This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Crashes and slow running

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My wife was getting some emails that looked like they were from a friend but the content was DEFINITELY not something her friend would send. Shortly after that her computer startig acting sluggish and different programs would crash.She hasn't installed anything on the computer. I thought you guys could look to see if there is anything to worry about on her computer. Here are the OTL scans
OTL logfile created on: 9/27/2011 7:56:44 PM - Run 1
OTL by OldTimer - Version 3.2.29.1 Folder = C:\Documents and Settings\Bonita Davenport\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

502.42 Mb Total Physical Memory | 136.88 Mb Available Physical Memory | 27.24% Memory free
1.20 Gb Paging File | 0.67 Gb Available in Paging File | 55.83% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 26.27 Gb Total Space | 14.42 Gb Free Space | 54.91% Space Free | Partition Type: FAT32
Drive D: | 26.66 Gb Total Space | 26.65 Gb Free Space | 99.96% Space Free | Partition Type: FAT32

Computer Name: ACER-684C9A655D | User Name: Bonita Davenport | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Bonita Davenport\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Security Client\Antimalware\MpCmdRun.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe (Yahoo! Inc)
PRC - C:\Program Files\HP\HP UT\bin\hppusg.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Launch Manager\LaunchAp.exe ()
PRC - C:\Program Files\Launch Manager\WButton.exe ()
PRC - C:\Program Files\Launch Manager\OSDCtrl.exe ()
PRC - C:\Program Files\acer\eRecovery\Monitor.exe (acer Inc.)
PRC - C:\Acer\eManager\anbmServ.exe (OSA Technologies Inc.)
PRC - C:\Program Files\Launch Manager\HotkeyApp.exe (Wistron)
PRC - C:\Acer\ePM\epm-dm.exe (Acer Inc)
PRC - C:\Program Files\Yahoo!\browser\ycommon.exe (Yahoo!, Inc.)
PRC - C:\Program Files\Arcade\PCMService.exe (CyberLink Corp.)
PRC - C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
PRC - C:\Program Files\SBC Self Support Tool\SmartBridge\MotiveSB.exe (Motive Communications, Inc.)
PRC - C:\Program Files\ScanSoft\OmniPageSE2.0\opwareSE2.exe (ScanSoft, Inc.)
PRC - C:\Program Files\BroadJump\Client Foundation\CFD.exe ()
PRC - C:\Program Files\Launch Manager\Powerkey.exe ()
PRC - C:\Program Files\Microsoft Office\Office\FINDFAST.EXE ()
PRC - C:\Program Files\Microsoft Office\Office\OSA.EXE ()


========== Modules (No Company Name) ==========

MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\21248037960cf6dfa2ce401d355bd6c9\System.Runtime.Serialization.Formatters.Soap.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\77df2cd21a5b85a1605b335aa9ad9d44\System.Configuration.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\10154dcad2d62f226af2fd4211460a4b\System.Xml.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\d00cc387e462e4c3cdcd112b137cac87\System.Windows.Forms.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\7ed09623172a292eaee51e2e3bcaf784\System.Drawing.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\e6c79e1d71b0c9000afd7e5e439b5c54\System.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\0309936a8e1672d39b9cf14463ce69f9\mscorlib.ni.dll ()
MOD - C:\WINDOWS\assembly\GAC\Interop.hpqusg\3.0.0.0__a53cf5803f4c3827\Interop.hpqusg.dll ()
MOD - C:\Program Files\HP\HP UT\bin\HPToolkit.dll ()
MOD - C:\Program Files\HP\HP UT\bin\HPUsageTracking.dll ()
MOD - C:\Program Files\HP\HP UT\bin\Enumeration.dll ()
MOD - C:\Program Files\HP\HP UT\bin\hppusg.exe ()
MOD - C:\Program Files\HP\HP UT\bin\HPTools.dll ()
MOD - C:\Program Files\Launch Manager\LaunchAp.exe ()
MOD - C:\Program Files\Launch Manager\WButton.exe ()
MOD - C:\Program Files\Launch Manager\OSDCtrl.exe ()
MOD - C:\Program Files\Yahoo!\browser\YCommonPS.dll ()
MOD - C:\Program Files\BroadJump\Client Foundation\CFD.exe ()
MOD - C:\Program Files\Launch Manager\Powerkey.exe ()
MOD - C:\Program Files\BroadJump\Client Foundation\TimerManager.dll ()
MOD - C:\Program Files\BroadJump\Client Foundation\AppProperties.dll ()
MOD - C:\Program Files\BroadJump\Client Foundation\BJComBase.dll ()
MOD - C:\Program Files\BroadJump\Client Foundation\BJComSRCManager.dll ()
MOD - C:\Program Files\BroadJump\Client Foundation\BasicLoaderService.dll ()
MOD - C:\Program Files\BroadJump\Client Foundation\BJComRT.dll ()
MOD - C:\Program Files\BroadJump\Client Foundation\BJIntlCore_1_1_DDR.dll ()
MOD - C:\Program Files\BroadJump\Client Foundation\stlport_4_0_0_DDR.dll ()
MOD - C:\Program Files\Microsoft Office\Office\MSO97.DLL ()
MOD - C:\Program Files\Microsoft Office\Office\FINDFAST.EXE ()
MOD - C:\Program Files\Microsoft Office\Office\OSA.EXE ()


========== Win32 Services (SafeList) ==========

SRV - (AppMgmt) – File not found
SRV - (MsMpSvc) – C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV - (anbmService) – C:\Acer\eManager\anbmServ.exe (OSA Technologies Inc.)


========== Driver Services (SafeList) ==========

DRV - (MpKsl2c431cc4) – C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{CD739184-F9F3-49AA-BC35-853112C26429}\MpKsl2c431cc4.sys (Microsoft Corporation)
DRV - (HPFXBULK) – C:\WINDOWS\system32\drivers\hpfxbulk.sys (Hewlett Packard)
DRV - (BVRPMPR5) – C:\WINDOWS\system32\drivers\BVRPMPR5.SYS (BVRP Software)
DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (EpmShd) – C:\WINDOWS\system32\drivers\epm-shd.sys (Acer Value Labs, USA)
DRV - (osaio) – C:\WINDOWS\system32\drivers\osaio.sys (Avocent/OSA Technologies Inc.)
DRV - (osanbm) – C:\WINDOWS\system32\drivers\osanbm.sys (Windows ® 2000 DDK provider)
DRV - (int15.sys) – C:\Program Files\acer\eRecovery\int15.sys ()
DRV - (BCM43XX) – C:\WINDOWS\system32\drivers\BCMWL5.SYS (Broadcom Corporation)
DRV - (HSFHWICH) – C:\WINDOWS\system32\drivers\HSFHWICH.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) – C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (RTL8023xp) – C:\WINDOWS\system32\drivers\Rtlnicxp.sys (Realtek Semiconductor Corporation )
DRV - (EpmPsd) – C:\WINDOWS\system32\drivers\epm-psd.sys (Acer Value Labs, USA)
DRV - (pfc) – C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
DRV - (Hotkey) – C:\WINDOWS\System32\drivers\HOTKEY.sys ()
DRV - (POWERKEY) – C:\Program Files\Launch Manager\POWERKEY.SYS ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://red.clientapps.yahoo.com/customize/…/search/ie.html

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp/def…/search/ie.html
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp/def…//www.yahoo.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1

FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.1: C:\Program Files\Yahoo!\Shared\npYState.dll ( )
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)



O1 HOSTS File: ([2004/08/04 05:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (UberButton Class) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\common\yiesrvc.dll (Yahoo!)
O2 - BHO: (YahooTaggedBM Class) - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\common\YIeTagBm.dll (Yahoo! Inc.)
O2 - BHO: (SidebarAutoLaunch Class) - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe ()
O4 - HKLM..\Run: [CtrlVol] C:\Program Files\Launch Manager\CtrlVol.exe (Wistron)
O4 - HKLM..\Run: [EPM-DM] c:\Acer\ePM\epm-dm.exe (Acer Inc)
O4 - HKLM..\Run: [ePowerManagement] C:\Acer\ePM\ePM.exe (Acer Value Labs, Taiwan)
O4 - HKLM..\Run: [eRecoveryService] C:\Program Files\acer\eRecovery\Monitor.exe (acer Inc.)
O4 - HKLM..\Run: [HPPQVideo] "C:\Program Files\HP\ScheduledLaunch\HP LaserJet P2050 Series\bin\hppschlnch.exe" -r SOFTWARE\Hewlett-Packard\ScheduledLaunch\LJ_P2050_Series -f PQOptimizerVideo.xml -o RemindLater File not found
O4 - HKLM..\Run: [HPUsageTracking] C:\Program Files\HP\HP UT\bin\hppusg.exe ()
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [LaunchAp] C:\Program Files\Launch Manager\LaunchAp.exe ()
O4 - HKLM..\Run: [LManager] C:\Program Files\Launch Manager\HotkeyApp.exe (Wistron)
O4 - HKLM..\Run: [LMgrOSD] C:\Program Files\Launch Manager\OSDCtrl.exe ()
O4 - HKLM..\Run: [Motive SmartBridge] C:\Program Files\SBC Self Support Tool\SmartBridge\MotiveSB.exe (Motive Communications, Inc.)
O4 - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [OpwareSE2] C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe (ScanSoft, Inc.)
O4 - HKLM..\Run: [PCMService] C:\Program Files\Arcade\PCMService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PowerKey] C:\Program Files\Launch Manager\PowerKey.exe ()
O4 - HKLM..\Run: [preload] C:\WINDOWS\RUNXMLPL.EXE (Wistron)
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [ToolBoxFX] C:\Program Files\HP\ToolBoxFX\bin\HPTLBXFX.exe (HP)
O4 - HKLM..\Run: [Wbutton] C:\Program Files\Launch Manager\Wbutton.exe ()
O4 - HKLM..\Run: [YBrowser] C:\Program Files\Yahoo!\browser\ybrwicon.exe (Yahoo!, Inc.)
O4 - HKLM..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe (Yahoo! Inc)
O4 - HKCU..\Run: [Search Protection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe (Yahoo! Inc)
O4 - HKCU..\Run: [Yahoo! Pager] 1 File not found
O4 - HKCU..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe (Yahoo! Inc)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Easy-WebPrint Add To Print List - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint High Speed Print - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint Preview - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint Print - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O9 - Extra Button: SBC Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\common\yiesrvc.dll (Yahoo!)
O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe File not found
O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe File not found
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\common\yinsthelper.dll (YInstStarter Class)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6D0DF362-B85F-4A87-9DBC-D21116C5D77E}: DhcpNameServer = 192.168.1.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - (igfxsrvc.dll) - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\ACERTX.BMP
O24 - Desktop BackupWallPaper: C:\WINDOWS\ACERTX.BMP
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{57f06c14-aca0-11de-b824-0014a43373e3}\Shell - "" = AutoRun
O33 - MountPoints2\{57f06c14-aca0-11de-b824-0014a43373e3}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{57f06c14-aca0-11de-b824-0014a43373e3}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe win32.dll.vbs
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/09/27 19:53:32 | 000,582,656 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Bonita Davenport\Desktop\OTL.exe
[2011/09/27 19:49:59 | 000,000,000 | —D | C] – C:\WINDOWS\pss
[2011/09/27 17:54:58 | 001,916,416 | —- | C] (AVAST Software) – C:\Documents and Settings\Bonita Davenport\Desktop\aswMBR.exe
[2011/09/27 17:52:16 | 000,000,000 | R–D | C] – C:\Documents and Settings\Bonita Davenport\Start Menu\Programs\Administrative Tools
[2011/09/22 20:39:30 | 000,404,640 | —- | C] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/09/22 17:40:17 | 000,139,656 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rdpwd.sys
[2011/09/11 16:46:05 | 000,010,496 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ndistapi.sys
[2011/09/09 02:12:13 | 000,599,040 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\crypt32.dll
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/09/27 20:08:02 | 000,000,390 | -H– | M] () – C:\WINDOWS\tasks\MpIdleTask.job
[2011/09/27 20:06:16 | 000,000,112 | —- | M] () – C:\WINDOWS\ChkMail.Ini
[2011/09/27 19:53:46 | 000,582,656 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Bonita Davenport\Desktop\OTL.exe
[2011/09/27 19:43:22 | 000,475,136 | -H– | M] () – C:\ffastun.ffl
[2011/09/27 19:43:22 | 000,155,648 | -H– | M] () – C:\ffastun.ffo
[2011/09/27 19:43:22 | 000,004,717 | -H– | M] () – C:\ffastun.ffa
[2011/09/27 19:43:20 | 001,495,040 | -H– | M] () – C:\ffastun0.ffx
[2011/09/27 17:43:42 | 000,000,424 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/09/27 17:38:22 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\eRLog.ini
[2011/09/27 17:37:50 | 000,000,098 | —- | M] () – C:\WINDOWS\ComponentList.xml
[2011/09/27 17:37:32 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/09/27 17:37:30 | 526,897,152 | -HS- | M] () – C:\hiberfil.sys
[2011/09/26 18:41:16 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/09/22 20:39:32 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/09/22 18:07:56 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/09/22 18:07:06 | 000,434,688 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/09/22 18:07:06 | 000,068,808 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/09/22 18:02:14 | 000,001,945 | —- | M] () – C:\WINDOWS\epplauncher.mif
[2011/09/12 08:29:40 | 000,007,062 | —- | M] () – C:\WINDOWS\Bonita Davenport8.xlb
[2011/09/11 16:37:52 | 000,231,984 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/09/09 02:12:14 | 000,599,040 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\crypt32.dll
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/09/27 19:32:43 | 000,000,512 | —- | C] () – C:\Documents and Settings\Bonita Davenport\Desktop\MBR.dat
[2011/09/22 18:06:52 | 000,000,424 | -H– | C] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/09/22 18:06:30 | 000,000,390 | -H– | C] () – C:\WINDOWS\tasks\MpIdleTask.job
[2009/09/12 16:52:38 | 000,000,619 | R— | C] () – C:\WINDOWS\System32\hppapr13.dat
[2009/09/12 16:48:22 | 000,175,594 | —- | C] () – C:\WINDOWS\hppins13.dat
[2009/09/12 16:48:22 | 000,005,989 | —- | C] () – C:\WINDOWS\hppmdl13.dat
[2008/10/19 08:04:19 | 000,008,704 | —- | C] () – C:\WINDOWS\System32\CNMVS7K.DLL
[2008/06/15 18:25:21 | 000,007,680 | —- | C] () – C:\WINDOWS\System32\CNMVS5y.DLL
[2008/06/15 17:15:10 | 000,000,247 | —- | C] () – C:\WINDOWS\LEXSTAT.INI
[2007/03/16 17:00:00 | 000,003,403 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini
[2007/02/25 09:59:14 | 000,008,266 | —- | C] () – C:\WINDOWS\extend.dat
[2007/02/04 16:04:07 | 000,001,517 | —- | C] () – C:\WINDOWS\checkip.dat
[2006/07/26 15:56:20 | 000,000,022 | —- | C] () – C:\WINDOWS\exchng.ini
[2006/07/26 15:56:19 | 000,000,611 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/06/12 14:51:24 | 000,000,532 | —- | C] () – C:\WINDOWS\MAXLINK.INI
[2006/03/11 11:08:30 | 000,008,704 | —- | C] () – C:\WINDOWS\System32\CNMVS7I.DLL
[2006/02/14 12:50:44 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\YCRWin32.dll
[2006/02/14 12:29:37 | 000,006,550 | —- | C] () – C:\WINDOWS\jautoexp.dat
[2006/02/13 18:24:42 | 000,078,031 | —- | C] () – C:\WINDOWS\System32\Autorun.ini
[2006/02/13 18:13:29 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\eRLog.ini
[2005/11/19 10:40:23 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2005/11/19 10:40:23 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2005/11/19 10:40:23 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2005/11/19 10:40:23 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2005/11/19 10:40:22 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2005/11/19 10:40:22 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2005/06/24 10:48:03 | 000,009,867 | —- | C] () – C:\WINDOWS\System32\drivers\HOTKEY.sys
[2005/06/20 02:42:13 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/06/20 02:17:30 | 000,001,024 | RH– | C] () – C:\WINDOWS\System32\NTIBUN4.dll
[2005/06/20 02:16:31 | 000,001,024 | RH– | C] () – C:\WINDOWS\System32\NTIMPEG2.dll
[2005/06/20 02:16:31 | 000,001,024 | RH– | C] () – C:\WINDOWS\System32\NTIMP3.dll
[2005/06/20 02:16:31 | 000,001,024 | RH– | C] () – C:\WINDOWS\System32\NTIFCD3.dll
[2005/06/20 02:16:31 | 000,001,024 | RH– | C] () – C:\WINDOWS\System32\NTICDMK7.dll
[2005/06/20 02:09:07 | 000,156,672 | —- | C] () – C:\WINDOWS\System32\RtlCPAPI.dll
[2005/06/20 02:09:07 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\ChCfg.exe
[2005/06/20 02:09:03 | 000,001,048 | —- | C] () – C:\WINDOWS\System32\drivers\alcxinit.dat
[2005/06/20 01:39:37 | 000,872,448 | —- | C] () – C:\WINDOWS\iconv.dll
[2005/06/20 01:39:37 | 000,743,424 | —- | C] () – C:\WINDOWS\libxml2.dll
[2005/06/20 01:39:37 | 000,049,152 | —- | C] () – C:\WINDOWS\XMLaunch.exe
[2005/06/20 01:39:37 | 000,001,150 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2005/06/20 01:38:13 | 000,000,215 | —- | C] () – C:\WINDOWS\FlashSaver.dat
[2004/12/17 17:14:44 | 000,013,952 | —- | C] () – C:\WINDOWS\System32\drivers\UBHelper.sys
[2004/09/14 13:08:28 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2004/09/14 13:02:53 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2004/09/14 13:01:42 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2004/09/14 12:56:56 | 000,004,346 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2004/09/14 12:56:10 | 000,231,984 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2001/12/26 16:12:30 | 000,065,536 | R— | C] () – C:\WINDOWS\System32\multiplex_vcd.dll
[2001/09/03 23:46:38 | 000,110,592 | R— | C] () – C:\WINDOWS\System32\Hmpg12.dll
[2001/07/30 16:33:56 | 000,118,784 | R— | C] () – C:\WINDOWS\System32\HMPV2_ENC.dll
[2001/07/23 22:04:36 | 000,118,784 | R— | C] () – C:\WINDOWS\System32\HMPV2_ENC_MMX.dll
[1997/07/11 00:00:00 | 000,047,104 | —- | C] () – C:\WINDOWS\System32\WRKGADM.EXE
[1997/07/11 00:00:00 | 000,031,232 | —- | C] () – C:\WINDOWS\System32\XLREC.DLL
[1997/07/11 00:00:00 | 000,025,600 | —- | C] () – C:\WINDOWS\System32\RECNCL.DLL
[1997/07/11 00:00:00 | 000,022,016 | —- | C] () – C:\WINDOWS\System32\ODBCSTF.DLL
[1997/07/11 00:00:00 | 000,022,016 | —- | C] () – C:\WINDOWS\System32\DOCOBJ.DLL
[1997/07/11 00:00:00 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\HLINKPRX.DLL
[1980/01/01 00:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[1980/01/01 00:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[1980/01/01 00:00:00 | 000,434,688 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[1980/01/01 00:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[1980/01/01 00:00:00 | 000,225,280 | —- | C] () – C:\WINDOWS\Capsule.dll
[1980/01/01 00:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[1980/01/01 00:00:00 | 000,068,808 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[1980/01/01 00:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[1980/01/01 00:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[1980/01/01 00:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[1980/01/01 00:00:00 | 000,004,524 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[1980/01/01 00:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\Dcache.bin
[1980/01/01 00:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat

========== LOP Check ==========

[2006/03/11 11:08:34 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2006/06/12 14:51:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SSScanAppDataDir
[2006/06/12 14:51:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SSScanWizard
[2007/02/04 18:52:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Yahoo
[2008/06/15 18:00:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2005/11/19 10:40:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Bonita Davenport\Application Data\InterVideo
[2006/06/12 14:51:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Bonita Davenport\Application Data\ScanSoft
[2007/02/04 16:33:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Bonita Davenport\Application Data\MSNInstaller
[2009/09/11 17:28:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Bonita Davenport\Application Data\Canon
[2011/09/27 20:08:02 | 000,000,390 | -H– | M] () – C:\WINDOWS\Tasks\MpIdleTask.job
[2011/09/27 17:43:42 | 000,000,424 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2011/09/27 19:43:22 | 000,155,648 | -H– | M] () – C:\ffastun.ffo
[2004/09/14 12:46:06 | 000,000,512 | -HS- | M] () – C:\BOOTSECT.DOS
[2010/04/14 22:31:52 | 000,250,048 | RHS- | M] () – C:\ntldr
[2004/08/04 05:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2006/02/13 18:10:46 | 000,000,196 | RHS- | M] () – C:\BOOT.INI
[2011/09/27 19:43:22 | 000,475,136 | -H– | M] () – C:\ffastun.ffl
[2005/06/20 02:52:18 | 000,000,066 | RHS- | M] () – C:\PRELOAD.AAA
[2005/06/20 01:40:04 | 000,000,004 | —- | M] () – C:\wps.dat
[2005/06/20 02:52:18 | 000,000,066 | RHS- | M] () – C:\PRELOAD.REV
[2005/08/13 13:07:44 | 000,001,202 | -HS- | M] () – C:\PATCH.REV
[2011/09/27 17:37:28 | 792,723,456 | -HS- | M] () – C:\pagefile.sys
[2011/09/27 17:37:30 | 526,897,152 | -HS- | M] () – C:\hiberfil.sys
[2011/09/27 19:43:20 | 001,495,040 | -H– | M] () – C:\ffastun0.ffx
[2011/09/27 19:43:22 | 000,004,717 | -H– | M] () – C:\ffastun.ffa
[2006/02/13 18:50:22 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2006/02/13 18:50:22 | 000,000,000 | RHS- | M] () – C:\IO.SYS

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2004/09/14 13:04:34 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2005/05/06 21:00:00 | 000,020,992 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD7I.DLL
[2005/05/06 21:00:00 | 000,059,392 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP7I.DLL
[2006/05/10 21:46:58 | 000,080,896 | —- | M] (Lexmark International) – C:\WINDOWS\system32\spool\prtprocs\w32x86\LXDAPP5C.DLL
[2004/04/23 14:00:00 | 000,017,920 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD5y.DLL
[2004/04/23 14:00:00 | 000,054,272 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP5y.DLL
[2005/05/06 22:00:00 | 000,020,992 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD7K.DLL
[2005/05/06 22:00:00 | 000,059,392 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP7K.DLL
[2008/07/23 13:01:08 | 000,273,408 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpcpp6bu.DLL
[2008/07/06 03:50:04 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
[2008/07/06 05:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2004/06/14 11:50:08 | 000,187,392 | —- | M] () – C:\WINDOWS\ACER.SCR
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >
[2009/09/11 18:22:18 | 000,001,618 | -H– | M] () – C:\Documents and Settings\Bonita Davenport\Application Data\Microsoft\LastFlashConfig.WFC

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2004/09/14 12:55:48 | 000,892,928 | —- | M] () – C:\WINDOWS\System32\config\system.sav
[2004/09/14 12:55:48 | 000,634,880 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2004/09/14 12:55:48 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2010/04/14 22:43:36 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >
[2005/06/20 02:21:16 | 000,003,967 | —- | M] () – C:\WINDOWS\system32\config\systemprofile\launApp.log

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2004/09/14 13:09:34 | 000,000,079 | —- | M] () – C:\Documents and Settings\Bonita Davenport\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
[2006/02/13 18:11:14 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Bonita Davenport\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/09/27 19:53:46 | 000,582,656 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Bonita Davenport\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-09-28 00:54:51

< >

< >

< End of report >

OTL Extras logfile created on: 9/27/2011 7:56:44 PM - Run 1
OTL by OldTimer - Version 3.2.29.1 Folder = C:\Documents and Settings\Bonita Davenport\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

502.42 Mb Total Physical Memory | 136.88 Mb Available Physical Memory | 27.24% Memory free
1.20 Gb Paging File | 0.67 Gb Available in Paging File | 55.83% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 26.27 Gb Total Space | 14.42 Gb Free Space | 54.91% Space Free | Partition Type: FAT32
Drive D: | 26.66 Gb Total Space | 26.65 Gb Free Space | 99.96% Space Free | Partition Type: FAT32

Computer Name: ACER-684C9A655D | User Name: Bonita Davenport | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Yahoo!\Messenger\YPager.exe" = C:\Program Files\Yahoo!\Messenger\YPager.exe:*:Enabled:Yahoo! Messenger – ()
"C:\Program Files\Yahoo!\Messenger\YServer.exe" = C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server – (Yahoo! Inc.)
"C:\Program Files\Yahoo!\Yahoo! Music Jukebox\YahooMusicEngine.exe" = C:\Program Files\Yahoo!\Yahoo! Music Jukebox\YahooMusicEngine.exe:*:Enabled:Yahoo! Music Jukebox – (Yahoo!)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{022C88CA-59B0-492F-A711-8ADA8EC0D94F}" = CGA District Software
"{02B89B7B-CE43-4166-BA93-5EF42F9DEE5A}" = CGA District Software
"{05BFB060-4F22-4710-B0A2-2801A1B606C5}" = Microsoft Antimalware
"{0EABE101-46B8-49CF-878A-3654B542D3FF}" = CGA District Software
"{11B83AD3-7A46-4C2E-A568-9505981D4C6F}" = HP Update
"{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = Arcade 3.0
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{45DD5AC8-3957-4B35-BC9F-FA7C24638CF9}" = CGA District Software
"{51D5F2F7-18A9-4ABC-B1E8-BC3EC053C76E}" = hppPQVideoP2050
"{54956A0C-3456-4430-BF3C-C3868E733785}" = CGA District Software
"{54B6DC7D-8C5B-4DFB-BC15-C010A3326B2B}" = Microsoft Security Client
"{589F986E-5A4C-4D97-A755-8A3F57683A6D}" = hppTLBXFXP2050
"{58E5844B-7CE2-413D-83D1-99294BF6C74F}" = Acer ePowerManagement
"{5C13B800-859A-4365-B711-2D615B3E5BA9}" = CGA District Software
"{5FDE3A66-69EF-4625-8490-EABF91E6B8A0}" = hpzTLBXFX
"{621C02EA-AAFF-4026-A903-165D59529A16}" = Driver Detective
"{65C39C99-F2C0-4286-A37A-23182E9A5E8E}" = NTI CD & DVD-Maker
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{6F801026-6AF0-4520-9153-4C9B4CAAB361}" = HP LaserJet P2050 Series 3.0
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{79D5997E-BF79-48BB-8B41-9BE59C15C2D7}" = OmniPage SE 2.0
"{7B0E9DBC-31BD-43AB-AEE9-E9946CBE5916}" = CGA District Software
"{827289F5-B44F-4E49-9993-840741585A62}" = Acer eManager for Notebook
"{85309D89-7BE9-4094-BB17-24999C6118FC}" = ArcSoft PhotoStudio 5.5
"{89B6F63A-7E0C-424A-9D39-C4EF59E96D78}" = hppQFolderP2050
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver for Mobile
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{995F2783-8311-49BF-833E-DB659774B4F6}" = hppFonts
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AC76BA86-7AD7-1033-7B44-000000000001}" = Adobe Reader 6.0
"{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = PowerProducer
"{B8DBED1E-8BC3-4d08-B94A-F9D7D88E9BBF}" = HPSSupply
"{BD69DAB8-E483-4E45-A052-16D1C360B67D}" = hppusgP2050
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CCB9B81A-167F-4832-B305-D2A0430840B3}" = WebReg
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CF23AFD7-3078-4134-8823-EBF6D1FE6FAD}" = Canon MP450
"{D0846526-66DD-4DC9-A02C-98F9A2806812}" = Launch Manager V1.0.8.8
"{D2E0F0CC-6BE0-490b-B08B-9267083E34C9}" = MarketResearch
"{ED79C7E1-386E-4C12-81C7-8FEFB6D396B5}" = NTI Backup NOW! 4
"{F181FBC3-C155-4FCB-AD46-9252440ACC5A}" = hppManualsP2050
"{F7B0E599-C114-4493-BC4D-D8FC7CBBABBB}" = 32 Bit HP CIO Components Installer
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"BroadJump Client Foundation" = BroadJump Client Foundation
"CANONBJ_Deinstall_CNMCP5y.DLL" = Canon PIXMA iP1500
"CNXT_MODEM_PCI_VEN_8086&DEV_266D&SUBSYS_006A1025" = SoftV90 Data Fax Modem with SmartCP
"Easy-PhotoPrint" = Canon Utilities Easy-PhotoPrint
"Easy-WebPrint" = Easy-WebPrint
"GridVista" = Acer GridVista
"HPExtendedCapabilities" = HP Customer Participation Program 10.0
"ie8" = Windows Internet Explorer 8
"InstallShield_{621C02EA-AAFF-4026-A903-165D59529A16}" = Driver Detective
"InstallShield_{65C39C99-F2C0-4286-A37A-23182E9A5E8E}" = NTI CD & DVD-Maker Gold
"InstallShield_{827289F5-B44F-4E49-9993-840741585A62}" = Acer eManager for Notebook
"InstallShield_{ED79C7E1-386E-4C12-81C7-8FEFB6D396B5}" = NTI Backup NOW! 4
"Lexmark 640 Series" = Lexmark 640 Series
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Security Client" = Microsoft Security Essentials
"MP Navigator 2.0" = Canon MP Navigator 2.0
"MSNINST" = MSN
"Office8.0" = Microsoft Office 97, Professional Edition
"oggcodecs" = oggcodecs 0.71.0946
"SBC Yahoo! Applications" = SBC Yahoo! Applications
"SBC.MCCInstall" = SBC Self Support Tool
"Shop for HP Supplies" = Shop for HP Supplies
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows XP Service Pack" = Windows XP Service Pack 3
"Yahoo! Search Defender" = Yahoo! Search Protection
"Yahoo! Toolbar" = Yahoo! Toolbar

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 10/15/2008 9:57:19 PM | Computer Name = ACER-684C9A655D | Source = Application Error | ID = 1000
Description = Faulting application dbanal.exe, version 9.0.0.924, faulting module
msvcrt.dll, version 7.0.2600.2180, fault address 0x00030ac4.

Error - 10/15/2008 10:01:13 PM | Computer Name = ACER-684C9A655D | Source = Application Error | ID = 1000
Description = Faulting application dbanal.exe, version 9.0.0.924, faulting module
msvcrt.dll, version 7.0.2600.2180, fault address 0x00030ac4.

Error - 10/15/2008 10:02:52 PM | Computer Name = ACER-684C9A655D | Source = Application Error | ID = 1000
Description = Faulting application dbanal.exe, version 9.0.0.924, faulting module
msvcrt.dll, version 7.0.2600.2180, fault address 0x00030ac4.

Error - 11/8/2008 5:28:49 PM | Computer Name = ACER-684C9A655D | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.2180, faulting
module flash.ocx, version 7.0.19.0, fault address 0x000235d9.

Error - 11/8/2008 5:35:33 PM | Computer Name = ACER-684C9A655D | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.2180, faulting
module mshtml.dll, version 6.0.2900.2180, fault address 0x0009d1a8.

Error - 11/11/2008 5:00:03 PM | Computer Name = ACER-684C9A655D | Source = Application Error | ID = 1000
Description = Faulting application dbanal.exe, version 9.0.0.924, faulting module
msvcrt.dll, version 7.0.2600.2180, fault address 0x00030ac4.

Error - 11/12/2008 6:19:53 PM | Computer Name = ACER-684C9A655D | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.2180, faulting
module mshtml.dll, version 6.0.2900.2180, fault address 0x000d82b2.

Error - 1/12/2009 10:07:17 PM | Computer Name = ACER-684C9A655D | Source = Application Error | ID = 1000
Description = Faulting application dbanal.exe, version 9.0.0.924, faulting module
msvcrt.dll, version 7.0.2600.2180, fault address 0x00030ac4.

Error - 8/26/2009 8:33:28 PM | Computer Name = ACER-684C9A655D | Source = Driver Detective | ID = 1000
Description =

Error - 9/15/2009 12:06:54 AM | Computer Name = ACER-684C9A655D | Source = Application Error | ID = 1000
Description = Faulting application dbanal.exe, version 9.0.0.934, faulting module
msvcrt.dll, version 7.0.2600.2180, fault address 0x00030ac4.

[ System Events ]
Error - 6/19/2011 9:31:19 AM | Computer Name = ACER-684C9A655D | Source = Print | ID = 19
Description = Sharing printer failed + 1722, Printer Canon PIXMA iP1500 share name
Printer2.

Error - 6/19/2011 9:42:34 AM | Computer Name = ACER-684C9A655D | Source = Microsoft Antimalware | ID = 2001
Description = %%860 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.105.2055.0 Update Source: %%859 Update Stage:
%%852 Source Path: http://www.microsoft.com Signature Type: %%800 Update Type: %%803

User:
NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.6903.0 Error
code: 0x8024402c Error description: An unexpected problem occurred while checking
for updates. For information on installing or troubleshooting updates, see Help
and Support.

Error - 6/21/2011 8:59:32 PM | Computer Name = ACER-684C9A655D | Source = Microsoft Antimalware | ID = 2001
Description = %%860 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.105.2055.0 Update Source: %%859 Update Stage:
%%852 Source Path: http://www.microsoft.com Signature Type: %%800 Update Type: %%803

User:
NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.6903.0 Error
code: 0x8024402c Error description: An unexpected problem occurred while checking
for updates. For information on installing or troubleshooting updates, see Help
and Support.

Error - 6/21/2011 8:59:34 PM | Computer Name = ACER-684C9A655D | Source = Microsoft Antimalware | ID = 2001
Description = %%860 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.105.2055.0 Update Source: %%851 Update Stage:
%%852 Source Path: http://go.microsoft.com/fwlink/?LinkID=121…5D-99752CCA7094

Signature
Type: %%800 Update Type: %%803 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version:
Previous Engine Version: 1.1.6903.0 Error code: 0x80072ee7 Error description: The
server name or address could not be resolved

Error - 6/21/2011 8:59:34 PM | Computer Name = ACER-684C9A655D | Source = Microsoft Antimalware | ID = 2001
Description = %%860 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.105.2055.0 Update Source: %%851 Update Stage:
%%852 Source Path: http://go.microsoft.com/fwlink/?LinkID=121…5D-99752CCA7094

Signature
Type: %%801 Update Type: %%803 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version:
Previous Engine Version: 1.1.6903.0 Error code: 0x80072ee7 Error description: The
server name or address could not be resolved

Error - 6/21/2011 8:59:34 PM | Computer Name = ACER-684C9A655D | Source = Microsoft Antimalware | ID = 2001
Description = %%860 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.105.2055.0 Update Source: %%851 Update Stage:
%%852 Source Path: http://go.microsoft.com/fwlink/?LinkID=121…5D-99752CCA7094

Signature
Type: %%800 Update Type: %%803 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version:
Previous Engine Version: 1.1.6903.0 Error code: 0x80072ee7 Error description: The
server name or address could not be resolved

Error - 6/21/2011 8:59:34 PM | Computer Name = ACER-684C9A655D | Source = Microsoft Antimalware | ID = 2001
Description = %%860 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.105.2055.0 Update Source: %%851 Update Stage:
%%852 Source Path: http://go.microsoft.com/fwlink/?LinkID=121…5D-99752CCA7094

Signature
Type: %%801 Update Type: %%803 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version:
Previous Engine Version: 1.1.6903.0 Error code: 0x80072ee7 Error description: The
server name or address could not be resolved

Error - 9/25/2011 9:29:59 AM | Computer Name = ACER-684C9A655D | Source = Microsoft Antimalware | ID = 2001
Description = %%860 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.113.85.0 Update Source: %%859 Update Stage:
%%852 Source Path: http://www.microsoft.com Signature Type: %%800 Update Type: %%803

User:
NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.7702.0 Error
code: 0x8024402c Error description: An unexpected problem occurred while checking
for updates. For information on installing or troubleshooting updates, see Help
and Support.

Error - 9/25/2011 10:44:39 AM | Computer Name = ACER-684C9A655D | Source = Microsoft Antimalware | ID = 2001
Description = %%860 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.113.85.0 Update Source: %%859 Update Stage:
%%852 Source Path: http://www.microsoft.com Signature Type: %%800 Update Type: %%803

User:
NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.7702.0 Error
code: 0x8024402c Error description: An unexpected problem occurred while checking
for updates. For information on installing or troubleshooting updates, see Help
and Support.

Error - 9/27/2011 12:27:09 AM | Computer Name = ACER-684C9A655D | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the WZCSVC service.


< End of report >
Hi poporacer and welcome to WhatTheTech forums!
I'm Sunyata and I will be helping you with your computer problems.

Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts before I post them. This is to ensure that I am giving you the best possible advice. This may cause a delay, but I will do my very best to keep it as short as possible.

Please read the following guidelines which will help to make cleaning your machine easier:

  • Malware logs are often lengthy and can take a lot of time to research and interpret. Please be patient while I review your logs.
  • The fixes I will give you are specific to your problem and should only be used for this issue on this machine.
  • Please make sure to carefully read any instructions posted. If you're not sure, please stop and ask!
  • Please stay with this thread until I tell you your machine appears to be clean. Absence of symptoms does not necessarily mean that all malware is gone.
  • PLEASE DO NOT install/uninstall any programs unless asked to.
  • PLEASE DO NOT run any malware scans other than those requested.
  • Please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
  • I will reply back shortly with instructions
Hello poporacer :)
You do have some malware on your machine. But before we deal with what we can see from your OTL scan, I'd like to look a little deeper with another tool.

Please download aswMBR to your desktop.
  • Double click the aswMBR icon to run it.

    Vista and Windows 7 users right click the icon and choose "Run as administrator".

  • When asked if you want to download Avast's virus definitions please select Yes.
  • Click the Scan button to start scan.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]

Here it is.\, aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software Run date: 2011-09-29 06:26:37 —————————– 06:26:37.640 OS Version: Windows 5.1.2600 Service Pack 3 06:26:37.640 Number of processors: 1 586 0xD08 06:26:37.640 ComputerName: ACER-684C9A655D UserName: 06:26:38.406 Initialize success 06:35:16.093 AVAST engine defs: 11092900 17:46:28.859 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4 17:46:28.859 Disk 0 Vendor: WDC_WD600UE-22HCT1 09.07D09 Size: 57231MB BusType: 3 17:46:30.875 Disk 0 MBR read successfully 17:46:30.875 Disk 0 MBR scan 17:46:32.953 Disk 0 unknown MBR code 17:46:32.984 Disk 0 scanning sectors +117210240 17:46:33.062 Disk 0 scanning C:\WINDOWS\system32\drivers 17:47:27.140 Service scanning 17:47:28.437 Service MpKslb3a46829 C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{6CD64B54-884D-4BFC-8259-48448640E016}\MpKslb3a46829.sys **LOCKED** 32 17:47:29.234 Modules scanning 17:47:55.468 Disk 0 trace - called modules: 17:47:55.484 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS 17:47:55.500 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x82fd5750] 17:47:55.500 3 CLASSPNP.SYS[f8694fd7] -> nt!IofCallDriver -> \Device\0000009e[0x82f65f18] 17:47:55.515 5 ACPI.sys[f848b620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-4[0x82fdd5f0] 17:47:56.078 AVAST engine scan C:\WINDOWS 17:48:24.296 AVAST engine scan C:\WINDOWS\system32 17:52:53.218 AVAST engine scan C:\WINDOWS\system32\drivers 17:53:23.578 AVAST engine scan C:\Documents and Settings\Bonita Davenport 18:08:13.125 AVAST engine scan C:\Documents and Settings\All Users 18:08:30.328 Scan finished successfully 18:16:14.093 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Bonita Davenport\Desktop\MBR.dat" 18:16:14.140 The log file has been saved successfully to "C:\Documents and Settings\Bonita Davenport\Desktop\aswMBR.txt"
Hello poporacer. The aswMBR tool you just ran placed a copy of your boot record on your desktop: C:\Documents and Settings\Bonita Davenport\Desktop\MBR.dat Would you please zip that up and attach it in your next post so that we can get a look at it? Thanks.
Hello poporacer,

Your MBR looks to be consistent with an Acer machine, and therefore OK.
We will go ahead and take care of the problems shown in your OTL scan…

Next, we need to run an OTL Fix

  • Please reopen [external image: Posted Image].
  • Copy and Paste the following code into the [external image: Posted Image] textbox. Do not include the word "Code"

    :Services
    
    :OTL
    O4 - HKLM..\Run: [] File not found
    O4 - HKLM..\Run: [HPPQVideo] "C:\Program Files\HP\ScheduledLaunch\HP LaserJet P2050 Series\bin\hppschlnch.exe" -r SOFTWARE\Hewlett-Packard\ScheduledLaunch\LJ_P2050_Series -f PQOptimizerVideo.xml -o RemindLater File not found
    O4 - HKCU..\Run: [Yahoo! Pager] 1 File not found
    O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe File not found
    O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe File not found
    O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
    O33 - MountPoints2\{57f06c14-aca0-11de-b824-0014a43373e3}\Shell - "" = AutoRun
    O33 - MountPoints2\{57f06c14-aca0-11de-b824-0014a43373e3}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{57f06c14-aca0-11de-b824-0014a43373e3}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe win32.dll.vbs
    
    
    :Files
    C:\WINDOWS\System32\Autorun.ini
    C:\Win32.dll.vbs /s
    
    :Commands
    [purity]
    [emptytemp]
    [EMPTYFLASH]
    [start explorer]
    [Reboot]

  • Push [external image: Posted Image]
  • OTL may ask to reboot the machine. Please do so if asked.
  • Click [external image: Posted Image].
  • A report will open. Copy and Paste that report in your next reply.
  • If the machine reboots, the log will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.
How is the machine behaving now? Are there still issues?
I ran the fix, and it took forever!!! After a couple of hours, I took a closer look and the status bar said it was completed, but the computer was frozen. OTL would not respond to any mouse clicks. I had to do the three finger kill switch (ctrl alt del) to restart the computer. When it rebooted, there was a log open, here is the log: As far as how it is working…I am not sure, it seems a little better, but the only thing I have been doing is posting your requests. I will let you know. All processes killed ========== SERVICES/DRIVERS ========== ========== OTL ========== Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\HPPQVideo deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Yahoo! Pager deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1}\ not found. File oft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab not found. Starting removal of ActiveX control Microsoft XML Parser for Java Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Microsoft XML Parser for Java\DownloadInformation\\INF . Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Microsoft XML Parser for Java\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\Microsoft XML Parser for Java\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{57f06c14-aca0-11de-b824-0014a43373e3}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{57f06c14-aca0-11de-b824-0014a43373e3}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{57f06c14-aca0-11de-b824-0014a43373e3}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{57f06c14-aca0-11de-b824-0014a43373e3}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{57f06c14-aca0-11de-b824-0014a43373e3}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{57f06c14-aca0-11de-b824-0014a43373e3}\ not found. File C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe win32.dll.vbs not found. ========== FILES ========== C:\WINDOWS\System32\Autorun.ini moved successfully. File\Folder C:\Win32.dll.vbs not found. ========== COMMANDS ========== [EMPTYTEMP] User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 295046 bytes User: All Users User: NetworkService ->Temp folder emptied: 420006 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 32902 bytes User: Bonita Davenport ->Temp folder emptied: 186803858 bytes ->Temporary Internet Files folder emptied: 727166985 bytes ->Flash cache emptied: 21728 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 19569 bytes %systemroot%\System32 .tmp files removed: 2577 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 8401198 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 142230670 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes RecycleBin emptied: 10522994 bytes Total Files Cleaned = 1,026.00 mb [EMPTYFLASH] User: Default User User: All Users User: NetworkService User: LocalService User: Bonita Davenport ->Flash cache emptied: 0 bytes Total Flash Files Cleaned = 0.00 mb OTL by OldTimer - Version 3.2.29.1 log created on 09302011_165937 Files\Folders moved on Reboot… File\Folder C:\Documents and Settings\Bonita Davenport\Local Settings\Temp\~DFB0F4.tmp not found! File\Folder C:\Documents and Settings\Bonita Davenport\Local Settings\Temp\~DFB0FC.tmp not found! File\Folder C:\Documents and Settings\Bonita Davenport\Local Settings\Temp\~DFB16F.tmp not found! File\Folder C:\Documents and Settings\Bonita Davenport\Local Settings\Temp\~DFB177.tmp not found! C:\Documents and Settings\Bonita Davenport\Local Settings\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully. C:\Documents and Settings\Bonita Davenport\Local Settings\Temporary Internet Files\Content.IE5\S9MJCP27\like[1].htm moved successfully. C:\Documents and Settings\Bonita Davenport\Local Settings\Temporary Internet Files\Content.IE5\UJMVIX2V\iframe[1].htm moved successfully. C:\Documents and Settings\Bonita Davenport\Local Settings\Temporary Internet Files\Content.IE5\F3533TOW\index[1].htm moved successfully. C:\WINDOWS\temp\MpCmdRun.log moved successfully. File\Folder C:\WINDOWS\temp\TMP00000002ED858490CE756F24 not found! Registry entries deleted on Reboot…
Hello popracer,

One of your infections likely came from a flash drive…


Please download Flash_Disinfector.exe by sUBs and save it to your desktop.
  • Double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.
  • The utility may ask you to insert your flash drive and/or other removable drives. Please do so and allow the utility to clean up those drives as well.
  • Hold down the Shift key when inserting the drive until Windows detects it to keep autorun.inf from executing if it is present.
  • Wait until it has finished scanning and then exit the program.
  • Reboot your computer when done.
Note: As part of its routine, Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive that was plugged in when you ran it. Do not delete this folder…it will help protect your drives from future infection by keeping the autorun file from being installed on the root drive and running other malicious files.


Next, time to sweep for leftovers…

Scan For Malware:

Download and save to your desktop Malwarebytes Anti-Malware

Double Click mbam-setup.exe to install the application.

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately.




Do An Online Scan For Viruses:

Note: It is recommended to disable on-board anti-virus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your anti-virus along with your anti-spyware programs.

  • Hold down Control and click on the following link to open ESET OnlineScan in a new window. ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as MyEsetScan. Include the contents of this report in your next reply.
  • Push the Back button.
  • Push Finish
In your next reply please post the logs created by Malwarebytes and the ESET Online Scan.
OK here are the logs: Malwarebytes' Anti-Malware 1.51.2.1300 www.malwarebytes.org Database version: 7870 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 10/4/2011 6:46:33 PM mbam-log-2011-10-04 (18-46-32).txt Scan type: Quick scan Objects scanned: 156738 Time elapsed: 9 minute(s), 11 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) The Eset scan said that it did not find any threats but did not print a log
Hello poporacer.

Your machine appears to be ALL CLEAN :)

Lets cleanup our tools now…


From your desktop, please delete

  • logs that we created
  • MBR.dat
  • MBR.zip
  • aswMBR.exe

Create a new restore point
  • You must be logged on to an administrator account
  • Go to Start - All Programs - Accessories - System Tools - System Restore.
  • Click Create a restore point, and then click Next.
  • In the text box labeled Restore Point Description, type a name for this restore point
  • click create


Remove old restore points

  • Go to Start - All Programs - Accessories - system tools.
  • Launch the Disk Cleanup tool and let it run.
  • When it finishes a box with tabs will appear, select the more options tab.
  • On this tab you will find a section for System Restore.
  • If you press the Clean Up button for that section, Windows will delete all restore points except for the most recent one.


Open OTL then click the Clean Up button. You may get prompted by your firewall that OTL wants to contact the internet - allow this. A cleanup.txt will be downloaded, a message dialog will ask you if you want to proceed with the cleanup process, click Yes. This will do some clean up tasks and delete some of the tools you have downloaded plus itself.

I suggest you keep MBAM. Keep it updated and use it regularly.
ESET online scan can be removed via add/remove programs.


Some recomendations to remain malware-free:

Your version of Adobe Reader is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. Please follow these steps to remove older version Adobe components and update:

  • Download the latest version of Adobe Reader Version X. and save it to your desktop.
  • Uncheck the "Free McAfee Security plan Plus" option or any other Toolbar you are offered.
  • Click the download button at the bottom.
  • If you use Internet Explorer and do not wish to install the ActiveX element, simply click on the "click here" to download link on the next page.
  • Remove all older version of Adobe Reader: Go to Add/remove and uninstall all versions of Adobe Reader, Acrobat Reader and Adobe Acrobat.
  • If you are unsure of how to use Add or Remove Programs, the please see this tutorial: How To Remove An Installed Program From Your Computer
  • Then from your desktop double-click on Adobe Reader to install the newest version.
  • If using Windows Vista and the installer refuses to launch due to insufficient user permissions, then Run As Administrator.
  • When the "Adobe Setup - Welcome" window opens, click the Install > button.
  • If offered to install a Toolbar, just uncheck the box before continuing unless you want it.
  • Once the installation is finished, open Adobe Reader and accept the warranty if prompted.
  • Click on Help and select Check for Updates.
  • A window will open and Adobe will check for Updates. If any updates are found to be available click on Download.
  • Once the update is downloaded you will get a system notification telling you so. Click on the popup to restore the window.
  • In the window that opens click Install.
  • Once the update is done click Close.
  • Your Adobe Reader is updated now.

Make your Internet Explorer more secure - This can be done by following these simple instructions:

  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
  • Next press the Apply button and then the OK to exit the Internet Properties page.

Update your AntiVirus Software - It is imperative that you update your Antivirus software at least once a week
(Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.


Use a Firewall - I can not stress how important it is that you use a Firewall on your computer.
Without a firewall your computer is succeptible to being hacked and taken over.
I am very serious about this and see it happen almost every day with my clients.
Simply using a Firewall in its default configuration can lower your risk greatly.


WOT , Web of Trust, As 'Googling' is such an integral part of internet life, this free browser add on warns you about risky websites that try to scam visitors, deliver malware or send spam. It is especially helpful when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
Green to go
Yellow for caution
Red to stop
WOT has an addon available for both Firefox and IE.


Please download JavaRa and unzip it to its own folder
  • Run JavaRa.exe (double-click for XP/right-click and Run as Administrator for Vista or Windows 7), pick the language of your choice and click "Select".
  • Then click "Remove Older Versions".
  • Accept any prompts.
  • Open JavaRa.exe (double-click for XP/right-click and Run as Administrator for Vista or Windows 7) again and select "Search For Updates".
  • Select "Update Using Sun Java's Website".
  • Then click "Search" and click on the "Open Webpage" button.
  • Download and install the latest Java Runtime Environment (JRE) version for your computer.
Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly.
This will ensure your computer has always the latest security updates available installed on your computer.
If there are new updates to install, install them immediately, reboot your computer, and revisit the site
until there are no more critical updates.

Only run one Anti-Virus and Firewall program.

I would suggest you read:
PC Safety and Security–What Do I Need?
How to Prevent Malware

Thanks for all your help. One concern I have is you identified a virus common to flash drives. I transfer files with a flash drive. Should I send logs of my other computers or will the virus scanners I used catch them?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI