This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Constantly blinking hard drive

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My computer was infected with a virus after downloading some music. My Webroot was able to remove the virus but I think there is something else. The write/read light constantly blink every 2-3 seconds, even though there is nothing going on. No significant performance drag, but I know there is something going on. My computer has never done this before the "music download". attach.txt is availble at request gmer doesn't work on 64 bit system, so I don't have that log Thanks in advance, high appreciate the works that you guys do here. DDS (Ver_10-03-17.01) - NTFSX64 Run by [removed] at 16:07:14.79 on Thu 05/06/2010 Internet Explorer: 8.0.7600.16385 Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.4029.2927 [GMT -5:00] ============== Running Processes =============== C:\windows\system32\wininit.exe C:\windows\system32\lsm.exe C:\windows\system32\svchost.exe -k DcomLaunch C:\Program Files (x86)\Webroot\WebrootSecurity\WRConsumerService.exe C:\windows\system32\svchost.exe -k RPCSS C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\windows\system32\svchost.exe -k netsvcs C:\windows\system32\svchost.exe -k LocalService C:\windows\system32\svchost.exe -k NetworkService C:\windows\System32\spoolsv.exe C:\windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files (x86)\Bonjour\mDNSResponder.exe C:\windows\SysWOW64\CTsvcCDA.exe C:\Program Files (x86)\Lenovo\ReadyComm\common\IGRS.exe C:\windows\system32\taskhost.exe C:\windows\system32\Dwm.exe C:\windows\Explorer.EXE C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe C:\windows\system32\svchost.exe -k imgsvc C:\Program Files (x86)\Webroot\WebrootSecurity\SpySweeper.exe C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe C:\Program Files (x86)\Lenovo\Energy Management\utility.exe C:\Program Files\Synaptics\SynTP\SynTPHelper.exe C:\windows\System32\svchost.exe -k secsvcs C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe C:\Windows\System32\igfxtray.exe C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe C:\Program Files (x86)\Creative\Sync Manager Unicode\CTSyncU.exe C:\Users\Khoa\AppData\Roaming\Dropbox\bin\Dropbox.exe C:\windows\system32\wbem\wmiprvse.exe C:\Users\Khoa\AppData\Local\Google\Update\1.2.183.23\GoogleCrashHandler.exe C:\windows\system32\SearchIndexer.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Program Files (x86)\Webroot\WebrootSecurity\SpySweeperUI.exe C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files (x86)\DDNI\Lenovo Idea Notes\DDNIMSGService.exe C:\Program Files (x86)\Webroot\WebrootSecurity\SSU.EXE C:\Users\Khoa\Desktop\dds.scr C:\windows\system32\conhost.exe C:\windows\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com/ uDefault_Page_URL = hxxp://www.bing.com mStart Page = hxxp://lenovo.live.com/ uInternet Settings,ProxyOverride = ;*.local mWinlogon: Userinit=userinit.exe BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files (x86)\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files (x86)\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files (x86)\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files (x86)\windows live\toolbar\wltcore.dll TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files (x86)\windows live\toolbar\wltcore.dll uRun: [FactoryTest] c:\windows\Test.bat uRun: [Google Update] "c:\users\khoa\appdata\local\google\update\GoogleUpdate.exe" /c uRun: [CTSyncU.exe] "c:\program files (x86)\creative\sync manager unicode\CTSyncU.exe" mRun: [UpdateP2GShortCut] "c:\program files (x86)\lenovo\power2go\muitransfer\muistartmenu.exe" "c:\program files (x86)\lenovo\power2go" updatewithcreateonce "software\cyberlink\power2go\5.0" StartupFolder: c:\users\khoa\appdata\roaming\micros~1\windows\startm~1\programs\startup\dropbox.lnk - c:\users\khoa\appdata\roaming\dropbox\bin\Dropbox.exe mPolicies-explorer: NoActiveDesktop = 1 (0x1) mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1) mPolicies-explorer: ForceActiveDesktopOn = 0 (0x0) mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableLUA = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) mPolicies-system: PromptOnSecureDesktop = 0 (0x0) IE: E&xport to Microsoft Excel - c:\progra~2\mif5ba~1\office11\EXCEL.EXE/3000 IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files (x86)\windows live\writer\WriterBrowserExtension.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~2\mif5ba~1\office11\REFIEBAR.DLL BHO-X64: Windows Live Family Safety Browser Helper Class: {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - c:\program files\windows live\family safety\fssbho.dll BHO-X64: Windows Live Family Safety Browser Helper - No File BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll TB-X64: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File mRun-x64: [IAAnotif] "c:\program files (x86)\intel\intel matrix storage manager\iaanotif.exe" mRun-x64: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe mRun-x64: [RtHDVCpl] "c:\program files\realtek\audio\hda\RAVCpl64.exe" -s mRun-x64: [EnergyUtility] "c:\program files (x86)\lenovo\energy management\utility.exe" mRun-x64: [Energy Management] c:\program files (x86)\lenovo\energy management\Energy Management.exe mRun-x64: [IgfxTray] "c:\windows\system32\igfxtray.exe" mRun-x64: [HotKeysCmds] "c:\windows\system32\hkcmd.exe" ============= SERVICES / DRIVERS =============== R0 ssfs0bbc;ssfs0bbc;c:\windows\system32\drivers\ssfs0bbc.sys [2009-11-6 37488] R1 funfrm;funfrm;c:\windows\system32\drivers\funfrm.sys [2009-10-15 73744] R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-13 59904] R2 DDNIMSGService;DDNIMSGService;c:\program files (x86)\ddni\lenovo idea notes\DDNIMSGService.exe [2009-6-23 172720] R2 IGRS;IGRS;c:\program files (x86)\lenovo\readycomm\common\IGRS.exe [2009-7-14 38152] R2 WebrootSpySweeperService;Webroot Spy Sweeper Engine;c:\program files (x86)\webroot\webrootsecurity\SpySweeper.exe [2009-11-6 4048240] R2 WRConsumerService;Webroot Client Service;c:\program files (x86)\webroot\webrootsecurity\WRConsumerService.exe [2010-5-2 1201640] R3 ACPIVPC;Lenovo Virtual Power Controller Driver;c:\windows\system32\drivers\AcpiVpc.sys [2009-10-15 26128] R3 IntcHdmiAddService;Intel® High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [2009-10-15 138752] R3 NETw5s64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;c:\windows\system32\drivers\NETw5s64.sys [2009-9-15 6952960] R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt64win7.sys [2010-3-4 346144] R3 wdmirror;wdmirror;c:\windows\system32\drivers\WDMirror.sys [2009-10-15 11280] S2 ReadyComm.DirectRouter;ReadyComm.DirectRouter;c:\windows\system32\igrssvcs.exe -k igrssvcs –> c:\windows\system32\IgrsSvcs.exe -k IgrsSvcs [?] S3 Bridge0;Bridge0;c:\windows\system32\drivers\WDBridge.sys [2009-10-15 79376] S3 fssfltr;fssfltr;c:\windows\system32\drivers\fssfltr.sys [2009-10-28 61280] S3 fsssvc;Windows Live Family Safety Service;c:\program files (x86)\windows live\family safety\fsssvc.exe [2009-8-5 704864] S3 k57nd60a;Broadcom NetLink ™ Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\k57nd60a.sys [2009-6-10 270848] S3 Lenovo ReadyComm AppSvc;Lenovo ReadyComm AppSvc;c:\program files\lenovo\readycomm\AppSvc.exe [2009-10-15 414984] S3 Lenovo ReadyComm ConnSvc;Lenovo ReadyComm ConnSvc;c:\program files\lenovo\readycomm\ConnSvc.exe [2009-10-15 472328] S3 netw5v64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\drivers\NETw5v64.sys [2009-10-15 5435904] S3 PS_MDP;ReadyComm Presentation Space Helper Service;c:\windows\system32\igrssvcs.exe -k igrssvcs –> c:\windows\system32\IgrsSvcs.exe -k IgrsSvcs [?] S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RtsUStor.sys [2009-9-25 219136] S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2010-4-1 1255736] S3 wsvd;wsvd;c:\windows\system32\drivers\wsvd.sys [2009-7-21 121840] =============== Created Last 30 ================ 2010-05-06 20:30:23 20 —-a-w- c:\users\khoa\defogger_reenable 2010-05-05 17:07:49 0 d—–w- c:\program files (x86)\Trend Micro 2010-05-04 02:29:18 0 d—–w- c:\programdata\NCH Swift Sound 2010-05-04 02:28:46 0 d—–w- c:\program files (x86)\NCH Software 2010-05-04 02:28:42 0 d—–w- c:\program files (x86)\NCH Swift Sound 2010-05-03 03:32:53 511328 —-a-w- c:\windows\syswow64\capicom.dll 2010-05-03 03:32:34 0 d—–w- c:\program files (x86)\MSSOAP 2010-05-03 03:32:34 0 d—–w- c:\program files (x86)\common files\MSSoap 2010-05-03 03:32:24 1563008 —-a-w- c:\windows\WRSetup.dll 2010-05-03 03:32:24 0 d—–w- c:\users\khoa\appdata\roaming\Webroot 2010-05-03 03:32:24 0 d—–w- c:\programdata\Webroot 2010-05-03 03:32:24 0 d—–w- c:\program files (x86)\Webroot 2010-05-03 03:25:53 164 —-a-w- c:\windows\install.dat 2010-04-27 19:15:51 223448 —-a-w- c:\windows\system32\drivers\fvevol.sys 2010-04-27 19:15:48 12867072 —-a-w- c:\windows\syswow64\shell32.dll 2010-04-27 19:15:47 96768 —-a-w- c:\windows\syswow64\sspicli.dll 2010-04-27 19:15:47 22016 —-a-w- c:\windows\syswow64\secur32.dll 2010-04-27 19:15:47 153160 —-a-w- c:\windows\system32\drivers\ksecpkg.sys 2010-04-27 19:15:47 1446912 —-a-w- c:\windows\system32\lsasrv.dll 2010-04-27 05:13:36 0 d—–w- c:\programdata\Sports Interactive 2010-04-27 05:04:57 4496232 —-a-w- c:\windows\system32\d3dx9_34.dll 2010-04-27 04:58:56 0 d–h–w- c:\program files (x86)\Zero G Registry 2010-04-27 04:57:23 0 d—–w- c:\users\khoa\appdata\roaming\Sports Interactive 2010-04-27 04:49:14 834544 —-a-w- c:\windows\system32\drivers\sptd.sys 2010-04-27 04:48:45 0 d—–w- c:\program files (x86)\DAEMON Tools Lite 2010-04-27 04:47:55 0 d—–w- c:\users\khoa\appdata\roaming\DAEMON Tools Lite 2010-04-27 04:47:51 0 d—–w- c:\programdata\DAEMON Tools Lite 2010-04-14 13:40:02 612352 —-a-w- c:\windows\system32\vbscript.dll 2010-04-14 13:40:02 427520 —-a-w- c:\windows\syswow64\vbscript.dll 2010-04-14 13:40:02 286720 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys 2010-04-14 13:40:02 157696 —-a-w- c:\windows\system32\drivers\mrxsmb.sys 2010-04-14 13:40:02 125952 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys 2010-04-14 13:40:01 5509008 —-a-w- c:\windows\system32\ntoskrnl.exe 2010-04-14 13:40:01 3899280 —-a-w- c:\windows\syswow64\ntoskrnl.exe 2010-04-14 13:40:00 3954568 —-a-w- c:\windows\syswow64\ntkrnlpa.exe 2010-04-14 13:38:04 220672 —-a-w- c:\windows\system32\wintrust.dll 2010-04-14 13:38:03 172032 —-a-w- c:\windows\syswow64\wintrust.dll 2010-04-14 13:37:49 139264 —-a-w- c:\windows\system32\cabview.dll 2010-04-14 13:37:49 132608 —-a-w- c:\windows\syswow64\cabview.dll 2010-04-08 01:14:51 0 d—–w- c:\program files (x86)\MSECache ==================== Find3M ==================== 2010-04-02 04:58:49 0 —ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf 2010-02-24 15:16:06 212864 ——w- c:\windows\system32\MpSigStub.exe 2010-02-23 08:22:50 1192960 —-a-w- c:\windows\system32\wininet.dll 2010-02-23 07:56:00 977920 —-a-w- c:\windows\syswow64\wininet.dll 2010-02-23 07:55:56 1225216 —-a-w- c:\windows\syswow64\urlmon.dll 2010-02-23 07:55:45 606208 —-a-w- c:\windows\syswow64\mstime.dll 2010-02-23 07:55:43 64512 —-a-w- c:\windows\syswow64\msfeedsbs.dll 2010-02-23 07:55:43 5964800 —-a-w- c:\windows\syswow64\mshtml.dll 2010-02-23 07:55:24 10978816 —-a-w- c:\windows\syswow64\ieframe.dll 2010-02-23 07:55:20 381440 —-a-w- c:\windows\syswow64\iedkcs32.dll 2010-02-12 17:01:24 95520 —-a-w- c:\windows\system32\dnssd.dll 2010-02-12 17:01:24 119584 —-a-w- c:\windows\system32\dns-sd.exe 2010-02-12 16:46:14 91424 —-a-w- c:\windows\syswow64\dnssd.dll 2010-02-12 16:46:14 107808 —-a-w- c:\windows\syswow64\dns-sd.exe 2010-02-11 06:08:26 948760 —-a-w- c:\windows\syswow64\igxpun.exe 2010-02-11 06:08:24 509976 —-a-w- c:\windows\system32\igfxsrvc.exe 2010-02-11 06:08:24 166424 —-a-w- c:\windows\system32\igfxtray.exe 2010-02-11 06:08:22 410648 —-a-w- c:\windows\system32\igfxpers.exe 2010-02-11 06:08:20 222744 —-a-w- c:\windows\system32\igfxext.exe 2010-02-11 06:08:18 391192 —-a-w- c:\windows\system32\hkcmd.exe 2010-02-11 06:08:16 3126808 —-a-w- c:\windows\system32\GfxUI.exe 2010-02-11 06:08:16 152600 —-a-w- c:\windows\system32\difx64.exe 2010-02-11 06:00:46 90112 —-a-w- c:\windows\system32\igfxCoIn_v2082.dll 2010-02-11 05:56:24 5972480 —-a-w- c:\windows\system32\igdumd64.dll 2010-02-11 05:54:24 982224 —-a-w- c:\windows\syswow64\igkrng500.bin 2010-02-11 05:54:24 982224 —-a-w- c:\windows\system32\igkrng500.bin 2010-02-11 05:54:24 92292 —-a-w- c:\windows\syswow64\igfcg500m.bin 2010-02-11 05:54:24 92292 —-a-w- c:\windows\system32\igfcg500m.bin 2010-02-11 05:54:24 439336 —-a-w- c:\windows\syswow64\igcompkrng500.bin 2010-02-11 05:54:24 439336 —-a-w- c:\windows\system32\igcompkrng500.bin 2010-02-11 05:50:18 4502016 —-a-w- c:\windows\syswow64\igdumd32.dll 2010-02-11 05:45:32 550912 —-a-w- c:\windows\syswow64\igdumdx32.dll 2010-02-11 05:44:48 4088320 —-a-w- c:\windows\system32\igd10umd64.dll 2010-02-11 05:41:56 3890688 —-a-w- c:\windows\syswow64\igd10umd32.dll 2010-02-11 05:38:36 5519872 —-a-w- c:\windows\system32\ig4dev64.dll 2010-02-11 05:38:22 8132608 —-a-w- c:\windows\system32\ig4icd64.dll 2010-02-11 05:33:08 4079616 —-a-w- c:\windows\syswow64\ig4dev32.dll 2010-02-11 05:32:52 6061568 —-a-w- c:\windows\syswow64\ig4icd32.dll 2010-02-11 05:23:14 377856 —-a-w- c:\windows\system32\igfxTMM.dll 2010-02-11 05:23:14 248320 —-a-w- c:\windows\system32\igfxpph.dll 2010-02-11 05:23:06 27648 —-a-w- c:\windows\system32\igfxexps.dll 2010-02-11 05:22:42 61440 —-a-w- c:\windows\system32\igfxsrvc.dll 2010-02-11 05:22:00 108544 —-a-w- c:\windows\system32\hccutils.dll 2010-02-11 05:21:48 4096 —-a-w- c:\windows\system32\IGFXDEVLib.dll 2010-02-11 05:21:48 268800 —-a-w- c:\windows\system32\igfxdev.dll 2010-02-11 05:21:48 119296 —-a-w- c:\windows\system32\gfxSrvc.dll 2010-02-11 05:21:12 9014784 —-a-w- c:\windows\system32\igfxress.dll 2010-02-11 05:21:12 142336 —-a-w- c:\windows\system32\igfxdo.dll 2010-02-11 05:16:20 59392 —-a-w- c:\windows\syswow64\oemdspif.dll 2010-02-11 05:14:52 225792 —-a-w- c:\windows\syswow64\igfxdv32.dll 2010-02-11 05:05:42 208896 —-a-w- c:\windows\syswow64\iglhsip32.dll 2010-02-11 05:05:42 205824 —-a-w- c:\windows\system32\iglhsip64.dll 2010-02-11 05:05:42 187392 —-a-w- c:\windows\system32\iglhcp64.dll 2010-02-11 05:05:42 143360 —-a-w- c:\windows\syswow64\iglhcp32.dll 2009-07-14 05:37:38 31548 —-a-w- c:\windows\inf\perflib\0409\perfd.dat 2009-07-14 05:37:38 31548 —-a-w- c:\windows\inf\perflib\0409\perfc.dat 2009-07-14 05:37:38 291294 —-a-w- c:\windows\inf\perflib\0409\perfi.dat 2009-07-14 05:37:38 291294 —-a-w- c:\windows\inf\perflib\0409\perfh.dat 2009-07-14 04:54:24 174 –sha-w- c:\program files\desktop.ini 2009-07-14 04:54:24 174 –sha-w- c:\program files (x86)\desktop.ini 2009-07-14 01:00:34 291294 —-a-w- c:\windows\inf\perflib\0000\perfi.dat 2009-07-14 01:00:34 291294 —-a-w- c:\windows\inf\perflib\0000\perfh.dat 2009-07-14 01:00:32 31548 —-a-w- c:\windows\inf\perflib\0000\perfd.dat 2009-07-14 01:00:32 31548 —-a-w- c:\windows\inf\perflib\0000\perfc.dat 2009-06-10 20:44:08 9633792 –sha-r- c:\windows\fonts\StaticCache.dat 2009-07-14 01:39:53 398848 –sha-w- c:\windows\winsxs\amd64_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_4d4d1f2f696639a2\WinMail.exe 2009-07-14 01:14:45 396800 –sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe ============= FINISH: 16:08:14.77 ===============
Hi,

Please do the following:

Download OTL to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under the Custom Scan box paste this in


    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    /md5stop
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\drivers\*.sys /90
    CREATERESTOREPOINT

  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them in your next reply.
old.txt

OTL logfile created on: 5/7/2010 11:11:34 PM - Run 1
OTL by OldTimer - Version 3.2.4.1 Folder = C:\Users\Khoa\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 70.00% Memory free
8.00 Gb Paging File | 7.00 Gb Available in Paging File | 83.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 252.89 Gb Total Space | 203.93 Gb Free Space | 80.64% Space Free | Partition Type: NTFS
Drive D: | 30.25 Gb Total Space | 29.39 Gb Free Space | 97.16% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: KLAM
Current User Name: Khoa
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Minimal
Quick Scan

========== Processes (SafeList) ==========

PRC - C:\Users\Khoa\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Webroot\WebrootSecurity\WRConsumerService.exe (Webroot Software, Inc. )
PRC - C:\Users\Khoa\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Users\Khoa\AppData\Local\Google\Update\1.2.183.23\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Users\Khoa\AppData\Roaming\Dropbox\bin\Dropbox.exe ()
PRC - C:\Program Files (x86)\Webroot\WebrootSecurity\SpySweeperUI.exe (Webroot Software, Inc.)
PRC - C:\Program Files (x86)\Webroot\WebrootSecurity\SpySweeper.exe (Webroot Software, Inc. (www.webroot.com))
PRC - C:\Program Files (x86)\Webroot\WebrootSecurity\SSU.exe (Webroot Software, Inc. (www.webroot.com))
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Lenovo\ReadyComm\common\IGRS.exe (Lenovo Group Limited)
PRC - C:\Program Files (x86)\DDNI\Lenovo Idea Notes\DDNIMSGService.exe (Digital Delivery Networks, Inc.)
PRC - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Creative\Sync Manager Unicode\CTSyncU.exe ()
PRC - C:\Windows\SysWOW64\CTSVCCDA.EXE (Creative Technology Ltd)


========== Modules (SafeList) ==========

MOD - C:\Users\Khoa\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\SysWOW64\comdlg32.dll (Microsoft Corporation)
MOD - C:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV:64bit: - (WatAdminSvc) – C:\Windows\SysNative\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV:64bit: - (wlidsvc) – C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation)
SRV:64bit: - (Lenovo ReadyComm ConnSvc) – C:\Program Files\Lenovo\ReadyComm\ConnSvc.exe (Lenovo Group Limited)
SRV:64bit: - (Lenovo ReadyComm AppSvc) – C:\Program Files\Lenovo\ReadyComm\AppSvc.exe (Lenovo Group Limited)
SRV:64bit: - (WwanSvc) – C:\Windows\SysNative\wwansvc.dll (Microsoft Corporation)
SRV:64bit: - (WbioSrvc) – C:\Windows\SysNative\wbiosrvc.dll (Microsoft Corporation)
SRV:64bit: - (Power) – C:\Windows\SysNative\umpo.dll (Microsoft Corporation)
SRV:64bit: - (Themes) – C:\Windows\SysNative\themeservice.dll (Microsoft Corporation)
SRV:64bit: - (sppuinotify) – C:\Windows\SysNative\sppuinotify.dll (Microsoft Corporation)
SRV:64bit: - (SensrSvc) – C:\Windows\SysNative\sensrsvc.dll (Microsoft Corporation)
SRV:64bit: - (PNRPsvc) – C:\Windows\SysNative\pnrpsvc.dll (Microsoft Corporation)
SRV:64bit: - (p2pimsvc) – C:\Windows\SysNative\pnrpsvc.dll (Microsoft Corporation)
SRV:64bit: - (HomeGroupProvider) – C:\Windows\SysNative\provsvc.dll (Microsoft Corporation)
SRV:64bit: - (RpcEptMapper) – C:\Windows\SysNative\RpcEpMap.dll (Microsoft Corporation)
SRV:64bit: - (PNRPAutoReg) – C:\Windows\SysNative\pnrpauto.dll (Microsoft Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (HomeGroupListener) – C:\Windows\SysNative\ListSvc.dll (Microsoft Corporation)
SRV:64bit: - (FontCache) – C:\Windows\SysNative\FntCache.dll (Microsoft Corporation)
SRV:64bit: - (Dhcp) – C:\Windows\SysNative\dhcpcore.dll (Microsoft Corporation)
SRV:64bit: - (defragsvc) – C:\Windows\SysNative\defragsvc.dll (Microsoft Corporation)
SRV:64bit: - (bthserv) – C:\Windows\SysNative\bthserv.dll (Microsoft Corporation)
SRV:64bit: - (BDESVC) – C:\Windows\SysNative\bdesvc.dll (Microsoft Corporation)
SRV:64bit: - (AxInstSV) – C:\Windows\SysNative\AxInstSv.dll (Microsoft Corporation)
SRV:64bit: - (AppIDSvc) – C:\Windows\SysNative\appidsvc.dll (Microsoft Corporation)
SRV:64bit: - (wbengine) – C:\windows\SysNative\wbengine.exe (Microsoft Corporation)
SRV:64bit: - (sppsvc) – C:\Windows\SysNative\sppsvc.exe (Microsoft Corporation)
SRV:64bit: - (Fax) – C:\Windows\SysNative\FXSSVC.exe (Microsoft Corporation)
SRV - (WRConsumerService) – C:\Program Files (x86)\Webroot\WebrootSecurity\WRConsumerService.exe (Webroot Software, Inc. )
SRV - (Apple Mobile Device) – C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (WebrootSpySweeperService) – C:\Program Files (x86)\Webroot\WebrootSecurity\SpySweeper.exe (Webroot Software, Inc. (www.webroot.com))
SRV - (IAANTMON) Intel® – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (fsssvc) – C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (IGRS) – C:\Program Files (x86)\Lenovo\ReadyComm\common\IGRS.exe (Lenovo Group Limited)
SRV - (VSS) – C:\Windows\Vss [2009/07/13 22:20:14 | 000,000,000 | —D | M]
SRV - (MSDTC) – C:\Windows\SysWOW64\Msdtc [2009/07/13 22:20:14 | 000,000,000 | —D | M]
SRV - (HomeGroupProvider) – C:\Windows\SysWOW64\provsvc.dll (Microsoft Corporation)
SRV - (Dhcp) – C:\Windows\SysWOW64\dhcpcore.dll (Microsoft Corporation)
SRV - (ReadyComm.DirectRouter) – C:\windows\SysWow64\IgrsSvcs.exe (Microsoft Corporation)
SRV - (PS_MDP) – C:\windows\SysWow64\IgrsSvcs.exe (Microsoft Corporation)
SRV - (vds) – C:\Windows\SysWOW64\wbem\vds.mof ()
SRV - (MpfService) – C:\Program Files (x86)\McAfee\MPF\MPFSrv.exe (McAfee, Inc.)
SRV - (DDNIMSGService) – C:\Program Files (x86)\DDNI\Lenovo Idea Notes\DDNIMSGService.exe (Digital Delivery Networks, Inc.)
SRV - (clr_optimization_v2.0.50727_64) – C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (SeaPort) – C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (Creative Service for CDROM Access) – C:\Windows\SysWOW64\CTSVCCDA.EXE (Creative Technology Ltd)


========== Driver Services (SafeList) ==========

DRV:64bit: - (sptd) – C:\Windows\SysNative\drivers\sptd.sys (Duplex Secure Ltd.)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (KSecPkg) – C:\Windows\SysNative\drivers\ksecpkg.sys (Microsoft Corporation)
DRV:64bit: - (ssidrv) – C:\Windows\SysNative\drivers\ssidrv.sys (Webroot Software, Inc. (www.webroot.com))
DRV:64bit: - (ssfs0bbc) – C:\Windows\SysNative\drivers\ssfs0bbc.sys (Webroot Software, Inc. (www.webroot.com))
DRV:64bit: - (funfrm) – C:\Windows\SysNative\drivers\funfrm.sys ()
DRV:64bit: - (fvevol) – C:\Windows\SysNative\drivers\fvevol.sys (Microsoft Corporation)
DRV:64bit: - (NETw5s64) Intel® – C:\Windows\SysNative\drivers\NETw5s64.sys (Intel Corporation)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (fssfltr) – C:\Windows\SysNative\drivers\fssfltr.sys (Microsoft Corporation)
DRV:64bit: - (Cam5607) – C:\Windows\SysNative\drivers\BisonC07.sys (Bison Electronics. Inc. )
DRV:64bit: - (wsvd) – C:\Windows\SysNative\drivers\wsvd.sys (CyberLink)
DRV:64bit: - (wdmirror) – C:\Windows\SysNative\drivers\WDMirror.sys (Lenovo)
DRV:64bit: - (Bridge0) – C:\Windows\SysNative\drivers\WDBridge.sys (Lenovo)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (hwpolicy) – C:\Windows\SysNative\drivers\hwpolicy.sys (Microsoft Corporation)
DRV:64bit: - (FsDepends) – C:\Windows\SysNative\drivers\fsdepends.sys (Microsoft Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (WIMMount) – C:\Windows\SysNative\drivers\wimmount.sys (Microsoft Corporation)
DRV:64bit: - (vhdmp) – C:\Windows\SysNative\drivers\vhdmp.sys (Microsoft Corporation)
DRV:64bit: - (vdrvroot) – C:\Windows\SysNative\drivers\vdrvroot.sys (Microsoft Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (rdyboost) – C:\Windows\SysNative\drivers\rdyboost.sys (Microsoft Corporation)
DRV:64bit: - (pcw) – C:\Windows\SysNative\drivers\pcw.sys (Microsoft Corporation)
DRV:64bit: - (CNG) – C:\Windows\SysNative\drivers\cng.sys (Microsoft Corporation)
DRV:64bit: - (rdpbus) – C:\Windows\SysNative\drivers\rdpbus.sys (Microsoft Corporation)
DRV:64bit: - (RDPREFMP) – C:\Windows\SysNative\drivers\RDPREFMP.sys (Microsoft Corporation)
DRV:64bit: - (RasAgileVpn) WAN Miniport (IKEv2) – C:\Windows\SysNative\drivers\agilevpn.sys (Microsoft Corporation)
DRV:64bit: - (WfpLwf) – C:\Windows\SysNative\drivers\wfplwf.sys (Microsoft Corporation)
DRV:64bit: - (NdisCap) – C:\Windows\SysNative\drivers\ndiscap.sys (Microsoft Corporation)
DRV:64bit: - (vwififlt) – C:\Windows\SysNative\drivers\vwififlt.sys (Microsoft Corporation)
DRV:64bit: - (vwifibus) – C:\Windows\SysNative\drivers\vwifibus.sys (Microsoft Corporation)
DRV:64bit: - (1394ohci) – C:\Windows\SysNative\drivers\1394ohci.sys (Microsoft Corporation)
DRV:64bit: - (HdAudAddService) – C:\Windows\SysNative\drivers\HdAudio.sys (Microsoft Corporation)
DRV:64bit: - (usbvideo) USB Video Device (WDM) – C:\Windows\SysNative\drivers\usbvideo.sys (Microsoft Corporation)
DRV:64bit: - (BthPan) Bluetooth Device (Personal Area Network) – C:\Windows\SysNative\drivers\bthpan.sys (Microsoft Corporation)
DRV:64bit: - (BTHPORT) – C:\Windows\SysNative\drivers\bthport.sys (Microsoft Corporation)
DRV:64bit: - (RFCOMM) Bluetooth Device (RFCOMM Protocol TDI) – C:\Windows\SysNative\drivers\rfcomm.sys (Microsoft Corporation)
DRV:64bit: - (BthEnum) – C:\Windows\SysNative\drivers\bthenum.sys (Microsoft Corporation)
DRV:64bit: - (BTHUSB) – C:\Windows\SysNative\drivers\BTHUSB.SYS (Microsoft Corporation)
DRV:64bit: - (UmPass) – C:\Windows\SysNative\drivers\umpass.sys (Microsoft Corporation)
DRV:64bit: - (WinUsb) – C:\Windows\SysNative\drivers\winusb.sys (Microsoft Corporation)
DRV:64bit: - (mshidkmdf) – C:\Windows\SysNative\drivers\mshidkmdf.sys (Microsoft Corporation)
DRV:64bit: - (WudfPf) – C:\Windows\SysNative\drivers\WUDFPf.sys (Microsoft Corporation)
DRV:64bit: - (MTConfig) – C:\Windows\SysNative\drivers\MTConfig.sys (Microsoft Corporation)
DRV:64bit: - (CompositeBus) – C:\Windows\SysNative\drivers\CompositeBus.sys (Microsoft Corporation)
DRV:64bit: - (Beep) – C:\Windows\SysNative\drivers\beep.sys (Microsoft Corporation)
DRV:64bit: - (AppID) – C:\Windows\SysNative\drivers\appid.sys (Microsoft Corporation)
DRV:64bit: - (scfilter) – C:\Windows\SysNative\drivers\scfilter.sys (Microsoft Corporation)
DRV:64bit: - (discache) – C:\Windows\SysNative\drivers\discache.sys (Microsoft Corporation)
DRV:64bit: - (HidBatt) – C:\Windows\SysNative\drivers\hidbatt.sys (Microsoft Corporation)
DRV:64bit: - (CmBatt) – C:\Windows\SysNative\drivers\CmBatt.sys (Microsoft Corporation)
DRV:64bit: - (AcpiPmi) – C:\Windows\SysNative\drivers\acpipmi.sys (Microsoft Corporation)
DRV:64bit: - (AmdPPM) – C:\Windows\SysNative\drivers\amdppm.sys (Microsoft Corporation)
DRV:64bit: - (RSUSBSTOR) – C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (k57nd60a) Broadcom NetLink ™ – C:\Windows\SysNative\drivers\k57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (IntcHdmiAddService) Intel® – C:\Windows\SysNative\drivers\IntcHdmi.sys (Intel® Corporation)
DRV:64bit: - (ACPIVPC) – C:\Windows\SysNative\drivers\AcpiVpc.sys (Lenovo Corporation)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (netw5v64) Intel® – C:\Windows\SysNative\drivers\NETw5v64.sys (Intel Corporation)
DRV:64bit: - (MPFP) – C:\Windows\SysNative\drivers\Mpfp.sys (McAfee, Inc.)
DRV:64bit: - (WimFltr) – C:\Windows\SysNative\drivers\WimFltr.sys (Microsoft Corporation)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (WinUsb) – C:\Windows\SysWOW64\winusb.dll (Microsoft Corporation)
DRV - (NetBIOS) – C:\Windows\SysWOW64\netbios.dll (Microsoft Corporation)
DRV - (mpsdrv) – C:\Windows\SysWOW64\wbem\mpsdrv.mof ()
DRV - (Tcpip) – C:\Windows\SysWOW64\wbem\tcpip.mof ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.lenovo.com/ [binary data]
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://lenovo.live.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.lenovo.com/ [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://lenovo.live.com/

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [Binary data over 100 bytes]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ;*.local



O1 HOSTS File: ([2010/05/02 22:36:32 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Windows Live Family Safety Browser Helper Class) - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation)
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [Energy Management] C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe (Lenovo (Beijing) Limited)
O4:64bit: - HKLM..\Run: [EnergyUtility] C:\Program Files (x86)\Lenovo\Energy Management\utility.exe (Lenovo(beijing) Limited)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SpySweeper] C:\Program Files (x86)\Webroot\WebrootSecurity\SpySweeperUI.exe (Webroot Software, Inc.)
O4 - HKLM..\Run: [UpdateP2GShortCut] C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKCU..\Run: [CTSyncU.exe] C:\Program Files (x86)\Creative\Sync Manager Unicode\CTSyncU.exe ()
O4 - HKCU..\Run: [FactoryTest] C:\Windows\Test.bat File not found
O4 - Startup: C:\Users\Khoa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Khoa\AppData\Roaming\Dropbox\bin\Dropbox.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8:64bit: - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files (x86)\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files (x86)\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files (x86)\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Windows\SysNative\wshbth.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Windows\SysWOW64\wshbth.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files (x86)\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - Reg Error: Key error. File not found
O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - C:\windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O30:64bit: - LSA: Security Packages - (pku2u) - C:\windows\SysNative\pku2u.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (livessp) - C:\windows\SysNative\livessp.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (pku2u) - C:\windows\SysWow64\pku2u.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (livessp) - C:\windows\SysWow64\livessp.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{320dca2f-52ec-11df-9cfc-002622cc1862}\Shell - "" = AutoRun
O33 - MountPoints2\{320dca2f-52ec-11df-9cfc-002622cc1862}\Shell\AutoRun\command - "" = G:\LaunchU3.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs:64bit: Ias - C:\Windows\SysNative\ias [2009/07/13 22:20:14 | 000,000,000 | —D | M]
NetSvcs:64bit: Irmon - C:\Windows\SysNative\irmon.dll (Microsoft Corporation)
NetSvcs:64bit: Wmi - C:\Windows\SysNative\wmi.dll (Microsoft Corporation)
NetSvcs:64bit: Themes - C:\Windows\SysNative\themeservice.dll (Microsoft Corporation)
NetSvcs:64bit: BDESVC - C:\Windows\SysNative\bdesvc.dll (Microsoft Corporation)
NetSvcs: Ias - C:\Windows\SysWOW64\ias.dll (Microsoft Corporation)
NetSvcs: Wmi - C:\Windows\SysWOW64\wmi.dll (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 90 Days ==========

[2010/05/07 23:08:34 | 000,570,880 | —- | C] (OldTimer Tools) – C:\Users\Khoa\Desktop\OTL.exe
[2010/05/06 16:27:45 | 000,000,000 | —D | C] – C:\Users\Khoa\Desktop\Fixing
[2010/05/05 12:07:49 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2010/05/03 21:29:18 | 000,000,000 | —D | C] – C:\ProgramData\NCH Swift Sound
[2010/05/03 21:28:46 | 000,000,000 | —D | C] – C:\Program Files (x86)\NCH Software
[2010/05/03 21:28:42 | 000,000,000 | —D | C] – C:\Program Files (x86)\NCH Swift Sound
[2010/05/02 22:32:34 | 000,000,000 | —D | C] – C:\Program Files (x86)\MSSOAP
[2010/05/02 22:32:34 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\MSSoap
[2010/05/02 22:32:24 | 001,563,008 | —- | C] (Webroot Software, Inc.) – C:\windows\WRSetup.dll
[2010/05/02 22:32:24 | 000,000,000 | —D | C] – C:\Users\Khoa\AppData\Roaming\Webroot
[2010/05/02 22:32:24 | 000,000,000 | —D | C] – C:\ProgramData\Webroot
[2010/05/02 22:32:24 | 000,000,000 | —D | C] – C:\Program Files (x86)\Webroot
[2010/05/02 22:17:16 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2010/04/27 00:13:36 | 000,000,000 | —D | C] – C:\ProgramData\Sports Interactive
[2010/04/27 00:12:45 | 000,000,000 | —D | C] – C:\Users\Public\Documents\Sports Interactive
[2010/04/26 23:58:56 | 000,000,000 | -H-D | C] – C:\Program Files (x86)\Zero G Registry
[2010/04/26 23:57:23 | 000,000,000 | —D | C] – C:\Users\Khoa\AppData\Roaming\Sports Interactive
[2010/04/26 23:49:14 | 000,834,544 | —- | C] (Duplex Secure Ltd.) – C:\windows\SysNative\drivers\sptd.sys
[2010/04/26 23:48:45 | 000,000,000 | —D | C] – C:\Program Files (x86)\DAEMON Tools Lite
[2010/04/26 23:47:55 | 000,000,000 | —D | C] – C:\Users\Khoa\AppData\Roaming\DAEMON Tools Lite
[2010/04/26 23:47:51 | 000,000,000 | —D | C] – C:\ProgramData\DAEMON Tools Lite
[2010/04/07 20:14:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\MSECache
[2010/04/06 00:40:22 | 000,000,000 | —D | C] – C:\windows\SysWow64\Adobe
[2010/04/04 21:32:07 | 000,000,000 | —D | C] – C:\Program Files (x86)\MSXML 4.0
[2010/04/04 14:36:36 | 000,000,000 | —D | C] – C:\Users\Khoa\AppData\Roaming\Yahoo!
[2010/04/04 14:36:36 | 000,000,000 | —D | C] – C:\Users\Khoa\AppData\Local\Yahoo
[2010/04/04 14:35:19 | 000,000,000 | —D | C] – C:\ProgramData\Yahoo!
[2010/04/04 14:33:54 | 000,000,000 | —D | C] – C:\Program Files (x86)\Yahoo!
[2010/04/03 22:45:41 | 000,000,000 | —D | C] – C:\Users\Khoa\Documents\My Games
[2010/04/03 22:45:41 | 000,000,000 | —D | C] – C:\ProgramData\Age of Empires 3
[2010/04/03 21:55:12 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Microsoft Games
[2010/04/03 21:44:44 | 000,000,000 | —D | C] – C:\My Games
[2010/04/02 13:16:09 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Creative
[2010/04/02 13:16:07 | 000,000,000 | -H-D | C] – C:\Program Files (x86)\Creative Installation Information
[2010/04/02 13:14:05 | 000,000,000 | —D | C] – C:\Program Files (x86)\Creative
[2010/04/01 22:45:19 | 000,000,000 | —D | C] – C:\windows\SysWow64\Wat
[2010/04/01 22:45:18 | 000,000,000 | —D | C] – C:\windows\SysNative\Wat
[2010/04/01 22:40:09 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Steam
[2010/04/01 22:40:07 | 000,000,000 | —D | C] – C:\Program Files (x86)\Steam
[2010/04/01 22:07:13 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft ActiveSync
[2010/04/01 22:07:11 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\DESIGNER
[2010/04/01 22:07:02 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft.NET
[2010/04/01 22:07:02 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Office
[2010/04/01 22:05:54 | 000,000,000 | RH-D | C] – C:\MSOCache
[2010/04/01 22:04:31 | 000,000,000 | —D | C] – C:\Users\Khoa\My Software
[2010/04/01 21:21:54 | 000,000,000 | —D | C] – C:\Users\Khoa\AppData\Roaming\Mp3tag
[2010/04/01 21:21:47 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mp3tag
[2010/04/01 21:11:57 | 000,000,000 | —D | C] – C:\ProgramData\FreeRIP
[2010/04/01 21:07:58 | 000,000,000 | —D | C] – C:\Program Files (x86)\WMPCDText
[2010/04/01 20:52:42 | 000,000,000 | —D | C] – C:\Users\Khoa\AppData\Roaming\Apple Computer
[2010/04/01 20:52:42 | 000,000,000 | —D | C] – C:\Users\Khoa\AppData\Local\Apple Computer
[2010/04/01 20:52:02 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2010/04/01 20:52:00 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2010/04/01 20:52:00 | 000,000,000 | —D | C] – C:\Program Files (x86)\iTunes
[2010/04/01 20:52:00 | 000,000,000 | —D | C] – C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
[2010/04/01 20:50:58 | 000,000,000 | —D | C] – C:\Program Files (x86)\QuickTime
[2010/04/01 20:50:58 | 000,000,000 | —D | C] – C:\ProgramData\Apple Computer
[2010/04/01 20:50:49 | 000,000,000 | —D | C] – C:\Users\Khoa\AppData\Local\Apple
[2010/04/01 20:50:46 | 000,000,000 | —D | C] – C:\Program Files (x86)\Apple Software Update
[2010/04/01 20:50:22 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Apple
[2010/04/01 20:50:13 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2010/04/01 20:50:13 | 000,000,000 | —D | C] – C:\Program Files (x86)\Bonjour
[2010/04/01 20:49:50 | 000,000,000 | —D | C] – C:\ProgramData\Apple
[2010/04/01 20:49:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Apple
[2010/04/01 18:22:12 | 000,000,000 | R–D | C] – C:\Users\Khoa\My Dropbox
[2010/04/01 18:13:26 | 000,000,000 | —D | C] – C:\Program Files (x86)\Adobe
[2010/04/01 18:05:20 | 000,000,000 | —D | C] – C:\Program Files (x86)\IZArc
[2010/04/01 18:01:17 | 000,000,000 | —D | C] – C:\Users\Khoa\AppData\Roaming\Dropbox
[2010/04/01 10:09:23 | 000,000,000 | —D | C] – C:\Program Files (x86)\CCleaner
[2010/04/01 10:04:46 | 000,000,000 | —D | C] – C:\Users\Khoa\Documents\Downloads
[2010/04/01 10:03:42 | 000,000,000 | —D | C] – C:\Users\Khoa\AppData\Local\Google
[2010/04/01 10:03:30 | 000,000,000 | —D | C] – C:\Users\Khoa\AppData\Local\Apps
[2010/04/01 10:03:29 | 000,000,000 | —D | C] – C:\Users\Khoa\AppData\Local\Deployment
[2010/04/01 07:58:35 | 000,000,000 | —D | C] – C:\Users\Khoa\AppData\Local\VirtualStore
[2010/04/01 07:58:28 | 000,000,000 | -HSD | C] – C:\Users\Khoa\AppData\Local\Temporary Internet Files
[2010/04/01 07:58:28 | 000,000,000 | -HSD | C] – C:\Users\Khoa\Templates
[2010/04/01 07:58:28 | 000,000,000 | -HSD | C] – C:\Users\Khoa\Start Menu
[2010/04/01 07:58:28 | 000,000,000 | -HSD | C] – C:\Users\Khoa\SendTo
[2010/04/01 07:58:28 | 000,000,000 | -HSD | C] – C:\Users\Khoa\Recent
[2010/04/01 07:58:28 | 000,000,000 | -HSD | C] – C:\Users\Khoa\PrintHood
[2010/04/01 07:58:28 | 000,000,000 | -HSD | C] – C:\Users\Khoa\NetHood
[2010/04/01 07:58:28 | 000,000,000 | -HSD | C] – C:\Users\Khoa\Documents\My Videos
[2010/04/01 07:58:28 | 000,000,000 | -HSD | C] – C:\Users\Khoa\Documents\My Pictures
[2010/04/01 07:58:28 | 000,000,000 | -HSD | C] – C:\Users\Khoa\Documents\My Music
[2010/04/01 07:58:28 | 000,000,000 | -HSD | C] – C:\Users\Khoa\My Documents
[2010/04/01 07:58:28 | 000,000,000 | -HSD | C] – C:\Users\Khoa\Local Settings
[2010/04/01 07:58:28 | 000,000,000 | -HSD | C] – C:\Users\Khoa\AppData\Local\History
[2010/04/01 07:58:28 | 000,000,000 | -HSD | C] – C:\Users\Khoa\Cookies
[2010/04/01 07:58:28 | 000,000,000 | -HSD | C] – C:\Users\Khoa\Application Data
[2010/04/01 07:58:28 | 000,000,000 | -HSD | C] – C:\Users\Khoa\AppData\Local\Application Data
[2010/04/01 07:58:16 | 000,000,000 | –SD | C] – C:\Users\Khoa\AppData\Roaming\Microsoft
[2010/04/01 07:58:16 | 000,000,000 | R-SD | C] – C:\Users\Khoa\Documents\My Stationery
[2010/04/01 07:58:16 | 000,000,000 | R–D | C] – C:\Users\Khoa\Videos
[2010/04/01 07:58:16 | 000,000,000 | R–D | C] – C:\Users\Khoa\Searches
[2010/04/01 07:58:16 | 000,000,000 | R–D | C] – C:\Users\Khoa\Saved Games
[2010/04/01 07:58:16 | 000,000,000 | R–D | C] – C:\Users\Khoa\Pictures
[2010/04/01 07:58:16 | 000,000,000 | R–D | C] – C:\Users\Khoa\Music
[2010/04/01 07:58:16 | 000,000,000 | R–D | C] – C:\Users\Khoa\Links
[2010/04/01 07:58:16 | 000,000,000 | R–D | C] – C:\Users\Khoa\Favorites
[2010/04/01 07:58:16 | 000,000,000 | R–D | C] – C:\Users\Khoa\Downloads
[2010/04/01 07:58:16 | 000,000,000 | R–D | C] – C:\Users\Khoa\My Documents
[2010/04/01 07:58:16 | 000,000,000 | R–D | C] – C:\Users\Khoa\Desktop
[2010/04/01 07:58:16 | 000,000,000 | R–D | C] – C:\Users\Khoa\Contacts
[2010/04/01 07:58:16 | 000,000,000 | -H-D | C] – C:\Users\Khoa\AppData
[2010/04/01 07:58:16 | 000,000,000 | —D | C] – C:\Users\Khoa\AppData\Local\White_Sky,_Inc
[2010/04/01 07:58:16 | 000,000,000 | —D | C] – C:\Users\Khoa\Tracing
[2010/04/01 07:58:16 | 000,000,000 | —D | C] – C:\Users\Khoa\AppData\Local\Temp
[2010/04/01 07:58:16 | 000,000,000 | —D | C] – C:\Users\Khoa\AppData\Local\Seven Zip
[2010/04/01 07:58:16 | 000,000,000 | —D | C] – C:\Users\Khoa\AppData\Local\Microsoft Help
[2010/04/01 07:58:16 | 000,000,000 | —D | C] – C:\Users\Khoa\AppData\Local\Microsoft
[2010/04/01 07:58:16 | 000,000,000 | —D | C] – C:\Users\Khoa\AppData\Roaming\Macromedia
[2010/04/01 07:58:16 | 000,000,000 | —D | C] – C:\Users\Khoa\AppData\Roaming\Lenovo
[2010/04/01 07:58:16 | 000,000,000 | —D | C] – C:\Users\Khoa\AppData\Local\IsolatedStorage
[2010/04/01 07:58:16 | 000,000,000 | —D | C] – C:\Users\Khoa\AppData\Roaming\InstallShield
[2010/04/01 07:58:16 | 000,000,000 | —D | C] – C:\Users\Khoa\AppData\Roaming\Identities
[2010/04/01 07:58:16 | 000,000,000 | —D | C] – C:\Users\Khoa\AppData\Roaming\ID Vault
[2010/04/01 07:58:16 | 000,000,000 | —D | C] – C:\Users\Khoa\AppData\Local\ID Vault
[2010/04/01 07:58:16 | 000,000,000 | —D | C] – C:\Users\Khoa\AppData\Roaming\CyberLink
[2010/04/01 07:58:16 | 000,000,000 | —D | C] – C:\Users\Khoa\AppData\Local\assembly
[2010/04/01 07:58:16 | 000,000,000 | —D | C] – C:\Users\Khoa\AppData\Roaming\Adobe
[2010/04/01 07:58:16 | 000,000,000 | —D | C] – C:\Users\Khoa\AppData\Local\Adobe
[2010/04/01 07:58:00 | 000,000,000 | -HSD | C] – C:\Recovery
[2010/03/04 13:43:00 | 000,346,144 | —- | C] (Realtek ) – C:\windows\SysNative\drivers\Rt64win7.sys
[2010/02/11 00:21:48 | 000,004,096 | —- | C] ( ) – C:\windows\SysNative\IGFXDEVLib.dll
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]

========== Files - Modified Within 90 Days ==========

[2010/05/07 23:13:48 | 001,572,864 | -HS- | M] () – C:\Users\Khoa\NTUSER.DAT
[2010/05/07 23:08:34 | 000,570,880 | —- | M] (OldTimer Tools) – C:\Users\Khoa\Desktop\OTL.exe
[2010/05/07 23:08:03 | 000,000,904 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-1808124184-2126047323-2208561221-1003UA.job
[2010/05/07 23:06:28 | 000,067,584 | –S- | M] () – C:\windows\bootstat.dat
[2010/05/06 15:38:37 | 000,013,632 | -H– | M] () – C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/05/06 15:38:37 | 000,013,632 | -H– | M] () – C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/05/06 15:31:17 | 000,000,006 | -H– | M] () – C:\windows\tasks\SA.DAT
[2010/05/06 15:31:10 | 3168,169,984 | -HS- | M] () – C:\hiberfil.sys
[2010/05/06 15:30:35 | 001,070,788 | -H– | M] () – C:\Users\Khoa\AppData\Local\IconCache.db
[2010/05/06 15:30:23 | 000,000,020 | —- | M] () – C:\Users\Khoa\defogger_reenable
[2010/05/06 10:08:00 | 000,000,852 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-1808124184-2126047323-2208561221-1003Core.job
[2010/05/02 22:32:26 | 000,017,264 | —- | M] () – C:\windows\SysNative\SsiEfr.exe
[2010/05/02 22:25:56 | 000,000,164 | —- | M] () – C:\windows\install.dat
[2010/04/30 00:44:26 | 000,713,888 | —- | M] () – C:\windows\SysNative\PerfStringBackup.INI
[2010/04/30 00:44:26 | 000,615,360 | —- | M] () – C:\windows\SysNative\perfh009.dat
[2010/04/30 00:44:26 | 000,103,702 | —- | M] () – C:\windows\SysNative\perfc009.dat
[2010/04/26 23:49:14 | 000,834,544 | —- | M] (Duplex Secure Ltd.) – C:\windows\SysNative\drivers\sptd.sys
[2010/04/01 23:58:49 | 000,000,000 | -H– | M] () – C:\windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2010/04/01 22:50:51 | 000,110,776 | —- | M] () – C:\Users\Khoa\AppData\Local\GDIPFONTCACHEV1.DAT
[2010/04/01 22:50:31 | 000,432,736 | —- | M] () – C:\windows\SysNative\FNTCACHE.DAT
[2010/04/01 22:08:02 | 000,000,376 | —- | M] () – C:\windows\ODBC.INI
[2010/04/01 21:24:07 | 000,000,033 | —- | M] () – C:\ProgramData\{081230F8-EA50-42A9-983C-D22ABC2EED3B}.ini
[2010/04/01 21:14:02 | 000,000,073 | —- | M] () – C:\windows\cdplayer.ini
[2010/04/01 21:12:06 | 000,001,074 | —- | M] () – C:\ProgramData\ss.ini
[2010/04/01 18:22:12 | 000,000,987 | —- | M] () – C:\Users\Khoa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2010/04/01 10:20:10 | 000,524,288 | -HS- | M] () – C:\Users\Khoa\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
[2010/04/01 10:20:10 | 000,524,288 | -HS- | M] () – C:\Users\Khoa\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
[2010/04/01 10:20:10 | 000,065,536 | -HS- | M] () – C:\Users\Khoa\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
[2010/04/01 09:57:28 | 000,039,252 | —- | M] () – C:\windows\SysWow64\license.rtf
[2010/04/01 09:57:28 | 000,039,252 | —- | M] () – C:\windows\SysNative\license.rtf
[2010/03/04 13:43:00 | 000,346,144 | —- | M] (Realtek ) – C:\windows\SysNative\drivers\Rt64win7.sys
[2010/02/11 01:27:54 | 000,005,156 | —- | M] () – C:\windows\SysNative\iglhxs64.vp
[2010/02/11 01:08:16 | 000,152,600 | —- | M] () – C:\windows\SysNative\difx64.exe
[2010/02/11 00:54:24 | 000,982,224 | —- | M] () – C:\windows\SysWow64\igkrng500.bin
[2010/02/11 00:54:24 | 000,982,224 | —- | M] () – C:\windows\SysNative\igkrng500.bin
[2010/02/11 00:54:24 | 000,439,336 | —- | M] () – C:\windows\SysWow64\igcompkrng500.bin
[2010/02/11 00:54:24 | 000,439,336 | —- | M] () – C:\windows\SysNative\igcompkrng500.bin
[2010/02/11 00:54:24 | 000,092,292 | —- | M] () – C:\windows\SysWow64\igfcg500m.bin
[2010/02/11 00:54:24 | 000,092,292 | —- | M] () – C:\windows\SysNative\igfcg500m.bin
[2010/02/11 00:27:38 | 000,102,380 | —- | M] () – C:\windows\SysNative\Gfxres.zh-TW.resources
[2010/02/11 00:27:38 | 000,101,267 | —- | M] () – C:\windows\SysNative\Gfxres.zh-CN.resources
[2010/02/11 00:27:36 | 000,119,498 | —- | M] () – C:\windows\SysNative\Gfxres.tr-TR.resources
[2010/02/11 00:27:34 | 000,188,052 | —- | M] () – C:\windows\SysNative\Gfxres.th-TH.resources
[2010/02/11 00:27:34 | 000,117,708 | —- | M] () – C:\windows\SysNative\Gfxres.sv-SE.resources
[2010/02/11 00:27:32 | 000,112,701 | —- | M] () – C:\windows\SysNative\Gfxres.sl-SI.resources
[2010/02/11 00:27:30 | 000,163,802 | —- | M] () – C:\windows\SysNative\Gfxres.ru-RU.resources
[2010/02/11 00:27:30 | 000,116,410 | —- | M] () – C:\windows\SysNative\Gfxres.sk-SK.resources
[2010/02/11 00:27:28 | 000,117,404 | —- | M] () – C:\windows\SysNative\Gfxres.pt-PT.resources
[2010/02/11 00:27:26 | 000,118,737 | —- | M] () – C:\windows\SysNative\Gfxres.pt-BR.resources
[2010/02/11 00:27:26 | 000,116,799 | —- | M] () – C:\windows\SysNative\Gfxres.pl-PL.resources
[2010/02/11 00:27:24 | 000,117,941 | —- | M] () – C:\windows\SysNative\Gfxres.nl-NL.resources
[2010/02/11 00:27:22 | 000,121,633 | —- | M] () – C:\windows\SysNative\Gfxres.ko-KR.resources
[2010/02/11 00:27:22 | 000,113,210 | —- | M] () – C:\windows\SysNative\Gfxres.nb-NO.resources
[2010/02/11 00:27:20 | 000,134,790 | —- | M] () – C:\windows\SysNative\Gfxres.ja-JP.resources
[2010/02/11 00:27:18 | 000,123,921 | —- | M] () – C:\windows\SysNative\Gfxres.it-IT.resources
[2010/02/11 00:27:16 | 000,132,112 | —- | M] () – C:\windows\SysNative\Gfxres.he-IL.resources
[2010/02/11 00:27:16 | 000,117,919 | —- | M] () – C:\windows\SysNative\Gfxres.hu-HU.resources
[2010/02/11 00:27:14 | 000,119,142 | —- | M] () – C:\windows\SysNative\Gfxres.fr-FR.resources
[2010/02/11 00:27:12 | 000,121,312 | —- | M] () – C:\windows\SysNative\Gfxres.es-ES.resources
[2010/02/11 00:27:12 | 000,117,032 | —- | M] () – C:\windows\SysNative\Gfxres.fi-FI.resources
[2010/02/11 00:27:10 | 000,176,762 | —- | M] () – C:\windows\SysNative\Gfxres.el-GR.resources
[2010/02/11 00:27:08 | 000,121,077 | —- | M] () – C:\windows\SysNative\Gfxres.de-DE.resources
[2010/02/11 00:27:08 | 000,112,605 | —- | M] () – C:\windows\SysNative\Gfxres.da-DK.resources
[2010/02/11 00:27:06 | 000,117,117 | —- | M] () – C:\windows\SysNative\Gfxres.cs-CZ.resources
[2010/02/11 00:27:04 | 000,138,293 | —- | M] () – C:\windows\SysNative\Gfxres.ar-SA.resources
[2010/02/11 00:26:48 | 000,108,574 | —- | M] () – C:\windows\SysNative\Gfxres.en-US.resources
[2010/02/11 00:21:48 | 000,004,096 | —- | M] ( ) – C:\windows\SysNative\IGFXDEVLib.dll
[2010/02/11 00:12:08 | 000,000,151 | —- | M] () – C:\windows\SysNative\GfxUI.exe.config
[2010/02/11 00:05:42 | 001,991,936 | —- | M] () – C:\windows\SysNative\iglhxa64.cpa
[2010/02/11 00:05:42 | 000,208,896 | —- | M] () – C:\windows\SysWow64\iglhsip32.dll
[2010/02/11 00:05:42 | 000,205,824 | —- | M] () – C:\windows\SysNative\iglhsip64.dll
[2010/02/11 00:05:42 | 000,187,392 | —- | M] () – C:\windows\SysNative\iglhcp64.dll
[2010/02/11 00:05:42 | 000,143,360 | —- | M] () – C:\windows\SysWow64\iglhcp32.dll
[2010/02/11 00:05:42 | 000,060,254 | —- | M] () – C:\windows\SysNative\iglhxg64.vp
[2010/02/11 00:05:42 | 000,060,226 | —- | M] () – C:\windows\SysNative\iglhxc64.vp
[2010/02/11 00:05:42 | 000,060,015 | —- | M] () – C:\windows\SysNative\iglhxo64.vp
[2010/02/11 00:05:42 | 000,001,090 | —- | M] () – C:\windows\SysNative\iglhxa64.vp
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/05/06 15:30:23 | 000,000,020 | —- | C] () – C:\Users\Khoa\defogger_reenable
[2010/05/02 22:32:27 | 000,017,264 | —- | C] () – C:\windows\SysNative\SsiEfr.exe
[2010/05/02 22:25:53 | 000,000,164 | —- | C] () – C:\windows\install.dat
[2010/04/01 23:58:49 | 000,000,000 | -H– | C] () – C:\windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2010/04/01 22:08:01 | 000,000,376 | —- | C] () – C:\windows\ODBC.INI
[2010/04/01 21:24:07 | 000,000,033 | —- | C] () – C:\ProgramData\{081230F8-EA50-42A9-983C-D22ABC2EED3B}.ini
[2010/04/01 21:12:28 | 000,000,073 | —- | C] () – C:\windows\cdplayer.ini
[2010/04/01 21:12:06 | 000,001,074 | —- | C] () – C:\ProgramData\ss.ini
[2010/04/01 18:22:12 | 000,000,987 | —- | C] () – C:\Users\Khoa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2010/04/01 10:03:44 | 000,000,904 | —- | C] () – C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-1808124184-2126047323-2208561221-1003UA.job
[2010/04/01 10:03:44 | 000,000,852 | —- | C] () – C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-1808124184-2126047323-2208561221-1003Core.job
[2010/04/01 07:58:28 | 000,524,288 | -HS- | C] () – C:\Users\Khoa\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
[2010/04/01 07:58:28 | 000,524,288 | -HS- | C] () – C:\Users\Khoa\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
[2010/04/01 07:58:28 | 000,262,144 | -HS- | C] () – C:\Users\Khoa\ntuser.dat.LOG1
[2010/04/01 07:58:28 | 000,065,536 | -HS- | C] () – C:\Users\Khoa\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
[2010/04/01 07:58:28 | 000,000,000 | -HS- | C] () – C:\Users\Khoa\ntuser.dat.LOG2
[2010/04/01 07:58:16 | 001,572,864 | -HS- | C] () – C:\Users\Khoa\NTUSER.DAT
[2010/04/01 07:58:16 | 000,000,020 | -HS- | C] () – C:\Users\Khoa\ntuser.ini
[2010/02/11 01:27:54 | 000,005,156 | —- | C] () – C:\windows\SysNative\iglhxs64.vp
[2010/02/11 01:08:16 | 000,152,600 | —- | C] () – C:\windows\SysNative\difx64.exe
[2010/02/11 00:54:24 | 000,982,224 | —- | C] () – C:\windows\SysWow64\igkrng500.bin
[2010/02/11 00:54:24 | 000,982,224 | —- | C] () – C:\windows\SysNative\igkrng500.bin
[2010/02/11 00:54:24 | 000,439,336 | —- | C] () – C:\windows\SysWow64\igcompkrng500.bin
[2010/02/11 00:54:24 | 000,439,336 | —- | C] () – C:\windows\SysNative\igcompkrng500.bin
[2010/02/11 00:54:24 | 000,092,292 | —- | C] () – C:\windows\SysWow64\igfcg500m.bin
[2010/02/11 00:54:24 | 000,092,292 | —- | C] () – C:\windows\SysNative\igfcg500m.bin
[2010/02/11 00:27:38 | 000,102,380 | —- | C] () – C:\windows\SysNative\Gfxres.zh-TW.resources
[2010/02/11 00:27:38 | 000,101,267 | —- | C] () – C:\windows\SysNative\Gfxres.zh-CN.resources
[2010/02/11 00:27:36 | 000,119,498 | —- | C] () – C:\windows\SysNative\Gfxres.tr-TR.resources
[2010/02/11 00:27:34 | 000,188,052 | —- | C] () – C:\windows\SysNative\Gfxres.th-TH.resources
[2010/02/11 00:27:34 | 000,117,708 | —- | C] () – C:\windows\SysNative\Gfxres.sv-SE.resources
[2010/02/11 00:27:32 | 000,112,701 | —- | C] () – C:\windows\SysNative\Gfxres.sl-SI.resources
[2010/02/11 00:27:30 | 000,163,802 | —- | C] () – C:\windows\SysNative\Gfxres.ru-RU.resources
[2010/02/11 00:27:30 | 000,116,410 | —- | C] () – C:\windows\SysNative\Gfxres.sk-SK.resources
[2010/02/11 00:27:28 | 000,117,404 | —- | C] () – C:\windows\SysNative\Gfxres.pt-PT.resources
[2010/02/11 00:27:26 | 000,118,737 | —- | C] () – C:\windows\SysNative\Gfxres.pt-BR.resources
[2010/02/11 00:27:26 | 000,116,799 | —- | C] () – C:\windows\SysNative\Gfxres.pl-PL.resources
[2010/02/11 00:27:24 | 000,117,941 | —- | C] () – C:\windows\SysNative\Gfxres.nl-NL.resources
[2010/02/11 00:27:22 | 000,121,633 | —- | C] () – C:\windows\SysNative\Gfxres.ko-KR.resources
[2010/02/11 00:27:22 | 000,113,210 | —- | C] () – C:\windows\SysNative\Gfxres.nb-NO.resources
[2010/02/11 00:27:20 | 000,134,790 | —- | C] () – C:\windows\SysNative\Gfxres.ja-JP.resources
[2010/02/11 00:27:18 | 000,123,921 | —- | C] () – C:\windows\SysNative\Gfxres.it-IT.resources
[2010/02/11 00:27:16 | 000,132,112 | —- | C] () – C:\windows\SysNative\Gfxres.he-IL.resources
[2010/02/11 00:27:16 | 000,117,919 | —- | C] () – C:\windows\SysNative\Gfxres.hu-HU.resources
[2010/02/11 00:27:14 | 000,119,142 | —- | C] () – C:\windows\SysNative\Gfxres.fr-FR.resources
[2010/02/11 00:27:12 | 000,121,312 | —- | C] () – C:\windows\SysNative\Gfxres.es-ES.resources
[2010/02/11 00:27:12 | 000,117,032 | —- | C] () – C:\windows\SysNative\Gfxres.fi-FI.resources
[2010/02/11 00:27:10 | 000,176,762 | —- | C] () – C:\windows\SysNative\Gfxres.el-GR.resources
[2010/02/11 00:27:08 | 000,121,077 | —- | C] () – C:\windows\SysNative\Gfxres.de-DE.resources
[2010/02/11 00:27:08 | 000,112,605 | —- | C] () – C:\windows\SysNative\Gfxres.da-DK.resources
[2010/02/11 00:27:06 | 000,117,117 | —- | C] () – C:\windows\SysNative\Gfxres.cs-CZ.resources
[2010/02/11 00:27:04 | 000,138,293 | —- | C] () – C:\windows\SysNative\Gfxres.ar-SA.resources
[2010/02/11 00:26:48 | 000,108,574 | —- | C] () – C:\windows\SysNative\Gfxres.en-US.resources
[2010/02/11 00:12:08 | 000,000,151 | —- | C] () – C:\windows\SysNative\GfxUI.exe.config
[2010/02/11 00:05:42 | 001,991,936 | —- | C] () – C:\windows\SysNative\iglhxa64.cpa
[2010/02/11 00:05:42 | 000,208,896 | —- | C] () – C:\windows\SysWow64\iglhsip32.dll
[2010/02/11 00:05:42 | 000,205,824 | —- | C] () – C:\windows\SysNative\iglhsip64.dll
[2010/02/11 00:05:42 | 000,187,392 | —- | C] () – C:\windows\SysNative\iglhcp64.dll
[2010/02/11 00:05:42 | 000,143,360 | —- | C] () – C:\windows\SysWow64\iglhcp32.dll
[2010/02/11 00:05:42 | 000,060,254 | —- | C] () – C:\windows\SysNative\iglhxg64.vp
[2010/02/11 00:05:42 | 000,060,226 | —- | C] () – C:\windows\SysNative\iglhxc64.vp
[2010/02/11 00:05:42 | 000,060,015 | —- | C] () – C:\windows\SysNative\iglhxo64.vp
[2010/02/11 00:05:42 | 000,001,090 | —- | C] () – C:\windows\SysNative\iglhxa64.vp
[2009/11/06 12:00:28 | 000,031,088 | —- | C] () – C:\windows\SysWow64\wrLZMA.dll
[2009/10/15 03:06:14 | 002,110,728 | —- | C] () – C:\windows\SysWow64\Apblend.dll
[2009/10/15 03:06:14 | 001,171,456 | —- | C] () – C:\windows\SysWow64\PicNotify.dll
[2009/10/15 03:05:59 | 001,044,480 | —- | C] () – C:\windows\SysWow64\3DImageRenderer.dll
[2009/10/15 03:04:57 | 000,057,344 | —- | C] () – C:\windows\AsfHelper.dll
[2009/10/15 03:04:31 | 000,015,190 | —- | C] () – C:\windows\M3000Twn.ini
[2009/10/15 03:04:04 | 000,016,648 | R— | C] () – C:\windows\SysWow64\LogAPI.dll
[2009/09/25 21:11:23 | 000,731,106 | —- | C] () – C:\windows\SysWow64\PerfStringBackup.INI
[2009/07/13 18:42:10 | 000,064,000 | —- | C] () – C:\windows\SysWow64\BWContextHandler.dll
[2009/07/13 16:03:59 | 000,364,544 | —- | C] () – C:\windows\SysWow64\msjetoledb40.dll

========== LOP Check ==========

[2010/04/26 23:55:41 | 000,000,000 | —D | M] – C:\Users\Khoa\AppData\Roaming\DAEMON Tools Lite
[2010/05/07 01:53:46 | 000,000,000 | —D | M] – C:\Users\Khoa\AppData\Roaming\Dropbox
[2009/10/28 05:38:31 | 000,000,000 | —D | M] – C:\Users\Khoa\AppData\Roaming\ID Vault
[2009/10/15 03:04:07 | 000,000,000 | —D | M] – C:\Users\Khoa\AppData\Roaming\Lenovo
[2010/04/01 21:23:33 | 000,000,000 | —D | M] – C:\Users\Khoa\AppData\Roaming\Mp3tag
[2010/04/27 00:12:44 | 000,000,000 | —D | M] – C:\Users\Khoa\AppData\Roaming\Sports Interactive
[2009/07/14 00:08:49 | 000,010,698 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2009/07/13 20:52:21 | 000,061,008 | —- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 – C:\windows\SysWow64\DriverStore\FileRepository\machine.inf_amd64_neutral_9e6bb86c3b39a3e9\AGP440.sys
[2009/07/13 20:52:21 | 000,061,008 | —- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 – C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys

< MD5 for: ATAPI.SYS >
[2009/07/13 20:52:21 | 000,024,128 | —- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C – C:\windows\SysWow64\DriverStore\FileRepository\mshdc.inf_amd64_neutral_a69a58a4286f0b22\atapi.sys
[2009/07/13 20:52:21 | 000,024,128 | —- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C – C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys

< MD5 for: CNGAUDIT.DLL >
[2009/07/13 20:15:06 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E – C:\Windows\SysWOW64\cngaudit.dll
[2009/07/13 20:15:06 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E – C:\Windows\SysWOW64\cngaudit.dll
[2009/07/13 20:15:06 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E – C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009/07/13 20:40:20 | 000,018,944 | —- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 – C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll

< MD5 for: IASTOR.SYS >
[2009/08/07 00:17:26 | 000,330,264 | —- | M] (Intel Corporation) MD5=01446278D4563B3013C92830AE6CBB26 – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\driver\IaStor.sys
[2009/08/07 00:24:14 | 000,408,600 | —- | M] (Intel Corporation) MD5=BBB3B6DF1ABB0FE35802EDE85CC1C011 – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\driver64\IaStor.sys
[2009/08/07 00:24:14 | 000,408,600 | —- | M] (Intel Corporation) MD5=BBB3B6DF1ABB0FE35802EDE85CC1C011 – C:\windows\SysWow64\DriverStore\FileRepository\iaahci.inf_amd64_neutral_4fa22a1c88c09097\iaStor.sys

< MD5 for: IASTORV.SYS >
[2009/07/13 20:48:04 | 000,410,688 | —- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 – C:\windows\SysWow64\DriverStore\FileRepository\iastorv.inf_amd64_neutral_18cccb83b34e1453\iaStorV.sys
[2009/07/13 20:48:04 | 000,410,688 | —- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 – C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_0b06441fa1790136\iaStorV.sys

< MD5 for: NETLOGON.DLL >
[2009/07/13 20:41:52 | 000,692,736 | —- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 – C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll
[2009/07/13 20:16:02 | 000,563,712 | —- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 – C:\Windows\SysWOW64\netlogon.dll
[2009/07/13 20:16:02 | 000,563,712 | —- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 – C:\Windows\SysWOW64\netlogon.dll
[2009/07/13 20:16:02 | 000,563,712 | —- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 – C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll

< MD5 for: NVSTOR.SYS >
[2009/07/13 20:45:45 | 000,167,488 | —- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 – C:\windows\SysWow64\DriverStore\FileRepository\nvraid.inf_amd64_neutral_5bde3fe2945bce9e\nvstor.sys
[2009/07/13 20:45:45 | 000,167,488 | —- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys

< MD5 for: SCECLI.DLL >
[2009/07/13 20:16:13 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 – C:\Windows\SysWOW64\scecli.dll
[2009/07/13 20:16:13 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 – C:\Windows\SysWOW64\scecli.dll
[2009/07/13 20:16:13 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 – C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll
[2009/07/13 20:41:53 | 000,232,448 | —- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 – C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2009/07/13 20:15:21 | 000,462,848 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\SysWOW64\FirewallAPI.dll
[2009/11/06 12:00:28 | 000,031,088 | —- | M] () Unable to obtain MD5 – C:\Windows\SysWOW64\wrLZMA.dll

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >

< %systemroot%\system32\drivers\*.sys /90 >
< End of report >

extra.txt

OTL Extras logfile created on: 5/7/2010 11:11:34 PM - Run 1
OTL by OldTimer - Version 3.2.4.1 Folder = C:\Users\Khoa\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 70.00% Memory free
8.00 Gb Paging File | 7.00 Gb Available in Paging File | 83.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 252.89 Gb Total Space | 203.93 Gb Free Space | 80.64% Space Free | Partition Type: NTFS
Drive D: | 30.25 Gb Total Space | 29.39 Gb Free Space | 97.16% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: KLAM
Current User Name: Khoa
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Minimal
Quick Scan

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html[@ = htmlfile] – Reg Error: Key error. File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] – Reg Error: Key error. File not found

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – C:\Users\Khoa\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
htmlfile – "C:\Program Files (x86)\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] – Reg Error: Key error.
htmlfile [opennew] – Reg Error: Key error.
htmlfile [print] – "C:\Program Files (x86)\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] – "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome File not found
https [open] – "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome File not found
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – Reg Error: Key error.
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – Reg Error: Key error.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – "C:\Program Files (x86)\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] – Reg Error: Key error.
htmlfile [opennew] – Reg Error: Key error.
htmlfile [print] – "C:\Program Files (x86)\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] – "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome File not found
https [open] – "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome File not found
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – Reg Error: Key error.
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – Reg Error: Key error.

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{20387B45-18A4-4D48-ABD9-A23D2CBE42B3}" = Dolby Control Center
"{46F4D124-20E5-4D12-BE52-EC177A7A4B42}" = Lenovo OneKey Recovery
"{4CE36E6A-300B-427C-BEC7-B261CC13814E}" = iTunes
"{6ACE7F46-FACE-4125-AE86-672F4F2A6A28}" = Bing Maps 3D
"{79BF7CB8-1E09-489F-9547-DB3EE8EA3F16}" = Microsoft SQL Server Native Client
"{86177DAE-38B1-49DD-912E-35CB703AB779}" = Microsoft SQL Server VSS Writer
"{877924AA-E044-4266-B37D-E974CD799934}" = Bonjour
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9B48B0AC-C813-4174-9042-476A887592C7}" = Windows Live ID Sign-in Assistant
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}" = PlayReady PC Runtime amd64
"{CA4AF936-3312-4AF4-A191-527531490DCD}" = Apple Mobile Device Support
"{F7513E19-6224-485E-988D-9BF45BE64B53}" = Windows Live Family Safety
"92F4CDC794E6E4E29DC063D292D1C94F6FA1EA1E" = Windows Driver Package - Lenovo (ACPIVPC) System (05/19/2009 4.4.0.1)
"HDMI" = Intel® Graphics Media Accelerator Driver
"SynTPDeinstKey" = Synaptics Pointing Device Driver

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{17542DBF-E17C-4562-BC4D-FA3EF3076C45}" = Lenovo ReadyComm 5
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{1C08A24C-B168-407E-A826-68FAF5F20710}" = Age of Empires III - The WarChiefs
"{1FCC574F-AFA2-4432-9EF1-79CA7BA73431}_is1" = Webroot AntiVirus with Spy Sweeper
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{32343DB6-9A52-40C9-87E4-5E7C79791C87}" = MSXML 4.0 SP2 and SOAP Toolkit 3.0
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3D5044A5-97B8-45C0-B956-BB2376569188}" = Windows Live Movie Maker
"{3F5B6210-0903-4DC6-8034-8F488AA3A782}" = Spy Sweeper Core
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{4BB1DCED-84D3-47F9-B718-5947E904593E}" = Lenovo EasyCamera
"{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}" = Microsoft Search Enhancement Pack
"{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)
"{553255F3-78FD-40F1-A6F8-6882140265FE}" = Apple Application Support
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{76C66170-C538-4E77-B54D-48E136B5B533}" = Lenovo ReadyComm 5.0 Service
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7B9CC60A-9B81-46A3-A953-76B6BF9EEC97}" = Age of Empires III
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8136 8168 8169 Ethernet Driver
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader
"{97C82B44-D408-4F14-9252-47FC1636D23E}_is1" = IZArc 4.1
"{995F1E2E-F542-4310-8E1D-9926F5A279B3}" = Windows Live Toolbar
"{A06E1854-1580-4157-AD70-72734D324DEA}" = Lenovo Idea Notes
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3
"{AE1E24C2-E720-42D5-B8E1-48F71A97B4DB}" = Energy Management
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C43C1415-3DFC-4089-9A32-0BECF28A6046}" = Age of Empires III - The Asian Dynasties
"{CE4CAD46-3F3F-4248-B0F2-6B0FAFBE40B1}_is1" = WMPCDText 1.2
"{D6C75F0B-3BC1-4FC9-B8C5-3F7E8ED059CA}" = Windows Live Photo Gallery
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F2602F16-02D1-4F1C-99A5-E246C522A59D}" = Lenovo First Boot
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"CCleaner" = CCleaner
"EasyCapture4.0" = EasyCapture
"ExpressRip" = Express Rip
"HijackThis" = HijackThis 2.0.2
"InstallShield_{1C08A24C-B168-407E-A826-68FAF5F20710}" = Age of Empires III - The WarChiefs
"InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}" = Lenovo OneKey Recovery
"InstallShield_{7B9CC60A-9B81-46A3-A953-76B6BF9EEC97}" = Age of Empires III
"InstallShield_{C43C1415-3DFC-4089-9A32-0BECF28A6046}" = Age of Empires III - The Asian Dynasties
"Mp3tag" = Mp3tag v2.46a
"Steam App 240" = Counter-Strike: Source
"WinLiveSuite_Wave3" = Windows Live Essentials
"Yahoo! Messenger" = Yahoo! Messenger
"Zen V Series Media Explorer" = ZEN V Series Media Explorer

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dropbox" = Dropbox
"Google Chrome" = Google Chrome

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 4/1/2010 11:43:19 PM | Computer Name = KLam | Source = SideBySide | ID = 16842787
Description = Activation context generation failed for "C:\Program Files (x86)\Windows
Live\Photo Gallery\MovieMaker.Exe".Error in manifest or policy file "C:\Program
Files (x86)\Windows Live\Photo Gallery\WLMFDS.DLL" on line 8. Component identity
found in manifest does not match the identity of the component requested. Reference
is WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition
is WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Please use
sxstrace.exe for detailed diagnosis.

Error - 4/1/2010 11:43:19 PM | Computer Name = KLam | Source = SideBySide | ID = 16842787
Description = Activation context generation failed for "C:\Program Files (x86)\Windows
Live\Photo Gallery\MovieMaker.Exe".Error in manifest or policy file "C:\Program
Files (x86)\Windows Live\Photo Gallery\WLMFDS.DLL" on line 8. Component identity
found in manifest does not match the identity of the component requested. Reference
is WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition
is WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Please use
sxstrace.exe for detailed diagnosis.

Error - 4/1/2010 11:43:19 PM | Computer Name = KLam | Source = SideBySide | ID = 16842787
Description = Activation context generation failed for "C:\Program Files (x86)\Windows
Live\Photo Gallery\MovieMaker.Exe".Error in manifest or policy file "C:\Program
Files (x86)\Windows Live\Photo Gallery\WLMFDS.DLL" on line 8. Component identity
found in manifest does not match the identity of the component requested. Reference
is WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition
is WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Please use
sxstrace.exe for detailed diagnosis.

Error - 4/1/2010 11:43:19 PM | Computer Name = KLam | Source = SideBySide | ID = 16842787
Description = Activation context generation failed for "C:\Program Files (x86)\Windows
Live\Photo Gallery\MovieMaker.Exe".Error in manifest or policy file "C:\Program
Files (x86)\Windows Live\Photo Gallery\WLMFDS.DLL" on line 8. Component identity
found in manifest does not match the identity of the component requested. Reference
is WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition
is WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Please use
sxstrace.exe for detailed diagnosis.

Error - 4/1/2010 11:43:19 PM | Computer Name = KLam | Source = SideBySide | ID = 16842787
Description = Activation context generation failed for "C:\Program Files (x86)\Windows
Live\Photo Gallery\MovieMaker.Exe".Error in manifest or policy file "C:\Program
Files (x86)\Windows Live\Photo Gallery\WLMFDS.DLL" on line 8. Component identity
found in manifest does not match the identity of the component requested. Reference
is WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition
is WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Please use
sxstrace.exe for detailed diagnosis.

Error - 4/1/2010 11:43:19 PM | Computer Name = KLam | Source = SideBySide | ID = 16842787
Description = Activation context generation failed for "C:\Program Files (x86)\Windows
Live\Photo Gallery\MovieMaker.Exe".Error in manifest or policy file "C:\Program
Files (x86)\Windows Live\Photo Gallery\WLMFDS.DLL" on line 8. Component identity
found in manifest does not match the identity of the component requested. Reference
is WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition
is WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Please use
sxstrace.exe for detailed diagnosis.

Error - 4/1/2010 11:43:19 PM | Computer Name = KLam | Source = SideBySide | ID = 16842787
Description = Activation context generation failed for "C:\Program Files (x86)\Windows
Live\Photo Gallery\MovieMaker.Exe".Error in manifest or policy file "C:\Program
Files (x86)\Windows Live\Photo Gallery\WLMFDS.DLL" on line 8. Component identity
found in manifest does not match the identity of the component requested. Reference
is WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition
is WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Please use
sxstrace.exe for detailed diagnosis.

Error - 4/1/2010 11:43:20 PM | Computer Name = KLam | Source = SideBySide | ID = 16842787
Description = Activation context generation failed for "C:\Program Files (x86)\Windows
Live\Photo Gallery\MovieMaker.Exe".Error in manifest or policy file "C:\Program
Files (x86)\Windows Live\Photo Gallery\WLMFDS.DLL" on line 8. Component identity
found in manifest does not match the identity of the component requested. Reference
is WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition
is WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Please use
sxstrace.exe for detailed diagnosis.

Error - 4/1/2010 11:43:20 PM | Computer Name = KLam | Source = SideBySide | ID = 16842787
Description = Activation context generation failed for "C:\Program Files (x86)\Windows
Live\Photo Gallery\MovieMaker.Exe".Error in manifest or policy file "C:\Program
Files (x86)\Windows Live\Photo Gallery\WLMFDS.DLL" on line 8. Component identity
found in manifest does not match the identity of the component requested. Reference
is WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition
is WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Please use
sxstrace.exe for detailed diagnosis.

Error - 4/1/2010 11:43:20 PM | Computer Name = KLam | Source = SideBySide | ID = 16842787
Description = Activation context generation failed for "C:\Program Files (x86)\Windows
Live\Photo Gallery\MovieMaker.Exe".Error in manifest or policy file "C:\Program
Files (x86)\Windows Live\Photo Gallery\WLMFDS.DLL" on line 8. Component identity
found in manifest does not match the identity of the component requested. Reference
is WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition
is WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Please use
sxstrace.exe for detailed diagnosis.

[ System Events ]
Error - 4/1/2010 10:48:23 PM | Computer Name = KLam | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk1\DR2.

Error - 4/1/2010 10:48:52 PM | Computer Name = KLam | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk1\DR2.

Error - 4/1/2010 11:45:54 PM | Computer Name = KLam | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk1\DR2.

Error - 4/1/2010 11:50:56 PM | Computer Name = KLam | Source = Service Control Manager | ID = 7000
Description = The ReadyComm.DirectRouter service failed to start due to the following
error: %%2

Error - 4/2/2010 3:59:53 AM | Computer Name = KLam | Source = Service Control Manager | ID = 7000
Description = The ReadyComm.DirectRouter service failed to start due to the following
error: %%2

Error - 4/2/2010 1:32:51 PM | Computer Name = KLam | Source = Service Control Manager | ID = 7011
Description = A timeout (30000 milliseconds) was reached while waiting for a transaction
response from the Wlansvc service.

Error - 4/2/2010 2:20:39 PM | Computer Name = KLam | Source = Service Control Manager | ID = 7000
Description = The ReadyComm.DirectRouter service failed to start due to the following
error: %%2

Error - 4/5/2010 11:46:14 PM | Computer Name = KLam | Source = DCOM | ID = 10010
Description =

Error - 4/7/2010 6:17:17 PM | Computer Name = KLam | Source = Tcpip | ID = 4199
Description = The system detected an address conflict for IP address 192.168.2.3
with the system having network hardware address 00-14-A5-42-48-5A. Network operations
on this system may be disrupted as a result.

Error - 4/14/2010 7:45:30 PM | Computer Name = KLam | Source = Tcpip | ID = 4199
Description = The system detected an address conflict for IP address 192.168.2.2
with the system having network hardware address 00-26-5E-18-6F-9B. Network operations
on this system may be disrupted as a result.


< End of report >


Thanks
Hi.

Please do the following:


Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
    O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O4 - HKCU..\Run: [FactoryTest] C:\Windows\Test.bat File not found
    
    :Commands
    [resethosts]
    [emptyflash]
    [purity]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post the OTL log


NEXT




Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT

**Vista users - right click on the IE icon and run as administrator

Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
All processes killed ========== OTL ========== Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\FactoryTest not found. ========== COMMANDS ========== C:\windows\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully [EMPTYFLASH] User: Administrator ->Flash cache emptied: 0 bytes User: All Users User: Default ->Flash cache emptied: 0 bytes User: Default User ->Flash cache emptied: 0 bytes User: Khoa ->Flash cache emptied: 716 bytes User: Public Total Flash Files Cleaned = 0.00 mb [EMPTYTEMP] User: Administrator ->Flash cache emptied: 0 bytes User: All Users User: Default ->Temp folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Khoa ->Temp folder emptied: 107127136 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Java cache emptied: 128094 bytes ->FireFox cache emptied: 30882752 bytes ->Google Chrome cache emptied: 29328411 bytes ->Flash cache emptied: 0 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 844 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 160.00 mb OTL by OldTimer - Version 3.2.4.1 log created on 05082010_154714 Files\Folders moved on Reboot… C:\Users\Khoa\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. Registry entries deleted on Reboot… Kaspersky scan ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Saturday, May 8, 2010 Operating system: Microsoft (build 7600) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Saturday, May 08, 2010 16:01:22 Records in database: 4086397 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: C:\ D:\ E:\ Scan statistics: Objects scanned: 105324 Threats found: 1 Infected objects found: 0 Suspicious objects found: 2 Scan duration: 02:17:54 File name / Threat / Threats count C:\Program Files (x86)\DDNI\Lenovo First Boot\DDNIOOBE.VBS Suspicious: Type_Script 1 C:\Windows\Installer\14aa7.msi Suspicious: Type_Script 1 Selected area has been scanned.
Please post a fresh DDS Log and Attach.txt and advise how your computer is running now and if there are any outstanding issues.
Nothing change, light stills constantly blinking every 2 seconds and hard drive also spin the same way DDS (Ver_10-03-17.01) - NTFSX64 Run by [removed] at 23:00:05.94 on Sun 05/09/2010 Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_20 Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.4029.2579 [GMT -5:00] ============== Running Processes =============== C:\windows\system32\wininit.exe C:\windows\system32\lsm.exe C:\windows\system32\svchost.exe -k DcomLaunch C:\Program Files (x86)\Webroot\WebrootSecurity\WRConsumerService.exe C:\windows\system32\svchost.exe -k RPCSS C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\windows\system32\svchost.exe -k netsvcs C:\windows\system32\svchost.exe -k LocalService C:\windows\system32\svchost.exe -k NetworkService C:\windows\System32\spoolsv.exe C:\windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files (x86)\Bonjour\mDNSResponder.exe C:\windows\SysWOW64\CTsvcCDA.exe C:\Program Files (x86)\Lenovo\ReadyComm\common\IGRS.exe C:\windows\system32\taskhost.exe C:\windows\system32\Dwm.exe C:\windows\Explorer.EXE C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe C:\windows\system32\svchost.exe -k imgsvc C:\Program Files (x86)\Webroot\WebrootSecurity\SpySweeper.exe C:\windows\System32\svchost.exe -k secsvcs C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe C:\windows\system32\SearchIndexer.exe C:\windows\system32\wbem\wmiprvse.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe C:\Program Files (x86)\Lenovo\Energy Management\utility.exe C:\Program Files\Synaptics\SynTP\SynTPHelper.exe C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe C:\Windows\System32\igfxtray.exe C:\Program Files (x86)\Creative\Sync Manager Unicode\CTSyncU.exe C:\Users\Khoa\AppData\Local\Google\Update\1.2.183.23\GoogleCrashHandler.exe C:\Users\Khoa\AppData\Roaming\Dropbox\bin\Dropbox.exe C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Program Files (x86)\Webroot\WebrootSecurity\SpySweeperUI.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files (x86)\DDNI\Lenovo Idea Notes\DDNIMSGService.exe C:\Program Files (x86)\Webroot\WebrootSecurity\SSU.EXE C:\windows\system32\taskhost.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe C:\windows\system32\igfxsrvc.exe C:\windows\system32\taskeng.exe C:\Users\Khoa\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Khoa\AppData\Local\Google\Chrome\Application\chrome.exe C:\windows\system32\taskhost.exe C:\windows\system32\SearchProtocolHost.exe C:\windows\system32\SearchFilterHost.exe C:\Users\Khoa\Desktop\dds.scr C:\windows\system32\conhost.exe C:\windows\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com/ uDefault_Page_URL = hxxp://www.bing.com mStart Page = hxxp://lenovo.live.com/ uInternet Settings,ProxyOverride = ;*.local mWinlogon: Userinit=userinit.exe BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files (x86)\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files (x86)\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files (x86)\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files (x86)\java\jre6\bin\jp2ssv.dll BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files (x86)\windows live\toolbar\wltcore.dll TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files (x86)\windows live\toolbar\wltcore.dll uRun: [Google Update] "c:\users\khoa\appdata\local\google\update\GoogleUpdate.exe" /c uRun: [CTSyncU.exe] "c:\program files (x86)\creative\sync manager unicode\CTSyncU.exe" mRun: [UpdateP2GShortCut] "c:\program files (x86)\lenovo\power2go\muitransfer\muistartmenu.exe" "c:\program files (x86)\lenovo\power2go" updatewithcreateonce "software\cyberlink\power2go\5.0" mRun: [SunJavaUpdateSched] "c:\program files (x86)\common files\java\java update\jusched.exe" mRun: [SpySweeper] "c:\program files (x86)\webroot\webrootsecurity\SpySweeperUI.exe" /startintray mRun: [LogMeIn Hamachi Ui] "c:\program files (x86)\logmein hamachi\hamachi-2-ui.exe" –auto-start StartupFolder: c:\users\khoa\appdata\roaming\micros~1\windows\startm~1\programs\startup\dropbox.lnk - c:\users\khoa\appdata\roaming\dropbox\bin\Dropbox.exe mPolicies-explorer: NoActiveDesktop = 1 (0x1) mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1) mPolicies-explorer: ForceActiveDesktopOn = 0 (0x0) mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableLUA = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) mPolicies-system: PromptOnSecureDesktop = 0 (0x0) IE: E&xport to Microsoft Excel - c:\progra~2\mif5ba~1\office11\EXCEL.EXE/3000 IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files (x86)\windows live\writer\WriterBrowserExtension.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~2\mif5ba~1\office11\REFIEBAR.DLL DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab BHO-X64: Windows Live Family Safety Browser Helper Class: {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - c:\program files\windows live\family safety\fssbho.dll BHO-X64: Windows Live Family Safety Browser Helper - No File BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll TB-X64: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File mRun-x64: [IAAnotif] "c:\program files (x86)\intel\intel matrix storage manager\iaanotif.exe" mRun-x64: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe mRun-x64: [RtHDVCpl] "c:\program files\realtek\audio\hda\RAVCpl64.exe" -s mRun-x64: [EnergyUtility] "c:\program files (x86)\lenovo\energy management\utility.exe" mRun-x64: [Energy Management] c:\program files (x86)\lenovo\energy management\Energy Management.exe mRun-x64: [IgfxTray] "c:\windows\system32\igfxtray.exe" mRun-x64: [HotKeysCmds] "c:\windows\system32\hkcmd.exe" ================= FIREFOX =================== FF - ProfilePath - c:\users\khoa\appdata\roaming\mozilla\firefox\profiles\578iss5j.default\ FF - plugin: c:\program files (x86)\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files (x86)\virtual earth 3d\npVE3D.dll FF - plugin: c:\program files (x86)\windows live\photo gallery\NPWLPG.dll FF - plugin: c:\users\khoa\appdata\local\google\update\1.2.183.23\npGoogleOneClick8.dll FF - HiddenExtension: Java Console: No Registry Reference - c:\program files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} —- FIREFOX POLICIES —- c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true); c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false); c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true); c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true); c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32); c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600); c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false); c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false); c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1); c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false); c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2); c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1); c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25); c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800); c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25); c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5); c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("html5.enable", false); c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr ef", true); c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", ""); c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false); c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false); c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); c:\program files (x86)\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600); c:\program files (x86)\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com"); c:\program files (x86)\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff"); c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties"); c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties"); c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org"); c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com"); c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true); c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false); c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false); c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false); c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false); c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false); c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20); c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20); ============= SERVICES / DRIVERS =============== R0 ssfs0bbc;ssfs0bbc;c:\windows\system32\drivers\ssfs0bbc.sys [2009-11-6 37488] R1 funfrm;funfrm;c:\windows\system32\drivers\funfrm.sys [2009-10-15 73744] R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-13 59904] R2 DDNIMSGService;DDNIMSGService;c:\program files (x86)\ddni\lenovo idea notes\DDNIMSGService.exe [2009-6-23 172720] R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files (x86)\logmein hamachi\hamachi-2.exe [2010-3-30 1823112] R2 IGRS;IGRS;c:\program files (x86)\lenovo\readycomm\common\IGRS.exe [2009-7-14 38152] R2 WebrootSpySweeperService;Webroot Spy Sweeper Engine;c:\program files (x86)\webroot\webrootsecurity\SpySweeper.exe [2009-11-6 4048240] R2 WRConsumerService;Webroot Client Service;c:\program files (x86)\webroot\webrootsecurity\WRConsumerService.exe [2010-5-2 1201640] R3 ACPIVPC;Lenovo Virtual Power Controller Driver;c:\windows\system32\drivers\AcpiVpc.sys [2009-10-15 26128] R3 IntcHdmiAddService;Intel® High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [2009-10-15 138752] R3 NETw5s64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;c:\windows\system32\drivers\NETw5s64.sys [2009-9-15 6952960] R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt64win7.sys [2010-3-4 346144] R3 wdmirror;wdmirror;c:\windows\system32\drivers\WDMirror.sys [2009-10-15 11280] S2 ReadyComm.DirectRouter;ReadyComm.DirectRouter;c:\windows\system32\igrssvcs.exe -k igrssvcs –> c:\windows\system32\IgrsSvcs.exe -k IgrsSvcs [?] S3 Bridge0;Bridge0;c:\windows\system32\drivers\WDBridge.sys [2009-10-15 79376] S3 fssfltr;fssfltr;c:\windows\system32\drivers\fssfltr.sys [2009-10-28 61280] S3 fsssvc;Windows Live Family Safety Service;c:\program files (x86)\windows live\family safety\fsssvc.exe [2009-8-5 704864] S3 k57nd60a;Broadcom NetLink ™ Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\k57nd60a.sys [2009-6-10 270848] S3 Lenovo ReadyComm AppSvc;Lenovo ReadyComm AppSvc;c:\program files\lenovo\readycomm\AppSvc.exe [2009-10-15 414984] S3 Lenovo ReadyComm ConnSvc;Lenovo ReadyComm ConnSvc;c:\program files\lenovo\readycomm\ConnSvc.exe [2009-10-15 472328] S3 netw5v64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\drivers\NETw5v64.sys [2009-10-15 5435904] S3 PS_MDP;ReadyComm Presentation Space Helper Service;c:\windows\system32\igrssvcs.exe -k igrssvcs –> c:\windows\system32\IgrsSvcs.exe -k IgrsSvcs [?] S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RtsUStor.sys [2009-9-25 219136] S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2010-4-1 1255736] S3 wsvd;wsvd;c:\windows\system32\drivers\wsvd.sys [2009-7-21 121840] =============== Created Last 30 ================ 2010-05-09 22:17:16 0 d—–w- c:\program files (x86)\LogMeIn Hamachi 2010-05-08 16:34:31 0 d—–w- c:\programdata\Sun 2010-05-08 16:34:18 411368 —-a-w- c:\windows\syswow64\deployJava1.dll 2010-05-08 16:34:18 153376 —-a-w- c:\windows\syswow64\javaws.exe 2010-05-08 16:34:18 145184 —-a-w- c:\windows\syswow64\javaw.exe 2010-05-08 16:34:18 145184 —-a-w- c:\windows\syswow64\java.exe 2010-05-08 16:20:08 0 d—–w- c:\users\khoa\appdata\roaming\Malwarebytes 2010-05-08 16:19:58 24664 —-a-w- c:\windows\system32\drivers\mbam.sys 2010-05-08 16:19:58 0 d—–w- c:\programdata\Malwarebytes 2010-05-08 16:19:57 0 d—–w- c:\program files (x86)\Malwarebytes' Anti-Malware 2010-05-08 15:47:40 0 d—–w- C:\_OTL 2010-05-06 20:30:23 20 —-a-w- c:\users\khoa\defogger_reenable 2010-05-05 17:07:49 0 d—–w- c:\program files (x86)\Trend Micro 2010-05-04 02:29:18 0 d—–w- c:\programdata\NCH Swift Sound 2010-05-04 02:28:46 0 d—–w- c:\program files (x86)\NCH Software 2010-05-04 02:28:42 0 d—–w- c:\program files (x86)\NCH Swift Sound 2010-05-03 03:32:53 511328 —-a-w- c:\windows\syswow64\capicom.dll 2010-05-03 03:32:34 0 d—–w- c:\program files (x86)\MSSOAP 2010-05-03 03:32:34 0 d—–w- c:\program files (x86)\common files\MSSoap 2010-05-03 03:32:24 1563008 —-a-w- c:\windows\WRSetup.dll 2010-05-03 03:32:24 0 d—–w- c:\users\khoa\appdata\roaming\Webroot 2010-05-03 03:32:24 0 d—–w- c:\programdata\Webroot 2010-05-03 03:32:24 0 d—–w- c:\program files (x86)\Webroot 2010-05-03 03:25:53 164 —-a-w- c:\windows\install.dat 2010-04-27 19:15:51 223448 —-a-w- c:\windows\system32\drivers\fvevol.sys 2010-04-27 19:15:48 12867072 —-a-w- c:\windows\syswow64\shell32.dll 2010-04-27 19:15:47 96768 —-a-w- c:\windows\syswow64\sspicli.dll 2010-04-27 19:15:47 22016 —-a-w- c:\windows\syswow64\secur32.dll 2010-04-27 19:15:47 153160 —-a-w- c:\windows\system32\drivers\ksecpkg.sys 2010-04-27 19:15:47 1446912 —-a-w- c:\windows\system32\lsasrv.dll 2010-04-27 05:13:36 0 d—–w- c:\programdata\Sports Interactive 2010-04-27 05:04:57 4496232 —-a-w- c:\windows\system32\d3dx9_34.dll 2010-04-27 04:58:56 0 d–h–w- c:\program files (x86)\Zero G Registry 2010-04-27 04:57:23 0 d—–w- c:\users\khoa\appdata\roaming\Sports Interactive 2010-04-27 04:49:14 834544 —-a-w- c:\windows\system32\drivers\sptd.sys 2010-04-27 04:48:45 0 d—–w- c:\program files (x86)\DAEMON Tools Lite 2010-04-27 04:47:55 0 d—–w- c:\users\khoa\appdata\roaming\DAEMON Tools Lite 2010-04-27 04:47:51 0 d—–w- c:\programdata\DAEMON Tools Lite 2010-04-14 13:40:02 612352 —-a-w- c:\windows\system32\vbscript.dll 2010-04-14 13:40:02 427520 —-a-w- c:\windows\syswow64\vbscript.dll 2010-04-14 13:40:02 286720 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys 2010-04-14 13:40:02 157696 —-a-w- c:\windows\system32\drivers\mrxsmb.sys 2010-04-14 13:40:02 125952 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys 2010-04-14 13:40:01 5509008 —-a-w- c:\windows\system32\ntoskrnl.exe 2010-04-14 13:40:01 3899280 —-a-w- c:\windows\syswow64\ntoskrnl.exe 2010-04-14 13:40:00 3954568 —-a-w- c:\windows\syswow64\ntkrnlpa.exe 2010-04-14 13:38:04 220672 —-a-w- c:\windows\system32\wintrust.dll 2010-04-14 13:38:03 172032 —-a-w- c:\windows\syswow64\wintrust.dll 2010-04-14 13:37:49 139264 —-a-w- c:\windows\system32\cabview.dll 2010-04-14 13:37:49 132608 —-a-w- c:\windows\syswow64\cabview.dll ==================== Find3M ==================== 2010-04-02 04:58:49 0 —ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf 2010-02-24 15:16:06 212864 ——w- c:\windows\system32\MpSigStub.exe 2010-02-23 08:22:50 1192960 —-a-w- c:\windows\system32\wininet.dll 2010-02-23 07:56:00 977920 —-a-w- c:\windows\syswow64\wininet.dll 2010-02-23 07:55:56 1225216 —-a-w- c:\windows\syswow64\urlmon.dll 2010-02-23 07:55:45 606208 —-a-w- c:\windows\syswow64\mstime.dll 2010-02-23 07:55:43 64512 —-a-w- c:\windows\syswow64\msfeedsbs.dll 2010-02-23 07:55:43 5964800 —-a-w- c:\windows\syswow64\mshtml.dll 2010-02-23 07:55:24 10978816 —-a-w- c:\windows\syswow64\ieframe.dll 2010-02-23 07:55:20 381440 —-a-w- c:\windows\syswow64\iedkcs32.dll 2010-02-12 17:01:24 95520 —-a-w- c:\windows\system32\dnssd.dll 2010-02-12 17:01:24 119584 —-a-w- c:\windows\system32\dns-sd.exe 2010-02-12 16:46:14 91424 —-a-w- c:\windows\syswow64\dnssd.dll 2010-02-12 16:46:14 107808 —-a-w- c:\windows\syswow64\dns-sd.exe 2010-02-11 06:08:26 948760 —-a-w- c:\windows\syswow64\igxpun.exe 2010-02-11 06:08:24 509976 —-a-w- c:\windows\system32\igfxsrvc.exe 2010-02-11 06:08:24 166424 —-a-w- c:\windows\system32\igfxtray.exe 2010-02-11 06:08:22 410648 —-a-w- c:\windows\system32\igfxpers.exe 2010-02-11 06:08:20 222744 —-a-w- c:\windows\system32\igfxext.exe 2010-02-11 06:08:18 391192 —-a-w- c:\windows\system32\hkcmd.exe 2010-02-11 06:08:16 3126808 —-a-w- c:\windows\system32\GfxUI.exe 2010-02-11 06:08:16 152600 —-a-w- c:\windows\system32\difx64.exe 2010-02-11 06:00:46 90112 —-a-w- c:\windows\system32\igfxCoIn_v2082.dll 2010-02-11 05:56:24 5972480 —-a-w- c:\windows\system32\igdumd64.dll 2010-02-11 05:54:24 982224 —-a-w- c:\windows\syswow64\igkrng500.bin 2010-02-11 05:54:24 982224 —-a-w- c:\windows\system32\igkrng500.bin 2010-02-11 05:54:24 92292 —-a-w- c:\windows\syswow64\igfcg500m.bin 2010-02-11 05:54:24 92292 —-a-w- c:\windows\system32\igfcg500m.bin 2010-02-11 05:54:24 439336 —-a-w- c:\windows\syswow64\igcompkrng500.bin 2010-02-11 05:54:24 439336 —-a-w- c:\windows\system32\igcompkrng500.bin 2010-02-11 05:50:18 4502016 —-a-w- c:\windows\syswow64\igdumd32.dll 2010-02-11 05:45:32 550912 —-a-w- c:\windows\syswow64\igdumdx32.dll 2010-02-11 05:44:48 4088320 —-a-w- c:\windows\system32\igd10umd64.dll 2010-02-11 05:41:56 3890688 —-a-w- c:\windows\syswow64\igd10umd32.dll 2010-02-11 05:38:36 5519872 —-a-w- c:\windows\system32\ig4dev64.dll 2010-02-11 05:38:22 8132608 —-a-w- c:\windows\system32\ig4icd64.dll 2010-02-11 05:33:08 4079616 —-a-w- c:\windows\syswow64\ig4dev32.dll 2010-02-11 05:32:52 6061568 —-a-w- c:\windows\syswow64\ig4icd32.dll 2010-02-11 05:23:14 377856 —-a-w- c:\windows\system32\igfxTMM.dll 2010-02-11 05:23:14 248320 —-a-w- c:\windows\system32\igfxpph.dll 2010-02-11 05:23:06 27648 —-a-w- c:\windows\system32\igfxexps.dll 2010-02-11 05:22:42 61440 —-a-w- c:\windows\system32\igfxsrvc.dll 2010-02-11 05:22:00 108544 —-a-w- c:\windows\system32\hccutils.dll 2010-02-11 05:21:48 4096 —-a-w- c:\windows\system32\IGFXDEVLib.dll 2010-02-11 05:21:48 268800 —-a-w- c:\windows\system32\igfxdev.dll 2010-02-11 05:21:48 119296 —-a-w- c:\windows\system32\gfxSrvc.dll 2010-02-11 05:21:12 9014784 —-a-w- c:\windows\system32\igfxress.dll 2010-02-11 05:21:12 142336 —-a-w- c:\windows\system32\igfxdo.dll 2010-02-11 05:16:20 59392 —-a-w- c:\windows\syswow64\oemdspif.dll 2010-02-11 05:14:52 225792 —-a-w- c:\windows\syswow64\igfxdv32.dll 2010-02-11 05:05:42 208896 —-a-w- c:\windows\syswow64\iglhsip32.dll 2010-02-11 05:05:42 205824 —-a-w- c:\windows\system32\iglhsip64.dll 2010-02-11 05:05:42 187392 —-a-w- c:\windows\system32\iglhcp64.dll 2010-02-11 05:05:42 143360 —-a-w- c:\windows\syswow64\iglhcp32.dll 2009-07-14 05:37:38 31548 —-a-w- c:\windows\inf\perflib\0409\perfd.dat 2009-07-14 05:37:38 31548 —-a-w- c:\windows\inf\perflib\0409\perfc.dat 2009-07-14 05:37:38 291294 —-a-w- c:\windows\inf\perflib\0409\perfi.dat 2009-07-14 05:37:38 291294 —-a-w- c:\windows\inf\perflib\0409\perfh.dat 2009-07-14 04:54:24 174 –sha-w- c:\program files\desktop.ini 2009-07-14 04:54:24 174 –sha-w- c:\program files (x86)\desktop.ini 2009-07-14 01:00:34 291294 —-a-w- c:\windows\inf\perflib\0000\perfi.dat 2009-07-14 01:00:34 291294 —-a-w- c:\windows\inf\perflib\0000\perfh.dat 2009-07-14 01:00:32 31548 —-a-w- c:\windows\inf\perflib\0000\perfd.dat 2009-07-14 01:00:32 31548 —-a-w- c:\windows\inf\perflib\0000\perfc.dat 2009-06-10 20:44:08 9633792 –sha-r- c:\windows\fonts\StaticCache.dat 2009-07-14 01:39:53 398848 –sha-w- c:\windows\winsxs\amd64_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_4d4d1f2f696639a2\WinMail.exe 2009-07-14 01:14:45 396800 –sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe ============= FINISH: 23:00:53.27 ===============

Attachments:

Please run the following program:

Download and run Auslogics Disc Defragmenter

There doesn't appear to be any remaining malware on your system, so it may be a hardware or compatibility issues or some other setting that needs an adjustment.

I will clean up the tools and give my usual closing recommendations, then I suggest you start a new topic in our windows section to see if our expert techs can assist with the outstanding issues.


please do the following:

Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.


If any logs/tools remain on your desktop > right click and delete them.


NEXT


Below I have included a number of recommendations for how to protect your computer against malware infections.

  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them

    Then consider a password keeper, to keep all your passwords safe.

  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.


    WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox, IE and chrome.

  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.

  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.

  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
    Think Prevention.
    PC Safety and Security–What Do I Need?.


**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.


Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI