Hi Tom …
Log 1 - CFScript
ComboFix 08-12-18.03 - HP_Owner 2008-12-21 10:31:45.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1023.441 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\Worknow.com.exe
Command switches used :: c:\documents and settings\HP_Owner\Desktop\CFScript.txt
* Created a new restore point
FILE ::
c:\program files\Online Services\AOL90US\comps\toolbar\toolbr.EXE
c:\program files\Windows Live\Messenger\msimg32.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\HP_Owner\Application Data\WeatherBug
c:\documents and settings\HP_Owner\Application Data\WeatherBug\
0107_Winter.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\
0107_Winter_Mask.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\
06_Winter_031208.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\
06_Winter_121807.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\
06_Winter_121807_Mask.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\
06_Winter_BUBBLE_Mask.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\
06_Winter_BUBBLE_Mask_updated.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\
06_Winter_Bubble_Wrap.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\
06_Winter_Bubble_Wrap_updated.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\
06_Winter_Mask_031208.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\102x96_ActiveStorms.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\102x96_Allergy.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\102x96_Allergy2.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\102x96_B&B.JPG
c:\documents and settings\HP_Owner\Application Data\WeatherBug\102x96_BeachAndBoating.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\102x96_Cold&Flu_Blue.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\102x96_ColdAndFlu.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\102x96_ColdAndFlu_VZ.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\102x96_ColdAndFluMobile.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\102x96_Disney.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\102x96_Disney_2.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\102x96_Disney_3.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\102x96_Disney_Chance2Win.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\102x96_DisneyCru.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\102x96_DisneyRoadTrip.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\102x96_GreenSection.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\102x96_GrHog_tile.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\102x96_Hurricane_09252007.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\102x96_Hurricane_Dean.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\102x96_Hurricane_withColdandFlu.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\102x96_HurricaneCommandCenter.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\102x96_HurricaneCommandCenterWithFlag.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\102x96_IKE_v2.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\102x96_NST_3-22-07.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\102x96_NWF.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\102x96_Plus_iPhone.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\102x96_Storm_Tracker_Beach_Plus.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\102x96_Storm_Tracker_Beach_Plus2.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\102x96_VZW.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\102x96AIMlogoad.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\102x96BlowoutSale.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\102x96BlowoutSalev2.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\102x96DisneyQuestforGold.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\102x96FarmersAlmanacOutlookTile.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\102x96FOG_Lightning.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\102x96FreeTrial.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\102x96HurricaneNameVideo_Plus_Mobile.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\102x96HurricaneVideo.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\102x96LiveTrafficCameras.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\102x96Mobile2_0507.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\102x96New_Disney_2.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\102x96PlusMobile.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\102x96PlusNVerizon.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\102x96Professional.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\102x96SponsorTileMobileVideo.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\102x96TP-MA-FF.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\102x96Verizon.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\102x96video.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\102x96video1_mobile2.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\102x96vidgallery.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\102x96vidgallery2.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\4th_of_July_0707.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\4th_of_July_0707_Mask.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\501.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60-AOL-AIMNew-mask.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60-AOL-AIMNew3.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_blueyellow.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_blueyellow_mask.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_blueyellow_nav_traffic.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_brand_cw_APPROVED.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_brand_cw_MASK.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_brand_delta_approved.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_brand_delta_mask.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_brand_holidayinn_approved1.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_brand_holidayinn_mask.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_brand_IceAgeAPPROVED.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_brand_IceAgeMASK.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_brandwrap_APPROVED.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_brandwrap_cherryb_approved.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_brandwrap_cherryb_mask.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_brandwrap_MASK.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_brandwrap_mobile.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_brandwrap_mobile_mask.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_brandwrap_Mobile_MASK_bubble.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_brandwrap_MobileAPPROVED.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_brandwrap_plus.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_brandwrap_PLUS_AP_Holiday.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_brandwrap_plus_mask.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_brandwrap_PLUS_MASK_Holiday.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_brandwrap_pws.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_brandwrap_pws_mask_new.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_brandwrap_spring2.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_brandwrap_spring2_mask.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_brandwrap_valAPPROVED.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_brandwrap_valMASK.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_brandwrap_winter_PLUS.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_brandwrap_winter_Plus_MASK.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_Default_Fall_1007.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_Default_Fall_1007_Mask.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_Default_Spring_Mobile_BG_0506.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_Default_Spring_Mobile_MASK_0506.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_default_winter_0106_Background.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_default_winter_0106_bg_updated.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_default_winter_0106_MASK.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_fall_mobile1_new.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_fall_mobile2_mask.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_fallbrandwrap_mobile1.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_fallbrandwrap_mobile2B.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_fallbrandwrap_plus.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_fallbrandwrap_plus_mask.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_Fixed_BRWP_valMASK.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_FixedBRWP_valAPPROVED.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_Generic_Forecast_BG_0206.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_Generic_Forecast_MASK_0206.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_Generic_Photo_Approved.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_Generic_Photo_MASK.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_generic_summerAPPROVED.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_generic_summerMASK.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_Generic_Sun_0306_Final.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_Generic_Sun_0306_Final.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_Generic_WinterWrap08.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_Generic_WinterWrap08_MASK.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_Generic200_Spring_Mask_031908.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_Generic2005_Final.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_Generic2005_Final.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_Generic2006_Fall_091406.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_Generic2006_Fall_091406.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_Generic2007_Fall_1107.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_Generic2007_Mask_1107.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_Generic2007_Spring_031908.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_Generic2007_Spring_060807.JPG
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_Generic2007_Summe_0807r.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_Generic2007_Summer.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_Generic2007_Summer_070507.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_Generic2007_Summer_070507_Mask.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_Generic2007_Summer_Mask.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_Generic2007_Summer_Mask_0807.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_Generic2008_Summer.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_Generic2008_Summer_Mask.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_GenericPLUS_approved.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_GenericPLUS_FALL_Revised.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_GenericPLUS_FALL_Revised_MASK.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_GenericPLUS_MASK.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_GenericPLUS_Summer_082906.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_GenericPLUS_Summer_082906.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_GenericRadarMaps_Final.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_GenericRadarMaps_MASK.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_GenericThanksgiv08_mask.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_GenericThanksgiving08.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_GeorgPac_Mask.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_GeorgPacific.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_nav_dark_round_1105.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_nav_dark_square_0206.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_nav_light_round_0206.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_nav_light_round_0706.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_nav_light_square_0206.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_nav_light_square_0706.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_Protonix_Approved2.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_Protonix_MASK.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_Share_alert_tab2.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_Share_alert_tab2_mask.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_Spring_Bubble_0507.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_Spring_Bubble_Mask_0507.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_Tornado_Spring_0607.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60_Tornado_Spring_0607_Mask.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\605_NewDefault-maskl.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\605_NewDefault.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Default-Fall0908.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Default-Fall0908.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Default-Halloween08.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Default-Halloween08.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Default-mask.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Default.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Mktg_MyThemes2.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Mktg_MyThemes2_mask.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60nav_dark_round.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60nav_Generic2005.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60nav_Generic2005_1.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60nav_light_round.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60nav_light_square.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Sales-ACE-ATH_110608.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Sales-ACE-ATH_110608.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Sales-ACE-GNO-0608.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Sales-ACE-GNO-0608.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Sales-ACE_DTS1008.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Sales-ACE_DTS1008.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Sales-ACE_DTS1008_2.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Sales-ACE_DTS1008_2.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Sales-ACE_GOC_120408.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Sales-ACE_GOC_120408.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Sales-ACE_Hardware-Thanksgiving1107.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Sales-ACE_Hardware-Thanksgiving1107.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Sales-Ace_Hurricane.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Sales-Ace_Hurricane.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Sales-ACE_LMG121808.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Sales-ACE_LMG121808.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Sales-ChantixAge_0108.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Sales-ChantixAge_0108.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Sales-ChantixDMA_0108.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Sales-ChantixDMA_0108.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Sales-Columbia_GO_MASK.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Sales-Columbia_GO_SKIN.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Sales-DiscoveryShark_mask.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Sales-DiscoverySharkWeek.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Sales-Folgers0808.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Sales-Folgers0808_2.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Sales-MyMMs.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Sales-MyMMs.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Sales-NationWideEST647.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Sales-NationWideEST647_mask.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Sales-NexTag-mask.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Sales-NexTag.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Sales-QualityInn_Mask.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Sales-QualityInn_Skin1.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Sales-StaticGuard1008.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Sales-StaticGuard1008.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Sales-SuperpagesNEW.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Sales-Tamiflu.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Sales-Tamiflu_mask.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Sales-Tide0808.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Sales-Tide0808.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Sales-trane2_mask.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Sales-trane3_shell.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Sales-Wendys_0608.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Sales-Wendys_0608.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Sales_Alaway_mask.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Sales_Alaway_shell.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Sales_Expedia1.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Sales_Expedia1_mask.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Sales_ExpediaWinter.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Sales_Lipton_mask.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Sales_Lipton_shell.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Sales_monopoly_mask.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Sales_monopoly_shell.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Sales_Sudafed_MASK.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Sales_Sudafed_shell.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Sales_SuperpagesEST635_mask.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Sales_united_0707_MASK.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Sales_united_0707_SKIN.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Sales_VWBeetle.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Sales_VWBeetle_mask.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60Sales_Winter_mask.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60SalesBR-Nair_skin.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\60SalesBR_Nair_MASK.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\AIMsptile1.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\Allstate.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\Allstate_Mask.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\Amica.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\Amica_MASK.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\Army_background.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\Army_mask.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\Claritin.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\Claritin_Mask.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\disney_wrap.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\disney_wrap_background.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\Election2008.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\Election2008_mask.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\Eucerin.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\Eucerin_Mask.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\Fall-VZWbubble_APPROVED.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\Fall-VZWbubble_APPROVED_102407.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\Fall-VZWbubble_MASK.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\Fall-VZWbubble_MASK_102407.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\Fall.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\Fall_Mask.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\Fox_Theatrical_approved.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\Fox_Theatrical_MASK.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\Frontier_042808.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\Frontier_Mask_0408.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\GE_Eco.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\GE_Eco_MASK.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\HBO_Sopranos_Mask.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\HBO_Sopranos_shell.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\HurricaneRelief.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\IKEWrap_Callout.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\IKEWrap_MASK.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\jcPenny_60wrap.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\jcPenny_60wrap_MASK.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\katrina.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\KatrinaRelief.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\leftnav_605Generic.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\Lennox_Approved.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\Lennox_MASK.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\LocalWeather.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\LocalWeather_Mask.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\Lowes_Mask_NoShadow.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\Lowes_Skin_NoShadow.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\Memorial_Generic_07.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\Memorial_Generic_07_MASK.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\Nationwide_Approved_v2.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\Nationwide_MASK.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\nav_07182007.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\nav_alt2.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\nav_Generic_Forecast_0206.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\nav_Generic_Photos_0206.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\nav_Generic_Radar_0206.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\nav_Generic2005_0106.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\nav_Generic2005_032907.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\nav_Generic2006.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\nav_Generic2006_0706.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\nav_square_traffic.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\nav_square2.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\New_Spring_Bubble_052007.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\New_Spring_Bubble_052007_Mask.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\newkatrina.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\NghtAtTheMus_back.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\NghtAtTheMus_mask.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\ProMeris.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\ProMeris_Mask.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\rita.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\Rita_Relief.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\Sanyo_APPROVED.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\Sanyo_MASK.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\Sears_Generic.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\Sears_Generic_MASK.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\Sears_Mobile.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\Sears_Mobile_MASK.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\SponsorFreeTrial.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\SponsorTile28b.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\sponsortile34.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\SponsorTile37.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\SponsorTile38.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\SponsorTile39.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\SponsorTile40.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\SponsorTile42.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\Spring_2007.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\Spring_2007_Mask.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\Sudafed_APPROVED_112408.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\Sudafed_MASK_112408.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\Summer_Hurricane_Bubble_071707.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\Summer_Hurricane_Bubble_071707_Mask.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\SurveyAIMTile.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\Take-Me-Fishing_APPROVED.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\Take Me Fishing_MASK.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\Tamiflu.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\Tamiflu_mask.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\topnav_605Generic.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\topnav_Business.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\TopNav_Free_Round_Green.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\TopNav_Free_Sq_Green.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\topnav_Generic2005.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\topnav_Generic2005_121505.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\topnav_Generic2007.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\topnav_round_121505.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\topnav_square.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\topnav_square_121505.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\topnav_stations_generic.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\topnav_stations_round.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\topnav_stations_square.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\Verizon_Bubble_0208.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\Verizon_Bubble_0208_MASK.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\VerizonWrap_Approved.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\VerizonWrap_MASK.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\Video21_60_nav_dark_square.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\Video21_60_nav_light_square.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\Visa_Mask_revised.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\Visa_revised.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\visaNFL.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\visaNFL_mask.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\WeatherAlert.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\WeatherAlert_Mask.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\Wellbridge_Colorado_0908.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\Wellbridge_Mask_Colorado_0908.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\wilma.jpg
c:\documents and settings\HP_Owner\Application Data\WeatherBug\Winter_BUBBLE2.bmp
c:\documents and settings\HP_Owner\Application Data\WeatherBug\Winter_BUBBLE2.jpg
c:\program files\AWS\WeatherBug
c:\program files\AWS\WeatherBug\REMOVE.EXE
c:\program files\AWS\WeatherBug\WxBugAutoUpgrade605b6.05.0.15d.EXE
c:\program files\Online Services\AOL90US\comps\toolbar\toolbr.EXE
c:\program files\Windows Live\Messenger\msimg32.dll
.
((((((((((((((((((((((((( Files Created from 2008-11-21 to 2008-12-21 )))))))))))))))))))))))))))))))
.
2008-12-20 10:11 . 2008-12-20 10:11 410,984 –a—— c:\windows\system32\deploytk.dll
2008-12-19 15:22 . 2008-12-19 15:22 d–h—– c:\windows\PIF
2008-12-19 10:25 . 2008-12-19 10:25 d——– c:\program files\XoftSpySE
2008-12-13 04:24 . 2008-12-13 04:25 d——– c:\documents and settings\HP_Owner\Application Data\Move Networks
2008-12-11 15:42 . 2008-12-11 15:43 d——– c:\program files\Virtual Earth 3D
2008-11-30 09:03 . 2008-11-30 09:03 d——– c:\program files\Microsoft Silverlight
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-21 17:33 ——— d—–w c:\program files\AWS
2008-12-20 21:02 47,312 —-a-w c:\documents and settings\HP_Owner\Application Data\wklnhst.dat
2008-12-20 18:34 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2008-12-20 18:28 ——— d—–w c:\program files\MioNet
2008-12-20 17:15 ——— d—–w c:\program files\Malwarebytes' Anti-Malware
2008-12-20 17:10 ——— d—–w c:\program files\Java
2008-12-20 01:15 ——— d—–w c:\program files\Viewpoint
2008-12-20 01:15 ——— d—–w c:\documents and settings\All Users\Application Data\Viewpoint
2008-12-15 18:22 ——— d—–w c:\program files\Easy CD-DA Extractor 9
2008-12-04 02:52 38,496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-04 02:52 15,504 —-a-w c:\windows\system32\drivers\mbam.sys
2008-11-19 02:55 ——— d—–w c:\program files\Common Files\HP
2008-11-19 02:49 3,645 —-a-w c:\windows\viassary-hp.reg
2008-10-30 17:34 ——— d—–w c:\program files\Avery Wizard 3.1
2008-10-29 17:53 ——— d—–w c:\program files\Avery
2008-10-24 11:21 455,296 —-a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-23 12:36 286,720 —-a-w c:\windows\system32\gdi32.dll
2008-10-16 21:13 202,776 —-a-w c:\windows\system32\wuweb.dll
2008-10-16 21:13 1,809,944 —-a-w c:\windows\system32\wuaueng.dll
2008-10-16 21:12 561,688 —-a-w c:\windows\system32\wuapi.dll
2008-10-16 21:12 323,608 —-a-w c:\windows\system32\wucltui.dll
2008-10-16 21:09 92,696 —-a-w c:\windows\system32\cdm.dll
2008-10-16 21:09 51,224 —-a-w c:\windows\system32\wuauclt.exe
2008-10-16 21:09 43,544 —-a-w c:\windows\system32\wups2.dll
2008-10-16 21:08 34,328 —-a-w c:\windows\system32\wups.dll
2008-10-16 21:06 268,648 —-a-w c:\windows\system32\mucltui.dll
2008-10-16 21:06 208,744 —-a-w c:\windows\system32\muweb.dll
2008-10-16 20:38 826,368 —-a-w c:\windows\system32\wininet.dll
2008-10-10 19:21 44,032 —-a-w c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\LocalContent\Attachments\devcon.exe
2008-10-10 19:21 307,200 —-a-w c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\pchnotify.exe
2008-10-10 19:21 3,072 —-a-w c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\jsharpde\pchealthde.exe
2008-10-03 10:02 247,326 —-a-w c:\windows\system32\strmdll.dll
2008-09-30 23:43 1,286,152 —-a-w c:\windows\system32\msxml4.dll
2008-06-25 16:07 113,144 —-a-w c:\documents and settings\HP_Owner\Application Data\GDIPFONTCACHEV1.DAT
.
((((((((((((((((((((((((((((( snapshot@2008-12-19_17.42.14.50 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-10-21 03:02:28 163,328 —-a-w c:\windows\ERDNT\subs\ERDNT.EXE
- 2008-12-20 00:24:06 32,768 —-a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2008-12-21 17:25:05 32,768 —-a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2008-12-20 00:24:06 32,768 —-a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-12-21 17:25:05 32,768 —-a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-12-20 00:24:06 32,768 —-a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-12-21 17:25:05 32,768 —-a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2008-06-10 07:21:01 135,168 —-a-w c:\windows\system32\java.exe
+ 2008-12-20 17:11:07 144,792 —-a-w c:\windows\system32\java.exe
- 2008-06-10 07:21:04 135,168 —-a-w c:\windows\system32\javaw.exe
+ 2008-12-20 17:11:07 144,792 —-a-w c:\windows\system32\javaw.exe
- 2008-06-10 08:32:34 139,264 —-a-w c:\windows\system32\javaws.exe
+ 2008-12-20 17:11:07 148,888 —-a-w c:\windows\system32\javaws.exe
+ 2008-12-20 18:30:52 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_1c8.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-12 68856]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"RegistryMechanic"="c:\program files\Registry Mechanic\RegMech.exe" [2008-07-08 2828184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-09-09 344064]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-08-20 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-08-20 118784]
"HPHUPD06"="c:\program files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe" [2004-06-07 49152]
"HPHmon06"="c:\windows\system32\hphmon06.exe" [2004-06-07 659456]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2004-10-21 180269]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2004-04-14 233472]
"CTDVDDET"="c:\program files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE" [2003-06-18 45056]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-14 253952]
"USSShReg"="c:\progra~1\ULEADS~1\ULEADP~1.2\SSaver\Ussshreg.exe" [1997-11-23 20992]
"phc710"="c:\windows\vphc700.exe" [2005-07-20 339968]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-01 582992]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 49152]
"McAfee Backup"="c:\program files\McAfee\MBK\McAfeeDataBackup.exe" [2007-01-16 4838952]
"MBkLogOnHook"="c:\program files\McAfee\MBK\LogOnHook.exe" [2007-01-08 20480]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-09-03 111936]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-09-10 289576]
"KBD"="c:\hp\KBD\KBD.EXE" [2005-02-02 61440]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-20 136600]
"CTHelper"="CTHELPER.EXE" [2003-11-14 c:\windows\system32\CTHELPER.EXE]
"AGRSMMSG"="AGRSMMSG.exe" [2005-03-04 c:\windows\AGRSMMSG.exe]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 c:\windows\ALCXMNTR.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="c:\program files\MySpace\IM\MySpaceIM.exe" [2007-05-29 5419008]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"StartMS"="c:\program files\Creative\Shared Files\Media Sniffer\StartMS.EXE" [2003-03-26 57344]
"CMSRegOW.exe"="c:\program files\InstallShield Installation Information\{56F3E1FF-54FE-4384-A153-6CCABA097814}\CMSRegOW.exe" [2003-06-16 57344]
"SetDefaultMIDI"="MIDIDEF.EXE" [2003-06-21 c:\windows\MIDIDEF.EXE]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.exe.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-04-07 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-03-11 210520]
TrayMin710.exe.lnk - c:\program files\Philips\Philips SPC710NC Webcam\TrayMin710.exe [2008-05-09 278528]
Updates from HP.lnk - c:\program files\Updates from HP\309731\Program\Updates from HP.exe [2004-10-21 45056]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Updates from HP\\309731\\Program\\Updates from HP.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\WS_FTP\\WS_FTP95.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Comcast\\Comcast Messaging\\ComcastMessaging.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\McAfee\\MBK\\McAfeeDataBackup.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1700:TCP"= 1700:TCP:MioNet Remote Drive Access
"1641:TCP"= 1641:TCP:MioNet Remote Drive Verification
R2 MioNet;MioNet Service;"c:\program files\MioNet\MioNetManager.exe" -s "c:\program files\MioNet\wrapper.conf" [2005-07-15 139264]
R2 WinDefend;Windows Defender;"c:\program files\Windows Defender\MsMpEng.exe" [2006-11-03 13592]
S3 phc700;USB PC Camera (phc710);c:\windows\system32\DRIVERS\phc700.sys [2008-05-09 541568]
S3 US122;US122 Driver;c:\windows\system32\Drivers\US122.sys [2003-12-19 213196]
S3 US122DL;US122 Firmware Downloader;c:\windows\system32\Drivers\US122DL.sys [2003-12-19 17277]
S3 Us122WdmService;US122 Wdm Audio;c:\windows\system32\Drivers\US122Wdm.sys [2003-12-19 86648]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
2008-12-18 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2008-12-15 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 12:32]
2008-12-01 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 12:32]
2008-12-21 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 19:20]
2008-12-13 c:\windows\Tasks\Uniblue SpeedUpMyPC Nag.job
- c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe []
2008-05-20 c:\windows\Tasks\Uniblue SpeedUpMyPC.job
- c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe []
2008-12-21 c:\windows\Tasks\XoftSpySE 2.job
- c:\program files\XoftSpySE\XoftSpy.exe [2008-12-17 10:43]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.deryn.netfirms.com/
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mStart Page = hxxp://www.deryn.netfirms.com/
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &AIM Search - c:\program files\AIM Toolbar\AIMBar.dll/aimsearch.htm
IE: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\aoltbhtml.dll/search.html
IE: Add To HP Organize… - c:\progra~1\HEWLET~1\HPORGA~1\bin/module.main/favorites\ie_add_to.html
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
c:\windows\Downloaded Program Files\HPSWUpdate.ocx - O16 -: {EBF85371-A38F-485B-B28F-0B4C82D25937}
hxxp://update.hpphoto.com/download/HPSWUpdate.ocx
FF - ProfilePath - c:\documents and settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\1ofksgjd.default\
FF - prefs.js: browser.startup.homepage - www.pookiesplayground.net
FF - plugin: c:\program files\Microsoft Silverlight\2.0.31005.0\npctrl.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - plugin: c:\program files\Virtual Earth 3D\npVE3D.dll
FF - plugin: c:\program files\Yahoo!\Common\npyaxmpb.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-12-21 10:35:27
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
McAfee Backup = c:\program files\McAfee\MBK\McAfeeDataBackup.exe?????????????????????????????????????????????????????????????????????????????????
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(612)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2008-12-21 10:36:37
ComboFix-quarantined-files.txt 2008-12-21 17:36:33
ComboFix2.txt 2008-12-20 01:24:04
ComboFix3.txt 2008-12-20 00:42:49
Pre-Run: 116,513,202,176 bytes free
Post-Run: 116,546,551,808 bytes free
602
LOG 2 - Hijack This
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:52:19 AM, on 12/21/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTSvcCDA.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\McAfee\MBK\MBackMonitor.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\windows\system\hpsysdrv.exe
C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\HP\KBD\KBD.EXE
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\MioNet\MioNetManager.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\MioNet\jvm\bin\MioNet.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
c:\PROGRA~1\mcafee\msc\mcuimgr.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\HP\Smart Web Printing\hpswp_clipbook.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.deryn.netfirms.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.deryn.netfirms.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [CTDVDDET] C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [USSShReg] C:\PROGRA~1\ULEADS~1\ULEADP~1.2\SSaver\Ussshreg.exe /r
O4 - HKLM\..\Run: [phc710] C:\WINDOWS\vphc700.exe
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [McAfee Backup] C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe
O4 - HKLM\..\Run: [MBkLogOnHook] C:\Program Files\McAfee\MBK\LogOnHook.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RegMech.exe /H
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [SetDefaultMIDI] MIDIDEF.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [CMSRegOW.exe] "C:\Program Files\InstallShield Installation Information\{56F3E1FF-54FE-4384-A153-6CCABA097814}\CMSRegOW.exe" /r (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [SetDefaultMIDI] MIDIDEF.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: TrayMin710.exe.lnk = ?
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &AOL Toolbar Search - res://c:\program files\aol\aol toolbar 2.0\aoltbhtml.dll/search.html
O8 - Extra context menu item: Add To HP Organize… - C:\PROGRA~1\HEWLET~1\HPORGA~1\bin/module.main/favorites\ie_add_to.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - c:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) -
http://h20270.www2.hp.com/ediags/gmn2/inst…ctDetection.cab
O16 - DPF: {A9F8D9EC-3D0A-4A60-BD82-FBD64BAD370D} (DDRevision Class) -
http://h20264.www2.hp.com/ediags/dd/instal…nosticsxp2k.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,26/mcgdmgr.cab
O16 - DPF: {EBF85371-A38F-485B-B28F-0B4C82D25937} (CUpdateCtl Object) -
http://update.hpphoto.com/download/HPSWUpdate.ocx
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTSvcCDA.EXE
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: MioNet Service (MioNet) - Unknown owner - C:\Program Files\MioNet\MioNetManager.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
–
End of file - 14140 bytes