This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Intense lag!

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, I recently got rid of some malware (I am not sure about the specifics). After that, I installed AVG. Today, my computer started lagging intensely and profusely so I scanned and found some tracking cookies. But they still lag after removal. ): Here is my DDS: DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 21:48:37.06 on 06/16/2010 Wed Internet Explorer: 8.0.6001.18928 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.949.82.1033.18.958.458 [GMT -7:00] SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Program Files\AVG\AVG9\avgchsvx.exe C:\Program Files\AVG\AVG9\avgrsx.exe C:\Program Files\AVG\AVG9\avgcsrvx.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\nvvsvc.exe C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\rundll32.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\system32\taskeng.exe C:\Windows\Explorer.EXE C:\Windows\RtHDVCpl.exe C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\Windows\system32\AERTSrv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\AVG\AVG9\avgwdsvc.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\DRIVERS\xaudio.exe C:\Program Files\AVG\AVG9\avgemc.exe C:\Program Files\AVG\AVG9\avgnsx.exe C:\Program Files\AVG\AVG9\avgcsrvx.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\AIM\aim.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\system32\SearchProtocolHost.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Users\Jay\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\K6IYWHAB\dds[1].scr C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\conime.exe C:\Windows\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com/ uInternet Settings,ProxyOverride = localhost;*.local BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll TB: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide mRun: [RtHDVCpl] RtHDVCpl.exe mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [fullmusic_info] c:\program files\fullmusicp\fullmusic_info.exe mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableLUA = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll AppInit_DLLs: avgrsstx.dll ============= SERVICES / DRIVERS =============== R0 amacpi;Microsoft Away Mode System;c:\windows\system32\drivers\null.sys [2009-10-21 4608] R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2010-6-4 216200] R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-6-4 242896] S4 nvrd32;NVIDIA nForce RAID Driver;c:\windows\system32\drivers\nvrd32.sys [2007-8-27 129832] =============== Created Last 30 ================ 2010-06-16 15:25 –d—– c:\program files\iPod 2010-06-16 15:24 –d—– c:\program files\iTunes 2010-06-16 15:18 –d—– c:\program files\Bonjour 2010-06-08 15:38 67,072 a——- c:\windows\system32\asycfilt.dll 2010-06-08 15:38 289,792 a——- c:\windows\system32\atmfd.dll 2010-06-08 15:38 34,304 a——- c:\windows\system32\atmlib.dll 2010-06-04 17:50 –d-h— C:\$AVG 2010-06-04 16:26 12,464 a——- c:\windows\system32\avgrsstx.dll 2010-06-04 16:26 242,896 a——- c:\windows\system32\drivers\avgtdix.sys 2010-06-04 16:26 216,200 a——- c:\windows\system32\drivers\avgldx86.sys 2010-06-04 16:26 –d—– c:\windows\system32\drivers\Avg 2010-05-28 20:09 2,048 a——- c:\windows\system32\tzres.dll 2010-05-28 19:44 –dsh— C:\$RECYCLE.BIN 2010-05-28 19:18 256,512 a——- c:\windows\PEV.exe 2010-05-28 19:18 161,792 a——- c:\windows\SWREG.exe 2010-05-28 19:18 98,816 a——- c:\windows\sed.exe 2010-05-28 19:18 77,312 a——- c:\windows\MBR.exe 2010-05-28 19:07 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2010-05-28 19:07 20,952 a——- c:\windows\system32\drivers\mbam.sys 2010-05-28 19:07 –d—– c:\program files\Malwarebytes' Anti-Malware 2010-05-24 15:13 –d—– C:\acccore 2010-05-23 12:59 –d—– c:\program files\Steam 2010-05-18 16:35 107,808 a——- c:\windows\system32\dns-sd.exe 2010-05-18 16:35 91,424 a——- c:\windows\system32\dnssd.dll ==================== Find3M ==================== 2010-06-16 15:21 143,360 a——- c:\windows\inf\infstrng.dat 2010-06-16 15:21 86,016 a——- c:\windows\inf\infstor.dat 2010-06-16 15:21 51,200 a——- c:\windows\inf\infpub.dat 2010-06-08 20:30 2,482 a——- c:\users\jay\appdata\roaming\wklnhst.dat 2010-05-21 14:14 221,568 ——– c:\windows\system32\MpSigStub.exe 2010-05-03 22:59 916,480 a——- c:\windows\system32\wininet.dll 2010-05-03 22:55 109,056 a——- c:\windows\system32\iesysprep.dll 2010-05-03 22:55 71,680 a——- c:\windows\system32\iesetup.dll 2010-05-03 21:31 133,632 a——- c:\windows\system32\ieUnatt.exe 2010-05-01 07:13 2,037,248 a——- c:\windows\system32\win32k.sys 2010-04-08 23:58 65,536 a——- c:\windows\IFinst27.exe 2010-04-08 15:19 73,216 a——- c:\windows\ST6UNST.EXE 2010-04-08 15:19 286,720 ——– c:\windows\Setup1.exe 2010-03-20 20:55 81,920 ——– c:\windows\bwUnin-6.1.4.68-8876480L.exe 2009-11-17 15:23 665,600 a——- c:\windows\inf\drvindex.dat 2009-10-24 09:03 174 a–sh— c:\program files\desktop.ini 2009-10-12 17:08 56 a—h— c:\programdata\ezsidmv.dat 2009-10-12 17:08 56 a—h— c:\progra~2\ezsidmv.dat 2006-11-02 05:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat 2006-11-02 05:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat 2006-11-02 05:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat 2006-11-02 05:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat 2006-11-02 02:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 02:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 02:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 02:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat 2009-10-21 16:46 245,760 a–sh— c:\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\ietldcache\index.dat 2007-08-27 22:51 8,192 a–sh— c:\windows\users\default\NTUSER.DAT ============= FINISH: 21:51:52.39 ===============
Hello, SubstantDisorder
Welcome to the WhatTheTech Forums. My name is Thomas (Tom is fine), and I will be helping you fixing your problems.



Please take note of some guidelines for this fix:
  • Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
  • If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
  • Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
  • Do not start a new topic. The logs that you post should be pasted directly into the reply. Only attach them if requested or if they do not fit into the post.
  • Please set your system to show all files.
    Click Start, open My Computer, select the Tools menu and click Folder Options.
    Select the View Tab. Under the Hidden files and folders heading, select Show hidden files and folders.
    Uncheck: Hide file extensions for known file types
    Uncheck the Hide protected operating system files (recommended) option.
    Click Yes to confirm.





  • Please download OTL from one of the following mirrors:
    • This is THE Mirror
  • Save it to your desktop.
  • Double click on the [external image: Posted Image] icon on your desktop.
  • Under the Custom Scan box paste this in
    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    /md5stop
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
  • Push the Quick Scan button.
  • Two reports will open, copy and paste them in a reply here:
    • OTL.txt <– Will be opened
    • Extra.txt <– Will be minimized
OTL logfile created on: 6/20/2010 10:00:06 AM - Run 1
OTL by OldTimer - Version 3.2.6.0 Folder = C:\Users\Jay\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18928)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

958.00 Mb Total Physical Memory | 274.00 Mb Available Physical Memory | 29.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 50.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 288.04 Gb Total Space | 107.36 Gb Free Space | 37.27% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 6.21 Gb Free Space | 62.05% Space Free | Partition Type: NTFS
Drive E: | 608.81 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: JAY-PC
Current User Name: Jay
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan

========== Processes (SafeList) ==========

PRC - [2010/06/20 09:59:27 | 000,572,416 | —- | M] (OldTimer Tools) – C:\Users\Jay\Desktop\OTL.exe
PRC - [2010/06/10 21:03:08 | 000,144,176 | —- | M] (Apple Inc.) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2010/06/04 16:35:55 | 002,065,248 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgtray.exe
PRC - [2010/06/04 16:35:51 | 000,515,424 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgrsx.exe
PRC - [2010/06/04 16:35:50 | 000,620,896 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgnsx.exe
PRC - [2010/06/04 16:35:43 | 000,722,784 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgcsrvx.exe
PRC - [2010/06/04 16:35:38 | 001,101,152 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgchsvx.exe
PRC - [2010/06/04 16:24:58 | 000,916,760 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgemc.exe
PRC - [2010/06/04 16:24:53 | 000,308,064 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgwdsvc.exe
PRC - [2010/03/08 14:04:49 | 003,972,440 | —- | M] (AOL Inc.) – C:\Program Files\AIM\aim.exe
PRC - [2009/04/10 23:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) – C:\Windows\explorer.exe
PRC - [2008/01/17 07:22:20 | 004,907,008 | —- | M] (Realtek Semiconductor) – C:\Windows\RtHDVCpl.exe
PRC - [2007/12/05 06:17:24 | 000,077,824 | —- | M] (Andrea Electronics Corporation) – C:\Windows\System32\AERTSrv.exe
PRC - [2006/10/03 09:37:04 | 000,081,920 | —- | M] (Macrovision Corporation) – C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe


========== Modules (SafeList) ==========

MOD - [2010/06/20 09:59:27 | 000,572,416 | —- | M] (OldTimer Tools) – C:\Users\Jay\Desktop\OTL.exe
MOD - [2010/06/04 16:26:20 | 000,012,464 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\avgrsstx.dll
MOD - [2009/04/10 23:21:38 | 001,686,016 | —- | M] (Microsoft Corporation) – C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll
MOD - [2008/01/19 00:33:00 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msscript.ocx


========== Win32 Services (SafeList) ==========

SRV - File not found [On_Demand | Stopped] – – (U1expskpn_3.0)
SRV - File not found [On_Demand | Stopped] – – (stllssvr)
SRV - File not found [Auto | Stopped] – – (CLTNetCnService)
SRV - [2010/06/10 21:03:08 | 000,144,176 | —- | M] (Apple Inc.) [Auto | Running] – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe – (Apple Mobile Device)
SRV - [2010/06/04 16:24:58 | 000,916,760 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files\AVG\AVG9\avgemc.exe – (avg9emc)
SRV - [2010/06/04 16:24:53 | 000,308,064 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files\AVG\AVG9\avgwdsvc.exe – (avg9wd)
SRV - [2010/05/23 13:00:12 | 000,395,048 | —- | M] (Valve Corporation) [On_Demand | Stopped] – C:\Program Files\Common Files\Steam\SteamService.exe – (Steam Client Service)
SRV - [2009/09/24 18:27:04 | 000,793,088 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\FntCache.dll – (FontCache)
SRV - [2008/01/19 00:38:24 | 000,272,952 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2007/12/05 06:17:24 | 000,077,824 | —- | M] (Andrea Electronics Corporation) [Auto | Running] – C:\Windows\System32\AERTSrv.exe – (AERTFilters)
SRV - [2007/03/19 10:44:44 | 000,070,656 | —- | M] () [On_Demand | Stopped] – C:\Program Files\DellSupport\brkrsvc.exe – (DSBrokerService)


========== Driver Services (SafeList) ==========

DRV - [2010/06/04 16:35:51 | 000,242,896 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\Windows\System32\drivers\avgtdix.sys – (AvgTdiX)
DRV - [2010/06/04 16:35:51 | 000,029,584 | —- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] – C:\Windows\System32\drivers\avgmfx86.sys – (AvgMfx86)
DRV - [2010/06/04 16:26:11 | 000,216,200 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\Windows\System32\drivers\avgldx86.sys – (AvgLdx86)
DRV - [2009/07/14 19:54:00 | 009,557,216 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\nvlddmkm.sys – (nvlddmkm)
DRV - [2008/01/24 11:06:40 | 002,054,872 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\RTKVHDA.sys – (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2007/08/27 22:48:42 | 000,020,152 | —- | M] (VIA Technologies, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\viaide.sys – (viaide)
DRV - [2007/08/27 22:48:42 | 000,019,128 | —- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\cmdide.sys – (cmdide)
DRV - [2007/08/27 22:48:42 | 000,017,592 | —- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\aliide.sys – (aliide)
DRV - [2007/08/09 18:12:30 | 000,110,624 | —- | M] (NVIDIA Corporation) [Kernel | Boot | Running] – C:\Windows\system32\drivers\nvstor32.sys – (nvstor32)
DRV - [2007/03/23 04:09:16 | 000,129,832 | —- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\nvrd32.sys – (nvrd32)
DRV - [2007/03/15 06:57:30 | 001,059,112 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\nvmfdx32.sys – (NVENETFD)
DRV - [2007/02/25 10:10:48 | 000,005,376 | –S- | M] (Gteko Ltd.) [Kernel | Auto | Running] – C:\Windows\System32\drivers\dsunidrv.sys – (dsunidrv)
DRV - [2006/11/02 02:51:45 | 000,900,712 | —- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\ql2300.sys – (ql2300)
DRV - [2006/11/02 02:51:38 | 000,420,968 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\adp94xx.sys – (adp94xx)
DRV - [2006/11/02 02:51:34 | 000,316,520 | —- | M] (Emulex) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\elxstor.sys – (elxstor)
DRV - [2006/11/02 02:51:32 | 000,297,576 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\adpahci.sys – (adpahci)
DRV - [2006/11/02 02:51:25 | 000,235,112 | —- | M] (ULi Electronics Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\uliahci.sys – (uliahci)
DRV - [2006/11/02 02:51:25 | 000,232,040 | —- | M] (Intel Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\iastorv.sys – (iaStorV)
DRV - [2006/11/02 02:51:00 | 000,147,048 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\adpu320.sys – (adpu320)
DRV - [2006/11/02 02:50:45 | 000,115,816 | —- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\ulsata2.sys – (ulsata2)
DRV - [2006/11/02 02:50:41 | 000,112,232 | —- | M] (VIA Technologies Inc.,Ltd) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\vsmraid.sys – (vsmraid)
DRV - [2006/11/02 02:50:35 | 000,106,088 | —- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\ql40xx.sys – (ql40xx)
DRV - [2006/11/02 02:50:35 | 000,098,408 | —- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\ulsata.sys – (UlSata)
DRV - [2006/11/02 02:50:35 | 000,098,408 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\adpu160m.sys – (adpu160m)
DRV - [2006/11/02 02:50:24 | 000,088,680 | —- | M] (NVIDIA Corporation) [Kernel | Boot | Running] – C:\Windows\system32\drivers\nvraid.sys – (nvraid)
DRV - [2006/11/02 02:50:19 | 000,045,160 | —- | M] (IBM Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\nfrd960.sys – (nfrd960)
DRV - [2006/11/02 02:50:17 | 000,041,576 | —- | M] (Intel Corp./ICP vortex GmbH) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\iirsp.sys – (iirsp)
DRV - [2006/11/02 02:50:16 | 000,071,784 | —- | M] (Silicon Integrated Systems) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\sisraid4.sys – (SiSRaid4)
DRV - [2006/11/02 02:50:13 | 000,040,040 | —- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\nvstor.sys – (nvstor)
DRV - [2006/11/02 02:50:11 | 000,071,272 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\djsvs.sys – (aic78xx)
DRV - [2006/11/02 02:50:10 | 000,067,688 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\arcsas.sys – (arcsas)
DRV - [2006/11/02 02:50:10 | 000,065,640 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\lsi_scsi.sys – (LSI_SCSI)
DRV - [2006/11/02 02:50:10 | 000,038,504 | —- | M] (Silicon Integrated Systems Corp.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\sisraid2.sys – (SiSRaid2)
DRV - [2006/11/02 02:50:10 | 000,037,480 | —- | M] (Hewlett-Packard Company) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\hpcisss.sys – (HpCISSs)
DRV - [2006/11/02 02:50:09 | 000,067,688 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\arc.sys – (arc)
DRV - [2006/11/02 02:50:09 | 000,035,944 | —- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\iteraid.sys – (iteraid)
DRV - [2006/11/02 02:50:07 | 000,035,944 | —- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\iteatapi.sys – (iteatapi)
DRV - [2006/11/02 02:50:05 | 000,065,640 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\lsi_sas.sys – (LSI_SAS)
DRV - [2006/11/02 02:50:05 | 000,035,944 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\symc8xx.sys – (Symc8xx)
DRV - [2006/11/02 02:50:04 | 000,065,640 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\lsi_fc.sys – (LSI_FC)
DRV - [2006/11/02 02:50:03 | 000,034,920 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\sym_u3.sys – (Sym_u3)
DRV - [2006/11/02 02:49:59 | 000,033,384 | —- | M] (LSI Logic Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\mraid35x.sys – (Mraid35x)
DRV - [2006/11/02 02:49:56 | 000,031,848 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\sym_hi.sys – (Sym_hi)
DRV - [2006/11/02 02:49:53 | 000,028,776 | —- | M] (LSI Logic Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\megasas.sys – (megasas)
DRV - [2006/11/02 01:25:24 | 000,071,808 | —- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\brserid.sys – (Brserid) Brother MFC Serial Port Interface Driver (WDM)
DRV - [2006/11/02 01:24:47 | 000,011,904 | —- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\brusbser.sys – (BrUsbSer)
DRV - [2006/11/02 01:24:46 | 000,005,248 | —- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\brfiltup.sys – (BrFiltUp)
DRV - [2006/11/02 01:24:45 | 000,013,568 | —- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\brfiltlo.sys – (BrFiltLo)
DRV - [2006/11/02 01:24:44 | 000,062,336 | —- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\brserwdm.sys – (BrSerWdm)
DRV - [2006/11/02 01:24:44 | 000,012,160 | —- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\brusbmdm.sys – (BrUsbMdm)
DRV - [2006/11/02 00:36:50 | 000,020,608 | —- | M] (N-trig Innovative Technologies) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\ntrigdigi.sys – (ntrigdigi)
DRV - [2006/11/02 00:36:43 | 002,028,032 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\atikmdag.sys – (R300)
DRV - [2006/11/02 00:30:55 | 000,200,704 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\e1e6032.sys – (e1express) Intel®
DRV - [2006/11/02 00:30:54 | 000,117,760 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\E1G60I32.sys – (E1G60) Intel®
DRV - [2006/10/18 11:09:26 | 000,986,624 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\HSX_DPV.sys – (HSF_DPV)
DRV - [2006/10/18 11:08:18 | 000,258,048 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\HSXHWBS2.sys – (HSXHWBS2)
DRV - [2006/10/18 11:08:04 | 000,659,968 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\HSX_CNXT.sys – (winachsf)
DRV - [2006/10/05 15:07:28 | 000,004,736 | —- | M] (Gteko Ltd.) [Kernel | On_Demand | Stopped] – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys – (DSproct)
DRV - [2006/08/04 17:39:10 | 000,008,192 | —- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] – C:\Windows\System32\drivers\XAudio.sys – (XAudio)
DRV - [2005/01/31 08:20:04 | 000,211,712 | —- | M] (Logitech Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\LV561AV.SYS – (PID_0928) Logitech QuickCam Express(PID_0928)
DRV - [2005/01/31 08:12:46 | 000,022,016 | —- | M] (Logitech Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\LVUSBSta.sys – (LVUSBSta)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = localhost;*.local


[2009/10/17 09:49:29 | 000,000,000 | —D | M] – C:\Users\Jay\AppData\Roaming\Mozilla\Extensions
[2009/10/17 09:49:29 | 000,000,000 | —D | M] – C:\Users\Jay\AppData\Roaming\Mozilla\Extensions\[removed]

O1 HOSTS File: ([2010/05/28 19:41:19 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [fullmusic_info] C:\Program Files\FullMusicP\fullmusic_info.exe ()
O4 - HKLM..\Run: [ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (Macrovision Corporation)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - AppInit_DLLs: (avgrsstx.dll) - C:\Windows\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 14:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [1998/12/13 07:43:32 | 000,000,040 | R— | M] () - E:\AUTORUN.INF – [ CDFS ]
O33 - MountPoints2\{59488c71-54e8-11dc-8e24-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{59488c71-54e8-11dc-8e24-806e6f6e6963}\Shell\AutoRun\command - "" = E:\SETUP.EXE – [1998/12/01 05:04:40 | 000,025,600 | R— | M] ()
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias [2009/10/24 01:10:30 | 000,000,000 | —D | M]
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 90 Days ==========

[2010/06/20 09:59:24 | 000,572,416 | —- | C] (OldTimer Tools) – C:\Users\Jay\Desktop\OTL.exe
[2010/06/16 15:25:08 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2010/06/16 15:24:34 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2010/06/16 15:18:30 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2010/06/09 21:48:32 | 000,000,000 | —D | C] – C:\Windows\Sun
[2010/06/04 17:50:35 | 000,000,000 | -H-D | C] – C:\$AVG
[2010/06/04 16:26:18 | 000,012,464 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\avgrsstx.dll
[2010/06/04 16:26:16 | 000,242,896 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgtdix.sys
[2010/06/04 16:26:10 | 000,216,200 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgldx86.sys
[2010/06/04 16:26:08 | 000,029,584 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgmfx86.sys
[2010/06/04 16:26:06 | 000,000,000 | —D | C] – C:\Windows\System32\drivers\Avg
[2010/05/28 19:46:27 | 000,000,000 | —D | C] – C:\Users\Jay\AppData\Local\temp
[2010/05/28 19:44:42 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2010/05/28 19:39:38 | 000,000,000 | —D | C] – C:\Windows\temp
[2010/05/28 19:21:42 | 000,212,480 | —- | C] (SteelWerX) – C:\Windows\SWXCACLS.exe
[2010/05/28 19:18:59 | 000,161,792 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2010/05/28 19:18:59 | 000,136,704 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2010/05/28 19:18:59 | 000,031,232 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2010/05/28 19:18:48 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2010/05/28 19:18:11 | 000,000,000 | —D | C] – C:\Qoobox
[2010/05/28 19:09:40 | 000,000,000 | —D | C] – C:\Users\Jay\Documents\Starcraft
[2010/05/28 19:07:31 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/05/28 19:07:30 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/05/28 19:07:30 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/05/28 15:16:37 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2010/05/24 15:13:52 | 000,000,000 | —D | C] – C:\acccore
[2010/05/23 12:59:11 | 000,000,000 | —D | C] – C:\Program Files\Steam
[2010/04/09 14:42:58 | 000,000,000 | —D | C] – C:\Program Files\ElcomSoft
[2010/04/08 23:58:22 | 000,000,000 | —D | C] – C:\Program Files\FullMusicP
[2010/04/08 23:58:16 | 000,000,000 | —D | C] – C:\Program Files\fullmusic
[2010/04/02 20:29:09 | 000,000,000 | —D | C] – C:\ProgramData\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010/04/02 20:26:35 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 90 Days ==========

[2010/06/20 10:06:58 | 003,932,160 | -HS- | M] () – C:\Users\Jay\NTUSER.DAT
[2010/06/20 09:59:27 | 000,572,416 | —- | M] (OldTimer Tools) – C:\Users\Jay\Desktop\OTL.exe
[2010/06/20 09:57:55 | 061,256,026 | —- | M] () – C:\Windows\System32\drivers\Avg\incavi.avm
[2010/06/20 09:51:16 | 000,003,696 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/06/20 09:51:16 | 000,003,696 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/06/20 09:51:14 | 000,000,882 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/06/20 09:51:11 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/06/20 09:51:08 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/06/20 09:51:05 | 1005,051,904 | -HS- | M] () – C:\hiberfil.sys
[2010/06/20 01:54:21 | 000,524,288 | -HS- | M] () – C:\Users\Jay\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms
[2010/06/20 01:54:21 | 000,065,536 | -HS- | M] () – C:\Users\Jay\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf
[2010/06/20 01:53:06 | 001,484,908 | -H– | M] () – C:\Users\Jay\AppData\Local\IconCache.db
[2010/06/20 01:23:00 | 000,000,886 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/06/19 21:46:34 | 000,002,231 | —- | M] () – C:\Users\Jay\Desktop\iTunes.lnk
[2010/06/19 09:05:22 | 000,137,216 | —- | M] () – C:\Users\Jay\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/06/11 16:05:16 | 000,282,928 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2010/06/08 20:30:02 | 000,002,482 | —- | M] () – C:\Users\Jay\AppData\Roaming\wklnhst.dat
[2010/06/08 20:27:16 | 000,022,528 | —- | M] () – C:\Users\Jay\Documents\TKM.wps
[2010/06/07 22:31:47 | 000,000,884 | —- | M] () – C:\Users\Jay\Desktop\Starcraft - Oblivion.lnk
[2010/06/07 22:31:42 | 000,000,843 | —- | M] () – C:\Users\Jay\Desktop\Starcraft - DLL.lnk
[2010/06/07 16:59:26 | 000,000,870 | —- | M] () – C:\Users\Jay\Desktop\Starcraft - DHP.lnk
[2010/06/06 21:00:01 | 000,414,198 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2010/06/06 21:00:01 | 000,307,644 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/06/06 21:00:01 | 000,105,448 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/06/04 16:35:51 | 000,242,896 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgtdix.sys
[2010/06/04 16:35:51 | 000,029,584 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgmfx86.sys
[2010/06/04 16:26:20 | 000,012,464 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\avgrsstx.dll
[2010/06/04 16:26:11 | 000,216,200 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgldx86.sys
[2010/06/04 16:26:08 | 000,113,461 | —- | M] () – C:\Windows\System32\drivers\Avg\iavichjw.avm
[2010/05/28 19:41:24 | 000,000,215 | —- | M] () – C:\Windows\system.ini
[2010/05/28 19:41:19 | 000,000,027 | —- | M] () – C:\Windows\System32\drivers\etc\hosts
[2010/05/09 18:12:26 | 000,067,552 | —- | M] () – C:\Users\Jay\AppData\Local\GDIPFONTCACHEV1.DAT
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/04/29 15:39:26 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/04/26 15:58:12 | 000,256,512 | —- | M] () – C:\Windows\PEV.exe
[2010/04/08 23:58:02 | 000,065,536 | —- | M] () – C:\Windows\IFinst27.exe
[2010/04/08 12:11:02 | 000,000,303 | —- | M] () – C:\Windows\ST6UNST.001
[2010/04/08 12:10:46 | 000,000,303 | —- | M] () – C:\Windows\ST6UNST.000
[2010/04/01 22:08:16 | 000,000,707 | -H– | M] () – C:\IPH.PH
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2099/01/01 12:00:00 | 000,006,456 | -H– | C] () – C:\ProgramData\vawotuwu
[2010/06/16 19:38:36 | 000,002,231 | —- | C] () – C:\Users\Jay\Desktop\iTunes.lnk
[2010/06/08 19:00:06 | 000,022,528 | —- | C] () – C:\Users\Jay\Documents\TKM.wps
[2010/06/05 21:50:10 | 000,000,884 | —- | C] () – C:\Users\Jay\Desktop\Starcraft - Oblivion.lnk
[2010/06/05 21:50:10 | 000,000,870 | —- | C] () – C:\Users\Jay\Desktop\Starcraft - DHP.lnk
[2010/06/05 21:50:10 | 000,000,843 | —- | C] () – C:\Users\Jay\Desktop\Starcraft - DLL.lnk
[2010/06/04 16:26:08 | 000,113,461 | —- | C] () – C:\Windows\System32\drivers\Avg\iavichjw.avm
[2010/06/04 16:26:06 | 061,256,026 | —- | C] () – C:\Windows\System32\drivers\Avg\incavi.avm
[2010/05/28 19:18:59 | 000,256,512 | —- | C] () – C:\Windows\PEV.exe
[2010/05/28 19:18:59 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2010/05/28 19:18:59 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2010/05/28 19:18:59 | 000,077,312 | —- | C] () – C:\Windows\MBR.exe
[2010/05/28 19:18:59 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2010/05/28 17:53:31 | 1005,051,904 | -HS- | C] () – C:\hiberfil.sys
[2010/04/08 23:58:02 | 000,065,536 | —- | C] () – C:\Windows\IFinst27.exe
[2010/04/08 12:11:01 | 000,000,303 | —- | C] () – C:\Windows\ST6UNST.001
[2010/04/08 12:10:46 | 000,000,303 | —- | C] () – C:\Windows\ST6UNST.000
[2010/03/20 21:46:21 | 000,000,039 | —- | C] () – C:\Windows\WININIT.INI
[2010/01/12 00:29:52 | 000,178,176 | —- | C] () – C:\Windows\System32\unrar.dll
[2009/10/24 15:35:59 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2007/03/19 03:04:58 | 000,003,584 | —- | C] () – C:\Windows\System32\namResES.dll
[2007/03/19 03:04:58 | 000,003,072 | —- | C] () – C:\Windows\System32\namResIT.dll
[2007/03/19 03:04:58 | 000,003,072 | —- | C] () – C:\Windows\System32\namResFR.dll
[2007/03/19 03:04:58 | 000,003,072 | —- | C] () – C:\Windows\System32\namResENG.dll
[2007/03/19 03:04:58 | 000,003,072 | —- | C] () – C:\Windows\System32\namResDE.dll
[2007/03/19 03:04:56 | 000,003,584 | —- | C] () – C:\Windows\System32\namResPTB.dll
[2007/03/19 03:04:56 | 000,003,072 | —- | C] () – C:\Windows\System32\namResZHC.dll
[2007/03/19 03:04:56 | 000,003,072 | —- | C] () – C:\Windows\System32\namResKO.dll
[2007/03/19 03:04:56 | 000,003,072 | —- | C] () – C:\Windows\System32\namResJA.dll
[2007/03/19 03:04:54 | 000,022,016 | —- | C] () – C:\Windows\System32\nam_page.dll
[2007/03/19 03:04:54 | 000,003,072 | —- | C] () – C:\Windows\System32\namResZHT.dll
[2006/11/02 05:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 03:25:44 | 000,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2006/11/02 00:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2005/01/31 06:37:58 | 000,009,255 | —- | C] () – C:\Windows\System32\lvcoinst.ini
[1999/01/27 13:39:06 | 000,065,024 | —- | C] () – C:\Windows\System32\indounin.dll
[1997/06/13 07:56:08 | 000,056,832 | —- | C] () – C:\Windows\System32\Iyvu9_32.dll

========== LOP Check ==========

[2009/10/12 14:19:50 | 000,000,000 | —D | M] – C:\Users\Jay\AppData\Roaming\acccore
[2010/06/14 20:07:54 | 000,000,000 | —D | M] – C:\Users\Jay\AppData\Roaming\Audacity
[2010/06/19 20:47:09 | 000,000,000 | —D | M] – C:\Users\Jay\AppData\Roaming\BitTorrent
[2010/02/20 01:20:42 | 000,000,000 | —D | M] – C:\Users\Jay\AppData\Roaming\GetRightToGo
[2009/10/23 16:36:53 | 000,000,000 | —D | M] – C:\Users\Jay\AppData\Roaming\gtk-2.0
[2010/02/15 00:33:27 | 000,000,000 | —D | M] – C:\Users\Jay\AppData\Roaming\LimeWire
[2010/01/03 12:58:56 | 000,000,000 | -HSD | M] – C:\Users\Jay\AppData\Roaming\lowsec
[2010/02/07 03:22:00 | 000,000,000 | —D | M] – C:\Users\Jay\AppData\Roaming\ooVoo Details
[2010/02/08 01:35:59 | 000,000,000 | —D | M] – C:\Users\Jay\AppData\Roaming\schtml
[2009/10/19 21:16:04 | 000,000,000 | —D | M] – C:\Users\Jay\AppData\Roaming\Template
[2009/10/12 20:59:09 | 000,000,000 | —D | M] – C:\Users\Jay\AppData\Roaming\Uniblue
[2010/06/20 01:54:05 | 000,032,634 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2008/01/19 00:42:25 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\System32\DriverStore\FileRepository\machine.inf_51b95d75\AGP440.sys
[2008/01/19 00:42:25 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\System32\DriverStore\FileRepository\machine.inf_f750e484\AGP440.sys
[2008/01/19 00:42:25 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys
[2008/01/19 00:42:25 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647bbd2a4c6\AGP440.sys
[2007/08/27 22:48:07 | 000,053,864 | —- | M] (Microsoft Corporation) MD5=8B10CE1C1F9F1D47E4DEB1A547A00CD4 – C:\Windows\ERDNT\cache\AGP440.sys
[2007/08/27 22:48:07 | 000,053,864 | —- | M] (Microsoft Corporation) MD5=8B10CE1C1F9F1D47E4DEB1A547A00CD4 – C:\Windows\System32\drivers\AGP440.sys
[2007/08/27 22:48:07 | 000,053,864 | —- | M] (Microsoft Corporation) MD5=8B10CE1C1F9F1D47E4DEB1A547A00CD4 – C:\Windows\System32\DriverStore\FileRepository\machine.inf_8ed06b47\AGP440.sys
[2007/08/27 22:48:07 | 000,053,864 | —- | M] (Microsoft Corporation) MD5=8B10CE1C1F9F1D47E4DEB1A547A00CD4 – C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6000.16400_none_b82caac9c18a4e3b\AGP440.sys
[2007/08/27 22:48:07 | 000,053,864 | —- | M] (Microsoft Corporation) MD5=BF34B4A0E0B64440C5389AA6B902F4AD – C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6000.20496_none_b85af81edaeb8461\AGP440.sys
[2006/11/02 02:49:52 | 000,053,864 | —- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 – C:\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys

< MD5 for: ATAPI.SYS >
[2009/04/10 23:32:26 | 000,019,944 | —- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 – C:\Windows\ERDNT\cache\atapi.sys
[2009/04/10 23:32:26 | 000,019,944 | —- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 – C:\Windows\System32\drivers\atapi.sys
[2009/04/10 23:32:26 | 000,019,944 | —- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys
[2009/04/10 23:32:26 | 000,019,944 | —- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys
[2008/01/19 00:41:30 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
[2008/01/19 00:41:30 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
[2006/11/02 02:49:36 | 000,019,048 | —- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
[2007/08/27 22:48:52 | 000,019,048 | —- | M] (Microsoft Corporation) MD5=5653737BAD8C6C10136451C195C19881 – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20485_none_db8a029f3dbd443b\atapi.sys
[2007/08/27 22:48:42 | 000,021,688 | —- | M] (Microsoft Corporation) MD5=9E7E85EC61D1C9C3171CC08427108863 – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_5a9555b4\atapi.sys
[2007/08/27 22:48:42 | 000,021,688 | —- | M] (Microsoft Corporation) MD5=9E7E85EC61D1C9C3171CC08427108863 – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20509_none_dbe4850d3d78c736\atapi.sys
[2007/08/27 22:48:51 | 000,019,048 | —- | M] (Microsoft Corporation) MD5=A779CA2C76DA4FCB595E692C05E8E4EB – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_82339ef2\atapi.sys
[2007/08/27 22:48:51 | 000,019,048 | —- | M] (Microsoft Corporation) MD5=A779CA2C76DA4FCB595E692C05E8E4EB – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.16391_none_daf194c024ab5b06\atapi.sys
[2009/10/17 00:16:00 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_7de13c21\atapi.sys
[2009/10/17 00:16:00 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.16632_none_db337a442479c42c\atapi.sys
[2009/10/17 00:15:58 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=E03E8C99D15D0381E02743C36AFC7C6F – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_64dfd8ea\atapi.sys
[2009/10/17 00:15:58 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=E03E8C99D15D0381E02743C36AFC7C6F – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20757_none_dbac78a93da31a8b\atapi.sys

< MD5 for: CNGAUDIT.DLL >
[2006/11/02 02:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\ERDNT\cache\cngaudit.dll
[2006/11/02 02:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\System32\cngaudit.dll
[2006/11/02 02:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll

< MD5 for: IASTORV.SYS >
[2008/01/19 00:42:51 | 000,235,064 | —- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 – C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_c9df7691\iaStorV.sys
[2008/01/19 00:42:51 | 000,235,064 | —- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 – C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_af11527887c7fa8f\iaStorV.sys
[2006/11/02 02:51:25 | 000,232,040 | —- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 – C:\Windows\System32\drivers\iaStorV.sys
[2006/11/02 02:51:25 | 000,232,040 | —- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 – C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys

< MD5 for: NETLOGON.DLL >
[2006/11/02 02:46:11 | 000,559,616 | —- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B – C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6000.16386_none_fb80f5473b0ed783\netlogon.dll
[2009/04/10 23:28:23 | 000,592,896 | —- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE – C:\Windows\ERDNT\cache\netlogon.dll
[2009/04/10 23:28:23 | 000,592,896 | —- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE – C:\Windows\System32\netlogon.dll
[2009/04/10 23:28:23 | 000,592,896 | —- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE – C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_ffa3304f351bb3a3\netlogon.dll
[2008/01/19 00:35:36 | 000,592,384 | —- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F – C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll

< MD5 for: NVSTOR.SYS >
[2006/11/02 02:50:13 | 000,040,040 | —- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC – C:\Windows\System32\drivers\nvstor.sys
[2006/11/02 02:50:13 | 000,040,040 | —- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC – C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2008/01/19 00:42:09 | 000,045,112 | —- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 – C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvstor.sys
[2008/01/19 00:42:09 | 000,045,112 | —- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 – C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvstor.sys

< MD5 for: SCECLI.DLL >
[2008/01/19 00:36:19 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 – C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll
[2006/11/02 02:46:12 | 000,176,640 | —- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 – C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6000.16386_none_35d7205fdc305e3e\scecli.dll
[2009/04/10 23:28:24 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 – C:\Windows\ERDNT\cache\scecli.dll
[2009/04/10 23:28:24 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 – C:\Windows\System32\scecli.dll
[2009/04/10 23:28:24 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 – C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_39f95b67d63d3a5e\scecli.dll

< %systemroot%\*. /mp /s >

< CREATERESTOREPOINT >

========== Alternate Data Streams ==========

@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:A8ADE5D8
@Alternate Data Stream - 103 bytes -> C:\ProgramData\TEMP:DFC5A2B2
< End of report >

















OTL Extras logfile created on: 6/20/2010 10:00:06 AM - Run 1
OTL by OldTimer - Version 3.2.6.0 Folder = C:\Users\Jay\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18928)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

958.00 Mb Total Physical Memory | 274.00 Mb Available Physical Memory | 29.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 50.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 288.04 Gb Total Space | 107.36 Gb Free Space | 37.27% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 6.21 Gb Free Space | 62.05% Space Free | Partition Type: NTFS
Drive E: | 608.81 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: JAY-PC
Current User Name: Jay
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.exe [@ = exefile] – Reg Error: Key error. File not found
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – Reg Error: Key error.
https [open] – Reg Error: Value error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{22C8CD0A-6DFD-4220-BED3-A398733687B4}" = lport=443 | protocol=6 | dir=in | name=oovoo tcp port 443 |
"{6ECCA040-EFC3-44F2-8B48-10C1AB357E89}" = lport=443 | protocol=17 | dir=in | name=oovoo udp port 443 |
"{91F430E7-5754-4DC9-8774-37C7C723657A}" = lport=6112 | protocol=6 | dir=in | name=6112tcp |
"{A2313E4A-2CBF-4A49-9A04-26BFE97D7163}" = lport=37675 | protocol=17 | dir=in | name=oovoo udp port 37675 |
"{B99AEA20-A855-4FA5-A4DF-9534F20A17F4}" = lport=37674 | protocol=17 | dir=in | name=oovoo udp port 37674 |
"{C7AF28EA-D75A-4437-9311-55A5F0F74AB3}" = lport=37674 | protocol=6 | dir=in | name=oovoo tcp port 37674 |
"{E55CC513-187A-4CB8-AB57-387F6C894B90}" = lport=6112 | protocol=17 | dir=in | name=6112udp |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{05B373E5-AB8E-4A68-BD49-EFB6A0CFAD81}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{07247F72-D0AF-4C68-9844-47CD5EB63DAF}" = protocol=17 | dir=in | app=c:\program files\steam\steam.exe |
"{0B41C49E-EC2D-409B-BCEC-D6E3CB1382A3}" = dir=in | app=c:\program files\avg\avg9\avgnsx.exe |
"{3DD7D6B1-ECB9-48EF-9357-C677F3D7CCBA}" = protocol=6 | dir=in | app=c:\program files\aim\aim.exe |
"{438298FD-BDC7-4594-9712-715A978100C0}" = protocol=6 | dir=in | app=c:\program files\starcraft\starcraft.exe |
"{4AC8FE26-BA50-4383-B0C5-19C738F27178}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{4CB94F4A-9CE2-4509-8230-C62DCA5C2125}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{5ABBC8C4-4F65-4435-81DF-2707BADFBD75}" = protocol=6 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"{5F784585-F71E-4D61-9272-BA3C93984C87}" = protocol=6 | dir=in | app=c:\users\jay\documents\super simple wall 6.81\sswv6.81.exe |
"{8C81DFBB-4641-4AF6-8F4F-2241DC4B58E0}" = protocol=17 | dir=in | app=c:\program files\aim\aim.exe |
"{A09E5826-9E12-432E-95B4-1AB172DED0BE}" = protocol=17 | dir=in | app=c:\users\jay\documents\super simple wall 6.81\sswv6.81.exe |
"{A58DA086-0AC8-4027-9604-99FBDD3A0458}" = protocol=17 | dir=in | app=c:\program files\starcraft\starcraft.exe |
"{B2822383-D59F-4625-8A96-3363F850900D}" = dir=in | app=c:\program files\avg\avg9\avgemc.exe |
"{C8C10538-EAB4-47F2-864D-0F4E7BA69961}" = protocol=17 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"{E32BF5A9-11E5-4A4B-884A-2308CECC5F26}" = dir=in | app=c:\program files\avg\avg9\avgupd.exe |
"{E86A01DA-2EE0-41BA-9B9B-10CD1EBC5A0F}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{F06C799F-2E61-4C86-AF40-9395C7A7F3CD}" = protocol=6 | dir=in | app=c:\program files\steam\steam.exe |
"TCP Query User{1770B185-889F-49FE-A07A-71B25C5D6C3F}C:\program files\bittorrent\bittorrent.exe" = protocol=6 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"TCP Query User{181877FE-7CAB-40C8-B32C-5CD01CFE8A9E}C:\program files\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
"TCP Query User{26F2A05D-5664-4A5D-9877-7884C24578CC}C:\program files\logitech\desktop messenger\8876480\program\backweb-8876480.exe" = protocol=6 | dir=in | app=c:\program files\logitech\desktop messenger\8876480\program\backweb-8876480.exe |
"TCP Query User{483C07A3-2A46-4DE2-88B7-F55C29D97243}C:\program files\safari\safari.exe" = protocol=6 | dir=in | app=c:\program files\safari\safari.exe |
"TCP Query User{4A0BC0BF-2F63-4354-ABCC-994B8123644B}C:\program files\bittorrent\bittorrent.exe" = protocol=6 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"TCP Query User{63834C13-DC93-4ADE-B6D3-E1226D64ECAC}C:\program files\logitech\desktop messenger\8876480\program\backweb-8876480.exe" = protocol=6 | dir=in | app=c:\program files\logitech\desktop messenger\8876480\program\backweb-8876480.exe |
"UDP Query User{0D455044-0C55-4DEE-B168-E0291135B963}C:\program files\safari\safari.exe" = protocol=17 | dir=in | app=c:\program files\safari\safari.exe |
"UDP Query User{37ABA933-C836-430E-BF2F-C00B26C9F439}C:\program files\logitech\desktop messenger\8876480\program\backweb-8876480.exe" = protocol=17 | dir=in | app=c:\program files\logitech\desktop messenger\8876480\program\backweb-8876480.exe |
"UDP Query User{5A5EF40B-FE9F-4439-8188-EB20B1191631}C:\program files\bittorrent\bittorrent.exe" = protocol=17 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"UDP Query User{65A084D5-7402-4490-832D-89A5FE5461DF}C:\program files\bittorrent\bittorrent.exe" = protocol=17 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"UDP Query User{763984DA-1231-4314-99F1-152E78D8A4E4}C:\program files\logitech\desktop messenger\8876480\program\backweb-8876480.exe" = protocol=17 | dir=in | app=c:\program files\logitech\desktop messenger\8876480\program\backweb-8876480.exe |
"UDP Query User{CB62250E-6EA7-48A1-A192-586FF4D1133D}C:\program files\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\java.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{0CB9668D-F979-4F31-B8B8-67FE90F929F8}" = Bonjour
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{26A24AE4-039D-4CA4-87B4-2F83216016FF}" = Java™ 6 Update 18
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{3248F0A8-6813-11D6-A77B-00B0D0160000}" = Java™ SE Runtime Environment 6
"{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}" = Sonic Activation Module
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{7AB3A249-FB81-416B-917A-A2A10E74C503}" = iTunes
"{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{85991ED2-010C-4930-96FA-52F43C2CE98A}" = Apple Mobile Device Support
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-A70800000002}" = Adobe Reader 7.0.8
"{AFAC914D-9E83-4A89-8ABE-427521C82CCF}" = Safari
"{B2D328BE-45AD-4D92-96F9-2151490A203E}" = Apple Application Support
"{C4124E95-5061-4776-8D5D-E3D931C778E1}" = Microsoft VC9 runtime libraries
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{EFAD4066-CAF3-4B27-9669-12EED352C376}" = NVIDIANetworkDiagnostic
"{EFB21DE7-8C19-4A88-BB28-A766E16493BC}" = Adobe Photoshop CS
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AIM_7" = AIM 7
"Audacity 1.3 Beta (Unicode)_is1" = Audacity 1.3.11 (Unicode)
"AVG9Uninstall" = AVG Free 9.0
"AviSynth" = AviSynth 2.5
"BitTorrent" = BitTorrent
"CCleaner" = CCleaner
"Cg Toolkit_is1" = NVIDIA Cg Toolkit 2.2 October 2009
"CNXT_MODEM_PCI_VEN_14F1&DEV;_2F20&SUBSYS;_200F14F1" = Conexant D850 PCI V.92 Modem
"InstallShield_{EFAD4066-CAF3-4B27-9669-12EED352C376}" = NVIDIANetworkDiagnostic
"KLiteCodecPack_is1" = K-Lite Codec Pack 5.6.1 (Standard)
"LAME for Audacity_is1" = LAME v3.98.2 for Audacity
"LimeWire" = LimeWire 5.4.6
"LiveUpdate" = LiveUpdate 3.2 (Symantec Corporation)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft DirectX SDK (August 2009)" = Microsoft DirectX SDK (August 2009)
"NVIDIA Drivers" = NVIDIA Drivers
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"Starcraft" = Starcraft
"SymSetup.{5AA2CD16-706F-41f3-87C5-2B5A031F2B3B}" = Norton Internet Security (Symantec Corporation)
"TuxGuitar_0" = TuxGuitar 1.2
"Videora iPod Converter" = Videora iPod Converter 5.03
"WinRAR archiver" = WinRAR archiver

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 6/13/2010 12:34:11 PM | Computer Name = Jay-PC | Source = Application Error | ID = 1000
Description = Faulting application audacity.exe, version 1.3.11.0, time stamp 0x4b54d68b,
faulting module wxbase28u_vc_custom.dll, version 2.8.10.0, time stamp 0x4a47bb6f,
exception code 0xc0000005, fault offset 0x00047110, process id 0x52c, application
start time 0x01cb0b162da1b039.

Error - 6/13/2010 12:34:14 PM | Computer Name = Jay-PC | Source = Application Error | ID = 1000
Description = Faulting application audacity.exe, version 1.3.11.0, time stamp 0x4b54d68b,
faulting module ntdll.dll, version 6.0.6002.18005, time stamp 0x49e03821, exception
code 0xc0000005, fault offset 0x000675ff, process id 0x52c, application start time
0x01cb0b162da1b039.

Error - 6/14/2010 7:14:44 PM | Computer Name = Jay-PC | Source = Application Hang | ID = 1002
Description = The program ScmDraft2.exe version 0.8.0.0 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 1390 Start Time: 01cb0c162e5ff11e Termination Time: 6

Error - 6/14/2010 7:18:19 PM | Computer Name = Jay-PC | Source = Application Hang | ID = 1002
Description = The program ScmDraft2.exe version 0.8.0.0 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 1324 Start Time: 01cb0c17a455bcae Termination Time: 4

Error - 6/15/2010 12:40:31 AM | Computer Name = Jay-PC | Source = Application Hang | ID = 1002
Description = The program iexplore.exe version 8.0.6001.18928 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 16a4 Start Time: 01cb0c384657a510 Termination Time: 63

Error - 6/15/2010 10:47:30 PM | Computer Name = Jay-PC | Source = Application Hang | ID = 1002
Description = The program ScmDraft2.exe version 0.8.0.0 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: df4 Start Time: 01cb0ce258020af6 Termination Time: 4

Error - 6/15/2010 10:52:20 PM | Computer Name = Jay-PC | Source = Application Hang | ID = 1002
Description = The program ScmDraft2.exe version 0.8.0.0 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 9f4 Start Time: 01cb0cfe443eed06 Termination Time: 3

Error - 6/16/2010 11:32:52 PM | Computer Name = Jay-PC | Source = Application Hang | ID = 1002
Description = The program Explorer.EXE version 6.0.6002.18005 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: d40 Start Time: 01cb0dc60f5c9e34 Termination Time: 60000

Error - 6/17/2010 1:28:29 AM | Computer Name = Jay-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 6/17/2010 1:28:30 AM | Computer Name = Jay-PC | Source = Windows Search Service | ID = 3013
Description =

[ System Events ]
Error - 11/17/2009 6:26:22 PM | Computer Name = Jay-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 11/17/2009 6:26:22 PM | Computer Name = Jay-PC | Source = Service Control Manager | ID = 7026
Description =


< End of report >
Hi,


Download GMER from Here. Note the file's name and save it to your root folder, such as C:\.
  • Disconnect from the Internet and close all running programs.
  • Temporarily disable any real-time active protection so your security program drivers will not conflict with this file.
  • Click on this link to see a list of programs that should be disabled.
  • Double-click on the downloaded file to start the program. (If running Vista, right click on it and select "Run as an Administrator")
  • Allow the driver to load if asked.
  • You may be prompted to scan immediately if it detects rootkit activity.
  • If you are prompted to scan your system click "No", save the log and post back the results.
  • If not prompted, click the "Rootkit/Malware" tab.
  • On the right-side, all items to be scanned should be checked by default except for "Show All". Leave that box unchecked.
  • Select all drives that are connected to your system to be scanned.
  • Click the Scan button to begin. (Please be patient as it can take some time to complete)
  • When the scan is finished, click Save to save the scan results to your Desktop.
  • Save the file as Results.log and copy/paste the contents in your next reply.
  • Exit the program and re-enable all active protection when done.
I disabled active protection and downloaded the file to C as you said. After launching it, I clicked Scan. A few minutes later, my computer crashed and displayed the blue screen, then restarted. *Edit: I tried it again, but then this time it just froze during the scan. *Edit 2: Now the lag has taken over. It takes about 30 seconds to minimize or move from window to window. Certain websites won't connect even though my internet is fine (Namely Facebook and Google).
Hi,


Please go here and have a look how you can disable your security software.

Download Combofix from any of the links below but rename it to before saving it to your desktop.

Link 1
Link 2



——————————————————————–

Double click on the renamed Combofix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it will produce a log for you. Please include the C:\ComboFix.txt in your next reply.

This tool is not a toy and not for everyday use.
ComboFix SHOULD NOT be used unless requested by a forum helper


If you need help, see this link:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix
ComboFix 10-06-23.01 - Jay 3/2010 Wed 13:03:28.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.949.82.1033.18.958.502 [GMT -7:00]
Running from: c:\users\[removed]\Desktop\schrauber.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((( Files Created from 2010-05-23 to 2010-06-23 )))))))))))))))))))))))))))))))
.

2010-06-23 20:10 . 2010-06-23 20:11 ——– d—–w- c:\users\Jay\AppData\Local\temp
2010-06-23 20:10 . 2010-06-23 20:10 ——– d—–w- c:\users\Public\AppData\Local\temp
2010-06-23 20:10 . 2010-06-23 20:10 ——– d—–w- c:\users\Default\AppData\Local\temp
2010-06-23 19:59 . 2010-06-23 20:00 ——– d—–w- C:\32788R22FWJFW
2010-06-23 19:33 . 2009-11-08 17:55 99176 —-a-w- c:\windows\system32\PresentationHostProxy.dll
2010-06-23 19:33 . 2009-11-08 17:55 295264 —-a-w- c:\windows\system32\PresentationHost.exe
2010-06-23 19:33 . 2009-11-08 17:55 49472 —-a-w- c:\windows\system32\netfxperf.dll
2010-06-23 19:33 . 2009-11-08 17:55 297808 —-a-w- c:\windows\system32\mscoree.dll
2010-06-23 19:33 . 2009-11-08 17:55 1130824 —-a-w- c:\windows\system32\dfshim.dll
2010-06-23 00:13 . 2010-04-16 16:43 28672 —-a-w- c:\windows\system32\Apphlpdm.dll
2010-06-23 00:13 . 2010-04-16 14:39 4240384 —-a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2010-06-16 22:25 . 2010-06-16 22:25 ——– d—–w- c:\program files\iPod
2010-06-16 22:24 . 2010-06-16 22:26 ——– d—–w- c:\program files\iTunes
2010-06-16 22:18 . 2010-06-16 22:18 ——– d—–w- c:\program files\Bonjour
2010-06-16 22:17 . 2010-06-16 22:17 72504 —-a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.2.0.61\SetupAdmin.exe
2010-06-10 04:48 . 2010-06-10 04:48 ——– d—–w- c:\windows\Sun
2010-06-09 22:26 . 2010-06-09 22:26 71992 —-a-w- c:\programdata\Apple Computer\Installer Cache\Safari 5.33.16.0\SetupAdmin.exe
2010-06-08 22:38 . 2010-04-05 17:01 67072 —-a-w- c:\windows\system32\asycfilt.dll
2010-06-08 22:38 . 2010-05-26 14:47 289792 —-a-w- c:\windows\system32\atmfd.dll
2010-06-08 22:38 . 2010-05-26 17:06 34304 —-a-w- c:\windows\system32\atmlib.dll
2010-06-05 00:50 . 2010-06-05 00:50 ——– d—–w- C:\$AVG
2010-06-04 23:26 . 2010-06-04 23:26 12464 —-a-w- c:\windows\system32\avgrsstx.dll
2010-06-04 23:26 . 2010-06-04 23:35 242896 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2010-06-04 23:26 . 2010-06-04 23:26 216200 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2010-06-04 23:26 . 2010-06-04 23:35 29584 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-06-04 23:26 . 2010-06-23 19:39 ——– d—–w- c:\windows\system32\drivers\Avg
2010-05-29 03:09 . 2010-04-23 14:13 2048 —-a-w- c:\windows\system32\tzres.dll
2010-05-29 02:07 . 2010-04-29 22:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-05-29 02:07 . 2010-05-29 02:07 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-05-29 02:07 . 2010-04-29 22:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-05-24 22:13 . 2010-05-24 22:13 ——– d—–w- C:\acccore

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-23 04:44 . 2009-10-12 21:58 ——– d—a-w- c:\users\Jay\AppData\Roaming\BitTorrent
2010-06-21 23:20 . 2010-05-23 19:59 ——– d—–w- c:\program files\Steam
2010-06-17 02:40 . 2010-02-21 04:41 ——– d—–w- c:\program files\CCleaner
2010-06-16 22:25 . 2009-10-12 22:08 ——– d—–w- c:\program files\Common Files\Apple
2010-06-16 02:30 . 2009-12-27 19:36 ——– d—–w- c:\program files\Starcraft
2010-06-15 03:07 . 2010-02-23 04:50 ——– d—a-w- c:\users\Jay\AppData\Roaming\Audacity
2010-06-09 22:28 . 2010-02-04 22:07 ——– d—–w- c:\program files\Safari
2010-06-09 03:30 . 2009-10-20 04:15 2482 —-a-w- c:\users\Jay\AppData\Roaming\wklnhst.dat
2010-06-08 22:51 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2010-06-07 03:55 . 2010-04-09 06:58 ——– d—–w- c:\program files\FullMusicP
2010-06-05 00:32 . 2007-08-27 22:31 ——– d—–w- c:\program files\Microsoft Works
2010-06-04 23:23 . 2010-02-21 05:20 ——– d—–w- c:\programdata\avg9
2010-05-23 20:01 . 2010-03-12 00:12 ——– d—–w- c:\program files\Common Files\Steam
2010-05-21 21:14 . 2009-10-15 22:56 221568 ——w- c:\windows\system32\MpSigStub.exe
2010-05-18 23:35 . 2010-05-18 23:35 91424 —-a-w- c:\windows\system32\dnssd.dll
2010-05-18 23:35 . 2010-05-18 23:35 107808 —-a-w- c:\windows\system32\dns-sd.exe
2010-05-10 01:12 . 2009-10-12 21:09 67552 —-a-w- c:\users\Jay\AppData\Local\GDIPFONTCACHEV1.DAT
2010-05-04 05:59 . 2010-06-08 22:37 916480 —-a-w- c:\windows\system32\wininet.dll
2010-05-04 05:55 . 2010-06-08 22:37 109056 —-a-w- c:\windows\system32\iesysprep.dll
2010-05-04 05:55 . 2010-06-08 22:37 71680 —-a-w- c:\windows\system32\iesetup.dll
2010-05-04 04:31 . 2010-06-08 22:37 133632 —-a-w- c:\windows\system32\ieUnatt.exe
2010-05-01 14:13 . 2010-06-08 22:37 2037248 —-a-w- c:\windows\system32\win32k.sys
2010-04-16 16:43 . 2010-06-23 00:13 173056 —-a-w- c:\windows\AppPatch\AcXtrnal.dll
2010-04-16 16:43 . 2010-06-23 00:13 458752 —-a-w- c:\windows\AppPatch\AcSpecfc.dll
2010-04-16 16:43 . 2010-06-23 00:13 542720 —-a-w- c:\windows\AppPatch\AcLayers.dll
2010-04-16 16:43 . 2010-06-23 00:13 2159616 —-a-w- c:\windows\AppPatch\AcGenral.dll
2010-04-16 02:10 . 2010-04-16 02:10 509552 —-a-w- c:\programdata\Google\Google Toolbar\Update\gtb6B00.tmp.exe
2010-04-09 06:58 . 2010-04-09 06:58 65536 —-a-w- c:\windows\IFinst27.exe
2010-04-08 22:19 . 2010-04-08 19:15 286720 ——w- c:\windows\Setup1.exe
2010-04-08 22:19 . 2010-04-08 19:15 73216 —-a-w- c:\windows\ST6UNST.EXE
2007-08-28 05:51 . 2007-08-28 05:48 8192 –sha-w- c:\windows\Users\Default\NTUSER.DAT
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-17 4907008]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 81920]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 221184]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-18 421888]
"fullmusic_info"="c:\program files\FullMusicP\fullmusic_info.exe" [2010-03-05 861184]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-06-04 2065248]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-06-15 141624]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-11-9 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(B):03,08,46,34,96,56,ca,01

R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [x]
R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [x]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-02-10 135664]
R3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [x]
R3 U1expskpn_3.0;U1expskpn_3.0; [x]
S0 amacpi;Microsoft Away Mode System;c:\windows\system32\DRIVERS\null.sys [2008-01-19 4608]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2010-06-04 216200]
S1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\Drivers\avgtdix.sys [2010-06-04 242896]
S2 AERTFilters;Andrea RT Filters Service;c:\windows\system32\AERTSrv.exe [2007-12-05 77824]
S2 avg9emc;AVG Free E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [2010-06-04 916760]
S2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [2010-06-04 308064]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder

2010-06-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-10 08:58]

2010-06-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-10 08:58]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = localhost;*.local
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-23 13:11
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2010-06-23 13:13:33
ComboFix-quarantined-files.txt 2010-06-23 20:13
ComboFix2.txt 2010-05-29 02:46

Pre-Run: 107,332,673,536 bytes free
Post-Run: 107,492,233,216 bytes free

- - End Of File - - 6ED33A98A8E9A429CBCFECCB155F8DE4


*Some websites still won't work. And I still get lag, except less.
ComboFix 10-05-28.02 - Jay 8/2010 Fri 19:29:03.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.949.82.1033.18.958.164 [GMT -7:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\Jay\Desktop\CFScript.txt
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Created a new restore point

FILE ::
"c:\users\jay\appdata\roaming\bpzmnq.dat"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\users\Jay\AppData\Local\Temp\dnscPlay.dll
c:\users\jay\appdata\roaming\bpzmnq.dat
c:\users\Jay\AppData\Roaming\skynet.dat
c:\users\Jay\AppData\Roaming\wp3.dat
c:\users\Jay\AppData\Roaming\wp4.dat
c:\windows\Tasks.\ijydccia.job

Infected copy of c:\windows\system32\drivers\volmgr.sys was found and disinfected
Restored copy from - Kitty had a snack :P
.
((((((((((((((((((((((((( Files Created from 2010-04-28 to 2010-05-29 )))))))))))))))))))))))))))))))
.

2010-05-29 02:39 . 2010-05-29 02:41 ——– d—–w- c:\users\Jay\AppData\Local\temp
2010-05-29 02:07 . 2010-04-29 22:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-05-29 02:07 . 2010-05-29 02:07 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-05-29 02:07 . 2010-04-29 22:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-05-24 22:13 . 2010-05-24 22:13 ——– d—–w- C:\acccore
2010-05-23 19:59 . 2010-05-26 22:07 ——– d—–w- c:\program files\Steam
2010-05-11 22:53 . 2010-01-29 15:40 738816 —-a-w- c:\windows\system32\inetcomm.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-28 22:56 . 2009-12-27 19:36 ——– d—–w- c:\program files\Starcraft
2010-05-28 04:21 . 2009-10-12 21:58 ——– d—a-w- c:\users\Jay\AppData\Roaming\BitTorrent
2010-05-23 20:56 . 2010-02-21 04:41 ——– d—–w- c:\program files\CCleaner
2010-05-23 20:01 . 2010-03-12 00:12 ——– d—–w- c:\program files\Common Files\Steam
2010-05-21 21:14 . 2009-10-15 22:56 221568 ——w- c:\windows\system32\MpSigStub.exe
2010-05-20 04:14 . 2010-02-23 04:50 ——– d—a-w- c:\users\Jay\AppData\Roaming\Audacity
2010-05-20 01:54 . 2009-10-20 04:15 2414 —-a-w- c:\users\Jay\AppData\Roaming\wklnhst.dat
2010-05-11 23:06 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2010-05-10 01:12 . 2009-10-12 21:09 67552 —-a-w- c:\users\Jay\AppData\Local\GDIPFONTCACHEV1.DAT
2010-04-28 23:00 . 2010-04-28 22:59 ——– d—–w- c:\program files\iTunes
2010-04-28 22:59 . 2010-04-28 22:59 ——– d—–w- c:\program files\iPod
2010-04-28 22:59 . 2009-10-12 22:08 ——– d—–w- c:\program files\Common Files\Apple
2010-04-28 22:56 . 2010-04-28 22:56 ——– d—–w- c:\program files\Bonjour
2010-04-28 22:52 . 2010-04-28 22:52 73000 —-a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.1.1.11\SetupAdmin.exe
2010-04-16 22:29 . 2009-12-14 05:08 ——– d—–w- c:\program files\Google
2010-04-16 02:10 . 2010-04-16 02:10 509552 —-a-w- c:\programdata\Google\Google Toolbar\Update\gtb6B00.tmp.exe
2010-04-09 21:48 . 2010-04-09 21:42 ——– d—–w- c:\program files\ElcomSoft
2010-04-09 21:38 . 2010-04-09 06:58 ——– d—–w- c:\program files\FullMusicP
2010-04-09 06:59 . 2010-04-09 06:58 ——– d—–w- c:\program files\fullmusic
2010-04-09 06:58 . 2010-04-09 06:58 65536 —-a-w- c:\windows\IFinst27.exe
2010-04-08 22:19 . 2010-04-08 19:15 286720 ——w- c:\windows\Setup1.exe
2010-04-08 22:19 . 2010-04-08 19:15 73216 —-a-w- c:\windows\ST6UNST.EXE
2010-04-08 20:20 . 2010-04-08 20:20 91424 —-a-w- c:\windows\system32\dnssd.dll
2010-04-08 20:20 . 2010-04-08 20:20 107808 —-a-w- c:\windows\system32\dns-sd.exe
2010-04-03 17:21 . 2009-10-12 22:27 ——– d—a-w- c:\users\Jay\AppData\Roaming\Apple Computer
2010-04-03 03:30 . 2010-04-03 03:29 ——– d—–w- c:\programdata\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-04-03 03:26 . 2010-04-03 03:26 ——– d—–w- c:\program files\QuickTime
2010-04-02 05:08 . 2009-10-12 21:18 ——– d—–w- c:\program files\AIM
2010-04-02 05:08 . 2009-10-12 21:19 ——– d—–w- c:\program files\Common Files\Software Update Utility
2010-03-21 03:55 . 2010-03-21 03:55 81920 ——w- c:\windows\bwUnin-6.1.4.68-8876480L.exe
2010-03-11 22:48 . 2010-03-11 22:48 79144 —-a-w- c:\programdata\Apple Computer\Installer Cache\Safari 5.31.22.7\SetupAdmin.exe
2010-03-05 14:01 . 2010-04-14 03:40 420352 —-a-w- c:\windows\system32\vbscript.dll
2007-08-28 05:51 . 2007-08-28 05:48 8192 –sha-w- c:\windows\Users\Default\NTUSER.DAT
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-17 4907008]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 81920]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 221184]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-18 421888]
"fullmusic_info"="c:\program files\FullMusicP\fullmusic_info.exe" [2010-03-05 861184]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-04-25 142120]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-04-29 1090952]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-11-9 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"VistaSp2"=hex(B):03,08,46,34,96,56,ca,01

R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [x]
R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [x]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-02-10 135664]
R3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [x]
R3 U1expskpn_3.0;U1expskpn_3.0; [x]
S0 amacpi;Microsoft Away Mode System;c:\windows\system32\DRIVERS\null.sys [2008-01-19 4608]
S2 AERTFilters;Andrea RT Filters Service;c:\windows\system32\AERTSrv.exe [2007-12-05 77824]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder

2010-05-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-10 08:58]

2010-05-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-10 08:58]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = localhost;*.local
.
- - - - ORPHANS REMOVED - - - -

WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-05-28 19:41
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
———————— Other Running Processes ————————
.
c:\windows\system32\nvvsvc.exe
c:\windows\system32\rundll32.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\DRIVERS\xaudio.exe
c:\windows\system32\conime.exe
c:\\?\c:\windows\system32\wbem\WMIADAP.EXE
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Completion time: 2010-05-28 19:46:24 - machine was rebooted
ComboFix-quarantined-files.txt 2010-05-29 02:46

Pre-Run: 163,499,597,824 bytes free
Post-Run: 163,474,575,360 bytes free

- - End Of File - - 671E4421A5672340793FAFB581ECCDAB
Hi,

[external image: Posted Image] Please download Malwarebytes' Anti-Malware from Here.

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediatly.




Please run a free online scan with the ESET Online Scanner
Note: You will need to use Internet Explorer for this scan
  • Tick the box next to YES, I accept the Terms of Use
  • Click Start
  • When asked, allow the ActiveX control to install
  • Click Start
  • Make sure that the options Remove found threats and the option Scan unwanted applications is checked
  • Click Scan (This scan can take several hours, so please be patient)
  • Once the scan is completed, you may close the window
  • Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  • Copy and paste that log as a reply to this topic





Please open OTL, set the extra registry tab to use safe list and hit the run scan button, post back with the 2 logfiles.

How is it running now?
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4259

Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18928

6/29/2010 7:08:17 PM
mbam-log-2010-06-29 (19-08-17).txt

Scan type: Quick scan
Objects scanned: 122887
Time elapsed: 8 minute(s), 9 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)



ESETSmartInstaller@High as CAB hook log:
OnlineScanner.ocx - registred OK



OTL logfile created on: 6/29/2010 9:47:41 PM - Run 2
OTL by OldTimer - Version 3.2.7.0 Folder = C:\Users\Jay\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18928)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

958.00 Mb Total Physical Memory | 230.00 Mb Available Physical Memory | 24.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 44.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 288.04 Gb Total Space | 30.23 Gb Free Space | 10.50% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 6.21 Gb Free Space | 62.05% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: JAY-PC
Current User Name: Jay
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2010/06/29 21:46:42 | 000,574,464 | —- | M] (OldTimer Tools) – C:\Users\Jay\Desktop\OTL.exe
PRC - [2010/06/12 20:50:47 | 000,231,888 | —- | M] (Adobe Systems, Inc.) – C:\Windows\System32\Macromed\Flash\FlashUtil10h_ActiveX.exe
PRC - [2010/06/10 21:03:08 | 000,144,176 | —- | M] (Apple Inc.) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2010/06/04 16:35:55 | 002,065,248 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgtray.exe
PRC - [2010/06/04 16:35:51 | 000,515,424 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgrsx.exe
PRC - [2010/06/04 16:35:50 | 000,620,896 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgnsx.exe
PRC - [2010/06/04 16:35:43 | 000,722,784 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgcsrvx.exe
PRC - [2010/06/04 16:35:38 | 001,101,152 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgchsvx.exe
PRC - [2010/06/04 16:24:58 | 000,916,760 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgemc.exe
PRC - [2010/06/04 16:24:53 | 000,308,064 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgwdsvc.exe
PRC - [2010/03/08 14:04:49 | 003,972,440 | —- | M] (AOL Inc.) – C:\Program Files\AIM\aim.exe
PRC - [2009/04/10 23:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) – C:\Windows\explorer.exe
PRC - [2009/04/10 23:27:28 | 000,069,120 | —- | M] (Microsoft Corporation) – C:\Windows\System32\conime.exe
PRC - [2008/01/17 07:22:20 | 004,907,008 | —- | M] (Realtek Semiconductor) – C:\Windows\RtHDVCpl.exe
PRC - [2007/12/05 06:17:24 | 000,077,824 | —- | M] (Andrea Electronics Corporation) – C:\Windows\System32\AERTSrv.exe
PRC - [2006/10/03 09:37:04 | 000,081,920 | —- | M] (Macrovision Corporation) – C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe


========== Modules (SafeList) ==========

MOD - [2010/06/29 21:46:42 | 000,574,464 | —- | M] (OldTimer Tools) – C:\Users\Jay\Desktop\OTL.exe
MOD - [2009/04/10 23:21:38 | 001,686,016 | —- | M] (Microsoft Corporation) – C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll
MOD - [2008/01/19 00:33:00 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msscript.ocx


========== Win32 Services (SafeList) ==========

SRV - File not found [On_Demand | Stopped] – – (U1expskpn_3.0)
SRV - File not found [On_Demand | Stopped] – – (stllssvr)
SRV - [2010/06/21 15:31:26 | 000,395,048 | —- | M] (Valve Corporation) [On_Demand | Stopped] – C:\Program Files\Common Files\Steam\SteamService.exe – (Steam Client Service)
SRV - [2010/06/10 21:03:08 | 000,144,176 | —- | M] (Apple Inc.) [Auto | Running] – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe – (Apple Mobile Device)
SRV - [2010/06/04 16:24:58 | 000,916,760 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files\AVG\AVG9\avgemc.exe – (avg9emc)
SRV - [2010/06/04 16:24:53 | 000,308,064 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files\AVG\AVG9\avgwdsvc.exe – (avg9wd)
SRV - [2010/03/18 13:16:28 | 000,753,504 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe – (WPFFontCache_v0400)
SRV - [2010/03/18 13:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2009/09/24 18:27:04 | 000,793,088 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\System32\FntCache.dll – (FontCache)
SRV - [2008/01/19 00:38:24 | 000,272,952 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2007/12/05 06:17:24 | 000,077,824 | —- | M] (Andrea Electronics Corporation) [Auto | Running] – C:\Windows\System32\AERTSrv.exe – (AERTFilters)
SRV - [2007/03/19 10:44:44 | 000,070,656 | —- | M] () [On_Demand | Stopped] – C:\Program Files\DellSupport\brkrsvc.exe – (DSBrokerService)


========== Driver Services (SafeList) ==========

DRV - [2010/06/04 16:35:51 | 000,242,896 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\Windows\System32\drivers\avgtdix.sys – (AvgTdiX)
DRV - [2010/06/04 16:35:51 | 000,029,584 | —- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] – C:\Windows\System32\drivers\avgmfx86.sys – (AvgMfx86)
DRV - [2010/06/04 16:26:11 | 000,216,200 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\Windows\System32\drivers\avgldx86.sys – (AvgLdx86)
DRV - [2009/07/14 19:54:00 | 009,557,216 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\nvlddmkm.sys – (nvlddmkm)
DRV - [2008/01/24 11:06:40 | 002,054,872 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\RTKVHDA.sys – (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2007/08/27 22:48:42 | 000,020,152 | —- | M] (VIA Technologies, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\viaide.sys – (viaide)
DRV - [2007/08/27 22:48:42 | 000,019,128 | —- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\cmdide.sys – (cmdide)
DRV - [2007/08/27 22:48:42 | 000,017,592 | —- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\aliide.sys – (aliide)
DRV - [2007/08/09 18:12:30 | 000,110,624 | —- | M] (NVIDIA Corporation) [Kernel | Boot | Running] – C:\Windows\system32\drivers\nvstor32.sys – (nvstor32)
DRV - [2007/03/23 04:09:16 | 000,129,832 | —- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\nvrd32.sys – (nvrd32)
DRV - [2007/03/15 06:57:30 | 001,059,112 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\nvmfdx32.sys – (NVENETFD)
DRV - [2007/02/25 10:10:48 | 000,005,376 | –S- | M] (Gteko Ltd.) [Kernel | Auto | Running] – C:\Windows\System32\drivers\dsunidrv.sys – (dsunidrv)
DRV - [2006/11/02 02:51:45 | 000,900,712 | —- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\ql2300.sys – (ql2300)
DRV - [2006/11/02 02:51:38 | 000,420,968 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\adp94xx.sys – (adp94xx)
DRV - [2006/11/02 02:51:34 | 000,316,520 | —- | M] (Emulex) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\elxstor.sys – (elxstor)
DRV - [2006/11/02 02:51:32 | 000,297,576 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\adpahci.sys – (adpahci)
DRV - [2006/11/02 02:51:25 | 000,235,112 | —- | M] (ULi Electronics Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\uliahci.sys – (uliahci)
DRV - [2006/11/02 02:51:25 | 000,232,040 | —- | M] (Intel Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\iastorv.sys – (iaStorV)
DRV - [2006/11/02 02:51:00 | 000,147,048 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\adpu320.sys – (adpu320)
DRV - [2006/11/02 02:50:45 | 000,115,816 | —- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\ulsata2.sys – (ulsata2)
DRV - [2006/11/02 02:50:41 | 000,112,232 | —- | M] (VIA Technologies Inc.,Ltd) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\vsmraid.sys – (vsmraid)
DRV - [2006/11/02 02:50:35 | 000,106,088 | —- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\ql40xx.sys – (ql40xx)
DRV - [2006/11/02 02:50:35 | 000,098,408 | —- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\ulsata.sys – (UlSata)
DRV - [2006/11/02 02:50:35 | 000,098,408 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\adpu160m.sys – (adpu160m)
DRV - [2006/11/02 02:50:24 | 000,088,680 | —- | M] (NVIDIA Corporation) [Kernel | Boot | Running] – C:\Windows\system32\drivers\nvraid.sys – (nvraid)
DRV - [2006/11/02 02:50:19 | 000,045,160 | —- | M] (IBM Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\nfrd960.sys – (nfrd960)
DRV - [2006/11/02 02:50:17 | 000,041,576 | —- | M] (Intel Corp./ICP vortex GmbH) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\iirsp.sys – (iirsp)
DRV - [2006/11/02 02:50:16 | 000,071,784 | —- | M] (Silicon Integrated Systems) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\sisraid4.sys – (SiSRaid4)
DRV - [2006/11/02 02:50:13 | 000,040,040 | —- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\nvstor.sys – (nvstor)
DRV - [2006/11/02 02:50:11 | 000,071,272 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\djsvs.sys – (aic78xx)
DRV - [2006/11/02 02:50:10 | 000,067,688 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\arcsas.sys – (arcsas)
DRV - [2006/11/02 02:50:10 | 000,065,640 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\lsi_scsi.sys – (LSI_SCSI)
DRV - [2006/11/02 02:50:10 | 000,038,504 | —- | M] (Silicon Integrated Systems Corp.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\sisraid2.sys – (SiSRaid2)
DRV - [2006/11/02 02:50:10 | 000,037,480 | —- | M] (Hewlett-Packard Company) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\hpcisss.sys – (HpCISSs)
DRV - [2006/11/02 02:50:09 | 000,067,688 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\arc.sys – (arc)
DRV - [2006/11/02 02:50:09 | 000,035,944 | —- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\iteraid.sys – (iteraid)
DRV - [2006/11/02 02:50:07 | 000,035,944 | —- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\iteatapi.sys – (iteatapi)
DRV - [2006/11/02 02:50:05 | 000,065,640 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\lsi_sas.sys – (LSI_SAS)
DRV - [2006/11/02 02:50:05 | 000,035,944 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\symc8xx.sys – (Symc8xx)
DRV - [2006/11/02 02:50:04 | 000,065,640 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\lsi_fc.sys – (LSI_FC)
DRV - [2006/11/02 02:50:03 | 000,034,920 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\sym_u3.sys – (Sym_u3)
DRV - [2006/11/02 02:49:59 | 000,033,384 | —- | M] (LSI Logic Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\mraid35x.sys – (Mraid35x)
DRV - [2006/11/02 02:49:56 | 000,031,848 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\sym_hi.sys – (Sym_hi)
DRV - [2006/11/02 02:49:53 | 000,028,776 | —- | M] (LSI Logic Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\megasas.sys – (megasas)
DRV - [2006/11/02 01:25:24 | 000,071,808 | —- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\brserid.sys – (Brserid) Brother MFC Serial Port Interface Driver (WDM)
DRV - [2006/11/02 01:24:47 | 000,011,904 | —- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\brusbser.sys – (BrUsbSer)
DRV - [2006/11/02 01:24:46 | 000,005,248 | —- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\brfiltup.sys – (BrFiltUp)
DRV - [2006/11/02 01:24:45 | 000,013,568 | —- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\brfiltlo.sys – (BrFiltLo)
DRV - [2006/11/02 01:24:44 | 000,062,336 | —- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\brserwdm.sys – (BrSerWdm)
DRV - [2006/11/02 01:24:44 | 000,012,160 | —- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\brusbmdm.sys – (BrUsbMdm)
DRV - [2006/11/02 00:36:50 | 000,020,608 | —- | M] (N-trig Innovative Technologies) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\ntrigdigi.sys – (ntrigdigi)
DRV - [2006/11/02 00:36:43 | 002,028,032 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\atikmdag.sys – (R300)
DRV - [2006/11/02 00:30:55 | 000,200,704 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\e1e6032.sys – (e1express) Intel®
DRV - [2006/11/02 00:30:54 | 000,117,760 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\E1G60I32.sys – (E1G60) Intel®
DRV - [2006/10/18 11:09:26 | 000,986,624 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\HSX_DPV.sys – (HSF_DPV)
DRV - [2006/10/18 11:08:18 | 000,258,048 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\HSXHWBS2.sys – (HSXHWBS2)
DRV - [2006/10/18 11:08:04 | 000,659,968 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\HSX_CNXT.sys – (winachsf)
DRV - [2006/10/05 15:07:28 | 000,004,736 | —- | M] (Gteko Ltd.) [Kernel | On_Demand | Stopped] – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys – (DSproct)
DRV - [2006/08/04 17:39:10 | 000,008,192 | —- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] – C:\Windows\System32\drivers\XAudio.sys – (XAudio)
DRV - [2005/01/31 08:20:04 | 000,211,712 | —- | M] (Logitech Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\LV561AV.SYS – (PID_0928) Logitech QuickCam Express(PID_0928)
DRV - [2005/01/31 08:12:46 | 000,022,016 | —- | M] (Logitech Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\LVUSBSta.sys – (LVUSBSta)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = localhost;*.local


[2009/10/17 09:49:29 | 000,000,000 | —D | M] – C:\Users\Jay\AppData\Roaming\Mozilla\Extensions
[2009/10/17 09:49:29 | 000,000,000 | —D | M] – C:\Users\Jay\AppData\Roaming\Mozilla\Extensions\[removed]

O1 HOSTS File: ([2010/05/28 19:41:19 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [fullmusic_info] C:\Program Files\FullMusicP\fullmusic_info.exe ()
O4 - HKLM..\Run: [ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (Macrovision Corporation)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.10.115.cab (Reg Error: Key error.)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - AppInit_DLLs: (C:\Windows\System32\avgrsstx.dll) - C:\Windows\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 14:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found

========== Files/Folders - Created Within 30 Days ==========

[2010/06/29 21:46:38 | 000,574,464 | —- | C] (OldTimer Tools) – C:\Users\Jay\Desktop\OTL.exe
[2010/06/29 19:12:58 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2010/06/29 18:59:38 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/06/29 18:59:37 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/06/29 18:59:37 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/06/28 22:46:51 | 000,000,000 | —D | C] – C:\Users\Jay\AppData\Roaming\Atari
[2010/06/28 22:43:29 | 000,000,000 | —D | C] – C:\Users\Jay\AppData\Roaming\Leadertech
[2010/06/28 22:43:17 | 000,000,000 | —D | C] – C:\Users\Jay\Documents\RCT3
[2010/06/28 19:27:55 | 002,558,274 | —- | C] (Half-Life Improvement Team) – C:\Users\Jay\Documents\bshift_unlocked_v1.1.exe
[2010/06/25 19:13:45 | 000,000,000 | —D | C] – C:\Users\Jay\AppData\Local\Graboid_Inc
[2010/06/25 19:13:44 | 000,000,000 | —D | C] – C:\Users\Jay\AppData\Local\Graboid
[2010/06/25 19:13:28 | 000,000,000 | —D | C] – C:\Users\Jay\AppData\Roaming\MozillaControl
[2010/06/25 19:12:36 | 000,000,000 | —D | C] – C:\Program Files\Mozilla ActiveX Control v1.7.12
[2010/06/25 19:11:24 | 000,000,000 | —D | C] – C:\Program Files\VideoLAN
[2010/06/25 19:10:57 | 000,000,000 | —D | C] – C:\Program Files\Graboid
[2010/06/24 23:44:09 | 000,000,000 | —D | C] – C:\Program Files\Microsoft.NET
[2010/06/24 12:28:26 | 000,000,000 | —D | C] – C:\Users\Jay\Documents\Tabs
[2010/06/23 13:13:39 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2010/06/23 13:13:35 | 000,000,000 | —D | C] – C:\Windows\temp
[2010/06/23 13:13:35 | 000,000,000 | —D | C] – C:\Users\Jay\AppData\Local\temp
[2010/06/23 13:00:35 | 000,000,000 | —D | C] – C:\schrauber
[2010/06/23 12:59:51 | 000,212,480 | —- | C] (SteelWerX) – C:\Windows\SWXCACLS.exe
[2010/06/23 12:59:48 | 000,000,000 | —D | C] – C:\32788R22FWJFW
[2010/06/23 12:33:24 | 000,295,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationHost.exe
[2010/06/23 12:33:24 | 000,099,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationHostProxy.dll
[2010/06/23 12:33:23 | 000,049,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netfxperf.dll
[2010/06/22 17:13:12 | 004,240,384 | —- | C] (Microsoft) – C:\Windows\System32\GameUXLegacyGDFs.dll
[2010/06/22 17:13:12 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Apphlpdm.dll
[2010/06/16 15:25:08 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2010/06/16 15:24:34 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2010/06/16 15:18:30 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2010/06/09 21:48:32 | 000,000,000 | —D | C] – C:\Windows\Sun
[2010/06/08 15:38:11 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\System32\asycfilt.dll
[2010/06/08 15:38:09 | 000,289,792 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\atmfd.dll
[2010/06/08 15:38:05 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\System32\atmlib.dll
[2010/06/08 15:37:50 | 000,599,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2010/06/08 15:37:49 | 000,611,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2010/06/08 15:37:49 | 000,387,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2010/06/08 15:37:48 | 001,469,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2010/06/08 15:37:48 | 000,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2010/06/08 15:37:47 | 000,184,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2010/06/08 15:37:47 | 000,133,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2010/06/08 15:37:46 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2010/06/08 15:37:46 | 000,055,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2010/06/08 15:37:46 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2010/06/08 15:37:45 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2010/06/08 15:37:45 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2010/06/08 15:37:45 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2010/06/08 15:37:44 | 001,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2010/06/08 15:37:44 | 000,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2010/06/08 15:37:21 | 002,037,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2010/06/04 17:50:35 | 000,000,000 | —D | C] – C:\$AVG
[2010/06/04 16:26:18 | 000,012,464 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\avgrsstx.dll
[2010/06/04 16:26:16 | 000,242,896 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgtdix.sys
[2010/06/04 16:26:10 | 000,216,200 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgldx86.sys
[2010/06/04 16:26:08 | 000,029,584 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgmfx86.sys
[2010/06/04 16:26:06 | 000,000,000 | —D | C] – C:\Windows\System32\drivers\Avg
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/06/29 21:49:49 | 003,932,160 | -HS- | M] () – C:\Users\Jay\NTUSER.DAT
[2010/06/29 21:46:42 | 000,574,464 | —- | M] (OldTimer Tools) – C:\Users\Jay\Desktop\OTL.exe
[2010/06/29 21:41:02 | 061,514,236 | —- | M] () – C:\Windows\System32\drivers\Avg\incavi.avm
[2010/06/29 21:23:04 | 000,000,886 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/06/29 20:47:10 | 000,003,696 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/06/29 20:47:09 | 000,003,696 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/06/29 20:23:22 | 000,000,882 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/06/29 18:46:51 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/06/29 18:46:49 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/06/29 18:46:47 | 1005,051,904 | -HS- | M] () – C:\hiberfil.sys
[2010/06/29 18:45:51 | 000,524,288 | -HS- | M] () – C:\Users\Jay\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms
[2010/06/29 18:45:51 | 000,065,536 | -HS- | M] () – C:\Users\Jay\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf
[2010/06/29 18:44:52 | 001,889,994 | -H– | M] () – C:\Users\Jay\AppData\Local\IconCache.db
[2010/06/28 19:48:12 | 000,141,312 | —- | M] () – C:\Users\Jay\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/06/28 19:28:08 | 002,558,274 | —- | M] (Half-Life Improvement Team) – C:\Users\Jay\Documents\bshift_unlocked_v1.1.exe
[2010/06/28 19:22:45 | 000,002,231 | —- | M] () – C:\Users\Jay\Desktop\iTunes.lnk
[2010/06/28 12:49:44 | 000,002,305 | —- | M] () – C:\Users\Jay\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk
[2010/06/25 10:15:36 | 000,000,258 | RHS- | M] () – C:\ProgramData\ntuser.pol
[2010/06/24 23:50:52 | 000,430,148 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2010/06/24 23:50:52 | 000,316,462 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/06/24 23:50:52 | 000,108,268 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/06/23 13:11:16 | 000,000,215 | —- | M] () – C:\Windows\system.ini
[2010/06/11 16:05:16 | 000,282,928 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2010/06/08 20:30:02 | 000,002,482 | —- | M] () – C:\Users\Jay\AppData\Roaming\wklnhst.dat
[2010/06/04 16:35:51 | 000,242,896 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgtdix.sys
[2010/06/04 16:35:51 | 000,029,584 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgmfx86.sys
[2010/06/04 16:26:20 | 000,012,464 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\avgrsstx.dll
[2010/06/04 16:26:11 | 000,216,200 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgldx86.sys
[2010/06/04 16:26:08 | 000,113,461 | —- | M] () – C:\Windows\System32\drivers\Avg\iavichjw.avm
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2099/01/01 12:00:00 | 000,006,456 | -H– | C] () – C:\ProgramData\vawotuwu
[2010/06/25 10:15:36 | 000,000,258 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2010/06/16 19:38:36 | 000,002,231 | —- | C] () – C:\Users\Jay\Desktop\iTunes.lnk
[2010/06/04 16:26:08 | 000,113,461 | —- | C] () – C:\Windows\System32\drivers\Avg\iavichjw.avm
[2010/06/04 16:26:06 | 061,514,236 | —- | C] () – C:\Windows\System32\drivers\Avg\incavi.avm
[2010/03/20 21:46:21 | 000,000,039 | —- | C] () – C:\Windows\WININIT.INI
[2010/01/12 00:29:52 | 000,178,176 | —- | C] () – C:\Windows\System32\unrar.dll
[2009/10/24 15:35:59 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2007/03/19 03:04:58 | 000,003,584 | —- | C] () – C:\Windows\System32\namResES.dll
[2007/03/19 03:04:58 | 000,003,072 | —- | C] () – C:\Windows\System32\namResIT.dll
[2007/03/19 03:04:58 | 000,003,072 | —- | C] () – C:\Windows\System32\namResFR.dll
[2007/03/19 03:04:58 | 000,003,072 | —- | C] () – C:\Windows\System32\namResENG.dll
[2007/03/19 03:04:58 | 000,003,072 | —- | C] () – C:\Windows\System32\namResDE.dll
[2007/03/19 03:04:56 | 000,003,584 | —- | C] () – C:\Windows\System32\namResPTB.dll
[2007/03/19 03:04:56 | 000,003,072 | —- | C] () – C:\Windows\System32\namResZHC.dll
[2007/03/19 03:04:56 | 000,003,072 | —- | C] () – C:\Windows\System32\namResKO.dll
[2007/03/19 03:04:56 | 000,003,072 | —- | C] () – C:\Windows\System32\namResJA.dll
[2007/03/19 03:04:54 | 000,022,016 | —- | C] () – C:\Windows\System32\nam_page.dll
[2007/03/19 03:04:54 | 000,003,072 | —- | C] () – C:\Windows\System32\namResZHT.dll
[2006/11/02 05:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 03:25:44 | 000,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2006/11/02 00:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2005/01/31 06:37:58 | 000,009,255 | —- | C] () – C:\Windows\System32\lvcoinst.ini
[1999/01/27 13:39:06 | 000,065,024 | —- | C] () – C:\Windows\System32\indounin.dll
[1997/06/13 07:56:08 | 000,056,832 | —- | C] () – C:\Windows\System32\Iyvu9_32.dll

========== Alternate Data Streams ==========

@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:A8ADE5D8
@Alternate Data Stream - 103 bytes -> C:\ProgramData\TEMP:DFC5A2B2
< End of report >




OTL Extras logfile created on: 6/29/2010 9:47:41 PM - Run 2
OTL by OldTimer - Version 3.2.7.0 Folder = C:\Users\Jay\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18928)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

958.00 Mb Total Physical Memory | 230.00 Mb Available Physical Memory | 24.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 44.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 288.04 Gb Total Space | 30.23 Gb Free Space | 10.50% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 6.21 Gb Free Space | 62.05% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: JAY-PC
Current User Name: Jay
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.exe [@ = exefile] – Reg Error: Key error. File not found
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – Reg Error: Key error.
https [open] – Reg Error: Value error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{22C8CD0A-6DFD-4220-BED3-A398733687B4}" = lport=443 | protocol=6 | dir=in | name=oovoo tcp port 443 |
"{6ECCA040-EFC3-44F2-8B48-10C1AB357E89}" = lport=443 | protocol=17 | dir=in | name=oovoo udp port 443 |
"{91F430E7-5754-4DC9-8774-37C7C723657A}" = lport=6112 | protocol=6 | dir=in | name=6112tcp |
"{A2313E4A-2CBF-4A49-9A04-26BFE97D7163}" = lport=37675 | protocol=17 | dir=in | name=oovoo udp port 37675 |
"{B99AEA20-A855-4FA5-A4DF-9534F20A17F4}" = lport=37674 | protocol=17 | dir=in | name=oovoo udp port 37674 |
"{C7AF28EA-D75A-4437-9311-55A5F0F74AB3}" = lport=37674 | protocol=6 | dir=in | name=oovoo tcp port 37674 |
"{E55CC513-187A-4CB8-AB57-387F6C894B90}" = lport=6112 | protocol=17 | dir=in | name=6112udp |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{05B373E5-AB8E-4A68-BD49-EFB6A0CFAD81}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{06908E79-2348-4D84-947E-B83019F30AAF}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\pengi86\counter-strike\hl.exe |
"{07247F72-D0AF-4C68-9844-47CD5EB63DAF}" = protocol=17 | dir=in | app=c:\program files\steam\steam.exe |
"{0B41C49E-EC2D-409B-BCEC-D6E3CB1382A3}" = dir=in | app=c:\program files\avg\avg9\avgnsx.exe |
"{343D54BE-65AD-4F1E-BC55-6D5796546938}" = protocol=17 | dir=in | app=c:\users\jay\appdata\local\temp\7zsf557.tmp\symnrt.exe |
"{3DD7D6B1-ECB9-48EF-9357-C677F3D7CCBA}" = protocol=6 | dir=in | app=c:\program files\aim\aim.exe |
"{438298FD-BDC7-4594-9712-715A978100C0}" = protocol=6 | dir=in | app=c:\program files\starcraft\starcraft.exe |
"{4AC8FE26-BA50-4383-B0C5-19C738F27178}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{4CB94F4A-9CE2-4509-8230-C62DCA5C2125}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{4EE09D12-D74E-41BA-9C1C-C5107BD2BBB5}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\pengi86\counter-strike\hl.exe |
"{50DDD31C-A67A-48CB-A94B-F56A3FD3B707}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\pengi86\opposing force\hl.exe |
"{5ABBC8C4-4F65-4435-81DF-2707BADFBD75}" = protocol=6 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"{5F784585-F71E-4D61-9272-BA3C93984C87}" = protocol=6 | dir=in | app=c:\users\jay\documents\super simple wall 6.81\sswv6.81.exe |
"{8C81DFBB-4641-4AF6-8F4F-2241DC4B58E0}" = protocol=17 | dir=in | app=c:\program files\aim\aim.exe |
"{A09E5826-9E12-432E-95B4-1AB172DED0BE}" = protocol=17 | dir=in | app=c:\users\jay\documents\super simple wall 6.81\sswv6.81.exe |
"{A58DA086-0AC8-4027-9604-99FBDD3A0458}" = protocol=17 | dir=in | app=c:\program files\starcraft\starcraft.exe |
"{A7E8822C-F77C-4A02-8A09-8FC3F3CE9EDD}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\pengi86\opposing force\hl.exe |
"{B2822383-D59F-4625-8A96-3363F850900D}" = dir=in | app=c:\program files\avg\avg9\avgemc.exe |
"{BDD512D3-4DDA-4DA5-9537-CDAEF618C1F1}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\pengi86\half-life\hl.exe |
"{C8C10538-EAB4-47F2-864D-0F4E7BA69961}" = protocol=17 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"{DA29134B-9208-4344-897D-C44098FAB07E}" = protocol=6 | dir=in | app=c:\users\jay\appdata\local\temp\7zsf557.tmp\symnrt.exe |
"{E32BF5A9-11E5-4A4B-884A-2308CECC5F26}" = dir=in | app=c:\program files\avg\avg9\avgupd.exe |
"{E3D5E777-E30D-491E-BF40-D7F451454D10}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\pengi86\half-life\hl.exe |
"{E86A01DA-2EE0-41BA-9B9B-10CD1EBC5A0F}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{F06C799F-2E61-4C86-AF40-9395C7A7F3CD}" = protocol=6 | dir=in | app=c:\program files\steam\steam.exe |
"TCP Query User{1770B185-889F-49FE-A07A-71B25C5D6C3F}C:\program files\bittorrent\bittorrent.exe" = protocol=6 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"TCP Query User{181877FE-7CAB-40C8-B32C-5CD01CFE8A9E}C:\program files\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
"TCP Query User{26F2A05D-5664-4A5D-9877-7884C24578CC}C:\program files\logitech\desktop messenger\8876480\program\backweb-8876480.exe" = protocol=6 | dir=in | app=c:\program files\logitech\desktop messenger\8876480\program\backweb-8876480.exe |
"TCP Query User{483C07A3-2A46-4DE2-88B7-F55C29D97243}C:\program files\safari\safari.exe" = protocol=6 | dir=in | app=c:\program files\safari\safari.exe |
"TCP Query User{4A0BC0BF-2F63-4354-ABCC-994B8123644B}C:\program files\bittorrent\bittorrent.exe" = protocol=6 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"TCP Query User{63834C13-DC93-4ADE-B6D3-E1226D64ECAC}C:\program files\logitech\desktop messenger\8876480\program\backweb-8876480.exe" = protocol=6 | dir=in | app=c:\program files\logitech\desktop messenger\8876480\program\backweb-8876480.exe |
"TCP Query User{F94C3651-E516-4A84-8C54-9686DA7E2DC6}C:\program files\steam\steamapps\pengi86\half-life blue shift\hl.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\pengi86\half-life blue shift\hl.exe |
"UDP Query User{0D455044-0C55-4DEE-B168-E0291135B963}C:\program files\safari\safari.exe" = protocol=17 | dir=in | app=c:\program files\safari\safari.exe |
"UDP Query User{25528EF4-133C-4F13-BB60-34FEE42589DD}C:\program files\steam\steamapps\pengi86\half-life blue shift\hl.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\pengi86\half-life blue shift\hl.exe |
"UDP Query User{37ABA933-C836-430E-BF2F-C00B26C9F439}C:\program files\logitech\desktop messenger\8876480\program\backweb-8876480.exe" = protocol=17 | dir=in | app=c:\program files\logitech\desktop messenger\8876480\program\backweb-8876480.exe |
"UDP Query User{5A5EF40B-FE9F-4439-8188-EB20B1191631}C:\program files\bittorrent\bittorrent.exe" = protocol=17 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"UDP Query User{65A084D5-7402-4490-832D-89A5FE5461DF}C:\program files\bittorrent\bittorrent.exe" = protocol=17 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"UDP Query User{763984DA-1231-4314-99F1-152E78D8A4E4}C:\program files\logitech\desktop messenger\8876480\program\backweb-8876480.exe" = protocol=17 | dir=in | app=c:\program files\logitech\desktop messenger\8876480\program\backweb-8876480.exe |
"UDP Query User{CB62250E-6EA7-48A1-A192-586FF4D1133D}C:\program files\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\java.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{0CB9668D-F979-4F31-B8B8-67FE90F929F8}" = Bonjour
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{26A24AE4-039D-4CA4-87B4-2F83216016FF}" = Java™ 6 Update 18
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{3248F0A8-6813-11D6-A77B-00B0D0160000}" = Java™ SE Runtime Environment 6
"{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}" = Sonic Activation Module
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{7AB3A249-FB81-416B-917A-A2A10E74C503}" = iTunes
"{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{85991ED2-010C-4930-96FA-52F43C2CE98A}" = Apple Mobile Device Support
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-A70800000002}" = Adobe Reader 7.0.8
"{AFAC914D-9E83-4A89-8ABE-427521C82CCF}" = Safari
"{B2D328BE-45AD-4D92-96F9-2151490A203E}" = Apple Application Support
"{C4124E95-5061-4776-8D5D-E3D931C778E1}" = Microsoft VC9 runtime libraries
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{EFAD4066-CAF3-4B27-9669-12EED352C376}" = NVIDIANetworkDiagnostic
"{EFB21DE7-8C19-4A88-BB28-A766E16493BC}" = Adobe Photoshop CS
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AIM_7" = AIM 7
"Audacity 1.3 Beta (Unicode)_is1" = Audacity 1.3.11 (Unicode)
"AVG9Uninstall" = AVG Free 9.0
"AviSynth" = AviSynth 2.5
"BitTorrent" = BitTorrent
"CCleaner" = CCleaner
"Cg Toolkit_is1" = NVIDIA Cg Toolkit 2.2 October 2009
"CNXT_MODEM_PCI_VEN_14F1&DEV;_2F20&SUBSYS;_200F14F1" = Conexant D850 PCI V.92 Modem
"InstallShield_{EFAD4066-CAF3-4B27-9669-12EED352C376}" = NVIDIANetworkDiagnostic
"KLiteCodecPack_is1" = K-Lite Codec Pack 5.6.1 (Standard)
"LAME for Audacity_is1" = LAME v3.98.2 for Audacity
"LimeWire" = LimeWire 5.4.6
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft DirectX SDK (August 2009)" = Microsoft DirectX SDK (August 2009)
"NVIDIA Drivers" = NVIDIA Drivers
"Steam App 10" = Counter-Strike
"Steam App 130" = Half-Life: Blue Shift
"Steam App 50" = Half-Life: Opposing Force
"TuxGuitar_0" = TuxGuitar 1.2
"Videora iPod Converter" = Videora iPod Converter 5.03
"WinRAR archiver" = WinRAR archiver

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 6/20/2010 1:58:08 PM | Computer Name = Jay-PC | Source = Application Hang | ID = 1002
Description = The program iexplore.exe version 8.0.6001.18928 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 1220 Start Time: 01cb109f8f979f3c Termination Time: 22

Error - 6/21/2010 1:53:36 AM | Computer Name = Jay-PC | Source = Application Hang | ID = 1002
Description = The program iexplore.exe version 8.0.6001.18928 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 560 Start Time: 01cb10eefc067124 Termination Time: 93

Error - 6/21/2010 7:00:15 PM | Computer Name = Jay-PC | Source = Bonjour Service | ID = 100
Description = 396: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

Error - 6/21/2010 8:10:22 PM | Computer Name = Jay-PC | Source = Application Error | ID = 1000
Description = Faulting application Steam.exe, version 1.0.843.387, time stamp 0x4bd213c2,
faulting module Steam.dll_unloaded, version 0.0.0.0, time stamp 0x4c112b3e, exception
code 0xc0000005, fault offset 0x301e4d5a, process id 0x628, application start time
0x01cb119003846cfa.

Error - 6/21/2010 8:16:07 PM | Computer Name = Jay-PC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18928, time stamp
0x4bdfa327, faulting module mshtml.dll, version 8.0.6001.18928, time stamp 0x4bdfb76d,
exception code 0xc0000005, fault offset 0x00085ccc, process id 0x10bc, application
start time 0x01cb119f7c0806fa.

Error - 6/22/2010 9:49:00 PM | Computer Name = Jay-PC | Source = Application Error | ID = 1000
Description = Faulting application 14jp4ie0.exe, version 1.0.15.15281, time stamp
0x4b2763f0, faulting module 14jp4ie0.exe, version 1.0.15.15281, time stamp 0x4b2763f0,
exception code 0xc0000005, fault offset 0x0000c4b1, process id 0x1700, application
start time 0x01cb127569c4f224.

Error - 6/22/2010 10:10:08 PM | Computer Name = Jay-PC | Source = Application Hang | ID = 1002
Description = The program aim.exe version 7.2.6.1 stopped interacting with Windows
and was closed. To see if more information about the problem is available, check
the problem history in the Problem Reports and Solutions control panel. Process
ID: 8c4 Start Time: 01cb126b2192a154 Termination Time: 44

Error - 6/23/2010 3:58:55 PM | Computer Name = Jay-PC | Source = Application Hang | ID = 1002
Description = The program iexplore.exe version 8.0.6001.18928 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 818 Start Time: 01cb130cbdc89299 Termination Time: 0

Error - 6/24/2010 3:06:26 PM | Computer Name = Jay-PC | Source = VSS | ID = 8194
Description =

Error - 6/25/2010 10:49:40 PM | Computer Name = Jay-PC | Source = Application Error | ID = 1000
Description = Faulting application Explorer.EXE, version 6.0.6002.18005, time stamp
0x49e01da5, faulting module korwbrkr.dll_unloaded, version 0.0.0.0, time stamp
0x49e03745, exception code 0xc0000005, fault offset 0x69cf7d32, process id 0xc, application
start time 0x01cb1497cba8dd6f.

[ System Events ]
Error - 6/28/2010 2:11:47 PM | Computer Name = Jay-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 6/28/2010 2:11:47 PM | Computer Name = Jay-PC | Source = Service Control Manager | ID = 7026
Description =

Error - 6/28/2010 2:12:30 PM | Computer Name = Jay-PC | Source = Service Control Manager | ID = 7009
Description =

Error - 6/28/2010 2:12:30 PM | Computer Name = Jay-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 6/28/2010 4:33:12 PM | Computer Name = Jay-PC | Source = volsnap | ID = 393251
Description = The shadow copies of volume C: were aborted because the shadow copy
storage failed to grow.

Error - 6/29/2010 12:46:49 PM | Computer Name = Jay-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 6/29/2010 12:46:49 PM | Computer Name = Jay-PC | Source = Service Control Manager | ID = 7026
Description =

Error - 6/29/2010 7:15:19 PM | Computer Name = Jay-PC | Source = Dhcp | ID = 1000
Description = Your computer has lost the lease to its IP address 192.168.2.3 on
the Network Card with network address 001AA0577AF0.

Error - 6/29/2010 9:48:22 PM | Computer Name = Jay-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 6/29/2010 9:48:22 PM | Computer Name = Jay-PC | Source = Service Control Manager | ID = 7026
Description =


< End of report >
Hi,


[external image: Posted Image] Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version of Java components and upgrade the application. NOT supported for use in 9x or ME

Upgrading Java:
  • Download the latest version of Java SE Runtime Environment (JRE)JRE 6 Update 20.
  • Click the "Download" button to the right.
  • Select your Platform and check the box that says: "I agree to the Java SE Runtime Environment 6 License Agreement.".
  • Click on Continue.
  • Click on the link to download Windows Offline Installation (jre-6u20-windows-i586.exe) and save it to your desktop. Do NOT use the Sun Download Manager..
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel, double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java version.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on the download to install the newest version.(Vista users, right click on the jre-6u20-windows-i586.exe and select "Run as an Administrator.")




Your log(s) show that you are using so called peer-to-peer or file-sharing programmes (in your case Bittorrent). These programmes allow to share files between users as the name(s) suggest. In today's world the cyber crime has come to an enormous dimension and any means is used to infect personal computers to make use of their stored data or machine power for further propagation of the malware files. A popular means is the use of file-sharing tools as a tremendous amount of prospective victims can be reached through it.

It is therefore possible to be infected by downloading manipulated files via peer-to-peer tools and thus suggested to be used with intense care. Some further readings on this subject, along the included links, are as follows: "File-Sharing, otherwise known as Peer To Peer" and "Risks of File-Sharing Technology."

It is also important to note that sharing entertainment files and proprietary software infringes the copyright laws in many countries over the world and you are putting yourself at risk of being indicted through organisations watching over the rights of the authors of such files (i.e. the RIAA for music files, or the MPAA for movie files in the USA) or the authors of the files themselves.

Naturally there are also legal ways to use these services, such as downloading Linux distributions or office suites such as "Open Office."



How is the system running now?
My system seems to be the same. It's very slow sometimes, and it's out of nowhere. Then I have the periods of relative peace.
Can you have a look when exactly the system is slow? maybe more at startup, or when the system is already running a few hours? Is it maybe related when you run the same programs everytime? Also please post back with a fresh OTL logfile.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI