This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Really Slow PC

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello there, fulton1888

:welcome:

I'm Conspire, I'll be glad to help you with your computer problems.

Please observe these rules while we work:
  • Read the entire procedure
  • It is important to perform ALL actions in sequence.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with me till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
  • Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process.
Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise.
This may cause a delay, but I will do my best to keep it as short as possible.

Please bear with me, I will post back to you as soon as I can.

IMPORTANT NOTE : Please do not delete anything unless instructed to.

**In any case where you happen to be busy or unable to give us a reply, we would be more than grateful if you keep us informed in advance and we will be more than happy to wait. :)
Hi,

Do not register nor download any other things except the ones I told you to, as this would interfere the fixing process. Meanwhile, please do the following :-

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in
    netsvcs
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %PROGRAMFILES%\Internet Explorer\*.dat
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
===================================================

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scanโ€ฆclick on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following โ€ฆ
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<โ€” ROOKIT" entries


===================================================


On your next reply please post :
OTL log
GMER log

Good Day!
OTL logfile created on: 8/23/2010 11:58:04 PM - Run 3
OTL by OldTimer - Version 3.2.10.0 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 54.00% Memory free
3.00 Gb Paging File | 2.00 Gb Available in Paging File | 67.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 112.38 Gb Total Space | 72.20 Gb Free Space | 64.24% Space Free | Partition Type: NTFS
Drive D: | 36.66 Gb Total Space | 32.79 Gb Free Space | 89.45% Space Free | Partition Type: FAT32
Drive E: | 7.45 Gb Total Space | 5.71 Gb Free Space | 76.71% Space Free | Partition Type: FAT32
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: JOHNCOLLINS
Current User Name: Owner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\STOPzilla!\STOPzilla.exe (iS3, Inc.)
PRC - C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe (iS3, Inc.)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Program Files\MSN Toolbar\Platform\4.0.0379.0\mswinext.exe (Microsoft Corp.)
PRC - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation)
PRC - C:\Program Files\LTCM Client\ltcmScheduler.exe (Leader Technologies Inc.)
PRC - C:\Program Files\Epson Software\FAX Utility\FUFAXSTM.exe (SEIKO EPSON CORPORATION)
PRC - C:\Program Files\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\NewSoft\Presto! PageManager 8 for EP\PMSpeed.exe (NewSoft Technology Corporation)
PRC - C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtProc.exe (NewSoft Technology Corporation)
PRC - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe (Lavasoft)
PRC - C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtMon.exe (NewSoft Technology Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\EPSON\EBAPI\eEBSvc.exe (SEIKO EPSON CORPORATION)
PRC - C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe (Hewlett-Packard Company)
PRC - C:\WINDOWS\system32\hphmon05.exe (Hewlett-Packard)
PRC - C:\WINDOWS\system32\Brmfrmps.exe (Brother Industries, Ltd.)
PRC - C:\WINDOWS\system32\BRSVC01A.EXE (brother Industries Ltd)
PRC - C:\WINDOWS\system32\BRSS01A.EXE (brother Industries Ltd)
PRC - C:\WINDOWS\system32\BrmfRsmg.exe (Brother Industries, Ltd.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (getPlusHelper) getPlusยฎ โ€“ C:\Program Files\NOS\bin\getPlus_Helper.dll File not found
SRV - (AppMgmt) โ€“ C:\WINDOWS\System32\appmgmts.dll File not found
SRV - (ACDaemon) โ€“ C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe File not found
SRV - (szserver) โ€“ C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe (iS3, Inc.)
SRV - (SeaPort) โ€“ C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (wlidsvc) โ€“ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation)
SRV - (AVP) โ€“ C:\Program Files\SureWest Communications\SureWest Internet Security 2009\avp.exe (SureWest Communications)
SRV - (aawservice) โ€“ C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe (Lavasoft)
SRV - (WPEServ) โ€“ C:\Program Files\Common Files\WPE\wpeserv.exe (soft Xpansion)
SRV - (EpsonBidirectionalService) โ€“ C:\Program Files\Common Files\EPSON\EBAPI\eEBSvc.exe (SEIKO EPSON CORPORATION)
SRV - (brmfrmps) โ€“ C:\WINDOWS\System32\Brmfrmps.exe (Brother Industries, Ltd.)
SRV - (Brother XP spl Service) โ€“ C:\WINDOWS\system32\BRSVC01A.EXE (brother Industries Ltd)


========== Driver Services (SafeList) ==========

DRV - (Sunkfiltp) โ€“ C:\WINDOWS\System32\Drivers\sunkfiltp.sys File not found
DRV - (NETGEAR_WG311T_SERVICE) โ€“ C:\WINDOWS\System32\DRIVERS\wg311tn5.sys File not found
DRV - (klim5) โ€“ C:\WINDOWS\System32\DRIVERS\klim5.sys File not found
DRV - (szkgfs) โ€“ C:\WINDOWS\system32\drivers\szkgfs.sys (iS3, Inc.)
DRV - (szkg5) โ€“ C:\WINDOWS\system32\DRIVERS\szkg.sys (iS3 Inc.)
DRV - (is3srv) โ€“ C:\WINDOWS\system32\drivers\is3srv.sys (iS3 Inc.)
DRV - (KLIF) โ€“ C:\WINDOWS\system32\drivers\klif.sys (Kaspersky Lab)
DRV - (kl1) โ€“ C:\WINDOWS\system32\drivers\kl1.sys (Kaspersky Lab)
DRV - (gameenum) โ€“ C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (mf) โ€“ C:\WINDOWS\system32\drivers\mf.sys (Microsoft Corporation)
DRV - (KLFLTDEV) โ€“ C:\WINDOWS\system32\drivers\klfltdev.sys (Kaspersky Lab)
DRV - (klbg) โ€“ C:\WINDOWS\system32\drivers\klbg.sys (Kaspersky Lab)
DRV - (MxlW2k) โ€“ C:\WINDOWS\System32\drivers\MxlW2k.sys (MusicMatch, Inc.)
DRV - (Ps2) โ€“ C:\WINDOWS\system32\drivers\PS2.sys (Hewlett-Packard Company)
DRV - (AFS2K) โ€“ C:\WINDOWS\System32\drivers\AFS2K.SYS (Oak Technology Inc.)
DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) โ€“ C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (S3Psddr) โ€“ C:\WINDOWS\system32\drivers\s3gnbm.sys (S3 Graphics, Inc.)
DRV - (nv) โ€“ C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (AgereSoftModem) โ€“ C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (ALCXSENS) โ€“ C:\WINDOWS\system32\drivers\ALCXSENS.SYS (Sensaura Ltd)
DRV - (SiS315) โ€“ C:\WINDOWS\system32\drivers\sisgrp.sys (Silicon Integrated Systems Corporation)
DRV - (SiSkp) โ€“ C:\WINDOWS\system32\drivers\srvkp.sys (Silicon Integrated Systems Corporation)
DRV - (cdrbsvsd) โ€“ C:\WINDOWS\System32\drivers\cdrbsvsd.sys (B.H.A Corporation)
DRV - (fasttx2k) โ€“ C:\WINDOWS\System32\DRIVERS\fasttx2k.sys (Promise Technology, Inc.)
DRV - (SunkFilt) โ€“ C:\WINDOWS\system32\drivers\Sunkfilt.sys (Alcor Micro Corp.)
DRV - (Pfc) โ€“ C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
DRV - (nv_agp) โ€“ C:\WINDOWS\System32\DRIVERS\nv_agp.sys (NVIDIA Corporation)
DRV - (SISAGP) โ€“ C:\WINDOWS\System32\DRIVERS\SISAGPX.sys (Silicon Integrated Systems Corporation)
DRV - (viaagp1) โ€“ C:\WINDOWS\System32\DRIVERS\viaagp1.sys (VIA Technologies, Inc.)
DRV - (ltmodem5) โ€“ C:\WINDOWS\system32\drivers\ltmdmnt.sys (Agere Systems)
DRV - (NVENET) โ€“ C:\WINDOWS\system32\drivers\NVENET.sys (NVIDIA Corporation)
DRV - (BrSerWDM) โ€“ C:\WINDOWS\system32\drivers\BrSerWdm.sys (Brother Industries Ltd.)
DRV - (rtl8139) โ€“ C:\WINDOWS\system32\drivers\R8139n51.sys (Realtek Semiconductor Corporation )
DRV - (AWINDIS5) โ€“ C:\WINDOWS\system32\AWINDIS5.SYS (AMBIT Microsystems Corporation.)
DRV - (ms_mpu401) โ€“ C:\WINDOWS\system32\drivers\msmpu401.sys (Microsoft Corporation)
DRV - (brparimg) โ€“ C:\WINDOWS\system32\drivers\BrParImg.sys (Brother Industries Ltd.)
DRV - (BrUsbScn) โ€“ C:\WINDOWS\system32\drivers\BrUsbScn.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) โ€“ C:\WINDOWS\system32\drivers\BrUsbMdm.sys (Brother Industries Ltd.)
DRV - (BrParWdm) โ€“ C:\WINDOWS\system32\drivers\BrParwdm.sys (Brother Industries Ltd.)
DRV - (brfilt) โ€“ C:\WINDOWS\system32\drivers\BrFilt.sys (Brother Industries Ltd.)
DRV - (BrPar) โ€“ C:\WINDOWS\System32\drivers\BrPar.sys (Brother Industries Ltd.)
DRV - (PfModNT) โ€“ C:\WINDOWS\system32\PfModNT.sys (Creative Technology Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Live Search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.live.com/results.aspx?q={seaโ€ฆferrer:source?}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = localhost

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Live Search"
FF - prefs.js..browser.search.defaulturl: "http://search.live.com/results.aspx?FORM=SOLTDF&q;="
FF - prefs.js..browser.search.selectedEngine: "Live Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://yahoo.com/"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2.1
FF - prefs.js..extensions.enabledItems: {e1170235-2845-420c-acc3-42261a29dd46}:4.0.1
FF - prefs.js..extensions.enabledItems: {2fa4ed95-0317-4c6a-a74c-5f3e3912c1f9}:2.1.072
FF - prefs.js..extensions.enabledItems: {DB2EA31C-58F5-48b7-8D60-CB0739257904}:0.19
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {e2337727-f9c9-411b-929e-287584341d1a}:3.2.1
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.1.3
FF - prefs.js..extensions.enabledItems: {F807FACD-E46A-4793-B345-D58CB177673C}:3.5.3
FF - prefs.js..extensions.enabledItems: {27182e60-b5f3-411c-b545-b44205977502}:1.0
FF - prefs.js..extensions.enabledItems: {AE93811A-5C9A-4d34-8462-F7B864FC4696}:3.64
FF - prefs.js..extensions.enabledItems: {75623d5d-4683-402a-b610-ac4bab767c86}:3.0.6
FF - prefs.js..extensions.enabledItems: {10c62ce3-3794-4c18-a881-481733c1a425}:1.6.1
FF - prefs.js..extensions.enabledItems: [removed]:3.7.8
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.3.20100310105313
FF - prefs.js..extensions.enabledItems: {d9284e50-81fc-11da-a72b-0800200c9a66}:7.3.3
FF - prefs.js..keyword.URL: "http://search.live.com/results.aspx?FORM=SOLTDF&q;="
FF - prefs.js..network.proxy.no_proxies_on: "localhost"

FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010/04/03 13:01:19 | 000,000,000 | โ€”D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{27182e60-b5f3-411c-b545-b44205977502}: C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ [2010/06/08 21:48:15 | 000,000,000 | โ€”D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.10\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/06/24 07:40:24 | 000,000,000 | โ€”D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.10\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/07/11 06:25:03 | 000,000,000 | โ€”D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\{eea12ec4-729d-4703-bc37-106ce9879ce2}: C:\Program Files\SureWest Communications\SureWest Internet Security 2009\THBExt [2009/07/28 06:47:46 | 000,000,000 | โ€”D | M]

[2008/09/23 13:49:01 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions
[2010/07/16 06:28:42 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\712ne2si.default\extensions
[2010/04/25 12:21:09 | 000,000,000 | โ€”D | M] (UrlbarExt) โ€“ C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\712ne2si.default\extensions\{10c62ce3-3794-4c18-a881-481733c1a425}
[2010/06/23 13:54:51 | 000,000,000 | โ€”D | M] (Microsoft .NET Framework Assistant) โ€“ C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\712ne2si.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/12/14 10:06:04 | 000,000,000 | โ€”D | M] (No name found) โ€“ C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\712ne2si.default\extensions\{2fa4ed95-0317-4c6a-a74c-5f3e3912c1f9}
[2010/04/25 12:20:53 | 000,000,000 | โ€”D | M] (FoxyTunes) โ€“ C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\712ne2si.default\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}
[2008/07/30 08:29:18 | 000,000,000 | โ€”D | M] (Map+) โ€“ C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\712ne2si.default\extensions\{5359A5B3-9AFD-49ee-8C39-0A8F97A2A2D6}
[2010/04/25 12:20:56 | 000,000,000 | โ€”D | M] (Yahoo! Toolbar) โ€“ C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\712ne2si.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2010/07/07 08:40:36 | 000,000,000 | โ€”D | M] (Surf Canyon - Search Engine Assistant) โ€“ C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\712ne2si.default\extensions\{75623d5d-4683-402a-b610-ac4bab767c86}
[2010/04/25 12:20:57 | 000,000,000 | โ€”D | M] (No name found) โ€“ C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\712ne2si.default\extensions\{AE93811A-5C9A-4d34-8462-F7B864FC4696}
[2010/07/16 06:18:27 | 000,000,000 | โ€”D | M] (Adblock Plus) โ€“ C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\712ne2si.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/07/07 08:40:39 | 000,000,000 | โ€”D | M] (Yoono) โ€“ C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\712ne2si.default\extensions\{d9284e50-81fc-11da-a72b-0800200c9a66}
[2010/04/25 12:21:08 | 000,000,000 | โ€”D | M] (ImageTweak) โ€“ C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\712ne2si.default\extensions\{DB2EA31C-58F5-48b7-8D60-CB0739257904}
[2010/04/25 12:21:01 | 000,000,000 | โ€”D | M] (Clipmarks) โ€“ C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\712ne2si.default\extensions\{e1170235-2845-420c-acc3-42261a29dd46}
[2010/04/25 12:21:02 | 000,000,000 | โ€”D | M] (LinkedIn Companion for Firefox) โ€“ C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\712ne2si.default\extensions\{e2337727-f9c9-411b-929e-287584341d1a}
[2010/07/07 08:40:37 | 000,000,000 | โ€”D | M] (ScribeFire) โ€“ C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\712ne2si.default\extensions\{F807FACD-E46A-4793-B345-D58CB177673C}
[2010/07/07 08:40:33 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\712ne2si.default\extensions\[removed]
[2008/10/14 21:01:41 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\712ne2si.default\extensions\[removed]
[2008/10/14 21:01:41 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\712ne2si.default\extensions\[removed]\chrome
[2008/10/14 21:01:41 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\712ne2si.default\extensions\[removed]\defaults
[2010/07/16 06:28:43 | 000,005,227 | โ€”- | M] () โ€“ C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\712ne2si.default\searchplugins\linkedin.xml
[2010/07/16 06:28:43 | 000,005,242 | โ€”- | M] () โ€“ C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\712ne2si.default\searchplugins\linkedinjobs.xml
[2009/12/14 10:06:27 | 000,001,633 | โ€”- | M] () โ€“ C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\712ne2si.default\searchplugins\live-search.xml
[2009/02/28 12:01:06 | 000,001,898 | โ€”- | M] () โ€“ C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\712ne2si.default\searchplugins\surf-canyon.xml
[2010/07/16 06:28:42 | 000,000,000 | โ€”D | M] โ€“ C:\Program Files\Mozilla Firefox\extensions
[2004/11/12 20:36:20 | 000,005,120 | โ€”- | M] (Adobe Systems Incorporated) โ€“ C:\Program Files\Mozilla Firefox\plugins\NPAdbESD.dll
[2006/05/08 21:12:30 | 000,024,576 | โ€”- | M] (My Search) โ€“ C:\Program Files\Mozilla Firefox\plugins\NPMySrch.dll

O1 HOSTS File: ([2010/08/23 07:47:40 | 000,407,402 | Rโ€” | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 14115 more linesโ€ฆ
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\SureWest Communications\SureWest Internet Security 2009\ievkbd.dll (SureWest Communications)
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (MSN Toolbar BHO) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN Toolbar\Platform\4.0.0379.0\npwinext.dll (Microsoft Corporation)
O2 - BHO: (STOPzilla Browser Helper Object) - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\Program Files\STOPzilla!\SZIEBHO.dll (iS3, Inc.)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found.
O3 - HKLM\..\Toolbar: (MSN Toolbar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\MSN Toolbar\Platform\4.0.0379.0\npwinext.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (HP View) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\hpdtlk02.dll (Hewlett-Packard Company)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (HP View) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\hpdtlk02.dll (Hewlett-Packard Company)
O3 - HKCU\..\Toolbar\WebBrowser: (HP View) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\hpdtlk02.dll (Hewlett-Packard Company)
O4 - HKLM..\Run: [AVP] C:\Program Files\SureWest Communications\SureWest Internet Security 2009\avp.exe (SureWest Communications)
O4 - HKLM..\Run: [EEventManager] C:\Program Files\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [FUFAXSTM] C:\Program Files\Epson Software\FAX Utility\FUFAXSTM.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [HPHmon05] C:\WINDOWS\system32\hphmon05.exe (Hewlett-Packard)
O4 - HKLM..\Run: [HPHUPD05] c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe (Hewlett-Packard)
O4 - HKLM..\Run: [MSN Toolbar] C:\Program Files\MSN Toolbar\Platform\4.0.0379.0\mswinext.exe (Microsoft Corp.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\Recguard.exe ()
O4 - HKLM..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl03a\BrStDvPt.exe ()
O4 - HKLM..\Run: [WrtMon.exe] C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtMon.exe (NewSoft Technology Corporation)
O4 - HKCU..\Run: [BackupNotify] c:\Program Files\HP\Digital Imaging\bin\BackupNotify.exe (Hewlett-Packard Company)
O4 - HKCU..\Run: [ltcmScheduler] C:\Program Files\LTCM Client\ltcmScheduler.exe (Leader Technologies Inc.)
O4 - HKCU..\Run: [PMSpeed] C:\Program Files\NewSoft\Presto! PageManager 8 for EP\PMSpeed.exe (NewSoft Technology Corporation)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SmartUI.lnk = C:\Program Files\Scansoft\PaperPort\SmartUI\SmartUI.exe File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: _NoDriveTypeAutoRun = 323
O8 - Extra context menu item: Add to Banner Ad Blocker - C:\Program Files\SureWest Communications\SureWest Internet Security 2009\ie_banner_deny.htm ()
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\SureWest Communications\SureWest Internet Security 2009\SCIEPlgn.dll (SureWest Communications)
O9 - Extra Button: Send to 'Perfect PDF Creator Essentials' - {722FE9B2-6895-42D9-9984-F4CB26616023} - C:\Program Files\Cosmi\Perfect PDF Creator Essentials\pdfshell.dll (soft Xpansion)
O9 - Extra 'Tools' menuitem : Send to 'Perfect PDF Creator Essentials' - {722FE9B2-6895-42D9-9984-F4CB26616023} - C:\Program Files\Cosmi\Perfect PDF Creator Essentials\pdfshell.dll (soft Xpansion)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O15 - HKCU\..Trusted Domains: firstamres.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: mercadomls.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: metrolist.net ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: rapmls.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: schwab.com ([investing] https in Trusted sites)
O15 - HKCU\..Trusted Domains: schwab.com ([www] https in Trusted sites)
O15 - HKCU\..Trusted Domains: west-sacramento.ca.us ([www.ci] https in Trusted sites)
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {060239F1-8B5B-4F2B-814C-28F92FDCE231} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwaโ€ฆdirector/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/โ€ฆlscbase6087.cab (Windows Live Safety Center Base Module)
O16 - DPF: {62BC5DB2-0044-4040-B366-D628F3CFD551} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0โ€ฆoUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} http://picture.vzw.com/activex/VerizonWireโ€ฆloadControl.cab (Verizon Wireless Media Upload)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-โ€ฆindows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashโ€ฆr/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} http://lads.myspace.com/upload/MySpaceUploader2.cab (MySpace Uploader Control)
O16 - DPF: {A8658086-E6AC-4957-BC8E-8D54A7E8A790} http://www.microsoft.com/security/controls/GDI/0/GDIChk.CAB (GDIChk Object)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-โ€ฆindows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-โ€ฆindows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} Reg Error: Value error. (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {F375116A-793C-11D2-BFE1-444553540001} http://realist2.firstamres.com/mapviewer/mapviewer.cab (First American Res MapActiveX Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O20 - Winlogon\Notify\klogon: DllName - C:\WINDOWS\system32\klogon.dll - C:\WINDOWS\system32\klogon.dll (SureWest Communications)
O24 - Desktop WallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/01/20 18:16:37 | 000,000,000 | โ€”- | M] () - C:\AUTOEXEC.BAT โ€“ [ NTFS ]
O32 - AutoRun File - [2001/07/28 06:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT โ€“ [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] โ€“ "%1" %*
O35 - HKLM\..exefile [open] โ€“ "%1" %*
O37 - HKLM\โ€ฆcom [@ = comfile] โ€“ "%1" %*
O37 - HKLM\โ€ฆexe [@ = exefile] โ€“ "%1" %*
O37 - HKCU\โ€ฆcom [@ = ComFile] โ€“ Reg Error: Key error. File not found
O37 - HKCU\โ€ฆexe [@ = exefile] โ€“ Reg Error: Key error. File not found

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (17183584330711040)

========== Files/Folders - Created Within 30 Days ==========

[2010/08/23 23:39:19 | 000,575,488 | โ€”- | C] (OldTimer Tools) โ€“ C:\Documents and Settings\Owner\Desktop\OTL.exe
[2010/08/23 07:42:44 | 000,000,000 | โ€”D | C] โ€“ C:\Program Files\STOPzilla!
[2010/08/23 07:42:44 | 000,000,000 | โ€”D | C] โ€“ C:\Program Files\Common Files\iS3
[2010/08/23 07:42:43 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2010/08/18 19:11:46 | 000,546,256 | Rโ€” | C] (iS3, Inc.) โ€“ C:\WINDOWS\System32\SZComp5.dll
[2010/08/18 19:11:46 | 000,132,560 | Rโ€” | C] (iS3, Inc.) โ€“ C:\WINDOWS\System32\IS3HTUI5.dll
[2010/08/18 19:11:46 | 000,022,992 | Rโ€” | C] (iS3, Inc.) โ€“ C:\WINDOWS\System32\SZIO5.dll
[2010/08/18 19:11:44 | 000,447,952 | Rโ€” | C] (iS3, Inc.) โ€“ C:\WINDOWS\System32\SZBase5.dll
[2010/08/18 19:11:44 | 000,398,800 | Rโ€” | C] (iS3, Inc.) โ€“ C:\WINDOWS\System32\IS3DBA5.dll
[2010/08/18 19:11:44 | 000,099,792 | Rโ€” | C] (iS3, Inc.) โ€“ C:\WINDOWS\System32\IS3Svc5.dll
[2010/08/18 19:11:44 | 000,067,024 | Rโ€” | C] (iS3, Inc.) โ€“ C:\WINDOWS\System32\IS3Hks5.dll
[2010/08/18 19:11:44 | 000,028,624 | Rโ€” | C] (iS3, Inc.) โ€“ C:\WINDOWS\System32\IS3XDat5.dll
[2010/08/18 19:11:42 | 000,738,768 | Rโ€” | C] (iS3, Inc.) โ€“ C:\WINDOWS\System32\IS3Base5.dll
[2010/08/18 19:11:42 | 000,390,608 | Rโ€” | C] (iS3, Inc.) โ€“ C:\WINDOWS\System32\IS3UI5.dll
[2010/08/18 19:11:42 | 000,230,864 | Rโ€” | C] (iS3, Inc.) โ€“ C:\WINDOWS\System32\IS3Win325.dll
[2010/08/18 19:11:42 | 000,099,792 | Rโ€” | C] (iS3, Inc.) โ€“ C:\WINDOWS\System32\IS3Inet5.dll
[2010/08/13 14:55:52 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Owner\My Documents\Education
[2010/08/13 09:56:33 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\All Users\Application Data\SUIIMAGE
[2010/08/07 17:44:51 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Owner\My Documents\Escrow Coordination System
[2010/07/26 10:14:26 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Owner\My Documents\Real Estate Files Final

========== Files - Modified Within 30 Days ==========

[2010/08/23 23:39:19 | 000,575,488 | โ€”- | M] (OldTimer Tools) โ€“ C:\Documents and Settings\Owner\Desktop\OTL.exe
[2010/08/23 23:35:15 | 000,000,286 | โ€”- | M] () โ€“ C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-4176258438-1254130368-891754562-1003.job
[2010/08/23 23:35:15 | 000,000,278 | โ€”- | M] () โ€“ C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-4176258438-1254130368-891754562-1003.job
[2010/08/23 23:34:13 | 000,001,132 | โ€”- | M] () โ€“ C:\WINDOWS\winpoint.ini
[2010/08/23 15:30:36 | 000,002,185 | โ€”- | M] () โ€“ C:\WINDOWS\BrmfBidi.ini
[2010/08/23 12:58:11 | 000,000,744 | โ€”- | M] () โ€“ C:\WINDOWS\System32\drivers\kgpcpy.cfg
[2010/08/23 12:54:03 | 000,000,006 | -Hโ€“ | M] () โ€“ C:\WINDOWS\tasks\SA.DAT
[2010/08/23 12:53:13 | 000,002,048 | โ€“S- | M] () โ€“ C:\WINDOWS\bootstat.dat
[2010/08/23 12:46:39 | 013,107,200 | โ€”- | M] () โ€“ C:\Documents and Settings\Owner\NTUSER.DAT
[2010/08/23 12:46:39 | 000,004,720 | -HS- | M] () โ€“ C:\WINDOWS\System32\drivers\fidbox2.idx
[2010/08/23 12:46:38 | 004,594,720 | -HS- | M] () โ€“ C:\WINDOWS\System32\drivers\fidbox.dat
[2010/08/23 12:46:38 | 001,064,992 | -HS- | M] () โ€“ C:\WINDOWS\System32\drivers\fidbox2.dat
[2010/08/23 12:46:38 | 000,036,976 | -HS- | M] () โ€“ C:\WINDOWS\System32\drivers\fidbox.idx
[2010/08/23 12:46:12 | 000,000,278 | -HS- | M] () โ€“ C:\Documents and Settings\Owner\ntuser.ini
[2010/08/23 11:54:09 | 000,044,544 | โ€”- | M] () โ€“ C:\Documents and Settings\Owner\My Documents\Professional Fax.doc
[2010/08/21 11:27:56 | 000,006,991 | โ€”- | M] () โ€“ C:\Documents and Settings\Owner\Desktop\DDS.zip
[2010/08/21 11:27:40 | 000,004,890 | โ€”- | M] () โ€“ C:\Documents and Settings\Owner\Desktop\Attach.zip
[2010/08/18 19:11:46 | 000,546,256 | Rโ€” | M] (iS3, Inc.) โ€“ C:\WINDOWS\System32\SZComp5.dll
[2010/08/18 19:11:46 | 000,132,560 | Rโ€” | M] (iS3, Inc.) โ€“ C:\WINDOWS\System32\IS3HTUI5.dll
[2010/08/18 19:11:46 | 000,022,992 | Rโ€” | M] (iS3, Inc.) โ€“ C:\WINDOWS\System32\SZIO5.dll
[2010/08/18 19:11:44 | 000,447,952 | Rโ€” | M] (iS3, Inc.) โ€“ C:\WINDOWS\System32\SZBase5.dll
[2010/08/18 19:11:44 | 000,398,800 | Rโ€” | M] (iS3, Inc.) โ€“ C:\WINDOWS\System32\IS3DBA5.dll
[2010/08/18 19:11:44 | 000,099,792 | Rโ€” | M] (iS3, Inc.) โ€“ C:\WINDOWS\System32\IS3Svc5.dll
[2010/08/18 19:11:44 | 000,067,024 | Rโ€” | M] (iS3, Inc.) โ€“ C:\WINDOWS\System32\IS3Hks5.dll
[2010/08/18 19:11:44 | 000,028,624 | Rโ€” | M] (iS3, Inc.) โ€“ C:\WINDOWS\System32\IS3XDat5.dll
[2010/08/18 19:11:42 | 000,738,768 | Rโ€” | M] (iS3, Inc.) โ€“ C:\WINDOWS\System32\IS3Base5.dll
[2010/08/18 19:11:42 | 000,390,608 | Rโ€” | M] (iS3, Inc.) โ€“ C:\WINDOWS\System32\IS3UI5.dll
[2010/08/18 19:11:42 | 000,230,864 | Rโ€” | M] (iS3, Inc.) โ€“ C:\WINDOWS\System32\IS3Win325.dll
[2010/08/18 19:11:42 | 000,099,792 | Rโ€” | M] (iS3, Inc.) โ€“ C:\WINDOWS\System32\IS3Inet5.dll
[2010/08/17 12:31:02 | 000,000,284 | โ€”- | M] () โ€“ C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/08/16 13:24:57 | 000,000,920 | โ€”- | M] () โ€“ C:\WINDOWS\QUICKEN.INI
[2010/08/16 13:07:53 | 000,000,000 | โ€”- | M] () โ€“ C:\WINDOWS\System32\BIPORT
[2010/08/12 03:30:25 | 000,236,760 | โ€”- | M] () โ€“ C:\WINDOWS\System32\FNTCACHE.DAT
[2010/08/12 03:10:14 | 000,536,974 | โ€”- | M] () โ€“ C:\WINDOWS\System32\PerfStringBackup.INI
[2010/08/12 03:10:14 | 000,466,834 | โ€”- | M] () โ€“ C:\WINDOWS\System32\perfh009.dat
[2010/08/12 03:10:14 | 000,080,050 | โ€”- | M] () โ€“ C:\WINDOWS\System32\perfc009.dat
[2010/08/05 08:16:52 | 000,000,000 | โ€”- | M] () โ€“ C:\WINDOWS\System32\NULL
[2010/08/04 13:53:47 | 000,072,080 | โ€”- | M] () โ€“ C:\Documents and Settings\Owner\g2mdlhlpx.exe
[2010/07/29 08:11:11 | 000,113,933 | โ€”- | M] () โ€“ C:\WINDOWS\System32\drivers\klin.dat
[2010/07/29 08:11:11 | 000,097,549 | โ€”- | M] () โ€“ C:\WINDOWS\System32\drivers\klick.dat
[2010/07/26 23:30:35 | 008,462,336 | โ€”- | M] (Microsoft Corporation) โ€“ C:\WINDOWS\System32\dllcache\shell32.dll

========== Files Created - No Company Name ==========

[2010/08/23 12:57:55 | 000,000,744 | โ€”- | C] () โ€“ C:\WINDOWS\System32\drivers\kgpcpy.cfg
[2010/08/21 11:27:56 | 000,006,991 | โ€”- | C] () โ€“ C:\Documents and Settings\Owner\Desktop\DDS.zip
[2010/08/21 11:27:40 | 000,004,890 | โ€”- | C] () โ€“ C:\Documents and Settings\Owner\Desktop\Attach.zip
[2010/08/04 13:53:47 | 000,072,080 | โ€”- | C] () โ€“ C:\Documents and Settings\Owner\g2mdlhlpx.exe
[2010/04/18 19:08:29 | 000,000,000 | โ€”- | C] () โ€“ C:\WINDOWS\EEventManager.INI
[2010/04/16 12:23:20 | 000,000,097 | โ€”- | C] () โ€“ C:\WINDOWS\System32\PICSDK.ini
[2010/04/16 12:22:17 | 000,000,089 | โ€”- | C] () โ€“ C:\WINDOWS\EPWF610.ini
[2009/11/26 11:53:57 | 000,000,767 | โ€”- | C] () โ€“ C:\WINDOWS\maxlink.ini
[2009/01/30 21:38:36 | 000,000,362 | โ€”- | C] () โ€“ C:\WINDOWS\wininit.ini
[2008/10/30 21:17:55 | 000,000,000 | โ€”- | C] () โ€“ C:\WINDOWS\setup32.INI
[2008/10/08 14:37:08 | 000,000,040 | โ€”- | C] () โ€“ C:\WINDOWS\opt_2460.ini
[2008/10/08 14:37:07 | 000,000,024 | โ€”- | C] () โ€“ C:\WINDOWS\brqikmon.ini
[2008/06/01 08:36:35 | 000,086,016 | โ€”- | C] () โ€“ C:\WINDOWS\System32\custmon32.dll
[2008/05/13 22:51:29 | 000,000,030 | โ€”- | C] () โ€“ C:\WINDOWS\System32\brss01a.ini
[2008/01/26 15:18:15 | 000,000,501 | โ€”- | C] () โ€“ C:\WINDOWS\dellstat.ini
[2007/09/27 10:51:02 | 000,020,698 | โ€”- | C] () โ€“ C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 10:48:48 | 000,030,628 | โ€”- | C] () โ€“ C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 10:48:28 | 000,031,698 | โ€”- | C] () โ€“ C:\WINDOWS\System32\gthrctr.ini
[2007/08/07 09:40:50 | 000,002,185 | โ€”- | C] () โ€“ C:\WINDOWS\BrmfBidi.ini
[2007/08/07 09:39:48 | 000,000,637 | โ€”- | C] () โ€“ C:\WINDOWS\Brpcfx.ini
[2007/08/07 09:39:47 | 000,000,078 | โ€”- | C] () โ€“ C:\WINDOWS\BRPP2KA.INI
[2007/05/12 11:18:07 | 000,000,111 | โ€”- | C] () โ€“ C:\WINDOWS\Brownie.ini
[2007/05/12 11:18:07 | 000,000,051 | โ€”- | C] () โ€“ C:\WINDOWS\brmx2001.ini
[2007/05/12 11:18:07 | 000,000,011 | โ€”- | C] () โ€“ C:\WINDOWS\BRVIDEO.INI
[2007/05/12 11:17:29 | 000,000,426 | โ€”- | C] () โ€“ C:\WINDOWS\BRWMARK.INI
[2007/04/11 12:52:16 | 000,000,058 | โ€”- | C] () โ€“ C:\Documents and Settings\All Users\Application Data\mchguid.ini
[2007/03/24 15:27:52 | 000,000,000 | โ€”- | C] () โ€“ C:\WINDOWS\PNTINFO.INI
[2006/11/30 06:27:31 | 000,000,214 | โ€”- | C] () โ€“ C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2006/10/02 07:02:07 | 000,000,000 | โ€”- | C] () โ€“ C:\WINDOWS\iPlayer.INI
[2006/09/21 10:50:58 | 000,000,037 | โ€”- | C] () โ€“ C:\WINDOWS\ipixActivex.ini
[2006/05/27 07:13:05 | 000,001,755 | โ€”- | C] () โ€“ C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/04/08 08:08:56 | 000,005,921 | โ€”- | C] () โ€“ C:\Documents and Settings\Owner\Application Data\GdiplusUpgrade_MSIApproach_Wrapper.log
[2006/04/08 08:08:56 | 000,000,206 | โ€”- | C] () โ€“ C:\WINDOWS\HPGdiPlus.ini
[2006/03/28 13:15:14 | 000,002,761 | โ€”- | C] () โ€“ C:\WINDOWS\compedia.ini
[2006/03/04 17:14:36 | 000,001,454 | โ€”- | C] () โ€“ C:\WINDOWS\cdPlayer.ini
[2005/12/27 10:31:38 | 000,000,058 | โ€”- | C] () โ€“ C:\WINDOWS\mchguid.ini
[2005/08/29 09:16:19 | 000,000,181 | โ€”- | C] () โ€“ C:\WINDOWS\import.INI
[2005/07/11 09:39:54 | 000,004,148 | โ€”- | C] () โ€“ C:\Documents and Settings\Owner\Application Data\ViewerApp.dat
[2005/07/11 09:32:03 | 000,003,654 | โ€”- | C] () โ€“ C:\WINDOWS\System32\drivers\Sonyhcp.dll
[2005/06/22 06:02:00 | 000,184,320 | โ€”- | C] () โ€“ C:\WINDOWS\System32\EmbeddedDX.dll
[2005/06/22 06:02:00 | 000,010,875 | โ€”- | C] () โ€“ C:\WINDOWS\ESOA.INI
[2005/06/22 06:02:00 | 000,003,679 | โ€”- | C] () โ€“ C:\WINDOWS\GrAddrBk.ini
[2005/06/22 06:02:00 | 000,000,995 | โ€”- | C] () โ€“ C:\WINDOWS\GRACE.INI
[2005/06/22 06:02:00 | 000,000,053 | โ€”- | C] () โ€“ C:\WINDOWS\PRSRVDLL.INI
[2005/06/22 06:01:29 | 000,001,132 | โ€”- | C] () โ€“ C:\WINDOWS\winpoint.ini
[2005/06/19 07:35:41 | 000,000,284 | โ€”- | C] () โ€“ C:\WINDOWS\SIERRA.INI
[2005/03/07 01:23:48 | 000,141,312 | โ€”- | C] () โ€“ C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2004/01/22 02:26:03 | 000,000,000 | โ€”- | C] () โ€“ C:\WINDOWS\System32\VGAunistlog.ini
[2004/01/22 02:26:02 | 000,000,451 | โ€”- | C] () โ€“ C:\WINDOWS\VGAsetup.ini
[2004/01/21 03:04:38 | 000,000,061 | โ€”- | C] () โ€“ C:\WINDOWS\smscfg.ini
[2004/01/21 02:52:52 | 000,002,146 | โ€”- | C] () โ€“ C:\WINDOWS\System32\mshrml.ini
[2004/01/20 21:08:05 | 000,028,672 | โ€”- | C] () โ€“ C:\WINDOWS\System32\JAWTAccessBridge.dll
[2004/01/20 21:07:21 | 000,094,208 | โ€”- | C] () โ€“ C:\WINDOWS\System32\PcdrKernelModeServices.dll
[2004/01/20 21:07:21 | 000,077,824 | โ€”- | C] () โ€“ C:\WINDOWS\System32\ProgressTrace.dll
[2004/01/20 21:04:56 | 000,000,128 | โ€”- | C] () โ€“ C:\Documents and Settings\Owner\Local Settings\Application Data\fusioncache.dat
[2004/01/20 21:02:24 | 000,167,936 | โ€”- | C] () โ€“ C:\WINDOWS\System32\PCDrJNI_1_1.dll
[2004/01/20 20:56:41 | 000,030,197 | โ€”- | C] () โ€“ C:\WINDOWS\System32\CHODDI.SYS
[2004/01/20 20:56:16 | 000,024,576 | โ€”- | C] () โ€“ C:\WINDOWS\System32\syscontr.dll
[2004/01/20 20:55:38 | 000,045,056 | โ€”- | C] () โ€“ C:\WINDOWS\System32\hpreg.dll
[2004/01/20 20:42:36 | 000,000,975 | โ€”- | C] () โ€“ C:\WINDOWS\ODBC.INI
[2004/01/20 20:34:02 | 000,000,920 | โ€”- | C] () โ€“ C:\WINDOWS\QUICKEN.INI
[2004/01/20 19:30:23 | 000,001,220 | โ€”- | C] () โ€“ C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2004/01/20 19:21:37 | 000,001,793 | โ€”- | C] () โ€“ C:\WINDOWS\System32\fxsperf.ini
[2004/01/20 18:47:52 | 000,363,520 | โ€”- | C] () โ€“ C:\WINDOWS\System32\psisdecd.dll
[2004/01/20 18:38:07 | 000,299,073 | โ€”- | C] () โ€“ C:\WINDOWS\System32\PythonCOM22.dll
[2004/01/20 18:38:07 | 000,065,536 | โ€”- | C] () โ€“ C:\WINDOWS\System32\PyWinTypes22.dll
[2004/01/20 18:37:39 | 000,016,896 | โ€”- | C] () โ€“ C:\WINDOWS\System32\bcbmm.dll
[2004/01/20 18:20:37 | 000,000,904 | โ€”- | C] () โ€“ C:\WINDOWS\orun32.ini
[2004/01/20 17:05:12 | 000,000,549 | โ€”- | C] () โ€“ C:\WINDOWS\System32\oeminfo.ini
[2003/09/23 01:19:42 | 000,000,000 | โ€”- | C] () โ€“ C:\WINDOWS\System32\px.ini
[2003/03/06 23:53:16 | 000,012,288 | โ€”- | C] () โ€“ C:\WINDOWS\System32\hpnvr82.dll
[2002/08/12 09:19:42 | 000,101,376 | โ€”- | C] () โ€“ C:\WINDOWS\System32\Welsof32.dll
[2002/01/08 17:57:34 | 000,110,592 | โ€”- | C] () โ€“ C:\WINDOWS\System32\Jpeg32.dll
[2002/01/01 01:12:17 | 000,032,768 | โ€”- | C] () โ€“ C:\WINDOWS\System32\readdata2.dll
[2002/01/01 01:12:17 | 000,032,768 | โ€”- | C] () โ€“ C:\WINDOWS\System32\readdata.dll
[2002/01/01 01:12:17 | 000,022,528 | โ€”- | C] () โ€“ C:\WINDOWS\System32\re_main.dll
[2002/01/01 01:12:14 | 000,049,152 | โ€”- | C] () โ€“ C:\WINDOWS\System32\CCPRSearch.dll
[2002/01/01 01:11:49 | 000,204,800 | โ€”- | C] () โ€“ C:\WINDOWS\System32\IVIresizeW7.dll
[2002/01/01 01:11:48 | 000,200,704 | โ€”- | C] () โ€“ C:\WINDOWS\System32\IVIresizeA6.dll
[2002/01/01 01:11:48 | 000,192,512 | โ€”- | C] () โ€“ C:\WINDOWS\System32\IVIresizeP6.dll
[2002/01/01 01:11:48 | 000,192,512 | โ€”- | C] () โ€“ C:\WINDOWS\System32\IVIresizeM6.dll
[2002/01/01 01:11:48 | 000,188,416 | โ€”- | C] () โ€“ C:\WINDOWS\System32\IVIresizePX.dll
[2002/01/01 01:11:48 | 000,020,480 | โ€”- | C] () โ€“ C:\WINDOWS\System32\IVIresize.dll
[1998/10/11 01:07:38 | 000,088,576 | โ€”- | C] () โ€“ C:\WINDOWS\System32\Iticheck.dll

========== LOP Check ==========

[2008/06/23 08:10:28 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\Cosmi
[2010/04/26 19:11:25 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\EPSON
[2009/11/26 12:48:15 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\ScanSoft
[2010/08/24 00:00:18 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2010/08/16 08:38:33 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\SUIIMAGE
[2010/08/23 12:56:23 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\SureWest Communications
[2009/07/28 06:31:18 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\SureWest Setup Files
[2010/02/18 12:10:57 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\TEMP
[2010/08/23 12:54:28 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Owner\Application Data\.oit
[2008/08/16 00:29:52 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Owner\Application Data\Business Logic
[2009/09/08 22:11:54 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Owner\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2005/03/07 04:36:57 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Owner\Application Data\Common Files
[2007/07/30 10:51:29 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Owner\Application Data\Costco Photo Organizer
[2007/07/28 22:41:24 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Owner\Application Data\Costco Photo Viewer US
[2006/03/03 08:22:23 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Owner\Application Data\eLanguage
[2010/04/22 11:41:53 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Owner\Application Data\Epson
[2006/09/03 13:32:46 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Owner\Application Data\interMute
[2006/12/15 19:58:08 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Owner\Application Data\InterVideo
[2010/04/25 08:07:30 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Owner\Application Data\Leader Technologies
[2005/02/06 01:33:37 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Owner\Application Data\Leadertech
[2010/04/23 10:16:46 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Owner\Application Data\NewSoft
[2009/11/26 12:48:23 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Owner\Application Data\PPIMAGES
[2008/08/28 15:31:34 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Owner\Application Data\Printer Info Cache
[2004/01/20 21:29:05 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Owner\Application Data\SampleView
[2006/09/16 23:15:23 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Owner\Application Data\Snapfish
[2010/04/19 23:43:07 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Owner\Application Data\Windows Desktop Search
[2010/06/11 11:01:02 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Owner\Application Data\Windows Search

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/01/31 18:45:20 | 000,000,353 | โ€”- | M] () โ€“ C:\aaw7boot.log
[2004/01/20 18:16:37 | 000,000,000 | โ€”- | M] () โ€“ C:\AUTOEXEC.BAT
[2008/07/09 23:25:12 | 000,000,281 | RHS- | M] () โ€“ C:\boot.ini
[2010/07/18 23:40:24 | 000,066,684 | โ€”- | M] () โ€“ C:\CheckExist.log
[2002/08/29 05:00:00 | 000,245,920 | RHS- | M] () โ€“ C:\cmldr
[2010/06/25 23:47:19 | 000,022,553 | โ€”- | M] () โ€“ C:\ComboFix.txt
[2004/01/20 18:16:37 | 000,000,000 | โ€”- | M] () โ€“ C:\CONFIG.SYS
[2004/05/04 11:53:40 | 001,645,320 | โ€”- | M] (Microsoft Corporation) โ€“ C:\gdiplus.dll
[2004/01/20 19:33:40 | 000,001,808 | โ€”- | M] () โ€“ C:\HP Digital Imaging Monitor.lnk
[2004/01/20 18:16:37 | 000,000,000 | RHS- | M] () โ€“ C:\IO.SYS
[2008/05/30 19:27:56 | 000,000,129 | โ€”- | M] () โ€“ C:\jetscan.log
[2005/06/29 02:00:30 | 000,006,937 | โ€”- | M] () โ€“ C:\mrnet1.imp
[2005/08/29 09:14:20 | 000,007,136 | โ€”- | M] () โ€“ C:\mrnet2.imp
[2005/06/29 02:00:32 | 000,007,374 | โ€”- | M] () โ€“ C:\mrnet3.imp
[2004/01/20 18:16:37 | 000,000,000 | RHS- | M] () โ€“ C:\MSDOS.SYS
[2005/06/24 06:25:12 | 000,047,564 | RHS- | M] () โ€“ C:\NTDETECT.COM
[2009/02/03 13:02:40 | 000,250,048 | RHS- | M] () โ€“ C:\ntldr
[2004/01/20 20:46:26 | 000,001,687 | โ€”- | M] () โ€“ C:\Organize.lnk
[2010/08/23 12:52:48 | 805,306,368 | -HS- | M] () โ€“ C:\pagefile.sys
[2005/07/11 09:31:48 | 000,000,763 | โ€”- | M] () โ€“ C:\Picture Package Menu.lnk
[2005/07/11 09:31:46 | 000,000,813 | โ€”- | M] () โ€“ C:\Picture Package VCD Maker.lnk
[2005/06/22 23:54:09 | 000,032,768 | โ€”- | M] () โ€“ C:\pointetrack.exe
[2005/06/22 23:57:58 | 000,000,621 | โ€”- | M] () โ€“ C:\pointetrack.txt
[2006/03/21 22:04:37 | 000,003,926 | โ€”- | M] () โ€“ C:\pointexp.txt
[2006/03/21 22:10:28 | 000,002,096 | โ€”- | M] () โ€“ C:\pointimp.txt
[2007/11/09 14:26:32 | 000,001,158 | โ€”- | M] () โ€“ C:\Rescued document.txt
[2009/09/19 07:57:45 | 000,000,086 | โ€”- | M] () โ€“ C:\sgde_log.txt
[2009/11/26 11:53:46 | 000,000,727 | โ€”- | M] () โ€“ C:\SmartUI.lnk
[2005/10/31 08:56:00 | 000,700,416 | โ€”- | M] (LimeWire) โ€“ C:\StubInstaller.exe
[2009/02/01 11:40:23 | 000,000,136 | โ€”- | M] () โ€“ C:\VundoFix.txt
[2006/03/12 15:25:14 | 000,002,180 | โ€”- | M] () โ€“ C:\Windows Desktop Search.lnk
[2010/04/19 23:39:54 | 000,001,798 | โ€”- | M] () โ€“ C:\Windows Search.lnk

< %systemroot%\Fonts\*.com >
[2006/04/18 16:39:28 | 000,026,040 | โ€”- | M] () โ€“ C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 15:53:56 | 000,026,489 | โ€”- | M] () โ€“ C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 16:39:28 | 000,029,779 | โ€”- | M] () โ€“ C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 15:58:52 | 000,030,808 | โ€”- | M] () โ€“ C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2004/01/20 18:16:06 | 000,000,067 | โ€”- | M] () โ€“ C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2002/10/24 08:00:00 | 000,028,365 | โ€”- | M] (Brother Industries ,Ltd ) โ€“ C:\WINDOWS\system32\spool\prtprocs\w32x86\BRMFPP1.DLL
[2008/07/06 05:06:10 | 000,089,088 | โ€”- | M] (Microsoft Corporation) โ€“ C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2003/06/19 01:31:48 | 000,018,944 | โ€”- | M] (Microsoft Corporation) โ€“ C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2002/01/08 16:51:00 | 000,047,616 | โ€”- | M] (Black Ice Software) โ€“ C:\WINDOWS\system32\spool\prtprocs\w32x86\ppbiPr.dll
[2008/07/06 03:50:03 | 000,597,504 | โ€”- | M] (Microsoft Corporation) โ€“ C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
[2007/05/08 15:30:48 | 000,188,416 | โ€”- | M] (soft Xpansion) โ€“ C:\WINDOWS\system32\spool\prtprocs\w32x86\wpeproc.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >
[2006/11/17 23:29:44 | 000,001,610 | -Hโ€“ | M] () โ€“ C:\Documents and Settings\Owner\Application Data\Microsoft\LastFlashConfig.WFC

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2004/01/20 10:08:08 | 000,094,208 | โ€”- | M] () โ€“ C:\WINDOWS\system32\config\default.sav
[2004/01/20 10:08:08 | 000,602,112 | โ€”- | M] () โ€“ C:\WINDOWS\system32\config\software.sav
[2004/01/20 10:08:08 | 000,385,024 | โ€”- | M] () โ€“ C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2009/02/03 13:07:05 | 000,000,272 | -HS- | M] () โ€“ C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >
[2004/01/20 18:36:28 | 000,014,536 | โ€”- | M] () โ€“ C:\WINDOWS\system32\config\systemprofile\ml1.srt
[2004/01/20 18:36:28 | 000,014,226 | โ€”- | M] () โ€“ C:\WINDOWS\system32\config\systemprofile\ml2.srt
[2004/01/20 18:36:28 | 000,011,899 | โ€”- | M] () โ€“ C:\WINDOWS\system32\config\systemprofile\tempdiff.txt

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/05/15 21:36:09 | 000,000,177 | -HS- | M] () โ€“ C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2004/01/20 18:20:24 | 000,000,079 | โ€”- | M] () โ€“ C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2006/09/26 22:09:58 | 000,077,824 | โ€”- | M] (Brother Industries Ltd.) โ€“ C:\Documents and Settings\Owner\Desktop\BrScUtil.exe
[2010/06/25 23:05:32 | 003,720,783 | Rโ€” | M] () โ€“ C:\Documents and Settings\Owner\Desktop\ComboFix.exe
[2008/05/30 21:50:28 | 000,068,491 | โ€”- | M] (A.I.SOFT,INC.) โ€“ C:\Documents and Settings\Owner\Desktop\Delinfe.EXE
[2010/04/07 17:00:12 | 000,280,576 | โ€”- | M] () โ€“ C:\Documents and Settings\Owner\Desktop\Lumbleau_Broker_Logon.exe
[2008/12/09 22:21:54 | 000,280,576 | โ€”- | M] () โ€“ C:\Documents and Settings\Owner\Desktop\Lumbleau_Schools_Logon.exe
[2006/02/26 01:57:30 | 012,754,672 | โ€”- | M] (Microsoft Corporation) โ€“ C:\Documents and Settings\Owner\Desktop\MP10Setup.exe
[2009/08/16 23:51:56 | 001,753,768 | โ€”- | M] (Microsoft Corporation) โ€“ C:\Documents and Settings\Owner\Desktop\olk1004.exe
[2010/08/23 23:39:19 | 000,575,488 | โ€”- | M] (OldTimer Tools) โ€“ C:\Documents and Settings\Owner\Desktop\OTL.exe
[2009/11/17 08:15:23 | 000,063,244 | โ€”- | M] (A.I.SOFT,INC.) โ€“ C:\Documents and Settings\Owner\Desktop\ScnUtil.EXE
[2009/07/14 12:28:56 | 004,927,864 | โ€”- | M] (Microsoft Corporation) โ€“ C:\Documents and Settings\Owner\Desktop\Silverlight(2).exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-08-12 10:13:41

< >

========== Alternate Data Streams ==========

@Alternate Data Stream - 88 bytes -> C:\Documents and Settings\Owner\Desktop\Delinfe.EXE:SummaryInformation
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4829695F
< End of report >

I ran this 3 times not inserting the pasted items in the custom scan box. I was unsure if I did it correctly. The first two times the extras file came up. In the last scan the extras file did not appear. Please advise. :pullhair:
You have already posted the extras log in your first post. So that won't matter now. Please hold on while I'm getting my fix approved. :)
I ran the GMER. It locked up my system. I will wait for a while to see if it stops. I have the log, I copied it but it will not save. Just an hour glass.
This gmer.zip programs has caused my computer to stall completely. I tried running it with just sections and c drive checked. Now it will not shut down and will not open applications with a message that is is shutting down but does not do so. Any suggestions?
Try to press and hold the power button for a hard boot when the computer is not responding. When you are booted up, re-run Combofix, allow it to update itself and leave it to continue for another round of scan and post back the log.
Here is the combofix file:

ComboFix 10-08-26.02 - Owner 08/26/2010 19:37:15.7.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2047.1368 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.1exe.exe
AV: SureWest Internet Security *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: SureWest Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Owner\g2mdlhlpx.exe

.
((((((((((((((((((((((((( Files Created from 2010-07-27 to 2010-08-27 )))))))))))))))))))))))))))))))
.

2010-08-24 17:26 . 2010-08-24 17:26 โ€”โ€”โ€“ dโ€”โ€“w- c:\documents and settings\Administrator\Application Data\Windows Search
2010-08-23 14:47 . 2010-08-23 14:44 1129120 โ€”-a-w- c:\documents and settings\All Users\Application Data\STOPzilla!\vdb\vbcorent.dll
2010-08-23 14:42 . 2010-08-24 15:02 โ€”โ€”โ€“ dโ€”โ€“w- c:\documents and settings\All Users\Application Data\STOPzilla!
2010-08-13 16:56 . 2010-08-16 15:38 โ€”โ€”โ€“ dโ€”โ€“w- c:\documents and settings\All Users\Application Data\SUIIMAGE
2010-08-05 15:23 . 2010-08-05 15:23 10134 โ€”-a-r- c:\documents and settings\Owner\Application Data\Microsoft\Installer\{691652E3-D900-49C8-843B-2EB459A13653}\ARPPRODUCTICON.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-26 14:21 . 2010-04-22 02:19 โ€”โ€”โ€“ dโ€”โ€“w- c:\documents and settings\Owner\Application Data\.oit
2010-08-26 14:21 . 2009-07-28 13:47 โ€”โ€”โ€“ dโ€”โ€“w- c:\documents and settings\All Users\Application Data\SureWest Communications
2010-08-26 14:16 . 2009-07-28 13:47 4720 โ€“sha-w- c:\windows\system32\drivers\fidbox2.idx
2010-08-26 14:16 . 2009-07-28 13:47 4594720 โ€“sha-w- c:\windows\system32\drivers\fidbox.dat
2010-08-26 14:16 . 2009-07-28 13:47 36976 โ€“sha-w- c:\windows\system32\drivers\fidbox.idx
2010-08-26 14:16 . 2009-07-28 13:47 1064992 โ€“sha-w- c:\windows\system32\drivers\fidbox2.dat
2010-08-25 21:58 . 2010-04-20 05:16 โ€”โ€”โ€“ dโ€”โ€“w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-08-24 14:47 . 2010-08-24 14:47 744 โ€”-a-w- c:\windows\system32\drivers\kgpcpy.cfg
2010-08-16 20:28 . 2005-03-14 09:10 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files\Zone.com Deluxe Games
2010-08-16 19:37 . 2004-01-21 03:23 โ€”โ€”โ€“ dโ€“hโ€“w- c:\program files\InstallShield Installation Information
2010-08-12 16:45 . 2007-10-23 16:23 2600960 โ€”-a-w- c:\documents and settings\Owner\Application Data\U3\0000174B6A62AA6B\u3dapi10.dll
2010-08-12 16:45 . 2007-12-09 23:00 593920 โ€”-a-w- c:\documents and settings\Owner\Application Data\U3\0000174B6A62AA6B\PelicanExtension.dll
2010-08-12 16:45 . 2007-10-23 17:32 544768 โ€”-a-w- c:\documents and settings\Owner\Application Data\U3\0000174B6A62AA6B\SanDiskFormatExtension.dll
2010-08-12 16:45 . 2007-10-23 16:44 54584 โ€”-a-w- c:\documents and settings\Owner\Application Data\U3\0000174B6A62AA6B\U3AccessGrant.exe
2010-08-12 16:45 . 2008-05-04 23:02 4603904 โ€”-a-w- c:\documents and settings\Owner\Application Data\U3\0000174B6A62AA6B\LaunchPad.exe
2010-08-12 16:45 . 2007-10-23 17:33 2129920 โ€”-a-w- c:\documents and settings\Owner\Application Data\U3\0000174B6A62AA6B\LPSecurityExtension.dll
2010-08-12 16:45 . 2008-05-02 17:41 3493888 โ€”-a-w- c:\documents and settings\Owner\Application Data\U3\0000174B6A62AA6B\Launchpad Removal.exe
2010-08-12 16:45 . 2007-04-28 20:01 3493888 โ€”ha-w- c:\documents and settings\Owner\Application Data\U3\temp\Launchpad Removal.exe
2010-07-29 15:11 . 2009-07-28 13:48 97549 โ€”-a-w- c:\windows\system32\drivers\klick.dat
2010-07-29 15:11 . 2009-07-28 13:48 113933 โ€”-a-w- c:\windows\system32\drivers\klin.dat
2010-06-30 12:31 . 2004-11-08 17:15 149504 โ€”-a-w- c:\windows\system32\schannel.dll
2010-06-26 06:04 . 2010-06-26 06:05 389120 โ€”-a-w- c:\windows\system32\CF25032.exe
2010-06-24 12:15 . 2005-04-27 18:54 832512 โ€”-a-w- c:\windows\system32\wininet.dll
2010-06-24 12:15 . 2004-11-08 17:50 17408 โ€”โ€”w- c:\windows\system32\corpol.dll
2010-06-24 12:15 . 2004-08-04 07:56 78336 โ€”โ€”w- c:\windows\system32\ieencode.dll
2010-06-23 13:44 . 2004-01-21 00:04 1851904 โ€”โ€”w- c:\windows\system32\win32k.sys
2010-06-21 15:27 . 2004-01-21 00:04 354304 โ€”โ€”w- c:\windows\system32\drivers\srv.sys
2010-06-17 14:03 . 2004-11-08 17:50 80384 โ€”โ€”w- c:\windows\system32\iccvid.dll
2010-06-15 01:54 . 2010-07-07 15:40 11776 โ€”-a-w- c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\712ne2si.default\extensions\{d9284e50-81fc-11da-a72b-0800200c9a66}\lib\WINNT_x86-msvc\1.9.1\yoono.dll
2010-06-14 14:31 . 2004-11-08 17:50 744448 โ€”โ€”w- c:\windows\PCHealth\HelpCtr\Binaries\helpsvc.exe
2010-06-14 07:41 . 2004-11-08 17:51 1172480 โ€”-a-w- c:\windows\system32\msxml3.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BackupNotify"="c:\program files\HP\Digital Imaging\bin\backupnotify.exe" [2004-01-09 32768]
"PMSpeed"="c:\program files\NewSoft\Presto! PageManager 8 for EP\PMSpeed.EXE" [2008-12-09 55120]
"ltcmScheduler"="c:\program files\LTCM Client\ltcmScheduler.exe" [2009-08-05 105664]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2003-11-04 221184]
"HPHUPD05"="c:\program files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe" [2003-08-21 49152]
"HPHmon05"="c:\windows\System32\hphmon05.exe" [2003-08-21 483328]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2005-01-12 241664]
"AGRSMMSG"="AGRSMMSG.exe" [2003-12-13 88363]
"AVP"="c:\program files\SureWest Communications\SureWest Internet Security 2009\avp.exe" [2009-03-23 200376]
"SetDefPrt"="c:\program files\Brother\Brmfl03a\BrStDvPt.exe" [2003-07-10 45056]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"MSN Toolbar"="c:\program files\MSN Toolbar\Platform\4.0.0379.0\mswinext.exe" [2009-12-09 240992]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"EEventManager"="c:\progra~1\EPSONS~1\EVENTM~1\EEventManager.exe" [2009-04-07 673616]
"FUFAXSTM"="c:\program files\Epson Software\FAX Utility\FUFAXSTM.exe" [2009-06-05 843776]
"WrtMon.exe"="c:\windows\system32\spool\drivers\w32x86\3\WrtMon.exe" [2008-05-24 26448]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2004-02-23 3026944]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2003-9-16 237568]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"navapsvc"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Updates from HP\\137903\\Program\\BackWeb-137903.exe"=
"c:\\WINDOWS\\system32\\fxsclnt.exe"=
"c:\\WINDOWS\\system32\\mshta.exe"=
"c:\\Program Files\\HP\\HP Software Update\\HPWUCli.exe"=
"c:\\Program Files\\Real\\RealOne Player\\realplay.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\StubInstaller.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Abacast\\Abaclient.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Epson Software\\Event Manager\\EEventManager.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\NewSoft\\Presto! PageManager 8 for EP\\LicenseCheck.exe"=

R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [1/29/2008 5:29 PM 32784]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\drivers\klfltdev.sys [3/13/2008 6:02 PM 26640]
S2 mrtRate;mrtRate; [x]
S3 AWINDIS5;AWINDIS5 Protocol Driver;c:\windows\system32\AWINDIS5.SYS [4/10/2005 12:28 AM 16194]
S3 brfilt;Brother MFC Filter Driver;c:\windows\system32\drivers\BrFilt.sys [8/7/2007 9:40 AM 2944]
S3 brparimg;Brother Multi Function Parallel Image driver;c:\windows\system32\drivers\BrParImg.sys [5/14/2008 12:20 PM 3168]
S3 BrParWdm;Brother WDM Parallel Driver;c:\windows\system32\drivers\BrParwdm.sys [5/14/2008 12:19 PM 39552]
S3 BrSerWDM;Brother Serial driver;c:\windows\system32\drivers\BrSerWdm.sys [8/7/2007 9:39 AM 61952]
S3 BrUsbMdm;Brother MFC USB Fax Only Modem;c:\windows\system32\drivers\BrUsbMdm.sys [8/7/2007 9:40 AM 11008]
S3 BrUsbScn;Brother MFC USB Scanner driver;c:\windows\system32\drivers\BrUsbScn.sys [8/7/2007 9:40 AM 10368]
S3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys โ€“> c:\windows\system32\DRIVERS\klim5.sys [?]
S3 NETGEAR_WG311T_SERVICE;NETGEAR WG311T Wireless Adapter Service;c:\windows\system32\DRIVERS\wg311tn5.sys โ€“> c:\windows\system32\DRIVERS\wg311tn5.sys [?]
S3 WPEServ;soft Xpansion Print2Document;c:\program files\Common Files\WPE\wpeserv.exe [6/23/2008 8:10 AM 323584]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contents of the 'Scheduled Tasks' folder

2010-08-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]

2010-08-27 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-4176258438-1254130368-891754562-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-25 05:09]

2010-08-27 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-4176258438-1254130368-891754562-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-25 05:09]
.
.
โ€”โ€”- Supplementary Scan โ€”โ€”-
.
uSearchMigratedDefaultURL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
mStart Page = hxxp://www.yahoo.com
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = localhost
IE: Add to Banner Ad Blocker - c:\program files\SureWest Communications\SureWest Internet Security 2009\ie_banner_deny.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office10\EXCEL.EXE/3000
Trusted Zone: firstamres.com
Trusted Zone: mercadomls.com
Trusted Zone: metrolist.net
Trusted Zone: rapmls.com
Trusted Zone: schwab.com\investing
Trusted Zone: schwab.com\www
Trusted Zone: west-sacramento.ca.us\www.ci
DPF: {060239F1-8B5B-4F2B-814C-28F92FDCE231}
DPF: {62BC5DB2-0044-4040-B366-D628F3CFD551}
DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} - hxxp://lads.myspace.com/upload/MySpaceUploader2.cab
DPF: {F375116A-793C-11D2-BFE1-444553540001} - hxxp://realist2.firstamres.com/mapviewer/mapviewer.cab
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\712ne2si.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.live.com/results.aspx?FORM=SOLTDF&q=
FF - prefs.js: browser.search.selectedEngine - Live Search
FF - prefs.js: browser.startup.homepage - hxxp://yahoo.com/
FF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?FORM=SOLTDF&q=
FF - component: c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\components\nprpffbrowserrecordext.dll
FF - component: c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\712ne2si.default\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}\platform\WINNT\components\FoxyTunes.dll
FF - component: c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\712ne2si.default\extensions\{d9284e50-81fc-11da-a72b-0800200c9a66}\lib\WINNT_x86-msvc\1.9.1\yoono.dll
FF - component: c:\program files\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\components\SEPsearchhelperff.dll
FF - plugin: c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPAdbESD.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPMySrch.dll
FF - plugin: c:\program files\real\realone player\Netscape6\nppl3260.dll
FF - plugin: c:\program files\real\realone player\Netscape6\nprjplug.dll
FF - plugin: c:\program files\real\realone player\Netscape6\nprpjplug.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

โ€”- FIREFOX POLICIES โ€”-
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
.
- - - - ORPHANS REMOVED - - - -

AddRemove-HijackThis - c:\docume~1\Owner\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-08-26 19:43
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes โ€ฆ

scanning hidden autostart entries โ€ฆ

scanning hidden files โ€ฆ

scan completed successfully
hidden files: 0

**************************************************************************
.
โ€”โ€”โ€”โ€”โ€”โ€”โ€” LOCKED REGISTRY KEYS โ€”โ€”โ€”โ€”โ€”โ€”โ€”

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
โ€”โ€”โ€”โ€”โ€”โ€”โ€” DLLs Loaded Under Running Processes โ€”โ€”โ€”โ€”โ€”โ€”โ€”

- - - - - - - > 'winlogon.exe'(644)
c:\windows\system32\igfxsrvc.dll
c:\windows\system32\hccutils.DLL
.
Completion time: 2010-08-26 19:47:16
ComboFix-quarantined-files.txt 2010-08-27 02:47
ComboFix2.txt 2010-06-26 06:47
ComboFix3.txt 2009-04-07 20:43
ComboFix4.txt 2009-02-04 17:39
ComboFix5.txt 2010-08-27 02:34

Pre-Run: 77,095,030,784 bytes free
Post-Run: 77,126,369,280 bytes free

- - End Of File - - 8DC85268C0966ADDFA73D030685765FE
Conspire, I ran GMER.exe on safe mode and got the same. Lock up. My computer does not like that scanner. I sent the combofix scan. Can you determine anything with that. I can try GMER.exe on safe mode and only run c: and sections to see if I can get something. Whatever you have told me to do so far is working. My computer seems to be running a lot faster!!!! Good Work! Mark
Glad to know :thumbup:

Just skip with GMER for the time being.

Kaspersky Online Scanner in IE

I recommend you to leave your computer on for the whole night as the scanning will take longer than you expected.

Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

Please go to Kaspersky website and click on Kaspersky Online Scanner to perform an online scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
    • Archives
    • Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report Asโ€ฆ.
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.

    [external image: Posted Image]
  • Please post this log in your next reply.

**Note

For clearer guidance, here's the animated tutorial :-

Click here

To optimize scanning time and produce a more sensible report for review:
  • Close any open programs.
  • Turn off the real-time scanner of all antivirus or antispyware programs while performing the online scan. Once scan is finished remember to re-enable resident antivirus protection along with whatever antispyware app you use.

Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the license, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license is accepted, reset to 100%.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI