Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

computer slow


  • Please log in to reply

#1
justmom

justmom

    Member

  • Member
  • PipPip
  • 16 posts
my comp is running slow did virus and spyware scan using malwarebytes and eset online scanner have to svchost in running processes at 28 and 128 close them comp works good but they come right back here is otl log ...............OTL logfile created on: 6/13/2011 9:25:04 AM - Run 1
OTL by OldTimer - Version 3.2.24.0 Folder = C:\Documents and Settings\Administrator\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

894.42 Mb Total Physical Memory | 449.06 Mb Available Physical Memory | 50.21% Memory free
2.12 Gb Paging File | 1.65 Gb Available in Paging File | 78.09% Paging File free
Paging file location(s): C:\pagefile.sys 1344 2688 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 127.99 Gb Total Space | 88.51 Gb Free Space | 69.16% Space Free | Partition Type: NTFS
Drive D: | 575.68 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: MOMS | User Name: Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/06/13 09:24:44 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTL.exe
PRC - [2011/05/29 09:11:28 | 000,366,640 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2011/01/12 16:41:42 | 000,810,144 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
PRC - [2011/01/12 16:41:24 | 002,219,184 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
PRC - [2010/10/29 18:12:22 | 001,652,736 | R--- | M] (AWS Convergence Technologies, Inc.) -- C:\Program Files\AWS\WeatherBug\Weather.exe
PRC - [2010/06/01 12:17:48 | 005,252,408 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
PRC - [2008/04/14 06:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/12/11 12:15:04 | 000,012,800 | R--- | M] (Agere Systems) -- C:\WINDOWS\system32\agrsmsvc.exe


========== Modules (SafeList) ==========

MOD - [2011/06/13 09:24:44 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTL.exe
MOD - [2010/08/23 11:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] -- -- (HidServ)
SRV - [2011/05/29 09:11:28 | 000,366,640 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2011/01/12 16:44:02 | 000,033,584 | ---- | M] (ESET) [On_Demand | Stopped] -- C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe -- (EhttpSrv)
SRV - [2011/01/12 16:41:42 | 000,810,144 | ---- | M] (ESET) [Auto | Running] -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe -- (ekrn)
SRV - [2008/04/14 06:42:04 | 000,105,472 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\system32\p2pgasvc.dll -- (p2pgasvc)
SRV - [2008/04/14 06:41:56 | 000,035,328 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\iprip.dll -- (Iprip)
SRV - [2007/12/11 12:15:04 | 000,012,800 | R--- | M] (Agere Systems) [Auto | Running] -- C:\WINDOWS\system32\agrsmsvc.exe -- (AgereModemAudio)


========== Driver Services (SafeList) ==========

DRV - [2011/05/29 09:11:20 | 000,022,712 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2011/04/09 23:58:12 | 004,800,000 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2011/04/09 23:49:59 | 000,132,096 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\nvgts.sys -- (nvgts)
DRV - [2011/04/09 23:49:52 | 000,054,016 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD)
DRV - [2011/04/09 23:49:52 | 000,022,016 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus)
DRV - [2010/12/21 15:04:06 | 000,141,264 | ---- | M] (ESET) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\eamon.sys -- (eamon)
DRV - [2010/12/21 15:04:06 | 000,115,008 | ---- | M] (ESET) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ehdrv.sys -- (ehdrv)
DRV - [2010/12/21 13:47:38 | 000,094,872 | ---- | M] (ESET) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\epfwtdir.sys -- (epfwtdir)
DRV - [2010/02/11 07:02:15 | 000,226,880 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\tcpip6.sys -- (Tcpip6)
DRV - [2008/03/05 14:10:54 | 001,203,808 | R--- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2007/11/12 05:40:18 | 000,103,296 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.desoto.net/
IE - HKCU\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files\Zynga\prxtbZyng.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.desoto.net/"
FF - prefs.js..network.proxy.type: 0

FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/05/27 20:36:26 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{22119944-ED35-4ab1-910B-E619EA06A115}: C:\Program Files\Siber Systems\AI RoboForm\Firefox [2011/05/17 09:08:05 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/05/30 10:41:32 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
FF - HKLM\software\mozilla\Thunderbird\Extensions\\[email protected]: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2011/05/09 09:31:43 | 000,000,000 | ---D | M]

[2011/04/25 09:20:48 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Extensions
[2011/05/28 07:42:09 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\npd2hh2w.default\extensions
[2011/04/22 14:38:46 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
File not found (No name found) --
[2011/04/10 14:19:02 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/05/17 09:08:05 | 000,000,000 | ---D | M] (Roboform Toolbar for Firefox) -- C:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\FIREFOX
[2011/05/20 01:47:48 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2011/05/30 10:41:28 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2010/01/01 03:00:00 | 000,002,252 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\bing.xml

O1 HOSTS File: ([2007/08/11 00:58:33 | 000,000,768 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 mpa.one.microsoft.com
O2 - BHO: (Gamers Unite! Snag Bar BHO) - {26A7CA19-7D58-411D-B2DA-F1B0324CBFFC} - C:\Program Files\Gamers Unite! Snag Bar\Toolbar.dll ()
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O2 - BHO: (Zynga Toolbar) - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files\Zynga\prxtbZyng.dll (Conduit Ltd.)
O2 - BHO: (BlingeeTb Class) - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files\Blingee Plus\blingeetb.dll (Blingee.com)
O3 - HKLM\..\Toolbar: (Gamers Unite! Snag Bar) - {25515A79-C1C7-4B97-97F8-31A711694487} - C:\Program Files\Gamers Unite! Snag Bar\Toolbar.dll ()
O3 - HKLM\..\Toolbar: (&RoboForm) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKLM\..\Toolbar: (Zynga Toolbar) - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files\Zynga\prxtbZyng.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Blingee Toolbar) - {D1121FE0-0145-44C9-AA35-72071AC20A9B} - C:\Program Files\Blingee Plus\blingeetb.dll (Blingee.com)
O3 - HKCU\..\Toolbar\WebBrowser: (Gamers Unite! Snag Bar) - {25515A79-C1C7-4B97-97F8-31A711694487} - C:\Program Files\Gamers Unite! Snag Bar\Toolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (&RoboForm) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Zynga Toolbar) - {7B13EC3E-999A-4B70-B9CB-2617B8323822} - C:\Program Files\Zynga\prxtbZyng.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Blingee Toolbar) - {D1121FE0-0145-44C9-AA35-72071AC20A9B} - C:\Program Files\Blingee Plus\blingeetb.dll (Blingee.com)
O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKCU..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe (AWS Convergence Technologies, Inc.)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O8 - Extra context menu item: Customize Menu - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html ()
O8 - Extra context menu item: Fill Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O8 - Extra context menu item: RoboForm Toolbar - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O8 - Extra context menu item: Save Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra 'Tools' menuitem : Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra Button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra 'Tools' menuitem : Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra 'Tools' menuitem : RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.appl...ex/qtplugin.cab (QuickTime Object)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macr...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.micros...b?1302372403406 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {C75BE5CC-7F80-458C-8B66-FAB86E3B13C3} http://images.fotki....tkiUploader.cab (FotkiUploader Control)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {D1121FE0-0145-44C9-AA35-72071AC20A9B} http://downloads.bli...p_d_1.0.0.7.cab (Blingee Toolbar)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/04/09 12:10:04 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [1998/04/20 05:44:30 | 000,000,029 | R--- | M] () - D:\AUTORUN.INF -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/06/13 09:24:44 | 000,580,608 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2011/06/13 09:05:06 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Administrator\Recent
[2011/06/09 22:47:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\WINDOWS
[2011/06/08 14:08:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Zynga
[2011/06/07 09:00:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\FotkiDesktop
[2011/06/03 16:48:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\Recolored
[2011/06/03 16:48:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Recolored
[2011/06/03 16:48:32 | 000,000,000 | ---D | C] -- C:\Program Files\Recolored
[2011/06/03 14:19:20 | 000,000,000 | ---D | C] -- C:\Program Files\Conduit
[2011/06/03 14:19:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Local Settings\Application Data\Zynga
[2011/06/03 14:19:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Local Settings\Application Data\Conduit
[2011/06/03 14:19:17 | 000,000,000 | ---D | C] -- C:\Program Files\Zynga
[2011/05/28 21:17:55 | 000,000,000 | ---D | C] -- C:\Program Files\Pool Buddy Pogo
[2011/05/28 21:17:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Play Buddy
[2011/05/27 20:36:25 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\xing shared
[2011/05/27 20:36:24 | 000,000,000 | ---D | C] -- C:\Config.Msi
[2011/05/27 14:43:49 | 000,000,000 | ---D | C] -- C:\Program Files\Web Photo Search
[2011/05/27 14:41:56 | 000,000,000 | ---D | C] -- C:\Program Files\ImageGrabber
[2011/05/27 14:41:41 | 000,000,000 | ---D | C] -- C:\Program Files\AF Uninstalls
[2011/05/27 14:23:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\photodb
[2011/05/23 08:17:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\VitySoft
[2011/05/23 07:56:45 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft.NET
[2011/05/21 08:13:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\My Documents\New Folder (4)
[2011/05/21 07:49:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\Jasc
[2011/05/21 07:48:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Jasc Software
[2011/05/21 07:48:27 | 000,000,000 | ---D | C] -- C:\Program Files\Jasc Software Inc
[2011/05/21 07:48:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\My Documents\New Folder (3)
[2011/05/21 07:17:29 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Administrator\Start Menu\Programs\Administrative Tools
[2011/05/20 21:52:27 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Adobe
[2011/05/20 16:46:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Local Settings\Application Data\ApplicationHistory
[2011/05/18 06:29:11 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Windows Live
[2011/05/18 06:24:00 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\XPSViewer
[2011/05/18 06:23:55 | 000,000,000 | ---D | C] -- C:\Program Files\MSBuild
[2011/05/18 06:23:45 | 000,000,000 | ---D | C] -- C:\Program Files\Reference Assemblies
[2011/05/18 06:23:24 | 001,676,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xpssvcs.dll
[2011/05/18 06:23:24 | 001,676,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\xpssvcs.dll
[2011/05/18 06:23:24 | 000,597,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\printfilterpipelinesvc.exe
[2011/05/18 06:23:24 | 000,575,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\xpsshhdr.dll
[2011/05/18 06:23:24 | 000,117,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\prntvpt.dll
[2011/05/18 06:23:24 | 000,089,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\filterpipelineprintproc.dll
[2011/05/18 06:23:24 | 000,000,000 | ---D | C] -- C:\b16c021ba8406286d1ab
[2011/05/18 06:20:45 | 000,016,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\spmsg.dll
[2011/05/18 06:20:30 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Media Connect 2
[2011/05/18 06:19:33 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\UMDF
[2011/05/18 06:18:00 | 000,000,000 | R-SD | C] -- C:\WINDOWS\assembly
[2011/05/18 06:18:00 | 000,000,000 | ---D | C] -- C:\WINDOWS\Microsoft.NET
[2011/05/18 06:17:58 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\URTTemp
[2011/05/17 09:09:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\RoboForm
[2011/05/17 09:08:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\RoboForm
[2011/05/17 09:08:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\RoboForm
[2011/05/17 09:07:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\My Documents\My RoboForm Data
[2011/05/17 09:07:51 | 000,000,000 | ---D | C] -- C:\Program Files\Siber Systems
[2011/05/17 09:04:39 | 000,000,000 | ---D | C] -- C:\Program Files\FormAutoFiller
[2011/05/16 09:24:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Local Settings\Application Data\ESET

========== Files - Modified Within 30 Days ==========

[2011/06/13 09:24:44 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2011/06/13 09:20:19 | 000,013,908 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Local Sales Network - find local products and services in the mid south - Go LSN!.url
[2011/06/13 09:09:00 | 000,000,802 | ---- | M] () -- C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2011/06/13 09:03:23 | 000,000,302 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-1085031214-688789844-1177238915-500.job
[2011/06/13 09:03:23 | 000,000,294 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1085031214-688789844-1177238915-500.job
[2011/06/13 06:17:19 | 000,481,000 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011/06/13 06:17:18 | 000,079,074 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011/06/13 06:12:14 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/06/13 06:11:50 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/06/12 23:07:48 | 000,000,351 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\pogo.com-action-pogo-signin.doreturnType=homePage&pageSection=homnav_pro_signin.url
[2011/06/12 21:16:33 | 000,000,997 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Get free Email accounts Web based and secure Email - mail.com.url
[2011/06/12 14:02:00 | 000,001,044 | ---- | M] () -- C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Monterey News - Topix.url
[2011/06/12 10:43:29 | 000,000,241 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\craigslist knoxville classifieds for jobs, apartments, personals, for sale, services, community, and events.url
[2011/06/12 09:59:52 | 000,000,248 | ---- | M] () -- C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\the pic of the day.url
[2011/06/11 22:06:02 | 000,001,139 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Facebook.url
[2011/06/11 16:40:23 | 000,000,298 | ---- | M] () -- C:\WINDOWS\tasks\wavepadDowngrade.job
[2011/06/11 12:10:38 | 000,000,298 | ---- | M] () -- C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\walmartmoneycard.com-walmart.url
[2011/06/10 22:20:46 | 000,000,729 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Yahoo! Mail The best web-based email!.url
[2011/06/08 14:08:31 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/06/07 13:52:27 | 000,000,331 | ---- | M] () -- C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\MapQuest Maps - Driving Directions - Map.url
[2011/06/07 08:58:31 | 000,441,000 | --S- | M] () -- C:\WINDOWS\System32\FotkiUploadThumbDB.dat
[2011/06/07 08:58:31 | 000,004,440 | --S- | M] () -- C:\WINDOWS\System32\FotkiUploadThumbDB.idx
[2011/06/07 08:56:24 | 004,480,000 | --S- | M] () -- C:\WINDOWS\System32\FotkiThumbDB.dat
[2011/06/07 08:56:24 | 000,014,482 | --S- | M] () -- C:\WINDOWS\System32\FotkiThumbDB.idx
[2011/06/06 11:57:57 | 000,000,245 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\PGAC - MyPolicy.url
[2011/06/06 02:25:00 | 000,001,875 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Local Sales Network - 6 wheeler in whitley, KY #2133119 - Go LSN!.url
[2011/06/05 11:21:57 | 000,000,288 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Snags for you in SNAGSHARE Forum.url
[2011/06/04 19:44:55 | 000,012,288 | ---- | M] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/06/03 22:10:18 | 000,000,237 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Win Spin Win.url
[2011/05/29 09:11:30 | 000,039,984 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/05/29 09:11:20 | 000,022,712 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2011/05/28 21:17:56 | 000,000,741 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Pool Buddy Pogo.lnk
[2011/05/23 23:26:00 | 000,000,376 | ---- | M] () -- C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Year 2011 Calendar – United States.url
[2011/05/18 06:30:04 | 000,099,048 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/05/18 06:20:40 | 000,000,800 | ---- | M] () -- C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2011/05/18 06:20:39 | 000,023,392 | ---- | M] () -- C:\WINDOWS\System32\nscompat.tlb
[2011/05/18 06:20:39 | 000,016,832 | ---- | M] () -- C:\WINDOWS\System32\amcompat.tlb
[2011/05/18 06:19:37 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\System32\drivers\UMDF\MsftWdf_user_01_00_00.Wdf

========== Files Created - No Company Name ==========

[2011/06/11 22:06:02 | 000,001,139 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\Facebook.url
[2011/06/07 08:51:23 | 004,480,000 | --S- | C] () -- C:\WINDOWS\System32\FotkiThumbDB.dat
[2011/06/07 08:51:23 | 000,441,000 | --S- | C] () -- C:\WINDOWS\System32\FotkiUploadThumbDB.dat
[2011/06/07 08:51:23 | 000,014,482 | --S- | C] () -- C:\WINDOWS\System32\FotkiThumbDB.idx
[2011/06/07 08:51:23 | 000,004,440 | --S- | C] () -- C:\WINDOWS\System32\FotkiUploadThumbDB.idx
[2011/06/06 11:57:57 | 000,000,245 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\PGAC - MyPolicy.url
[2011/06/05 11:21:57 | 000,000,288 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\Snags for you in SNAGSHARE Forum.url
[2011/06/02 03:04:51 | 000,001,875 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\Local Sales Network - 6 wheeler in whitley, KY #2133119 - Go LSN!.url
[2011/05/28 21:17:56 | 000,000,741 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\Pool Buddy Pogo.lnk
[2011/05/27 19:26:12 | 000,000,294 | ---- | C] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1085031214-688789844-1177238915-500.job
[2011/05/19 16:40:36 | 000,000,237 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\Win Spin Win.url
[2011/05/18 06:19:37 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\drivers\UMDF\MsftWdf_user_01_00_00.Wdf
[2011/04/22 14:39:03 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2011/04/13 08:37:14 | 000,121,254 | ---- | C] () -- C:\WINDOWS\File Renamer - Basic Uninstaller.exe
[2011/04/10 06:58:23 | 000,012,288 | ---- | C] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/04/10 01:08:52 | 000,252,316 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb1.bin
[2011/04/10 01:08:52 | 000,000,001 | ---- | C] () -- C:\WINDOWS\System32\nvdrssel.bin
[2011/04/10 00:01:10 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\ChCfg.exe
[2011/04/09 13:54:09 | 000,003,948 | R--- | C] () -- C:\WINDOWS\System32\drivers\nvphy.bin
[2011/04/09 12:12:47 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2011/04/09 12:06:24 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2011/04/09 09:20:41 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011/04/09 04:53:49 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2011/04/09 04:52:21 | 000,099,048 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/02/23 10:27:00 | 002,292,678 | ---- | C] () -- C:\WINDOWS\System32\nvdata.bin
[2010/01/16 22:34:45 | 000,000,167 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2008/04/14 06:55:28 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2006/12/31 08:57:08 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2001/08/23 05:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2001/08/23 05:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2001/08/23 05:00:00 | 000,481,000 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2001/08/23 05:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2001/08/23 05:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2001/08/23 05:00:00 | 000,079,074 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2001/08/23 05:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2001/08/23 05:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2001/08/23 05:00:00 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2001/08/23 05:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2000/01/06 19:00:00 | 000,020,000 | ---- | C] () -- C:\WINDOWS\sysgtime.dll
[2000/01/06 19:00:00 | 000,020,000 | ---- | C] () -- C:\WINDOWS\System32\proclsvr.drv

========== Alternate Data Streams ==========

@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4
@Alternate Data Stream - 101 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CD16517D

< End of report >
  • 0

Advertisements







Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP