This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

I believe I have the AntiVir virus

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I downloaded the OTL here is the results:

OTL logfile created on: 8/8/2010 4:38:42 PM - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Users\xsdfghbnm\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 60.00% Memory free
8.00 Gb Paging File | 6.00 Gb Available in Paging File | 72.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 420.33 Gb Total Space | 368.20 Gb Free Space | 87.60% Space Free | Partition Type: NTFS
Drive D: | 30.48 Gb Total Space | 28.77 Gb Free Space | 94.41% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
Drive F: | 3.12 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DAVIDS-LAPTOP
Current User Name: xsdfghbnm
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Users\xsdfghbnm\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
PRC - C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10h_ActiveX.exe (Adobe Systems, Inc.)
PRC - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files (x86)\Spyware Doctor\pctsTray.exe (PC Tools)
PRC - C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe (Lenovo)
PRC - C:\Program Files (x86)\Spyware Doctor\pctsSvc.exe (PC Tools)
PRC - C:\Program Files (x86)\Spyware Doctor\pctsAuxs.exe (PC Tools)
PRC - C:\Program Files (x86)\DDNI\DIBS\DDNIService.exe (Digital Delivery Networks, Inc.)
PRC - C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe (CyberLink Corp.)
PRC - C:\Program Files\Lenovo\Lenovo SplitScreen\SplitScreen\SpScreen.exe (Lenovo)
PRC - C:\Program Files\Lenovo\Lenovo SlideNav\SlidebarNavigator\SlidebarNavigator.exe (Lenovo)
PRC - C:\Program Files (x86)\Spyware Doctor\BDT\BDTUpdateService.exe (Threat Expert Ltd.)
PRC - C:\Program Files (x86)\DDNI\Lenovo Idea Notes\DDNIMSGService.exe (Digital Delivery Networks, Inc.)
PRC - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeySupport.exe ()
PRC - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\ooVoo\ooVoo.exe (ooVoo LLC)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\ID Vault\IDVault.exe (White Sky, Inc.)
PRC - C:\Program Files (x86)\USB Camera2\VM332_STI.EXE (Vimicro)
PRC - C:\Program Files (x86)\DDNI\Lenovo Idea Notes\DDNIMSGUser.exe (Digital Delivery Networks, Inc.)
PRC - C:\Program Files (x86)\Windows Live\Toolbar\wltuser.exe (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - C:\Users\xsdfghbnm\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files (x86)\Spyware Doctor\smum32.dll (PC Tools)
MOD - C:\Program Files (x86)\Spyware Doctor\PCTGMhk.dll (PC Tools)
MOD - C:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV:64bit: - (avast! Web Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV:64bit: - (avast! Mail Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV:64bit: - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (Slidebar Notifier Service) – C:\Program Files\Lenovo\Lenovo SlideNav\SlidebarNavigator\SlidebarNotifier.exe (Lenovo)
SRV:64bit: - (Lenovo ReadyComm ConnSvc) – C:\Program Files\Lenovo\ReadyComm\ConnSvc.exe (Lenovo Group Limited)
SRV:64bit: - (wlidsvc) – C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation)
SRV:64bit: - (Lenovo ReadyComm AppSvc) – C:\Program Files\Lenovo\ReadyComm\AppSvc.exe (Lenovo Group Limited)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (avg9wd) – C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Apple Mobile Device) – C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (clr_optimization_v4.0.30319_64) – C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (sdCoreService) – C:\Program Files (x86)\Spyware Doctor\pctsSvc.exe (PC Tools)
SRV - (sdAuxService) – C:\Program Files (x86)\Spyware Doctor\pctsAuxs.exe (PC Tools)
SRV - (DDNIService) – C:\Program Files (x86)\DDNI\DIBS\DDNIService.exe (Digital Delivery Networks, Inc.)
SRV - (Browser Defender Update Service) – C:\Program Files (x86)\Spyware Doctor\BDT\BDTUpdateService.exe (Threat Expert Ltd.)
SRV - (DDNIMSGService) – C:\Program Files (x86)\DDNI\Lenovo Idea Notes\DDNIMSGService.exe (Digital Delivery Networks, Inc.)
SRV - (SeaPort) – C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (IAStorDataMgrSvc) Intel® – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
SRV - (UNS) Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (IGRS) – C:\Program Files (x86)\Lenovo\ReadyComm\common\IGRS.exe (Lenovo Group Limited)
SRV - (ReadyComm.DirectRouter) – C:\windows\SysWow64\IgrsSvcs.exe (Microsoft Corporation)
SRV - (PS_MDP) – C:\windows\SysWow64\IgrsSvcs.exe (Microsoft Corporation)
SRV - (BcmSqlStartupSvc) – C:\Program Files (x86)\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (AvgTdiA) – C:\Windows\SysNative\drivers\avgtdia.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (AvgLdx64) – C:\Windows\SysNative\drivers\avgldx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (aswMonFlt) – C:\Windows\SysNative\drivers\aswMonFlt.sys (ALWIL Software)
DRV:64bit: - (AvgMfx64) – C:\Windows\SysNative\drivers\avgmfx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (easytether) – C:\Windows\SysNative\drivers\easytthr.sys (Mobile Stream)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (PCTCore) – C:\Windows\SysNative\drivers\PCTCore64.sys (PC Tools)
DRV:64bit: - (atikmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (vm332avs) – C:\Windows\SysNative\drivers\vm332avs.sys (Vimicro Corporation)
DRV:64bit: - (RTHDMIAzAudService) – C:\Windows\SysNative\drivers\RtHDMIVX.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (JMCR) – C:\Windows\SysNative\drivers\jmcr.sys (JMicron Technology Corporation)
DRV:64bit: - (LHDmgr) – C:\Windows\SysNative\drivers\LhdX64.sys (Lenovo.)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (ACPIVPC) – C:\Windows\SysNative\drivers\AcpiVpc.sys (Lenovo Corporation)
DRV:64bit: - (k57nd60a) Broadcom NetLink ™ – C:\Windows\SysNative\drivers\k57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (HECIx64) Intel® – C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (NETw5s64) Intel® – C:\Windows\SysNative\drivers\NETw5s64.sys (Intel Corporation)
DRV:64bit: - (wsvd) – C:\Windows\SysNative\drivers\wsvd.sys (CyberLink)
DRV:64bit: - (wdmirror) – C:\Windows\SysNative\drivers\WDMirror.sys (Lenovo)
DRV:64bit: - (Bridge0) – C:\Windows\SysNative\drivers\WDBridge.sys (Lenovo)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (sdbus) – C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (Ntfs) – C:\Windows\SysNative\wbem\ntfs.mof ()
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (netw5v64) Intel® – C:\Windows\SysNative\drivers\netw5v64.sys (Intel Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (WimFltr) – C:\Windows\SysNative\drivers\WimFltr.sys (Microsoft Corporation)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.lenovo.com/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://lenovo.msn.com
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\software\mozilla\Firefox\Extensions\\{27182e60-b5f3-411c-b545-b44205977502}: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ [2010/08/06 23:15:24 | 000,000,000 | —D | M]


O1 HOSTS File: ([2009/06/10 14:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (PC Tools Browser Guard BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files (x86)\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (&Windows; Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files (x86)\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows; Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files (x86)\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O4:64bit: - HKLM..\Run: [Energy Management] C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe (Lenovo (Beijing) Limited)
O4:64bit: - HKLM..\Run: [EnergyUtility] C:\Program Files (x86)\Lenovo\Energy Management\utility.exe (Lenovo(beijing) Limited)
O4:64bit: - HKLM..\Run: [OnekeyStudio] C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeyStudio.exe (Lenovo)
O4:64bit: - HKLM..\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [SynBtnAsst] C:\Program Files\Synaptics\SynTP\SynBtnAsst.exe (Synaptics Incorporated)
O4 - HKLM..\Run: [332BigDog] C:\Program Files (x86)\USB Camera2\VM332_STI.EXE (Vimicro)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files (x86)\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [IdeaNotesUser] C:\Program Files (x86)\DDNI\Lenovo Idea Notes\DDNIMSGUser.exe (Digital Delivery Networks, Inc.)
O4 - HKLM..\Run: [ISTray] C:\Program Files (x86)\Spyware Doctor\pctsTray.exe (PC Tools)
O4 - HKLM..\Run: [Lenovo SlideNav2] C:\Program Files\Lenovo\Lenovo SlideNav\SlidebarNavigator\SlideNavVDM.exe (Lenovo)
O4 - HKLM..\Run: [Lenovo SplitScreen] C:\Program Files\Lenovo\Lenovo SplitScreen\SplitScreen\AutoRunSpS.exe (Lenovo)
O4 - HKLM..\Run: [MDS_Menu] c:\Program Files (x86)\Lenovo\MediaShow\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [MuteSync] C:\Program Files (x86)\Lenovo\Lenovo MuteSync\MuteSync.exe (Lenovo)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [UCam_Menu] c:\Program Files (x86)\Lenovo\YouCam\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateP2GShortCut] C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [VeriFaceManager] C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe (Lenovo)
O4 - HKLM..\Run: [YouCam Mirror Tray icon] c:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe (CyberLink Corp.)
O4 - HKCU..\Run: [ooVoo.exe] C:\Program Files (x86)\ooVoo\ooVoo.exe (ooVoo LLC)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog; This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 [removed]
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - AppInit_DLLs: (avgrssta.dll) - C:\windows\SysNative\avgrssta.dll (AVG Technologies CZ, s.r.o.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O30:64bit: - LSA: Security Packages - (livessp) - C:\windows\SysNative\livessp.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (livessp) - C:\windows\SysWow64\livessp.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/05/26 12:12:22 | 000,000,059 | R— | M] () - F:\autorun.inf – [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*


CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2010/08/08 16:35:05 | 000,574,976 | —- | C] (OldTimer Tools) – C:\Users\xsdfghbnm\Desktop\OTL.exe
[2010/08/07 13:40:06 | 000,000,000 | —D | C] – C:\Users\xsdfghbnm\AppData\Roaming\Malwarebytes
[2010/08/07 13:39:52 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\windows\SysWow64\drivers\mbamswissarmy.sys
[2010/08/07 13:39:51 | 000,024,664 | —- | C] (Malwarebytes Corporation) – C:\windows\SysNative\drivers\mbam.sys
[2010/08/07 13:39:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2010/08/07 13:39:51 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/08/07 13:21:05 | 000,000,000 | —D | C] – C:\Users\xsdfghbnm\AppData\Local\ElevatedDiagnostics
[2010/08/07 13:17:05 | 000,000,000 | —D | C] – C:\Users\xsdfghbnm\AppData\Roaming\ID Vault
[2010/08/07 13:16:03 | 000,000,000 | —D | C] – C:\Users\xsdfghbnm\AppData\Local\White_Sky,_Inc
[2010/08/07 13:16:03 | 000,000,000 | —D | C] – C:\Users\xsdfghbnm\AppData\Local\ID Vault
[2010/08/07 00:34:34 | 000,121,936 | —- | C] (ALWIL Software) – C:\windows\SysNative\drivers\aswSP.sys
[2010/08/07 00:34:34 | 000,020,048 | —- | C] (ALWIL Software) – C:\windows\SysNative\drivers\aswFsBlk.sys
[2010/08/07 00:34:33 | 000,051,280 | —- | C] (ALWIL Software) – C:\windows\SysNative\drivers\aswTdi.sys
[2010/08/07 00:34:33 | 000,028,752 | —- | C] (ALWIL Software) – C:\windows\SysNative\drivers\aswRdr.sys
[2010/08/07 00:34:32 | 000,061,008 | —- | C] (ALWIL Software) – C:\windows\SysNative\drivers\aswMonFlt.sys
[2010/08/07 00:34:04 | 000,165,032 | —- | C] (AVAST Software) – C:\windows\SysWow64\aswBoot.exe
[2010/08/07 00:34:04 | 000,038,848 | —- | C] (ALWIL Software) – C:\windows\avastSS.scr
[2010/08/07 00:34:01 | 000,000,000 | —D | C] – C:\ProgramData\Alwil Software
[2010/08/07 00:34:01 | 000,000,000 | —D | C] – C:\Program Files\Alwil Software
[2010/08/07 00:21:41 | 000,149,456 | —- | C] (PC Tools) – C:\windows\SGDetectionTool.dll
[2010/08/07 00:21:40 | 001,652,688 | —- | C] (Threat Expert Ltd.) – C:\windows\PCTBDCore.dll
[2010/08/07 00:21:40 | 000,165,840 | —- | C] (Threat Expert Ltd.) – C:\windows\PCTBDRes.dll
[2010/08/07 00:20:44 | 000,306,648 | —- | C] (PC Tools) – C:\windows\SysNative\drivers\pctgntdi64.sys
[2010/08/07 00:20:44 | 000,133,072 | —- | C] (PC Tools) – C:\windows\SysNative\drivers\pctwfpfilter64.sys
[2010/08/07 00:20:38 | 000,233,488 | —- | C] (PC Tools) – C:\windows\SysNative\drivers\PCTCore64.sys
[2010/08/07 00:20:32 | 000,092,896 | —- | C] (PC Tools) – C:\windows\SysNative\drivers\pctplsg64.sys
[2010/08/07 00:20:24 | 000,000,000 | —D | C] – C:\Program Files (x86)\Spyware Doctor
[2010/08/07 00:20:24 | 000,000,000 | —D | C] – C:\Users\xsdfghbnm\AppData\Roaming\PC Tools
[2010/08/07 00:20:24 | 000,000,000 | —D | C] – C:\ProgramData\PC Tools
[2010/08/07 00:20:24 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\PC Tools
[2010/08/07 00:18:19 | 000,000,000 | —D | C] – C:\Users\xsdfghbnm\AppData\Roaming\Macromedia
[2010/08/07 00:18:19 | 000,000,000 | —D | C] – C:\Users\xsdfghbnm\AppData\Roaming\Adobe
[2010/08/06 23:54:06 | 000,000,000 | —D | C] – C:\Users\xsdfghbnm\AppData\Roaming\ooVoo Details
[2010/08/06 23:54:06 | 000,000,000 | —D | C] – C:\Users\xsdfghbnm\AppData\Roaming\Apple Computer
[2010/08/06 23:54:04 | 000,000,000 | —D | C] – C:\Users\xsdfghbnm\AppData\Roaming\Intel Corporation
[2010/08/06 23:54:03 | 000,000,000 | —D | C] – C:\Users\xsdfghbnm\AppData\Roaming\Lenovo
[2010/08/06 23:53:58 | 000,000,000 | —D | C] – C:\Users\xsdfghbnm\AppData\Roaming\ATI
[2010/08/06 23:53:58 | 000,000,000 | —D | C] – C:\Users\xsdfghbnm\AppData\Local\ATI
[2010/08/06 23:53:45 | 000,000,000 | R–D | C] – C:\Users\xsdfghbnm\Searches
[2010/08/06 23:53:44 | 000,000,000 | -H-D | C] – C:\Users\xsdfghbnm\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2010/08/06 23:53:36 | 000,000,000 | —D | C] – C:\Users\xsdfghbnm\AppData\Roaming\Identities
[2010/08/06 23:53:33 | 000,000,000 | R–D | C] – C:\Users\xsdfghbnm\Contacts
[2010/08/06 23:53:32 | 000,000,000 | —D | C] – C:\Users\xsdfghbnm\AppData\Local\VirtualStore
[2010/08/06 23:53:27 | 000,000,000 | -HSD | C] – C:\Users\xsdfghbnm\AppData\Local\Temporary Internet Files
[2010/08/06 23:53:27 | 000,000,000 | -HSD | C] – C:\Users\xsdfghbnm\Templates
[2010/08/06 23:53:27 | 000,000,000 | -HSD | C] – C:\Users\xsdfghbnm\Start Menu
[2010/08/06 23:53:27 | 000,000,000 | -HSD | C] – C:\Users\xsdfghbnm\SendTo
[2010/08/06 23:53:27 | 000,000,000 | -HSD | C] – C:\Users\xsdfghbnm\Recent
[2010/08/06 23:53:27 | 000,000,000 | -HSD | C] – C:\Users\xsdfghbnm\PrintHood
[2010/08/06 23:53:27 | 000,000,000 | -HSD | C] – C:\Users\xsdfghbnm\NetHood
[2010/08/06 23:53:27 | 000,000,000 | -HSD | C] – C:\Users\xsdfghbnm\Documents\My Videos
[2010/08/06 23:53:27 | 000,000,000 | -HSD | C] – C:\Users\xsdfghbnm\Documents\My Pictures
[2010/08/06 23:53:27 | 000,000,000 | -HSD | C] – C:\Users\xsdfghbnm\Documents\My Music
[2010/08/06 23:53:27 | 000,000,000 | -HSD | C] – C:\Users\xsdfghbnm\My Documents
[2010/08/06 23:53:27 | 000,000,000 | -HSD | C] – C:\Users\xsdfghbnm\Local Settings
[2010/08/06 23:53:27 | 000,000,000 | -HSD | C] – C:\Users\xsdfghbnm\AppData\Local\History
[2010/08/06 23:53:27 | 000,000,000 | -HSD | C] – C:\Users\xsdfghbnm\Cookies
[2010/08/06 23:53:27 | 000,000,000 | -HSD | C] – C:\Users\xsdfghbnm\Application Data
[2010/08/06 23:53:27 | 000,000,000 | -HSD | C] – C:\Users\xsdfghbnm\AppData\Local\Application Data
[2010/08/06 23:53:26 | 000,000,000 | –SD | C] – C:\Users\xsdfghbnm\AppData\Roaming\Microsoft
[2010/08/06 23:53:26 | 000,000,000 | R–D | C] – C:\Users\xsdfghbnm\Videos
[2010/08/06 23:53:26 | 000,000,000 | R–D | C] – C:\Users\xsdfghbnm\Saved Games
[2010/08/06 23:53:26 | 000,000,000 | R–D | C] – C:\Users\xsdfghbnm\Pictures
[2010/08/06 23:53:26 | 000,000,000 | R–D | C] – C:\Users\xsdfghbnm\Music
[2010/08/06 23:53:26 | 000,000,000 | R–D | C] – C:\Users\xsdfghbnm\Links
[2010/08/06 23:53:26 | 000,000,000 | R–D | C] – C:\Users\xsdfghbnm\Favorites
[2010/08/06 23:53:26 | 000,000,000 | R–D | C] – C:\Users\xsdfghbnm\Downloads
[2010/08/06 23:53:26 | 000,000,000 | R–D | C] – C:\Users\xsdfghbnm\My Documents
[2010/08/06 23:53:26 | 000,000,000 | R–D | C] – C:\Users\xsdfghbnm\Desktop
[2010/08/06 23:53:26 | 000,000,000 | -H-D | C] – C:\Users\xsdfghbnm\AppData
[2010/08/06 23:53:26 | 000,000,000 | —D | C] – C:\Users\xsdfghbnm\AppData\Local\Temp
[2010/08/06 23:53:26 | 000,000,000 | —D | C] – C:\Users\xsdfghbnm\AppData\Local\Microsoft
[2010/08/06 23:53:26 | 000,000,000 | —D | C] – C:\Users\xsdfghbnm\AppData\Roaming\Media Center Programs
[2010/08/06 23:10:49 | 000,000,000 | —D | C] – C:\Program Files (x86)\Vuze
[2010/08/06 23:09:24 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2010/08/06 23:09:23 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2010/07/24 13:51:06 | 000,000,000 | —D | C] – C:\windows\Minidump
[2010/07/21 16:39:52 | 000,000,000 | —D | C] – C:\ProgramData\Qwest
[2010/07/21 16:39:40 | 000,000,000 | —D | C] – C:\windows\XSxS
[2010/07/21 16:39:40 | 000,000,000 | —D | C] – C:\Program Files (x86)\Xenocode
[2010/07/19 11:26:13 | 000,144,384 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\cdd.dll
[2010/07/19 11:24:34 | 000,013,048 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\windows\SysNative\avgrssta.dll

========== Files - Modified Within 30 Days ==========

[2010/08/08 16:44:34 | 001,048,576 | -HS- | M] () – C:\Users\xsdfghbnm\NTUSER.DAT
[2010/08/08 16:35:20 | 063,098,205 | —- | M] () – C:\windows\SysNative\drivers\Avg\incavi.avm
[2010/08/08 16:35:16 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Users\xsdfghbnm\Desktop\OTL.exe
[2010/08/08 16:31:34 | 000,000,908 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-1329038116-1785691961-154557434-1003UA.job
[2010/08/08 16:31:34 | 000,000,856 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-1329038116-1785691961-154557434-1003Core.job
[2010/08/08 16:31:33 | 000,067,584 | –S- | M] () – C:\windows\bootstat.dat
[2010/08/07 13:39:55 | 000,001,009 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/08/07 04:06:35 | 000,013,632 | -H– | M] () – C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/08/07 04:06:35 | 000,013,632 | -H– | M] () – C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/08/07 03:17:34 | 000,000,006 | -H– | M] () – C:\windows\tasks\SA.DAT
[2010/08/07 03:17:06 | 3168,190,464 | -HS- | M] () – C:\hiberfil.sys
[2010/08/07 03:16:13 | 001,357,397 | -H– | M] () – C:\Users\xsdfghbnm\AppData\Local\IconCache.db
[2010/08/07 00:34:36 | 000,001,852 | —- | M] () – C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2010/08/07 00:34:32 | 000,000,000 | —- | M] () – C:\windows\SysWow64\config.nt
[2010/08/07 00:20:44 | 000,002,136 | —- | M] () – C:\Users\Public\Desktop\Spyware Doctor.lnk
[2010/08/07 00:18:02 | 000,001,437 | —- | M] () – C:\Users\xsdfghbnm\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/08/07 00:12:11 | 000,524,288 | -HS- | M] () – C:\Users\xsdfghbnm\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
[2010/08/07 00:12:11 | 000,524,288 | -HS- | M] () – C:\Users\xsdfghbnm\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
[2010/08/07 00:12:11 | 000,065,536 | -HS- | M] () – C:\Users\xsdfghbnm\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
[2010/08/06 23:54:08 | 000,002,030 | —- | M] () – C:\Users\xsdfghbnm\Desktop\MediaShow.lnk
[2010/08/06 23:54:07 | 000,001,122 | —- | M] () – C:\Users\xsdfghbnm\Desktop\Cyberlink Power2Go.lnk
[2010/08/06 23:54:05 | 000,002,429 | —- | M] () – C:\Users\xsdfghbnm\Desktop\CyberLink YouCam.lnk
[2010/08/06 23:53:58 | 000,116,736 | —- | M] () – C:\Users\xsdfghbnm\AppData\Local\GDIPFONTCACHEV1.DAT
[2010/08/06 23:53:27 | 000,000,020 | -HS- | M] () – C:\Users\xsdfghbnm\ntuser.ini
[2010/08/06 23:11:16 | 000,001,848 | —- | M] () – C:\Users\Public\Desktop\Vuze.lnk
[2010/08/06 23:09:41 | 000,002,429 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2010/08/06 22:56:03 | 000,002,178 | —- | M] () – C:\Users\Public\Desktop\Miro.lnk
[2010/07/24 13:51:03 | 433,983,612 | —- | M] () – C:\windows\MEMORY.DMP
[2010/07/19 11:24:35 | 000,317,520 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\windows\SysNative\drivers\avgtdia.sys
[2010/07/19 11:24:34 | 000,013,048 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\windows\SysNative\avgrssta.dll
[2010/07/19 11:24:27 | 000,269,904 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\windows\SysNative\drivers\avgldx64.sys

========== Files Created - No Company Name ==========

[2010/08/07 13:39:55 | 000,001,009 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/08/07 00:34:36 | 000,001,852 | —- | C] () – C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2010/08/07 00:34:32 | 000,000,000 | —- | C] () – C:\windows\SysWow64\config.nt
[2010/08/07 00:21:41 | 000,767,952 | —- | C] () – C:\windows\BDTSupport.dll
[2010/08/07 00:21:41 | 000,000,882 | —- | C] () – C:\windows\RegSDImport.xml
[2010/08/07 00:21:41 | 000,000,879 | —- | C] () – C:\windows\RegISSImport.xml
[2010/08/07 00:21:41 | 000,000,131 | —- | C] () – C:\windows\IDB.zip
[2010/08/07 00:21:40 | 001,152,444 | —- | C] () – C:\windows\UDB.zip
[2010/08/07 00:20:44 | 000,007,357 | —- | C] () – C:\windows\SysNative\drivers\pctgntdi64.cat
[2010/08/07 00:20:38 | 000,007,353 | —- | C] () – C:\windows\SysNative\drivers\pctcore64.cat
[2010/08/07 00:20:34 | 000,002,136 | —- | C] () – C:\Users\Public\Desktop\Spyware Doctor.lnk
[2010/08/07 00:20:32 | 000,007,353 | —- | C] () – C:\windows\SysNative\drivers\pctplsg64.cat
[2010/08/07 00:18:02 | 000,001,437 | —- | C] () – C:\Users\xsdfghbnm\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/08/06 23:53:27 | 000,000,020 | -HS- | C] () – C:\Users\xsdfghbnm\ntuser.ini
[2010/08/06 23:53:26 | 001,048,576 | -HS- | C] () – C:\Users\xsdfghbnm\NTUSER.DAT
[2010/08/06 23:53:26 | 000,524,288 | -HS- | C] () – C:\Users\xsdfghbnm\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
[2010/08/06 23:53:26 | 000,524,288 | -HS- | C] () – C:\Users\xsdfghbnm\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
[2010/08/06 23:53:26 | 000,262,144 | -HS- | C] () – C:\Users\xsdfghbnm\ntuser.dat.LOG1
[2010/08/06 23:53:26 | 000,065,536 | -HS- | C] () – C:\Users\xsdfghbnm\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
[2010/08/06 23:53:26 | 000,002,429 | —- | C] () – C:\Users\xsdfghbnm\Desktop\CyberLink YouCam.lnk
[2010/08/06 23:53:26 | 000,002,104 | —- | C] () – C:\Users\xsdfghbnm\Desktop\OneKey Recovery.lnk
[2010/08/06 23:53:26 | 000,002,030 | —- | C] () – C:\Users\xsdfghbnm\Desktop\MediaShow.lnk
[2010/08/06 23:53:26 | 000,001,122 | —- | C] () – C:\Users\xsdfghbnm\Desktop\Cyberlink Power2Go.lnk
[2010/08/06 23:53:26 | 000,000,290 | —- | C] () – C:\Users\xsdfghbnm\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2010/08/06 23:53:26 | 000,000,272 | —- | C] () – C:\Users\xsdfghbnm\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2010/08/06 23:53:26 | 000,000,000 | -HS- | C] () – C:\Users\xsdfghbnm\ntuser.dat.LOG2
[2010/08/06 23:11:16 | 000,001,848 | —- | C] () – C:\Users\Public\Desktop\Vuze.lnk
[2010/08/06 23:09:41 | 000,002,429 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2010/07/24 13:51:03 | 433,983,612 | —- | C] () – C:\windows\MEMORY.DMP
[2010/04/30 23:18:30 | 000,016,648 | R— | C] () – C:\windows\SysWow64\LogAPI.dll
[2010/04/30 23:03:16 | 002,110,816 | —- | C] () – C:\windows\SysWow64\Apblend.dll
[2010/04/30 23:03:16 | 001,171,456 | —- | C] () – C:\windows\SysWow64\PicNotify.dll
[2010/04/30 23:03:05 | 001,044,480 | —- | C] () – C:\windows\SysWow64\3DImageRenderer.dll
[2010/04/30 22:43:42 | 000,731,106 | —- | C] () – C:\windows\SysWow64\PerfStringBackup.INI
[2010/02/24 22:43:08 | 000,001,309 | —- | C] () – C:\windows\vm332Rmv.ini
[2009/07/13 16:42:10 | 000,064,000 | —- | C] () – C:\windows\SysWow64\BWContextHandler.dll
[2009/07/13 14:03:59 | 000,364,544 | —- | C] () – C:\windows\SysWow64\msjetoledb40.dll

========== LOP Check ==========

[2010/08/07 13:17:05 | 000,000,000 | —D | M] – C:\Users\xsdfghbnm\AppData\Roaming\ID Vault
[2010/08/06 23:54:03 | 000,000,000 | —D | M] – C:\Users\xsdfghbnm\AppData\Roaming\Lenovo
[2010/08/06 23:54:06 | 000,000,000 | —D | M] – C:\Users\xsdfghbnm\AppData\Roaming\ooVoo Details
[2009/07/13 22:08:49 | 000,008,594 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2009/07/13 18:52:21 | 000,061,008 | —- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 – C:\windows\SysWow64\DriverStore\FileRepository\machine.inf_amd64_neutral_9e6bb86c3b39a3e9\AGP440.sys
[2009/07/13 18:52:21 | 000,061,008 | —- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 – C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys

< MD5 for: ATAPI.SYS >
[2009/07/13 18:52:21 | 000,024,128 | —- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C – C:\windows\SysWow64\DriverStore\FileRepository\mshdc.inf_amd64_neutral_a69a58a4286f0b22\atapi.sys
[2009/07/13 18:52:21 | 000,024,128 | —- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C – C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys

< MD5 for: CNGAUDIT.DLL >
[2009/07/13 18:15:06 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E – C:\Windows\SysWOW64\cngaudit.dll
[2009/07/13 18:15:06 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E – C:\Windows\SysWOW64\cngaudit.dll
[2009/07/13 18:15:06 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E – C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009/07/13 18:40:20 | 000,018,944 | —- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 – C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll

< MD5 for: IASTOR.SYS >
[2009/11/20 08:09:48 | 000,537,112 | —- | M] (Intel Corporation) MD5=073A606333B6F7BBF20AA856DF7F0997 – C:\windows\SysWow64\DriverStore\FileRepository\iaahci.inf_amd64_neutral_53f33454d751d4bd\iaStor.sys

< MD5 for: IASTORV.SYS >
[2009/07/13 18:48:04 | 000,410,688 | —- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 – C:\windows\SysWow64\DriverStore\FileRepository\iastorv.inf_amd64_neutral_18cccb83b34e1453\iaStorV.sys
[2009/07/13 18:48:04 | 000,410,688 | —- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 – C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_0b06441fa1790136\iaStorV.sys

< MD5 for: NETLOGON.DLL >
[2009/07/13 18:41:52 | 000,692,736 | —- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 – C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll
[2009/07/13 18:16:02 | 000,563,712 | —- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 – C:\Windows\SysWOW64\netlogon.dll
[2009/07/13 18:16:02 | 000,563,712 | —- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 – C:\Windows\SysWOW64\netlogon.dll
[2009/07/13 18:16:02 | 000,563,712 | —- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 – C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll

< MD5 for: NVSTOR.SYS >
[2009/07/13 18:45:45 | 000,167,488 | —- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 – C:\windows\SysWow64\DriverStore\FileRepository\nvraid.inf_amd64_neutral_5bde3fe2945bce9e\nvstor.sys
[2009/07/13 18:45:45 | 000,167,488 | —- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys

< MD5 for: SCECLI.DLL >
[2009/07/13 18:16:13 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 – C:\Windows\SysWOW64\scecli.dll
[2009/07/13 18:16:13 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 – C:\Windows\SysWOW64\scecli.dll
[2009/07/13 18:16:13 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 – C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll
[2009/07/13 18:41:53 | 000,232,448 | —- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 – C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2009/07/13 18:15:13 | 000,346,112 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\SysWOW64\dxtmsft.dll
[2009/07/13 18:15:13 | 000,215,552 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\SysWOW64\dxtrans.dll

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >

========== Alternate Data Streams ==========

@Alternate Data Stream - 158 bytes -> C:\ProgramData\Temp:DFC5A2B2
@Alternate Data Stream - 122 bytes -> C:\ProgramData\Temp:A8ADE5D8
< End of report >
********************************************************************************
**

OTL Extras logfile created on: 8/8/2010 4:38:46 PM - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Users\xsdfghbnm\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 60.00% Memory free
8.00 Gb Paging File | 6.00 Gb Available in Paging File | 72.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 420.33 Gb Total Space | 368.20 Gb Free Space | 87.60% Space Free | Partition Type: NTFS
Drive D: | 30.48 Gb Total Space | 28.77 Gb Free Space | 94.41% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
Drive F: | 3.12 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DAVIDS-LAPTOP
Current User Name: xsdfghbnm
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\windows\SysWow64\control.exe (Microsoft Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
htmlfile – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{0A307A50-0822-AB08-E7F3-90830E018183}" = ccc-utility64
"{23B45E10-0CA5-43E9-BD6D-C2BD6CBE11AC}" = iTunes
"{328CC232-CFDC-468B-A214-2E21300E4CB5}" = Apple Mobile Device Support
"{46F4D124-20E5-4D12-BE52-EC177A7A4B42}" = Lenovo OneKey Recovery
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{69E17212-8EB0-EAEE-5391-84AF24E72DA5}" = ATI Catalyst Install Manager
"{79BF7CB8-1E09-489F-9547-DB3EE8EA3F16}" = Microsoft SQL Server Native Client
"{86177DAE-38B1-49DD-912E-35CB703AB779}" = Microsoft SQL Server VSS Writer
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9B48B0AC-C813-4174-9042-476A887592C7}" = Windows Live ID Sign-in Assistant
"{A84DB02B-9C2B-4272-9D2D-A80E00A56513}" = Broadcom Gigabit NetLink Controller
"{B91110FB-33B4-468B-90C2-4D5E8AE3FAE1}" = Bonjour
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{FCD2F99C-3CB4-454E-BBA6-28FDCF2040D0}" = EasyTether
"0A4175B489A1B4A6E07E11B063A6263480C51D71" = Windows Driver Package - Lenovo (ACPIVPC) System (10/19/2009 5.4.0.1)
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"SynTPDeinstKey" = Synaptics Pointing Device Driver

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"{04A2E55B-A2C4-1FF7-BE8F-7851AF014535}" = CCC Help Turkish
"{0CE226F3-EB27-4ECD-BBF5-F088716779FD}" = Energy Management
"{17542DBF-E17C-4562-BC4D-FA3EF3076C45}" = Lenovo ReadyComm 5
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{1D89AD87-A734-4D7D-32CB-80E4AB2B1781}" = Catalyst Control Center Localization All
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26604C7E-A313-4D12-867F-7C6E7820BE4C}" = JMicron Flash Media Controller Driver
"{28B2171A-DE5A-642C-0B56-4A4CBEA1270F}" = CCC Help English
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{2955FADE-ADED-44AD-A853-D1EAEA7ACAD5}" = Lenovo MuteSync
"{29955D0F-5BAF-6CEC-8024-EBE31C05EEB2}" = Catalyst Control Center Graphics Full Existing
"{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}" = Microsoft SQL Server 2005 Express Edition (MSSMLBIZ)
"{2FDBBCEA-62DB-45F4-B6E5-0E1FB2A1F29D}" = Visual C++ 8.0 Runtime Setup Package (x64)
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3D5044A5-97B8-45C0-B956-BB2376569188}" = Windows Live Movie Maker
"{3D959874-DFFB-3FB3-7CE5-3EA86CD59CB9}" = CCC Help Chinese Traditional
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel® Rapid Storage Technology
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{4A7E0F8B-78F8-DD99-9E36-6062592F8B11}" = CCC Help Thai
"{50120000-1105-0000-0000-0000000FF1CE}" = Microsoft Office 2007 Primary Interop Assemblies
"{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)
"{5449FB4F-1802-4D5B-A6D8-087DB1142147}" = Realtek HDMI Audio Driver for ATI
"{55A291D8-9738-5FB8-D1A0-F17C4763FB77}" = Catalyst Control Center Graphics Light
"{5885739F-97FF-4907-AC74-065515FFAFF0}" = Catalyst Control Center - Branding
"{5E4B86E5-CD0E-4D3D-BE21-45A30326850A}" = Microsoft Search Enhancement Pack
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel® Management Engine Components
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{6C287668-66C1-4441-8194-94B68AC12717}" = CCC Help Greek
"{734DF1AE-57C0-0B89-D97F-FE473D8AD155}" = CCC Help Russian
"{76C66170-C538-4E77-B54D-48E136B5B533}" = Lenovo ReadyComm 5.0 Service
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{7B645E4C-1FF8-64C3-7A24-CF3282877D89}" = CCC Help Italian
"{7ED2709E-A4AF-58AD-5AB6-9CF79E4E3133}" = CCC Help German
"{7F9C6841-7709-5DC6-EE12-5766D22B4CC9}" = CCC Help Czech
"{80E158EA-7181-40FE-A701-301CE6BE64AB}" = MediaShow
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{8564C690-46EC-D931-A7EA-DAFD6229EC0E}" = CCC Help Spanish
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90A40409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office 2003 Web Components
"{91120000-0031-0000-0000-0000000FF1CE}" = Microsoft Office Professional Hybrid 2007
"{952B888A-8206-EBF8-CF87-215D3BD058A4}" = CCC Help Japanese
"{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars
"{995F1E2E-F542-4310-8E1D-9926F5A279B3}" = Windows Live Toolbar
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A06E1854-1580-4157-AD70-72734D324DEA}" = Lenovo Idea Notes
"{A0D1714D-675E-1CC0-9A1B-B1FED5F5C78F}" = CCC Help Polish
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{A939D341-5A04-4E0A-BB55-3E65B386432D}" = Microsoft Office Small Business Connectivity Components
"{AA6624F0-FFD4-990C-E44F-4CF1DB9AE4C7}" = CCC Help Portuguese
"{AC76BA86-7AD7-1033-7B44-A90100000001}" = Adobe Reader 9.0.1
"{ADE16A9D-FBDC-4ecc-B6BD-9C31E51D0333}" = Lenovo EasyCamera
"{ADF334AE-4CE0-D3E4-D4ED-7FC9CDB98EDC}" = ccc-core-static
"{B00F0588-D5F3-39AD-F079-4ACB72E252B7}" = Catalyst Control Center Graphics Previews Vista
"{B2164CCB-C002-4B80-8550-7535D80DF237}" = Lenovo DirectShare
"{B2D328BE-45AD-4D92-96F9-2151490A203E}" = Apple Application Support
"{B32C4059-6E7A-41EF-AD20-56DF1872B923}" = Business Contact Manager for Outlook 2007 SP1
"{BA1E2E1A-3900-3DE1-D046-2B60F353BF3B}" = CCC Help Korean
"{BA9193FE-8D35-0CC4-1FB2-59395A63518A}" = CCC Help Norwegian
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C7FB1A71-D808-4CD2-997D-837B39EA7EB0}" = DIBS
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D148A2D9-EE66-CE1C-E425-EE6BEDDE129B}" = CCC Help French
"{D1B70158-8502-7A7C-00CF-0BCB4F23E751}" = CCC Help Finnish
"{D6C75F0B-3BC1-4FC9-B8C5-3F7E8ED059CA}" = Windows Live Photo Gallery
"{DB1C702E-8472-08BE-FFDF-627974584E2D}" = CCC Help Hungarian
"{DFB19121-0609-49C1-92B1-546E5A940FE8}" = Onekey Theater
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{E35E7CDB-92F7-FF59-7B7F-2364DDE5CA4C}" = Catalyst Control Center InstallProxy
"{E6B8CFA3-14D8-FFC8-8BC5-5FF742375FF9}" = CCC Help Swedish
"{EB608E00-5105-5860-CFAC-3D234B9E26A4}" = Catalyst Control Center Graphics Full New
"{EB84A05A-94ED-D185-F1B4-1FF437A44D39}" = CCC Help Dutch
"{EDCB1BF6-EF8A-251B-9F22-439A85E14AD2}" = CCC Help Chinese Standard
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F2602F16-02D1-4F1C-99A5-E246C522A59D}" = Lenovo First Boot
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel® Control Center
"{FAA7F8FF-3C05-4A61-8F14-D8A6E9ED6623}" = ooVoo
"{FC2D2C28-30EE-6BD7-3AB3-87857166A9BF}" = Catalyst Control Center Core Implementation
"{FFFE4DBA-AFD4-8FB6-6E82-D36D8DBCC7BD}" = CCC Help Danish
"8461-7759-5462-8226" = Vuze
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"avast5" = avast! Free Antivirus
"AVG9Uninstall" = AVG Free 9.0
"Browser Defender_is1" = Browser Defender 2.0.6.15
"Business Contact Manager" = Business Contact Manager for Outlook 2007 SP1
"ID Vault" = ID Vault
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"InstallShield_{2955FADE-ADED-44AD-A853-D1EAEA7ACAD5}" = Lenovo MuteSync
"InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}" = Lenovo OneKey Recovery
"InstallShield_{80E158EA-7181-40FE-A701-301CE6BE64AB}" = MediaShow
"InstallShield_{B2164CCB-C002-4B80-8550-7535D80DF237}" = Lenovo DirectShare
"Lenovo Idea Central" = Lenovo Idea Central
"Lenovo SlideNav2" = Lenovo SlideNav
"Lenovo SplitScreen" = Lenovo SplitScreen
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft SQL Server 2005" = Microsoft SQL Server 2005
"Miro" = Miro
"PROHYBRIDR" = 2007 Microsoft Office system
"Spyware Doctor" = Spyware Doctor 7.0
"VeriFace" = VeriFace
"WinLiveSuite_Wave3" = Windows Live Essentials

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 7/5/2010 5:38:32 PM | Computer Name = Davids-Laptop | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 1029

Error - 7/7/2010 8:24:49 PM | Computer Name = Davids-Laptop | Source = Google Update | ID = 20
Description =

Error - 7/7/2010 8:30:28 PM | Computer Name = Davids-Laptop | Source = Bonjour Service | ID = 100
Description = 540: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

Error - 7/7/2010 8:30:28 PM | Computer Name = Davids-Laptop | Source = Bonjour Service | ID = 100
Description = 544: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

Error - 7/7/2010 8:30:28 PM | Computer Name = Davids-Laptop | Source = Bonjour Service | ID = 100
Description = 244: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

Error - 7/7/2010 8:30:28 PM | Computer Name = Davids-Laptop | Source = Bonjour Service | ID = 100
Description = 528: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

Error - 7/7/2010 8:30:28 PM | Computer Name = Davids-Laptop | Source = Bonjour Service | ID = 100
Description = 380: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

Error - 7/7/2010 9:34:02 PM | Computer Name = Davids-Laptop | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 7/7/2010 9:34:02 PM | Computer Name = Davids-Laptop | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 999

Error - 7/7/2010 9:34:02 PM | Computer Name = Davids-Laptop | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 999

[ System Events ]
Error - 7/4/2010 4:32:08 PM | Computer Name = Davids-Laptop | Source = Service Control Manager | ID = 7000
Description = The ReadyComm.DirectRouter service failed to start due to the following
error: %%2

Error - 7/7/2010 8:33:37 PM | Computer Name = Davids-Laptop | Source = Service Control Manager | ID = 7000
Description = The ReadyComm.DirectRouter service failed to start due to the following
error: %%2

Error - 7/19/2010 5:31:12 PM | Computer Name = Davids-Laptop | Source = DCOM | ID = 10010
Description =

Error - 7/22/2010 8:12:40 PM | Computer Name = Davids-Laptop | Source = Service Control Manager | ID = 7000
Description = The ReadyComm.DirectRouter service failed to start due to the following
error: %%2

Error - 7/24/2010 4:51:12 PM | Computer Name = Davids-Laptop | Source = EventLog | ID = 6008
Description = The previous system shutdown at 1:32:09 AM on ?7/?23/?2010 was unexpected.

Error - 7/24/2010 4:51:13 PM | Computer Name = Davids-Laptop | Source = BugCheck | ID = 1001
Description =

Error - 7/24/2010 4:53:27 PM | Computer Name = Davids-Laptop | Source = Service Control Manager | ID = 7000
Description = The ReadyComm.DirectRouter service failed to start due to the following
error: %%2

Error - 8/6/2010 9:46:16 PM | Computer Name = Davids-Laptop | Source = ACPI | ID = 327693
Description = : The embedded controller (EC) did not respond within the specified
timeout period. This may indicate that there is an error in the EC hardware or
firmware or that the BIOS is accessing the EC incorrectly. You should check with
your computer manufacturer for an upgraded BIOS. In some situations, this error
may cause the computer to function incorrectly.

Error - 8/6/2010 9:48:01 PM | Computer Name = Davids-Laptop | Source = Service Control Manager | ID = 7000
Description = The ReadyComm.DirectRouter service failed to start due to the following
error: %%2

Error - 8/7/2010 2:07:55 AM | Computer Name = Davids-Laptop | Source = Service Control Manager | ID = 7031
Description = The Apple Mobile Device service terminated unexpectedly. It has done
this 1 time(s). The following corrective action will be taken in 60000 milliseconds:
Restart the service.


< End of report >

I dont knowif it matters on the reports but it wont let me do anything on my User account so I am on a different User. I saw a few Antivir posts but im not 100T sure thats what i have and i am not a big time computer person so i didnt want to just try what was in those. I have run a Malware remover that i have seen suggested on here and it didnt find anything. I alspo have AVG the free version which has not found anything either. I know its bad to have multiple but i just downloaded a few trying to fix this. Thanks in advance and if I forgotr some info im sorrfy, if you need more info just let me know and I will give your all of the info i have.
Hi David211,

:welcome:

My name is NightWizard and I will be your helper. :)

While I go through your log, I would very much appreciate it if you read the following.

  • I aim provide you with the best instructions possible to resolve your issue. However, I ask that you understand that malware is complex and the process usually takes a few attempts before successfully cleaning everything out. In severe cases cleaning may not be possible and a reformat may be our only option.
  • If you are unresponsive to this thread within three days, the thread will be locked due to inactivity. However, if you will be away, let us know and we will be sure to keep the thread open.
  • Please do not make any new threads about this issue here or any other malware removal forum; it wastes other helpers' time and it can be dangerous for your PC.
  • If you don't understand a set of instructions or you are having trouble performing some of the fix, don't panic! Let me know and I will be happy to help in any way I can.
  • Please remember that the absence of symptoms does not mean you are clean. I request that you stick to this log until the very end - I will inform you when your system is clean.
  • Please do not use any tools other than the ones I instruct you to use. Some of the tools available can be dangerous if used incorrectly.

Please be advised that I am still in training at this forum. My posts will be checked by experts before I post in this thread. This is to ensure you get the best possible help available. This may cause delay however I will do my best to limit the time gaps between posts.



Thanks for choosing WhatTheTech and I will be back with a fix shortly! :)


-NightWizard
Hi David211,

Please work you way through the following:

1. Two Antivirus Programs Installed
You are operating your computer with multiple Anti-virus programs:

  • AVG
  • Avast


It is not safe to have more than one anti-virus installed on a computer, and doing so not only does not provide better protection, it will actually cause additional problems.

Anti-virus programs hook deep into the system to provide their protection and take up an enormous amount of your computer's resources when they are actively scanning your computer.

Having multiple anti-virus programs on one computer can cause your computer to run very slow, become unstable and even crash, You must remove all but one anti-virus program now.

To do this click Start > Run then copy/paste this: control.exe appwiz.cpl and click Ok. Then remove your chosen AV's from the list presented.



2. OTL Fix:
Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
    O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
    O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
    O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
    O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
    O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
    
    
    
    :Commands
    [emptytemp]
    [emptyflash]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • After rebooting, please post the OTL you are presented with on startup.



3. Updated MalwareBytes Scan:
Please launch Malwarebytes Anti-malware.
  • Once the program has loaded click the "Update taband then "Check for Updates" if any are found they will be downloaded. When prompted click Ok to install the updates.
  • After updating navigate to the main menu and check Perform Full Scan, then click Scan.
    The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to restart. Restart if it tells you to.
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the entire report in your next reply.


In your next reply please include:
  • The OTL log.
  • The MBAM log.
Cheers! :thumbup:
Im here still dont worry, but the MBAM scan is on like hour 18… is that normal? and do you want the otl log now or just wait for the MBAM? Thanks
It just finished, here are logs: OTL: All processes killed ========== OTL ========== Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found. 64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktop deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktopChanges deleted successfully. 64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully. 64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: David ->Temp folder emptied: 428087669 bytes ->Temporary Internet Files folder emptied: 612499922 bytes ->Google Chrome cache emptied: 338475360 bytes ->Flash cache emptied: 24407 bytes User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Public User: xsdfghbnm ->Temp folder emptied: 29626991 bytes ->Temporary Internet Files folder emptied: 188278463 bytes ->Flash cache emptied: 4141 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 40525161 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50400 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 1,562.00 mb [EMPTYFLASH] User: All Users User: David ->Flash cache emptied: 0 bytes User: Default User: Default User User: Public User: xsdfghbnm ->Flash cache emptied: 0 bytes Total Flash Files Cleaned = 0.00 mb OTL by OldTimer - Version 3.2.9.1 log created on 08172010_231705 Files\Folders moved on Reboot… C:\Users\xsdfghbnm\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. Registry entries deleted on Reboot… MBAM: Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4443 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 8/18/2010 5:41:24 PM mbam-log-2010-08-18 (17-41-24).txt Scan type: Full scan (C:\|D:\|) Objects scanned: 249074 Time elapsed: 18 hour(s), 17 minute(s), 45 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Hi David211,

Please work your way through the following:

1. Update Java
Java is out of date and older versions contain vulnerabilities. Please update to the newest version.

Download the newest version from HERE.

It's important to remove older versions of Java since it does not do so automatically and old versions still leave you vulnerable.
Go to Start > Control Panel > Software and open Add or Remove Programs.
Search in the list for all previous installed versions of Java. (J2SE Runtime Environment).
They will have this icon next to them: [external image: Posted Image]
Select each in turn and click Remove.

Once old versions are gone, please install the newest version.



Please be sure to disable AVG before doing this Kaspersky online scan!



2. Kaspersky Scan
Using Internet Explorer or Firefox, visit Kaspersky Online Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.

2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan. Click HERE to see how to disable the most common antivirus programs.
3. Click Run at the Security prompt.

The program will then begin downloading and installing and will also update the database.
Please be patient as this can take quite a long time to download.
  • Once the update is complete, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, adware, dialers, and other riskware
    • Archives
    • E-mail databases
  • Click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View report… at the bottom.
  • Click the Save report… button.

    [external image: Posted Image]

  • Change the Files of type dropdown box to Text file (.txt) and name the file KasReport.txt to save the file to your desktop so that you may post it in your next reply



In your next reply please include:
  • The Kaserpsky log.
  • How is your computer running?
Cheers :thumbup:
Sorry, I have some family in town from Florida so I have been really busy. Ill have the stuff posted later today/tonightor tomorrow. Thanks
——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Friday, August 27, 2010 Operating system: Microsoft (build 7600) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Wednesday, August 25, 2010 21:43:47 Records in database: 4144304 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: C:\ D:\ F:\ Scan statistics: Objects scanned: 115221 Threats found: 1 Infected objects found: 0 Suspicious objects found: 2 Scan duration: 33:25:12 File name / Threat / Threats count C:\Program Files (x86)\DDNI\Lenovo First Boot\DDNIOOBE.VBS Suspicious: Type_Script 1 C:\Windows\Installer\f042.msi Suspicious: Type_Script 1 Selected area has been scanned. On this user account, everthing seems to be running pretty good, however if I go to my actual user account it wont let me axcess the internet, as well as being slowish. besides that its working pretty good. AVG often pops up with alerts, like every 2-5 minutes it pops up about something.
Hi David211,

Please work your way through the following steps:

Show Hidden Files

Click on Control Panel
Click on Folder Options
Click on View Tab

Check:
Show hidden files,folders, or drives, press OK



1. VirScan
————————————-


I need to get more information on a file… please perform the following:

Note: Internet Explorer should be used… for best results.
  • Please go to VirSCAN.org… a free on-line file scanning service.
  • Copy / paste the complete path and file name (below) into the "Suspicious files to scan" box… at the top of the page.

    C:\Program Files (x86)\DDNI\Lenovo First Boot\DDNIOOBE.VBS
    C:\Windows\Installer\f042.msi


  • Click on the Upload button. Once the file is uploaded, the scanning process will begin.
  • Once the Scan completes… (scroll down) click on the "Copy to Clipboard" button.
  • Open Notepad… then paste (Ctrl &V) the contents of the Clipboard into the open Notepad window.
  • Save the Notepad file as "VirScan.txt"… save it to your desktop.
  • Paste the contents of the VirScan.txt file, in your next reply.



2. Fresh OTL log
————————————-


Please open OTL
  • Make sure all other windows are closed and to let it run uninterrupted.
  • Under the Custom Scan box paste this in;

    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
    %PROGRAMFILES%\PC-Doctor\Downloads\*.*
    %PROGRAMFILES%\Internet Explorer\*.tmp
    %PROGRAMFILES%\Internet Explorer\*.dat
    %USERPROFILE%\My Documents\*.exe
    %USERPROFILE%\*.exe
    %systemroot%\ADDINS\*.*
    %systemroot%\assembly\*.bak2
    %systemroot%\Config\*.*
    %systemroot%\REPAIR\*.bak2
    %systemroot%\SECURITY\Database\*.sdb /x
    %systemroot%\SYSTEM\*.bak2
    %systemroot%\Web\*.bak2
    %systemroot%\Driver Cache\*.*
    %PROGRAMFILES%\Mozilla Firefox\0*.exe
    %ProgramFiles%\Microsoft Common\*.*
    %ProgramFiles%\TinyProxy.
    %USERPROFILE%\Favorites\*.url /x
    %systemroot%\System32\Wbem\*.exe
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs


  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them if you need to start a new topic.



In your next reply please include:
  • The VirScan Logs.
  • The OTL log.
Cheers! :thumbup:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI