This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Possible Malware - Computer Shutdown Slow

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I really don't understand why my computer is running slow? I don't experience any pop ups or weird things while surfing the internet… except for the fact that… my speed from going page to page is decreased… and pages take a little more time to load than in the past. I have noticed when I do power on my computer for the next day… all of my Internet History (browser pages) are erased from the previous day. That use to never happen before? Like I said… my computer has been acting very strange. Also, when I shutdown my computer it takes about 45 seconds longer than normal to to a complete shutdown. I was just wondering if someone could show me a few steps to take to get my computer working as fast as it should be. Thanks!
Just moments ago my computer just reset (restarted) itself all on its own. It never did that before! This is so weird! I have also noticed that sometimes when I listen to music on Windows Media Player the song will freeze and the computer will lock up. I have to hold the power button down in order to turn off computer.

**In any case where you happen to be busy or unable to give us a reply, we would be grateful if you keep us informed in advance and we will be more than happy to wait. Failure to do so we will have your thread closed in THREE(3) days. :)


Hello there, T.C.

:welcome:

I'm Conspire, I'll be glad to help you with your computer problems.

Please observe these rules while we work:
  • Read the entire procedure
  • It is important to perform ALL actions in sequence.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with me till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
  • Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
Hello there,

I'm leaning towards more on hardware issues than malware issues. We will see what we can get from here. :)

Download OTL to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Click on Minimal Output at the top
  • Download the following file scan.txt to your Desktop. Click here to download it. You may need to right click on it and select "Save"
  • Double click inside the Custom Scan box at the bottom
  • A window will appear saying "Click OK to load a custom scan from a file or Cancel to cancel"
  • Click the OK button and navigate to the file scan.txt which we just saved to your desktop
  • Select scan.txt and click Open. Writing will now appear under the Custom Scan box
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan won't take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time and post them in your topic
===================================================

[external image: Posted Image]
  • Please download GMER from one of the following locations, and save it to your desktop:
  • Main Mirror
    This version will download a randomly named file (Recommended)
  • Zip Mirror
    This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.
  • Extract the contents of the zipped file to desktop (applicable only to Zip mirror) .
  • Double click [external image: Posted Image] or [external image: Posted Image] on your desktop.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
    [external image: Posted Image]

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


===================================================

Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
===================================================

On your next reply please post :
OTL log
GMER log
Checkup log

Let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
OTL logfile created on: 5/9/2011 2:58:13 AM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\HP_Owner\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 76.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 89.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 458.24 Gb Total Space | 291.95 Gb Free Space | 63.71% Space Free | Partition Type: NTFS
Drive D: | 7.50 Gb Total Space | 1.16 Gb Free Space | 15.47% Space Free | Partition Type: FAT32
Unable to calculate disk information.

Computer Name: YOUR-27E1513D96 | User Name: HP_Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\HP_Owner\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH)
PRC - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe (Cisco Systems, Inc.)
PRC - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe (Cisco Systems, Inc.)
PRC - C:\Program Files\Creative\MediaSource5\MtdAcqu.exe (Creative Technology Ltd)
PRC - C:\WINDOWS\CTHELPER.EXE (Creative Technology Ltd)
PRC - C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe (Creative Technology Ltd.)
PRC - C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\Creative\SBAudigy4\Surround Mixer\CTSysVol.exe (Creative Technology Ltd)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Creative\SBAudigy4\DVDAudio\CTDVDDET.exe (Creative Technology Ltd)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\HP_Owner\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\CTAGENT.DLL (Creative Technology Ltd)
MOD - C:\WINDOWS\system32\nview.dll ()
MOD - C:\WINDOWS\system32\nvwddi.dll (NVIDIA Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – File not found
SRV - (AppMgmt) – File not found
SRV - (AntiVirSchedulerService) – C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (AntiVirService) – C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (IntuitUpdateService) – C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
SRV - (nmservice) – C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe (Cisco Systems, Inc.)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)


========== Driver Services (SafeList) ==========

DRV - (avipbb) – C:\WINDOWS\system32\drivers\avipbb.sys (Avira GmbH)
DRV - (stdriver) – C:\WINDOWS\system32\drivers\stdriver32.sys (NCH Software)
DRV - (avgntflt) – C:\WINDOWS\system32\drivers\avgntflt.sys (Avira GmbH)
DRV - (avgio) – C:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (ssmdrv) – C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (purendis) – C:\WINDOWS\system32\drivers\purendis.sys (Cisco Systems, Inc.)
DRV - (pnarp) – C:\WINDOWS\system32\drivers\pnarp.sys (Cisco Systems, Inc.)
DRV - (PfModNT) – C:\WINDOWS\system32\drivers\pfmodnt.sys (Creative Technology Ltd.)
DRV - (ctaud2k) Creative Audio Driver (WDM) – C:\WINDOWS\system32\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV - (ctprxy2k) – C:\WINDOWS\system32\drivers\ctprxy2k.sys (Creative Technology Ltd)
DRV - (hap17v2k) – C:\WINDOWS\system32\drivers\haP17v2k.sys (Creative Technology Ltd)
DRV - (hap16v2k) – C:\WINDOWS\system32\drivers\haP16v2k.sys (Creative Technology Ltd)
DRV - (ha10kx2k) – C:\WINDOWS\system32\drivers\ha10kx2k.sys (Creative Technology Ltd)
DRV - (ossrv) – C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (ctsfm2k) – C:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (emupia) – C:\WINDOWS\system32\drivers\emupia2k.sys (Creative Technology Ltd)
DRV - (ctac32k) – C:\WINDOWS\system32\drivers\ctac32k.sys (Creative Technology Ltd)
DRV - (ctdvda2k) – C:\WINDOWS\system32\drivers\ctdvda2k.sys (Creative Technology Ltd)
DRV - (Ps2) – C:\WINDOWS\system32\drivers\PS2.sys (Hewlett-Packard Company)
DRV - (AgereSoftModem) – C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (ftsata2) – C:\WINDOWS\system32\DRIVERS\ftsata2.sys (Promise Technology, Inc.)
DRV - (gameenum) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (rtl8139) Realtek RTL8139(A/B/C) – C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)
DRV - (bb-run) – C:\WINDOWS\system32\DRIVERS\bb-run.sys (Promise Technology, Inc.)
DRV - (HCF_MSFT) – C:\WINDOWS\system32\drivers\HCF_MSFT.sys (Conexant)
DRV - (rthwcls) – C:\WINDOWS\system32\drivers\rthwcls.sys (Conexant Systems Inc.)
DRV - (rpfun) – C:\WINDOWS\system32\drivers\rpfun.sys (Conexant Systems Inc.)
DRV - (crtaud) – C:\WINDOWS\system32\drivers\crtaud.sys (Conexant Systems Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…arm1=seconduser

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…arm1=seconduser
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…arm1=seconduser
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…arm1=seconduser
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…arm1=seconduser
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?fr=ffds1&p="
FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.search.defaulturl: "http://search.yahoo.com/search?fr=ffsp1&p="



[2009/11/07 23:49:44 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\9t8ng48w.default\extensions
[2009/07/22 03:38:13 | 000,000,000 | —D | M] ("Ask Toolbar for Firefox") – C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\9t8ng48w.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}
[2007/02/20 16:15:00 | 002,115,816 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\NPSWF32.dll

O1 HOSTS File: ([2004/08/04 15:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O4 - HKLM..\Run: [AudioDrvEmulator] C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [CTDVDDET] C:\Program Files\Creative\SBAudigy4\DVDAudio\CTDVDDET.EXE (Creative Technology Ltd)
O4 - HKLM..\Run: [CTHelper] C:\WINDOWS\CTHELPER.EXE (Creative Technology Ltd)
O4 - HKLM..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy4\Surround Mixer\CTSysVol.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [HPBootOp] C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\LSBurnWatcher.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [nmctxth] C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe (Cisco Systems, Inc.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [PCDrProfiler] File not found
O4 - HKLM..\Run: [Recordpad] C:\Program Files\NCH Swift Sound\Recordpad\recordpad.exe (NCH Software)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UpdReg] C:\WINDOWS\Updreg.EXE (Creative Technology Ltd.)
O4 - HKCU..\Run: [MtdAcqu] C:\Program Files\Creative\MediaSource5\MtdAcqu.exe (Creative Technology Ltd)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Co.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &Google Search - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Backward Links - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Cached Snapshot of Page - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Similar Pages - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Translate into English - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O9 - Extra Button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ()
O9 - Extra 'Tools' menuitem : Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ()
O15 - HKCU\..Trusted Domains: intuit.com ([ttlc] https in Trusted sites)
O16 - DPF: {33564D57-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/D/0…D0C/wmv9dmo.cab (Reg Error: Key error.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1282527261703 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (Reg Error: Value error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\pure-go {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files\Common Files\Pure Networks Shared\Platform\puresp4.dll (Cisco Systems, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/11/23 04:30:44 | 000,000,050 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2001/07/28 07:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O33 - MountPoints2\{2d435b36-e506-11d9-9b78-e6b009352ae7}\Shell - "" = AutoRun
O33 - MountPoints2\{2d435b36-e506-11d9-9b78-e6b009352ae7}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{2d435b36-e506-11d9-9b78-e6b009352ae7}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.LEAD - C:\WINDOWS\System32\LCodcCMP.dll (LEAD Technologies, Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (54619700398653440)

========== Files/Folders - Created Within 30 Days ==========

[2011/05/09 02:53:52 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Documents and Settings\HP_Owner\Desktop\OTL.exe
[2011/05/06 18:49:58 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/05/06 18:49:49 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/04/28 02:51:29 | 000,005,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ptpusb.dll
[2011/04/28 02:51:28 | 000,159,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ptpusd.dll
[2011/04/16 04:00:17 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\Payroll Mate 2011
[2011/04/16 04:00:17 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Payroll Mate (2011)
[2011/04/16 04:00:11 | 000,000,000 | —D | C] – C:\Program Files\Real Business Solutions
[2011/04/16 03:59:38 | 008,452,520 | —- | C] (Real Business Solutions Inc. ) – C:\Documents and Settings\HP_Owner\My Documents\PayrollMateSetup.exe
[2009/08/19 18:35:13 | 000,047,360 | —- | C] (VSO Software) – C:\Documents and Settings\HP_Owner\Application Data\pcouffin.sys
[2005/11/23 04:00:30 | 000,033,792 | —- | C] ( ) – C:\WINDOWS\System32\a3d.dll
[2005/11/23 04:00:30 | 000,009,216 | —- | C] ( ) – C:\WINDOWS\System32\KILLAPPS.EXE
[55 C:\Documents and Settings\HP_Owner\My Documents\*.tmp files -> C:\Documents and Settings\HP_Owner\My Documents\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/05/09 02:54:06 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\HP_Owner\Desktop\OTL.exe
[2011/05/09 02:06:00 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/05/09 01:39:31 | 004,958,588 | —- | M] () – C:\WINDOWS\{00000002-00000000-00000007-00001102-00000008-10221102}.CDF
[2011/05/09 01:38:13 | 000,365,722 | —- | M] () – C:\Documents and Settings\HP_Owner\My Documents\BostonSeriesNHL2.jpg
[2011/05/09 00:47:11 | 000,296,452 | —- | M] () – C:\Documents and Settings\HP_Owner\My Documents\BostonSeriesNHL.jpg
[2011/05/09 00:24:33 | 000,000,248 | —- | M] () – C:\WINDOWS\System\hpsysdrv.dat
[2011/05/09 00:22:56 | 000,000,296 | —- | M] () – C:\WINDOWS\tasks\recordpadShakeIcon.job
[2011/05/09 00:22:51 | 000,029,204 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2011/05/09 00:22:49 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/05/09 00:22:46 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/05/09 00:22:45 | 2145,894,400 | -HS- | M] () – C:\hiberfil.sys
[2011/05/08 03:49:35 | 000,030,480 | —- | M] () – C:\WINDOWS\System32\BMXStateBkp-{00000002-00000000-00000007-00001102-00000008-10221102}.rfx
[2011/05/08 03:49:35 | 000,030,480 | —- | M] () – C:\WINDOWS\System32\BMXState-{00000002-00000000-00000007-00001102-00000008-10221102}.rfx
[2011/05/08 03:49:35 | 000,029,772 | —- | M] () – C:\WINDOWS\System32\BMXCtrlState-{00000002-00000000-00000007-00001102-00000008-10221102}.rfx
[2011/05/08 03:49:35 | 000,029,772 | —- | M] () – C:\WINDOWS\System32\BMXBkpCtrlState-{00000002-00000000-00000007-00001102-00000008-10221102}.rfx
[2011/05/08 03:49:35 | 000,011,564 | —- | M] () – C:\WINDOWS\System32\DVCState-{00000002-00000000-00000007-00001102-00000008-10221102}.rfx
[2011/05/08 03:49:35 | 000,001,080 | —- | M] () – C:\WINDOWS\System32\settingsbkup.sfm
[2011/05/08 03:49:35 | 000,001,080 | —- | M] () – C:\WINDOWS\System32\settings.sfm
[2011/05/08 03:48:29 | 004,958,588 | —- | M] () – C:\WINDOWS\{00000002-00000000-00000007-00001102-00000008-10221102}.BAK
[2011/05/07 12:10:18 | 001,875,246 | —- | M] () – C:\Documents and Settings\HP_Owner\My Documents\2010 Cichanski T Form 1040 Individual Tax Return.pdf
[2011/05/06 18:49:58 | 000,000,795 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/05/05 15:27:12 | 000,000,512 | —- | M] () – C:\Documents and Settings\HP_Owner\Application Data\wklnhst.dat
[2011/05/05 03:04:10 | 000,850,042 | —- | M] () – C:\Documents and Settings\HP_Owner\My Documents\MosleyPacquiaoDraw.jpg
[2011/05/01 02:14:47 | 000,036,091 | —- | M] () – C:\Documents and Settings\HP_Owner\My Documents\Sunami001.jpg
[2011/04/25 20:02:31 | 000,344,718 | —- | M] () – C:\Documents and Settings\HP_Owner\My Documents\USPSReship.jpg
[2011/04/22 22:50:47 | 000,259,984 | —- | M] () – C:\Documents and Settings\HP_Owner\My Documents\Wendy030
[2011/04/19 01:26:01 | 000,000,288 | —- | M] () – C:\WINDOWS\tasks\wavepadShakeIcon.job
[2011/04/17 01:27:25 | 000,202,034 | —- | M] () – C:\Documents and Settings\HP_Owner\My Documents\savedImage44.jpg
[2011/04/17 01:23:27 | 000,330,693 | —- | M] () – C:\Documents and Settings\HP_Owner\My Documents\savedImage31
[2011/04/17 01:22:55 | 000,231,943 | —- | M] () – C:\Documents and Settings\HP_Owner\My Documents\savedImage45
[2011/04/17 01:22:18 | 000,283,309 | —- | M] () – C:\Documents and Settings\HP_Owner\My Documents\savedImage44
[2011/04/17 01:21:04 | 000,275,879 | —- | M] () – C:\Documents and Settings\HP_Owner\My Documents\savedImage43
[2011/04/16 23:26:08 | 000,063,863 | —- | M] () – C:\Documents and Settings\HP_Owner\My Documents\billDetailDownload.pdf
[2011/04/16 15:09:10 | 000,220,205 | —- | M] () – C:\Documents and Settings\HP_Owner\My Documents\savedImage29
[2011/04/16 04:10:12 | 000,807,646 | —- | M] () – C:\Documents and Settings\HP_Owner\My Documents\5DimesFieldWager.jpg
[2011/04/16 04:00:17 | 000,001,831 | —- | M] () – C:\Documents and Settings\HP_Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Payroll Mate (2011).lnk
[2011/04/16 04:00:17 | 000,001,811 | —- | M] () – C:\Documents and Settings\HP_Owner\Desktop\Payroll Mate (2011).lnk
[2011/04/16 03:59:42 | 008,452,520 | —- | M] (Real Business Solutions Inc. ) – C:\Documents and Settings\HP_Owner\My Documents\PayrollMateSetup.exe
[2011/04/16 01:26:36 | 000,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2011/04/16 01:26:36 | 000,001,409 | —- | M] () – C:\WINDOWS\QTFont.for
[2011/04/15 02:09:36 | 002,270,369 | —- | M] () – C:\Documents and Settings\HP_Owner\My Documents\Clipboard03.jpg
[2011/04/11 23:59:37 | 000,416,457 | —- | M] () – C:\Documents and Settings\HP_Owner\My Documents\TheGreekHockey.jpg
[55 C:\Documents and Settings\HP_Owner\My Documents\*.tmp files -> C:\Documents and Settings\HP_Owner\My Documents\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/05/09 01:36:13 | 000,365,722 | —- | C] () – C:\Documents and Settings\HP_Owner\My Documents\BostonSeriesNHL2.jpg
[2011/05/09 00:47:11 | 000,296,452 | —- | C] () – C:\Documents and Settings\HP_Owner\My Documents\BostonSeriesNHL.jpg
[2011/05/07 12:10:17 | 001,875,246 | —- | C] () – C:\Documents and Settings\HP_Owner\My Documents\2010 Cichanski T Form 1040 Individual Tax Return.pdf
[2011/05/06 18:49:58 | 000,000,795 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/05/05 03:04:10 | 000,850,042 | —- | C] () – C:\Documents and Settings\HP_Owner\My Documents\MosleyPacquiaoDraw.jpg
[2011/05/04 10:54:08 | 000,000,296 | —- | C] () – C:\WINDOWS\tasks\recordpadShakeIcon.job
[2011/05/01 02:15:02 | 000,036,091 | —- | C] () – C:\Documents and Settings\HP_Owner\My Documents\Sunami001.jpg
[2011/04/25 20:02:31 | 000,344,718 | —- | C] () – C:\Documents and Settings\HP_Owner\My Documents\USPSReship.jpg
[2011/04/22 22:50:42 | 000,259,984 | —- | C] () – C:\Documents and Settings\HP_Owner\My Documents\Wendy030
[2011/04/17 01:27:25 | 000,202,034 | —- | C] () – C:\Documents and Settings\HP_Owner\My Documents\savedImage44.jpg
[2011/04/17 01:23:21 | 000,330,693 | —- | C] () – C:\Documents and Settings\HP_Owner\My Documents\savedImage31
[2011/04/17 01:22:51 | 000,231,943 | —- | C] () – C:\Documents and Settings\HP_Owner\My Documents\savedImage45
[2011/04/17 01:22:11 | 000,283,309 | —- | C] () – C:\Documents and Settings\HP_Owner\My Documents\savedImage44
[2011/04/17 01:20:59 | 000,275,879 | —- | C] () – C:\Documents and Settings\HP_Owner\My Documents\savedImage43
[2011/04/16 23:26:08 | 000,063,863 | —- | C] () – C:\Documents and Settings\HP_Owner\My Documents\billDetailDownload.pdf
[2011/04/16 15:09:05 | 000,220,205 | —- | C] () – C:\Documents and Settings\HP_Owner\My Documents\savedImage29
[2011/04/16 04:10:12 | 000,807,646 | —- | C] () – C:\Documents and Settings\HP_Owner\My Documents\5DimesFieldWager.jpg
[2011/04/16 04:00:17 | 000,001,831 | —- | C] () – C:\Documents and Settings\HP_Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Payroll Mate (2011).lnk
[2011/04/16 04:00:17 | 000,001,811 | —- | C] () – C:\Documents and Settings\HP_Owner\Desktop\Payroll Mate (2011).lnk
[2011/04/16 01:26:36 | 000,054,156 | -H– | C] () – C:\WINDOWS\QTFont.qfn
[2011/04/16 01:26:36 | 000,001,409 | —- | C] () – C:\WINDOWS\QTFont.for
[2011/04/15 02:09:35 | 002,270,369 | —- | C] () – C:\Documents and Settings\HP_Owner\My Documents\Clipboard03.jpg
[2011/04/11 23:59:37 | 000,416,457 | —- | C] () – C:\Documents and Settings\HP_Owner\My Documents\TheGreekHockey.jpg
[2010/08/22 19:00:14 | 000,088,397 | —- | C] () – C:\WINDOWS\hpoins06.dat
[2010/08/22 19:00:14 | 000,005,389 | —- | C] () – C:\WINDOWS\hpomdl06.dat
[2010/08/22 18:26:09 | 000,077,824 | R— | C] () – C:\WINDOWS\System32\hpzids01.dll
[2010/08/22 18:17:07 | 000,000,552 | —- | C] () – C:\WINDOWS\System32\d3d8caps.dat
[2010/08/22 18:12:36 | 000,000,131 | —- | C] () – C:\Documents and Settings\HP_Owner\Local Settings\Application Data\fusioncache.dat
[2010/08/22 16:05:42 | 000,088,397 | —- | C] () – C:\WINDOWS\hpoins06.dat.temp
[2010/08/22 16:05:42 | 000,005,389 | —- | C] () – C:\WINDOWS\hpomdl06.dat.temp
[2010/05/01 19:45:01 | 008,892,928 | —- | C] () – C:\Documents and Settings\All Users\Application Data\atscie.msi
[2010/01/04 02:18:35 | 000,000,312 | —- | C] () – C:\WINDOWS\EReg515.dat
[2010/01/04 02:16:18 | 000,001,356 | —- | C] () – C:\WINDOWS\disney.ini
[2009/11/22 22:35:51 | 000,260,608 | —- | C] () – C:\WINDOWS\PEV.exe
[2009/11/22 22:35:51 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2009/11/22 22:35:51 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2009/11/22 22:35:51 | 000,077,312 | —- | C] () – C:\WINDOWS\MBR.exe
[2009/11/22 22:35:51 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2009/08/19 18:35:36 | 000,001,044 | —- | C] () – C:\Documents and Settings\HP_Owner\Application Data\vso_ts_preview.xml
[2009/08/19 18:35:13 | 000,007,887 | —- | C] () – C:\Documents and Settings\HP_Owner\Application Data\pcouffin.cat
[2009/08/19 18:35:13 | 000,001,144 | —- | C] () – C:\Documents and Settings\HP_Owner\Application Data\pcouffin.inf
[2008/11/22 02:45:35 | 000,006,550 | —- | C] () – C:\WINDOWS\jautoexp.dat
[2008/05/01 20:54:56 | 000,002,528 | —- | C] () – C:\Documents and Settings\HP_Owner\Application Data\$_hpcst$.hpc
[2008/01/11 02:25:42 | 000,000,017 | —- | C] () – C:\WINDOWS\MovingPicture.ini
[2007/12/17 16:19:50 | 000,000,015 | —- | C] () – C:\WINDOWS\2693-C7CF-41DD-E164.dat
[2007/11/25 15:03:03 | 000,000,214 | —- | C] () – C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2007/11/25 15:02:54 | 000,000,227 | —- | C] () – C:\WINDOWS\HP_CounterReport_Update_HPSU.ini
[2007/11/25 15:02:43 | 000,000,221 | —- | C] () – C:\WINDOWS\HP_RedboxHprblog_HPSU.ini
[2007/11/25 15:02:33 | 000,000,214 | —- | C] () – C:\WINDOWS\HP_InstantSHareJPG.ini
[2007/11/25 15:02:23 | 000,000,228 | —- | C] () – C:\WINDOWS\HP_ISRegionListUpdatelog_HPSU.ini
[2007/11/25 15:02:13 | 000,000,217 | —- | C] () – C:\WINDOWS\HP_IZClosingDiscErrorPatch.ini
[2007/11/25 15:02:03 | 000,000,234 | —- | C] () – C:\WINDOWS\PrnHlpLogConfig.ini
[2007/07/08 03:06:25 | 000,001,429 | —- | C] () – C:\WINDOWS\mozver.dat
[2007/03/02 06:28:11 | 004,965,360 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2006/07/10 22:05:50 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2006/05/07 05:52:38 | 000,000,281 | —- | C] () – C:\WINDOWS\EReg072.dat
[2006/03/21 12:33:49 | 000,202,752 | —- | C] () – C:\WINDOWS\CDAC14BA.DLL
[2006/03/21 12:33:49 | 000,020,992 | —- | C] () – C:\WINDOWS\CDAC13BA.EXE
[2006/03/21 12:33:41 | 000,001,345 | —- | C] () – C:\WINDOWS\MPCWIN02.INI
[2006/01/31 07:42:58 | 000,000,512 | —- | C] () – C:\Documents and Settings\HP_Owner\Application Data\wklnhst.dat
[2006/01/04 15:09:49 | 000,003,072 | —- | C] () – C:\WINDOWS\wpdsvr.exe
[2006/01/04 14:56:10 | 000,000,687 | —- | C] () – C:\WINDOWS\eReg.dat
[2005/12/25 06:34:18 | 000,118,784 | —- | C] () – C:\WINDOWS\dsdxirmv.exe
[2005/12/09 21:55:57 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2005/12/09 21:55:01 | 000,000,028 | —- | C] () – C:\WINDOWS\atid.ini
[2005/12/09 05:25:47 | 000,156,160 | —- | C] () – C:\Documents and Settings\HP_Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005/11/23 04:58:01 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/11/23 04:34:23 | 000,118,842 | R— | C] () – C:\WINDOWS\HPCPCUninstaller-6.3.2.116-9972322.exe
[2005/11/23 04:33:13 | 000,013,543 | —- | C] () – C:\WINDOWS\System32\CHODDI.SYS
[2005/11/23 04:33:07 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\hpreg.dll
[2005/11/23 04:31:20 | 000,000,172 | —- | C] () – C:\WINDOWS\Quicken.ini
[2005/11/23 04:27:36 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/11/23 04:22:51 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2005/11/23 04:22:51 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2005/11/23 04:22:51 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2005/11/23 04:22:51 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2005/11/23 04:22:51 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2005/11/23 04:22:51 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2005/11/23 04:18:00 | 000,000,056 | —- | C] () – C:\WINDOWS\WININIT.INI
[2005/11/23 04:06:53 | 000,072,881 | —- | C] () – C:\WINDOWS\hpiins01.dat
[2005/11/23 04:06:01 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2005/11/23 04:02:15 | 000,044,330 | —- | C] () – C:\WINDOWS\System32\hptina.ini
[2005/11/23 04:02:15 | 000,000,191 | —- | C] () – C:\WINDOWS\System32\ctzapxx.ini
[2005/11/23 04:00:30 | 000,313,207 | —- | C] () – C:\WINDOWS\System32\ctstatic.dat
[2005/11/23 04:00:30 | 000,293,547 | —- | C] () – C:\WINDOWS\System32\ctdlang.dat
[2005/11/23 04:00:30 | 000,265,066 | —- | C] () – C:\WINDOWS\System32\ctsbas2w.dat
[2005/11/23 04:00:30 | 000,231,821 | —- | C] () – C:\WINDOWS\System32\CTSBASW.DAT
[2005/11/23 04:00:30 | 000,140,643 | —- | C] () – C:\WINDOWS\System32\ctbas2w.dat
[2005/11/23 04:00:30 | 000,113,221 | —- | C] () – C:\WINDOWS\System32\CTBASICW.DAT
[2005/11/23 04:00:30 | 000,053,932 | —- | C] () – C:\WINDOWS\System32\ctdaught.dat
[2005/11/23 04:00:30 | 000,038,400 | —- | C] () – C:\WINDOWS\System32\CTBURST.DLL
[2005/11/23 04:00:30 | 000,034,304 | —- | C] () – C:\WINDOWS\PSCONV.EXE
[2005/11/23 04:00:30 | 000,033,792 | —- | C] () – C:\WINDOWS\System32\REGPLIB.EXE
[2005/11/23 04:00:29 | 000,000,194 | —- | C] () – C:\WINDOWS\System32\KILL.INI
[2005/11/23 03:59:45 | 001,662,976 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2005/11/23 03:59:45 | 001,519,616 | —- | C] () – C:\WINDOWS\System32\nwiz.exe
[2005/11/23 03:59:45 | 001,466,368 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2005/11/23 03:59:45 | 001,339,392 | —- | C] () – C:\WINDOWS\System32\nvdspsch.exe
[2005/11/23 03:59:45 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2005/11/23 03:59:45 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2005/11/23 03:59:45 | 000,442,368 | —- | C] () – C:\WINDOWS\System32\nvappbar.exe
[2005/11/23 03:48:34 | 000,000,780 | —- | C] () – C:\WINDOWS\orun32.ini
[2005/11/23 03:45:51 | 000,323,584 | —- | C] () – C:\WINDOWS\System32\pythoncom22.dll
[2005/11/23 03:45:51 | 000,094,208 | —- | C] () – C:\WINDOWS\System32\pywintypes22.dll
[2005/11/23 03:45:34 | 000,016,896 | —- | C] () – C:\WINDOWS\System32\bcbmm.dll
[2005/07/07 16:07:24 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2005/06/25 02:29:32 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2005/06/25 01:43:44 | 000,411,566 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2005/06/25 01:43:44 | 000,066,392 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2005/06/25 01:42:06 | 000,204,920 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2005/06/25 01:31:46 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2005/06/25 01:30:20 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2005/05/10 03:52:32 | 000,022,396 | —- | C] () – C:\WINDOWS\System32\drivers\USBkey.sys
[2004/08/04 15:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/04 08:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/04 08:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/04 08:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/04 08:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/04 08:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/04 08:00:00 | 000,027,440 | —- | C] () – C:\WINDOWS\System32\drivers\secdrv.sys
[2004/08/04 08:00:00 | 000,001,788 | —- | C] () – C:\WINDOWS\System32\Dcache.bin
[2004/08/04 08:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2004/06/16 01:38:02 | 000,000,560 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2001/08/23 19:12:28 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2001/08/23 19:11:02 | 000,004,490 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2001/08/23 08:00:00 | 000,008,192 | R— | C] () – C:\WINDOWS\mtexp.dat
[2001/07/07 02:30:00 | 000,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini

========== Custom Scans ==========


< >

< %SYSTEMDRIVE%\*.* >
[2009/11/06 12:03:35 | 000,000,000 | -HS- | M] () – C:\1872244670
[2008/05/01 21:07:38 | 000,002,976 | —- | M] () – C:\additdiag.txt
[2009/11/02 20:30:02 | 000,030,502 | —- | M] () – C:\ASLog.txt
[2005/11/23 04:30:44 | 000,000,050 | —- | M] () – C:\AUTOEXEC.BAT
[2010/08/22 22:07:53 | 000,000,213 | RHS- | M] () – C:\BOOT.BAK
[2010/08/22 18:19:14 | 000,000,283 | RHS- | M] () – C:\boot.ini
[2004/08/04 08:00:00 | 000,260,272 | RHS- | M] () – C:\cmldr
[2009/12/03 01:21:23 | 000,013,286 | —- | M] () – C:\ComboFix.txt
[2005/06/25 01:32:00 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2007/03/04 11:10:22 | 000,106,497 | —- | M] () – C:\debug.log
[2011/05/09 00:22:45 | 2145,894,400 | -HS- | M] () – C:\hiberfil.sys
[2005/06/25 01:32:00 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/07/13 21:13:57 | 000,000,724 | -H– | M] () – C:\IPH.PH
[2009/10/07 14:29:49 | 000,000,069 | —- | M] () – C:\kl2log.htm
[2010/08/16 08:42:16 | 000,187,055 | —- | M] () – C:\mombi.log
[2005/06/25 01:32:00 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2007/07/22 03:48:41 | 000,001,186 | —- | M] () – C:\net_save.dna
[2004/08/04 08:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2004/08/04 08:00:00 | 000,250,032 | RHS- | M] () – C:\ntldr
[2011/05/09 00:22:44 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
[2009/12/31 23:55:32 | 000,029,875 | —- | M] () – C:\RunSilent.txt
[2006/06/18 19:59:19 | 000,581,880 | —- | M] () – C:\sweb_install.log
[2007/02/08 16:30:31 | 000,036,607 | —- | M] () – C:\VETlog.dmp
[2007/02/08 16:30:31 | 000,014,142 | —- | M] () – C:\VETlog.txt

< %systemroot%\Fonts\*.com >
[2006/04/18 16:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 15:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 16:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 15:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >
[2005/05/11 23:36:48 | 000,012,288 | —- | M] (Hewlett-Packard Co.) – C:\WINDOWS\Fonts\RandFont.dll

< %systemroot%\Fonts\*.ini >
[2005/06/25 01:31:38 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 08:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2005/05/05 08:48:54 | 000,067,072 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp3xu.dll
[2003/06/19 04:31:48 | 000,018,944 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 06:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >
[2010/04/20 21:24:37 | 000,001,538 | -H– | M] () – C:\Documents and Settings\HP_Owner\Application Data\Microsoft\LastFlashConfig.WFC

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2005/06/24 18:25:14 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2005/06/24 18:25:14 | 000,634,880 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2005/06/24 18:25:14 | 000,884,736 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2005/06/25 01:32:04 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
[2006/03/21 03:59:48 | 000,000,177 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Free AOL & Unlimited Internet.url

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2005/12/08 19:39:37 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\HP_Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2005/06/24 18:42:40 | 000,000,079 | —- | M] () – C:\Documents and Settings\HP_Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2011/05/09 02:54:06 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\HP_Owner\Desktop\OTL.exe
[2008/09/25 15:19:18 | 014,968,808 | —- | M] (Safer Networking Limited ) – C:\Documents and Settings\HP_Owner\Desktop\spybotsd160.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< End of report >






OTL Extras logfile created on: 5/9/2011 2:58:13 AM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\HP_Owner\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 76.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 89.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 458.24 Gb Total Space | 291.95 Gb Free Space | 63.71% Space Free | Partition Type: NTFS
Drive D: | 7.50 Gb Total Space | 1.16 Gb Free Space | 15.47% Space Free | Partition Type: FAT32
Unable to calculate disk information.

Computer Name: YOUR-27E1513D96 | User Name: HP_Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe" = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe:*:Enabled:Updates from HP – (Hewlett-Packard)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe" = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe:*:Enabled:Updates from HP – (Hewlett-Packard)
"C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" = C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe" = C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe – ()
"C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe – ( )
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe – (Hewlett-Packard Co.)
"C:\Program Files\LimeWire\LimeWire.exe" = C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire – ()
"C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe" = C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe:LocalSubNet:Disabled:Intuit Update Shared Downloads Server – (Intuit Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{03B1B42B-F6DE-41d9-8CFF-DC44E895C7A7}" = PhotoGallery
"{05BDC796-3451-4F81-B91D-E98F7ADA76C2}" = TurboTax 2010 WinPerTaxSupport
"{0611BD4E-4FE4-4a62-B0C0-18A4CC463428}" = CP_Package_Variety1
"{075473F5-846A-448B-BCB3-104AA1760205}" = Sonic RecordNow Data
"{09984AEC-6B9F-4ca7-B78D-CB44D4771DA3}" = Destinations
"{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}" = Microsoft Plus! Photo Story 2 LE
"{1330F885-F8E4-4c36-9B88-E19F82042C06}" = 3100_3200_3300trb
"{14589F05-C658-4594-9429-D437BA688686}" = IntelliMover Data Transfer Demo
"{15EE79F4-4ED1-4267-9B0F-351009325D7D}" = HP Software Update
"{172975EB-9465-4861-95B5-C7BB6D3DE62A}" = DocumentViewer
"{1A103D70-5C9B-4E1A-B306-5106C68F9914}" = Microsoft Plus! Dancer LE
"{1C139D7D-9FEA-468d-A9C8-2A6E3BDE564A}" = CP_Package_Variety3
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{21657574-BD54-48A2-9450-EB03B2C7FC29}" = Sonic MyDVD Plus
"{21DB3D90-D816-4092-A260-CA3F6B55A6DD}" = Sonic_PrimoSDK
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{23A7B376-BBEC-4e76-BBD7-0F155E70D74B}" = CP_Panorama1Config
"{26A24AE4-039D-4CA4-87B4-2F83216024FF}" = Java™ 6 Update 24
"{2C3D719A-92C7-4323-89CC-C937D0267B84}" = muvee autoProducer 4.0
"{2C5D07FB-31A2-4F2D-9FDA-0B24ACD42BD0}" = HP Deskjet Printer Preload
"{2CADCEAB-D5DA-44D6-B5FC-7DEE87AB3C0C}" = Unload
"{2DBE41DD-2129-4C65-A3D3-5647236A60F3}" = Quicken 2005
"{2E0C1913-886B-4C5C-8DAF-D1E649CE5FCC}" = Creative MediaSource
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
"{30C19FF2-7FBA-4d09-B9DE-1659977F64F6}" = TrayApp
"{32BDCCB8-9DC8-496d-9DB1-F77510775BDB}" = InstantShareDevices
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{36E47DA1-10E1-45d9-8B19-14D19607CDCF}" = CP_CalendarTemplates1
"{3782EC09-4000-475E-8A59-9CABD6F03B4C}" = TurboTax 2010 WinPerFedFormset
"{3881DB80-EAA2-012B-ADAE-000000000000}" = TurboTax 2009 WinPerFedFormset
"{38975F50-EAA2-012B-ADB4-000000000000}" = TurboTax 2009 WinPerReleaseEngine
"{38A34630-EAA2-012B-ADB6-000000000000}" = TurboTax 2009 WinPerTaxSupport
"{3912A629-0020-0005-3757-2FBA74D4DF0A}" = InterVideo WinDVD Player
"{39C16060-EAA2-012B-ADFC-000000000000}" = TurboTax 2009 wmiiper
"{3BA95526-6AE0-4B87-A62D-17187EF565FC}" = HP Boot Optimizer
"{3C5A81D0-EAA2-012B-AE9F-000000000000}" = TurboTax 2009 wrapper
"{3E386744-10FA-44b2-98C9-DF7A270DECB3}" = HP PSC & OfficeJet 5.3.A
"{416D80BA-6F6D-4672-B7CF-F54DA2F80B44}" = Microsoft Works
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4ED47439-5232-4BBC-93F2-7BC895B56246}" = 3300
"{4F2FCCCF-29F3-44B9-886F-6D16F8417522}" = TurboTax 2010 wrapper
"{50E7BB78-02B4-469a-9D8B-B2F42835F90E}" = ProductContextNPI
"{523E6F2A-2D59-4D91-90E8-6C49931C9F50}" = iTunes
"{53EE9E42-CECB-4C92-BF76-9CA65DAF8F1C}" = FullDPAppQFolder
"{567C23E1-7580-4185-B8C2-30805677297C}" = NewCopy_CDA
"{56EE8B17-8274-418d-89AC-C057C5DB251E}" = RandMap
"{56F8AFC3-FA98-4ff1-9673-8A026CBF85BE}" = WebReg
"{5A01C58E-B0EC-49b9-AD71-7C0468688087}" = CP_Package_Basic1
"{5BA1D11C-B981-4CAA-B2B5-B8ADF413EBA5}" = Pure Networks Platform
"{5F26311C-B135-4F7F-B11E-8E650F83651E}" = DeviceFunctionQFolder
"{64D5E9DE-7890-4FB0-8865-8B24BE1773F7}" = LightScribe [removed]
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Sonic Express Labeler
"{66BA8C26-AFE4-4408-807B-43E76B57EF53}" = SkinsHP1
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{6BB6627C-694F-4FDC-A3E5-C7F4BED4C724}" = DocProc
"{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}" = Microsoft Plus! Digital Media Edition Installer
"{7C03270C-4FAB-4F5C-B10D-52FEDA190790}" = DocumentViewerQFolder
"{7E27304E-BAA2-4d90-A34E-76641FAFABB4}" = CP_AtenaShokunin1Config
"{7FCC4EDC-6EE2-4309-ABD7-85F2667A7B90}" = WebEx Support Manager for Internet Explorer
"{8105684D-8CA6-440D-8F58-7E5FD67A499D}" = Easy Internet Sign-up
"{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder
"{90280409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional with FrontPage
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD Player
"{923A7F5A-1E8C-4FBE-8DF6-85940A60A79F}" = Readme
"{9E5A03E3-6246-4920-9630-0527D5DA9B07}" = iSEEK AnswerWorks English Runtime
"{A195B13E-A5E3-4BAF-A995-7F70F445CD06}" = ScannerCopy
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A525E00B-6609-442E-9DCD-64453C233E8D}" = TurboTax 2010 WinPerReleaseEngine
"{A5BB5365-EFB4-44c3-A7E2-EB59B7EFD23D}" = CueTour
"{A8AD6CB8-DE96-43FA-9B73-5FB873DD1CAE}" = Sound Blaster Audigy 4
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AB61A692-5543-4C48-979B-8CEA1C52FE9C}" = PC-Doctor 5 for Windows
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Sonic RecordNow Audio
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.2
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Sonic RecordNow Copy
"{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}" = Adobe AIR
"{B276997E-4367-4b1b-A39C-4CAE7464337A}" = AiO_Scan_CDA
"{B4D279F1-4309-49cc-A4B5-3A0D2E59C7B5}" = PanoStandAlone
"{B60E7826-F117-4d26-8165-D2DC5A494AB0}" = Fax_CDA
"{B64E3AFC-59EF-4f18-BF11-E751462450D3}" = AiOSoftwareNPI
"{B824B5C9-849F-4b9e-9EA7-6FD8CD8116DA}" = CP_Package_Variety2
"{B996AE66-10DB-4ac5-B151-E8B4BFBC42FC}" = BufferChm
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C14201FD-245D-4CA9-A582-47D842C6AC59}" = TurboTax 2010 wmiiper
"{C506A18C-1469-4678-B094-F4EC9DAE6DB7}" = Scan
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0122362-6333-4DE4-93F6-A5A2F3CC101A}" = HP Organize
"{DB518BA6-CB74-4EB6-9ABD-880B6D6E1F38}" = HpSdpAppCoreApp
"{E3F90083-80D4-4b5a-87C7-E97E12F5516D}" = HPProductAssistant
"{EA103B64-C0E4-4C0E-A506-751590E1653D}" = SolutionCenter
"{ECFDD6BD-E0C0-41CC-A171-E6D6AF4C0E93}" = HP Software Update
"{F1931CAB-C7DD-4825-8A58-BC5278805200}" = 3100_3200_3300_Help
"{F4C2E5F5-2970-45f4-ABD3-C180C4D961C4}" = Status
"010D7E30-8019-4477-AE7C-BFBBDE570CB9" = Insaniquarium Deluxe from Hewlett-Packard Desktops (remove only)
"0B99A43B-A792-4003-9295-604BC687B6F6" = Big Kahuna Reef from Hewlett-Packard Desktops (remove only)
"1E728F26-D920-45F1-9E97-4A5690B07A7F" = Jewel Quest from Hewlett-Packard Desktops (remove only)
"27C7083E-4ECB-4C88-ACC1-0EDA88C00257" = Ricochet Lost Worlds from Hewlett-Packard Desktops (remove only)
"3295A049-B970-4CC5-847C-7ABF14B9F8F1" = Mah Jong Quest from Hewlett-Packard Desktops (remove only)
"36317AE4-57EC-4F3E-B828-009A3DD96BE8" = Polar Bowler from Hewlett-Packard Desktops (remove only)
"3F34F72F-9BB0-4B73-8312-558953ACF56F" = Super Granny from Hewlett-Packard Desktops (remove only)
"46CD7AAB-D3C9-41DB-8AEC-5BD24169B0E1" = Flip Words from Hewlett-Packard Desktops (remove only)
"47298745-7194-4142-AFDA-8BE2EDFDF82E" = Bookworm Deluxe from Hewlett-Packard Desktops (remove only)
"5253F22E-D4B6-49B7-9106-28D9C5395F22" = Barnyard Invasion from Hewlett-Packard Desktops (remove only)
"58D1A004-6D3C-480A-9E0D-FAA58F3C2A62" = Blackhawk Striker 2 from Hewlett-Packard Desktops (remove only)
"5F5B2E2A-5924-4DAB-825A-10BEA50A4DA1" = Boggle Supreme from Hewlett-Packard Desktops (remove only)
"663A22CB-3C2B-4302-9A14-BC5DAFAB2071" = FATE Demo from Hewlett-Packard Desktops (remove only)
"6E4D87E1-83A3-4029-A9E4-2F360442E1FC" = SCRABBLE Rack Attack from Hewlett-Packard Desktops (remove only)
"703E3900-69DA-47C9-9768-C6514098F149" = Shrek 2 Ogre Bowler from Hewlett-Packard Desktops (remove only)
"7978E9A8-5A11-4406-BA8F-866E120352DF" = Bejeweled 2 Deluxe from Hewlett-Packard Desktops (remove only)
"8C4E79CC-03E1-43AA-9910-9A5113F24603" = Blasterball 2 from Hewlett-Packard Desktops (remove only)
"95A4B97A-C363-41DD-B907-BD4AB9E4FF16" = SCRABBLE Blast from Hewlett-Packard Desktops (remove only)
"A9C7B4D4-A866-4696-B115-77B65D0A641A" = Swarm from Hewlett-Packard Desktops (remove only)
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Agere Systems Soft Modem" = Agere Systems PCI Soft Modem
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"B2D3332F-EA2D-42B3-8E4A-F74D052BCBC1" = Polar Golfer from Hewlett-Packard Desktops (remove only)
"B41503CB-5FE0-47E0-87C1-47BA8E660BCC" = Blasterball 2 Holidays from Hewlett-Packard Desktops (remove only)
"BA910432-2C22-4BB8-9D13-46170F52C5AC" = Puzzle Express from Hewlett-Packard Desktops (remove only)
"C1241092-7183-480A-A289-B5920C7C56D0" = Slingo Deluxe from Hewlett-Packard Desktops (remove only)
"C2C3C2DB-7D8A-4E20-B527-E3149FAECC3A" = Slyder from Hewlett-Packard Desktops (remove only)
"Creative MuVo N200 Media Explorer" = Creative MuVo N200 Media Explorer
"D11F7128-8CBD-408B-8BF8-034604DEDD42" = Bounce Symphony from Hewlett-Packard Desktops (remove only)
"D3203C96-6C76-43D6-A3D0-5DD6A0732E83" = SCRABBLE from Hewlett-Packard Desktops (remove only)
"DAE7A92A-BAC7-42FA-AC62-53DEF1DC4292" = Crystal Maze from Hewlett-Packard Desktops (remove only)
"DBS2K" = DBS2K 2.42
"ED8E7ECA-9D6A-46BA-BF46-D97774AA7117" = Digby's Donuts from Hewlett-Packard Desktops (remove only)
"F5215F01-DFC0-475D-A910-6F1AF94E807E" = Tradewinds from Hewlett-Packard Desktops (remove only)
"HP Document Viewer" = HP Document Viewer 5.3
"HP Game Console" = HP Game Console and games
"HP Imaging Device Functions" = HP Imaging Device Functions 5.3
"HP Photo & Imaging" = HP Image Zone 5.3
"HP Solution Center & Imaging Support Tools" = HP Solution Center & Imaging Support Tools 5.3
"HPOOVClient-9972322 Uninstaller" = Updates from HP (remove only)
"ie8" = Windows Internet Explorer 8
"Install WeatherBug" = Remove WeatherBug Installer
"InstallShield_{2DBE41DD-2129-4C65-A3D3-5647236A60F3}" = Quicken 2005
"InstallShield_{523E6F2A-2D59-4D91-90E8-6C49931C9F50}" = iTunes
"InstallShield_{8105684D-8CA6-440D-8F58-7E5FD67A499D}" = Easy Internet Sign-up
"InstallShield_{AB61A692-5543-4C48-979B-8CEA1C52FE9C}" = PC-Doctor 5 for Windows
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Money2005b" = Microsoft Money 2005
"NavNet_is1" = NavNet
"Network MagicUninstall" = Network Magic
"NVIDIA Drivers" = NVIDIA Drivers
"Payroll Mate (2011) Evaluation_is1" = Payroll Mate 2011
"PROSet" = Intel® PRO Network Connections Drivers
"PS2" = PS2
"Python 2.2.3" = Python 2.2.3
"pywin32-py2.2" = Python 2.2 pywin32 extensions (build 203)
"QuickTime" = QuickTime
"RealPlayer 6.0" = RealPlayer
"Recordpad" = RecordPad Sound Recorder
"SoundTap" = SoundTap Streaming Audio Recorder
"Switch" = Switch Sound File Converter
"TurboTax 2010" = TurboTax 2010
"WavePad" = WavePad Sound Editor
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows Media Player" = Windows Media Player 10
"WinRAR archiver" = WinRAR 4.00 (32-bit)

========== Last 10 Event Log Errors ==========

Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!

< End of report >





The GMER LOG didn't work. Scan took 5 + hours I tried to save the file. Computer said insufficient memory. Couldn't save file. Had to restart computer.




Results of screen317's Security Check version 0.99.10
Windows XP Service Pack 2
Out of date service pack!!
Internet Explorer 8
``````````````````````````````
Antivirus/Firewall Check:

Windows Firewall Enabled!
Avira AntiVir Personal - Free Antivirus
Avira successfully updated!
```````````````````````````````
Anti-malware/Other Utilities Check:

Malwarebytes' Anti-Malware
Java™ 6 Update 24
Adobe Flash Player
Adobe Reader 9.4.2
Out of date Adobe Reader installed!
````````````````````````````````
Process Check:
objlist.exe by Laurent

Avira Antivir avgnt.exe
Avira Antivir avguard.exe
``````````End of Log````````````
I need you to try and check only both "Sections" and "C:\" ; leaving all others unchecked.

If that fails, please try to run it in Safe Mode and again with the same settings as above.

Reboot your computer in Safe Mode
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
Tutorial if you need it How to boot into Safemode

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI