This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Slow Start Up [Solved]

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

I have an older Compaq Presario SR215ONX 120GB that belonged to my mom-in-law. It is has been sitting unplugged for about a year and is a probably about 4 years old. She replaced the PC because it was so slow.

Recently I starting dinking around with it to see if I can get it working well enough to replace my moms 30gb laptop. The PC was slow and the clock wasn’t holding the date and time.

I did as much cleaning on the software and personal files that I felt safe getting rid of, ran disc clean up, defragged, replaced the battery, added another slot of 512mb memory, downloaded MS updates and ran CC Cleaner.

The response time on IE has greatly improved. However the start up time is still really slow, about 8 -10 minutes. There isn’t much left in the start up menu. But I will say my mom-in law is all over the internet and has been had a lot of spyware in the past.

Before handing the PC off to my mom I want to make sure it is free of any spyware.

Note about my Hijack: When I downloaded the file to the desktop I right clicked and ‘ran as administrator’. The scan ran and opened in note pad, however the program isn’t in my program files folder. Did I download this correctly?


Thanks for your help my Hijack log is below


Denise


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 4:44:15 PM, on 2/20/2012
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Norton Security Suite\Engine\4.4.0.12\ccSvcHst.exe
C:\hp\support\hpsysdrv.exe
C:\WINDOWS\RtHDVCpl.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
c:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Home\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Security Suite\Engine\4.4.0.12\coIEPlg.dll
O2 - BHO: flvpremier - {6a8fb514-9724-e9b2-063c-3275bdee15f0} - C:\Windows\system32\4vQA9d-W-WQ_jN.dll (file missing)
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Security Suite\Engine\4.4.0.12\IPSBHO.DLL
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Babylon IE plugin - {9CFACCB6-2F3F-4177-94EA-0D2B72D384C1} - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll (file missing)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\4.4.0.12\coIEPlg.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [ATICCC] "c:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [DPService] "C:\Program Files\HP\DVDPlay\DPService.exe"
O4 - HKLM\..\Run: [HP Software Update] c:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll/cmsidewiki.html
O8 - Extra context menu item: Translate this web page with Babylon - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm
O8 - Extra context menu item: Translate with Babylon - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Action.htm
O9 - Extra button: Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll (file missing)
O9 - Extra 'Tools' menuitem: Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll (file missing)
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O20 - AppInit_DLLs:
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Norton Security Suite (N360) - Symantec Corporation - C:\Program Files\Norton Security Suite\Engine\4.4.0.12\ccSvcHst.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 6169 bytes
Hello and welcome to What the Tech.

My name is Michael and I will be helping you with your computer problems.

Be aware that I am currently in training, which means that my replies must first be approved by one of my teachers. This may cause a slight delay in my responses, but keep in mind that this process is only to ensure you are receiving advice of the utmost accuracy.

Please keep the following points in mind:
  • Malware research is often a time consuming process and sometimes multiple tools/methods will have to be employed before an infection is completely dealt with. Please be patient during the process of removal.
  • Read my instructions carefully before carrying them out. Also, consider printing out any instructions in case you lose your Internet connection.
  • If you have any questions, please ask before carrying out a fix. Clearing up any confusion beforehand will save time in the long run. That said, I will try to post instructions as clearly and concisely as possible.
  • Please reply to this thread. Do not start a new topic, and do not request help on other forums during the course of the cleaning process.
  • If you do not reply after three (3) days, your thread will be closed.
IMPORTANT NOTE: Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.

I will be back as soon as possible with a response.
Hi denisemn,

Yes, you downloaded HJT correctly. HJT, like the other programs we'll be using, doesn't require an installation procedure.

  • OTL

    Download OTL to your desktop.

  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Select All Users
  • Under the Custom Scan box paste this in
    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    /md5stop
    %systemroot%\*. /rp /s
    CREATERESTOREPOINT
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan won't take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Post both logs

[*]aswMBR


Please download aswMBR.exe and save it to your desktop.

  • Double click aswMBR.exe to start the tool.
  • When prompted to download virus definitions, please do so.
  • Click Scan. Note: Do NOT attempt any Fix yet.
  • When the scan completes, click Save log, save it to your desktop and post it in your next reply.
  • There should also be another file that is created on your desktop named MBR.dat. Please right-click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well.
Hi mrb,

The logs are attached, not certain I did the MBR attacment correctly or not.

Thanks for your help.



📎MBR.zip

OTL logfile created on: 2/21/2012 6:14:39 PM - Run 1
OTL by OldTimer - Version 3.2.33.1 Folder = C:\Users\Home\Desktop
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

894.58 Mb Total Physical Memory | 440.05 Mb Available Physical Memory | 49.19% Memory free
2.01 Gb Paging File | 1.30 Gb Available in Paging File | 64.69% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 48.83 Gb Total Space | 19.51 Gb Free Space | 39.95% Space Free | Partition Type: NTFS
Drive D: | 5.76 Gb Total Space | 0.86 Gb Free Space | 15.02% Space Free | Partition Type: NTFS
Drive E: | 9.77 Gb Total Space | 9.26 Gb Free Space | 94.79% Space Free | Partition Type: NTFS

Computer Name: HOME-PC | User Name: Home | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/02/21 18:08:23 | 000,583,168 | —- | M] (OldTimer Tools) – C:\Users\Home\Desktop\OTL.exe
PRC - [2011/08/03 22:18:43 | 000,126,400 | R— | M] (Symantec Corporation) – C:\Program Files\Norton Security Suite\Engine\4.4.0.12\ccsvchst.exe
PRC - [2009/04/11 00:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2006/11/09 04:57:52 | 003,784,704 | —- | M] (Realtek Semiconductor) – C:\WINDOWS\RtHDVCpl.exe
PRC - [2006/09/28 07:42:24 | 000,065,536 | —- | M] (Hewlett-Packard Company) – C:\hp\support\hpsysdrv.exe
PRC - [2006/04/28 11:14:44 | 000,045,056 | —- | M] (ATI Technologies Inc.) – C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
PRC - [2006/04/28 11:14:44 | 000,045,056 | —- | M] (ATI Technologies Inc.) – c:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
PRC - [2006/04/28 11:14:44 | 000,045,056 | —- | M] (ATI Technologies Inc.) – C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe


========== Modules (No Company Name) ==========

MOD - [2012/02/20 16:18:06 | 000,998,400 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\8b5f54e3b382fc1720c76557ef8c8bc3\System.Management.ni.dll
MOD - [2012/02/20 16:14:21 | 011,820,032 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\2598077ccea480c6120d3a1ad4455be0\System.Web.ni.dll
MOD - [2012/02/18 13:01:11 | 000,771,584 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\5c3bfd69e0c268baff0d169e11a6a784\System.Runtime.Remoting.ni.dll
MOD - [2012/02/18 12:49:31 | 000,971,264 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\7fd6c62196829d1e2dce5a253145d51a\System.Configuration.ni.dll
MOD - [2012/02/17 20:19:20 | 005,450,752 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\f4c98b14c32dde050bcf79b7e6c5e8e3\System.Xml.ni.dll
MOD - [2012/02/17 20:17:47 | 012,430,848 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\65450889f3742aada2a6c0cf8e6173e3\System.Windows.Forms.ni.dll
MOD - [2012/02/17 20:17:22 | 001,587,200 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\137696d0416b65dbc1561152971488b4\System.Drawing.ni.dll
MOD - [2012/02/17 20:09:12 | 007,953,408 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System\c50133cb67d7c013fa31e1ffb942060b\System.ni.dll
MOD - [2007/06/13 18:18:54 | 000,159,744 | —- | M] () – C:\WINDOWS\System32\atitmmxx.dll
MOD - [2007/04/11 00:12:58 | 011,490,816 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\b6632a8b2f276a8e31f5b0f6b2006cd1\mscorlib.ni.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Auto | Stopped] – – (CLTNetCnService)
SRV - [2011/08/03 22:18:43 | 000,126,400 | R— | M] (Symantec Corporation) [Unknown | Running] – C:\Program Files\Norton Security Suite\Engine\4.4.0.12\ccSvcHst.exe – (N360)
SRV - [2009/07/14 13:36:00 | 000,066,056 | —- | M] (NOS Microsystems Ltd.) [On_Demand | Stopped] – C:\Program Files\NOS\bin\getPlus_HelperSvc.exe – (getPlus® Helper) getPlus®
SRV - [2008/01/19 01:38:24 | 000,272,952 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)


========== Driver Services (SafeList) ==========

DRV - [2012/02/05 15:00:24 | 000,106,104 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys – (EraserUtilRebootDrv)
DRV - [2012/02/05 15:00:19 | 000,374,392 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys – (eeCtrl)
DRV - [2012/01/27 19:43:11 | 001,576,312 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20120221.002\NAVEX15.SYS – (NAVEX15)
DRV - [2012/01/27 19:43:10 | 000,086,136 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20120221.002\NAVENG.SYS – (NAVENG)
DRV - [2011/12/23 21:17:32 | 000,820,344 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\BASHDefs\20120215.001\BHDrvx86.sys – (BHDrvx86)
DRV - [2011/11/30 17:49:06 | 000,368,248 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\IPSDefs\20120218.003\IDSvix86.sys – (IDSVix86)
DRV - [2011/08/21 20:53:36 | 000,340,088 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Windows\System32\Drivers\N360\0404000.00C\SYMTDIV.SYS – (SYMTDIv)
DRV - [2011/08/21 20:53:35 | 000,173,176 | —- | M] (Symantec Corporation) [File_System | Boot | Running] – C:\Windows\system32\drivers\N360\0404000.00C\SYMEFA.SYS – (SymEFA)
DRV - [2011/08/03 22:19:30 | 000,485,512 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Windows\system32\drivers\N360\0404000.00C\ccHPx86.sys – (ccHP)
DRV - [2010/10/16 19:00:14 | 000,124,976 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\drivers\SYMEVENT.SYS – (SymEvent)
DRV - [2010/04/28 23:03:51 | 000,116,784 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Windows\system32\drivers\N360\0404000.00C\Ironx86.SYS – (SymIRON)
DRV - [2010/04/21 20:29:50 | 000,325,680 | —- | M] (Symantec Corporation) [File_System | On_Demand | Running] – C:\Windows\System32\Drivers\N360\0404000.00C\SRTSP.SYS – (SRTSP)
DRV - [2010/04/21 20:29:50 | 000,043,696 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Windows\system32\drivers\N360\0404000.00C\SRTSPX.SYS – (SRTSPX) Symantec Real Time Storage Protection (PEL)
DRV - [2009/10/14 21:50:05 | 000,328,752 | R— | M] (Symantec Corporation) [Kernel | Boot | Running] – C:\Windows\system32\drivers\N360\0404000.00C\SYMDS.SYS – (SymDS)
DRV - [2009/06/17 06:20:34 | 000,012,648 | —- | M] (Secunia) [File_System | On_Demand | Stopped] – C:\WINDOWS\System32\drivers\psi_mf.sys – (PSI)
DRV - [2008/07/22 06:42:58 | 000,051,200 | —- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\drivers\Rtnicxp.sys – (RTL8023xp)
DRV - [2008/05/08 04:05:18 | 000,266,752 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\drivers\HSXHWBS2.sys – (HSXHWBS2)
DRV - [2008/05/08 04:03:18 | 000,980,992 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\drivers\HSX_DP.sys – (HSF_DP)
DRV - [2007/10/18 06:36:54 | 000,008,704 | —- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] – C:\WINDOWS\System32\drivers\XAudio.sys – (XAudio)
DRV - [2007/06/13 18:28:12 | 002,600,448 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\System32\drivers\atikmdag.sys – (R300)
DRV - [2007/06/13 18:28:12 | 002,600,448 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\drivers\atikmdag.sys – (atikmdag)
DRV - [2006/11/10 15:05:00 | 000,018,688 | —- | M] (Arcsoft, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\drivers\afc.sys – (Afc)
DRV - [2006/11/03 09:29:18 | 000,008,192 | —- | M] (ATI Technologies Inc.) [Kernel | Boot | Running] – C:\Windows\system32\DRIVERS\AtiPcie.sys – (AtiPcie) ATI PCI Express (3GIO)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-2559784832-2112059209-2043554392-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKU\S-1-5-21-2559784832-2112059209-2043554392-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKU\S-1-5-21-2559784832-2112059209-2043554392-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKU\S-1-5-21-2559784832-2112059209-2043554392-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://bing.zugo.com/?cfg=2-76-0-HXl0
IE - HKU\S-1-5-21-2559784832-2112059209-2043554392-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-2559784832-2112059209-2043554392-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\IPSFFPlgn\ [2007/04/10 23:04:07 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\coFFPlgn_2010_9_0_6 [2012/02/21 16:51:34 | 000,000,000 | —D | M]


O1 HOSTS File: ([2006/09/18 15:41:30 | 000,000,761 | —- | M]) - C:\WINDOWS\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Security Suite\Engine\4.4.0.12\coieplg.dll (Symantec Corporation)
O2 - BHO: (flvpremier) - {6a8fb514-9724-e9b2-063c-3275bdee15f0} - C:\Windows\system32\4vQA9d-W-WQ_jN.dll File not found
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Security Suite\Engine\4.4.0.12\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Babylon IE plugin) - {9CFACCB6-2F3F-4177-94EA-0D2B72D384C1} - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll File not found
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\4.4.0.12\coieplg.dll (Symantec Corporation)
O3 - HKU\S-1-5-21-2559784832-2112059209-2043554392-1000\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
O3 - HKU\S-1-5-21-2559784832-2112059209-2043554392-1000\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\4.4.0.12\coieplg.dll (Symantec Corporation)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [ATICCC] c:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe ()
O4 - HKLM..\Run: [DPService] C:\Program Files\HP\DVDPlay\DPService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKLM..\RunOnce: [Launcher] C:\WINDOWS\SMINST\Launcher.exe (soft thinks)
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll/cmsidewiki.html File not found
O8 - Extra context menu item: Translate this web page with Babylon - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm File not found
O8 - Extra context menu item: Translate with Babylon - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Action.htm File not found
O9 - Extra Button: Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm File not found
O9 - Extra 'Tools' menuitem : Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm File not found
O13 - gopher Prefix: missing
O15 - HKU\.DEFAULT\..Trusted Ranges: Range1 ([http] in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Ranges: Range1 ([http] in Local intranet)
O15 - HKU\S-1-5-21-2559784832-2112059209-2043554392-1000\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.76.76 75.75.75.75
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F62C4470-9CA5-4842-A9E8-DDB9838C16BC}: DhcpNameServer = 75.75.76.76 75.75.75.75
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\WINDOWS\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Home\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Home\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 15:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/02/21 18:08:22 | 000,583,168 | —- | C] (OldTimer Tools) – C:\Users\Home\Desktop\OTL.exe
[2012/02/20 16:42:30 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\Home\Desktop\HiJackThis.exe
[2012/01/28 20:15:52 | 000,000,000 | —D | C] – C:\Program Files\Windows Portable Devices
[2012/01/28 17:15:29 | 000,000,000 | —D | C] – C:\Windows\System32\WindowsPowerShell
[2009/08/08 19:26:03 | 000,000,051 | —- | C] () – C:\ProgramData\lxdd
[2009/07/26 17:46:05 | 000,002,668 | —- | C] () – C:\Users\Home\AppData\Roaming\wklnhst.dat
[2009/07/26 17:37:20 | 000,012,800 | —- | C] () – C:\Users\Home\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/07/18 17:13:33 | 002,348,242 | -H– | C] () – C:\Users\Home\AppData\Local\IconCache.db
[2009/07/18 16:54:05 | 000,068,064 | —- | C] () – C:\Users\Home\AppData\Local\GDIPFONTCACHEV1.DAT
[2007/04/11 00:47:39 | 000,001,940 | —- | C] () – C:\Users\Home\AppData\Local\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[20 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[20 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/02/21 18:08:23 | 000,583,168 | —- | M] (OldTimer Tools) – C:\Users\Home\Desktop\OTL.exe
[2012/02/21 17:55:15 | 000,001,724 | -H– | M] () – C:\Users\Home\Documents\Default.rdp
[2012/02/21 17:17:50 | 000,001,597 | —- | M] () – C:\Users\Home\Desktop\Remote Desktop Connection.lnk
[2012/02/21 16:48:28 | 000,003,552 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/02/21 16:48:28 | 000,003,552 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/02/21 16:48:03 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/02/21 16:47:57 | 938,795,008 | -HS- | M] () – C:\hiberfil.sys
[2012/02/20 16:42:30 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Home\Desktop\HiJackThis.exe
[2012/02/19 13:52:30 | 000,000,810 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2012/02/17 20:49:53 | 000,000,949 | —- | M] () – C:\Users\Home\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/02/17 20:33:30 | 000,604,264 | —- | M] () – C:\Windows\System32\perfh009.dat
[2012/02/17 20:33:29 | 000,103,964 | —- | M] () – C:\Windows\System32\perfc009.dat
[2012/02/17 20:31:11 | 000,008,798 | —- | M] () – C:\Windows\System32\icrav03.rat
[2012/02/17 20:31:11 | 000,001,988 | —- | M] () – C:\Windows\System32\ticrf.rat
[2012/02/17 20:30:53 | 000,072,822 | —- | M] () – C:\Windows\System32\ieuinit.inf
[2012/02/17 20:05:12 | 000,281,488 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2012/01/28 20:12:53 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_User_WpdFs_01_07_00.Wdf
[20 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[20 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/02/21 17:17:50 | 000,001,597 | —- | C] () – C:\Users\Home\Desktop\Remote Desktop Connection.lnk
[2012/02/20 17:34:52 | 000,001,724 | -H– | C] () – C:\Users\Home\Documents\Default.rdp
[2012/02/17 20:30:53 | 000,072,822 | —- | C] () – C:\Windows\System32\ieuinit.inf
[2012/01/28 20:12:53 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_User_WpdFs_01_07_00.Wdf
[2012/01/28 17:29:05 | 000,001,804 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader 9.lnk
[2012/01/28 17:02:43 | 000,201,184 | —- | C] () – C:\Windows\System32\winrm.vbs
[2012/01/28 17:02:43 | 000,002,426 | —- | C] () – C:\Windows\System32\WsmTxt.xsl
[2012/01/28 17:02:42 | 000,004,675 | —- | C] () – C:\Windows\System32\wsmanconfig_schema.xml
[2010/11/24 16:21:26 | 000,000,047 | —- | C] () – C:\Windows\WinInit.Ini

========== LOP Check ==========

[2010/02/06 17:56:35 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\Babylon
[2007/04/10 23:27:55 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\Canon
[2010/02/17 14:10:04 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\DriverCure
[2009/08/11 17:56:34 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\Lexmark Productivity Studio
[2009/07/26 17:46:09 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\Template
[2010/02/17 18:48:18 | 000,000,348 | —- | M] () – C:\Windows\Tasks\File Helper.job
[2012/02/20 20:53:02 | 000,032,536 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: EXPLORER.EXE >
[2009/07/18 20:49:01 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE – C:\WINDOWS\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_4f83bb287ccdb7e3\explorer.exe
[2009/07/18 20:49:00 | 002,927,104 | —- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D – C:\WINDOWS\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_5177ca9879e978e8\explorer.exe
[2009/07/18 20:48:57 | 002,927,616 | —- | M] (Microsoft Corporation) MD5=50BA5850147410CDE89C523AD3BC606E – C:\WINDOWS\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_51e4f8c7931bd1e1\explorer.exe
[2009/07/18 22:02:58 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=6D06CD98D954FE87FB2DB8108793B399 – C:\WINDOWS\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16549_none_4fac29707cae347a\explorer.exe
[2009/07/18 22:02:56 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=BD06F0BF753BC704B653C3A50F89D362 – C:\WINDOWS\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20668_none_501f261995dcf2cf\explorer.exe
[2009/04/11 00:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 – C:\WINDOWS\explorer.exe
[2009/04/11 00:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 – C:\WINDOWS\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_53a0201e76de3a0b\explorer.exe
[2009/07/18 20:49:00 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=E7156B0B74762D9DE0E66BDCDE06E5FB – C:\WINDOWS\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_5033cb5995cd990b\explorer.exe
[2006/11/02 03:45:07 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=FD8C53FB002217F6F888BCF6F5D7084D – C:\WINDOWS\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16386_none_4f7de5167cd15deb\explorer.exe
[2008/01/19 01:33:10 | 002,927,104 | —- | M] (Microsoft Corporation) MD5=FFA764631CB70A30065C12EF8E174F9F – C:\WINDOWS\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_51b4a71279bc6ebf\explorer.exe

< MD5 for: SVCHOST.EXE >
[2006/11/02 03:45:47 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=10DA15933D582D2FEDCF705EFE394B09 – C:\WINDOWS\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.0.6000.16386_none_b38497a50862ad11\svchost.exe
[2008/01/19 01:33:32 | 000,021,504 | —- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF – C:\WINDOWS\System32\svchost.exe
[2008/01/19 01:33:32 | 000,021,504 | —- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF – C:\WINDOWS\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.0.6001.18000_none_b5bb59a1054dbde5\svchost.exe

< MD5 for: USERINIT.EXE >
[2008/01/19 01:33:33 | 000,025,088 | —- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 – C:\WINDOWS\System32\userinit.exe
[2008/01/19 01:33:33 | 000,025,088 | —- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 – C:\WINDOWS\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
[2006/11/02 03:45:50 | 000,024,576 | —- | M] (Microsoft Corporation) MD5=22027835939F86C3E47AD8E3FBDE3D11 – C:\WINDOWS\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6000.16386_none_d9f1f819d4c4e737\userinit.exe

< MD5 for: WINLOGON.EXE >
[2009/04/11 00:28:13 | 000,314,368 | —- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 – C:\WINDOWS\System32\winlogon.exe
[2009/04/11 00:28:13 | 000,314,368 | —- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 – C:\WINDOWS\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2006/11/02 03:45:57 | 000,308,224 | —- | M] (Microsoft Corporation) MD5=9F75392B9128A91ABAFB044EA350BAAD – C:\WINDOWS\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6000.16386_none_6d8c3f1ad8066b21\winlogon.exe
[2008/01/19 01:33:37 | 000,314,880 | —- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 – C:\WINDOWS\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe

< %systemroot%\*. /rp /s >

========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
[C:\Windows\System32\config\systemprofile\AppData\Local\History] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History -> Junction
[C:\Windows\System32\config\systemprofile\AppData\Local\Temporary Internet Files] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files -> Junction
[C:\Windows\System32\config\systemprofile\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Roaming -> Junction
[C:\Windows\System32\config\systemprofile\Cookies] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies -> Junction
[C:\Windows\System32\config\systemprofile\Local Settings] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction

========== Alternate Data Streams ==========

@Alternate Data Stream - 95 bytes -> C:\ProgramData\TEMP:5C321E34
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:DFC5A2B2
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:D1B5B4F1
@Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:A8ADE5D8

< End of report >

OTL Extras logfile created on: 2/21/2012 6:14:39 PM - Run 1
OTL by OldTimer - Version 3.2.33.1 Folder = C:\Users\Home\Desktop
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

894.58 Mb Total Physical Memory | 440.05 Mb Available Physical Memory | 49.19% Memory free
2.01 Gb Paging File | 1.30 Gb Available in Paging File | 64.69% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 48.83 Gb Total Space | 19.51 Gb Free Space | 39.95% Space Free | Partition Type: NTFS
Drive D: | 5.76 Gb Total Space | 0.86 Gb Free Space | 15.02% Space Free | Partition Type: NTFS
Drive E: | 9.77 Gb Total Space | 9.26 Gb Free Space | 94.79% Space Free | Partition Type: NTFS

Computer Name: HOME-PC | User Name: Home | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 0
"InternetSettingsDisableNotify" = 0
"AutoUpdateDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" = C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{03DE18A1-593E-47EA-A26D-562F9516BE4D}" = protocol=6 | dir=in | app=c:\windows\system32\lxddcoms.exe |
"{0A46C421-359B-4BF9-B3CD-5A10F4F57E73}" = protocol=6 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{164FAEC6-309E-4171-9811-92635192280A}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxddpswx.exe |
"{1DAFEC76-4F1D-4FC8-A31C-924C7CE9FF03}" = protocol=17 | dir=in | app=c:\program files\compaq connections\3572475\program\compaq connections.exe |
"{23DC91C9-5AF8-45A5-B3EB-F97C9D530A2C}" = protocol=6 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{2E530B70-3235-4BA4-8F69-B338D8F72B42}" = protocol=17 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{39A95D51-DEF4-49FE-9B5F-847D327A8BA6}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxddjswx.exe |
"{4690E3ED-B7F8-411A-9287-DA6B401B0F9C}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxddjswx.exe |
"{5794892D-4A6F-451C-B58D-0A2FAB71EB88}" = protocol=6 | dir=in | app=c:\program files\compaq connections\3572475\program\compaq connections.exe |
"{5C03BB82-E667-40D5-AC32-7D5FF407CFF7}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxddpswx.exe |
"{5FC5C9F3-A6BE-4598-91A9-A19E83F39339}" = protocol=6 | dir=in | app=c:\program files\lexmark 2500 series\lxddmon.exe |
"{6E68C077-86DD-465D-ADEB-134119C2FC52}" = protocol=17 | dir=in | app=c:\windows\system32\lxddcoms.exe |
"{72905238-D965-4E85-9DBB-FC160383E6E1}" = protocol=17 | dir=in | app=c:\program files\compaq connections\3572475\program\compaq connections.exe |
"{739353C4-F189-47E1-ACF2-DDD5FF5E659D}" = protocol=17 | dir=in | app=c:\program files\lexmark 2500 series\lxddamon.exe |
"{7B40135B-1D13-400E-9CE7-0DBB5E000912}" = protocol=6 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{875FA7AC-AB29-48F3-A1A7-BCFD277B9097}" = protocol=6 | dir=in | app=c:\program files\bearshare applications\bearshare\bearshare.exe |
"{8D91F772-F3F1-4F42-BC82-AE4DCE628B63}" = protocol=6 | dir=in | app=c:\program files\lexmark 2500 series\lxddamon.exe |
"{8F292366-BA27-49AE-970C-DC11B0A40B4B}" = protocol=6 | dir=in | app=c:\program files\bearshare applications\bearshare\bearshare.exe |
"{98334664-5E50-4117-A656-3DAA501DF095}" = protocol=17 | dir=in | app=c:\program files\lexmark 2500 series\lxddmon.exe |
"{A2A36AA0-DF41-41D9-917F-3AFC3F3E029B}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxddtime.exe |
"{A8819E7E-D8DA-485A-B035-B4C9A2872E08}" = protocol=6 | dir=in | app=c:\program files\compaq connections\3572475\program\compaq connections.exe |
"{AFB9DC65-EB61-4F74-8AEA-4C5D242B9516}" = protocol=17 | dir=in | app=c:\program files\bearshare applications\bearshare\bearshare.exe |
"{B5194E6A-3F93-4F1E-8FDB-A4023B1B8C7F}" = protocol=17 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{CAD53C50-E8AC-4AB4-8B0E-A8F66046FE5C}" = protocol=17 | dir=in | app=c:\program files\bearshare applications\bearshare\bearshare.exe |
"{D512736F-2361-47AB-BE60-871265EC0A8C}" = protocol=6 | dir=in | app=c:\program files\lexmark 2500 series\app4r.exe |
"{DC385B58-D3FE-4667-9C95-F9198EB32121}" = protocol=17 | dir=in | app=c:\program files\compaq connections\3572475\program\compaq connections.exe |
"{E4D84204-D926-4B37-B7C5-5BD0D49A3374}" = protocol=6 | dir=in | app=c:\program files\compaq connections\3572475\program\compaq connections.exe |
"{F7F491F0-7C13-43DD-AE50-949341B915EA}" = dir=in | app=c:\program files\compaq connections\3572475\program\compaq connections |
"{F9226024-F20D-4703-BC0F-E012C8098DA9}" = protocol=17 | dir=in | app=c:\program files\lexmark 2500 series\app4r.exe |
"{FA4CE0FE-C296-4417-8CA2-1B19A11DE46B}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxddtime.exe |
"{FF36F8D6-9327-4C9F-9F25-4C48319C773E}" = protocol=17 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"TCP Query User{C5F4792C-B075-4F1C-BD5C-43B31F7C07A8}C:\program files\bearshare applications\bearshare\bearshare.exe" = protocol=6 | dir=in | app=c:\program files\bearshare applications\bearshare\bearshare.exe |
"UDP Query User{43774776-3DDC-4043-A81D-2A843753766C}C:\program files\bearshare applications\bearshare\bearshare.exe" = protocol=17 | dir=in | app=c:\program files\bearshare applications\bearshare\bearshare.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{0373779B-A362-4B2E-B8E9-7442F19F9394}" = HP Total Care Advisor
"{0394CDC8-FABD-4ed8-B104-03393876DFDF}" = Roxio Creator Tools
"{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}" = Windows Live ID Sign-in Assistant
"{0D397393-9B50-4c52-84D5-77E344289F87}" = Roxio Creator Data
"{11F93B4B-48F0-4A4E-AE77-DFA96A99664B}" = Roxio Creator EasyArchive
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 22
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{40F7AED3-0C7D-4582-99F6-484A515C73F2}" = HP Easy Setup - Frontend
"{4160DC5B-4C56-D0C3-C5FD-F5BDAD3C882B}" = ATI Catalyst Install Manager
"{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = DVD Play
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}" = Roxio Creator Copy
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{6D8D64BE-F500-55B6-705D-DFD08AFE0624}" = Acrobat.com
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{75E71ADD-042C-4F30-BFAC-A9EC42351313}" = Python 2.4.3
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{83FFCFC7-88C6-41c6-8752-958A45325C82}" = Roxio Creator Audio
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C6027FD-53DC-446D-BB75-CACD7028A134}" = HP Update
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9DBA770F-BF73-4D39-B1DF-6035D95268FC}" = HP Customer Feedback
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{AB5E289E-76BF-4251-9F3F-9B763F681AE0}" = HP Customer Experience Enhancements
"{AC76BA86-7AD7-1033-7B44-A95000000001}" = Adobe Reader 9.5.0
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}" = Roxio Creator Basic v9
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D8ED8FEC-0FAA-F0C2-0008-7830DE40AF86}" = ATI Catalyst Control Center Ex
"{E1180142-3B31-4DCC-9D27-7AC2D37662BF}" = LightScribe 1.4.124.1
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F94234DB-FD06-42C3-B88D-6FC4DC9F988C}" = HP Easy Setup - Core
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"CCleaner" = CCleaner
"CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200C14F1" = Soft Data Fax Modem with SmartCP
"HPOOVClient-3572475 Uninstaller" = Compaq Connections (remove only)
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"N360" = Norton Security Suite
"PC-Doctor 5 for Windows" = Hardware Diagnostic Tools
"Secunia PSI" = Secunia PSI
"SpywareBlaster_is1" = SpywareBlaster 4.4
"WildTangent hpdesktop Master Uninstall" = My HP Games

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 1/28/2012 9:09:12 PM | Computer Name = Home-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Program Files\Hewlett-Packard\HP
Advisor\SecurityStatusServer.dll". Dependent Assembly Microsoft.VC90.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.30729.4148"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 4/11/2007 1:10:38 AM | Computer Name = Home-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 4/11/2007 1:10:46 AM | Computer Name = Home-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 4/11/2007 1:11:07 AM | Computer Name = Home-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 4/11/2007 1:11:08 AM | Computer Name = Home-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 4/11/2007 1:11:23 AM | Computer Name = Home-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 4/11/2007 1:11:23 AM | Computer Name = Home-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 4/11/2007 1:11:26 AM | Computer Name = Home-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 4/11/2007 1:11:27 AM | Computer Name = Home-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 4/11/2007 1:11:32 AM | Computer Name = Home-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

[ System Events ]
Error - 2/16/2012 7:05:28 PM | Computer Name = Home-PC | Source = Service Control Manager | ID = 7011
Description =

Error - 2/16/2012 7:05:30 PM | Computer Name = Home-PC | Source = Service Control Manager | ID = 7011
Description =

Error - 2/16/2012 7:05:30 PM | Computer Name = Home-PC | Source = Service Control Manager | ID = 7011
Description =

Error - 2/16/2012 7:05:30 PM | Computer Name = Home-PC | Source = Service Control Manager | ID = 7011
Description =

Error - 2/17/2012 8:28:51 PM | Computer Name = Home-PC | Source = Service Control Manager | ID = 7022
Description =

Error - 2/17/2012 8:57:26 PM | Computer Name = Home-PC | Source = Service Control Manager | ID = 7011
Description =

Error - 2/17/2012 10:49:40 PM | Computer Name = Home-PC | Source = Service Control Manager | ID = 7009
Description =

Error - 2/20/2012 6:09:21 PM | Computer Name = Home-PC | Source = netbt | ID = 4321
Description = The name "WORKGROUP :1d" could not be registered on the interface
with IP address 192.168.1.103. The computer with the IP address 192.168.1.100 did
not allow the name to be claimed by this computer.

Error - 2/20/2012 6:17:37 PM | Computer Name = Home-PC | Source = Service Control Manager | ID = 7031
Description =

Error - 2/20/2012 8:22:29 PM | Computer Name = Home-PC | Source = Service Control Manager | ID = 7011
Description =


< End of report >

aswMBR version 0.9.9.1649 Copyright© 2011 AVAST Software
Run date: 2012-02-21 18:37:06
—————————–
18:37:06.432 OS Version: Windows 6.0.6002 Service Pack 2
18:37:06.432 Number of processors: 1 586 0x605
18:37:06.432 ComputerName: HOME-PC UserName: Home
18:37:13.670 Initialize success
18:38:08.270 AVAST engine defs: 12022101
18:39:16.494 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
18:39:16.494 Disk 0 Vendor: ST3120213AS 3.AHL Size: 114473MB BusType: 3
18:39:16.525 Disk 0 MBR read successfully
18:39:16.525 Disk 0 MBR scan
18:39:16.619 Disk 0 unknown MBR code
18:39:16.634 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 49999 MB offset 63
18:39:16.728 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 10001 MB offset 102400000
18:39:16.822 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 5895 MB offset 222363648
18:39:16.853 Disk 0 scanning sectors +234436608
18:39:17.071 Disk 0 scanning C:\Windows\system32\drivers
18:39:43.872 Service scanning
18:40:46.288 Modules scanning
18:41:05.663 Disk 0 trace - called modules:
18:41:05.710 ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll ataport.SYS pciide.sys PCIIDEX.SYS atapi.sys dxgkrnl.sys atikmdag.sys watchdog.sys tcpip.sys NETIO.SYS RTKVHDA.sys
18:41:05.725 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8466a670]
18:41:05.725 3 CLASSPNP.SYS[82ba18b3] -> nt!IofCallDriver -> [0x8468f918]
18:41:05.741 5 acpi.sys[806966bc] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0x8465eb98]
18:41:06.630 AVAST engine scan C:\Windows
18:41:10.249 AVAST engine scan C:\Windows\system32
18:46:27.460 AVAST engine scan C:\Windows\system32\drivers
18:46:50.251 AVAST engine scan C:\Users\Home
18:48:22.978 AVAST engine scan C:\ProgramData
18:50:25.360 Scan finished successfully
18:50:53.424 Disk 0 MBR has been saved successfully to "C:\Users\Home\Desktop\MBR.dat"
18:50:53.440 The log file has been saved successfully to "C:\Users\Home\Desktop\aswMBR.txt"
  • ComboFix


    Refer to the ComboFix User's Guide

  • Download ComboFix from one of these locations:

    Link 1
    Link 2

    * IMPORTANT !!! Place ComboFix.exe on your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with ComboFix.
    You can get help on disabling your protection programs here
  • Double click on ComboFix.exe & follow the prompts.
  • Your desktop may go blank. This is normal. It will return when ComboFix is done. ComboFix may reboot your machine. This is normal.
  • When finished, it shall produce a log for you. Post that log in your next reply

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.


    ———————————————————————————————
  • Ensure your AntiVirus and AntiSpyware applications are re-enabled.

    ———————————————————————————————

NOTE: If you encounter a message "illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error.
Hi Mrp, below is my combo log - thanks

ComboFix 12-02-22.01 - Home 02/22/2012 18:46:31.1.1 - x86
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.1.1033.18.895.372 [GMT -6:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: Norton Security Suite *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
FW: Norton Security Suite *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
SP: Norton Security Suite *Disabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\FunWebProducts
c:\program files\FunWebProducts\Installr\4.bin\F3EZSETP.DLL
c:\programdata\SPL1E03.tmp
c:\programdata\SPL22EA.tmp
c:\programdata\SPL2C92.tmp
c:\programdata\SPL339D.tmp
c:\programdata\SPL3504.tmp
c:\programdata\SPL364B.tmp
c:\programdata\SPL3D5D.tmp
c:\programdata\SPL40A8.tmp
c:\programdata\SPL676A.tmp
c:\programdata\SPL6EA1.tmp
c:\programdata\SPL7FDC.tmp
c:\programdata\SPL845D.tmp
c:\programdata\SPL97CB.tmp
c:\programdata\SPLBED6.tmp
c:\programdata\SPLD4DB.tmp
c:\programdata\SPLE591.tmp
c:\programdata\SPLEBEA.tmp
c:\programdata\SPLF072.tmp
c:\programdata\SPLF91D.tmp
c:\programdata\SPLFA6.tmp
c:\windows\HPCPCUninstaller-6.3.2.139-3572475.exe
.
.
((((((((((((((((((((((((( Files Created from 2012-01-23 to 2012-02-23 )))))))))))))))))))))))))))))))
.
.
2012-02-23 00:57 . 2012-02-23 00:58 ——– d—–w- c:\users\Home\AppData\Local\temp
2012-02-23 00:57 . 2012-02-23 00:57 ——– d—–w- c:\users\Default\AppData\Local\temp
2012-02-19 19:42 . 2012-01-17 10:39 6557240 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{0AC3C082-5DE5-436A-A14B-55CD2F8BE4F9}\mpengine.dll
2012-02-18 01:37 . 2011-12-14 16:17 680448 —-a-w- c:\windows\system32\msvcrt.dll
2012-02-18 01:37 . 2012-01-12 19:52 2044416 —-a-w- c:\windows\system32\win32k.sys
2012-02-18 01:37 . 2011-12-20 10:56 2409784 —-a-w- c:\program files\Windows Mail\OESpamFilter.dat
2012-02-16 22:48 . 2012-02-16 22:48 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-02-05 21:41 . 2011-03-12 21:55 876032 —-a-w- c:\windows\system32\XpsPrint.dll
2012-01-29 02:15 . 2012-01-29 02:15 ——– d—–w- c:\program files\Windows Portable Devices
2012-01-29 01:36 . 2009-09-10 02:00 92672 —-a-w- c:\windows\system32\UIAnimation.dll
2012-01-29 01:36 . 2009-09-10 02:00 1164800 —-a-w- c:\windows\system32\UIRibbonRes.dll
2012-01-29 01:36 . 2009-09-10 02:01 3023360 —-a-w- c:\windows\system32\UIRibbon.dll
2012-01-29 01:34 . 2009-09-25 01:33 369664 —-a-w- c:\windows\system32\WMPhoto.dll
2012-01-29 01:34 . 2009-09-25 02:07 189440 —-a-w- c:\windows\system32\WindowsCodecsExt.dll
2012-01-29 01:34 . 2009-09-25 02:10 974848 —-a-w- c:\windows\system32\WindowsCodecs.dll
2012-01-29 01:34 . 2009-09-25 02:04 321024 —-a-w- c:\windows\system32\PhotoMetadataHandler.dll
2012-01-29 01:34 . 2009-09-25 01:33 195584 —-a-w- c:\windows\system32\dxdiagn.dll
2012-01-29 01:34 . 2009-09-25 01:32 252928 —-a-w- c:\windows\system32\dxdiag.exe
2012-01-29 01:34 . 2009-09-25 01:31 519680 —-a-w- c:\windows\system32\d3d11.dll
2012-01-28 23:05 . 2009-10-09 21:56 2048 —-a-w- c:\windows\system32\winrsmgr.dll
2012-01-28 23:03 . 2009-10-09 21:56 12800 —-a-w- c:\windows\system32\wsmprovhost.exe
2012-01-28 23:03 . 2009-10-09 21:56 20480 —-a-w- c:\windows\system32\winrshost.exe
2012-01-28 23:03 . 2009-10-09 21:56 40448 —-a-w- c:\windows\system32\winrs.exe
2012-01-28 23:03 . 2009-10-09 21:56 10240 —-a-w- c:\windows\system32\wsmplpxy.dll
2012-01-28 23:03 . 2009-10-09 21:56 10240 —-a-w- c:\windows\system32\winrssrv.dll
2012-01-28 23:03 . 2009-10-09 21:55 79872 —-a-w- c:\windows\system32\wecutil.exe
2012-01-28 23:03 . 2009-10-09 21:55 81408 —-a-w- c:\windows\system32\wevtfwd.dll
2012-01-28 23:03 . 2009-10-09 21:55 56320 —-a-w- c:\windows\system32\wecapi.dll
2012-01-28 23:03 . 2009-10-09 21:55 54272 —-a-w- c:\windows\system32\WsmRes.dll
2012-01-28 23:03 . 2009-10-09 21:55 146944 —-a-w- c:\windows\system32\wecsvc.dll
2012-01-28 23:03 . 2009-10-09 21:56 41472 —-a-w- c:\windows\system32\pwrshplugin.dll
2012-01-28 23:02 . 2009-08-01 06:27 201184 —-a-w- c:\windows\system32\winrm.vbs
2012-01-28 23:02 . 2009-10-09 21:56 214016 —-a-w- c:\windows\system32\WsmWmiPl.dll
2012-01-28 23:02 . 2009-10-09 21:56 241152 —-a-w- c:\windows\system32\winrscmd.dll
2012-01-28 23:02 . 2009-10-09 21:56 145408 —-a-w- c:\windows\system32\WsmAuto.dll
2012-01-28 23:02 . 2009-10-09 21:55 252416 —-a-w- c:\windows\system32\WSManMigrationPlugin.dll
2012-01-28 23:02 . 2009-10-09 21:56 246272 —-a-w- c:\windows\system32\WSManHTTPConfig.exe
2012-01-28 23:02 . 2009-10-09 21:56 1181696 —-a-w- c:\windows\system32\WsmSvc.dll
2012-01-27 23:46 . 2011-11-18 17:47 66560 —-a-w- c:\windows\system32\packager.dll
2012-01-27 23:46 . 2010-10-12 13:41 515584 —-a-w- c:\program files\Windows Mail\wab.exe
2012-01-27 23:46 . 2010-10-12 15:53 33280 —-a-w- c:\program files\Windows Mail\wabfind.dll
2012-01-27 23:46 . 2010-10-12 13:41 66048 —-a-w- c:\program files\Windows Mail\wabmig.exe
2012-01-27 23:44 . 2011-03-10 17:03 1162240 —-a-w- c:\windows\system32\mfc42u.dll
2012-01-27 23:43 . 2011-03-02 15:44 86528 —-a-w- c:\windows\system32\dnsrslvr.dll
2012-01-27 23:43 . 2009-05-04 09:59 25088 —-a-w- c:\windows\system32\dnscacheugc.exe
2012-01-27 23:43 . 2011-10-14 16:02 429056 —-a-w- c:\windows\system32\EncDec.dll
2012-01-27 23:43 . 2011-04-21 13:58 273408 —-a-w- c:\windows\system32\drivers\afd.sys
2012-01-27 23:41 . 2011-11-25 15:59 376320 —-a-w- c:\windows\system32\winsrv.dll
2012-01-27 23:41 . 2011-03-03 15:40 28672 —-a-w- c:\windows\system32\Apphlpdm.dll
2012-01-27 23:41 . 2011-03-03 13:35 4240384 —-a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2012-01-27 23:36 . 2010-12-29 18:28 322560 —-a-w- c:\windows\system32\sbe.dll
2012-01-27 23:36 . 2010-12-29 18:28 153088 —-a-w- c:\windows\system32\sbeio.dll
2012-01-27 23:36 . 2010-12-29 18:26 177664 —-a-w- c:\windows\system32\mpg2splt.ax
2012-01-27 23:36 . 2011-09-20 21:02 905088 —-a-w- c:\windows\system32\drivers\tcpip.sys
2012-01-27 23:35 . 2010-11-04 18:55 601600 —-a-w- c:\windows\system32\schedsvc.dll
2012-01-27 23:35 . 2010-11-04 18:55 352768 —-a-w- c:\windows\system32\taskschd.dll
2012-01-27 23:35 . 2010-11-04 18:56 345600 —-a-w- c:\windows\system32\wmicmiplugin.dll
2012-01-27 23:35 . 2010-11-04 18:55 270336 —-a-w- c:\windows\system32\taskcomp.dll
2012-01-27 23:35 . 2010-11-04 16:34 171520 —-a-w- c:\windows\system32\taskeng.exe
2012-01-27 23:35 . 2011-05-02 17:16 739328 —-a-w- c:\windows\system32\inetcomm.dll
2012-01-27 23:35 . 2010-10-18 13:37 81920 —-a-w- c:\windows\system32\consent.exe
2012-01-27 23:35 . 2011-10-25 15:56 49152 —-a-w- c:\windows\system32\csrsrv.dll
2012-01-27 23:35 . 2011-10-25 15:58 1314816 —-a-w- c:\windows\system32\quartz.dll
2012-01-27 23:35 . 2011-10-25 15:58 497152 —-a-w- c:\windows\system32\qdvd.dll
2012-01-27 23:34 . 2011-11-08 14:42 2048 —-a-w- c:\windows\system32\tzres.dll
2012-01-27 23:34 . 2011-08-25 16:15 555520 —-a-w- c:\windows\system32\UIAutomationCore.dll
2012-01-27 23:34 . 2011-08-25 13:31 4096 —-a-w- c:\windows\system32\oleaccrc.dll
2012-01-27 23:34 . 2011-08-25 16:14 563712 —-a-w- c:\windows\system32\oleaut32.dll
2012-01-27 23:34 . 2011-08-25 16:14 238080 —-a-w- c:\windows\system32\oleacc.dll
2012-01-27 23:33 . 2011-09-30 15:57 707584 —-a-w- c:\program files\Common Files\System\wab32.dll
2012-01-27 22:27 . 2010-05-04 19:13 231424 —-a-w- c:\windows\system32\msshsq.dll
2012-01-27 21:37 . 2010-12-17 15:45 2067968 —-a-w- c:\windows\system32\mstscax.dll
2012-01-27 21:37 . 2010-12-17 13:54 677888 —-a-w- c:\windows\system32\mstsc.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-01-29 11:10 . 2009-10-03 17:21 237072 ——w- c:\windows\system32\MpSigStub.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2005-02-17 221184]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2006-09-28 65536]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-07-12 90112]
"RtHDVCpl"="RtHDVCpl.exe" [2006-11-09 3784704]
"DPService"="c:\program files\HP\DVDPlay\DPService.exe" [2006-11-08 81920]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-02-17 49152]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-01-04 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-02 843712]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="c:\windows\SMINST\launcher.exe" [2006-11-25 44136]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2008-01-19 07:38 1008184 —-a-w- c:\program files\Windows Defender\MSASCui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
.
2010-02-18 c:\windows\Tasks\File Helper.job
- c:\program files\File Helper\1.2.0.1\FileHelper.exe [2010-02-17 20:34]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=71&bd=Presario&pf=desktop
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll/cmsidewiki.html
IE: Translate this web page with Babylon - c:\program files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm
IE: Translate with Babylon - c:\program files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Action.htm
TCP: DhcpNameServer = 75.75.76.76 75.75.75.75
.
- - - - ORPHANS REMOVED - - - -.
BHO-{6a8fb514-9724-e9b2-063c-3275bdee15f0} - c:\windows\system32\4vQA9d-W-WQ_jN.dll
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
SafeBoot-mcmscsvc
SafeBoot-MCODS
MSConfigStartUp-Babylon Client - c:\program files\Babylon\Babylon-Pro\Babylon.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-02-22 18:58
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\N360]
"ImagePath"="\"c:\program files\Norton Security Suite\Engine\4.4.0.12\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton Security Suite\Engine\4.4.0.12\diMaster.dll\" /prefetch:1"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2012-02-22 19:04:24
ComboFix-quarantined-files.txt 2012-02-23 01:04
.
Pre-Run: 22,242,754,560 bytes free
Post-Run: 22,259,773,440 bytes free
.
- - End Of File - - AAF49455DE81658D1C220A93D2297404
Hi denisemn,

Do you recognize the program named "File Helper" on this machine?

  • Malwarebytes' Anti-Malware

    Download Malwarebytes' Anti-Malware to your desktop.

    • Double-click mbam-setup.exe and follow the prompts to install the program.
    • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    • If an update is found, it will download and install the latest version.
    • Once the program has loaded, select Perform quick scan, then click Scan.
    • When the scan is complete, click OK, then Show Results to view the results.
    • Be sure that everything is checked, and click Remove Selected.
    • When completed, a log will open in Notepad. This log is saved by MBAM and can be viewed by clicking the Logs tab.
    • Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.
    • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
  • ESET Online Scanner

    Please disable any real-time security programs such as your anti-virus before proceeding with this scan.

    • Open Internet Explorer.
    • Download ESET Online Scanner.
    • Put a checkmark in the checkbox next to YES, I accept the Terms of Use.
    • Click Start.
    • When prompted by your web browser, click Install.
    • Uncheck Remove found threats.
    • Check Scan archives.
    • Click Start and let the scanner finish downloading virus signatures. The scan will begin afterward.
    • When the scan completes, click List of found threats.
    • Click Export to text file… and save the file to your desktop.
    • Click Back.
    • Click Finish.
Hi mrb, I have no idea what the 'File Helper ' is. It says it is from Blitware Technolgies. One concern I have is my norton program; I thought I had disabled everything on it, but it popped up during the Eset scan that it was performing tasks in the background. I had stepped away from the pc so I am not certain if it was during or after the scan. Malwarebytes Anti-Malware 1.60.1.1000 www.malwarebytes.org Database version: v2012.02.23.04 Windows Vista Service Pack 2 x86 NTFS Internet Explorer 9.0.8112.16421 Home :: HOME-PC [administrator] 2/23/2012 5:08:36 PM mbam-log-2012-02-23 (17-08-36).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 168568 Time elapsed: 8 minute(s), 34 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 3 HKCR\Typelib\{D518921A-4A03-425E-9873-B9A71756821E} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKCR\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully. Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) C:\Qoobox\Quarantine\C\Program Files\FunWebProducts\Installr\4.bin\F3EZSETP.DLL.vir a variant of Win32/FunWeb.AA application
Let's update a few programs that are known for their security vulnerabilities. It is important these programs be kept up-to-date for your safety.

  • Java is out of date

    Java™ 6 Update 22 can be updated from the Java control panel. Start > Control Panel (Classic View) > Java (looks like a coffee cup) > Update Tab > Update Now.
    An update should begin. You may be prompted to close the Java control panel before updating; do so.

    Clear Java cache

    Go into the Control Panel and double-click the Java icon (looks like a coffee cup). If you do not see the icon, switch to Classic View.

    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - Leave BOTH Checked
      • Applications and Applets
      • Trace and Log Files
    • Click OK on Delete Temporary Files Window
      Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
    • Click OK to leave the Temporary Files Window
    • You may now close the Java control panel.
  • Adobe Reader is out of date

    The latest version of Adobe Reader can be downloaded here.

How is your computer running? Are there any outstanding issues?
Hi mrp, There is a slight improvement in the start up time, down to about 5 minutes now. But the response time on the internet is good. I think the new battery, additional memory and clean up will work for my mom as she doesn’t do a lot on the internet. It is certainly an improvement over her 8 year old 30 GB laptop. Thanks so much for all your time. Denise
No problem. :thumbup: There are a few things left to do, so bear with me.

  • OTL

    Run OTL.exe. Make sure all other windows are closed and to let it run uninterrupted.

  • Select All Users
  • Under the Custom Scan box paste this in
    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    /md5stop
    %systemroot%\*. /rp /s
    CREATERESTOREPOINT
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan won't take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Post both logs
Oops. I brought the PC to my moms thinking all was good to go. I'll need to go pick up as she is on a dial up and the amount of time it takes .. well I could cook a full turkey dinner on that method. I won't be able to get it back until Thursday or Friday this week. Will it be okay to leave this open until at least until I can get back to you?
Hi Mrp,

I re-down loaded OTL as I had already deleted it. I am a little concerned that the scan only generated the .txt log.
I can re-run it if you feel it is needed. Let me know and I will re-do.

==================================================================
OTL logfile created on: 3/1/2012 4:49:10 PM - Run 2
OTL by OldTimer - Version 3.2.34.0 Folder = C:\Users\Home\Desktop
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

894.58 Mb Total Physical Memory | 383.03 Mb Available Physical Memory | 42.82% Memory free
2.01 Gb Paging File | 1.26 Gb Available in Paging File | 63.01% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 48.83 Gb Total Space | 20.44 Gb Free Space | 41.85% Space Free | Partition Type: NTFS
Drive D: | 5.76 Gb Total Space | 0.87 Gb Free Space | 15.03% Space Free | Partition Type: NTFS
Drive E: | 9.77 Gb Total Space | 9.26 Gb Free Space | 94.79% Space Free | Partition Type: NTFS

Computer Name: HOME-PC | User Name: Home | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/03/01 16:46:26 | 000,584,704 | —- | M] (OldTimer Tools) – C:\Users\Home\Desktop\OTL.exe
PRC - [2012/02/24 16:59:48 | 000,909,152 | —- | M] () – C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\10.0.6\ToolbarUpdater.exe
PRC - [2012/02/24 16:59:47 | 000,939,872 | —- | M] () – C:\Program Files\AVG Secure Search\vprot.exe
PRC - [2012/01/24 17:24:26 | 002,416,480 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG2012\avgtray.exe
PRC - [2012/01/03 07:10:42 | 000,063,928 | —- | M] (Adobe Systems Incorporated) – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011/11/28 01:19:04 | 001,229,664 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG2012\avgnsx.exe
PRC - [2011/10/12 06:25:22 | 004,433,248 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
PRC - [2011/10/10 06:23:34 | 000,973,664 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG2012\avgemcx.exe
PRC - [2011/09/08 20:53:26 | 000,743,264 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG2012\avgrsx.exe
PRC - [2011/08/15 06:21:40 | 000,337,760 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG2012\avgcsrvx.exe
PRC - [2011/08/02 06:09:08 | 000,192,776 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG2012\avgwdsvc.exe
PRC - [2009/04/11 00:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2008/01/19 01:33:23 | 000,020,480 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\RacAgent.exe
PRC - [2006/11/09 04:57:52 | 003,784,704 | —- | M] (Realtek Semiconductor) – C:\WINDOWS\RtHDVCpl.exe
PRC - [2006/09/28 07:42:24 | 000,065,536 | —- | M] (Hewlett-Packard Company) – C:\hp\support\hpsysdrv.exe
PRC - [2006/04/28 11:14:44 | 000,045,056 | —- | M] (ATI Technologies Inc.) – c:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
PRC - [2006/04/28 11:14:44 | 000,045,056 | —- | M] (ATI Technologies Inc.) – C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe


========== Modules (No Company Name) ==========

MOD - [2012/02/24 16:59:47 | 000,939,872 | —- | M] () – C:\Program Files\AVG Secure Search\vprot.exe
MOD - [2012/02/20 16:18:06 | 000,998,400 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\8b5f54e3b382fc1720c76557ef8c8bc3\System.Management.ni.dll
MOD - [2012/02/20 16:14:21 | 011,820,032 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\2598077ccea480c6120d3a1ad4455be0\System.Web.ni.dll
MOD - [2012/02/18 13:01:11 | 000,771,584 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\5c3bfd69e0c268baff0d169e11a6a784\System.Runtime.Remoting.ni.dll
MOD - [2012/02/18 12:49:31 | 000,971,264 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\7fd6c62196829d1e2dce5a253145d51a\System.Configuration.ni.dll
MOD - [2012/02/17 20:19:20 | 005,450,752 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\f4c98b14c32dde050bcf79b7e6c5e8e3\System.Xml.ni.dll
MOD - [2012/02/17 20:17:47 | 012,430,848 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\65450889f3742aada2a6c0cf8e6173e3\System.Windows.Forms.ni.dll
MOD - [2012/02/17 20:17:22 | 001,587,200 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\137696d0416b65dbc1561152971488b4\System.Drawing.ni.dll
MOD - [2012/02/17 20:09:12 | 007,953,408 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System\c50133cb67d7c013fa31e1ffb942060b\System.ni.dll
MOD - [2007/06/13 18:18:54 | 000,159,744 | —- | M] () – C:\WINDOWS\System32\atitmmxx.dll
MOD - [2007/04/11 00:12:58 | 011,490,816 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\b6632a8b2f276a8e31f5b0f6b2006cd1\mscorlib.ni.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Auto | Stopped] – – (CLTNetCnService)
SRV - [2012/02/24 16:59:48 | 000,909,152 | —- | M] () [Auto | Running] – C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\10.0.6\ToolbarUpdater.exe – (vToolbarUpdater)
SRV - [2012/01/03 07:10:42 | 000,063,928 | —- | M] (Adobe Systems Incorporated) [Auto | Running] – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe – (AdobeARMservice)
SRV - [2011/10/12 06:25:22 | 004,433,248 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe – (AVGIDSAgent)
SRV - [2011/08/02 06:09:08 | 000,192,776 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files\AVG\AVG2012\avgwdsvc.exe – (avgwd)
SRV - [2009/07/14 13:36:00 | 000,066,056 | —- | M] (NOS Microsystems Ltd.) [On_Demand | Stopped] – C:\Program Files\NOS\bin\getPlus_HelperSvc.exe – (getPlus® Helper) getPlus®
SRV - [2008/01/19 01:38:24 | 000,272,952 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)


========== Driver Services (SafeList) ==========

DRV - [2011/10/07 06:23:48 | 000,230,608 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\WINDOWS\System32\drivers\avgldx86.sys – (Avgldx86)
DRV - [2011/10/04 06:21:16 | 000,016,720 | —- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\drivers\AVGIDSShim.sys – (AVGIDSShim)
DRV - [2011/09/13 06:30:10 | 000,032,592 | —- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] – C:\Windows\system32\DRIVERS\avgrkx86.sys – (Avgrkx86)
DRV - [2011/08/08 06:08:58 | 000,040,016 | —- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] – C:\WINDOWS\System32\drivers\avgmfx86.sys – (Avgmfx86)
DRV - [2011/07/11 01:14:38 | 000,295,248 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\WINDOWS\System32\drivers\avgtdix.sys – (Avgtdix)
DRV - [2011/07/11 01:14:02 | 000,024,272 | —- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\drivers\AVGIDSFilter.sys – (AVGIDSFilter)
DRV - [2011/07/11 01:14:00 | 000,023,120 | —- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] – C:\Windows\system32\DRIVERS\AVGIDSEH.Sys – (AVGIDSEH)
DRV - [2011/07/11 01:13:58 | 000,134,736 | —- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\drivers\AVGIDSDriver.sys – (AVGIDSDriver)
DRV - [2009/06/17 06:20:34 | 000,012,648 | —- | M] (Secunia) [File_System | On_Demand | Stopped] – C:\WINDOWS\System32\drivers\psi_mf.sys – (PSI)
DRV - [2008/07/22 06:42:58 | 000,051,200 | —- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\drivers\Rtnicxp.sys – (RTL8023xp)
DRV - [2008/05/08 04:05:18 | 000,266,752 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\drivers\HSXHWBS2.sys – (HSXHWBS2)
DRV - [2008/05/08 04:03:18 | 000,980,992 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\drivers\HSX_DP.sys – (HSF_DP)
DRV - [2007/10/18 06:36:54 | 000,008,704 | —- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] – C:\WINDOWS\System32\drivers\XAudio.sys – (XAudio)
DRV - [2007/06/13 18:28:12 | 002,600,448 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\System32\drivers\atikmdag.sys – (R300)
DRV - [2007/06/13 18:28:12 | 002,600,448 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\drivers\atikmdag.sys – (atikmdag)
DRV - [2006/11/10 15:05:00 | 000,018,688 | —- | M] (Arcsoft, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\drivers\afc.sys – (Afc)
DRV - [2006/11/03 09:29:18 | 000,008,192 | —- | M] (ATI Technologies Inc.) [Kernel | Boot | Running] – C:\Windows\system32\DRIVERS\AtiPcie.sys – (AtiPcie) ATI PCI Express (3GIO)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://my.juno.com/s/search?r=minisearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://my.juno.com/s/search?r=minisearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://my.juno.com/s/search?r=minisearch
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{30BE9173-249A-4F0B-B775-51E6E873F9B6}: "URL" = http://www.ask.com/web?q={searchTerms}&l=dis&o=uscqd
IE - HKLM\..\SearchScopes\{3E935B96-16B0-4512-8E7B-1E9632A5114D}: "URL" = http://search.yahoo.com/search?p={searchTe…&fr=hp-psdt
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2A69}: "URL" = http://search.bearshare.com/web?src=ieb&q={searchTerms}
IE - HKLM\..\SearchScopes\{FD14B97B-A346-4E7E-B268-D48526127F0C}: "URL" = http://search.live.com/results.aspx?q={sea…amp;FORM=HQDUS7


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-2559784832-2112059209-2043554392-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://my.juno.com/s/search?r=minisearch
IE - HKU\S-1-5-21-2559784832-2112059209-2043554392-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://my.juno.com/s/search?r=minisearch
IE - HKU\S-1-5-21-2559784832-2112059209-2043554392-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://my.juno.com/
IE - HKU\S-1-5-21-2559784832-2112059209-2043554392-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-2559784832-2112059209-2043554392-1000\..\URLSearchHook: {37D2CDBF-2AF4-44AA-8113-BD0D2DA3C2B8} - C:\Program Files\Juno\SearchEnh1.dll (Juno, Inc.)
IE - HKU\..\SearchScopes,DefaultScope = {95B7759C-8C7F-4BF1-B163-73684A933233}
IE - HKU\..\SearchScopes\{3CCA4B1C-FEE3-4ABF-9CFB-3B14A8691F1B}: "URL" = http://search.juno.com/search?action=searc…y={searchTerms}
IE - HKU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://isearch.avg.com/search?cid={8F57200…mp;d=2012-02-24 16:59:53&v=10.0.0.7&sap=dsp&q={searchTerms}
IE - HKU\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2A69}: "URL" = http://search.bearshare.com/web?src=ieb&q={searchTerms}
IE - HKU\S-1-5-21-2559784832-2112059209-2043554392-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG2012\Firefox4\ [2012/02/24 17:00:17 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\ProgramData\AVG Secure Search\10.0.0.7\ [2012/02/24 17:00:12 | 000,000,000 | —D | M]


O1 HOSTS File: ([2012/02/22 18:58:10 | 000,000,027 | —- | M]) - C:\WINDOWS\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Pop-up Blocker) - {52706EF7-D7A2-49AD-A615-E903858CF284} - C:\Program Files\Juno\qsacc\X1IEBHO.dll (Juno, Inc.)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\10.0.0.7\AVG Secure Search_toolbar.dll ()
O2 - BHO: (Babylon IE plugin) - {9CFACCB6-2F3F-4177-94EA-0D2B72D384C1} - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll File not found
O2 - BHO: (Juno Toolbar Helper) - {FE3098B1-04A3-41fd-8CA9-BEA39CB14C87} - C:\Program Files\Juno\UCReg.dll (Juno, Inc.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\10.0.0.7\AVG Secure Search_toolbar.dll ()
O3 - HKU\S-1-5-21-2559784832-2112059209-2043554392-1000\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-21-2559784832-2112059209-2043554392-1000\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
O3 - HKU\S-1-5-21-2559784832-2112059209-2043554392-1000\..\Toolbar\WebBrowser: (no name) - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No CLSID value found.
O4 - HKLM..\Run: [ATICCC] c:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe ()
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [DPService] C:\Program Files\HP\DVDPlay\DPService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [vProt] C:\Program Files\AVG Secure Search\vprot.exe ()
O4 - HKU\S-1-5-21-2559784832-2112059209-2043554392-1000..\Run: [Juno_uoltray] C:\Program Files\Juno\exec.exe (Juno, Inc.)
O4 - HKLM..\RunOnce: [Launcher] C:\WINDOWS\SMINST\Launcher.exe (soft thinks)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2559784832-2112059209-2043554392-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2559784832-2112059209-2043554392-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Display All Images with Full Quality - C:\Program Files\Juno\qsacc\appres.dll (Juno, Inc.)
O8 - Extra context menu item: Display Image with Full Quality - C:\Program Files\Juno\qsacc\appres.dll (Juno, Inc.)
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html File not found
O8 - Extra context menu item: Translate this web page with Babylon - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm File not found
O8 - Extra context menu item: Translate with Babylon - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Action.htm File not found
O9 - Extra Button: Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm File not found
O9 - Extra 'Tools' menuitem : Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm File not found
O15 - HKU\.DEFAULT\..Trusted Ranges: Range1 ([http] in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Ranges: Range1 ([http] in Local intranet)
O15 - HKU\S-1-5-21-2559784832-2112059209-2043554392-1000\..Trusted Domains: juno.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-2559784832-2112059209-2043554392-1000\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.76.76 75.75.75.75
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F62C4470-9CA5-4842-A9E8-DDB9838C16BC}: DhcpNameServer = 75.75.76.76 75.75.75.75
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\10.0.6\ViProtocol.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\WINDOWS\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Home\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Home\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 15:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2012\avgrsx.exe /sync /restart)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/03/01 16:46:26 | 000,584,704 | —- | C] (OldTimer Tools) – C:\Users\Home\Desktop\OTL.exe
[2012/02/24 17:06:03 | 000,000,000 | —D | C] – C:\Users\Home\AppData\Roaming\AVG2012
[2012/02/24 17:00:17 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG 2012
[2012/02/24 16:59:50 | 000,000,000 | —D | C] – C:\ProgramData\AVG Secure Search
[2012/02/24 16:59:47 | 000,000,000 | —D | C] – C:\Program Files\Common Files\AVG Secure Search
[2012/02/24 16:59:46 | 000,000,000 | —D | C] – C:\Program Files\AVG Secure Search
[2012/02/24 16:59:41 | 000,000,000 | -H-D | C] – C:\ProgramData\Common Files
[2012/02/24 16:57:31 | 000,000,000 | —D | C] – C:\ProgramData\AVG2012
[2012/02/24 16:57:31 | 000,000,000 | —D | C] – C:\Windows\System32\drivers\AVG
[2012/02/24 16:55:47 | 000,000,000 | —D | C] – C:\Program Files\AVG
[2012/02/24 16:52:09 | 000,000,000 | —D | C] – C:\ProgramData\MFAData
[2012/02/24 15:32:34 | 000,000,000 | —D | C] – C:\Program Files\Juno
[2012/02/24 15:32:19 | 000,000,000 | —D | C] – C:\JunoInstaller
[2012/02/24 15:14:24 | 000,000,000 | —D | C] – C:\ProgramData\Juno
[2012/02/24 15:14:23 | 000,000,000 | —D | C] – C:\Program Files\JunoConnection Wizard
[2012/02/24 15:14:23 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Juno Internet
[2012/02/24 14:07:26 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe
[2012/02/24 13:59:47 | 000,000,000 | —D | C] – C:\Users\Home\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2012/02/24 13:53:51 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2012/02/23 17:07:04 | 000,000,000 | —D | C] – C:\Users\Home\AppData\Roaming\Malwarebytes
[2012/02/23 17:06:43 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/02/23 17:06:42 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2012/02/23 17:06:40 | 000,020,464 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2012/02/23 17:06:40 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2012/02/23 16:46:35 | 000,000,000 | —D | C] – C:\Windows\temp
[2012/02/22 19:04:41 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2012/02/22 19:04:29 | 000,000,000 | —D | C] – C:\Users\Home\AppData\Local\temp
[2012/02/22 18:43:07 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2012/02/22 18:43:07 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2012/02/22 18:43:07 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2012/02/22 18:42:55 | 000,000,000 | —D | C] – C:\ComboFix
[2012/02/22 18:35:19 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2012/02/22 18:26:23 | 000,000,000 | —D | C] – C:\Qoobox

========== Files - Modified Within 30 Days ==========

[2012/03/01 16:46:26 | 000,584,704 | —- | M] (OldTimer Tools) – C:\Users\Home\Desktop\OTL.exe
[2012/03/01 16:38:31 | 090,531,853 | —- | M] () – C:\Windows\System32\drivers\AVG\incavi.avm
[2012/03/01 16:32:37 | 000,003,552 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/03/01 16:32:35 | 000,003,552 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/03/01 16:32:08 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/03/01 16:31:58 | 938,795,008 | -HS- | M] () – C:\hiberfil.sys
[2012/02/24 17:00:18 | 000,000,848 | —- | M] () – C:\Users\Public\Desktop\AVG 2012.lnk
[2012/02/24 15:33:26 | 000,001,608 | —- | M] () – C:\Users\Public\Desktop\Juno Internet.lnk
[2012/02/24 15:33:24 | 000,001,707 | —- | M] () – C:\Users\Public\Desktop\Juno Quick Help.lnk
[2012/02/24 15:29:35 | 004,396,208 | —- | M] () – C:\Users\Home\Desktop\JunoSBSetup.exe
[2012/02/22 18:58:10 | 000,000,027 | —- | M] () – C:\Windows\System32\drivers\etc\hosts
[2012/02/22 17:37:00 | 000,001,724 | -H– | M] () – C:\Users\Home\Documents\Default.rdp
[2012/02/19 13:52:30 | 000,000,810 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2012/02/17 20:49:53 | 000,000,949 | —- | M] () – C:\Users\Home\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/02/17 20:33:30 | 000,604,264 | —- | M] () – C:\Windows\System32\perfh009.dat
[2012/02/17 20:33:29 | 000,103,964 | —- | M] () – C:\Windows\System32\perfc009.dat
[2012/02/17 20:31:11 | 000,008,798 | —- | M] () – C:\Windows\System32\icrav03.rat
[2012/02/17 20:31:11 | 000,001,988 | —- | M] () – C:\Windows\System32\ticrf.rat
[2012/02/17 20:30:53 | 000,072,822 | —- | M] () – C:\Windows\System32\ieuinit.inf
[2012/02/17 20:05:12 | 000,281,488 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT

========== Files Created - No Company Name ==========

[2012/03/01 16:38:31 | 090,531,853 | —- | C] () – C:\Windows\System32\drivers\AVG\incavi.avm
[2012/02/24 17:00:18 | 000,000,848 | —- | C] () – C:\Users\Public\Desktop\AVG 2012.lnk
[2012/02/24 15:33:25 | 000,001,620 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Juno Internet.lnk
[2012/02/24 15:33:24 | 000,001,707 | —- | C] () – C:\Users\Public\Desktop\Juno Quick Help.lnk
[2012/02/24 15:33:24 | 000,001,608 | —- | C] () – C:\Users\Public\Desktop\Juno Internet.lnk
[2012/02/24 15:29:33 | 004,396,208 | —- | C] () – C:\Users\Home\Desktop\JunoSBSetup.exe
[2012/02/24 14:08:58 | 000,001,804 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
[2012/02/24 14:01:14 | 000,000,890 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat_com.lnk
[2012/02/22 18:43:07 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2012/02/22 18:43:07 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2012/02/22 18:43:07 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2012/02/22 18:43:07 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2012/02/22 18:43:07 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2012/02/20 17:34:52 | 000,001,724 | -H– | C] () – C:\Users\Home\Documents\Default.rdp
[2012/02/17 20:30:53 | 000,072,822 | —- | C] () – C:\Windows\System32\ieuinit.inf
[2010/11/24 16:21:26 | 000,000,047 | —- | C] () – C:\Windows\WinInit.Ini

========== LOP Check ==========

[2012/02/24 17:06:03 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\AVG2012
[2010/02/06 17:56:35 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\Babylon
[2007/04/10 23:27:55 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\Canon
[2012/02/24 13:59:47 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010/02/17 14:10:04 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\DriverCure
[2009/08/11 17:56:34 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\Lexmark Productivity Studio
[2009/07/26 17:46:09 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\Template
[2010/02/17 18:48:18 | 000,000,348 | —- | M] () – C:\Windows\Tasks\File Helper.job
[2012/02/26 12:35:51 | 000,032,536 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: EXPLORER.EXE >
[2009/07/18 20:49:01 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE – C:\WINDOWS\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_4f83bb287ccdb7e3\explorer.exe
[2009/07/18 20:49:00 | 002,927,104 | —- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D – C:\WINDOWS\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_5177ca9879e978e8\explorer.exe
[2009/07/18 20:48:57 | 002,927,616 | —- | M] (Microsoft Corporation) MD5=50BA5850147410CDE89C523AD3BC606E – C:\WINDOWS\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_51e4f8c7931bd1e1\explorer.exe
[2009/07/18 22:02:58 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=6D06CD98D954FE87FB2DB8108793B399 – C:\WINDOWS\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16549_none_4fac29707cae347a\explorer.exe
[2009/07/18 22:02:56 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=BD06F0BF753BC704B653C3A50F89D362 – C:\WINDOWS\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20668_none_501f261995dcf2cf\explorer.exe
[2009/04/11 00:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 – C:\WINDOWS\ERDNT\cache\explorer.exe
[2009/04/11 00:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 – C:\WINDOWS\explorer.exe
[2009/04/11 00:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 – C:\WINDOWS\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_53a0201e76de3a0b\explorer.exe
[2009/07/18 20:49:00 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=E7156B0B74762D9DE0E66BDCDE06E5FB – C:\WINDOWS\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_5033cb5995cd990b\explorer.exe
[2006/11/02 03:45:07 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=FD8C53FB002217F6F888BCF6F5D7084D – C:\WINDOWS\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16386_none_4f7de5167cd15deb\explorer.exe
[2008/01/19 01:33:10 | 002,927,104 | —- | M] (Microsoft Corporation) MD5=FFA764631CB70A30065C12EF8E174F9F – C:\WINDOWS\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_51b4a71279bc6ebf\explorer.exe

< MD5 for: SVCHOST.EXE >
[2006/11/02 03:45:47 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=10DA15933D582D2FEDCF705EFE394B09 – C:\WINDOWS\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.0.6000.16386_none_b38497a50862ad11\svchost.exe
[2008/01/19 01:33:32 | 000,021,504 | —- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF – C:\WINDOWS\ERDNT\cache\svchost.exe
[2008/01/19 01:33:32 | 000,021,504 | —- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF – C:\WINDOWS\System32\svchost.exe
[2008/01/19 01:33:32 | 000,021,504 | —- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF – C:\WINDOWS\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.0.6001.18000_none_b5bb59a1054dbde5\svchost.exe
[2012/01/31 13:13:46 | 000,182,856 | —- | M] () MD5=9F37B15F56C3D248CD299D34BCB2CEFA – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\svchost.exe

< MD5 for: USERINIT.EXE >
[2008/01/19 01:33:33 | 000,025,088 | —- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 – C:\WINDOWS\ERDNT\cache\userinit.exe
[2008/01/19 01:33:33 | 000,025,088 | —- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 – C:\WINDOWS\System32\userinit.exe
[2008/01/19 01:33:33 | 000,025,088 | —- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 – C:\WINDOWS\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
[2006/11/02 03:45:50 | 000,024,576 | —- | M] (Microsoft Corporation) MD5=22027835939F86C3E47AD8E3FBDE3D11 – C:\WINDOWS\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6000.16386_none_d9f1f819d4c4e737\userinit.exe

< MD5 for: WINLOGON.EXE >
[2009/04/11 00:28:13 | 000,314,368 | —- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 – C:\WINDOWS\ERDNT\cache\winlogon.exe
[2009/04/11 00:28:13 | 000,314,368 | —- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 – C:\WINDOWS\System32\winlogon.exe
[2009/04/11 00:28:13 | 000,314,368 | —- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 – C:\WINDOWS\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2012/01/31 13:13:46 | 000,182,856 | —- | M] () MD5=9F37B15F56C3D248CD299D34BCB2CEFA – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2006/11/02 03:45:57 | 000,308,224 | —- | M] (Microsoft Corporation) MD5=9F75392B9128A91ABAFB044EA350BAAD – C:\WINDOWS\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6000.16386_none_6d8c3f1ad8066b21\winlogon.exe
[2008/01/19 01:33:37 | 000,314,880 | —- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 – C:\WINDOWS\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe

< %systemroot%\*. /rp /s >

========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
[C:\Windows\System32\config\systemprofile\AppData\Local\History] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History -> Junction
[C:\Windows\System32\config\systemprofile\AppData\Local\Temporary Internet Files] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files -> Junction
[C:\Windows\System32\config\systemprofile\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Roaming -> Junction
[C:\Windows\System32\config\systemprofile\Local Settings] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction

========== Alternate Data Streams ==========

@Alternate Data Stream - 95 bytes -> C:\ProgramData\TEMP:5C321E34
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:DFC5A2B2
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:D1B5B4F1
@Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:A8ADE5D8

< End of report >
Don't worry about the other log.

I would recommend you uninstall File Helper. You should be able to uninstall it by going to Start > Control Panel (non-category view) > Programs and Features. If it's not listed there, then its folder should be located at C:\Program Files\File Helper, which you can right-click and delete.

  • OTL

    Run OTL.exe.

  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL.

    :OTL
    [2010/02/17 18:48:18 | 000,000,348 | —- | M] () – C:\Windows\Tasks\File Helper.job
    @Alternate Data Stream - 95 bytes -> C:\ProgramData\TEMP:5C321E34
    @Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:DFC5A2B2
    @Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:D1B5B4F1
    @Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:A8ADE5D8
    
    :Commands
    [createrestorepoint]
    [purity]
    [emptytemp]

  • Click the Run Fix button.
  • OTL will now process the instructions.
  • When finished a box will open asking you to open the fix log, click OK.
  • The fix log will open.
  • Copy/Paste the log in your next reply please.

Note: If necessary, OTL may reboot your computer, or request that you do so. If it does, please go ahead and reboot your machine. After rebooting, open up Windows Explorer (Windows Key +E) and navigate to C:\_OTL\MovedFiles. Within, you should find a .log file with the format mmddyyyy_hhmmss, which represents the date and time the fix was run. Please copy and paste the contents of that file, making sure Word Wrap is off beforehand, if necessary.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI