This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Slow operating system Windows XP

19 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi

i have had slow computers before but this is getting beyond the joke. Everything is working slowly. Happy to add / delete any programs / files that may assist in speeding it up.


OTL logfile created on: 19/03/2012 3:39:12 PM - Run 1
OTL by OldTimer - Version 3.2.39.1 Folder = C:\downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

511.53 Mb Total Physical Memory | 200.67 Mb Available Physical Memory | 39.23% Memory free
1.22 Gb Paging File | 0.53 Gb Available in Paging File | 43.19% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.54 Gb Total Space | 23.83 Gb Free Space | 31.97% Space Free | Partition Type: FAT32
Drive E: | 232.88 Gb Total Space | 215.69 Gb Free Space | 92.62% Space Free | Partition Type: NTFS

Computer Name: HOME | User Name: Kevin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/03/19 15:28:04 | 000,594,432 | —- | M] (OldTimer Tools) – C:\downloads\OTL.exe
PRC - [2012/01/13 14:53:18 | 000,652,360 | —- | M] (Malwarebytes Corporation) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2011/11/28 01:19:04 | 001,229,664 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG2012\avgnsx.exe
PRC - [2011/10/12 06:25:22 | 004,433,248 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
PRC - [2011/09/08 20:53:26 | 000,743,264 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG2012\avgrsx.exe
PRC - [2011/08/15 06:21:40 | 000,337,760 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG2012\avgcsrvx.exe
PRC - [2011/08/02 06:09:08 | 000,192,776 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG2012\avgwdsvc.exe
PRC - [2011/05/08 08:19:36 | 000,924,632 | —- | M] (Mozilla Corporation) – C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2011/04/19 16:14:40 | 000,993,848 | —- | M] (Secunia) – C:\Program Files\Secunia\PSI\psia.exe
PRC - [2011/04/19 16:14:40 | 000,399,416 | —- | M] (Secunia) – C:\Program Files\Secunia\PSI\sua.exe
PRC - [2011/03/01 12:12:00 | 000,136,584 | —- | M] (LogMeIn, Inc.) – C:\Program Files\LogMeIn\x86\ramaint.exe
PRC - [2010/11/08 12:04:20 | 000,390,528 | —- | M] (LogMeIn, Inc.) – C:\Program Files\LogMeIn\x86\LogMeIn.exe
PRC - [2010/08/01 16:16:38 | 001,101,152 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgchsvx.exe
PRC - [2010/08/01 16:15:36 | 000,308,136 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgwdsvc.exe
PRC - [2008/04/14 09:42:20 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2003/05/22 20:38:26 | 000,106,496 | —- | M] (Matsushita Electric Industrial Co., Ltd.) – C:\WINDOWS\system32\DVDRAMSV.exe
PRC - [2002/09/20 15:50:10 | 000,045,056 | —- | M] (Analog Devices, Inc.) – C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe


========== Modules (No Company Name) ==========

MOD - [2012/03/18 15:00:06 | 008,527,520 | —- | M] () – C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
MOD - [2011/05/08 08:19:38 | 001,874,904 | —- | M] () – C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2010/03/04 16:55:34 | 000,147,456 | —- | M] () – C:\WINDOWS\system32\HP1100LM.DLL
MOD - [2010/03/04 16:55:14 | 000,069,632 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\HP1100PP.dll
MOD - [2009/09/04 23:15:06 | 000,067,872 | —- | M] () – C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2006/10/22 12:22:00 | 000,212,992 | —- | M] () – C:\WINDOWS\system32\nvapi.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] – %SystemRoot%\System32\hidserv.dll – (HidServ)
SRV - File not found [Auto | Stopped] – – (CCALib8)
SRV - File not found [On_Demand | Stopped] – %SystemRoot%\System32\appmgmts.dll – (AppMgmt)
SRV - File not found [Auto | Stopped] – – (AdobeActiveFileMonitor4.0)
SRV - [2012/01/13 14:53:18 | 000,652,360 | —- | M] (Malwarebytes Corporation) [Auto | Running] – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe – (MBAMService)
SRV - [2011/10/12 06:25:22 | 004,433,248 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe – (AVGIDSAgent)
SRV - [2011/08/02 06:09:08 | 000,192,776 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files\AVG\AVG2012\avgwdsvc.exe – (avgwd)
SRV - [2011/04/19 16:14:40 | 000,993,848 | —- | M] (Secunia) [Auto | Running] – C:\Program Files\Secunia\PSI\psia.exe – (Secunia PSI Agent)
SRV - [2011/04/19 16:14:40 | 000,399,416 | —- | M] (Secunia) [Auto | Running] – C:\Program Files\Secunia\PSI\sua.exe – (Secunia Update Agent)
SRV - [2011/03/01 12:12:00 | 000,136,584 | —- | M] (LogMeIn, Inc.) [Auto | Running] – C:\Program Files\LogMeIn\x86\ramaint.exe – (LMIMaint)
SRV - [2010/11/08 12:04:20 | 000,390,528 | —- | M] (LogMeIn, Inc.) [Auto | Running] – C:\Program Files\LogMeIn\x86\LogMeIn.exe – (LogMeIn)
SRV - [2010/08/01 16:15:36 | 000,308,136 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files\AVG\AVG9\avgwdsvc.exe – (avg9wd)
SRV - [2010/06/03 14:44:28 | 000,655,624 | —- | M] (Acresso Software Inc.) [On_Demand | Stopped] – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe – (FLEXnet Licensing Service)
SRV - [2009/07/14 14:36:00 | 000,066,056 | —- | M] (NOS Microsystems Ltd.) [On_Demand | Stopped] – C:\Program Files\NOS\bin\getPlus_HelperSvc.exe – (getPlus® Helper) getPlus®
SRV - [2008/08/15 05:46:20 | 000,284,016 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\Program Files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe – (Adobe Version Cue CS4)
SRV - [2006/11/03 19:19:58 | 000,013,592 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Program Files\Windows Defender\MsMpEng.exe – (WinDefend)
SRV - [2003/05/22 20:38:26 | 000,106,496 | —- | M] (Matsushita Electric Industrial Co., Ltd.) [Auto | Running] – C:\WINDOWS\system32\DVDRAMSV.exe – (DVD-RAM_Service)
SRV - [2002/09/20 15:50:10 | 000,045,056 | —- | M] (Analog Devices, Inc.) [Auto | Running] – C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe – (SoundMAX Agent Service (default))


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] – – (WDICA)
DRV - File not found [Kernel | Boot | Stopped] – system32\drivers\TfSysMon.sys – (TfSysMon)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\TfNetMon.sys – (TfNetMon)
DRV - File not found [Kernel | Boot | Stopped] – system32\drivers\TfFsMon.sys – (TfFsMon)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDCOMP)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\pctplsg.sys – (pctplsg)
DRV - File not found [Kernel | On_Demand | Stopped] – System32\Drivers\Pcouffin.sys – (Pcouffin)
DRV - File not found [Kernel | System | Stopped] – – (PCIDump)
DRV - File not found [Kernel | System | Stopped] – – (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] – – (i2omgmt)
DRV - File not found [Kernel | System | Stopped] – – (Changer)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\DOCUME~1\Kevin\LOCALS~1\Temp\catchme.sys – (catchme)
DRV - [2012/03/18 16:13:16 | 000,029,712 | —- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] – C:\WINDOWS\system32\drivers\avgmfx86.sys – (AvgMfx86)
DRV - [2011/12/10 15:24:06 | 000,020,464 | —- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] – C:\WINDOWS\system32\drivers\mbam.sys – (MBAMProtector)
DRV - [2011/10/07 06:23:48 | 000,230,608 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\avgldx86.sys – (AvgLdx86)
DRV - [2011/10/04 06:21:42 | 000,016,720 | —- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\AVGIDSShim.sys – (AVGIDSShim)
DRV - [2011/09/13 06:30:10 | 000,032,592 | —- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] – C:\WINDOWS\system32\drivers\avgrkx86.sys – (Avgrkx86)
DRV - [2011/07/11 01:14:38 | 000,295,248 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\avgtdix.sys – (AvgTdiX)
DRV - [2011/07/11 01:14:28 | 000,024,272 | —- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\AVGIDSFilter.sys – (AVGIDSFilter)
DRV - [2011/07/11 01:14:28 | 000,023,120 | —- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\AVGIDSEH.sys – (AVGIDSEH)
DRV - [2011/07/11 01:14:26 | 000,134,608 | —- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\AVGIDSDriver.sys – (AVGIDSDriver)
DRV - [2010/09/01 18:00:58 | 000,015,544 | —- | M] (Secunia) [File_System | On_Demand | Running] – C:\WINDOWS\system32\drivers\psi_mf.sys – (PSI)
DRV - [2010/06/10 20:37:26 | 000,083,360 | —- | M] (LogMeIn, Inc.) [File_System | Disabled | Stopped] – C:\WINDOWS\System32\LMIRfsClientNP.dll – (LMIRfsClientNP)
DRV - [2010/01/14 11:27:32 | 000,186,128 | —- | M] (Kaspersky Lab) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\klif.sys – (KLIF)
DRV - [2009/08/05 22:48:42 | 000,054,752 | —- | M] (Microsoft Corporation) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\fssfltr_tdi.sys – (fssfltr)
DRV - [2008/10/18 20:51:10 | 000,047,640 | —- | M] (LogMeIn, Inc.) [File_System | Auto | Running] – C:\WINDOWS\system32\drivers\LMIRfsDriver.sys – (LMIRfsDriver)
DRV - [2008/10/14 19:53:18 | 000,015,271 | —- | M] (MediaTek Corporation) [File_System | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\FIDE.SYS – (MTK)
DRV - [2008/02/28 15:31:52 | 000,012,856 | —- | M] (LogMeIn, Inc.) [Kernel | Auto | Running] – C:\Program Files\LogMeIn\x86\rainfo.sys – (LMIInfo)
DRV - [2005/03/04 12:02:20 | 001,066,278 | —- | M] (Agere Systems) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\AGRSM.sys – (AgereSoftModem)
DRV - [2004/11/13 22:03:30 | 000,068,608 | —- | M] (VSO Software) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\Pcatip.sys – (Pcatip)
DRV - [2004/08/04 15:01:34 | 000,032,768 | —- | M] (SiS Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\sisnic.sys – (SISNIC)
DRV - [2004/03/08 13:25:50 | 000,013,567 | —- | M] (B.H.A Corporation) [Kernel | System | Running] – C:\WINDOWS\System32\drivers\cdrbsdrv.sys – (cdrbsdrv)
DRV - [2003/12/03 18:14:58 | 000,013,566 | —- | M] (B.H.A Corporation) [Kernel | System | Running] – C:\WINDOWS\System32\drivers\cdrbsvsd.sys – (cdrbsvsd)
DRV - [2003/06/19 11:44:16 | 000,390,016 | —- | M] (B.H.A Co.,Ltd.) [File_System | Disabled | Running] – C:\WINDOWS\System32\drivers\BsUDF.sys – (BsUDF)
DRV - [2003/01/31 00:45:56 | 000,090,416 | —- | M] (Matsushita Electric Industrial Co.,Ltd.) [File_System | System | Running] – C:\WINDOWS\system32\drivers\meiudf.sys – (meiudf)
DRV - [2002/06/06 01:07:00 | 000,009,344 | —- | M] (B.H.A Co.,Ltd.) [Kernel | Boot | Running] – C:\WINDOWS\System32\drivers\BsStor.sys – (BsStor)
DRV - [2001/08/17 14:02:56 | 000,003,968 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\SWUSBFLT.SYS – (SWUSBFLT)
DRV - [2001/08/17 14:02:50 | 000,002,688 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\HIDSwvd.sys – (HIDSwvd)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.news.com.au/adelaidenow/
IE - HKCU\..\SearchScopes,DefaultScope = {8FDAA6FC-DEA4-4FBC-9684-91F3D8E4A931}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{8FDAA6FC-DEA4-4FBC-9684-91F3D8E4A931}: "URL" = http://www.google.com/search?q={searchTerm…age={startPage}
IE - HKCU\..\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}: "URL" = http://search.avg.com/route/?d=4b3d2cf0&am…hte=au&nt=1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.iprimus.com.au;*.primustel.com.au;*.primus.com.au;;*.local
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = proxy.iprimus.com.au:8080

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://www.adelaidenow.com.au/"
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.872
FF - prefs.js..network.proxy.ftp: "proxy.iprimus.com.au"
FF - prefs.js..network.proxy.ftp_port: 8080
FF - prefs.js..network.proxy.gopher: "proxy.iprimus.com.au"
FF - prefs.js..network.proxy.gopher_port: 8080
FF - prefs.js..network.proxy.http: "proxy.iprimus.com.au"
FF - prefs.js..network.proxy.http_port: 8080
FF - prefs.js..network.proxy.no_proxies_on: "*.iprimus.com.au,*.primustel.com.au,*.primus.com.au,localhost,127.0.0.1"
FF - prefs.js..network.proxy.share_proxy_settings: true
FF - prefs.js..network.proxy.socks: "proxy.iprimus.com.au"
FF - prefs.js..network.proxy.socks_port: 8080
FF - prefs.js..network.proxy.ssl: "proxy.iprimus.com.au"
FF - prefs.js..network.proxy.ssl_port: 8080
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/npracplug;version=1.0.0.0: File not found
FF - HKCU\Software\MozillaPlugins\@abr.gov.au/KeyMgmtPlugin: C:\Documents and Settings\Kevin\Local Settings\Application Data\ABR\Plug-In\bin\npAUSkeyPlugin.dll (Commonwealth Government of Australia)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/04/22 19:11:46 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox [2010/08/01 16:15:12 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG2012\Firefox4\ [2012/03/18 15:40:36 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2004/10/08 18:16:40 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2004/10/08 18:16:38 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/04/22 19:11:46 | 000,000,000 | —D | M]

[2009/03/27 06:06:22 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Kevin\Application Data\Mozilla\Extensions
[2009/05/05 19:15:34 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Kevin\Application Data\Mozilla\Extensions\[removed]
[2006/04/11 12:39:48 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\8uqh3fqo.Default User\extensions
[2009/08/06 17:42:42 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\8uqh3fqo.Default User\extensions\{20a82645-c095-46ed-80e3-08825760534b}(2)
[2004/10/08 18:17:50 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/03/18 15:40:36 | 000,000,000 | —D | M] (AVG Safe Search) – C:\PROGRAM FILES\AVG\AVG2012\FIREFOX4
[2011/05/08 08:19:36 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2010/04/12 17:29:20 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/05/08 08:19:42 | 000,001,538 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2011/05/08 08:19:42 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/05/08 08:19:42 | 000,000,947 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
[2011/05/08 08:19:42 | 000,001,180 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
[2011/05/08 08:19:42 | 000,001,135 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: ([2010/08/03 20:27:58 | 001,014,948 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 fr.a2dfp.net
O1 - Hosts: 127.0.0.1 m.fr.a2dfp.net
O1 - Hosts: 127.0.0.1 ad.a8.net
O1 - Hosts: 127.0.0.1 asy.a8ww.net
O1 - Hosts: 127.0.0.1 acezip.net #[SiteAdvisor.acezip.net]
O1 - Hosts: 127.0.0.1 www.acezip.net #[Win32/Adware.180Solutions]
O1 - Hosts: 127.0.0.1 phpadsnew.abac.com
O1 - Hosts: 127.0.0.1 a.abnad.net
O1 - Hosts: 127.0.0.1 b.abnad.net
O1 - Hosts: 127.0.0.1 c.abnad.net #[eTrust.Tracking.Cookie]
O1 - Hosts: 127.0.0.1 d.abnad.net
O1 - Hosts: 127.0.0.1 e.abnad.net
O1 - Hosts: 127.0.0.1 t.abnad.net
O1 - Hosts: 127.0.0.1 z.abnad.net
O1 - Hosts: 127.0.0.1 banners.absolpublisher.com
O1 - Hosts: 127.0.0.1 tracking.absolstats.com
O1 - Hosts: 127.0.0.1 adv.abv.bg
O1 - Hosts: 127.0.0.1 bimg.abv.bg
O1 - Hosts: 127.0.0.1 www2.a-counter.kiev.ua
O1 - Hosts: 127.0.0.1 track.acclaimnetwork.com
O1 - Hosts: 127.0.0.1 accuserveadsystem.com
O1 - Hosts: 127.0.0.1 www.accuserveadsystem.com
O1 - Hosts: 127.0.0.1 gtb5.acecounter.com
O1 - Hosts: 127.0.0.1 gtb19.acecounter.com
O1 - Hosts: 30319 more lines…
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 55924053
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Back = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Forward = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Stop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Refresh = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Home = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Search = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_History = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Favorites = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Folders = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Fullscreen = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Tools = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_MailNews = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Size = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Print = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Edit = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Discussions = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Cut = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Copy = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Paste = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Encoding = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 55924053
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://www.pcpitstop.com/betapit/PCPitStop.CAB (Reg Error: Key error.)
O16 - DPF: {1671869C-25B3-4C80-9446-8AE6111F8765} http://thesims.ea.com/teleport/hotdate/NPC…otDateTeleX.cab (Reg Error: Key error.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} http://messenger.zone.msn.com/binary/MineS…er.cab30149.cab (Reg Error: Key error.)
O16 - DPF: {3D3B42C2-11BF-4732-A304-A01384B70D68} http://picasaweb.google.com/s/v/58.09/uploader2.cab (Reg Error: Key error.)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://coolbananas007.spaces.msn.com//Phot…ad/MsnPUpld.cab (Reg Error: Key error.)
O16 - DPF: {5D1E3FA5-64FF-4387-9418-F1D67AFB2247} http://thesims.ea.com/teleport/superstar/M…erstarTeleX.cab (Reg Error: Key error.)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/EN-AU/a-UNO1/GAME_UNO1.cab (Reg Error: Key error.)
O16 - DPF: {8629CFEB-C31A-4429-9BB0-8765A8A24FDA} http://thesims.ea.com/teleport/unleashed/L…hedLotTeleX.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_09)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_09)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab (Reg Error: Key error.)
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} http://messenger.zone.msn.com/binary/Solit…wn.cab31267.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{95660D96-2C19-43FA-B1F3-6408E3A0DAB4}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{95660D96-2C19-43FA-B1F3-6408E3A0DAB4}: NameServer = 192.231.203.132,192.231.203.3
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\mctp - No CLSID value found
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\itss.dll (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - (avgrsstx.dll) - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\LMIinit: DllName - (LMIinit.dll) - C:\WINDOWS\System32\LMIinit.dll (LogMeIn, Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Kevin\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Kevin\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2003/12/05 15:20:10 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ FAT32 ]
O33 - MountPoints2\{53a1277c-0640-11de-bdde-000c6edf1785}\Shell\AutoRun\command - "" = ReCYClER\\explorer.exe
O33 - MountPoints2\{53a1277c-0640-11de-bdde-000c6edf1785}\Shell\eXPLOre\cOMMANd - "" = rECyCLeR\\explorer.exe
O33 - MountPoints2\{53a1277c-0640-11de-bdde-000c6edf1785}\Shell\OPen\coMMaNd - "" = rECYCLEr\explorer.exe
O33 - MountPoints2\{edea2390-d2f8-11dd-bd6e-000c6edf1785}\Shell\AutoRun\command - "" = G:\cold\hott\raidhost.exe
O33 - MountPoints2\{edea2390-d2f8-11dd-bd6e-000c6edf1785}\Shell\Explore\Command - "" = G:\cold\hott\raidhost.exe
O33 - MountPoints2\{edea2390-d2f8-11dd-bd6e-000c6edf1785}\Shell\open\command - "" = G:\cold\hott\raidhost.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2012\avgrsx.exe /sync /restart)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
NetSvcs: HidServ - %SystemRoot%\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - C:\WINDOWS\System32\iprip.dll (Microsoft Corporation)
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: MIDI1 - C:\WINDOWS\System32\Syncor11.dll (SoundMAX)
Drivers32: MSACM.CEGSM - mobilev.acm File not found
Drivers32: msacm.divxa32 - C:\WINDOWS\System32\divxa32.acm (Kristal StudioDFileDescription)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Ligos Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.scg726 - C:\WINDOWS\System32\scg726.acm (SHARP Corporation)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIV3 - C:\WINDOWS\System32\DivXc32.dll (Hacked with Joy !)
Drivers32: vidc.DIV4 - C:\WINDOWS\System32\DivXc32f.dll (Hacked with Joy !)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll (Ligos Corporation)
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll (Ligos Corporation)
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.mxmc - MimicICM.DLL File not found
Drivers32: vidc.tscc - C:\WINDOWS\System32\tsccvid.dll (TechSmith Corporation)
Drivers32: vidc.VP60 - C:\WINDOWS\system32\vp6vfw.dll (On2.com)
Drivers32: vidc.VP61 - C:\WINDOWS\system32\vp6vfw.dll (On2.com)
Drivers32: VIDC.wmv3 - C:\WINDOWS\System32\WMV9VCM.dll (Microsoft Corporation)
Drivers32: vidc.XVID - C:\WINDOWS\System32\xvid.dll ()
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: wave1 - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/03/19 14:36:10 | 000,000,000 | —D | C] – C:\WINDOWS\System32\NtmsData
[2012/03/19 13:58:48 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Kevin\Recent
[2012/03/19 13:56:23 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2012/03/18 16:57:18 | 000,000,000 | —D | C] – C:\Documents and Settings\Kevin\Application Data\AVG
[2012/03/18 16:55:35 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\AVG PC Tuneup
[2012/03/18 16:13:15 | 000,012,536 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll.prepare
[2012/03/18 15:53:24 | 000,000,000 | —D | C] – C:\Documents and Settings\Kevin\Application Data\AVG2012
[2012/03/18 15:47:02 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\AVG 2012
[2012/03/18 15:40:17 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\AVG2012
[2012/03/18 15:29:41 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\MFAData
[2012/03/18 15:25:11 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/03/18 15:25:05 | 000,020,464 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2012/03/18 15:25:05 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\Documents and Settings\Kevin\My Documents\*.tmp files -> C:\Documents and Settings\Kevin\My Documents\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/03/19 14:56:50 | 000,501,596 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2012/03/19 14:56:50 | 000,089,104 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2012/03/19 14:51:00 | 000,088,566 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2012/03/19 14:48:12 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/03/19 13:56:40 | 000,000,586 | —- | M] () – C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2012/03/19 13:55:40 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2012/03/19 13:45:44 | 000,001,374 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/03/19 13:23:46 | 002,901,280 | -HS- | M] () – C:\WINDOWS\System32\drivers\fidbox.dat
[2012/03/19 13:23:46 | 000,217,632 | -HS- | M] () – C:\WINDOWS\System32\drivers\fidbox2.dat
[2012/03/19 13:23:46 | 000,040,952 | -HS- | M] () – C:\WINDOWS\System32\drivers\fidbox.idx
[2012/03/19 13:23:46 | 000,022,520 | -HS- | M] () – C:\WINDOWS\System32\drivers\fidbox2.idx
[2012/03/19 10:38:26 | 002,170,160 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2012/03/18 18:11:04 | 000,000,000 | —- | M] () – C:\Documents and Settings\Kevin\Local Settings\Application Data\prvlcl.dat
[2012/03/18 16:55:50 | 000,000,699 | —- | M] () – C:\Documents and Settings\Kevin\Desktop\AVG PC Tuneup.lnk
[2012/03/18 16:13:16 | 000,029,712 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2012/03/18 16:13:16 | 000,012,536 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll.prepare
[2012/03/18 15:47:06 | 000,000,606 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG 2012.lnk
[2012/03/18 15:25:14 | 000,000,688 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/03/18 15:00:08 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/03/18 13:07:24 | 000,002,187 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Safari.lnk
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\Documents and Settings\Kevin\My Documents\*.tmp files -> C:\Documents and Settings\Kevin\My Documents\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/03/19 13:56:38 | 000,000,586 | —- | C] () – C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2012/03/19 12:01:16 | 000,047,104 | R— | C] () – C:\WINDOWS\System32\HP1100SMs.dll
[2012/03/19 12:01:02 | 000,284,160 | —- | C] () – C:\WINDOWS\System32\mvhlewsi.DLL
[2012/03/19 12:01:01 | 001,511,424 | —- | C] () – C:\WINDOWS\System32\HP1100SM.EXE
[2012/03/19 12:01:01 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\HP1100LM.DLL
[2012/03/18 16:55:49 | 000,000,699 | —- | C] () – C:\Documents and Settings\Kevin\Desktop\AVG PC Tuneup.lnk
[2012/03/18 15:47:05 | 000,000,606 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AVG 2012.lnk
[2012/03/18 15:25:13 | 000,000,688 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2011/05/07 19:18:19 | 000,000,022 | -HS- | C] () – C:\Documents and Settings\Kevin\Application Data\Sys2662.Config.Repository.bin
[2010/08/12 18:47:37 | 000,000,000 | —- | C] () – C:\Documents and Settings\Kevin\Local Settings\Application Data\prvlcl.dat
[2010/08/09 07:38:03 | 000,000,520 | —- | C] () – C:\WINDOWS\_delis32.ini
[2010/08/07 21:23:09 | 000,000,022 | -HS- | C] () – C:\Documents and Settings\Kevin\Application Data\Sys6925.Config Collection.sys
[2010/08/07 21:23:09 | 000,000,022 | -HS- | C] () – C:\WINDOWS\Sys3390 SettingsCollection.bin
[2010/08/06 21:47:56 | 002,901,280 | -HS- | C] () – C:\WINDOWS\System32\drivers\fidbox.dat
[2010/08/06 21:47:56 | 000,217,632 | -HS- | C] () – C:\WINDOWS\System32\drivers\fidbox2.dat
[2010/04/22 19:10:22 | 000,023,110 | —- | C] () – C:\WINDOWS\hpqins15.dat
[2010/04/22 19:03:50 | 000,077,349 | —- | C] () – C:\WINDOWS\hpqins05.dat

========== LOP Check ==========

[2010/08/01 16:12:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2012/03/18 15:40:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG2012
[2010/08/12 18:59:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SecTaskMan
[2010/08/06 21:01:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2010/08/18 11:33:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSScanAppDataDir
[2011/03/17 19:12:12 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2011/06/03 09:27:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\IObit
[2005/11/30 14:21:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\espionServerData
[2006/12/15 13:09:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CA
[2012/03/18 15:29:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2010/08/18 11:33:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SSScanAppDataDir
[2008/02/02 22:04:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/08/19 18:41:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Panda Security
[2008/05/10 12:34:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LogMeIn
[2009/03/13 15:45:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[2009/06/03 22:08:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2009/12/13 00:13:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2010/04/29 13:57:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2005/01/16 21:11:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Kevin\Application Data\Absolutist.com
[2005/06/05 19:53:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Kevin\Application Data\DeepBurner Pro
[2007/05/30 21:59:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Kevin\Application Data\LimeWire
[2009/08/07 21:46:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Kevin\Application Data\Uniblue
[2010/07/26 21:19:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Kevin\Application Data\AUSkey
[2010/08/19 18:44:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Kevin\Application Data\Panda Security
[2011/02/15 19:09:22 | 000,000,000 | —D | M] – C:\Documents and Settings\Kevin\Application Data\Pointstone
[2011/05/26 12:17:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Kevin\Application Data\IObit
[2012/03/18 15:53:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Kevin\Application Data\AVG2012
[2012/03/18 16:57:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Kevin\Application Data\AVG

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.* >
[2012/03/19 14:48:04 | 805,306,368 | -HS- | M] () – C:\pagefile.sys
[2011/06/06 13:54:44 | 000,016,740 | —- | M] () – C:\Workouts.html
[2008/11/14 15:48:18 | 000,001,052 | —- | M] () – C:\log_err.log
[2008/06/30 20:45:06 | 000,250,048 | RHS- | M] () – C:\ntldr
[2004/09/27 14:14:58 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2012/03/19 13:55:40 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2003/12/05 15:20:10 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2003/12/05 15:20:10 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2003/12/05 15:20:10 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2003/12/05 15:20:10 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2009/08/04 19:07:06 | 000,003,262 | —- | M] () – C:\uvnwl.txt
[2009/08/18 19:45:56 | 000,000,000 | —- | M] () – C:\AdobeDebug.txt
[2008/05/10 12:34:22 | 000,001,024 | —- | M] () – C:\.rnd
[2010/08/24 19:12:56 | 000,005,324 | —- | M] () – C:\rollback.ini
[2009/11/03 21:39:14 | 000,024,720 | —- | M] () – C:\RECORD-L.REC
[2009/08/25 17:01:54 | 000,000,922 | —- | M] () – C:\updatedatfix.log
[2004/07/26 21:36:20 | 000,000,413 | -H– | M] () – C:\IPH.PH
[1 C:\*.tmp files -> C:\*.tmp -> ]

< %systemroot%\Fonts\*.com >

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2003/12/05 15:19:54 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2007/04/09 13:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2010/06/10 20:37:24 | 000,053,632 | —- | M] (LogMeIn, Inc.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\LMIproc.dll
[2007/10/20 18:21:50 | 000,278,016 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp5mu.dll
[2008/07/06 20:20:04 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
[2008/07/06 21:36:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2010/03/04 16:55:14 | 000,069,632 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\HP1100PP.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2004/11/08 16:42:04 | 000,184,912 | —- | M] (MacSourcery) – C:\WINDOWS\Fairies.scr
[2010/04/17 00:04:40 | 000,306,032 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WLXPGSS.SCR
[2006/01/23 13:18:28 | 000,471,040 | —- | M] (ScreenTime Media) – C:\WINDOWS\HarryPotter_screensaver_pc.scr
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2003/12/05 15:13:52 | 000,385,024 | —- | M] () – C:\WINDOWS\System32\config\system.sav
[2003/12/05 15:13:52 | 000,602,112 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2003/12/05 15:13:52 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/06/30 20:51:14 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2004/09/27 14:33:54 | 000,000,177 | -HS- | M] () – C:\Documents and Settings\Kevin\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2003/12/30 14:16:48 | 000,000,079 | —- | M] () – C:\Documents and Settings\Kevin\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2006/06/10 13:53:54 | 000,531,760 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Kevin\Desktop\GenuineCheck.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-03-19 05:25:49

< End of report >


OTL Extras logfile created on: 19/03/2012 3:39:13 PM - Run 1
OTL by OldTimer - Version 3.2.39.1 Folder = C:\downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

511.53 Mb Total Physical Memory | 200.67 Mb Available Physical Memory | 39.23% Memory free
1.22 Gb Paging File | 0.53 Gb Available in Paging File | 43.19% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.54 Gb Total Space | 23.83 Gb Free Space | 31.97% Space Free | Partition Type: FAT32
Drive E: | 232.88 Gb Total Space | 215.69 Gb Free Space | 92.62% Space Free | Partition Type: NTFS

Computer Name: HOME | User Name: Kevin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirewallDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"5353:UDP" = 5353:UDP:*:Enabled:Bonjour
"3043:UDP" = 3043:UDP:*:Enabled:Windows Media Format SDK (firefox.exe)
"3042:UDP" = 3042:UDP:*:Enabled:Windows Media Format SDK (firefox.exe)
"3049:UDP" = 3049:UDP:*:Enabled:Windows Media Format SDK (firefox.exe)
"3076:UDP" = 3076:UDP:*:Enabled:Windows Media Format SDK (firefox.exe)
"3077:UDP" = 3077:UDP:*:Enabled:Windows Media Format SDK (firefox.exe)
"3082:UDP" = 3082:UDP:*:Enabled:Windows Media Format SDK (firefox.exe)
"3103:UDP" = 3103:UDP:*:Enabled:Windows Media Format SDK (firefox.exe)
"3102:UDP" = 3102:UDP:*:Enabled:Windows Media Format SDK (firefox.exe)
"3110:UDP" = 3110:UDP:*:Enabled:Windows Media Format SDK (firefox.exe)
"5353:TCP" = 5353:TCP:*:Enabled:Adobe CSI CS4
"3703:TCP" = 3703:TCP:*:Enabled:Adobe Version Cue CS4 Server
"3704:TCP" = 3704:TCP:*:Enabled:Adobe Version Cue CS4 Server
"51000:TCP" = 51000:TCP:*:Enabled:Adobe Version Cue CS4 Server
"51001:TCP" = 51001:TCP:*:Enabled:Adobe Version Cue CS4 Server

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\HP\Digital Imaging\BIN\hposid01.exe" = C:\Program Files\HP\Digital Imaging\BIN\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\BIN\hpqcopy2.exe" = C:\Program Files\HP\Digital Imaging\BIN\hpqcopy2.exe:*:Enabled:hpqcopy2.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\BIN\hpiscnapp.exe" = C:\Program Files\HP\Digital Imaging\BIN\hpiscnapp.exe:*:Enabled:hpiscnapp.exe – (Hewlett-Packard)
"C:\Program Files\Common Files\hp\Digital Imaging\bin\hpqPhotoCrm.exe" = C:\Program Files\Common Files\hp\Digital Imaging\bin\hpqPhotoCrm.exe:*:Enabled:hpqphotocrm.exe – (Hewlett-Packard Development Co. L.P.)
"C:\Program Files\HP\Digital Imaging\BIN\hpqsudi.exe" = C:\Program Files\HP\Digital Imaging\BIN\hpqsudi.exe:*:Enabled:hpqsudi.exe – (Hewlett-Packard Development Co. L.P.)
"C:\Program Files\HP\Digital Imaging\BIN\hpqpsapp.exe" = C:\Program Files\HP\Digital Imaging\BIN\hpqpsapp.exe:*:Enabled:hpqpsapp.exe – (Hewlett-Packard Development Co. L.P.)
"C:\Program Files\HP\Digital Imaging\BIN\hpqpse.exe" = C:\Program Files\HP\Digital Imaging\BIN\hpqpse.exe:*:Enabled:hpqpse.exe – (Hewlett-Packard Development Co. L.P.)
"C:\Program Files\HP\Digital Imaging\BIN\hpqusgm.exe" = C:\Program Files\HP\Digital Imaging\BIN\hpqusgm.exe:*:Enabled:hpqusgm.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\BIN\hpqusgh.exe" = C:\Program Files\HP\Digital Imaging\BIN\hpqusgh.exe:*:Enabled:hpqusgh.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\HP Software Update\hpwucli.exe" = C:\Program Files\HP\HP Software Update\hpwucli.exe:*:Enabled:hpwucli.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\Smart Web Printing\SmartWebPrintExe.exe" = C:\Program Files\HP\Digital Imaging\Smart Web Printing\SmartWebPrintExe.exe:*:Enabled:smartwebprintexe.exe – (Hewlett-Packard Co.)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\WINDOWS\System32\dpvsetup.exe" = C:\WINDOWS\System32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test – (Microsoft Corporation)
"C:\WINDOWS\System32\java.exe" = C:\WINDOWS\System32\java.exe:*:Disabled:Java™ 2 Platform Standard Edition binary – (Sun Microsystems, Inc.)
"E:\Swimming\Meet Manager\SwimMM2.exe" = E:\Swimming\Meet Manager\SwimMM2.exe:*:Enabled:Swim Meet Manager – (HY-TEK Sports Software)
"C:\WINDOWS\System32\ftp.exe" = C:\WINDOWS\System32\ftp.exe:*:Enabled:File Transfer Program – (Microsoft Corporation)
"C:\Program Files\Photo Story 3 for Windows\PhotoStory3.exe" = C:\Program Files\Photo Story 3 for Windows\PhotoStory3.exe:*:Enabled:Photo Story 3 for Windows – (Microsoft Corp.)
"C:\Program Files\HP\Digital Imaging\BIN\hpqcopy2.exe" = C:\Program Files\HP\Digital Imaging\BIN\hpqcopy2.exe:*:Enabled:hpqcopy2.exe – (Hewlett-Packard Co.)
"C:\Program Files\Common Files\hp\Digital Imaging\bin\hpqPhotoCrm.exe" = C:\Program Files\Common Files\hp\Digital Imaging\bin\hpqPhotoCrm.exe:*:Enabled:hpqphotocrm.exe – (Hewlett-Packard Development Co. L.P.)
"C:\Program Files\HP\Digital Imaging\BIN\hpqsudi.exe" = C:\Program Files\HP\Digital Imaging\BIN\hpqsudi.exe:*:Enabled:hpqsudi.exe – (Hewlett-Packard Development Co. L.P.)
"C:\Program Files\HP\Digital Imaging\BIN\hpqpsapp.exe" = C:\Program Files\HP\Digital Imaging\BIN\hpqpsapp.exe:*:Enabled:hpqpsapp.exe – (Hewlett-Packard Development Co. L.P.)
"C:\Program Files\HP\Digital Imaging\BIN\hpqpse.exe" = C:\Program Files\HP\Digital Imaging\BIN\hpqpse.exe:*:Enabled:hpqpse.exe – (Hewlett-Packard Development Co. L.P.)
"C:\Program Files\HP\Digital Imaging\BIN\hpqusgm.exe" = C:\Program Files\HP\Digital Imaging\BIN\hpqusgm.exe:*:Enabled:hpqusgm.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\BIN\hpqusgh.exe" = C:\Program Files\HP\Digital Imaging\BIN\hpqusgh.exe:*:Enabled:hpqusgh.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\HP Software Update\hpwucli.exe" = C:\Program Files\HP\HP Software Update\hpwucli.exe:*:Enabled:hpwucli.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\Smart Web Printing\SmartWebPrintExe.exe" = C:\Program Files\HP\Digital Imaging\Smart Web Printing\SmartWebPrintExe.exe:*:Enabled:smartwebprintexe.exe – (Hewlett-Packard Co.)
"C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" = C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:*:Enabled:Adobe CSI CS4 – (Adobe Systems Incorporated)
"C:\Program Files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe" = C:\Program Files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe:*:Enabled:Adobe Version Cue CS4 Server – (Adobe Systems Incorporated)
"C:\Program Files\AVG\AVG9\avgupd.exe" = C:\Program Files\AVG\AVG9\avgupd.exe:*:Enabled:avgupd.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgnsx.exe" = C:\Program Files\AVG\AVG9\avgnsx.exe:*:Enabled:avgnsx.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe" = C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe – (Hewlett-Packard)
"C:\Program Files\AVG\AVG2012\avgnsx.exe" = C:\Program Files\AVG\AVG2012\avgnsx.exe:*:Enabled:Online Shield – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG2012\avgdiagex.exe" = C:\Program Files\AVG\AVG2012\avgdiagex.exe:*:Enabled:AVG Diagnostics 2012 – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG2012\avgmfapx.exe" = C:\Program Files\AVG\AVG2012\avgmfapx.exe:*:Enabled:AVG Installer – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG2012\avgemcx.exe" = C:\Program Files\AVG\AVG2012\avgemcx.exe:*:Enabled:Personal E-mail Scanner – (AVG Technologies CZ, s.r.o.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4EFC72DA-2314-4E5D-AC8E-1C954CDB8BBF}" = AVG 2012
"{50316C0A-CC2A-460A-9EA5-F486E54AC17D}_is1" = AVG PC Tuneup
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{65179FD8-04C0-40A7-87FC-007F2CD5BF1E}" = LogMeIn
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{91E30409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D92FF8EB-BD77-40AE-B68B-A6BFC6F8661D}" = Windows Live Family Safety
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{E7E84E23-C5C0-4B15-B13A-C63149E59C98}" = AVG 2012
"{EE39FFBD-544E-49E4-A999-6819828EAE91}" = Windows Live Photo Gallery
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F59A9E08-A6A4-4ACF-91F2-D0344956C30B}" = iTunes
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"AVG" = AVG 2012
"CCleaner" = CCleaner
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.60.1.1000
"Mozilla Firefox 4.0.1 (x86 en-GB)" = Mozilla Firefox 4.0.1 (x86 en-GB)
"Secunia PSI" = Secunia PSI (2.0.0.3003)
"WinLiveSuite_Wave3" = Windows Live Essentials

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 9/05/2011 10:23:39 PM | Computer Name = HOME | Source = Application Hang | ID = 1002
Description = Hanging application avgui.exe, version 9.0.0.892, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 10/05/2011 9:10:38 PM | Computer Name = HOME | Source = Application Hang | ID = 1002
Description = Hanging application WINWORD.EXE, version 11.0.8328.0, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 11/05/2011 9:31:37 PM | Computer Name = HOME | Source = Application Error | ID = 1000
Description = Faulting application swimmm2.exe, version 2.0.0.341, faulting module
unknown, version 0.0.0.0, fault address 0x03754b90.

Error - 19/05/2011 7:08:37 PM | Computer Name = HOME | Source = Application Hang | ID = 1002
Description = Hanging application Acrobat.exe, version 9.4.2.220, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 29/05/2011 11:10:56 PM | Computer Name = HOME | Source = Application Error | ID = 1000
Description = Faulting application cfm7.exe, version 7.6.0.0, faulting module itircl.dll,
version 5.2.3790.2453, fault address 0x000091ae.

Error - 16/06/2011 4:36:13 AM | Computer Name = HOME | Source = LoadPerf | ID = 3006
Description = Unable to read the performance counter strings of the 009 language
ID. The Win32 status returned by the call is the first DWORD in Data section.

Error - 18/08/2011 6:49:13 AM | Computer Name = HOME | Source = MsiInstaller | ID = 10005
Description = Product: Windows Live Mail – The installer has encountered an unexpected
error installing this package. This may indicate a problem with this package. The
error code is 2762. The arguments are: , ,

Error - 18/08/2011 6:49:17 AM | Computer Name = HOME | Source = MsiInstaller | ID = 10005
Description = Product: Windows Live Communications Platform – The installer has
encountered an unexpected error installing this package. This may indicate a problem
with this package. The error code is 2762. The arguments are: , ,

Error - 18/08/2011 6:49:17 AM | Computer Name = HOME | Source = MsiInstaller | ID = 10005
Description = Product: Windows Live Communications Platform – The installer has
encountered an unexpected error installing this package. This may indicate a problem
with this package. The error code is 2762. The arguments are: , ,

Error - 12/02/2012 1:14:24 AM | Computer Name = HOME | Source = Microsoft Office 11 | ID = 2000
Description = Accepted Safe Mode action : Microsoft Office Outlook.

[ System Events ]
Error - 18/03/2012 8:10:07 PM | Computer Name = HOME | Source = Service Control Manager | ID = 7001
Description = The Canon Camera Access Library 8 service depends on the SSDP Discovery
Service service which failed to start because of the following error: %%1058

Error - 18/03/2012 8:10:29 PM | Computer Name = HOME | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
TfFsMon TfSysMon

Error - 18/03/2012 8:10:30 PM | Computer Name = HOME | Source = Service Control Manager | ID = 7034
Description = The NVIDIA Display Driver Service service terminated unexpectedly.
It has done this 1 time(s).

Error - 18/03/2012 10:56:44 PM | Computer Name = HOME | Source = Service Control Manager | ID = 7000
Description = The Adobe Active File Monitor V4 service failed to start due to the
following error: %%3

Error - 18/03/2012 10:56:44 PM | Computer Name = HOME | Source = Service Control Manager | ID = 7001
Description = The Canon Camera Access Library 8 service depends on the SSDP Discovery
Service service which failed to start because of the following error: %%1058

Error - 18/03/2012 10:56:55 PM | Computer Name = HOME | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
TfFsMon TfSysMon

Error - 18/03/2012 11:54:31 PM | Computer Name = HOME | Source = DCOM | ID = 10010
Description = The server {98D9A6F1-4696-4B5E-A2E8-36B3F9C1E12C} did not register
with DCOM within the required timeout.

Error - 19/03/2012 12:21:16 AM | Computer Name = HOME | Source = Service Control Manager | ID = 7000
Description = The Adobe Active File Monitor V4 service failed to start due to the
following error: %%3

Error - 19/03/2012 12:21:16 AM | Computer Name = HOME | Source = Service Control Manager | ID = 7001
Description = The Canon Camera Access Library 8 service depends on the SSDP Discovery
Service service which failed to start because of the following error: %%1058

Error - 19/03/2012 12:21:19 AM | Computer Name = HOME | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
TfFsMon TfSysMon


< End of report >
Hi TTGSC and welcome to the forums!
I'm Sunyata and I will be helping you with your computer problems.

Please read the following guidelines which will help to make cleaning your machine easier:

  • Malware logs are often lengthy and can take a lot of time to research and interpret. Please be patient while I review your logs.
  • The fixes I will give you are specific to your problem and should only be used for this issue on this machine.
  • Please make sure to carefully read any instructions posted. If you're not sure, please stop and ask!
  • Please stay with this thread until I tell you your machine appears to be clean. Absence of symptoms does not necessarily mean that all malware is gone.
  • PLEASE DO NOT install/uninstall any programs unless asked to.
  • PLEASE DO NOT run any malware scans other than those requested.
  • Please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
  • I will reply back shortly with instructions

Note to Vista and Windows 7 users:
  • These tools MUST be run from the executable. (.exe) every time you run them
  • These tools MUST be run With Admin Rights (Right click, choose "Run as Administrator")
Hello TTGSC

First,

Please download Listparts
Run the tool, click Scan and post the log (Result.txt) it makes.


Next,

Please download aswMBR to your desktop.

  • Double click the aswMBR icon to run it.
  • When asked if you want to download Avast's virus definitions please select Yes.
  • Click the Scan button to start scan.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]

Part 1 ListParts by Farbar Version: 12-03-2012 03 Ran by [removed] (administrator) on 20-03-2012 at 17:35:05 Windows XP (X86) Running From: C:\downloads Language: 0409 ************************************************************ ========================= Memory info ====================== Percentage of memory in use: 37% Total physical RAM: 511.53 MB Available physical RAM: 317.91 MB Total Pagefile: 1249.98 MB Available Pagefile: 747.34 MB Total Virtual: 2047.88 MB Available Virtual: 2001.39 MB ======================= Partitions =========================
Part 2 aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software Run date: 2012-03-20 17:36:53 —————————– 17:36:53.109 OS Version: Windows 5.1.2600 Service Pack 3 17:36:53.109 Number of processors: 1 586 0x209 17:36:53.109 ComputerName: HOME UserName: 17:36:58.109 Initialize success 17:40:30.781 AVAST engine defs: 12031700 17:42:01.125 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4 17:42:01.125 Disk 0 Vendor: SAMSUNG_SP0802N TK100-23 Size: 76351MB BusType: 3 17:42:01.125 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP0T1L0-c 17:42:01.125 Disk 1 Vendor: WDC_WD2500JB-00REA0 20.00K20 Size: 238475MB BusType: 3 17:42:01.156 Disk 0 MBR read successfully 17:42:01.156 Disk 0 MBR scan 17:42:01.296 Disk 0 Windows XP default MBR code 17:42:01.312 Disk 0 Partition 1 80 (A) 0C FAT32 LBA MSWIN4.1 76347 MB offset 63 17:42:01.312 Disk 0 scanning sectors +156360645 17:42:01.359 Disk 0 scanning C:\WINDOWS\system32\drivers 17:42:59.828 Service scanning 17:43:27.875 Modules scanning 17:43:34.578 Disk 0 trace - called modules: 17:43:34.921 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS 17:43:34.921 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x82f89ab8] 17:43:34.937 3 CLASSPNP.SYS[f8635fd7] -> nt!IofCallDriver -> \Device\00000060[0x82f84f18] 17:43:34.937 5 ACPI.sys[f85ac620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-4[0x82f88d98] 17:43:35.609 AVAST engine scan C:\WINDOWS 17:44:23.609 AVAST engine scan C:\WINDOWS\system32 17:51:13.375 AVAST engine scan C:\WINDOWS\system32\drivers 17:51:55.984 AVAST engine scan C:\Documents and Settings\Kevin 17:56:11.140 AVAST engine scan C:\Documents and Settings\All Users 17:58:19.625 Scan finished successfully 22:51:49.593 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Kevin\My Documents\MBR.dat" 22:51:49.671 The log file has been saved successfully to "C:\Documents and Settings\Kevin\My Documents\aswMBR.txt"
Hello TTGSC

I don't know what kind of speed you are used to on this machine, but the biggest problem I see is in it's configuration:
  • The machine only has 500mb of physical memory. Many of today's common applications won't work well with less than twice that. Quadruple that amount and you should see a big difference in performance.
  • Your XP operating system is installed on a partition that is formatted in FAT32. You have another partition on the machine formatted in NTFS (your E: drive), which is a much more modern file system. Your E: drive has plenty of room to house your OS. I'd consider installing XP on that partition.
  • Your paging file is on the same partition as your OS. You get better performance when you keep your paging file on a separate partition.

In terms of installed software, this is what I see:
  • You have the AVG 2012 antimalware suite installed. I like AVG and use it myself, but it is a bit of a memory hog - and you can't afford it. If you are not going to upgrade your memory, I'd suggest uninstalling AVG and installing Avira. Avira is also a very good anti-virus app and uses less resources.
  • Secuna PSI - This keeps all your progams up to date with the latest version, which is important to keep malware at bay. But there are some complaints about how much CPU it can use. I would uninstall it and use FileHippo, which does the same thing - only you will have to remember to run it from time to time.
  • It looks like all your internet activity is routed through a proxy which keeps count of your download byte total. I would look into a different ISP arrangement, for I would think this must slow down your browsing experience.
There is some garbage and a wee bit of malware on your machine, which we can remove here:
  • Please reopen [external image: Posted Image].
  • Copy and Paste the following code into the [external image: Posted Image] textbox. Do not include the word "Code"

    :Services
    
    :OTL
    O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://www.pcpitstop.com/betapit/PCPitStop.CAB (Reg Error: Key error.)
    O16 - DPF: {1671869C-25B3-4C80-9446-8AE6111F8765} http://thesims.ea.com/teleport/hotdate/NPC…otDateTeleX.cab (Reg Error: Key error.)
    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} http://messenger.zone.msn.com/binary/MineS…er.cab30149.cab (Reg Error: Key error.)
    O16 - DPF: {3D3B42C2-11BF-4732-A304-A01384B70D68} http://picasaweb.google.com/s/v/58.09/uploader2.cab (Reg Error: Key error.)
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://coolbananas007.spaces.msn.com//Phot…ad/MsnPUpld.cab (Reg Error: Key error.)
    O16 - DPF: {5D1E3FA5-64FF-4387-9418-F1D67AFB2247} http://thesims.ea.com/teleport/superstar/M…erstarTeleX.cab (Reg Error: Key error.)
    O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/EN-AU/a-UNO1/GAME_UNO1.cab (Reg Error: Key error.)
    O16 - DPF: {8629CFEB-C31A-4429-9BB0-8765A8A24FDA} http://thesims.ea.com/teleport/unleashed/L…hedLotTeleX.cab (Reg Error: Key error.)
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
    O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab (Reg Error: Key error.)
    O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} http://messenger.zone.msn.com/binary/Solit…wn.cab31267.cab (Reg Error: Key error.)
    O33 - MountPoints2\{53a1277c-0640-11de-bdde-000c6edf1785}\Shell\AutoRun\command - "" = ReCYClER\\explorer.exe
    O33 - MountPoints2\{53a1277c-0640-11de-bdde-000c6edf1785}\Shell\eXPLOre\cOMMANd - "" = rECyCLeR\\explorer.exe
    O33 - MountPoints2\{53a1277c-0640-11de-bdde-000c6edf1785}\Shell\OPen\coMMaNd - "" = rECYCLEr\explorer.exe
    O33 - MountPoints2\{edea2390-d2f8-11dd-bd6e-000c6edf1785}\Shell\AutoRun\command - "" = G:\cold\hott\raidhost.exe
    O33 - MountPoints2\{edea2390-d2f8-11dd-bd6e-000c6edf1785}\Shell\Explore\Command - "" = G:\cold\hott\raidhost.exe
    O33 - MountPoints2\{edea2390-d2f8-11dd-bd6e-000c6edf1785}\Shell\open\command - "" = G:\cold\hott\raidhost.exe
    [6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
    [3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
    [2 C:\Documents and Settings\Kevin\My Documents\*.tmp files -> C:\Documents and Settings\Kevin\My Documents\*.tmp -> ]
    [1 C:\*.tmp files -> C:\*.tmp -> ]
    
    :Files
    C:\Documents and Settings\Kevin\Application Data\LimeWire
    
    :Commands
    [purity]
    [emptytemp]
    [EMPTYFLASH]
    [CREATERESTOREPOINT] 
    [Reboot]

  • Push [external image: Posted Image]
  • OTL may ask to reboot the machine. Please do so if asked.
  • Click [external image: Posted Image].
  • A report will open. Copy and Paste that report in your next reply.
  • If the machine reboots, the log will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.

This will inoculate your machine against the type of malware we found there, plus all the USB media you plug into it:

download and use Panda USB Vaccine which allows for computer and usb vaccination..
alternate download link 1
alternate download link 2

  • Double-click on USBVaccineSetup.exe to install the program to C:\Program Files\Panda USB Vaccine.
  • Read and accept the license agreement, then click Next.
  • When setup completes, make sure "Launch Panda USB Vaccine" is checked and click Finish to open the program.
  • Click the Vaccinate computer button. It should now show a green checkmark and confirm Computer vaccinated.
  • Hold down the Shift key and insert your USB flash drive.
  • When the name of the drive appears in the dialog box, click the button to Vaccinate USB drive(s).
  • Exit the program when done
– Computer Vaccination will prevent any AutoRun file from running, regardless of whether the removable device is infected or not.

– USB Vaccination disables the autorun file so it cannot be read, modified or replaced and creates a hidden AUTORUN_.INF on the flash drive partition as protection against malevolent code by preventing a malicious autorun file from being installed. The Panda Resarch Blog advises that once USB drives have been vaccinated, they cannot be reversed except with a format. If you do this, be sure to back up your data files first or they will be lost during the formatting process.



All processes killed ========== SERVICES/DRIVERS ========== ========== OTL ========== Starting removal of ActiveX control {0E5F0222-96B9-11D3-8997-00104BD12D94} C:\WINDOWS\Downloaded Program Files\PCPitstop.inf not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{0E5F0222-96B9-11D3-8997-00104BD12D94}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0E5F0222-96B9-11D3-8997-00104BD12D94}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{0E5F0222-96B9-11D3-8997-00104BD12D94}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0E5F0222-96B9-11D3-8997-00104BD12D94}\ not found. Starting removal of ActiveX control {1671869C-25B3-4C80-9446-8AE6111F8765} C:\WINDOWS\Downloaded Program Files\MaxisHotDateTeleX.inf not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1671869C-25B3-4C80-9446-8AE6111F8765}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1671869C-25B3-4C80-9446-8AE6111F8765}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{1671869C-25B3-4C80-9446-8AE6111F8765}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1671869C-25B3-4C80-9446-8AE6111F8765}\ not found. Starting removal of ActiveX control {2917297F-F02B-4B9D-81DF-494B6333150B} Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{2917297F-F02B-4B9D-81DF-494B6333150B}\DownloadInformation\\INF . Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{2917297F-F02B-4B9D-81DF-494B6333150B}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2917297F-F02B-4B9D-81DF-494B6333150B}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2917297F-F02B-4B9D-81DF-494B6333150B}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2917297F-F02B-4B9D-81DF-494B6333150B}\ not found. Starting removal of ActiveX control {3D3B42C2-11BF-4732-A304-A01384B70D68} C:\WINDOWS\Downloaded Program Files\default.inf not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{3D3B42C2-11BF-4732-A304-A01384B70D68}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3D3B42C2-11BF-4732-A304-A01384B70D68}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{3D3B42C2-11BF-4732-A304-A01384B70D68}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3D3B42C2-11BF-4732-A304-A01384B70D68}\ not found. Starting removal of ActiveX control {4F1E5B1A-2A80-42CA-8532-2D05CB959537} C:\WINDOWS\Downloaded Program Files\MsnPUpld.inf not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{4F1E5B1A-2A80-42CA-8532-2D05CB959537}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4F1E5B1A-2A80-42CA-8532-2D05CB959537}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{4F1E5B1A-2A80-42CA-8532-2D05CB959537}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4F1E5B1A-2A80-42CA-8532-2D05CB959537}\ not found. Starting removal of ActiveX control {5D1E3FA5-64FF-4387-9418-F1D67AFB2247} C:\WINDOWS\Downloaded Program Files\MaxisSuperstarTeleX.inf not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{5D1E3FA5-64FF-4387-9418-F1D67AFB2247}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5D1E3FA5-64FF-4387-9418-F1D67AFB2247}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5D1E3FA5-64FF-4387-9418-F1D67AFB2247}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5D1E3FA5-64FF-4387-9418-F1D67AFB2247}\ not found. Starting removal of ActiveX control {5D6F45B3-9043-443D-A792-115447494D24} C:\WINDOWS\Downloaded Program Files\GAME_UNO1.INF not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{5D6F45B3-9043-443D-A792-115447494D24}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5D6F45B3-9043-443D-A792-115447494D24}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5D6F45B3-9043-443D-A792-115447494D24}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5D6F45B3-9043-443D-A792-115447494D24}\ not found. Starting removal of ActiveX control {8629CFEB-C31A-4429-9BB0-8765A8A24FDA} C:\WINDOWS\Downloaded Program Files\MaxisUnleashedLotTeleX.inf not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8629CFEB-C31A-4429-9BB0-8765A8A24FDA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8629CFEB-C31A-4429-9BB0-8765A8A24FDA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8629CFEB-C31A-4429-9BB0-8765A8A24FDA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8629CFEB-C31A-4429-9BB0-8765A8A24FDA}\ not found. Starting removal of ActiveX control {C3F79A2B-B9B4-4A66-B012-3EE46475B072} Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{C3F79A2B-B9B4-4A66-B012-3EE46475B072}\DownloadInformation\\INF . Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{C3F79A2B-B9B4-4A66-B012-3EE46475B072}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C3F79A2B-B9B4-4A66-B012-3EE46475B072}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{C3F79A2B-B9B4-4A66-B012-3EE46475B072}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C3F79A2B-B9B4-4A66-B012-3EE46475B072}\ not found. Starting removal of ActiveX control {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA}\ not found. Starting removal of ActiveX control {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA}\ not found. Starting removal of ActiveX control {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA}\ not found. Starting removal of ActiveX control {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}\ not found. Starting removal of ActiveX control {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found. Starting removal of ActiveX control {E2883E8F-472F-4FB0-9522-AC9BF37916A7} C:\WINDOWS\Downloaded Program Files\gp.inf not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found. Starting removal of ActiveX control {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{F5A7706B-B9C0-4C89-A715-7A0C6B05DD48}\DownloadInformation\\INF . Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{F5A7706B-B9C0-4C89-A715-7A0C6B05DD48}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F5A7706B-B9C0-4C89-A715-7A0C6B05DD48}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{F5A7706B-B9C0-4C89-A715-7A0C6B05DD48}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F5A7706B-B9C0-4C89-A715-7A0C6B05DD48}\ not found. Starting removal of ActiveX control {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{F6BF0D00-0B2A-4A75-BF7B-F385591623AF}\DownloadInformation\\INF . Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{F6BF0D00-0B2A-4A75-BF7B-F385591623AF}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F6BF0D00-0B2A-4A75-BF7B-F385591623AF}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{F6BF0D00-0B2A-4A75-BF7B-F385591623AF}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F6BF0D00-0B2A-4A75-BF7B-F385591623AF}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{53a1277c-0640-11de-bdde-000c6edf1785}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{53a1277c-0640-11de-bdde-000c6edf1785}\ not found. File C:\ReCYClER\\explorer.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{53a1277c-0640-11de-bdde-000c6edf1785}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{53a1277c-0640-11de-bdde-000c6edf1785}\ not found. File C:\rECyCLeR\\explorer.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{53a1277c-0640-11de-bdde-000c6edf1785}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{53a1277c-0640-11de-bdde-000c6edf1785}\ not found. File C:\rECYCLEr\explorer.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{edea2390-d2f8-11dd-bd6e-000c6edf1785}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{edea2390-d2f8-11dd-bd6e-000c6edf1785}\ not found. File G:\cold\hott\raidhost.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{edea2390-d2f8-11dd-bd6e-000c6edf1785}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{edea2390-d2f8-11dd-bd6e-000c6edf1785}\ not found. File G:\cold\hott\raidhost.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{edea2390-d2f8-11dd-bd6e-000c6edf1785}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{edea2390-d2f8-11dd-bd6e-000c6edf1785}\ not found. File G:\cold\hott\raidhost.exe not found. C:\WINDOWS\System32\SET63.tmp deleted successfully. C:\WINDOWS\System32\SET66.tmp deleted successfully. C:\WINDOWS\System32\SET72.tmp deleted successfully. C:\WINDOWS\System32\setb5.tmp deleted successfully. C:\WINDOWS\System32\CONFIG.TMP deleted successfully. C:\WINDOWS\System32\SET74.tmp deleted successfully. C:\WINDOWS\002345_.tmp deleted successfully. C:\WINDOWS\msdownld.tmp folder deleted successfully. C:\WINDOWS\005531_.tmp deleted successfully. C:\Documents and Settings\Kevin\My Documents\~WRL1726.tmp deleted successfully. C:\Documents and Settings\Kevin\My Documents\~WRL0915.tmp deleted successfully. C:\USMT.TMP folder deleted successfully. ========== FILES ========== C:\Documents and Settings\Kevin\Application Data\LimeWire\browser\xulrunner\res\html folder moved successfully. C:\Documents and Settings\Kevin\Application Data\LimeWire\browser\xulrunner\res\fonts folder moved successfully. C:\Documents and Settings\Kevin\Application Data\LimeWire\browser\xulrunner\res\entityTables folder moved successfully. C:\Documents and Settings\Kevin\Application Data\LimeWire\browser\xulrunner\res\dtd folder moved successfully. C:\Documents and Settings\Kevin\Application Data\LimeWire\browser\xulrunner\res folder moved successfully. C:\Documents and Settings\Kevin\Application Data\LimeWire\browser\xulrunner\plugins folder moved successfully. C:\Documents and Settings\Kevin\Application Data\LimeWire\browser\xulrunner\modules folder moved successfully. C:\Documents and Settings\Kevin\Application Data\LimeWire\browser\xulrunner\greprefs folder moved successfully. C:\Documents and Settings\Kevin\Application Data\LimeWire\browser\xulrunner\dictionaries folder moved successfully. C:\Documents and Settings\Kevin\Application Data\LimeWire\browser\xulrunner\defaults\profile\chrome folder moved successfully. C:\Documents and Settings\Kevin\Application Data\LimeWire\browser\xulrunner\defaults\profile\US\chrome folder moved successfully. C:\Documents and Settings\Kevin\Application Data\LimeWire\browser\xulrunner\defaults\profile\US folder moved successfully. C:\Documents and Settings\Kevin\Application Data\LimeWire\browser\xulrunner\defaults\profile folder moved successfully. C:\Documents and Settings\Kevin\Application Data\LimeWire\browser\xulrunner\defaults\pref folder moved successfully. C:\Documents and Settings\Kevin\Application Data\LimeWire\browser\xulrunner\defaults\autoconfig folder moved successfully. C:\Documents and Settings\Kevin\Application Data\LimeWire\browser\xulrunner\defaults folder moved successfully. C:\Documents and Settings\Kevin\Application Data\LimeWire\browser\xulrunner\components folder moved successfully. C:\Documents and Settings\Kevin\Application Data\LimeWire\browser\xulrunner\chrome folder moved successfully. C:\Documents and Settings\Kevin\Application Data\LimeWire\browser\xulrunner folder moved successfully. C:\Documents and Settings\Kevin\Application Data\LimeWire\browser folder moved successfully. C:\Documents and Settings\Kevin\Application Data\LimeWire\promotion folder moved successfully. C:\Documents and Settings\Kevin\Application Data\LimeWire\.AppSpecialShare folder moved successfully. C:\Documents and Settings\Kevin\Application Data\LimeWire\.NetworkShare\Incomplete folder moved successfully. C:\Documents and Settings\Kevin\Application Data\LimeWire\.NetworkShare folder moved successfully. C:\Documents and Settings\Kevin\Application Data\LimeWire\mozilla-profile\Cache folder moved successfully. C:\Documents and Settings\Kevin\Application Data\LimeWire\mozilla-profile\updates\0 folder moved successfully. C:\Documents and Settings\Kevin\Application Data\LimeWire\mozilla-profile\updates folder moved successfully. C:\Documents and Settings\Kevin\Application Data\LimeWire\mozilla-profile\extensions folder moved successfully. C:\Documents and Settings\Kevin\Application Data\LimeWire\mozilla-profile folder moved successfully. C:\Documents and Settings\Kevin\Application Data\LimeWire\certificate folder moved successfully. C:\Documents and Settings\Kevin\Application Data\LimeWire\themes\windows_theme folder moved successfully. C:\Documents and Settings\Kevin\Application Data\LimeWire\themes\other_theme folder moved successfully. C:\Documents and Settings\Kevin\Application Data\LimeWire\themes\limewire_theme folder moved successfully. C:\Documents and Settings\Kevin\Application Data\LimeWire\themes\classic_theme folder moved successfully. C:\Documents and Settings\Kevin\Application Data\LimeWire\themes\black_theme folder moved successfully. C:\Documents and Settings\Kevin\Application Data\LimeWire\themes folder moved successfully. C:\Documents and Settings\Kevin\Application Data\LimeWire\xml\schemas folder moved successfully. C:\Documents and Settings\Kevin\Application Data\LimeWire\xml\misc folder moved successfully. C:\Documents and Settings\Kevin\Application Data\LimeWire\xml\data folder moved successfully. C:\Documents and Settings\Kevin\Application Data\LimeWire\xml folder moved successfully. C:\Documents and Settings\Kevin\Application Data\LimeWire folder moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: All Users User: NetworkService ->Temp folder emptied: 107440 bytes ->Temporary Internet Files folder emptied: 406556840 bytes User: LocalService ->Temp folder emptied: 66016 bytes ->Temporary Internet Files folder emptied: 65737 bytes ->Flash cache emptied: 300 bytes User: Kevin ->Temp folder emptied: 54283571 bytes ->Temporary Internet Files folder emptied: 52032980 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 35012632 bytes ->Apple Safari cache emptied: 0 bytes ->Flash cache emptied: 456 bytes User: Rebecca ->Temp folder emptied: 83287936 bytes ->Temporary Internet Files folder emptied: 283482152 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 28133762 bytes ->Flash cache emptied: 218233 bytes User: Jades ->Temp folder emptied: 69750452 bytes ->Temporary Internet Files folder emptied: 246192490 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 30114777 bytes ->Flash cache emptied: 17546 bytes User: Incomplete User: LogMeInRemoteUser ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes User: LogMeInRemoteUser.HOME ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Guest ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 36621 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 106549234 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33726 bytes RecycleBin emptied: 25450080 bytes Total Files Cleaned = 1,356.00 mb [EMPTYFLASH] User: Default User User: All Users User: NetworkService User: LocalService ->Flash cache emptied: 0 bytes User: Kevin ->Flash cache emptied: 0 bytes User: Rebecca ->Flash cache emptied: 0 bytes User: Jades ->Flash cache emptied: 0 bytes User: Incomplete User: LogMeInRemoteUser User: Administrator User: LogMeInRemoteUser.HOME User: Guest Total Flash Files Cleaned = 0.00 mb Restore point Set: OTL Restore Point (0) OTL by OldTimer - Version 3.2.39.1 log created on 03222012_172250 Files\Folders moved on Reboot… Registry entries deleted on Reboot…
Hello TTGSC

Speed has definitely increased

Very good :thumbup:

Let's do a sweep to see if there is anything we missed…


Scan For Malware:

Download and save to your desktop Malwarebytes Anti-Malware

Double Click mbam-setup.exe to install the application.

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately.



Do An Online Scan For Viruses:

Note: It is recommended to disable on-board anti-virus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your anti-virus along with your anti-spyware programs.

  • Hold down Control and click on the following link to open ESET OnlineScan in a new window. ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as MyEsetScan. Include the contents of this report in your next reply.
  • Push the Back button.
  • Push Finish
In your next reply please post the logs created by Malwarebytes and the ESET Online Scan.
Might have to rephrase my last message, its fast than it was, it still gets stuck trying to operate programs. Malwarebytes Anti-Malware (Trial) 1.60.1.1000 www.malwarebytes.org Database version: v2012.03.22.05 Windows XP Service Pack 3 x86 FAT32 Internet Explorer 7.0.5730.13 Kevin :: HOME [administrator] Protection: Disabled 23/03/2012 8:30:31 PM mbam-log-2012-03-23 (20-30-31).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 313444 Time elapsed: 14 minute(s), 22 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end)
C:\System Volume Information\_restore{212DD8E2-26DF-40B6-98B2-3A61566F26A8}\RP639\A0093792.exe a variant of Win32/Toolbar.Widgi application C:\System Volume Information\_restore{212DD8E2-26DF-40B6-98B2-3A61566F26A8}\RP639\A0093793.exe a variant of Win32/Toolbar.Widgi application
Hello TTGSC

Your ESET scan found a bit of malware on one of your restore points. We'll just remove all your restore points and set a new one…

  • Please reopen [external image: Posted Image].
  • Copy and Paste the following code into the [external image: Posted Image] textbox. Do not include the word "Code"

    :Commands
    [CLEARALLRESTOREPOINTS]

  • Push [external image: Posted Image]
  • OTL may ask to reboot the machine. Please do so if asked.
  • Click [external image: Posted Image].
  • A report will open. Copy and Paste that report in your next reply.
  • If the machine reboots, the log will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.

Next, we'll move your paging file to your E: drive, and check a couple other settings, which should improve performance further…

  • Click Start, click Run, type sysdm.cpl in the Run box, and then press ENTER to open the System Properties dialog box.
  • Click the Advanced tab, and then under Performance click Settings.
  • Click the Advanced tab
  • Under Processor scheduling:
    • Click Programs to assign more processor resources to the foreground programs. This setting is recommended for most users.
  • Under Memory Usage:
    • Click Programs . This option allocates more memory to your programs.
  • Under Virtual memory click Change. :
    • Select Drive E:
    • Under Paging file size for selected drive, click Custom size, type 1536 in the Initial size (MB) and 2048 for Maximum size (MB) box, and then click Set.

  • Select Drive C:
  • Under Paging file size for selected drive, click No Paging File and then click Set.
  • You may get a warning, but click Yes anyway
Reboot your computer

Do you notice any further difference in performance?
========== COMMANDS ========== Restore points cleared and new OTL Restore Point set! OTL by OldTimer - Version 3.2.39.1 log created on 03252012_170959
Performance is a lot better than when we started. i will monitor it over the new few start ups. that's where the problem was yesterday it would take forever to get going, after a while it worked pretty good.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI