computer slow even without known programs running [CLOSED] |
![]() ![]() |
computer slow even without known programs running [CLOSED] |
Oct 1 2008, 10:32 AM
Post
#1
|
|
|
New Member ![]() Posts: 5 OS: WinXP SP3 |
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 9:31:35 AM, on 10/1/2008 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16705) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\OPHALDCS.EXE C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe C:\WINDOWS\System32\svchost.exe c:\WINDOWS\system32\ZuneBusEnum.exe C:\WINDOWS\system32\SearchIndexer.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\PROGRA~1\AVG\AVG8\avgemc.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\AOL\1219794450\ee\AOLSoftware.exe C:\WINDOWS\system32\devldr32.exe C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\AOL\Loader\aolload.exe C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe C:\PROGRA~1\AVG\AVG8\avgtray.exe C:\Program Files\Zune\ZuneLauncher.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Okidata\OKI LPR Utility\okilpr.exe C:\Program Files\Common Files\AOL\1219794450\ee\AOLDesktop.exe C:\Program Files\Common Files\AOL\Loader\aolload.exe C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R3 - URLSearchHook: IAOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL Toolbar\aoltb.dll O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O2 - BHO: AOL Toolbar Loader - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL Toolbar\aoltb.dll O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.509.6972\swg.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL Toolbar\aoltb.dll O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1219794450\ee\AOLSoftware.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" O4 - HKLM\..\Run: [EEventManager] C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe O4 - HKLM\..\Run: [Zune Launcher] "c:\Program Files\Zune\ZuneLauncher.exe" O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - Startup: AOL Desktop.lnk = C:\Program Files\Common Files\AOL\Launch\aollaunch.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: OKI LPR Utility.lnk = C:\Program Files\Okidata\OKI LPR Utility\okilpr.exe O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe O8 - Extra context menu item: &AOL Toolbar Search - C:\Documents and Settings\All Users\Application Data\AOL\ieToolbar\resources\en-US\local\search.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1222535705687 O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll O20 - AppInit_DLLs: avgrsstx.dll O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe O23 - Service: DCS Loader (DCSLoader) - Oki Data Corporation - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\OPHALDCS.EXE O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe -- End of file - 6997 bytes |
|
|
Oct 5 2008, 07:48 PM
Post
#2
|
|
![]() Trusted Helper Posts: 2,342 OS: XP Pro |
Hello,
Welcome to Geekstogo. Sorry for the delay. Nothing I can see at first sight. Your Adobe Acrobat Reader is out of date. Older versions are vunerable to attack. Please go to the link below to update. http://www.adobe.com/products/acrobat/readstep2.html Now Please download Runscanner to your desktop and run it.
|
|
|
Oct 5 2008, 10:45 PM
Post
#3
|
|
|
New Member ![]() Posts: 5 OS: WinXP SP3 |
Here's the file you requested.
And about the Adobe, I have both Adobe 9 and Adobe 7...I have a few old files that for some reason refuse to open in Adobe 9 (hence why I have the old one) Thanks so far for the help
Attached File(s)
|
|
|
Oct 6 2008, 03:10 AM
Post
#4
|
|
![]() Trusted Helper Posts: 2,342 OS: XP Pro |
Hello again Old Computer Sucks,
Just out of interest how long have you had the program called Instant Memory Cleaner? Was it after installation of that program that your problems appeared? Now Download the attachment at the end of this post (this will be your runscanner file fixed by me)
Next Please download Malwarebytes' Anti-Malware from Here or Here Double Click mbam-setup.exe to install the application.
Extra Note: If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly. Finally in this post Kaspersky only works if you are using Internet Explorer. Please do an online scan with Kaspersky WebScanner. Click on the Kaspersky Online Scanner button. A box will come up, click Accept, this will allow it to install an ActiveX component and download its latest anti-virus database. (Note: It may take a couple of minutes)
Copy and paste that information in your next post. So when you return please post
oldcomputersucksfix.run ( 158.52K )
Number of downloads: 1 |
|
|
Oct 8 2008, 04:23 PM
Post
#5
|
|
|
New Member ![]() Posts: 5 OS: WinXP SP3 |
Hello again
I've only had Instant Memory Cleaner for a few days and I'm not sure but I think it had a CNet test rating. As you requested, logs: Malwarebytes' Anti-Malware 1.28 Database version: 1241 Windows 5.1.2600 Service Pack 3 10/7/2008 8:22:46 PM mbam-log-2008-10-07 (20-22-46).txt Scan type: Quick Scan Objects scanned: 46904 Time elapsed: 9 minute(s), 59 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) -------------------------------------------------------------------------------- KASPERSKY ONLINE SCANNER 7 REPORT Wednesday, October 8, 2008 Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600) Kaspersky Online Scanner 7 version: 7.0.25.0 Program database last update: Wednesday, October 08, 2008 04:47:35 Records in database: 1298977 -------------------------------------------------------------------------------- Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: A:\ C:\ D:\ E:\ Scan statistics: Files scanned: 67536 Threat name: 1 Infected objects: 1 Suspicious objects: 0 Duration of the scan: 03:54:07 File name / Threat name / Threats count C:\Documents and Settings\Tom Butz\Local Settings\Temp\74E2EBB8.nbp Infected: Backdoor.Win32.Delf.lhl 1 The selected area was scanned. As alwaysm thanks for the help |
|
|
Oct 8 2008, 06:17 PM
Post
#6
|
|
![]() Trusted Helper Posts: 2,342 OS: XP Pro |
Hello Old Computer Sucks,
Please download the OTMoveIt3 by OldTimer.
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post. Next
So when you return please post
|
|
|
Oct 8 2008, 08:05 PM
Post
#7
|
|
|
New Member ![]() Posts: 5 OS: WinXP SP3 |
Hi again ========== PROCESSES ========== Process explorer.exe killed successfully. ========== FILES ========== C:\Documents and Settings\Tom Butz\Local Settings\Temp\74E2EBB8.nbp moved successfully. ========== COMMANDS ========== File delete failed. C:\DOCUME~1\TOMBUT~1\LOCALS~1\Temp\74E2EBB9.nbp scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\TOMBUT~1\LOCALS~1\Temp\CMLS--2008-10-07--20-05-29.log scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\TOMBUT~1\LOCALS~1\Temp\etilqs_MqmLyDtmi1v78TybtgfV scheduled to be deleted on reboot. User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. Windows Temp folder emptied. Java cache emptied. File delete failed. C:\Documents and Settings\Tom Butz\Local Settings\Application Data\Mozilla\Firefox\Profiles\g63ybrn8.default\Cache\_CACHE_001_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Tom Butz\Local Settings\Application Data\Mozilla\Firefox\Profiles\g63ybrn8.default\Cache\_CACHE_002_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Tom Butz\Local Settings\Application Data\Mozilla\Firefox\Profiles\g63ybrn8.default\Cache\_CACHE_003_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Tom Butz\Local Settings\Application Data\Mozilla\Firefox\Profiles\g63ybrn8.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Tom Butz\Local Settings\Application Data\Mozilla\Firefox\Profiles\g63ybrn8.default\urlclassifier3.sqlite scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Tom Butz\Local Settings\Application Data\Mozilla\Firefox\Profiles\g63ybrn8.default\XUL.mfl scheduled to be deleted on reboot. FireFox cache emptied. Temp folders emptied. Explorer started successfully OTMoveIt3 by OldTimer - Version 1.0.4.2 log created on 10082008_184702 Files moved on Reboot... C:\DOCUME~1\TOMBUT~1\LOCALS~1\Temp\74E2EBB9.nbp moved successfully. C:\DOCUME~1\TOMBUT~1\LOCALS~1\Temp\CMLS--2008-10-07--20-05-29.log moved successfully. File C:\DOCUME~1\TOMBUT~1\LOCALS~1\Temp\etilqs_MqmLyDtmi1v78TybtgfV not found! File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot. C:\Documents and Settings\Tom Butz\Local Settings\Application Data\Mozilla\Firefox\Profiles\g63ybrn8.default\Cache\_CACHE_001_ moved successfully. C:\Documents and Settings\Tom Butz\Local Settings\Application Data\Mozilla\Firefox\Profiles\g63ybrn8.default\Cache\_CACHE_002_ moved successfully. C:\Documents and Settings\Tom Butz\Local Settings\Application Data\Mozilla\Firefox\Profiles\g63ybrn8.default\Cache\_CACHE_003_ moved successfully. C:\Documents and Settings\Tom Butz\Local Settings\Application Data\Mozilla\Firefox\Profiles\g63ybrn8.default\Cache\_CACHE_MAP_ moved successfully. C:\Documents and Settings\Tom Butz\Local Settings\Application Data\Mozilla\Firefox\Profiles\g63ybrn8.default\urlclassifier3.sqlite moved successfully. C:\Documents and Settings\Tom Butz\Local Settings\Application Data\Mozilla\Firefox\Profiles\g63ybrn8.default\XUL.mfl moved successfully. Logfile of random's system information tool 1.04 (written by random/random) Run by Tom Butz at 2008-10-08 19:00:03 Microsoft Windows XP Home Edition Service Pack 3 System drive C: has 12 GB (31%) free of 38 GB Total RAM: 255 MB (9% free) Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 7:00:55 PM, on 10/8/2008 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16705) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\OPHALDCS.EXE C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe C:\WINDOWS\System32\svchost.exe c:\WINDOWS\system32\ZuneBusEnum.exe C:\WINDOWS\system32\SearchIndexer.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\PROGRA~1\AVG\AVG8\avgemc.exe C:\WINDOWS\notepad.exe C:\Program Files\Common Files\AOL\1219794450\ee\AOLSoftware.exe C:\WINDOWS\system32\devldr32.exe C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe C:\PROGRA~1\AVG\AVG8\avgtray.exe C:\Program Files\Zune\ZuneLauncher.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Okidata\OKI LPR Utility\okilpr.exe C:\Program Files\Windows Desktop Search\WindowsSearch.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Vasilios Applications\Instant Memory Cleaner\Instant Memory Cleaner.exe C:\Program Files\Common Files\AOL\1219794450\ee\AOLDesktop.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\Tom Butz\Desktop\RSIT.exe C:\WINDOWS\system32\SearchProtocolHost.exe C:\Program Files\Trend Micro\HijackThis\Tom Butz.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R3 - URLSearchHook: IAOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL Toolbar\aoltb.dll R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O2 - BHO: AOL Toolbar Loader - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL Toolbar\aoltb.dll O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.509.6972\swg.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL Toolbar\aoltb.dll O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1219794450\ee\AOLSoftware.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" O4 - HKLM\..\Run: [EEventManager] C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe O4 - HKLM\..\Run: [Zune Launcher] "c:\Program Files\Zune\ZuneLauncher.exe" O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - Startup: AOL Desktop.lnk = C:\Program Files\Common Files\AOL\Launch\aollaunch.exe O4 - Startup: Instant Memory Cleaner.lnk = C:\Program Files\Vasilios Applications\Instant Memory Cleaner\Instant Memory Cleaner.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: OKI LPR Utility.lnk = C:\Program Files\Okidata\OKI LPR Utility\okilpr.exe O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe O8 - Extra context menu item: &AOL Toolbar Search - C:\Documents and Settings\All Users\Application Data\AOL\ieToolbar\resources\en-US\local\search.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1222535705687 O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll O20 - AppInit_DLLs: avgrsstx.dll O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe O23 - Service: DCS Loader (DCSLoader) - Oki Data Corporation - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\OPHALDCS.EXE O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe -- End of file - 7579 bytes ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}] &Yahoo! Toolbar Helper - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll [2008-05-15 817936] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}] AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2004-12-14 63136] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}] Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}] AVG Safe Search - C:\Program Files\AVG\AVG8\avgssie.dll [2008-09-09 455960] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}] SSVHelper Class - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll [2008-06-10 509328] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7C554162-8CB7-45A4-B8F4-8EA1C75885F9}] AOL Toolbar Loader - C:\Program Files\AOL Toolbar\aoltb.dll [2008-07-07 1275232] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}] AVG Security Toolbar - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [2008-09-09 2055960] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}] Google Toolbar Helper - c:\program files\google\googletoolbar3.dll [2008-08-26 2549368] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}] Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\4.1.509.6972\swg.dll [2008-08-26 651760] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] {2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google - c:\program files\google\googletoolbar3.dll [2008-08-26 2549368] {DE9C389F-3316-41A7-809B-AA305ED9D922} - AOL Toolbar - C:\Program Files\AOL Toolbar\aoltb.dll [2008-07-07 1275232] {A057A204-BACC-4D26-9990-79A187E2698E} - AVG Security Toolbar - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [2008-09-09 2055960] {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll [2008-05-15 817936] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "HostManager"=C:\Program Files\Common Files\AOL\1219794450\ee\AOLSoftware.exe [2008-06-24 41824] "Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672] "SunJavaUpdateSched"=C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe [2008-06-10 144784] "EEventManager"=C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe [2005-04-08 102400] "AVG8_TRAY"=C:\PROGRA~1\AVG\AVG8\avgtray.exe [2008-09-29 1234712] "Zune Launcher"=c:\Program Files\Zune\ZuneLauncher.exe [2008-09-12 160160] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2008-08-26 39408] "ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360] C:\Documents and Settings\All Users\Start Menu\Programs\Startup Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe OKI LPR Utility.lnk - C:\Program Files\Okidata\OKI LPR Utility\okilpr.exe Windows Search.lnk - C:\Program Files\Windows Desktop Search\WindowsSearch.exe C:\Documents and Settings\Tom Butz\Start Menu\Programs\Startup AOL Desktop.lnk - C:\Program Files\Common Files\AOL\Launch\aollaunch.exe Instant Memory Cleaner.lnk - C:\Program Files\Vasilios Applications\Instant Memory Cleaner\Instant Memory Cleaner.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLS"="avgrsstx.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] "{56F9679E-7826-4C84-81F3-532071A8BCC5}"=C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2008-05-26 304128] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "NoDriveTypeAutoRun"=145 [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\Program Files\Common Files\AOL\TopSpeed\3.0\aoltpsd3.exe"="C:\Program Files\Common Files\AOL\TopSpeed\3.0\aoltpsd3.exe:*:Enabled:AOL TopSpeed" "C:\Program Files\Common Files\AOL\ACS\AOLDial.exe"="C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL Connectivity Service Dialer" "C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe"="C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL Connectivity Service" "C:\Program Files\Common Files\AOL\1219794450\ee\aolsoftware.exe"="C:\Program Files\Common Files\AOL\1219794450\ee\aolsoftware.exe:*:Enabled:AOL Shared Components" "C:\Program Files\Common Files\AOL\Loader\aolload.exe"="C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader" "C:\Program Files\Common Files\AOL\1219794450\ee\AOLDesktop.exe"="C:\Program Files\Common Files\AOL\1219794450\ee\AOLDesktop.exe:*:Enabled:AOL Desktop" "C:\Program Files\AVG\AVG8\avgemc.exe"="C:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe" "C:\Program Files\AVG\AVG8\avgupd.exe"="C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe" "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" "C:\Program Files\ShoopedLife\SLVoice.exe"="C:\Program Files\ShoopedLife\SLVoice.exe:*:Enabled:SLVoice" "C:\Documents and Settings\Tom Butz\Desktop\Ali's Media Files\1-19-0-S2\SLVoice.exe"="C:\Documents and Settings\Tom Butz\Desktop\Ali's Media Files\1-19-0-S2\SLVoice.exe:*:Enabled:SLVoice" "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger" "C:\Program Files\Internet Explorer\iexplore.exe"="C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer" [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" ======List of files/folders created in the last 1 months====== 2008-10-08 19:00:03 ----D---- C:\rsit 2008-10-08 18:47:02 ----D---- C:\_OTMoveIt 2008-10-08 14:05:02 ----D---- C:\Documents and Settings\Tom Butz\Application Data\GnomiAir.E8DDAF2CE800FE5D0E15A57C791BB105A1CA6C54.1 2008-10-08 14:01:08 ----D---- C:\Program Files\Common Files\Adobe AIR 2008-10-08 14:00:01 ----D---- C:\Program Files\Gnomiverse 2008-10-07 20:39:26 ----D---- C:\Documents and Settings\Tom Butz\Application Data\Yahoo! 2008-10-07 20:39:26 ----D---- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion 2008-10-07 20:09:35 ----D---- C:\Documents and Settings\Tom Butz\Application Data\Malwarebytes 2008-10-07 20:09:18 ----D---- C:\Program Files\Malwarebytes' Anti-Malware 2008-10-07 20:09:18 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes 2008-10-06 12:01:37 ----HD---- C:\$AVG8.VAULT$ 2008-10-05 20:59:40 ----D---- C:\Documents and Settings\All Users\Application Data\Yahoo! 2008-10-05 20:59:22 ----D---- C:\Program Files\Yahoo! 2008-10-05 17:08:47 ----D---- C:\Program Files\Vasilios Applications 2008-10-05 17:08:31 ----A---- C:\psapi.dll 2008-10-05 17:04:04 ----D---- C:\Program Files\FrostWire 2008-10-05 16:57:58 ----D---- C:\Program Files\CCleaner 2008-10-01 18:44:56 ----D---- C:\WINDOWS\system32\Adobe 2008-10-01 09:24:01 ----D---- C:\Program Files\Trend Micro 2008-09-30 20:26:59 ----D---- C:\870763bf2208f622814b7ae3619a7391 2008-09-30 16:33:25 ----D---- C:\Documents and Settings\Tom Butz\Application Data\Windows Search 2008-09-28 20:23:41 ----D---- C:\Documents and Settings\Tom Butz\Application Data\Mozilla 2008-09-28 20:22:54 ----D---- C:\Program Files\Mozilla Firefox 2008-09-28 19:53:27 ----HDC---- C:\WINDOWS\$NtUninstallwinusb0100$ 2008-09-28 19:32:01 ----HDC---- C:\WINDOWS\$NtUninstallWudf01007$ 2008-09-28 19:31:14 ----D---- C:\5813e7e1d62d963967 2008-09-28 19:15:58 ----N---- C:\WINDOWS\system32\spmsgXP_2k3.dll 2008-09-28 19:15:49 ----HDC---- C:\WINDOWS\$NtUninstallWdf01007$ 2008-09-28 19:08:58 ----D---- C:\Program Files\Zune 2008-09-28 19:04:20 ----N---- C:\WINDOWS\system32\imapi2fs.dll 2008-09-28 19:04:20 ----N---- C:\WINDOWS\system32\imapi2.dll 2008-09-28 15:08:11 ----SHD---- C:\found.000 2008-09-28 11:29:11 ----D---- C:\Documents and Settings\Tom Butz\Application Data\realXtend 2008-09-28 11:22:17 ----D---- C:\Documents and Settings\Tom Butz\Application Data\SecondLife 2008-09-28 08:51:26 ----D---- C:\Documents and Settings\Tom Butz\Application Data\Auslogics 2008-09-28 08:50:53 ----D---- C:\Program Files\Auslogics 2008-09-28 08:25:28 ----D---- C:\ATI 2008-09-27 20:42:49 ----D---- C:\Program Files\Microsoft MapPoint 2008-09-27 20:42:49 ----D---- C:\Program Files\Microsoft Location Finder 2008-09-27 11:33:01 ----A---- C:\WINDOWS\system32\mucltui.dll.mui 2008-09-27 11:33:00 ----A---- C:\WINDOWS\system32\mucltui.dll 2008-09-27 11:21:37 ----D---- C:\Program Files\Microsoft Silverlight 2008-09-27 11:20:37 ----D---- C:\Documents and Settings\Tom Butz\Application Data\Windows Desktop Search 2008-09-27 11:19:06 ----D---- C:\WINDOWS\system32\GroupPolicy 2008-09-27 11:19:06 ----D---- C:\Program Files\Windows Desktop Search 2008-09-27 11:18:46 ----HDC---- C:\WINDOWS\$NtUninstallKB940157$ 2008-09-27 10:06:39 ----D---- C:\WINDOWS\ie7updates 2008-09-27 10:05:19 ----D---- C:\WINDOWS\WBEM 2008-09-27 10:03:56 ----HDC---- C:\WINDOWS\ie7 2008-09-27 10:03:19 ----HDC---- C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$ 2008-09-27 10:02:56 ----HDC---- C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$ 2008-09-27 09:55:51 ----RSD---- C:\WINDOWS\assembly 2008-09-27 09:55:50 ----D---- C:\WINDOWS\Microsoft.NET 2008-09-27 09:55:47 ----D---- C:\WINDOWS\system32\URTTemp 2008-09-27 09:50:05 ----A---- C:\WINDOWS\system32\javaws.exe 2008-09-27 09:50:05 ----A---- C:\WINDOWS\system32\javaw.exe 2008-09-27 09:50:05 ----A---- C:\WINDOWS\system32\java.exe 2008-09-26 23:06:58 ----D---- C:\Documents and Settings\Tom Butz\Application Data\KirstensViewer 2008-09-14 12:14:48 ----D---- C:\WINDOWS\Prefetch 2008-09-14 11:52:08 ----D---- C:\WINDOWS\system32\en-us 2008-09-14 11:52:06 ----D---- C:\WINDOWS\system32\scripting 2008-09-14 11:52:03 ----D---- C:\WINDOWS\l2schemas 2008-09-14 11:52:01 ----D---- C:\WINDOWS\system32\en 2008-09-14 11:41:34 ----D---- C:\WINDOWS\network diagnostic 2008-09-12 18:48:22 ----A---- C:\WINDOWS\system32\ZuneWlanCfgSvc.exe 2008-09-12 18:46:32 ----A---- C:\WINDOWS\system32\ZuneBusEnum.exe 2008-09-12 18:32:14 ----A---- C:\WINDOWS\system32\ZuneUsbTransport.dll 2008-09-12 18:32:14 ----A---- C:\WINDOWS\system32\ZuneTcp2Udp.dll 2008-09-12 18:32:12 ----A---- C:\WINDOWS\system32\ZuneRegUtil.dll 2008-09-12 18:32:12 ----A---- C:\WINDOWS\system32\ZunePTDNS.dll 2008-09-12 18:32:10 ----A---- C:\WINDOWS\system32\ZuneNetProxy.dll 2008-09-12 18:32:08 ----A---- C:\WINDOWS\system32\ZuneMTPZ.dll 2008-09-12 18:32:08 ----A---- C:\WINDOWS\system32\ZuneIPTransport.dll 2008-09-12 01:11:42 ----N---- C:\WINDOWS\system32\xmllite.dll 2008-09-12 01:11:35 ----N---- C:\WINDOWS\system32\wmphoto.dll 2008-09-12 01:11:30 ----N---- C:\WINDOWS\system32\wlanapi.dll 2008-09-12 01:11:26 ----N---- C:\WINDOWS\system32\windowscodecsext.dll 2008-09-12 01:11:26 ----N---- C:\WINDOWS\system32\windowscodecs.dll 2008-09-12 01:11:17 ----N---- C:\WINDOWS\system32\verclsid.exe 2008-09-12 01:11:11 ----N---- C:\WINDOWS\system32\tspkg.dll 2008-09-12 01:11:11 ----N---- C:\WINDOWS\system32\tsgqec.dll 2008-09-12 01:10:53 ----N---- C:\WINDOWS\system32\setupn.exe 2008-09-12 01:10:47 ----N---- C:\WINDOWS\system32\rhttpaa.dll 2008-09-12 01:10:44 ----N---- C:\WINDOWS\system32\rasqec.dll 2008-09-12 01:10:43 ----N---- C:\WINDOWS\system32\qutil.dll 2008-09-12 01:10:41 ----N---- C:\WINDOWS\system32\qcliprov.dll 2008-09-12 01:10:41 ----N---- C:\WINDOWS\system32\qagentrt.dll 2008-09-12 01:10:41 ----N---- C:\WINDOWS\system32\qagent.dll 2008-09-12 01:10:38 ----N---- C:\WINDOWS\system32\photometadatahandler.dll 2008-09-12 01:10:33 ----N---- C:\WINDOWS\system32\onex.dll 2008-09-12 01:10:18 ----N---- C:\WINDOWS\system32\napstat.exe 2008-09-12 01:10:17 ----N---- C:\WINDOWS\system32\napmontr.dll 2008-09-12 01:10:17 ----N---- C:\WINDOWS\system32\napipsec.dll 2008-09-12 01:10:15 ----N---- C:\WINDOWS\system32\msxml6r.dll 2008-09-12 01:10:15 ----N---- C:\WINDOWS\system32\msxml6.dll 2008-09-12 01:10:11 ----N---- C:\WINDOWS\system32\msshavmsg.dll 2008-09-12 01:10:11 ----N---- C:\WINDOWS\system32\mssha.dll 2008-09-12 01:09:46 ----N---- C:\WINDOWS\system32\mmcperf.exe 2008-09-12 01:09:46 ----N---- C:\WINDOWS\system32\mmcfxcommon.dll 2008-09-12 01:09:46 ----N---- C:\WINDOWS\system32\mmcex.dll 2008-09-12 01:09:45 ----N---- C:\WINDOWS\system32\microsoft.managementconsole.dll 2008-09-12 01:09:28 ----N---- C:\WINDOWS\system32\l2gpstore.dll 2008-09-12 01:09:12 ----N---- C:\WINDOWS\system32\kmsvc.dll 2008-09-12 01:09:09 ----N---- C:\WINDOWS\system32\kbdpash.dll 2008-09-12 01:09:09 ----N---- C:\WINDOWS\system32\kbdnepr.dll 2008-09-12 01:09:09 ----N---- C:\WINDOWS\system32\kbdiultn.dll 2008-09-12 01:09:08 ----N---- C:\WINDOWS\system32\kbdbhc.dll 2008-09-12 01:08:17 ----A---- C:\WINDOWS\005204_.tmp 2008-09-12 01:08:13 ----N---- C:\WINDOWS\system32\eapsvc.dll 2008-09-12 01:08:13 ----N---- C:\WINDOWS\system32\eapqec.dll 2008-09-12 01:08:13 ----N---- C:\WINDOWS\system32\eappprxy.dll 2008-09-12 01:08:13 ----N---- C:\WINDOWS\system32\eapphost.dll 2008-09-12 01:08:13 ----N---- C:\WINDOWS\system32\eappgnui.dll 2008-09-12 01:08:13 ----N---- C:\WINDOWS\system32\eappcfg.dll 2008-09-12 01:08:12 ----N---- C:\WINDOWS\system32\eapp3hst.dll 2008-09-12 01:08:12 ----N---- C:\WINDOWS\system32\eapolqec.dll 2008-09-12 01:08:02 ----N---- C:\WINDOWS\system32\dot3ui.dll 2008-09-12 01:08:02 ----N---- C:\WINDOWS\system32\dot3svc.dll 2008-09-12 01:08:02 ----N---- C:\WINDOWS\system32\dot3msm.dll 2008-09-12 01:08:02 ----N---- C:\WINDOWS\system32\dot3gpclnt.dll 2008-09-12 01:08:02 ----N---- C:\WINDOWS\system32\dot3dlg.dll 2008-09-12 01:08:02 ----N---- C:\WINDOWS\system32\dot3cfg.dll 2008-09-12 01:08:02 ----N---- C:\WINDOWS\system32\dot3api.dll 2008-09-12 01:07:58 ----N---- C:\WINDOWS\system32\dimsroam.dll 2008-09-12 01:07:58 ----N---- C:\WINDOWS\system32\dimsntfy.dll 2008-09-12 01:07:56 ----N---- C:\WINDOWS\system32\dhcpqec.dll 2008-09-12 01:07:44 ----N---- C:\WINDOWS\system32\credssp.dll 2008-09-12 01:07:18 ----N---- C:\WINDOWS\system32\bitsprx4.dll 2008-09-12 01:07:17 ----N---- C:\WINDOWS\system32\azroles.dll 2008-09-12 01:06:32 ----N---- C:\WINDOWS\system32\aaclient.dll 2008-09-09 16:22:20 ----D---- C:\Documents and Settings\Tom Butz\Application Data\gtk-2.0 2008-09-09 16:18:44 ----D---- C:\Program Files\GIMP-2.0 2008-09-09 15:40:29 ----A---- C:\WINDOWS\system32\escdev.dll 2008-09-09 15:40:18 ----A---- C:\WINDOWS\system32\eswiaml.dll 2008-09-09 15:40:18 ----A---- C:\WINDOWS\system32\eswia54.dll 2008-09-09 15:40:17 ----A---- C:\WINDOWS\system32\esint54.dll 2008-09-09 09:15:23 ----A---- C:\WINDOWS\system32\avgrsstx.dll 2008-09-09 09:15:10 ----D---- C:\Documents and Settings\Tom Butz\Application Data\AVGTOOLBAR 2008-09-09 09:14:56 ----D---- C:\Program Files\AVG 2008-09-09 09:14:55 ----D---- C:\Documents and Settings\All Users\Application Data\avg8 ======List of files/folders modified in the last 1 months====== 2008-10-08 19:00:54 ----D---- C:\WINDOWS\Temp 2008-10-08 18:53:30 ----A---- C:\WINDOWS\SchedLgU.Txt 2008-10-08 14:06:21 ----SHD---- C:\WINDOWS\Installer 2008-10-08 14:01:08 ----D---- C:\Program Files\Common Files 2008-10-08 14:00:01 ----RD---- C:\Program Files 2008-10-08 13:59:40 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe 2008-10-08 10:52:04 ----D---- C:\Documents and Settings\All Users\Application Data\Google Updater 2008-10-07 20:10:15 ----D---- C:\WINDOWS\system32\drivers 2008-10-05 21:16:36 ----D---- C:\WINDOWS\system32\CatRoot2 2008-10-05 20:59:20 ----D---- C:\WINDOWS\system32 2008-10-05 20:12:10 ----D---- C:\WINDOWS 2008-10-01 22:12:28 ----SD---- C:\Documents and Settings\Tom Butz\Application Data\Microsoft 2008-10-01 22:07:05 ----HD---- C:\WINDOWS\inf 2008-10-01 19:39:22 ----D---- C:\Documents and Settings\Tom Butz\Application Data\Adobe 2008-10-01 15:34:16 ----D---- C:\Program Files\Common Files\Microsoft Shared 2008-10-01 14:54:34 ----A---- C:\WINDOWS\win.ini 2008-10-01 11:12:58 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft 2008-09-30 20:35:30 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI 2008-09-30 20:34:36 ----D---- C:\WINDOWS\WinSxS 2008-09-30 20:22:47 ----RSHDC---- C:\WINDOWS\system32\dllcache 2008-09-30 20:22:35 ----D---- C:\WINDOWS\system32\ReinstallBackups 2008-09-28 19:50:51 ----D---- C:\WINDOWS\system32\LogFiles 2008-09-28 14:13:05 ----D---- C:\WINDOWS\PCHEALTH 2008-09-28 08:59:22 ----D---- C:\WINDOWS\Debug 2008-09-28 08:19:03 ----D---- C:\WINDOWS\system32\DirectX 2008-09-28 08:17:59 ----HD---- C:\WINDOWS\msdownld.tmp 2008-09-27 13:37:56 ----D---- C:\Documents and Settings 2008-09-27 11:25:43 ----D---- C:\WINDOWS\system32\spool 2008-09-27 11:20:57 ----HD---- C:\WINDOWS\$hf_mig$ 2008-09-27 11:19:06 ----D---- C:\WINDOWS\system32\wbem 2008-09-27 11:07:03 ----D---- C:\WINDOWS\Registration 2008-09-27 10:15:16 ----SD---- C:\WINDOWS\Downloaded Program Files 2008-09-27 10:09:09 ----D---- C:\WINDOWS\Help 2008-09-27 10:09:09 ----D---- C:\Program Files\Internet Explorer 2008-09-27 10:05:29 ----D---- C:\WINDOWS\system32\config 2008-09-27 10:05:10 ----D---- C:\WINDOWS\Media 2008-09-27 09:56:11 ----D---- C:\WINDOWS\system32\mui 2008-09-27 09:50:03 ----D---- C:\Program Files\Java 2008-09-26 09:46:29 ----D---- C:\Aircraft 2008-09-18 08:53:34 ----RD---- C:\Music 2008-09-14 12:14:09 ----D---- C:\WINDOWS\system32\Setup 2008-09-14 12:14:09 ----D---- C:\WINDOWS\AppPatch 2008-09-14 12:14:09 ----D---- C:\Program Files\Messenger 2008-09-14 12:14:07 ----RSD---- C:\WINDOWS\Fonts 2008-09-14 12:13:22 ----D---- C:\WINDOWS\security 2008-09-14 12:01:23 ----D---- C:\WINDOWS\system32\CatRoot 2008-09-14 11:52:48 ----D---- C:\WINDOWS\ServicePackFiles 2008-09-14 11:52:38 ----D---- C:\WINDOWS\ime 2008-09-14 11:52:08 ----D---- C:\WINDOWS\system32\usmt 2008-09-14 11:52:00 ----D---- C:\WINDOWS\system32\bits 2008-09-14 11:52:00 ----D---- C:\WINDOWS\peernet 2008-09-14 11:52:00 ----D---- C:\Program Files\Movie Maker 2008-09-14 11:45:25 ----D---- C:\WINDOWS\system32\Restore 2008-09-14 11:45:25 ----D---- C:\WINDOWS\system32\npp 2008-09-14 11:45:21 ----D---- C:\WINDOWS\msagent 2008-09-14 11:45:18 ----D---- C:\WINDOWS\srchasst 2008-09-14 11:45:17 ----D---- C:\Program Files\NetMeeting 2008-09-14 11:45:14 ----D---- C:\WINDOWS\system32\Com 2008-09-14 11:45:10 ----D---- C:\Program Files\Windows Media Player 2008-09-14 11:45:08 ----D---- C:\Program Files\Windows NT 2008-09-14 11:45:08 ----D---- C:\Program Files\Outlook Express 2008-09-14 11:45:02 ----D---- C:\Program Files\Common Files\System 2008-09-14 11:44:32 ----D---- C:\WINDOWS\system32\oobe 2008-09-14 11:44:28 ----D---- C:\WINDOWS\system 2008-09-14 11:38:51 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$ 2008-09-14 11:33:21 ----D---- C:\WINDOWS\EHome 2008-09-11 11:39:45 ----D---- C:\Data Files 2008-09-09 15:40:16 ----D---- C:\WINDOWS\twain_32 2008-09-09 15:37:07 ----D---- C:\Program Files\epson 2008-09-09 15:23:56 ----D---- C:\Decals ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R1 AvgLdx86;AVG Free AVI Loader Driver x86; C:\WINDOWS\System32\Drivers\avgldx86.sys [2008-09-09 97928] R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86; C:\WINDOWS\System32\Drivers\avgmfx86.sys [2008-09-09 26824] R2 AvgTdiX;AVG Free8 Network Redirector; C:\WINDOWS\System32\Drivers\avgtdix.sys [2008-09-09 76040] R2 zumbus;Zune Bus Enumerator Driver; C:\WINDOWS\system32\DRIVERS\zumbus.sys [2008-09-12 40832] R3 ati2mtaa;ati2mtaa; C:\WINDOWS\System32\DRIVERS\ati2mtaa.sys [2002-01-11 295168] R3 DM9102;DAVICOM 9102(A) PCI Fast Ethernet Based NT Driver; C:\WINDOWS\System32\DRIVERS\DM9PCI5.SYS [2001-08-17 29696] R3 emu10k;Creative SB Live! (WDM); C:\WINDOWS\system32\drivers\emu10k1m.sys [2001-08-17 283904] R3 emu10k1;Creative Interface Manager Driver (WDM); C:\WINDOWS\system32\drivers\ctlfacem.sys [2001-08-17 6912] R3 sfman;Creative SoundFont Manager Driver (WDM); C:\WINDOWS\system32\drivers\sfmanm.sys [2001-08-17 36480] R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2008-04-13 59520] R3 usbscan;USB Scanner Driver; C:\WINDOWS\System32\DRIVERS\usbscan.sys [2008-04-13 15104] R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2008-04-13 20608] R3 wanatw;WAN Miniport (ATW); C:\WINDOWS\system32\DRIVERS\wanatw4.sys [2003-01-10 33588] R3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2008-03-27 503008] R3 Winachcf;Winachcf; C:\WINDOWS\system32\DRIVERS\winachcf.sys [2001-08-13 737973] S3 ati2mpaa;ati2mpaa; C:\WINDOWS\System32\DRIVERS\ati2mpaa.sys [2001-08-17 281856] S3 ctljystk;Creative SBLive! Gameport; C:\WINDOWS\System32\DRIVERS\ctljystk.sys [2001-08-17 3712] S3 HCF_MSFT;HCF_MSFT; C:\WINDOWS\System32\DRIVERS\HCF_MSFT.sys [2001-08-17 907456] S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368] S3 WinUSB;WinUSB; C:\WINDOWS\system32\DRIVERS\WinUSB.sys [2006-11-02 39368] S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2008-01-18 83328] ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R2 avg8emc;AVG Free8 E-mail Scanner; C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-09-09 875288] R2 avg8wd;AVG Free8 WatchDog; C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-09-09 231704] R2 DCSLoader;DCS Loader; C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\OPHALDCS.EXE [2004-02-29 24576] R2 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-08-26 137200] R2 WSearch;Windows Search; C:\WINDOWS\system32\SearchIndexer.exe [2008-05-26 439808] R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-13 14336] R2 ZuneBusEnum;Zune Bus Enumerator; c:\WINDOWS\system32\ZuneBusEnum.exe [2008-09-12 61856] R3 AOL ACS;AOL Connectivity Service; C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe [2006-10-23 46640] S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800] S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144] S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136] S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408] S3 ZuneNetworkSvc;Zune Network Sharing Service; c:\Program Files\Zune\ZuneNss.exe [2008-09-12 5119392] S3 ZuneWlanCfgSvc;Zune Wireless Configuration Service; c:\WINDOWS\system32\ZuneWlanCfgSvc.exe [2008-09-12 245664] -----------------EOF----------------- info.txt logfile of random's system information tool 1.04 2008-10-08 19:01:05 ======Uninstall list====== -->C:\PROGRA~1\Yahoo!\Common\UNYT_W~1.EXE -->MsiExec.exe /I{219B0DA4-8F1A-499D-8795-4A07C632521E} -->MsiExec.exe /I{644B991F-B109-4360-9DA3-40CDAD13961C} -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf ABBYY FineReader 6.0 Sprint-->MsiExec.exe /I{ACF60000-22B9-4CE9-98D6-2CCF359BAC07} Acrobat.com-->msiexec /qb /x {77DCDCE3-2DED-62F3-8154-05E745472D07} Acrobat.com-->MsiExec.exe /I{77DCDCE3-2DED-62F3-8154-05E745472D07} Adobe AIR-->C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe -arp:uninstall Adobe AIR-->MsiExec.exe /I{197A3012-8C85-4FD3-AB66-9EC7E13DB92E} Adobe Flash Player ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe Adobe Flash Player Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe Adobe Reader 7.0-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70000000000} Adobe Reader 9-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A90000000001} Adobe Shockwave Player 11-->C:\WINDOWS\system32\adobe\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Adobe\SHOCKW~1\Install.log AOL Registration-->"C:\Program Files\AOL\RC\uninstall.exe" AOL Toolbar for Firefox-->"aoldesktop\extensions\{7affbfae-c4e2-4915-8c0f-00fa3ec610a1}\uninstall.exe" AOL Toolbar for Internet Explorer-->"C:\Program Files\AOL Toolbar\uninstall.exe" AOL Uninstaller (Choose which Products to Remove)-->C:\Program Files\Common Files\AOL\uninstaller.exe ATI Display Driver-->rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean AusLogics Disk Defrag-->"C:\Program Files\Auslogics\AusLogics Disk Defrag\unins000.exe" AVG Free 8.0-->C:\Program Files\AVG\AVG8\setup.exe /UNINSTALL CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe" EPSON Attach To Email-->C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{20C45B32-5AB6-46A4-94EF-58950CAF05E5} /l1033 ADDREMOVEDLG EPSON Copy Utility 3-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{67EDD823-135A-4D59-87BD-950616D6E857}\SETUP.EXE" -l0x9 -UnInstall EPSON Event Manager-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{48F22622-1CC2-4A83-9C1E-644DD96F832D}\Setup.exe" -l0x9 -u EPSON File Manager-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E86BC406-944E-41F6-ADE6-2C136734C96B}\Setup.exe" -l0x9 UNINST EPSON Perf 4490P Guide-->C:\Program Files\epson\guide\perf4490_e\uninstall.exe EPSON Scan Assistant-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}\Setup.exe" -l0x9 -u EPSON Scan-->C:\Program Files\epson\escndv\setup\setup.exe /r FrostWire 4.17.0-->C:\Program Files\FrostWire\Uninstall.exe GIMP 2.4.7-->"C:\Program Files\GIMP-2.0\setup\unins000.exe" GnomiAir-->msiexec /qb /x {A5F43786-7D2E-7A74-5765-869CE18D4B4C} GnomiAir-->MsiExec.exe /I{A5F43786-7D2E-7A74-5765-869CE18D4B4C} Google Earth-->MsiExec.exe /I{1D14373E-7970-4F2F-A467-ACA4F0EA21E3} Google Toolbar for Internet Explorer-->MsiExec.exe /I{DBEA1034-5882-4A88-8033-81C4EF0CFA29} Google Toolbar for Internet Explorer-->regsvr32 /u /s "c:\program files\google\googletoolbar3.dll" Google Updater-->"C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall Instant Memory Cleaner-->"C:\Program Files\Vasilios Applications\Instant Memory Cleaner\IMC.exe" Java 6 Update 5-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050} Java 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070} Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware |