This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Slow computer PLUS new Malware found using Search & Destory

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I recently restore my PC to original factory settings, using boot CDs. After a week, my computer still runs slows, something freezes. I run a Search & Destroy everything other day, and it found some Malware. Even after I remove it, using Search & destroy, they appear again & again. attached is the screenshot.

Attachments:

:welcome:

Looks like there just tracking cookies, when you delete them they will just come back


Lets check a few things

Download aswMBR.exe ( 511KB ) to your desktop.

Double click the aswMBR.exe to run it

Click the "Scan" button to start scan
[external image: Posted Image]

On completion of the scan click save log, save it to your desktop and post in your next reply
[external image: Posted Image]






Download DDS from one of the links below to your desktop

Link 1
Link 2

  • Double click the tool to run it.
  • A black Screen will open, just read the contents and do nothing.
  • When the tool finishes, it will open 2 reports, DDS.txt and attach.txt
  • Copy/Paste the contents of 'DDS.txt' into your post.
  • 'attach.txt' should be zipped using Windows native zip utility and attached to your post. Compress and uncompress files (zip files)
Thanks for replying. when I ran aswMBR, I did not see the "Scan Succesfully Finished", so I saved the log. aswMBR version 0.9.8.986 Copyrightยฉ 2011 AVAST Software Run date: 2011-08-30 18:03:09 โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€“ 18:03:09.125 OS Version: Windows 5.1.2600 Service Pack 3 18:03:09.125 Number of processors: 1 586 0x207 18:03:09.125 ComputerName: COMPUTERPC1 UserName: bashir 18:03:10.015 Initialize success 18:03:18.156 AVAST engine defs: 11083001 18:03:34.046 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 18:03:34.046 Disk 0 Vendor: WDC_WD800AB-22CBA1 04.07B04 Size: 76319MB BusType: 3 18:03:36.062 Disk 0 MBR read successfully 18:03:36.062 Disk 0 MBR scan 18:03:36.109 Disk 0 Windows XP default MBR code 18:03:36.109 Disk 0 scanning sectors +156280320 18:03:36.203 Disk 0 scanning C:\WINDOWS\system32\drivers 18:04:30.531 Service scanning 18:04:31.218 Service SysPlant C:\WINDOWS\SYSTEM32\Drivers\SysPlant.sys **LOCKED** 32 18:04:31.218 Service Teefer2 C:\WINDOWS\System32\DRIVERS\teefer2.sys **LOCKED** 32 18:04:31.250 Service WPS C:\WINDOWS\System32\drivers\wpsdrvnt.sys **LOCKED** 32 18:04:31.250 Service WpsHelper C:\WINDOWS\System32\drivers\WpsHelper.sys **LOCKED** 32 18:04:31.765 Modules scanning 18:05:03.359 Disk 0 trace - called modules: 18:05:03.375 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS 18:05:03.375 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x89c00ab8] 18:05:03.375 3 CLASSPNP.SYS[f7637fd7] -> nt!IofCallDriver -> \Device\00000063[0x89bda1b0] 18:05:03.375 5 ACPI.sys[f75ae620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x89bbc940] 18:05:04.000 AVAST engine scan C:\WINDOWS 18:05:27.140 AVAST engine scan C:\WINDOWS\system32 18:12:24.468 AVAST engine scan C:\WINDOWS\system32\drivers 18:13:21.140 AVAST engine scan C:\Documents and Settings\bashir 18:24:06.734 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\bashir\Desktop\MBR.dat" 18:24:06.750 The log file has been saved successfully to "C:\Documents and Settings\bashir\Desktop\aswMBR.txt" . DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 8.0.6001.18702 Run by [removed] at 18:24:19 on 2011-08-30 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2047.998 [GMT -8:00] . AV: Symantec Endpoint Protection *Enabled/Outdated* {FB06448E-52B8-493A-90F3-E43226D3305C} FW: Symantec Endpoint Protection *Enabled* . ============== Running Processes =============== . C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe C:\WINDOWS\Explorer.EXE svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe C:\Program Files\compaq\Compaq Advisor\bin\compaq-rba.exe C:\WINDOWS\system32\ctfmon.exe C:\windows\system\hpsysdrv.exe C:\WINDOWS\System32\igfxtray.exe C:\WINDOWS\System32\hkcmd.exe C:\WINDOWS\system32\dla\tfswctrl.exe C:\Program Files\WildTangent\DDC\DDCManager\DDCMan.exe C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe C:\PROGRA~1\NORTON~1\navapw32.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\Lexmark Pro700 Series\lxeemon.exe C:\Program Files\Lexmark Pro700 Series\ezprint.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\SentrilockCardUtility\SentriLockCardUtility.exe C:\Program Files\Compaq\Easy Access Button Support\CPQEADM.EXE C:\Compaq\EAKDRV\EAUSBKBD.EXE C:\WINDOWS\System32\lxeecoms.exe C:\PROGRA~1\Compaq\EASYAC~1\BttnServ.exe C:\WINDOWS\System32\svchost.exe -k imgsvc C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe C:\WINDOWS\system32\wscntfy.exe C:\Program Files\Tenda\Common\RaRegistry.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Firefox\plugin-container.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.yahoo.com/ uSearch Page = hxxp://rd.yahoo.com/customize/yessentials_cq/defaults/sp/*http://www.yahoo.com uWindow Title = Windows Internet Explorer provided by MSN & Bing mSearch Bar = hxxp://rd.yahoo.com/customize/yessentials_cq/defaults/sb/*http://www.yahoo.com/search/ie.html BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll BHO: CNavExtBho Class: {bdf3e430-b101-42ad-a544-fadc6b084872} - c:\program files\norton antivirus\NavShExt.dll BHO: Lexmark Printable Web: {d2c5e510-be6d-42cc-9f61-e4f939078474} - c:\program files\lexmark printable web\bho.dll BHO: {fdd3b846-8d59-4ffb-8758-209b6ad74acc} - c:\program files\microsoft money\system\mnyviewer.dll TB: Norton AntiVirus: {42cdd1bf-3ffb-4238-8ad1-7859df00b1d6} - c:\program files\norton antivirus\NavShExt.dll EB: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - No File EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [DriverMax] uRun: [DriverMax_RESTART] mRun: [hpsysdrv] c:\windows\system\hpsysdrv.exe mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [StorageGuard] "c:\program files\veritas software\update manager\sgtray.exe" /r mRun: [dla] c:\windows\system32\dla\tfswctrl.exe mRun: [Recguard] c:\windows\sminst\RECGUARD.EXE mRun: [WCOLOREAL] "c:\program files\compaq\coloreal\coloreal.exe" mRun: [DDCM] "c:\program files\wildtangent\ddc\ddcmanager\DDCMan.exe" -Background mRun: [DDCActiveMenu] "c:\program files\wildtangent\ddc\activemenu\DDCActiveMenu.exe" -boot mRun: [srmclean] c:\cpqs\scom\srmclean.exe mRun: [CPQEASYACC] c:\program files\compaq\easy access button support\StartEAK.exe mRun: [NAV CfgWiz] c:\progra~1\norton~1\Cfgwiz.exe /R mRun: [NAV Agent] c:\progra~1\norton~1\navapw32.exe mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [lxeemon.exe] "c:\program files\lexmark pro700 series\lxeemon.exe" mRun: [EzPrint] "c:\program files\lexmark pro700 series\ezprint.exe" mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\sentri~1.lnk - c:\windows\installer\{c9b8d365-a6c3-4c4d-9624-0f0078feb1b4}\Icon037926361.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\tendaw~1.lnk - c:\program files\tenda\common\RaUI.exe IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office12\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~4\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office12\REFIEBAR.DLL IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll IE: {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - {301DA1EE-F65C-4188-A417-9E915CC8FBFA} - c:\program files\microsoft money\system\mnyviewer.dll DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/products/plugin/1.3.1/jinstall-131-win.cab DPF: {BEA7310D-06C4-4339-A784-DC3804819809} - hxxp://www.cvsphoto.com/upload/activex/v3_0_0_7/PhotoCenter_ActiveX_Control.cab DPF: {CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/1.3.1/jinstall-131-win.cab TCP: DhcpNameServer = 192.168.1.1 [removed] TCP: Interfaces\{ABE09A71-AB51-4EE3-8C2E-E0CE5B367520} : DhcpNameServer = 192.168.1.1 [removed] Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll Notify: igfxcui - igfxsrvc.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll Hosts: 127.0.0.1 www.spywareinfo.com . ================= FIREFOX =================== . FF - ProfilePath - c:\documents and settings\bashir\application data\mozilla\firefox\profiles\4u3piybz.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll FF - plugin: c:\program files\microsoft silverlight\4.0.60531.0\npctrlui.dll . ============= SERVICES / DRIVERS =============== . R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccSvcHst.exe [2009-7-8 108392] R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSvcHst.exe [2009-7-8 108392] R2 lxee_device;lxee_device;c:\windows\system32\lxeecoms.exe -service โ€“> c:\windows\system32\lxeecoms.exe -service [?] R2 RalinkRegistryWriter;Ralink Registry Writer;c:\program files\tenda\common\RaRegistry.exe [2011-8-30 185632] R2 Scutum50;Scutum50 NDIS Protocol Driver;c:\windows\system32\drivers\Scutum50.sys [2011-8-30 19072] R2 Symantec AntiVirus;Symantec Endpoint Protection;c:\program files\symantec\symantec endpoint protection\Rtvscan.exe [2009-9-17 2477304] R2 ZDCNDIS5;ZDCNDIS5 NDIS5.1 Protocol Driver;c:\windows\system32\ZDCndis5.sys [2011-8-29 20736] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2011-7-15 102448] R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20101013.002\NAVENG.SYS [2011-7-15 86064] R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20101013.002\NAVEX15.SYS [2011-7-15 1371184] R3 rt2870;Ralink 802.11n USB Wireless LAN Card Driver;c:\windows\system32\drivers\rt2870.sys [2011-8-30 827488] S2 lxeeCATSCustConnectService;lxeeCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxeeserv.exe [2010-4-14 193192] S2 SBService;ScriptBlocking Service;c:\progra~1\common~1\symant~1\script~1\SBServ.exe [2001-8-14 54408] S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [2009-7-14 23888] S3 SCR3XX2K;SCR3xx USB SmartCardReader;c:\windows\system32\drivers\SCR3XX2K.sys [2011-6-16 59520] S4 NAVAP;NAVAP;c:\windows\system32\drivers\NAVAP.SYS [2001-8-4 182896] S4 navapsvc;Norton AntiVirus Auto Protect Service;c:\program files\norton antivirus\Navapsvc.exe [2001-8-17 115792] . =============== Created Last 30 ================ . 2011-08-31 01:32:21 796032 โ€”-a-w- c:\windows\system32\Scutum.dll 2011-08-31 01:32:21 200704 โ€”-a-w- c:\windows\system32\ssleay32.dll 2011-08-31 01:32:21 19072 โ€”-a-w- c:\windows\system32\drivers\Scutum50.sys 2011-08-31 01:32:21 180224 โ€”-a-w- c:\windows\system32\W32N55.dll 2011-08-31 01:32:21 152968 โ€”-a-w- c:\windows\system32\RalinkGina.dll 2011-08-31 01:32:21 147456 โ€”-a-w- c:\windows\system32\DiagFunc.dll 2011-08-31 01:32:21 1085440 โ€”-a-w- c:\windows\system32\libeay32.dll 2011-08-31 01:32:08 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files\Tenda 2011-08-31 01:31:45 827488 โ€”-a-w- c:\windows\system32\drivers\rt2870.sys 2011-08-31 01:31:45 238944 โ€”-a-w- c:\windows\system32\RaCoInst.dll 2011-08-31 01:31:43 โ€”โ€”โ€“ dโ€”โ€“w- c:\documents and settings\all users\application data\Tenda Driver 2011-08-30 01:48:26 94208 โ€”-a-w- c:\windows\system32\ZDCN50.dll 2011-08-30 01:48:26 20736 โ€”-a-w- c:\windows\system32\ZDCndis5.sys 2011-08-30 01:48:26 20608 โ€”-a-w- c:\windows\system32\drivers\BRGSp50.sys 2011-08-30 01:37:10 โ€”โ€”โ€“ dโ€”โ€“w- c:\windows\system32\wbem\repository\FS 2011-08-30 01:37:10 โ€”โ€”โ€“ dโ€”โ€“w- c:\windows\system32\wbem\Repository 2011-08-29 21:08:50 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files\Cisco 2011-08-29 01:04:54 โ€”โ€”โ€“ dโ€”โ€“w- c:\documents and settings\all users\application data\Atheros 2011-08-29 01:04:49 โ€”โ€”โ€“ dโ€”โ€“w- C:\SWSetup 2011-08-29 00:47:15 โ€”โ€”โ€“ dโ€”โ€“w- C:\temp 2011-08-29 00:22:57 โ€”โ€”โ€“ dโ€”โ€“w- c:\documents and settings\bashir\local settings\application data\Innovative Solutions 2011-08-29 00:22:57 โ€”โ€”โ€“ dโ€”โ€“w- c:\documents and settings\all users\application data\Innovative Solutions 2011-08-15 16:47:19 โ€”โ€”โ€“ dโ€”โ€“w- c:\documents and settings\all users\application data\Lexmark Pro700 Series 2011-08-11 03:25:11 139656 -cโ€”-w- c:\windows\system32\dllcache\rdpwd.sys 2011-08-11 03:24:16 10496 -cโ€”-w- c:\windows\system32\dllcache\ndistapi.sys 2011-08-05 17:54:07 โ€”โ€”โ€“ dโ€”โ€“w- c:\documents and settings\bashir\application data\SentriLock 2011-08-05 17:52:55 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files\SentrilockCardUtility 2011-08-05 17:52:41 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files\common files\Wise Installation Wizard 2011-08-05 17:52:41 โ€”โ€”โ€“ dโ€”โ€“w- c:\documents and settings\all users\application data\SentriLock . ==================== Find3M ==================== . 2011-08-31 01:31:52 4645 โ€”-a-w- c:\windows\compaq.reg 2011-07-16 18:00:56 335 โ€”-a-w- c:\windows\INET.reg 2011-07-16 01:36:24 404640 โ€”-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-07-15 18:52:59 60808 โ€”-a-w- c:\windows\system32\S32EVNT1.DLL 2011-07-15 18:52:59 124976 โ€”-a-w- c:\windows\system32\drivers\SYMEVENT.SYS 2011-07-15 13:29:31 456320 โ€”-a-w- c:\windows\system32\drivers\mrxsmb.sys 2011-07-08 14:02:00 10496 โ€”-a-w- c:\windows\system32\drivers\ndistapi.sys 2011-06-24 14:10:36 139656 โ€”-a-w- c:\windows\system32\drivers\rdpwd.sys 2011-06-23 18:36:30 916480 โ€”-a-w- c:\windows\system32\wininet.dll 2011-06-23 18:36:30 43520 โ€”โ€”w- c:\windows\system32\licmgr10.dll 2011-06-23 18:36:30 1469440 โ€”โ€”w- c:\windows\system32\inetcpl.cpl 2011-06-23 12:05:13 385024 โ€”โ€”w- c:\windows\system32\html.iec 2011-06-20 17:44:52 293376 โ€”-a-w- c:\windows\system32\winsrv.dll 2011-06-16 13:51:42 59520 โ€”-a-w- c:\windows\system32\drivers\SCR3XX2K.sys 2011-06-02 14:02:05 1858944 โ€”-a-w- c:\windows\system32\win32k.sys . ============= FINISH: 18:25:24.07 ===============
Symantec Endpoint Protection <โ€“ Was wondering why you had this installed ?

Please download Malwarebytes from Here or Here

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the report please
Hi,

Well what you have are both good, there two different things, Symantec is Anti Virus and Spybot is Anti Malware, you can keep them both with no problems.

Your DDS log looks ok and Malwarebytes found nothing so lets dig a bit deeper.

ESET Online Scanner
I'd like us to scan your machine with ESET OnlineScan

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the [external image: Posted Image] button.
  • Push [external image: Posted Image]
Please make sure you include the following items in your next post:
The log that was produced after running ESET Online Scanner.
I got a message "No Threats Found", there wasnt any option to export log. I am using : Pentium 4 CPU 2.40Ghz 2.39Ghz 2.0GB of RAM You think because my computer is old, and its time to upgrade?
Well, how old is it ? I still use a desktop I built with the same specs that your using, getting outdated but still runs fairly well. Prices have come down so getting a new system is totally up to you, the newer systems with Win 7 are lightning fast.

Lets take a final look


If you have never run a system cleaner before this program may bog down, you may have to just check one box per run until it cleans it all

Please download ATF Cleaner by Atribune to your desktop.
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
Your system may start up slower after running ATF Cleaner, this is expected but will be back to normal after the first or second boot up
Please note: If you use online banking or are registered online with any other organizations, ensure you have memorized password and other personal information as removing cookies will temporarily disable the auto-login facility. If you want to keep your log on info, just click on Select All and then uncheck cookies
[external image: Posted Image]





OTL by OldTimer
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Click the "Scan All Users" checkbox.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
it is about 7 yrs old. I have used "factory restored" from the original CDs, about few times within that period. do u know where can I buy good price,good PC. My friend is selling me HP Win 7, w/ wireless built-in for $150.

log is attached/

OTL logfile created on: 9/6/2011 12:39:55 PM - Run 1
OTL by OldTimer - Version 3.2.27.0 Folder = C:\Documents and Settings\bashir\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.44 Gb Available Physical Memory | 71.80% Memory free
3.85 Gb Paging File | 3.52 Gb Available in Paging File | 91.35% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 51.43 Gb Free Space | 69.02% Space Free | Partition Type: NTFS

Computer Name: COMPUTERPC1 | User Name: bashir | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\bashir\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe (Research In Motion Limited)
PRC - C:\Program Files\Lexmark Pro700 Series\ezprint.exe ()
PRC - C:\Program Files\Lexmark Pro700 Series\lxeemon.exe ()
PRC - C:\WINDOWS\system32\lxeecoms.exe ( )
PRC - C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
PRC - C:\Program Files\SentrilockCardUtility\SentriLockCardUtility.exe (SentriLock LLC)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Compaq\EAKDRV\EAUSBKBD.exe (Compaq)
PRC - C:\Program Files\WildTangent\DDC\DDCManager\DDCMan.exe (WildTangent)
PRC - C:\Program Files\compaq\Compaq Advisor\bin\compaq-rba.exe (NeoPlanet)
PRC - C:\Program Files\compaq\Easy Access Button Support\CPQEADM.exe (Compaq Computer Corporation)
PRC - C:\Program Files\compaq\Easy Access Button Support\STARTEAK.exe (Compaq Computer Corporation)
PRC - C:\Program Files\Norton AntiVirus\Navapw32.exe (Symantec Corporation)
PRC - C:\Program Files\compaq\Easy Access Button Support\BttnServ.exe (Compaq Computer Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Lexmark Pro700 Series\ezprint.exe ()
MOD - C:\Program Files\Lexmark Pro700 Series\lxeemon.exe ()
MOD - C:\Program Files\Lexmark Pro700 Series\epoemdll.dll ()
MOD - C:\Program Files\Lexmark Pro700 Series\epstring.dll ()
MOD - C:\Program Files\Lexmark Pro700 Series\epwizres.dll ()
MOD - C:\Program Files\Lexmark Pro700 Series\epwizard.dll ()
MOD - C:\Program Files\Lexmark Pro700 Series\customui.dll ()
MOD - C:\Program Files\Lexmark Pro700 Series\epfunct.dll ()
MOD - C:\Program Files\Lexmark Pro700 Series\eputil.dll ()
MOD - C:\Program Files\Lexmark Pro700 Series\imagutil.dll ()
MOD - C:\Program Files\Lexmark\Pro700 Series\lxeedrs.dll ()
MOD - C:\Program Files\Lexmark Pro700 Series\lxeedrs.dll ()
MOD - C:\Program Files\Lexmark Pro700 Series\lxeescw.dll ()
MOD - C:\Program Files\Lexmark\Pro700 Series\lxeemicro.dll ()
MOD - C:\WINDOWS\system32\spool\prtprocs\w32x86\lxeedrpp.dll ()
MOD - C:\WINDOWS\system32\spool\drivers\w32x86\3\lxeedatr.dll ()
MOD - C:\Program Files\Lexmark Pro700 Series\iptk.dll ()
MOD - C:\Program Files\Lexmark\Pro700 Series\lxeecaps.dll ()
MOD - C:\Program Files\Lexmark Pro700 Series\lxeecaps.dll ()
MOD - C:\Program Files\Lexmark Pro700 Series\lxeeptp.dll ()
MOD - C:\WINDOWS\system32\lxeesmr.dll ()
MOD - C:\WINDOWS\system32\lxeesm.dll ()
MOD - C:\Program Files\WildTangent\DDC\DDCManager\DDCManps.dll ()
MOD - C:\Program Files\compaq\Compaq Advisor\bin\nsreg.dll ()
MOD - C:\Program Files\compaq\Easy Access Button Support\BttnSeps.dll ()


========== Win32 Services (SafeList) ==========

SRV - (AppMgmt) โ€“ File not found
SRV - (lxee_device) โ€“ C:\WINDOWS\System32\lxeecoms.exe ( )
SRV - (lxeeCATSCustConnectService) โ€“ C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxeeserv.exe ()
SRV - (Symantec AntiVirus) โ€“ C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe (Symantec Corporation)
SRV - (SmcService) โ€“ C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe (Symantec Corporation)
SRV - (SNAC) โ€“ C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE (Symantec Corporation)
SRV - (LiveUpdate) โ€“ C:\Program Files\Symantec\LiveUpdate\LuComServer_3_3.EXE (Symantec Corporation)
SRV - (Automatic LiveUpdate Scheduler) โ€“ C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (Symantec Corporation)
SRV - (ccSetMgr) โ€“ C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccEvtMgr) โ€“ C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (Compaq_RBA) โ€“ C:\Program Files\compaq\Compaq Advisor\bin\compaq-rba.exe (NeoPlanet)
SRV - (navapsvc) โ€“ c:\Program Files\Norton AntiVirus\Navapsvc.exe (Symantec Corporation)
SRV - (SBService) โ€“ C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe (Symantec Corporation)


========== Driver Services (SafeList) ==========

DRV - (SymEvent) โ€“ C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (SCR3XX2K) โ€“ C:\WINDOWS\system32\drivers\SCR3XX2K.sys (SCM Microsystems Inc.)
DRV - (NAVEX15) โ€“ C:\Program Files\Common Files\Symantec Shared\VirusDefs\20101013.002\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) โ€“ C:\Program Files\Common Files\Symantec Shared\VirusDefs\20101013.002\NAVENG.SYS (Symantec Corporation)
DRV - (WpsHelper) โ€“ C:\WINDOWS\system32\drivers\wpshelper.sys (Symantec Corporation)
DRV - (rt2870) โ€“ C:\WINDOWS\system32\drivers\rt2870.sys (Ralink Technology, Corp.)
DRV - (SysPlant) โ€“ C:\WINDOWS\SYSTEM32\Drivers\SysPlant.sys (Symantec Corporation)
DRV - (WPS) โ€“ C:\WINDOWS\system32\drivers\WPSDRVnt.sys (Symantec Corporation)
DRV - (eeCtrl) โ€“ C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) โ€“ C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (SYMTDI) โ€“ C:\WINDOWS\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (SYMREDRV) โ€“ C:\WINDOWS\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (SPBBCDrv) โ€“ C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (SRTSPX) โ€“ C:\WINDOWS\system32\drivers\srtspx.sys (Symantec Corporation)
DRV - (SRTSPL) โ€“ C:\WINDOWS\system32\drivers\srtspl.sys (Symantec Corporation)
DRV - (SRTSP) โ€“ C:\WINDOWS\system32\drivers\srtsp.sys (Symantec Corporation)
DRV - (COH_Mon) โ€“ C:\WINDOWS\system32\drivers\COH_Mon.sys (Symantec Corporation)
DRV - (Teefer2) โ€“ C:\WINDOWS\system32\drivers\Teefer2.sys (Symantec Corporation)
DRV - (ZDCNDIS5) โ€“ C:\WINDOWS\system32\ZDCndis5.sys (ZDC., Inc. (ZDC))
DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) โ€“ C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (rtl8139) Realtek RTL8139(A/B/C) โ€“ C:\WINDOWS\system32\drivers\rtl8139.sys (Realtek Semiconductor Corporation)
DRV - (ltmodem5) โ€“ C:\WINDOWS\system32\drivers\ltmdmnt.sys (LT)
DRV - (S3Psddr) โ€“ C:\WINDOWS\system32\drivers\s3gnbm.sys (S3 Graphics, Inc.)
DRV - (viaagp1) โ€“ C:\WINDOWS\System32\DRIVERS\viaagp1.sys (VIA Technologies, Inc.)
DRV - (wandrv) โ€“ C:\WINDOWS\system32\drivers\wandrv.sys (America Online, Inc.)
DRV - (i81x) โ€“ C:\WINDOWS\system32\drivers\i81xnt5.sys (Intelยฎ Corporation)
DRV - (iAimFP0) โ€“ C:\WINDOWS\system32\drivers\wADV01nt.sys (Intelยฎ Corporation)
DRV - (iAimFP1) โ€“ C:\WINDOWS\system32\drivers\wADV02NT.sys (Intelยฎ Corporation)
DRV - (iAimFP2) โ€“ C:\WINDOWS\system32\drivers\wADV05NT.sys (Intelยฎ Corporation)
DRV - (iAimFP4) โ€“ C:\WINDOWS\system32\drivers\wVchNTxx.sys (Intelยฎ Corporation)
DRV - (iAimFP3) โ€“ C:\WINDOWS\system32\drivers\wSiINTxx.sys (Intelยฎ Corporation)
DRV - (iAimTV3) โ€“ C:\WINDOWS\system32\drivers\wATV04nt.sys (Intelยฎ Corporation)
DRV - (iAimTV0) โ€“ C:\WINDOWS\system32\drivers\wATV01nt.sys (Intelยฎ Corporation)
DRV - (iAimTV4) โ€“ C:\WINDOWS\system32\drivers\wCh7xxNT.sys (Intelยฎ Corporation)
DRV - (iAimTV1) โ€“ C:\WINDOWS\system32\drivers\wATV02NT.sys (Intelยฎ Corporation)
DRV - (NAVAP) โ€“ C:\WINDOWS\system32\drivers\NAVAP.SYS ()
DRV - (EAWDMFD) โ€“ C:\WINDOWS\system32\drivers\EAWDMFD.SYS (Compaq Computer Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://rd.yahoo.com/customize/yessentials_โ€ฆ/search/ie.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://rd.yahoo.com/customize/yessentials_โ€ฆ/search/ie.html


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-173008773-919082819-4212676017-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://rd.yahoo.com/customize/yessentials_โ€ฆ//www.yahoo.com
IE - HKU\S-1-5-21-173008773-919082819-4212676017-1006\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\S-1-5-21-173008773-919082819-4212676017-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKU\S-1-5-21-173008773-919082819-4212676017-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-173008773-919082819-4212676017-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKU\S-1-5-21-173008773-919082819-4212676017-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 4C 8C B2 6E 03 44 CC 01 [binary data]
IE - HKU\S-1-5-21-173008773-919082819-4212676017-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.com/"

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@RIM.com/WebSLLauncher,version=1.0: C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 5.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/07/15 13:51:56 | 000,000,000 | โ€”D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 5.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins

[2011/07/15 16:56:47 | 000,000,000 | โ€”D | M] (No name found) โ€“ C:\Documents and Settings\bashir\Application Data\Mozilla\Extensions
[2011/08/13 19:57:22 | 000,000,000 | โ€”D | M] (No name found) โ€“ C:\Documents and Settings\bashir\Application Data\Mozilla\Firefox\Profiles\4u3piybz.default\extensions
[2011/07/15 13:51:56 | 000,000,000 | โ€”D | M] (No name found) โ€“ C:\Program Files\Mozilla Firefox\extensions
() (No name found) โ€“ C:\DOCUMENTS AND SETTINGS\BASHIR\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\4U3PIYBZ.DEFAULT\EXTENSIONS\[removed]
[2011/09/03 08:15:12 | 000,000,000 | โ€”D | M] (Microsoft .NET Framework Assistant) โ€“ C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2011/07/07 23:16:28 | 000,142,296 | โ€”- | M] (Mozilla Foundation) โ€“ C:\Program Files\mozilla firefox\components\browsercomps.dll
[2010/01/01 00:00:00 | 000,002,252 | โ€”- | M] () โ€“ C:\Program Files\mozilla firefox\searchplugins\bing.xml

O1 HOSTS File: ([2011/08/28 16:10:17 | 000,435,650 | Rโ€” | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 14994 more linesโ€ฆ
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (CNavExtBho Class) - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NAVShExt.dll (Symantec Corporation)
O2 - BHO: (Lexmark Printable Web) - {D2C5E510-BE6D-42CC-9F61-E4F939078474} - C:\Program Files\Lexmark Printable Web\bho.dll ()
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - c:\Program Files\Microsoft Money\System\mnyviewer.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Norton AntiVirus) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NAVShExt.dll (Symantec Corporation)
O3 - HKU\S-1-5-21-173008773-919082819-4212676017-1006\..\Toolbar\WebBrowser: (Norton AntiVirus) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NAVShExt.dll (Symantec Corporation)
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [CPQEASYACC] C:\Program Files\compaq\Easy Access Button Support\STARTEAK.exe (Compaq Computer Corporation)
O4 - HKLM..\Run: [DDCActiveMenu] C:\Program Files\WildTangent\DDC\ActiveMenu\DDCActiveMenu.exe (WildTangent)
O4 - HKLM..\Run: [DDCM] C:\Program Files\WildTangent\DDC\DDCManager\DDCMan.exe (WildTangent)
O4 - HKLM..\Run: [EzPrint] C:\Program Files\Lexmark Pro700 Series\ezprint.exe ()
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [lxeemon.exe] C:\Program Files\Lexmark Pro700 Series\lxeemon.exe ()
O4 - HKLM..\Run: [NAV Agent] c:\Program Files\Norton AntiVirus\Navapw32.exe (Symantec Corporation)
O4 - HKLM..\Run: [NAV CfgWiz] c:\Program Files\Norton AntiVirus\Cfgwiz.exe (Symantec Corporation)
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\Recguard.exe ()
O4 - HKLM..\Run: [RIMBBLaunchAgent.exe] C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe (Research In Motion Limited)
O4 - HKLM..\Run: [srmclean] C:\cpqs\scom\srmclean.exe ()
O4 - HKLM..\Run: [StorageGuard] C:\Program Files\VERITAS Software\Update Manager\sgtray.exe (VERITAS Software, Inc.)
O4 - HKLM..\Run: [WCOLOREAL] C:\Program Files\COMPAQ\Coloreal\coloreal.exe ()
O4 - HKU\S-1-5-21-173008773-919082819-4212676017-1006..\Run: [DriverMax] File not found
O4 - HKU\S-1-5-21-173008773-919082819-4212676017-1006..\Run: [DriverMax_RESTART] File not found
O4 - HKU\S-1-5-21-173008773-919082819-4212676017-1006..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O4 - HKLM..\RunOnce: [Compaq_RBA] C:\Program Files\compaq\Compaq Advisor\bin\compaq-rba.exe (NeoPlanet)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SentriLockCardUtility.lnk = C:\WINDOWS\Installer\{C9B8D365-A6C3-4C4D-9624-0F0078FEB1B4}\Icon037926361.exe ()
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-173008773-919082819-4212676017-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra Button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll (Microsoft Corporation)
O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\PLUGINS\NPDocBox.dll (InterTrust Technologies Corporation, Inc.)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/products/plugin/1.3.1/โ€ฆall-131-win.cab (Java Plug-in 1.3.1)
O16 - DPF: {BEA7310D-06C4-4339-A784-DC3804819809} http://www.cvsphoto.com/upload/activex/v3_โ€ฆveX_Control.cab (Photo Upload Plugin Class)
O16 - DPF: {CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA} http://java.sun.com/products/plugin/1.3.1/โ€ฆall-131-win.cab (Java Plug-in 1.3.1)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D5575F4C-0121-4B10-B0FF-B689F36CC8D9}: DhcpNameServer = 192.168.1.1 [removed]
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\bashir\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\bashir\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2002/08/01 18:46:53 | 000,000,000 | โ€”- | M] () - C:\AUTOEXEC.BAT โ€“ [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] โ€“ "%1" %*
O35 - HKLM\..exefile [open] โ€“ "%1" %*
O37 - HKLM\โ€ฆcom [@ = comfile] โ€“ "%1" %*
O37 - HKLM\โ€ฆexe [@ = exefile] โ€“ "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/09/03 08:16:54 | 000,000,000 | -HSD | C] โ€“ C:\Config.Msi
[2011/09/01 18:08:07 | 000,827,488 | โ€”- | C] (Ralink Technology, Corp.) โ€“ C:\WINDOWS\System32\drivers\rt2870.sys
[2011/09/01 18:08:07 | 000,238,944 | โ€”- | C] (Ralink Technology, Inc.) โ€“ C:\WINDOWS\System32\RaCoInst.dll
[2011/09/01 18:08:05 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\All Users\Application Data\Tenda Driver
[2011/09/01 17:33:48 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\bashir\My Documents\BlackBerry
[2011/09/01 17:33:33 | 000,016,928 | โ€”- | C] (Microsoft Corporation) โ€“ C:\WINDOWS\System32\spmsgXP_2k3.dll
[2011/09/01 17:30:05 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\bashir\Local Settings\Application Data\Research In Motion
[2011/09/01 17:30:02 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\bashir\Application Data\Research In Motion
[2011/09/01 17:12:15 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\All Users\Start Menu\Programs\BlackBerry
[2011/09/01 17:12:08 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\All Users\Application Data\Research In Motion
[2011/09/01 17:11:43 | 000,000,000 | โ€”D | C] โ€“ C:\Program Files\Common Files\Research In Motion
[2011/09/01 17:11:42 | 000,000,000 | โ€”D | C] โ€“ C:\Program Files\Research In Motion
[2011/09/01 17:04:27 | 000,000,000 | โ€”D | C] โ€“ C:\WINDOWS\System32\XPSViewer
[2011/09/01 17:04:12 | 000,000,000 | โ€”D | C] โ€“ C:\Program Files\Reference Assemblies
[2011/09/01 17:03:11 | 000,117,760 | โ€”- | C] (Microsoft Corporation) โ€“ C:\WINDOWS\System32\prntvpt.dll
[2011/09/01 17:03:10 | 001,676,288 | โ€”- | C] (Microsoft Corporation) โ€“ C:\WINDOWS\System32\xpssvcs.dll
[2011/09/01 17:03:10 | 001,676,288 | โ€”- | C] (Microsoft Corporation) โ€“ C:\WINDOWS\System32\dllcache\xpssvcs.dll
[2011/09/01 17:03:10 | 000,597,504 | โ€”- | C] (Microsoft Corporation) โ€“ C:\WINDOWS\System32\dllcache\printfilterpipelinesvc.exe
[2011/09/01 17:03:10 | 000,575,488 | โ€”- | C] (Microsoft Corporation) โ€“ C:\WINDOWS\System32\dllcache\xpsshhdr.dll
[2011/09/01 17:03:10 | 000,089,088 | โ€”- | C] (Microsoft Corporation) โ€“ C:\WINDOWS\System32\dllcache\filterpipelineprintproc.dll
[2011/09/01 17:03:10 | 000,000,000 | โ€”D | C] โ€“ C:\833e95aa7beb5ba2451718d3
[2011/09/01 17:02:21 | 000,000,000 | R-SD | C] โ€“ C:\WINDOWS\assembly
[2011/09/01 17:01:40 | 000,000,000 | โ€”D | C] โ€“ C:\WINDOWS\Microsoft.NET
[2011/09/01 14:57:29 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\bashir\Application Data\Malwarebytes
[2011/09/01 14:57:23 | 000,041,272 | โ€”- | C] (Malwarebytes Corporation) โ€“ C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/09/01 14:57:23 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/09/01 14:57:22 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/09/01 14:57:19 | 000,022,712 | โ€”- | C] (Malwarebytes Corporation) โ€“ C:\WINDOWS\System32\drivers\mbam.sys
[2011/09/01 14:57:19 | 000,000,000 | โ€”D | C] โ€“ C:\Program Files\Malwarebytes' Anti-Malware
[2011/08/30 18:24:21 | 000,000,000 | Rโ€“D | C] โ€“ C:\Documents and Settings\bashir\Start Menu\Programs\Administrative Tools
[2011/08/30 17:49:19 | 000,607,260 | Rโ€” | C] (Swearware) โ€“ C:\Documents and Settings\bashir\Desktop\dds.scr
[2011/08/29 17:48:26 | 000,094,208 | โ€”- | C] (ZDC., Inc. (ZDC)) โ€“ C:\WINDOWS\System32\ZDCN50.dll
[2011/08/29 17:48:26 | 000,020,736 | โ€”- | C] (ZDC., Inc. (ZDC)) โ€“ C:\WINDOWS\System32\ZDCndis5.sys
[2011/08/29 17:48:26 | 000,020,608 | โ€”- | C] (Printing Communications Assoc., Inc. (PCAUSA)) โ€“ C:\WINDOWS\System32\drivers\BRGSp50.sys
[2011/08/29 17:36:38 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\bashir\Application Data\InstallShield
[2011/08/29 13:09:29 | 000,000,000 | โ€”D | C] โ€“ C:\WINDOWS\System32\zh-TW
[2011/08/29 13:09:29 | 000,000,000 | โ€”D | C] โ€“ C:\WINDOWS\System32\zh-CN
[2011/08/29 13:09:29 | 000,000,000 | โ€”D | C] โ€“ C:\WINDOWS\System32\tr-TR
[2011/08/29 13:09:29 | 000,000,000 | โ€”D | C] โ€“ C:\WINDOWS\System32\sv-SE
[2011/08/29 13:09:29 | 000,000,000 | โ€”D | C] โ€“ C:\WINDOWS\System32\ru-RU
[2011/08/29 13:09:29 | 000,000,000 | โ€”D | C] โ€“ C:\WINDOWS\System32\pt-PT
[2011/08/29 13:09:29 | 000,000,000 | โ€”D | C] โ€“ C:\WINDOWS\System32\pl-PL
[2011/08/29 13:09:29 | 000,000,000 | โ€”D | C] โ€“ C:\WINDOWS\System32\nn-NO
[2011/08/29 13:09:29 | 000,000,000 | โ€”D | C] โ€“ C:\WINDOWS\System32\nl-NL
[2011/08/29 13:09:29 | 000,000,000 | โ€”D | C] โ€“ C:\WINDOWS\System32\ko-KR
[2011/08/29 13:09:29 | 000,000,000 | โ€”D | C] โ€“ C:\WINDOWS\System32\ja-JP
[2011/08/29 13:09:29 | 000,000,000 | โ€”D | C] โ€“ C:\WINDOWS\System32\it-IT
[2011/08/29 13:09:29 | 000,000,000 | โ€”D | C] โ€“ C:\WINDOWS\System32\hu-HU
[2011/08/29 13:09:29 | 000,000,000 | โ€”D | C] โ€“ C:\WINDOWS\System32\fr-FR
[2011/08/29 13:09:29 | 000,000,000 | โ€”D | C] โ€“ C:\WINDOWS\System32\fi-FI
[2011/08/29 13:09:29 | 000,000,000 | โ€”D | C] โ€“ C:\WINDOWS\System32\es-ES
[2011/08/29 13:09:28 | 000,000,000 | โ€”D | C] โ€“ C:\WINDOWS\System32\el-GR
[2011/08/29 13:09:28 | 000,000,000 | โ€”D | C] โ€“ C:\WINDOWS\System32\de-DE
[2011/08/29 13:09:28 | 000,000,000 | โ€”D | C] โ€“ C:\WINDOWS\System32\da-DK
[2011/08/29 13:09:28 | 000,000,000 | โ€”D | C] โ€“ C:\WINDOWS\System32\cs-CZ
[2011/08/29 13:08:50 | 000,000,000 | โ€”D | C] โ€“ C:\Program Files\Cisco
[2011/08/28 17:04:54 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\All Users\Application Data\Atheros
[2011/08/28 17:04:49 | 000,000,000 | โ€”D | C] โ€“ C:\SWSetup
[2011/08/28 16:47:15 | 000,000,000 | โ€”D | C] โ€“ C:\temp
[2011/08/28 16:22:57 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\bashir\My Documents\My Drivers
[2011/08/28 16:22:57 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\bashir\Local Settings\Application Data\Innovative Solutions
[2011/08/28 16:22:57 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\All Users\Application Data\Innovative Solutions
[2011/08/18 19:48:57 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\bashir\Desktop\Rental
[2011/08/15 08:47:19 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\All Users\Application Data\Lexmark Pro700 Series
[2011/08/13 14:48:09 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\bashir\Desktop\fluschipranie
[2011/08/10 19:25:11 | 000,139,656 | โ€”- | C] (Microsoft Corporation) โ€“ C:\WINDOWS\System32\dllcache\rdpwd.sys
[2011/08/10 19:24:16 | 000,010,496 | โ€”- | C] (Microsoft Corporation) โ€“ C:\WINDOWS\System32\dllcache\ndistapi.sys
[2011/07/19 11:58:08 | 000,442,368 | โ€”- | C] ( ) โ€“ C:\WINDOWS\System32\lxeecoin.dll
[2011/07/19 11:55:12 | 000,847,872 | โ€”- | C] ( ) โ€“ C:\WINDOWS\System32\lxeeusb1.dll
[2011/07/19 11:55:12 | 000,364,544 | โ€”- | C] ( ) โ€“ C:\WINDOWS\System32\lxeeinpa.dll
[2011/07/19 11:55:12 | 000,356,352 | โ€”- | C] ( ) โ€“ C:\WINDOWS\System32\LXEEhcp.dll
[2011/07/19 11:55:12 | 000,344,064 | โ€”- | C] ( ) โ€“ C:\WINDOWS\System32\lxeeiesc.dll
[2011/07/19 11:55:11 | 001,048,576 | โ€”- | C] ( ) โ€“ C:\WINDOWS\System32\lxeeserv.dll
[2011/07/19 11:55:11 | 000,643,072 | โ€”- | C] ( ) โ€“ C:\WINDOWS\System32\lxeepmui.dll
[2011/07/19 11:55:11 | 000,577,536 | โ€”- | C] ( ) โ€“ C:\WINDOWS\System32\lxeelmpm.dll
[2011/07/19 11:55:10 | 000,688,128 | โ€”- | C] ( ) โ€“ C:\WINDOWS\System32\lxeehbn3.dll
[2011/07/19 11:55:10 | 000,324,264 | โ€”- | C] ( ) โ€“ C:\WINDOWS\System32\lxeeih.exe
[2011/07/19 11:55:09 | 000,598,696 | โ€”- | C] ( ) โ€“ C:\WINDOWS\System32\lxeecoms.exe
[2011/07/19 11:55:08 | 000,802,816 | โ€”- | C] ( ) โ€“ C:\WINDOWS\System32\lxeecomc.dll
[2011/07/19 11:55:08 | 000,373,416 | โ€”- | C] ( ) โ€“ C:\WINDOWS\System32\lxeecfg.exe
[2011/07/19 11:55:08 | 000,372,736 | โ€”- | C] ( ) โ€“ C:\WINDOWS\System32\lxeecomm.dll
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/09/05 21:55:07 | 000,004,645 | โ€”- | M] () โ€“ C:\WINDOWS\compaq.reg
[2011/09/05 21:55:07 | 000,004,645 | โ€”- | M] () โ€“ C:\WINDOWS\.compaq.bak
[2011/09/05 18:57:09 | 000,002,361 | โ€”- | M] () โ€“ C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SentriLockCardUtility.lnk
[2011/09/05 18:56:34 | 000,000,183 | โ€”- | M] () โ€“ C:\WINDOWS\System\hpsysdrv.DAT
[2011/09/05 18:56:00 | 000,002,048 | โ€“S- | M] () โ€“ C:\WINDOWS\bootstat.dat
[2011/09/05 18:55:45 | 2146,004,992 | -HS- | M] () โ€“ C:\hiberfil.sys
[2011/09/04 09:03:01 | 000,264,704 | โ€”- | M] () โ€“ C:\Documents and Settings\bashir\Desktop\Publication1.pub
[2011/09/03 08:36:57 | 000,436,932 | โ€”- | M] () โ€“ C:\WINDOWS\System32\perfh009.dat
[2011/09/03 08:36:57 | 000,069,032 | โ€”- | M] () โ€“ C:\WINDOWS\System32\perfc009.dat
[2011/09/02 11:11:17 | 000,163,033 | โ€”- | M] () โ€“ C:\Documents and Settings\bashir\Desktop\col9.gif
[2011/09/01 17:33:45 | 000,000,000 | -Hโ€“ | M] () โ€“ C:\WINDOWS\System32\drivers\Msft_Kernel_RimUsb_01009.Wdf
[2011/09/01 17:33:44 | 000,000,000 | -Hโ€“ | M] () โ€“ C:\WINDOWS\System32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
[2011/09/01 17:33:43 | 000,001,355 | โ€”- | M] () โ€“ C:\WINDOWS\imsins.BAK
[2011/09/01 17:15:22 | 000,270,984 | โ€”- | M] () โ€“ C:\WINDOWS\System32\FNTCACHE.DAT
[2011/09/01 17:12:16 | 000,001,964 | โ€”- | M] () โ€“ C:\Documents and Settings\All Users\Desktop\BlackBerry Desktop Software.lnk
[2011/09/01 14:57:24 | 000,000,792 | โ€”- | M] () โ€“ C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/09/01 14:33:35 | 000,210,437 | โ€”- | M] () โ€“ C:\Documents and Settings\bashir\My Documents\09-01-2011 02;33;35PM.PDF
[2011/09/01 14:31:06 | 005,934,621 | โ€”- | M] () โ€“ C:\Documents and Settings\bashir\My Documents\09-01-2011 02;31;03PM.PDF
[2011/09/01 10:35:55 | 000,002,515 | โ€”- | M] () โ€“ C:\Documents and Settings\bashir\Desktop\Microsoft Office Word 2007.lnk
[2011/08/30 18:24:19 | 000,607,260 | Rโ€” | M] (Swearware) โ€“ C:\Documents and Settings\bashir\Desktop\dds.scr
[2011/08/29 17:51:20 | 000,004,158 | โ€”- | M] () โ€“ C:\SentriLockCardUtil.err
[2011/08/29 17:38:22 | 000,001,158 | โ€”- | M] () โ€“ C:\WINDOWS\System32\wpa.dbl
[2011/08/28 16:38:39 | 000,000,799 | โ€”- | M] () โ€“ C:\WINDOWS\orun32.ini
[2011/08/28 16:10:17 | 000,435,650 | Rโ€” | M] () โ€“ C:\WINDOWS\System32\drivers\etc\hosts
[2011/08/28 16:03:28 | 000,000,734 | Rโ€” | M] () โ€“ C:\WINDOWS\System32\drivers\etc\hosts.20110828-161017.backup
[2011/08/22 20:54:28 | 000,001,098 | โ€”- | M] () โ€“ C:\Documents and Settings\bashir\My Documents\realtor_disclosure.PDF.lnk
[2011/08/13 09:28:12 | 000,000,085 | โ€”- | M] () โ€“ C:\WINDOWS\SentriLockCardUtilSuppressedMsg.INI
[2011/08/12 22:58:09 | 000,013,824 | โ€”- | M] () โ€“ C:\Documents and Settings\bashir\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/08/11 10:54:12 | 000,000,499 | โ€”- | M] () โ€“ C:\Documents and Settings\bashir\Desktop\#p-u-1-67xcbww9bfo#p-u-6-M6lirThNnkg#p-u-0-OV0xI6EFp2k#p-u-1-b14OeT1gNFo.url
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/09/03 10:08:52 | 000,160,544 | โ€”- | C] () โ€“ C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2011/09/02 11:11:41 | 000,163,033 | โ€”- | C] () โ€“ C:\Documents and Settings\bashir\Desktop\col9.gif
[2011/09/01 18:08:06 | 000,013,931 | โ€”- | C] () โ€“ C:\WINDOWS\System32\RaCoInst.dat
[2011/09/01 17:33:45 | 000,000,000 | -Hโ€“ | C] () โ€“ C:\WINDOWS\System32\drivers\Msft_Kernel_RimUsb_01009.Wdf
[2011/09/01 17:33:44 | 000,000,000 | -Hโ€“ | C] () โ€“ C:\WINDOWS\System32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
[2011/09/01 17:12:16 | 000,001,964 | โ€”- | C] () โ€“ C:\Documents and Settings\All Users\Desktop\BlackBerry Desktop Software.lnk
[2011/09/01 14:57:24 | 000,000,792 | โ€”- | C] () โ€“ C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/09/01 14:33:35 | 000,210,437 | โ€”- | C] () โ€“ C:\Documents and Settings\bashir\My Documents\09-01-2011 02;33;35PM.PDF
[2011/09/01 14:31:03 | 005,934,621 | โ€”- | C] () โ€“ C:\Documents and Settings\bashir\My Documents\09-01-2011 02;31;03PM.PDF
[2011/08/23 04:31:53 | 000,004,158 | โ€”- | C] () โ€“ C:\SentriLockCardUtil.err
[2011/08/22 20:55:04 | 000,001,098 | โ€”- | C] () โ€“ C:\Documents and Settings\bashir\My Documents\realtor_disclosure.PDF.lnk
[2011/08/13 17:49:16 | 000,264,704 | โ€”- | C] () โ€“ C:\Documents and Settings\bashir\Desktop\Publication1.pub
[2011/08/11 10:54:12 | 000,000,499 | โ€”- | C] () โ€“ C:\Documents and Settings\bashir\Desktop\#p-u-1-67xcbww9bfo#p-u-6-M6lirThNnkg#p-u-0-OV0xI6EFp2k#p-u-1-b14OeT1gNFo.url
[2011/08/10 18:37:48 | 000,000,085 | โ€”- | C] () โ€“ C:\WINDOWS\SentriLockCardUtilSuppressedMsg.INI
[2011/07/19 11:58:12 | 000,040,960 | โ€”- | C] () โ€“ C:\WINDOWS\System32\lxeevs.dll
[2011/07/19 11:57:59 | 000,086,016 | โ€”- | C] () โ€“ C:\WINDOWS\System32\lxeegcfg.dll
[2011/07/19 11:57:58 | 000,294,912 | โ€”- | C] () โ€“ C:\WINDOWS\System32\lxeecui.dll
[2011/07/19 11:57:58 | 000,110,592 | โ€”- | C] () โ€“ C:\WINDOWS\System32\lxeecuir.dll
[2011/07/19 11:55:27 | 000,000,044 | -Hโ€“ | C] () โ€“ C:\WINDOWS\System32\lxeerwrd.ini
[2011/07/19 11:55:13 | 000,331,776 | โ€”- | C] () โ€“ C:\WINDOWS\System32\LXEEinst.dll
[2011/07/19 11:55:11 | 000,057,344 | โ€”- | C] () โ€“ C:\WINDOWS\System32\lxeejswr.dll
[2011/07/19 11:55:10 | 000,323,584 | โ€”- | C] () โ€“ C:\WINDOWS\System32\lxeeins.dll
[2011/07/19 11:55:10 | 000,262,144 | โ€”- | C] () โ€“ C:\WINDOWS\System32\lxeeinsb.dll
[2011/07/19 11:55:10 | 000,106,496 | โ€”- | C] () โ€“ C:\WINDOWS\System32\lxeeinsr.dll
[2011/07/19 11:55:09 | 000,253,952 | โ€”- | C] () โ€“ C:\WINDOWS\System32\lxeecu.dll
[2011/07/19 11:55:09 | 000,208,896 | โ€”- | C] () โ€“ C:\WINDOWS\System32\lxeegrd.dll
[2011/07/19 11:55:09 | 000,090,112 | โ€”- | C] () โ€“ C:\WINDOWS\System32\lxeecub.dll
[2011/07/19 11:55:09 | 000,036,864 | โ€”- | C] () โ€“ C:\WINDOWS\System32\lxeecur.dll
[2011/07/16 21:42:58 | 000,013,824 | โ€”- | C] () โ€“ C:\Documents and Settings\bashir\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/07/15 16:56:41 | 000,000,000 | โ€”- | C] () โ€“ C:\WINDOWS\nsreg.dat
[2011/07/15 11:43:12 | 000,001,804 | โ€”- | C] () โ€“ C:\WINDOWS\System32\dcache.bin
[2011/07/15 11:12:58 | 000,272,128 | โ€”- | C] () โ€“ C:\WINDOWS\System32\perfi009.dat
[2011/07/15 11:12:58 | 000,028,626 | โ€”- | C] () โ€“ C:\WINDOWS\System32\perfd009.dat
[2011/07/15 11:12:55 | 000,004,490 | โ€”- | C] () โ€“ C:\WINDOWS\System32\oembios.dat
[2011/07/15 11:12:49 | 013,107,200 | โ€”- | C] () โ€“ C:\WINDOWS\System32\oembios.bin
[2011/07/15 11:12:43 | 000,000,741 | โ€”- | C] () โ€“ C:\WINDOWS\System32\noise.dat
[2011/07/15 11:12:24 | 000,673,088 | โ€”- | C] () โ€“ C:\WINDOWS\System32\mlang.dat
[2011/07/15 11:12:24 | 000,046,258 | โ€”- | C] () โ€“ C:\WINDOWS\System32\mib.bin
[2011/07/15 11:12:01 | 000,218,003 | โ€”- | C] () โ€“ C:\WINDOWS\System32\dssec.dat
[2011/07/15 11:01:18 | 000,000,002 | โ€”- | C] () โ€“ C:\WINDOWS\msoffice.ini
[2011/07/15 10:44:11 | 000,299,008 | Rโ€” | C] () โ€“ C:\WINDOWS\System32\lxeesm.dll
[2011/07/15 10:44:11 | 000,023,552 | Rโ€” | C] () โ€“ C:\WINDOWS\System32\lxeesmr.dll
[2011/07/15 09:01:31 | 000,004,645 | โ€”- | C] () โ€“ C:\WINDOWS\.compaq.bak
[2004/08/02 13:20:40 | 000,004,569 | โ€”- | C] () โ€“ C:\WINDOWS\System32\secupd.dat
[2002/08/02 00:11:20 | 000,000,061 | โ€”- | C] () โ€“ C:\WINDOWS\smscfg.ini
[2002/08/01 21:19:00 | 000,000,470 | โ€”- | C] () โ€“ C:\WINDOWS\ikey.ini
[2002/08/01 21:17:01 | 000,020,549 | โ€”- | C] () โ€“ C:\WINDOWS\System32\javaw.exe
[2002/08/01 21:17:01 | 000,020,547 | โ€”- | C] () โ€“ C:\WINDOWS\System32\java.exe
[2002/08/01 21:16:30 | 000,009,310 | โ€”- | C] () โ€“ C:\WINDOWS\mozver.dat
[2002/08/01 21:01:50 | 000,006,550 | โ€”- | C] () โ€“ C:\WINDOWS\jautoexp.dat
[2002/08/01 20:59:15 | 000,000,052 | โ€”- | C] () โ€“ C:\WINDOWS\intuprof.ini
[2002/08/01 20:59:14 | 000,000,599 | โ€”- | C] () โ€“ C:\WINDOWS\QUICKEN.INI
[2002/08/01 20:10:54 | 000,000,138 | โ€”- | C] () โ€“ C:\WINDOWS\wininit.ini
[2002/08/01 19:50:25 | 000,000,029 | โ€”- | C] () โ€“ C:\WINDOWS\ALSndMgr.ini
[2002/08/01 19:41:52 | 000,299,073 | โ€”- | C] () โ€“ C:\WINDOWS\System32\PythonCOM22.dll
[2002/08/01 19:41:52 | 000,065,536 | โ€”- | C] () โ€“ C:\WINDOWS\System32\PyWinTypes22.dll
[2002/08/01 19:41:23 | 000,016,896 | โ€”- | C] () โ€“ C:\WINDOWS\System32\bcbmm.dll
[2002/08/01 18:52:20 | 000,000,799 | โ€”- | C] () โ€“ C:\WINDOWS\orun32.ini
[2002/08/01 18:50:22 | 000,002,048 | โ€“S- | C] () โ€“ C:\WINDOWS\bootstat.dat
[2002/08/01 18:43:39 | 000,021,640 | โ€”- | C] () โ€“ C:\WINDOWS\System32\emptyregdb.dat
[2002/08/01 18:41:46 | 000,001,793 | โ€”- | C] () โ€“ C:\WINDOWS\System32\fxsperf.ini
[2002/08/01 18:33:03 | 000,000,664 | โ€”- | C] () โ€“ C:\WINDOWS\System32\oeminfo.ini
[2002/08/01 18:32:23 | 000,436,932 | โ€”- | C] () โ€“ C:\WINDOWS\System32\perfh009.dat
[2002/08/01 18:32:23 | 000,069,032 | โ€”- | C] () โ€“ C:\WINDOWS\System32\perfc009.dat
[2002/08/01 11:37:30 | 000,004,161 | โ€”- | C] () โ€“ C:\WINDOWS\ODBCINST.INI
[2002/08/01 11:36:30 | 000,270,984 | โ€”- | C] () โ€“ C:\WINDOWS\System32\FNTCACHE.DAT
[2002/05/31 21:59:12 | 000,000,000 | โ€”- | C] () โ€“ C:\WINDOWS\System32\px.ini
[2002/05/22 18:44:14 | 000,009,785 | โ€”- | C] () โ€“ C:\WINDOWS\System32\drivers\a312.sys
[2002/05/22 18:04:26 | 000,262,144 | โ€”- | C] () โ€“ C:\WINDOWS\System32\shpshftr.dll
[2002/05/15 02:26:00 | 000,028,672 | โ€”- | C] () โ€“ C:\WINDOWS\System32\igfxdgps.dll
[2001/09/05 04:25:36 | 000,040,960 | โ€”- | C] () โ€“ C:\WINDOWS\LoadDll.dll
[2001/08/31 21:33:58 | 000,425,984 | โ€”- | C] () โ€“ C:\WINDOWS\System32\VxDMDcDlg.dll
[2001/08/08 12:13:22 | 000,012,351 | โ€”- | C] () โ€“ C:\WINDOWS\System32\i81xcoin.dll
[2001/08/04 01:22:00 | 000,182,896 | โ€”- | C] () โ€“ C:\WINDOWS\System32\drivers\NAVAP.SYS

========== LOP Check ==========

[2011/08/28 16:22:57 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\Innovative Solutions
[2011/08/15 08:47:19 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\Lexmark Pro700 Series
[2011/09/01 17:12:08 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\Research In Motion
[2011/08/05 09:52:41 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\SentriLock
[2011/09/01 18:08:05 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\Tenda Driver
[2002/08/02 01:14:59 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\bashir\Application Data\InterTrust
[2011/07/15 17:52:05 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\bashir\Application Data\Notepad++
[2011/09/01 17:30:56 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\bashir\Application Data\Research In Motion
[2011/08/05 09:54:07 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\bashir\Application Data\SentriLock
[2002/08/02 01:15:02 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\bashir\Application Data\VERITAS
[2002/08/02 01:14:59 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Default User\Application Data\InterTrust
[2002/08/02 01:15:02 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Default User\Application Data\VERITAS
[2002/08/02 01:14:59 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Owner\Application Data\InterTrust
[2002/08/02 01:15:02 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Owner\Application Data\VERITAS

========== Purity Check ==========



< End of report >

Attachments:

HP has nice systems, the one your talking about dont sound to bad, but $150 sounds kind of cheap, how old is it, is Win 7 original or has it been upgraded from maybe an older computer.

DriverMax <โ€“ What you want to do is download drivers straight from the Manufacturer, not from places like these, install the wrong driver and it can cause all sorts of problems

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI