This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Extremely slow computer [Solved]

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi Saquin,

It is important for you to complete the requested scans and fixes in a timely manner. Failing to do so may be allowing the lingering malware to fester or respawn. Subsequently delaying us from getting your computer clean.

To assist in the process please remember the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.

DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.

= = = = = = = = = =

Download AdwCleaner from here and save it to your desktop.
  • Run AdwCleaner and select Delete
  • Once done it will ask to reboot, allow the reboot
  • On reboot a log will be produced, please attach the content of the log to your next reply
Next
  • Re-run OTL (it should be located on your desktop).
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Uncheck the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open one notepad window. OTL.Txt.
    Note:The log can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of the file, and post it with your next reply.
Next

Please download aswMBR to your desktop.
  • Double click the aswMBR icon to run it.
    Vista and Windows 7 users right click the icon and choose "Run as administrator".
  • Click the Scan button to start scan.
  • When it finishes, press the save log button, save the log file to your desktop.
[external image: Posted Image]
Click the image to enlarge it

In your next post please provide the following:
  • AdwCleaner log
  • OTL.txt
  • aswMBR log
# AdwCleaner v2.007 - Logfile created 11/17/2012 at 03:22:14
# Updated 06/11/2012 by Xplode
# Operating system : Microsoft Windows XP Service Pack 3 (32 bits)
# User : Anna - P-EE951AC334294
# Boot Mode : Normal
# Running from : C:\Documents and Settings\Anna\My Documents\Downloads\AdwCleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****


***** [Registry] *****

Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}
Key Deleted : HKCU\Software\Softonic

***** [Internet Browsers] *****

-\\ Internet Explorer v8.0.6001.18702

[OK] Registry is clean.

-\\ Mozilla Firefox v15.0 (en-US)

Profile name : default
File : C:\Documents and Settings\Anna\Application Data\Mozilla\Firefox\Profiles\jomfg8s5.default\prefs.js

[OK] File is clean.

Profile name : default
File : C:\Documents and Settings\Administrator.P-EE951AC334294.000\Application Data\Mozilla\Firefox\Profiles\094hgi5n.default\prefs.js

[OK] File is clean.

*************************

AdwCleaner[R1].txt - [1353 octets] - [17/11/2012 03:20:33]
AdwCleaner[S2].txt - [1137 octets] - [17/11/2012 03:22:14]

########## EOF - C:\AdwCleaner[S2].txt - [1197 octets] ##########



OTL logfile created on: 11/17/2012 3:28:34 AM - Run 4
OTL by OldTimer - Version 3.2.69.0 Folder = E:\homework
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

988.42 Mb Total Physical Memory | 388.42 Mb Available Physical Memory | 39.30% Memory free
2.32 Gb Paging File | 1.60 Gb Available in Paging File | 69.23% Paging File free
Paging file location(s): C:\pagefile.sys 1476 2952 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.05 Gb Total Space | 130.42 Gb Free Space | 87.50% Space Free | Partition Type: NTFS
Drive E: | 953.00 Mb Total Space | 278.66 Mb Free Space | 29.24% Space Free | Partition Type: FAT

Computer Name: P-EE951AC334294 | User Name: Anna | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - E:\homework\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Constant Guard Protection Suite\IDVaultSvc.exe (White Sky, Inc.)
PRC - C:\Program Files\Constant Guard Protection Suite\IDVault.exe (White Sky, Inc.)
PRC - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe (Oracle Corporation)
PRC - C:\Program Files\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe (Logitech Inc.)
PRC - C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.)
PRC - C:\Program Files\Logitech\LWS\Webcam Software\CameraHelperShell.exe ()
PRC - C:\Program Files\Common Files\LogiShrd\LQCVFX\COCIManager.exe ()
PRC - C:\Program Files\SFT\GuardedID\GIDD.exe (StrikeForce Technologies Inc.)
PRC - C:\Program Files\Norton Security Suite\Engine\5.2.2.3\ccsvchst.exe (Symantec Corporation)
PRC - C:\WINDOWS\system32\nlssrv32.exe (Nalpeiron Ltd.)
PRC - C:\Program Files\Gigabyte\EasySaver\essvr.exe ()
PRC - C:\Program Files\DeviceVM\Browser Configuration Utility\BCUService.exe (DeviceVM, Inc.)
PRC - C:\Program Files\DeviceVM\Browser Configuration Utility\BCU.exe (DeviceVM, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\PSIService.exe ()
PRC - C:\Program Files\Palm\Hotsync.exe (PalmSource, Inc)


========== Modules (No Company Name) ==========

MOD - C:\WINDOWS\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.Xml.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll ()
MOD - C:\Program Files\Constant Guard Protection Suite\IdVaultCore.XmlSerializers.dll ()
MOD - C:\Program Files\Constant Guard Protection Suite\sqlite3.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\WindowsBase\3.0.0.0__31bf3856ad364e35\WindowsBase.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\PresentationFramework\3.0.0.0__31bf3856ad364e35\PresentationFramework.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\PresentationCore.dll ()
MOD - C:\Program Files\Common Files\LogiShrd\LWSPlugins\LWS\Applets\CameraHelper\DevManagerCore.dll ()
MOD - C:\Program Files\Logitech\LWS\Webcam Software\CameraHelperShell.exe ()
MOD - C:\Program Files\Common Files\LogiShrd\LQCVFX\COCIManager.exe ()
MOD - C:\Program Files\Logitech\LWS\Webcam Software\QTXml4.dll ()
MOD - C:\Program Files\Logitech\LWS\Webcam Software\ImageFormats\QJpeg4.dll ()
MOD - C:\Program Files\Logitech\LWS\Webcam Software\ImageFormats\QGif4.dll ()
MOD - C:\Program Files\Logitech\LWS\Webcam Software\QTGui4.dll ()
MOD - C:\Program Files\Logitech\LWS\Webcam Software\QTCore4.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.ServiceModel\3.0.0.0__b77a5c561934e089\System.ServiceModel.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Serialization\3.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.IdentityModel\3.0.0.0__b77a5c561934e089\System.IdentityModel.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\SMDiagnostics\3.0.0.0__b77a5c561934e089\SMDiagnostics.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.WorkflowServices\3.5.0.0__31bf3856ad364e35\System.WorkflowServices.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.ServiceModel.Web\3.5.0.0__31bf3856ad364e35\System.ServiceModel.Web.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\PresentationFramework.Luna\3.0.0.0__31bf3856ad364e35\PresentationFramework.Luna.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\WindowsFormsIntegration\3.0.0.0__31bf3856ad364e35\WindowsFormsIntegration.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\UIAutomationTypes\3.0.0.0__31bf3856ad364e35\UIAutomationTypes.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\UIAutomationProvider\3.0.0.0__31bf3856ad364e35\UIAutomationProvider.dll ()
MOD - C:\Program Files\Gigabyte\EasySaver\essvr.exe ()
MOD - C:\Program Files\DeviceVM\Browser Configuration Utility\sqlite3.dll ()
MOD - C:\WINDOWS\system32\EasyHook32.dll ()
MOD - C:\Program Files\Gigabyte\EasySaver\ycc.dll ()
MOD - C:\WINDOWS\system32\PSIService.exe ()


========== Services (SafeList) ==========

SRV - (AppMgmt) – %SystemRoot%\System32\appmgmts.dll File not found
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (IDVaultSvc) – C:\Program Files\Constant Guard Protection Suite\IDVaultSvc.exe (White Sky, Inc.)
SRV - (SkypeUpdate) – C:\Program Files\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (JavaQuickStarterService) – C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe (Oracle Corporation)
SRV - (UMVPFSrv) – C:\Program Files\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe (Logitech Inc.)
SRV - (N360) – C:\Program Files\Norton Security Suite\Engine\5.2.2.3\ccSvcHst.exe (Symantec Corporation)
SRV - (nlsX86cc) – C:\WINDOWS\system32\nlssrv32.exe (Nalpeiron Ltd.)
SRV - (ES lite Service) – C:\Program Files\Gigabyte\EasySaver\essvr.exe ()
SRV - (BCUService) – C:\Program Files\DeviceVM\Browser Configuration Utility\BCUService.exe (DeviceVM, Inc.)
SRV - (ProtexisLicensing) – C:\WINDOWS\system32\PSIService.exe ()


========== Driver Services (SafeList) ==========

DRV - (WDICA) – File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (Changer) – File not found
DRV - (gdrv) – C:\WINDOWS\gdrv.sys (Windows ® 2000 DDK provider)
DRV - (NAVEX15) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\VirusDefs\20121116.020\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\VirusDefs\20121116.020\NAVENG.SYS (Symantec Corporation)
DRV - (IDSxpx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\IPSDefs\20121116.001\IDSXpx86.sys (Symantec Corporation)
DRV - (BHDrvx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\BASHDefs\20121106.001\BHDrvx86.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (LVUVC) – C:\WINDOWS\system32\drivers\lvuvc.sys (Logitech Inc.)
DRV - (LVRS) – C:\WINDOWS\system32\drivers\lvrs.sys (Logitech Inc.)
DRV - (PalmUSBD) – C:\WINDOWS\system32\drivers\PalmUSBD.sys (PalmSource, Inc.)
DRV - (SymEvent) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (GIDv2) – C:\WINDOWS\System32\drivers\gidv2.sys (StrikeForce Technologies, Inc.)
DRV - (SYMTDI) – C:\WINDOWS\system32\drivers\N360\0502020.003\symtdi.sys (Symantec Corporation)
DRV - (SRTSP) – C:\WINDOWS\system32\drivers\N360\0502020.003\srtsp.sys (Symantec Corporation)
DRV - (SRTSPX) – C:\WINDOWS\system32\drivers\N360\0502020.003\srtspx.sys (Symantec Corporation)
DRV - (SymEFA) – C:\WINDOWS\system32\drivers\N360\0502020.003\symefa.sys (Symantec Corporation)
DRV - (SymDS) – C:\WINDOWS\system32\drivers\N360\0502020.003\symds.sys (Symantec Corporation)
DRV - (SymIRON) – C:\WINDOWS\system32\drivers\N360\0502020.003\ironx86.sys (Symantec Corporation)
DRV - (RTL8192su) – C:\WINDOWS\system32\drivers\RTL8192su.sys (Realtek Semiconductor Corporation )
DRV - (IntcAzAudAddService) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (RTLE8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (Monfilt) – C:\WINDOWS\system32\drivers\Monfilt.sys (Creative Technology Ltd.)
DRV - (Ambfilt) – C:\WINDOWS\system32\drivers\Ambfilt.sys (Creative)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}

IE - HKCU\..\URLSearchHook: {BC86E1AB-EDA5-4059-938F-CE307B0C6F0A} - C:\Program Files\DeviceVM\Browser Configuration Utility\AddressBarSearch.dll (DeviceVM, Inc.)
IE - HKCU\..\SearchScopes,DefaultScope =
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{0A65ED42-75AD-4bbe-8E8B-EF542DC9B1AD}: "URL" = http://search.yahoo.com/search?p={searchTe…m&type=IEBD
IE - HKCU\..\SearchScopes\{3725716F-C2A9-4c1e-968D-23988B72A3A6}: "URL" = http://www.google.com/custom?client=pub-37…q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.com/firefox"
FF - prefs.js..extensions.enabledAddons: [removed]:0.79.1
FF - prefs.js..extensions.enabledAddons: {84625510-7e5d-11e0-a411-0800200c9a66}:1.15
FF - prefs.js..extensions.enabledAddons: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:[removed] - 3
FF - prefs.js..extensions.enabledAddons: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:2011.7.13.2
FF - prefs.js..extensions.enabledItems: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}:5.6.0.8442
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:10.1.0.68 - 1
FF - prefs.js..extensions.enabledItems: [removed]:0.79.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}:6.0.29
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20120302
FF - prefs.js..extensions.enabledItems: {5A170DD3-63CA-4c58-93B7-DE9FF536C2FF}:1.8.81
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_4_402_265.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.1: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1: C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\IPSFFPlgn\ [2012/02/16 03:22:31 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\coFFPlgn_2011_7_13_2 [2012/11/17 03:24:46 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{6D5C8FC4-DE46-41bf-9092-93F0F78E9115}: C:\Documents and Settings\All Users\Application Data\Norton\{78CA3BF0-9C3B-40e1-B46D-38C877EF059A}\NSM_2.2.0.28\coFFFw\
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/10/28 06:32:38 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins

[2011/08/13 23:48:19 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Anna\Application Data\Mozilla\Extensions
[2012/11/09 06:26:57 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Anna\Application Data\Mozilla\Firefox\Profiles\jomfg8s5.default\extensions
[2011/09/12 00:22:39 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Anna\Application Data\Mozilla\Firefox\Profiles\jomfg8s5.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012/08/20 11:07:31 | 000,000,000 | —D | M] (WOT) – C:\Documents and Settings\Anna\Application Data\Mozilla\Firefox\Profiles\jomfg8s5.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}(2)
[2012/11/09 06:26:57 | 000,000,000 | —D | M] (XFINITY Constant Guard Protection Suite) – C:\Documents and Settings\Anna\Application Data\Mozilla\Firefox\Profiles\jomfg8s5.default\extensions\idvaultaddin@whitesky
[2011/11/19 21:19:38 | 000,000,000 | —D | M] (OptimizeGoogle) – C:\Documents and Settings\Anna\Application Data\Mozilla\Firefox\Profiles\jomfg8s5.default\extensions\[removed]
[2012/10/16 03:47:06 | 000,672,576 | —- | M] () (No name found) – C:\Documents and Settings\Anna\Application Data\Mozilla\Firefox\Profiles\jomfg8s5.default\extensions\{5A170DD3-63CA-4c58-93B7-DE9FF536C2FF}.xpi
[2012/08/31 23:49:14 | 000,036,056 | —- | M] () (No name found) – C:\Documents and Settings\Anna\Application Data\Mozilla\Firefox\Profiles\jomfg8s5.default\extensions\{84625510-7e5d-11e0-a411-0800200c9a66}.xpi
[2011/07/28 01:05:20 | 000,002,468 | —- | M] () – C:\Documents and Settings\Anna\Application Data\Mozilla\Firefox\Profiles\jomfg8s5.default\searchplugins\safesearch.xml
[2012/11/10 05:21:01 | 000,002,112 | —- | M] () – C:\Documents and Settings\Anna\Application Data\Mozilla\Firefox\Profiles\jomfg8s5.default\searchplugins\wot-safe-search.xml
[2012/11/09 06:24:28 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/10/28 06:31:50 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012/11/17 03:24:46 | 000,000,000 | —D | M] (Norton Toolbar) – C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\COFFPLGN_2011_7_13_2
[2012/02/16 03:22:31 | 000,000,000 | —D | M] (Symantec Intrusion Prevention) – C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\IPSFFPLGN
[2012/10/28 06:32:38 | 000,261,600 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/09/24 04:12:57 | 000,002,465 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/10/28 06:32:23 | 000,002,058 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2004/08/04 07:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Security Suite\Engine\5.2.2.3\coieplg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Security Suite\Engine\5.2.2.3\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Constant Guard Protection Suite) - {B84CDBE7-1B46-494B-A188-01D4C52DEB61} - C:\Documents and Settings\All Users\Application Data\White Sky, Inc\ID Vault\IEBHO1.12.1012.1\NativeBHO.dll (WhiteSky)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\5.2.2.3\coieplg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\5.2.2.3\coieplg.dll (Symantec Corporation)
O4 - HKLM..\Run: [BCU] C:\Program Files\DeviceVM\Browser Configuration Utility\BCU.exe (DeviceVM, Inc.)
O4 - HKLM..\Run: [GIDDesktop] C:\Program Files\SFT\GuardedID\gidd.exe (StrikeForce Technologies Inc.)
O4 - HKLM..\Run: [LWS] C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Constant Guard.lnk = C:\Program Files\Constant Guard Protection Suite\IDVault.exe (White Sky, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HOTSYNCSHORTCUTNAME.lnk = C:\Program Files\Palm\Hotsync.exe (PalmSource, Inc)
O4 - Startup: C:\Documents and Settings\Anna\Start Menu\Programs\Startup\Palm Registration.lnk = C:\Program Files\Palm\register.exe (Palm/Leader Technologies)
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1311645391250 (WUWebControl Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AB065480-E775-4735-BD9F-CE0EDD8DCA77}: DhcpNameServer = 75.75.75.75 75.75.76.76
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GIDLogonXP: DllName - (GIDLogonXP.dll) - C:\WINDOWS\System32\GIDLogonXP.dll (StrikeForce Technologies Inc)
O24 - Desktop WallPaper: C:\WINDOWS\Coffee Bean.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Coffee Bean.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/07/24 22:41:50 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2012/11/09 05:23:41 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2012/11/03 10:46:12 | 000,000,000 | —D | C] – C:\Documents and Settings\Anna\Desktop\kitten's editz & phewtews
[2012/11/03 10:39:44 | 000,000,000 | —D | C] – C:\Documents and Settings\Anna\Desktop\warehouse 13 & st0of
[2012/10/28 06:31:43 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2012/10/27 17:33:59 | 000,000,000 | —D | C] – C:\Documents and Settings\Anna\Local Settings\Application Data\White_Sky,_Inc
[2012/10/27 01:20:55 | 000,275,696 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mucltui.dll
[2012/10/20 14:56:56 | 000,000,000 | —D | C] – C:\TDSSKiller_Quarantine
[2012/10/18 16:10:10 | 000,000,000 | —D | C] – C:\Documents and Settings\Anna\Desktop\RK_Quarantine
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/11/17 03:24:40 | 000,017,488 | —- | M] (Windows ® 2000 DDK provider) – C:\WINDOWS\gdrv.sys
[2012/11/17 03:24:33 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/11/17 03:15:24 | 000,001,545 | —- | M] () – C:\Documents and Settings\Anna\My Documents\Document.rtf
[2012/11/16 13:21:23 | 000,032,146 | —- | M] () – C:\Documents and Settings\Anna\Desktop\tumblr_lhafjcNw8g1qfyncko1_400.jpg
[2012/11/16 09:47:49 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2012/11/16 09:46:41 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/11/15 20:17:35 | 000,000,952 | -HS- | M] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2012/11/14 04:44:53 | 000,095,072 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2012/11/14 03:04:26 | 000,001,393 | —- | M] () – C:\WINDOWS\imsins.BAK
[2012/11/14 03:03:12 | 000,448,380 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2012/11/14 03:03:12 | 000,074,236 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2012/11/12 15:36:25 | 000,040,784 | —- | M] () – C:\Documents and Settings\Anna\Desktop\182525_419534718112700_932993505_n.jpg
[2012/11/11 20:54:26 | 000,246,839 | —- | M] () – C:\Documents and Settings\Anna\Desktop\Image1.jpg
[2012/11/11 06:19:13 | 000,072,797 | —- | M] () – C:\Documents and Settings\Anna\Desktop\tumblr_mbt9xkWgP81r9c522o1_500.jpg
[2012/11/11 06:15:04 | 000,503,651 | —- | M] () – C:\Documents and Settings\Anna\Desktop\tumblr_m6r0xcfBRo1rp5q5p.gif
[2012/11/11 06:08:10 | 000,007,965 | —- | M] () – C:\Documents and Settings\Anna\Desktop\images.jpg
[2012/11/11 06:04:50 | 000,055,705 | —- | M] () – C:\Documents and Settings\Anna\Desktop\tumblr_mbybhkTwJn1rsy3fxo3_500.jpg
[2012/11/11 06:01:00 | 000,203,231 | —- | M] () – C:\Documents and Settings\Anna\Desktop\tumblr_mdba5weU9n1qf5a0go1_500.png
[2012/11/11 06:00:37 | 000,587,581 | —- | M] () – C:\Documents and Settings\Anna\Desktop\tumblr_mdbjmm3mrT1rxcjk9o1_500.png
[2012/11/11 06:00:10 | 000,083,477 | —- | M] () – C:\Documents and Settings\Anna\Desktop\tumblr_mc4gc02usu1qccsdho1_500.jpg
[2012/11/11 05:59:07 | 000,330,413 | —- | M] () – C:\Documents and Settings\Anna\Desktop\tumblr_mc8235045o1rhqdq1o1_500.png
[2012/11/11 05:58:53 | 000,009,749 | —- | M] () – C:\Documents and Settings\Anna\Desktop\tumblr_mc9hn7WT6y1r4y07mo2_400.jpg
[2012/11/11 05:58:27 | 000,086,214 | —- | M] () – C:\Documents and Settings\Anna\Desktop\pp-darcy-elizabeth.jpg
[2012/11/11 05:56:48 | 000,048,155 | —- | M] () – C:\Documents and Settings\Anna\Desktop\beautiful-elizabeth-bennet-fashion-girl-Favim.com-500711.jpg
[2012/11/11 05:55:45 | 000,052,350 | —- | M] () – C:\Documents and Settings\Anna\Desktop\Jennifer_Ehle_as_Eli_40249a.jpg
[2012/11/10 21:09:35 | 000,000,757 | —- | M] () – C:\Documents and Settings\Anna\Start Menu\Programs\Startup\Palm Registration.lnk
[2012/11/09 06:27:19 | 000,001,324 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2012/11/09 06:24:05 | 000,001,943 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Constant Guard.lnk
[2012/11/09 06:24:04 | 000,001,931 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Constant Guard.lnk
[2012/11/09 05:08:51 | 000,000,791 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/11/09 04:57:22 | 000,030,976 | —- | M] () – C:\{A0EB2E57-D532-48D3-9FD9-A56B2DB9EF1E}
[2012/11/07 11:06:15 | 000,044,944 | —- | M] () – C:\Documents and Settings\Anna\Desktop\Darla Karnes.jpg
[2012/11/06 16:09:32 | 000,016,896 | —- | M] () – C:\Documents and Settings\Anna\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/11/05 20:11:30 | 000,523,577 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_lyovwdpg9T1qgyazf.gif
[2012/11/05 12:41:14 | 000,523,577 | —- | M] () – C:\Documents and Settings\Anna\Desktop\tumblr_lyovwdpg9T1qgyazf.gif
[2012/11/03 17:21:58 | 000,062,047 | —- | M] () – C:\Documents and Settings\Anna\Desktop\539940_620715955950_1926955227_n.jpg
[2012/11/03 09:52:38 | 000,220,494 | —- | M] () – C:\Documents and Settings\Anna\Desktop\subliminal LOVE.JPG
[2012/10/25 23:06:02 | 000,156,495 | —- | M] () – C:\Documents and Settings\Anna\Desktop\forest_scene_by_therueroyale-d32r72z.jpg
[2012/10/25 04:01:31 | 001,440,054 | —- | M] () – C:\Documents and Settings\Anna\Desktop\locusts.bmp
[2012/10/24 01:47:16 | 000,048,942 | —- | M] () – C:\Documents and Settings\Anna\My Documents\60976898624A1E7449F45A58CFA_h316_w628_m4_cYkoMkSPp.jpg
[2012/10/24 01:46:44 | 000,072,837 | —- | M] () – C:\Documents and Settings\Anna\My Documents\2D4B57898F3B285FCA43464116FBB9_h316_w628_m4_cUNlDCdpE.jpg
[2012/10/22 04:31:43 | 000,498,458 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_mbsiwfsvDV1r4t7nto1_500.gif
[2012/10/22 03:37:31 | 001,866,368 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\win32k.sys
[2012/10/22 03:37:31 | 001,866,368 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\win32k.sys
[2012/10/19 12:48:46 | 000,024,074 | —- | M] () – C:\Documents and Settings\Anna\Desktop\spanishdesert.jpg
[2012/10/18 16:08:18 | 000,429,490 | —- | M] () – C:\Documents and Settings\Anna\Desktop\Image4.pspimage
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/11/17 03:15:23 | 000,001,545 | —- | C] () – C:\Documents and Settings\Anna\My Documents\Document.rtf
[2012/11/16 13:21:20 | 000,032,146 | —- | C] () – C:\Documents and Settings\Anna\Desktop\tumblr_lhafjcNw8g1qfyncko1_400.jpg
[2012/11/12 15:36:23 | 000,040,784 | —- | C] () – C:\Documents and Settings\Anna\Desktop\182525_419534718112700_932993505_n.jpg
[2012/11/11 20:54:26 | 000,246,839 | —- | C] () – C:\Documents and Settings\Anna\Desktop\Image1.jpg
[2012/11/11 06:19:12 | 000,072,797 | —- | C] () – C:\Documents and Settings\Anna\Desktop\tumblr_mbt9xkWgP81r9c522o1_500.jpg
[2012/11/11 06:15:04 | 000,503,651 | —- | C] () – C:\Documents and Settings\Anna\Desktop\tumblr_m6r0xcfBRo1rp5q5p.gif
[2012/11/11 06:08:10 | 000,007,965 | —- | C] () – C:\Documents and Settings\Anna\Desktop\images.jpg
[2012/11/11 06:04:49 | 000,055,705 | —- | C] () – C:\Documents and Settings\Anna\Desktop\tumblr_mbybhkTwJn1rsy3fxo3_500.jpg
[2012/11/11 06:01:00 | 000,203,231 | —- | C] () – C:\Documents and Settings\Anna\Desktop\tumblr_mdba5weU9n1qf5a0go1_500.png
[2012/11/11 06:00:37 | 000,587,581 | —- | C] () – C:\Documents and Settings\Anna\Desktop\tumblr_mdbjmm3mrT1rxcjk9o1_500.png
[2012/11/11 06:00:09 | 000,083,477 | —- | C] () – C:\Documents and Settings\Anna\Desktop\tumblr_mc4gc02usu1qccsdho1_500.jpg
[2012/11/11 05:59:06 | 000,330,413 | —- | C] () – C:\Documents and Settings\Anna\Desktop\tumblr_mc8235045o1rhqdq1o1_500.png
[2012/11/11 05:58:53 | 000,009,749 | —- | C] () – C:\Documents and Settings\Anna\Desktop\tumblr_mc9hn7WT6y1r4y07mo2_400.jpg
[2012/11/11 05:58:27 | 000,086,214 | —- | C] () – C:\Documents and Settings\Anna\Desktop\pp-darcy-elizabeth.jpg
[2012/11/11 05:56:48 | 000,048,155 | —- | C] () – C:\Documents and Settings\Anna\Desktop\beautiful-elizabeth-bennet-fashion-girl-Favim.com-500711.jpg
[2012/11/11 05:55:44 | 000,052,350 | —- | C] () – C:\Documents and Settings\Anna\Desktop\Jennifer_Ehle_as_Eli_40249a.jpg
[2012/11/09 04:57:22 | 000,030,976 | —- | C] () – C:\{A0EB2E57-D532-48D3-9FD9-A56B2DB9EF1E}
[2012/11/07 11:06:14 | 000,044,944 | —- | C] () – C:\Documents and Settings\Anna\Desktop\Darla Karnes.jpg
[2012/11/05 20:11:23 | 000,523,577 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_lyovwdpg9T1qgyazf.gif
[2012/11/05 12:41:13 | 000,523,577 | —- | C] () – C:\Documents and Settings\Anna\Desktop\tumblr_lyovwdpg9T1qgyazf.gif
[2012/11/03 17:21:53 | 000,062,047 | —- | C] () – C:\Documents and Settings\Anna\Desktop\539940_620715955950_1926955227_n.jpg
[2012/11/03 09:52:38 | 000,220,494 | —- | C] () – C:\Documents and Settings\Anna\Desktop\subliminal LOVE.JPG
[2012/10/25 23:06:01 | 000,156,495 | —- | C] () – C:\Documents and Settings\Anna\Desktop\forest_scene_by_therueroyale-d32r72z.jpg
[2012/10/25 04:01:31 | 001,440,054 | —- | C] () – C:\Documents and Settings\Anna\Desktop\locusts.bmp
[2012/10/24 01:47:16 | 000,048,942 | —- | C] () – C:\Documents and Settings\Anna\My Documents\60976898624A1E7449F45A58CFA_h316_w628_m4_cYkoMkSPp.jpg
[2012/10/24 01:46:44 | 000,072,837 | —- | C] () – C:\Documents and Settings\Anna\My Documents\2D4B57898F3B285FCA43464116FBB9_h316_w628_m4_cUNlDCdpE.jpg
[2012/10/22 04:31:42 | 000,498,458 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_mbsiwfsvDV1r4t7nto1_500.gif
[2012/10/19 12:48:46 | 000,024,074 | —- | C] () – C:\Documents and Settings\Anna\Desktop\spanishdesert.jpg
[2012/10/18 16:08:17 | 000,429,490 | —- | C] () – C:\Documents and Settings\Anna\Desktop\Image4.pspimage
[2012/08/23 00:42:11 | 000,107,520 | —- | C] () – C:\WINDOWS\System32\libgcc_s_dw2-1.dll
[2012/08/23 00:39:11 | 000,015,960 | —- | C] () – C:\WINDOWS\System32\mingwm10.dll
[2012/08/23 00:16:34 | 004,325,376 | —- | C] () – C:\WINDOWS\System32\QtGui4.dll
[2012/08/21 02:18:29 | 000,317,288 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2012/04/29 13:41:54 | 000,296,448 | —- | C] () – C:\WINDOWS\Xenofex.ini
[2012/03/25 10:41:34 | 000,000,060 | —- | C] () – C:\Documents and Settings\Anna\jagex_cl_runescape_LIVE.dat
[2012/03/25 10:41:34 | 000,000,024 | —- | C] () – C:\Documents and Settings\Anna\random.dat
[2012/02/15 06:07:54 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2011/10/15 02:43:33 | 000,000,000 | —- | C] () – C:\WINDOWS\QuickInstall.INI
[2011/10/11 10:56:04 | 000,016,896 | —- | C] () – C:\Documents and Settings\Anna\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/08/28 18:45:39 | 000,000,952 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2011/08/12 11:20:14 | 000,015,896 | —- | C] () – C:\WINDOWS\System32\drivers\iKeyLFT2.dll
[2011/07/26 23:54:01 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2011/07/25 23:22:07 | 000,001,324 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/07/25 00:09:37 | 000,073,728 | R— | C] () – C:\WINDOWS\System32\RtNicProp32.dll
[2011/07/25 00:08:47 | 000,004,096 | R— | C] ( ) – C:\WINDOWS\System32\IGFXDEVLib.dll
[2011/07/25 00:08:43 | 000,982,224 | R— | C] () – C:\WINDOWS\System32\igkrng500.bin
[2011/07/25 00:08:43 | 000,439,336 | R— | C] () – C:\WINDOWS\System32\igcompkrng500.bin
[2011/07/24 23:59:32 | 000,207,400 | R— | C] () – C:\WINDOWS\GSetup.exe
[2011/07/24 23:59:32 | 000,000,010 | —- | C] () – C:\WINDOWS\GSetup.ini
[2011/07/24 22:49:09 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2011/07/24 22:35:53 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2011/07/24 17:21:58 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2011/07/24 17:18:57 | 000,095,072 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/04/01 00:07:02 | 010,920,984 | —- | C] () – C:\WINDOWS\System32\LogiDPP.dll
[2011/04/01 00:07:02 | 000,104,472 | —- | C] () – C:\WINDOWS\System32\LogiDPPApp.exe
[2011/04/01 00:06:56 | 000,336,408 | —- | C] () – C:\WINDOWS\System32\DevManagerCore.dll
[2011/03/31 23:56:00 | 000,028,418 | —- | C] () – C:\WINDOWS\System32\lvcoinst.ini

========== ZeroAccess Check ==========

[2011/07/25 00:02:50 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll – [2008/04/13 19:12:05 | 001,499,136 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll – [2009/02/09 07:10:48 | 000,473,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll – [2008/04/13 19:12:08 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

< End of report >



aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software
Run date: 2012-11-17 03:36:19
—————————–
03:36:19.656 OS Version: Windows 5.1.2600 Service Pack 3
03:36:19.656 Number of processors: 2 586 0x170A
03:36:19.656 ComputerName: P-EE951AC334294 UserName: Anna
03:36:22.156 Initialize success
03:40:38.593 AVAST engine defs: 12111601
03:40:48.109 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T1L0-c
03:40:48.109 Disk 0 Vendor: Size: 0MB BusType: 0
03:40:48.109 Disk 1 \Device\Harddisk1\DR2 -> \Device\00000071
03:40:48.109 Disk 1 Vendor: Size: 0MB BusType: 0
03:40:50.125 Disk 0 MBR read successfully
03:40:50.125 Disk 0 MBR scan
03:40:50.156 Disk 0 Windows XP default MBR code
03:40:50.156 Disk 0 MBR hidden
03:40:50.171 Disk 0 scanning C:\WINDOWS\system32\drivers
03:41:01.171 Service scanning
03:41:03.109 Modules scanning
03:41:09.343 Disk 0 trace - called modules:
03:41:09.359 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
03:41:09.359 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x85f6dab8]
03:41:09.359 3 CLASSPNP.SYS[f756cfd7] -> nt!IofCallDriver -> \Device\00000068[0x85f87f18]
03:41:09.375 5 ACPI.sys[f7403620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T1L0-c[0x85f49b00]
03:41:10.843 AVAST engine scan C:\WINDOWS
03:41:19.156 AVAST engine scan C:\WINDOWS\system32
03:42:47.562 AVAST engine scan C:\WINDOWS\system32\drivers
03:43:00.171 AVAST engine scan C:\Documents and Settings\Anna
03:48:03.156 AVAST engine scan C:\Documents and Settings\All Users
03:49:21.234 Scan finished successfully
03:50:34.078 Disk 0 MBR has been saved successfully to "E:\homework\MBR.dat"
03:50:34.609 The log file has been saved successfully to "E:\homework\aswMBRlog2.txt"
Hi Saguin,

I am not finding any malware in the logs you provided, let's try to defrag your hard drive see if that improves the performance.

Disk Defragmenter for XP
  • Open My Computer.
  • Right-click the local disk volume that you want to defragment, and then click Properties.
  • On the Tools tab, click Defragment Now.
  • Click Defragment.
Any performance change after running Disk Defragmenter?
Seems to be running a lot more smoothly, thanks! Is there anymore scans I should run to check for anything? Also, I wanted to know whether I should take out Norton/ConstantGuard and put in Avast/Zonealarm for this computer (It is my Sister's and both programs seem lackluster compared to the ones that I use mentioned)?
Hi Saguin,

I would keep the Norton Security Suite (N360) since it is most likely a product you paid for. In the interim I would research online what my alternatives are, and which Anti-Virus products out there best suit my needs. Do this prior to the Norton subscription expiring so you are ready to make the switch when the time comes.

Here are just a few Free Anti-Virus suggestions:
Are there any remaining issues/questions?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI