This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] running slow having defragment issues

24 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:02:37 PM, on 5/3/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AVG\AVG9\avgemc.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (file missing)
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O12 - Plugin for .do: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1243653217515
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20270.www2.hp.com/ediags/gmn2/inst…tDetection2.cab
O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} (CBSTIEPrint Class) - http://offers.e-centives.com/cif/download/bin/actxcab.cab
O16 - DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eB…l_v1-0-29-0.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: AVG Free E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgemc.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

–
End of file - 5274 bytes


could someone look at my log, im running slow and cant seem to defragment the hard drive properly. i have a malware bytes log on the way

heres the current malware log




Malwarebytes' Anti-Malware 1.41
Database version: 2976
Windows 5.1.2600 Service Pack 3

5/3/2010 8:32:00 PM
mbam-log-2010-05-03 (20-32-00).txt

Scan type: Full Scan (C:\|)
Objects scanned: 210306
Time elapsed: 1 hour(s), 34 minute(s), 12 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
My name is SweetTech. I would be glad to take a look at your log and help you with solving any malware problems. I'd be grateful if you would note the following:
  • Logs from malware removal programs (DDS is one of them) can take some time to analyze. I need you to be patient while I analyze any logs you post.
  • Please make sure to carefully read any instruction that I give you.
    Reading too lightly will cause you to miss important steps, which could have destructive effects.
  • If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • These instructions have been specifically tailored to your computer and the issues you are experiencing with your computer. It's important to note that these instructions are not suitable for any other computer, even if the issues are fairly similar.
  • Do not do things I do not ask for, such as running a spyware scan on your computer. The one thing that you should always do, is to make sure sure that your anti-virus definitions are up-to-date!
  • If I instruct you to download a specific tool in which you already have, please delete the copy that you have and re-download the tool. The reason I ask you to do this is because these tools are updated fairly regularly.
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • I am going to stick with you until ALL malware is gone from your system. I would appreciate it if you would do the same. From this point, we're in this together ;)
    Because of this, you must reply within three days
    failure to reply will result in the topic being closed!
  • Please do not PM me directly for help. If you have any questions, post them in this topic. The only time you can and should PM me is when I have not been replying to you for several days (usually around 4 days) and you need an explanation. If that's the case, just send me a message on here. ;)
  • Lastly, I am no magician. I will try very hard to fix your issues, but no promises can be made. Also be aware that some infections are so severe that you might need to resort to reformatting and reinstalling your operating system.
    Don't worry, this only happens in severe cases, but it sadly does happen. Be prepared to back up your data. Have means of backing up your data available.
____________________________________________________


OTL Custom Scan
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in


    netsvcs
    %SYSTEMDRIVE%\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\drivers\*.sys /90

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.


NEXT:



Scanning with GMER

Please download GMER from one of the following locations and save it to your desktop:
  • Main Mirror
    This version will download a randomly named file (Recommended)
  • Zipped Mirror
    This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.
  • Disconnect from the Internet and close all running programs.
  • Temporarily disable any real-time active protection so your security programs will not conflict with gmer's driver.
  • Double-click on the randomly named GMER file (i.e. n7gmo46c.exe) and allow the gmer.sys driver to load if asked.
  • Note: If you downloaded the zipped version, extract the file to its own folder such as C:\gmer and then double-click on gmer.exe.

    [external image: Posted Image]
  • GMER will open to the Rootkit/Malware tab and perform an automatic quick scan when first run. (do not use the computer while the scan is in progress)
  • If you receive a WARNING!!! about rootkit activity and are asked to fully scan your system…click NO.
  • Now click the Scan button. If you see a rootkit warning window, click OK.
  • When the scan is finished, click the Save… button to save the scan results to your Desktop. Save the file as gmer.log.
  • Click the Copy button and paste the results into your next reply.
  • Exit GMER and be sure to re-enable your anti-virus, Firewall and any other security programs you had disabled.
– If you encounter any problems, try running GMER in safe mode.
– If GMER crashes or keeps resulting in a BSODs, uncheck Devices on the right side before scanning
.



NEXT:



Please make sure you include the following items in your next post:

1. Any comments or questions you may have that you'd like for me to answer in my next post to you.
2. The logs that were produced after running the OTL scans. (OTL.txt & Extras.txt)
3. The log that was produced after running GMER
4. An update on how your computer is currently running.

It would be helpful if you could answer each question in the order asked, as well as numbering your answers.
first off thank you for your help!!! ive been through the help process here before and im going to do my absolute best to do EXACTLY as you say :)

ive got the 1st log you asked for but the second program has been giving me lots of trouble. i dont know if its me or the machine but as it was running it would just STOP, lock up if you will and do nothing. it did show some things on the screen and they are down below at the botttom of this response. hopefiully you can make somthing of it.
heres the 1st logs

OTL Extras logfile created on: 5/4/2010 8:36:01 PM - Run 1
OTL by OldTimer - Version 3.2.4.1 Folder = C:\Documents and Settings\augustus able\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

512.00 Mb Total Physical Memory | 250.00 Mb Available Physical Memory | 49.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 79.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 127.97 Gb Total Space | 93.69 Gb Free Space | 73.21% Space Free | Partition Type: FAT32
D: Drive not present or media not loaded
Drive E: | 654.81 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: HOME-3XQK3JVJDE
Current User Name: augustus able
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\AVG\AVG8\avgemc.exe" = C:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe – File not found
"C:\Program Files\AVG\AVG8\avgupd.exe" = C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe – File not found
"C:\Program Files\AVG\AVG8\avgnsx.exe" = C:\Program Files\AVG\AVG8\avgnsx.exe:*:Enabled:avgnsx.exe – File not found
"C:\WINDOWS\System32\usmt\migwiz.exe" = C:\WINDOWS\System32\usmt\migwiz.exe:*:Disabled:Files and Settings Transfer Wizard – (Microsoft Corporation)
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe" = C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe – ()
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\AVG\AVG9\avgemc.exe" = C:\Program Files\AVG\AVG9\avgemc.exe:*:Enabled:avgemc.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgupd.exe" = C:\Program Files\AVG\AVG9\avgupd.exe:*:Enabled:avgupd.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgnsx.exe" = C:\Program Files\AVG\AVG9\avgnsx.exe:*:Enabled:avgnsx.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger – File not found


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3A316611-45D1-429C-AA26-B71259C44689}" = HP Photosmart, Officejet and Deskjet 7.0.A
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1
"{C8753E28-2680-49BF-BD48-DD38FD086EFE}" = AiO_Scan_CDA
"{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}" = HP Product Detection
"{F2527115-B8BF-4FDB-B5DA-5AADFB7C13E1}" = The Sims Complete Collection
"{F3760724-B29D-465B-BC53-E5D72095BCC4}" = Scan
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"AVG9Uninstall" = AVG Free 9.0
"Coupon Printer for Windows4.0" = Coupon Printer for Windows
"HijackThis" = HijackThis 2.0.2
"ie8" = Windows Internet Explorer 8
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"NVIDIA Drivers" = NVIDIA Drivers
"Windows XP Service Pack" = Windows XP Service Pack 3

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 2/17/2010 5:36:55 PM | Computer Name = HOME-3XQK3JVJDE | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: The data is invalid.

Error - 2/17/2010 5:36:56 PM | Computer Name = HOME-3XQK3JVJDE | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: The data is invalid.

Error - 2/17/2010 5:36:57 PM | Computer Name = HOME-3XQK3JVJDE | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: The data is invalid.

Error - 2/17/2010 5:36:58 PM | Computer Name = HOME-3XQK3JVJDE | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: The data is invalid.

Error - 2/17/2010 5:36:58 PM | Computer Name = HOME-3XQK3JVJDE | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: The data is invalid.

Error - 2/17/2010 5:36:59 PM | Computer Name = HOME-3XQK3JVJDE | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: The data is invalid.

Error - 2/17/2010 5:36:59 PM | Computer Name = HOME-3XQK3JVJDE | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: The data is invalid.

Error - 2/17/2010 5:37:00 PM | Computer Name = HOME-3XQK3JVJDE | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: The data is invalid.

Error - 2/17/2010 6:11:10 PM | Computer Name = HOME-3XQK3JVJDE | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: The data is invalid.

Error - 2/17/2010 7:18:47 PM | Computer Name = HOME-3XQK3JVJDE | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: The data is invalid.

[ System Events ]
Error - 5/2/2010 11:58:33 AM | Computer Name = HOME-3XQK3JVJDE | Source = DCOM | ID = 10000
Description = Unable to start a DCOM Server: {FB7199AB-79BF-11D2-8D94-0000F875C541}.
The
error: "%2" Happened while starting this command: C:\Program Files\Messenger\msmsgs.exe
-Embedding

Error - 5/2/2010 3:08:31 PM | Computer Name = HOME-3XQK3JVJDE | Source = DCOM | ID = 10000
Description = Unable to start a DCOM Server: {FB7199AB-79BF-11D2-8D94-0000F875C541}.
The
error: "%2" Happened while starting this command: C:\Program Files\Messenger\msmsgs.exe
-Embedding

Error - 5/3/2010 7:48:36 PM | Computer Name = HOME-3XQK3JVJDE | Source = DCOM | ID = 10000
Description = Unable to start a DCOM Server: {FB7199AB-79BF-11D2-8D94-0000F875C541}.
The
error: "%2" Happened while starting this command: C:\Program Files\Messenger\msmsgs.exe
-Embedding

Error - 5/3/2010 8:07:14 PM | Computer Name = HOME-3XQK3JVJDE | Source = DCOM | ID = 10000
Description = Unable to start a DCOM Server: {FB7199AB-79BF-11D2-8D94-0000F875C541}.
The
error: "%2" Happened while starting this command: C:\Program Files\Messenger\msmsgs.exe
-Embedding

Error - 5/3/2010 9:34:44 PM | Computer Name = HOME-3XQK3JVJDE | Source = DCOM | ID = 10000
Description = Unable to start a DCOM Server: {FB7199AB-79BF-11D2-8D94-0000F875C541}.
The
error: "%2" Happened while starting this command: C:\Program Files\Messenger\msmsgs.exe
-Embedding

Error - 5/3/2010 10:38:25 PM | Computer Name = HOME-3XQK3JVJDE | Source = DCOM | ID = 10000
Description = Unable to start a DCOM Server: {FB7199AB-79BF-11D2-8D94-0000F875C541}.
The
error: "%2" Happened while starting this command: C:\Program Files\Messenger\msmsgs.exe
-Embedding

Error - 5/4/2010 7:15:18 PM | Computer Name = HOME-3XQK3JVJDE | Source = DCOM | ID = 10000
Description = Unable to start a DCOM Server: {FB7199AB-79BF-11D2-8D94-0000F875C541}.
The
error: "%2" Happened while starting this command: C:\Program Files\Messenger\msmsgs.exe
-Embedding

Error - 5/4/2010 7:24:07 PM | Computer Name = HOME-3XQK3JVJDE | Source = DCOM | ID = 10000
Description = Unable to start a DCOM Server: {FB7199AB-79BF-11D2-8D94-0000F875C541}.
The
error: "%2" Happened while starting this command: C:\Program Files\Messenger\msmsgs.exe
-Embedding

Error - 5/4/2010 9:15:41 PM | Computer Name = HOME-3XQK3JVJDE | Source = DCOM | ID = 10000
Description = Unable to start a DCOM Server: {FB7199AB-79BF-11D2-8D94-0000F875C541}.
The
error: "%2" Happened while starting this command: C:\Program Files\Messenger\msmsgs.exe
-Embedding

Error - 5/4/2010 9:34:09 PM | Computer Name = HOME-3XQK3JVJDE | Source = Service Control Manager | ID = 7034
Description = The AVG Free E-mail Scanner service terminated unexpectedly. It has
done this 1 time(s).


< End of report >
OTL logfile created on: 5/4/2010 8:36:01 PM - Run 1
OTL by OldTimer - Version 3.2.4.1 Folder = C:\Documents and Settings\augustus able\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

512.00 Mb Total Physical Memory | 250.00 Mb Available Physical Memory | 49.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 79.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 127.97 Gb Total Space | 93.69 Gb Free Space | 73.21% Space Free | Partition Type: FAT32
D: Drive not present or media not loaded
Drive E: | 654.81 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: HOME-3XQK3JVJDE
Current User Name: augustus able
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\augustus able\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG9\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\augustus able\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (avg9wd) – C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg9emc) – C:\Program Files\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)


========== Driver Services (SafeList) ==========

DRV - (AvgTdiX) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (gameenum) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (wdm_opl3sax) YAMAHA OPL3-SAx Audio Driver (WDM) – C:\WINDOWS\system32\drivers\opl3sax.sys (Yamaha Corp.)
DRV - (EL90X) – C:\WINDOWS\system32\drivers\el90xnd5.sys (3Com Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



O1 HOSTS File: ([2001/08/23 12:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll File not found
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKCU..\Run: [MSMSGS] C:\Program Files\Messenger\msmsgs.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe File not found
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe File not found
O12 - Plugin for: .do - C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll (Adobe Systems Inc.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {33564D57-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/D/0…D0C/wmv9dmo.cab (Reg Error: Key error.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1243653217515 (WUWebControl Class)
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab (HP Download Manager)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20270.www2.hp.com/ediags/gmn2/inst…tDetection2.cab (GMNRev Class)
O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} http://offers.e-centives.com/cif/download/bin/actxcab.cab (CBSTIEPrint Class)
O16 - DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} http://tools.ebayimg.com/eps/wl/activex/eB…l_v1-0-29-0.cab (EPUImageControl Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop WallPaper: C:\Documents and Settings\augustus able\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\augustus able\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/03/26 18:19:08 | 000,000,194 | —- | M] () - C:\AUTOEXEC.BAT – [ FAT32 ]
O32 - AutoRun File - [2005/07/29 20:24:42 | 000,000,044 | R— | M] () - E:\autorun.inf – [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2009/05/29 20:53:56 | 000,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)

========== Files/Folders - Created Within 30 Days ==========

[2010/05/04 20:17:15 | 000,570,880 | —- | C] (OldTimer Tools) – C:\Documents and Settings\augustus able\Desktop\OTL.exe
[2010/05/02 20:10:42 | 000,000,000 | —D | C] – C:\WINDOWS\System32\appmgmt
[2010/05/02 19:47:07 | 000,012,464 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2010/05/02 19:40:31 | 003,558,912 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\moviemk.exe
[2010/05/02 19:35:20 | 000,000,000 | —D | C] – C:\found files whatever
[2010/05/02 19:32:59 | 000,000,000 | —D | C] – C:\Documents and Settings\augustus able\Desktop\Unused Desktop Shortcuts
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/05/04 20:32:54 | 000,013,050 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/05/04 20:32:34 | 000,088,566 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2010/05/04 20:31:54 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/05/04 20:31:44 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/05/04 20:24:24 | 004,283,640 | -H– | M] () – C:\Documents and Settings\augustus able\Local Settings\Application Data\IconCache.db
[2010/05/04 20:18:54 | 000,293,376 | —- | M] () – C:\Documents and Settings\augustus able\Desktop\xjcbr3vl.exe
[2010/05/04 20:17:16 | 000,570,880 | —- | M] (OldTimer Tools) – C:\Documents and Settings\augustus able\Desktop\OTL.exe
[2010/05/04 17:47:36 | 000,000,438 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{19EC8709-8E90-4F72-A317-CA9CE6ADC554}.job
[2010/05/02 20:08:56 | 000,004,507 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/05/02 20:08:54 | 000,355,086 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/05/02 20:08:54 | 000,311,604 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/05/02 20:08:54 | 000,039,992 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/05/02 20:03:30 | 001,572,864 | —- | M] () – C:\Documents and Settings\augustus able\ntuser.dat
[2010/05/02 20:03:30 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\augustus able\ntuser.ini
[2010/05/02 19:47:16 | 000,242,896 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2010/05/02 19:47:08 | 000,029,512 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2010/05/02 19:47:08 | 000,012,464 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2010/05/02 19:46:14 | 000,216,200 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2010/05/02 19:33:36 | 000,000,104 | —- | M] () – C:\Documents and Settings\augustus able\Desktop\Shortcut to E-mail.lnk
[2010/05/02 19:33:30 | 000,000,104 | —- | M] () – C:\Documents and Settings\augustus able\Desktop\Internet.lnk
[2010/05/01 10:28:16 | 000,226,728 | R— | M] (Coupons, Inc.) – C:\WINDOWS\System32\cpnprt2.cid
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/05/04 20:18:51 | 000,293,376 | —- | C] () – C:\Documents and Settings\augustus able\Desktop\xjcbr3vl.exe
[2010/05/02 19:33:35 | 000,000,104 | —- | C] () – C:\Documents and Settings\augustus able\Desktop\Shortcut to E-mail.lnk
[2010/05/02 19:33:28 | 000,000,104 | —- | C] () – C:\Documents and Settings\augustus able\Desktop\Internet.lnk
[2009/06/15 11:52:24 | 000,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2009/05/30 23:31:45 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\HPZIDS01.dll
[2006/10/22 12:22:00 | 001,662,976 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2006/10/22 12:22:00 | 001,470,464 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2006/10/22 12:22:00 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2006/10/22 12:22:00 | 000,581,632 | —- | C] () – C:\WINDOWS\System32\nvhwvid.dll
[2006/10/22 12:22:00 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2006/10/22 12:22:00 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2006/10/22 12:22:00 | 000,212,992 | —- | C] () – C:\WINDOWS\System32\nvapi.dll

========== LOP Check ==========

[2009/11/02 15:51:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Grisoft
[2009/11/02 16:05:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Avg7
[2009/11/02 16:29:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\avg9
[2009/11/22 16:56:54 | 000,000,000 | —D | M] – C:\Documents and Settings\augustus able\Application Data\E-centives
[2010/05/04 17:47:36 | 000,000,438 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{19EC8709-8E90-4F72-A317-CA9CE6ADC554}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2007/10/08 10:25:08 | 000,011,539 | —- | M] () – C:\ComboFix3.txt
[2010/05/04 20:31:38 | 805,306,368 | -HS- | M] () – C:\PAGEFILE.SYS
[2009/05/25 07:41:52 | 000,003,736 | —- | M] () – C:\VundoFix.txt
[2006/03/26 18:14:04 | 000,001,660 | RHS- | M] () – C:\MSDOS.SYS
[2009/05/29 23:52:24 | 000,000,282 | RHS- | M] () – C:\boot.ini
[2007/10/06 11:13:20 | 002,028,640 | —- | M] () – C:\sp1aexpress_usa.exe
[2006/03/26 18:19:08 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2000/06/08 17:00:00 | 000,110,080 | RHS- | M] () – C:\IO.SYS
[2006/03/26 18:19:08 | 000,000,194 | —- | M] () – C:\AUTOEXEC.BAT
[2006/03/26 18:09:20 | 000,241,696 | RH– | M] () – C:\CLASSES.1ST
[2006/03/26 18:19:10 | 000,000,000 | —- | M] () – C:\CONFIG.BAK
[2007/06/07 23:27:06 | 000,000,146 | —- | M] () – C:\YServer.txt
[2006/03/26 18:29:10 | 000,000,512 | -HS- | M] () – C:\BOOTSECT.DOS
[2009/05/31 16:27:06 | 000,250,048 | RHS- | M] () – C:\ntldr
[2009/05/29 23:44:40 | 000,047,564 | RHS- | M] () – C:\ntdetect.com
[2007/07/15 22:10:52 | 000,000,000 | —- | M] () – C:\CB_Server_Errors.txt
[2007/06/13 12:56:56 | 000,028,074 | —- | M] () – C:\EXIFTable.dbf
[2006/03/26 17:10:32 | 021,920,944 | —- | M] (NVIDIA Corporation) – C:\84.21_forceware_winxp2k_english_whql.exe
[2006/01/29 16:41:12 | 001,579,352 | —- | M] () – C:\HiSpeed.exe
[2009/05/24 07:48:42 | 000,006,752 | —- | M] () – C:\ComboFix.txt
[2007/07/15 22:11:02 | 000,000,786 | —- | M] () – C:\administrativeInfo.dbf
[2007/07/15 22:11:02 | 000,003,089 | —- | M] () – C:\pathnameTable.dbf
[2007/07/15 22:11:02 | 000,004,608 | —- | M] () – C:\pathnameTable.cdx
[2007/07/15 22:11:02 | 000,036,891 | —- | M] () – C:\imageTable.dbf
[2007/06/13 12:55:16 | 000,001,024 | —- | M] () – C:\imageTable.fpt
[2007/06/13 12:56:56 | 000,003,072 | —- | M] () – C:\EXIFTable.cdx
[2005/02/16 11:06:00 | 000,218,112 | —- | M] (Soeperman Enterprises Ltd.) – C:\HijackThis.exe
[2007/07/15 22:11:02 | 000,020,480 | —- | M] () – C:\imageTable.cdx
[2007/07/15 22:11:02 | 000,003,762 | —- | M] () – C:\albumTable.dbf
[2007/07/15 22:11:02 | 000,004,608 | —- | M] () – C:\albumTable.cdx
[2006/03/28 10:46:54 | 000,002,076 | —- | M] () – C:\hijackthis.log
[2007/06/13 12:49:52 | 000,000,392 | —- | M] () – C:\ROFTable.dbf
[2007/07/15 22:11:02 | 000,095,298 | —- | M] () – C:\albumImagesTable.dbf
[2007/07/15 22:11:02 | 000,012,800 | —- | M] () – C:\albumImagesTable.cdx
[2007/06/13 12:49:52 | 000,000,456 | —- | M] () – C:\keywordTable.dbf
[2007/06/13 12:49:52 | 000,004,608 | —- | M] () – C:\keywordTable.cdx
[2007/06/13 12:49:52 | 000,000,360 | —- | M] () – C:\keywordImagesTable.dbf
[2007/06/13 12:49:52 | 000,003,072 | —- | M] () – C:\ROFTable.cdx
[2007/06/13 12:49:52 | 000,006,144 | —- | M] () – C:\keywordImagesTable.cdx
[2007/06/13 12:56:56 | 000,000,378 | —- | M] () – C:\managedFolderTable.dbf
[2007/06/13 12:49:52 | 000,000,360 | —- | M] () – C:\ROFImagesTable.dbf
[2007/06/13 12:49:52 | 000,006,144 | —- | M] () – C:\ROFImagesTable.cdx
[2004/08/03 23:00:00 | 000,260,272 | —- | M] () – C:\cmldr
[2007/10/09 23:55:48 | 000,012,104 | —- | M] () – C:\ComboFix2.txt
[2007/10/10 01:40:56 | 000,103,370 | —- | M] () – C:\ComboFix-quarantined-files.txt

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2009/05/29 20:58:02 | 000,380,928 | —- | M] () – C:\WINDOWS\system32\config\system.sav
[2009/05/29 20:58:02 | 000,630,784 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2009/05/29 20:58:02 | 000,090,112 | —- | M] () – C:\WINDOWS\system32\config\default.sav

< %systemroot%\system32\drivers\*.sys /90 >
[2010/05/02 19:47:08 | 000,029,512 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\system32\drivers\avgmfx86.sys
[2010/05/02 19:46:14 | 000,216,200 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\system32\drivers\avgldx86.sys
[2010/05/02 19:47:16 | 000,242,896 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\system32\drivers\avgtdix.sys
[2010/02/24 08:11:08 | 000,455,680 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\drivers\mrxsmb.sys
[2010/02/11 07:02:16 | 000,226,880 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\drivers\tcpip6.sys
< End of report >

ON THE 2ND APPLICATION IT SHOWED windows\system32\DRIVERS\nv4-mini.sys AND filesystem\fastfat\fat fltmgr.sys
well i tried to run it again this time in safe mode and everytime i run safemode the screen locks up. it shows the areas of hard disk its going through and when it gets to somthin/somthin/somthing/drivers/agp440.sys it locks up. GOOD news is that the hard drive finally completed at disk defrangmenter on its own. it gave a report on that too. see below. the overall performance of the machine is OK and internet usage is completely normal. my amatuer opinion about my problem is that its maybe a partition issue? i dont know. heres the defrag log and i have AVG,combofix,malware bytes, hjt, and atf cleaner on the system so i can run any of those if you see fit. thanks again gus Volume DSK1_VOL1 (C:) Volume size = 128 GB Cluster size = 32 KB Used space = 34.31 GB Free space = 93.66 GB Percent free space = 73 % Volume fragmentation Total fragmentation = 14 % File fragmentation = 28 % Free space fragmentation = 0 % File fragmentation Total files = 78,038 Average file size = 425 KB Total fragmented files = 629 Total excess fragments = 3,264 Average fragments per file = 1.04 Pagefile fragmentation Pagefile size = 768 MB Total fragments = 5 Folder fragmentation Total folders = 8,687 Fragmented folders = 19 Excess folder fragments = 42 ——————————————————————————– Fragments File Size Files that cannot be defragmented 221 30 MB \WINDOWS\SYSTEM32\MRT.EXE 22 102 MB \Program Files\Adobe\Reader 9.0\Setup Files\{AC76BA86-7AD7-1033-7B44-A91000000001}\Data1.cab 108 249 MB \Program Files\Maxis\The Sims\ExpansionShared\Sound\Sound.far 31 394 MB \Program Files\Maxis\The Sims\ExpansionPack7\Sound\Sound.far 105 1.07 GB \Documents and Settings\HOME\Local Settings\Application Data\Microsoft\CD Burning\OCX.ZIP 24 16 MB \Documents and Settings\All Users.WINDOWS\Documents\IE8-WindowsXP-x86-ENU.exe 82 184 MB \Documents and Settings\augustus able\Local Settings\Application Data\Identities\{5CED0C7C-A0B9-4D34-B10E-BA59B365D5DA}\Microsoft\Outlook Express\Sent Items.dbx 19 18 MB \System Volume Information\_restore{7414B7E4-AE32-4466-A99C-B72EBC18FE1B}\RP167\SNAPSHOT\Repository\FS\OBJECTS.DATA 28 12 MB \System Volume Information\_restore{7414B7E4-AE32-4466-A99C-B72EBC18FE1B}\RP182\SNAPSHOT\_REGISTRY_MACHINE_SOFTWARE 46 12 MB \System Volume Information\_restore{7414B7E4-AE32-4466-A99C-B72EBC18FE1B}\RP187\SNAPSHOT\_REGISTRY_MACHINE_SOFTWARE 35 18 MB \System Volume Information\_restore{7414B7E4-AE32-4466-A99C-B72EBC18FE1B}\RP188\SNAPSHOT\Repository\FS\OBJECTS.DATA 58 18 MB \System Volume Information\_restore{7414B7E4-AE32-4466-A99C-B72EBC18FE1B}\RP189\SNAPSHOT\Repository\FS\OBJECTS.DATA 85 12 MB \System Volume Information\_restore{7414B7E4-AE32-4466-A99C-B72EBC18FE1B}\RP207\SNAPSHOT\_REGISTRY_MACHINE_SOFTWARE 24 18 MB \System Volume Information\_restore{7414B7E4-AE32-4466-A99C-B72EBC18FE1B}\RP212\SNAPSHOT\Repository\FS\OBJECTS.DATA 26 18 MB \System Volume Information\_restore{7414B7E4-AE32-4466-A99C-B72EBC18FE1B}\RP217\SNAPSHOT\Repository\FS\OBJECTS.DATA 299 18 MB \System Volume Information\_restore{7414B7E4-AE32-4466-A99C-B72EBC18FE1B}\RP219\SNAPSHOT\Repository\FS\OBJECTS.DATA 127 12 MB \System Volume Information\_restore{7414B7E4-AE32-4466-A99C-B72EBC18FE1B}\RP221\SNAPSHOT\_REGISTRY_MACHINE_SOFTWARE 80 5 MB \System Volume Information\_restore{7414B7E4-AE32-4466-A99C-B72EBC18FE1B}\RP221\SNAPSHOT\_REGISTRY_MACHINE_SYSTEM 67 12 MB \System Volume Information\_restore{7414B7E4-AE32-4466-A99C-B72EBC18FE1B}\RP225\SNAPSHOT\_REGISTRY_MACHINE_SOFTWARE 244 18 MB \System Volume Information\_restore{7414B7E4-AE32-4466-A99C-B72EBC18FE1B}\RP242\SNAPSHOT\Repository\FS\OBJECTS.DATA 22 12 MB \System Volume Information\_restore{7414B7E4-AE32-4466-A99C-B72EBC18FE1B}\RP244\SNAPSHOT\_REGISTRY_MACHINE_SOFTWARE 18 18 MB \System Volume Information\_restore{7414B7E4-AE32-4466-A99C-B72EBC18FE1B}\RP260\SNAPSHOT\Repository\FS\OBJECTS.DATA 18 18 MB \System Volume Information\_restore{7414B7E4-AE32-4466-A99C-B72EBC18FE1B}\RP261\SNAPSHOT\Repository\FS\OBJECTS.DATA 24 18 MB \System Volume Information\_restore{7414B7E4-AE32-4466-A99C-B72EBC18FE1B}\RP263\SNAPSHOT\Repository\FS\OBJECTS.DATA 22 6 MB \System Volume Information\_restore{7414B7E4-AE32-4466-A99C-B72EBC18FE1B}\RP264\A0019290.DLL 82 28 MB \System Volume Information\_restore{7414B7E4-AE32-4466-A99C-B72EBC18FE1B}\RP264\A0019335.EXE 113 12 MB \System Volume Information\_restore{7414B7E4-AE32-4466-A99C-B72EBC18FE1B}\RP264\SNAPSHOT\_REGISTRY_MACHINE_SOFTWARE 34 5 MB \System Volume Information\_restore{7414B7E4-AE32-4466-A99C-B72EBC18FE1B}\RP264\SNAPSHOT\_REGISTRY_MACHINE_SYSTEM 67 12 MB \System Volume Information\_restore{7414B7E4-AE32-4466-A99C-B72EBC18FE1B}\RP269\SNAPSHOT\_REGISTRY_MACHINE_SOFTWARE 52 768 MB \FOUND.057\FILE0000.CHK
Hello,

OTL Fix

We need to run an OTL Fix
  • Please reopen [external image: Posted Image] on your desktop.
  • Copy and Paste the following code into the [external image: Posted Image] textbox. Do not include the word "Code"

    :Services
    :OTL
    PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
    O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll File not found
    O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
    O4 - HKCU..\Run: [MSMSGS] C:\Program Files\Messenger\msmsgs.exe File not found
    O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe File not found
    O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe File not found
    O16 - DPF: {33564D57-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/D/0…D0C/wmv9dmo.cab (Reg Error: Key error.)
    O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} http://offers.e-centives.com/cif/download/bin/actxcab.cab (CBSTIEPrint Class)
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
    [2010/05/02 20:10:42 | 000,000,000 | —D | C] – C:\WINDOWS\System32\appmgmt
    [2010/05/02 19:35:20 | 000,000,000 | —D | C] – C:\found files whatever
    [4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
    [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
    :Reg
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
    "C:\Program Files\AVG\AVG8\avgemc.exe" =-
    "C:\Program Files\AVG\AVG8\avgupd.exe" =-
    "C:\Program Files\AVG\AVG8\avgnsx.exe" =-
    "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" =-
    :Commands
    [purity]
    [emptytemp]
    [EMPTYFLASH]
    [start explorer]
    [Reboot]
  • Push [external image: Posted Image]
  • OTL may ask to reboot the machine. Please do so if asked.
  • Click [external image: Posted Image].
  • A report will open. Copy and Paste that report in your next reply.
  • If the machine reboots, the log will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.


NEXT:



Malwarebytes' Anti-Malware

I see that you have Malwarebytes' Anti-Malware installed on your computer could you please do a scan using these settings:

  • Open Malwarebytes' Anti-Malware
  • Select the Update tab
  • Click Check for Updates
  • After the update have been completed, Select the Scanner tab.
  • Select Perform quick scan, then click on Scan
  • Leave the default options as it is and click on Start Scan
  • When done, you will be prompted. Click OK, then click on Show Results
  • Checked (ticked) all items and click on Remove Selected
  • After it has removed the items, Notepad will open. Please post this log in your next reply. You can also find the log in the Logs tab. The bottom most log is the latest
Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT:



ESET Online Scanner
I'd like us to scan your machine with ESET Online Scan

Note: It is recommended to disable on-board anti-virus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your anti-virus along with your anti-spyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the [external image: Posted Image] button.
  • Push [external image: Posted Image]


NEXT:



OTL Custom Scan
  • Double click on OTL icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Extra Registry select Use Safe List
  • Under Custom Scan paste this in


    netsvcs
    %SYSTEMDRIVE%\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\drivers\*.sys /90

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.


NEXT:


Please make sure you include the following items in your next post:

1. Any comments or questions you may have that you'd like for me to answer in my next post to you.
2. The log that was produced after running the OTL fix.
3. The log that was produced after running the updated MalwareBytes' Anti-Malware scan.
4. The log that was produced after running the ESET Online Virus Scanner.
5. The logs that were produced after running the OTL scan.
6. An update on how your computer is currently running.

It would be helpful if you could answer each question in the order asked, as well as numbering your answers.
ive done the new otl scan and the updated malware bytes and the MWB found somthing. i still need to do the other things tomorrow so ill see you then. take care thanks again gus
IVE DONE THE ESET AND IT FOUND SOMTHING. I NEED TO DO THE NEW OTL NEXT BUT I DONT HAVE TIME THIS MORNING. ILL HAVE THE COMPLETE PACKAGE ASAP. THANKS GUS
ok here we go. i think this is everything you are looking for. :popcorn:

All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
No active process named explorer.exe was found!
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DBC80044-A445-435b-BC74-9C25C1C588A9}\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\MSMSGS deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{FB5F1910-F110-11d2-BB9E-00C04F795683}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FB5F1910-F110-11d2-BB9E-00C04F795683}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{FB5F1910-F110-11d2-BB9E-00C04F795683}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FB5F1910-F110-11d2-BB9E-00C04F795683}\ not found.
Starting removal of ActiveX control {33564D57-9980-0010-8000-00AA00389B71}
C:\WINDOWS\Downloaded Program Files\wmv9dmo.inf moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{33564D57-9980-0010-8000-00AA00389B71}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{33564D57-9980-0010-8000-00AA00389B71}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{33564D57-9980-0010-8000-00AA00389B71}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{33564D57-9980-0010-8000-00AA00389B71}\ not found.
Starting removal of ActiveX control {A7EA8AD2-287F-11D3-B120-006008C39542}
C:\WINDOWS\Downloaded Program Files\default.inf moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{A7EA8AD2-287F-11D3-B120-006008C39542}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A7EA8AD2-287F-11D3-B120-006008C39542}\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{A7EA8AD2-287F-11D3-B120-006008C39542}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{A7EA8AD2-287F-11D3-B120-006008C39542}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A7EA8AD2-287F-11D3-B120-006008C39542}\ not found.
Starting removal of ActiveX control {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
C:\WINDOWS\Downloaded Program Files\gp.inf not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
C:\WINDOWS\System32\appmgmt\MACHINE folder moved successfully.
C:\WINDOWS\System32\appmgmt\S-1-5-21-515967899-1229272821-682003330-1003 folder moved successfully.
C:\WINDOWS\System32\appmgmt folder moved successfully.
Folder C:\found files whatever\ not found.
C:\WINDOWS\SET3.tmp deleted successfully.
C:\WINDOWS\SET7.tmp deleted successfully.
C:\WINDOWS\002383_.tmp deleted successfully.
C:\WINDOWS\005489_.tmp deleted successfully.
C:\WINDOWS\System32\CONFIG.TMP deleted successfully.
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\AVG\AVG8\avgemc.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\AVG\AVG8\avgupd.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\AVG\AVG8\avgnsx.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe deleted successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: All Users

User: gg
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 15622 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: home
->Temp folder emptied: 508490570 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Java cache emptied: 14885870 bytes
->Flash cache emptied: 315961 bytes

User: Default User.WINDOWS
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Flash cache emptied: 0 bytes

User: All Users.WINDOWS

User: NetworkService.NT AUTHORITY
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: LocalService.NT AUTHORITY
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes

User: augustus able
->Temp folder emptied: 849112523 bytes
->Temporary Internet Files folder emptied: 45812467 bytes
->Java cache emptied: 66182247 bytes
->Flash cache emptied: 79088 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 483 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33722 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 1,416.00 mb


[EMPTYFLASH]

User: Default User

User: All Users

User: gg
->Flash cache emptied: 0 bytes

User: NetworkService

User: LocalService

User: Administrator

User: home
->Flash cache emptied: 0 bytes

User: Default User.WINDOWS
->Flash cache emptied: 0 bytes

User: All Users.WINDOWS

User: NetworkService.NT AUTHORITY

User: LocalService.NT AUTHORITY

User: augustus able
->Flash cache emptied: 0 bytes

Total Flash Files Cleaned = 0.00 mb


OTL by OldTimer - Version 3.2.4.1 log created on 05052010_214808

Files\Folders moved on Reboot…

Registry entries deleted on Reboot…


Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4052

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

5/5/2010 10:22:17 PM
mbam-log-2010-05-05 (22-22-17).txt

Scan type: Quick scan
Objects scanned: 153593
Time elapsed: 17 minute(s), 52 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Program Files\Common\_helper.sig (Malware.Trace) -> Quarantined and deleted successfully.

eset scan=======

C:\Adobe\Acrobat 7.0\Setup Files\RdrBig\ENU\Program Files\Terminal Reality\4x4 Evo2\4x42.exe probably unknown NewHeur_PE virus




OTL logfile created on: 5/7/2010 6:55:23 PM - Run 2
OTL by OldTimer - Version 3.2.4.1 Folder = C:\Documents and Settings\augustus able\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

512.00 Mb Total Physical Memory | 240.00 Mb Available Physical Memory | 47.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 72.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 127.97 Gb Total Space | 95.01 Gb Free Space | 74.24% Space Free | Partition Type: FAT32
D: Drive not present or media not loaded
Drive E: | 654.81 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: HOME-3XQK3JVJDE
Current User Name: augustus able
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\augustus able\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\augustus able\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (avg9wd) – C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg9emc) – C:\Program Files\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)


========== Driver Services (SafeList) ==========

DRV - (AvgTdiX) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (gameenum) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (wdm_opl3sax) YAMAHA OPL3-SAx Audio Driver (WDM) – C:\WINDOWS\system32\drivers\opl3sax.sys (Yamaha Corp.)
DRV - (EL90X) – C:\WINDOWS\system32\drivers\el90xnd5.sys (3Com Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



O1 HOSTS File: ([2001/08/23 12:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O12 - Plugin for: .do - C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll (Adobe Systems Inc.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1243653217515 (WUWebControl Class)
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab (HP Download Manager)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20270.www2.hp.com/ediags/gmn2/inst…tDetection2.cab (GMNRev Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} http://tools.ebayimg.com/eps/wl/activex/eB…l_v1-0-29-0.cab (EPUImageControl Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop WallPaper: C:\Documents and Settings\augustus able\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\augustus able\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/03/26 18:19:08 | 000,000,194 | —- | M] () - C:\AUTOEXEC.BAT – [ FAT32 ]
O32 - AutoRun File - [2005/07/29 20:24:42 | 000,000,044 | R— | M] () - E:\autorun.inf – [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2009/05/29 20:53:56 | 000,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)

========== Files/Folders - Created Within 30 Days ==========

[2010/05/06 18:51:51 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2010/05/05 21:48:08 | 000,000,000 | —D | C] – C:\_OTL
[2010/05/04 21:49:29 | 000,000,000 | -HSD | C] – C:\FOUND.017
[2010/05/04 21:49:29 | 000,000,000 | -HSD | C] – C:\FOUND.016
[2010/05/04 21:49:29 | 000,000,000 | -HSD | C] – C:\FOUND.015
[2010/05/04 21:49:29 | 000,000,000 | -HSD | C] – C:\FOUND.014
[2010/05/04 21:49:29 | 000,000,000 | -HSD | C] – C:\FOUND.013
[2010/05/04 21:49:29 | 000,000,000 | -HSD | C] – C:\FOUND.012
[2010/05/04 21:49:29 | 000,000,000 | -HSD | C] – C:\FOUND.011
[2010/05/04 21:49:29 | 000,000,000 | -HSD | C] – C:\FOUND.010
[2010/05/04 21:49:29 | 000,000,000 | -HSD | C] – C:\FOUND.004
[2010/05/04 21:49:29 | 000,000,000 | -HSD | C] – C:\FOUND.003
[2010/05/04 21:49:29 | 000,000,000 | -HSD | C] – C:\FOUND.002
[2010/05/04 21:49:26 | 000,000,000 | -HSD | C] – C:\FOUND.061
[2010/05/04 21:49:26 | 000,000,000 | -HSD | C] – C:\FOUND.060
[2010/05/04 21:49:26 | 000,000,000 | -HSD | C] – C:\FOUND.001
[2010/05/04 21:49:26 | 000,000,000 | -HSD | C] – C:\FOUND.000
[2010/05/04 21:49:26 | 000,000,000 | -H-D | C] – C:\Config.Msi
[2010/05/04 21:49:25 | 000,000,000 | -HSD | C] – C:\FOUND.059
[2010/05/04 21:49:25 | 000,000,000 | -HSD | C] – C:\FOUND.058
[2010/05/04 21:48:16 | 000,000,000 | -HSD | C] – C:\FOUND.057
[2010/05/04 21:47:00 | 000,000,000 | -HSD | C] – C:\FOUND.056
[2010/05/04 21:47:00 | 000,000,000 | -HSD | C] – C:\FOUND.055
[2010/05/04 21:47:00 | 000,000,000 | -HSD | C] – C:\FOUND.054
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.053
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.052
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.051
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.050
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.049
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.048
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.047
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.046
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.045
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.044
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.043
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.042
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.041
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.040
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.039
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.038
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.037
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.036
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.035
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.034
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.033
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.032
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.031
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.030
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.029
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.028
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.027
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.026
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.025
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.024
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.023
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.022
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.021
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.020
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.019
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.018
[2010/05/04 20:17:15 | 000,570,880 | —- | C] (OldTimer Tools) – C:\Documents and Settings\augustus able\Desktop\OTL.exe
[2010/05/02 19:47:07 | 000,012,464 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2010/05/02 19:40:31 | 003,558,912 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\moviemk.exe
[2010/05/02 19:32:59 | 000,000,000 | —D | C] – C:\Documents and Settings\augustus able\Desktop\Unused Desktop Shortcuts

========== Files - Modified Within 30 Days ==========

[2010/05/07 18:37:40 | 000,000,438 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{19EC8709-8E90-4F72-A317-CA9CE6ADC554}.job
[2010/05/07 12:06:00 | 000,088,566 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2010/05/07 12:05:58 | 000,013,050 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/05/07 06:54:38 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/05/07 06:54:30 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/05/07 06:52:20 | 001,835,008 | —- | M] () – C:\Documents and Settings\augustus able\ntuser.dat
[2010/05/07 06:52:14 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\augustus able\ntuser.ini
[2010/05/05 22:38:18 | 004,286,566 | -H– | M] () – C:\Documents and Settings\augustus able\Local Settings\Application Data\IconCache.db
[2010/05/04 20:18:54 | 000,293,376 | —- | M] () – C:\Documents and Settings\augustus able\Desktop\xjcbr3vl.exe
[2010/05/04 20:17:16 | 000,570,880 | —- | M] (OldTimer Tools) – C:\Documents and Settings\augustus able\Desktop\OTL.exe
[2010/05/02 20:08:56 | 000,004,507 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/05/02 20:08:54 | 000,355,086 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/05/02 20:08:54 | 000,311,604 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/05/02 20:08:54 | 000,039,992 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/05/02 19:47:16 | 000,242,896 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2010/05/02 19:47:08 | 000,029,512 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2010/05/02 19:47:08 | 000,012,464 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2010/05/02 19:46:14 | 000,216,200 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2010/05/02 19:33:36 | 000,000,104 | —- | M] () – C:\Documents and Settings\augustus able\Desktop\Shortcut to E-mail.lnk
[2010/05/02 19:33:30 | 000,000,104 | —- | M] () – C:\Documents and Settings\augustus able\Desktop\Internet.lnk
[2010/05/01 10:28:16 | 000,226,728 | R— | M] (Coupons, Inc.) – C:\WINDOWS\System32\cpnprt2.cid
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/04/29 15:39:26 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys

========== Files Created - No Company Name ==========

[2010/05/04 20:18:51 | 000,293,376 | —- | C] () – C:\Documents and Settings\augustus able\Desktop\xjcbr3vl.exe
[2010/05/02 19:33:35 | 000,000,104 | —- | C] () – C:\Documents and Settings\augustus able\Desktop\Shortcut to E-mail.lnk
[2010/05/02 19:33:28 | 000,000,104 | —- | C] () – C:\Documents and Settings\augustus able\Desktop\Internet.lnk
[2009/06/15 11:52:24 | 000,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2009/05/30 23:31:45 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\HPZIDS01.dll
[2006/10/22 12:22:00 | 001,662,976 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2006/10/22 12:22:00 | 001,470,464 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2006/10/22 12:22:00 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2006/10/22 12:22:00 | 000,581,632 | —- | C] () – C:\WINDOWS\System32\nvhwvid.dll
[2006/10/22 12:22:00 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2006/10/22 12:22:00 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2006/10/22 12:22:00 | 000,212,992 | —- | C] () – C:\WINDOWS\System32\nvapi.dll

========== LOP Check ==========

[2009/11/02 15:51:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Grisoft
[2009/11/02 16:05:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Avg7
[2009/11/02 16:29:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\avg9
[2009/11/22 16:56:54 | 000,000,000 | —D | M] – C:\Documents and Settings\augustus able\Application Data\E-centives
[2010/05/07 18:37:40 | 000,000,438 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{19EC8709-8E90-4F72-A317-CA9CE6ADC554}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2007/10/08 10:25:08 | 000,011,539 | —- | M] () – C:\ComboFix3.txt
[2010/05/07 06:54:26 | 805,306,368 | -HS- | M] () – C:\PAGEFILE.SYS
[2009/05/25 07:41:52 | 000,003,736 | —- | M] () – C:\VundoFix.txt
[2006/03/26 18:14:04 | 000,001,660 | RHS- | M] () – C:\MSDOS.SYS
[2009/05/29 23:52:24 | 000,000,282 | RHS- | M] () – C:\boot.ini
[2007/10/06 11:13:20 | 002,028,640 | —- | M] () – C:\sp1aexpress_usa.exe
[2006/03/26 18:19:08 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2000/06/08 17:00:00 | 000,110,080 | RHS- | M] () – C:\IO.SYS
[2006/03/26 18:19:08 | 000,000,194 | —- | M] () – C:\AUTOEXEC.BAT
[2006/03/26 18:09:20 | 000,241,696 | RH– | M] () – C:\CLASSES.1ST
[2006/03/26 18:19:10 | 000,000,000 | —- | M] () – C:\CONFIG.BAK
[2007/06/07 23:27:06 | 000,000,146 | —- | M] () – C:\YServer.txt
[2006/03/26 18:29:10 | 000,000,512 | -HS- | M] () – C:\BOOTSECT.DOS
[2009/05/31 16:27:06 | 000,250,048 | RHS- | M] () – C:\ntldr
[2009/05/29 23:44:40 | 000,047,564 | RHS- | M] () – C:\ntdetect.com
[2007/07/15 22:10:52 | 000,000,000 | —- | M] () – C:\CB_Server_Errors.txt
[2007/06/13 12:56:56 | 000,028,074 | —- | M] () – C:\EXIFTable.dbf
[2006/03/26 17:10:32 | 021,920,944 | —- | M] (NVIDIA Corporation) – C:\84.21_forceware_winxp2k_english_whql.exe
[2006/01/29 16:41:12 | 001,579,352 | —- | M] () – C:\HiSpeed.exe
[2009/05/24 07:48:42 | 000,006,752 | —- | M] () – C:\ComboFix.txt
[2007/07/15 22:11:02 | 000,000,786 | —- | M] () – C:\administrativeInfo.dbf
[2007/07/15 22:11:02 | 000,003,089 | —- | M] () – C:\pathnameTable.dbf
[2007/07/15 22:11:02 | 000,004,608 | —- | M] () – C:\pathnameTable.cdx
[2007/07/15 22:11:02 | 000,036,891 | —- | M] () – C:\imageTable.dbf
[2007/06/13 12:55:16 | 000,001,024 | —- | M] () – C:\imageTable.fpt
[2007/06/13 12:56:56 | 000,003,072 | —- | M] () – C:\EXIFTable.cdx
[2005/02/16 11:06:00 | 000,218,112 | —- | M] (Soeperman Enterprises Ltd.) – C:\HijackThis.exe
[2007/07/15 22:11:02 | 000,020,480 | —- | M] () – C:\imageTable.cdx
[2007/07/15 22:11:02 | 000,003,762 | —- | M] () – C:\albumTable.dbf
[2007/07/15 22:11:02 | 000,004,608 | —- | M] () – C:\albumTable.cdx
[2006/03/28 10:46:54 | 000,002,076 | —- | M] () – C:\hijackthis.log
[2007/06/13 12:49:52 | 000,000,392 | —- | M] () – C:\ROFTable.dbf
[2007/07/15 22:11:02 | 000,095,298 | —- | M] () – C:\albumImagesTable.dbf
[2007/07/15 22:11:02 | 000,012,800 | —- | M] () – C:\albumImagesTable.cdx
[2007/06/13 12:49:52 | 000,000,456 | —- | M] () – C:\keywordTable.dbf
[2007/06/13 12:49:52 | 000,004,608 | —- | M] () – C:\keywordTable.cdx
[2007/06/13 12:49:52 | 000,000,360 | —- | M] () – C:\keywordImagesTable.dbf
[2007/06/13 12:49:52 | 000,003,072 | —- | M] () – C:\ROFTable.cdx
[2007/06/13 12:49:52 | 000,006,144 | —- | M] () – C:\keywordImagesTable.cdx
[2007/06/13 12:56:56 | 000,000,378 | —- | M] () – C:\managedFolderTable.dbf
[2007/06/13 12:49:52 | 000,000,360 | —- | M] () – C:\ROFImagesTable.dbf
[2007/06/13 12:49:52 | 000,006,144 | —- | M] () – C:\ROFImagesTable.cdx
[2004/08/03 23:00:00 | 000,260,272 | —- | M] () – C:\cmldr
[2007/10/09 23:55:48 | 000,012,104 | —- | M] () – C:\ComboFix2.txt
[2007/10/10 01:40:56 | 000,103,370 | —- | M] () – C:\ComboFix-quarantined-files.txt
[2010/05/05 21:56:12 | 000,000,109 | —- | M] () – C:\mbam-error.txt

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2009/05/29 20:58:02 | 000,380,928 | —- | M] () – C:\WINDOWS\system32\config\system.sav
[2009/05/29 20:58:02 | 000,630,784 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2009/05/29 20:58:02 | 000,090,112 | —- | M] () – C:\WINDOWS\system32\config\default.sav

< %systemroot%\system32\drivers\*.sys /90 >
[2010/05/02 19:47:08 | 000,029,512 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\system32\drivers\avgmfx86.sys
[2010/05/02 19:46:14 | 000,216,200 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\system32\drivers\avgldx86.sys
[2010/05/02 19:47:16 | 000,242,896 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\system32\drivers\avgtdix.sys
[2010/04/29 15:39:26 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\system32\drivers\mbam.sys
[2010/02/24 08:11:08 | 000,455,680 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\drivers\mrxsmb.sys
[2010/02/11 07:02:16 | 000,226,880 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\drivers\tcpip6.sys
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\system32\drivers\mbamswissarmy.sys

< >

< >
< End of report >




OTL Extras logfile created on: 5/7/2010 6:55:23 PM - Run 2
OTL by OldTimer - Version 3.2.4.1 Folder = C:\Documents and Settings\augustus able\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

512.00 Mb Total Physical Memory | 240.00 Mb Available Physical Memory | 47.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 72.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 127.97 Gb Total Space | 95.01 Gb Free Space | 74.24% Space Free | Partition Type: FAT32
D: Drive not present or media not loaded
Drive E: | 654.81 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: HOME-3XQK3JVJDE
Current User Name: augustus able
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\WINDOWS\System32\usmt\migwiz.exe" = C:\WINDOWS\System32\usmt\migwiz.exe:*:Disabled:Files and Settings Transfer Wizard – (Microsoft Corporation)
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe" = C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe – ()
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\AVG\AVG9\avgemc.exe" = C:\Program Files\AVG\AVG9\avgemc.exe:*:Enabled:avgemc.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgupd.exe" = C:\Program Files\AVG\AVG9\avgupd.exe:*:Enabled:avgupd.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgnsx.exe" = C:\Program Files\AVG\AVG9\avgnsx.exe:*:Enabled:avgnsx.exe – (AVG Technologies CZ, s.r.o.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3A316611-45D1-429C-AA26-B71259C44689}" = HP Photosmart, Officejet and Deskjet 7.0.A
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1
"{C8753E28-2680-49BF-BD48-DD38FD086EFE}" = AiO_Scan_CDA
"{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}" = HP Product Detection
"{F2527115-B8BF-4FDB-B5DA-5AADFB7C13E1}" = The Sims Complete Collection
"{F3760724-B29D-465B-BC53-E5D72095BCC4}" = Scan
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"AVG9Uninstall" = AVG Free 9.0
"Coupon Printer for Windows4.0" = Coupon Printer for Windows
"ESET Online Scanner" = ESET Online Scanner v3
"HijackThis" = HijackThis 2.0.2
"ie8" = Windows Internet Explorer 8
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"NVIDIA Drivers" = NVIDIA Drivers
"Windows XP Service Pack" = Windows XP Service Pack 3

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 2/17/2010 7:18:50 PM | Computer Name = HOME-3XQK3JVJDE | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: The data is invalid.

Error - 2/17/2010 7:18:51 PM | Computer Name = HOME-3XQK3JVJDE | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: The data is invalid.

Error - 2/17/2010 7:18:51 PM | Computer Name = HOME-3XQK3JVJDE | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: The data is invalid.

Error - 2/17/2010 7:18:52 PM | Computer Name = HOME-3XQK3JVJDE | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: The data is invalid.

Error - 2/17/2010 7:18:53 PM | Computer Name = HOME-3XQK3JVJDE | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: The data is invalid.

Error - 2/17/2010 7:18:53 PM | Computer Name = HOME-3XQK3JVJDE | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: The data is invalid.

Error - 2/17/2010 7:18:54 PM | Computer Name = HOME-3XQK3JVJDE | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: The data is invalid.

Error - 2/17/2010 9:38:55 PM | Computer Name = HOME-3XQK3JVJDE | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: The data is invalid.

Error - 2/17/2010 9:38:56 PM | Computer Name = HOME-3XQK3JVJDE | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: The data is invalid.

Error - 2/17/2010 9:38:56 PM | Computer Name = HOME-3XQK3JVJDE | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: The data is invalid.

[ System Events ]
Error - 5/5/2010 9:38:20 PM | Computer Name = HOME-3XQK3JVJDE | Source = DCOM | ID = 10000
Description = Unable to start a DCOM Server: {FB7199AB-79BF-11D2-8D94-0000F875C541}.
The
error: "%2" Happened while starting this command: C:\Program Files\Messenger\msmsgs.exe
-Embedding

Error - 5/5/2010 10:43:58 PM | Computer Name = HOME-3XQK3JVJDE | Source = DCOM | ID = 10000
Description = Unable to start a DCOM Server: {FB7199AB-79BF-11D2-8D94-0000F875C541}.
The
error: "%2" Happened while starting this command: C:\Program Files\Messenger\msmsgs.exe
-Embedding

Error - 5/5/2010 10:48:11 PM | Computer Name = HOME-3XQK3JVJDE | Source = Service Control Manager | ID = 7034
Description = The NVIDIA Display Driver Service service terminated unexpectedly.
It has done this 1 time(s).

Error - 5/5/2010 10:48:11 PM | Computer Name = HOME-3XQK3JVJDE | Source = Service Control Manager | ID = 7034
Description = The Pml Driver HPZ12 service terminated unexpectedly. It has done
this 1 time(s).

Error - 5/5/2010 10:48:11 PM | Computer Name = HOME-3XQK3JVJDE | Source = Service Control Manager | ID = 7031
Description = The AVG Free WatchDog service terminated unexpectedly. It has done
this 1 time(s). The following corrective action will be taken in 0 milliseconds:
Restart the service.

Error - 5/5/2010 10:48:12 PM | Computer Name = HOME-3XQK3JVJDE | Source = Service Control Manager | ID = 7034
Description = The AVG Free E-mail Scanner service terminated unexpectedly. It has
done this 1 time(s).

Error - 5/5/2010 11:28:57 PM | Computer Name = HOME-3XQK3JVJDE | Source = DCOM | ID = 10000
Description = Unable to start a DCOM Server: {FB7199AB-79BF-11D2-8D94-0000F875C541}.
The
error: "%2" Happened while starting this command: C:\Program Files\Messenger\msmsgs.exe
-Embedding

Error - 5/6/2010 7:46:39 PM | Computer Name = HOME-3XQK3JVJDE | Source = DCOM | ID = 10000
Description = Unable to start a DCOM Server: {FB7199AB-79BF-11D2-8D94-0000F875C541}.
The
error: "%2" Happened while starting this command: C:\Program Files\Messenger\msmsgs.exe
-Embedding

Error - 5/6/2010 7:49:40 PM | Computer Name = HOME-3XQK3JVJDE | Source = Service Control Manager | ID = 7034
Description = The AVG Free E-mail Scanner service terminated unexpectedly. It has
done this 1 time(s).

Error - 5/7/2010 7:51:52 AM | Computer Name = HOME-3XQK3JVJDE | Source = DCOM | ID = 10000
Description = Unable to start a DCOM Server: {FB7199AB-79BF-11D2-8D94-0000F875C541}.
The
error: "%2" Happened while starting this command: C:\Program Files\Messenger\msmsgs.exe
-Embedding


< End of report >
Hello,

VirusTotal File Scan
Please go to: VirusTotal
  • [external image: Posted Image]
  • Click the Browse button and search for the following file: C:\Adobe\Acrobat 7.0\Setup Files\RdrBig\ENU\Program Files\Terminal Reality\4x4 Evo2\4x42.exe
  • Click Open
  • Then click Send File
  • Please be patient while the file is scanned.
  • Once the scan results appear, please provide them in your next reply.
If it says already scanned – click "reanalyze now"

Please post the results in your next reply
Virustotal is a service that analyzes suspicious files and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware detected by antivirus engines. More information… File 4x42.exe received on 2010.05.08 02:03:18 (UTC) Current status: finished Result: 1/41 (2.44%) Compact Print results Antivirus Version Last Update Result a-squared 4.5.0.50 2010.05.07 - AhnLab-V3 2010.05.08.00 2010.05.07 - AntiVir 8.2.1.236 2010.05.07 - Antiy-AVL 2.0.3.7 2010.05.07 - Authentium 5.2.0.5 2010.05.07 - Avast 4.8.1351.0 2010.05.07 - Avast5 5.0.332.0 2010.05.07 - AVG 9.0.0.787 2010.05.07 - BitDefender 7.2 2010.05.08 - CAT-QuickHeal 10.00 2010.05.07 - ClamAV 0.96.0.3-git 2010.05.08 - Comodo 4789 2010.05.08 - DrWeb 5.0.2.03300 2010.05.08 - eSafe 7.0.17.0 2010.05.06 - eTrust-Vet 35.2.7474 2010.05.07 - F-Prot 4.5.1.85 2010.05.07 - F-Secure 9.0.15370.0 2010.05.07 - Fortinet 4.1.133.0 2010.05.07 - GData 21 2010.05.08 - Ikarus T3.1.1.84.0 2010.05.07 - Jiangmin 13.0.900 2010.05.07 - Kaspersky 7.0.0.125 2010.05.08 - McAfee 5.400.0.1158 2010.05.08 - McAfee-GW-Edition 2010.1 2010.05.07 - Microsoft 1.5703 2010.05.08 - NOD32 5096 2010.05.07 probably unknown NewHeur_PE Norman 6.04.12 2010.05.07 - nProtect 2010-05-07.01 2010.05.07 - Panda 10.0.2.7 2010.05.07 - PCTools 7.0.3.5 2010.05.07 - Prevx 3.0 2010.05.08 - Rising 22.46.04.04 2010.05.07 - Sophos 4.53.0 2010.05.08 - Sunbelt 6276 2010.05.08 - Symantec 20091.2.0.41 2010.05.08 - TheHacker 6.5.2.0.277 2010.05.07 - TrendMicro 9.120.0.1004 2010.05.07 - TrendMicro-HouseCall 9.120.0.1004 2010.05.08 - VBA32 3.12.12.4 2010.05.06 - ViRobot 2010.5.7.2306 2010.05.07 - VirusBuster 5.0.27.0 2010.05.07 - Additional information File size: 2776064 bytes MD5 : d476380ab257486896ba1a6593c70e87 SHA1 : 3c95adea582a972cf9279108f012d8730dc325cc SHA256: ab8286e6bce8a1bf3769acddfeb0a79df2e5d43c72f462a89aa90f477951ec75 PEInfo: PE Structure information ( base data ) entrypointaddress.: 0x21673C timedatestamp…..: 0x3BB0A933 (Tue Sep 25 17:56:35 2001) machinetype…….: 0x14C (Intel I386) ( 6 sections ) name viradd virsiz rawdsiz ntrpy md5 AUTO 0x1000 0x0 0x22A600 6.54 3e52d124ae3b0d11a33441e0baccf6ec .idata 0x22C000 0x0 0x1600 5.24 13866451bd9e4a1906178160c8c109ba DGROUP 0x22E000 0x0 0x53A00 5.31 84e7664996dfc3ba03550bedb34b85fa .bss 0x282000 0x0 0x6EAC00 6.67 d476380ab257486896ba1a6593c70e87 .reloc 0x96D000 0x0 0x22A00 6.83 506671d7c46484624ad8e1dfa4b83d59 .rsrc 0x990000 0x0 0x3800 3.22 cbf61f804b77a365a3fc2039af99852c ( 10 imports ) > advapi32.dll: GetUserNameA, RegCloseKey, RegCreateKeyExA, RegOpenKeyExA, RegQueryValueExA, RegSetValueExA > binkw32.dll: _BinkClose@4, _BinkCopyToBuffer@28, _BinkDoFrame@4, _BinkNextFrame@4, _BinkOpen@8, _BinkOpenDirectSound@4, _BinkSetSoundSystem@8, _BinkWait@4 > ddraw.dll: DirectDrawCreate > dinput.dll: DirectInputCreateA > dsound.dll: -, - > gdi32.dll: CreateBrushIndirect, CreateCompatibleDC, CreateDIBSection, CreateFontA, DeleteDC, DeleteObject, GetStockObject, GetTextExtentPoint32A, Rectangle, SelectObject, SetBkColor, SetBkMode, SetTextColor, TextOutA > kernel32.dll: CloseHandle, CreateDirectoryA, CreateEventA, CreateFileA, CreateMutexA, CreateThread, DeleteCriticalSection, DeleteFileA, DosDateTimeToFileTime, EnterCriticalSection, ExitProcess, ExitThread, FileTimeToDosDateTime, FileTimeToLocalFileTime, FindClose, FindFirstFileA, FindNextFileA, FlushFileBuffers, FreeEnvironmentStringsA, FreeLibrary, GetACP, GetCPInfo, GetCommandLineA, GetCommandLineW, GetComputerNameA, GetConsoleMode, GetCurrentDirectoryA, GetCurrentProcess, GetCurrentProcessId, GetCurrentThreadId, GetCurrentThread, GetEnvironmentStrings, GetFileAttributesA, GetFileSize, GetFileTime, GetFileType, GetFullPathNameA, GetLastError, GetLocalTime, GetModuleFileNameA, GetModuleFileNameW, GetModuleHandleA, GetOEMCP, GetProcAddress, GetStdHandle, GetTickCount, GetTimeZoneInformation, GetVersion, GetVolumeInformationA, GlobalAlloc, GlobalFree, GlobalLock, GlobalMemoryStatus, GlobalUnlock, InitializeCriticalSection, IsDBCSLeadByte, LeaveCriticalSection, LoadLibraryA, LocalFileTimeToFileTime, MoveFileA, MultiByteToWideChar, OutputDebugStringA, QueryPerformanceCounter, QueryPerformanceFrequency, ReadConsoleInputA, ReadFile, ReleaseMutex, SetConsoleCtrlHandler, SetConsoleMode, SetCurrentDirectoryA, SetEndOfFile, SetEnvironmentVariableA, SetEnvironmentVariableW, SetEvent, SetFileAttributesA, SetFilePointer, SetFileTime, SetLastError, SetStdHandle, SetThreadPriority, SetUnhandledExceptionFilter, Sleep, SystemTimeToFileTime, TlsAlloc, TlsFree, TlsGetValue, TlsSetValue, UnhandledExceptionFilter, VirtualAlloc, VirtualFree, VirtualQuery, WaitForSingleObject, WideCharToMultiByte, WriteConsoleA, WriteFile > user32.dll: BringWindowToTop, ChangeDisplaySettingsA, CharUpperBuffA, CloseClipboard, CreateWindowExA, DefWindowProcA, DestroyWindow, DispatchMessageA, FindWindowA, GetClipboardData, GetKeyNameTextA, GetKeyState, GetLastActivePopup, IsIconic, LoadCursorA, LoadIconA, MessageBoxA, OpenClipboard, PeekMessageA, PostQuitMessage, RegisterClassA, SetClipboardData, SetCursorPos, SetCursor, SetFocus, SetForegroundWindow, ShowWindow, TranslateMessage, UpdateWindow > winmm.dll: mciGetErrorStringA, mciSendCommandA, mixerClose, mixerGetLineControlsA, mixerGetLineInfoA, mixerOpen, mixerSetControlDetails, timeBeginPeriod, timeEndPeriod, timeGetTime, waveInAddBuffer, waveInClose, waveInGetDevCapsA, waveInOpen, waveInPrepareHeader, waveInReset, waveInStart, waveInUnprepareHeader, waveOutClose, waveOutGetDevCapsA, waveOutOpen, waveOutPrepareHeader, waveOutReset, waveOutUnprepareHeader, waveOutWrite > wsock32.dll: -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, - ( 0 exports ) TrID : File type identification Win32 Executable Generic (38.3%) Win32 Dynamic Link Library (generic) (34.1%) Win16/32 Executable Delphi generic (9.3%) Generic Win/DOS Executable (9.0%) DOS Executable Generic (9.0%) ssdeep: 49152:jCuqL3z5vFCSdIAg13AUpr4yRnNUXc0XVxvRxMlDBs:jCuqLj5rds13AUpr4yRnWXcAVxvRelD S sigcheck: publisher….: Terminal Reality Inc. copyright….: © 1995-2001 Terminal Reality Inc. product……: 4x4 EVO 2 description..: 4x4 EVO 2™ original name: 4x4.exe internal name: Metal Crush 4 file version.: 1.00.139 comments…..: n/a signers……: - signing date.: - verified…..: Unsigned PEiD : - packers (Kaspersky): PE_Patch RDS : NSRL Reference Data Set ( Global Star Software ) Maximum Racing: 4x42.exe

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI