This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Desktop runs slow [Closed]

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

:huh: It seems as if something is causing everything to run slow. Anyones help or guidance would be appreciated. jp

OTL logfile created on: 1/1/2012 10:50:03 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:Documents and SettingsDadDesktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1015.00 Mb Total Physical Memory | 465.89 Mb Available Physical Memory | 45.90% Memory free
2.40 Gb Paging File | 1.89 Gb Available in Paging File | 78.59% Paging File free
Paging file location(s): C:pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:WINDOWS | %ProgramFiles% = C:Program Files
Drive C: | 74.50 Gb Total Space | 17.19 Gb Free Space | 23.07% Space Free | Partition Type: NTFS
Drive D: | 465.75 Gb Total Space | 312.53 Gb Free Space | 67.10% Space Free | Partition Type: NTFS

Computer Name: DESKTOP | User Name: Dad | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:Documents and SettingsDadDesktopOTL.exe (OldTimer Tools)
PRC - C:Program FilesMediaMallMediaMallServer.exe (MediaMall Technologies, Inc.)
PRC - C:Program FilesMediaMallPlayOn.exe (MediaMall Technologies, Inc.)
PRC - C:Program FilesDivXDivX UpdateDivXUpdate.exe ()
PRC - C:Program FilesSymantecSymantec Endpoint ProtectionSmc.exe (Symantec Corporation)
PRC - C:Program FilesSymantecSymantec Endpoint ProtectionSmcGui.exe (Symantec Corporation)
PRC - C:Program FilesSymantecSymantec Endpoint ProtectionRtvscan.exe (Symantec Corporation)
PRC - C:Program FilesCommon FilesIntuitUpdate ServiceIntuitUpdateService.exe (Intuit Inc.)
PRC - C:Program FilesCommon FilesSymantec SharedccApp.exe (Symantec Corporation)
PRC - C:Program FilesCommon FilesSymantec SharedccSvcHst.exe (Symantec Corporation)
PRC - C:WINDOWSsystem32logon.scr (Microsoft Corporation)
PRC - C:WINDOWSsystem32rdpclip.exe (Microsoft Corporation)
PRC - C:WINDOWSexplorer.exe (Microsoft Corporation)
PRC - C:WINDOWSsystem32HPZipm12.exe (HP)
PRC - C:Program FilesCommon FilesAheadLibNMBgMonitor.exe (Nero AG)
PRC - C:Program FilesNeroNero PhotoShow 4dataXtrasmssysmgr.exe (Nero AG / Nero Inc.)


========== Modules (No Company Name) ==========

MOD - C:WINDOWSassemblyNativeImages_v2.0.50727_32System.Management90b90e700e59d73
d6d692cf74e1ba16eSystem.Management.ni.dll ()
MOD - C:WINDOWSassemblyNativeImages_v2.0.50727_32CustomMarshalers3e6deccf191ab943
d3a0812a38ab5c97CustomMarshalers.ni.dll ()
MOD - C:WINDOWSassemblyNativeImages_v2.0.50727_32System.ServiceProce#abef85f2fb8b
a830eda73e2d12e8d41eSystem.ServiceProcess.ni.dll ()
MOD - C:WINDOWSassemblyNativeImages_v2.0.50727_32System.Configurationbce0720436dc
6cb76006377f295ea365System.Configuration.ni.dll ()
MOD - C:WINDOWSassemblyNativeImages_v2.0.50727_32System.Xml70cacc44f0b4257f6037ed
a7a59a0aebSystem.Xml.ni.dll ()
MOD - C:WINDOWSassemblyNativeImages_v2.0.50727_32System.Windows.Forms71a2ae9ad561
a62181cbd9fb11e9de7aSystem.Windows.Forms.ni.dll ()
MOD - C:WINDOWSassemblyNativeImages_v2.0.50727_32System.Drawingc10bea3c4bb7ef6546
51141bf9419090System.Drawing.ni.dll ()
MOD - C:WINDOWSassemblyNativeImages_v2.0.50727_32Systemaf39f6e644af02873b9bae319f
2bfb13System.ni.dll ()
MOD - C:WINDOWSassemblyNativeImages_v2.0.50727_32mscorlibca87ba84221991839abbe7d4
bc9c6721mscorlib.ni.dll ()
MOD - C:WINDOWSassemblyGAC_MSILSystem.Xml2.0.0.0__b77a5c561934e089System.Xml.dll ()
MOD - C:WINDOWSassemblyGAC_MSILSystem2.0.0.0__b77a5c561934e089System.dll ()
MOD - C:WINDOWSassemblyGAC_32System.Data2.0.0.0__b77a5c561934e089System.Data.dll ()
MOD - C:WINDOWSassemblyGAC_MSILSystem.Configuration2.0.0.0__b03f5f7f11d50a3aSyst
em.Configuration.dll ()
MOD - C:WINDOWSassemblyGAC_MSILSystem.Drawing2.0.0.0__b03f5f7f11d50a3aSystem.Dra
wing.dll ()
MOD - C:WINDOWSassemblyGAC_MSILSystem.Runtime.Remoting2.0.0.0__b77a5c561934e089S
ystem.Runtime.Remoting.dll ()
MOD - C:WINDOWSassemblyGAC_32System.EnterpriseServices2.0.0.0__b03f5f7f11d50a3aS
ystem.EnterpriseServices.dll ()
MOD - C:WINDOWSassemblyGAC_32System.Transactions2.0.0.0__b77a5c561934e089System.
Transactions.dll ()
MOD - C:WINDOWSassemblyGAC_MSILSystem.ServiceProcess2.0.0.0__b03f5f7f11d50a3aSys
tem.ServiceProcess.dll ()
MOD - C:WINDOWSassemblyGAC_32CustomMarshalers2.0.0.0__b03f5f7f11d50a3aCustomMars
halers.dll ()
MOD - C:WINDOWSassemblyGAC_MSILSystem.Windows.Forms2.0.0.0__b77a5c561934e089Syst
em.Windows.Forms.dll ()
MOD - C:Program FilesCommon FilesAppleApple Application Supportzlib1.dll ()
MOD - C:Program FilesCommon FilesAppleApple Application Supportlibxml2.dll ()
MOD - C:Program FilesDivXDivX UpdateDivXUpdateCheck.dll ()
MOD - C:Program FilesDivXDivX UpdateDivXUpdate.exe ()
MOD - C:WINDOWSassemblyGAC_32System.Data.SQLite1.0.61.0__db937bc2d44ff139System.
Data.SQLite.dll ()
MOD - C:WINDOWSassemblyGAC_MSILlog4net1.2.10.0__1b44e1d426115821log4net.dll ()
MOD - C:WINDOWSassemblyGAC_MSILIntuit.Spc.Map.WindowsFirewallUtilities5.0.136.0__
7ce6deabcb36a8eaIntuit.Spc.Map.WindowsFirewallUtilities.dll ()
MOD - C:WINDOWSassemblyGAC_MSILIntuit.Spc.Map.Reporter5.0.136.0__7ce6deabcb36a8ea
Intuit.Spc.Map.Reporter.dll ()
MOD - C:WINDOWSassemblyGAC_MSILIntuit.Spc.Esd.WinClient.Application.UpdateServiceP
lugin3.1.31.0__540d4816ead86321Intuit.Spc.Esd.WinClient.Application.UpdateServi
cePlugin.dll ()
MOD - C:WINDOWSassemblyGAC_MSILIntuit.Spc.Esd.WinClient.Api.Net3.1.31.0__540d4816
ead86321Intuit.Spc.Esd.WinClient.Api.Net.dll ()
MOD - C:WINDOWSassemblyGAC_MSILIntuit.Spc.Esd.WinClient.Application.UpdateService
1.0.0.0__540d4816ead86321Intuit.Spc.Esd.WinClient.Application.UpdateService.dll ()
MOD - C:WINDOWSassemblyGAC_MSILIntuit.Spc.Esd.WinClient.Ipc.Remoting.UpdateService
Worker3.1.31.0__540d4816ead86321Intuit.Spc.Esd.WinClient.Ipc.Remoting.UpdateSer
viceWorker.dll ()
MOD - C:WINDOWSassemblyGAC_MSILIntuit.Spc.Esd.WinClient.Application.UpdateService.
PluginContract1.0.0.0__540d4816ead86321Intuit.Spc.Esd.WinClient.Application.Upd
ateService.PluginContract.dll ()
MOD - C:WINDOWSassemblyGAC_MSILIntuit.Spc.Esd.Core3.1.26.0__540d4816ead86321Intu
it.Spc.Esd.Core.dll ()
MOD - C:WINDOWSassemblyGAC_MSILIntuit.Spc.Esd.Client.BusinessLogic3.1.31.0__540d4
816ead86321Intuit.Spc.Esd.Client.BusinessLogic.dll ()
MOD - C:WINDOWSassemblyGAC_MSILIntuit.Spc.Esd.Client.DataAccess3.1.31.0__540d4816
ead86321Intuit.Spc.Esd.Client.DataAccess.dll ()
MOD - C:WINDOWSassemblyGAC_MSILIntuit.Spc.Esd.Client.Common3.1.31.0__540d4816ead8
6321Intuit.Spc.Esd.Client.Common.dll ()
MOD - C:WINDOWSsystem32tsd32.dll ()
MOD - C:Program FilesAdobeAcrobat 5.0Distillradistres.dll ()
MOD - C:Program FilesAdobeAcrobat 5.0AcrobatActiveXAcroIEHelper.ocx ()


========== Win32 Services (SafeList) ==========

SRV - (gusvc) – File not found
SRV - (MediaMall Server) – C:Program FilesMediaMallMediaMallServer.exe (MediaMall Technologies, Inc.)
SRV - (SNAC) – C:Program FilesSymantecSymantec Endpoint ProtectionSNAC.EXE (Symantec Corporation)
SRV - (SmcService) – C:Program FilesSymantecSymantec Endpoint ProtectionSmc.exe (Symantec Corporation)
SRV - (Symantec AntiVirus) – C:Program FilesSymantecSymantec Endpoint ProtectionRtvscan.exe (Symantec Corporation)
SRV - (LiveUpdate) – C:Program FilesSymantecLiveUpdateLuComServer_3_3.EXE (Symantec Corporation)
SRV - (IntuitUpdateService) – C:Program FilesCommon FilesIntuitUpdate ServiceIntuitUpdateService.exe (Intuit Inc.)
SRV - (ccSetMgr) – C:Program FilesCommon FilesSymantec SharedccSvcHst.exe (Symantec Corporation)
SRV - (ccEvtMgr) – C:Program FilesCommon FilesSymantec SharedccSvcHst.exe (Symantec Corporation)
SRV - (Pml Driver HPZ12) – C:WINDOWSsystem32HPZipm12.exe (HP)
SRV - (NSCTOP) – C:Program FilesSSCNscTop.exe (Symantec Corporation)


========== Driver Services (SafeList) ==========

DRV - (eeCtrl) – C:Program FilesCommon FilesSymantec SharedEENGINEeeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:Program FilesCommon FilesSymantec SharedEENGINEEraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (NAVEX15) – C:Program FilesCommon FilesSymantec SharedVirusDefs20111230.025NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:Program FilesCommon FilesSymantec SharedVirusDefs20111230.025NAVENG.SYS (Symantec Corporation)
DRV - (WpsHelper) – C:WINDOWSsystem32driverswpshelper.sys (Symantec Corporation)
DRV - (busenum) – C:WINDOWSsystem32driversbusenum.sys (Windows ® Win 7 DDK provider)
DRV - (SymEvent) – C:WINDOWSsystem32driversSYMEVENT.SYS (Symantec Corporation)
DRV - (SysPlant) – C:WINDOWSSYSTEM32DriversSysPlant.sys (Symantec Corporation)
DRV - (WPS) – C:WINDOWSsystem32driversWPSDRVnt.sys (Symantec Corporation)
DRV - (COH_Mon) – C:WINDOWSsystem32driversCOH_Mon.sys (Symantec Corporation)
DRV - (SRTSPL) – C:WINDOWSsystem32driverssrtspl.sys (Symantec Corporation)
DRV - (SRTSP) – C:WINDOWSsystem32driverssrtsp.sys (Symantec Corporation)
DRV - (SRTSPX) – C:WINDOWSsystem32driverssrtspx.sys (Symantec Corporation)
DRV - (Teefer2) – C:WINDOWSsystem32driversTeefer2.sys (Symantec Corporation)
DRV - (msvad_simple) – C:WINDOWSsystem32driverspovrtdev.sys (MediaMall Technologies, Inc.)
DRV - (SPBBCDrv) – C:Program FilesCommon FilesSymantec SharedSPBBCSPBBCDrv.sys (Symantec Corporation)
DRV - (SYMTDI) – C:WINDOWSSystem32DriversSYMTDI.SYS (Symantec Corporation)
DRV - (SYMREDRV) – C:WINDOWSSystem32DriversSYMREDRV.SYS (Symantec Corporation)
DRV - (BVRPMPR5) – C:WINDOWSsystem32driversBVRPMPR5.SYS (Avanquest Software)
DRV - (m4cxw2k3) – C:WINDOWSsystem32driversm4cxw2k3.sys (Marvell)
DRV - (SkLaggProtocol) – C:WINDOWSsystem32driversyk51x32l.sys (Marvell)
DRV - (SkVlanProtocol) – C:WINDOWSsystem32driversyk51x32v.sys (Marvell)
DRV - (senfilt) – C:WINDOWSsystem32driverssenfilt.sys (Creative Technology Ltd.)
DRV - (BCMModem) – C:WINDOWSsystem32driversBCMSM.sys (Broadcom Corporation)
DRV - (bcm4sbxp) – C:WINDOWSsystem32driversbcm4sbxp.sys (Broadcom Corporation)
DRV - (PfModNT) – C:WINDOWSsystem32driversPFMODNT.SYS (Creative Technology Ltd.)
DRV - (OMCI) – C:WINDOWSSYSTEM32DRIVERSOMCI.SYS (Dell Computer Corporation)
DRV - (tgiul50) – C:WINDOWSsystem32driverstgiulnt5.sys (Trident Microsystems Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCUSOFTWAREMicrosoftInternet ExplorerMain,Start Page = http://www.google.com/
IE - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings: "ProxyEnable" = 0
IE - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings: "ProxyOverride" = *.local

FF - [removed]/FlashPlayer: C:WINDOWSsystem32MacromedFlashNPSWF32.dll ()
FF - [removed]/iTunes,version=: File not found
FF - [removed]/iTunes,version=1.0: C:Program FilesiTunesMozilla Pluginsnpitunes.dll ()
FF - [removed]/DivX Browser Plugin,version=1.0.0: C:Program FilesDivXDivX Plus Web Playernpdivx32.dll (DivX, LLC)
FF - [removed]/DivX Player Plugin,version=1.0.0: C:Program FilesDivXDivX PlayernpDivxPlayerPlugin.dll File not found
FF - [removed]/DivX VOD Helper,version=1.0.0: C:Program FilesDivXDivX OVS Helpernpovshelper.dll (DivX, LLC.)
FF - [removed]/GoogleEarthPlugin: C:Program FilesGoogleGoogle Earthpluginnpgeplugin.dll (Google)
FF - [removed]/NpCtrl,version=1.0: C:Program FilesMicrosoft Silverlight5.0.61118.0npctrl.dll ( Microsoft Corporation)
FF - [removed]/WPF,version=3.5: C:WINDOWSMicrosoft.NETFrameworkv3.5Windows Presentation FoundationNPWPF.dll (Microsoft Corporation)
FF - [removed]/Google Updater;version=14: C:Program FilesGoogleGoogle Updater2.4.2432.1652npCIDetect14.dll (Google)
FF - [removed]/Google Update;version=3: C:Program FilesGoogleUpdate1.3.21.79npGoogleUpdate3.dll (Google Inc.)
FF - [removed]/Google Update;version=9: C:Program FilesGoogleUpdate1.3.21.79npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINEsoftwaremozillaFirefoxExtensions{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:Program FilesDivXDivX Plus Web PlayerfirefoxDivXHTML5 [2011/12/18 11:01:46 | 000,000,000 | —D | M]


========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chr
o
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:Program FilesGoogleChromeApplication16.0.912.63ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:Program FilesGoogleChromeApplication16.0.912.63pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:Program FilesGoogleChromeApplication16.0.912.63gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:WINDOWSsystem32MacromedFlashNPSWF32.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:Program FilesAdobeAcrobat 5.0AcrobatBrowsernppdf32.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:Program FilesQuickTimepluginsnpqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:Program FilesQuickTimepluginsnpqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:Program FilesQuickTimepluginsnpqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:Program FilesQuickTimepluginsnpqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:Program FilesQuickTimepluginsnpqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:Program FilesQuickTimepluginsnpqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:Program FilesQuickTimepluginsnpqtplugin7.dll
CHR - plugin: Microsoftu00AE DRM (Enabled) = C:Program FilesWindows Media Playernpdrmv2.dll
CHR - plugin: Microsoftu00AE DRM (Enabled) = C:Program FilesWindows Media Playernpwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:Program FilesWindows Media Playernpdsplay.dll
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:Program FilesDivXDivX OVS Helpernpovshelper.dll
CHR - plugin: DivX Plus Web Player (Enabled) = C:Program FilesDivXDivX Plus Web Playernpdivx32.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:Program FilesGoogleGoogle Earthpluginnpgeplugin.dll
CHR - plugin: Google Updater (Enabled) = C:Program FilesGoogleGoogle Updater2.4.2432.1652npCIDetect14.dll
CHR - plugin: Google Update (Enabled) = C:Program FilesGoogleUpdate1.3.21.79npGoogleUpdate3.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:Program FilesiTunesMozilla Pluginsnpitunes.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:WINDOWSMicrosoft.NETFrameworkv3.5Windows Presentation FoundationNPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:Documents and SettingsDadLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsblpcfgokakmgnkcojhhkbfbldkacnbeo4.2_0
CHR - Extension: Google Search = C:Documents and SettingsDadLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionscoobgpohoikkiipiblmjeljniedjpjpf\0.0.0.14_0
CHR - Extension: DivX Plus Web Player HTML5 u003Cvideou003E = C:Documents and SettingsDadLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsnneajnkjbffgblleaoojgaacokifdkhm2.1.2.145_0
CHR - Extension: Gmail = C:Documents and SettingsDadLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionspjkljhegncpnkpknbcohdijeoejaedia6.1.3_0

O1 HOSTS File: ([2002/09/03 13:39:21 | 000,000,734 | —- | M]) - C:WINDOWSsystem32driversetchosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesAdobeAcrobat 5.0AcrobatActiveXAcroIEHelper.ocx ()
O2 - BHO: (DivX Plus Web Player HTML5 ) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:Program FilesDivXDivX Plus Web PlayerieDivXHTML5DivXHTML5.dll (DivX, LLC)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:Program FilesGoogleGoogleToolbarNotifier5.7.7018.1622swg.dll (Google Inc.)
O4 - HKLM..Run: [] File not found
O4 - HKLM..Run: [APSDaemon] C:Program FilesCommon FilesAppleApple Application SupportAPSDaemon.exe (Apple Inc.)
O4 - HKLM..Run: [ccApp] C:Program FilesCommon FilesSymantec SharedccApp.exe (Symantec Corporation)
O4 - HKLM..Run: [DivXUpdate] C:Program FilesDivXDivX UpdateDivXUpdate.exe ()
O4 - HKLM..Run: [NeroFilterCheck] C:Program FilesCommon FilesAheadLibNeroCheck.exe (Nero AG)
O4 - HKLM..Run: [NWEReboot] File not found
O4 - HKCU..Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:Program FilesCommon FilesAheadLibNMBgMonitor.exe (Nero AG)
O4 - HKCU..Run: [Nero PhotoShow Media Manager] C:Program FilesNeroNero PhotoShow 4dataXtrasmssysmgr.exe (Nero AG / Nero Inc.)
O4 - HKCU..Run: [PlayOn] C:Program FilesMediaMallPlayOn.exe (MediaMall Technologies, Inc.)
O4 - Startup: C:Documents and SettingsAll UsersStart MenuProgramsStartupD-Link Media Server.lnk = C:Program FilesD-Link Media ServerMediaGUI.exe (D-Link systems Inc.)
O6 - HKLMSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: HonorAutoRunSetting = 1
O7 - HKCUSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoDriveTypeAutoRun = 145
O10 - NameSpace_Catalog5Catalog_Entries\000000000004 [] - C:Program FilesBonjourmdnsNSP.dll (Apple Inc.)
O12 - Plugin for: .spop - C:Program FilesInternet ExplorerPLUGINSNPDocBox.dll (Intertrust Technologies, Inc.)
O15 - HKCU..Trusted Domains: intuit.com ([ttlc] https in Trusted sites)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/C/0…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windowsupd…b?1204231653421 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1204231708453 (MUWebControl Class)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: DirectAnimation Java Classes file://C:WINDOWSJavaclassesdajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:WINDOWSJavaclassesxmldso.cab (Reg Error: Key error.)
O17 - HKLMSystemCCSServicesTcpipParameters: DhcpNameServer = [removed]
O17 - HKLMSystemCCSServicesTcpipParametersInterfaces{A929437A-506B-49E5-8813-9E9D8ACFF279}: DhcpNameServer = [removed]
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:WINDOWSexplorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:WINDOWSsystem32userinit.exe) -C:WINDOWSsystem32userinit.exe (Microsoft Corporation)
O20 - WinlogonNotifyigfxcui: DllName - (igfxsrvc.dll) - C:WINDOWSSystem32igfxsrvc.dll (Intel Corporation)
O20 - WinlogonNotifyNavLogon: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O24 - Desktop WallPaper: C:WINDOWSWebWallpaperBliss.bmp
O24 - Desktop BackupWallPaper: C:WINDOWSWebWallpaperBliss.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/02/28 14:33:03 | 000,000,000 | —- | M] () - C:AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM..comfile [open] – "%1" %*
O35 - HKLM..exefile [open] – "%1" %*
O37 - HKLM…com [@ = comfile] – "%1" %*
O37 - HKLM…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.l3acm - C:WINDOWSsystem32l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:WINDOWSSystem32sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:WINDOWSSystem32tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:WINDOWSSystem32iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:WINDOWSSystem32DivX.dll (DivX, Inc.)
Drivers32: vidc.iv31 - C:WINDOWSSystem32ir32_32.dll ()
Drivers32: vidc.iv32 - C:WINDOWSSystem32ir32_32.dll ()
Drivers32: vidc.LEAD - LCODCCMP.DLL File not found
Drivers32: vidc.yv12 - C:WINDOWSSystem32DivX.dll (DivX, Inc.)
Drivers32: wave - C:WINDOWSSystem32serwvdrv.dll (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/01/01 22:47:49 | 000,584,192 | —- | C] (OldTimer Tools) – C:Documents and SettingsDadDesktopOTL.exe
[2011/12/21 16:59:49 | 000,000,000 | —D | C] – C:Documents and SettingsAll UsersStart MenuProgramsMicrosoft Silverlight
[2011/12/21 16:57:23 | 000,000,000 | —D | C] – C:Program FilesMicrosoft Silverlight
[2011/12/21 16:57:18 | 000,000,000 | —D | C] – C:WINDOWSLastGood
[2011/12/21 16:57:15 | 000,023,920 | —- | C] (MediaMall Technologies, Inc.) – C:WINDOWSSystem32driverspovrtdev.sys
[2011/12/21 16:56:57 | 000,000,000 | —D | C] – C:Documents and SettingsLocalServiceApplication DataAdobe
[2011/12/21 16:56:36 | 000,000,000 | —D | C] – C:Documents and SettingsAll UsersStart MenuProgramsPlayOn
[2011/12/21 16:56:25 | 000,000,000 | —D | C] – C:Program FilesMediaMall
[2011/12/21 16:56:25 | 000,000,000 | —D | C] – C:Program FilesCommon FilesffdshowEx
[2011/12/21 16:54:58 | 000,000,000 | —D | C] – C:Documents and SettingsAll UsersApplication DataMediaMall
[2011/12/21 16:54:35 | 000,000,000 | —D | C] – C:WINDOWSDownloaded Installations
[2011/12/18 11:03:41 | 000,000,000 | —D | C] – C:Documents and SettingsDadApplication DataDDMSettings
[2011/12/17 15:48:09 | 000,000,000 | —D | C] – C:Documents and SettingsAll UsersStart MenuProgramsiTunes
[2011/12/17 15:45:13 | 000,000,000 | —D | C] – C:Program FilesiPod
[2011/12/17 15:44:53 | 000,000,000 | —D | C] – C:Program FilesiTunes
[2011/12/17 15:33:52 | 000,000,000 | —D | C] – C:Program FilesSafari
[2011/12/11 14:06:44 | 000,000,000 | —D | C] – C:Documents and SettingsAll UsersStart MenuProgramsQuickTime
[2011/12/11 13:57:07 | 000,000,000 | —D | C] – C:Documents and SettingsLocalServiceApplication DataApple Computer
[2011/12/11 13:56:04 | 000,000,000 | —D | C] – C:Program FilesBonjour
[5 C:WINDOWS*.tmp files -> C:WINDOWS*.tmp -> ]
[3 C:WINDOWSSystem32*.tmp files -> C:WINDOWSSystem32*.tmp -> ]
[1 C:Documents and SettingsDadLocal SettingsApplication Data*.tmp files -> C:Documents and SettingsDadLocal SettingsApplication Data*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/01/01 22:48:01 | 000,584,192 | —- | M] (OldTimer Tools) – C:Documents and SettingsDadDesktopOTL.exe
[2012/01/01 22:28:00 | 000,000,886 | —- | M] () – C:WINDOWStasksGoogleUpdateTaskMachineUA.job
[2012/01/01 19:28:00 | 000,000,882 | —- | M] () – C:WINDOWStasksGoogleUpdateTaskMachineCore.job
[2012/01/01 14:43:00 | 000,000,868 | —- | M] () – C:WINDOWStasksGoogle Software Updater.job
[2011/12/31 11:29:31 | 000,000,786 | —- | M] () – C:Documents and SettingsDadDesktopShortcut to Vixen.lnk
[2011/12/29 13:48:15 | 000,724,146 | —- | M] () – C:Documents and SettingsDadDesktopscan0001.jpg
[2011/12/29 09:57:01 | 000,000,284 | —- | M] () – C:WINDOWStasksAppleSoftwareUpdate.job
[2011/12/28 23:32:16 | 000,001,324 | —- | M] () – C:WINDOWSSystem32d3d9caps.dat
[2011/12/26 11:32:27 | 000,002,187 | —- | M] () – C:Documents and SettingsAll UsersDesktopSafari.lnk
[2011/12/22 16:11:35 | 000,000,664 | —- | M] () – C:Documents and SettingsDadLocal SettingsApplication Datad3d9caps.dat
[2011/12/21 17:03:41 | 000,000,047 | —- | M] () – C:WINDOWSMediaGUI.INI
[2011/12/21 16:56:37 | 000,001,800 | —- | M] () – C:Documents and SettingsAll UsersDesktopPlayOn.lnk
[2011/12/18 11:01:56 | 000,001,757 | —- | M] () – C:Documents and SettingsAll UsersDesktopDivX Plus Converter.lnk
[2011/12/18 11:01:56 | 000,001,463 | —- | M] () – C:Documents and SettingsDadDesktopDivX Movies.lnk
[2011/12/18 11:01:28 | 000,000,777 | —- | M] () – C:Documents and SettingsAll UsersDesktopDivX Plus Player.lnk
[2011/12/17 17:32:06 | 000,002,048 | –S- | M] () – C:WINDOWSbootstat.dat
[2011/12/17 15:56:11 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:WINDOWSSystem32FlashPlayerCPLApp.cpl
[2011/12/17 15:54:55 | 000,022,348 | -H– | M] () – C:WINDOWSSystem32mlfcache.dat
[2011/12/17 15:34:29 | 000,001,854 | —- | M] () – C:Documents and SettingsDadApplication DataMicrosoftInternet ExplorerQuick LaunchApple Safari.lnk
[2011/12/17 15:20:34 | 000,002,206 | —- | M] () – C:WINDOWSSystem32wpa.dbl
[2011/12/15 20:31:21 | 000,001,813 | —- | M] () – C:Documents and SettingsAll UsersDesktopGoogle Chrome.lnk
[2011/12/15 03:23:59 | 000,132,480 | —- | M] () – C:WINDOWSSystem32FNTCACHE.DAT
[2011/12/15 03:07:16 | 000,001,393 | —- | M] () – C:WINDOWSimsins.BAK
[2011/12/11 14:06:44 | 000,001,604 | —- | M] () – C:Documents and SettingsAll UsersDesktopQuickTime Player.lnk
[2011/12/07 16:27:14 | 000,000,116 | —- | M] () – C:WINDOWSNeroDigital.ini
[5 C:WINDOWS*.tmp files -> C:WINDOWS*.tmp -> ]
[3 C:WINDOWSSystem32*.tmp files -> C:WINDOWSSystem32*.tmp -> ]
[1 C:Documents and SettingsDadLocal SettingsApplication Data*.tmp files -> C:Documents and SettingsDadLocal SettingsApplication Data*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/12/31 11:29:31 | 000,000,786 | —- | C] () – C:Documents and SettingsDadDesktopShortcut to Vixen.lnk
[2011/12/29 13:48:15 | 000,724,146 | —- | C] () – C:Documents and SettingsDadDesktopscan0001.jpg
[2011/12/25 07:19:22 | 000,001,324 | —- | C] () – C:WINDOWSSystem32d3d9caps.dat
[2011/12/21 17:03:41 | 000,000,047 | —- | C] () – C:WINDOWSMediaGUI.INI
[2011/12/21 16:56:37 | 000,001,800 | —- | C] () – C:Documents and SettingsAll UsersDesktopPlayOn.lnk
[2011/12/18 11:01:28 | 000,000,777 | —- | C] () – C:Documents and SettingsAll UsersDesktopDivX Plus Player.lnk
[2011/12/17 15:54:55 | 000,022,348 | -H– | C] () – C:WINDOWSSystem32mlfcache.dat
[2011/12/17 15:34:29 | 000,002,193 | —- | C] () – C:Documents and SettingsAll UsersStart MenuProgramsSafari.lnk
[2011/12/17 15:34:29 | 000,002,187 | —- | C] () – C:Documents and SettingsAll UsersDesktopSafari.lnk
[2011/12/17 15:34:29 | 000,001,854 | —- | C] () – C:Documents and SettingsDadApplication DataMicrosoftInternet ExplorerQuick LaunchApple Safari.lnk
[2011/12/11 14:06:44 | 000,001,604 | —- | C] () – C:Documents and SettingsAll UsersDesktopQuickTime Player.lnk
[2011/08/04 17:17:58 | 000,000,664 | —- | C] () – C:Documents and SettingsDadLocal SettingsApplication Datad3d9caps.dat
[2011/07/24 08:44:58 | 000,008,192 | —- | C] () – C:Documents and SettingsNetworkServiceLocal SettingsApplication DataDCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/02/01 03:51:12 | 000,838,656 | —- | C] () – C:Documents and SettingsLocalServiceLocal SettingsApplication DataFontCache3.0.0.0.dat
[2010/02/07 14:42:09 | 000,000,214 | —- | C] () – C:WINDOWSHP_InstantSHareJPG.ini
[2010/02/07 14:41:25 | 000,000,217 | —- | C] () – C:WINDOWSHP_IZClosingDiscErrorPatch.ini
[2010/02/07 14:40:12 | 000,000,214 | —- | C] () – C:WINDOWSHP_48BitScanUpdatePatch.ini
[2010/02/07 14:33:42 | 000,000,221 | —- | C] () – C:WINDOWSHP_RedboxHprblog_HPSU.ini
[2009/10/26 20:30:52 | 000,000,000 | —- | C] () – C:WINDOWSVPC32.INI
[2008/05/25 08:10:10 | 000,000,151 | —- | C] () – C:WINDOWSPhotoSnapViewer.INI
[2008/03/08 12:12:07 | 000,000,116 | —- | C] () – C:WINDOWSNeroDigital.ini
[2008/02/28 23:02:35 | 000,000,126 | —- | C] () – C:Documents and SettingsDadLocal SettingsApplication Datafusioncache.dat
[2008/02/28 22:55:30 | 000,000,022 | —- | C] () – C:WINDOWSexchng.ini
[2008/02/28 22:55:29 | 000,000,611 | —- | C] () – C:WINDOWSODBC.INI
[2008/02/28 22:32:51 | 000,112,410 | —- | C] () – C:WINDOWShpoins07.dat
[2008/02/28 22:32:51 | 000,021,124 | —- | C] () – C:WINDOWShpomdl07.dat
[2008/02/28 22:31:26 | 000,077,824 | —- | C] () – C:WINDOWSSystem32adistres.dll
[2008/02/28 22:27:57 | 000,000,040 | —- | C] () – C:WINDOWSSystem32profile.dat
[2008/02/28 22:21:53 | 000,024,576 | —- | C] () – C:Documents and SettingsDadLocal SettingsApplication DataDCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/02/28 15:33:22 | 000,004,569 | —- | C] () – C:WINDOWSSystem32secupd.dat
[2008/02/28 15:02:29 | 000,006,550 | —- | C] () – C:WINDOWSjautoexp.dat
[2008/02/28 14:35:27 | 000,002,048 | –S- | C] () – C:WINDOWSbootstat.dat
[2008/02/28 14:30:08 | 000,021,640 | —- | C] () – C:WINDOWSSystem32emptyregdb.dat
[2008/02/28 06:22:02 | 000,004,346 | —- | C] () – C:WINDOWSODBCINST.INI
[2008/02/28 06:21:00 | 000,132,480 | —- | C] () – C:WINDOWSSystem32FNTCACHE.DAT
[2002/09/03 14:07:03 | 013,107,200 | —- | C] () – C:WINDOWSSystem32oembios.bin
[2002/09/03 14:07:00 | 000,004,594 | —- | C] () – C:WINDOWSSystem32oembios.dat
[2002/09/03 13:51:48 | 000,272,128 | —- | C] () – C:WINDOWSSystem32perfi009.dat
[2002/09/03 13:51:47 | 000,441,552 | —- | C] () – C:WINDOWSSystem32perfh009.dat
[2002/09/03 13:51:46 | 000,028,626 | —- | C] () – C:WINDOWSSystem32perfd009.dat
[2002/09/03 13:51:44 | 000,071,488 | —- | C] () – C:WINDOWSSystem32perfc009.dat
[2002/09/03 13:50:11 | 000,000,741 | —- | C] () – C:WINDOWSSystem32noise.dat
[2002/09/03 13:44:25 | 000,673,088 | —- | C] () – C:WINDOWSSystem32mlang.dat
[2002/09/03 13:44:11 | 000,046,258 | —- | C] () – C:WINDOWSSystem32mib.bin
[2002/09/03 13:37:19 | 000,218,003 | —- | C] () – C:WINDOWSSystem32dssec.dat
[2002/09/03 13:36:07 | 000,001,804 | —- | C] () – C:WINDOWSSystem32dcache.bin
[2001/07/06 08:30:00 | 000,003,399 | —- | C] () – C:WINDOWSSystem32hptcpmon.ini
[1996/11/16 17:00:00 | 000,047,104 | —- | C] () – C:WINDOWSSystem32WRKGADM.EXE
[1996/11/16 17:00:00 | 000,022,016 | —- | C] () – C:WINDOWSSystem32ODBCSTF.DLL
[1996/11/16 17:00:00 | 000,022,016 | —- | C] () – C:WINDOWSSystem32DOCOBJ.DLL
[1996/11/16 17:00:00 | 000,012,288 | —- | C] () – C:WINDOWSSystem32HLINKPRX.DLL

========== LOP Check ==========

[2012/01/01 04:46:50 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication DataMediaMall
[2011/06/12 11:18:43 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication Data{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010/01/29 23:28:45 | 000,000,000 | —D | M] – C:Documents and SettingsDadApplication DataBitZipper
[2011/07/24 08:17:08 | 000,000,000 | —D | M] – C:Documents and SettingsDadApplication Datacom.pandora.desktop.FB9956FD96E03239939108614098AD95535EE674.1
[2011/12/18 11:03:41 | 000,000,000 | —D | M] – C:Documents and SettingsDadApplication DataDDMSettings
[2008/02/28 22:30:17 | 000,000,000 | —D | M] – C:Documents and SettingsDadApplication DataInterTrust
[2008/02/28 23:26:47 | 000,000,000 | —D | M] – C:Documents and SettingsDadApplication DataSimple Star
[2011/10/29 00:23:58 | 000,000,000 | —D | M] – C:Documents and SettingsDadApplication DatauTorrent
[2010/01/28 16:46:51 | 000,000,000 | —D | M] – C:Documents and SettingsDadApplication DataVirtualStore

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%*.* >
[2008/02/28 14:33:03 | 000,000,000 | —- | M] () – C:AUTOEXEC.BAT
[2008/02/28 15:43:58 | 000,000,211 | RHS- | M] () – C:boot.ini
[2008/02/28 14:33:03 | 000,000,000 | —- | M] () – C:CONFIG.SYS
[2010/02/09 20:11:57 | 000,004,795 | -H– | M] () – C:ffastun.ffa
[2010/02/09 20:11:57 | 000,212,992 | -H– | M] () – C:ffastun.ffl
[2010/02/09 20:11:57 | 000,094,208 | -H– | M] () – C:ffastun.ffo
[2010/02/09 20:11:57 | 001,134,592 | -H– | M] () – C:ffastun0.ffx
[2008/02/28 14:33:03 | 000,000,000 | RHS- | M] () – C:IO.SYS
[2008/02/28 14:33:03 | 000,000,000 | RHS- | M] () – C:MSDOS.SYS
[2008/02/28 15:39:42 | 000,047,564 | RHS- | M] () – C:NTDETECT.COM
[2010/01/31 11:52:08 | 000,250,048 | RHS- | M] () – C:ntldr
[2011/12/17 17:31:44 | 1610,612,736 | -HS- | M] () – C:pagefile.sys
[2011/10/21 16:50:19 | 000,000,000 | —- | M] () – C:t1f0
[2008/02/28 22:21:29 | 000,010,134 | -H– | M] () – C:_NavCClt.Log

< %systemroot%Fonts*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:WINDOWSFontsGlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:WINDOWSFontsGlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:WINDOWSFontsGlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:WINDOWSFontsGlobalUserInterface.CompositeFont

< %systemroot%Fonts*.dll >
[2005/05/11 16:36:48 | 000,012,288 | —- | M] (Hewlett-Packard Co.) – C:WINDOWSFontsRandFont.dll

< %systemroot%Fonts*.ini >
[2008/02/28 14:32:40 | 000,000,067 | -HS- | M] () – C:WINDOWSFontsdesktop.ini

< %systemroot%Fonts*.ini2 >

< %systemroot%Fonts*.exe >

< %systemroot%system32spoolprtprocsw32x86*.* >
[2008/07/06 06:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:WINDOWSsystem32spoolprtprocsw32x86filterpipelineprintproc.dll
[2008/07/06 04:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:WINDOWSsystem32spoolprtprocsw32x86printfilterpipelinesvc.exe

< %systemroot%REPAIR*.bak1 >

< %systemroot%REPAIR*.ini >

< %systemroot%system32*.jpg >

< %systemroot%*.jpg >

< %systemroot%*.png >

< %systemroot%*.scr >
[2006/05/18 13:20:35 | 000,319,488 | —- | M] (Nero AG / Nero Inc.) – C:WINDOWSNero PhotoShow.scr
[5 C:WINDOWS*.tmp files -> C:WINDOWS*.tmp -> ]

< %systemroot%*._sy >

< %APPDATA%AdobeUpdate*.* >

< %ALLUSERSPROFILE%Favorites*.* >

< %APPDATA%Microsoft*.* >
[2010/01/28 21:44:54 | 000,001,538 | -H– | M] () – C:Documents and SettingsDadApplication DataMicrosoftLastFlashConfig.WFC

< %PROGRAMFILES%*.* >

< %APPDATA%Update*.* >

< %systemroot%*. /mp /s >

< %systemroot%System32config*.sav >
[2008/02/28 06:07:38 | 000,094,208 | —- | M] () – C:WINDOWSSystem32configdefault.sav
[2008/02/28 06:07:38 | 000,626,688 | —- | M] () – C:WINDOWSSystem32configsoftware.sav
[2008/02/28 06:07:38 | 000,413,696 | —- | M] () – C:WINDOWSSystem32configsystem.sav

< %PROGRAMFILES%bak. /s >

< %systemroot%system32bak. /s >

< %ALLUSERSPROFILE%Start Menu*.lnk /x >
[2010/01/31 12:08:36 | 000,000,272 | -HS- | M] () – C:Documents and SettingsAll UsersStart Menudesktop.ini

< %systemroot%system32configsystemprofile*.dat /x >

< %systemroot%*.config >

< %systemroot%system32*.db >

< %PROGRAMFILES%Internet Explorer*.dat >

< %APPDATA%MicrosoftInternet ExplorerQuick Launch*.lnk /x >
[2008/02/28 20:06:49 | 000,000,177 | -HS- | M] () – C:Documents and SettingsDadApplication DataMicrosoftInternet ExplorerQuick Launchdesktop.ini
[2008/02/28 14:38:16 | 000,000,079 | —- | M] () – C:Documents and SettingsDadApplication DataMicrosoftInternet ExplorerQuick LaunchShow Desktop.scf

< %USERPROFILE%Desktop*.exe >
[2012/01/01 22:48:01 | 000,584,192 | —- | M] (OldTimer Tools) – C:Documents and SettingsDadDesktopOTL.exe

< %PROGRAMFILES%Common Files*.* >

< %systemroot%*.src >

< %systemroot%install*.* >

< %systemroot%system32DLL*.* >

< %systemroot%system32HelpFiles*.* >

< %systemroot%system32rundll*.* >

< %systemroot%winn32*.* >

< %systemroot%Java*.* >

< %systemroot%system32test*.* >

< %systemroot%system32Rundll32*.* >

< %systemroot%AppPatchCustom*.* >

< HKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftWindowsWindowsUpdateAU >

< HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionWindowsUpdateAuto UpdateResultsInstall|LastSuccessTime /rs >
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionWindowsUpdateAuto UpdateResultsInstallLastSuccessTime: 2011-12-22 22:39:03

< >

< >

< End of report >

OTL Extras logfile created on: 1/1/2012 10:50:03 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:Documents and SettingsDadDesktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1015.00 Mb Total Physical Memory | 465.89 Mb Available Physical Memory | 45.90% Memory free
2.40 Gb Paging File | 1.89 Gb Available in Paging File | 78.59% Paging File free
Paging file location(s): C:pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:WINDOWS | %ProgramFiles% = C:Program Files
Drive C: | 74.50 Gb Total Space | 17.19 Gb Free Space | 23.07% Space Free | Partition Type: NTFS
Drive D: | 465.75 Gb Total Space | 312.53 Gb Free Space | 67.10% Space Free | Partition Type: NTFS

Computer Name: DESKTOP | User Name: Dad | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINESOFTWAREClasses]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = SafariHTML] – C:Program FilesSafariSafari.exe (Apple Inc.)

[HKEY_CURRENT_USERSOFTWAREClasses]
.html [@ = SafariHTML] – C:Program FilesSafariSafari.exe (Apple Inc.)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINESOFTWAREClassesshell[command]command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – "C:Program FilesMicrosoft OfficeOfficeWinword.exe" /n ()
http [open] – "C:Program FilesSafariSafari.exe" -url "%1" (Apple Inc.)
https [open] – "C:Program FilesSafariSafari.exe" -url "%1" (Apple Inc.)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%system32rundll32.exe %SystemRoot%system32shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:Program FilesVideoLANVLCvlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [find] – %SystemRoot%Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:Program FilesVideoLANVLCvlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 1
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoring]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringAhnlabAntiVirus]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringKasperskyAntiVirus]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringMcAfeeAntiVirus]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringMcAfeeFirewall]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringPandaAntiVirus]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringPandaFirewall]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringSophosAntiVirus]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringSymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringSymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringTinyFirewall]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringTrendAntiVirus]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringTrendFirewall]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionSystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSr]
"Start" = 0

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyDomainProfile]

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyDomainProfileGloballyOpenPortsList]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"3389:TCP" = 3389:TCP:*:Enabled:@xpsp2res.dll,-22009

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyStandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyStandardProfileGloballyOpenPortsList]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"3389:TCP" = 3389:TCP:*:Enabled:@xpsp2res.dll,-22009

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyDomainProfileAuthorizedApplicationsList]

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyStandardProfileAuthorizedApplicationsList]
"C:Program FilesHPDigital Imagingbinhpofxm08.exe" = C:Program FilesHPDigital Imagingbinhpofxm08.exe:*:Enabled:hpofxm08.exe – (Hewlett-Packard Co.)
"C:Program FilesHPDigital Imagingbinhposfx08.exe" = C:Program FilesHPDigital Imagingbinhposfx08.exe:*:Enabled:hposfx08.exe – (Hewlett-Packard Co.)
"C:Program FilesHPDigital Imagingbinhposid01.exe" = C:Program FilesHPDigital Imagingbinhposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Co.)
"C:Program FilesHPDigital ImagingbinhpqCopy.exe" = C:Program FilesHPDigital ImagingbinhpqCopy.exe:*:Enabled:hpqcopy.exe – (Hewlett-Packard Co.)
"C:Program FilesHPDigital Imagingbinhpfccopy.exe" = C:Program FilesHPDigital Imagingbinhpfccopy.exe:*:Enabled:hpfccopy.exe – (Hewlett-Packard)
"C:Program FilesHPDigital Imagingbinhpzwiz01.exe" = C:Program FilesHPDigital Imagingbinhpzwiz01.exe:*:Enabled:hpzwiz01.exe – (Hewlett-Packard Co.)
"C:Program FilesHPDigital ImagingUnloadHpqPhUnl.exe" = C:Program FilesHPDigital ImagingUnloadHpqPhUnl.exe:*:Enabled:hpqphunl.exe – ()
"C:Program FilesHPDigital ImagingUnloadHpqDIA.exe" = C:Program FilesHPDigital ImagingUnloadHpqDIA.exe:*:Enabled:hpqdia.exe – ( )
"C:Program FilesHPDigital Imagingbinhpoews01.exe" = C:Program FilesHPDigital Imagingbinhpoews01.exe:*:Enabled:hpoews01.exe – (Hewlett-Packard Co.)
"C:Program FilesD-Link Media ServerMediaGUI.exe" = C:Program FilesD-Link Media ServerMediaGUI.exe:*:Enabled:D-Link_MediaServerGUI – (D-Link systems Inc.)
"C:Program FilesD-Link Media ServerMediaServer.exe" = C:Program FilesD-Link Media ServerMediaServer.exe:*:Enabled:D-Link_MediaServer – (D-Link systems Inc.)
"C:WINDOWSsystem32MediaServerDumpLiveUpdateOLUpdate.exe" = C:WINDOWSsystem32MediaServerDumpLiveUpdateOLUpdate.exe:*:Enabled:Media Server LiveUpdate – ()
"C:Program FilesuTorrentuTorrent.exe" = C:Program FilesuTorrentuTorrent.exe:*:Enabled:µTorrent – ()
"C:Program FilesSymantecSymantec Endpoint ProtectionSmc.exe" = C:Program FilesSymantecSymantec Endpoint ProtectionSmc.exe:*:Enabled:SMC Service – (Symantec Corporation)
"C:Program FilesSymantecSymantec Endpoint ProtectionSNAC.EXE" = C:Program FilesSymantecSymantec Endpoint ProtectionSNAC.EXE:*:Enabled:SNAC Service – (Symantec Corporation)
"C:Program FilesCommon FilesSymantec SharedccApp.exe" = C:Program FilesCommon FilesSymantec SharedccApp.exe:*:Enabled:Symantec Email – (Symantec Corporation)
"C:Program FilesCommon FilesIntuitUpdate ServiceIntuitUpdateService.exe" = C:Program FilesCommon FilesIntuitUpdate ServiceIntuitUpdateService.exe:LocalSubNet:Disabled:Intuit Update Shared Downloads Server – (Intuit Inc.)
"C:WINDOWSsystem32dpvsetup.exe" = C:WINDOWSsystem32dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test – (Microsoft Corporation)
"C:Program FilesCommon FilesAppleApple Application SupportWebKit2WebProcess.exe" = C:Program FilesCommon FilesAppleApple Application SupportWebKit2WebProcess.exe:*:Enabled:WebKit – (Apple Inc.)
"C:Program FilesMediaMallMediaMallServer.exe" = C:Program FilesMediaMallMediaMallServer.exe:*:Enabled:MediaMall Server – (MediaMall Technologies, Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstall]
"{03B1B42B-F6DE-41d9-8CFF-DC44E895C7A7}" = PhotoGallery
"{05BDC796-3451-4F81-B91D-E98F7ADA76C2}" = TurboTax 2010 WinPerTaxSupport
"{0611BD4E-4FE4-4a62-B0C0-18A4CC463428}" = CP_Package_Variety1
"{09984AEC-6B9F-4ca7-B78D-CB44D4771DA3}" = Destinations
"{0B33B738-AD79-4E32-90C5-E67BFB10BBFF}" = AiO_Scan
"{0B99A52F-A87D-470B-BBDC-1FE4B7B1EA8A}" = PlayOn
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{172975EB-9465-4861-95B5-C7BB6D3DE62A}" = DocumentViewer
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{193DB24F-9A66-4896-8404-22D53EA89075}" = 1400_Help
"{1C139D7D-9FEA-468d-A9C8-2A6E3BDE564A}" = CP_Package_Variety3
"{1C220811-048F-4D60-B42E-B86027C57372}" = LightScribe [removed]
"{1E83D2D0-188B-4A4D-BEF7-72E370747AA3}" = D-Link Corporation Control Program
"{21DB3D90-D816-4092-A260-CA3F6B55A6DD}" = Sonic_PrimoSDK
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{23A7B376-BBEC-4e76-BBD7-0F155E70D74B}" = CP_Panorama1Config
"{266959FA-0AEE-41D0-A88E-F1EAC10A7C14}" = 1400
"{2CADCEAB-D5DA-44D6-B5FC-7DEE87AB3C0C}" = Unload
"{30C19FF2-7FBA-4d09-B9DE-1659977F64F6}" = TrayApp
"{32BDCCB8-9DC8-496d-9DB1-F77510775BDB}" = InstantShareDevices
"{343666E2-A059-48AC-AD67-230BF74E2DB2}" = Apple Application Support
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{36E47DA1-10E1-45d9-8B19-14D19607CDCF}" = CP_CalendarTemplates1
"{36FDBE6E-6684-462B-AE98-9A39A1B200CC}" = HP Product Assistant
"{3782EC09-4000-475E-8A59-9CABD6F03B4C}" = TurboTax 2010 WinPerFedFormset
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{4F2FCCCF-29F3-44B9-886F-6D16F8417522}" = TurboTax 2010 wrapper
"{52504CE6-E909-4113-B232-4AFEC6543A61}" = Broadcom 440x 10/100 Integrated Controller
"{53EE9E42-CECB-4C92-BF76-9CA65DAF8F1C}" = FullDPAppQFolder
"{54E3707F-808E-4fd4-95C9-15D1AB077E5D}" = NewCopy
"{56EE8B17-8274-418d-89AC-C057C5DB251E}" = RandMap
"{56F8AFC3-FA98-4ff1-9673-8A026CBF85BE}" = WebReg
"{5A01C58E-B0EC-49b9-AD71-7C0468688087}" = CP_Package_Basic1
"{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth
"{5B79CFD1-6845-4158-9D7D-6BE89DF2C135}" = HP PSC & OfficeJet 5.3.B
"{5F26311C-B135-4F7F-B11E-8E650F83651E}" = DeviceFunctionQFolder
"{66BA8C26-AFE4-4408-807B-43E76B57EF53}" = SkinsHP1
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{6BB6627C-694F-4FDC-A3E5-C7F4BED4C724}" = DocProc
"{7850A6D2-CBEA-4728-9877-F1BEDEA9F619}" = AiOSoftware
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7B63B2922B174135AFC0E1377DD81EC2}" =
"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
"{7C03270C-4FAB-4F5C-B10D-52FEDA190790}" = DocumentViewerQFolder
"{7C9B95B7-B598-4398-B30F-7F6827192E6C}" = ProductContext
"{7E27304E-BAA2-4d90-A34E-76641FAFABB4}" = CP_AtenaShokunin1Config
"{8153ED9A-C94A-426E-9880-5E6775C08B62}" = Apple Mobile Device Support
"{818ABC3C-635C-4651-8183-D0E9640B7DD1}" = HP Update
"{84B70C16-7032-41EE-965C-3C8D9D566CBB}" = Symantec Endpoint Protection
"{8867CEBD-E6C0-4C7A-83B3-9E45669A1033}" = Nero 7 Essentials
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics Driver
"{923A7F5A-1E8C-4FBE-8DF6-85940A60A79F}" = Readme
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{A195B13E-A5E3-4BAF-A995-7F70F445CD06}" = ScannerCopy
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A339200B-21F9-4F47-BE9B-0C23CC77A68D}" = YV12 QuickTime Codec
"{A525E00B-6609-442E-9DCD-64453C233E8D}" = TurboTax 2010 WinPerReleaseEngine
"{A5BB5365-EFB4-44c3-A7E2-EB59B7EFD23D}" = CueTour
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B4D279F1-4309-49cc-A4B5-3A0D2E59C7B5}" = PanoStandAlone
"{B7DBF6E8-0D17-4BE4-853B-ACD6EFBD4A1F}" = iTunes
"{B824B5C9-849F-4b9e-9EA7-6FD8CD8116DA}" = CP_Package_Variety2
"{B996AE66-10DB-4ac5-B151-E8B4BFBC42FC}" = BufferChm
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C506A18C-1469-4678-B094-F4EC9DAE6DB7}" = Scan
"{C510CA36-98D6-4F07-8AFF-81E7399A075B}" = 1400Trb
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE24344F-DFD8-40C8-8FD8-C9740B5F25AC}" = Fax
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D78653C3-A8FF-415F-92E6-D774E634FF2D}" = Dell ResourceCD
"{E3E3C2C5-B78F-560D-01C0-A9F11945D17B}" = Pandora
"{E3F90083-80D4-4b5a-87C7-E97E12F5516D}" = HPProductAssistant
"{EA103B64-C0E4-4C0E-A506-751590E1653D}" = SolutionCenter
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F2AF3E5D-9697-485C-A5AC-E2B9468C446A}" = Safari
"{F4C2E5F5-2970-45f4-ABD3-C180C4D961C4}" = Status
"{FE23D063-934D-4829-A0D8-00634CE79B4A}" = Adobe AIR
"Adobe Acrobat 5.0" = Adobe Acrobat 5.0
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"BCM V.92 56K Modem" = BCM V.92 56K Modem
"com.pandora.desktop.FB9956FD96E03239939108614098AD95535EE674.1" = Pandora
"DECCHECK" = Microsoft Windows XP Video Decoder Checkup Utility
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"DivX Setup" = DivX Setup
"D-Link Media Server_is1" = D-Link Media Server 1.09
"DVD Decrypter" = DVD Decrypter (Remove Only)
"DVD Shrink_is1" = DVD Shrink 3.2
"Google Chrome" = Google Chrome
"Google Updater" = Google Updater
"HP Document Viewer" = HP Document Viewer 5.3
"HP Imaging Device Functions" = HP Imaging Device Functions 5.3
"HP Photo & Imaging" = HP Image Zone 5.3
"HP Solution Center & Imaging Support Tools" = HP Solution Center & Imaging Support Tools 5.3
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{52504CE6-E909-4113-B232-4AFEC6543A61}" = Broadcom 440x 10/100 Integrated Controller
"LiveUpdate" = LiveUpdate 3.3 (Symantec Corporation)
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Nero PhotoShow Express 4" = Nero PhotoShow Express 4
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Office8.0" = Microsoft Office 97, Professional Edition
"Rhapsody" = Rhapsody
"Symantec System Center" = Symantec System Center
"TurboTax 2010" = TurboTax 2010
"VLC media player" = VLC media player 1.0.5
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionUninstall]
"f031ef6ac137efc5" = Dell Driver Download Manager
"uTorrent" = µTorrent

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 11/21/2011 6:19:14 PM | Computer Name = DESKTOP | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module flash11c.ocx, version 11.0.1.152, fault address 0x001b0b5c.

Error - 11/21/2011 6:27:04 PM | Computer Name = DESKTOP | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

[ System Events ]
Error - 12/22/2011 6:08:00 PM | Computer Name = DESKTOP | Source = TermServDevices | ID = 1111
Description = Driver Microsoft Shared Fax Driver required for printer Fax is unknown.
Contact the administrator to install the driver before you log in again.

Error - 12/22/2011 7:07:50 PM | Computer Name = DESKTOP | Source = TermServDevices | ID = 1111
Description = Driver Microsoft Shared Fax Driver required for printer Fax is unknown.
Contact the administrator to install the driver before you log in again.

Error - 12/22/2011 7:28:03 PM | Computer Name = DESKTOP | Source = TermServDevices | ID = 1111
Description = Driver Microsoft Shared Fax Driver required for printer Fax is unknown.
Contact the administrator to install the driver before you log in again.

Error - 12/25/2011 9:22:26 AM | Computer Name = DESKTOP | Source = TermServDevices | ID = 1111
Description = Driver Microsoft Shared Fax Driver required for printer Fax is unknown.
Contact the administrator to install the driver before you log in again.

Error - 12/27/2011 3:18:56 PM | Computer Name = DESKTOP | Source = TermServDevices | ID = 1111
Description = Driver Microsoft Shared Fax Driver required for printer Fax is unknown.
Contact the administrator to install the driver before you log in again.

Error - 12/29/2011 1:31:17 AM | Computer Name = DESKTOP | Source = TermServDevices | ID = 1111
Description = Driver Microsoft Shared Fax Driver required for printer Fax is unknown.
Contact the administrator to install the driver before you log in again.

Error - 12/29/2011 3:36:01 PM | Computer Name = DESKTOP | Source = TermServDevices | ID = 1111
Description = Driver Microsoft Shared Fax Driver required for printer Fax is unknown.
Contact the administrator to install the driver before you log in again.

Error - 12/31/2011 12:45:40 PM | Computer Name = DESKTOP | Source = TermServDevices | ID = 1111
Description = Driver Microsoft Shared Fax Driver required for printer Fax is unknown.
Contact the administrator to install the driver before you log in again.

Error - 12/31/2011 12:56:17 PM | Computer Name = DESKTOP | Source = TermServDevices | ID = 1111
Description = Driver Microsoft Shared Fax Driver required for printer Fax is unknown.
Contact the administrator to install the driver before you log in again.

Error - 1/2/2012 12:44:35 AM | Computer Name = DESKTOP | Source = TermServDevices | ID = 1111
Description = Driver Microsoft Shared Fax Driver required for printer Fax is unknown.
Contact the administrator to install the driver before you log in again.


< End of report >

This is a different box/OS and not a duplicate post.
Hi,

Please do the following:

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
Hi

Please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

File::
c:\windows\system32\sho2B97.tmp
c:\windows\system32\shoACE5.tmp
c:\windows\system32\sho338F.tmp
c:\windows\system32\sho2B2A.tmp
c:\windows\system32\shoF84E.tmp
c:\windows\system32\shoDB14.tmp
c:\windows\system32\sho898D.tmp
c:\windows\system32\sho6EBA.tmp
c:\windows\system32\sho6655.tmp
c:\windows\system32\sho7C43.tmp
c:\windows\system32\shoB26B.tmp
c:\windows\system32\sho1294.tmp
c:\windows\system32\sho4985.tmp
c:\windows\system32\sho7874.tmp
c:\windows\system32\shoD88F.tmp
c:\windows\system32\shoA0CB.tmp

DirLook::
c:\programdata\{D3B41B92-9BC2-43EB-916A-4FA9E8191837}

ClearJavaCache::

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix may request an update; please allow it.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.


NEXT

Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Go here to run an online scanner from ESET.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan completes, press the LIST OF THREATS FOUND button
  • Press EXPORT TO TEXT FILE , name the file ESETSCAN and save it to your desktop
  • Include the contents of this report in your next reply.
  • Press the BACK button.
  • Press Finish

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI