exe
C:\WINDOWS\System32\taskmgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Hijack This\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus8.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://news.myway.com/index/id/top%7Cap.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://qus8.hpwis.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: (no name) - {02DCA195-602B-4B1F-83FF-381B7E804BDB} - C:\WINDOWS\system32\HDBHO.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptcl.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1125684819\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [WD Button Manager] WDBtnMgr.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [AOLAspSunset2] C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\updates\aspapp\sunsetAsp2.exe
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\AOL 9.0b\AOL.EXE" -b
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: Print Screen Deluxe.lnk = C:\Program Files\American Systems\Print Screen Deluxe\psdeluxe.exe
O4 - Startup: Shortcut to EZMacros.lnk = C:\Program Files\American Systems\EZ Macros\EZMacros.exe
O4 - Startup: URL Address Book.lnk = C:\Program Files\GBCS Software\URL Address Book\Urlbook.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O4 - Global Startup: Zip Up The Web Tray Icon.lnk = C:\Program Files\Insight Development\Zip Up The Web Pro\ZUTWTray.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra button: URLBook - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files\GBCS Software\URL Address Book\Urlbook.exe (HKCU)
O9 - Extra 'Tools' menuitem: URL Address Book - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files\GBCS Software\URL Address Book\Urlbook.exe (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://www.lizardtech.com/download/files/w…ntrol_en_US.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.snapfish.com/SnapfishActivia.cab
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://www.tscmaps.com/shared/viewer/mgaxctrl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1189980911625
O16 - DPF: {6BF35011-3AE5-44D3-A8BB-73ED462A0BC0} (EZUploader Control) - http://www.ezprints.com/software/ezuploader.cab
O16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} - http://toolbar.google.com/data/GoogleActivate.cab
O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - http://www.rentmanager.com/demo/msrdp.cab
O16 - DPF: {A93B47FD-9BF6-4DA8-97FC-9270B9D64A6C} (VaPgCtrl Class) - http://www.dlink.com/products/livedemo/plugin/h263ctrl.cab
O16 - DPF: {BAC01377-73DD-4796-854D-2A8997E3D68A} (Yahoo! Photos Easy Upload Tool Class) - http://us.dl1.yimg.com/download.yahoo.com/…ropper1_6us.cab
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://download.toontown.com/sv1.0.13.16/ttinst.cab
O16 - DPF: {D53A9247-2FEA-4E93-8EEE-9A9B07E8D760} (EZPCropFit Class) - http://www.ezprints.com/software/cropfit.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Retrospect Launcher (RetroLauncher) - Dantz Development Corporation - C:\Program Files\Dantz\Retrospect\retrorun.exe
O23 - Service: Retrospect Helper - Dantz Development Corporation - C:\Program Files\Dantz\Retrospect\rthlpsvc.exe
O23 - Service: Retrospect WD Service (RetroWDSvc) - Dantz Development Corporation - C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
Hi Im a bit concerned that after we clean up the main drive you reconnect the others that may be infected and re-introduce the problem. Im going to make sure I have the right idea before we proceed, if you can bear with me a bit longer?
Hello How does this sound to you? The files you want to keep on the G drive. Can you back them up to the H drive, which only has an infected Restore Point? Before moving/copying the files you want to keep, do individual anti-virus scans on them, to make sure they are not infected. Once you have everything, format and disconnect the G drive, then we can proceed with the cleaning. Let me know if that sounds good to you?
Scotty, This will take me some time, so please bear with me. I have a lot of very old stuff on these disks, and need to go through all of it to purge what I don't need, toss out duplicates, etc. I will need to find a day in which I can concentrate on this alone - hopefully in a couple of days. On the G: and H: drives, which are the USB externals, I believe that they sometimes exchange designations (G and H) depending on which one I turn of first. How can I identify the one on which to consolodate everything and the one to reformat? Thanks, Ron Cobb
Hi Sorry for the delay in getting back to you. I think the option here is for you to back up what you need onto CD or something (no bak files) and leave the USB drives connected while we do the clean up. Let me know when you are ready to proceed.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI