This is a read-only archive. No new posts or registrations. Privacy Page
Software

Had 104 bugs Cleaned BUT system running Very slow LONG boot up and 45

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

The Team at Sypbot sent me here..

They did a great job in cleaning out my system have been a massive infection
BUT now it takes sooo long for anything to happen
when i click on any app it take 30 45 sec for the apps to start.
I am virus free.
PLEASE help solve this finial part…

My system information is :.
Item Value
OS Name Microsoft Windows XP Professional
Version 5.1.2600 Service Pack 3 Build 2600
OS Manufacturer Microsoft Corporation
System Name KEN-6F846939A5D
System Manufacturer SNC302EEH
System Model Not Available
System Type X86-based PC
Processor x86 Family 6 Model 8 Stepping 6 GenuineIntel ~701 Mhz
BIOS Version/Date Award Software International, Inc. 6.00 PG, 1/16/2001
SMBIOS Version 2.1
Windows Directory C:\WINDOWS
System Directory C:\WINDOWS\system32
Boot Device \Device\HarddiskVolume1
Locale United States
Hardware Abstraction Layer Version = "5.1.2600.5512 (xpsp.080413-2111)"
User Name KEN-6F846939A5D\Ken
Time Zone Eastern Daylight Time
Total Physical Memory 512.00 MB
Available Physical Memory 190.81 MB
Total Virtual Memory 2.00 GB
Available Virtual Memory 1.96 GB
Page File Space 865.49 MB
Page File C:\pagefile.sys

We have run;

random's system information tool (RSIT)
Run Malwarebytes' Anti-Malware no virus found
Ran Kaspersky Online Scan no virus found
StartupLite.
ATF (Atribune Temp File) Cleaner© by Atribune cleaned out all files
Ran OTL by Old Timer …showed a lot of errors in the error log


Thanks for any help… :thumbup:


HR




Greetings. Did you have any such issues prior to your infection? What is the size of your C: drive and how much is used? (right click C: under My Computer then click Properties)
Hi jephree and thanks for responding… :notworthy:

NO my son (this is his PC) was having NO issues to speak of..
He has a Laptop he uses for school and plays games and music on this one.
We know it's slow BUT Never like this. The 104 bugs must have left some big holes in the OS.
He was useing PC One Care but o have tried to disablem and tried to remove it but it was difficult.
He uses Spybot S&D and Malwarebytes.. now but had nothing Subscription ran out on One Care
and he was wide open and thats how he got infected.

To answer your question:
HD= 14GB
6.92 used
6.83 Free
Hello HR

That is an incredibly small hard drive but as it is @50% free should not be an issue.

Ran OTL by Old Timer …showed a lot of errors in the error log


Can you please post this error log here?
evening jephree :wavey:

There are 2 logs that are generated I have posted both.
The 2nd log shows most of the errors..
Plus looks like there are too many virus programs running. :wacko:
thanks for looking
even now there is a 2 -3 sec delay after i hit a key and see it on the screen????

HR


File #1

OTL logfile created on: 10/22/2009 12:17:47 AM - Run 3
OTL by OldTimer - Version 3.0.18.4 Folder = C:\Documents and Settings\Ken\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

510.55 Mb Total Physical Memory | 335.06 Mb Available Physical Memory | 65.63% Memory free
865.49 Mb Paging File | 745.51 Mb Available in Paging File | 86.14% Paging File free
Paging file location(s): C:\pagefile.sys 384 768 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 13.77 Gb Total Space | 6.80 Gb Free Space | 49.39% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: KEN-6F846939A5D
Current User Name: Ken
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\WINDOWS\System32\lxdccoms.exe ( )
PRC - C:\WINDOWS\System32\wscntfy.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\Ken\Desktop\OTL.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (Bonjour Service [Auto | Running]) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) – c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (idsvc [Unknown | Stopped]) – c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (JavaQuickStarterService [Auto | Running]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (lxdc_device [Auto | Running]) – C:\WINDOWS\System32\lxdccoms.exe ( )
SRV - (NetTcpPortSharing [Disabled | Stopped]) – c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (ac97intc [On_Demand | Running]) – C:\WINDOWS\System32\drivers\ac97intc.sys (Intel Corporation)
DRV - (EL90XBC [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\el90xbc5.sys (3Com Corporation)
DRV - (gameenum [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\gameenum.sys (Microsoft Corporation)
DRV - (i81x [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\i81xnt5.sys (Intel® Corporation)
DRV - (iAimFP0 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wADV01nt.sys (Intel® Corporation)
DRV - (iAimFP1 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wADV02NT.sys (Intel® Corporation)
DRV - (iAimFP2 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wADV05NT.sys (Intel® Corporation)
DRV - (iAimFP3 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wSiINTxx.sys (Intel® Corporation)
DRV - (iAimFP4 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wVchNTxx.sys (Intel® Corporation)
DRV - (iAimFP5 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wADV07nt.sys (Intel® Corporation)
DRV - (iAimFP6 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wADV08nt.sys (Intel® Corporation)
DRV - (iAimFP7 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wADV09nt.sys (Intel® Corporation)
DRV - (iAimTV0 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wATV01nt.sys (Intel® Corporation)
DRV - (iAimTV1 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wATV02NT.sys (Intel® Corporation)
DRV - (iAimTV3 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wATV04nt.sys (Intel® Corporation)
DRV - (iAimTV4 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wCh7xxNT.sys (Intel® Corporation)
DRV - (iAimTV5 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wATV10nt.sys (Intel® Corporation)
DRV - (iAimTV6 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wATV06nt.sys (Intel® Corporation)
DRV - (ms_mpu401 [On_Demand | Running]) – C:\WINDOWS\System32\drivers\msmpu401.sys (Microsoft Corporation)
DRV - (NtApm [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\NtApm.sys (Microsoft Corporation)
DRV - (NwlnkIpx [Auto | Running]) – C:\WINDOWS\System32\DRIVERS\nwlnkipx.sys (Microsoft Corporation)
DRV - (NwlnkNb [Auto | Running]) – C:\WINDOWS\System32\DRIVERS\nwlnknb.sys (Microsoft Corporation)
DRV - (NwlnkSpx [Auto | Running]) – C:\WINDOWS\System32\DRIVERS\nwlnkspx.sys (Microsoft Corporation)
DRV - (NWRDR [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\nwrdr.sys (Microsoft Corporation)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm


IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p…&ar;=msnhome
IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p…&ar;=msnhome
IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-484763869-113007714-1957994488-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKU\S-1-5-21-484763869-113007714-1957994488-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKU\S-1-5-21-484763869-113007714-1957994488-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKU\S-1-5-21-484763869-113007714-1957994488-1003\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
IE - HKU\S-1-5-21-484763869-113007714-1957994488-1003\S-1-5-21-484763869-113007714-1957994488-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-484763869-113007714-1957994488-1003\S-1-5-21-484763869-113007714-1957994488-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Ask"
FF - prefs.js..browser.search.defaulturl: "http://search.yahoo.com/search?ei=UTF-8&fr;=ytff-yff3&p;="
FF - prefs.js..browser.search.order.1: "Ask"
FF - prefs.js..browser.search.param.yahoo-fr: "moz2-ytff-yff3"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "moz2-ytff-yff3"
FF - prefs.js..browser.search.selectedEngine: "Ask"
FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com/?fr=fptb-yff3"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}:6.0.16
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.5
FF - prefs.js..keyword.URL: "http://toolbar.ask.com/toolbarv/askRedirect?o=20008&gct;=&gc;=1&q;="

FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/09/02 00:37:34 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2009/10/13 01:47:57 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.5\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/10/13 19:13:43 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.5\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/10/04 19:41:12 | 00,000,000 | —D | M]

[2009/08/23 20:08:54 | 00,000,000 | —D | M] – C:\Documents and Settings\Ken\Application Data\mozilla\Extensions
[2008/09/01 05:32:25 | 00,000,000 | —D | M] – C:\Documents and Settings\Ken\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/08/23 20:08:54 | 00,000,000 | —D | M] – C:\Documents and Settings\Ken\Application Data\mozilla\Extensions\[removed]
[2009/10/18 19:01:20 | 00,000,000 | —D | M] – C:\Documents and Settings\Ken\Application Data\mozilla\Firefox\Profiles\ia1phobk.default\extensions
[2009/09/02 09:28:56 | 00,000,000 | —D | M] – C:\Documents and Settings\Ken\Application Data\mozilla\Firefox\Profiles\ia1phobk.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/09/20 07:40:33 | 00,000,000 | —D | M] – C:\Documents and Settings\Ken\Application Data\mozilla\Firefox\Profiles\ia1phobk.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/06/19 10:44:30 | 00,004,207 | —- | M] () – C:\Documents and Settings\Ken\Application Data\Mozilla\FireFox\Profiles\ia1phobk.default\searchplugins\aim-search.xml
[2009/09/19 22:50:44 | 00,000,681 | —- | M] () – C:\Documents and Settings\Ken\Application Data\Mozilla\FireFox\Profiles\ia1phobk.default\searchplugins\ask.xml
[2009/10/18 19:01:20 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009/10/04 19:41:13 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/10/13 01:48:41 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
[2008/12/02 16:12:11 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2008/12/02 16:12:12 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/10/13 01:47:53 | 00,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeploytk.dll
[2008/12/02 16:12:14 | 00,065,528 | —- | M] (mozilla.org) – C:\Program Files\mozilla firefox\plugins\npnul32.dll
[2009/02/27 12:13:42 | 00,103,792 | —- | M] (Adobe Systems Inc.) – C:\Program Files\mozilla firefox\plugins\nppdf32.dll
[2009/09/19 23:39:07 | 00,159,744 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin.dll
[2009/09/19 23:39:07 | 00,159,744 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll
[2009/09/19 23:39:07 | 00,159,744 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll
[2009/09/19 23:39:08 | 00,159,744 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll
[2009/09/19 23:39:08 | 00,159,744 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll
[2009/09/19 23:39:08 | 00,159,744 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll
[2009/09/19 23:39:09 | 00,159,744 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll
[2008/12/02 04:04:40 | 00,001,394 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2008/12/02 04:04:40 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2008/12/02 04:04:40 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2008/12/02 04:04:40 | 00,002,343 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2008/12/02 04:04:40 | 00,001,706 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2008/12/02 04:04:40 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2008/12/02 04:04:40 | 00,000,792 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (343356 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 11796 more lines…
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKU\S-1-5-21-484763869-113007714-1957994488-1003\..\Toolbar\WebBrowser: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - Startup: C:\Documents and Settings\Ken\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-484763869-113007714-1957994488-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-484763869-113007714-1957994488-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-484763869-113007714-1957994488-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-484763869-113007714-1957994488-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-484763869-113007714-1957994488-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: disableregistrytools = 0
O7 - HKU\S-1-5-21-484763869-113007714-1957994488-1003_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\System32\nwprovau.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 58 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\.DEFAULT\..Trusted Domains: 57 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\S-1-5-18\..Trusted Domains: 57 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\S-1-5-21-484763869-113007714-1957994488-1003\..Trusted Domains: 57 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O30 - LSA: Authentication Packages - (nwprovau) - C:\WINDOWS\System32\nwprovau.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/08/31 23:54:22 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O35 - comfile [open] – "%1" %* File not found
O35 - exefile [open] – "%1" %* File not found

========== Files/Folders - Created Within 30 Days ==========

[2009/10/04 05:56:54 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/10/04 11:20:56 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2009/10/04 05:57:14 | 00,000,000 | —D | C] – C:\Documents and Settings\Ken\Application Data\Malwarebytes
[2009/10/04 19:49:07 | 00,000,000 | —D | C] – C:\Program Files\ERUNT
[2009/10/13 01:47:35 | 00,000,000 | —D | C] – C:\Program Files\Java
[2009/10/04 05:56:52 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/10/04 11:20:56 | 00,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2009/10/04 20:29:02 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/10/14 19:22:53 | 00,204,496 | —- | C] (Malwarebytes) – C:\Documents and Settings\Ken\Desktop\StartUpLite.exe
[2009/10/13 01:58:01 | 00,050,688 | —- | C] (Atribune.org) – C:\Documents and Settings\Ken\Desktop\ATF-Cleaner.exe
[2009/10/13 01:48:35 | 00,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2009/10/13 01:48:34 | 00,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2009/10/13 01:48:34 | 00,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2009/10/13 01:48:34 | 00,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2009/10/13 01:36:18 | 16,664,352 | —- | C] (Sun Microsystems, Inc.) – C:\Documents and Settings\Ken\Desktop\jre-6u16-windows-i586.exe
[2009/10/08 06:36:09 | 00,520,704 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Ken\Desktop\OTL.exe
[2009/10/07 20:47:19 | 00,000,000 | —D | C] – C:\rsit
[2009/10/04 10:53:54 | 00,000,000 | -HSD | C] – C:\RECYCLER
[2009/10/04 10:44:38 | 00,000,000 | —D | C] – C:\WINDOWS\temp
[2009/10/04 09:16:52 | 00,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2009/10/04 05:56:59 | 00,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/10/04 05:56:53 | 00,019,160 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/10/04 00:42:06 | 00,000,000 | —D | C] – C:\WINDOWS\Sun
[2009/10/04 00:27:55 | 00,000,000 | —D | C] – C:\DOWNLOADS
[2009/10/03 00:15:00 | 00,000,000 | —D | C] – C:\WINDOWS\pss
[2009/10/03 00:10:06 | 00,221,184 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wmpns.dll
[2009/04/21 10:03:20 | 00,323,584 | —- | C] ( ) – C:\WINDOWS\System32\LXDChcp.dll
[2007/05/17 10:19:57 | 00,643,072 | —- | C] ( ) – C:\WINDOWS\System32\lxdcpmui.dll
[2007/05/17 10:17:22 | 01,232,896 | —- | C] ( ) – C:\WINDOWS\System32\lxdcserv.dll
[2007/05/17 10:11:47 | 00,425,984 | —- | C] ( ) – C:\WINDOWS\System32\lxdccomm.dll
[2007/05/17 10:10:16 | 00,585,728 | —- | C] ( ) – C:\WINDOWS\System32\lxdclmpm.dll
[2007/05/17 10:08:43 | 00,397,312 | —- | C] ( ) – C:\WINDOWS\System32\lxdciesc.dll
[2007/05/17 10:07:51 | 00,094,208 | —- | C] ( ) – C:\WINDOWS\System32\lxdcpplc.dll
[2007/05/17 10:07:02 | 00,684,032 | —- | C] ( ) – C:\WINDOWS\System32\lxdccomc.dll
[2007/05/17 10:06:32 | 00,163,840 | —- | C] ( ) – C:\WINDOWS\System32\lxdcprox.dll
[2007/05/17 09:59:50 | 00,413,696 | —- | C] ( ) – C:\WINDOWS\System32\lxdcinpa.dll
[2007/05/17 09:58:46 | 00,999,424 | —- | C] ( ) – C:\WINDOWS\System32\lxdcusb1.dll
[2007/05/17 09:53:19 | 00,700,416 | —- | C] ( ) – C:\WINDOWS\System32\lxdchbn3.dll

========== Files - Modified Within 30 Days ==========

[2009/10/22 00:02:15 | 00,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/10/22 00:01:26 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/10/22 00:01:21 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/10/20 23:58:14 | 04,786,666 | -H– | M] () – C:\Documents and Settings\Ken\Local Settings\Application Data\IconCache.db
[2009/10/18 20:39:31 | 00,019,456 | —- | M] () – C:\Documents and Settings\Ken\My Documents\OTL by Old Timer.doc
[2009/10/18 20:00:47 | 00,002,473 | —- | M] () – C:\Documents and Settings\Ken\Desktop\Microsoft Word.lnk
[2009/10/16 21:46:06 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/10/16 21:36:05 | 00,343,356 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2009/10/14 19:23:31 | 00,204,496 | —- | M] (Malwarebytes) – C:\Documents and Settings\Ken\Desktop\StartUpLite.exe
[2009/10/13 01:58:35 | 00,050,688 | —- | M] (Atribune.org) – C:\Documents and Settings\Ken\Desktop\ATF-Cleaner.exe
[2009/10/13 01:47:48 | 00,149,280 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2009/10/13 01:47:48 | 00,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2009/10/13 01:47:47 | 00,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2009/10/13 01:47:47 | 00,073,728 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2009/10/13 01:47:46 | 00,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deploytk.dll
[2009/10/13 01:36:18 | 16,664,352 | —- | M] (Sun Microsystems, Inc.) – C:\Documents and Settings\Ken\Desktop\jre-6u16-windows-i586.exe
[2009/10/08 06:36:24 | 00,520,704 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Ken\Desktop\OTL.exe
[2009/10/07 20:34:04 | 00,781,909 | —- | M] () – C:\Documents and Settings\Ken\Desktop\RSIT.exe
[2009/10/04 20:29:05 | 00,001,734 | —- | M] () – C:\Documents and Settings\Ken\Desktop\HijackThis.lnk
[2009/10/04 19:49:27 | 00,000,767 | —- | M] () – C:\Documents and Settings\Ken\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/10/04 19:49:15 | 00,000,611 | —- | M] () – C:\Documents and Settings\Ken\Desktop\NTREGOPT.lnk
[2009/10/04 19:49:15 | 00,000,592 | —- | M] () – C:\Documents and Settings\Ken\Desktop\ERUNT.lnk
[2009/10/04 19:44:38 | 00,000,139 | —- | M] () – C:\Documents and Settings\Ken\Desktop\Forum Spybot S&D.URL;
[2009/10/04 19:41:20 | 00,001,602 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2009/10/04 13:48:46 | 00,337,430 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20091016-213605.backup
[2009/10/04 11:22:22 | 00,000,933 | —- | M] () – C:\Documents and Settings\Ken\Desktop\Spybot - Search & Destroy.lnk
[2009/10/04 11:17:25 | 00,001,240 | —- | M] () – C:\Documents and Settings\Ken\Desktop\MY Downloads.lnk
[2009/10/04 10:31:12 | 00,000,246 | —- | M] () – C:\WINDOWS\system.ini
[2009/10/04 09:50:12 | 00,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20091004-134846.backup
[2009/10/04 05:57:06 | 00,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/10/04 00:11:58 | 00,650,240 | —- | M] () – C:\Documents and Settings\Ken\My Documents\MicrosoftFixit50203.msi
[2009/10/03 23:50:13 | 00,000,543 | —- | M] () – C:\WINDOWS\win.ini
[2009/10/03 23:50:13 | 00,000,210 | -HS- | M] () – C:\boot.ini
[2009/10/03 00:11:08 | 00,014,816 | —- | M] () – C:\WINDOWS\System32\GDIPFONTCACHEV1.DAT
[2009/09/30 08:02:18 | 00,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2009/09/30 07:58:20 | 00,022,016 | —- | M] () – C:\Documents and Settings\Ken\My Documents\Chelsea Smit1.doc
[2009/09/30 00:12:24 | 00,020,992 | —- | M] () – C:\Documents and Settings\Ken\My Documents\chelseat.doc
[2009/09/30 00:11:12 | 00,021,504 | —- | M] () – C:\Documents and Settings\Ken\My Documents\The struggle for womens rights has been long and difficult.doc
[2009/09/29 23:33:00 | 00,002,471 | —- | M] () – C:\Documents and Settings\Ken\Desktop\Microsoft Excel.lnk

========== Files - No Company Name ==========
[2009/10/18 20:39:30 | 00,019,456 | —- | C] () – C:\Documents and Settings\Ken\My Documents\OTL by Old Timer.doc
[2009/10/07 20:33:43 | 00,781,909 | —- | C] () – C:\Documents and Settings\Ken\Desktop\RSIT.exe
[2009/10/04 20:29:05 | 00,001,734 | —- | C] () – C:\Documents and Settings\Ken\Desktop\HijackThis.lnk
[2009/10/04 19:49:27 | 00,000,767 | —- | C] () – C:\Documents and Settings\Ken\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/10/04 19:49:15 | 00,000,611 | —- | C] () – C:\Documents and Settings\Ken\Desktop\NTREGOPT.lnk
[2009/10/04 19:49:15 | 00,000,592 | —- | C] () – C:\Documents and Settings\Ken\Desktop\ERUNT.lnk
[2009/10/04 19:37:49 | 00,000,139 | —- | C] () – C:\Documents and Settings\Ken\Desktop\Forum Spybot S&D.URL;
[2009/10/04 11:22:22 | 00,000,933 | —- | C] () – C:\Documents and Settings\Ken\Desktop\Spybot - Search & Destroy.lnk
[2009/10/04 11:16:37 | 00,001,240 | —- | C] () – C:\Documents and Settings\Ken\Desktop\MY Downloads.lnk
[2009/10/04 05:57:06 | 00,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/10/04 00:11:56 | 00,650,240 | —- | C] () – C:\Documents and Settings\Ken\My Documents\MicrosoftFixit50203.msi
[2009/10/03 00:11:01 | 00,014,816 | —- | C] () – C:\WINDOWS\System32\GDIPFONTCACHEV1.DAT
[2009/09/30 07:58:17 | 00,022,016 | —- | C] () – C:\Documents and Settings\Ken\My Documents\Chelsea Smit1.doc
[2009/09/30 00:12:24 | 00,020,992 | —- | C] () – C:\Documents and Settings\Ken\My Documents\chelseat.doc
[2009/09/30 00:11:12 | 00,021,504 | —- | C] () – C:\Documents and Settings\Ken\My Documents\The struggle for womens rights has been long and difficult.doc
[2009/09/19 23:52:46 | 04,786,666 | -H– | C] () – C:\Documents and Settings\Ken\Local Settings\Application Data\IconCache.db
[2009/08/23 08:50:11 | 00,009,216 | —- | C] () – C:\Documents and Settings\Ken\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/04/21 10:03:21 | 00,286,720 | —- | C] () – C:\WINDOWS\System32\LXDCinst.dll
[2009/04/08 22:16:09 | 00,344,064 | R— | C] () – C:\WINDOWS\System32\lxdccoin.dll
[2008/09/01 05:29:17 | 00,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2008/09/01 01:42:38 | 00,014,816 | —- | C] () – C:\Documents and Settings\Ken\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2008/09/01 00:06:36 | 00,000,062 | -HS- | C] () – C:\Documents and Settings\Ken\Application Data\desktop.ini
[2008/08/31 19:09:44 | 00,000,062 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\desktop.ini
[2007/05/24 00:04:56 | 00,208,896 | —- | C] () – C:\WINDOWS\System32\lxdcgrd.dll
[2006/05/17 22:47:12 | 00,040,960 | —- | C] () – C:\WINDOWS\System32\lxdcvs.dll
[2004/08/04 08:00:00 | 00,000,543 | —- | C] () – C:\WINDOWS\win.ini
[2004/08/04 08:00:00 | 00,000,246 | —- | C] () – C:\WINDOWS\system.ini
< End of report >





File #2



OTL Extras logfile created on: 10/22/2009 12:17:47 AM - Run 3
OTL by OldTimer - Version 3.0.18.4 Folder = C:\Documents and Settings\Ken\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

510.55 Mb Total Physical Memory | 335.06 Mb Available Physical Memory | 65.63% Memory free
865.49 Mb Paging File | 745.51 Mb Available in Paging File | 86.14% Paging File free
Paging file location(s): C:\pagefile.sys 384 768 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 13.77 Gb Total Space | 6.80 Gb Free Space | 49.39% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: KEN-6F846939A5D
Current User Name: Ken
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.chm [@ = chm.file] – C:\WINDOWS\hh.exe (Microsoft Corporation)
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-484763869-113007714-1957994488-1003\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
chm.file [open] – "%SYSTEMROOT%\hh.exe" %1 (Microsoft Corporation)
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
htmlfile – "C:\Program Files\Microsoft Office\Office\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "%programfiles%\internet explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)
"C:\Program Files\Lexmark 1300 Series\app4r.exe" = C:\Program Files\Lexmark 1300 Series\App4R.exe:*:Enabled:Lexmark Imaging Studio – File not found

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)
"C:\WINDOWS\system32\lxdccoms.exe" = C:\WINDOWS\system32\lxdccoms.exe:*:Enabled:1300 Series Server – ( )
"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour – (Apple Inc.)
"C:\Program Files\LimeWire\LimeWire.exe" = C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire – File not found
"C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdcwbgw.exe" = C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdcwbgw.exe:*:Enabled: – (Copyright 2006-2007 Lexmark International, Inc. All rights reserved.)
"C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdctime.exe" = C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdctime.exe:*:Enabled: – (Lexmark International, Inc.)
"C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdcpswx.exe" = C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdcpswx.exe:*:Enabled: – ()
"C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdcjswx.exe" = C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdcjswx.exe:*:Enabled: – ()
"C:\WINDOWS\system32\mmc.exe" = C:\WINDOWS\system32\mmc.exe:*:Disabled:Microsoft Management Console – (Microsoft Corporation)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00030409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 Small Business
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{0C34B801-6AEC-4667-B053-03A67E2D0415}" = Apple Application Support
"{1017A80C-6F09-4548-A84D-EDD6AC9525F0}" = Lexmark Toolbar
"{26A24AE4-039D-4CA4-87B4-2F83216016FF}" = Java™ 6 Update 16
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A429C2AE-EBF1-4F81-A221-1C115CAADDAD}" = QuickTime
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C4124E95-5061-4776-8D5D-E3D931C778E1}" = Microsoft VC9 runtime libraries
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Bejeweled 2 Deluxe" = Bejeweled 2 Deluxe (remove only)
"ERUNT_is1" = ERUNT 1.1j
"HijackThis" = HijackThis 2.0.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"Lexmark 1300 Series" = Lexmark 1300 Series
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.0.5)" = Mozilla Firefox (3.0.5)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSNINST" = MSN
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"WhiteCap" = WhiteCap
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Toolbar" = Yahoo! Toolbar

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 10/3/2009 11:53:34 PM | Computer Name = KEN-6F846939A5D | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

Error - 10/4/2009 12:02:09 AM | Computer Name = KEN-6F846939A5D | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

Error - 10/4/2009 12:21:52 AM | Computer Name = KEN-6F846939A5D | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.

Error - 10/4/2009 12:22:03 AM | Computer Name = KEN-6F846939A5D | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

Error - 10/4/2009 8:02:34 PM | Computer Name = KEN-6F846939A5D | Source = Application Hang | ID = 1002
Description = Hanging application SpybotSD.exe, version 1.6.2.46, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 10/4/2009 8:02:35 PM | Computer Name = KEN-6F846939A5D | Source = Application Hang | ID = 1002
Description = Hanging application SpybotSD.exe, version 1.6.2.46, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 10/4/2009 8:02:36 PM | Computer Name = KEN-6F846939A5D | Source = Application Hang | ID = 1002
Description = Hanging application SpybotSD.exe, version 1.6.2.46, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 10/4/2009 8:03:45 PM | Computer Name = KEN-6F846939A5D | Source = Application Hang | ID = 1002
Description = Hanging application SpybotSD.exe, version 1.6.2.46, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 10/11/2009 9:35:15 PM | Computer Name = KEN-6F846939A5D | Source = Application Hang | ID = 1002
Description = Hanging application firefox.exe, version 1.9.0.3257, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 10/13/2009 1:50:29 AM | Computer Name = KEN-6F846939A5D | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.16876, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

[ System Events ]
Error - 10/4/2009 10:30:38 AM | Computer Name = KEN-6F846939A5D | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the PEVSystemStart service
to connect.

Error - 10/4/2009 11:00:03 AM | Computer Name = KEN-6F846939A5D | Source = Service Control Manager | ID = 7031
Description = The OneCare AntiSpyware and AntiVirus service terminated unexpectedly.
It has done this 1 time(s). The following corrective action will be taken in
15000 milliseconds: Restart the service.

Error - 10/4/2009 11:00:03 AM | Computer Name = KEN-6F846939A5D | Source = Service Control Manager | ID = 7031
Description = The Apple Mobile Device service terminated unexpectedly. It has done
this 1 time(s). The following corrective action will be taken in 60000 milliseconds:
Restart the service.

Error - 10/4/2009 11:00:03 AM | Computer Name = KEN-6F846939A5D | Source = Service Control Manager | ID = 7034
Description = The Bonjour Service service terminated unexpectedly. It has done
this 1 time(s).

Error - 10/4/2009 11:00:03 AM | Computer Name = KEN-6F846939A5D | Source = Service Control Manager | ID = 7034
Description = The lxdc_device service terminated unexpectedly. It has done this
1 time(s).

Error - 10/4/2009 11:00:03 AM | Computer Name = KEN-6F846939A5D | Source = Service Control Manager | ID = 7031
Description = The OneCare Firewall service terminated unexpectedly. It has done
this 1 time(s). The following corrective action will be taken in 60000 milliseconds:
Restart the service.

Error - 10/4/2009 11:00:13 AM | Computer Name = KEN-6F846939A5D | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the lxdc_device service to
connect.

Error - 10/4/2009 11:00:13 AM | Computer Name = KEN-6F846939A5D | Source = Service Control Manager | ID = 7000
Description = The lxdc_device service failed to start due to the following error:
%%1053

Error - 10/11/2009 8:10:29 PM | Computer Name = KEN-6F846939A5D | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.2.32 for the Network Card with network
address 000103CD93B5 has been denied by the DHCP server 0.0.0.0 (The DHCP Server
sent a DHCPNACK message).

Error - 10/15/2009 7:01:46 PM | Computer Name = KEN-6F846939A5D | Source = DCOM | ID = 10010
Description = The server {D6015EC3-FA16-4813-9CA1-DA204574F5DA} did not register
with DCOM within the required timeout.


< End of report >
Hello HR, Sorry for the delay. Have you removed all but one Anti Virus and one Firewall? Also have you ever tried running in Safe Mode to see if there is a difference?
Yo jephree, Have ahs some long work days Uninstalled every other virus program just running Malwarebytes and Spybot S&D NOW it's i think back to normal speed BUT Everything is jerky… :pullhair: any video stream even ones I have on HD. the IE loads but when finished the clips in yahoo play like FRAME at a time ??? like plays a fram and waits a sec and plays so we got the speed back but now cannot watch any videos like we were doing before I did clean up. any suggestions HR
Hey HR.

Just to verify you say you unistalled every other virus program and yet neither Malwarebytes nor Spybot S&D is an anti virus program nor a firewall.

Your previous post was such as:

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]


Indicating you were running all the above programs.

One system can only run one anti virus and one firewall program.

If I am reading your log wrong please correct me.
Man SORRY jephree

have been working doubles this week and have been dead tired when i got home

So we were at that i removed all the unneeded virus programs..which i did.

can find any other process running..

but everything moves jerky still …??

while running spybot S&D i saw it reading for a long time files
called Virtumonde. dll .prx .sc .sdn
surfing says it's a bug but malwarebytes, S&D and spyblaster
have not seen it.

and to answer your question

If I am reading your log wrong please correct me.


man I have never seen this log before this month so I cannot tell you when thos entries mean???

the processor is always max out at 100%

can you shed some light on the subject??



HR
What I suggest here is just a test so please undo it after said test.

Go to start > Run… and type: MSCONFIG

In the new little box click Startup then click the lower right option to Disable All

Re-start your computer and you will be told you are in a diagnostic mode so just say OK.

Now see if there is any behavior difference.

Let us know.

Do not use your computer for any extended time on-line as this setting will have turned off your Anti-Virus.

You can start it manually or else go back to MSCONFIG and Enable All and restart which will reverse our test set up.


MSCONFIG > Startup simply lists all the third party startup entries that have been established by third party software you have installed outside of Windows itself.
:wavey: HI jephree, been a short time ..had some RL problems.. BUT my poor son has not had his PC in a while so I'm back looking to solve the ways the system is running…. Start up is back to normal Boots up fine. BUT after that everything is stop load the processor running at 85-95% when you start any program. when nothing is running it sits at 2- 6% when you play any streaming vid like off of Utube or a goggle home page vid the play back is really slow and jerky????? Reminder..had (was infected) and the spybot team clean it up and sent me here… :thumbup: to fix what the infection did. WHERE do we start??? HR

Hey HR.

Just to verify you say you unistalled every other virus program and yet neither Malwarebytes nor Spybot S&D is an anti virus program nor a firewall.

Your previous post was such as:

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]


Indicating you were running all the above programs.

One system can only run one anti virus and one firewall program.

If I am reading your log wrong please correct me.


Jephree, those are anti-virus programs that security center already has listed, I guess. All XP machines have those listed as far as I know. Take a look in your registry.
HI ARCHellRaiser… Can you post a PCPitStop test for us?

How to run PCPitStop's Overdrive tests:
  • Please click here to go to the PCPitStop Overdrive sign-up page: Signup at PCPitStop (You need to use Internet Explorer with this test so that an ActiveX control can be installed.)
  • Click "Create a free account"
  • Enter in your relevant information on the sign-up page. You must sign-up in order to have your results recorded so that we can take a look at them here.
  • After signing up you'll see the "Registration Complete" page, and you can click "Test Your System Now" to return to the test page.
  • Login with your newly created e-mail address and password on the left hand side.
  • Follow the directions to "Scan this system now." An activeX control will need to be installed. It is safe, and you should allow it to be installed.
  • Once the tests have been run, you will see an "Almost there" page requesting further information about your computer and your experience with PCPitStop, just scroll down to the bottom and click "GO."
  • A test results page will display, and I need the link to that page.
  • Look in the address bar of your browser. It will look like 'http://www.pcpitstop.com/betapit/…' Please copy and paste that here to the forum.

    Note: PCPitStop may recommend that you use certain utilities to fix problems on your computer. At WhatTheTech, the help we provide is free. We do not endorse or recommend the use of any products PCPitStop may suggest. Instead, we prefer to help you with each issue manually without using possible pay to use programs.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI