This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] very slow, unresponsive and freezes up laptop

43 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My laptop gradually started running very slow and non responsive to commands also started to freeze up more often.It also takes ages to boot up.I expect a malware infection.It runs windows XP with SP2.Please help.
Hi almar,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

  • Download DDS and save it to your desktop from
  • Here
  • here or
  • here.
    • Disable any script blocking protection (How to Disable your Security Programs)
    • Double click DDS icon to run the tool (may take up to 3 minutes to run)
    • When done, DDS.txt will open.
    • After a few moments, attach.txt will open in a second window.
    • Save both reports to your desktop.
  • We Need to check for Rootkits with RootRepeal
    • Download RootRepeal from one of the following locations and save it to your desktop.
    • Open [external image: Posted Image] on your desktop.
    • Click the [external image: Posted Image] tab.
    • Click the [external image: Posted Image] button.
    • In the Select Scan dialog, check
      [external image: Posted Image]
    • Push Ok
    • Check the box for your main system drive (Usually C:), and press Ok.
    • Allow RootRepeal to run a scan of your system. This may take some time.
    • Once the scan completes, push the [external image: Posted Image] button. Save the log to your desktop, using a distinctive name, such as RootRepeal.txt.
  • Copy/paste the log (that you've previously saved to your desktop) from RootRepeal onto your post.

  • Copy/paste the DDS.txt log (that you've previously saved to your desktop) onto your post.

  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/12/08 11:28
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP2
==================================================

Drivers
——————-
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xECDEB000 Size: 98304 File Visible: No Signed: -
Status: -

Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF7BBC000 Size: 8192 File Visible: No Signed: -
Status: -

Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xB8958000 Size: 49152 File Visible: No Signed: -
Status: -

SSDT
——————-
#: 019 Function Name: NtAssignProcessToJobObject
Status: Hooked by "C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys" at address 0xece93d10

#: 025 Function Name: NtClose
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xece0b6b8

#: 037 Function Name: NtCreateFile
Status: Hooked by "C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys" at address 0xece9443a

#: 041 Function Name: NtCreateKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xece0b574

#: 062 Function Name: NtDeleteFile
Status: Hooked by "C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys" at address 0xece94586

#: 063 Function Name: NtDeleteKey
Status: Hooked by "C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys" at address 0xece97a36

#: 065 Function Name: NtDeleteValueKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xece0ba52

#: 068 Function Name: NtDuplicateObject
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xece0b14c

#: 116 Function Name: NtOpenFile
Status: Hooked by "C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys" at address 0xece944ea

#: 119 Function Name: NtOpenKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xece0b64e

#: 122 Function Name: NtOpenProcess
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xece0b08c

#: 128 Function Name: NtOpenThread
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xece0b0f0

#: 137 Function Name: NtProtectVirtualMemory
Status: Hooked by "C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys" at address 0xece94188

#: 177 Function Name: NtQueryValueKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xece0b76e

#: 192 Function Name: NtRenameKey
Status: Hooked by "C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys" at address 0xece97aa6

#: 193 Function Name: NtReplaceKey
Status: Hooked by "C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys" at address 0xece97ad8

#: 204 Function Name: NtRestoreKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xece0b72e

#: 213 Function Name: NtSetContextThread
Status: Hooked by "C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys" at address 0xece93cbe

#: 224 Function Name: NtSetInformationFile
Status: Hooked by "C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys" at address 0xece945e6

#: 247 Function Name: NtSetValueKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xece0b8ae

#: 254 Function Name: NtSuspendThread
Status: Hooked by "C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys" at address 0xece93c54

#: 257 Function Name: NtTerminateProcess
Status: Hooked by "C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys" at address 0xece93b94

#: 258 Function Name: NtTerminateThread
Status: Hooked by "C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys" at address 0xece93bea

==EOF==
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 11:18:20.40 on 12/08/2009 Tue
Internet Explorer: 6.0.2900.2180
Microsoft Windows XP Home Edition 5.1.2600.2.[removed].18.382.52 [GMT -5:00]

AV: avast! antivirus 4.8.1356 [VPS 091208-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost -k rpcss
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Trusteer\Rapport\bin\RapportService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\AOL\1151722181\ee\AOLSoftware.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\g\My Documents\Downloads\dds.scr
C:\WINDOWS\system32\conime.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.yahoo.com/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://red.clientapps.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
mSearchAssistant = hxxp://www.google.com/ie
uURLSearchHooks: N/A: {00a6faf6-072e-44cf-8957-5838f569a31d} - c:\program files\mywebsearch\srchastt\1.bin\MWSSRCAS.DLL
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: MyWebSearch Search Assistant BHO: {00a6faf1-072e-44cf-8957-5838f569a31d} - c:\program files\mywebsearch\srchastt\1.bin\MWSSRCAS.DLL
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: mwsBar BHO: {07b18ea1-a523-4961-b6bb-170de4475cca} - c:\program files\mywebsearch\bar\1.bin\MWSBAR.DLL
BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll
TB: {4982D40A-C53B-4615-B15B-B5B5E98D167C} - No File
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File
TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [MyWebSearch Email Plugin] c:\progra~1\mywebs~1\bar\1.bin\mwsoemon.exe
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
mRun: [ATIPTA] c:\program files\ati technologies\ati control panel\atiptaxx.exe
mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [eabconfg.cpl] c:\program files\hpq\quick launch buttons\EabServr.exe /Start
mRun: [Cpqset] c:\program files\hpq\default settings\cpqset.exe
mRun: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
mRun: [My Web Search Bar] rundll32 c:\progra~1\mywebs~1\bar\1.bin\MWSBAR.DLL,S
mRun: [MyWebSearch Email Plugin] c:\progra~1\mywebs~1\bar\1.bin\mwsoemon.exe
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [RealTray] c:\program files\real\realplayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [HostManager] c:\program files\common files\aol\1151722181\ee\AOLSoftware.exe
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [AOLDialer] c:\program files\common files\aol\acs\AOLDial.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\americ~1.lnk - c:\program files\america online 9.0\aoltray.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
IE: &AOL Toolbar search - c:\program files\aol toolbar\toolbar.dll/SEARCH.HTML
IE: &Search - http://edits.mywebsearch.com/toolbaredits/…arch.jhtml?p=ZR
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {4982D40A-C53B-4615-B15B-B5B5E98D167C} - {4982D40A-C53B-4615-B15B-B5B5E98D167C}
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} - hxxp://us.dl1.yimg.com/download.yahoo.com/dl/yinst/yinst_current.cab
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://by110fd.bay110.hotmail.msn.com/resources/MsnPUpld.cab
Notify: AtiExtEvent - Ati2evxx.dll
AppInit_DLLs: c:\progra~1\google\google~2\GOEC62~1.DLL
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\window~4\MpShHook.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\g\applic~1\mozilla\firefox\profiles\mkw9dmh9.default\
FF - prefs.js: browser.startup.homepage - hxxp://my.yahoo.com/
FF - component: c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll

—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");

============= SERVICES / DRIVERS ===============

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-11-15 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-11-15 20560]
R3 HSFHWATI;HSFHWATI;c:\windows\system32\drivers\HSFHWATI.sys [2004-12-15 200192]
S3 brfilt;Brother MFC Filter Driver;c:\windows\system32\drivers\BrFilt.sys [2007-8-23 2944]
S3 BrSerWDM;Brother Serial driver;c:\windows\system32\drivers\BrSerWdm.sys [2007-8-23 60416]
S3 BrUsbMdm;Brother MFC USB Fax Only Modem;c:\windows\system32\drivers\BrUsbMdm.sys [2007-8-23 11008]
S3 BrUsbScn;Brother MFC USB Scanner driver;c:\windows\system32\drivers\BrUsbScn.sys [2007-8-23 10368]

=============== Created Last 30 ================

2009-12-07 22:28 1,409 a——- c:\windows\QTFont.for
2009-12-07 22:28 54,156 a—h— c:\windows\QTFont.qfn
2009-11-29 22:25 378 a——- C:\Shortcut to WINDOWS.lnk
2009-11-27 11:33 –d—– c:\program files\common files\Scanner
2009-11-24 16:52 –d—– c:\windows\pss

==================== Find3M ====================

2009-11-30 23:57 4,016 a——- c:\docume~1\g\applic~1\wklnhst.dat
2009-11-02 20:42 195,456 ——– c:\windows\system32\MpSigStub.exe
2009-10-19 19:08 3,063,296 a——- c:\windows\system32\dllcache\mshtml.dll
2009-09-18 04:56 18,432 a——- c:\windows\system32\dllcache\iedw.exe
2009-09-11 09:33 133,632 a——- c:\windows\system32\msv1_0.dll
2009-09-11 09:33 133,632 ——– c:\windows\system32\dllcache\msv1_0.dll
2004-02-12 11:54 470,528 a——- c:\program files\Manual DVD shrink 3.doc
2004-01-25 23:11 848,763 a——- c:\program files\dvdshrink314setup.exe

============= FINISH: 11:20:07.34 ===============

Attachments:

Hi Tomk Thank you for offering to help me out with my problem.Please find all the reports as instructed on my previous reply from the infected laptop.I am unable to write anything on that laptop using the keyboard ,It just does not type ever since I had the problem.I am using another computer to write right now.I hope you will be able to clear this problem too.Many thanks Almar
almar,

Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean

Then

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot (shut down your computer then restart it).

Also please describe how your computer behaves at the moment.
Hi TomK There is not much improvement in performance .it takes around 7 minutes to get Firefox starting for example and when it comes up it is a duplicate of five pages of the same.I am now getting an error message at startup: RUNDLL error loading C:\program~1\MyWebs~1\1.bin\MWSBAR.DLL opining any other program still takes a long time. I still don not have the Note Pad program on The Accessory list of Windows? the good news I can have the functionality of using the keyboard to type. The Malware scan found 156 objects infected which have now been deleted.
almar,

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://forums.whatthetech.com/How_Disable_…ams_t96260.html

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
hi TomK tried to download combo fix but the instructions with the..? YES or No buttons came out with chinese alphabets that I could not understand. Just wanted to check with you before I proceed.thx
almar,

Please drag your copy of ComboFix to the recycle bin.

Then download a fresh copy and save it on your desktop as Worksnow.com.

Double click it to run.
Hi TomK followed yr instructions.the same thing HAPPENED .IT IS NOT WORKING.NOW I CAN ONLY TYPE IN CAPS FOR SOME REASON. IS THERE ANOTHER PROGRAM WE CAN TRY INSTEAD. WHY AM I GETTING THIS IN CHINESE? it did not happen before.
almar,

Let's get a little different look at things.

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
Hi TomK
As requested, the OTL scans:




OTL logfile created on: 12/9/2009 8:48:18 PM - Run 1
OTL by OldTimer - Version 3.1.12.0 Folder = C:\Documents and Settings\g\My Documents\Downloads
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

382.48 Mb Total Physical Memory | 53.50 Mb Available Physical Memory | 13.99% Memory free
947.64 Mb Paging File | 241.73 Mb Available in Paging File | 25.51% Paging File free
Paging file location(s): C:\pagefile.sys 576 1152 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55.88 Gb Total Space | 39.05 Gb Free Space | 69.88% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: PC129202628113
Current User Name: g
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2009/12/09 20:46:33 | 00,537,088 | —- | M] (OldTimer Tools) – C:\Documents and Settings\g\My Documents\Downloads\OTL.exe
PRC - [2009/11/02 22:23:08 | 00,908,248 | —- | M] (Mozilla Corporation) – C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2009/09/15 06:56:48 | 00,081,000 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashDisp.exe
PRC - [2009/09/15 06:56:43 | 00,138,680 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashServ.exe
PRC - [2009/09/15 06:54:13 | 00,352,920 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
PRC - [2009/09/15 06:49:40 | 00,018,752 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
PRC - [2009/07/14 18:01:34 | 01,373,416 | —- | M] (Trusteer Ltd.) – C:\Program Files\Trusteer\Rapport\bin\RapportService.exe
PRC - [2009/07/14 18:01:34 | 00,918,760 | —- | M] (Trusteer Ltd.) – C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe
PRC - [2007/07/13 17:04:42 | 00,068,856 | —- | M] (Google Inc.) – C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
PRC - [2007/07/10 08:18:20 | 00,270,648 | —- | M] (Apple Inc.) – C:\Program Files\iTunes\iTunesHelper.exe
PRC - [2007/07/10 08:18:14 | 00,501,048 | —- | M] (Apple Inc.) – C:\Program Files\iPod\bin\iPodService.exe
PRC - [2007/07/09 17:46:50 | 00,106,496 | —- | M] (Apple, Inc.) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
PRC - [2007/06/29 05:24:52 | 00,286,720 | —- | M] (Apple Inc.) – C:\Program Files\QuickTime\QTTask.exe
PRC - [2007/06/13 05:23:07 | 01,033,216 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2006/11/03 18:20:12 | 00,866,584 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Defender\MSASCui.exe
PRC - [2006/11/03 18:19:58 | 00,013,592 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Defender\MsMpEng.exe
PRC - [2006/10/23 07:50:35 | 00,046,640 | R— | M] (AOL LLC) – C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
PRC - [2006/09/25 19:52:48 | 00,050,736 | —- | M] (America Online, Inc.) – C:\Program Files\Common Files\AOL\1151722181\ee\aolsoftware.exe
PRC - [2006/05/15 17:24:33 | 00,100,032 | —- | M] (Symantec Corporation) – C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
PRC - [2006/04/14 12:06:55 | 00,026,112 | —- | M] (RealNetworks, Inc.) – C:\Program Files\Real\RealPlayer\realplay.exe
PRC - [2005/05/11 22:23:26 | 00,282,624 | —- | M] (Hewlett-Packard Co.) – C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
PRC - [2005/05/11 22:16:22 | 00,077,824 | —- | M] (Hewlett-Packard Co.) – C:\Program Files\Hp\Digital Imaging\Product Assistant\bin\hprblog.exe
PRC - [2005/05/11 22:12:54 | 00,049,152 | —- | M] (Hewlett-Packard Co.) – C:\Program Files\Hp\HP Software Update\hpwuSchd2.exe
PRC - [2005/04/11 12:00:00 | 00,339,968 | —- | M] (ATI Technologies, Inc.) – C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
PRC - [2005/04/11 08:31:26 | 00,360,448 | —- | M] (ATI Technologies Inc.) – C:\WINDOWS\system32\ati2evxx.exe
PRC - [2005/02/22 18:32:14 | 00,038,912 | —- | M] () – C:\Program Files\Common Files\LightScribe\LSSrvc.exe
PRC - [2005/02/02 07:12:22 | 00,102,492 | —- | M] (Synaptics, Inc.) – C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
PRC - [2005/02/02 07:11:12 | 00,692,316 | —- | M] (Synaptics, Inc.) – C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
PRC - [2004/12/03 13:24:20 | 00,290,816 | —- | M] (Hewlett-Packard ) – C:\Program Files\HPQ\Quick Launch Buttons\eabservr.exe
PRC - [2004/09/29 11:14:36 | 00,069,632 | —- | M] (HP) – C:\WINDOWS\system32\HPZipm12.exe
PRC - [2004/08/04 03:00:00 | 00,027,648 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\conime.exe
PRC - [2004/08/04 03:00:00 | 00,013,824 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\wscntfy.exe
PRC - [2003/08/27 09:29:46 | 00,065,536 | —- | M] (America Online, Inc.) – C:\WINDOWS\wanmpsvc.exe
PRC - [2003/02/25 00:52:00 | 00,303,104 | —- | M] (Lexmark International, Inc.) – C:\WINDOWS\system32\LEXBCES.EXE
PRC - [2003/02/25 00:50:00 | 00,174,592 | —- | M] (Lexmark International, Inc.) – C:\WINDOWS\system32\LEXPPS.EXE


========== Modules (SafeList) ==========

MOD - [2009/12/09 20:46:33 | 00,537,088 | —- | M] (OldTimer Tools) – C:\Documents and Settings\g\My Documents\Downloads\OTL.exe
MOD - [2009/07/14 18:01:36 | 00,632,040 | —- | M] (Microsoft Corporation) – C:\Program Files\Trusteer\Rapport\bin\msvcr80.dll
MOD - [2009/07/14 18:01:34 | 00,341,224 | —- | M] (Trusteer Ltd.) – C:\Program Files\Trusteer\Rapport\bin\rooksbas.dll
MOD - [2006/08/25 10:45:55 | 01,054,208 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll
MOD - [2005/02/02 07:12:14 | 00,069,724 | —- | M] (Synaptics, Inc.) – C:\WINDOWS\system32\SynTPFcs.dll


========== Win32 Services (SafeList) ==========

SRV - File not found – – (gusvc)
SRV - [2009/10/31 10:21:33 | 00,030,192 | —- | M] (Google) – C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe – (GoogleDesktopManager-093009-130223)
SRV - [2009/09/15 06:56:43 | 00,138,680 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashServ.exe – (avast! Antivirus)
SRV - [2009/09/15 06:56:28 | 00,254,040 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe – (avast! Mail Scanner)
SRV - [2009/09/15 06:54:13 | 00,352,920 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe – (avast! Web Scanner)
SRV - [2009/09/15 06:49:40 | 00,018,752 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe – (aswUpdSv)
SRV - [2009/07/14 18:01:34 | 00,918,760 | —- | M] (Trusteer Ltd.) – C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe – (RapportMgmtService)
SRV - [2007/07/10 08:18:14 | 00,501,048 | —- | M] (Apple Inc.) – C:\Program Files\iPod\bin\iPodService.exe – (iPod Service)
SRV - [2007/07/09 17:46:50 | 00,106,496 | —- | M] (Apple, Inc.) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe – (Apple Mobile Device)
SRV - [2007/01/19 11:54:14 | 00,097,136 | —- | M] (Microsoft Corporation) – C:\Program Files\MSN Messenger\usnsvc.exe – (usnjsvc)
SRV - [2006/11/03 18:19:58 | 00,013,592 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Defender\MsMpEng.exe – (WinDefend)
SRV - [2006/10/23 07:50:35 | 00,046,640 | R— | M] (AOL LLC) – C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe – (AOL ACS)
SRV - [2006/05/15 17:24:33 | 02,086,592 | —- | M] (Symantec Corporation) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_0.EXE – (LiveUpdate)
SRV - [2006/05/15 17:24:33 | 00,100,032 | —- | M] (Symantec Corporation) – C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe – (Automatic LiveUpdate Scheduler)
SRV - [2005/04/11 08:31:26 | 00,360,448 | —- | M] (ATI Technologies Inc.) – C:\WINDOWS\system32\ati2evxx.exe – (Ati HotKey Poller)
SRV - [2005/03/04 14:16:18 | 00,098,304 | R— | M] (Hewlett-Packard Development Company, L.P.) – C:\Program Files\HPQ\Shared\hpqwmi.exe – (hpqwmi)
SRV - [2005/02/22 18:32:14 | 00,038,912 | —- | M] () – C:\Program Files\Common Files\LightScribe\LSSrvc.exe – (LightScribeService)
SRV - [2004/09/29 11:14:36 | 00,069,632 | —- | M] (HP) – C:\WINDOWS\system32\HPZipm12.exe – (Pml Driver HPZ12)
SRV - [2004/07/15 03:49:26 | 00,032,768 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe – (aspnet_state)
SRV - [2003/08/27 09:29:46 | 00,065,536 | —- | M] (America Online, Inc.) – C:\WINDOWS\wanmpsvc.exe – (WANMiniportService) WAN Miniport (ATW)
SRV - [2003/02/25 00:52:00 | 00,303,104 | —- | M] (Lexmark International, Inc.) – C:\WINDOWS\system32\LEXBCES.EXE – (LexBceS)


========== Driver Services (SafeList) ==========

DRV - [2009/09/15 06:56:14 | 00,094,160 | —- | M] (ALWIL Software) – C:\WINDOWS\system32\drivers\aswmon2.sys – (aswMon2)
DRV - [2009/09/15 06:55:30 | 00,114,768 | —- | M] (ALWIL Software) – C:\WINDOWS\system32\drivers\aswSP.sys – (aswSP)
DRV - [2009/09/15 06:55:19 | 00,020,560 | —- | M] (ALWIL Software) – C:\WINDOWS\system32\drivers\aswFsBlk.sys – (aswFsBlk)
DRV - [2009/09/15 06:54:30 | 00,052,368 | —- | M] (ALWIL Software) – C:\WINDOWS\system32\drivers\aswTdi.sys – (aswTdi)
DRV - [2009/09/15 06:54:21 | 00,023,152 | —- | M] (ALWIL Software) – C:\WINDOWS\system32\drivers\aswRdr.sys – (aswRdr)
DRV - [2009/09/15 06:53:24 | 00,027,408 | —- | M] (ALWIL Software) – C:\WINDOWS\system32\drivers\aavmker4.sys – (Aavmker4)
DRV - [2009/07/14 18:01:36 | 00,301,928 | —- | M] (Trusteer Ltd.) – C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys – (RapportPG)
DRV - [2009/07/14 18:01:36 | 00,058,728 | —- | M] (Trusteer Ltd.) – C:\Program Files\Trusteer\Rapport\bin\RapportKELL.sys – (RapportKELL)
DRV - [2007/11/13 05:25:53 | 00,020,480 | —- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) – C:\WINDOWS\system32\drivers\secdrv.sys – (Secdrv)
DRV - [2007/02/03 09:32:36 | 00,041,504 | —- | M] (Logitech Inc.) – C:\WINDOWS\system32\drivers\LVUSBSta.sys – (LVUSBSta)
DRV - [2007/02/03 09:25:56 | 01,075,360 | —- | M] (Logitech Inc.) – C:\WINDOWS\system32\drivers\Camdrl.sys – (CamDrL) Logitech QuickCam Pro 3000(CamDrl)
DRV - [2006/09/19 13:44:04 | 00,015,664 | —- | M] (GEAR Software Inc.) – C:\WINDOWS\system32\drivers\GEARAspiWDM.sys – (GEARAspiWDM)
DRV - [2006/05/16 13:34:37 | 00,107,696 | —- | M] (Symantec Corporation) – C:\Program Files\Symantec\SYMEVENT.SYS – (SymEvent)
DRV - [2006/04/14 12:07:00 | 00,008,552 | —- | M] (Windows ® 2000 DDK provider) – C:\WINDOWS\system32\drivers\asctrm.sys – (ASCTRM)
DRV - [2005/04/11 08:33:52 | 01,035,264 | —- | M] (ATI Technologies Inc.) – C:\WINDOWS\system32\drivers\ati2mtag.sys – (ati2mtag)
DRV - [2005/03/16 07:43:06 | 00,159,488 | —- | M] (Texas Instruments) – C:\WINDOWS\system32\drivers\tifm21.sys – (tifm21)
DRV - [2005/03/10 04:41:52 | 00,371,712 | —- | M] (Broadcom Corporation) – C:\WINDOWS\system32\drivers\BCMWL5.SYS – (BCM43XX)
DRV - [2005/03/08 07:52:28 | 00,021,744 | R— | M] (HP) – C:\WINDOWS\system32\drivers\HPZius12.sys – (HPZius12)
DRV - [2005/03/08 07:52:27 | 00,016,496 | R— | M] (HP) – C:\WINDOWS\system32\drivers\HPZipr12.sys – (HPZipr12)
DRV - [2005/03/08 07:52:26 | 00,051,120 | R— | M] (HP) – C:\WINDOWS\system32\drivers\HPZid412.sys – (HPZid412)
DRV - [2005/03/03 14:10:26 | 00,074,496 | —- | M] (Realtek Semiconductor Corporation ) – C:\WINDOWS\system32\drivers\Rtlnicxp.sys – (RTL8023xp)
DRV - [2005/02/18 10:42:02 | 00,349,696 | —- | M] (Conexant Systems Inc.) – C:\WINDOWS\system32\drivers\camc6hal.sys – (CAMCHALA)
DRV - [2005/02/18 10:41:18 | 00,038,016 | —- | M] (Conexant Systems Inc.) – C:\WINDOWS\system32\drivers\camc6aud.sys – (CAMCAUD)
DRV - [2005/02/02 06:58:58 | 00,191,456 | —- | M] (Synaptics, Inc.) – C:\WINDOWS\system32\drivers\SynTP.sys – (SynTP)
DRV - [2005/01/26 04:03:00 | 00,020,576 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\Drivers\PxHelp20.sys – (PxHelp20)
DRV - [2005/01/18 11:52:16 | 00,055,320 | —- | M] (Broadcom Corporation.) – C:\WINDOWS\system32\drivers\btwusb.sys – (BTWUSB)
DRV - [2004/12/15 10:18:30 | 00,200,192 | —- | M] (Conexant Systems, Inc.) – C:\WINDOWS\system32\drivers\HSFHWATI.sys – (HSFHWATI)
DRV - [2004/12/15 10:18:28 | 00,703,232 | —- | M] (Conexant Systems, Inc.) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys – (winachsf)
DRV - [2004/12/15 10:18:26 | 01,038,208 | —- | M] (Conexant Systems, Inc.) – C:\WINDOWS\system32\drivers\HSF_DP.sys – (HSF_DP)
DRV - [2004/08/11 18:30:00 | 00,039,424 | —- | M] (Advanced Micro Devices) – C:\WINDOWS\system32\drivers\AmdK8.sys – (AmdK8)
DRV - [2004/08/04 03:00:00 | 00,063,744 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\drivers\mf.sys – (mf)
DRV - [2004/08/04 03:00:00 | 00,017,792 | —- | M] (Parallel Technologies, Inc.) – C:\WINDOWS\system32\drivers\ptilink.sys – (Ptilink)
DRV - [2004/08/04 03:00:00 | 00,012,160 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\drivers\fsvga.sys – (FsVga)
DRV - [2004/08/03 22:07:56 | 00,059,264 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\drivers\USBAUDIO.sys – (usbaudio) USB Audio Driver (WDM)
DRV - [2004/04/14 09:36:50 | 00,007,432 | —- | M] (Hewlett-Packard Company) – C:\WINDOWS\system32\drivers\eabfiltr.sys – (eabfiltr)
DRV - [2004/03/17 06:04:14 | 00,013,059 | —- | M] (Conexant) – C:\WINDOWS\system32\drivers\mdmxsdk.sys – (mdmxsdk)
DRV - [2003/06/06 13:46:16 | 00,005,220 | —- | M] (Hewlett-Packard Company) – C:\WINDOWS\system32\drivers\EabUsb.sys – (eabusb)
DRV - [2003/01/10 15:13:04 | 00,033,588 | —- | M] (America Online, Inc.) – C:\WINDOWS\system32\drivers\wanatw4.sys – (wanatw) WAN Miniport (ATW)
DRV - [2001/08/17 14:10:28 | 00,035,913 | —- | M] (SMC) – C:\WINDOWS\system32\drivers\smcirda.sys – (SMCIRDA)
DRV - [2001/08/17 14:05:44 | 00,141,056 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\drivers\Icam3.sys – (ICAM3NT5)
DRV - [2001/08/17 12:12:22 | 00,010,368 | —- | M] (Brother Industries Ltd.) – C:\WINDOWS\system32\drivers\BrUsbScn.sys – (BrUsbScn)
DRV - [2001/08/17 12:12:20 | 00,060,416 | —- | M] (Brother Industries Ltd.) – C:\WINDOWS\system32\drivers\BrSerWdm.sys – (BrSerWDM)
DRV - [2001/08/17 12:12:20 | 00,011,008 | —- | M] (Brother Industries Ltd.) – C:\WINDOWS\system32\drivers\BrUsbMdm.sys – (BrUsbMdm)
DRV - [2001/08/17 12:12:12 | 00,002,944 | —- | M] (Brother Industries Ltd.) – C:\WINDOWS\system32\drivers\BrFilt.sys – (brfilt)
DRV - [2001/08/17 10:51:56 | 00,005,248 | —- | M] (Acer Laboratories Inc.) – C:\WINDOWS\system32\DRIVERS\aliide.sys – (AliIde)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://my.yahoo.com/"

FF - HKLM\software\mozilla\Mozilla Firefox 3.5.5\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/11/19 11:02:51 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.5\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/11/19 00:12:11 | 00,000,000 | —D | M]

[2009/11/19 00:19:20 | 00,000,000 | —D | M] – C:\Documents and Settings\g\Application Data\Mozilla\Extensions
[2009/11/19 00:19:20 | 00,000,000 | —D | M] – C:\Documents and Settings\g\Application Data\Mozilla\Firefox\Profiles\mkw9dmh9.default\extensions
[2009/11/19 00:12:14 | 00,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: (734 bytes) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found.
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe (AOL LLC)
O4 - HKLM..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc.)
O4 - HKLM..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\Cpqset.exe ()
O4 - HKLM..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe (Hewlett-Packard )
O4 - HKLM..\Run: [Google Desktop Search] C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
O4 - HKLM..\Run: [HostManager] C:\Program Files\Common Files\AOL\1151722181\ee\aolsoftware.exe (America Online, Inc.)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\hpwuSchd2.exe (Hewlett-Packard Co.)
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\LSBurnWatcher.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [My Web Search Bar] C:\PROGRA~1\MYWEBS~1\bar\1.bin\MWSBAR.DLL File not found
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
O4 - HKLM..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe (America Online, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk = C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - Reg Error: Key error. File not found
O9 - Extra 'Tools' menuitem : AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - Reg Error: Key error. File not found
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: //@signup.mar@ ([]money in My Computer)
O15 - HKCU\..Trusted Domains: //@surf.mar@ ([]money in Local intranet)
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} http://us.dl1.yimg.com/download.yahoo.com/…nst_current.cab (YInstStarter Class)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://by110fd.bay110.hotmail.msn.com/resources/MsnPUpld.cab (MSN Photo Upload Tool)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{d8e32852-a757-11dc-a403-00038a000015}\Shell\AutoRun\command - "" = E:\Autorun.exe – File not found
O33 - MountPoints2\{d8e32852-a757-11dc-a403-00038a000015}\Shell\Shell00\Command - "" = E:\Autorun.exe – File not found
O33 - MountPoints2\{d8e32852-a757-11dc-a403-00038a000015}\Shell\Shell01\Command - "" = E:\Autorun.exe – File not found
O33 - MountPoints2\{d8e32852-a757-11dc-a403-00038a000015}\Shell\Shell02\Command - "" = E:\Autorun.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2009/12/09 11:49:38 | 00,000,000 | —D | C] – C:\Qoobox
[2009/12/08 19:20:57 | 00,000,000 | —D | C] – C:\Documents and Settings\g\Application Data\Malwarebytes
[2009/12/08 19:20:39 | 00,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/12/08 19:20:35 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/12/08 19:20:33 | 00,019,160 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/12/08 19:20:33 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/12/08 11:07:15 | 00,000,000 | —D | C] – C:\Documents and Settings\g\My Documents\Downloads
[2009/11/27 11:33:33 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Scanner
[2009/11/24 16:52:13 | 00,000,000 | —D | C] – C:\WINDOWS\pss
[2009/11/19 00:13:49 | 00,000,000 | —D | C] – C:\Documents and Settings\g\Local Settings\Application Data\Mozilla
[2009/11/19 00:13:46 | 00,000,000 | —D | C] – C:\Documents and Settings\g\Application Data\Mozilla
[2009/11/19 00:11:49 | 00,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2009/11/15 01:10:35 | 00,023,152 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswRdr.sys
[2009/11/15 01:10:32 | 00,052,368 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswTdi.sys
[2009/11/15 01:10:30 | 00,027,408 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aavmker4.sys
[2009/11/15 01:10:23 | 00,097,480 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\AvastSS.scr
[2009/11/15 01:10:13 | 00,020,560 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2009/11/15 01:10:12 | 00,114,768 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswSP.sys
[2009/11/15 01:10:10 | 00,094,160 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswmon2.sys
[2009/11/15 01:10:10 | 00,093,424 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswmon.sys
[2009/11/15 01:08:25 | 01,279,968 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\aswBoot.exe
[2009/11/15 01:07:35 | 00,000,000 | —D | C] – C:\Program Files\Alwil Software

========== Files - Modified Within 30 Days ==========

[2009/12/09 16:56:38 | 04,456,448 | -H– | M] () – C:\Documents and Settings\g\NTUSER.DAT
[2009/12/09 12:00:00 | 00,000,330 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2009/12/09 08:05:11 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/12/09 08:03:24 | 00,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2009/12/09 07:59:30 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/12/09 00:34:15 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/12/09 00:14:08 | 00,000,178 | -HS- | M] () – C:\Documents and Settings\g\ntuser.ini
[2009/12/08 21:55:45 | 00,004,016 | —- | M] () – C:\Documents and Settings\g\Application Data\wklnhst.dat
[2009/12/08 20:40:42 | 04,843,458 | -H– | M] () – C:\Documents and Settings\g\Local Settings\Application Data\IconCache.db
[2009/12/08 19:20:48 | 00,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/12/07 22:28:17 | 00,001,409 | —- | M] () – C:\WINDOWS\QTFont.for
[2009/12/07 20:25:52 | 00,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/12/03 16:14:06 | 00,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/12/03 16:13:56 | 00,019,160 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/12/02 22:24:17 | 00,000,581 | —- | M] () – C:\WINDOWS\win.ini
[2009/12/02 22:24:17 | 00,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2009/12/02 22:24:17 | 00,000,211 | RHS- | M] () – C:\boot.ini
[2009/11/29 22:25:50 | 00,000,378 | —- | M] () – C:\Shortcut to WINDOWS.lnk
[2009/11/24 22:10:24 | 00,018,620 | —- | M] () – C:\Documents and Settings\g\My Documents\speeding start up.rtf
[2009/11/23 21:08:50 | 00,004,972 | —- | M] () – C:\Documents and Settings\g\My Documents\check disc.rtf
[2009/11/22 20:14:22 | 00,035,039 | —- | M] () – C:\Documents and Settings\g\My Documents\Document.rtf
[2009/11/19 22:47:19 | 00,000,244 | -H– | M] () – C:\sqmnoopt05.sqm
[2009/11/19 22:47:19 | 00,000,232 | -H– | M] () – C:\sqmdata05.sqm
[2009/11/19 00:12:46 | 00,001,602 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2009/11/17 21:26:05 | 00,000,244 | -H– | M] () – C:\sqmnoopt04.sqm
[2009/11/17 21:26:05 | 00,000,232 | -H– | M] () – C:\sqmdata04.sqm
[2009/11/17 20:38:01 | 00,001,558 | —- | M] () – C:\Documents and Settings\g\My Documents\#36 north.rd ltr.rtf
[2009/11/15 13:28:24 | 00,000,232 | -H– | M] () – C:\sqmdata03.sqm
[2009/11/15 13:28:22 | 00,000,244 | -H– | M] () – C:\sqmnoopt03.sqm
[2009/11/15 01:10:47 | 00,001,709 | —- | M] () – C:\Documents and Settings\All Users\Desktop\avast! Antivirus.lnk
[2009/11/15 01:10:12 | 00,002,626 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2009/11/14 17:33:18 | 00,243,128 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT

========== Files Created - No Company Name ==========

[2009/12/08 19:20:48 | 00,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/12/07 22:28:17 | 00,001,409 | —- | C] () – C:\WINDOWS\QTFont.for
[2009/12/07 22:28:15 | 00,054,156 | -H– | C] () – C:\WINDOWS\QTFont.qfn
[2009/12/02 16:30:14 | 00,000,831 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
[2009/12/02 16:30:12 | 00,001,808 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
[2009/11/29 22:25:50 | 00,000,378 | —- | C] () – C:\Shortcut to WINDOWS.lnk
[2009/11/27 08:57:46 | 00,001,757 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
[2009/11/24 22:10:23 | 00,018,620 | —- | C] () – C:\Documents and Settings\g\My Documents\speeding start up.rtf
[2009/11/23 21:08:49 | 00,004,972 | —- | C] () – C:\Documents and Settings\g\My Documents\check disc.rtf
[2009/11/22 20:14:21 | 00,035,039 | —- | C] () – C:\Documents and Settings\g\My Documents\Document.rtf
[2009/11/19 00:12:46 | 00,001,602 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2009/11/17 20:38:00 | 00,001,558 | —- | C] () – C:\Documents and Settings\g\My Documents\#36 north.rd ltr.rtf
[2009/11/15 01:10:47 | 00,001,709 | —- | C] () – C:\Documents and Settings\All Users\Desktop\avast! Antivirus.lnk
[2009/11/15 01:08:25 | 00,380,928 | —- | C] () – C:\WINDOWS\System32\actskin4.ocx
[2009/07/27 16:19:39 | 00,002,118 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2009/07/27 16:18:46 | 00,077,824 | R— | C] () – C:\WINDOWS\System32\hpzids01.dll
[2009/03/27 17:05:31 | 00,000,028 | —- | C] () – C:\WINDOWS\ICOA.INI
[2009/03/27 17:00:27 | 00,000,052 | —- | C] () – C:\WINDOWS\intuprof.ini
[2009/03/27 17:00:24 | 00,001,491 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2009/03/27 17:00:07 | 00,000,252 | —- | C] () – C:\WINDOWS\ADDRBOOK.INI
[2009/03/27 17:00:03 | 00,207,872 | —- | C] () – C:\WINDOWS\System32\RDMWIN32.DLL
[2009/03/27 16:59:36 | 00,000,054 | —- | C] () – C:\WINDOWS\QFP.INI
[2009/03/27 16:59:36 | 00,000,054 | —- | C] () – C:\WINDOWS\MFF.INI
[2008/03/06 22:09:31 | 00,000,760 | —- | C] () – C:\WINDOWS\lexstat.ini
[2008/03/06 22:08:30 | 00,040,960 | —- | C] () – C:\WINDOWS\System32\lxblvs.dll
[2008/03/06 21:57:24 | 00,077,824 | —- | C] () – C:\WINDOWS\System32\LXBLLCNP.DLL
[2007/10/12 21:19:33 | 00,000,051 | —- | C] () – C:\WINDOWS\brmx2001.ini
[2007/10/12 21:19:33 | 00,000,040 | —- | C] () – C:\WINDOWS\opt_2460.ini
[2007/10/01 11:59:56 | 00,001,751 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/08/23 11:44:34 | 00,000,267 | —- | C] () – C:\WINDOWS\Brpcfx.ini
[2007/08/23 11:44:30 | 00,000,052 | —- | C] () – C:\WINDOWS\BRPP2KA.INI
[2007/08/23 11:44:30 | 00,000,000 | —- | C] () – C:\WINDOWS\brwmark.ini
[2007/08/23 11:44:11 | 00,651,264 | —- | C] () – C:\WINDOWS\System32\brfxdial.dll
[2007/08/23 11:35:40 | 00,002,652 | —- | C] () – C:\WINDOWS\BRMFBIDI.INI
[2007/06/14 09:39:13 | 00,040,448 | —- | C] () – C:\WINDOWS\System32\BJAXSecurityManager.dll
[2007/06/14 09:39:09 | 00,086,016 | —- | C] () – C:\WINDOWS\System32\BJInstaller.dll
[2007/02/03 07:59:04 | 00,050,127 | —- | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2006/05/14 20:15:36 | 00,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2006/04/17 15:30:06 | 00,000,000 | —- | C] () – C:\WINDOWS\OpPrintServer.INI
[2006/01/15 13:41:28 | 00,000,049 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2006/01/06 19:53:17 | 00,002,585 | —- | C] () – C:\WINDOWS\Xtreme.ini
[2005/12/31 15:08:09 | 00,004,016 | —- | C] () – C:\Documents and Settings\g\Application Data\wklnhst.dat
[2005/12/16 23:31:41 | 00,000,000 | —- | C] () – C:\WINDOWS\muveeapp.INI
[2005/12/15 10:04:49 | 00,019,456 | —- | C] () – C:\Documents and Settings\g\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005/04/29 07:54:19 | 00,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2005/04/29 07:54:19 | 00,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2005/04/29 07:54:18 | 00,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2005/04/29 07:54:18 | 00,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2005/04/29 07:54:18 | 00,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2005/04/29 07:54:18 | 00,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2005/04/29 07:42:10 | 00,015,669 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2005/02/12 03:33:06 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2004/08/07 08:16:44 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2004/08/07 08:10:08 | 00,000,882 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/02/12 11:54:18 | 00,470,528 | —- | C] () – C:\Program Files\Manual DVD shrink 3.doc
[2004/01/25 23:11:42 | 00,848,763 | —- | C] () – C:\Program Files\dvdshrink314setup.exe

========== LOP Check ==========

[2008/05/06 21:41:38 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\IM
[2008/05/06 21:38:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\IncrediMail
[2005/04/29 08:10:03 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\muvee Technologies
[2008/06/03 18:46:23 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\n7-89-o9-3r-4t-r9
[2009/07/24 11:38:49 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Trusteer
[2007/01/28 16:26:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2005/12/19 10:48:09 | 00,000,000 | —D | M] – C:\Documents and Settings\g\Application Data\InterVideo
[2006/01/02 18:21:52 | 00,000,000 | —D | M] – C:\Documents and Settings\g\Application Data\Leadertech
[2005/12/16 23:30:20 | 00,000,000 | —D | M] – C:\Documents and Settings\g\Application Data\muvee Technologies
[2005/12/31 15:08:10 | 00,000,000 | —D | M] – C:\Documents and Settings\g\Application Data\Template
[2009/07/24 11:38:48 | 00,000,000 | —D | M] – C:\Documents and Settings\g\Application Data\Trusteer
[2007/01/28 20:39:39 | 00,000,000 | —D | M] – C:\Documents and Settings\g\Application Data\Viewpoint
[2009/12/09 12:00:00 | 00,000,330 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job

========== Purity Check ==========



========== Files - Unicode (All) ==========
[2006/09/30 17:08:43 | 01,465,856 | —- | M] ()(C:\Documents and Settings\g\My Documents\a??a??a??e??a??e·?a–‧.pps) – C:\Documents and Settings\g\My Documents\扂參堎謠冞跤斕.pps
[2006/09/30 17:05:43 | 01,465,856 | —- | C] ()(C:\Documents and Settings\g\My Documents\a??a??a??e??a??e·?a–‧.pps) – C:\Documents and Settings\g\My Documents\扂參堎謠冞跤斕.pps
< End of report >

================================================================================
======================
OTL EXtra


OTL Extras logfile created on: 12/9/2009 8:48:19 PM - Run 1
OTL by OldTimer - Version 3.1.12.0 Folder = C:\Documents and Settings\g\My Documents\Downloads
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

382.48 Mb Total Physical Memory | 53.50 Mb Available Physical Memory | 13.99% Memory free
947.64 Mb Paging File | 241.73 Mb Available in Paging File | 25.51% Paging File free
Paging file location(s): C:\pagefile.sys 576 1152 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55.88 Gb Total Space | 39.05 Gb Free Space | 69.88% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: PC129202628113
Current User Name: g
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL – (AOL LLC)
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL – (AOL LLC)
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:America Online 9.0 – (America Online, Inc.)
"C:\Program Files\MSN Messenger\msncall.exe" = C:\Program Files\MSN Messenger\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone) – File not found
"C:\Program Files\MSN Messenger\livecall.exe" = C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone) – (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" = C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Disabled:Earthlink – File not found
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL – (AOL LLC)
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL – (AOL LLC)
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:America Online 9.0 – (America Online, Inc.)
"C:\Program Files\MSN Messenger\msncall.exe" = C:\Program Files\MSN Messenger\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone) – File not found
"C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype – File not found
"C:\Program Files\Common Files\AOL\TopSpeed\3.0\aoltpsd3.exe" = C:\Program Files\Common Files\AOL\TopSpeed\3.0\aoltpsd3.exe:*:Enabled:AOL TopSpeed – File not found
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)
"C:\Program Files\Common Files\AOL\1151722181\ee\aolsoftware.exe" = C:\Program Files\Common Files\AOL\1151722181\ee\aolsoftware.exe:*:Enabled:AOL Services – (America Online, Inc.)
"C:\Program Files\MSN Messenger\livecall.exe" = C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone) – (Microsoft Corporation)
"C:\Program Files\IncrediMail\bin\ImApp.exe" = C:\Program Files\IncrediMail\bin\ImApp.exe:*:Enabled:IncrediMail – File not found
"C:\Program Files\IncrediMail\bin\IncMail.exe" = C:\Program Files\IncrediMail\bin\IncMail.exe:*:Enabled:IncrediMail – File not found
"C:\Program Files\IncrediMail\bin\ImpCnt.exe" = C:\Program Files\IncrediMail\bin\ImpCnt.exe:*:Enabled:IncrediMail – File not found
"D:\majang 2002\server.exe" = D:\majang 2002\server.exe:*:Enabled:server – File not found


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{075473F5-846A-448B-BCB3-104AA1760205}" = Sonic Data Module
"{0878E100-C0BB-41E8-B4C6-C486B61FDA7B}" = Canon PhotoRecord
"{09984AEC-6B9F-4ca7-B78D-CB44D4771DA3}" = Destinations
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{0C3FCE48-6984-11D5-90F8-00E029591716}" = Brother MFL Pro Suite
"{0D499481-22C6-4B25-8AC2-6D3F6C885FB9}" = OpenOffice.org Installer 1.0
"{15D91706-6ADF-44CF-9D7D-FF2D8ACD2C6F}" = LS_HSI
"{15EE79F4-4ED1-4267-9B0F-351009325D7D}" = HP Software Update
"{21657574-BD54-48A2-9450-EB03B2C7FC29}" = Sonic MyDVD Plus
"{218BBBE3-FE63-4BB2-81A8-7435575A84FA}" = PhotoStitch
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{28291BD5-92D2-4685-82DC-CCA925C53CCA}" = RemoteCapture Task 1.1
"{2CADCEAB-D5DA-44D6-B5FC-7DEE87AB3C0C}" = Unload
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
"{30C19FF2-7FBA-4d09-B9DE-1659977F64F6}" = TrayApp
"{30C2FCD0-FF7B-4FFA-8DDE-43A22E01A1E7}" = Rhapsody Player Engine
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3DE5E7D4-7B88-403C-A3FD-2017A8240C5B}" = Google Earth
"{416D80BA-6F6D-4672-B7CF-F54DA2F80B44}" = Microsoft Works
"{4302B2DD-D958-40E3-BAF3-B07FFE1978CE}" = HP Wireless Assistant 1.01 A2
"{45EF4EE3-F591-4B74-A477-0CAE12934CE7}" = RAW Image Task 1.2
"{4C96958A-6562-4143-B820-FF4890D3B734}" = Camera Window DVC
"{534AA552-E1F1-4965-B2AA-FBDEB0730D60}" = muvee autoProducer 4.0 - SE
"{53EE9E42-CECB-4C92-BF76-9CA65DAF8F1C}" = FullDPAppQFolder
"{56F8AFC3-FA98-4ff1-9673-8A026CBF85BE}" = WebReg
"{571700F0-DB9D-4B3A-B03D-35A14BB5939F}" = Windows Live Messenger
"{5F26311C-B135-4F7F-B11E-8E650F83651E}" = DeviceFunctionQFolder
"{612DC38A-B36A-4699-88EB-12C7394DE2FC}" = TIxx21
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Sonic Express Labeler
"{66C018BD-6F16-4B32-B4CD-1DC1B21FBDFF}" = Zone Deluxe Games
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{74EC78BC-B379-4E29-9006-8F161DCAABA6}" = Apple Software Update
"{79546A5F-AE7C-4693-8670-A3401B43ABD2}" = HP Deskjet 5900 series
"{8105684D-8CA6-440D-8F58-7E5FD67A499D}" = Easy Internet Sign-up
"{8AF1E098-1A5C-4336-BBE2-D047ABB401ED}" = MovieEdit Task
"{91203BD3-6C3E-472F-ADBD-F60FDC7C4010}" = Camera Window DS
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD
"{91F1A0D6-23AD-49FE-8D4E-379485652214}" = Camera Support Core Library
"{9357AE3A-B2ED-4138-BB9B-0564352C3F0A}" = iTunes
"{95A890AA-B3B1-44B6-9C18-A8F7AB3EE7FC}" = QuickTime
"{A06275F4-324B-4E85-95E6-87B2CD729401}" = Windows Defender
"{A43B2A2F-1DB5-47F9-A608-F11A4835D7CB}" = Apple Mobile Device Support
"{A5222E5A-13CB-4C98-9F5C-21CF6896A25C}" = HPDeskjet5900Series
"{A93C4E94-1005-489D-BEAA-B873C1AA6CFC}" = HP Help and Support
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Sonic Audio Module
"{AC76BA86-7AD7-1033-7B44-A70000000000}" = Adobe Reader 7.0
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Sonic Copy Module
"{B996AE66-10DB-4ac5-B151-E8B4BFBC42FC}" = BufferChm
"{C151CE54-E7EA-4804-854B-F515368B0798}" = Athlon 64 Processor Driver
"{C1D76D7A-F3BB-47EA-A746-5B1E2FFC1DF2}" = Canon ZoomBrowser EX
"{C7281207-4AA4-425E-B57A-0E9EF8445635}" = Camera Window MC
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CEB326EC-8F40-47B2-BA22-BB092565D66F}" = Quick Launch Buttons 5.10 B2
"{D1E8DC27-C3CD-4DD8-B37B-D26D7D7CFCBD}" = HP User Guides 0002
"{DB518BA6-CB74-4EB6-9ABD-880B6D6E1F38}" = HpSdpAppCoreApp
"{E3F90083-80D4-4b5a-87C7-E97E12F5516D}" = HPProductAssistant
"{EA103B64-C0E4-4C0E-A506-751590E1653D}" = SolutionCenter
"{F4C2E5F5-2970-45f4-ABD3-C180C4D961C4}" = Status
"{F652D238-5F29-42D5-BAF3-0115EF977EC2}" = Windows Live Sign-in Assistant
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"All ATI Software" = ATI - Software Uninstall Utility
"AOL Toolbar" = AOL Toolbar
"AOL Uninstaller" = AOL Uninstaller (Choose which Products to Remove)
"AOL YGP Screensaver" = AOL You've Got Pictures Screensaver
"AOLCoach" = AOL Coach Version 1.0(Build:20040229.1 en)
"ATI Display Driver" = ATI Display Driver
"avast!" = avast! Antivirus
"CNXT_AUDIO" = Conexant AC-Link Audio
"CNXT_MODEM_PCI_VEN_1002&DEV;_4378&SUBSYS;_3091103C" = Data Fax SoftModem with SmartCP
"DVD Shrink_is1" = DVD Shrink 3.1.4
"Extreme" = Extreme Chess
"Google Desktop" = Google Desktop
"HP Imaging Device Functions" = HP Imaging Device Functions 5.0
"HP Solution Center & Imaging Support Tools" = HP Solution Center & Imaging Support Tools 5.0
"InstallShield_{218BBBE3-FE63-4BB2-81A8-7435575A84FA}" = Canon Utilities PhotoStitch 3.1
"InstallShield_{28291BD5-92D2-4685-82DC-CCA925C53CCA}" = Canon RemoteCapture Task for ZoomBrowser EX
"InstallShield_{45EF4EE3-F591-4B74-A477-0CAE12934CE7}" = Canon RAW Image Task for ZoomBrowser EX
"InstallShield_{4C96958A-6562-4143-B820-FF4890D3B734}" = Canon Camera Window DVC for ZoomBrowser EX
"InstallShield_{612DC38A-B36A-4699-88EB-12C7394DE2FC}" = Texas Instruments PCIxx21/x515 drivers.
"InstallShield_{8105684D-8CA6-440D-8F58-7E5FD67A499D}" = Easy Internet Sign-up
"InstallShield_{8AF1E098-1A5C-4336-BBE2-D047ABB401ED}" = Canon MovieEdit Task for ZoomBrowser EX
"InstallShield_{91203BD3-6C3E-472F-ADBD-F60FDC7C4010}" = Canon Camera Window DS for ZoomBrowser EX
"InstallShield_{91F1A0D6-23AD-49FE-8D4E-379485652214}" = Canon Camera Support Core Library
"InstallShield_{C7281207-4AA4-425E-B57A-0E9EF8445635}" = Canon Camera Window for ZoomBrowser EX
"Lexmark Z600 Series" = Lexmark Z600 Series
"Lexmark Z700-P700 Series" = Lexmark Z700-P700 Series
"LiveUpdate" = LiveUpdate 3.0 (Symantec Corporation)
"Living Trust Forms" = Living Trust Forms
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Money2005b" = Microsoft Money 2005
"Mozilla Firefox (3.5.5)" = Mozilla Firefox (3.5.5)
"MSNINST" = MSN
"Nero - Burning Rom!UninstallKey" = Nero 6 Ultra Edition
"PANZERS - Phase1" = PANZERS - Phase1
"Quicken Deluxe 98" = Quicken Deluxe 98
"Rapport_is1" = Rapport
"RealPlayer 6.0" = RealPlayer Basic
"ShockwaveFlash" = Macromedia Flash Player 8
"StreetPlugin" = Learn2 Player (Uninstall Only)
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"TCDIT-1.0" = TCDIT-1.0
"ViewpointMediaPlayer" = Viewpoint Media Player
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows Media Player" = Windows Media Player 10
"Yahoo! Anti-Spy" = Yahoo! Anti-Spy
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Toolbar" = Yahoo! Toolbar
"YInstHelper" = Yahoo! Install Manager

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 11/15/2009 2:11:07 AM | Computer Name = PC129202628113 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.

Error - 11/15/2009 2:11:08 AM | Computer Name = PC129202628113 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.

Error - 11/21/2009 12:26:17 AM | Computer Name = PC129202628113 | Source = Application Hang | ID = 1002
Description = Hanging application explorer.exe, version 6.0.2900.3156, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 11/22/2009 12:26:02 AM | Computer Name = PC129202628113 | Source = Application Hang | ID = 1002
Description = Hanging application IEXPLORE.EXE, version 6.0.2900.2180, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 11/22/2009 12:26:02 AM | Computer Name = PC129202628113 | Source = Application Hang | ID = 1002
Description = Hanging application IEXPLORE.EXE, version 6.0.2900.2180, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 11/22/2009 12:26:03 AM | Computer Name = PC129202628113 | Source = Application Hang | ID = 1002
Description = Hanging application IEXPLORE.EXE, version 6.0.2900.2180, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 11/22/2009 12:26:04 AM | Computer Name = PC129202628113 | Source = Application Hang | ID = 1002
Description = Hanging application IEXPLORE.EXE, version 6.0.2900.2180, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 12/1/2009 12:59:02 AM | Computer Name = PC129202628113 | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.3156, faulting
module ntdll.dll, version 5.1.2600.3520, fault address 0x000101b3.

Error - 12/1/2009 12:59:33 AM | Computer Name = PC129202628113 | Source = Application Error | ID = 1000
Description = Faulting application drwtsn32.exe, version 5.1.2600.0, faulting module
dbghelp.dll, version 5.1.2600.2180, fault address 0x0001295d.

Error - 12/2/2009 5:53:17 PM | Computer Name = PC129202628113 | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 80240016, P2 begininstall, P3 install, P4
1.1.1593.0, P5 mpsigdwn.dll, P6 1.1.1593.0, P7 windows defender, P8 NIL, P9 NIL,
P10 NIL.

[ System Events ]
Error - 12/9/2009 9:17:42 AM | Computer Name = PC129202628113 | Source = Service Control Manager | ID = 7000
Description = The avast! Web Scanner service failed to start due to the following
error: %%1053

Error - 12/9/2009 9:18:12 AM | Computer Name = PC129202628113 | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the avast! Web Scanner service
to connect.

Error - 12/9/2009 9:18:12 AM | Computer Name = PC129202628113 | Source = Service Control Manager | ID = 7000
Description = The avast! Web Scanner service failed to start due to the following
error: %%1053

Error - 12/9/2009 9:18:59 AM | Computer Name = PC129202628113 | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the avast! Web Scanner service
to connect.

Error - 12/9/2009 9:19:00 AM | Computer Name = PC129202628113 | Source = Service Control Manager | ID = 7000
Description = The avast! Web Scanner service failed to start due to the following
error: %%1053

Error - 12/9/2009 9:19:27 AM | Computer Name = PC129202628113 | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the avast! Web Scanner service
to connect.

Error - 12/9/2009 9:19:27 AM | Computer Name = PC129202628113 | Source = Service Control Manager | ID = 7000
Description = The avast! Web Scanner service failed to start due to the following
error: %%1053

Error - 12/9/2009 9:20:01 AM | Computer Name = PC129202628113 | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the avast! Web Scanner service
to connect.

Error - 12/9/2009 9:20:01 AM | Computer Name = PC129202628113 | Source = Service Control Manager | ID = 7000
Description = The avast! Web Scanner service failed to start due to the following
error: %%1053

Error - 12/9/2009 9:23:08 AM | Computer Name = PC129202628113 | Source = Service Control Manager | ID = 7034
Description = The avast! Web Scanner service terminated unexpectedly. It has done
this 1 time(s).


< End of report >
almar,

Double click on OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Processes
explorer.exe

:OTL
SRV - File not found – – (gusvc)
SRV - [2006/05/15 17:24:33 | 02,086,592 | —- | M] (Symantec Corporation) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_0.EXE – (LiveUpdate)
SRV - [2006/05/15 17:24:33 | 00,100,032 | —- | M] (Symantec Corporation) – C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe – (Automatic LiveUpdate Scheduler)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found.
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [My Web Search Bar] C:\PROGRA~1\MYWEBS~1\bar\1.bin\MWSBAR.DLL File not found
O33 - MountPoints2\{d8e32852-a757-11dc-a403-00038a000015}\Shell\AutoRun\command - "" = E:\Autorun.exe – File not found
O33 - MountPoints2\{d8e32852-a757-11dc-a403-00038a000015}\Shell\Shell00\Command - "" = E:\Autorun.exe – File not found
O33 - MountPoints2\{d8e32852-a757-11dc-a403-00038a000015}\Shell\Shell01\Command - "" = E:\Autorun.exe – File not found
O33 - MountPoints2\{d8e32852-a757-11dc-a403-00038a000015}\Shell\Shell02\Command - "" = E:\Autorun.exe – File not found
[2009/11/19 22:47:19 | 00,000,244 | -H– | M] () – C:\sqmnoopt05.sqm
[2009/11/19 22:47:19 | 00,000,232 | -H– | M] () – C:\sqmdata05.sqm
[2009/11/17 21:26:05 | 00,000,244 | -H– | M] () – C:\sqmnoopt04.sqm
[2009/11/17 21:26:05 | 00,000,232 | -H– | M] () – C:\sqmdata04.sqm
[2009/11/15 13:28:24 | 00,000,232 | -H– | M] () – C:\sqmdata03.sqm
[2009/11/15 13:28:22 | 00,000,244 | -H– | M] () – C:\sqmnoopt03.sqm


:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
  • Reboot your computer
Please post the OTL log.



Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI