This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

slow computer

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, I'm trying to help my friend. His computer is running very slowly. I'm not sure what the problem is. Could someone please help me?
Here are the results from OTL:

OTL logfile created on: 8/26/2011 10:22:08 PM - Run 1
OTL by OldTimer - Version 3.2.26.5 Folder = C:\Documents and Settings\Sergiy G\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

502.11 Mb Total Physical Memory | 255.68 Mb Available Physical Memory | 50.92% Memory free
1.20 Gb Paging File | 0.87 Gb Available in Paging File | 72.88% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 68.52 Gb Total Space | 31.71 Gb Free Space | 46.28% Space Free | Partition Type: NTFS
Unable to calculate disk information.

Computer Name: SERGIY | User Name: Sergiy G | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Sergiy G\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Panda Security\Panda Cloud Antivirus\PSUNMain.exe (Panda Security, S.L.)
PRC - C:\Program Files\Panda Security\Panda Cloud Antivirus\PSANHost.exe (Panda Security, S.L.)
PRC - C:\Documents and Settings\Sergiy G\Local Settings\Application Data\Yandex\Updater\praetorian.exe (ООО «ЯНДЕКС»)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe (Sony Corporation)
PRC - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe (Sony Corporation)
PRC - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe (Sony Corporation)
PRC - C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe (Sony Corporation)
PRC - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe (Sony Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Lavasoft\Ad-Aware\ShellExt.dll ()
MOD - C:\Program Files\WinRAR\RarExt.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\WINDOWS\system32\msjetoledb40.dll ()
MOD - C:\Program Files\Panda Security\Panda Cloud Antivirus\MiniCrypto.dll ()
MOD - C:\Program Files\Panda Security\Panda Cloud Antivirus\APIcr.dll ()
MOD - C:\Program Files\Intel\Wireless\Bin\Libeay32.dll ()
MOD - C:\Program Files\Intel\Wireless\Bin\iWMSProv.dll ()
MOD - C:\Program Files\Intel\Wireless\Bin\IntStngs.dll ()
MOD - C:\Program Files\Sony\VAIO Event Service\VESBasePS.dll ()


========== Win32 Services (SafeList) ==========

SRV - (AppMgmt) – File not found
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (NanoServiceMain) – C:\Program Files\Panda Security\Panda Cloud Antivirus\PSANHost.exe (Panda Security, S.L.)
SRV - (VAIOMediaPlatform-IntegratedServer-AppServer) – C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe (Sony Corporation)
SRV - (SSScsiSV) – C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe (Sony Corporation)
SRV - (VAIOMediaPlatform-Mobile-Gateway) – C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe (Sony Corporation)
SRV - (VzFw) – C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe (Sony Corporation)
SRV - (VzCdbSvc) – C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe (Sony Corporation)
SRV - (Vcsw) – C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe (Sony Corporation)
SRV - (VAIO Entertainment TV Device Arbitration Service) – C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe (Sony Corporation)
SRV - (MSCSPTISRV) – C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe (Sony Corporation)
SRV - (PACSPTISVR) – C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe (Sony Corporation)
SRV - (SPTISRV) – C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe (Sony Corporation)
SRV - (VAIOMediaPlatform-IntegratedServer-UPnP) VAIO Media Integrated Server (UPnP) – C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe (Sony Corporation)
SRV - (VAIOMediaPlatform-IntegratedServer-HTTP) VAIO Media Integrated Server (HTTP) – C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe (Sony Corporation)
SRV - (Image Converter video recording monitor for VAIO Entertainment) – C:\Program Files\Sony\Image Converter 2\IcVzMon.exe (Sony Corporation)
SRV - (VAIO Event Service) – C:\Program Files\Sony\VAIO Event Service\VESMgr.exe (Sony Corporation)


========== Driver Services (SafeList) ==========

DRV - (PSINProt) – C:\WINDOWS\system32\drivers\PSINProt.sys (Panda Security, S.L.)
DRV - (PSINProc) – C:\WINDOWS\system32\drivers\PSINProc.sys (Panda Security, S.L.)
DRV - (PSINKNC) – C:\WINDOWS\system32\drivers\PSINKNC.sys (Panda Security, S.L.)
DRV - (PSINFile) – C:\WINDOWS\system32\drivers\PSINFile.sys (Panda Security, S.L.)
DRV - (PSINAflt) – C:\WINDOWS\system32\drivers\PSINAflt.sys (Panda Security, S.L.)
DRV - (Lbd) – C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (ti21sony) – C:\WINDOWS\system32\drivers\ti21sony.sys (Texas Instruments)
DRV - (STHDA) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (usbvm321) – C:\WINDOWS\system32\drivers\usbvm321.sys (Vimicro Corporation)
DRV - (SonyImgF) – C:\WINDOWS\system32\drivers\SonyImgF.sys (Sony Corporation)
DRV - (w39n51) Intel® – C:\WINDOWS\system32\drivers\w39n51.sys (Intel® Corporation)
DRV - (s24trans) – C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (Tosrfusb) – C:\WINDOWS\system32\drivers\tosrfusb.sys (TOSHIBA CORPORATION)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (HSFHWAZL) – C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (Tosrfbd) – C:\WINDOWS\system32\drivers\tosrfbd.sys (TOSHIBA CORPORATION)
DRV - (Tosrfhid) – C:\WINDOWS\system32\drivers\tosrfhid.sys (TOSHIBA Corporation.)
DRV - (SI3132) – C:\WINDOWS\system32\DRIVERS\SI3132.sys (Silicon Image, Inc.)
DRV - (SiRemFil) – C:\WINDOWS\system32\DRIVERS\SiRemFil.sys (Silicon Image, Inc.)
DRV - (tosporte) – C:\WINDOWS\system32\drivers\tosporte.sys (TOSHIBA Corporation)
DRV - (Tosrfbnp) – C:\WINDOWS\system32\drivers\tosrfbnp.sys (TOSHIBA Corporation)
DRV - (Tosrfcom) – C:\WINDOWS\system32\drivers\tosrfcom.sys (TOSHIBA Corporation)
DRV - (tosrfnds) – C:\WINDOWS\system32\drivers\tosrfnds.sys (TOSHIBA Corporation.)
DRV - (ApfiltrService) – C:\WINDOWS\system32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (SiFilter) – C:\WINDOWS\system32\DRIVERS\SiWinAcc.sys (Silicon Image, Inc.)
DRV - (DMICall) – C:\WINDOWS\system32\drivers\DMICall.sys (Sony Corporation)
DRV - (SNC) – C:\WINDOWS\system32\drivers\SonyNC.sys (Sony Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yandex.ru/?clid=47540
IE - HKCU\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: {54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - C:\Program Files\AOL\AOL Search Enhancement\AOLSearch.dll (America Online, Inc.)
IE - HKCU\..\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\tbuTo1.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Rambler"
FF - prefs.js..browser.search.defaultthis.engineName: "Elf 1.12 Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2857572&SearchSource;=3&q;={searchTerms}"
FF - prefs.js..browser.search.param.yahoo-type: "${8}"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "www.google.com"
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.3.20100310105313
FF - prefs.js..extensions.enabledItems: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..keyword.URL: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&q;="


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKCU\Software\MozillaPlugins\@yahoo.com/BrowserPlus,version=2.9.8: C:\Documents and Settings\Sergiy G\Local Settings\Application Data\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll (Yahoo! Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.20\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/08/23 09:49:03 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.20\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/08/23 09:49:03 | 000,000,000 | —D | M]

[2010/03/16 13:01:24 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Sergiy G\Application Data\Mozilla\Extensions
[2011/08/26 21:21:07 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Sergiy G\Application Data\Mozilla\Firefox\Profiles\9vk5a34w.default\extensions
[2011/08/23 07:17:15 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Sergiy G\Application Data\Mozilla\Firefox\Profiles\9vk5a34w.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/08/26 21:20:32 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\Sergiy G\Application Data\Mozilla\Firefox\Profiles\9vk5a34w.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011/08/26 21:19:54 | 000,000,000 | —D | M] (uTorrentBar Community Toolbar) – C:\Documents and Settings\Sergiy G\Application Data\Mozilla\Firefox\Profiles\9vk5a34w.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
[2011/01/17 15:46:04 | 000,000,919 | —- | M] () – C:\Documents and Settings\Sergiy G\Application Data\Mozilla\Firefox\Profiles\9vk5a34w.default\searchplugins\conduit.xml
[2010/11/14 21:26:30 | 000,002,020 | —- | M] () – C:\Documents and Settings\Sergiy G\Application Data\Mozilla\Firefox\Profiles\9vk5a34w.default\searchplugins\osd.xml
[2011/08/26 21:21:07 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/04/13 08:17:59 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/07/08 23:20:05 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2011/04/13 08:16:53 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/05/04 05:52:23 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2010/06/03 13:06:29 | 000,005,257 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 practivate.adobe.com
O1 - Hosts: 127.0.0.1 ereg.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com
O1 - Hosts: 127.0.0.1 wip3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com
O1 - Hosts: 127.0.0.1 ereg.wip3.adobe.com
O1 - Hosts: 127.0.0.1 activate-sea.adobe.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com
O1 - Hosts: 127.0.0.1 practivate.adobe.com
O1 - Hosts: 127.0.0.1 ereg.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com
O1 - Hosts: 127.0.0.1 wip3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com
O1 - Hosts: 127.0.0.1 ereg.wip3.adobe.com
O1 - Hosts: 107 more lines…
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngin0.dll (Conduit Ltd.)
O2 - BHO: (AOLSearchHook Class) - {54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - C:\Program Files\AOL\AOL Search Enhancement\AOLSearch.dll (America Online, Inc.)
O2 - BHO: (uTorrentBar Toolbar) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\tbuTo1.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngin0.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Яндекс.Бар) - {91397D20-1446-11D4-8AF4-0040CA1127B6} - C:\Program Files\Yandex\YandexBarIE\yndbar.dll (ООО «ЯНДЕКС»)
O3 - HKLM\..\Toolbar: (uTorrentBar Toolbar) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\tbuTo1.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Яндекс.Бар) - {91397D20-1446-11D4-8AF4-0040CA1127B6} - C:\Program Files\Yandex\YandexBarIE\yndbar.dll (ООО «ЯНДЕКС»)
O3 - HKCU\..\Toolbar\WebBrowser: (uTorrentBar Toolbar) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - C:\Program Files\uTorrentBar\tbuTo1.dll (Conduit Ltd.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [PartSeal] C:\WINDOWS\SONYSYS\VAIO Recovery\PartSeal.exe (Sony Electronics Inc)
O4 - HKLM..\Run: [PSUNMain] C:\Program Files\Panda Security\Panda Cloud Antivirus\PSUNMain.exe (Panda Security, S.L.)
O4 - HKLM..\Run: [Switcher.exe] C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe (Sony Corporation)
O4 - HKCU..\Run: [AdobeBridge] File not found
O4 - HKCU..\Run: [Praetorian] C:\Documents and Settings\Sergiy G\Local Settings\Application Data\Yandex\Updater\praetorian.exe (ООО «ЯНДЕКС»)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 8
O8 - Extra context menu item: Transfer by Image Converter 2 Plus - C:\Program Files\Sony\Image Converter 2\menu.htm ()
O9 - Extra Button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe (PokerStars)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\VESWinlogon: DllName - VESWinlogon.dll - C:\WINDOWS\System32\VESWinlogon.dll (Sony Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\VAIO Light Flo Wallpaper TrueColor 1920x1200.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\VAIO Light Flo Wallpaper TrueColor 1920x1200.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/03/15 17:09:18 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: VIDC.dvsd - C:\Program Files\Common Files\Sony Shared\VideoLib\sonydv.dll (Sony Corporation)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/08/26 21:12:07 | 000,000,000 | R–D | C] – C:\Documents and Settings\Sergiy G\Start Menu\Programs\Administrative Tools
[2011/08/26 20:46:26 | 000,580,096 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Sergiy G\Desktop\OTL.exe
[2011/08/23 10:03:58 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Sergiy G\Recent
[2011/08/23 07:16:58 | 000,139,656 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rdpwd.sys
[2011/08/20 12:16:25 | 000,010,496 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ndistapi.sys
[2011/08/01 21:57:27 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\iTunes
[2011/08/01 21:57:14 | 000,107,368 | —- | C] (GEAR Software Inc.) – C:\WINDOWS\System32\GEARAspi.dll
[2011/08/01 21:55:37 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2011/08/01 21:55:05 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2011/08/01 21:50:51 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/08/26 21:49:20 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2011/08/26 21:04:05 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/08/26 21:04:04 | 526,569,472 | -HS- | M] () – C:\hiberfil.sys
[2011/08/26 20:59:59 | 000,462,848 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/08/26 20:59:59 | 000,080,276 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/08/26 20:55:33 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/08/26 20:46:44 | 000,580,096 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Sergiy G\Desktop\OTL.exe
[2011/08/15 07:47:47 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/08/08 19:24:04 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/08/26 20:48:40 | 000,001,374 | —- | C] () – C:\WINDOWS\imsins.BAK
[2011/03/02 22:00:13 | 000,013,576 | —- | C] () – C:\WINDOWS\System32\wnaspi32.dll
[2010/10/05 19:29:59 | 000,003,584 | —- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/06/25 21:33:46 | 000,000,264 | —- | C] () – C:\WINDOWS\System32\PSUNCpl.dat
[2010/03/17 00:11:39 | 000,036,128 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2010/03/16 21:44:58 | 000,015,872 | —- | C] () – C:\Documents and Settings\Sergiy G\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/03/16 12:34:29 | 000,000,131 | —- | C] () – C:\Documents and Settings\Sergiy G\Local Settings\Application Data\fusioncache.dat
[2010/03/16 12:18:14 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2010/03/16 12:18:14 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2010/03/16 12:18:14 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2010/03/16 12:18:14 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2010/03/16 12:18:14 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2010/03/16 12:18:14 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2010/03/16 12:17:22 | 000,000,004 | —- | C] () – C:\WINDOWS\Pix11.dat
[2010/03/16 12:07:05 | 000,019,968 | —- | C] () – C:\WINDOWS\System32\Cpuinf32.dll
[2010/03/16 12:05:23 | 000,000,166 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2010/03/16 12:02:43 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2010/03/16 11:56:13 | 000,002,158 | —- | C] () – C:\WINDOWS\System32\tmmute.ini
[2006/03/16 23:41:35 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/03/15 21:13:43 | 000,610,304 | —- | C] () – C:\WINDOWS\System32\lpykrp.exe
[2006/03/15 18:36:02 | 000,000,056 | —- | C] () – C:\WINDOWS\WININIT.INI
[2006/03/15 18:27:57 | 000,000,000 | —- | C] () – C:\WINDOWS\VAIOUpdt.INI
[2006/03/15 17:46:50 | 000,111,552 | —- | C] () – C:\WINDOWS\setup.exe
[2006/03/15 17:33:17 | 000,000,032 | —- | C] () – C:\WINDOWS\System32\elcric.dat
[2006/03/15 17:15:18 | 000,000,800 | —- | C] () – C:\WINDOWS\orun32.ini
[2006/03/15 17:11:39 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2006/03/15 17:07:06 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2006/03/15 15:53:41 | 000,094,208 | —- | C] () – C:\WINDOWS\System32\nvapi.dll
[2006/03/15 15:53:35 | 000,000,758 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2006/03/15 15:53:13 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2006/03/15 15:53:11 | 000,462,848 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2006/03/15 15:53:11 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2006/03/15 15:53:11 | 000,080,276 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2006/03/15 15:53:11 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2006/03/15 15:53:09 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2006/03/15 15:53:09 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2006/03/15 15:53:07 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2006/03/15 15:53:04 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2006/03/15 15:53:04 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2006/03/15 15:53:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2006/03/15 15:52:54 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2006/03/15 09:00:41 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2006/03/15 08:59:51 | 002,175,680 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2006/01/25 16:15:38 | 000,046,345 | —- | C] () – C:\WINDOWS\NSSetDefaultBrowser.EXE
[2005/11/01 21:53:38 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2002/06/12 16:21:12 | 000,049,152 | R— | C] () – C:\WINDOWS\System32\winchip.dll

========== LOP Check ==========

[2011/03/31 08:45:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Broderbund
[2010/10/18 09:33:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Fiesta Download Manager
[2010/11/14 21:25:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ICQ
[2010/06/25 21:33:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Panda Security
[2010/12/22 19:56:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Yandex
[2010/04/26 13:41:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010/03/18 15:46:56 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
[2010/03/16 13:17:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2011/03/31 08:45:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Sergiy G\Application Data\Broderbund
[2010/04/16 15:02:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Sergiy G\Application Data\GARMIN
[2011/01/13 15:08:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Sergiy G\Application Data\ICQ
[2010/06/22 11:53:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Sergiy G\Application Data\InterVideo
[2010/08/18 09:19:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Sergiy G\Application Data\Leadertech
[2010/05/11 08:53:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Sergiy G\Application Data\OpenOffice.org
[2010/12/22 19:56:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Sergiy G\Application Data\Opera
[2010/03/16 15:45:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Sergiy G\Application Data\Panda Security
[2011/08/01 18:37:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Sergiy G\Application Data\PriceGong
[2011/02/01 21:37:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Sergiy G\Application Data\Sony
[2011/04/25 12:03:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Sergiy G\Application Data\uTorrent
[2010/12/30 16:40:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Sergiy G\Application Data\Yandex
[2011/08/26 21:49:20 | 000,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2006/03/15 17:09:18 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/08/25 09:39:35 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2006/03/15 17:09:18 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/08/17 22:24:35 | 000,000,081 | —- | M] () – C:\DVDPATH.TXT
[2011/08/26 21:04:04 | 526,569,472 | -HS- | M] () – C:\hiberfil.sys
[2006/03/15 17:09:18 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/03/16 12:16:05 | 000,001,031 | -H– | M] () – C:\IPH.PH
[2006/03/15 17:09:18 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/04 08:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2010/08/04 21:52:46 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/08/26 21:04:02 | 792,723,456 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2006/04/18 16:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 15:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 16:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 15:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/03/15 17:08:47 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 08:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2004/03/22 19:17:08 | 000,025,840 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2006/10/26 20:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
[2008/07/06 06:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2006/03/15 08:59:13 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2006/03/15 08:59:13 | 000,638,976 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2006/03/15 08:59:12 | 000,897,024 | —- | M] () – C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2010/08/04 22:01:13 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/03/16 12:34:49 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Sergiy G\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2006/03/15 17:15:03 | 000,000,079 | —- | M] () – C:\Documents and Settings\Sergiy G\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2011/08/26 20:46:44 | 000,580,096 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Sergiy G\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-08-27 01:00:58

< End of report >


OTL Extras logfile created on: 8/26/2011 10:22:08 PM - Run 1
OTL by OldTimer - Version 3.2.26.5 Folder = C:\Documents and Settings\Sergiy G\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

502.11 Mb Total Physical Memory | 255.68 Mb Available Physical Memory | 50.92% Memory free
1.20 Gb Paging File | 0.87 Gb Available in Paging File | 72.88% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 68.52 Gb Total Space | 31.71 Gb Free Space | 46.28% Space Free | Partition Type: NTFS
Unable to calculate disk information.

Computer Name: SERGIY | User Name: Sergiy G | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = aol_htm] – Reg Error: Key error. File not found

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile [print] – Reg Error: Key error.
http [open] – Reg Error: Key error.
https [open] – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\BitTorrent\bittorrent.exe" = C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent – (BitTorrent, Inc.)
"C:\Program Files\Longman iBT\jre1.3.0\bin\rmiregistry.exe" = C:\Program Files\Longman iBT\jre1.3.0\bin\rmiregistry.exe:*:Enabled:rmiregistry – ()


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{013E1BA8-C815-4E27-BCB9-D6B1B2E24094}" = SonicStage Mastering Studio Audio Filter Custom Preset
"{01FDC9FC-4D4F-4DB0-ACD1-D3E8E1D52902}" = Sony MP4 Shared Library
"{0712667C-A171-49AE-A098-4ACDA28625F8}" = Sony Sound Forge 7.0
"{075473F5-846A-448B-BCB3-104AA1760205}" = Roxio DigitalMedia Data
"{0DF00135-D5A7-476A-BFB3-EDFF2840076A}" = VAIO Wireless LAN Setup Utility
"{197A3012-8C85-4FD3-AB66-9EC7E13DB92E}" = Adobe AIR
"{1BEF9285-5530-426B-A5F1-5836B95C7EB1}" = VAIO Original Screen Saver
"{2063C2E8-3812-4BBD-9998-6610F80C1DD4}" = VAIO Media AC3 Decoder 1.0
"{23FB368F-1399-4EAC-817C-4B83ECBE3D83}" = mProSafe
"{26A24AE4-039D-4CA4-87B4-2F83216024FF}" = Java™ 6 Update 26
"{27337663-2619-11D4-99DC-0000F49094C7}" = Memory Stick Formatter
"{2818095F-FB6C-42C8-827E-0A406CC9AFF5}" = Quicken 2006
"{2A0F3EF9-68EE-49E9-A05B-ED5B82DF63E5}" = Wireless Switch Setting Utility
"{2EA7CF7E-0C76-44A5-B0CF-A1D171476E42}" = VAIO Breeze Wallpaper
"{315BA29D-2644-4760-B5FD-5AC04A52B8C5}" = VAIO Registration
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{47D2103B-FD51-4017-9C20-DD408B17D726}" = Office 2003 Trial Assistant
"{48820099-ED7D-424B-890C-9A82EF00656D}" = VAIO Update 2
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4E993095-28F2-4060-9101-99C1FD1195C0}" = VAIO Central
"{560F6B2E-F0DF-44E5-8190-A4A161F0E205}" = VAIO Media 5.0
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5855C127-1F20-404D-B7FB-1FD84D7EAB5E}" = VAIO Media Redistribution 5.0
"{58F9D852-9443-4955-A1ED-12C9E0504DD0}" = Mavis Beacon Teaches Typing Platinum 20
"{59452470-A902-477F-9338-9B88101681BD}" = Setting Utility Series
"{5958CAC6-373E-402F-84FE-0A699AA920B9}" = LAN Setting Utility
"{5D95AD35-368F-47D5-B63A-A082DDF00111}" = Microsoft Digital Image Starter Edition 2006 Editor
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{639BB4D3-AA30-4A7B-8CB5-6DE681AD6659}" = VAIO Light Flo Wallpaper
"{63B8FB69-A1B6-425D-B67D-5257B7A1F663}" = Image Converter 2 Plus
"{6815FCDD-401D-481E-BA88-31B4754C2B46}" = Macromedia Flash Player 8
"{685BCC47-B8EC-45EC-BBCE-77DF2451502C}" = DVgate Plus
"{691F4068-81BF-49E3-B32E-FE3E16400111}" = Microsoft Digital Image Starter Edition 2006 Library
"{6ADD0603-16EF-400D-9F9E-486432835002}" = OpenOffice.org 3.2
"{6B1F20F2-6321-4669-A58C-33DF8E7517FF}" = VAIO Entertainment Platform
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{76EFFC7C-17A6-479D-9E47-8E658C1695AE}" = Windows Backup Utility
"{785EB1D4-ECEC-4195-99B4-73C47E187721}" = VAIO Media Integrated Server 5.0
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{80EE18E6-F16C-11D4-8BE8-006097C9A3ED}" = ISScript
"{82081533-F045-469E-BD53-F16839E445C3}" = VAIO Support Central
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver
"{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}" = mPfMgr
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{926CC8AE-8414-43DF-8EB4-CF26D9C3C663}" =
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD for VAIO
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9B202815-09F6-4D0F-96F8-24A42277B9B8}" = Яндекс.Бар 5.1 для Internet Explorer
"{9CC89556-3578-48DD-8408-04E66EBEF401}" = mXML
"{9E319E96-ED8E-4B01-9775-C521A1869A25}" = VAIO Power Management
"{9E407618-D9CD-4F39-9490-9ED45294073D}" = Click to DVD 2.0.03 Menu Data
"{9F7FC79B-3059-4264-9450-39EB368E3225}" = Microsoft Digital Image Library 9 - Blocker
"{A0EB195B-5876-48E6-879D-33D4B2102610}" = SonicStage 3.4
"{A0F925BF-5C55-44C2-A4E7-5A4C59791C29}" = mDriver
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = SigmaTel Audio
"{A947C2B3-7445-42C4-9063-EE704CACCB22}" = VAIO Hardware Diagnostics
"{AB467B85-4F52-48C2-AEED-0673D00417B0}" = SonicStage Mastering Studio Audio Filter
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Roxio DigitalMedia Audio
"{AC76BA86-7AD7-1033-7B44-A70000000000}" = Adobe Reader 7.0.7
"{AF9A04EB-7D8E-41DE-9EDE-4AB9BB2B71B6}" = VAIO Media Registration Tool 5.0
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Roxio DigitalMedia Copy
"{B3575D00-27EF-49C2-B9E0-14B3D954E992}" = Apple Application Support
"{BA46CCF2-2C59-4DEB-93DC-7000B7C53B4E}" = VAIOSurveySA
"{BE56FEF0-1A0F-4719-B3AD-34B5087AFA6D}" = Sony Video Shared Library
"{BF3B304B-8A18-452D-A19F-6012CA8418D7}" = SonicStage Mastering Studio 2.2
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C23CD6DA-1958-43A5-ADD0-59396572E02E}" = Apple Mobile Device Support
"{C27BF761-C499-488D-A964-A3718BC6EC3E}" = DSD Direct
"{C73CA646-73B3-4AEF-A136-C37505745174}" = iTunes
"{C89EB8CD-675F-44F4-9729-4C9A8FAC2D4F}" = DSD Playback Plug-in 1.0
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CFB17307-B244-4EAD-AE8E-CDAF440477C2}" = OpenMG Secure Module 4.4.00
"{D03482C5-9AD8-496D-B388-692AE04C93AF}" = Bonjour
"{D0448678-1203-4158-A58F-B3D0B616BF9E}" = Sony Certificate PCH
"{D4C9692E-4EFA-4DA0-8B7F-9439466D9E31}" = Full Tilt Poker
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E09B48B5-E141-427A-AB0C-D3605127224A}" = Microsoft SQL Server Desktop Engine (VAIO_VEDB)
"{E809063C-51A3-4269-8984-D1EB742F2151}" = Click to DVD 2.5.20
"{E81667C6-2856-46D6-ABEA-6A2F42166779}" = mCore
"{EE7EB179-5AA2-4B28-AC92-5CBAAF82BA7F}" = SonicStage Mastering Studio Plugins
"{EF3D45BB-2260-4008-88EA-492E7744A9DF}" = Sony Utilities DLL
"{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}" = mMHouse
"{F0D85ADD-DD61-4B43-87A0-6DA52A211A8B}" = VAIO Event Service
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{FB714F13-10C9-48DB-91C9-DDBCCCBF9370}" = VAIO Original Screen Saver VAIO Cozy Screen SD Wide Contents
"{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}" = mWlsSafe
"{FE3BF611-9B8B-44DC-A424-F8C4BA122A1D}" = VAIO Security Center
"{FEB2D0CA-9912-4AA1-8FBE-CFD852F9F1FC}" = Panda Cloud Antivirus
"Ad-Aware" = Ad-Aware
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AOL Search Enhancement" = Search Enhancement by AOL Search
"CCleaner" = CCleaner
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV;_2BFA&SUBSYS;_20030003" = HDAUDIO SoftV92 Data Fax Modem with SmartCP
"conduitEngine" = Conduit Engine
"DivX Setup.divx.com" = DivX Setup
"ENTERPRISE" = Microsoft Office Enterprise 2007
"F-Manager" = Fiesta Download Manager
"ie8" = Windows Internet Explorer 8
"InstallShield_{315BA29D-2644-4760-B5FD-5AC04A52B8C5}" = VAIO Registration
"InstallShield_{BA46CCF2-2C59-4DEB-93DC-7000B7C53B4E}" = VAIOSurveySA
"InstallShield_{CFB17307-B244-4EAD-AE8E-CDAF440477C2}" = OpenMG Secure Module 4.4.00
"Longman iBT" = Longman iBT
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.20)" = Mozilla Firefox (3.6.20)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Nero BurnRights!UninstallKey" = Nero BurnRights
"NVIDIA Drivers" = NVIDIA Drivers
"Panda Cloud Antivirus" = Panda Cloud Antivirus
"PictureItSuiteTrial_v11" = Microsoft Digital Image Starter Edition 2006
"PokerStars" = PokerStars
"ProInst" = Intel® PROSet/Wireless Software
"PROSet" = Intel® PRO Network Connections Drivers
"uTorrent" = µTorrent
"uTorrentBar Toolbar" = uTorrentBar Toolbar
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Yahoo! BrowserPlus" = Yahoo! BrowserPlus 2.9.8

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 3/18/2011 3:18:21 PM | Computer Name = SERGIY | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 13053234

Error - 3/21/2011 11:12:49 AM | Computer Name = SERGIY | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 3/21/2011 11:12:49 AM | Computer Name = SERGIY | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 2031

Error - 3/21/2011 11:12:49 AM | Computer Name = SERGIY | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 2031

Error - 3/21/2011 11:12:51 AM | Computer Name = SERGIY | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 3/21/2011 11:12:51 AM | Computer Name = SERGIY | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 4250

Error - 3/21/2011 11:12:51 AM | Computer Name = SERGIY | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 4250

Error - 3/21/2011 11:12:53 AM | Computer Name = SERGIY | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 3/21/2011 11:12:53 AM | Computer Name = SERGIY | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 6203

Error - 3/21/2011 11:12:53 AM | Computer Name = SERGIY | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 6203

[ System Events ]
Error - 8/23/2011 6:59:06 AM | Computer Name = SERGIY | Source = Service Control Manager | ID = 7000
Description = The adfs service failed to start due to the following error: %%2

Error - 8/23/2011 7:15:42 AM | Computer Name = SERGIY | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.0.102 for the Network Card with network
address 0013025147F5 has been denied by the DHCP server 0.0.0.0 (The DHCP Server
sent a DHCPNACK message).

Error - 8/23/2011 9:24:33 AM | Computer Name = SERGIY | Source = Service Control Manager | ID = 7000
Description = The adfs service failed to start due to the following error: %%2

Error - 8/25/2011 8:17:05 AM | Computer Name = SERGIY | Source = Dhcp | ID = 1000
Description = Your computer has lost the lease to its IP address 192.168.101.30
on the Network Card with network address 0013025147F5.

Error - 8/26/2011 8:27:12 PM | Computer Name = SERGIY | Source = ACPIEC | ID = 327681
Description = \Device\ACPIEC: The embedded controller (EC) hardware didn't respond
within the timeout period. This may indicate an error in the EC hardware or firmware,
or possibly a poorly designed BIOS which accesses the EC in an unsafe manner.
The EC driver will retry the failed transaction if possible.

Error - 8/26/2011 9:04:24 PM | Computer Name = SERGIY | Source = Service Control Manager | ID = 7000
Description = The adfs service failed to start due to the following error: %%2

Error - 8/26/2011 9:09:09 PM | Computer Name = SERGIY | Source = Service Control Manager | ID = 7031
Description = The Windows Media Player Network Sharing Service service terminated
unexpectedly. It has done this 1 time(s). The following corrective action will
be taken in 30000 milliseconds: Restart the service.

Error - 8/26/2011 9:16:27 PM | Computer Name = SERGIY | Source = DCOM | ID = 10010
Description = The server {0002DF01-0000-0000-C000-000000000046} did not register
with DCOM within the required timeout.

Error - 8/26/2011 10:11:01 PM | Computer Name = SERGIY | Source = Service Control Manager | ID = 7031
Description = The Windows Media Player Network Sharing Service service terminated
unexpectedly. It has done this 1 time(s). The following corrective action will
be taken in 30000 milliseconds: Restart the service.

Error - 8/26/2011 10:11:54 PM | Computer Name = SERGIY | Source = Service Control Manager | ID = 7031
Description = The Windows Media Player Network Sharing Service service terminated
unexpectedly. It has done this 1 time(s). The following corrective action will
be taken in 30000 milliseconds: Restart the service.


< End of report >



Thank you
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your log and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise, this will be a team effort.
This may cause a delay, but I will do my best to keep it as short as possible. Please bear with me, I will post back to you as soon as I can.


IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.


Vista and Windows 7 users:

These tools MUST be run from the executable. (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

Having said that….Let's get going!! :thumbup:
Hi houngan666,

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
.
———–

Please download aswMBR to your desktop.

  • Double click the aswMBR icon to run it.
    Vista and Windows 7 users right click the icon and choose "Run as administrator".
  • Click the Scan button to start scan.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
———-

In your next reply please post the logs created by both GMER and aswMBR.exe. :)
Here are the GMER and aswMBR logs

GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2011-08-29 22:47:41
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-e HTS541080G9SA00 rev.MB4OC65D
Running: gmer.exe; Driver: C:\DOCUME~1\SERGIY~1\LOCALS~1\Temp\pxtdypod.sys


—- System - GMER 1.0.15 —-

SSDT Lbd.sys (Boot Driver/Lavasoft AB) ZwCreateKey [0xF86A587E]
SSDT Lbd.sys (Boot Driver/Lavasoft AB) ZwSetValueKey [0xF86A5BFE]
SSDT \SystemRoot\system32\DRIVERS\PSINProc.sys (PSINProc Filter Driver for XP32/Panda Security, S.L.) ZwTerminateProcess [0xA9FE3416]

—- User code sections - GMER 1.0.15 —-

.text C:\Program Files\Mozilla Firefox\firefox.exe[3888] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 004013F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)

—- Devices - GMER 1.0.15 —-

Device mrxsmb.sys (Windows NT SMB Minirdr/Microsoft Corporation)

—- EOF - GMER 1.0.15 —-





aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software
Run date: 2011-08-29 23:01:38
—————————–
23:01:38.291 OS Version: Windows 5.1.2600 Service Pack 3
23:01:38.291 Number of processors: 2 586 0xE08
23:01:38.291 ComputerName: SERGIY UserName:
23:01:38.963 Initialize success
23:02:09.948 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-e
23:02:09.948 Disk 0 Vendor: HTS541080G9SA00 MB4OC65D Size: 76319MB BusType: 3
23:02:09.948 Disk 1 \Device\Harddisk1\DR3 -> \Device\00000088
23:02:09.963 Disk 1 Vendor: ( Size: 76319MB BusType: 0
23:02:12.026 Disk 0 MBR read successfully
23:02:12.026 Disk 0 MBR scan
23:02:12.026 Disk 0 Windows XP default MBR code
23:02:12.057 Disk 0 scanning sectors +156296385
23:02:12.276 Disk 0 scanning C:\WINDOWS\system32\drivers
23:02:56.557 Service scanning
23:02:59.791 Modules scanning
23:03:39.291 Disk 0 trace - called modules:
23:03:39.354 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
23:03:39.354 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x82fcd778]
23:03:39.354 3 CLASSPNP.SYS[f8695fd7] -> nt!IofCallDriver -> \Device\00000080[0x82fcf940]
23:03:39.354 5 ACPI.sys[f850c620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP1T0L0-e[0x82fd3d98]
23:03:39.354 Scan finished successfully
23:39:04.979 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Sergiy G\Desktop\MBR.dat"
23:39:04.979 The log file has been saved successfully to "C:\Documents and Settings\Sergiy G\Desktop\aswMBR.txt"



Thanks Jeff :)
Hi houngan666,

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    IE - HKCU\..\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\tbuTo1.dll (Conduit Ltd.)
    FF - prefs.js..browser.search.defaultthis.engineName: "Elf 1.12 Customized Web Search"
    FF - prefs.js..keyword.URL: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&q="
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
    O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngin0.dll (Conduit Ltd.)
    O2 - BHO: (uTorrentBar Toolbar) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\tbuTo1.dll (Conduit Ltd.)
    O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngin0.dll (Conduit Ltd.)
    O3 - HKLM\..\Toolbar: (uTorrentBar Toolbar) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\tbuTo1.dll (Conduit Ltd.)
    O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (uTorrentBar Toolbar) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - C:\Program Files\uTorrentBar\tbuTo1.dll (Conduit Ltd.)
    O4 - HKCU..\Run: [AdobeBridge] File not found
    [2010/10/05 19:29:59 | 000,003,584 | —- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2010/03/16 21:44:58 | 000,015,872 | —- | C] () – C:\Documents and Settings\Sergiy G\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2006/03/15 21:13:43 | 000,610,304 | —- | C] () – C:\WINDOWS\System32\lpykrp.exe
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then run a new scan and post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
Here is the new OTL log

OTL logfile created on: 8/30/2011 3:09:10 PM - Run 2
OTL by OldTimer - Version 3.2.26.5 Folder = C:\Documents and Settings\Sergiy G\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

502.11 Mb Total Physical Memory | 62.45 Mb Available Physical Memory | 12.44% Memory free
1.20 Gb Paging File | 0.77 Gb Available in Paging File | 64.66% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 68.52 Gb Total Space | 31.43 Gb Free Space | 45.87% Space Free | Partition Type: NTFS

Computer Name: SERGIY | User Name: Sergiy G | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Sergiy G\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Panda Security\Panda Cloud Antivirus\PSUNMain.exe (Panda Security, S.L.)
PRC - C:\Program Files\Panda Security\Panda Cloud Antivirus\PSANHost.exe (Panda Security, S.L.)
PRC - C:\Documents and Settings\Sergiy G\Local Settings\Application Data\Yandex\Updater\praetorian.exe (ООО «ЯНДЕКС»)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe (Sony Corporation)
PRC - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe (Sony Corporation)
PRC - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe (Sony Corporation)
PRC - C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe (Sony Corporation)
PRC - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe (Sony Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Mozilla Firefox\js3250.dll ()
MOD - C:\Documents and Settings\Sergiy G\Application Data\Mozilla\Firefox\Profiles\9vk5a34w.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\components\RadioWMPCoreGecko19.dll ()
MOD - C:\Documents and Settings\Sergiy G\Application Data\Mozilla\Firefox\Profiles\9vk5a34w.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\components\RadioWMPCoreGecko6.dll ()
MOD - C:\Documents and Settings\Sergiy G\Application Data\Mozilla\Firefox\Profiles\9vk5a34w.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\components\RadioWMPCoreGecko5.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\WINDOWS\system32\msjetoledb40.dll ()
MOD - C:\Program Files\Panda Security\Panda Cloud Antivirus\MiniCrypto.dll ()
MOD - C:\Program Files\Panda Security\Panda Cloud Antivirus\APIcr.dll ()
MOD - C:\Program Files\Intel\Wireless\Bin\Libeay32.dll ()
MOD - C:\Program Files\Intel\Wireless\Bin\iWMSProv.dll ()
MOD - C:\Program Files\Intel\Wireless\Bin\IntStngs.dll ()
MOD - C:\Program Files\Sony\VAIO Event Service\VESBasePS.dll ()


========== Win32 Services (SafeList) ==========

SRV - (AppMgmt) – File not found
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (NanoServiceMain) – C:\Program Files\Panda Security\Panda Cloud Antivirus\PSANHost.exe (Panda Security, S.L.)
SRV - (VUAgent) – C:\Program Files\Sony\VAIO Update 5\VUAgent.exe (Sony Corporation)
SRV - (VAIOMediaPlatform-IntegratedServer-AppServer) – C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe (Sony Corporation)
SRV - (SSScsiSV) – C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe (Sony Corporation)
SRV - (VAIOMediaPlatform-Mobile-Gateway) – C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe (Sony Corporation)
SRV - (VzFw) – C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe (Sony Corporation)
SRV - (VzCdbSvc) – C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe (Sony Corporation)
SRV - (Vcsw) – C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe (Sony Corporation)
SRV - (VAIO Entertainment TV Device Arbitration Service) – C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe (Sony Corporation)
SRV - (MSCSPTISRV) – C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe (Sony Corporation)
SRV - (PACSPTISVR) – C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe (Sony Corporation)
SRV - (SPTISRV) – C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe (Sony Corporation)
SRV - (VAIOMediaPlatform-IntegratedServer-UPnP) VAIO Media Integrated Server (UPnP) – C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe (Sony Corporation)
SRV - (VAIOMediaPlatform-IntegratedServer-HTTP) VAIO Media Integrated Server (HTTP) – C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe (Sony Corporation)
SRV - (Image Converter video recording monitor for VAIO Entertainment) – C:\Program Files\Sony\Image Converter 2\IcVzMon.exe (Sony Corporation)
SRV - (VAIO Event Service) – C:\Program Files\Sony\VAIO Event Service\VESMgr.exe (Sony Corporation)


========== Driver Services (SafeList) ==========

DRV - (PSINProt) – C:\WINDOWS\system32\drivers\PSINProt.sys (Panda Security, S.L.)
DRV - (PSINAflt) – C:\WINDOWS\system32\drivers\PSINAflt.sys (Panda Security, S.L.)
DRV - (PSINKNC) – C:\WINDOWS\system32\drivers\PSINKNC.sys (Panda Security, S.L.)
DRV - (PSINProc) – C:\WINDOWS\system32\drivers\PSINProc.sys (Panda Security, S.L.)
DRV - (PSINFile) – C:\WINDOWS\system32\drivers\PSINFile.sys (Panda Security, S.L.)
DRV - (Lbd) – C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (ti21sony) – C:\WINDOWS\system32\drivers\ti21sony.sys (Texas Instruments)
DRV - (STHDA) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (usbvm321) – C:\WINDOWS\system32\drivers\usbvm321.sys (Vimicro Corporation)
DRV - (SonyImgF) – C:\WINDOWS\system32\drivers\SonyImgF.sys (Sony Corporation)
DRV - (w39n51) Intel® – C:\WINDOWS\system32\drivers\w39n51.sys (Intel® Corporation)
DRV - (s24trans) – C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (Tosrfusb) – C:\WINDOWS\system32\drivers\tosrfusb.sys (TOSHIBA CORPORATION)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (HSFHWAZL) – C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (Tosrfbd) – C:\WINDOWS\system32\drivers\tosrfbd.sys (TOSHIBA CORPORATION)
DRV - (Tosrfhid) – C:\WINDOWS\system32\drivers\tosrfhid.sys (TOSHIBA Corporation.)
DRV - (SI3132) – C:\WINDOWS\system32\DRIVERS\SI3132.sys (Silicon Image, Inc.)
DRV - (SiRemFil) – C:\WINDOWS\system32\DRIVERS\SiRemFil.sys (Silicon Image, Inc.)
DRV - (tosporte) – C:\WINDOWS\system32\drivers\tosporte.sys (TOSHIBA Corporation)
DRV - (Tosrfbnp) – C:\WINDOWS\system32\drivers\tosrfbnp.sys (TOSHIBA Corporation)
DRV - (Tosrfcom) – C:\WINDOWS\system32\drivers\tosrfcom.sys (TOSHIBA Corporation)
DRV - (tosrfnds) – C:\WINDOWS\system32\drivers\tosrfnds.sys (TOSHIBA Corporation.)
DRV - (ApfiltrService) – C:\WINDOWS\system32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (SiFilter) – C:\WINDOWS\system32\DRIVERS\SiWinAcc.sys (Silicon Image, Inc.)
DRV - (DMICall) – C:\WINDOWS\system32\drivers\DMICall.sys (Sony Corporation)
DRV - (SNC) – C:\WINDOWS\system32\drivers\SonyNC.sys (Sony Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yandex.ru/?clid=47540
IE - HKCU\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: {54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - C:\Program Files\AOL\AOL Search Enhancement\AOLSearch.dll (America Online, Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Rambler"
FF - prefs.js..browser.search.defaultthis.engineName: ""
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2857572&SearchSource;=3&q;={searchTerms}"
FF - prefs.js..browser.search.param.yahoo-type: "${8}"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "www.google.com"
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.3.20100310105313
FF - prefs.js..extensions.enabledItems: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKCU\Software\MozillaPlugins\@yahoo.com/BrowserPlus,version=2.9.8: C:\Documents and Settings\Sergiy G\Local Settings\Application Data\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll (Yahoo! Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.20\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/08/27 13:33:21 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.20\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/08/27 13:33:21 | 000,000,000 | —D | M]

[2010/03/16 13:01:24 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Sergiy G\Application Data\Mozilla\Extensions
[2011/08/30 15:04:57 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Sergiy G\Application Data\Mozilla\Firefox\Profiles\9vk5a34w.default\extensions
[2011/08/23 07:17:15 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Sergiy G\Application Data\Mozilla\Firefox\Profiles\9vk5a34w.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/08/26 21:20:32 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\Sergiy G\Application Data\Mozilla\Firefox\Profiles\9vk5a34w.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011/08/26 21:19:54 | 000,000,000 | —D | M] (uTorrentBar Community Toolbar) – C:\Documents and Settings\Sergiy G\Application Data\Mozilla\Firefox\Profiles\9vk5a34w.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
[2011/01/17 15:46:04 | 000,000,919 | —- | M] () – C:\Documents and Settings\Sergiy G\Application Data\Mozilla\Firefox\Profiles\9vk5a34w.default\searchplugins\conduit.xml
[2010/11/14 21:26:30 | 000,002,020 | —- | M] () – C:\Documents and Settings\Sergiy G\Application Data\Mozilla\Firefox\Profiles\9vk5a34w.default\searchplugins\osd.xml
[2011/08/29 23:58:52 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/04/13 08:17:59 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/07/08 23:20:05 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2011/04/13 08:16:53 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/05/04 05:52:23 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2010/06/03 13:06:29 | 000,005,257 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 practivate.adobe.com
O1 - Hosts: 127.0.0.1 ereg.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com
O1 - Hosts: 127.0.0.1 wip3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com
O1 - Hosts: 127.0.0.1 ereg.wip3.adobe.com
O1 - Hosts: 127.0.0.1 activate-sea.adobe.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com
O1 - Hosts: 127.0.0.1 practivate.adobe.com
O1 - Hosts: 127.0.0.1 ereg.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com
O1 - Hosts: 127.0.0.1 wip3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com
O1 - Hosts: 127.0.0.1 ereg.wip3.adobe.com
O1 - Hosts: 107 more lines…
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AOLSearchHook Class) - {54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - C:\Program Files\AOL\AOL Search Enhancement\AOLSearch.dll (America Online, Inc.)
O3 - HKLM\..\Toolbar: (Яндекс.Бар) - {91397D20-1446-11D4-8AF4-0040CA1127B6} - C:\Program Files\Yandex\YandexBarIE\yndbar.dll (ООО «ЯНДЕКС»)
O3 - HKCU\..\Toolbar\WebBrowser: (Яндекс.Бар) - {91397D20-1446-11D4-8AF4-0040CA1127B6} - C:\Program Files\Yandex\YandexBarIE\yndbar.dll (ООО «ЯНДЕКС»)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [PartSeal] C:\WINDOWS\SONYSYS\VAIO Recovery\PartSeal.exe (Sony Electronics Inc)
O4 - HKLM..\Run: [PSUNMain] C:\Program Files\Panda Security\Panda Cloud Antivirus\PSUNMain.exe (Panda Security, S.L.)
O4 - HKLM..\Run: [Switcher.exe] C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe (Sony Corporation)
O4 - HKCU..\Run: [Praetorian] C:\Documents and Settings\Sergiy G\Local Settings\Application Data\Yandex\Updater\praetorian.exe (ООО «ЯНДЕКС»)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 8
O8 - Extra context menu item: Transfer by Image Converter 2 Plus - C:\Program Files\Sony\Image Converter 2\menu.htm ()
O9 - Extra Button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe (PokerStars)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://www.pcpitstop.com/betapit/PCPitStop.CAB (PCPitstop Utility)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\VESWinlogon: DllName - VESWinlogon.dll - C:\WINDOWS\System32\VESWinlogon.dll (Sony Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\VAIO Light Flo Wallpaper TrueColor 1920x1200.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\VAIO Light Flo Wallpaper TrueColor 1920x1200.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/03/15 17:09:18 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/08/30 14:58:50 | 000,000,000 | —D | C] – C:\_OTL
[2011/08/29 21:06:31 | 000,000,000 | —D | C] – C:\Documents and Settings\Sergiy G\Desktop\gmer
[2011/08/29 21:05:43 | 001,916,416 | —- | C] (AVAST Software) – C:\Documents and Settings\Sergiy G\Desktop\aswMBR.exe
[2011/08/28 12:39:21 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Sergiy G\Recent
[2011/08/27 19:16:16 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\The KMPlayer
[2011/08/27 19:15:46 | 000,000,000 | —D | C] – C:\Program Files\The KMPlayer
[2011/08/27 13:38:42 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\iTunes
[2011/08/27 13:37:46 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2011/08/27 13:37:22 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2011/08/27 13:33:11 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\QuickTime
[2011/08/27 13:32:50 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2011/08/27 01:08:55 | 000,000,000 | —D | C] – C:\Documents and Settings\Sergiy G\Application Data\InstallShield
[2011/08/27 01:02:46 | 000,000,000 | —D | C] – C:\Update
[2011/08/26 21:12:07 | 000,000,000 | R–D | C] – C:\Documents and Settings\Sergiy G\Start Menu\Programs\Administrative Tools
[2011/08/26 20:46:26 | 000,580,096 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Sergiy G\Desktop\OTL.exe
[2011/08/23 07:16:58 | 000,139,656 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rdpwd.sys
[2011/08/20 12:16:25 | 000,010,496 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ndistapi.sys
[2011/08/01 21:57:14 | 000,107,368 | —- | C] (GEAR Software Inc.) – C:\WINDOWS\System32\GEARAspi.dll
[2011/08/01 21:50:51 | 000,000,000 | —D | C] – C:\Program Files\Bonjour

========== Files - Modified Within 30 Days ==========

[2011/08/30 15:01:50 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/08/30 15:01:49 | 526,569,472 | -HS- | M] () – C:\hiberfil.sys
[2011/08/29 23:39:04 | 000,000,512 | —- | M] () – C:\Documents and Settings\Sergiy G\Desktop\MBR.dat
[2011/08/29 22:51:32 | 001,916,416 | —- | M] (AVAST Software) – C:\Documents and Settings\Sergiy G\Desktop\aswMBR.exe
[2011/08/29 20:49:37 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/08/28 14:49:47 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2011/08/27 19:30:30 | 000,000,264 | —- | M] () – C:\WINDOWS\System32\PSUNCpl.dat
[2011/08/27 14:34:40 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2011/08/27 13:38:43 | 000,001,542 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2011/08/27 00:43:34 | 000,462,874 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/08/27 00:43:34 | 000,080,302 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/08/26 20:46:44 | 000,580,096 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Sergiy G\Desktop\OTL.exe
[2011/08/08 19:24:04 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job

========== Files Created - No Company Name ==========

[2011/08/29 23:39:04 | 000,000,512 | —- | C] () – C:\Documents and Settings\Sergiy G\Desktop\MBR.dat
[2011/08/27 13:38:43 | 000,001,542 | —- | C] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2011/08/27 01:02:00 | 000,000,880 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\VAIO Update.lnk
[2011/03/02 22:00:13 | 000,013,576 | —- | C] () – C:\WINDOWS\System32\wnaspi32.dll
[2010/06/25 21:33:46 | 000,000,264 | —- | C] () – C:\WINDOWS\System32\PSUNCpl.dat
[2010/03/17 00:11:39 | 000,036,128 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2010/03/16 12:34:29 | 000,000,131 | —- | C] () – C:\Documents and Settings\Sergiy G\Local Settings\Application Data\fusioncache.dat
[2010/03/16 12:18:14 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2010/03/16 12:18:14 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2010/03/16 12:18:14 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2010/03/16 12:18:14 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2010/03/16 12:18:14 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2010/03/16 12:18:14 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2010/03/16 12:17:22 | 000,000,004 | —- | C] () – C:\WINDOWS\Pix11.dat
[2010/03/16 12:07:05 | 000,019,968 | —- | C] () – C:\WINDOWS\System32\Cpuinf32.dll
[2010/03/16 12:05:23 | 000,000,166 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2010/03/16 12:02:43 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2010/03/16 11:56:13 | 000,002,158 | —- | C] () – C:\WINDOWS\System32\tmmute.ini
[2006/03/16 23:41:35 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/03/15 18:36:02 | 000,000,056 | —- | C] () – C:\WINDOWS\WININIT.INI
[2006/03/15 18:27:57 | 000,000,000 | —- | C] () – C:\WINDOWS\VAIOUpdt.INI
[2006/03/15 17:46:50 | 000,111,552 | —- | C] () – C:\WINDOWS\setup.exe
[2006/03/15 17:33:17 | 000,000,032 | —- | C] () – C:\WINDOWS\System32\elcric.dat
[2006/03/15 17:15:18 | 000,000,800 | —- | C] () – C:\WINDOWS\orun32.ini
[2006/03/15 17:11:39 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2006/03/15 17:07:06 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2006/03/15 15:53:41 | 000,094,208 | —- | C] () – C:\WINDOWS\System32\nvapi.dll
[2006/03/15 15:53:35 | 000,000,758 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2006/03/15 15:53:13 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2006/03/15 15:53:11 | 000,462,874 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2006/03/15 15:53:11 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2006/03/15 15:53:11 | 000,080,302 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2006/03/15 15:53:11 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2006/03/15 15:53:09 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2006/03/15 15:53:09 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2006/03/15 15:53:07 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2006/03/15 15:53:04 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2006/03/15 15:53:04 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2006/03/15 15:53:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2006/03/15 15:52:54 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2006/03/15 09:00:41 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2006/03/15 08:59:51 | 002,175,680 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2006/01/25 16:15:38 | 000,046,345 | —- | C] () – C:\WINDOWS\NSSetDefaultBrowser.EXE
[2005/11/01 21:53:38 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2002/06/12 16:21:12 | 000,049,152 | R— | C] () – C:\WINDOWS\System32\winchip.dll

< End of report >
Hi houngan666,

P2P - I see you have P2P software uTorrent installed on your machine. We are not
here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having
this kind of software installed on your machine will always make you more susceptible to re-infections and possibly
Identity Theft. It likely contributed to your current situation. This page will give you further information.

Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files
from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread
their wares.

I would strongly recommend that you uninstall these now. You can do so via Control Panel >> Add or Remove
Programs
.
———-

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch
    Malwarebytes' Anti-Malware
    , then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan as shown below.

    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.

The log can also be found here:
C:\Documents and Settings\\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date
(time).txt
———-

ESET Online Scanner
I'd like us to scan your machine with ESET Online Scan

Note: It is recommended to disable on-board anti-virus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your anti-virus along with your anti-spyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the [external image: Posted Image] button.
  • Push [external image: Posted Image]
http://www.eset.com/onlinescan/

In your next reply please post the logs created by Malwarebytes and ESET Online Scanner.
Here are the Malwarebytes and eset logs Malwarebytes' Anti-Malware 1.51.1.1800 www.malwarebytes.org Database version: 7616 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 8/30/2011 11:26:46 PM mbam-log-2011-08-30 (23-26-46).txt Scan type: Quick scan Objects scanned: 163174 Time elapsed: 6 minute(s), 45 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) C:\Documents and Settings\Sergiy G\My Documents\Downloads\Mavis Beacon Teaches Typing @Platinum 20\setup.exe NSIS/TrojanDownloader.FakeAlert.DK.Gen trojan C:\Documents and Settings\Sergiy G\My Documents\Downloads\uTorrent Download\Mavis Beacon Teaches Typing @Platinum 20.rar NSIS/TrojanDownloader.FakeAlert.DK.Gen trojan C:\RECYCLER\S-1-5-21-764992494-444690527-3819968728-1006\Dc8.exe a variant of Win32/InstallCore.B application thanks :)
Hi houngan666,

Please download JavaRa to your desktop and unzip it to its own
folder
  • Run JavaRa.exe (double-click for XP/right-click and Run as Administrator for Vista), pick the language of your choice and click Select. Then
    click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe (double-click for XP/right-click and Run as Administrator for Vista) again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest
    Java Runtime Environment (JRE) version for your computer.
———-


You have an older version of Adobe Reader. You can download the current version HERE

You may want to consider Foxit Reader instead. It may be a bit lighter on resources.

Visit their support forum
Foxit Forum

In either case you should uninstall Adobe Reader 7.0.7 first. Be sure to move any PDF documents to another folder first though.
———-

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :Files
    C:\Documents and Settings\Sergiy G\My Documents\Downloads\Mavis Beacon Teaches Typing @Platinum 20\setup.exe
    C:\Documents and Settings\Sergiy G\My Documents\Downloads\uTorrent Download\Mavis Beacon Teaches Typing @Platinum 20.rar
    C:\RECYCLER\S-1-5-21-764992494-444690527-3819968728-1006\Dc8.exe
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then run a new scan and post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
———-

In your next reply post the log created by OTL and let me know how your system is running now? :)
My friend's computer is running much better now. Thank you so much Jeff :D .

Here is the OTL log

OTL logfile created on: 8/31/2011 9:39:23 PM - Run 3
OTL by OldTimer - Version 3.2.26.5 Folder = C:\Documents and Settings\Sergiy G\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

502.11 Mb Total Physical Memory | 75.12 Mb Available Physical Memory | 14.96% Memory free
1.20 Gb Paging File | 0.74 Gb Available in Paging File | 62.16% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 68.52 Gb Total Space | 31.08 Gb Free Space | 45.36% Space Free | Partition Type: NTFS

Computer Name: SERGIY | User Name: Sergiy G | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Sergiy G\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Panda Security\Panda Cloud Antivirus\PSUNMain.exe (Panda Security, S.L.)
PRC - C:\Program Files\Panda Security\Panda Cloud Antivirus\PSANHost.exe (Panda Security, S.L.)
PRC - C:\Documents and Settings\Sergiy G\Local Settings\Application Data\Yandex\Updater\praetorian.exe (ООО «ЯНДЕКС»)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe (Sony Corporation)
PRC - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe (Sony Corporation)
PRC - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe (Sony Corporation)
PRC - C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe (Sony Corporation)
PRC - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe (Sony Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Mozilla Firefox\js3250.dll ()
MOD - C:\Documents and Settings\Sergiy G\Application Data\Mozilla\Firefox\Profiles\9vk5a34w.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\components\RadioWMPCoreGecko19.dll ()
MOD - C:\Documents and Settings\Sergiy G\Application Data\Mozilla\Firefox\Profiles\9vk5a34w.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\components\RadioWMPCoreGecko6.dll ()
MOD - C:\Documents and Settings\Sergiy G\Application Data\Mozilla\Firefox\Profiles\9vk5a34w.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\components\RadioWMPCoreGecko5.dll ()
MOD - C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
MOD - C:\Program Files\Lavasoft\Ad-Aware\ShellExt.dll ()
MOD - C:\Program Files\WinRAR\RarExt.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\WINDOWS\system32\msjetoledb40.dll ()
MOD - C:\Program Files\Panda Security\Panda Cloud Antivirus\MiniCrypto.dll ()
MOD - C:\Program Files\Panda Security\Panda Cloud Antivirus\APIcr.dll ()
MOD - C:\Program Files\Intel\Wireless\Bin\Libeay32.dll ()
MOD - C:\Program Files\Intel\Wireless\Bin\iWMSProv.dll ()
MOD - C:\Program Files\Intel\Wireless\Bin\IntStngs.dll ()
MOD - C:\Program Files\Sony\VAIO Event Service\VESBasePS.dll ()


========== Win32 Services (SafeList) ==========

SRV - (AppMgmt) – File not found
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (NanoServiceMain) – C:\Program Files\Panda Security\Panda Cloud Antivirus\PSANHost.exe (Panda Security, S.L.)
SRV - (VUAgent) – C:\Program Files\Sony\VAIO Update 5\VUAgent.exe (Sony Corporation)
SRV - (VAIOMediaPlatform-IntegratedServer-AppServer) – C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe (Sony Corporation)
SRV - (SSScsiSV) – C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe (Sony Corporation)
SRV - (VAIOMediaPlatform-Mobile-Gateway) – C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe (Sony Corporation)
SRV - (VzFw) – C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe (Sony Corporation)
SRV - (VzCdbSvc) – C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe (Sony Corporation)
SRV - (Vcsw) – C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe (Sony Corporation)
SRV - (VAIO Entertainment TV Device Arbitration Service) – C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe (Sony Corporation)
SRV - (MSCSPTISRV) – C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe (Sony Corporation)
SRV - (PACSPTISVR) – C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe (Sony Corporation)
SRV - (SPTISRV) – C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe (Sony Corporation)
SRV - (VAIOMediaPlatform-IntegratedServer-UPnP) VAIO Media Integrated Server (UPnP) – C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe (Sony Corporation)
SRV - (VAIOMediaPlatform-IntegratedServer-HTTP) VAIO Media Integrated Server (HTTP) – C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe (Sony Corporation)
SRV - (Image Converter video recording monitor for VAIO Entertainment) – C:\Program Files\Sony\Image Converter 2\IcVzMon.exe (Sony Corporation)
SRV - (VAIO Event Service) – C:\Program Files\Sony\VAIO Event Service\VESMgr.exe (Sony Corporation)


========== Driver Services (SafeList) ==========

DRV - (PSINProt) – C:\WINDOWS\system32\drivers\PSINProt.sys (Panda Security, S.L.)
DRV - (PSINAflt) – C:\WINDOWS\system32\drivers\PSINAflt.sys (Panda Security, S.L.)
DRV - (PSINKNC) – C:\WINDOWS\system32\drivers\PSINKNC.sys (Panda Security, S.L.)
DRV - (PSINProc) – C:\WINDOWS\system32\drivers\PSINProc.sys (Panda Security, S.L.)
DRV - (PSINFile) – C:\WINDOWS\system32\drivers\PSINFile.sys (Panda Security, S.L.)
DRV - (Lbd) – C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (ti21sony) – C:\WINDOWS\system32\drivers\ti21sony.sys (Texas Instruments)
DRV - (STHDA) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (usbvm321) – C:\WINDOWS\system32\drivers\usbvm321.sys (Vimicro Corporation)
DRV - (SonyImgF) – C:\WINDOWS\system32\drivers\SonyImgF.sys (Sony Corporation)
DRV - (w39n51) Intel® – C:\WINDOWS\system32\drivers\w39n51.sys (Intel® Corporation)
DRV - (s24trans) – C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (Tosrfusb) – C:\WINDOWS\system32\drivers\tosrfusb.sys (TOSHIBA CORPORATION)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (HSFHWAZL) – C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (Tosrfbd) – C:\WINDOWS\system32\drivers\tosrfbd.sys (TOSHIBA CORPORATION)
DRV - (Tosrfhid) – C:\WINDOWS\system32\drivers\tosrfhid.sys (TOSHIBA Corporation.)
DRV - (SI3132) – C:\WINDOWS\system32\DRIVERS\SI3132.sys (Silicon Image, Inc.)
DRV - (SiRemFil) – C:\WINDOWS\system32\DRIVERS\SiRemFil.sys (Silicon Image, Inc.)
DRV - (tosporte) – C:\WINDOWS\system32\drivers\tosporte.sys (TOSHIBA Corporation)
DRV - (Tosrfbnp) – C:\WINDOWS\system32\drivers\tosrfbnp.sys (TOSHIBA Corporation)
DRV - (Tosrfcom) – C:\WINDOWS\system32\drivers\tosrfcom.sys (TOSHIBA Corporation)
DRV - (tosrfnds) – C:\WINDOWS\system32\drivers\tosrfnds.sys (TOSHIBA Corporation.)
DRV - (ApfiltrService) – C:\WINDOWS\system32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (SiFilter) – C:\WINDOWS\system32\DRIVERS\SiWinAcc.sys (Silicon Image, Inc.)
DRV - (DMICall) – C:\WINDOWS\system32\drivers\DMICall.sys (Sony Corporation)
DRV - (SNC) – C:\WINDOWS\system32\drivers\SonyNC.sys (Sony Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yandex.ru/?clid=47540
IE - HKCU\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: {54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - C:\Program Files\AOL\AOL Search Enhancement\AOLSearch.dll (America Online, Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Rambler"
FF - prefs.js..browser.search.defaultthis.engineName: ""
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2857572&SearchSource;=3&q;={searchTerms}"
FF - prefs.js..browser.search.param.yahoo-type: "${8}"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "www.google.com"
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.3.20100310105313
FF - prefs.js..extensions.enabledItems: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA}:7.0


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKCU\Software\MozillaPlugins\@yahoo.com/BrowserPlus,version=2.9.8: C:\Documents and Settings\Sergiy G\Local Settings\Application Data\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll (Yahoo! Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.20\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/08/27 13:33:21 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.20\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/08/27 13:33:21 | 000,000,000 | —D | M]

[2010/03/16 13:01:24 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Sergiy G\Application Data\Mozilla\Extensions
[2011/08/31 21:36:56 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Sergiy G\Application Data\Mozilla\Firefox\Profiles\9vk5a34w.default\extensions
[2011/08/23 07:17:15 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Sergiy G\Application Data\Mozilla\Firefox\Profiles\9vk5a34w.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/08/26 21:20:32 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\Sergiy G\Application Data\Mozilla\Firefox\Profiles\9vk5a34w.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011/08/26 21:19:54 | 000,000,000 | —D | M] (uTorrentBar Community Toolbar) – C:\Documents and Settings\Sergiy G\Application Data\Mozilla\Firefox\Profiles\9vk5a34w.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
[2011/01/17 15:46:04 | 000,000,919 | —- | M] () – C:\Documents and Settings\Sergiy G\Application Data\Mozilla\Firefox\Profiles\9vk5a34w.default\searchplugins\conduit.xml
[2010/11/14 21:26:30 | 000,002,020 | —- | M] () – C:\Documents and Settings\Sergiy G\Application Data\Mozilla\Firefox\Profiles\9vk5a34w.default\searchplugins\osd.xml
[2011/08/31 21:05:00 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/04/13 08:17:59 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/07/08 23:20:05 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2011/08/31 21:05:01 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA}
[2011/04/13 08:16:53 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/08/31 21:04:27 | 000,611,224 | —- | M] (Oracle Corporation) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2010/06/03 13:06:29 | 000,005,257 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 practivate.adobe.com
O1 - Hosts: 127.0.0.1 ereg.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com
O1 - Hosts: 127.0.0.1 wip3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com
O1 - Hosts: 127.0.0.1 ereg.wip3.adobe.com
O1 - Hosts: 127.0.0.1 activate-sea.adobe.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com
O1 - Hosts: 127.0.0.1 practivate.adobe.com
O1 - Hosts: 127.0.0.1 ereg.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com
O1 - Hosts: 127.0.0.1 wip3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com
O1 - Hosts: 127.0.0.1 ereg.wip3.adobe.com
O1 - Hosts: 107 more lines…
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (AOLSearchHook Class) - {54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - C:\Program Files\AOL\AOL Search Enhancement\AOLSearch.dll (America Online, Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (Яндекс.Бар) - {91397D20-1446-11D4-8AF4-0040CA1127B6} - C:\Program Files\Yandex\YandexBarIE\yndbar.dll (ООО «ЯНДЕКС»)
O3 - HKCU\..\Toolbar\WebBrowser: (Яндекс.Бар) - {91397D20-1446-11D4-8AF4-0040CA1127B6} - C:\Program Files\Yandex\YandexBarIE\yndbar.dll (ООО «ЯНДЕКС»)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [PartSeal] C:\WINDOWS\SONYSYS\VAIO Recovery\PartSeal.exe (Sony Electronics Inc)
O4 - HKLM..\Run: [PSUNMain] C:\Program Files\Panda Security\Panda Cloud Antivirus\PSUNMain.exe (Panda Security, S.L.)
O4 - HKLM..\Run: [Switcher.exe] C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe (Sony Corporation)
O4 - HKCU..\Run: [Praetorian] C:\Documents and Settings\Sergiy G\Local Settings\Application Data\Yandex\Updater\praetorian.exe (ООО «ЯНДЕКС»)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 8
O8 - Extra context menu item: Transfer by Image Converter 2 Plus - C:\Program Files\Sony\Image Converter 2\menu.htm ()
O9 - Extra Button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe (PokerStars)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://www.pcpitstop.com/betapit/PCPitStop.CAB (PCPitstop Utility)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\VESWinlogon: DllName - VESWinlogon.dll - C:\WINDOWS\System32\VESWinlogon.dll (Sony Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\VAIO Light Flo Wallpaper TrueColor 1920x1200.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\VAIO Light Flo Wallpaper TrueColor 1920x1200.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/03/15 17:09:18 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/08/31 21:41:13 | 000,000,000 | —D | C] – C:\Documents and Settings\Sergiy G\Local Settings\Application Data\Sun
[2011/08/31 21:25:01 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Foxit Reader 5.0
[2011/08/31 21:24:53 | 000,000,000 | —D | C] – C:\Program Files\Foxit Software
[2011/08/31 21:13:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Sergiy G\Start Menu\Programs\Revo Uninstaller
[2011/08/31 21:13:46 | 000,000,000 | —D | C] – C:\Program Files\VS Revo Group
[2011/08/31 21:05:32 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2011/08/31 21:04:58 | 000,214,408 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\javaws.exe
[2011/08/31 21:04:58 | 000,173,960 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\javaw.exe
[2011/08/31 21:04:58 | 000,173,960 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\java.exe
[2011/08/30 23:36:16 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2011/08/30 23:18:09 | 000,000,000 | —D | C] – C:\Documents and Settings\Sergiy G\Application Data\Malwarebytes
[2011/08/30 23:17:31 | 000,041,272 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/08/30 23:17:31 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/08/30 23:17:28 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/08/30 23:17:22 | 000,022,712 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/08/30 23:17:21 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/08/30 14:58:50 | 000,000,000 | —D | C] – C:\_OTL
[2011/08/29 21:06:31 | 000,000,000 | —D | C] – C:\Documents and Settings\Sergiy G\Desktop\gmer
[2011/08/29 21:05:43 | 001,916,416 | —- | C] (AVAST Software) – C:\Documents and Settings\Sergiy G\Desktop\aswMBR.exe
[2011/08/28 12:39:21 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Sergiy G\Recent
[2011/08/27 19:16:16 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\The KMPlayer
[2011/08/27 19:15:46 | 000,000,000 | —D | C] – C:\Program Files\The KMPlayer
[2011/08/27 13:38:42 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\iTunes
[2011/08/27 13:37:46 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2011/08/27 13:37:22 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2011/08/27 13:33:11 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\QuickTime
[2011/08/27 13:32:50 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2011/08/27 01:08:55 | 000,000,000 | —D | C] – C:\Documents and Settings\Sergiy G\Application Data\InstallShield
[2011/08/27 01:02:46 | 000,000,000 | —D | C] – C:\Update
[2011/08/26 21:12:07 | 000,000,000 | R–D | C] – C:\Documents and Settings\Sergiy G\Start Menu\Programs\Administrative Tools
[2011/08/26 20:46:26 | 000,580,096 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Sergiy G\Desktop\OTL.exe
[2011/08/23 07:16:58 | 000,139,656 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rdpwd.sys
[2011/08/20 12:16:25 | 000,010,496 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ndistapi.sys
[2011/08/01 21:57:14 | 000,107,368 | —- | C] (GEAR Software Inc.) – C:\WINDOWS\System32\GEARAspi.dll
[2011/08/01 21:50:51 | 000,000,000 | —D | C] – C:\Program Files\Bonjour

========== Files - Modified Within 30 Days ==========

[2011/08/31 21:33:26 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/08/31 21:33:25 | 526,569,472 | -HS- | M] () – C:\hiberfil.sys
[2011/08/31 21:04:26 | 000,544,656 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\deployJava1.dll
[2011/08/31 21:04:26 | 000,214,408 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\javaws.exe
[2011/08/31 21:04:26 | 000,173,960 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\javaw.exe
[2011/08/31 21:04:26 | 000,173,960 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\java.exe
[2011/08/31 21:04:26 | 000,128,000 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\javacpl.cpl
[2011/08/30 23:17:31 | 000,000,784 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/08/30 15:47:12 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2011/08/29 23:39:04 | 000,000,512 | —- | M] () – C:\Documents and Settings\Sergiy G\Desktop\MBR.dat
[2011/08/29 22:51:32 | 001,916,416 | —- | M] (AVAST Software) – C:\Documents and Settings\Sergiy G\Desktop\aswMBR.exe
[2011/08/29 20:49:37 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/08/27 19:30:30 | 000,000,264 | —- | M] () – C:\WINDOWS\System32\PSUNCpl.dat
[2011/08/27 14:34:40 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2011/08/27 13:38:43 | 000,001,542 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2011/08/27 00:43:34 | 000,462,874 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/08/27 00:43:34 | 000,080,302 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/08/26 20:46:44 | 000,580,096 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Sergiy G\Desktop\OTL.exe
[2011/08/08 19:24:04 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job

========== Files Created - No Company Name ==========

[2011/08/30 23:17:31 | 000,000,784 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/08/29 23:39:04 | 000,000,512 | —- | C] () – C:\Documents and Settings\Sergiy G\Desktop\MBR.dat
[2011/08/27 13:38:43 | 000,001,542 | —- | C] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2011/08/27 01:02:00 | 000,000,880 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\VAIO Update.lnk
[2011/03/02 22:00:13 | 000,013,576 | —- | C] () – C:\WINDOWS\System32\wnaspi32.dll
[2010/06/25 21:33:46 | 000,000,264 | —- | C] () – C:\WINDOWS\System32\PSUNCpl.dat
[2010/03/17 00:11:39 | 000,036,128 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2010/03/16 12:34:29 | 000,000,131 | —- | C] () – C:\Documents and Settings\Sergiy G\Local Settings\Application Data\fusioncache.dat
[2010/03/16 12:18:14 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2010/03/16 12:18:14 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2010/03/16 12:18:14 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2010/03/16 12:18:14 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2010/03/16 12:18:14 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2010/03/16 12:18:14 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2010/03/16 12:17:22 | 000,000,004 | —- | C] () – C:\WINDOWS\Pix11.dat
[2010/03/16 12:07:05 | 000,019,968 | —- | C] () – C:\WINDOWS\System32\Cpuinf32.dll
[2010/03/16 12:05:23 | 000,000,166 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2010/03/16 12:02:43 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2010/03/16 11:56:13 | 000,002,158 | —- | C] () – C:\WINDOWS\System32\tmmute.ini
[2006/03/16 23:41:35 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/03/15 18:36:02 | 000,000,056 | —- | C] () – C:\WINDOWS\WININIT.INI
[2006/03/15 18:27:57 | 000,000,000 | —- | C] () – C:\WINDOWS\VAIOUpdt.INI
[2006/03/15 17:46:50 | 000,111,552 | —- | C] () – C:\WINDOWS\setup.exe
[2006/03/15 17:33:17 | 000,000,032 | —- | C] () – C:\WINDOWS\System32\elcric.dat
[2006/03/15 17:15:18 | 000,000,800 | —- | C] () – C:\WINDOWS\orun32.ini
[2006/03/15 17:11:39 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2006/03/15 17:07:06 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2006/03/15 15:53:41 | 000,094,208 | —- | C] () – C:\WINDOWS\System32\nvapi.dll
[2006/03/15 15:53:35 | 000,000,758 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2006/03/15 15:53:13 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2006/03/15 15:53:11 | 000,462,874 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2006/03/15 15:53:11 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2006/03/15 15:53:11 | 000,080,302 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2006/03/15 15:53:11 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2006/03/15 15:53:09 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2006/03/15 15:53:09 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2006/03/15 15:53:07 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2006/03/15 15:53:04 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2006/03/15 15:53:04 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2006/03/15 15:53:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2006/03/15 15:52:54 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2006/03/15 09:00:41 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2006/03/15 08:59:51 | 002,175,680 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2006/01/25 16:15:38 | 000,046,345 | —- | C] () – C:\WINDOWS\NSSetDefaultBrowser.EXE
[2005/11/01 21:53:38 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2002/06/12 16:21:12 | 000,049,152 | R— | C] () – C:\WINDOWS\System32\winchip.dll

< End of report >

Just want to confirm if we are all done…?
Hi houngan666,

I was looking over your last OTL log that you sent me and I notice that you still have an entry for Java 1.6.026. That is an older version of Java that you can delete via Start > Control Panel > Add/Remove Programs. You currently have Java 1.7 which is the latest version of Java which is good. Leaving behind older, outdated versions of software can create security vulnerabilities that can lead to re-infection of the system.
———-

IT APPEARS THAT YOUR LOGS ARE NOW CLEAN :D SO LETS DO A COUPLE OF THINGS TO WRAP THIS UP!! :D

This infection appears to have been cleaned, but I can not give you any absolute guarantees. As a precaution, I would go ahead and change all of your passwords as this is especially important after an infection.
———-

Clean up with OTL:
  • Double-click (XP) or right-click and Run as Administrator (Vista) OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.
———-

**All of the remaining tools that we have used, as well as logs you created from these tools, can be deleted by right-clicking them and selecting delete so that they aren't cluttering up your desktop.**

Here are some tips to reduce the potential for spyware infection in the future:

1. Make your Internet Explorer more secure - This can be done by following these simple instructions:
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
  • Next press the Apply button and then the OK to exit the Internet Properties page.
2. Use and Update an Anti-Virus Software - I can not overemphasize the need for you to use and update your Anti-virus application on a regular basis. With the ever increasing number of new variants of malware arriving on the scene daily, you become very susceptible to an attack without updated protection.

3. Firewall
Using a third-party firewall will allow you to give/deny access for applications that want to go online. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a Firewall in its default configuration can lower your risk greatly. A tutorial on Firewalls and a listing of some available ones can be found here.
**Do not install more than one firewall program because they will conflict with each other**

4. Make sure you keep your Windows OS current by visiting Windows update regularly to download and install any critical updates and service packs. Without these you are leaving the back door open.

5. Filehippo's Update Checker. It is a free utilitiy that scan your computer for installed software, checks the versions and then sends this information to see if there are any newer releases. Available software updates are displayed and you can decide which ones to download and install. Among many other types of programs, they includes a number of the Anti-Spyware, Firewall/Security and Anti-Virus programs that have been recommended (though not all of them). Note: Definition files should be updated from within the programs themselves. The Update Checker look for newer versions of the software program, not definition files.

6. Consider a custom hosts file such as MVPS HOSTS. This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers. For information on how to download and install, please read this tutorial by WinHelp2002
Note: Be sure to follow the instructions to disable the DNS Client service before installing a custom hosts file.

7. WOT , Web of Trust, As 'Googling' is such an integral part of internet life, this free browser add on warns you about risky websites that try to scam visitors, deliver malware or send spam. It is especially helpful when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
  • Green to go
  • Yellow for caution
  • Red to stop
WOT has an add-on available for both Firefox and IE.

8. Install Spybot - Search and Destroy - Download and install Spybot - Search and Destroy with its TeaTimer option. This will provide real time spyware and hijacker protection on your computer alongside your virus protection. You should scan your computer with the program on a regular basis just as you would with your anti-virus software. A tutorial on installing and using this product can be found here:
Instructions for - Spybot S & D.

9. Finally, I strongly recommend that you read TonyKlein's good advice So how did I get infected in the first place?

Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.
Hello again Jeff - and thank you again for you patient help. I ran OTL as instructed and the computer rebooted. I'm feeling my way around to see if files, programs etc open any faster and I honestly can't say for sure that they do. I will run all the software as per instructions and links and let you know. I hope I can do this speedily and report back.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI