This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

browser non responsive infections?

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello my pc doesn't want to work with the internet very well. Can you check out my scans logs below? I am using win xp pro with all the latest updates. with 1 gig of ram. see the OTL scans below Thank You

OTL logfile created on: 9/28/2010 11:34:05 AM - Run 1
OTL by OldTimer - Version 3.2.14.1 Folder = C:\Documents and Settings\Larry Van Sweden\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 67.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 87.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.26 Gb Total Space | 27.59 Gb Free Space | 74.06% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: LARRY-DD246AB59
Current User Name: Larry Van Sweden
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Larry Van Sweden\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\IncrediMail\Bin\IncMail.exe (IncrediMail, Ltd.)
PRC - C:\Program Files\IncrediMail\Bin\ImApp.exe (IncrediMail, Ltd.)
PRC - C:\Program Files\Carbonite\Carbonite Backup\CarboniteService.exe (Carbonite, Inc. (www.carbonite.com))
PRC - C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe (Carbonite, Inc.)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\VTTimer.exe (S3 Graphics, Inc.)
PRC - C:\WINDOWS\system32\Brmfrmps.exe (Brother Industries, Ltd.)
PRC - C:\WINDOWS\system32\brsvc01a.exe (brother Industries Ltd)
PRC - C:\WINDOWS\system32\brss01a.exe (brother Industries Ltd)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Larry Van Sweden\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – C:\WINDOWS\System32\hidserv.dll File not found
SRV - (CarboniteService) – C:\Program Files\Carbonite\Carbonite Backup\carboniteservice.exe (Carbonite, Inc. (www.carbonite.com))
SRV - (AntiVirService) – C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (AntiVirSchedulerService) – C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (brmfrmps) – C:\WINDOWS\System32\Brmfrmps.exe (Brother Industries, Ltd.)
SRV - (Brother XP spl Service) – C:\WINDOWS\system32\brsvc01a.exe (brother Industries Ltd)


========== Driver Services (SafeList) ==========

DRV - (cpuz132) – C:\DOCUME~1\LARRYV~1\LOCALS~1\Temp\cpuz132\cpuz132_x32.sys File not found
DRV - (avipbb) – C:\WINDOWS\system32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) – C:\WINDOWS\system32\drivers\avgntflt.sys (Avira GmbH)
DRV - (VX6000) – C:\WINDOWS\system32\drivers\VX6000Xp.sys (Microsoft Corporation
)
DRV - (avgio) – C:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (ssmdrv) – C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (RT80x86) – C:\WINDOWS\system32\drivers\rt2860.sys (Ralink Technology, Corp.)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (RT73) – C:\WINDOWS\system32\drivers\rt73.sys (Ralink Technology, Corp.)
DRV - (BrScnUsb) – C:\WINDOWS\system32\drivers\BrScnUsb.sys (Brother Industries Ltd.)
DRV - (USR1806) – C:\WINDOWS\system32\drivers\USR1806.SYS (U.S. Robotics, Inc.)
DRV - (SetupNT) – C:\WINDOWS\system32\SetupNT.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.msn.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.charter.net/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



O1 HOSTS File: ([2006/02/28 08:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [Carbonite Backup] C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe (Carbonite, Inc.)
O4 - HKLM..\Run: [VTTimer] C:\WINDOWS\System32\VTTimer.exe (S3 Graphics, Inc.)
O4 - HKCU..\Run: [DW6] C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe (The Weather Channel Interactive, Inc.)
O4 - HKCU..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe (IncrediMail, Ltd.)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - Startup: C:\Documents and Settings\Larry Van Sweden\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/08/10 16:12:06 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: HidServ - C:\WINDOWS\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)

========== Files/Folders - Created Within 30 Days ==========

[2010/09/28 11:30:55 | 000,575,488 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Larry Van Sweden\Desktop\OTL.exe
[2010/09/27 16:15:22 | 000,000,000 | —D | C] – C:\Documents and Settings\Larry Van Sweden\Application Data\GetRightToGo
[2010/09/27 11:30:47 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Larry Van Sweden\Recent
[2010/09/17 12:56:10 | 000,000,000 | —D | C] – C:\Documents and Settings\Larry Van Sweden\Application Data\Avira
[2010/09/17 12:54:15 | 000,028,520 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\ssmdrv.sys
[2010/09/17 12:54:12 | 000,124,784 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\avipbb.sys
[2010/09/17 12:54:12 | 000,060,936 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\avgntflt.sys
[2010/09/17 12:54:12 | 000,045,416 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\avgntdd.sys
[2010/09/17 12:54:12 | 000,022,360 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\avgntmgr.sys
[2010/09/17 12:54:08 | 000,000,000 | —D | C] – C:\Program Files\Avira
[2010/09/17 12:54:08 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Avira
[2010/09/17 12:00:11 | 000,000,000 | —D | C] – C:\Documents and Settings\Larry Van Sweden\Local Settings\Application Data\Threat Expert
[2010/09/17 11:00:35 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/09/17 10:55:22 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\PC Tools
[2010/09/14 14:19:51 | 000,000,000 | —D | C] – C:\Documents and Settings\Larry Van Sweden\Application Data\OpenOffice.org
[2010/09/14 13:34:16 | 000,000,000 | —D | C] – C:\Program Files\JRE
[2010/09/14 13:33:39 | 000,000,000 | —D | C] – C:\Program Files\OpenOffice.org 3
[2010/09/14 13:32:32 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/09/14 13:32:32 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/09/14 13:32:32 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/09/13 18:49:02 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2010/09/13 18:49:02 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2010/09/11 13:50:11 | 000,000,000 | —D | C] – C:\Documents and Settings\Larry Van Sweden\My Documents\My WinZip Files
[2010/09/11 13:46:08 | 000,000,000 | —D | C] – C:\Documents and Settings\Larry Van Sweden\Local Settings\Application Data\WinZip
[2010/09/11 13:45:13 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\WinZip
[2010/09/11 13:45:01 | 000,000,000 | —D | C] – C:\Program Files\WinZip
[2010/09/10 12:20:25 | 000,015,104 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbscan.sys
[2010/09/10 12:20:25 | 000,005,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ptpusb.dll
[2010/09/10 12:20:24 | 000,159,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ptpusd.dll
[2010/09/07 23:20:03 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010/09/07 10:14:45 | 000,000,000 | —D | C] – C:\Documents and Settings\Larry Van Sweden\Local Settings\Application Data\NOS
[2010/09/05 23:07:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Larry Van Sweden\Application Data\Malwarebytes
[2010/09/05 23:06:55 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/09/05 23:06:53 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/09/05 23:06:53 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/09/05 23:06:53 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/09/05 19:07:26 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\F-Secure
[2010/09/05 18:55:48 | 000,000,000 | —D | C] – C:\WINDOWS\Sun
[2010/09/05 18:54:59 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sun
[2010/09/05 18:54:52 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2010/09/05 18:54:16 | 000,423,656 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2010/09/05 18:54:16 | 000,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2010/09/05 18:51:36 | 000,000,000 | —D | C] – C:\Program Files\Java
[2010/09/05 18:49:24 | 000,000,000 | —D | C] – C:\Documents and Settings\Larry Van Sweden\Application Data\Sun
[2010/09/04 13:56:28 | 000,000,000 | —D | C] – C:\Program Files\IncrediMail
[2010/09/03 20:01:08 | 000,000,000 | -H-D | C] – C:\WINDOWS\msdownld.tmp
[2010/09/02 13:11:12 | 000,000,000 | —D | C] – C:\Documents and Settings\Larry Van Sweden\Desktop\Unused Desktop Shortcuts
[2010/09/02 12:49:23 | 000,000,000 | —D | C] – C:\Program Files\The Weather Channel FW
[2010/09/01 16:06:04 | 000,000,000 | —D | C] – C:\Documents and Settings\Larry Van Sweden\Local Settings\Application Data\The Weather Channel
[2010/09/01 11:46:03 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
[2010/08/30 20:18:17 | 000,000,000 | —D | C] – C:\WINDOWS\System32\appmgmt
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/09/28 11:30:58 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Larry Van Sweden\Desktop\OTL.exe
[2010/09/28 10:57:54 | 000,013,712 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/09/28 10:57:22 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/09/28 10:57:19 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/09/28 10:56:15 | 002,621,440 | -H– | M] () – C:\Documents and Settings\Larry Van Sweden\NTUSER.DAT
[2010/09/28 10:56:15 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Larry Van Sweden\ntuser.ini
[2010/09/27 18:26:41 | 000,000,444 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{ED2A8C3F-0BFF-4996-AEE8-E677BFB0BF1D}.job
[2010/09/27 16:21:28 | 000,000,114 | —- | M] () – C:\WINDOWS\entpack.ini
[2010/09/27 16:21:03 | 000,000,951 | —- | M] () – C:\Documents and Settings\Larry Van Sweden\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2010/09/27 16:21:03 | 000,000,933 | —- | M] () – C:\Documents and Settings\Larry Van Sweden\Desktop\Spybot - Search & Destroy.lnk
[2010/09/26 18:35:42 | 000,196,597 | —- | M] () – C:\Documents and Settings\Larry Van Sweden\My Documents\32 roadster from midwest hot rods.JPG
[2010/09/26 18:29:54 | 000,002,265 | —- | M] () – C:\Documents and Settings\Larry Van Sweden\Desktop\Skype.lnk
[2010/09/25 14:38:11 | 000,010,960 | —- | M] () – C:\Documents and Settings\Larry Van Sweden\My Documents\current meds larry.odt
[2010/09/18 21:06:16 | 000,062,661 | —- | M] () – C:\Documents and Settings\Larry Van Sweden\My Documents\Heritage Hot Rods $17780..mht
[2010/09/17 23:10:40 | 000,007,680 | —- | M] () – C:\Documents and Settings\Larry Van Sweden\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/09/17 12:54:35 | 000,001,707 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Avira AntiVir Control Center.lnk
[2010/09/17 11:27:33 | 000,617,722 | —- | M] () – C:\WINDOWS\System32\drivers\Cat.DB
[2010/09/14 18:59:43 | 000,018,496 | —- | M] () – C:\Documents and Settings\Larry Van Sweden\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/09/14 18:57:36 | 000,118,952 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/09/14 14:21:10 | 000,000,864 | —- | M] () – C:\Documents and Settings\Larry Van Sweden\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk
[2010/09/10 15:35:50 | 000,000,682 | —- | M] () – C:\Documents and Settings\Larry Van Sweden\Desktop\CCleaner.lnk
[2010/09/07 23:20:12 | 000,001,734 | —- | M] () – C:\Documents and Settings\Larry Van Sweden\Desktop\HijackThis.lnk
[2010/09/06 10:30:59 | 000,000,815 | —- | M] () – C:\Documents and Settings\Larry Van Sweden\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/09/05 23:07:01 | 000,000,714 | —- | M] () – C:\Documents and Settings\Larry Van Sweden\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2010/09/05 23:07:01 | 000,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/09/05 18:51:43 | 000,423,656 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2010/09/05 18:51:43 | 000,153,376 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/09/05 18:51:43 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/09/05 18:51:43 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/09/05 18:51:43 | 000,073,728 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2010/09/04 21:56:58 | 000,000,804 | —- | M] () – C:\Documents and Settings\Larry Van Sweden\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2010/09/04 14:00:05 | 000,001,750 | —- | M] () – C:\Documents and Settings\Larry Van Sweden\Application Data\Microsoft\Internet Explorer\Quick Launch\IncrediMail.lnk
[2010/09/04 13:57:05 | 000,001,736 | —- | M] () – C:\Documents and Settings\Larry Van Sweden\Application Data\Microsoft\Internet Explorer\Quick Launch\IncrediMail 2.0.lnk
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/09/27 16:21:03 | 000,000,951 | —- | C] () – C:\Documents and Settings\Larry Van Sweden\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2010/09/27 16:21:03 | 000,000,933 | —- | C] () – C:\Documents and Settings\Larry Van Sweden\Desktop\Spybot - Search & Destroy.lnk
[2010/09/26 18:35:42 | 000,196,597 | —- | C] () – C:\Documents and Settings\Larry Van Sweden\My Documents\32 roadster from midwest hot rods.JPG
[2010/09/18 21:06:16 | 000,062,661 | —- | C] () – C:\Documents and Settings\Larry Van Sweden\My Documents\Heritage Hot Rods $17780..mht
[2010/09/17 12:54:35 | 000,001,707 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Avira AntiVir Control Center.lnk
[2010/09/17 11:27:27 | 000,617,722 | —- | C] () – C:\WINDOWS\System32\drivers\Cat.DB
[2010/09/14 14:21:09 | 000,000,864 | —- | C] () – C:\Documents and Settings\Larry Van Sweden\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk
[2010/09/07 23:20:04 | 000,001,734 | —- | C] () – C:\Documents and Settings\Larry Van Sweden\Desktop\HijackThis.lnk
[2010/09/05 23:07:01 | 000,000,714 | —- | C] () – C:\Documents and Settings\Larry Van Sweden\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2010/09/05 23:07:00 | 000,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/09/04 14:00:05 | 000,001,750 | —- | C] () – C:\Documents and Settings\Larry Van Sweden\Application Data\Microsoft\Internet Explorer\Quick Launch\IncrediMail.lnk
[2010/09/04 13:57:05 | 000,001,736 | —- | C] () – C:\Documents and Settings\Larry Van Sweden\Application Data\Microsoft\Internet Explorer\Quick Launch\IncrediMail 2.0.lnk
[2010/08/28 11:31:13 | 000,000,165 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2010/08/11 11:39:09 | 000,000,114 | —- | C] () – C:\WINDOWS\entpack.ini
[2010/08/10 22:32:07 | 000,000,000 | —- | C] () – C:\WINDOWS\Brownie.ini
[2010/08/10 19:27:23 | 000,015,497 | —- | C] () – C:\WINDOWS\VX6KStd.ini
[2010/08/10 18:57:14 | 000,000,030 | —- | C] () – C:\WINDOWS\System32\brss01a.ini
[2010/08/10 18:55:50 | 000,000,419 | —- | C] () – C:\WINDOWS\brwmark.ini
[2010/08/10 18:55:50 | 000,000,234 | —- | C] () – C:\WINDOWS\Brpfx04a.ini
[2010/08/10 18:55:50 | 000,000,092 | —- | C] () – C:\WINDOWS\brpcfx.ini
[2010/08/10 18:55:50 | 000,000,079 | —- | C] () – C:\WINDOWS\BRPP2KA.INI
[2010/08/10 18:54:27 | 000,027,019 | —- | C] () – C:\WINDOWS\maxlink.ini
[2010/08/10 18:49:51 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\cmirmdrv.dll
[2010/08/10 18:49:42 | 000,000,092 | —- | C] () – C:\WINDOWS\CMISETUP.INI
[2010/08/10 18:49:41 | 000,000,026 | —- | C] () – C:\WINDOWS\CMCDPLAY.INI
[2010/08/10 18:49:39 | 000,000,000 | —- | C] () – C:\WINDOWS\Wininit.ini
[2010/08/10 18:49:36 | 000,121,329 | R— | C] () – C:\WINDOWS\Cmuda.ini
[2010/08/10 18:49:33 | 000,028,672 | —- | C] () – C:\WINDOWS\CMIRmDriver.dll
[2010/08/10 18:43:10 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\vusetup.dll
[2010/08/10 18:39:07 | 000,003,000 | R— | C] () – C:\WINDOWS\System32\SetupNT.sys
[2010/08/10 16:41:52 | 000,007,680 | —- | C] () – C:\Documents and Settings\Larry Van Sweden\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2004/09/17 17:37:42 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\vuins32.dll
[2002/03/04 10:16:34 | 000,110,592 | R— | C] () – C:\WINDOWS\System32\Jpeg32.dll

========== LOP Check ==========

[2010/08/27 20:28:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Carbonite
[2010/09/05 19:07:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\F-Secure
[2010/08/28 11:15:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\IM
[2010/08/28 11:12:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\IncrediMail
[2010/08/11 12:20:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2010/08/25 21:50:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ralink Driver
[2010/08/10 18:54:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2010/09/17 18:32:29 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/09/11 13:46:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2010/09/27 16:16:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Larry Van Sweden\Application Data\GetRightToGo
[2010/09/14 14:19:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Larry Van Sweden\Application Data\OpenOffice.org
[2010/09/27 18:26:41 | 000,000,444 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{ED2A8C3F-0BFF-4996-AEE8-E677BFB0BF1D}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2010/08/10 16:12:06 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/08/11 15:42:14 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2010/08/10 16:12:06 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/08/10 16:12:06 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/08/10 16:12:06 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2006/02/28 08:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2010/08/11 17:33:16 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/09/28 10:57:16 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2010/08/10 16:11:33 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2004/02/09 00:00:00 | 000,026,285 | —- | M] (Brother Industries ,Ltd ) – C:\WINDOWS\system32\spool\prtprocs\w32x86\brmfpp1.dll
[2008/07/06 08:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2001/11/20 14:37:28 | 000,047,616 | R— | M] (Black Ice Software) – C:\WINDOWS\system32\spool\prtprocs\w32x86\ppbiPr.dll
[2008/07/06 06:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2010/08/10 09:48:09 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2010/08/10 09:48:08 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2010/08/10 09:48:08 | 000,884,736 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2010/08/11 17:38:05 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/08/10 16:21:24 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Larry Van Sweden\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2010/08/10 16:21:23 | 000,000,079 | —- | M] () – C:\Documents and Settings\Larry Van Sweden\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2010/09/28 11:30:58 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Larry Van Sweden\Desktop\OTL.exe
[1991/09/12 19:00:16 | 000,115,056 | —- | M] () – C:\Documents and Settings\Larry Van Sweden\Desktop\TRIPEAKS.EXE

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >
[2010/01/27 23:44:12 | 000,013,022 | —- | M] () – C:\WINDOWS\VX6000.src
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-09-14 22:55:57

========== Alternate Data Streams ==========

@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 102 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:430C6D84
< End of report >


OTL Extras logfile created on: 9/28/2010 11:34:05 AM - Run 1
OTL by OldTimer - Version 3.2.14.1 Folder = C:\Documents and Settings\Larry Van Sweden\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 67.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 87.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.26 Gb Total Space | 27.59 Gb Free Space | 74.06% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: LARRY-DD246AB59
Current User Name: Larry Van Sweden
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Microsoft LifeCam\LifeExp.exe" = C:\Program Files\Microsoft LifeCam\LifeExp.exe:*:Enabled:LifeExp.exe – (Microsoft Corporation)
"C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe" = C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:*:Enabled:McAfee Network Agent – File not found
"C:\Program Files\IncrediMail\Bin\IncMail.exe" = C:\Program Files\IncrediMail\Bin\IncMail.exe:*:Enabled:IncrediMail – (IncrediMail, Ltd.)
"C:\Program Files\IncrediMail\Bin\ImApp.exe" = C:\Program Files\IncrediMail\Bin\ImApp.exe:*:Enabled:IncrediMail – (IncrediMail, Ltd.)
"C:\Program Files\IncrediMail\Bin\ImpCnt.exe" = C:\Program Files\IncrediMail\Bin\ImpCnt.exe:*:Enabled:IncrediMail – (IncrediMail, Ltd.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{18DB3375-0649-4EA3-959A-44F1ACD278BA}" = IncrediMail
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{26A24AE4-039D-4CA4-87B4-2F83216020F0}" = Java™ 6 Update 20
"{26A24AE4-039D-4CA4-87B4-2F83216021FF}" = Java™ 6 Update 21
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{40A6C96D-808E-41DD-8716-617AB6B0F1F1}" = Brother MFL-Pro Suite
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{5A13987D-55F4-4271-A40E-76AC9B1B38FD}" = OpenOffice.org 3.2
"{63AFACBC-4795-4A1B-8037-5085DC03FC54}" = Microsoft LifeCam
"{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}" = Ralink RT2860 Wireless LAN Card
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A17EABB6-D0C6-44E5-820C-72DC7F495064}" = PaperPort
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AC76BA86-7AD7-1033-7B44-A70000000000}" = Adobe Reader 7.0
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240BD}" = WinZip 14.5
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{DBCC73BA-C69A-4BF5-B4BF-F07501EE7039}" = AnswerWorks 5.0 English Runtime
"{ED2A3C11-3EA8-4380-B59C-F2C1832731B0}" = Quicken 2009
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"Carbonite Backup" = Carbonite
"CCleaner" = CCleaner
"C-Media Audio" = C-Media 3D Audio
"C-Media Audio Driver" = C-Media WDM Audio Driver
"HijackThis" = HijackThis 2.0.2
"ie8" = Windows Internet Explorer 8
"IncrediMail" = IncrediMail 2.0
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"S3" = UniChrome IGP Driver and Utilities
"The Weather Channel Desktop 6" = The Weather Channel Desktop 6
"VN_VUIns_Rhine_VIA" = VIA Rhine-Family Fast Ethernet Adapter
"VTDisplay" = S3 S3Display
"VTGamma2" = S3 S3Gamma2
"VTInfo2" = S3 S3Info2
"VTOverlay" = S3 S3Overlay
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 9/17/2010 8:57:52 PM | Computer Name = LARRY-DD246AB59 | Source = crypt32 | ID = 131077
Description = Failed auto update retrieval of third-party root certificate from:
<http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/323C118E1BF7B8B65254E2E2100DD6029037F096.crt>
with error: This operation returned because the timeout period expired.

Error - 9/17/2010 8:57:52 PM | Computer Name = LARRY-DD246AB59 | Source = crypt32 | ID = 131077
Description = Failed auto update retrieval of third-party root certificate from:
<http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/323C118E1BF7B8B65254E2E2100DD6029037F096.crt>
with error: The specified server cannot perform the requested operation.

Error - 9/17/2010 10:37:03 PM | Computer Name = LARRY-DD246AB59 | Source = crypt32 | ID = 131077
Description = Failed auto update retrieval of third-party root certificate from:
<http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/323C118E1BF7B8B65254E2E2100DD6029037F096.crt>
with error: This operation returned because the timeout period expired.

Error - 9/17/2010 10:37:03 PM | Computer Name = LARRY-DD246AB59 | Source = crypt32 | ID = 131077
Description = Failed auto update retrieval of third-party root certificate from:
<http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/323C118E1BF7B8B65254E2E2100DD6029037F096.crt>
with error: The specified server cannot perform the requested operation.

Error - 9/17/2010 10:37:04 PM | Computer Name = LARRY-DD246AB59 | Source = crypt32 | ID = 131077
Description = Failed auto update retrieval of third-party root certificate from:
<http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/323C118E1BF7B8B65254E2E2100DD6029037F096.crt>
with error: The specified server cannot perform the requested operation.

Error - 9/17/2010 10:37:04 PM | Computer Name = LARRY-DD246AB59 | Source = crypt32 | ID = 131077
Description = Failed auto update retrieval of third-party root certificate from:
<http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/323C118E1BF7B8B65254E2E2100DD6029037F096.crt>
with error: The specified server cannot perform the requested operation.

Error - 9/27/2010 9:49:53 AM | Computer Name = LARRY-DD246AB59 | Source = Application Hang | ID = 1002
Description = Hanging application mbam.exe, version 1.46.0.1, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 9/27/2010 9:50:01 AM | Computer Name = LARRY-DD246AB59 | Source = Application Hang | ID = 1001
Description = Fault bucket 1836621447.

Error - 9/27/2010 9:53:14 AM | Computer Name = LARRY-DD246AB59 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.

Error - 9/27/2010 12:56:45 PM | Computer Name = LARRY-DD246AB59 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

[ System Events ]
Error - 9/23/2010 6:52:15 PM | Computer Name = LARRY-DD246AB59 | Source = W32Time | ID = 39452689
Description = Time Provider NtpClient: An error occurred during DNS lookup of the
manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup
again in 15 minutes. The error was: A socket operation was attempted to an unreachable
host. (0x80072751)

Error - 9/23/2010 6:52:15 PM | Computer Name = LARRY-DD246AB59 | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 14 minutes. NtpClient has no source of accurate
time.

Error - 9/23/2010 6:52:16 PM | Computer Name = LARRY-DD246AB59 | Source = W32Time | ID = 39452689
Description = Time Provider NtpClient: An error occurred during DNS lookup of the
manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup
again in 15 minutes. The error was: A socket operation was attempted to an unreachable
host. (0x80072751)

Error - 9/23/2010 6:52:16 PM | Computer Name = LARRY-DD246AB59 | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 14 minutes. NtpClient has no source of accurate
time.

Error - 9/23/2010 6:53:27 PM | Computer Name = LARRY-DD246AB59 | Source = W32Time | ID = 39452689
Description = Time Provider NtpClient: An error occurred during DNS lookup of the
manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup
again in 15 minutes. The error was: A socket operation was attempted to an unreachable
host. (0x80072751)

Error - 9/23/2010 6:53:27 PM | Computer Name = LARRY-DD246AB59 | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 14 minutes. NtpClient has no source of accurate
time.

Error - 9/23/2010 6:55:27 PM | Computer Name = LARRY-DD246AB59 | Source = W32Time | ID = 39452689
Description = Time Provider NtpClient: An error occurred during DNS lookup of the
manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup
again in 15 minutes. The error was: A socket operation was attempted to an unreachable
host. (0x80072751)

Error - 9/23/2010 6:55:27 PM | Computer Name = LARRY-DD246AB59 | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 14 minutes. NtpClient has no source of accurate
time.

Error - 9/23/2010 6:58:55 PM | Computer Name = LARRY-DD246AB59 | Source = W32Time | ID = 39452689
Description = Time Provider NtpClient: An error occurred during DNS lookup of the
manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup
again in 15 minutes. The error was: A socket operation was attempted to an unreachable
host. (0x80072751)

Error - 9/23/2010 6:58:55 PM | Computer Name = LARRY-DD246AB59 | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 14 minutes. NtpClient has no source of accurate
time.


< End of report >
Posted Image

Note:
You don't need to downlaod MalwareBytes again but make sure you check for updates before running it.


DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.


Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:

XP Users

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Uncheck "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Uncheck "Hide protected operating system files."
Click Apply, and then click OK.


Vista Users

To enable the viewing of hidden and protected system files in Windows Vista please follow these steps:

Close all programs so that you are at your desktop.
Click on the Start button. This is the small round button with the Windows flag in the lower left corner.

Click on the Control Panel menu option.
When the control panel opens you can either be in Classic View or Control Panel Home view:

If you are in the Classic View do the following:
Double-click on the Folder Options icon.
Click on the View tab.


If you are in the Control Panel Home view do the following:

Click on the Appearance and Personalization link.
Click on Show Hidden Files or Folders.
Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
Remove the checkmark from the checkbox labeled Hide extensions for known file types.
Remove the checkmark from the checkbox labeled Hide protected operating system files.



Please do not delete anything unless instructed to.


We've been seeing some Java infections lately.
Go here and follow the instructions to clear your Java Cache


Next:

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.


It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Next:

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • [external image: Posted Image]
  • Then click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.


Also please describe how your computer behaves at the moment.


Please don't attach the scans / logs, use "copy/paste". .
Hello My pc seems to be the same, it might be very slightly more responsive, but hardly noticable. Below is my new Malwarebytes scan results. Larry Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4727 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 10/1/2010 11:29:30 AM mbam-log-2010-10-01 (11-29-30).txt Scan type: Full scan (C:\|) Objects scanned: 160374 Time elapsed: 36 minute(s), 36 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
This doesn't appear to be an infection.

I'm not seeing anything bad in your log. I suggest you read this:


http://forums.whatthetech.com/How_clean_up…ce_t100889.html


You may wish to try StartupLite. Simply download this tool to your desktop and run it. It will explain any optional auto-start programs on your system, and offer the option to stop these programs from starting at startup. This will result in fewer programs running when you boot your system, and should improve performance.



Help! My computer is slow!

http://users.telenet.be/bluepatchy/miekiem…owcomputer.html


http://www.forums.security-central.us/showthread.php?t=5849
Hello again after leaving your site a few minutes ago I can no longer logon to face book. It takes about 3 min. to do something and then takes me to a generic logon site ( blank white screen with some blue text boxes.)all othe web sites seem to load correctly. Comments? Aalso I'll check out my startup in a little bit. Thanks Larry
I have corrected the logon to facebook problem. So I guess I am done here, and thank you for your help. You can call this fixed I think. Larry

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI