This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

computer slows and mouse left mouse click and double click could not w

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi

Its been a year or so since the good guys at what the tech helped me out in my previous problem

I'll need your kind assistance and advise again – Thank you in advance

1) My left mouse click (and double click) suddenly does not work. This happens suddenly and the last thing i saw is whenever the mouse points, there is a cicle and a slash, like the "no entry" sign. After 2 days, it is working fine again. After a week, the same thing happens again, and right now, it is working again! (and i have to take this opportunity to post this fast). My mouse right click was working fine all this while

2) My computer seems to "have a mind" of its own on the second time my mouse hangs, clicking and opening up applications on my desktop. Also, a lot of my programs are very slow to load up, and it sometime hangs, and my mozilla firefox crashes a lot, worse if i use my internet explorer browser.

3) I have done a "disk check" on my local C dirve and done a full scan of Norton on my C drive but no errors or virus found.

From the OTL scan, these are my results
OTL.TXT
OTL logfile created on: 1/16/2012 8:56:15 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\user\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

510.80 Mb Total Physical Memory | 192.21 Mb Available Physical Memory | 37.63% Memory free
1.22 Gb Paging File | 0.65 Gb Available in Paging File | 53.49% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 39.06 Gb Total Space | 22.69 Gb Free Space | 58.08% Space Free | Partition Type: NTFS
Drive D: | 37.26 Gb Total Space | 15.15 Gb Free Space | 40.65% Space Free | Partition Type: NTFS

Computer Name: USER-FD953F9ADA | User Name: user | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\user\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Norton AntiVirus\Engine\18.6.0.29\ccsvchst.exe (Symantec Corporation)
PRC - C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe ()
PRC - C:\Program Files\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\SMC\SMCWUSB-G 802.11g Wireless USB 2.0 Adapter\SMCWGUTI.exe ()
PRC - C:\WINDOWS\system32\CTHELPER.EXE (Creative Technology Ltd)


========== Modules (No Company Name) ==========

MOD - C:\Documents and Settings\user\Local Settings\temp\e3c74ee6-7482-4280-b9c3-f233b390296e\CliSecureRT.dll ()
MOD - C:\Program Files\Samsung\Kies\External\FirmwareUpdate\CommonModule.dll ()
MOD - C:\Program Files\Samsung\Kies\External\FirmwareUpdate\FirmwareUpdateAgent.Common.dll ()
MOD - C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe ()
MOD - C:\Program Files\Samsung\Kies\External\FirmwareUpdate\IPCServer.dll ()
MOD - C:\Program Files\Samsung\Kies\External\FirmwareUpdate\ISharedIPCInterface.dll ()
MOD - C:\WINDOWS\system32\Primomonnt.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Management\16670b6870746e5a8dc4a73a76a90bed\System.Management.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Core\e98726349766935ec0e9b980f19a046a\System.Core.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\7579c76fa81eb309d3170b62467be58d\PresentationFramework.Luna.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\2077ce69bd24a095dd54683ae26454d4\System.Runtime.Remoting.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\560662ada034afb6ec78a152bd9a47b5\PresentationFramework.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PresentationCore\9f5dff344ac6ac923b5ade8ba1ab9382\PresentationCore.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\WindowsBase\d63164ac4ed5adabc6a1b0fdf07eee05\WindowsBase.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\37217abe2c5164e59aba251860f4c79e\System.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\7124a40b9998f7b63c86bd1a2125ce26\mscorlib.ni.dll ()
MOD - C:\WINDOWS\system32\quartz.dll ()
MOD - C:\WINDOWS\system32\nvapi.dll ()
MOD - C:\Program Files\SMC\SMCWUSB-G 802.11g Wireless USB 2.0 Adapter\SMCWGUTI.exe ()
MOD - C:\Program Files\SMC\SMCWUSB-G 802.11g Wireless USB 2.0 Adapter\res.dll ()
MOD - C:\Program Files\SMC\SMCWUSB-G 802.11g Wireless USB 2.0 Adapter\iface.dll ()
MOD - C:\Program Files\SMC\SMCWUSB-G 802.11g Wireless USB 2.0 Adapter\ZDWlan.dll ()
MOD - C:\Program Files\SMC\SMCWUSB-G 802.11g Wireless USB 2.0 Adapter\dot1x_dll.dll ()
MOD - C:\Program Files\SMC\SMCWUSB-G 802.11g Wireless USB 2.0 Adapter\WCN_DLL.dll ()
MOD - C:\WINDOWS\system32\devenum.dll ()
MOD - C:\WINDOWS\system32\msdmo.dll ()
MOD - C:\Program Files\SMC\SMCWUSB-G 802.11g Wireless USB 2.0 Adapter\ssleay32.dll ()
MOD - C:\Program Files\SMC\SMCWUSB-G 802.11g Wireless USB 2.0 Adapter\libeay32.dll ()


========== Win32 Services (SafeList) ==========

SRV - (AppMgmt) – File not found
SRV - (NAV) – C:\Program Files\Norton AntiVirus\Engine\18.6.0.29\ccSvcHst.exe (Symantec Corporation)
SRV - (CCALib8) – C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)


========== Driver Services (SafeList) ==========

DRV - (BHDrvx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\BASHDefs\20111223.001\BHDrvx86.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (IDSxpx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\IPSDefs\20120113.002\IDSXpx86.sys (Symantec Corporation)
DRV - (NAVEX15) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\VirusDefs\20120115.009\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\VirusDefs\20120115.009\NAVENG.SYS (Symantec Corporation)
DRV - (SymEvent) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (SRTSP) – C:\WINDOWS\System32\Drivers\NAV\1206000.01D\SRTSP.SYS (Symantec Corporation)
DRV - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\WINDOWS\system32\drivers\NAV\1206000.01D\SRTSPX.SYS (Symantec Corporation)
DRV - (SYMTDI) – C:\WINDOWS\System32\Drivers\NAV\1206000.01D\SYMTDI.SYS (Symantec Corporation)
DRV - (SymEFA) – C:\WINDOWS\system32\drivers\NAV\1206000.01D\SYMEFA.SYS (Symantec Corporation)
DRV - (SymDS) – C:\WINDOWS\system32\drivers\NAV\1206000.01D\SYMDS.SYS (Symantec Corporation)
DRV - (SymIRON) – C:\WINDOWS\system32\drivers\NAV\1206000.01D\Ironx86.SYS (Symantec Corporation)
DRV - (ssadmdm) – C:\WINDOWS\system32\drivers\ssadmdm.sys (MCCI Corporation)
DRV - (ssadbus) SAMSUNG Android USB Composite Device driver (WDM) – C:\WINDOWS\system32\drivers\ssadbus.sys (MCCI Corporation)
DRV - (ssadmdfl) SAMSUNG Android USB Modem (Filter) – C:\WINDOWS\system32\drivers\ssadmdfl.sys (MCCI Corporation)
DRV - (MREMPR5) – C:\Program Files\Common Files\Motive\MREMPR5.sys (Motive, Inc.)
DRV - (MRENDIS5) – C:\Program Files\Common Files\Motive\MRENDIS5.sys (Motive, Inc.)
DRV - (SMCWGU(SMC)) SMCWUSB-G 802.11g Wireless USB 2.0 Adapter(SMC) – C:\WINDOWS\system32\drivers\SMCWGU.sys (SMC Corporation)
DRV - (symlcbrd) – C:\WINDOWS\system32\drivers\symlcbrd.sys (Symantec Corporation)
DRV - (ZDPSp50) – C:\WINDOWS\system32\drivers\ZDPSp50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (gameenum) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (ha10kx2k) – C:\WINDOWS\system32\drivers\ha10kx2k.sys (Creative Technology Ltd)
DRV - (emupia) – C:\WINDOWS\system32\drivers\emupia2k.sys (Creative Technology Ltd)
DRV - (ctsfm2k) – C:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (ctprxy2k) – C:\WINDOWS\system32\drivers\ctprxy2k.sys (Creative Technology Ltd)
DRV - (ossrv) – C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (ctaud2k) Creative Audio Driver (WDM) – C:\WINDOWS\system32\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV - (ctac32k) – C:\WINDOWS\system32\drivers\ctac32k.sys (Creative Technology Ltd)
DRV - (IntelC51) – C:\WINDOWS\system32\drivers\IntelC51.sys (Intel Corporation)
DRV - (IntelC52) Intel® – C:\WINDOWS\system32\drivers\IntelC52.sys (Intel Corporation)
DRV - (IntelC53) – C:\WINDOWS\system32\drivers\IntelC53.sys (Intel Corporation)
DRV - (sfman) Creative SoundFont Manager Driver (WDM) – C:\WINDOWS\system32\drivers\sfmanm.sys (Creative Technology Ltd.)
DRV - (emu10k1) Creative Interface Manager Driver (WDM) – C:\WINDOWS\system32\drivers\ctlfacem.sys (Creative Technology Ltd.)
DRV - (emu10k) Creative SB Live! (WDM) – C:\WINDOWS\system32\drivers\emu10k1m.sys (Creative Technology Ltd.)
DRV - (ctljystk) – C:\WINDOWS\system32\drivers\ctljystk.sys (Creative Technology Ltd.)
DRV - (PfModNT) – C:\WINDOWS\system32\PFMODNT.SYS (Creative Technology Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://sg.yahoo.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: ""
FF - prefs.js..browser.search.defaultenginename: ""
FF - prefs.js..browser.search.order.1: ""
FF - prefs.js..browser.search.selectedEngine: ""
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://sg.yahoo.com/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:2.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..keyword.URL: "http://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q="
FF - prefs.js..network.proxy.type: 0

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\IPSFFPlgn\ [2011/09/28 22:34:29 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/09/08 21:34:20 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/05/08 12:05:49 | 000,000,000 | —D | M]

[2010/06/23 19:14:47 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\user\Application Data\Mozilla\Extensions
[2011/05/08 11:21:05 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\jyhauqib.default\extensions
[2010/12/12 08:39:59 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\jyhauqib.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/03/30 23:22:13 | 000,002,567 | —- | M] () – C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\jyhauqib.default\searchplugins\askcom.xml
[2011/05/08 11:21:05 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/06/24 21:04:45 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/12/19 16:51:39 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/09/28 22:34:29 | 000,000,000 | —D | M] (Symantec IPS) – C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\IPSFFPLGN
[2010/12/19 16:50:56 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/09/08 21:34:20 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2010/12/19 16:50:55 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/05/08 12:05:40 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml

O1 HOSTS File: ([2004/08/04 20:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\18.6.0.29\ips\ipsbho.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKLM..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE (Creative Technology Ltd.)
O4 - HKLM..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE (CANON INC.)
O4 - HKLM..\Run: [Jet Detection] C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe ()
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [UpdReg] C:\WINDOWS\Updreg.EXE (Creative Technology Ltd.)
O4 - HKLM..\Run: [WINDVDPatch] C:\WINDOWS\System32\CTHELPER.EXE (Creative Technology Ltd)
O4 - HKCU..\Run: [KiesHelper] C:\Program Files\Samsung\Kies\KiesHelper.exe (Samsung)
O4 - HKCU..\Run: [KiesPDLR] C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe ()
O4 - HKCU..\Run: [KiesTrayAgent] C:\Program Files\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SMCWUSB-G 802.11g Wireless USB Utility.lnk = C:\Program Files\SMC\SMCWUSB-G 802.11g Wireless USB 2.0 Adapter\SMCWGUTI.exe ()
O4 - Startup: C:\Documents and Settings\user\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Easy-WebPrint Add To Print List - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint High Speed Print - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint Preview - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint Print - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O15 - HKCU\..Trusted Domains: aol.com ([free] http in Trusted sites)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{93CCFC05-3915-400D-BEB8-842FC3933D6B}: DhcpNameServer = 192.168.1.254
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop Components:0 () - file:///C:/DOCUME~1/user/LOCALS~1/Temp/msoclip1/01/clip_image002.jpg
O24 - Desktop Components:1 (My Current Home Page) - About:Home
O24 - Desktop WallPaper: C:\WINDOWS\subaru-wrx-sti-s204-8.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\subaru-wrx-sti-s204-8.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/11/30 14:18:49 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: aux - C:\WINDOWS\System32\ctwdm32.dll (Creative Technology Ltd.)
Drivers32: msacm.ctmp3 - C:\WINDOWS\system32\ctmp3.acm (Creative Technology Ltd.)
Drivers32: msacm.divxa32 - C:\WINDOWS\System32\msaud32_divx.acm (Microsoft Corporation)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FMVC - C:\WINDOWS\System32\fmcodec.DLL (Fox Magic Software)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/01/16 20:46:24 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\user\Desktop\OTL.exe
[2007/02/20 13:16:14 | 000,065,536 | —- | C] ( ) – C:\WINDOWS\System32\a3d.dll

========== Files - Modified Within 30 Days ==========

[2012/01/16 20:46:28 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\user\Desktop\OTL.exe
[2012/01/16 20:26:38 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/01/16 20:25:46 | 000,081,191 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2012/01/16 20:25:42 | 003,375,034 | —- | M] () – C:\WINDOWS\{00000002-00000000-00000004-00001102-00000002-80651102}.CDF
[2012/01/16 20:25:42 | 003,375,034 | —- | M] () – C:\WINDOWS\{00000002-00000000-00000004-00001102-00000002-80651102}.BAK
[2012/01/16 20:25:21 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/01/16 20:25:16 | 535,678,976 | -HS- | M] () – C:\hiberfil.sys
[2012/01/16 20:24:35 | 000,025,296 | —- | M] () – C:\WINDOWS\System32\BMXCtrlState-{00000002-00000000-00000004-00001102-00000002-80651102}.rfx
[2012/01/16 20:24:35 | 000,025,296 | —- | M] () – C:\WINDOWS\System32\BMXBkpCtrlState-{00000002-00000000-00000004-00001102-00000002-80651102}.rfx
[2012/01/16 20:24:35 | 000,016,516 | —- | M] () – C:\WINDOWS\System32\BMXStateBkp-{00000002-00000000-00000004-00001102-00000002-80651102}.rfx
[2012/01/16 20:24:35 | 000,016,516 | —- | M] () – C:\WINDOWS\System32\BMXState-{00000002-00000000-00000004-00001102-00000002-80651102}.rfx
[2012/01/16 20:24:35 | 000,002,064 | —- | M] () – C:\WINDOWS\System32\settingsbkup.sfm
[2012/01/16 20:24:35 | 000,002,064 | —- | M] () – C:\WINDOWS\System32\settings.sfm
[2012/01/16 20:24:35 | 000,000,024 | —- | M] () – C:\WINDOWS\System32\DVCStateBkp-{00000002-00000000-00000004-00001102-00000002-80651102}.dat
[2012/01/16 20:24:35 | 000,000,024 | —- | M] () – C:\WINDOWS\System32\DVCState-{00000002-00000000-00000004-00001102-00000002-80651102}.dat
[2012/01/11 00:26:34 | 000,000,116 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2012/01/10 23:44:18 | 000,040,448 | —- | M] () – C:\Documents and Settings\user\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/12/22 23:24:17 | 000,006,197 | —- | M] () – C:\Documents and Settings\user\Desktop\parking Dec11_to_Mar12.pdf

========== Files Created - No Company Name ==========

[2011/12/22 23:24:17 | 000,006,197 | —- | C] () – C:\Documents and Settings\user\Desktop\parking Dec11_to_Mar12.pdf
[2011/07/27 01:31:35 | 000,180,624 | —- | C] () – C:\WINDOWS\System32\Primomonnt.dll
[2011/03/28 15:17:20 | 000,008,704 | —- | C] () – C:\WINDOWS\System32\CNMVS78.DLL
[2011/03/23 07:43:36 | 000,329,392 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2011/02/10 12:03:48 | 000,000,314 | —- | C] () – C:\WINDOWS\primopdf.ini
[2011/01/29 17:00:24 | 000,030,568 | —- | C] () – C:\WINDOWS\MusiccityDownload.exe
[2011/01/29 17:00:22 | 000,974,848 | —- | C] () – C:\WINDOWS\System32\cis-2.4.dll
[2011/01/29 17:00:22 | 000,081,920 | —- | C] () – C:\WINDOWS\System32\issacapi_bs-2.3.dll
[2011/01/29 17:00:22 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\issacapi_pe-2.3.dll
[2011/01/29 17:00:22 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\issacapi_se-2.3.dll
[2010/12/01 03:13:12 | 008,596,886 | —- | C] () – C:\Documents and Settings\user\Application Data\Black Eyed Peas - The Time (Dirty Bit).zip
[2010/11/14 18:23:30 | 007,198,459 | —- | C] () – C:\Documents and Settings\user\Application Data\Kesha - We R Who We R.zip
[2010/10/21 19:16:51 | 000,001,940 | —- | C] () – C:\Documents and Settings\user\Local Settings\Application Data\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2010/10/21 07:41:34 | 000,001,940 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2010/09/04 00:54:11 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/06/23 19:14:28 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2009/10/06 15:16:00 | 000,819,200 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2009/08/16 09:26:11 | 000,006,550 | —- | C] () – C:\WINDOWS\jautoexp.dat
[2009/01/04 20:02:08 | 000,040,448 | —- | C] () – C:\Documents and Settings\user\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/11/09 19:25:59 | 000,000,398 | —- | C] () – C:\WINDOWS\NJCOM.INI
[2008/06/07 15:04:14 | 001,662,976 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2008/06/07 15:04:14 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2008/06/07 15:04:07 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2008/06/07 15:04:05 | 000,581,632 | —- | C] () – C:\WINDOWS\System32\nvhwvid.dll
[2008/06/07 15:04:03 | 001,339,392 | —- | C] () – C:\WINDOWS\System32\nvdspsch.exe
[2008/06/07 15:03:46 | 000,442,368 | —- | C] () – C:\WINDOWS\System32\nvappbar.exe
[2008/06/07 15:03:46 | 000,196,608 | —- | C] () – C:\WINDOWS\System32\nvapi.dll
[2008/06/07 15:03:41 | 000,425,984 | —- | C] () – C:\WINDOWS\System32\keystone.exe
[2008/06/07 14:50:55 | 000,000,024 | —- | C] () – C:\WINDOWS\System32\DVCStateBkp-{00000001-00000000-00000004-00001102-00000002-80651102}.dat
[2008/06/07 14:50:55 | 000,000,024 | —- | C] () – C:\WINDOWS\System32\DVCState-{00000001-00000000-00000004-00001102-00000002-80651102}.dat
[2008/04/25 20:22:57 | 000,000,000 | —- | C] () – C:\WINDOWS\mngui.INI
[2007/02/20 13:23:08 | 000,000,024 | —- | C] () – C:\WINDOWS\System32\DVCStateBkp-{00000002-00000000-00000004-00001102-00000002-80651102}.dat
[2007/02/20 13:23:08 | 000,000,024 | —- | C] () – C:\WINDOWS\System32\DVCState-{00000002-00000000-00000004-00001102-00000002-80651102}.dat
[2007/02/20 13:17:48 | 000,000,231 | —- | C] () – C:\WINDOWS\AC3API.INI
[2007/02/20 13:17:47 | 001,048,576 | —- | C] () – C:\WINDOWS\System32\SFMAN.DAT
[2007/02/20 13:16:44 | 000,037,727 | —- | C] () – C:\WINDOWS\System32\Emu10kx.ini
[2007/02/20 13:16:44 | 000,000,029 | —- | C] () – C:\WINDOWS\System32\ctzapxx.ini
[2007/02/20 13:16:35 | 000,164,044 | —- | C] () – C:\WINDOWS\System32\ctdlang.dat
[2007/02/20 13:16:35 | 000,113,373 | —- | C] () – C:\WINDOWS\System32\ctbasicw.dat
[2007/02/20 13:16:35 | 000,113,273 | —- | C] () – C:\WINDOWS\System32\CTBAS2W.DAT
[2007/02/20 13:16:33 | 000,179,669 | —- | C] () – C:\WINDOWS\System32\ctstatic.dat
[2007/02/20 13:16:33 | 000,044,055 | —- | C] () – C:\WINDOWS\System32\ctdaught.dat
[2007/02/20 13:16:22 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\KILLAPPS.EXE
[2007/02/20 13:16:22 | 000,000,180 | —- | C] () – C:\WINDOWS\System32\KILL.INI
[2007/02/20 13:16:20 | 000,184,320 | —- | C] () – C:\WINDOWS\PSCONV.EXE
[2007/02/20 13:16:20 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\REGPLIB.EXE
[2007/02/20 12:35:52 | 000,000,307 | —- | C] () – C:\WINDOWS\SBWIN.INI
[2006/03/20 23:36:32 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2005/11/30 22:09:29 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2005/11/30 22:08:17 | 000,134,072 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2005/11/30 14:43:21 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/11/30 14:38:37 | 001,519,616 | —- | C] () – C:\WINDOWS\System32\nwiz.exe
[2005/11/30 14:38:37 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2005/11/30 14:38:36 | 001,470,464 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2005/11/30 14:21:25 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2005/11/30 14:15:45 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2005/07/12 14:44:42 | 000,015,872 | —- | C] () – C:\WINDOWS\System32\InsDrvZD64.DLL
[2004/08/04 20:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2004/08/04 20:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/04 20:00:00 | 000,432,686 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/04 20:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/04 20:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/04 20:00:00 | 000,067,516 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/04 20:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/04 20:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/04 20:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/04 20:00:00 | 000,004,461 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/04 20:00:00 | 000,001,788 | —- | C] () – C:\WINDOWS\System32\Dcache.bin
[2004/08/04 20:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2004/03/23 16:38:00 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\InsDrvZD.dll
[2003/03/14 12:24:00 | 000,024,576 | —- | C] () – C:\WINDOWS\System32\ZyDelReg.exe
[1999/01/23 02:46:56 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL

========== LOP Check ==========

[2011/03/28 17:29:04 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2009/06/27 10:41:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PCSettings
[2010/12/23 11:09:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PPLive
[2011/03/28 17:56:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Samsung
[2010/11/08 21:17:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Thomson Reuters
[2010/07/03 19:35:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2008/02/20 21:02:15 | 000,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\ICAClient
[2008/11/09 19:26:04 | 000,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\NJStar
[2011/12/15 22:34:49 | 000,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\PrimoPDF
[2011/03/28 17:55:55 | 000,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Samsung
[2011/07/27 01:33:37 | 000,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Softland
[2006/10/20 20:27:46 | 000,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Sports Interactive
[2006/09/17 17:18:52 | 000,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Teleca
[2010/11/04 19:20:27 | 000,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Tific
[2012/01/13 00:49:16 | 000,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\uTorrent

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2005/11/30 14:18:49 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2005/11/30 14:12:58 | 000,000,211 | —- | M] () – C:\Boot.bak
[2010/12/18 15:29:25 | 000,000,327 | RHS- | M] () – C:\boot.ini
[2004/08/03 23:00:00 | 000,260,272 | RHS- | M] () – C:\cmldr
[2005/11/30 14:18:49 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2012/01/16 20:25:16 | 535,678,976 | -HS- | M] () – C:\hiberfil.sys
[2005/11/30 14:18:49 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2005/11/30 14:18:49 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/04 20:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2004/08/04 20:00:00 | 000,250,032 | RHS- | M] () – C:\ntldr
[2012/01/16 20:25:15 | 805,306,368 | -HS- | M] () – C:\pagefile.sys
[2005/11/30 14:27:04 | 000,000,090 | —- | M] () – C:\setup.log
[2009/07/30 20:04:54 | 000,000,268 | -H– | M] () – C:\sqmdata00.sqm
[2009/08/14 07:12:25 | 000,000,268 | -H– | M] () – C:\sqmdata01.sqm
[2009/08/14 07:26:47 | 000,000,268 | -H– | M] () – C:\sqmdata02.sqm
[2009/08/14 20:05:58 | 000,000,268 | -H– | M] () – C:\sqmdata03.sqm
[2009/08/14 21:40:59 | 000,000,268 | -H– | M] () – C:\sqmdata04.sqm
[2009/08/14 22:28:32 | 000,000,268 | -H– | M] () – C:\sqmdata05.sqm
[2009/08/16 09:26:37 | 000,000,268 | -H– | M] () – C:\sqmdata06.sqm
[2009/08/16 10:06:08 | 000,000,268 | -H– | M] () – C:\sqmdata07.sqm
[2009/08/16 18:07:34 | 000,000,268 | -H– | M] () – C:\sqmdata08.sqm
[2009/08/17 22:16:39 | 000,000,268 | -H– | M] () – C:\sqmdata09.sqm
[2009/08/18 13:07:12 | 000,000,268 | -H– | M] () – C:\sqmdata10.sqm
[2009/08/18 14:13:20 | 000,000,268 | -H– | M] () – C:\sqmdata11.sqm
[2009/08/19 07:16:38 | 000,000,268 | -H– | M] () – C:\sqmdata12.sqm
[2009/08/20 13:56:16 | 000,000,268 | -H– | M] () – C:\sqmdata13.sqm
[2009/09/03 21:00:07 | 000,000,268 | -H– | M] () – C:\sqmdata14.sqm
[2009/07/14 07:43:03 | 000,000,268 | -H– | M] () – C:\sqmdata15.sqm
[2009/07/14 20:46:22 | 000,000,268 | -H– | M] () – C:\sqmdata16.sqm
[2009/07/29 07:42:37 | 000,000,268 | -H– | M] () – C:\sqmdata17.sqm
[2009/07/30 00:33:31 | 000,000,268 | -H– | M] () – C:\sqmdata18.sqm
[2009/07/30 07:40:29 | 000,000,268 | -H– | M] () – C:\sqmdata19.sqm
[2009/07/30 20:04:54 | 000,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
[2009/08/14 07:12:25 | 000,000,244 | -H– | M] () – C:\sqmnoopt01.sqm
[2009/08/14 07:26:46 | 000,000,244 | -H– | M] () – C:\sqmnoopt02.sqm
[2009/08/14 20:05:58 | 000,000,244 | -H– | M] () – C:\sqmnoopt03.sqm
[2009/08/14 21:40:58 | 000,000,244 | -H– | M] () – C:\sqmnoopt04.sqm
[2009/08/14 22:28:32 | 000,000,244 | -H– | M] () – C:\sqmnoopt05.sqm
[2009/08/16 09:26:37 | 000,000,244 | -H– | M] () – C:\sqmnoopt06.sqm
[2009/08/16 10:06:08 | 000,000,244 | -H– | M] () – C:\sqmnoopt07.sqm
[2009/08/16 18:07:33 | 000,000,244 | -H– | M] () – C:\sqmnoopt08.sqm
[2009/08/17 22:16:38 | 000,000,244 | -H– | M] () – C:\sqmnoopt09.sqm
[2009/08/18 13:07:12 | 000,000,244 | -H– | M] () – C:\sqmnoopt10.sqm
[2009/08/18 14:13:20 | 000,000,244 | -H– | M] () – C:\sqmnoopt11.sqm
[2009/08/19 07:16:38 | 000,000,244 | -H– | M] () – C:\sqmnoopt12.sqm
[2009/08/20 13:56:14 | 000,000,244 | -H– | M] () – C:\sqmnoopt13.sqm
[2009/09/03 21:00:06 | 000,000,244 | -H– | M] () – C:\sqmnoopt14.sqm
[2009/07/14 07:43:03 | 000,000,244 | -H– | M] () – C:\sqmnoopt15.sqm
[2009/07/14 20:46:22 | 000,000,244 | -H– | M] () – C:\sqmnoopt16.sqm
[2009/07/29 07:42:37 | 000,000,244 | -H– | M] () – C:\sqmnoopt17.sqm
[2009/07/30 00:33:31 | 000,000,244 | -H– | M] () – C:\sqmnoopt18.sqm
[2009/07/30 07:40:29 | 000,000,244 | -H– | M] () – C:\sqmnoopt19.sqm

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2005/11/30 14:18:14 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2005/08/26 13:00:00 | 000,020,992 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD78.DLL
[2005/08/26 13:00:00 | 000,059,392 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP78.DLL
[2008/07/06 20:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/07/06 18:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2005/11/30 22:07:31 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2005/11/30 22:07:31 | 000,634,880 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2005/11/30 22:07:31 | 000,876,544 | —- | M] () – C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2005/11/30 14:18:56 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
[2007/02/20 13:17:53 | 000,000,180 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Free AOL & Unlimited Internet.url

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2005/11/30 14:23:35 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2005/11/30 14:23:34 | 000,000,079 | —- | M] () – C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2011/04/13 00:03:22 | 000,301,568 | —- | M] () – C:\Documents and Settings\user\Desktop\0gr89kho.exe
[2010/12/21 20:03:51 | 000,791,393 | —- | M] (Lars Hederer ) – C:\Documents and Settings\user\Desktop\erunt-setup.exe
[2011/10/23 23:06:03 | 009,168,552 | —- | M] (Gretech Corporation) – C:\Documents and Settings\user\Desktop\GOMPLAYERENSETUP.EXE
[2008/11/09 19:25:17 | 006,212,784 | —- | M] (NJStar Software Corp.) – C:\Documents and Settings\user\Desktop\njcom273sw8618.exe
[2012/01/16 20:46:28 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\user\Desktop\OTL.exe
[2008/12/28 21:18:59 | 001,234,120 | —- | M] () – C:\Documents and Settings\user\Desktop\wrar380.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-01-15 16:28:04

< End of report >
from EXTRAS.TXT

OTL Extras logfile created on: 1/16/2012 8:56:15 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\user\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

510.80 Mb Total Physical Memory | 192.21 Mb Available Physical Memory | 37.63% Memory free
1.22 Gb Paging File | 0.65 Gb Available in Paging File | 53.49% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 39.06 Gb Total Space | 22.69 Gb Free Space | 58.08% Space Free | Partition Type: NTFS
Drive D: | 37.26 Gb Total Space | 15.15 Gb Free Space | 40.65% Space Free | Partition Type: NTFS

Computer Name: USER-FD953F9ADA | User Name: user | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] – rundll32.exe shdocvw.dll,OpenURL %l

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office\msohtmed.exe" /p %1 (Microsoft Corporation)
InternetShortcut [open] – rundll32.exe shdocvw.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\MSN Messenger\livecall.exe" = C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Funshion Online\Funshion\FunshionService.exe" = C:\Program Files\Funshion Online\Funshion\FunshionService.exe:*:Disabled:FunshionService
"C:\Program Files\Funshion Online\Funshion\FunshionUpgrade.exe" = C:\Program Files\Funshion Online\Funshion\FunshionUpgrade.exe:*:Disabled:FunshionUpgrade
"C:\Program Files\PPLive\PPTV\PPLive.exe" = C:\Program Files\PPLive\PPTV\PPLive.exe:*:Disabled:PPLive
"C:\Program Files\Common Files\PPLiveNetwork\PPAP.exe" = C:\Program Files\Common Files\PPLiveNetwork\PPAP.exe:*:Disabled:PPLive
"C:\Program Files\PPLive\PPTV\PPLiveU.exe" = C:\Program Files\PPLive\PPTV\PPLiveU.exe:*:Disabled:PPLiveU
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent – (BitTorrent, Inc.)
"C:\WINDOWS\system32\muzapp.exe" = C:\WINDOWS\system32\muzapp.exe:*:Enabled:MUZ AOD APP player – (Musiccity Co.Ltd.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00010409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 SR-1 Professional
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216023FF}" = Java™ 6 Update 23
"{2DED5EA5-7C5E-4477-83F6-3BDCBE320FF0}" = Citrix Presentation Server Client - Web Only
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3B124151-B6A0-492C-8838-0854B800535D}" = Creative MuVo NX-TX
"{3D9892BB-A751-4E48-ADC8-E4289956CE1D}" = QuickTime
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{6C117F31-28A8-4477-BE91-64AC0A2204AD}" = Microsoft IntelliPoint 6.01
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{802C87BF-3A1E-45B0-8C12-9527A5C572B3}" = SMCWUSB-G 802.11g Wireless USB 2.0 Adapter
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{9115E7DB-3B29-445A-802D-11E0AA945B7F}" = Sound Blaster Live!
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{a0fe116e-9a8a-466f-aee0-625cb7c207e3}" = Microsoft Visual C++ 2005 Redistributable - KB2467175
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AC76BA86-7AD7-1033-7B44-A81000000003}" = Adobe Reader 8.1.1
"{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}" = Adobe AIR
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones
"{D75915D3-6CFF-445F-A346-18ED6EF2F618}" = Microsoft IntelliType Pro 6.01
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"aTube Catcher" = aTube Catcher
"CAL" = Canon Camera Access Library
"CameraUserGuide-PSSD1300IS_IXUS105" = Canon PowerShot SD1300 IS_IXUS 105 Camera User Guide
"CameraWindowDC8" = Canon Utilities CameraWindow DC 8
"CameraWindowLauncher" = Canon Utilities CameraWindow
"Canon Setup Utility 2.0" = Canon Setup Utility 2.0
"CANONBJ_Deinstall_CNMCP78.DLL" = Canon iP4200
"doPDF 7 printer_is1" = doPDF 7.2 printer
"Easy-PhotoPrint" = Canon Utilities Easy-PhotoPrint
"Easy-PrintToolBox" = Canon Utilities Easy-PrintToolBox
"Easy-WebPrint" = Easy-WebPrint
"ERUNT_is1" = ERUNT 1.1j
"ESET Online Scanner" = ESET Online Scanner v3
"GOM Player" = GOM Player
"InstallShield_{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"InstallShield_{802C87BF-3A1E-45B0-8C12-9527A5C572B3}" = SMCWUSB-G 802.11g Wireless USB 2.0 Adapter
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"MediaNavigation.CDLabelPrint" = CD-LabelPrint
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MovieEditTask" = Canon MovieEdit Task for ZoomBrowser EX
"MovieUploaderForYouTube" = Canon Utilities Movie Uploader for YouTube
"Mozilla Firefox 6.0.2 (x86 en-US)" = Mozilla Firefox 6.0.2 (x86 en-US)
"MSN Music Assistant" = MSN Music Assistant
"MSNINST" = MSN
"MuVo Driver" = MuVo Driver
"MyCamera" = Canon Utilities MyCamera
"NAV" = Norton AntiVirus
"NeroMultiInstaller!UninstallKey" = Nero Suite
"NJStar Communicator" = NJStar Communicator
"NVIDIA Drivers" = NVIDIA Drivers
"Personal Printing Guide" = Canon Personal Printing Guide
"PhotoStitch" = Canon Utilities PhotoStitch
"PrimoPDF" = PrimoPDF – brought to you by Nitro PDF Software
"Software Guide" = Canon DIGITAL CAMERA Solution Disk Software Guide
"SysInfo" = Creative System Information
"uTorrent" = µTorrent
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 10
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"ZoomBrowser EX" = Canon Utilities ZoomBrowser EX
"ZoomBrowser EX Memory Card Utility" = Canon ZoomBrowser EX Memory Card Utility

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 12/14/2011 8:42:57 AM | Computer Name = USER-FD953F9ADA | Source = Application Error | ID = 1004
Description = Faulting application ccsvchst.exe, version 10.1.1.16, faulting module
dscli.dll, version 1.2.0.15, fault address 0x00011465.

Error - 12/18/2011 12:07:24 PM | Computer Name = USER-FD953F9ADA | Source = Application Error | ID = 1000
Description = Faulting application ccsvchst.exe, version 10.1.1.16, faulting module
msvcrt.dll, version 7.0.2600.2180, fault address 0x0001ba4e.

Error - 12/24/2011 10:42:34 PM | Computer Name = USER-FD953F9ADA | Source = Application Error | ID = 1000
Description = Faulting application smcwguti.exe, version 2.3.0.2, faulting module
smcwguti.exe, version 2.3.0.2, fault address 0x0000a7f1.

Error - 12/26/2011 1:47:13 AM | Computer Name = USER-FD953F9ADA | Source = Application Error | ID = 1000
Description = Faulting application ccsvchst.exe, version 10.1.1.16, faulting module
dscli.dll, version 1.2.0.15, fault address 0x00022f88.

Error - 12/26/2011 11:44:02 AM | Computer Name = USER-FD953F9ADA | Source = Application Error | ID = 1000
Description = Faulting application ccsvchst.exe, version 10.1.1.16, faulting module
msvcrt.dll, version 7.0.2600.2180, fault address 0x0001b9b5.

Error - 12/29/2011 8:34:56 PM | Computer Name = USER-FD953F9ADA | Source = Application Error | ID = 1000
Description = Faulting application ccsvchst.exe, version 10.1.1.16, faulting module
msvcrt.dll, version 7.0.2600.2180, fault address 0x0001b9b5.

Error - 12/30/2011 11:25:51 PM | Computer Name = USER-FD953F9ADA | Source = Application Error | ID = 1000
Description = Faulting application smcwguti.exe, version 2.3.0.2, faulting module
smcwguti.exe, version 2.3.0.2, fault address 0x0000a7f1.

Error - 12/31/2011 10:52:10 PM | Computer Name = USER-FD953F9ADA | Source = Application Error | ID = 1000
Description = Faulting application ccsvchst.exe, version 10.1.1.16, faulting module
dscli.dll, version 1.2.0.15, fault address 0x00027d7e.

Error - 1/12/2012 7:51:05 AM | Computer Name = USER-FD953F9ADA | Source = Application Error | ID = 1000
Description = Faulting application ccsvchst.exe, version 10.1.1.16, faulting module
msvcrt.dll, version 7.0.2600.2180, fault address 0x0001b9b5.

Error - 1/15/2012 12:23:06 AM | Computer Name = USER-FD953F9ADA | Source = Application Error | ID = 1000
Description = Faulting application smcwguti.exe, version 2.3.0.2, faulting module
smcwguti.exe, version 2.3.0.2, fault address 0x0000a7f1.

[ System Events ]
Error - 1/16/2012 9:07:56 AM | Computer Name = USER-FD953F9ADA | Source = Service Control Manager | ID = 7000
Description = The PCASp50 NDIS Protocol Driver service failed to start due to the
following error: %%2

Error - 1/16/2012 9:07:56 AM | Computer Name = USER-FD953F9ADA | Source = Service Control Manager | ID = 7000
Description = The PCASp50 NDIS Protocol Driver service failed to start due to the
following error: %%2

Error - 1/16/2012 9:07:57 AM | Computer Name = USER-FD953F9ADA | Source = Service Control Manager | ID = 7000
Description = The PCASp50 NDIS Protocol Driver service failed to start due to the
following error: %%2

Error - 1/16/2012 9:07:57 AM | Computer Name = USER-FD953F9ADA | Source = Service Control Manager | ID = 7000
Description = The PCASp50 NDIS Protocol Driver service failed to start due to the
following error: %%2

Error - 1/16/2012 9:07:57 AM | Computer Name = USER-FD953F9ADA | Source = Service Control Manager | ID = 7000
Description = The PCASp50 NDIS Protocol Driver service failed to start due to the
following error: %%2

Error - 1/16/2012 9:07:57 AM | Computer Name = USER-FD953F9ADA | Source = Service Control Manager | ID = 7000
Description = The PCASp50 NDIS Protocol Driver service failed to start due to the
following error: %%2

Error - 1/16/2012 9:07:58 AM | Computer Name = USER-FD953F9ADA | Source = Service Control Manager | ID = 7000
Description = The PCASp50 NDIS Protocol Driver service failed to start due to the
following error: %%2

Error - 1/16/2012 9:07:58 AM | Computer Name = USER-FD953F9ADA | Source = Service Control Manager | ID = 7000
Description = The PCASp50 NDIS Protocol Driver service failed to start due to the
following error: %%2

Error - 1/16/2012 9:07:58 AM | Computer Name = USER-FD953F9ADA | Source = Service Control Manager | ID = 7000
Description = The PCASp50 NDIS Protocol Driver service failed to start due to the
following error: %%2

Error - 1/16/2012 9:07:58 AM | Computer Name = USER-FD953F9ADA | Source = Service Control Manager | ID = 7000
Description = The PCASp50 NDIS Protocol Driver service failed to start due to the
following error: %%2


< End of report >
Hi speedz76,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

µTorrent
You have µTorrent, a P2P/file sharing programs installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it.

References for the risk of these programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx
http://www.techweb.com/wire/160500554
http://www.internetworldstats.com/articles/art053.htm://http://www.techweb.com/wire/1605005…cles/art053.htm


I would recommend that you uninstall µTorrent, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.

If you wish to keep it, please do not use it until your computer is cleaned.

Now… let's try this:

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop



**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you -- please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Hi Tomk Thanks for your reply. Appreciate it very much Currently, I am not able to connect to my wireless network on my infected PC. I am not sure if that is caused by virus as i have no problems connecting to the wireless network in the past. Unless its partly due to my SMC wireless USB adaptor fault (its an old USB adaptor) I'm currently using my working laptop to transfer combo fix and files to my infected PC and vice versa. This post is from my working latop. Also, my wireless mouse left click and double click is not working again. This problem has been coming on and off, sometimes it works, sometimes it doesn't. I tried the same wireless mouse on my separate working laptop and it has the same problem as well. On my infected PC, i use a a normal working wired mouse and it works. In addition to the above 2, my infected PC is really slow nowadays and the simple applications like MS office and mozilla firefox hangs frequently. Last week, (just beofre i decided to post on this forum) the applications open up by itself as though someone else is controlling it. I have attached the log file from combo fix. Please take a look and look forward to your advise Thank you PS: I did not uninstall utorrent yet

Attachments:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI