Welcome to MalwareRemoval.com,
What if we told you that you could get malware removal help from experts, and that it was 100% free? MalwareRemoval.com provides free support for people with infected computers. Our help, and the tools we use are always 100% free. No hidden catch. We simply enjoy helping others. You enjoy a clean, safe computer.

Malware Removal Instructions

Can't update anti-virus software, access iTunes

MalwareRemoval.com provides free support for people with infected computers. Using plain language that anyone can understand, our community of volunteer experts will walk you through each step.

Can't update anti-virus software, access iTunes

Unread postby cheetahmeow » May 16th, 2009, 10:33 am

Hi there -

The Hijack This log is below, first let me explain what I'm experiencing.

I have a Samsung NC10 net book with Windows XP Home Edition with SP3 and OpenOffice 3.0. Firefox 3.0 and IE 7.0 are also loaded. My antivirus program is the free version of Avira.

Here's my problem:
It began a few months ago while traveling in India. I was using WiFi when there was a power outage. When the power came back on it showed I was connected to the internet and had a strong signal strength however when I opened a Firefox or IE Window I was told there was no access to the internet. I don't remember why but I fiddled with a setting either AVG (I was running AVG and swapped it out for Avira when troubleshooting) or Firefox and was able to get Firefox working again. The problem is I still can't get IE and other programs to connect to the internet.

When I access iTunes Store and when I try to download MP3 audio books from Barnes and Noble (using the OD Media downloader tool) I get error messages saying the programs cannot connect to the stores. "The network connection timed out. Make sure your network settings are correct and your network connection is active then try again."

I also can't get updates to my antivirus software. Both AVG and Avira timeout and don't let me download the latest updates.

I have been able to visit other sites including secure sites with Firefox. For example I can access my bank accounts and credit cards.

What I've tried:

-I've disabled the Windows Firewall (it's now reenabled).
-I've looked at and compared my IE settings to a friend's computer.
-I've removed AVG and replaced it with Avira.
-The Tech Support Guy site suggested refresh my DNS and also reset
netsh winsock. Neither helped.

Do you have any ideas? BTW - India is rife with viruses and hacking and I've been told it's risky to use WiFi but I did it anyway.




Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:48:56 PM, on 5/11/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\samsung\Samsung Network Manager\SNMWLANService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Samsung\Samsung EDS\EDSAgent.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Samsung\Samsung Battery Manager\BatteryManager.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\SAMSUNG\MagicKBD\MagicKBD.exe
C:\WINDOWS\system32\igfxext.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\SAMSUNG\MagicKBD\PerformanceManager.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\iTunes\iTunes.exe
C:\Program Files\Avira\AntiVir Desktop\update.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/ig?hl=en&source=iglk
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = proxy.net.sy.3028
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.0.1:80
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [EDS] C:\Program Files\Samsung\Samsung EDS\EDSAgent.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [DMHotKey] C:\Program Files\Samsung\Easy Display Manager\DMLoader.exe
O4 - HKLM\..\Run: [BatteryManager] C:\Program Files\Samsung\Samsung Battery Manager\BatteryManager.exe
O4 - HKLM\..\Run: [MagicKeyboard] C:\Program Files\SAMSUNG\MagicKBD\PreMKBD.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SUPBackGround] C:\Program Files\Samsung\Samsung Update Plus\SUPBackGround.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/...oUploader5.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: SNM WLAN Service - Unknown owner - C:\Program Files\samsung\Samsung Network Manager\SNMWLANService.exe

Kind regards,
Sara
cheetahmeow
Active Member
 
Posts: 10
Joined: May 16th, 2009, 10:21 am
Advertisement
Register to Remove

Re: Can't update anti-virus software, access iTunes

Unread postby MWR 3 day Mod » May 19th, 2009, 10:09 am

Hi,

We are sorry to see your topic is over three days old and no one has yet been able to respond and offer help.

If you still require assistance, please post a link to your topic in our Waiting for help with malware removal? forum, and our staff will make an effort to assist you as promptly as possible. Only post a LINK to this topic, DO NOT post your DDS log!

Please do not reply to this topic.

If you haven't posted within two days in the "Waiting for help with malware removal?" forum, we will assume you have been able to get assistance in other ways and this topic will be closed.
MWR 3 day Mod
MRU Undergrad
MRU Undergrad
 
Posts: 2534
Joined: April 4th, 2008, 8:40 am

Re: Can't update anti-virus software, access iTunes

Unread postby peku006 » May 21st, 2009, 2:47 am

Hello and welcome to Malware Removal.

My name is peku006 and I will be helping you to remove any infection(s) that you may have.
I will be giving you a series of instructions that need to be followed in the order in which I give them to you.

Please observe these rules while we work:

  • I f you don't know or understand something please don't hesitate to ask
  • Please DO NOT run any other tools or scans whilst I am helping you.
  • It is important that you reply to this thread. Do not start a new topic.
  • Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
  • Absence of symptoms does not mean that everything is clear.

1 - Download and Run Malwarebytes' Anti-Malware
  1. Please download Malwarebytes' Anti-Malware and save it to a convenient location.
  2. Double click on mbam-setup.exe to install it.
  3. Before clicking the Finish button, make sure that these 2 boxes are checked (ticked):
      Update Malwarebytes' Anti-Malware
      Launch Malwarebytes' Anti-Malware
  4. Malwarebytes' Anti-Malware will now check for updates. If your firewall prompts, please allow it. If you can't update it, select the Update tab. Under Update Mirror, select one of the websites and click on Check for Updates.
  5. Select the Scanner tab. Click on Perform full scan, then click on Scan.
  6. Leave the default options as it is and click on Start Scan.
  7. When done, you will be prompted. Click OK, then click on Show Results.
  8. Checked (ticked) all items except items in the System Volume Information folder and click on Remove Selected.

    Image
  9. After it has removed the items, Notepad will open. Please post this log in your next reply. You can also find the log in the Logs tab. The bottom most log is the latest.

2 - download and run RSIT

  • Download random's system information tool (RSIT) by random/random from here and save it to your desktop.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt<- (will be maximized) and info.txt<- (will be minimized)

3 - Status Check
Please reply with

1.the logs from RSIT (log.txt ,info.txt)
2. the Malwarebytes' Anti-Malware Log
description of any problems you are having with your PC

Thanks peku006
User avatar
peku006
MRU Emeritus
MRU Emeritus
 
Posts: 3357
Joined: May 14th, 2007, 2:18 pm
Location: Norway

Re: Can't update anti-virus software, access iTunes

Unread postby cheetahmeow » May 21st, 2009, 4:57 am

Thank you for helping me. I really appreciate it.

I downloaded Malwarebytes. When I tried to update it I received the error message "Make sure you are connected to the internet and your firewall is set to allow Malwarebytes Anti-Malware to access the internet."

I couldn't find anything that read "Update Mirror" (or maybe that's some term I'm not familiar with?). I opened Windows Firewall. I clicked on exceptions. I browsed to find Malwarebytes. I added it to the list. It is checked.

I then went back to the program and clicked on update. I received the same message. It's much like the message that I'm getting from iTunes, Avira and Barnes & Nobel MP3.

I went ahead and ran a scan. The scan didn't find anything. Here are the log results. Results from the other program you asked me to run follow:
Malwarebytes' Anti-Malware 1.36
Database version: 1945
Windows 5.1.2600 Service Pack 3

5/21/2009 10:36:32 AM
mbam-log-2009-05-21 (10-36-32).txt

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 117674
Time elapsed: 41 minute(s), 11 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)




info.txt logfile of random's system information tool 1.06 2009-05-21 10:50:00

======Uninstall list======

-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
32 Bit HP CIO Components Installer-->MsiExec.exe /I{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}
Adobe AIR-->C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe -arp:uninstall
Adobe AIR-->MsiExec.exe /I{A2BCA9F1-566C-4805-97D1-7FDC93386723}
Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Media Player-->MsiExec.exe /X{9455959E-D588-EFAE-329C-F66CC797F32A}
Adobe Reader 8.1.0-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81000000003}
Apple Mobile Device Support-->MsiExec.exe /I{EC4455AB-F155-4CC1-A4C5-88F3777F9886}
Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
Atheros WLAN Client-->C:\Program Files\InstallShield Installation Information\{F4F41D14-E0DD-4FB4-AA09-A14225C769BD}\setup.exe -runfromtemp -l0x0009 -removeonly
Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir Desktop\setup.exe /REMOVE
Bonjour-->MsiExec.exe /I{07287123-B8AC-41CE-8346-3D777245C35B}
Easy Display Manager-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{17283B95-21A8-4996-97DA-547A48DB266F}\setup.exe" -l0x9 -removeonly
Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_0531C63A913CC9D1.exe" /uninstall
HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Hotfix for Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
HP Customer Participation Program 9.0-->C:\Program Files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat
HP Deskjet All-In-One Software 9.0-->C:\Program Files\HP\Digital Imaging\{FA8A44D7-3E8A-4034-9C4F-088FA6B72BC4}\setup\hpzscr01.exe -datfile hposcr14.dat
HP Imaging Device Functions 9.0-->C:\Program Files\HP\Digital Imaging\DeviceManagement\hpzscr01.exe -datfile hpqbud01.dat
HP Photosmart Essential 2.01-->C:\Program Files\HP\Digital Imaging\PhotoSmartEssential\hpzscr01.exe -datfile hpqbud13.dat
HP Smart Web Printing-->MsiExec.exe /X{415CDA53-9100-476F-A7B2-476691E117C7}
HP Solution Center 9.0-->C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
HP Update-->MsiExec.exe /X{AB40272D-92AB-4F30-B36B-22EDE16F8FE5}
HPSSupply-->MsiExec.exe /X{487B0B9B-DCD4-440D-89A0-A6EDE1A545A3}
imagine digital freedom - Samsung-->MsiExec.exe /X{00AF10C1-44BD-4862-9D7F-24E6BA3E87FD}
Intel(R) Graphics Media Accelerator Driver-->C:\WINDOWS\system32\igxpun.exe -uninstall
iTunes-->MsiExec.exe /I{318AB667-3230-41B5-A617-CB3BF748D371}
J2SE Runtime Environment 5.0-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150000}
Java(TM) 6 Update 11-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216011FF}
Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
Magic Keyboard-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BD723E53-A42C-4702-AA04-1D74A0311590}\Setup.exe" -l0x9 Remove
Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Marvell Miniport Driver-->C:\Program Files\Marvell\Miniport Driver\Uninst.exe
Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
Mozilla Firefox (3.0.10)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 4.0 SP2 Parser and SDK-->MsiExec.exe /I{716E0306-8318-4364-8B8F-0CC4E9376BAC}
Namuga 1.3M Webcam-->C:\Program Files\InstallShield Installation Information\{71A51B59-E7D3-11DB-A386-005056C00008}\setup.exe -runfromtemp -l0x0009 -removeonly
OpenOffice.org 3.0-->MsiExec.exe /I{F44DA61E-720D-4E79-871F-F6E628B33242}
OverDrive Media Console-->MsiExec.exe /I{34D6EED8-7650-4E1C-BC26-F5B2DDE185C6}
Picasa 3-->"C:\Program Files\Google\Picasa3\Uninstall.exe"
Play Camera-->C:\Program Files\InstallShield Installation Information\{7B46F9CF-CF60-492E-816E-95EB1A9D1BB4}\setup.exe -runfromtemp -l0x0409
QuickTime-->MsiExec.exe /I{F958CA02-BB40-4007-894B-258729456EE4}
Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\setup.exe" -l0x9 -removeonly
Samsung Battery Manager-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6F730513-8688-4C3C-90A3-6B9792CE2EF3}\Setup.exe" -l0x9 Remove
Samsung EDS-->MsiExec.exe /X{ABB14904-A11B-4F42-996C-80FD608A0F17}
Samsung Magic Doctor-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{32D6A58F-9659-446C-BBFC-E6F2B41F24DC}\Setup.exe" -l0x9 Remove
Samsung Network Manager 2.0-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\10\INTEL3~1\IDriver.exe /M{DEA48EFD-22C1-4CD6-B887-EB2E6B2E4735} /l1033
Samsung Recovery Solution III-->"C:\Program Files\InstallShield Installation Information\{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}\setup.exe" -runfromtemp -l0x0009 -removeonly
Samsung Update Plus-->"C:\Program Files\InstallShield Installation Information\{A5F483F0-2D79-4FCA-AE09-D0D96E23EBF7}\setup.exe" -runfromtemp -l0x0409 -removeonly
Samsung Update Plus-->MsiExec.exe /X{A5F483F0-2D79-4FCA-AE09-D0D96E23EBF7}
Security Update for Windows Internet Explorer 7 (KB938127-v2)-->"C:\WINDOWS\ie7updates\KB938127-v2-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB960714)-->"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB961260)-->"C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB963027)-->"C:\WINDOWS\ie7updates\KB963027-IE7\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
Security Update for Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
Security Update for Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956390)-->"C:\WINDOWS\$NtUninstallKB956390$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958690)-->"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
Security Update for Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB961373)-->"C:\WINDOWS\$NtUninstallKB961373$\spuninst\spuninst.exe"
Skype™ 3.8-->MsiExec.exe /X{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}
Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
Uninstall Star Alliance Mileage Calculator-->"C:\Program Files\Star Alliance Mileage Calculator\unins000.exe"
Update for Windows XP (KB898461)-->"C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe"
Update for Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
Update for Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
Update for Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
Update for Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
User Guide-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BAE68339-B0F6-4D33-9554-5A3DB2DFF5DA}\setup.exe" -l0x9 Remove
WD Diagnostics-->MsiExec.exe /X{0AB76F69-E761-4CFA-B9B0-A1906B4E9E4B}
WIDCOMM Bluetooth Software-->MsiExec.exe /X{84814E6B-2581-46EC-926A-823BD1C670F6}
Windows Internet Explorer 7-->"C:\WINDOWS\ie7\spuninst\spuninst.exe"

======Security center information======

AV: AntiVir Desktop (outdated)

======System event log======

Computer Name: SARA
Event Code: 1001
Message: Your computer was not assigned an address from the network (by the DHCP
Server) for the Network Card with network address 002163882B60. The following error
occurred:
The operation was canceled by the user.
.
Your computer will continue to try and obtain an address on its own from
the network address (DHCP) server.

Record Number: 4391
Source Name: Dhcp
Time Written: 20090217214621.000000+060
Event Type: error
User:

Computer Name: SARA
Event Code: 1003
Message: Your computer was not able to renew its address from the network (from the
DHCP Server) for the Network Card with network address 002163882B60. The following
error occurred:
The operation was canceled by the user.
.
Your computer will continue to try and obtain an address on its own from
the network address (DHCP) server.

Record Number: 4389
Source Name: Dhcp
Time Written: 20090217214620.000000+060
Event Type: warning
User:

Computer Name: SARA
Event Code: 1007
Message: Your computer has automatically configured the IP address for the Network
Card with network address 001377ADB049. The IP address being used is 169.254.40.89.

Record Number: 4358
Source Name: Dhcp
Time Written: 20090217185010.000000+060
Event Type: warning
User:

Computer Name: SARA
Event Code: 1000
Message: Your computer has lost the lease to its IP address 192.168.1.2 on the
Network Card with network address 002163882B60.

Record Number: 4336
Source Name: Dhcp
Time Written: 20090217151941.000000+060
Event Type: error
User:

Computer Name: SARA
Event Code: 1003
Message: Your computer was not able to renew its address from the network (from the
DHCP Server) for the Network Card with network address 002163882B60. The following
error occurred:
The semaphore timeout period has expired.
.
Your computer will continue to try and obtain an address on its own from
the network address (DHCP) server.

Record Number: 4335
Source Name: Dhcp
Time Written: 20090217151941.000000+060
Event Type: warning
User:

=====Application event log=====

Computer Name: SARA
Event Code: 10005
Message: Product: iTunes -- A later version of iTunes is already installed on this computer.

Record Number: 194
Source Name: MsiInstaller
Time Written: 20081127195818.000000+060
Event Type: error
User: SARA\Sara Helen

Computer Name: SARA
Event Code: 1001
Message: Fault bucket 529734960.

Record Number: 116
Source Name: Application Hang
Time Written: 20081121100342.000000+060
Event Type: error
User:

Computer Name: SARA
Event Code: 1002
Message: Hanging application iexplore.exe, version 7.0.5730.13, hang module hungapp, version 0.0.0.0, hang address 0x00000000.

Record Number: 115
Source Name: Application Hang
Time Written: 20081121100329.000000+060
Event Type: error
User:

Computer Name: SARA
Event Code: 1002
Message: Hanging application IEXPLORE.EXE, version 6.0.2900.5512, hang module hungapp, version 0.0.0.0, hang address 0x00000000.

Record Number: 87
Source Name: Application Hang
Time Written: 20081120164653.000000+060
Event Type: error
User:

Computer Name: SARA
Event Code: 1517
Message: Windows saved user SARA\Sara Helen registry while an application or service was still using the registry during log off. The memory used by the user's registry has not been freed. The registry will be unloaded when it is no longer in use.


This is often caused by services running as a user account, try configuring the services to run in either the LocalService or NetworkService account.

Record Number: 78
Source Name: Userenv
Time Written: 20081120124615.000000+060
Event Type: warning
User: NT AUTHORITY\SYSTEM

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\QuickTime\QTSystem\
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 28 Stepping 2, GenuineIntel
"PROCESSOR_REVISION"=1c02
"NUMBER_OF_PROCESSORS"=2
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"CLASSPATH"=.;C:\Program Files\Java\jre1.6.0_07\lib\ext\QTJava.zip
"QTJAVA"=C:\Program Files\Java\jre1.6.0_07\lib\ext\QTJava.zip

-----------------EOF-----------------


Logfile of random's system information tool 1.06 (written by random/random)
Run by Sara Helen at 2009-05-21 10:49:50
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 10 GB (14%) free of 73 GB
Total RAM: 1014 MB (42% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:49:57 AM, on 5/21/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\samsung\Samsung Network Manager\SNMWLANService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Samsung\Samsung EDS\EDSAgent.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Samsung\Samsung Battery Manager\BatteryManager.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SAMSUNG\MagicKBD\MagicKBD.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\SAMSUNG\MagicKBD\PerformanceManager.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\igfxext.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Sara Helen\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Sara Helen.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/ig?hl=en&source=iglk
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = proxy.net.sy.3028
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.0.1:80
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [EDS] C:\Program Files\Samsung\Samsung EDS\EDSAgent.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [DMHotKey] C:\Program Files\Samsung\Easy Display Manager\DMLoader.exe
O4 - HKLM\..\Run: [BatteryManager] C:\Program Files\Samsung\Samsung Battery Manager\BatteryManager.exe
O4 - HKLM\..\Run: [MagicKeyboard] C:\Program Files\SAMSUNG\MagicKBD\PreMKBD.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SUPBackGround] C:\Program Files\Samsung\Samsung Update Plus\SUPBackGround.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/200 ... oader5.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: SNM WLAN Service - Unknown owner - C:\Program Files\samsung\Samsung Network Manager\SNMWLANService.exe

--
End of file - 9638 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\Low Battery Alarm Program.job
C:\WINDOWS\tasks\User_Feed_Synchronization-{0F981175-FD05-4D51-828A-B541A73A10BA}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]
HP Print Enhancer - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll [2007-03-02 1298024]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{053F9267-DC04-4294-A72C-58F732D338C0}]
HP Print Clips - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll [2007-03-02 177768]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-23 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
Skype add-on (mastermind) - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2008-11-07 1088296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2009-01-08 320920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll [2009-02-15 251504]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll [2009-02-16 657904]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]
Google Dictionary Compression sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll [2009-02-15 522224]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-01-08 34816]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-01-08 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll [2009-02-15 251504]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-01-08 136600]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2008-08-26 16851456]
"Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2008-06-20 57344]
""= []
"EDS"=C:\Program Files\Samsung\Samsung EDS\EDSAgent.exe [2007-12-21 659456]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2008-02-29 141848]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2008-02-29 166424]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2008-02-29 137752]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2008-08-28 1044480]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2007-05-11 40048]
"DMHotKey"=C:\Program Files\Samsung\Easy Display Manager\DMLoader.exe [2006-12-28 466944]
"BatteryManager"=C:\Program Files\Samsung\Samsung Battery Manager\BatteryManager.exe [2007-10-31 2768896]
"MagicKeyboard"=C:\Program Files\SAMSUNG\MagicKBD\PreMKBD.exe [2006-05-15 151552]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2008-11-04 413696]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2008-11-20 290088]
"SUPBackGround"=C:\Program Files\Samsung\Samsung Update Plus\SUPBackGround.exe [2008-10-27 298664]
"HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2007-03-11 49152]
"avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2009-03-02 209153]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Malwarebytes' Anti-Malware"=C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [2009-04-06 401040]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-02-16 39408]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

C:\Documents and Settings\Sara Helen\Start Menu\Programs\Startup
OpenOffice.org 3.0.lnk - C:\Program Files\OpenOffice.org 3\program\quickstart.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2008-02-15 208896]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Documents and Settings\Sara Helen\Desktop\fact.exe"="C:\Documents and Settings\Sara Helen\Desktop\fact.exe:*:Enabled:fact"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe"="C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe:*:Enabled:Malwarebytes' Anti-Malware"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6feab993-be1b-11dd-bb3f-001377adb049}]
shell\AutoRun\command - E:\wd_windows_tools\setup.exe


======List of files/folders created in the last 1 months======

2009-05-21 10:49:50 ----D---- C:\rsit
2009-05-21 09:42:37 ----D---- C:\Documents and Settings\Sara Helen\Application Data\Malwarebytes
2009-05-21 09:42:28 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2009-05-21 09:42:27 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-05-11 16:48:37 ----D---- C:\Program Files\Trend Micro
2009-05-08 16:26:24 ----D---- C:\Program Files\Avira
2009-05-08 16:26:24 ----D---- C:\Documents and Settings\All Users\Application Data\Avira
2009-05-08 16:25:37 ----SHD---- C:\Config.Msi
2009-05-08 13:01:40 ----D---- C:\Documents and Settings\Sara Helen\Application Data\HP
2009-05-04 09:51:44 ----D---- C:\Program Files\OverDrive Media Console
2009-04-30 03:32:08 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
2009-04-30 03:31:54 ----HDC---- C:\WINDOWS\$NtUninstallKB961373$
2009-04-30 03:30:58 ----HDC---- C:\WINDOWS\$NtUninstallKB960225$
2009-04-25 22:52:01 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
2009-04-25 22:51:43 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
2009-04-25 22:51:33 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
2009-04-25 22:51:25 ----HDC---- C:\WINDOWS\$NtUninstallKB958690$
2009-04-25 22:51:18 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
2009-04-25 22:51:07 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
2009-04-25 03:48:15 ----N---- C:\WINDOWS\system32\xpsp4res.dll

======List of files/folders modified in the last 1 months======

2009-05-21 10:49:57 ----D---- C:\WINDOWS\Prefetch
2009-05-21 09:44:46 ----D---- C:\WINDOWS\system32\drivers
2009-05-21 09:42:27 ----RD---- C:\Program Files
2009-05-21 09:04:04 ----D---- C:\WINDOWS\Temp
2009-05-21 07:48:04 ----D---- C:\Program Files\Mozilla Firefox
2009-05-20 17:15:25 ----D---- C:\WINDOWS\system32\CatRoot2
2009-05-20 16:13:14 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-05-20 13:24:41 ----D---- C:\Documents and Settings\Sara Helen\Application Data\Skype
2009-05-19 10:51:05 ----D---- C:\Documents and Settings\Sara Helen\Application Data\skypePM
2009-05-12 23:19:16 ----D---- C:\Documents and Settings\Sara Helen\Application Data\Apple Computer
2009-05-11 11:41:28 ----D---- C:\WINDOWS\Network Diagnostic
2009-05-08 17:23:44 ----D---- C:\Program Files\Star Alliance Mileage Calculator
2009-05-08 17:13:30 ----D---- C:\WINDOWS\system32
2009-05-08 17:13:30 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-05-08 17:13:21 ----D---- C:\WINDOWS
2009-05-08 17:13:18 ----A---- C:\WINDOWS\imsins.BAK
2009-05-08 16:26:36 ----HD---- C:\WINDOWS\inf
2009-05-08 16:25:46 ----SHD---- C:\WINDOWS\Installer
2009-05-08 16:25:44 ----D---- C:\WINDOWS\WinSxS
2009-05-08 11:55:10 ----D---- C:\Documents and Settings\All Users\Application Data\avg8
2009-05-08 11:53:56 ----SD---- C:\Documents and Settings\Sara Helen\Application Data\Microsoft
2009-05-07 09:16:29 ----A---- C:\WINDOWS\system32\MRT.exe
2009-05-05 08:39:32 ----HD---- C:\$AVG8.VAULT$
2009-04-30 03:32:10 ----RSHDC---- C:\WINDOWS\system32\dllcache
2009-04-30 03:31:37 ----D---- C:\WINDOWS\system32\en-US
2009-04-30 03:31:37 ----D---- C:\Program Files\Internet Explorer
2009-04-29 18:44:19 ----D---- C:\WINDOWS\system32\wbem
2009-04-29 18:44:18 ----D---- C:\WINDOWS\AppPatch
2009-04-25 22:51:52 ----HD---- C:\WINDOWS\$hf_mig$

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys []
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2009-03-30 96104]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 36352]
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2009-02-13 28376]
R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2009-03-24 55640]
R2 DOSMEMIO;MEMIO; \??\C:\WINDOWS\system32\MEMIO.SYS []
R3 AR5416;Atheros AR5008 Wireless Network Adapter Service; C:\WINDOWS\system32\DRIVERS\athw.sys [2008-08-30 1318784]
R3 btaudio;Bluetooth Audio Device; C:\WINDOWS\system32\drivers\btaudio.sys [2007-03-23 539072]
R3 BTDriver;Bluetooth Virtual Communications Driver; C:\WINDOWS\system32\DRIVERS\btport.sys [2007-03-23 37424]
R3 BTKRNL;Bluetooth Bus Enumerator; C:\WINDOWS\system32\DRIVERS\btkrnl.sys [2007-03-31 876384]
R3 BTWDNDIS;Bluetooth LAN Access Server; C:\WINDOWS\system32\DRIVERS\btwdndis.sys [2007-03-23 149123]
R3 BTWUSB;WIDCOMM USB Bluetooth Driver; C:\WINDOWS\System32\Drivers\btwusb.sys [2007-03-23 67960]
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\WINDOWS\system32\DRIVERS\CmBatt.sys [2008-04-14 13952]
R3 DNSeFilter;DNSeFilter; C:\WINDOWS\system32\drivers\SamsungEDS.sys [2008-01-15 30208]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-14 144384]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\igxpmp32.sys [2008-02-15 5854752]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2008-08-27 4753920]
R3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\WINDOWS\system32\drivers\mbamswissarmy.sys []
R3 SynTP;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2008-08-28 224736]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-14 30208]
R3 usbhub;Microsoft USB Standard Hub Driver; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
R3 VMC326;Vimicro Camera Service VMC326; C:\WINDOWS\System32\Drivers\VMC326.sys [2008-09-04 238464]
R3 yukonwxp;NDIS5.1 Miniport Driver for Marvell Yukon Ethernet Controller; C:\WINDOWS\system32\DRIVERS\yk51x86.sys [2008-06-27 289024]
S1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
S3 ADDMEM;ADDMEM; \??\C:\WINDOWS\TEMP\__Samsung_Update\ADDMEM.SYS []
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-14 17024]
S3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2008-04-17 15464]
S3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2007-03-08 49920]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2007-03-08 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2007-03-08 21568]
S3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-14 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-14 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-14 10880]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-14 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-14 15232]
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-14 25856]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
S3 usbvideo;USB Video Device (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2008-04-14 121984]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-14 19200]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AntiVirSchedulerService;Avira AntiVir Scheduler; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2009-04-01 108289]
R2 AntiVirService;Avira AntiVir Guard; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2009-03-02 185089]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2008-11-07 132424]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe [2007-04-01 273256]
R2 hpqddsvc;HP CUE DeviceDiscovery Service; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-01-08 152984]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 SNM WLAN Service;SNM WLAN Service; C:\Program Files\samsung\Samsung Network Manager\SNMWLANService.exe [2006-10-30 36864]
R3 hpqcxs08;hpqcxs08; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2008-11-20 536872]
S2 Net Driver HPZ12;Net Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-02-16 137200]

-----------------EOF-----------------
cheetahmeow
Active Member
 
Posts: 10
Joined: May 16th, 2009, 10:21 am

Re: Can't update anti-virus software, access iTunes

Unread postby peku006 » May 21st, 2009, 10:11 am

Hi cheetahmeow

it seems that you have a problem with internet connection... we can try these first

Go to Start -> Control Panel, and choose Network Connections. Then right click on your default connection, usually Local Area Connection or Dial-up Connection if you are using Dial-up, and left click on properties. Double-click on the Internet Protocol (TCP/IP) item and select the radio button that says Obtain DNS servers automatically. Click OK twice, and restart your computer.

Start-->Run, type in CMD to bring up command prompt.
At the C: prompt, type in ipconfig /release and hit enter.
(type)ipconfig /renew and hit enter.

After that, Reboot.

post back if it helped.

Thanks peku006
User avatar
peku006
MRU Emeritus
MRU Emeritus
 
Posts: 3357
Joined: May 14th, 2007, 2:18 pm
Location: Norway

Re: Can't update anti-virus software, access iTunes

Unread postby cheetahmeow » May 21st, 2009, 11:19 am

Sorry. That didn't help.

My default connection is wireless. I checked the setting and the radio button was already checked as you suggested.

My connection works fine as long as I use Firefox. The connection does not work with IE. I also can't get updates with Avira, iTunes, etc. Someone had suggested this was a sign of malware.

Any other ideas?

Thanks!
cheetahmeow
Active Member
 
Posts: 10
Joined: May 16th, 2009, 10:21 am

Re: Can't update anti-virus software, access iTunes

Unread postby peku006 » May 21st, 2009, 1:58 pm

Hi cheetahmeow
Let us take a deeper look

Please download OTSfrom Geeks to Go by OldTimer. Alternate download site.
Save it to your desktop.
  1. Double click on OTS.exe to run it.
  2. Click on Extract. Once done, when prompted. Click OK and click Close.
    This is a self-extracting file...It will create a folder named OTS. on your desktop.
  3. Double click on the OTS folder to open... then double click on OTS.exe.exe to run it.
  4. Under Rookit Search, select Yes.
  5. Click on Run Scan at the top left hand corner. It may take a few minutes...be patient, let it run.
  6. When done, Notepad will open with the log file "OTS.Txt" contents.
Please post the contents of the OTS.Txt Notepad file in your next reply.

Thanks peku006
User avatar
peku006
MRU Emeritus
MRU Emeritus
 
Posts: 3357
Joined: May 14th, 2007, 2:18 pm
Location: Norway

Re: Can't update anti-virus software, access iTunes

Unread postby cheetahmeow » May 21st, 2009, 3:17 pm

Done!
Code: Select all
OTS logfile created on: 5/21/2009 9:03:37 PM - Run 1
OTS by OldTimer - Version 3.0.2.4     Folder = C:\Documents and Settings\Sara Helen\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
1014.36 Mb Total Physical Memory | 382.57 Mb Available Physical Memory | 37.72% Memory free
2.39 Gb Paging File | 1.82 Gb Available in Paging File | 76.08% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 71.04 Gb Total Space | 10.10 Gb Free Space | 14.22% Space Free | Partition Type: NTFS
Drive D: | 72.00 Gb Total Space | 64.36 Gb Free Space | 89.39% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
 
Computer Name: SARA
Current User Name: Sara Helen
Logged in as Administrator.
 
Current Boot Mode: Normal
Scan Mode: Current user
Whitelist: On
File Age = 30 Days
 
[Processes - Safe List]
applemobiledeviceservice.exe -> C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> [2008/11/07 14:28:16 | 00,132,424 | ---- | M] (Apple Inc.)
avgnt.exe -> C:\Program Files\Avira\AntiVir Desktop\avgnt.exe -> [2009/03/02 13:08:47 | 00,209,153 | ---- | M] (Avira GmbH)
avguard.exe -> C:\Program Files\Avira\AntiVir Desktop\avguard.exe -> [2009/03/02 13:10:30 | 00,185,089 | ---- | M] (Avira GmbH)
batterymanager.exe -> C:\Program Files\Samsung\Samsung Battery Manager\BatteryManager.exe -> [2007/10/31 20:33:54 | 02,768,896 | ---- | M] ()
btstac~1.exe -> C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe -> [2007/04/01 11:02:38 | 01,416,072 | ---- | M] (Broadcom Corporation.)
bttray.exe -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe -> [2007/04/01 11:02:38 | 00,568,176 | ---- | M] (Broadcom Corporation.)
btwdins.exe -> C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe -> [2007/04/01 11:02:36 | 00,273,256 | ---- | M] (Broadcom Corporation.)
dmhkcore.exe -> C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe -> [2008/07/09 18:03:26 | 00,679,936 | ---- | M] (SAMSUNG Electronics)
edsagent.exe -> C:\Program Files\Samsung\Samsung EDS\EDSAgent.exe -> [2007/12/21 05:40:30 | 00,659,456 | ---- | M] (Samsung Electronics,.LTD)
explorer.exe -> C:\WINDOWS\Explorer.EXE -> [2008/04/14 14:00:00 | 01,033,728 | ---- | M] (Microsoft Corporation)
firefox.exe -> C:\Program Files\Mozilla Firefox\firefox.exe -> [2009/05/06 08:05:40 | 00,307,704 | ---- | M] (Mozilla Corporation)
fotki.exe -> C:\Program Files\Fotki Desktop\fotki.exe -> [2008/08/08 13:18:20 | 02,001,920 | ---- | M] (fotki.com)
googletoolbarnotifier.exe -> C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe -> [2009/02/16 18:11:33 | 00,039,408 | ---- | M] (Google Inc.)
hkcmd.exe -> C:\WINDOWS\System32\hkcmd.exe -> [2008/02/29 00:00:04 | 00,166,424 | ---- | M] (Intel Corporation)
hpqste08.exe -> C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe -> [2007/03/11 22:32:42 | 00,151,552 | ---- | M] (Hewlett-Packard Co.)
hpqtra08.exe -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe -> [2007/03/11 22:26:24 | 00,210,520 | ---- | M] (Hewlett-Packard Co.)
hpwuschd2.exe -> C:\Program Files\HP\HP Software Update\HPWuSchd2.exe -> [2007/03/11 22:34:40 | 00,049,152 | ---- | M] (Hewlett-Packard Co.)
igfxext.exe -> C:\WINDOWS\System32\igfxext.exe -> [2008/02/29 00:00:10 | 00,170,520 | ---- | M] (Intel Corporation)
igfxpers.exe -> C:\WINDOWS\System32\igfxpers.exe -> [2008/02/29 00:00:14 | 00,137,752 | ---- | M] (Intel Corporation)
igfxsrvc.exe -> C:\WINDOWS\System32\igfxsrvc.exe -> [2008/02/29 00:00:16 | 00,256,536 | ---- | M] (Intel Corporation)
igfxtray.exe -> C:\WINDOWS\System32\igfxtray.exe -> [2008/02/29 00:00:20 | 00,141,848 | ---- | M] (Intel Corporation)
ipodservice.exe -> C:\Program Files\iPod\bin\iPodService.exe -> [2008/11/20 13:20:44 | 00,536,872 | ---- | M] (Apple Inc.)
ituneshelper.exe -> C:\Program Files\iTunes\iTunesHelper.exe -> [2008/11/20 13:20:54 | 00,290,088 | ---- | M] (Apple Inc.)
java.exe -> C:\Program Files\Java\jre6\bin\java.exe -> [2009/01/08 18:57:22 | 00,144,792 | ---- | M] (Sun Microsystems, Inc.)
jqs.exe -> C:\Program Files\Java\jre6\bin\jqs.exe -> [2009/01/08 18:57:24 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.)
jusched.exe -> C:\Program Files\Java\jre6\bin\jusched.exe -> [2009/01/08 18:57:24 | 00,136,600 | ---- | M] (Sun Microsystems, Inc.)
magickbd.exe -> C:\Program Files\SAMSUNG\MagicKBD\MagicKBD.exe -> [2008/05/21 05:02:08 | 00,372,736 | ---- | M] (SAMSUNG Electronics Co., Ltd.)
mdnsresponder.exe -> C:\Program Files\Bonjour\mDNSResponder.exe -> [2008/12/12 12:17:38 | 00,238,888 | ---- | M] (Apple Inc.)
ots.exe -> C:\Documents and Settings\Sara Helen\Desktop\OTS.exe -> [2009/05/21 21:00:48 | 00,504,320 | ---- | M] (OldTimer Tools)
performancemanager.exe -> C:\Program Files\SAMSUNG\MagicKBD\PerformanceManager.exe -> [2008/05/22 01:44:30 | 00,299,008 | ---- | M] (Samsung Electronics Co., Ltd.)
rthdcpl.exe -> C:\WINDOWS\RTHDCPL.EXE -> [2008/08/26 22:51:00 | 16,851,456 | ---- | M] (Realtek Semiconductor Corp.)
sched.exe -> C:\Program Files\Avira\AntiVir Desktop\sched.exe -> [2009/04/01 15:46:23 | 00,108,289 | ---- | M] (Avira GmbH)
snmwlanservice.exe -> C:\Program Files\samsung\Samsung Network Manager\SNMWLANService.exe -> [2006/10/30 23:29:28 | 00,036,864 | ---- | M] ()
soffice.bin -> C:\Program Files\OpenOffice.org 3\program\soffice.bin -> [2009/01/09 21:00:52 | 07,418,368 | ---- | M] (OpenOffice.org)
soffice.exe -> C:\Program Files\OpenOffice.org 3\program\soffice.exe -> [2009/01/09 20:57:32 | 07,424,000 | ---- | M] (OpenOffice.org)
syntpenh.exe -> C:\Program Files\Synaptics\SynTP\SynTPEnh.exe -> [2008/08/28 20:34:52 | 01,044,480 | ---- | M] (Synaptics, Inc.)
wscntfy.exe -> C:\WINDOWS\System32\wscntfy.exe -> [2008/04/14 14:00:00 | 00,013,824 | ---- | M] (Microsoft Corporation)
 
[Win32 Services - Safe List]
(AntiVirSchedulerService) Avira AntiVir Scheduler [Win32_Own | Auto | Running] -> C:\Program Files\Avira\AntiVir Desktop\sched.exe -> [2009/04/01 15:46:23 | 00,108,289 | ---- | M] (Avira GmbH)
(AntiVirService) Avira AntiVir Guard [Win32_Own | Auto | Running] -> C:\Program Files\Avira\AntiVir Desktop\avguard.exe -> [2009/03/02 13:10:30 | 00,185,089 | ---- | M] (Avira GmbH)
(Apple Mobile Device) Apple Mobile Device [Win32_Own | Auto | Running] -> C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> [2008/11/07 14:28:16 | 00,132,424 | ---- | M] (Apple Inc.)
(Bonjour Service) Bonjour Service [Win32_Own | Auto | Running] -> C:\Program Files\Bonjour\mDNSResponder.exe -> [2008/12/12 12:17:38 | 00,238,888 | ---- | M] (Apple Inc.)
(btwdins) Bluetooth Service [Win32_Own | Auto | Running] -> C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe -> [2007/04/01 11:02:36 | 00,273,256 | ---- | M] (Broadcom Corporation.)
(gusvc) Google Updater Service [Win32_Own | On_Demand | Stopped] -> C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe -> [2009/02/16 18:11:24 | 00,137,200 | ---- | M] (Google)
(helpsvc) Help and Support [Win32_Shared | Auto | Running] -> C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -> [2008/04/14 14:00:00 | 00,038,400 | ---- | M] (Microsoft Corporation)
(hpqcxs08) hpqcxs08 [Win32_Shared | On_Demand | Running] -> C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll -> [2007/06/04 23:14:50 | 00,217,088 | ---- | M] (Hewlett-Packard Co.)
(hpqddsvc) HP CUE DeviceDiscovery Service [Win32_Shared | Auto | Running] -> C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll -> [2007/06/04 23:14:50 | 00,131,072 | ---- | M] (Hewlett-Packard Co.)
(iPod Service) iPod Service [Win32_Own | On_Demand | Running] -> C:\Program Files\iPod\bin\iPodService.exe -> [2008/11/20 13:20:44 | 00,536,872 | ---- | M] (Apple Inc.)
(JavaQuickStarterService) Java Quick Starter [Win32_Own | Auto | Running] -> C:\Program Files\Java\jre6\bin\jqs.exe -> [2009/01/08 18:57:24 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.)
(Net Driver HPZ12) Net Driver HPZ12 [Win32_Own | Auto | Running] -> C:\WINDOWS\System32\HPZinw12.dll -> [2006/11/08 17:35:36 | 00,043,520 | ---- | M] (Hewlett-Packard)
(Pml Driver HPZ12) Pml Driver HPZ12 [Win32_Own | Auto | Running] -> C:\WINDOWS\System32\HPZipm12.dll -> [2006/11/08 17:35:38 | 00,053,248 | ---- | M] (Hewlett-Packard)
(SNM WLAN Service) SNM WLAN Service [Win32_Own | Auto | Running] -> C:\Program Files\samsung\Samsung Network Manager\SNMWLANService.exe -> [2006/10/30 23:29:28 | 00,036,864 | ---- | M] ()
 
[Driver Services - Safe List]
(AR5416) Atheros AR5008 Wireless Network Adapter Service [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\athw.sys -> [2008/08/30 20:46:56 | 01,318,784 | ---- | M] (Atheros Communications, Inc.)
(avgio) avgio [Kernel | System | Running] -> C:\Program Files\Avira\AntiVir Desktop\avgio.sys -> [2009/02/13 12:35:05 | 00,011,608 | ---- | M] (Avira GmbH)
(avgntflt) avgntflt [File_System | Auto | Running] -> C:\WINDOWS\System32\DRIVERS\avgntflt.sys -> [2009/03/24 16:08:22 | 00,055,640 | ---- | M] (Avira GmbH)
(avipbb) avipbb [Kernel | System | Running] -> C:\WINDOWS\System32\DRIVERS\avipbb.sys -> [2009/03/30 10:33:07 | 00,096,104 | ---- | M] (Avira GmbH)
(btaudio) Bluetooth Audio Device [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\drivers\btaudio.sys -> [2007/03/23 19:49:54 | 00,539,072 | ---- | M] (Broadcom Corporation.)
(BTDriver) Bluetooth Virtual Communications Driver [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\btport.sys -> [2007/03/23 19:50:08 | 00,037,424 | ---- | M] (Broadcom Corporation.)
(BTKRNL) Bluetooth Bus Enumerator [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\btkrnl.sys -> [2007/03/31 22:02:42 | 00,876,384 | ---- | M] (Broadcom Corporation.)
(BTWDNDIS) Bluetooth LAN Access Server [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\btwdndis.sys -> [2007/03/23 19:50:24 | 00,149,123 | ---- | M] (Broadcom Corporation.)
(BTWUSB) WIDCOMM USB Bluetooth Driver [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\Drivers\btwusb.sys -> [2007/03/23 19:50:42 | 00,067,960 | ---- | M] (Broadcom Corporation.)
(DNSeFilter) DNSeFilter [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\drivers\SamsungEDS.sys -> [2008/01/15 04:01:02 | 00,030,208 | ---- | M] (Samsung Electronics,.LTD)
(DOSMEMIO) MEMIO [Kernel | Auto | Running] -> C:\WINDOWS\System32\MEMIO.SYS -> [2005/10/27 06:18:05 | 00,004,300 | ---- | M] ()
(GEARAspiWDM) GEAR ASPI Filter Driver [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\DRIVERS\GEARAspiWDM.sys -> [2008/04/17 15:12:54 | 00,015,464 | ---- | M] (GEAR Software Inc.)
(HDAudBus) Microsoft UAA Bus Driver for High Definition Audio [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\HDAudBus.sys -> [2008/04/14 14:00:00 | 00,144,384 | ---- | M] (Windows (R) Server 2003 DDK provider)
(HPZid412) IEEE-1284.4 Driver HPZid412 [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\DRIVERS\HPZid412.sys -> [2007/03/08 21:20:48 | 00,049,920 | ---- | M] (HP)
(HPZipr12) Print Class Driver for IEEE-1284.4 HPZipr12 [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\DRIVERS\HPZipr12.sys -> [2007/03/08 21:20:49 | 00,016,496 | ---- | M] (HP)
(HPZius12) USB to IEEE-1284.4 Translation Driver HPZius12 [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\DRIVERS\HPZius12.sys -> [2007/03/08 21:20:50 | 00,021,568 | ---- | M] (HP)
(ialm) ialm [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\igxpmp32.sys -> [2008/02/15 22:12:06 | 05,854,752 | ---- | M] (Intel Corporation)
(IntcAzAudAddService) Service for Realtek HD Audio (WDM) [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\drivers\RtkHDAud.sys -> [2008/08/27 01:35:00 | 04,753,920 | ---- | M] (Realtek Semiconductor Corp.)
(Ptilink) Direct Parallel Link Driver [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\ptilink.sys -> [2008/04/14 14:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.)
(PxHelp20) PxHelp20 [Kernel | Boot | Running] -> C:\WINDOWS\System32\Drivers\PxHelp20.sys -> [2008/08/01 00:17:04 | 00,043,872 | ---- | M] (Sonic Solutions)
(Secdrv) Secdrv [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\DRIVERS\secdrv.sys -> [2008/04/14 14:00:00 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
(ssmdrv) ssmdrv [Kernel | System | Running] -> C:\WINDOWS\System32\DRIVERS\ssmdrv.sys -> [2009/02/13 12:50:02 | 00,028,376 | ---- | M] (Avira GmbH)
(SynTP) Synaptics TouchPad Driver [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\SynTP.sys -> [2008/08/28 20:18:14 | 00,224,736 | ---- | M] (Synaptics, Inc.)
(VMC326) Vimicro Camera Service VMC326 [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\Drivers\VMC326.sys -> [2008/09/04 10:05:34 | 00,238,464 | ---- | M] (Vimicro Corporation)
(yukonwxp) NDIS5.1 Miniport Driver for Marvell Yukon Ethernet Controller [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\yk51x86.sys -> [2008/06/27 10:02:00 | 00,289,024 | ---- | M] (Marvell)
 
[Registry - Safe List]
< Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> -> 
HKEY_LOCAL_MACHINE\: Main\\"Default_Page_URL" -> http://go.microsoft.com/fwlink/?LinkId=69157 -> 
HKEY_LOCAL_MACHINE\: Main\\"Default_Search_URL" -> http://go.microsoft.com/fwlink/?LinkId=54896 -> 
HKEY_LOCAL_MACHINE\: Main\\"Default_Secondary_Page_URL" ->  [binary data] -> 
HKEY_LOCAL_MACHINE\: Main\\"Extensions Off Page" -> about:NoAdd-ons -> 
HKEY_LOCAL_MACHINE\: Main\\"Local Page" -> %SystemRoot%\system32\blank.htm -> 
HKEY_LOCAL_MACHINE\: Main\\"Search Page" -> http://go.microsoft.com/fwlink/?LinkId=54896 -> 
HKEY_LOCAL_MACHINE\: Main\\"Security Risk Page" -> about:SecurityRisk -> 
HKEY_LOCAL_MACHINE\: Main\\"Start Page" -> http://go.microsoft.com/fwlink/?LinkId=69157 -> 
HKEY_LOCAL_MACHINE\: Search\\"CustomizeSearch" -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm -> 
HKEY_LOCAL_MACHINE\: Search\\"SearchAssistant" -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm -> 
< Internet Explorer Settings [HKEY_CURRENT_USER\] > -> -> 
HKEY_CURRENT_USER\: Main\\"Local Page" -> C:\WINDOWS\system32\blank.htm -> 
HKEY_CURRENT_USER\: Main\\"Search Page" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> 
HKEY_CURRENT_USER\: Main\\"Start Page" -> http://www.google.co.uk/ig?hl=en&source=iglk -> 
HKEY_CURRENT_USER\: "ProxyEnable" -> 1 -> 
HKEY_CURRENT_USER\: "ProxyOverride" -> *.local -> 
< FireFox Settings [Prefs.js] > -> C:\Documents and Settings\Sara Helen\Application Data\Mozilla\FireFox\Profiles\36qyo7z0.default\prefs.js -> 
browser.startup.homepage -> "http://www.google.co.uk/ig?hl=en&source=iglk" ->
extensions.enabledItems -> {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.10 ->
< FireFox Extensions [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla
HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions ->  -> 
HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Components -> C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS] -> [2009/05/06 08:05:56 | 00,000,000 | ---D | M]
HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Plugins -> C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS] -> [2009/05/06 08:05:56 | 00,000,000 | ---D | M]
< FireFox Extensions [User Folders] > -> 
 -> C:\Documents and Settings\Sara Helen\Application Data\mozilla\Extensions -> [2009/02/19 13:35:09 | 00,000,000 | ---D | M]
 -> C:\Documents and Settings\Sara Helen\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} -> [2009/02/19 13:35:09 | 00,000,000 | ---D | M]
 -> C:\Documents and Settings\Sara Helen\Application Data\mozilla\Firefox\Profiles\36qyo7z0.default\extensions -> [2009/05/08 12:05:35 | 00,096,354 | ---- | M] ()
< FireFox Extensions [Program Folders] > -> 
 -> C:\PROGRAM FILES\MOZILLA FIREFOX\extensions -> [2009/05/06 08:05:56 | 09,756,664 | ---- | M] (Mozilla Foundation)
 -> C:\PROGRAM FILES\MOZILLA FIREFOX\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} -> [2009/05/06 08:05:56 | 09,756,664 | ---- | M] (Mozilla Foundation)
< FireFox Components [Program Folders] > -> 
C:\PROGRAM FILES\MOZILLA FIREFOX\components\ -> C:\PROGRAM FILES\MOZILLA FIREFOX\components -> [2009/05/06 08:05:56 | 00,000,000 | ---D | M]
browserdirprovider.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\components\browserdirprovider.dll -> [2009/05/06 08:05:32 | 00,023,032 | ---- | M] (Mozilla Foundation)
brwsrcmp.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\components\brwsrcmp.dll -> [2009/05/06 08:05:33 | 00,134,648 | ---- | M] (Mozilla Foundation)
< FireFox Plugins [Program Folders] > -> 
C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\ -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins -> [2009/05/06 08:05:56 | 00,000,000 | ---D | M]
npnul32.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\npnul32.dll -> [2009/05/06 08:05:44 | 00,065,528 | ---- | M] (mozilla.org)
< FireFox SearchPlugins [Program Folders] > -> 
C:\PROGRAM FILES\MOZILLA FIREFOX\searchplugins\ -> C:\PROGRAM FILES\MOZILLA FIREFOX\searchplugins -> [2009/05/08 11:54:59 | 00,000,000 | ---D | M]
amazondotcom.xml -> C:\PROGRAM FILES\MOZILLA FIREFOX\searchplugins\amazondotcom.xml -> [2009/05/06 08:05:46 | 00,001,394 | ---- | M] ()
answers.xml -> C:\PROGRAM FILES\MOZILLA FIREFOX\searchplugins\answers.xml -> [2009/05/06 08:05:46 | 00,002,193 | ---- | M] ()
creativecommons.xml -> C:\PROGRAM FILES\MOZILLA FIREFOX\searchplugins\creativecommons.xml -> [2009/05/06 08:05:47 | 00,001,534 | ---- | M] ()
eBay.xml -> C:\PROGRAM FILES\MOZILLA FIREFOX\searchplugins\eBay.xml -> [2009/05/06 08:05:47 | 00,002,343 | ---- | M] ()
google.xml -> C:\PROGRAM FILES\MOZILLA FIREFOX\searchplugins\google.xml -> [2009/05/06 08:05:47 | 00,001,706 | ---- | M] ()
wikipedia.xml -> C:\PROGRAM FILES\MOZILLA FIREFOX\searchplugins\wikipedia.xml -> [2009/05/06 08:05:47 | 00,001,178 | ---- | M] ()
< HOSTS File > (734 bytes and 19 lines) -> C:\WINDOWS\System32\drivers\etc\Hosts -> 
Reset Hosts
127.0.0.1       localhost
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ -> 
{0347C33E-8762-4905-BF09-768834316C61} [HKLM] -> C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll [HP Print Enhancer] -> [2007/03/02 17:52:24 | 01,298,024 | R--- | M] (Hewlett-Packard Co.)
{053F9267-DC04-4294-A72C-58F732D338C0} [HKLM] -> C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll [HP Print Clips] -> [2007/03/02 17:52:08 | 00,177,768 | R--- | M] (Hewlett-Packard Co.)
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [HKLM] -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [Adobe PDF Reader Link Helper] -> [2006/10/23 08:08:42 | 00,062,080 | ---- | M] (Adobe Systems Incorporated)
{22BF413B-C6D2-4d91-82A9-A0F997BA588C} [HKLM] -> C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [Skype add-on (mastermind)] -> [2008/11/07 15:31:40 | 01,088,296 | ---- | M] (Skype Technologies S.A.)
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [HKLM] -> C:\Program Files\Java\jre6\bin\ssv.dll [Java(tm) Plug-In SSV Helper] -> [2009/01/08 18:57:26 | 00,320,920 | ---- | M] (Sun Microsystems, Inc.)
{AA58ED58-01DD-4d91-8333-CF10577473F7} [HKLM] -> C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll [Google Toolbar Helper] -> [2009/02/15 20:06:44 | 00,251,504 | ---- | M] ()
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D} [HKLM] -> C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll [Google Toolbar Notifier BHO] -> [2009/02/16 18:11:32 | 00,657,904 | ---- | M] (Google Inc.)
{C84D72FE-E17D-4195-BB24-76C02E2E7C4E} [HKLM] -> C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll [Google Dictionary Compression sdch] -> [2009/02/15 20:06:43 | 00,522,224 | ---- | M] (Google Inc.)
{DBC80044-A445-435b-BC74-9C25C1C588A9} [HKLM] -> C:\Program Files\Java\jre6\bin\jp2ssv.dll [Java(tm) Plug-In 2 SSV Helper] -> [2009/01/08 18:57:23 | 00,034,816 | ---- | M] (Sun Microsystems, Inc.)
{E7E6F031-17CE-4C07-BC86-EABFE594F69C} [HKLM] -> C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [JQSIEStartDetectorImpl Class] -> [2009/01/08 18:57:28 | 00,073,728 | ---- | M] (Sun Microsystems, Inc.)
< Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar -> 
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" [HKLM] -> C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll [&Google Toolbar] -> [2009/02/15 20:06:44 | 00,251,504 | ---- | M] ()
< Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ -> 
WebBrowser\\"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" [HKLM] -> C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll [&Google Toolbar] -> [2009/02/15 20:06:44 | 00,251,504 | ---- | M] ()
WebBrowser\\"{A057A204-BACC-4D26-9990-79A187E2698E}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> 
"" ->  [] -> File not found
"Adobe Reader Speed Launcher" -> C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe ["C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"] -> [2007/05/11 12:06:32 | 00,040,048 | ---- | M] (Adobe Systems Incorporated)
"Alcmtr" -> C:\WINDOWS\ALCMTR.EXE [ALCMTR.EXE] -> [2008/06/20 01:20:00 | 00,057,344 | ---- | M] (Realtek Semiconductor Corp.)
"avgnt" -> C:\Program Files\Avira\AntiVir Desktop\avgnt.exe ["C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min] -> [2009/03/02 13:08:47 | 00,209,153 | ---- | M] (Avira GmbH)
"BatteryManager" -> C:\Program Files\Samsung\Samsung Battery Manager\BatteryManager.exe [C:\Program Files\Samsung\Samsung Battery Manager\BatteryManager.exe] -> [2007/10/31 20:33:54 | 02,768,896 | ---- | M] ()
"DMHotKey" -> C:\Program Files\Samsung\Easy Display Manager\DMLoader.exe [C:\Program Files\Samsung\Easy Display Manager\DMLoader.exe] -> [2006/12/28 00:45:42 | 00,466,944 | ---- | M] (SAMSUNG Electronics)
"EDS" -> C:\Program Files\Samsung\Samsung EDS\EDSAgent.exe [C:\Program Files\Samsung\Samsung EDS\EDSAgent.exe] -> [2007/12/21 05:40:30 | 00,659,456 | ---- | M] (Samsung Electronics,.LTD)
"HotKeysCmds" -> C:\WINDOWS\System32\hkcmd.exe [C:\WINDOWS\system32\hkcmd.exe] -> [2008/02/29 00:00:04 | 00,166,424 | ---- | M] (Intel Corporation)
"HP Software Update" -> C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [C:\Program Files\HP\HP Software Update\HPWuSchd2.exe] -> [2007/03/11 22:34:40 | 00,049,152 | ---- | M] (Hewlett-Packard Co.)
"IgfxTray" -> C:\WINDOWS\System32\igfxtray.exe [C:\WINDOWS\system32\igfxtray.exe] -> [2008/02/29 00:00:20 | 00,141,848 | ---- | M] (Intel Corporation)
"iTunesHelper" -> C:\Program Files\iTunes\iTunesHelper.exe ["C:\Program Files\iTunes\iTunesHelper.exe"] -> [2008/11/20 13:20:54 | 00,290,088 | ---- | M] (Apple Inc.)
"MagicKeyboard" -> C:\Program Files\SAMSUNG\MagicKBD\PreMKBD.exe [C:\Program Files\SAMSUNG\MagicKBD\PreMKBD.exe] -> [2006/05/15 04:00:24 | 00,151,552 | ---- | M] ()
"Persistence" -> C:\WINDOWS\System32\igfxpers.exe [C:\WINDOWS\system32\igfxpers.exe] -> [2008/02/29 00:00:14 | 00,137,752 | ---- | M] (Intel Corporation)
"QuickTime Task" -> C:\Program Files\QuickTime\qttask.exe ["C:\Program Files\QuickTime\qttask.exe" -atboottime] -> [2008/11/04 10:30:50 | 00,413,696 | ---- | M] (Apple Inc.)
"RTHDCPL" -> C:\WINDOWS\RTHDCPL.EXE [RTHDCPL.EXE] -> [2008/08/26 22:51:00 | 16,851,456 | ---- | M] (Realtek Semiconductor Corp.)
"SunJavaUpdateSched" -> C:\Program Files\Java\jre6\bin\jusched.exe ["C:\Program Files\Java\jre6\bin\jusched.exe"] -> [2009/01/08 18:57:24 | 00,136,600 | ---- | M] (Sun Microsystems, Inc.)
"SUPBackGround" -> C:\Program Files\Samsung\Samsung Update Plus\SUPBackGround.exe [C:\Program Files\Samsung\Samsung Update Plus\SUPBackGround.exe] -> [2008/10/27 15:38:52 | 00,298,664 | ---- | M] ()
"SynTPEnh" -> C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [C:\Program Files\Synaptics\SynTP\SynTPEnh.exe] -> [2008/08/28 20:34:52 | 01,044,480 | ---- | M] (Synaptics, Inc.)
< Run [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> 
"swg" -> C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe] -> [2009/02/16 18:11:33 | 00,039,408 | ---- | M] (Google Inc.)
< All Users Startup Folder > -> C:\Documents and Settings\All Users\Start Menu\Programs\Startup -> 
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe -> [2007/04/01 11:02:38 | 00,568,176 | ---- | M] (Broadcom Corporation.)
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe -> [2007/03/11 22:26:24 | 00,210,520 | ---- | M] (Hewlett-Packard Co.)
< Sara Helen Startup Folder > -> C:\Documents and Settings\Sara Helen\Start Menu\Programs\Startup -> 
C:\Documents and Settings\Sara Helen\Start Menu\Programs\Startup\Fotki Desktop.lnk -> C:\Program Files\Fotki Desktop\fotki.exe -> [2008/08/08 13:18:20 | 02,001,920 | ---- | M] (fotki.com)
C:\Documents and Settings\Sara Helen\Start Menu\Programs\Startup\OpenOffice.org 3.0.lnk -> C:\Program Files\OpenOffice.org 3\program\quickstart.exe -> [2008/12/15 14:40:44 | 00,384,000 | ---- | M] ()
< CurrentVersion Policy Settings - Explorer [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"HonorAutoRunSetting" ->  [1] -> File not found
< CurrentVersion Policy Settings - System [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
\\"dontdisplaylastusername" ->  [0] -> File not found
\\"legalnoticecaption" ->  [] -> File not found
\\"legalnoticetext" ->  [] -> File not found
\\"shutdownwithoutlogon" ->  [1] -> File not found
\\"undockwithoutlogon" ->  [1] -> File not found
< CurrentVersion Policy Settings - Explorer [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" ->  [145] -> File not found
< Internet Explorer Menu Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\ -> 
Add to Google Photos Screensa&ver -> C:\WINDOWS\System32\GPhotos.scr [res://C:\WINDOWS\system32\GPhotos.scr/200] -> [2009/01/06 00:33:03 | 03,751,995 | ---- | M] (Google Inc.)
Send to &Bluetooth Device... -> C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm [C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm] -> [2006/08/16 10:16:32 | 00,002,773 | ---- | M] ()
< Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ -> 
{58ECB495-38F0-49cb-A538-10282ABF65E7}:{E763472E-A716-4CD9-89BD-DBDA6122F741} [HKLM] -> C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll [Button: HP Clipbook] -> [2007/03/02 17:53:20 | 00,153,192 | R--- | M] (Hewlett-Packard Co.)
{700259D7-1666-479a-93B1-3250410481E8}:{A93C41D8-01F8-4F8B-B14C-DE20B117E636} [HKLM] -> C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll [Button: HP Smart Select] -> [2007/03/02 17:53:20 | 00,153,192 | R--- | M] (Hewlett-Packard Co.)
{77BF5300-1474-4EC7-9980-D32B190E9B07}:{77BF5300-1474-4EC7-9980-D32B190E9B07} [HKLM] -> C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [Button: Skype] -> [2008/11/07 15:31:40 | 01,088,296 | ---- | M] (Skype Technologies S.A.)
{CCA281CA-C863-46ef-9331-5C8D4460577F}:C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm [HKLM] -> C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm [Button: @btrez.dll,-4015] -> [2006/08/16 10:16:32 | 00,005,589 | ---- | M] ()
{CCA281CA-C863-46ef-9331-5C8D4460577F}:C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm [HKLM] -> C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm [Menu: @btrez.dll,-12650] -> [2006/08/16 10:16:32 | 00,005,589 | ---- | M] ()
{e2e2dd38-d088-4134-82b7-f2ba38496583}:Exec [HKLM] -> C:\WINDOWS\Network Diagnostic\xpnetdiag.exe [Menu: @xpsp3res.dll,-20001] -> [2008/04/14 14:00:00 | 00,558,080 | ---- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}:Exec [HKLM] -> C:\Program Files\Messenger\msmsgs.exe [Button: Messenger] -> [2008/04/14 14:42:30 | 01,695,232 | ---- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}:Exec [HKLM] -> C:\Program Files\Messenger\msmsgs.exe [Menu: Windows Messenger] -> [2008/04/14 14:42:30 | 01,695,232 | ---- | M] (Microsoft Corporation)
< Internet Explorer Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\ -> 
CmdMapping\\"{08B0E5C0-4FCB-11CF-AAA5-00401C608501}" [HKLM] ->  [Reg Error: Value error.] -> File not found
CmdMapping\\"{CCA281CA-C863-46ef-9331-5C8D4460577F}" [HKLM] ->  [@btrez.dll,-4015] -> File not found
CmdMapping\\"{e2e2dd38-d088-4134-82b7-f2ba38496583}" [HKLM] -> C:\WINDOWS\Network Diagnostic\xpnetdiag.exe [@xpsp3res.dll,-20001] -> [2008/04/14 14:00:00 | 00,558,080 | ---- | M] (Microsoft Corporation)
CmdMapping\\"{FB5F1910-F110-11d2-BB9E-00C04F795683}" [HKLM] -> C:\Program Files\Messenger\msmsgs.exe [Messenger] -> [2008/04/14 14:42:30 | 01,695,232 | ---- | M] (Microsoft Corporation)
< Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ -> 
PluginsPageFriendlyName -> Microsoft ActiveX Gallery -> 
PluginsPage -> http://activex.microsoft.com/controls/find.asp?ext=%s&mime=%s -> 
< Default Prefix > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix
"" -> http://
< Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 1 domain(s) found. -> 
1 domain(s) and sub-domain(s) not assigned to a zone.
< Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< Trusted Sites Domains [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 1 domain(s) found. -> 
fact.exe .[https] -> Trusted sites -> 
< Trusted Sites Ranges [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ -> 
{0CCA191D-13A6-4E29-B746-314DEE697D83} [HKLM] -> http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab [Facebook Photo Uploader 5 Control] -> 
{17492023-C23A-453E-A040-C7C580BBF700} [HKLM] -> http://download.microsoft.com/download/8/b/d/8bd77752-5704-4d68-a152-f7252adaa4f2/LegitCheckControl.cab [Windows Genuine Advantage Validation Tool] -> 
{4F1E5B1A-2A80-42CA-8532-2D05CB959537} [HKLM] -> http://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab [MSN Photo Upload Tool] -> 
{8AD9C840-044E-11D1-B3E9-00805F499D93} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab [Java Plug-in 1.6.0_11] -> 
{8FFBE65D-2C9C-4669-84BD-5829DC0B603C} [HKLM] -> http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab [Reg Error: Key error.] -> 
{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab [Java Plug-in 1.5.0] -> 
{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab [Java Plug-in 1.6.0_07] -> 
{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab [Java Plug-in 1.6.0_11] -> 
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab [Java Plug-in 1.6.0_11] -> 
< Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> 
*Shell* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell -> 
Explorer.exe -> C:\WINDOWS\Explorer.exe -> [2008/04/14 14:00:00 | 01,033,728 | ---- | M] (Microsoft Corporation)
*MultiFile Done* -> -> 
< Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ -> 
igfxcui -> C:\WINDOWS\System32\igfxdev.dll -> [2008/02/15 21:45:40 | 00,208,896 | ---- | M] (Intel Corporation)
< Domain Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List -> 
"%windir%\system32\sessmgr.exe" -> C:\WINDOWS\System32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> [2008/04/14 14:00:00 | 00,141,312 | ---- | M] (Microsoft Corporation)
< Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List -> 
"%windir%\system32\sessmgr.exe" -> C:\WINDOWS\System32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> [2008/04/14 14:00:00 | 00,141,312 | ---- | M] (Microsoft Corporation)
"C:\Documents and Settings\Sara Helen\Desktop\fact.exe" -> C:\Documents and Settings\Sara Helen\Desktop\fact.exe [C:\Documents and Settings\Sara Helen\Desktop\fact.exe:*:Enabled:fact] -> File not found
"C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" -> C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe:*:Enabled:Malwarebytes' Anti-Malware] -> [2009/04/06 15:32:44 | 01,277,584 | ---- | M] (Malwarebytes Corporation)
"C:\Program Files\Skype\Phone\Skype.exe" -> C:\Program Files\Skype\Phone\Skype.exe [C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype] -> [2008/11/07 15:31:38 | 21,633,320 | R--- | M] (Skype Technologies S.A.)
< SafeBoot AlternateShell [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot -> 
"AlternateShell" -> cmd.exe -> 
< CDROM Autorun Setting [HKEY_LOCAL_MACHINE]> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom ->
"AutoRun" -> 1 -> 
"DisplayName" -> CD-ROM Driver -> 
"ImagePath" ->  [system32\DRIVERS\cdrom.sys] -> File not found
< Drives with AutoRun files > ->  -> 
C:\AUTOEXEC.BAT [] -> C:\AUTOEXEC.BAT [ NTFS ] -> [2008/10/06 23:40:51 | 00,000,000 | ---- | M] ()
< MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 -> 
\{6feab993-be1b-11dd-bb3f-001377adb049}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6feab993-be1b-11dd-bb3f-001377adb049}\Shell\AutoRun\command
\{6feab993-be1b-11dd-bb3f-001377adb049}\Shell\AutoRun\command\\"" -> E:\wd_windows_tools\setup.exe [E:\wd_windows_tools\setup.exe] -> File not found
 
 
[Files/Folders - Created Within 30 Days]
OTS.exe -> C:\Documents and Settings\Sara Helen\Desktop\OTS.exe -> [2009/05/21 21:00:45 | 00,504,320 | ---- | C] (OldTimer Tools)
OTScanIt2 -> C:\Documents and Settings\Sara Helen\Desktop\OTScanIt2 -> [2009/05/21 20:54:31 | 00,000,000 | ---D | C]
OTScanIt2.exe -> C:\Documents and Settings\Sara Helen\Desktop\OTScanIt2.exe -> [2009/05/21 20:53:26 | 00,665,196 | ---- | C] ()
Fotki Desktop.lnk -> C:\Documents and Settings\Sara Helen\Start Menu\Programs\Startup\Fotki Desktop.lnk -> [2009/05/21 17:40:08 | 00,000,648 | ---- | C] ()
FotkiDesktop -> C:\Documents and Settings\Sara Helen\Application Data\FotkiDesktop -> [2009/05/21 17:40:08 | 00,000,000 | ---D | C]
Fotki Desktop -> C:\Program Files\Fotki Desktop -> [2009/05/21 17:40:07 | 00,000,000 | ---D | C]
FDSetup.exe -> C:\Documents and Settings\Sara Helen\Desktop\FDSetup.exe -> [2009/05/21 17:39:49 | 01,137,909 | ---- | C] (fotki.com                                                   )
rsit -> C:\rsit -> [2009/05/21 10:49:50 | 00,000,000 | ---D | C]
RSIT.exe -> C:\Documents and Settings\Sara Helen\Desktop\RSIT.exe -> [2009/05/21 10:49:08 | 00,781,909 | ---- | C] ()
Malwarebytes -> C:\Documents and Settings\Sara Helen\Application Data\Malwarebytes -> [2009/05/21 09:42:37 | 00,000,000 | ---D | C]
mbam.sys -> C:\WINDOWS\System32\drivers\mbam.sys -> [2009/05/21 09:42:34 | 00,015,504 | ---- | C] (Malwarebytes Corporation)
Malwarebytes' Anti-Malware.lnk -> C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk -> [2009/05/21 09:42:34 | 00,000,696 | ---- | C] ()
mbamswissarmy.sys -> C:\WINDOWS\System32\drivers\mbamswissarmy.sys -> [2009/05/21 09:42:31 | 00,038,496 | ---- | C] (Malwarebytes Corporation)
Malwarebytes -> C:\Documents and Settings\All Users\Application Data\Malwarebytes -> [2009/05/21 09:42:28 | 00,000,000 | ---D | C]
Malwarebytes' Anti-Malware -> C:\Program Files\Malwarebytes' Anti-Malware -> [2009/05/21 09:42:27 | 00,000,000 | ---D | C]
mbam-setup.exe -> C:\Documents and Settings\Sara Helen\Desktop\mbam-setup.exe -> [2009/05/21 09:37:33 | 02,967,800 | ---- | C] (Malwarebytes Corporation                                    )
EBROCHURE09.pdf -> C:\Documents and Settings\Sara Helen\Desktop\EBROCHURE09.pdf -> [2009/05/20 18:19:44 | 03,300,536 | ---- | C] ()
Travel -> C:\Documents and Settings\Sara Helen\My Documents\Travel -> [2009/05/20 15:18:54 | 00,000,000 | ---D | C]
Writing Folder -> C:\Documents and Settings\Sara Helen\My Documents\Writing Folder -> [2009/05/20 15:18:12 | 00,000,000 | ---D | C]
spybotsd162.exe -> C:\Documents and Settings\Sara Helen\Desktop\spybotsd162.exe -> [2009/05/19 09:23:25 | 16,409,960 | ---- | C] (Safer Networking Limited                                    )
.~lock.Left right brain.odt# -> C:\Documents and Settings\Sara Helen\My Documents\.~lock.Left right brain.odt# -> [2009/05/18 23:51:45 | 00,000,126 | -H-- | C] ()
P1030292.JPG -> C:\Documents and Settings\Sara Helen\Desktop\P1030292.JPG -> [2009/05/18 10:24:10 | 03,885,234 | ---- | C] ()
Finding a career -> C:\Documents and Settings\Sara Helen\My Documents\Finding a career -> [2009/05/16 16:03:20 | 00,000,000 | ---D | C]
US Trip July 09 -> C:\Documents and Settings\Sara Helen\My Documents\US Trip July 09 -> [2009/05/14 11:42:21 | 00,000,000 | ---D | C]
HijackThis.lnk -> C:\Documents and Settings\Sara Helen\Desktop\HijackThis.lnk -> [2009/05/11 16:48:38 | 00,001,734 | ---- | C] ()
Trend Micro -> C:\Program Files\Trend Micro -> [2009/05/11 16:48:37 | 00,000,000 | ---D | C]
HJTInstall.exe -> C:\Documents and Settings\Sara Helen\Desktop\HJTInstall.exe -> [2009/05/11 16:47:58 | 00,812,344 | ---- | C] (Trend Micro Inc.)
BYKIDownloaderPC.exe -> C:\Documents and Settings\Sara Helen\Desktop\BYKIDownloaderPC.exe -> [2009/05/10 11:40:49 | 00,239,480 | ---- | C] (Transparent Language)
setup.exe -> C:\Documents and Settings\Sara Helen\Desktop\setup.exe -> [2009/05/09 20:38:19 | 01,217,368 | ---- | C] (Microsoft Corporation.)
Windows Media Player.lnk -> C:\Documents and Settings\Sara Helen\Desktop\Windows Media Player.lnk -> [2009/05/08 16:47:40 | 00,000,786 | ---- | C] ()
Avira AntiVir Control Center.lnk -> C:\Documents and Settings\All Users\Desktop\Avira AntiVir Control Center.lnk -> [2009/05/08 16:26:43 | 00,001,707 | ---- | C] ()
avipbb.sys -> C:\WINDOWS\System32\drivers\avipbb.sys -> [2009/05/08 16:26:28 | 00,096,104 | ---- | C] (Avira GmbH)
avgntflt.sys -> C:\WINDOWS\System32\drivers\avgntflt.sys -> [2009/05/08 16:26:28 | 00,055,640 | ---- | C] (Avira GmbH)
avgntdd.sys -> C:\WINDOWS\System32\drivers\avgntdd.sys -> [2009/05/08 16:26:28 | 00,045,416 | ---- | C] (Avira GmbH)
avgntmgr.sys -> C:\WINDOWS\System32\drivers\avgntmgr.sys -> [2009/05/08 16:26:28 | 00,022,360 | ---- | C] (Avira GmbH)
ssmdrv.sys -> C:\WINDOWS\System32\drivers\ssmdrv.sys -> [2009/05/08 16:26:27 | 00,028,376 | ---- | C] (Avira GmbH)
Avira -> C:\Program Files\Avira -> [2009/05/08 16:26:24 | 00,000,000 | ---D | C]
Avira -> C:\Documents and Settings\All Users\Application Data\Avira -> [2009/05/08 16:26:24 | 00,000,000 | ---D | C]
Config.Msi -> C:\Config.Msi -> [2009/05/08 16:25:37 | 00,000,000 | -HSD | C]
scan0001.jpg -> C:\Documents and Settings\Sara Helen\Desktop\scan0001.jpg -> [2009/05/08 13:06:31 | 00,580,697 | ---- | C] ()
HP -> C:\Documents and Settings\Sara Helen\Application Data\HP -> [2009/05/08 13:01:40 | 00,000,000 | ---D | C]
OverDrive Media Console.lnk -> C:\Documents and Settings\All Users\Desktop\OverDrive Media Console.lnk -> [2009/05/04 09:52:15 | 00,001,888 | ---- | C] ()
OverDrive Media Console -> C:\Program Files\OverDrive Media Console -> [2009/05/04 09:51:44 | 00,000,000 | ---D | C]
xpsp4res.dll -> C:\WINDOWS\System32\xpsp4res.dll -> [2009/04/25 03:48:15 | 00,002,560 | ---- | C] (Microsoft Corporation)
Sara Helen_KBD.ini -> C:\WINDOWS\System32\Sara Helen_KBD.ini -> [2008/11/18 13:25:57 | 00,001,520 | ---- | C] ()
smscfg.ini -> C:\WINDOWS\smscfg.ini -> [2008/10/25 01:03:43 | 00,000,061 | ---- | C] ()
MagicKBD.INI -> C:\WINDOWS\System32\MagicKBD.INI -> [2008/10/06 23:53:53 | 00,001,522 | ---- | C] ()
Owner_KBD.ini -> C:\WINDOWS\System32\Owner_KBD.ini -> [2008/10/06 23:53:53 | 00,001,520 | ---- | C] ()
KBDR.INI -> C:\WINDOWS\System32\KBDR.INI -> [2008/10/06 23:53:51 | 00,003,425 | ---- | C] ()
KBDD.INI -> C:\WINDOWS\System32\KBDD.INI -> [2008/10/06 23:53:51 | 00,002,741 | ---- | C] ()
KBDO.INI -> C:\WINDOWS\System32\KBDO.INI -> [2008/10/06 23:53:51 | 00,002,699 | ---- | C] ()
KBDC.INI -> C:\WINDOWS\System32\KBDC.INI -> [2008/10/06 23:53:51 | 00,002,699 | ---- | C] ()
KBDB.INI -> C:\WINDOWS\System32\KBDB.INI -> [2008/10/06 23:53:51 | 00,002,606 | ---- | C] ()
KBDQ.INI -> C:\WINDOWS\System32\KBDQ.INI -> [2008/10/06 23:53:51 | 00,002,236 | ---- | C] ()
KBDE.INI -> C:\WINDOWS\System32\KBDE.INI -> [2008/10/06 23:53:51 | 00,001,956 | ---- | C] ()
KBDP.INI -> C:\WINDOWS\System32\KBDP.INI -> [2008/10/06 23:53:51 | 00,001,885 | ---- | C] ()
KBDUU.INI -> C:\WINDOWS\System32\KBDUU.INI -> [2008/10/06 23:53:51 | 00,001,857 | ---- | C] ()
KBDG.INI -> C:\WINDOWS\System32\KBDG.INI -> [2008/10/06 23:53:51 | 00,001,835 | ---- | C] ()
KBDA.INI -> C:\WINDOWS\System32\KBDA.INI -> [2008/10/06 23:53:51 | 00,001,835 | ---- | C] ()
KBDU.INI -> C:\WINDOWS\System32\KBDU.INI -> [2008/10/06 23:53:51 | 00,001,834 | ---- | C] ()
KBDN.INI -> C:\WINDOWS\System32\KBDN.INI -> [2008/10/06 23:53:51 | 00,001,819 | ---- | C] ()
KBDT.INI -> C:\WINDOWS\System32\KBDT.INI -> [2008/10/06 23:53:51 | 00,001,699 | ---- | C] ()
KBDV.INI -> C:\WINDOWS\System32\KBDV.INI -> [2008/10/06 23:53:51 | 00,001,697 | ---- | C] ()
KBDS.INI -> C:\WINDOWS\System32\KBDS.INI -> [2008/10/06 23:53:51 | 00,001,522 | ---- | C] ()
KBDF.INI -> C:\WINDOWS\System32\KBDF.INI -> [2008/10/06 23:53:51 | 00,001,476 | ---- | C] ()
lngEng.ini -> C:\WINDOWS\System32\lngEng.ini -> [2008/10/06 23:51:19 | 00,000,135 | R--- | C] ()
lngKor.ini -> C:\WINDOWS\System32\lngKor.ini -> [2008/10/06 23:51:19 | 00,000,117 | ---- | C] ()
igfxCoIn_v4926.dll -> C:\WINDOWS\System32\igfxCoIn_v4926.dll -> [2008/10/06 23:47:52 | 00,147,456 | ---- | C] ()
MEMIO.SYS -> C:\WINDOWS\System32\MEMIO.SYS -> [2008/10/06 23:45:10 | 00,004,300 | ---- | C] ()
oeminfo.ini -> C:\WINDOWS\System32\oeminfo.ini -> [2008/10/06 18:36:05 | 00,000,416 | ---- | C] ()
win.ini -> C:\WINDOWS\win.ini -> [2008/10/06 18:35:29 | 00,000,512 | ---- | C] ()
system.ini -> C:\WINDOWS\system.ini -> [2008/10/06 18:35:27 | 00,000,231 | ---- | C] ()
btwicons.dll -> C:\WINDOWS\System32\btwicons.dll -> [2007/04/01 11:00:28 | 02,842,624 | ---- | C] ()
btprn2k.dll -> C:\WINDOWS\System32\btprn2k.dll -> [2007/04/01 10:41:52 | 00,090,112 | ---- | C] ()
BTNeighborhood.dll.manifest -> C:\WINDOWS\System32\BTNeighborhood.dll.manifest -> [2005/02/17 14:41:32 | 00,000,603 | ---- | C] ()
btcss.dll.manifest -> C:\WINDOWS\System32\btcss.dll.manifest -> [2005/02/17 14:41:30 | 00,000,593 | ---- | C] ()
lcppn21.dll -> C:\WINDOWS\System32\lcppn21.dll -> [2001/11/14 15:56:00 | 01,802,240 | ---- | C] ()
 
[Files/Folders - Modified Within 30 Days]
1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> 
612 C:\Documents and Settings\Sara Helen\Local Settings\Temp\*.tmp files -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\*.tmp -> 
1 C:\WINDOWS\Temp\*.tmp files -> C:\WINDOWS\Temp\*.tmp -> 
OTS.exe -> C:\Documents and Settings\Sara Helen\Desktop\OTS.exe -> [2009/05/21 21:00:48 | 00,504,320 | ---- | M] (OldTimer Tools)
igtnlmsc.dll -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\igtnlmsc.dll -> [2009/05/21 20:55:18 | 00,053,248 | ---- | M] ()
OTScanIt2.exe -> C:\Documents and Settings\Sara Helen\Desktop\OTScanIt2.exe -> [2009/05/21 20:53:30 | 00,665,196 | ---- | M] ()
User_Feed_Synchronization-{0F981175-FD05-4D51-828A-B541A73A10BA}.job -> C:\WINDOWS\tasks\User_Feed_Synchronization-{0F981175-FD05-4D51-828A-B541A73A10BA}.job -> [2009/05/21 19:33:25 | 00,000,432 | -H-- | M] ()
AppleSoftwareUpdate.job -> C:\WINDOWS\tasks\AppleSoftwareUpdate.job -> [2009/05/21 19:27:01 | 00,000,284 | ---- | M] ()
Fotki Desktop.lnk -> C:\Documents and Settings\Sara Helen\Start Menu\Programs\Startup\Fotki Desktop.lnk -> [2009/05/21 17:43:53 | 00,000,648 | ---- | M] ()
FDSetup.exe -> C:\Documents and Settings\Sara Helen\Desktop\FDSetup.exe -> [2009/05/21 17:39:50 | 01,137,909 | ---- | M] (fotki.com                                                   )
Perflib_Perfdata_8c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_8c.dat -> [2009/05/21 17:14:23 | 00,016,384 | ---- | M] ()
SA.DAT -> C:\WINDOWS\tasks\SA.DAT -> [2009/05/21 17:14:13 | 00,000,006 | -H-- | M] ()
bootstat.dat -> C:\WINDOWS\bootstat.dat -> [2009/05/21 17:14:10 | 00,002,048 | --S- | M] ()
hiberfil.sys -> C:\hiberfil.sys -> [2009/05/21 17:14:08 | 10,637,02528 | -HS- | M] ()
NTUSER.DAT -> C:\Documents and Settings\Sara Helen\NTUSER.DAT -> [2009/05/21 17:12:50 | 03,407,872 | -H-- | M] ()
ntuser.ini -> C:\Documents and Settings\Sara Helen\ntuser.ini -> [2009/05/21 17:12:50 | 00,000,178 | -HS- | M] ()
RSIT.exe -> C:\Documents and Settings\Sara Helen\Desktop\RSIT.exe -> [2009/05/21 10:49:15 | 00,781,909 | ---- | M] ()
Malwarebytes' Anti-Malware.lnk -> C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk -> [2009/05/21 09:42:34 | 00,000,696 | ---- | M] ()
mbam-setup.exe -> C:\Documents and Settings\Sara Helen\Desktop\mbam-setup.exe -> [2009/05/21 09:38:10 | 02,967,800 | ---- | M] (Malwarebytes Corporation                                    )
EBROCHURE09.pdf -> C:\Documents and Settings\Sara Helen\Desktop\EBROCHURE09.pdf -> [2009/05/20 18:19:44 | 03,300,536 | ---- | M] ()
spybotsd162.exe -> C:\Documents and Settings\Sara Helen\Desktop\spybotsd162.exe -> [2009/05/19 09:23:56 | 16,409,960 | ---- | M] (Safer Networking Limited                                    )
.~lock.Left right brain.odt# -> C:\Documents and Settings\Sara Helen\My Documents\.~lock.Left right brain.odt# -> [2009/05/18 23:51:45 | 00,000,126 | -H-- | M] ()
qmgr1.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat -> [2009/05/13 08:01:47 | 00,005,531 | ---- | M] ()
qmgr0.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat -> [2009/05/13 08:01:47 | 00,004,232 | ---- | M] ()
Perflib_Perfdata_758.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_758.dat -> [2009/05/11 18:34:37 | 00,016,384 | ---- | M] ()
Perflib_Perfdata_a80.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_a80.dat -> [2009/05/11 18:06:33 | 00,016,384 | ---- | M] ()
HijackThis.lnk -> C:\Documents and Settings\Sara Helen\Desktop\HijackThis.lnk -> [2009/05/11 16:48:38 | 00,001,734 | ---- | M] ()
HJTInstall.exe -> C:\Documents and Settings\Sara Helen\Desktop\HJTInstall.exe -> [2009/05/11 16:47:58 | 00,812,344 | ---- | M] (Trend Micro Inc.)
BYKIDownloaderPC.exe -> C:\Documents and Settings\Sara Helen\Desktop\BYKIDownloaderPC.exe -> [2009/05/10 11:40:50 | 00,239,480 | ---- | M] (Transparent Language)
setup.exe -> C:\Documents and Settings\Sara Helen\Desktop\setup.exe -> [2009/05/09 20:38:19 | 01,217,368 | ---- | M] (Microsoft Corporation.)
PerfStringBackup.INI -> C:\WINDOWS\System32\PerfStringBackup.INI -> [2009/05/08 17:13:30 | 00,355,920 | ---- | M] ()
perfh009.dat -> C:\WINDOWS\System32\perfh009.dat -> [2009/05/08 17:13:30 | 00,312,172 | ---- | M] ()
perfc009.dat -> C:\WINDOWS\System32\perfc009.dat -> [2009/05/08 17:13:30 | 00,040,394 | ---- | M] ()
imsins.BAK -> C:\WINDOWS\imsins.BAK -> [2009/05/08 17:13:18 | 00,004,507 | ---- | M] ()
Windows Media Player.lnk -> C:\Documents and Settings\Sara Helen\Desktop\Windows Media Player.lnk -> [2009/05/08 16:47:40 | 00,000,786 | ---- | M] ()
Avira AntiVir Control Center.lnk -> C:\Documents and Settings\All Users\Desktop\Avira AntiVir Control Center.lnk -> [2009/05/08 16:26:43 | 00,001,707 | ---- | M] ()
scan0001.jpg -> C:\Documents and Settings\Sara Helen\Desktop\scan0001.jpg -> [2009/05/08 13:05:02 | 00,580,697 | ---- | M] ()
MRT.exe -> C:\WINDOWS\System32\MRT.exe -> [2009/05/07 09:16:29 | 24,699,336 | ---- | M] (Microsoft Corporation)
OverDrive Media Console.lnk -> C:\Documents and Settings\All Users\Desktop\OverDrive Media Console.lnk -> [2009/05/04 09:52:15 | 00,001,888 | ---- | M] ()
wpa.dbl -> C:\WINDOWS\System32\wpa.dbl -> [2009/04/29 18:44:25 | 00,001,158 | ---- | M] ()
FNTCACHE.DAT -> C:\WINDOWS\System32\FNTCACHE.DAT -> [2009/04/29 18:44:20 | 00,112,584 | ---- | M] ()
System.dll -> C:\WINDOWS\Temp\nseBF.tmp\System.dll -> [2009/01/28 16:08:12 | 00,009,216 | ---- | M] ()
NSIS_Picasa.dll -> C:\WINDOWS\Temp\nseBF.tmp\NSIS_Picasa.dll -> [2009/01/28 16:07:54 | 00,057,344 | ---- | M] ()
ConResEn.dll -> C:\WINDOWS\Temp\ConResEn.dll -> [2009/01/21 16:43:08 | 00,069,632 | ---- | M] ()
index.dat -> C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\index.dat -> [2009/01/21 16:39:04 | 00,032,768 | ---- | M] ()
index.dat -> C:\WINDOWS\Temp\History\History.IE5\index.dat -> [2009/01/21 16:39:04 | 00,032,768 | ---- | M] ()
index.dat -> C:\WINDOWS\Temp\Cookies\index.dat -> [2009/01/21 16:39:04 | 00,016,384 | ---- | M] ()
System.dll -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\nsd6CA.tmp\System.dll -> [2009/01/08 20:40:49 | 00,009,216 | ---- | M] ()
NSIS_Picasa.dll -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\nsd6CA.tmp\NSIS_Picasa.dll -> [2009/01/08 20:26:05 | 00,057,344 | ---- | M] ()
hpoprl06.dat -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\hpoprl06.dat -> [2007/09/20 17:56:11 | 00,002,965 | ---- | M] ()
hpoprl10.dat -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\hpoprl10.dat -> [2007/09/20 17:56:11 | 00,000,603 | ---- | M] ()
hposcr14.dat -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\setup\hposcr14.dat -> [2007/09/20 17:56:10 | 00,011,829 | ---- | M] ()
hpoprl09.dat -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\hpoprl09.dat -> [2007/09/20 17:56:10 | 00,002,439 | ---- | M] ()
hpoprl08.dat -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\hpoprl08.dat -> [2007/09/20 17:56:07 | 00,003,085 | ---- | M] ()
hpomdl14.dat -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\hpomdl14.dat -> [2007/09/20 17:56:07 | 00,002,000 | ---- | M] ()
hpoprl07.dat -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\hpoprl07.dat -> [2007/09/20 17:56:06 | 00,000,365 | ---- | M] ()
dj_aio_bid01.dat -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\dj_aio_bid01.dat -> [2007/06/26 13:17:15 | 00,276,968 | ---- | M] ()
hpqbud01.dat -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\setup\hpqbud01.dat -> [2007/06/22 20:26:33 | 00,055,757 | ---- | M] ()
hpqbid01.dat -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\hpqbid01.dat -> [2007/06/22 20:26:10 | 00,264,737 | ---- | M] ()
dj_aio_scr14.dat -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\dj_aio_scr14.dat -> [2007/06/06 14:06:02 | 00,013,266 | ---- | M] ()
dj_aio_scr12.dat -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\dj_aio_scr12.dat -> [2007/06/06 14:06:01 | 00,005,894 | ---- | M] ()
HPZchk01.exe -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\setup\HPZchk01.exe -> [2007/05/21 19:49:55 | 01,488,472 | ---- | M] (Hewlett-Packard)
Setup.exe -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\Setup.exe -> [2007/05/21 19:48:52 | 00,554,584 | ---- | M] (Hewlett-Packard)
HPZarp01.exe -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\setup\HPZarp01.exe -> [2007/05/21 19:48:43 | 00,370,264 | ---- | M] (Hewlett-Packard)
HPZwrp01.exe -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\setup\HPZwrp01.exe -> [2007/05/21 19:48:36 | 00,366,168 | ---- | M] (Hewlett-Packard)
hpzprl41.dat -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\hpzprl41.dat -> [2007/05/21 19:48:09 | 00,000,821 | ---- | M] ()
HPZsui01.exe -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\setup\HPZsui01.exe -> [2007/05/21 19:47:14 | 02,332,248 | ---- | M] (Hewlett-Packard)
HPZpsl01.exe -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\setup\HPZpsl01.exe -> [2007/05/21 19:47:10 | 00,415,320 | ---- | M] (Hewlett-Packard)
HPZwup01.exe -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\setup\HPZwup01.exe -> [2007/05/21 19:47:06 | 01,316,440 | ---- | M] (Hewlett-Packard)
HPZpsc01.exe -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\setup\HPZpsc01.exe -> [2007/05/21 19:47:00 | 00,599,640 | ---- | M] (Hewlett-Packard)
HPZrein01.exe -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\setup\HPZrein01.exe -> [2007/05/21 19:46:10 | 00,783,968 | ---- | M] (Hewlett-Packard)
HPZprl40.exe -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\setup\HPZprl40.exe -> [2007/05/21 19:45:53 | 00,594,008 | ---- | M] (Hewlett-Packard)
hpzprl01.dat -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\hpzprl01.dat -> [2007/05/21 19:45:42 | 00,004,267 | ---- | M] ()
HPZmsi01.exe -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\setup\HPZmsi01.exe -> [2007/05/21 19:45:34 | 01,140,312 | ---- | M] (Hewlett-Packard)
HPZpnp01.exe -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\setup\HPZpnp01.exe -> [2007/05/21 19:44:35 | 00,407,128 | ---- | M] (Hewlett-Packard)
HPZnop01.exe -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\setup\HPZnop01.exe -> [2007/05/21 19:44:33 | 00,366,168 | ---- | M] (Hewlett-Packard)
HPZopt01.exe -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\setup\HPZopt01.exe -> [2007/05/21 19:44:11 | 00,988,760 | ---- | M] (Hewlett-Packard)
HPZshl40.exe -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\setup\HPZshl40.exe -> [2007/05/21 19:43:50 | 01,670,232 | ---- | M] (Hewlett-Packard)
HPZrcn01.exe -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\setup\HPZrcn01.exe -> [2007/05/21 19:43:46 | 00,423,512 | ---- | M] (Hewlett-Packard)
HPZgat01.exe -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\setup\HPZgat01.exe -> [2007/05/21 19:43:35 | 00,366,168 | ---- | M] (Hewlett-Packard)
HPZstub.exe -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\HPZstub.exe -> [2007/05/21 19:43:27 | 00,385,024 | ---- | M] (Hewlett-Packard)
HPZrcv01.exe -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\setup\HPZrcv01.exe -> [2007/05/21 19:43:11 | 01,242,712 | ---- | M] (Hewlett-Packard)
HPZprl01.exe -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\setup\HPZprl01.exe -> [2007/05/21 19:43:06 | 00,394,840 | ---- | M] (Hewlett-Packard)
HPZcdl01.exe -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\setup\HPZcdl01.exe -> [2007/05/21 19:42:33 | 00,415,320 | ---- | M] (Hewlett-Packard)
hpzsetup.exe -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\hpzsetup.exe -> [2007/05/21 19:42:22 | 00,800,344 | ---- | M] (Hewlett-Packard)
HPZshl01.exe -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\setup\HPZshl01.exe -> [2007/05/21 19:41:48 | 01,287,768 | ---- | M] (Hewlett-Packard)
HPZscr40.exe -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\setup\HPZscr40.exe -> [2007/05/21 19:41:32 | 01,583,704 | ---- | M] (Hewlett-Packard)
HPZdui40.exe -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\setup\HPZdui40.exe -> [2007/05/21 19:40:08 | 02,934,872 | ---- | M] (Hewlett-Packard)
HPZpnp40.exe -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\setup\HPZpnp40.exe -> [2007/05/21 19:40:03 | 00,568,408 | ---- | M] (Hewlett-Packard)
HPZscr01.exe -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\setup\HPZscr01.exe -> [2007/05/21 19:39:39 | 01,099,352 | ---- | M] (Hewlett-Packard)
HPZtim01.exe -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\setup\HPZtim01.exe -> [2007/05/21 19:38:51 | 00,394,840 | ---- | M] (Hewlett-Packard)
HPZdui01.exe -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\setup\HPZdui01.exe -> [2007/05/21 19:38:46 | 02,643,544 | ---- | M] (Hewlett-Packard)
HPZwis01.exe -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\setup\HPZwis01.exe -> [2007/05/21 19:38:37 | 00,370,264 | ---- | M] (Hewlett-Packard)
hpzids40.dll -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\hpzids40.dll -> [2007/03/31 07:09:06 | 00,355,416 | ---- | M] (Hewlett-Packard)
hpzids01.dll -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\hpzids01.dll -> [2007/03/31 07:07:42 | 00,267,864 | ---- | M] (Hewlett-Packard)
hpqbid13c.dat -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\hpqbid13c.dat -> [2007/03/21 11:03:44 | 00,264,638 | ---- | M] ()
hpqbid13b.dat -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\hpqbid13b.dat -> [2007/03/21 11:03:43 | 00,264,641 | ---- | M] ()
hpqbid13a.dat -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\hpqbid13a.dat -> [2007/03/21 11:03:42 | 00,264,635 | ---- | M] ()
hpqbid15.dat -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\hpqbid15.dat -> [2007/03/21 10:53:04 | 00,264,552 | ---- | M] ()
hpqbid16.dat -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\hpqbid16.dat -> [2007/03/21 10:53:02 | 00,264,531 | ---- | M] ()
hpqbud13.dat -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\setup\hpqbud13.dat -> [2007/03/21 10:53:02 | 00,034,371 | ---- | M] ()
hpqbpl13.dat -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\hpqbpl13.dat -> [2007/03/21 10:53:01 | 00,000,796 | ---- | M] ()
hpqbid13.dat -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\hpqbid13.dat -> [2007/03/21 10:53:00 | 00,264,623 | ---- | M] ()
hpqbud05.dat -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\setup\hpqbud05.dat -> [2007/03/21 10:52:59 | 00,033,928 | ---- | M] ()
hpqbpl05.dat -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\hpqbpl05.dat -> [2007/03/21 10:52:58 | 00,000,697 | ---- | M] ()
hpqbid05.dat -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\hpqbid05.dat -> [2007/03/21 10:52:57 | 00,264,558 | ---- | M] ()
hpqbud11.dat -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\setup\hpqbud11.dat -> [2007/03/21 10:52:54 | 00,034,563 | ---- | M] ()
hpqbpl11.dat -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\hpqbpl11.dat -> [2007/03/21 10:52:53 | 00,000,650 | ---- | M] ()
hpqbid11.dat -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\hpqbid11.dat -> [2007/03/21 10:52:52 | 00,264,539 | ---- | M] ()
hpqbpl01.dat -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\hpqbpl01.dat -> [2007/03/21 10:52:50 | 00,000,781 | ---- | M] ()
hpqhsc01.dat -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\setup\hpqhsc01.dat -> [2007/03/21 10:52:48 | 00,033,725 | ---- | M] ()
hpqbpl06.dat -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\hpqbpl06.dat -> [2007/03/21 10:52:47 | 00,000,768 | ---- | M] ()
hpqbid06.dat -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\hpqbid06.dat -> [2007/03/21 10:52:46 | 00,264,612 | ---- | M] ()
hpowiax3.dll -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\drivers\scanner\x32\hpowiax3.dll -> [2007/03/18 08:11:13 | 00,675,840 | ---- | M] (Hewlett-Packard)
hpovst10.dll -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\drivers\scanner\x32\hpovst10.dll -> [2007/03/18 08:11:13 | 00,303,104 | ---- | M] (Hewlett-Packard Co.)
hpotscl3.dll -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\drivers\scanner\x32\hpotscl3.dll -> [2007/03/18 08:11:12 | 00,569,344 | ---- | M] (Hewlett-Packard Co.)
hpotpusd.dll -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\drivers\scanner\x32\hpotpusd.dll -> [2007/03/18 08:11:12 | 00,229,376 | ---- | M] (Hewlett-Packard)
hpotiop3.dll -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\drivers\scanner\x32\hpotiop3.dll -> [2007/03/18 08:11:11 | 00,958,464 | ---- | M] (Hewlett-Packard Co.)
hpowiax3.dll -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\drivers\scanner\x64\hpowiax3.dll -> [2007/03/18 08:11:11 | 00,861,184 | ---- | M] (Hewlett-Packard)
hpovst10.dll -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\drivers\scanner\x64\hpovst10.dll -> [2007/03/18 08:11:10 | 00,497,664 | ---- | M] (Hewlett-Packard Co.)
hpotiop3.dll -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\drivers\scanner\x64\hpotiop3.dll -> [2007/03/18 08:11:09 | 01,389,056 | ---- | M] (Hewlett-Packard Co.)
hpotscl3.dll -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\drivers\scanner\x64\hpotscl3.dll -> [2007/03/18 08:11:09 | 00,729,600 | ---- | M] (Hewlett-Packard Co.)
hpqbhp01.exe -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\setup\hpqbhp01.exe -> [2007/03/12 11:17:21 | 00,634,880 | ---- | M] (Hewlett-Packard)
hpqrrx08.exe -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\util\ccc\hpqrrx08.exe -> [2007/03/12 11:14:58 | 00,081,920 | ---- | M] (Hewlett-Packard Co.)
hppldcoi.x64.dll -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\drivers\dot4\amd64\winxp\hppldcoi.x64.dll -> [2007/03/08 21:21:00 | 00,481,280 | ---- | M] (Hewlett-Packard)
hppldcoi.dll -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\drivers\dot4\amd64\winxp\hppldcoi.dll -> [2007/03/08 21:20:59 | 00,540,672 | ---- | M] (Hewlett-Packard)
difxapi.dll -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\drivers\dot4\amd64\winxp\difxapi.dll -> [2007/03/08 21:20:58 | 00,508,928 | ---- | M] (Microsoft Corporation)
hpzc3212.dll -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\drivers\dot4\win2000\hpzc3212.dll -> [2007/03/08 21:20:47 | 00,286,720 | ---- | M] (Hewlett-Packard Co.)
hppldcoi.dll -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\drivers\dot4\win2000\hppldcoi.dll -> [2007/03/08 21:20:46 | 00,364,544 | ---- | M] (Hewlett-Packard)
difxapi.dll -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\drivers\dot4\win2000\difxapi.dll -> [2007/03/08 21:20:45 | 00,309,760 | ---- | M] (Microsoft Corporation)
hpzuci12.dll -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\hpzuci12.dll -> [2007/03/08 21:20:44 | 00,018,560 | ---- | M] ()
hpzc3212.dll -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\hpzc3212.dll -> [2007/03/08 21:20:37 | 00,282,624 | ---- | M] (Hewlett-Packard Co.)
hpzdirb.dat -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\setup\hpzdirb.dat -> [2007/01/12 12:59:29 | 00,004,523 | ---- | M] ()
hpzprl02.dat -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\hpzprl02.dat -> [2006/12/22 13:22:23 | 00,004,468 | ---- | M] ()
hpzprl42.dat -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\hpzprl42.dat -> [2006/12/22 13:17:57 | 00,001,092 | ---- | M] ()
HPZmsi40.exe -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\setup\HPZmsi40.exe -> [2006/12/21 00:05:23 | 01,364,568 | ---- | M] (Hewlett-Packard)
hpzmsirb.dat -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\setup\hpzmsirb.dat -> [2006/10/25 12:01:02 | 00,000,242 | ---- | M] ()
DPInst.exe -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\setup\DPInst_x64_VISTA\DPInst.exe -> [2006/10/24 21:48:05 | 00,667,648 | ---- | M] (Microsoft Corporation)
DPInst.exe -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\setup\DPInst_x32_VISTA\DPInst.exe -> [2006/10/24 21:47:22 | 00,534,528 | ---- | M] (Microsoft Corporation)
DPInst.exe -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\setup\DPInst_x32\DPInst.exe -> [2006/10/24 21:47:12 | 00,534,528 | ---- | M] (Microsoft Corporation)
HPZnet01.exe -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\setup\HPZnet01.exe -> [2006/09/05 09:41:36 | 00,397,312 | ---- | M] (Hewlett-Packard)
HPZnfx01.exe -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\setup\HPZnfx01.exe -> [2006/09/05 09:37:50 | 00,323,584 | ---- | M] (Hewlett-Packard)
WindowsXP-KB822603-x86-enu.exe -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\util\ccc\enu\WindowsXP-KB822603-x86-enu.exe -> [2006/08/24 04:08:34 | 00,349,472 | ---- | M] (Microsoft Corporation)
Q283787_W2K_SP3_x86.EXE -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\util\ccc\Q283787_W2K_SP3_x86.EXE -> [2006/08/24 04:08:32 | 00,103,664 | ---- | M] ()
Q283787_W2K_SP3_x86.EXE -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\util\ccc\enu\Q283787_W2K_SP3_x86.EXE -> [2006/08/24 04:08:32 | 00,103,664 | ---- | M] ()
FixErr1714.exe -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\util\ccc\FixErr1714.exe -> [2006/08/24 04:08:04 | 00,192,512 | ---- | M] (Hewlett-Packard)
AccessDeniedUtility.exe -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\util\ccc\AccessDeniedUtility.exe -> [2006/08/24 04:07:59 | 00,242,896 | ---- | M] (Hewlett-Packard)
DPInst.exe -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\setup\DPInst_x64\DPInst.exe -> [2006/08/24 03:58:34 | 00,667,648 | ---- | M] (Microsoft Corporation)
instmsi.exe -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\setup\wis\win2k_xp\instmsi.exe -> [2006/08/24 03:23:52 | 01,821,008 | ---- | M] (Microsoft Corporation)
usbready.exe -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\setup\usbready.exe -> [2006/08/24 03:23:47 | 00,545,280 | ---- | M] (Intel Corporation)
RulesEngine.dll -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\setup\RulesEngine.dll -> [2006/08/24 03:23:44 | 00,315,392 | ---- | M] (Hewlett-Packard)
msxml3r.dll -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\setup\msxml3r.dll -> [2006/08/24 03:23:38 | 00,044,032 | ---- | M] (Microsoft Corporation)
msxml3a.dll -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\setup\msxml3a.dll -> [2006/08/24 03:23:36 | 00,024,576 | ---- | M] (Microsoft Corporation)
msxml3.dll -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\setup\msxml3.dll -> [2006/08/24 03:23:32 | 01,118,720 | ---- | M] (Microsoft Corporation)
InternetUtil.dll -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\setup\InternetUtil.dll -> [2006/08/24 03:23:20 | 00,339,968 | ---- | M] (Hewlett-Packard)
InstallMetrics.dll -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\setup\InstallMetrics.dll -> [2006/08/24 03:23:18 | 00,176,128 | ---- | M] (Hewlett-Packard)
HPScripting.dll -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\setup\HPScripting.dll -> [2006/08/24 03:23:15 | 00,081,920 | ---- | M] (Hewlett-Packard)
HPeSupport.dll -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\setup\HPeSupport.dll -> [2006/08/24 03:23:13 | 00,124,016 | ---- | M] (Hewlett-Packard)
HPeDiag.dll -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\setup\HPeDiag.dll -> [2006/08/24 03:23:11 | 00,319,488 | ---- | M] (Hewlett-Packard)
HPCommunication.dll -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\setup\HPCommunication.dll -> [2006/08/24 03:23:08 | 00,208,896 | ---- | M] (Hewlett-Packard)
hpzprl03.dat -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\hpzprl03.dat -> [2006/08/24 03:22:56 | 00,000,507 | ---- | M] ()
hpqbid07.dat -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\hpqbid07.dat -> [2006/08/13 09:00:00 | 00,122,022 | ---- | M] ()
hpqbud06.dat -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\setup\hpqbud06.dat -> [2006/08/13 09:00:00 | 00,018,037 | ---- | M] ()
HPZscr01.exe.dat -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\setup\DeviceManagement\HPZscr01.exe.dat -> [2006/08/13 09:00:00 | 00,010,862 | ---- | M] ()
HPZscr01.exe.dat -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\setup\eSupport\HPZscr01.exe.dat -> [2006/08/13 09:00:00 | 00,010,629 | ---- | M] ()
hpqphbck.dat -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\hpqphbck.dat -> [2006/08/13 09:00:00 | 00,000,969 | ---- | M] ()
msvcp60.dll -> C:\Documents and Settings\Sara Helen\Local Settings\Temp\7zS197.tmp\setup\msvcp60.dll -> [2002/03/07 02:10:49 | 00,401,462 | ---- | M] (Microsoft Corporation)
< End of report >
cheetahmeow
Active Member
 
Posts: 10
Joined: May 16th, 2009, 10:21 am

Re: Can't update anti-virus software, access iTunes

Unread postby peku006 » May 22nd, 2009, 12:39 pm

Hi cheetahmeow

There is no malware that would be causing your problem..

Let's have a look at Windows Event Viewer. It might give us a clue as to what is causing these issues

Go to Start > Run - type in eventvwr <Press Enter>

You will see Application, Security & System listed in the left pane.
  • In the left pane click on Application.
  • Click the gray title "Type" at the top of the source name column in the right pane to sort by type name
  • Look for "Error" & double-click on the most recent 10, and evaluate the event description for any indication of the cause of the problem.
  • Make note of the Description, EventID and Source of these Event Properties.
  • From the right pane, doubleclick on the line where it says error & you should get a window like the example below:
  • Image
  • In the upper right corner of this picture, you should see 2 arrows. One is pointing up & the other, pointing down.
  • There is another button below the 2 arrows. Click once on it. (this will copy some information to clipboard)
  • Open notepad & paste the info in there. This will copy the event information to the clipboard. Paste the information for each event here

Thanks peku006
User avatar
peku006
MRU Emeritus
MRU Emeritus
 
Posts: 3357
Joined: May 14th, 2007, 2:18 pm
Location: Norway

Re: Can't update anti-virus software, access iTunes

Unread postby cheetahmeow » May 23rd, 2009, 11:19 am

Hi again -

The logs are below. I tried to include all of the different variations of source, category and events. Below these error logs you'll find a few warning logs. I thought they might be of interest. Thank you so much for your patient help. I really, really appreciate it.

ERROR

Event Type: Error
Event Source: Application Hang
Event Category: (101)
Event ID: 1002
Date: 5/21/2009
Time: 5:42:52 PM
User: N/A
Computer: SARA
Description:
Hanging application iexplore.exe, version 7.0.6000.16827, hang module hungapp, version 0.0.0.0, hang address 0x00000000.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 41 70 70 6c 69 63 61 74 Applicat
0008: 69 6f 6e 20 48 61 6e 67 ion Hang
0010: 20 20 69 65 78 70 6c 6f iexplo
0018: 72 65 2e 65 78 65 20 37 re.exe 7
0020: 2e 30 2e 36 30 30 30 2e .0.6000.
0028: 31 36 38 32 37 20 69 6e 16827 in
0030: 20 68 75 6e 67 61 70 70 hungapp
0038: 20 30 2e 30 2e 30 2e 30 0.0.0.0
0040: 20 61 74 20 6f 66 66 73 at offs
0048: 65 74 20 30 30 30 30 30 et 00000
0050: 30 30 30 000


No. 2

Event Type: Error
Event Source: crypt32
Event Category: None
Event ID: 8
Date: 5/19/2009
Time: 9:25:11 AM
User: N/A
Computer: SARA
Description:
Failed auto update retrieval of third-party root list sequence number from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> with error: This operation returned because the timeout period expired.


For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.

No 3:
Event Type: Error
Event Source: Application Error
Event Category: None
Event ID: 1000
Date: 5/18/2009
Time: 12:26:23 PM
User: N/A
Computer: SARA
Description:
Faulting application firefox.exe, version 1.9.0.3399, faulting module xul.dll, version 1.9.0.3399, fault address 0x0047c035.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 41 70 70 6c 69 63 61 74 Applicat
0008: 69 6f 6e 20 46 61 69 6c ion Fail
0010: 75 72 65 20 20 66 69 72 ure fir
0018: 65 66 6f 78 2e 65 78 65 efox.exe
0020: 20 31 2e 39 2e 30 2e 33 1.9.0.3
0028: 33 39 39 20 69 6e 20 78 399 in x
0030: 75 6c 2e 64 6c 6c 20 31 ul.dll 1
0038: 2e 39 2e 30 2e 33 33 39 .9.0.339
0040: 39 20 61 74 20 6f 66 66 9 at off
0048: 73 65 74 20 30 30 34 37 set 0047
0050: 63 30 33 35 0d 0a c035..

No. 4:
Event Type: Error
Event Source: Application Error
Event Category: (100)
Event ID: 1000
Date: 5/3/2009
Time: 8:24:50 PM
User: N/A
Computer: SARA
Description:
Faulting application AcroRd32.exe, version 8.1.0.137, faulting module AcroRd32.dll, version 8.1.0.137, fault address 0x002c07a4.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 41 70 70 6c 69 63 61 74 Applicat
0008: 69 6f 6e 20 46 61 69 6c ion Fail
0010: 75 72 65 20 20 41 63 72 ure Acr
0018: 6f 52 64 33 32 2e 65 78 oRd32.ex
0020: 65 20 38 2e 31 2e 30 2e e 8.1.0.
0028: 31 33 37 20 69 6e 20 41 137 in A
0030: 63 72 6f 52 64 33 32 2e croRd32.
0038: 64 6c 6c 20 38 2e 31 2e dll 8.1.
0040: 30 2e 31 33 37 20 61 74 0.137 at
0048: 20 6f 66 66 73 65 74 20 offset
0050: 30 30 32 63 30 37 61 34 002c07a4



The logs below are from around the day when the problems began:

Event Type: Error
Event Source: Application Hang
Event Category: (101)
Event ID: 1002
Date: 2/23/2009
Time: 3:17:54 PM
User: N/A
Computer: SARA
Description:
Hanging application iexplore.exe, version 7.0.6000.16791, hang module hungapp, version 0.0.0.0, hang address 0x00000000.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 41 70 70 6c 69 63 61 74 Applicat
0008: 69 6f 6e 20 48 61 6e 67 ion Hang
0010: 20 20 69 65 78 70 6c 6f iexplo
0018: 72 65 2e 65 78 65 20 37 re.exe 7
0020: 2e 30 2e 36 30 30 30 2e .0.6000.
0028: 31 36 37 39 31 20 69 6e 16791 in
0030: 20 68 75 6e 67 61 70 70 hungapp
0038: 20 30 2e 30 2e 30 2e 30 0.0.0.0
0040: 20 61 74 20 6f 66 66 73 at offs
0048: 65 74 20 30 30 30 30 30 et 00000
0050: 30 30 30 000


WARNINGS

Event Type: Warning
Event Source: Userenv
Event Category: None
Event ID: 1517
Date: 5/22/2009
Time: 12:18:18 PM
User: NT AUTHORITY\SYSTEM
Computer: SARA
Description:
Windows saved user SARA\Sara Helen registry while an application or service was still using the registry during log off. The memory used by the user's registry has not been freed. The registry will be unloaded when it is no longer in use.

This is often caused by services running as a user account, try configuring the services to run in either the LocalService or NetworkService account.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.

No. 2

Event Type: Warning
Event Source: Userenv
Event Category: None
Event ID: 1517
Date: 5/14/2009
Time: 11:43:20 AM
User: NT AUTHORITY\SYSTEM
Computer: SARA
Description:
Windows saved user SARA\Sara Helen registry while an application or service was still using the registry during log off. The memory used by the user's registry has not been freed. The registry will be unloaded when it is no longer in use.

This is often caused by services running as a user account, try configuring the services to run in either the LocalService or NetworkService account.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
cheetahmeow
Active Member
 
Posts: 10
Joined: May 16th, 2009, 10:21 am

Re: Can't update anti-virus software, access iTunes

Unread postby peku006 » May 23rd, 2009, 1:36 pm

Hi cheetahmeow

Check your hosts file

  • Click on Start
  • Click on Run
  • Copy & paste the text in the code box below
      Code: Select all
      notepad C:\WINDOWS\system32\drivers\etc\hosts

  • Click OK, notepad will then open with your host file
  • Copy and paste the whole hosts file in a reply

Thanks peku006
User avatar
peku006
MRU Emeritus
MRU Emeritus
 
Posts: 3357
Joined: May 14th, 2007, 2:18 pm
Location: Norway

Re: Can't update anti-virus software, access iTunes

Unread postby cheetahmeow » May 23rd, 2009, 3:25 pm

Here you go!

# Copyright (c) 1993-1999 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

127.0.0.1 localhost
cheetahmeow
Active Member
 
Posts: 10
Joined: May 16th, 2009, 10:21 am

Re: Can't update anti-virus software, access iTunes

Unread postby peku006 » May 23rd, 2009, 3:37 pm

Hi cheetahmeow

not showing any suspicious.......last attempt

Please download HostXpert.
  • Unzip HostsXpert.zip
  • Double click on HostsXpert.exe
  • Then click on Restore ms Hosts file to restore your Hosts file to its default condidtion..
  • Click on Make Read Only to secure it against further infection.
  • Close program when complete.

and post back if it helped.

Thanks peku006
User avatar
peku006
MRU Emeritus
MRU Emeritus
 
Posts: 3357
Joined: May 14th, 2007, 2:18 pm
Location: Norway

Re: Can't update anti-virus software, access iTunes

Unread postby cheetahmeow » May 24th, 2009, 10:50 am

Hi again,

I tried your suggestion last night and it didn't work. I thought I'd give it a whirl again today after restarting my machine. When I click on Restore MS Hosts File I get an error message. It reads: Error: Cannot create file C:\Windows\system32\drivers\ETC\hosts
cheetahmeow
Active Member
 
Posts: 10
Joined: May 16th, 2009, 10:21 am

Re: Can't update anti-virus software, access iTunes

Unread postby peku006 » May 26th, 2009, 1:38 am

Hi cheetahmeow

Rename your hosts file

  • Click on Start
  • Click on Run
  • Copy and paste line from below. Be sure and include the word notepad
      notepad C:\WINDOWS\system32\drivers\etc\

  • Click OK, notepad will then open where you host file is located
  • rename host to host.old by right clicking host and choosing rename from the menu.


and then try again "click on Restore ms Hosts file"

Thanks peku006
User avatar
peku006
MRU Emeritus
MRU Emeritus
 
Posts: 3357
Joined: May 14th, 2007, 2:18 pm
Location: Norway
Advertisement
Register to Remove

Next

  • Similar Topics
    Replies
    Views
    Last post

Return to Infected? Virus, malware, adware, ransomware, oh my!



Who is online

Users browsing this forum: No registered users and 433 guests

Contact us:

Advertisements do not imply our endorsement of that product or service. Register to remove all ads. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks are the property of their respective owners.

Member site: UNITE Against Malware