This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

slow xp [Closed]

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

OTL Extras logfile created on: 11/11/2012 10:42:14 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

759.52 Mb Total Physical Memory | 317.36 Mb Available Physical Memory | 41.78% Memory free
1.82 Gb Paging File | 1.42 Gb Available in Paging File | 78.10% Paging File free
Paging file location(s): C:\pagefile.sys 1140 2280 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 70.70 Gb Total Space | 49.96 Gb Free Space | 70.66% Space Free | Partition Type: NTFS
Drive D: | 3.81 Gb Total Space | 0.74 Gb Free Space | 19.41% Space Free | Partition Type: FAT32

Computer Name: LIVINGROOM | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML.PQICEYMIBZNZA56ESDSZGWR2BE] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)
"C:\Program Files\hp center\137903\Program\BackWeb-137903.exe" = C:\Program Files\hp center\137903\Program\BackWeb-137903.exe:*:Disabled:BackWeb-137903
"C:\Program Files\Google\Google Earth\client\googleearth.exe" = C:\Program Files\Google\Google Earth\client\googleearth.exe:*:Enabled:Google Earth – (Google)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}" = Windows Live ID Sign-in Assistant
"{09DA4F91-2A09-4232-AB8C-6BC740096DE3}" = RecordNow Update Manager
"{14589F05-C658-4594-9429-D437BA688686}" = IntelliMover Data Transfer Demo
"{1EEE2A9F-6471-42fa-8923-E8879168CE26}" = HP Photo and Imaging 1.1 - Photosmart Cameras
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{26A24AE4-039D-4CA4-87B4-2F83217009FF}" = Java 7 Update 9
"{29D88826-2AB9-11D5-8854-00902761A46D}" = WordPerfect Productivity Pack
"{2F1803DA-B49F-497A-AF88-AF8748284BE6}" = HumminbirdPC
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{47D4AF7B-EDE6-4ADB-8D2F-0BDA25C7321F}" = HP Digital Imaging Album Printing 1.0
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth
"{604CD5A1-4520-4844-B064-A3D884B77E91}" = SpeedyPC Pro
"{60E971B7-51A0-48CA-8687-C6B8F094A409}" = Simple Backup for My Pictures
"{6CAEFA23-0C08-4899-A661-29D69228AF6D}" = HP Memories Disc
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7148F0A8-6813-11D6-A77B-00B0D0142030}" = Java 2 Runtime Environment, SE v1.4.2_03
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77F8A71E-3515-4832-B8B2-2F1EDBD2E0F1}" = Bing Bar
"{8214CC02-6271-4DC8-B8DD-779933450264}" = RecordNow
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics Driver
"{8D5D99B8-DFA2-4018-ADE9-A6B83E655C65}" =
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{91110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{98E8A2EF-4EAE-43B8-A172-74842B764777}" = InterVideo WinDVD Player
"{98EABC7F-B1A1-43A5-B505-5B4EC3908DCD}" = Microsoft Security Client
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-A95000000001}" = Adobe Reader 9.5.2
"{B43357AA-3A6D-4D94-B56E-43C44D09E548}" = Microsoft .NET Framework (English)
"{B95B1BA9-F887-4B3C-8D3A-CCD4C4675120}" = Microsoft Default Manager
"{BC0EE7F1-32DE-4EE2-BE10-AE15DB394E84}" = PigPen
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{EEF397AC-DAEF-4C04-90A9-5B2BD31875DC}" = Simple Installer - Multilanguage Version
"{F61F2821-694C-475F-99AB-6AF2EFDF40FD}" = Quicken 2003 New User Edition
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"ArcSoft Software Suite" = ArcSoft Picture Software
"HijackThis" = HijackThis 2.0.2
"hp instant support" = HP Instant Support
"HPTOOLKIT" = toolkit
"ie8" = Windows Internet Explorer 8
"Inactive HP Printer Drivers (Remove only)" = Inactive HP Printer Drivers (Remove only)
"InstallShield_{F61F2821-694C-475F-99AB-6AF2EFDF40FD}" = Quicken 2003 New User Edition
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.65.1.1000
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework Full v1.0.3705 (1033)" = Microsoft .NET Framework (English) v1.0.3705
"Microsoft Security Client" = Microsoft Security Essentials
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NVIDIA" = NVIDIA Windows 2000/XP Display Drivers
"PS2" = PS2
"Python 2.2 combined Win32 extensions" = Python 2.2 combined Win32 extensions
"Python 2.2.1" = Python 2.2.1
"S3Display" = S3Display
"S3Gamma2" = S3Gamma2
"S3Info2" = S3Info2
"S3Overlay" = S3Overlay
"tv_enua" = Lernout & Hauspie TruVoice American English TTS Engine
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"WordPerfect Productivity Pack" = WordPerfect Productivity Pack
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 5/1/2012 8:42:48 PM | Computer Name = LIVINGROOM | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 0x80070003, P2 moac, P3 cachereset, P4 4.0.1526.0,
P5 unspecified, P6 unspecified, P7 unspecified, P8 NIL, P9 NIL, P10 NIL.

Error - 5/8/2012 3:03:14 PM | Computer Name = LIVINGROOM | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094),
P2 4.0.1526.0, P3 timeout, P4 1.1.8304.0, P5 fixed, P6 1 _ 1024, P7 5 _ not boot,
P8 NIL, P9 NIL, P10 NIL.

Error - 5/10/2012 9:46:42 PM | Computer Name = LIVINGROOM | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094),
P2 4.0.1526.0, P3 timeout, P4 1.1.8304.0, P5 fixed, P6 1 _ 1024, P7 5 _ not boot,
P8 NIL, P9 NIL, P10 NIL.

Error - 5/14/2012 3:48:14 PM | Computer Name = LIVINGROOM | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 5/15/2012 10:40:20 PM | Computer Name = LIVINGROOM | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094),
P2 4.0.1526.0, P3 timeout, P4 1.1.8304.0, P5 fixed, P6 1 _ 1024, P7 5 _ not boot,
P8 NIL, P9 NIL, P10 NIL.

Error - 5/20/2012 10:41:25 AM | Computer Name = LIVINGROOM | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 5/20/2012 9:31:21 PM | Computer Name = LIVINGROOM | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 5/26/2012 10:12:38 PM | Computer Name = LIVINGROOM | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094),
P2 4.0.1526.0, P3 timeout, P4 1.1.8403.0, P5 fixed, P6 1 _ 1024, P7 5 _ not boot,
P8 NIL, P9 NIL, P10 NIL.

Error - 6/8/2012 6:55:38 PM | Computer Name = LIVINGROOM | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 6/13/2012 9:14:33 PM | Computer Name = LIVINGROOM | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094),
P2 4.0.1526.0, P3 timeout, P4 1.1.8403.0, P5 fixed, P6 1 _ 1024, P7 5 _ not boot,
P8 NIL, P9 NIL, P10 NIL.

[ System Events ]
Error - 11/11/2012 1:57:28 AM | Computer Name = LIVINGROOM | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the WZCSVC service.

Error - 11/11/2012 1:25:16 PM | Computer Name = LIVINGROOM | Source = Service Control Manager | ID = 7000
Description = The mrtRate service failed to start due to the following error: %%2

Error - 11/11/2012 1:25:16 PM | Computer Name = LIVINGROOM | Source = Service Control Manager | ID = 7023
Description = The IPSEC Services service terminated with the following error: %%1747

Error - 11/11/2012 7:03:55 PM | Computer Name = LIVINGROOM | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the Netman service.

Error - 11/11/2012 7:20:10 PM | Computer Name = LIVINGROOM | Source = Service Control Manager | ID = 7000
Description = The mrtRate service failed to start due to the following error: %%2

Error - 11/11/2012 7:20:10 PM | Computer Name = LIVINGROOM | Source = Service Control Manager | ID = 7023
Description = The IPSEC Services service terminated with the following error: %%1747

Error - 11/11/2012 7:29:40 PM | Computer Name = LIVINGROOM | Source = Service Control Manager | ID = 7000
Description = The mrtRate service failed to start due to the following error: %%2

Error - 11/11/2012 7:29:40 PM | Computer Name = LIVINGROOM | Source = Service Control Manager | ID = 7023
Description = The IPSEC Services service terminated with the following error: %%1747

Error - 11/11/2012 9:46:07 PM | Computer Name = LIVINGROOM | Source = Service Control Manager | ID = 7000
Description = The mrtRate service failed to start due to the following error: %%2

Error - 11/11/2012 9:46:07 PM | Computer Name = LIVINGROOM | Source = Service Control Manager | ID = 7023
Description = The IPSEC Services service terminated with the following error: %%1747


< End of report >
OTL logfile created on: 11/11/2012 10:42:14 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

759.52 Mb Total Physical Memory | 317.36 Mb Available Physical Memory | 41.78% Memory free
1.82 Gb Paging File | 1.42 Gb Available in Paging File | 78.10% Paging File free
Paging file location(s): C:\pagefile.sys 1140 2280 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 70.70 Gb Total Space | 49.96 Gb Free Space | 70.66% Space Free | Partition Type: NTFS
Drive D: | 3.81 Gb Total Space | 0.74 Gb Free Space | 19.41% Space Free | Partition Type: FAT32

Computer Name: LIVINGROOM | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Java\jre7\bin\jqs.exe (Oracle Corporation)
PRC - c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Trend Micro\HijackThis\HijackThis.exe (Trend Micro Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========


========== Services (SafeList) ==========

SRV - (AppMgmt) – %SystemRoot%\System32\appmgmts.dll File not found
SRV - (JavaQuickStarterService) – C:\Program Files\Java\jre7\bin\jqs.exe (Oracle Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SRV - (BBSvc) – C:\Program Files\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation.)
SRV - (SeaPort) – C:\Program Files\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (WDICA) – File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (mrtRate) – File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (Freedom) – System32\DRIVERS\FREEDOM.SYS File not found
DRV - (Changer) – File not found
DRV - (SWDUMon) – C:\WINDOWS\system32\drivers\SWDUMon.sys ()
DRV - (rtl8139) – C:\WINDOWS\system32\drivers\rtl8139.sys (Realtek Semiconductor Corporation)
DRV - (S3Psddr) – C:\WINDOWS\system32\drivers\s3gnbm.sys (S3 Graphics, Inc.)
DRV - (AFS2K) – C:\WINDOWS\System32\drivers\AFS2K.SYS (Oak Technology Inc.)
DRV - (ALCXWDM) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (ltmodem5) – C:\WINDOWS\system32\drivers\ltmdmnt.sys (LT)
DRV - (pfc) – C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
DRV - (nv_agp) – C:\WINDOWS\system32\drivers\nv_agp.SYS (NVIDIA Corporation)
DRV - (AN983) – C:\WINDOWS\system32\drivers\an983.sys (ADMtek Incorporated.)
DRV - (viaagp1) – C:\WINDOWS\system32\drivers\VIAAGP1.SYS (VIA Technologies, Inc.)
DRV - (Ps2) – C:\WINDOWS\system32\drivers\PS2.sys (Hewlett-Packard Company)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us7.hpwis.com/
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us7.hpwis.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us7.hpwis.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us7.hpwis.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{61B1CD37-CD76-4CC5-B86C-CCBB136A013A}: "URL" = http://search.yahoo.com/search?p={searchte…1146,6901,0,8,0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1;localhost


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.9.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)


[2010/09/07 19:30:46 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/05/09 20:13:17 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/17 22:23:41 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/07/17 04:00:04 | 000,423,656 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2007/12/19 07:57:38 | 000,310,272 | —- | M] () – C:\Program Files\mozilla firefox\plugins\npGoogleGadgetPluginFirefoxWin.dll

O1 HOSTS File: ([2002/08/29 14:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (hp toolkit) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\hp\EXPLOREBAR\HPTOOLKT.DLL (Hewlett-Packard Company)
O3 - HKCU\..\Toolbar\ShellBrowser: (hp toolkit) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\hp\EXPLOREBAR\HPTOOLKT.DLL (Hewlett-Packard Company)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre7\bin\jusched.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1292973467296 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1293058097671 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.7.0_09)
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2_03)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5C5156EB-AF81-40F6-A645-542A5A47FDD6}: DhcpNameServer = 192.168.0.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - (igfxsrvc.dll) - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2003/02/20 12:39:06 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2001/07/28 07:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O32 - AutoRun File - [2002/09/11 02:02:32 | 000,000,045 | -HS- | M] () - D:\Autorun.inf – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: LanmanWorkstation - File not found
NetSvcs: Messenger - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\System32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.LEAD - C:\WINDOWS\System32\LCodcCMP.dll (LEAD Technologies, Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/11/11 22:38:42 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2012/11/11 22:25:16 | 000,163,840 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\igfxres.dll
[2012/11/11 22:12:37 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Start Menu\Programs\SpeedyPC Software
[2012/11/11 22:12:15 | 000,000,000 | —D | C] – C:\Program Files\Common Files\SpeedyPC Software
[2012/11/11 22:11:49 | 000,000,000 | —D | C] – C:\Program Files\SpeedyPC Software
[2012/11/11 22:01:31 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Java Web Start
[2012/11/11 21:55:04 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\{7148F0A6-6813-11D6-A77B-00B0D0142030}
[2012/11/11 21:48:16 | 000,000,000 | —D | C] – C:\WINDOWS\LastGood
[2012/11/10 22:33:09 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\ParetoLogic
[2012/11/10 22:31:01 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2012/11/10 22:25:48 | 005,162,600 | —- | C] (ParetoLogic, Inc.) – C:\Documents and Settings\Owner\My Documents\RegCureProSetup_RW.exe
[2012/10/27 19:51:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\SlimWare Utilities Inc
[2012/10/27 19:51:26 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\Downloaded Installers
[2012/10/22 19:34:53 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Start Menu\Programs\HumminbirdPC
[2012/10/22 19:34:08 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Crystal Decisions
[2012/10/22 19:34:07 | 000,000,000 | —D | C] – C:\Program Files\Johnson Outdoors Inc
[2012/10/21 20:08:11 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\Sun
[2012/10/21 20:00:07 | 000,143,872 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\javacpl.cpl
[2012/10/21 20:00:06 | 000,821,736 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\npDeployJava1.dll
[2012/10/21 20:00:06 | 000,246,760 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\javaws.exe
[2012/10/21 19:59:50 | 000,174,056 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\javaw.exe
[2012/10/21 19:59:50 | 000,174,056 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\java.exe
[2012/10/21 19:59:50 | 000,093,672 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\WindowsAccessBridge.dll
[2012/10/21 19:59:17 | 000,000,000 | —D | C] – C:\Program Files\Java
[2012/10/21 19:58:50 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\McAfee
[2012/10/21 18:33:51 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\My Documents\My_HumminbirdPC
[2012/10/21 18:28:13 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\Johnson_Outdoors_Inc
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[5 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/11/11 22:43:08 | 000,000,830 | —- | M] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/11/11 22:38:42 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2012/11/11 22:38:08 | 000,000,884 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/11/11 22:14:31 | 000,000,468 | —- | M] () – C:\WINDOWS\tasks\SpeedyPC Registration3.job
[2012/11/11 22:12:36 | 000,000,865 | —- | M] () – C:\Documents and Settings\Owner\Desktop\SpeedyPC Pro.lnk
[2012/11/11 22:12:33 | 000,000,492 | —- | M] () – C:\WINDOWS\tasks\SpeedyPC Update Version3 Startup Task.job
[2012/11/11 22:12:32 | 000,000,440 | —- | M] () – C:\WINDOWS\tasks\SpeedyPC Update Version3.job
[2012/11/11 22:12:27 | 000,000,396 | —- | M] () – C:\WINDOWS\tasks\SpeedyPC Pro.job
[2012/11/11 22:01:40 | 000,001,695 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Java Web Start.lnk
[2012/11/11 20:55:52 | 000,000,384 | -H– | M] () – C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job
[2012/11/11 20:46:33 | 000,000,880 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/11/11 20:45:43 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/11/11 20:45:41 | 796,487,680 | -HS- | M] () – C:\hiberfil.sys
[2012/11/11 18:27:37 | 000,000,247 | —- | M] () – C:\WINDOWS\System\hpsysdrv.dat
[2012/11/11 18:27:31 | 000,000,199 | RHS- | M] () – C:\boot.ini
[2012/11/10 22:29:04 | 005,162,600 | —- | M] (ParetoLogic, Inc.) – C:\Documents and Settings\Owner\My Documents\RegCureProSetup_RW.exe
[2012/11/09 10:46:22 | 000,000,795 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/11/09 09:56:44 | 000,435,556 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2012/11/09 09:56:44 | 000,069,016 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2012/11/09 09:47:41 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/11/08 19:06:35 | 000,013,024 | —- | M] () – C:\WINDOWS\System32\drivers\SWDUMon.sys
[2012/10/21 19:59:31 | 000,093,672 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\WindowsAccessBridge.dll
[2012/10/21 19:59:26 | 000,246,760 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\javaws.exe
[2012/10/21 19:59:26 | 000,174,056 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\javaw.exe
[2012/10/21 19:59:25 | 000,174,056 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\java.exe
[2012/10/21 19:59:25 | 000,143,872 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\javacpl.cpl
[2012/10/21 19:59:24 | 000,821,736 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\npDeployJava1.dll
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[5 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/11/11 22:14:29 | 000,000,468 | —- | C] () – C:\WINDOWS\tasks\SpeedyPC Registration3.job
[2012/11/11 22:12:34 | 000,000,865 | —- | C] () – C:\Documents and Settings\Owner\Desktop\SpeedyPC Pro.lnk
[2012/11/11 22:12:31 | 000,000,492 | —- | C] () – C:\WINDOWS\tasks\SpeedyPC Update Version3 Startup Task.job
[2012/11/11 22:12:30 | 000,000,440 | —- | C] () – C:\WINDOWS\tasks\SpeedyPC Update Version3.job
[2012/11/11 22:12:25 | 000,000,396 | —- | C] () – C:\WINDOWS\tasks\SpeedyPC Pro.job
[2012/11/11 22:01:40 | 000,001,695 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Java Web Start.lnk
[2012/10/27 19:51:45 | 000,013,024 | —- | C] () – C:\WINDOWS\System32\drivers\SWDUMon.sys
[2012/02/14 21:27:40 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2010/12/21 17:23:45 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\iAlmcoin.dll
[2010/09/08 19:40:37 | 001,015,808 | —- | C] () – C:\Documents and Settings\Owner\s-1-5-21-2770485156-1533747904-809340592-1003.rrr

========== ZeroAccess Check ==========

[2003/02/20 14:45:06 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll – [2010/11/05 00:05:36 | 001,510,400 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\System32\wbem\fastprox.dll – [2009/02/09 07:10:48 | 000,473,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\System32\wbem\wbemess.dll – [2008/04/14 05:42:10 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2010/12/29 15:31:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Alwil Software
[2010/12/21 21:50:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG10
[2003/02/20 13:59:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Freedom
[2010/12/21 21:49:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2012/11/11 12:27:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2010/12/21 19:21:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2008/05/01 05:57:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\qrerkpch
[2012/11/11 22:12:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SpeedyPC Software
[2010/09/08 19:45:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2012/04/11 19:19:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\DriverCure
[2012/09/28 20:56:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\InterVideo
[2012/10/21 18:28:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Johnson_Outdoors_Inc
[2012/11/10 22:33:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\ParetoLogic
[2003/02/20 14:10:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SampleView
[2012/04/11 19:19:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SpeedyPC Software
[2003/02/20 13:39:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\VERITAS

========== Purity Check ==========



========== Custom Scans ==========

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.EX_ >
[2002/08/29 05:00:00 | 000,351,603 | —- | M] () MD5=2690171B51B4DBA59C02E89DB7FE6C9B – C:\I386\EXPLORER.EX_
[2002/08/29 14:00:00 | 000,351,603 | —- | M] () MD5=2690171B51B4DBA59C02E89DB7FE6C9B – C:\WINDOWS\I386\EXPLORER.EX_

< MD5 for: EXPLORER.EXE >
[2008/04/14 05:42:20 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/13 19:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2007/06/13 06:26:03 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=7712DF0CDDE3A5AC89843E61CD5B3658 – C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
[2004/08/04 02:56:49 | 001,032,192 | —- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 – C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
[2002/08/29 05:00:00 | 001,004,032 | —- | M] (Microsoft Corporation) MD5=A82B28BFC2E4455FE43022A498C0EF0A – C:\WINDOWS\$NtServicePackUninstall$\explorer.exe

< MD5 for: EXPLORER.SC_ >
[2002/08/29 05:00:00 | 000,000,181 | —- | M] () MD5=BC5B38879C56DFBC05C8B5C43AC4D739 – C:\I386\EXPLORER.SC_
[2002/08/29 14:00:00 | 000,000,181 | —- | M] () MD5=BC5B38879C56DFBC05C8B5C43AC4D739 – C:\WINDOWS\I386\EXPLORER.SC_

< MD5 for: EXPLORER.SCF >
[2002/08/29 05:00:00 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\WINDOWS\explorer.scf

< MD5 for: IEXPLORE.CH_ >
[2002/08/29 05:00:00 | 000,161,725 | —- | M] () MD5=D94018D849BDF25E7ADB8CD46DA3DC7F – C:\I386\IEXPLORE.CH_
[2002/08/29 14:00:00 | 000,161,725 | —- | M] () MD5=D94018D849BDF25E7ADB8CD46DA3DC7F – C:\WINDOWS\I386\IEXPLORE.CH_

< MD5 for: IEXPLORE.CHM >
[2002/08/29 05:00:00 | 000,167,956 | —- | M] () MD5=13A43EAD75BC03C50815444AC3018010 – C:\WINDOWS\$NtServicePackUninstall$\iexplore.chm
[2009/02/21 01:21:24 | 000,529,818 | —- | M] () MD5=1435F4731719DF5F57D17DC38196245D – C:\WINDOWS\Help\iexplore.chm
[2007/04/02 22:09:24 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINDOWS\ie8\iexplore.chm
[2004/07/17 13:40:16 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINDOWS\ServicePackFiles\i386\iexplore.chm

< MD5 for: IEXPLORE.EX_ >
[2002/08/29 05:00:00 | 000,036,925 | —- | M] () MD5=BAC737FDAA9B648A6EBFF76BFAEC7501 – C:\I386\IEXPLORE.EX_
[2002/08/29 14:00:00 | 000,036,925 | —- | M] () MD5=BAC737FDAA9B648A6EBFF76BFAEC7501 – C:\WINDOWS\I386\IEXPLORE.EX_

< MD5 for: IEXPLORE.EXE >
[2002/08/29 05:00:00 | 000,091,136 | —- | M] (Microsoft Corporation) MD5=418D301C3B1FA94B19584AEEB3D65166 – C:\WINDOWS\$NtServicePackUninstall$\iexplore.exe
[2008/04/14 05:42:24 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINDOWS\ie8\iexplore.exe
[2008/04/13 19:12:22 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINDOWS\ServicePackFiles\i386\iexplore.exe
[2012/09/29 19:54:26 | 000,218,184 | —- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\Program Files\Internet Explorer\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINDOWS\system32\dllcache\iexplore.exe

< MD5 for: IEXPLORE.EXE.EXP.LOG >
[2010/08/07 19:48:40 | 000,056,525 | —- | M] () MD5=4DB82C12B119B5599221AFE34AD5B32F – C:\Program Files\Internet Explorer\iexplore.exe.exp.log

< MD5 for: IEXPLORE.EXE.MUI >
[2009/03/08 14:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2009/03/08 14:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\iexplore.exe.mui

< MD5 for: IEXPLORE.EXE-2D97EBE6.PF >
[2012/11/11 22:37:41 | 000,064,646 | —- | M] () MD5=9BAD5CEE7164D8B20290FEB0F509B186 – C:\WINDOWS\Prefetch\IEXPLORE.EXE-2D97EBE6.pf

< MD5 for: IEXPLORE.HL_ >
[2002/08/29 05:00:00 | 000,059,881 | —- | M] () MD5=D23388C8D5D82D4D1C3B0B6A256E3CB7 – C:\I386\IEXPLORE.HL_
[2002/08/29 14:00:00 | 000,059,881 | —- | M] () MD5=D23388C8D5D82D4D1C3B0B6A256E3CB7 – C:\WINDOWS\I386\IEXPLORE.HL_

< MD5 for: IEXPLORE.HLP >
[2002/08/29 05:00:00 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\WINDOWS\Help\iexplore.hlp

< MD5 for: SERVICES >
[2002/08/29 14:00:00 | 000,007,116 | —- | M] () MD5=95826940E657FE0567A8EC0F2A6AD11A – C:\WINDOWS\system32\drivers\etc\services

< MD5 for: SERVICES._ >
[2002/08/29 05:00:00 | 000,001,989 | —- | M] () MD5=29BB3BBBE3D49156A42BFB3DD000F554 – C:\I386\SERVICES._
[2002/08/29 14:00:00 | 000,001,989 | —- | M] () MD5=29BB3BBBE3D49156A42BFB3DD000F554 – C:\WINDOWS\I386\SERVICES._

< MD5 for: SERVICES.BMP >
[2001/03/14 04:14:56 | 000,005,030 | —- | M] () MD5=FDBB222415C2E2A4129C60B3133C2E0E – C:\Program Files\Quicken\hpbiz\services.bmp

< MD5 for: SERVICES.EX_ >
[2002/08/29 05:00:00 | 000,047,953 | —- | M] () MD5=78718439FA165A148B2F41A9EB41F488 – C:\I386\SERVICES.EX_
[2002/08/29 14:00:00 | 000,047,953 | —- | M] () MD5=78718439FA165A148B2F41A9EB41F488 – C:\WINDOWS\I386\SERVICES.EX_

< MD5 for: SERVICES.EXE >
[2009/02/06 06:06:24 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=020CEAAEDC8EB655B6506B8C70D53BB6 – C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
[2008/04/14 05:42:36 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINDOWS\$NtUninstallKB956572$\services.exe
[2008/04/13 19:12:34 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINDOWS\ServicePackFiles\i386\services.exe
[2009/02/06 05:22:21 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=4712531AB7A01B7EE059853CA17D39BD – C:\WINDOWS\$hf_mig$\KB956572\SP2QFE\services.exe
[2009/02/06 06:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\$hf_mig$\KB956572\SP3GDR\services.exe
[2009/02/06 06:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\dllcache\services.exe
[2009/02/06 06:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\services.exe
[2004/08/04 02:56:55 | 000,108,032 | —- | M] (Microsoft Corporation) MD5=C6CE6EEC82F187615D1002BB3BB50ED4 – C:\WINDOWS\$NtUninstallKB956572_0$\services.exe
[2002/08/29 05:00:00 | 000,101,376 | —- | M] (Microsoft Corporation) MD5=E3DF4A0252D287C44606EE55355E1623 – C:\WINDOWS\$NtServicePackUninstall$\services.exe

< MD5 for: SERVICES.LNK >
[2012/04/11 19:21:09 | 000,001,613 | —- | M] () MD5=F666189F93FCCEA50678D7E5A8DD4337 – C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Services.lnk

< MD5 for: SERVICES.MS_ >
[2002/08/29 05:00:00 | 000,003,649 | —- | M] () MD5=64E9F61D2ED093C361862DE36433B5E1 – C:\I386\SERVICES.MS_
[2002/08/29 14:00:00 | 000,003,649 | —- | M] () MD5=64E9F61D2ED093C361862DE36433B5E1 – C:\WINDOWS\I386\SERVICES.MS_

< MD5 for: SERVICES.MSC >
[2002/08/29 05:00:00 | 000,033,464 | —- | M] () MD5=E8089AA2A6F7FEE89B38C1F2D77BA6C6 – C:\WINDOWS\system32\services.msc

< MD5 for: SERVICES.SBS >
[2011/03/01 08:58:46 | 000,034,818 | —- | M] () MD5=62AFD4B2025CE6D4706B36F4C4808F9B – C:\Program Files\Spybot - Search & Destroy\Includes\Services.sbs

< MD5 for: WINLOGON.EX_ >
[2002/08/29 05:00:00 | 000,271,067 | —- | M] () MD5=C73F996304F177262B0C2B70A7DCB66C – C:\I386\WINLOGON.EX_
[2002/08/29 14:00:00 | 000,271,067 | —- | M] () MD5=C73F996304F177262B0C2B70A7DCB66C – C:\WINDOWS\I386\WINLOGON.EX_

< MD5 for: WINLOGON.EXE >
[2002/08/29 05:00:00 | 000,516,608 | —- | M] (Microsoft Corporation) MD5=2246D8D8F4714A2CEDB21AB9B1849ABB – C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2012/09/29 19:54:26 | 000,218,184 | —- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008/04/13 19:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/14 05:42:40 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe

< MD5 for: WINLOGON.REG >
[2001/10/24 00:49:08 | 000,000,278 | —- | M] () MD5=329635F24C2EB6E4B850598AC7CC7AA4 – C:\hp\bin\winlogon.reg

< %SYSTEMDRIVE%\*.* >
[2003/02/20 12:39:06 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2012/11/11 18:27:31 | 000,000,199 | RHS- | M] () – C:\boot.ini
[2003/02/20 12:39:06 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2008/10/20 13:24:20 | 000,031,915 | —- | M] () – C:\CybDefInstallInfo.log
[2007/12/04 18:59:33 | 001,469,992 | —- | M] (Microsoft Corporation) – C:\GenuineCheck.exe
[2012/11/11 20:45:41 | 796,487,680 | -HS- | M] () – C:\hiberfil.sys
[2003/02/20 12:39:06 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2008/11/30 15:07:03 | 000,006,140 | —- | M] () – C:\JavaRa.log
[2010/06/06 17:06:30 | 000,000,109 | —- | M] () – C:\mbam-error.txt
[2003/02/20 12:39:06 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008/11/12 13:58:30 | 000,000,571 | —- | M] () – C:\NTDClient.log
[2010/12/21 20:58:13 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2010/12/21 20:58:13 | 000,250,048 | RHS- | M] () – C:\ntldr
[2012/11/11 20:45:40 | 1195,376,640 | -HS- | M] () – C:\pagefile.sys
[2008/03/18 17:26:27 | 000,000,118 | —- | M] () – C:\remind.log
[2007/12/04 19:02:36 | 005,154,304 | —- | M] () – C:\WindowsDefender.msi

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2003/02/20 12:38:40 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2009/04/16 13:08:20 | 000,312,832 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpfpp70v.dll
[2007/04/09 12:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2003/02/20 04:31:07 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2003/02/20 04:31:07 | 000,602,112 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2003/02/20 04:31:07 | 000,385,024 | —- | M] () – C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2010/12/21 21:01:16 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >
[2010/09/08 19:40:38 | 001,015,808 | —- | M] () – C:\WINDOWS\system32\config\systemprofile\s-1-5-21-2770485156-1533747904-809340592-1003.rrr

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/12/21 22:40:49 | 000,000,177 | -HS- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2003/02/20 12:41:57 | 000,000,079 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2009/06/18 17:32:57 | 014,456,584 | —- | M] (Doctor Web, Ltd.) – C:\Documents and Settings\Owner\Desktop\drweb-cureit.exe
[2007/12/19 19:16:56 | 013,413,048 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Google_Earth_BZXD.exe
[2008/10/08 14:14:19 | 006,631,467 | —- | M] (GlaryUtilities.com ) – C:\Documents and Settings\Owner\Desktop\gusetupnew.exe
[2008/11/20 19:12:40 | 002,372,472 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Owner\Desktop\mbam-setup.exe
[2012/11/11 22:38:42 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2010/03/09 14:53:31 | 000,204,496 | —- | M] (Malwarebytes) – C:\Documents and Settings\Owner\Desktop\StartUpLite.exe
[2010/09/08 20:01:39 | 000,446,464 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\TFC.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >
[2008/11/27 08:07:59 | 000,000,000 | —- | M] () – C:\WINDOWS\Java\javalog.txt

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-10-11 10:07:18

< >
[2003/02/20 11:28:24 | 000,000,065 | RH– | C] () – C:\WINDOWS\Tasks\desktop.ini
[2003/02/20 12:38:55 | 000,000,006 | -H– | C] () – C:\WINDOWS\Tasks\SA.DAT
[2011/06/13 13:53:47 | 000,000,880 | —- | C] () – C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
[2011/06/13 13:53:48 | 000,000,884 | —- | C] () – C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
[2012/04/11 19:04:47 | 000,000,830 | —- | C] () – C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
[2012/10/02 19:41:10 | 000,000,384 | -H– | C] () – C:\WINDOWS\Tasks\Microsoft Antimalware Scheduled Scan.job
[2012/11/11 22:12:25 | 000,000,396 | —- | C] () – C:\WINDOWS\Tasks\SpeedyPC Pro.job
[2012/11/11 22:12:30 | 000,000,440 | —- | C] () – C:\WINDOWS\Tasks\SpeedyPC Update Version3.job
[2012/11/11 22:12:31 | 000,000,492 | —- | C] () – C:\WINDOWS\Tasks\SpeedyPC Update Version3 Startup Task.job
[2012/11/11 22:14:29 | 000,000,468 | —- | C] () – C:\WINDOWS\Tasks\SpeedyPC Registration3.job

< >

========== Alternate Data Streams ==========

@Alternate Data Stream - 98 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 142 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B63300D1
@Alternate Data Stream - 135 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:9B7E8561
@Alternate Data Stream - 131 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7054556B
@Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A73EAFFB
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1

< End of report >
Please run the following:

Download ComboFix from the following location:
Link

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
ComboFix 12-11-12.03 - Owner 11/12/2012 21:07:50.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.760.423 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\All Users\Application Data\TEMP\DFC5A2B2.TMP
c:\documents and settings\dad\WINDOWS
c:\documents and settings\Default User\WINDOWS
c:\documents and settings\KIDS\My Documents\~WRL0365.tmp
c:\documents and settings\KIDS\My Documents\~WRL2251.tmp
c:\documents and settings\KIDS\My Documents\~WRL2400.tmp
c:\documents and settings\KIDS\My Documents\~WRL3462.tmp
c:\documents and settings\KIDS\My Documents\~WRL3560.tmp
c:\documents and settings\KIDS\WINDOWS
c:\documents and settings\lynn\Application Data\EBBCC2
c:\documents and settings\lynn\WINDOWS
c:\documents and settings\Owner\WINDOWS
c:\windows\system32\config\systemprofile\WINDOWS
c:\windows\system32\dvshyitw.ini
c:\windows\system32\mwdohvvf.ini
c:\windows\system32\ps2.bat
c:\windows\system32\qeyjludi.ini
c:\windows\system32\sxvgwvkb.ini
c:\windows\system32\URTTemp
c:\windows\system32\URTTemp\fusion.dll
c:\windows\system32\URTTemp\mscoree.dll
c:\windows\system32\URTTemp\mscoree.dll.local
c:\windows\system32\URTTemp\mscorsn.dll
c:\windows\system32\URTTemp\mscorwks.dll
c:\windows\system32\URTTemp\msvcr70.dll
D:\Autorun.inf
.
.
((((((((((((((((((((((((( Files Created from 2012-10-13 to 2012-11-13 )))))))))))))))))))))))))))))))
.
.
2012-11-12 03:25 . 2004-11-02 13:58 163840 —-a-w- c:\windows\system32\igfxres.dll
2012-11-12 03:12 . 2012-11-12 03:12 ——– d—–w- c:\program files\Common Files\SpeedyPC Software
2012-11-12 03:11 . 2012-11-12 03:11 ——– d—–w- c:\program files\SpeedyPC Software
2012-11-12 02:55 . 2012-11-12 02:55 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\{7148F0A6-6813-11D6-A77B-00B0D0142030}
2012-11-11 03:33 . 2012-11-11 03:33 ——– d—–w- c:\documents and settings\Owner\Application Data\ParetoLogic
2012-11-11 03:31 . 2012-11-11 17:27 ——– d—–w- c:\documents and settings\All Users\Application Data\ParetoLogic
2012-11-11 03:06 . 2012-10-12 05:56 6918632 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{D6B83612-1F46-4DED-B914-7C9863CEB9F9}\mpengine.dll
2012-11-09 15:06 . 2012-10-12 05:56 6918632 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-11-09 15:05 . 2012-11-09 15:05 ——– d—–w- c:\windows\system32\wbem\Repository
2012-11-09 14:56 . 2012-11-09 14:56 4550 —-a-w- c:\windows\system32\PerfStringBackup.TMP
2012-10-28 00:51 . 2012-11-09 00:06 13024 —-a-w- c:\windows\system32\drivers\SWDUMon.sys
2012-10-28 00:51 . 2012-10-28 00:51 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\SlimWare Utilities Inc
2012-10-23 00:34 . 2012-10-23 00:34 ——– d—–w- c:\program files\Common Files\Crystal Decisions
2012-10-23 00:34 . 2012-10-23 00:34 ——– d—–w- c:\program files\Johnson Outdoors Inc
2012-10-22 01:08 . 2012-10-22 01:08 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\Sun
2012-10-22 01:00 . 2012-10-22 00:59 143872 —-a-w- c:\windows\system32\javacpl.cpl
2012-10-22 01:00 . 2012-10-22 00:59 821736 —-a-w- c:\windows\system32\npDeployJava1.dll
2012-10-22 00:59 . 2012-10-22 00:59 93672 —-a-w- c:\windows\system32\WindowsAccessBridge.dll
2012-10-22 00:59 . 2012-11-12 02:58 ——– d—–w- c:\program files\Java
2012-10-22 00:58 . 2012-10-22 00:58 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee
2012-10-21 23:28 . 2012-10-21 23:28 ——– d—–w- c:\documents and settings\Owner\Application Data\Johnson_Outdoors_Inc
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-10-11 00:44 . 2012-04-12 00:04 696760 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-10-11 00:44 . 2011-05-22 20:36 73656 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-09-30 00:54 . 2011-04-08 14:40 22856 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-08-31 02:03 . 2010-10-25 02:25 193552 —-a-w- c:\windows\system32\drivers\MpFilter.sys
2012-08-28 15:14 . 2007-12-05 00:20 916992 —-a-w- c:\windows\system32\wininet.dll
2012-08-28 15:14 . 2007-12-05 00:17 43520 ——w- c:\windows\system32\licmgr10.dll
2012-08-28 15:14 . 2007-12-05 00:16 1469440 ——w- c:\windows\system32\inetcpl.cpl
2012-08-28 12:07 . 2004-08-04 05:59 385024 —-a-w- c:\windows\system32\html.iec
2012-08-24 13:53 . 2007-12-05 00:20 177664 —-a-w- c:\windows\system32\wintrust.dll
2012-08-21 13:33 . 2002-08-29 08:04 2148864 —-a-w- c:\windows\system32\ntoskrnl.exe
2012-08-21 12:58 . 2002-08-29 08:04 2027520 —-a-w- c:\windows\system32\ntkrnlpa.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-11-02 126976]
.
c:\documents and settings\lynn\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [N/A]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG10\avgchsvx.exe /sync\0c:\progra~1\AVG\AVG10\avgrsx.exe /sync /restart
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^MsnFixer.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\MsnFixer.lnk
backup=c:\windows\pss\MsnFixer.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Scheduled Updates.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk
backup=c:\windows\pss\Quicken Scheduled Updates.lnkCommon Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Reminder
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2012-07-11 19:00 919008 —-a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2012-07-31 11:20 38872 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcxMonitor]
2004-09-07 18:47 57344 —-a-w- c:\windows\ALCXMNTR.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CamMonitor]
2002-06-18 07:11 69632 —-a-w- c:\program files\Hewlett-Packard\Digital Imaging\Unload\HpqCmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
2008-04-14 10:42 15360 —-a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpsysdrv]
1998-05-08 00:04 52736 —-a-w- c:\windows\system\hpsysdrv.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2004-11-02 14:03 155648 —-a-w- c:\windows\system32\igfxtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KBD]
2001-07-07 04:56 61440 —-a-w- c:\hp\KBD\kbd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Default Manager]
2009-11-11 22:43 288088 —-a-w- c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSC]
2012-09-12 21:19 947176 —-a-w- c:\program files\Microsoft Security Client\msseces.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PS2]
2002-10-16 23:57 81920 —-a-w- c:\windows\system32\ps2.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
2002-09-14 05:42 212992 —-a-w- c:\windows\SMINST\Recguard.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Share-to-Web Namespace Daemon]
2002-04-18 01:42 69632 —-a-w- c:\program files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StorageGuard]
2002-06-18 15:01 155648 —-a-w- c:\program files\VERITAS Software\Update Manager\sgtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2012-07-03 13:04 252848 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
.
S2 mrtRate;mrtRate; [x]
S3 BBSvc;Bing Bar Update Service;c:\program files\Microsoft\BingBar\BBSvc.EXE [2/28/2011 6:44 PM 183560]
S3 SWDUMon;SWDUMon;c:\windows\system32\drivers\SWDUMon.sys [10/27/2012 7:51 PM 13024]
.
Contents of the 'Scheduled Tasks' folder
.
2012-11-13 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-12 00:45]
.
2012-11-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-06-13 18:53]
.
2012-11-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-06-13 18:53]
.
2012-11-12 c:\windows\Tasks\Microsoft Antimalware Scheduled Scan.job
- c:\program files\Microsoft Security Client\MpCmdRun.exe [2012-09-12 21:25]
.
2012-11-12 c:\windows\Tasks\SpeedyPC Pro.job
- c:\program files\SpeedyPC Software\SpeedyPC\SpeedyPC.exe [2012-10-04 20:42]
.
2012-11-12 c:\windows\Tasks\SpeedyPC Registration3.job
- c:\program files\Common Files\SpeedyPC Software\UUS3\UUS3.dll [2012-10-04 20:42]
.
2012-11-12 c:\windows\Tasks\SpeedyPC Update Version3 Startup Task.job
- c:\program files\Common Files\SpeedyPC Software\UUS3\SpeedyPC_Update3.exe [2012-10-04 20:42]
.
2012-11-12 c:\windows\Tasks\SpeedyPC Update Version3.job
- c:\program files\Common Files\SpeedyPC Software\UUS3\SpeedyPC_Update3.exe [2012-10-04 20:42]
.
.
——- Supplementary Scan ——-
.
uDefault_Search_URL = hxxp://srch-us7.hpwis.com/
mSearch Bar = hxxp://srch-us7.hpwis.com/
uInternet Settings,ProxyOverride = 127.0.0.1;localhost
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.0.1
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-Run-SunJavaUpdateSched - c:\program files\Java\jre7\bin\jusched.exe
MSConfigStartUp-AutoTBar - c:\hp\bin\autotbar.exe
MSConfigStartUp-DriverUpdate - c:\program files\DriverUpdate\DriverUpdate.exe
MSConfigStartUp-Zero Knowledge Freedom - c:\program files\Zero Knowledge\Freedom\AutoStarterR.exe
AddRemove-{BC0EE7F1-32DE-4EE2-BE10-AE15DB394E84} - c:\program files\WildTangent\DDC\ActiveMenu\DDCActiveMenu.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-11-12 21:18
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Completion time: 2012-11-12 21:21:46
ComboFix-quarantined-files.txt 2012-11-13 02:21
.
Pre-Run: 53,610,254,336 bytes free
Post-Run: 54,375,383,040 bytes free
.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
.
- - End Of File - - 8DA110BE13E3AC5DEB5C9B7AAB292986
Please run the following:

Download AdwCleaner from here and save it to your desktop.
  • Run AdwCleaner and select Delete
  • Once done it will ask to reboot, allow the reboot
  • On reboot a log will be produced, please attach the content of the log to your next reply


NEXT


  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Go here to run an online scanner from ESET.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan completes, press the LIST OF THREATS FOUND button
  • Press EXPORT TO TEXT FILE , name the file ESETSCAN and save it to your desktop
  • Include the contents of this report in your next reply.
  • Press the BACK button.
  • Press Finish
try downloading it to a USB stick, it's probably the security setting on your browser, AV or Firewall, if you still can't download it, move on to the next
Here are the reports. I could not get the other one to download! Malwarebytes Anti-Malware 1.65.1.1000 www.malwarebytes.org Database version: v2012.11.13.01 Windows XP Service Pack 3 x86 NTFS Internet Explorer 8.0.6001.18702 Owner :: LIVINGROOM [administrator] 11/13/2012 5:28:37 AM mbam-log-2012-11-13 (05-28-37).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 267700 Time elapsed: 16 minute(s), 8 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\25\634b3299-77fc9195 Java/Agent.DR trojan C:\Program Files\WildTangent\Games\GameChannel\Space Rocks\SpaceRocksLaunch.exe probably a variant of Win32/TrojanClicker.Agent.GKIGBEK trojan C:\Program Files\WildTangent\Games\GameChannel\Virtual Warfare\VirtualWarfareLaunch.exe probably a variant of Win32/TrojanClicker.Agent.KZLZUJZ trojan C:\Qoobox\Quarantine\C\WINDOWS\system32\dvshyitw.ini.vir Win32/Adware.Virtumonde.NEO application C:\Qoobox\Quarantine\C\WINDOWS\system32\mwdohvvf.ini.vir Win32/Adware.Virtumonde.NEO application C:\Qoobox\Quarantine\C\WINDOWS\system32\qeyjludi.ini.vir Win32/Adware.Virtumonde.NEO application C:\Qoobox\Quarantine\C\WINDOWS\system32\sxvgwvkb.ini.vir Win32/Adware.Virtumonde.NEO application C:\System Volume Information\_restore{F03BC7CA-958E-4E73-B64E-7D9F75261CF2}\RP558\A0064203.ini Win32/Adware.Virtumonde.NEO application C:\System Volume Information\_restore{F03BC7CA-958E-4E73-B64E-7D9F75261CF2}\RP558\A0064204.ini Win32/Adware.Virtumonde.NEO application C:\System Volume Information\_restore{F03BC7CA-958E-4E73-B64E-7D9F75261CF2}\RP558\A0064206.ini Win32/Adware.Virtumonde.NEO application C:\System Volume Information\_restore{F03BC7CA-958E-4E73-B64E-7D9F75261CF2}\RP558\A0064207.ini Win32/Adware.Virtumonde.NEO application
what happens when you try and download adwCleaner?

try it from safe mode with networking:

To Enter Safemode
  • Go to Start> Shut off your Computer> Restart
  • As the computer starts to boot-up, Tap the F8 KEY repeatedly,
  • this will bring up a menu.
  • Use the Up and Down Arrow Keys to scroll up to Safemode with networking
  • Then press the Enter Key on your Keyboard
  • go into your usual account


NEXT


  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Press the WinKey + R to open a run box, type Notepad > click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

File::
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\25\634b3299-77fc9195 
C:\Program Files\WildTangent\Games\GameChannel\Space Rocks\SpaceRocksLaunch.exe 
C:\Program Files\WildTangent\Games\GameChannel\Virtual Warfare\VirtualWarfareLaunch.exe 

ClearJavaCache::

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix may request an update; please allow it.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
I did run adwcleaner from another website. Here is the log from combofix.

ComboFix 12-11-14.01 - Owner 11/14/2012 20:31:40.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.760.465 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Owner\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
FILE ::
"c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\25\634b3299-77fc9195"
"c:\program files\WildTangent\Games\GameChannel\Space Rocks\SpaceRocksLaunch.exe"
"c:\program files\WildTangent\Games\GameChannel\Virtual Warfare\VirtualWarfareLaunch.exe"
.
.
((((((((((((((((((((((((( Files Created from 2012-10-15 to 2012-11-15 )))))))))))))))))))))))))))))))
.
.
2012-11-14 23:50 . 2012-11-14 23:50 63115 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\USERTILE.JS
2012-11-14 23:50 . 2012-11-14 23:50 4599 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\UIRESOURCE.JS
2012-11-14 23:50 . 2012-11-14 23:50 8646 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\TILEBOX.JS
2012-11-14 23:50 . 2012-11-14 23:50 6429 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\UICORE.JS
2012-11-14 23:50 . 2012-11-14 23:50 9310 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\TEXTBOX.JS
2012-11-14 23:50 . 2012-11-14 23:50 5927 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\TEXT.JS
2012-11-14 23:50 . 2012-11-14 23:50 8613 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\SAVEDUSER.JS
2012-11-14 23:50 . 2012-11-14 23:50 1651 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\QUERYSTRING.JS
2012-11-14 23:50 . 2012-11-14 23:50 6910 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\NEWUSERCOMM.JS
2012-11-14 23:50 . 2012-11-14 23:50 6208 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\LINK.JS
2012-11-14 23:50 . 2012-11-14 23:50 18541 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\LOCALIZATION.JS
2012-11-14 23:50 . 2012-11-14 23:50 8288 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\IMAGE.JS
2012-11-14 23:49 . 2012-11-14 23:49 51852 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\EXTERNALWRAPPER.JS
2012-11-14 23:49 . 2012-11-14 23:49 20719 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\DIVWRAPPER.JS
2012-11-14 23:49 . 2012-11-14 23:49 23327 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\COMBOBOX.JS
2012-11-14 23:49 . 2012-11-14 23:49 8782 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\BUTTON.JS
2012-11-14 23:49 . 2012-11-14 23:49 7271 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\CHECKBOX.JS
2012-11-14 13:47 . 2012-10-12 05:56 6918632 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{D1761592-5EE5-4801-BDEF-BDD1F713AF56}\mpengine.dll
2012-11-14 10:31 . 2012-10-12 05:56 6918632 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-11-14 00:11 . 2012-11-14 00:11 ——– d—–w- c:\program files\ESET
2012-11-12 03:25 . 2004-11-02 13:58 163840 —-a-w- c:\windows\system32\igfxres.dll
2012-11-12 02:55 . 2012-11-12 02:55 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\{7148F0A6-6813-11D6-A77B-00B0D0142030}
2012-11-11 03:33 . 2012-11-11 03:33 ——– d—–w- c:\documents and settings\Owner\Application Data\ParetoLogic
2012-11-11 03:31 . 2012-11-11 17:27 ——– d—–w- c:\documents and settings\All Users\Application Data\ParetoLogic
2012-11-09 15:05 . 2012-11-09 15:05 ——– d—–w- c:\windows\system32\wbem\Repository
2012-11-09 14:56 . 2012-11-09 14:56 4550 —-a-w- c:\windows\system32\PerfStringBackup.TMP
2012-10-28 00:51 . 2012-11-09 00:06 13024 —-a-w- c:\windows\system32\drivers\SWDUMon.sys
2012-10-28 00:51 . 2012-10-28 00:51 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\SlimWare Utilities Inc
2012-10-23 00:34 . 2012-10-23 00:34 ——– d—–w- c:\program files\Common Files\Crystal Decisions
2012-10-23 00:34 . 2012-10-23 00:34 ——– d—–w- c:\program files\Johnson Outdoors Inc
2012-10-22 01:08 . 2012-10-22 01:08 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\Sun
2012-10-22 01:00 . 2012-10-22 00:59 143872 —-a-w- c:\windows\system32\javacpl.cpl
2012-10-22 01:00 . 2012-10-22 00:59 821736 —-a-w- c:\windows\system32\npDeployJava1.dll
2012-10-22 00:59 . 2012-10-22 00:59 93672 —-a-w- c:\windows\system32\WindowsAccessBridge.dll
2012-10-22 00:59 . 2012-11-12 02:58 ——– d—–w- c:\program files\Java
2012-10-22 00:58 . 2012-10-22 00:58 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee
2012-10-21 23:28 . 2012-10-21 23:28 ——– d—–w- c:\documents and settings\Owner\Application Data\Johnson_Outdoors_Inc
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-11-14 23:52 . 2012-04-12 00:04 697272 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-11-14 23:52 . 2011-05-22 20:36 73656 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-09-30 00:54 . 2011-04-08 14:40 22856 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-08-31 02:03 . 2010-10-25 02:25 193552 —-a-w- c:\windows\system32\drivers\MpFilter.sys
2012-08-28 15:14 . 2007-12-05 00:20 916992 —-a-w- c:\windows\system32\wininet.dll
2012-08-28 15:14 . 2007-12-05 00:17 43520 ——w- c:\windows\system32\licmgr10.dll
2012-08-28 15:14 . 2007-12-05 00:16 1469440 ——w- c:\windows\system32\inetcpl.cpl
2012-08-28 12:07 . 2004-08-04 05:59 385024 —-a-w- c:\windows\system32\html.iec
2012-08-24 13:53 . 2007-12-05 00:20 177664 —-a-w- c:\windows\system32\wintrust.dll
2012-08-21 13:33 . 2002-08-29 08:04 2148864 —-a-w- c:\windows\system32\ntoskrnl.exe
2012-08-21 12:58 . 2002-08-29 08:04 2027520 —-a-w- c:\windows\system32\ntkrnlpa.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-11-02 126976]
.
c:\documents and settings\lynn\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [N/A]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG10\avgchsvx.exe /sync\0c:\progra~1\AVG\AVG10\avgrsx.exe /sync /restart
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^MsnFixer.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\MsnFixer.lnk
backup=c:\windows\pss\MsnFixer.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Scheduled Updates.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk
backup=c:\windows\pss\Quicken Scheduled Updates.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2012-07-11 19:00 919008 —-a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2012-07-31 11:20 38872 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcxMonitor]
2004-09-07 18:47 57344 —-a-w- c:\windows\ALCXMNTR.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CamMonitor]
2002-06-18 07:11 69632 —-a-w- c:\program files\Hewlett-Packard\Digital Imaging\Unload\HpqCmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
2008-04-14 10:42 15360 —-a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpsysdrv]
1998-05-08 00:04 52736 —-a-w- c:\windows\system\hpsysdrv.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2004-11-02 14:03 155648 —-a-w- c:\windows\system32\igfxtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KBD]
2001-07-07 04:56 61440 —-a-w- c:\hp\KBD\kbd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Default Manager]
2009-11-11 22:43 288088 —-a-w- c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSC]
2012-09-12 21:19 947176 —-a-w- c:\program files\Microsoft Security Client\msseces.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PS2]
2002-10-16 23:57 81920 —-a-w- c:\windows\system32\ps2.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
2002-09-14 05:42 212992 —-a-w- c:\windows\SMINST\Recguard.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Share-to-Web Namespace Daemon]
2002-04-18 01:42 69632 —-a-w- c:\program files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StorageGuard]
2002-06-18 15:01 155648 —-a-w- c:\program files\VERITAS Software\Update Manager\sgtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2012-07-03 13:04 252848 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
.
S2 mrtRate;mrtRate; [x]
S3 BBSvc;Bing Bar Update Service;c:\program files\Microsoft\BingBar\BBSvc.EXE [2/28/2011 6:44 PM 183560]
S3 SWDUMon;SWDUMon;c:\windows\system32\drivers\SWDUMon.sys [10/27/2012 7:51 PM 13024]
.
Contents of the 'Scheduled Tasks' folder
.
2012-11-14 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-12 23:52]
.
2012-11-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-06-13 18:53]
.
2012-11-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-06-13 18:53]
.
2012-11-14 c:\windows\Tasks\Microsoft Antimalware Scheduled Scan.job
- c:\program files\Microsoft Security Client\MpCmdRun.exe [2012-09-12 21:25]
.
.
——- Supplementary Scan ——-
.
uDefault_Search_URL = hxxp://srch-us7.hpwis.com/
mSearch Bar = hxxp://srch-us7.hpwis.com/
uInternet Settings,ProxyOverride = 127.0.0.1;localhost
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.0.1
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-11-14 20:41
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_5_502_110_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_5_502_110_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(2808)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2012-11-14 20:44:21
ComboFix-quarantined-files.txt 2012-11-15 01:44
ComboFix2.txt 2012-11-13 02:21
.
Pre-Run: 54,071,939,072 bytes free
Post-Run: 54,095,118,336 bytes free
.
- - End Of File - - 789478C2BD7E2E0AF33E4E25B1B5F926
please do the following:


Visit ADOBE and download the latest version of Acrobat Reader (version XI)
Having the latest updates ensures there are no security vulnerabilities in your system.



NEXT

Please advise how the computer is running now and if there are any outstanding issues
The computer is really not much better than it was, I can open the programs that I couldn't before but it is still really slow! When I click on a link the mouse clicks up to 10 times before it starts to load. Why is automatic updates trying to load files for SP2 when I have SP3 installed?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI