This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Computer Slugglish & HD Seems To Be Running Constantly

20 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello;

First, my HD is running constantly without stop regardless of how many programs are or are not running. In addition, the whole system seems to be responding sluggishly without regard to any particular program. In some instances, everything seems to freeze in a particular application and the only way out is to open the task manager and close out the program from there. In other cases, the only resolution is to turn off the power and boot back up, not an ideal solution I know. Whether or not it is related, but in updating one of my programs, the Ask.com toolbar got installed on my system. Attempts to remove it through both CCleaner and Revo uninstallers have been unsuccessful. The uninstaller progress bar get to about 3/4 of the way through and CPU usage jumps to 100% and stays there, the end result being that the uninstall process freezes.

I forgot to add that scans with Malwarebytes, avast! and SuperAntispyware have all come back negative.

I very much appreciate any assistance that you can render.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:46:24 PM, on 3/17/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\COMODO\COMODO livePCsupport\CLPSLS.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\Program Files\Alwil Software\Avast5\avastUI.exe
C:\PROGRAM FILES\I8KFANGUI\I8KFANGUI.EXE
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\imapi.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\REALTEK\11n USB Wireless LAN Utility\RtWLan.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://my.myway.com/index.jsp?speedbarconfigchanged
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe -expressboot
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [i8kfangui] C:\PROGRAM FILES\I8KFANGUI\I8KFANGUI.EXE /startup
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [WallpaperChanger] C:\Program Files\Wallpaper Master\Wallpaper.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: REALTEK 11n USB Wireless LAN Utility.lnk = C:\Program Files\REALTEK\11n USB Wireless LAN Utility\RtWLan.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} -
O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: COMODO livePCsupport Service (CLPSLS) - COMODO - C:\Program Files\COMODO\COMODO livePCsupport\CLPSLS.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\hpbpro.exe
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\hpboid.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

–
End of file - 5548 bytes
It would appear that you have more than one anti-virus solution on your machine. I can see both Comodo Internet Security and Avast installed. Having more than one anti-virus program on your machine, even if only one is running, can cause conflicts and slowdowns in the performance of the machine. Before continuing on, please completely uninstall one of the programs.

To remove Avast: Avast Uninstall Utility
To remove Comodo Internet Security please use add/remove programs in your control panel

If you are not prompted to do so as a part of the uninstall, please reboot the machine after you have finishing uninstalling one of the programs and then continue with the following instructions:


HijackThis has largely been replaced by other tools. Since being acquired by TrendMicro, HijackThis has not been regularly updated. Many infections are now able to hide partly, or completely from a HijackThis scan. DDS includes all the scan locations of HijackThis and more.
Download and Run DDS by sUBs


Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done, DDS.txt will open.
  • Click Yes at the next prompt for Optional Scan.
  • Save both reports to your desktop.
—————————————————

Please Please copy / paste the scan reults.

DDS.txt

Please attach the second file; Attach.txt. To attach a file, do the following:
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on [external image: Posted Image] to insert the attachment into your post



Scan With RootKitUnHooker

  • Please choose one link and download Rootkit Unhooker and save it to your desktop.

    Link 1
    Link 2
    Link 3
  • Now double-click on RKUnhookerLE.exe to run it.
  • Click the Report tab, then click Scan.
  • Check (Tick) Drivers and Stealth
  • Uncheck the rest. then click OK
  • When prompted to Select Disks for Scan, make sure C:\ is checked and click OK
  • Wait till the scanner has finished and then click File > Save Report.[/b
  • Save the report somewhere where you can find it. Click Close.
  • Copy the entire contents of the report and paste it in your next reply.

Note** you may get the following warning, just click OK and continue.

"Rootkit Unhooker has detected a parasite inside itself!
It is recommended to remove parasite, okay?"



In addition to the logs, please let me know how the computer is performing after you remove one of the programs.
Hello Doris Thank you for responding to my post. Regarding the Comodo installation, I had thought I was running just the Firewall program and not the entire AV set. In any event, I uninstalled it and am using the Windows firewall. The result was no noticeable change in performance nor in the hard drive running continually. For whatever reason, I could not get the DDS scan to work. Below is the result of the RootKitUnhooker scan; RkU Version: 3.8.388.590, Type LE (SR2) ============================================== OS Name: Windows XP Version 5.1.2600 (Service Pack 3) Number of processors #1 ============================================== >Drivers ============================================== 0xBF012000 C:\WINDOWS\System32\nv4_disp.dll 3248128 bytes (NVIDIA Corporation, NVIDIA Compatible Windows 2000 Display driver, Version 44.68 ) 0x804D7000 C:\WINDOWS\system32\ntoskrnl.exe 2192768 bytes (Microsoft Corporation, NT Kernel & System) 0x804D7000 PnpManager 2192768 bytes 0x804D7000 RAW 2192768 bytes 0x804D7000 WMIxWDM 2192768 bytes 0xBF800000 Win32k 1855488 bytes 0xBF800000 C:\WINDOWS\System32\win32k.sys 1855488 bytes (Microsoft Corporation, Multi-User Win32 Driver) 0xF784E000 C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 1261568 bytes (NVIDIA Corporation, NVIDIA Compatible Windows 2000 Miniport Driver, Version 44.68 ) 0xF76E1000 C:\WINDOWS\System32\DRIVERS\WDHAALBA.sys 704512 bytes (3Com Corporation, Modem driver) 0xF403F000 C:\WINDOWS\system32\DRIVERS\RTL8192su.sys 598016 bytes (Realtek Semiconductor Corporation , Realtek RTL8192S USB NDIS Driver) 0xF84EB000 Ntfs.sys 577536 bytes (Microsoft Corporation, NT File System Driver) 0xF4226000 C:\WINDOWS\System32\DRIVERS\mrxsmb.sys 458752 bytes (Microsoft Corporation, Windows NT SMB Minirdr) 0xF77D4000 C:\WINDOWS\system32\drivers\es198xdl.sys 417792 bytes (ESS Technology, Inc., ES1988/ES1998/ES199A Adapter Driver) 0xF754D000 C:\WINDOWS\System32\DRIVERS\update.sys 385024 bytes (Microsoft Corporation, Update Driver) 0xF4355000 C:\WINDOWS\System32\DRIVERS\tcpip.sys 364544 bytes (Microsoft Corporation, TCP/IP Protocol Driver) 0xF35BE000 C:\WINDOWS\System32\DRIVERS\srv.sys 360448 bytes (Microsoft Corporation, Server driver) 0xF40F9000 C:\WINDOWS\System32\Drivers\aswSP.SYS 290816 bytes (AVAST Software, avast! self protection module) 0xBF32B000 C:\WINDOWS\System32\ATMFD.DLL 290816 bytes (Adobe Systems Incorporated, Windows NT OpenType/Type 1 Font Driver) 0xF3706000 C:\WINDOWS\System32\Drivers\HTTP.sys 266240 bytes (Microsoft Corporation, HTTP Protocol Stack) 0xF7687000 C:\WINDOWS\system32\DRIVERS\SynTP.sys 221184 bytes (Synaptics, Inc., Synaptics Touchpad Driver) 0xF8627000 ACPI.sys 188416 bytes (Microsoft Corporation, ACPI Driver for NT) 0xF37D2000 C:\WINDOWS\System32\DRIVERS\mrxdav.sys 184320 bytes (Microsoft Corporation, Windows NT WebDav Minirdr) 0xF84BE000 NDIS.sys 184320 bytes (Microsoft Corporation, NDIS 5.1 wrapper driver) 0xF42BE000 C:\WINDOWS\System32\DRIVERS\rdbss.sys 176128 bytes (Microsoft Corporation, Redirected Drive Buffering SubSystem Driver) 0xF432D000 C:\WINDOWS\System32\DRIVERS\netbt.sys 163840 bytes (Microsoft Corporation, MBT Transport driver) 0xF4200000 C:\WINDOWS\System32\DRIVERS\ipnat.sys 155648 bytes (Microsoft Corporation, IP Network Address Translator) 0xF2BBA000 C:\WINDOWS\System32\Drivers\Fastfat.SYS 147456 bytes (Microsoft Corporation, Fast FAT File System Driver) 0xF77B0000 C:\WINDOWS\system32\drivers\portcls.sys 147456 bytes (Microsoft Corporation, Port Class (Class Driver for Port/Miniport Devices)) 0xF76BD000 C:\WINDOWS\system32\DRIVERS\USBPORT.SYS 147456 bytes (Microsoft Corporation, USB 1.1 & 2.0 Port Driver) 0xF778D000 C:\WINDOWS\system32\drivers\ks.sys 143360 bytes (Microsoft Corporation, Kernel CSA Library) 0xF430B000 C:\WINDOWS\System32\drivers\afd.sys 139264 bytes (Microsoft Corporation, Ancillary Function Driver for WinSock) 0xF42E9000 C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS 139264 bytes (SUPERAdBlocker.com and SUPERAntiSpyware.com, SASKUTIL.SYS) 0xF85A1000 fltmgr.sys 131072 bytes (Microsoft Corporation, Microsoft Filesystem Filter Manager) 0xF85D9000 ftdisk.sys 126976 bytes (Microsoft Corporation, FT Disk Driver) 0xF85F8000 pcmcia.sys 122880 bytes (Microsoft Corporation, PCMCIA Bus Driver) 0xF84A4000 Mup.sys 106496 bytes (Microsoft Corporation, Multiple UNC Provider driver) 0xF85C1000 atapi.sys 98304 bytes (Microsoft Corporation, IDE/ATAPI Port Driver) 0xF4027000 C:\WINDOWS\System32\Drivers\dump_atapi.sys 98304 bytes 0xF3C0F000 C:\WINDOWS\System32\Drivers\aswMon2.SYS 94208 bytes (AVAST Software, avast! File System Filter Driver for Windows XP) 0xF8578000 KSecDD.sys 94208 bytes (Microsoft Corporation, Kernel Security Support Provider Interface) 0xF765C000 C:\WINDOWS\System32\DRIVERS\ndiswan.sys 94208 bytes (Microsoft Corporation, MS PPP Framing Driver (Strong Encryption)) 0xF3795000 C:\WINDOWS\system32\drivers\wdmaud.sys 86016 bytes (Microsoft Corporation, MMSYSTEM Wave/Midi API mapper) 0xF7673000 C:\WINDOWS\System32\DRIVERS\parport.sys 81920 bytes (Microsoft Corporation, Parallel Port Driver) 0xF783A000 C:\WINDOWS\system32\DRIVERS\VIDEOPRT.SYS 81920 bytes (Microsoft Corporation, Video Port Driver) 0x806EF000 ACPI_HAL 81152 bytes 0x806EF000 C:\WINDOWS\system32\hal.dll 81152 bytes (Microsoft Corporation, Hardware Abstraction Layer DLL) 0xF43AE000 C:\WINDOWS\System32\DRIVERS\ipsec.sys 77824 bytes (Microsoft Corporation, IPSec Driver) 0xBF000000 C:\WINDOWS\System32\drivers\dxg.sys 73728 bytes (Microsoft Corporation, DirectX Graphics Driver) 0xF858F000 sr.sys 73728 bytes (Microsoft Corporation, System Restore Filesystem Filter Driver) 0xF8616000 pci.sys 69632 bytes (Microsoft Corporation, NT Plug and Play PCI Enumerator) 0xF764B000 C:\WINDOWS\System32\DRIVERS\psched.sys 69632 bytes (Microsoft Corporation, MS QoS Packet Scheduler) 0xF8806000 C:\WINDOWS\System32\Drivers\Cdfs.SYS 65536 bytes (Microsoft Corporation, CD-ROM File System Driver) 0xF8896000 C:\WINDOWS\System32\DRIVERS\cdrom.sys 65536 bytes (Microsoft Corporation, SCSI CD-ROM Driver) 0xF8706000 C:\WINDOWS\System32\DRIVERS\nic1394.sys 65536 bytes (Microsoft Corporation, IEEE1394 Ndis Miniport and Call Manager) 0xF8686000 ohci1394.sys 65536 bytes (Microsoft Corporation, 1394 OpenHCI Port Driver) 0xF8886000 C:\WINDOWS\System32\DRIVERS\serial.sys 65536 bytes (Microsoft Corporation, Serial Device Driver) 0xF87D6000 C:\WINDOWS\System32\DRIVERS\arp1394.sys 61440 bytes (Microsoft Corporation, IP/1394 Arp Client) 0xF8856000 C:\WINDOWS\system32\drivers\drmk.sys 61440 bytes (Microsoft Corporation, Microsoft Kernel DRM Descrambler Filter) 0xF88A6000 C:\WINDOWS\System32\DRIVERS\redbook.sys 61440 bytes (Microsoft Corporation, Redbook Audio Filter Driver) 0xF3A3F000 C:\WINDOWS\system32\drivers\sysaudio.sys 61440 bytes (Microsoft Corporation, System Audio WDM Filter) 0xF8726000 C:\WINDOWS\System32\DRIVERS\usbhub.sys 61440 bytes (Microsoft Corporation, Default Hub Driver for USB) 0xF8696000 C:\WINDOWS\System32\DRIVERS\1394BUS.SYS 57344 bytes (Microsoft Corporation, 1394 Bus Device Driver) 0xF8866000 C:\WINDOWS\System32\DRIVERS\EL556ND5.sys 57344 bytes (3Com Corporation, 3Com 10/100 Mini PCI Ethernet Adapter Driver) 0xF86D6000 C:\WINDOWS\System32\DRIVERS\CLASSPNP.SYS 53248 bytes (Microsoft Corporation, SCSI Class System Dll) 0xF8876000 C:\WINDOWS\System32\DRIVERS\i8042prt.sys 53248 bytes (Microsoft Corporation, i8042 Port Driver) 0xF88B6000 C:\WINDOWS\System32\DRIVERS\rasl2tp.sys 53248 bytes (Microsoft Corporation, RAS L2TP mini-port/call-manager driver) 0xF86B6000 VolSnap.sys 53248 bytes (Microsoft Corporation, Volume Shadow Copy Driver) 0xF88D6000 C:\WINDOWS\System32\DRIVERS\raspptp.sys 49152 bytes (Microsoft Corporation, Peer-to-Peer Tunneling Protocol) 0xF86E6000 agp440.sys 45056 bytes (Microsoft Corporation, 440 NT AGP Filter) 0xF87B6000 C:\WINDOWS\System32\Drivers\Fips.SYS 45056 bytes (Microsoft Corporation, FIPS Crypto Driver) 0xF86A6000 MountMgr.sys 45056 bytes (Microsoft Corporation, Mount Manager) 0xF8846000 C:\WINDOWS\System32\DRIVERS\p3.sys 45056 bytes (Microsoft Corporation, Processor Device Driver) 0xF88C6000 C:\WINDOWS\System32\DRIVERS\raspppoe.sys 45056 bytes (Microsoft Corporation, RAS PPPoE mini-port/call-manager driver) 0xF8766000 C:\WINDOWS\System32\Drivers\aswTdi.SYS 40960 bytes (AVAST Software, avast! TDI Filter Driver) 0xF8676000 isapnp.sys 40960 bytes (Microsoft Corporation, PNP ISA Bus Driver) 0xF8736000 C:\WINDOWS\System32\Drivers\NDProxy.SYS 40960 bytes (Microsoft Corporation, NDIS Proxy) 0xF8716000 C:\WINDOWS\System32\DRIVERS\termdd.sys 40960 bytes (Microsoft Corporation, Terminal Server Driver) 0xF86C6000 disk.sys 36864 bytes (Microsoft Corporation, PnP Disk Driver) 0xF88E6000 C:\WINDOWS\System32\DRIVERS\msgpc.sys 36864 bytes (Microsoft Corporation, MS General Packet Classifier) 0xF8776000 C:\WINDOWS\System32\DRIVERS\netbios.sys 36864 bytes (Microsoft Corporation, NetBIOS interface driver) 0xF2C16000 C:\WINDOWS\System32\Drivers\Normandy.SYS 36864 bytes (RKU Driver) 0xF87C6000 C:\WINDOWS\System32\DRIVERS\wanarp.sys 36864 bytes (Microsoft Corporation, MS Remote Access and Routing ARP Driver) 0xF898E000 C:\WINDOWS\System32\Drivers\Modem.SYS 32768 bytes (Microsoft Corporation, Modem Device Driver) 0xF8A0E000 C:\WINDOWS\System32\Drivers\Npfs.SYS 32768 bytes (Microsoft Corporation, NPFS Driver) 0xF8996000 C:\WINDOWS\system32\DRIVERS\usbehci.sys 32768 bytes (Microsoft Corporation, EHCI eUSB Miniport Driver) 0xF89B6000 C:\WINDOWS\System32\DRIVERS\fdc.sys 28672 bytes (Microsoft Corporation, Floppy Disk Controller Driver) 0xF88F6000 C:\WINDOWS\System32\DRIVERS\PCIIDEX.SYS 28672 bytes (Microsoft Corporation, PCI IDE Bus Driver Extension) 0xF8A2E000 C:\WINDOWS\System32\Drivers\Aavmker4.SYS 24576 bytes (AVAST Software, avast! Base Kernel-Mode Device Driver for Windows NT/2000/XP) 0xF89AE000 C:\WINDOWS\System32\DRIVERS\kbdclass.sys 24576 bytes (Microsoft Corporation, Keyboard Class Driver) 0xF89A6000 C:\WINDOWS\System32\DRIVERS\mouclass.sys 24576 bytes (Microsoft Corporation, Mouse Class Driver) 0xF8A1E000 C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS 24576 bytes (SUPERAdBlocker.com and SUPERAntiSpyware.com, SASDIFSV.SYS) 0xF89BE000 C:\WINDOWS\System32\DRIVERS\usbuhci.sys 24576 bytes (Microsoft Corporation, UHCI USB Miniport Driver) 0xF89FE000 C:\WINDOWS\System32\drivers\vga.sys 24576 bytes (Microsoft Corporation, VGA/Super VGA Video Driver) 0xF8A46000 C:\WINDOWS\system32\DRIVERS\AegisP.sys 20480 bytes (Cisco Systems, Inc., IEEE 802.1X Protocol Driver) 0xF8A16000 C:\WINDOWS\System32\Drivers\aswRdr.SYS 20480 bytes (AVAST Software, avast! TDI RDR Driver) 0xF89EE000 C:\WINDOWS\system32\DRIVERS\flpydisk.sys 20480 bytes (Microsoft Corporation, Floppy Driver) 0xF8A06000 C:\WINDOWS\System32\Drivers\Msfs.SYS 20480 bytes (Microsoft Corporation, Mailslot driver) 0xF88FE000 PartMgr.sys 20480 bytes (Microsoft Corporation, Partition Manager) 0xF89D6000 C:\WINDOWS\System32\DRIVERS\ptilink.sys 20480 bytes (Parallel Technologies, Inc., Parallel Technologies DirectParallel IO Library) 0xF89DE000 C:\WINDOWS\System32\DRIVERS\raspti.sys 20480 bytes (Microsoft Corporation, PTI DirectParallel® mini-port/call-manager driver) 0xF89CE000 C:\WINDOWS\System32\DRIVERS\TDI.SYS 20480 bytes (Microsoft Corporation, TDI Wrapper) 0xF899E000 C:\WINDOWS\system32\DRIVERS\usbohci.sys 20480 bytes (Microsoft Corporation, OHCI USB Miniport Driver) 0xF8A36000 C:\WINDOWS\System32\watchdog.sys 20480 bytes (Microsoft Corporation, Watchdog Driver) 0xF8A8E000 C:\WINDOWS\System32\DRIVERS\BATTC.SYS 16384 bytes (Microsoft Corporation, Battery Class Driver) 0xF8B46000 C:\WINDOWS\System32\DRIVERS\CmBatt.sys 16384 bytes (Microsoft Corporation, Control Method Battery Driver) 0xF7A05000 C:\WINDOWS\system32\drivers\fanio.sys 16384 bytes (Christian Diefer, I8k Fan I/O) 0xF8B62000 C:\WINDOWS\System32\DRIVERS\mssmbios.sys 16384 bytes (Microsoft Corporation, System Management BIOS Driver) 0xF3DBA000 C:\WINDOWS\System32\DRIVERS\ndisuio.sys 16384 bytes (Microsoft Corporation, NDIS User mode I/O Driver) 0xF8B4A000 C:\WINDOWS\System32\DRIVERS\serenum.sys 16384 bytes (Microsoft Corporation, Serial Port Enumerator) 0xF8470000 C:\WINDOWS\System32\Drivers\aswFsBlk.SYS 12288 bytes (AVAST Software, avast! File System Access Blocking Driver) 0xF8A86000 C:\WINDOWS\system32\BOOTVID.dll 12288 bytes (Microsoft Corporation, VGA Boot Driver) 0xF8A8A000 compbatt.sys 12288 bytes (Microsoft Corporation, Composite Battery Driver) 0xF7545000 C:\WINDOWS\System32\drivers\Dxapi.sys 12288 bytes (Microsoft Corporation, DirectX API Driver) 0xF8B52000 C:\WINDOWS\System32\DRIVERS\ndistapi.sys 12288 bytes (Microsoft Corporation, NDIS 3.0 connection wrapper driver) 0xF7A15000 C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS 12288 bytes (Dell Computer Corporation, OMCI Device Driver) 0xF8468000 C:\WINDOWS\System32\DRIVERS\rasacd.sys 12288 bytes (Microsoft Corporation, RAS Automatic Connection Driver) 0xF845C000 C:\WINDOWS\System32\drivers\ws2ifsl.sys 12288 bytes (Microsoft Corporation, Winsock2 IFS Layer) 0xF8BAC000 C:\WINDOWS\System32\Drivers\Beep.SYS 8192 bytes (Microsoft Corporation, BEEP Driver) 0xF8BBC000 C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS 8192 bytes 0xF8BAA000 C:\WINDOWS\System32\Drivers\Fs_Rec.SYS 8192 bytes (Microsoft Corporation, File System Recognizer Driver) 0xF8B7A000 intelide.sys 8192 bytes (Microsoft Corporation, Intel PCI IDE Driver) 0xF8B76000 C:\WINDOWS\system32\KDCOM.DLL 8192 bytes (Microsoft Corporation, Kernel Debugger HW Extension DLL) 0xF8BAE000 C:\WINDOWS\System32\Drivers\mnmdd.SYS 8192 bytes (Microsoft Corporation, Frame buffer simulator) 0xF8BFC000 C:\WINDOWS\System32\Drivers\ParVdm.SYS 8192 bytes (Microsoft Corporation, VDM Parallel Driver) 0xF8BB0000 C:\WINDOWS\System32\DRIVERS\RDPCDD.sys 8192 bytes (Microsoft Corporation, RDP Miniport) 0xF8BA2000 C:\WINDOWS\System32\DRIVERS\swenum.sys 8192 bytes (Microsoft Corporation, Plug and Play Software Device Enumerator) 0xF8BA0000 C:\WINDOWS\system32\DRIVERS\USBD.SYS 8192 bytes (Microsoft Corporation, Universal Serial Bus Driver) 0xF8B78000 C:\WINDOWS\System32\DRIVERS\WMILIB.SYS 8192 bytes (Microsoft Corporation, WMILIB WMI support library Dll) 0xF8CCB000 C:\WINDOWS\System32\DRIVERS\audstub.sys 4096 bytes (Microsoft Corporation, AudStub Driver) 0xF8C61000 C:\WINDOWS\System32\drivers\dxgthk.sys 4096 bytes (Microsoft Corporation, DirectX Graphics Driver Thunk) 0xF8D8A000 C:\WINDOWS\System32\Drivers\LBeepKE.sys 4096 bytes (Logitech, Inc., Logitech Consumer Control Filter Driver.) 0xF8CE4000 C:\WINDOWS\System32\Drivers\Null.SYS 4096 bytes (Microsoft Corporation, NULL Driver) ============================================== >Stealth ============================================== Again, thanks for the help. Gerry
Let's try running an OTL scan instead if DDS won't run. If possible can you tell me what happened when you tried to run DDS? Did you get any errors?


OTL Custom Scan

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %PROGRAMFILES%\Internet Explorer\*.dat
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
Hello; Well each and every time I tried running the OTL scan per your instructions, the OTL program would stop responding and freeze up when it reached my Firefox files and would not complete the scan. I had been considering clearing out my Firefox profile and replacing it with a copy of the "fresh" one I recently made on my new lap top when I installed Firefox on it. Before I do so, I'll wait for your advice as to how to proceed from here. Also, whether or not it is related to my situation, I still cannot uninstall that Ask.com toolbar. Appreciate your time on this.
Let's try booting into safe mode and running OTL:

Boot your computer in Safe Mode
  • Turn the computer on or Restart the computer
  • As soon as BIOS is loaded, start tapping the F8 key.
  • The Windows Advanced Options Menu appears.
    If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Use the arrow keys to select the Safe Mode menu option.
  • Press Enter.
  • The computer then begins to start in Safe mode.
  • Log into your usual account
  • Let's try the OTL log again per the initial instructions and post the report
  • When you are finished with all troubleshooting, close all programs and restart the computer as you normally would.

Certainly, there are infections that can affect Firefox, but I have not encountered on that stops the tools from running. If we still can't get OTL to run, we'll tackle Firefox files at that point.


I doubt it's related to the tools not running, but if you want to try another way of removing the Ask Toolbar, as long as it is showing in add/remove programs, we can try RevoUninstaller:

Download Revo Uninstaller
  • Double click the installation file on the desktop to run the installer.
  • Let it install to the default location.
  • Double click the new Revo Uninstaller Icon on the desktop to start the program.
You will now see a list of installed programs that Revo Uninstaller can remove.
  • Locate the program you are uninstalling Ask Toolbar
  • Right Click the Icon then choose Uninstall.
  • Click yes to the warning and choose the Uninstall Mode
  • Choose the Advanced option and then click Next.
  • This will launch the programs built in uninstaller. Be patient it can take several seconds.
  • Once the uninstaller is done click Next.
  • Revo Uninstaller will now scan for leftover information. Be patient it can take several seconds.
  • Once this scan is done click Next.
  • You will then be presented of the leftover entries found by Revo Uninstaller
  • Look at ALL of the entries to ensure they relate to the program you are uninstalling.
  • Next click Select All > Delete to remove the entries.
  • Click Next.
  • If there are any program file folders left over you will be presented with a list to be removed.
  • Again look at ALL of the entries to ensure they are related to the program you are uninstalling.
  • Click Select All > Delete to remove the entries.
  • Click Finish to go back to the uninstall list.
  • Close the program

If it still won't remove, then we can do it manually with OTL once we have a log so I can identify all the necessary entries. One way or another we'll get it off the machine :)
I am trying not to bang my head on my desk. In the safe mode, when OTL started to scan the Firefox files, the program again stopped responding. When I checked CPU usage in Task manager, it was pegged at 100%. FYI, this is an old P3 mobile Dell Inspiron (hence the new one), maxed out at 512 MB of RAM, which I was planning to keep as a reserve/emergency unit as time and technology have pretty much passed it by. I tried using Revo as well as CCleaner to get rid of the toolbar without success.
Don't bang your head on the desk. It's not going to help the computer, but I can assure you it will give you a headache. :smack: Give me a bit to confer with some of my colleagues on how to deal with the issue of the Firefox files and I'll be back to you shortly.
Thanks for your patience, I've obtained some additional input and we'd like to try running DDS again, but we are going to make a slight change to rename the file. Please right-click and delete the copy that is currently on your desktop and then follow the directions below to download and try running it again. Hopefully, you should be able to do this all in normal mode. Let me know how it goes.


Download and Run DDS by sUBs

Please download DDS and save it to your desktop.
When you save it, make sure to rename it to save as DDS.com (to do this you may need to change the file type from screensaver to "all files" and add the .com on the end of the file name).
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done, DDS.txt will open.
  • Click Yes at the next prompt for Optional Scan.
  • Save both reports to your desktop.
—————————————————

Please Please copy / paste the scan reults.

DDS.txt

Please attach the second file; Attach.txt. To attach a file, do the following:
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on [external image: Posted Image] to insert the attachment into your post
Doris

I could not get DDS to run. So, I went ahead with my planned uninstallation of Firefox and cleaned out the old profile then reinstalled and then copied the fresh profile from my new laptop. Low and behold, OTL ran fine. Hopefully this will help. BTW, Firefox is running much faster now.

Here is the OTL Log:



OTL logfile created on: 3/21/2011 4:35:14 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Gerry Goldshine\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

511.00 Mb Total Physical Memory | 226.00 Mb Available Physical Memory | 44.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 75.00% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55.89 Gb Total Space | 34.38 Gb Free Space | 61.51% Space Free | Partition Type: NTFS

Computer Name: SAL-9000 | User Name: Gerry Goldshine | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Gerry Goldshine\desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe (BillP Studios)
PRC - C:\Program Files\REALTEK\11n USB Wireless LAN Utility\RtWLan.exe (Realtek Semiconductor Corp.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\I8kfanGUI\I8kfanGUI.exe (Christian Diefer)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Gerry Goldshine\desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\Alwil Software\Avast5\snxhk.dll (AVAST Software)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\BillP Studios\WinPatrol\patrolpro.dll (BillP Studios)


========== Win32 Services (SafeList) ==========

SRV - (CachemanService) – File not found
SRV - (AppMgmt) – File not found
SRV - (AdobeActiveFileMonitor9.0) – File not found
SRV - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (spupdsvc) – C:\WINDOWS\system32\spupdsvc.exe (Microsoft Corporation)
SRV - (HP Port Resolver) – C:\WINDOWS\system32\hpbpro.exe (Hewlett-Packard Company)
SRV - (HP Status Server) – C:\WINDOWS\system32\hpboid.exe (Hewlett-Packard Company)


========== Driver Services (SafeList) ==========

DRV - (aswSP) – C:\WINDOWS\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswTdi) – C:\WINDOWS\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswMon2) – C:\WINDOWS\System32\drivers\aswmon2.sys (AVAST Software)
DRV - (aswRdr) – C:\WINDOWS\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (Aavmker4) – C:\WINDOWS\System32\drivers\aavmker4.sys (AVAST Software)
DRV - (aswFsBlk) – C:\WINDOWS\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (LMouFilt) – C:\WINDOWS\system32\drivers\LMouFilt.Sys (Logitech, Inc.)
DRV - (LHidFilt) – C:\WINDOWS\system32\drivers\LHidFilt.Sys (Logitech, Inc.)
DRV - (LBeepKE) – C:\WINDOWS\system32\drivers\LBeepKE.sys (Logitech, Inc.)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (ivusb) – C:\WINDOWS\system32\drivers\ivusb.sys (Initio Corporation)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (Revoflt) – C:\WINDOWS\system32\drivers\revoflt.sys (VS Revo Group)
DRV - (RTL8192su) – C:\WINDOWS\system32\drivers\rtl8192su.sys (Realtek Semiconductor Corporation )
DRV - (moufiltr) – C:\WINDOWS\system32\drivers\moufiltr.sys (Chic Tech.)
DRV - (fanio) – C:\WINDOWS\system32\drivers\fanio.sys (Christian Diefer)
DRV - (whfltr2k) – C:\WINDOWS\system32\drivers\whfltr2k.sys ()
DRV - (SIS163u) – C:\WINDOWS\system32\drivers\sis163u.sys (Silicon Integrated Systems Corp.)
DRV - (BCM43XX) – C:\WINDOWS\system32\drivers\BCMWL5.SYS (Broadcom Corporation)
DRV - (odysseyIM4) – C:\WINDOWS\system32\drivers\odysseyIM4.sys (Funk Software, Inc.)
DRV - (ZD1211U(CellVision)) TRENDnet 802.11g wireless USB TEW-424UB(CellVision) – C:\WINDOWS\system32\drivers\ZD1211U.sys (ZyDAS Technology Corporation)
DRV - (whmice2k) – C:\WINDOWS\system32\drivers\whmice2k.sys ()
DRV - (CBTNDIS5) – C:\WINDOWS\system32\CBTNDIS5.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (maestro) ESS Maestro Audio Driver (WDM) – C:\WINDOWS\system32\drivers\es198xdl.sys (ESS Technology, Inc.)
DRV - (WDHAALBA) – C:\WINDOWS\system32\drivers\WDHAALBA.sys (3Com Corporation)
DRV - (nv4) – C:\WINDOWS\system32\drivers\nv4.sys (NVIDIA Corporation)
DRV - (EL556ND5) – C:\WINDOWS\system32\drivers\EL556ND5.sys (3Com Corporation)
DRV - (OMCI) – C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS (Dell Computer Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://my.myway.com/index.jsp?speedbarconfigchanged
IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://my.myway.com/index.jsp?speedbarconfigchanged"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:5.0.1
FF - prefs.js..extensions.enabledItems: [removed]:1.15.0
FF - prefs.js..extensions.enabledItems: [removed]:2.2.0
FF - prefs.js..extensions.enabledItems: [removed]:3.3.6
FF - prefs.js..extensions.enabledItems: [removed]:1.95.20100933
FF - prefs.js..extensions.enabledItems: [removed]:3.76
FF - prefs.js..extensions.enabledItems: [removed]:1.6.2
FF - prefs.js..extensions.enabledItems: [removed]:2.0.2c
FF - prefs.js..extensions.enabledItems: TFToolbarX@torrent-finder:1.2.6
FF - prefs.js..extensions.enabledItems: {03B08592-E5B4-45ff-A0BE-C1D975458688}:1.0
FF - prefs.js..extensions.enabledItems: {0538E3E3-7E9B-4d49-8831-A227C80A7AD3}:2.0.2
FF - prefs.js..extensions.enabledItems: {0fa2149e-bb2c-4ac2-a8d3-479599819475}:2.0.1
FF - prefs.js..extensions.enabledItems: {1018e4d6-728f-4b20-ad56-37578a4de76b}:4.1.1
FF - prefs.js..extensions.enabledItems: {19EB90DC-A456-458b-8AAC-616D91AAFCE1}:0.7
FF - prefs.js..extensions.enabledItems: {1cff04ef-0c75-4621-ba2a-2efb77346996}:2.3
FF - prefs.js..extensions.enabledItems: {2E481B23-66AC-313F-D6A8-A81DDDF26249}:1.0.20101216
FF - prefs.js..extensions.enabledItems: {6614d11d-d21d-b211-ae23-815234e1ebb5}:1.0.23
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20100908
FF - prefs.js..extensions.enabledItems: {a0faa0a4-f1a7-4098-9a74-21efc3a92372}:4.0.1
FF - prefs.js..extensions.enabledItems: {B17C1C5A-04B1-11DB-9804-B622A1EF5492}:1.2.1
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8.4
FF - prefs.js..extensions.enabledItems: {BFB5F154-9212-46F3-B547-AC6106030A54}:1.2
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3
FF - prefs.js..extensions.enabledItems: {daf44bf7-a45e-4450-979c-91cf07434c3d}:1.5.7
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:2.0.2
FF - prefs.js..extensions.enabledItems: {ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}:1.4.1
FF - prefs.js..extensions.enabledItems: {ef62e1ce-d2a4-4cdd-b7ec-92b120366b66}:2.7.1
FF - prefs.js..extensions.enabledItems: {F8A55C97-3DB6-4961-A81D-0DE0080E53CB}:0.9.5
FF - prefs.js..extensions.enabledItems: {FBF6D7FB-F305-4445-BB3D-FEF66579A033}:5.0
FF - prefs.js..extensions.enabledItems: [removed]:3.0
FF - prefs.js..extensions.enabledItems: {5b175400-2368-11de-8c30-0800200c9a66}:1.9
FF - prefs.js..extensions.enabledItems: {9f08cb5a-76b1-4bcf-aff9-90e1a5d60b1e}:3.76

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.15\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/03/21 13:24:29 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.15\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/03/21 13:22:01 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.9\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2011/03/12 22:22:06 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.9\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins

[2011/03/21 13:24:32 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Extensions
[2011/03/21 13:27:51 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions
[2011/03/21 13:26:13 | 000,000,000 | —D | M] (Toolbar Buttons) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\{03B08592-E5B4-45ff-A0BE-C1D975458688}
[2011/03/21 13:26:14 | 000,000,000 | —D | M] (Forecastfox Weather) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
[2011/03/21 13:26:17 | 000,000,000 | —D | M] (URL Fixer) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\{0fa2149e-bb2c-4ac2-a8d3-479599819475}
[2011/03/21 13:26:17 | 000,000,000 | —D | M] (Flagfox) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}
[2011/03/21 13:26:17 | 000,000,000 | —D | M] (Print/Print Preview) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\{19EB90DC-A456-458b-8AAC-616D91AAFCE1}
[2011/03/21 13:26:17 | 000,000,000 | —D | M] ("ChromaTabs Plus") – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\{1cff04ef-0c75-4621-ba2a-2efb77346996}
[2011/03/21 13:27:14 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/03/21 13:26:19 | 000,000,000 | —D | M] (Fierr) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\{2E481B23-66AC-313F-D6A8-A81DDDF26249}
[2011/03/21 13:26:19 | 000,000,000 | —D | M] (Oskar) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\{5b175400-2368-11de-8c30-0800200c9a66}
[2011/03/21 13:26:20 | 000,000,000 | —D | M] (Dr.Web anti-virus link checker) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\{6614d11d-d21d-b211-ae23-815234e1ebb5}
[2011/03/21 13:26:20 | 000,000,000 | —D | M] ("CuteMenus2") – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\{71C54606-83ED-4ea6-9315-1AAB29466D33}
[2011/03/21 13:26:22 | 000,000,000 | —D | M] (PhishTank SiteChecker) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\{8bc5b5eb-0ec4-46ed-a024-ace8a3032888}
[2011/03/21 13:26:22 | 000,000,000 | —D | M] (Update Notifier) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\{95f24680-9e31-11da-a746-0800200c9a66}
[2011/03/21 13:26:22 | 000,000,000 | —D | M] (Noia 2.0 (eXtreme)) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\{9f08cb5a-76b1-4bcf-aff9-90e1a5d60b1e}
[2011/03/21 13:26:22 | 000,000,000 | —D | M] (WOT) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2011/03/21 13:26:22 | 000,000,000 | —D | M] (DictionarySearch) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\{a0faa0a4-f1a7-4098-9a74-21efc3a92372}
[2011/03/21 13:26:23 | 000,000,000 | —D | M] (Password Exporter) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\{B17C1C5A-04B1-11DB-9804-B622A1EF5492}
[2011/03/21 13:26:24 | 000,000,000 | —D | M] (DownloadHelper) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2011/03/21 13:26:24 | 000,000,000 | —D | M] (BidNip Toolbar) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\{BFB5F154-9212-46F3-B547-AC6106030A54}
[2011/03/21 13:26:24 | 000,000,000 | —D | M] (Adblock Plus) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2011/03/21 13:26:25 | 000,000,000 | —D | M] (Extended Statusbar) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\{daf44bf7-a45e-4450-979c-91cf07434c3d}
[2011/03/21 13:26:26 | 000,000,000 | —D | M] (DownThemAll!) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2011/03/21 13:26:29 | 000,000,000 | —D | M] (FoxTab) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\{ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}
[2011/03/21 13:28:33 | 000,000,000 | —D | M] (FoxLingo) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\{ef62e1ce-d2a4-4cdd-b7ec-92b120366b66}
[2011/03/21 13:26:45 | 000,000,000 | —D | M] (Download Manager Tweak) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\{F8A55C97-3DB6-4961-A81D-0DE0080E53CB}
[2011/03/21 13:26:46 | 000,000,000 | —D | M] ("MultirowBookmarksToolbar") – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\{FBF6D7FB-F305-4445-BB3D-FEF66579A033}
[2011/03/21 13:25:58 | 000,000,000 | —D | M] (United States English Spellchecker) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\[removed]
[2011/03/21 13:26:00 | 000,000,000 | —D | M] (Extension List Dumper) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\[removed]
[2011/03/21 13:26:02 | 000,000,000 | —D | M] (Shareaholic) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\[removed]
[2011/03/21 13:26:02 | 000,000,000 | —D | M] (Get Mail Plus) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\[removed]
[2011/03/21 13:26:07 | 000,000,000 | —D | M] (IE Tab Plus) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\[removed]
[2011/03/21 13:26:07 | 000,000,000 | —D | M] (Noia 2.0 eXtreme OPT) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\[removed]
[2011/03/21 13:26:07 | 000,000,000 | —D | M] (Penguin) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\[removed]
[2011/03/21 13:26:07 | 000,000,000 | —D | M] (Personas) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\[removed]
[2011/03/21 13:26:08 | 000,000,000 | —D | M] (Splash) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\[removed]
[2011/03/21 13:26:12 | 000,000,000 | —D | M] (Torrent Finder Toolbar) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\TFToolbarX@torrent-finder
[2011/03/21 13:26:12 | 000,000,000 | —D | M] (Toggle Private Browsing) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\[removed]
[2011/03/21 13:25:58 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\[removed]\chrome
[2011/03/21 13:26:00 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\[removed]\defaults
[2011/03/21 13:26:00 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\[removed]\chrome
[2011/03/21 13:26:01 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\[removed]\defaults
[2011/03/11 22:48:50 | 000,002,470 | —- | M] () – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\searchplugins\safesearch.xml
[2011/03/21 13:22:02 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/03/12 22:00:37 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF

O1 HOSTS File: ([2008/06/09 23:45:48 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe (BillP Studios)
O4 - HKCU..\Run: [i8kfangui] C:\PROGRAM FILES\I8KFANGUI\I8KFANGUI.EXE (Christian Diefer)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [WallpaperChanger] C:\Program Files\Wallpaper Master\Wallpaper.exe (James Garton)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\REALTEK 11n USB Wireless LAN Utility.lnk = C:\Program Files\REALTEK\11n USB Wireless LAN Utility\RtWLan.exe (Realtek Semiconductor Corp.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoInternetOpenWith = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 02 F0 FF 03 [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: StartMenuLogOff = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMBalloonTip = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 0
O15 - HKCU\..Trusted Domains: microsoft.com ([office] http in Trusted sites)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: Microsoft XML Parser for Java Reg Error: Value error. (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\Documents and Settings\Gerry Goldshine\My Documents\My Pictures\Second Nature.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Gerry Goldshine\My Documents\My Pictures\Second Nature.bmp
O28 - HKLM ShellExecuteHooks: {097F10A7-487F-4457-AB1F-827C59479A72} - Reg Error: Key error. File not found
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/07/31 05:39:16 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - C:\WINDOWS\System32\iprip.dll (Microsoft Corporation)
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: UxTuneUp - C:\WINDOWS\System32\uxtuneup.dll (TuneUp Software GmbH)
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.ac3acm - C:\WINDOWS\System32\AC3ACM.acm (fccHandler)
Drivers32: msacm.ac3filter - C:\WINDOWS\System32\ac3filter.acm ()
Drivers32: msacm.alf2cd - C:\WINDOWS\System32\alf2cd.acm (NCT Company)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.scg726 - C:\WINDOWS\System32\Scg726.acm (SHARP Corporation)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: msacm.voxacm160 - C:\WINDOWS\System32\vct3216.acm (Voxware, Inc.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\divx.dll (DivXNetworks, Inc.)
Drivers32: vidc.dvsd - C:\WINDOWS\System32\mcdvd_32.dll (MainConcept)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.xvid - C:\WINDOWS\System32\xvidvfw.dll ()

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (56027131116781568)

========== Files/Folders - Created Within 30 Days ==========

[2011/03/21 13:22:09 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox
[2011/03/21 13:21:59 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2011/03/21 12:44:54 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Gerry Goldshine\Recent
[2011/03/18 23:11:33 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Gerry Goldshine\Desktop\OTL.exe
[2011/03/17 19:45:52 | 000,000,000 | —D | C] – C:\Documents and Settings\Gerry Goldshine\My Documents\HIJack This Logs
[2011/03/12 23:11:07 | 000,000,000 | —D | C] – C:\Program Files\Ask.com
[2011/03/12 22:01:44 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2011/03/12 22:01:04 | 000,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2011/03/12 22:01:02 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/03/12 22:01:02 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/03/12 22:01:02 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2011/03/12 21:54:15 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\CCleaner
[2011/03/12 20:43:09 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Zoner Photo Studio 12
[2011/03/12 20:42:44 | 000,000,000 | —D | C] – C:\Program Files\Zoner
[2011/03/11 00:13:04 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Bullzip
[2011/03/11 00:13:02 | 000,103,424 | —- | C] (Bullzip) – C:\WINDOWS\System32\bzDCT.dll
[2011/03/11 00:13:02 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Bullzip
[2011/03/11 00:13:01 | 000,227,840 | —- | C] (Bullzip) – C:\WINDOWS\System32\bzFlRdr.dll
[2011/03/11 00:13:01 | 000,135,168 | —- | C] (Bullzip) – C:\WINDOWS\System32\bzpdfc.dll
[2011/03/11 00:12:53 | 000,196,096 | —- | C] (Bullzip) – C:\WINDOWS\System32\bzpdf.dll
[2011/03/11 00:12:45 | 000,000,000 | —D | C] – C:\Program Files\Bullzip
[2011/03/11 00:10:07 | 000,000,000 | —D | C] – C:\Documents and Settings\Gerry Goldshine\Local Settings\Application Data\Tracker Software
[2011/03/11 00:06:50 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Tracker Software
[2011/03/11 00:04:22 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\PDF-XChange PDF Viewer
[2011/03/11 00:04:05 | 000,000,000 | —D | C] – C:\Program Files\Tracker Software
[2011/03/09 13:37:46 | 000,000,000 | —D | C] – C:\Documents and Settings\Gerry Goldshine\Local Settings\Application Data\VS Revo Group
[2011/03/09 13:37:06 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Revo Uninstaller Pro
[2011/03/09 13:37:04 | 000,027,064 | —- | C] (VS Revo Group) – C:\WINDOWS\System32\drivers\revoflt.sys
[2011/03/07 17:21:12 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Avery Dennison
[2011/03/07 17:20:04 | 000,000,000 | —D | C] – C:\Program Files\Avery Dennison
[2011/03/07 17:19:04 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Avery
[2011/03/05 14:39:40 | 000,323,624 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wiaaut.dll
[2011/03/01 04:29:15 | 000,000,000 | —D | C] – C:\Program Files\Stardock
[2011/03/01 04:24:11 | 000,000,000 | —D | C] – C:\Documents and Settings\Gerry Goldshine\Application Data\KeePass
[2011/03/01 04:16:03 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\KeePass Password Safe
[2011/03/01 04:16:01 | 000,000,000 | —D | C] – C:\Program Files\KeePass Password Safe
[2011/03/01 03:28:45 | 000,000,000 | —D | C] – C:\Documents and Settings\Gerry Goldshine\My Documents\My Wallpapers
[2011/03/01 03:27:49 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Wallpaper Master
[2011/03/01 03:27:47 | 000,000,000 | —D | C] – C:\Program Files\Wallpaper Master
[2011/03/01 03:19:44 | 000,000,000 | —D | C] – C:\Documents and Settings\Gerry Goldshine\Local Settings\Application Data\johnsadventures.com
[2011/03/01 03:14:09 | 000,000,000 | —D | C] – C:\Documents and Settings\Gerry Goldshine\Application Data\johnsadventures.com
[2011/03/01 02:56:55 | 000,000,000 | —D | C] – C:\Documents and Settings\Gerry Goldshine\Application Data\XnView
[2011/03/01 02:55:36 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\XnView
[2011/03/01 02:55:18 | 000,000,000 | —D | C] – C:\Program Files\XnView
[2011/03/01 02:32:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Gerry Goldshine\My Documents\ZPS12
[2011/03/01 02:19:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Gerry Goldshine\Application Data\Zoner
[2011/03/01 02:19:45 | 000,000,000 | —D | C] – C:\Documents and Settings\Gerry Goldshine\Local Settings\Application Data\Zoner
[2011/02/27 11:26:35 | 000,000,000 | —D | C] – C:\Documents and Settings\Gerry Goldshine\Local Settings\Application Data\Deployment
[2011/02/19 23:02:29 | 000,000,000 | —D | C] – C:\Documents and Settings\Gerry Goldshine\Local Settings\Application Data\Logishrd
[2011/02/19 22:37:44 | 000,010,448 | —- | C] (Logitech, Inc.) – C:\WINDOWS\System32\drivers\LBeepKE.sys
[86 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[46 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/03/21 13:22:09 | 000,001,620 | —- | M] () – C:\Documents and Settings\Gerry Goldshine\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/03/21 13:22:09 | 000,001,602 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/03/21 12:55:03 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\Auslogics BoostSpeed Integrator Start On Gerry Goldshine Logon.job
[2011/03/21 12:46:22 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/03/21 12:46:20 | 536,375,296 | -HS- | M] () – C:\hiberfil.sys
[2011/03/19 21:11:02 | 000,000,774 | —- | M] () – C:\Documents and Settings\Gerry Goldshine\Desktop\MozBackup.lnk
[2011/03/19 19:09:14 | 000,001,883 | —- | M] () – C:\Documents and Settings\Gerry Goldshine\Desktop\OTL Scan.rtf
[2011/03/18 23:11:41 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Gerry Goldshine\Desktop\OTL.exe
[2011/03/17 17:00:26 | 000,000,552 | —- | M] () – C:\WINDOWS\System32\d3d8caps.dat
[2011/03/17 15:08:04 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/03/13 16:52:57 | 000,503,788 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/03/13 16:52:57 | 000,089,424 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/03/13 01:46:53 | 000,002,515 | —- | M] () – C:\Documents and Settings\Gerry Goldshine\Desktop\Microsoft Word 2007.lnk
[2011/03/12 22:22:13 | 000,001,686 | —- | M] () – C:\Documents and Settings\Gerry Goldshine\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Thunderbird.lnk
[2011/03/12 22:22:13 | 000,001,668 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Thunderbird.lnk
[2011/03/12 22:06:59 | 000,000,812 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Paint.NET.lnk
[2011/03/12 22:00:33 | 000,157,472 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/03/12 22:00:33 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/03/12 22:00:32 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2011/03/12 22:00:32 | 000,073,728 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2011/03/12 22:00:31 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2011/03/12 21:54:15 | 000,000,682 | —- | M] () – C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2011/03/12 20:43:12 | 000,001,688 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Zoner Photo Studio 12.lnk
[2011/03/11 00:13:04 | 000,000,698 | —- | M] () – C:\Documents and Settings\Gerry Goldshine\Desktop\Bullzip PDF Printer.lnk
[2011/03/11 00:09:37 | 000,000,776 | —- | M] () – C:\Documents and Settings\Gerry Goldshine\Desktop\PDF-Viewer.lnk
[2011/03/09 13:37:08 | 000,000,925 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Revo Uninstaller Pro.lnk
[2011/03/07 20:07:15 | 000,516,152 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/03/07 19:53:30 | 000,001,993 | —- | M] () – C:\Documents and Settings\Gerry Goldshine\Desktop\DesignPro 5.4 Limited Edition.lnk
[2011/03/07 01:12:29 | 000,167,580 | —- | M] () – C:\WINDOWS\hphins33.dat
[2011/03/05 14:39:40 | 000,323,624 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\wiaaut.dll
[2011/03/01 04:16:04 | 000,000,688 | —- | M] () – C:\Documents and Settings\Gerry Goldshine\Desktop\KeePass.lnk
[2011/03/01 02:57:28 | 000,000,606 | —- | M] () – C:\Documents and Settings\Gerry Goldshine\Desktop\XnView.lnk
[2011/02/19 22:38:43 | 000,016,400 | —- | M] (Logitech, Inc.) – C:\WINDOWS\System32\drivers\LNonPnP.sys
[86 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[46 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/03/21 13:22:09 | 000,001,620 | —- | C] () – C:\Documents and Settings\Gerry Goldshine\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/03/21 13:22:09 | 000,001,602 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/03/19 21:11:02 | 000,000,774 | —- | C] () – C:\Documents and Settings\Gerry Goldshine\Desktop\MozBackup.lnk
[2011/03/19 19:25:01 | 536,375,296 | -HS- | C] () – C:\hiberfil.sys
[2011/03/19 19:09:14 | 000,001,883 | —- | C] () – C:\Documents and Settings\Gerry Goldshine\Desktop\OTL Scan.rtf
[2011/03/17 17:00:26 | 000,000,552 | —- | C] () – C:\WINDOWS\System32\d3d8caps.dat
[2011/03/12 22:06:59 | 000,000,818 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Paint.NET.lnk
[2011/03/12 20:43:12 | 000,001,688 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Zoner Photo Studio 12.lnk
[2011/03/11 00:13:04 | 000,000,698 | —- | C] () – C:\Documents and Settings\Gerry Goldshine\Desktop\Bullzip PDF Printer.lnk
[2011/03/11 00:04:24 | 000,000,776 | —- | C] () – C:\Documents and Settings\Gerry Goldshine\Desktop\PDF-Viewer.lnk
[2011/03/09 13:37:08 | 000,000,925 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Revo Uninstaller Pro.lnk
[2011/03/07 19:53:30 | 000,001,993 | —- | C] () – C:\Documents and Settings\Gerry Goldshine\Desktop\DesignPro 5.4 Limited Edition.lnk
[2011/03/05 11:16:26 | 000,001,924 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\REALTEK 11n USB Wireless LAN Utility.lnk
[2011/03/01 04:16:04 | 000,000,688 | —- | C] () – C:\Documents and Settings\Gerry Goldshine\Desktop\KeePass.lnk
[2011/03/01 02:55:38 | 000,000,606 | —- | C] () – C:\Documents and Settings\Gerry Goldshine\Desktop\XnView.lnk
[2010/11/10 03:29:37 | 000,224,632 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/11/02 15:44:09 | 000,451,072 | —- | C] () – C:\WINDOWS\System32\ISSRemoveSP.exe
[2010/06/21 15:44:17 | 000,077,853 | —- | C] () – C:\WINDOWS\hpqins05.dat
[2010/06/21 15:27:13 | 000,136,083 | —- | C] () – C:\WINDOWS\hphins33.dat.temp
[2010/06/21 15:27:13 | 000,000,512 | —- | C] () – C:\WINDOWS\hphmdl33.dat.temp
[2010/06/05 12:18:09 | 000,167,580 | —- | C] () – C:\WINDOWS\hphins33.dat
[2010/06/05 12:18:09 | 000,000,512 | —- | C] () – C:\WINDOWS\hphmdl33.dat
[2010/01/02 16:56:00 | 000,696,832 | —- | C] () – C:\WINDOWS\is-QIMO8.exe
[2008/06/16 20:02:52 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\swunilog.ini
[2008/06/12 10:41:46 | 000,004,096 | —- | C] () – C:\WINDOWS\d3dx.dat
[2008/04/10 19:23:56 | 000,162,304 | —- | C] () – C:\WINDOWS\System32\ztvunrar36.dll
[2008/04/10 19:23:56 | 000,077,312 | —- | C] () – C:\WINDOWS\System32\ztvunace26.dll
[2008/04/10 11:06:08 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\IPPCPUID.DLL
[2008/04/10 11:05:30 | 000,011,776 | —- | C] () – C:\WINDOWS\System32\pmsbfn32.dll
[2007/09/04 20:09:39 | 000,000,000 | —- | C] () – C:\WINDOWS\OpPrintServer.INI
[2007/09/04 20:05:32 | 000,007,680 | —- | C] () – C:\WINDOWS\System32\CNMVS5y.DLL
[2007/08/24 14:43:32 | 000,000,488 | —- | C] () – C:\WINDOWS\cmousecc.ini
[2007/06/18 18:55:17 | 000,000,058 | —- | C] () – C:\WINDOWS\System32\EAL32.INI
[2007/06/18 13:23:32 | 000,001,759 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/05/29 03:54:38 | 000,000,025 | —- | C] () – C:\WINDOWS\brassi.dat
[2007/05/27 04:29:47 | 000,000,214 | —- | C] () – C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2007/05/27 04:15:14 | 000,093,392 | —- | C] () – C:\WINDOWS\HPHins03.dat
[2007/05/27 04:15:14 | 000,002,655 | —- | C] () – C:\WINDOWS\hphmdl03.dat
[2007/05/24 18:05:09 | 000,000,140 | —- | C] () – C:\WINDOWS\ChssBase.ini
[2007/05/24 17:46:47 | 000,000,000 | —- | C] () – C:\WINDOWS\SETUP32.INI
[2007/05/24 17:37:48 | 000,000,053 | —- | C] () – C:\WINDOWS\WININIT.INI
[2007/04/06 01:57:06 | 000,156,160 | —- | C] () – C:\WINDOWS\System32\unrar3.dll
[2007/04/06 01:57:06 | 000,075,264 | —- | C] () – C:\WINDOWS\System32\unacev2.dll
[2007/01/25 23:45:02 | 000,006,784 | —- | C] () – C:\WINDOWS\System32\drivers\whfltr2k.sys
[2006/12/06 22:19:41 | 000,684,032 | —- | C] () – C:\WINDOWS\System32\libeay32.dll
[2006/12/06 22:19:41 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\ssleay32.dll
[2006/09/14 03:45:19 | 000,000,032 | —- | C] () – C:\WINDOWS\System32\thxcfg.ini
[2006/08/28 03:32:31 | 000,000,026 | —- | C] () – C:\WINDOWS\DfrgUIEx.INI
[2006/08/28 01:35:27 | 000,000,000 | —- | C] () – C:\WINDOWS\msicpl.ini
[2006/08/23 14:49:31 | 000,000,025 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2006/08/22 21:51:01 | 000,034,308 | —- | C] () – C:\WINDOWS\System32\BASSMOD.dll
[2006/08/09 02:00:52 | 000,176,128 | —- | C] () – C:\Documents and Settings\Gerry Goldshine\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/08/06 01:27:07 | 000,524,288 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2006/08/06 01:27:07 | 000,139,264 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2006/08/05 23:47:33 | 000,004,212 | -H– | C] () – C:\WINDOWS\System32\zllictbl.dat
[2006/08/02 00:45:29 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/08/01 21:53:52 | 000,001,218 | —- | C] () – C:\WINDOWS\Slideshw.ini
[2006/08/01 15:04:41 | 000,000,064 | —- | C] () – C:\WINDOWS\init.ini
[2006/07/31 08:40:32 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2006/07/31 08:39:42 | 000,007,107 | —- | C] () – C:\WINDOWS\mozver.dat
[2006/07/31 07:06:52 | 000,684,032 | —- | C] () – C:\WINDOWS\libeay32.dll
[2006/07/31 07:06:52 | 000,155,648 | —- | C] () – C:\WINDOWS\ssleay32.dll
[2006/07/31 05:46:34 | 000,006,550 | —- | C] () – C:\WINDOWS\jautoexp.dat
[2006/07/31 05:42:05 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2006/07/31 05:36:05 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2006/07/30 22:14:53 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2006/07/30 22:13:54 | 000,516,152 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2006/07/30 22:13:14 | 000,000,211 | —- | C] () – C:\WINDOWS\System32\BOOTBAK.INI
[2006/05/25 07:02:46 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\unwlsdrv.exe
[2004/08/02 14:20:40 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/04/26 08:38:20 | 000,006,885 | —- | C] () – C:\WINDOWS\System32\drivers\whmice2k.sys
[2002/12/05 18:51:00 | 000,059,392 | R— | C] () – C:\WINDOWS\System32\streamhlp.dll
[2002/03/14 12:00:26 | 000,038,567 | —- | C] () – C:\WINDOWS\System32\pcpbios.exe
[2001/08/18 05:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2001/08/18 05:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2001/08/18 05:00:00 | 000,503,788 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2001/08/18 05:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2001/08/18 05:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2001/08/18 05:00:00 | 000,089,424 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2001/08/18 05:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2001/08/18 05:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2001/08/18 05:00:00 | 000,004,594 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2001/08/18 05:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2001/08/18 05:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[1998/08/16 05:00:00 | 000,004,096 | —- | C] () – C:\WINDOWS\System32\sysres.dll

========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2006/07/31 05:39:16 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2006/09/01 02:19:39 | 000,000,205 | -HS- | M] () – C:\boot.ini
[2006/08/11 11:06:42 | 000,000,046 | —- | M] () – C:\CONFIG.SYS
[2008/06/16 10:45:22 | 000,000,397 | —- | M] () – C:\DownloadLog.txt
[2006/08/29 20:02:18 | 000,013,090 | —- | M] () – C:\drwtsn32.log
[2011/03/21 12:46:20 | 536,375,296 | -HS- | M] () – C:\hiberfil.sys
[2007/11/05 18:17:31 | 000,000,164 | —- | M] () – C:\install.dat
[2006/07/31 05:39:16 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2006/07/31 05:39:16 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2006/07/31 06:04:16 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2009/05/26 19:33:17 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/03/21 12:46:07 | 804,458,496 | -HS- | M] () – C:\pagefile.sys
[2008/06/17 20:07:59 | 000,000,150 | —- | M] () – C:\YServer.txt

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/07/31 05:38:36 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2004/04/22 22:00:00 | 000,017,920 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD5y.DLL
[2006/09/12 22:00:00 | 000,027,136 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD7Q.DLL
[2004/04/22 22:00:00 | 000,054,272 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP5y.DLL
[2006/09/12 22:00:00 | 000,069,632 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP7Q.DLL
[2008/07/06 05:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2009/04/16 14:08:20 | 000,312,832 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpfpp70v.dll
[2007/04/09 13:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 03:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2011/01/13 01:47:35 | 000,038,848 | —- | M] (AVAST Software) – C:\WINDOWS\avastSS.scr
[2007/05/29 03:54:37 | 000,672,256 | —- | M] ( Remco de Korte / Onwijs) – C:\WINDOWS\dogfight.scr
[2006/01/30 12:11:50 | 000,135,168 | —- | M] (Second Nature Software) – C:\WINDOWS\SNSVR.scr
[1996/10/07 17:38:34 | 000,420,576 | —- | M] () – C:\WINDOWS\voyager.scr
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >
[2007/08/25 08:26:11 | 000,001,610 | -H– | M] () – C:\Documents and Settings\Gerry Goldshine\Application Data\Microsoft\LastFlashConfig.WFC

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2006/07/30 22:13:13 | 000,090,112 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2006/07/30 22:13:13 | 000,606,208 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2006/07/30 22:13:13 | 000,393,216 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2009/05/26 19:44:20 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2006/07/31 06:19:46 | 000,000,177 | -HS- | M] () – C:\Documents and Settings\Gerry Goldshine\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2006/07/31 05:46:54 | 000,000,079 | —- | M] () – C:\Documents and Settings\Gerry Goldshine\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2011/03/18 23:11:41 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Gerry Goldshine\desktop\OTL.exe
[2011/01/20 16:41:54 | 000,476,040 | —- | M] (SpeedyFox) – C:\Documents and Settings\Gerry Goldshine\desktop\speedyfox.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
"NoAutoRebootWithLoggedOnUsers" = 0

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-03-09 18:03:34

========== Alternate Data Streams ==========

@Alternate Data Stream - 95 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
@Alternate Data Stream - 131 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:07BF512B
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1CA73D29

< End of report >

Here is the Extras Text:

OTL Extras logfile created on: 3/21/2011 4:35:14 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Gerry Goldshine\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

511.00 Mb Total Physical Memory | 226.00 Mb Available Physical Memory | 44.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 75.00% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55.89 Gb Total Space | 34.38 Gb Free Space | 61.51% Space Free | Partition Type: NTFS

Computer Name: SAL-9000 | User Name: Gerry Goldshine | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.chm [@ = chmfile] – Reg Error: Key error. File not found
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = Reg Error: Value error.] – Reg Error: Key error. File not found

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
http [open] – Reg Error: Key error.
https [open] – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" %*
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Digital Photo Professional] – C:\Program Files\Canon\Digital Photo Professional\DPPViewer.exe /path "%1" (CANON INC.)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"FirewallDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"21177:TCP" = 21177:TCP:*:Enabled:BitComet 21177 TCP
"21177:UDP" = 21177:UDP:*:Enabled:BitComet 21177 UDP
"1542:TCP" = 1542:TCP:*:Enabled:Realtek WPS TCP Prot
"1542:UDP" = 1542:UDP:*:Enabled:Realtek WPS UDP Prot
"53:UDP" = 53:UDP:*:Enabled:Realtek AP UDP Prot

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe:*:Enabled:hpqgplgtupl.exe – (Hewlett-Packard Co.)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent – (BitTorrent, Inc.)
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe:*:Enabled:hpqgplgtupl.exe – (Hewlett-Packard Co.)
"C:\Program Files\REALTEK\11n USB Wireless LAN Utility\RtWLan.exe" = C:\Program Files\REALTEK\11n USB Wireless LAN Utility\RtWLan.exe:*:Enabled:RtWlan – (Realtek Semiconductor Corp.)
"C:\Program Files\D4\D4.exe" = C:\Program Files\D4\D4.exe:*:Enabled:Dimension 4 – (Thinking Man Software)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{007811BF-E310-4285-BFC6-55DB29B3EDDE}" = WinPatrol
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{0D25F7CC-B99C-44ee-9945-B14532B2BB7B}" = Canon MP830
"{0F9196C6-58B4-445B-B56E-B1200FECC151}" = Microsoft Bootvis
"{150B6201-E9E6-4DFB-960E-CCBD53FBDDED}" = HPProductAssistant
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{26A24AE4-039D-4CA4-87B4-2F83216024FF}" = Java™ 6 Update 24
"{292F0F52-B62D-4E71-921B-89A682402201}" = Toolbox
"{343A1706-26A4-45EA-88CF-37CA172B0F27}" = D1600
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = eReg
"{46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB}" = Adobe AIR
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{58F9D852-9443-4955-A1ED-12C9E0504DD0}" = Mavis Beacon Teaches Typing Platinum 20
"{5DCF0E4B-F8EA-4229-A0BD-5CA6D4AFB749}" = SolutionCenter
"{601BE80D-247B-4084-94C7-7A54369DB7A2}" = Hallmark Card Studio 2010 Deluxe
"{60FFB3E0-6D5B-4D73-AE5B-07E58B83AF0C}" = 32 Bit HP CIO Components Installer
"{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1" = Revo Uninstaller Pro 2.5.1
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{71F6DF7D-B639-4FAD-BA93-E6DF267AA44D}" = DesignPro 5.4 Limited Edition
"{7216871F-869E-437C-B9BF-2A13F2DCE63F}_is1" = Auslogics BoostSpeed
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A5F34E2-37CF-4AD4-808C-2D413786E31A}" = Microsoft Visual C Runtime
"{8D273DE5-ABFA-4BD0-A9D7-EE9C971438C4}_is1" = PDF-Viewer
"{8EE94FD8-5F52-4463-A340-185D16328158}" = WebReg
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90170409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office FrontPage 2003
"{90520409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Visio Viewer 2003 (English)
"{90AF0409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office PowerPoint Viewer 2003
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{935FF092-EEBA-4E97-8C1B-CD2364F392A4}" = Dimension 4 v5.0
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9C049499-055C-4a0c-A916-1D8CA1FF45EB}" = REALTEK Wireless LAN Driver and Utility
"{9CF4A37B-A8C4-44D7-8C53-13B9D9594BB2}" = Paint.NET v3.5.8
"{A278382D-4F1B-4D47-9885-8523F7261E8D}_is1" = PDF-Viewer
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A4D77A09-10EA-4574-8C09-9B6E1A21C95F}" = Virus Guard - powered by BitDefender
"{B2395631-54D5-481E-B9A8-74B269546F40}" = Visual C++ CRT 8.0
"{BB3447F6-9553-4AA9-960E-0DB5310C5779}" = GPBaseService2
"{BD3DCAB0-3FE5-44FB-90DA-EFB0A2CD1387}" = Works Synchronization
"{BD7FE1BA-8766-45FA-BB05-CC014B00DFA7}" = Access Conversion Toolkit
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C3B95659-26C3-4448-8891-5E713F978F74}" = Texas Hold 'Em: High Stakes Poker
"{C9B2F671-870B-43A0-8B9D-7DB30CEBD87E}" = DJ_SF_06_D1600_SW_Min
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D78653C3-A8FF-415F-92E6-D774E634FF2D}" = Dell ResourceCD
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{DC19E750-988B-4005-A355-85EF66055EFE}" = Works Suite OS Pack
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{EEC2DAFD-5558-40AC-8E9C-5005C8F810E8}" = Microsoft Plus! for Windows XP
"{FA0FF682-CC70-4C57-93CD-E276F3E7537E}" = BufferChm
"4UOnly_is1" = 4UOnly 1.2.7
"7-Zip" = 7-Zip 9.20
"AC3Filter" = AC3Filter (remove only)
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Audacity 1.3 Beta (Unicode)_is1" = Audacity 1.3.3 (Unicode)
"avast5" = avast! Free Antivirus
"Branding" =
"Bullzip PDF Printer_is1" = Bullzip PDF Printer 7.1.0.1218
"CANON iMAGE GATEWAY Task" = CANON iMAGE GATEWAY Task for ZoomBrowser EX
"Canon Internet Library for ZoomBrowser EX" = Canon Internet Library for ZoomBrowser EX
"Canon MOV Decoder" = Canon MOV Decoder
"Canon MOV Encoder" = Canon MOV Encoder
"Canon MP830 User Registration" = Canon MP830 User Registration
"CCleaner" = CCleaner
"Connection Manager" =
"DPP" = Canon Utilities Digital Photo Professional 3.8
"drmtool.inf" = Personal License Update Wizard for Windows Media Player
"Easy-PhotoPrint" = Canon Utilities Easy-PhotoPrint
"ENTERPRISE" = Microsoft Office Enterprise 2007
"EOS Utility" = Canon Utilities EOS Utility
"filehippo.com" = FileHippo.com Update Checker
"Free Futurama Screensaver_is1" = Free Futurama Screensaver 1.0
"GPL Ghostscript 9.00" = GPL Ghostscript 9.00
"HP Solution Center & Imaging Support Tools" = HP Solution Center 14.0
"I8kfanGUI" = I8kfanGUI V3.1
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"InstallShield_{71F6DF7D-B639-4FAD-BA93-E6DF267AA44D}" = DesignPro 5.4 Limited Edition
"IrfanView" = IrfanView (remove only)
"KC Softwares SUMo_is1" = KC Softwares SUMo
"KeePass Password Safe_is1" = KeePass Password Safe 1.18
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"mmmusic" = Movie Maker Background Music Files
"mmsounds" = Movie Maker Sound Effects
"mmtitle" = Movie Maker Title Images
"MovieEditTask" = Canon MovieEdit Task for ZoomBrowser EX
"Mozilla Firefox (3.6.15)" = Mozilla Firefox (3.6.15)
"Mozilla Thunderbird (3.1.9)" = Mozilla Thunderbird (3.1.9)
"MP Navigator 2.2" = Canon MP Navigator 2.2
"mpxptray.inf" = Windows Media Player Tray Control
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSI30a-KB884016" =
"MSI30-Beta1" =
"MSI30-Beta2" =
"MSI30-KB884016" =
"MSI30-RC1" =
"MSI30-RC2" =
"MSI31-Beta" =
"MSI31-RC1" =
"NetMeeting" =
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA" = NVIDIA Windows 2000/XP Display Drivers
"Original Data Security Tools" = Canon Utilities Original Data Security Tools
"PbWrdArt.exe" = Publisher WordArt Compatibility Add-In
"PCHealth" =
"PhotoStitch" = Canon Utilities PhotoStitch
"Picture Style Editor" = Canon Utilities Picture Style Editor
"Second Nature - The Ultimate Escape Sampler" = Second Nature - The Ultimate Escape Sampler
"Second Nature Screen Saver Update" = Second Nature Screen Saver Update
"SiS163u" = 802.11 USB Wireless LAN Adapter
"SpywareBlaster_is1" = SpywareBlaster 4.4
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"The KMPlayer" = The KMPlayer (remove only)
"uTorrent" = µTorrent
"wa2wmp" = Windows Media Player Skin Importer
"Wallpaper Master_is1" = Wallpaper Master v2.16
"Wdf01009" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
"WFTK" = Canon Utilities WFT Utility
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinPatrol" = WinPatrol
"WMBK2" = Windows Media Bonus Pack for Windows XP
"WMCSetup" = Windows Media Connect
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XnView_is1" = XnView 1.97.8
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"ZonerPhotoStudio12_EN_is1" = Zoner Photo Studio 12
"ZoomBrowser EX" = Canon Utilities ZoomBrowser EX
"ZoomBrowser EX Memory Card Utility" = Canon ZoomBrowser EX Memory Card Utility

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Facebook Plug-In" = Facebook Plug-In
"uTorrent" = µTorrent

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 3/17/2011 6:08:23 PM | Computer Name = SAL-9000 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 3/17/2011 6:08:24 PM | Computer Name = SAL-9000 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 3/17/2011 6:08:31 PM | Computer Name = SAL-9000 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 3/17/2011 6:08:32 PM | Computer Name = SAL-9000 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 3/17/2011 6:08:33 PM | Computer Name = SAL-9000 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 3/17/2011 6:08:42 PM | Computer Name = SAL-9000 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The server name or address could not be resolved

Error - 3/17/2011 6:08:48 PM | Computer Name = SAL-9000 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 3/17/2011 6:08:50 PM | Computer Name = SAL-9000 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 3/17/2011 6:10:22 PM | Computer Name = SAL-9000 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.

Error - 3/17/2011 6:10:22 PM | Computer Name = SAL-9000 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.

[ System Events ]
Error - 3/21/2011 3:48:45 PM | Computer Name = SAL-9000 | Source = Service Control Manager | ID = 7001
Description = The Remote Access Connection Manager service depends on the Telephony
service which failed to start because of the following error: %%1058

Error - 3/21/2011 4:02:09 PM | Computer Name = SAL-9000 | Source = Service Control Manager | ID = 7001
Description = The Remote Access Connection Manager service depends on the Telephony
service which failed to start because of the following error: %%1058

Error - 3/21/2011 7:28:43 PM | Computer Name = SAL-9000 | Source = Service Control Manager | ID = 7001
Description = The Remote Access Connection Manager service depends on the Telephony
service which failed to start because of the following error: %%1058

Error - 3/21/2011 7:28:52 PM | Computer Name = SAL-9000 | Source = Service Control Manager | ID = 7001
Description = The Remote Access Connection Manager service depends on the Telephony
service which failed to start because of the following error: %%1058

Error - 3/21/2011 7:28:53 PM | Computer Name = SAL-9000 | Source = Service Control Manager | ID = 7001
Description = The Remote Access Connection Manager service depends on the Telephony
service which failed to start because of the following error: %%1058

Error - 3/21/2011 7:28:54 PM | Computer Name = SAL-9000 | Source = Service Control Manager | ID = 7001
Description = The Remote Access Connection Manager service depends on the Telephony
service which failed to start because of the following error: %%1058

Error - 3/21/2011 7:28:55 PM | Computer Name = SAL-9000 | Source = Service Control Manager | ID = 7001
Description = The Remote Access Connection Manager service depends on the Telephony
service which failed to start because of the following error: %%1058

Error - 3/21/2011 7:28:56 PM | Computer Name = SAL-9000 | Source = Service Control Manager | ID = 7001
Description = The Remote Access Connection Manager service depends on the Telephony
service which failed to start because of the following error: %%1058

Error - 3/21/2011 7:28:57 PM | Computer Name = SAL-9000 | Source = Service Control Manager | ID = 7001
Description = The Remote Access Connection Manager service depends on the Telephony
service which failed to start because of the following error: %%1058

Error - 3/21/2011 7:29:05 PM | Computer Name = SAL-9000 | Source = Service Control Manager | ID = 7001
Description = The Remote Access Connection Manager service depends on the Telephony
service which failed to start because of the following error: %%1058


< End of report >
I'm glad you were able to get the OTL scan.

First, let's see if we can't get rid of the Ask toolbar that's been so persistant.

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    :OTL
    IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
    O28 - HKLM ShellExecuteHooks: {097F10A7-487F-4457-AB1F-827C59479A72} - Reg Error: Key error. File not found
    
    :Commands
    [purity]
    [emptytemp]
    [emptyflash]
    [createrestorepoint]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post the resulting OTL log


When you scanned with Malwarebytes, can you please confirm that you did indeed update the definitions prior to the scan?


I'm not seeing anything in the way of malware, but let's do a couple more things and see if things improve any -

Download ATF Cleaner by Atribune.
Note: Close all browsers before running ATF Cleaner: IE, FireFox, etc.

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

If you use Firefox browser

Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.


This scan can take awhile so you may wish to set it up to run at night or at a time when you won't be using the machine:

http://www.eset.eu/online-scanner
Go here to run an online scannner from ESET.
Click the green ESET Online Scanner button.
Read the End User License Agreement and check the box: YES, I accept the Terms of Use.
Click on the Start button next to it.
You may receive an alert on the address bar that "This site might require the following ActiveX control…Click here to install…". Click on that alert and then click Insall ActiveX component.
A new window will appear asking "Do you want to install this software?"".
Answer Yes to download and install the ActiveX controls that allows the scan to run.
Click Start.
Check Remove found threats and Scan potentially unwanted applications.
Click Scan to begin.
If offered the option to get information or buy software. Just close the window.
Wait for the scan to finish
Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
Copy and paste that log as a reply to this topic.


Let me know if there is any improvement in the performance at this point.
Hello Doris; I've used both CCleaner and Auslogics BoostSpeed to clean out all the junk files on a regular basis, so ATF didn't do much of anything. I ran the most recent data base with Malwarebytes and SuperAntiSpyware plus I have SpywareBlaster up to date. I was able to remove the Ask Toolbar after I performed the Firefox reinstallation. That seemed to help with several related issues. However, I can still hear the HD churning away. BTW, I did run some checks on the HD, which is only a year old, and it appears to be functioning fine, mechanically. You didn't say whether I should paste the custom scan again before running UTL. I also have a link to Virus.org, where you can run multiple virus checkers in on scan. I've tried it on some single files with good results but never done a whole drive. Let me know if you think that might be a worthwhile option. I'm also wondering if the performance issue may be coming down to the fact that this is an old system and the newer programs are just getting beyond its ability to run them efficiently. Aside from coming across an exceptional bargain, that is one of the reasons I bought a new laptop in th e first place. I'll post the results of the ESET scan tomorrow. Many thanks again for all your efforts. Gerry I will run the ESET scan ESET came back negative for anything.
The only thing you need to paste into the Custom Scans/Fixes box is the text inside the box in my last instructions. That will remove a few remnants of the Ask bar.

I do want you to run the ESET scan, but I'm not expecting it to find anything of major concern. It will be the last scan you'll need to run unless it shows something unexpected.

It's obvious you keep your machine well protected and as free from malware as possible. 512MB of RAM is really on the very low end of things these days. If you wanted to make a small investment in RAM (which is really pretty cheap nowadays) you could put another 512 in and you'd probably see an improvement. With an older machine, there is only going to be so much you can do to speed it up.

CCleaner has a good utility for looking at and disabling some unnecessary startup items, as does WinPatrol. You might want to take a look at and disable anything that you know you don't need. Obviously, some items must run at startup so if you aren't sure of them you should leave them alone, but many things can safely be disabled at startup. They will still run when they are needed.

AVG is also pretty memory intensive and has a propensity for slowing things down. With AVG, if your scan is set to run at startup, or to scan immediately when starting after a missed scan, you may be finding it is interfering with your booting and running of programs for quite a bit after startup. On a newer machine with multiple cores and lots of RAM you'd probably never notice, but on an older machine it can be dramatic. Since you have SP3 installed you might want to consider removing AVG and installing Microsoft Security Essentials (MSE) as your antivirus solution. It's a little lighter on the resources and is less likely to bog your system down. It also scans when things are idle, vs. a predetermined scan like AVG.

Please post the OTL log after you've removed the Askbar remnants, and the results of the ESET scan and we can go from there.
Doris

First, I did finally get the Ask tooolbar to uninstall. The ESET scan came back negative for anything. I will take your suggestion and unistall avast! virus scan and use Windows Defender instead as again, this will no longer be my primary laptop for use. Here are the results of the UTL scan you requested:

OTL logfile created on: 3/23/2011 7:30:48 PM - Run 2
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Gerry Goldshine\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

511.00 Mb Total Physical Memory | 94.00 Mb Available Physical Memory | 18.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 67.00% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55.89 Gb Total Space | 28.79 Gb Free Space | 51.51% Space Free | Partition Type: NTFS

Computer Name: SAL-9000 | User Name: Gerry Goldshine | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Gerry Goldshine\desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe (BillP Studios)
PRC - C:\Program Files\REALTEK\11n USB Wireless LAN Utility\RtWLan.exe (Realtek Semiconductor Corp.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\I8kfanGUI\I8kfanGUI.exe (Christian Diefer)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Gerry Goldshine\desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\Alwil Software\Avast5\snxhk.dll (AVAST Software)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\BillP Studios\WinPatrol\patrolpro.dll (BillP Studios)


========== Win32 Services (SafeList) ==========

SRV - (CachemanService) – File not found
SRV - (AppMgmt) – File not found
SRV - (AdobeActiveFileMonitor9.0) – File not found
SRV - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (spupdsvc) – C:\WINDOWS\system32\spupdsvc.exe (Microsoft Corporation)
SRV - (HP Port Resolver) – C:\WINDOWS\system32\hpbpro.exe (Hewlett-Packard Company)
SRV - (HP Status Server) – C:\WINDOWS\system32\hpboid.exe (Hewlett-Packard Company)


========== Driver Services (SafeList) ==========

DRV - (aswSP) – C:\WINDOWS\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswTdi) – C:\WINDOWS\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswMon2) – C:\WINDOWS\System32\drivers\aswmon2.sys (AVAST Software)
DRV - (aswRdr) – C:\WINDOWS\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (Aavmker4) – C:\WINDOWS\System32\drivers\aavmker4.sys (AVAST Software)
DRV - (aswFsBlk) – C:\WINDOWS\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (LMouFilt) – C:\WINDOWS\system32\drivers\LMouFilt.Sys (Logitech, Inc.)
DRV - (LHidFilt) – C:\WINDOWS\system32\drivers\LHidFilt.Sys (Logitech, Inc.)
DRV - (LBeepKE) – C:\WINDOWS\system32\drivers\LBeepKE.sys (Logitech, Inc.)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (ivusb) – C:\WINDOWS\system32\drivers\ivusb.sys (Initio Corporation)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (Revoflt) – C:\WINDOWS\system32\drivers\revoflt.sys (VS Revo Group)
DRV - (RTL8192su) – C:\WINDOWS\system32\drivers\rtl8192su.sys (Realtek Semiconductor Corporation )
DRV - (moufiltr) – C:\WINDOWS\system32\drivers\moufiltr.sys (Chic Tech.)
DRV - (fanio) – C:\WINDOWS\system32\drivers\fanio.sys (Christian Diefer)
DRV - (whfltr2k) – C:\WINDOWS\system32\drivers\whfltr2k.sys ()
DRV - (SIS163u) – C:\WINDOWS\system32\drivers\sis163u.sys (Silicon Integrated Systems Corp.)
DRV - (BCM43XX) – C:\WINDOWS\system32\drivers\BCMWL5.SYS (Broadcom Corporation)
DRV - (odysseyIM4) – C:\WINDOWS\system32\drivers\odysseyIM4.sys (Funk Software, Inc.)
DRV - (ZD1211U(CellVision)) TRENDnet 802.11g wireless USB TEW-424UB(CellVision) – C:\WINDOWS\system32\drivers\ZD1211U.sys (ZyDAS Technology Corporation)
DRV - (whmice2k) – C:\WINDOWS\system32\drivers\whmice2k.sys ()
DRV - (CBTNDIS5) – C:\WINDOWS\system32\CBTNDIS5.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (maestro) ESS Maestro Audio Driver (WDM) – C:\WINDOWS\system32\drivers\es198xdl.sys (ESS Technology, Inc.)
DRV - (WDHAALBA) – C:\WINDOWS\system32\drivers\WDHAALBA.sys (3Com Corporation)
DRV - (nv4) – C:\WINDOWS\system32\drivers\nv4.sys (NVIDIA Corporation)
DRV - (EL556ND5) – C:\WINDOWS\system32\drivers\EL556ND5.sys (3Com Corporation)
DRV - (OMCI) – C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS (Dell Computer Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://my.myway.com/index.jsp?speedbarconfigchanged
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://my.myway.com/index.jsp?speedbarconfigchanged"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:5.0.1
FF - prefs.js..extensions.enabledItems: [removed]:1.15.0
FF - prefs.js..extensions.enabledItems: [removed]:2.2.0
FF - prefs.js..extensions.enabledItems: [removed]:3.3.6
FF - prefs.js..extensions.enabledItems: [removed]:1.98.20110322
FF - prefs.js..extensions.enabledItems: [removed]:3.76
FF - prefs.js..extensions.enabledItems: [removed]:1.6.2
FF - prefs.js..extensions.enabledItems: [removed]:2.0.2c
FF - prefs.js..extensions.enabledItems: TFToolbarX@torrent-finder:1.2.6
FF - prefs.js..extensions.enabledItems: [removed]:1.8
FF - prefs.js..extensions.enabledItems: {03B08592-E5B4-45ff-A0BE-C1D975458688}:1.0
FF - prefs.js..extensions.enabledItems: {0538E3E3-7E9B-4d49-8831-A227C80A7AD3}:2.0.2
FF - prefs.js..extensions.enabledItems: {0fa2149e-bb2c-4ac2-a8d3-479599819475}:2.0.1
FF - prefs.js..extensions.enabledItems: {1018e4d6-728f-4b20-ad56-37578a4de76b}:4.1.1
FF - prefs.js..extensions.enabledItems: {19EB90DC-A456-458b-8AAC-616D91AAFCE1}:0.7
FF - prefs.js..extensions.enabledItems: {1cff04ef-0c75-4621-ba2a-2efb77346996}:2.3
FF - prefs.js..extensions.enabledItems: {2E481B23-66AC-313F-D6A8-A81DDDF26249}:1.0.20101216
FF - prefs.js..extensions.enabledItems: {6614d11d-d21d-b211-ae23-815234e1ebb5}:1.0.23
FF - prefs.js..extensions.enabledItems: {71C54606-83ED-4ea6-9315-1AAB29466D33}:3.1
FF - prefs.js..extensions.enabledItems: {8bc5b5eb-0ec4-46ed-a024-ace8a3032888}:4.2.3
FF - prefs.js..extensions.enabledItems: {95f24680-9e31-11da-a746-0800200c9a66}:0.1.5.5
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20110323
FF - prefs.js..extensions.enabledItems: {a0faa0a4-f1a7-4098-9a74-21efc3a92372}:4.0.1
FF - prefs.js..extensions.enabledItems: {B17C1C5A-04B1-11DB-9804-B622A1EF5492}:1.2.1
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8.4
FF - prefs.js..extensions.enabledItems: {BFB5F154-9212-46F3-B547-AC6106030A54}:1.2
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3
FF - prefs.js..extensions.enabledItems: {daf44bf7-a45e-4450-979c-91cf07434c3d}:1.5.7
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:2.0.2
FF - prefs.js..extensions.enabledItems: {ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}:1.4.1
FF - prefs.js..extensions.enabledItems: {ef62e1ce-d2a4-4cdd-b7ec-92b120366b66}:2.7.1
FF - prefs.js..extensions.enabledItems: {F8A55C97-3DB6-4961-A81D-0DE0080E53CB}:0.9.5
FF - prefs.js..extensions.enabledItems: {FBF6D7FB-F305-4445-BB3D-FEF66579A033}:5.0
FF - prefs.js..extensions.enabledItems: [removed]:3.0
FF - prefs.js..extensions.enabledItems: {5b175400-2368-11de-8c30-0800200c9a66}:1.9
FF - prefs.js..extensions.enabledItems: {9f08cb5a-76b1-4bcf-aff9-90e1a5d60b1e}:3.76

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.15\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/03/21 13:24:29 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.15\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/03/21 13:22:01 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.9\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2011/03/12 22:22:06 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.9\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins

[2011/03/21 13:24:32 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Extensions
[2011/03/23 18:31:17 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions
[2011/03/21 13:26:13 | 000,000,000 | —D | M] (Toolbar Buttons) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\{03B08592-E5B4-45ff-A0BE-C1D975458688}
[2011/03/21 13:26:14 | 000,000,000 | —D | M] (Forecastfox Weather) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
[2011/03/21 13:26:17 | 000,000,000 | —D | M] (URL Fixer) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\{0fa2149e-bb2c-4ac2-a8d3-479599819475}
[2011/03/21 13:26:17 | 000,000,000 | —D | M] (Flagfox) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}
[2011/03/21 13:26:17 | 000,000,000 | —D | M] (Print/Print Preview) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\{19EB90DC-A456-458b-8AAC-616D91AAFCE1}
[2011/03/21 13:26:17 | 000,000,000 | —D | M] ("ChromaTabs Plus") – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\{1cff04ef-0c75-4621-ba2a-2efb77346996}
[2011/03/21 17:23:58 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/03/21 13:26:19 | 000,000,000 | —D | M] (Fierr) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\{2E481B23-66AC-313F-D6A8-A81DDDF26249}
[2011/03/21 13:26:19 | 000,000,000 | —D | M] (Oskar) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\{5b175400-2368-11de-8c30-0800200c9a66}
[2011/03/21 13:26:20 | 000,000,000 | —D | M] (Dr.Web anti-virus link checker) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\{6614d11d-d21d-b211-ae23-815234e1ebb5}
[2011/03/21 13:26:20 | 000,000,000 | —D | M] ("CuteMenus2") – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\{71C54606-83ED-4ea6-9315-1AAB29466D33}
[2011/03/21 13:26:22 | 000,000,000 | —D | M] (PhishTank SiteChecker) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\{8bc5b5eb-0ec4-46ed-a024-ace8a3032888}
[2011/03/21 13:26:22 | 000,000,000 | —D | M] (Update Notifier) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\{95f24680-9e31-11da-a746-0800200c9a66}
[2011/03/21 13:26:22 | 000,000,000 | —D | M] (Noia 2.0 (eXtreme)) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\{9f08cb5a-76b1-4bcf-aff9-90e1a5d60b1e}
[2011/03/23 18:30:23 | 000,000,000 | —D | M] (WOT) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2011/03/21 13:26:22 | 000,000,000 | —D | M] (DictionarySearch) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\{a0faa0a4-f1a7-4098-9a74-21efc3a92372}
[2011/03/21 13:26:23 | 000,000,000 | —D | M] (Password Exporter) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\{B17C1C5A-04B1-11DB-9804-B622A1EF5492}
[2011/03/21 13:26:24 | 000,000,000 | —D | M] (DownloadHelper) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2011/03/21 13:26:24 | 000,000,000 | —D | M] (BidNip Toolbar) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\{BFB5F154-9212-46F3-B547-AC6106030A54}
[2011/03/21 13:26:24 | 000,000,000 | —D | M] (Adblock Plus) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2011/03/21 13:26:25 | 000,000,000 | —D | M] (Extended Statusbar) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\{daf44bf7-a45e-4450-979c-91cf07434c3d}
[2011/03/21 13:26:26 | 000,000,000 | —D | M] (DownThemAll!) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2011/03/21 13:26:29 | 000,000,000 | —D | M] (FoxTab) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\{ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}
[2011/03/23 19:29:22 | 000,000,000 | —D | M] (FoxLingo) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\{ef62e1ce-d2a4-4cdd-b7ec-92b120366b66}
[2011/03/21 13:26:45 | 000,000,000 | —D | M] (Download Manager Tweak) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\{F8A55C97-3DB6-4961-A81D-0DE0080E53CB}
[2011/03/21 13:26:46 | 000,000,000 | —D | M] ("MultirowBookmarksToolbar") – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\{FBF6D7FB-F305-4445-BB3D-FEF66579A033}
[2011/03/21 13:25:58 | 000,000,000 | —D | M] (United States English Spellchecker) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\[removed]
[2011/03/21 13:26:00 | 000,000,000 | —D | M] (Extension List Dumper) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\[removed]
[2011/03/21 13:26:02 | 000,000,000 | —D | M] (Shareaholic) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\[removed]
[2011/03/21 13:26:02 | 000,000,000 | —D | M] (Get Mail Plus) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\[removed]
[2011/03/23 18:30:05 | 000,000,000 | —D | M] (IE Tab Plus) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\[removed]
[2011/03/21 13:26:07 | 000,000,000 | —D | M] (Noia 2.0 eXtreme OPT) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\[removed]
[2011/03/21 13:26:07 | 000,000,000 | —D | M] (Penguin) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\[removed]
[2011/03/21 13:26:07 | 000,000,000 | —D | M] (Personas) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\[removed]
[2011/03/21 13:26:08 | 000,000,000 | —D | M] (Splash) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\[removed]
[2011/03/21 13:26:12 | 000,000,000 | —D | M] (Torrent Finder Toolbar) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\TFToolbarX@torrent-finder
[2011/03/21 13:26:12 | 000,000,000 | —D | M] (Toggle Private Browsing) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\[removed]
[2011/03/21 13:25:58 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\[removed]\chrome
[2011/03/21 13:26:00 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\[removed]\defaults
[2011/03/21 13:26:00 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\[removed]\chrome
[2011/03/21 13:26:01 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\extensions\[removed]\defaults
[2011/03/11 22:48:50 | 000,002,470 | —- | M] () – C:\Documents and Settings\Gerry Goldshine\Application Data\Mozilla\Firefox\Profiles\qawc5lfm.default\searchplugins\safesearch.xml
[2011/03/21 13:22:02 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/03/12 22:00:37 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF

O1 HOSTS File: ([2008/06/09 23:45:48 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe (BillP Studios)
O4 - HKCU..\Run: [i8kfangui] C:\PROGRAM FILES\I8KFANGUI\I8KFANGUI.EXE (Christian Diefer)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [WallpaperChanger] C:\Program Files\Wallpaper Master\Wallpaper.exe (James Garton)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\REALTEK 11n USB Wireless LAN Utility.lnk = C:\Program Files\REALTEK\11n USB Wireless LAN Utility\RtWLan.exe (Realtek Semiconductor Corp.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoInternetOpenWith = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 02 F0 FF 03 [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: StartMenuLogOff = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMBalloonTip = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 0
O15 - HKCU\..Trusted Domains: microsoft.com ([office] http in Trusted sites)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: Microsoft XML Parser for Java Reg Error: Value error. (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\Documents and Settings\Gerry Goldshine\My Documents\My Pictures\Second Nature.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Gerry Goldshine\My Documents\My Pictures\Second Nature.bmp
O28 - HKLM ShellExecuteHooks: {097F10A7-487F-4457-AB1F-827C59479A72} - Reg Error: Key error. File not found
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/07/31 05:39:16 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - C:\WINDOWS\System32\iprip.dll (Microsoft Corporation)
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: UxTuneUp - C:\WINDOWS\System32\uxtuneup.dll (TuneUp Software GmbH)
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.ac3acm - C:\WINDOWS\System32\AC3ACM.acm (fccHandler)
Drivers32: msacm.ac3filter - C:\WINDOWS\System32\ac3filter.acm ()
Drivers32: msacm.alf2cd - C:\WINDOWS\System32\alf2cd.acm (NCT Company)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.scg726 - C:\WINDOWS\System32\Scg726.acm (SHARP Corporation)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: msacm.voxacm160 - C:\WINDOWS\System32\vct3216.acm (Voxware, Inc.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\divx.dll (DivXNetworks, Inc.)
Drivers32: vidc.dvsd - C:\WINDOWS\System32\mcdvd_32.dll (MainConcept)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.xvid - C:\WINDOWS\System32\xvidvfw.dll ()

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (56027131116781568)

========== Files/Folders - Created Within 30 Days ==========

[2011/03/23 17:23:16 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Gerry Goldshine\Recent
[2011/03/21 13:22:09 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox
[2011/03/21 13:21:59 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2011/03/18 23:11:33 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Gerry Goldshine\Desktop\OTL.exe
[2011/03/17 19:45:52 | 000,000,000 | —D | C] – C:\Documents and Settings\Gerry Goldshine\My Documents\HIJack This Logs
[2011/03/12 22:01:44 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2011/03/12 22:01:04 | 000,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2011/03/12 22:01:02 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/03/12 22:01:02 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/03/12 22:01:02 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2011/03/12 21:54:15 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\CCleaner
[2011/03/11 00:13:04 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Bullzip
[2011/03/11 00:13:02 | 000,103,424 | —- | C] (Bullzip) – C:\WINDOWS\System32\bzDCT.dll
[2011/03/11 00:13:02 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Bullzip
[2011/03/11 00:13:01 | 000,227,840 | —- | C] (Bullzip) – C:\WINDOWS\System32\bzFlRdr.dll
[2011/03/11 00:13:01 | 000,135,168 | —- | C] (Bullzip) – C:\WINDOWS\System32\bzpdfc.dll
[2011/03/11 00:12:53 | 000,196,096 | —- | C] (Bullzip) – C:\WINDOWS\System32\bzpdf.dll
[2011/03/11 00:12:45 | 000,000,000 | —D | C] – C:\Program Files\Bullzip
[2011/03/11 00:10:07 | 000,000,000 | —D | C] – C:\Documents and Settings\Gerry Goldshine\Local Settings\Application Data\Tracker Software
[2011/03/11 00:06:50 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Tracker Software
[2011/03/11 00:04:22 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\PDF-XChange PDF Viewer
[2011/03/11 00:04:05 | 000,000,000 | —D | C] – C:\Program Files\Tracker Software
[2011/03/09 13:37:46 | 000,000,000 | —D | C] – C:\Documents and Settings\Gerry Goldshine\Local Settings\Application Data\VS Revo Group
[2011/03/09 13:37:06 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Revo Uninstaller Pro
[2011/03/09 13:37:04 | 000,027,064 | —- | C] (VS Revo Group) – C:\WINDOWS\System32\drivers\revoflt.sys
[2011/03/07 17:19:04 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Avery
[2011/03/05 14:39:40 | 000,323,624 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wiaaut.dll
[2011/03/01 04:29:15 | 000,000,000 | —D | C] – C:\Program Files\Stardock
[2011/03/01 04:24:11 | 000,000,000 | —D | C] – C:\Documents and Settings\Gerry Goldshine\Application Data\KeePass
[2011/03/01 04:16:03 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\KeePass Password Safe
[2011/03/01 04:16:01 | 000,000,000 | —D | C] – C:\Program Files\KeePass Password Safe
[2011/03/01 03:28:45 | 000,000,000 | —D | C] – C:\Documents and Settings\Gerry Goldshine\My Documents\My Wallpapers
[2011/03/01 03:27:49 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Wallpaper Master
[2011/03/01 03:27:47 | 000,000,000 | —D | C] – C:\Program Files\Wallpaper Master
[2011/03/01 03:19:44 | 000,000,000 | —D | C] – C:\Documents and Settings\Gerry Goldshine\Local Settings\Application Data\johnsadventures.com
[2011/03/01 03:14:09 | 000,000,000 | —D | C] – C:\Documents and Settings\Gerry Goldshine\Application Data\johnsadventures.com
[2011/03/01 02:56:55 | 000,000,000 | —D | C] – C:\Documents and Settings\Gerry Goldshine\Application Data\XnView
[2011/03/01 02:32:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Gerry Goldshine\My Documents\ZPS12
[2011/03/01 02:19:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Gerry Goldshine\Application Data\Zoner
[2011/03/01 02:19:45 | 000,000,000 | —D | C] – C:\Documents and Settings\Gerry Goldshine\Local Settings\Application Data\Zoner
[2011/02/27 11:26:35 | 000,000,000 | —D | C] – C:\Documents and Settings\Gerry Goldshine\Local Settings\Application Data\Deployment
[86 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[46 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/03/23 17:41:40 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\Auslogics BoostSpeed Integrator Start On Gerry Goldshine Logon.job
[2011/03/23 17:26:24 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/03/23 17:26:21 | 536,375,296 | -HS- | M] () – C:\hiberfil.sys
[2011/03/21 13:22:09 | 000,001,620 | —- | M] () – C:\Documents and Settings\Gerry Goldshine\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/03/21 13:22:09 | 000,001,602 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/03/19 21:11:02 | 000,000,774 | —- | M] () – C:\Documents and Settings\Gerry Goldshine\Desktop\MozBackup.lnk
[2011/03/19 19:09:14 | 000,001,883 | —- | M] () – C:\Documents and Settings\Gerry Goldshine\Desktop\OTL Scan.rtf
[2011/03/18 23:11:41 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Gerry Goldshine\Desktop\OTL.exe
[2011/03/17 17:00:26 | 000,000,552 | —- | M] () – C:\WINDOWS\System32\d3d8caps.dat
[2011/03/17 15:08:04 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/03/13 16:52:57 | 000,503,788 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/03/13 16:52:57 | 000,089,424 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/03/13 01:46:53 | 000,002,515 | —- | M] () – C:\Documents and Settings\Gerry Goldshine\Desktop\Microsoft Word 2007.lnk
[2011/03/12 22:22:13 | 000,001,686 | —- | M] () – C:\Documents and Settings\Gerry Goldshine\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Thunderbird.lnk
[2011/03/12 22:22:13 | 000,001,668 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Thunderbird.lnk
[2011/03/12 22:06:59 | 000,000,812 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Paint.NET.lnk
[2011/03/12 22:00:33 | 000,157,472 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/03/12 22:00:33 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/03/12 22:00:32 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2011/03/12 22:00:32 | 000,073,728 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2011/03/12 22:00:31 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2011/03/12 21:54:15 | 000,000,682 | —- | M] () – C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2011/03/11 00:09:37 | 000,000,776 | —- | M] () – C:\Documents and Settings\Gerry Goldshine\Desktop\PDF-Viewer.lnk
[2011/03/09 13:37:08 | 000,000,925 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Revo Uninstaller Pro.lnk
[2011/03/07 20:07:15 | 000,516,152 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/03/07 01:12:29 | 000,167,580 | —- | M] () – C:\WINDOWS\hphins33.dat
[2011/03/05 14:39:40 | 000,323,624 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\wiaaut.dll
[2011/03/01 04:16:04 | 000,000,688 | —- | M] () – C:\Documents and Settings\Gerry Goldshine\Desktop\KeePass.lnk
[86 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[46 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/03/21 13:22:09 | 000,001,620 | —- | C] () – C:\Documents and Settings\Gerry Goldshine\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/03/21 13:22:09 | 000,001,602 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/03/19 21:11:02 | 000,000,774 | —- | C] () – C:\Documents and Settings\Gerry Goldshine\Desktop\MozBackup.lnk
[2011/03/19 19:25:01 | 536,375,296 | -HS- | C] () – C:\hiberfil.sys
[2011/03/19 19:09:14 | 000,001,883 | —- | C] () – C:\Documents and Settings\Gerry Goldshine\Desktop\OTL Scan.rtf
[2011/03/17 17:00:26 | 000,000,552 | —- | C] () – C:\WINDOWS\System32\d3d8caps.dat
[2011/03/12 22:06:59 | 000,000,818 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Paint.NET.lnk
[2011/03/11 00:04:24 | 000,000,776 | —- | C] () – C:\Documents and Settings\Gerry Goldshine\Desktop\PDF-Viewer.lnk
[2011/03/09 13:37:08 | 000,000,925 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Revo Uninstaller Pro.lnk
[2011/03/05 11:16:26 | 000,001,924 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\REALTEK 11n USB Wireless LAN Utility.lnk
[2011/03/01 04:16:04 | 000,000,688 | —- | C] () – C:\Documents and Settings\Gerry Goldshine\Desktop\KeePass.lnk
[2010/11/10 03:29:37 | 000,224,632 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/11/02 15:44:09 | 000,451,072 | —- | C] () – C:\WINDOWS\System32\ISSRemoveSP.exe
[2010/06/21 15:44:17 | 000,077,853 | —- | C] () – C:\WINDOWS\hpqins05.dat
[2010/06/21 15:27:13 | 000,136,083 | —- | C] () – C:\WINDOWS\hphins33.dat.temp
[2010/06/21 15:27:13 | 000,000,512 | —- | C] () – C:\WINDOWS\hphmdl33.dat.temp
[2010/06/05 12:18:09 | 000,167,580 | —- | C] () – C:\WINDOWS\hphins33.dat
[2010/06/05 12:18:09 | 000,000,512 | —- | C] () – C:\WINDOWS\hphmdl33.dat
[2010/01/02 16:56:00 | 000,696,832 | —- | C] () – C:\WINDOWS\is-QIMO8.exe
[2008/06/16 20:02:52 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\swunilog.ini
[2008/06/12 10:41:46 | 000,004,096 | —- | C] () – C:\WINDOWS\d3dx.dat
[2008/04/10 19:23:56 | 000,162,304 | —- | C] () – C:\WINDOWS\System32\ztvunrar36.dll
[2008/04/10 19:23:56 | 000,077,312 | —- | C] () – C:\WINDOWS\System32\ztvunace26.dll
[2008/04/10 11:06:08 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\IPPCPUID.DLL
[2008/04/10 11:05:30 | 000,011,776 | —- | C] () – C:\WINDOWS\System32\pmsbfn32.dll
[2007/09/04 20:09:39 | 000,000,000 | —- | C] () – C:\WINDOWS\OpPrintServer.INI
[2007/09/04 20:05:32 | 000,007,680 | —- | C] () – C:\WINDOWS\System32\CNMVS5y.DLL
[2007/08/24 14:43:32 | 000,000,488 | —- | C] () – C:\WINDOWS\cmousecc.ini
[2007/06/18 18:55:17 | 000,000,058 | —- | C] () – C:\WINDOWS\System32\EAL32.INI
[2007/06/18 13:23:32 | 000,001,759 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/05/29 03:54:38 | 000,000,025 | —- | C] () – C:\WINDOWS\brassi.dat
[2007/05/27 04:29:47 | 000,000,214 | —- | C] () – C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2007/05/27 04:15:14 | 000,093,392 | —- | C] () – C:\WINDOWS\HPHins03.dat
[2007/05/27 04:15:14 | 000,002,655 | —- | C] () – C:\WINDOWS\hphmdl03.dat
[2007/05/24 18:05:09 | 000,000,140 | —- | C] () – C:\WINDOWS\ChssBase.ini
[2007/05/24 17:46:47 | 000,000,000 | —- | C] () – C:\WINDOWS\SETUP32.INI
[2007/05/24 17:37:48 | 000,000,053 | —- | C] () – C:\WINDOWS\WININIT.INI
[2007/04/06 01:57:06 | 000,156,160 | —- | C] () – C:\WINDOWS\System32\unrar3.dll
[2007/04/06 01:57:06 | 000,075,264 | —- | C] () – C:\WINDOWS\System32\unacev2.dll
[2007/01/25 23:45:02 | 000,006,784 | —- | C] () – C:\WINDOWS\System32\drivers\whfltr2k.sys
[2006/12/06 22:19:41 | 000,684,032 | —- | C] () – C:\WINDOWS\System32\libeay32.dll
[2006/12/06 22:19:41 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\ssleay32.dll
[2006/09/14 03:45:19 | 000,000,032 | —- | C] () – C:\WINDOWS\System32\thxcfg.ini
[2006/08/28 03:32:31 | 000,000,026 | —- | C] () – C:\WINDOWS\DfrgUIEx.INI
[2006/08/28 01:35:27 | 000,000,000 | —- | C] () – C:\WINDOWS\msicpl.ini
[2006/08/23 14:49:31 | 000,000,025 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2006/08/22 21:51:01 | 000,034,308 | —- | C] () – C:\WINDOWS\System32\BASSMOD.dll
[2006/08/09 02:00:52 | 000,176,128 | —- | C] () – C:\Documents and Settings\Gerry Goldshine\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/08/06 01:27:07 | 000,524,288 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2006/08/06 01:27:07 | 000,139,264 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2006/08/05 23:47:33 | 000,004,212 | -H– | C] () – C:\WINDOWS\System32\zllictbl.dat
[2006/08/02 00:45:29 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/08/01 21:53:52 | 000,001,218 | —- | C] () – C:\WINDOWS\Slideshw.ini
[2006/08/01 15:04:41 | 000,000,064 | —- | C] () – C:\WINDOWS\init.ini
[2006/07/31 08:40:32 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2006/07/31 08:39:42 | 000,007,107 | —- | C] () – C:\WINDOWS\mozver.dat
[2006/07/31 07:06:52 | 000,684,032 | —- | C] () – C:\WINDOWS\libeay32.dll
[2006/07/31 07:06:52 | 000,155,648 | —- | C] () – C:\WINDOWS\ssleay32.dll
[2006/07/31 05:46:34 | 000,006,550 | —- | C] () – C:\WINDOWS\jautoexp.dat
[2006/07/31 05:42:05 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2006/07/31 05:36:05 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2006/07/30 22:14:53 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2006/07/30 22:13:54 | 000,516,152 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2006/07/30 22:13:14 | 000,000,211 | —- | C] () – C:\WINDOWS\System32\BOOTBAK.INI
[2006/05/25 07:02:46 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\unwlsdrv.exe
[2004/08/02 14:20:40 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/04/26 08:38:20 | 000,006,885 | —- | C] () – C:\WINDOWS\System32\drivers\whmice2k.sys
[2002/12/05 18:51:00 | 000,059,392 | R— | C] () – C:\WINDOWS\System32\streamhlp.dll
[2002/03/14 12:00:26 | 000,038,567 | —- | C] () – C:\WINDOWS\System32\pcpbios.exe
[2001/08/18 05:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2001/08/18 05:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2001/08/18 05:00:00 | 000,503,788 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2001/08/18 05:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2001/08/18 05:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2001/08/18 05:00:00 | 000,089,424 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2001/08/18 05:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2001/08/18 05:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2001/08/18 05:00:00 | 000,004,594 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2001/08/18 05:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2001/08/18 05:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[1998/08/16 05:00:00 | 000,004,096 | —- | C] () – C:\WINDOWS\System32\sysres.dll

========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2006/07/31 05:39:16 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2006/09/01 02:19:39 | 000,000,205 | -HS- | M] () – C:\boot.ini
[2006/08/11 11:06:42 | 000,000,046 | —- | M] () – C:\CONFIG.SYS
[2008/06/16 10:45:22 | 000,000,397 | —- | M] () – C:\DownloadLog.txt
[2006/08/29 20:02:18 | 000,013,090 | —- | M] () – C:\drwtsn32.log
[2011/03/23 17:26:21 | 536,375,296 | -HS- | M] () – C:\hiberfil.sys
[2007/11/05 18:17:31 | 000,000,164 | —- | M] () – C:\install.dat
[2006/07/31 05:39:16 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2006/07/31 05:39:16 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2006/07/31 06:04:16 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2009/05/26 19:33:17 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/03/23 17:26:08 | 804,458,496 | -HS- | M] () – C:\pagefile.sys
[2008/06/17 20:07:59 | 000,000,150 | —- | M] () – C:\YServer.txt

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/07/31 05:38:36 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2004/04/22 22:00:00 | 000,017,920 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD5y.DLL
[2006/09/12 22:00:00 | 000,027,136 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD7Q.DLL
[2004/04/22 22:00:00 | 000,054,272 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP5y.DLL
[2006/09/12 22:00:00 | 000,069,632 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP7Q.DLL
[2008/07/06 05:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2009/04/16 14:08:20 | 000,312,832 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpfpp70v.dll
[2007/04/09 13:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 03:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2011/01/13 01:47:35 | 000,038,848 | —- | M] (AVAST Software) – C:\WINDOWS\avastSS.scr
[2007/05/29 03:54:37 | 000,672,256 | —- | M] ( Remco de Korte / Onwijs) – C:\WINDOWS\dogfight.scr
[2006/01/30 12:11:50 | 000,135,168 | —- | M] (Second Nature Software) – C:\WINDOWS\SNSVR.scr
[1996/10/07 17:38:34 | 000,420,576 | —- | M] () – C:\WINDOWS\voyager.scr
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >
[2007/08/25 08:26:11 | 000,001,610 | -H– | M] () – C:\Documents and Settings\Gerry Goldshine\Application Data\Microsoft\LastFlashConfig.WFC

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2006/07/30 22:13:13 | 000,090,112 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2006/07/30 22:13:13 | 000,606,208 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2006/07/30 22:13:13 | 000,393,216 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2009/05/26 19:44:20 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2006/07/31 06:19:46 | 000,000,177 | -HS- | M] () – C:\Documents and Settings\Gerry Goldshine\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2006/07/31 05:46:54 | 000,000,079 | —- | M] () – C:\Documents and Settings\Gerry Goldshine\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2011/03/18 23:11:41 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Gerry Goldshine\desktop\OTL.exe
[2011/01/20 16:41:54 | 000,476,040 | —- | M] (SpeedyFox) – C:\Documents and Settings\Gerry Goldshine\desktop\speedyfox.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
"NoAutoRebootWithLoggedOnUsers" = 0

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-03-09 18:03:34

========== Alternate Data Streams ==========

@Alternate Data Stream - 95 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
@Alternate Data Stream - 131 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:07BF512B
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1CA73D29

< End of report >

As far as more memory, As I recall, 512 MB is the max that this old laptop can handle and even if it were not, it's just not worth it, give that it will only be used on a rare occasion for now on.

I appreciate all the help you and others here have given me on this. I think it's becoming a case of my system just reaching the limits of its capabilities.
I'll forgo my normal all clean speech because it's obvious you keep a very up to date and clean machine. I'll just give you a couple of tips for staying clean in the future. I think you'll find a wee bit of improvement using Miscrosoft Security Essentials over Avast, but I agree - you are close to the limits of your machine. When you have programs open you are probably maxing out the RAM and the system is temporarily writing to the hard drive to free up memory. That's why the HD is running so much.


Visit Microsoft's Windows Update Site Frequently
It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.


Keep your Java, Adobe Reader and Adobe Flash Up to Date
Older versions of these programs can contain security vulnerabilities. It is very important to keep them updated.

Update and Run Malwarebytes Anti-Malware
Scan your computer with this program on a regular basis just as you would an antivirus software making sure you update definitions each time you scan.

To simplify making sure you have the latest version of many of your security programs and applications, you may want to consider:
Secunia's Personal Software Inspector (PSI). It is a free utility that scans your computer for installed applications and checks to see if they have the latest security patches and updates. If it finds any applications with possible security issues, links and/or instructions are provided for the necessariy updates.

Filehippo's Update Checker. It is free utilitiy that scan your computer for installed software, checks the versions and then sends this information to see if there are any newer releases. Available software updates are displayed and you can decide which ones to download and install. Among many other types of programs, they includes a number of the Anti-Spyware, Firewall/Security and Anti-Virus programs that have been recommended (though not all of them). Note: Definition files should be updated from within the programs themselves. The Update Checker look for newer versions of the software program, not definition files.


Good luck and happy surfing!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI