I have the same problems
I've done everything listed here. I googled the virus and this forum came up and my problem happens when I open Deus Ex 2: Invisible War. It loads up the entire game until I click Load Game and select the level I want to load, then the program minimizes and I can't use it anymore, while AVG detects the Trojan horse Proxy.ABWC
the file name for me is C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\sintfnt.dll
Here's my ComboFix log:
ComboFix 08-05-26.2 - HP_Administrator 2008-05-26 22:20:13.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.452 [GMT -7:00]
Running from: C:\Documents and Settings\HP_Administrator\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
C:\Documents and Settings\HP_Administrator\Application Data\ShoppingReport
C:\Documents and Settings\HP_Administrator\Application Data\ShoppingReport\cs\Config.xml
C:\Documents and Settings\HP_Administrator\Application Data\ShoppingReport\cs\db\Aliases.dbs
C:\Documents and Settings\HP_Administrator\Application Data\ShoppingReport\cs\db\Sites.dbs
C:\Documents and Settings\HP_Administrator\Application Data\ShoppingReport\cs\dwld\WhiteList.xip
C:\Documents and Settings\HP_Administrator\Application Data\ShoppingReport\cs\report\aggr_storage.xml
C:\Documents and Settings\HP_Administrator\Application Data\ShoppingReport\cs\report\send_storage.xml
C:\Documents and Settings\HP_Administrator\Application Data\ShoppingReport\cs\res1\WhiteList.dbs
C:\Program Files\ShoppingReport
C:\Program Files\ShoppingReport\Uninst.exe
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2008-04-27 to 2008-05-27 )))))))))))))))))))))))))))))))
.
2008-05-16 18:21 . 2008-05-16 18:21 <DIR> d-------- C:\Documents and Settings\HP_Administrator\Application Data\Snapfish
2008-05-16 17:51 . 2008-05-16 17:51 <DIR> d-------- C:\Program Files\Picasa2
2008-05-11 12:08 . 2008-05-11 12:08 <DIR> d-------- C:\Program Files\iPod
2008-05-11 12:08 . 2008-05-11 12:08 <DIR> d-------- C:\Documents and Settings\HP_Administrator\Application Data\Apple Computer
2008-05-11 12:08 . 2008-05-26 11:07 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-05-11 12:08 . 2008-05-11 12:08 1,409 --a------ C:\WINDOWS\QTFont.for
2008-05-11 12:07 . 2008-05-11 12:07 <DIR> d-------- C:\Program Files\QuickTime
2008-05-11 12:07 . 2008-05-11 12:08 <DIR> d-------- C:\Program Files\iTunes
2008-05-11 12:07 . 2008-05-11 12:07 <DIR> d-------- C:\Program Files\Bonjour
2008-05-11 12:07 . 2008-05-11 12:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-05-11 12:06 . 2008-05-11 12:06 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-05-11 12:06 . 2008-05-11 12:06 <DIR> d-------- C:\Program Files\Common Files\Apple
2008-05-11 12:06 . 2008-05-11 12:06 <DIR> d-------- C:\Program Files\Apple Software Update
2008-05-11 12:06 . 2008-05-11 12:06 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-05-11 12:06 . 2008-02-18 11:16 30,464 --a------ C:\WINDOWS\system32\drivers\usbaapl.sys
2008-05-08 18:40 . 2008-05-08 18:40 <DIR> d-------- C:\Program Files\BitPim
2008-05-08 18:36 . 2008-05-08 18:36 <DIR> d--h----- C:\temp\pt8q3khslw
2008-05-08 18:27 . 2008-05-08 18:27 <DIR> d-------- C:\Program Files\Samsung
2008-05-08 18:27 . 2007-07-03 16:58 106,792 --a------ C:\WINDOWS\system32\drivers\sscdmdm.sys
2008-05-08 18:27 . 2007-07-03 16:59 86,824 --a------ C:\WINDOWS\system32\drivers\sscdserd.sys
2008-05-08 18:27 . 2007-07-03 16:54 80,552 --a------ C:\WINDOWS\system32\drivers\sscdbus.sys
2008-05-08 18:27 . 2007-07-03 16:57 11,944 --a------ C:\WINDOWS\system32\drivers\sscdmdfl.sys
2008-05-08 18:27 . 2007-07-03 17:00 9,256 --a------ C:\WINDOWS\system32\drivers\sscdwhnt.sys
2008-05-08 18:27 . 2007-07-03 17:00 9,256 --a------ C:\WINDOWS\system32\drivers\sscdwh.sys
2008-05-08 18:27 . 2007-07-03 16:56 9,256 --a------ C:\WINDOWS\system32\drivers\sscdcmnt.sys
2008-05-08 18:27 . 2007-07-03 16:56 9,256 --a------ C:\WINDOWS\system32\drivers\sscdcm.sys
2008-05-08 18:26 . 2008-05-08 18:26 <DIR> d-------- C:\Program Files\Verizon Wireless
2008-05-08 18:26 . 2008-05-26 12:47 1,609,728 --a------ C:\WINDOWS\MEDB.mdb
2008-05-08 18:26 . 2007-05-01 15:23 528,384 --------- C:\WINDOWS\system32\VZWDownManager.exe
2008-05-08 18:26 . 2007-05-01 15:23 49,152 --------- C:\WINDOWS\system32\VZWDLManager.dll
2008-05-08 18:26 . 2007-05-02 01:34 375 --------- C:\WINDOWS\system32\VZWDLManager.inf
2008-05-07 15:47 . 2008-05-07 15:47 <DIR> d-------- C:\Documents and Settings\HP_Administrator\Application Data\GarageGames
2008-05-06 22:26 . 2008-05-06 22:26 43,520 --a------ C:\WINDOWS\system32\CmdLineExt03.dll
2008-05-06 16:54 . 2008-05-06 16:54 <DIR> d-------- C:\Program Files\directx
2008-05-06 16:40 . 2008-05-06 22:54 <DIR> d-------- C:\Program Files\Deus Ex - Invisible War
2008-05-05 18:08 . 2008-05-05 18:08 <DIR> d-------- C:\Program Files\IrfanView
2008-05-04 15:31 . 2008-05-04 15:32 <DIR> d-------- C:\Documents and Settings\HP_Administrator\Application Data\Otto
2008-05-04 15:31 . 2008-05-04 15:32 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Otto
2008-05-04 15:15 . 2008-05-04 15:15 <DIR> d-------- C:\Documents and Settings\HP_Administrator\Application Data\Template
2008-05-04 15:15 . 2008-05-26 12:46 1,160 --a------ C:\Documents and Settings\HP_Administrator\Application Data\wklnhst.dat
2008-05-04 14:42 . 2008-05-04 14:43 <DIR> d-------- C:\Program Files\DISC
2008-05-04 14:08 . 2008-05-08 18:36 <DIR> d-------- C:\temp
2008-05-03 20:38 . 2008-05-10 21:55 <DIR> d-------- C:\Documents and Settings\HP_Administrator\Application Data\HP
2008-05-03 09:52 . 2004-08-03 23:01 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2008-05-03 09:52 . 2004-08-03 23:01 25,856 --a------ C:\WINDOWS\system32\dllcache\usbprint.sys
2008-05-03 09:52 . 2004-08-03 22:58 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2008-05-03 09:52 . 2004-08-03 22:58 15,104 --a------ C:\WINDOWS\system32\dllcache\usbscan.sys
2008-05-03 09:51 . 2004-08-03 23:08 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2008-05-03 09:51 . 2004-08-03 23:08 31,616 --a------ C:\WINDOWS\system32\dllcache\usbccgp.sys
2008-05-03 08:48 . 2008-05-03 08:48 227 --a------ C:\WINDOWS\HP_CounterReport_Update_HPSU.ini
2008-05-03 08:45 . 2008-05-03 08:45 <DIR> d-------- C:\SystemRoot
2008-05-02 16:24 . 2008-05-02 16:24 <DIR> d-------- C:\Program Files\Common Files\TiVo Shared
2008-05-02 16:13 . 2008-05-02 16:13 <DIR> d-------- C:\Documents and Settings\HP_Administrator\Application Data\Sonic
2008-05-02 16:12 . 2008-05-02 16:12 <DIR> d-------- C:\Documents and Settings\HP_Administrator\Application Data\Leadertech
2008-05-02 11:49 . 2008-05-02 11:49 <DIR> d-------- C:\Documents and Settings\HP_Administrator\Application Data\WildTangent
2008-05-02 11:49 . 2008-05-02 11:49 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WildTangent
2008-05-02 11:19 . 2008-05-02 11:19 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2008-05-02 11:17 . 2008-05-08 18:45 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2008-05-02 11:17 . 2008-05-02 11:18 <DIR> d-------- C:\fad5e8b528dbc97ae85030
2008-05-02 11:17 . 2008-05-02 11:17 <DIR> d-------- C:\
0514281461503bf77bfc3aa16f47
2008-04-30 21:54 . 2008-04-30 21:54 <DIR> d-------- C:\Documents and Settings\HP_Administrator\Application Data\AdobeUM
2008-04-27 19:48 . 2008-05-16 18:21 1,799 --a------ C:\WINDOWS\mozver.dat
2008-04-27 11:31 . 2008-04-27 11:31 0 --a------ C:\WINDOWS\nsreg.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-07 04:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\Digital Interactive Systems Corporation
2008-05-06 23:40 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-04 22:32 251 ----a-w C:\Program Files\wt3d.ini
2008-05-03 15:52 --------- d-----w C:\Program Files\HP
2008-05-03 15:52 --------- d-----w C:\Program Files\Hewlett-Packard
2008-05-02 23:24 --------- d-----w C:\Program Files\Sonic
2008-05-02 21:30 --------- d-----w C:\Program Files\PC-Doctor 5 for Windows
2008-04-26 19:19 --------- d-----w C:\Program Files\ANI
2008-04-26 19:18 --------- d-----w C:\Program Files\Airlink101
2008-04-26 13:29 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-04-26 13:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-04-26 06:10 96,520 ----a-w C:\WINDOWS\system32\drivers\avgldx86.sys
2008-04-26 06:10 75,272 ----a-w C:\WINDOWS\system32\drivers\avgtdix.sys
2008-04-26 06:10 --------- d-----w C:\Program Files\AVG
2008-04-26 06:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg8
2008-04-26 05:45 --------- d-----w C:\Program Files\Symantec
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-09 21:00 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 16:24 1694208]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-10-02 17:44 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-09-29 21:01 67584]
"RTHDCPL"="RTHDCPL.EXE" [2006-03-08 04:54 16010240 C:\WINDOWS\RTHDCPL.EXE]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-02 23:19 77312 C:\WINDOWS\arpwrmsg.exe]
"HPHUPD08"="c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-01 23:35 49152]
"DMAScheduler"="c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe" [2006-03-20 09:05 90112]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2005-07-22 22:14 237568]
"PCDrProfiler"="" []
"HPBootOp"="C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2006-02-15 22:34 249856]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 16:24 54840]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 18:30 517768]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00 132496]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-04-25 23:10 1177368]
"Airlink101 WLAN Monitor"="C:\Program Files\Airlink101\WLAN Monitor\WLANmon.exe" [2006-06-30 18:55 954368]
"ANIWZCS2Service"="C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [2006-06-01 16:59 49152]
"KBD"="C:\HP\KBD\KBD.EXE" [2005-02-02 16:44 61440]
"DISCover"="C:\Program Files\DISC\DISCover.exe" [2006-03-15 19:12 1077248]
"DiscUpdateManager"="C:\Program Files\DISC\DiscUpdMgr.exe" [2006-03-15 19:11 61440]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]
C:\Documents and Settings\HP_Administrator\Start Menu\Programs\Startup\
MEMonitor.lnk - C:\Program Files\Verizon Wireless\V CAST Music Manager\MEMonitor.exe [2008-05-08 18:26:50 947544]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2005-12-15 18:40:44 282624]
Updates From HP.lnk - C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe [2006-07-22 03:21:53 36903]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"C:\\Program Files\\DISC\\DISCover.exe"=
"C:\\Program Files\\DISC\\DiscStreamHub.exe"=
"C:\\Program Files\\DISC\\myFTP.exe"=
"C:\\Program Files\\Updates from HP\\9972322\\Program\\HPOOVClient.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-04-25 23:10]
R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-04-25 23:10]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-04-25 23:10]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-04-25 23:10]
R3 AL101;Airlink101 802.11g PCI Driver;C:\WINDOWS\system32\DRIVERS\AL101.sys [2006-07-04 15:28]
S3 GameConsoleService;GameConsoleService;"C:\Program Files\WildTangent\Apps\HP Game Console\GameConsoleService.exe" [2008-03-28 16:04]
S3 pohci13F;pohci13F;C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\pohci13F.sys []
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-05-26 22:24:24
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\WINDOWS\TEMP\4cc45e3a-99d2-49a4-9010-fa6e69a2e6fd.tmp
scan completed successfully
hidden files: 1
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\arservice.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\ehome\ehrecvr.exe
C:\WINDOWS\ehome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\ehome\ehmsas.exe
C:\Program Files\DISC\DiscStreamHub.exe
C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
.
**************************************************************************
.
Completion time: 2008-05-26 22:27:33 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-27 05:27:29
Pre-Run: 173,086,027,776 bytes free
Post-Run: 173,227,888,640 bytes free
219 --- E O F --- 2008-05-16 15:14:18
and here's my SDFix log:
SDFix: Version 1.186
Run by HP_Administrator on Mon 05/26/2008 at 10:51 PM
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix\SDFix
Checking Services :
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting
Checking Files :
No Trojan Files Found
Removing Temp Files
ADS Check :
Final Check :
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-05-26 23:00:58
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services :
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled
xpsp2res.dll,-22019"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe:*:Enabled:hpofxm08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe:*:Enabled:hposfx08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe:*:Enabled:hposid01.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe:*:Enabled:hpqcopy.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe:*:Enabled:hpfccopy.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"="C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe:*:Enabled:hpqphunl.exe"
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"="C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe:*:Enabled:hpqdia.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe:*:Enabled:hpoews01.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe:*:Enabled:hpqnrs08.exe"
"C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"="C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe:*:Enabled:Updates from HP"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"="C:\\Program Files\\AVG\\AVG8\\avgupd.exe:*:Enabled:avgupd.exe"
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"="C:\\Program Files\\AVG\\AVG8\\avgemc.exe:*:Enabled:avgemc.exe"
"C:\\Program Files\\DISC\\DISCover.exe"="C:\\Program Files\\DISC\\DISCover.exe:*:Enabled
ISCover Drop & Play System"
"C:\\Program Files\\DISC\\DiscStreamHub.exe"="C:\\Program Files\\DISC\\DiscStreamHub.exe:*:Enabled
ISCover Stream Hub"
"C:\\Program Files\\DISC\\myFTP.exe"="C:\\Program Files\\DISC\\myFTP.exe:*:Enabled
ISCover FTP"
"C:\\Program Files\\Updates from HP\\9972322\\Program\\HPOOVClient.exe"="C:\\Program Files\\Updates from HP\\9972322\\Program\\HPOOVClient.exe:*:Enabled:Updates from HP"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled
xpsp2res.dll,-22019"
"C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"="C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe:*:Enabled:Updates from HP"
Remaining Files :
File Backups: - C:\SDFix\SDFix\backups\backups.zip
Files with Hidden Attributes :
Sun 12 Aug 2007 211 A.SHR --- "C:\BOOT.BAK"
Fri 16 May 2008 6,104,632 A..H. --- "C:\Program Files\Picasa2\setup.exe"
Sat 26 Apr 2008 22 A.SH. --- "C:\WINDOWS\SMINST\HPCD.sys"
Fri 16 May 2008 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Thu 5 Jul 2007 146,432 ..SHR --- "C:\Program Files\Verizon Wireless\V CAST Music Manager\Setup.exe"
Mon 7 May 2007 53,248 A.SHR --- "C:\Program Files\Verizon Wireless\V CAST Music Manager\_Setupx.dll"
Fri 2 May 2008 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Tue 6 May 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\385cb67dda0ffd4dea8c0d990dc65796\BIT31.tmp"
Wed 14 Dec 2005 200,704 A..H. --- "C:\Program Files\Online Services\Aol\United States\AOL90\ACST4.DLL"
Tue 22 Nov 2005 81,920 A..H. --- "C:\Program Files\Online Services\Aol\United States\AOL90\AOLFIREWALLMGR.DLL"
Tue 22 Nov 2005 73,728 A..H. --- "C:\Program Files\Online Services\Aol\United States\AOL90\AOLINSTALLERFW.DLL"
Wed 14 Dec 2005 88,064 A..H. --- "C:\Program Files\Online Services\Aol\United States\AOL90\INSTPH.DLL"
Wed 14 Dec 2005 200,704 A..H. --- "C:\Program Files\Online Services\Aol\United States\AOL90E\ACST4.DLL"
Tue 22 Nov 2005 81,920 A..H. --- "C:\Program Files\Online Services\Aol\United States\AOL90E\AOLFIREWALLMGR.DLL"
Tue 22 Nov 2005 73,728 A..H. --- "C:\Program Files\Online Services\Aol\United States\AOL90E\AOLINSTALLERFW.DLL"
Wed 14 Dec 2005 88,064 A..H. --- "C:\Program Files\Online Services\Aol\United States\AOL90E\INSTPH.DLL"
Finished!