This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Slow Computer/ System Restored, Computer errors after system restore -

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I had a power outage and windows would not start up again. I had restore windows and have been having problems ever since (I could not use my back up files and have started re-downloading problems from scratch). Sometimes my computer screen turns black when going to other programs and my computer is really slow again. My HP computer is not even 2 years old yet and I am currently using AVG antivirus. Log files listed below. Thanks for your help!


OTL.txt log
OTL logfile created on: 11/22/2010 12:04:20 AM - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Users\Lindsay\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18975)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 52.00% Memory free
6.00 Gb Paging File | 4.00 Gb Available in Paging File | 71.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 285.94 Gb Total Space | 164.44 Gb Free Space | 57.51% Space Free | Partition Type: NTFS
Drive D: | 12.15 Gb Total Space | 1.66 Gb Free Space | 13.64% Space Free | Partition Type: NTFS

Computer Name: LINDSAY-PC | User Name: Lindsay | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Lindsay\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG PC Tuneup 2011\BoostSpeed.exe (AVG)
PRC - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Program Files (x86)\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\hp\support\hpsysdrv.exe (Hewlett-Packard Company)


========== Modules (SafeList) ==========

MOD - C:\Users\Lindsay\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (XAudioService) – C:\Windows\SysNative\DRIVERS\xaudio64.exe (Conexant Systems, Inc.)
SRV - (Apple Mobile Device) – C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (AVGIDSAgent) – C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) – C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (clr_optimization_v4.0.30319_32) – C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (NwlnkFwd) – C:\Windows\SysNative\DRIVERS\nwlnkfwd.sys File not found
DRV:64bit: - (NwlnkFlt) – C:\Windows\SysNative\DRIVERS\nwlnkflt.sys File not found
DRV:64bit: - (IpInIp) – C:\Windows\SysNative\DRIVERS\ipinip.sys File not found
DRV:64bit: - (AVGIDSEH) – C:\Windows\SysNative\DRIVERS\AVGIDSEH.Sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (Avgtdia) – C:\Windows\SysNative\DRIVERS\avgtdia.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgmfx64) – C:\Windows\SysNative\DRIVERS\avgmfx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgldx64) – C:\Windows\SysNative\DRIVERS\avgldx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgrkx64) – C:\Windows\SysNative\DRIVERS\avgrkx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (AVGIDSFilter) – C:\Windows\SysNative\DRIVERS\AVGIDSFilter.Sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (AVGIDSDriver) – C:\Windows\SysNative\DRIVERS\AVGIDSDriver.Sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\Drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (WpdUsb) – C:\Windows\SysNative\DRIVERS\wpdusb.sys (Microsoft Corporation)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (CAXHWBS2) – C:\Windows\SysNative\DRIVERS\CAXHWBS2.sys (Conexant Systems, Inc.)
DRV:64bit: - (winachsf) – C:\Windows\SysNative\DRIVERS\CAX_CNXT.sys (Conexant Systems, Inc.)
DRV:64bit: - (HSF_DP) – C:\Windows\SysNative\DRIVERS\CAX_DP.sys (Conexant Systems, Inc.)
DRV:64bit: - (XAudio) – C:\Windows\SysNative\DRIVERS\xaudio64.sys (Conexant Systems, Inc.)
DRV:64bit: - (netr7364) – C:\Windows\SysNative\DRIVERS\netr7364.sys (Ralink Technology Inc.)
DRV:64bit: - (Ntfs) – C:\Windows\SysNative\Wbem\ntfs.mof ()
DRV:64bit: - (mdmxsdk) – C:\Windows\SysNative\DRIVERS\mdmxsdk.sys (Conexant)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files (x86)\AVG\AVG10\Firefox\ [2010/10/29 19:19:27 | 000,000,000 | —D | M]


O1 HOSTS File: ([2006/09/18 15:37:24 | 000,000,761 | —- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG10\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O4:64bit: - HKLM..\Run: [NvCplDaemon] C:\Windows\SysNative\NvCpl.DLL (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [NvMediaCenter] C:\Windows\SysNative\NvMcTray.DLL (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [KBD] C:\hp\KBD\KbdStub.exe ()
O4 - HKLM..\RunOnce: [NSSInstallation] C:\Program Files (x86)\DivX\Symantec\scstubinstaller.exe (Symantec Corporation)
O4 - Startup: C:\Users\Lindsay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 [removed] [removed]
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Lindsay\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Lindsay\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{1e8f068d-b2c4-11df-8443-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{1e8f068d-b2c4-11df-8443-806e6f6e6963}\Shell\AutoRun\command - "" = F:\SetupAssistant.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (C:\PROGRA~2\AVG\AVG10\avgchsva.exe /sync) - C:\Program Files (x86)\AVG\AVG10\avgchsva.exe (AVG Technologies CZ, s.r.o.)
O34 - HKLM BootExecute: (C:\PROGRA~2\AVG\AVG10\avgrsa.exe /sync /restart) - C:\Program Files (x86)\AVG\AVG10\avgrsa.exe (AVG Technologies CZ, s.r.o.)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*


Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\WINDOWS\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:\Windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)
Drivers32: vidc.yv12 - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2010/11/22 00:03:10 | 000,575,488 | —- | C] (OldTimer Tools) – C:\Users\Lindsay\Desktop\OTL.exe
[2010/11/21 23:56:58 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2010/11/21 23:40:30 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2010/11/21 23:40:28 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2010/11/21 23:40:28 | 000,000,000 | —D | C] – C:\Program Files (x86)\iTunes
[2010/11/21 23:38:02 | 000,000,000 | —D | C] – C:\Windows\LastGood
[2010/11/21 23:12:31 | 000,000,000 | —D | C] – C:\Users\Lindsay\AppData\Roaming\AVG
[2010/11/21 23:11:16 | 000,000,000 | —D | C] – C:\ProgramData\TEMP
[2010/11/11 20:14:00 | 000,000,000 | —D | C] – C:\Users\Lindsay\AppData\Roaming\Ventrilo
[2010/11/11 20:09:44 | 000,000,000 | —D | C] – C:\Program Files\Ventrilo
[2010/11/11 20:08:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Wise Installation Wizard
[2010/10/29 19:20:53 | 001,927,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\gameux.dll
[2010/10/29 19:20:53 | 001,696,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\gameux.dll
[2010/10/29 19:20:52 | 000,032,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\Apphlpdm.dll
[2010/10/29 19:20:52 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\Apphlpdm.dll
[2010/10/29 19:20:51 | 004,240,384 | —- | C] (Microsoft) – C:\Windows\SysWow64\GameUXLegacyGDFs.dll
[2010/10/29 19:20:51 | 004,240,384 | —- | C] (Microsoft) – C:\Windows\SysNative\GameUXLegacyGDFs.dll

========== Files - Modified Within 30 Days ==========

[2010/11/22 00:03:17 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Users\Lindsay\Desktop\OTL.exe
[2010/11/21 23:57:05 | 000,002,563 | —- | M] () – C:\Users\Lindsay\Desktop\HiJackThis.lnk
[2010/11/21 23:53:10 | 000,001,919 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader 8.lnk
[2010/11/21 23:41:02 | 000,001,696 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2010/11/21 23:10:50 | 000,001,014 | —- | M] () – C:\Users\Lindsay\Desktop\AVG PC Tuneup 2011.lnk
[2010/11/21 23:02:43 | 000,001,422 | —- | M] () – C:\Users\Lindsay\Desktop\DivX Movies.lnk
[2010/11/21 23:02:25 | 000,000,949 | —- | M] () – C:\Users\Public\Desktop\DivX Plus Player.lnk
[2010/11/21 22:59:46 | 000,001,870 | —- | M] () – C:\Users\Lindsay\Desktop\Install_NSS.lnk
[2010/11/21 22:59:46 | 000,000,392 | —- | M] () – C:\Windows\tasks\Install_NSS.job
[2010/11/21 22:45:08 | 099,807,193 | —- | M] () – C:\Windows\SysNative\drivers\AVG\incavi.avm
[2010/11/21 22:41:19 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/11/18 22:49:42 | 000,003,616 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/11/18 22:49:42 | 000,003,616 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/11/12 19:23:42 | 000,703,388 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010/11/12 19:23:42 | 000,604,264 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010/11/12 19:23:42 | 000,103,964 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010/11/12 19:17:12 | 3084,050,432 | -HS- | M] () – C:\hiberfil.sys
[2010/11/11 22:56:04 | 000,000,705 | —- | M] () – C:\Users\Public\Desktop\World of Warcraft.lnk
[2010/11/11 20:09:47 | 000,000,262 | —- | M] () – C:\Windows\{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}_WiseFW.ini
[2010/11/11 20:09:46 | 000,000,754 | —- | M] () – C:\Users\Lindsay\Desktop\Ventrilo.lnk
[2010/11/07 17:54:07 | 000,000,342 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForLindsay.job
[2010/11/02 18:32:27 | 000,001,614 | —- | M] () – C:\Users\Lindsay\Desktop\Calculator.lnk
[2010/10/29 19:19:41 | 000,000,862 | —- | M] () – C:\Users\Public\Desktop\AVG 2011.lnk

========== Files Created - No Company Name ==========

[2010/11/21 23:56:58 | 000,002,563 | —- | C] () – C:\Users\Lindsay\Desktop\HiJackThis.lnk
[2010/11/21 23:53:10 | 000,001,919 | —- | C] () – C:\Users\Public\Desktop\Adobe Reader 8.lnk
[2010/11/21 23:41:02 | 000,001,696 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2010/11/21 23:10:50 | 000,001,014 | —- | C] () – C:\Users\Lindsay\Desktop\AVG PC Tuneup 2011.lnk
[2010/11/21 22:59:46 | 000,001,870 | —- | C] () – C:\Users\Lindsay\Desktop\Install_NSS.lnk
[2010/11/21 22:59:46 | 000,000,392 | —- | C] () – C:\Windows\tasks\Install_NSS.job
[2010/11/11 20:09:46 | 000,000,754 | —- | C] () – C:\Users\Lindsay\Desktop\Ventrilo.lnk
[2010/11/11 20:09:42 | 000,000,262 | —- | C] () – C:\Windows\{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}_WiseFW.ini
[2010/11/02 18:32:27 | 000,001,614 | —- | C] () – C:\Users\Lindsay\Desktop\Calculator.lnk
[2010/08/29 22:28:50 | 000,117,248 | —- | C] () – C:\Windows\SysWow64\EhStorAuthn.dll
[2010/08/29 22:27:27 | 000,368,640 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2010/08/29 21:30:06 | 000,005,120 | —- | C] () – C:\Users\Lindsay\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/07/31 19:16:51 | 000,000,349 | —- | C] () – C:\ProgramData\hpzinstall.log
[2008/07/31 18:53:24 | 000,327,680 | —- | C] () – C:\Windows\SysWow64\pythoncom25.dll
[2008/07/31 18:53:24 | 000,102,400 | —- | C] () – C:\Windows\SysWow64\pywintypes25.dll
[2008/01/20 20:50:05 | 000,060,124 | —- | C] () – C:\Windows\SysWow64\tcpmon.ini

========== LOP Check ==========

[2010/11/21 23:36:03 | 000,000,000 | —D | M] – C:\Users\Lindsay\AppData\Roaming\AVG
[2010/10/14 18:16:51 | 000,000,000 | —D | M] – C:\Users\Lindsay\AppData\Roaming\AVG10
[2010/10/12 22:54:28 | 000,000,000 | —D | M] – C:\Users\Lindsay\AppData\Roaming\uTorrent
[2010/08/30 18:53:31 | 000,000,000 | —D | M] – C:\Users\Lindsay\AppData\Roaming\WinBatch
[2010/11/21 22:59:46 | 000,000,392 | —- | M] () – C:\WINDOWS\Tasks\Install_NSS.job
[2010/11/11 23:39:27 | 000,013,522 | —- | M] () – C:\WINDOWS\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/04/11 00:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2008/07/31 19:34:22 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2010/11/12 19:17:12 | 3084,050,432 | -HS- | M] () – C:\hiberfil.sys
[2010/11/12 19:17:11 | 3397,791,744 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2006/11/02 09:06:41 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 09:06:41 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 09:06:41 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2010/08/31 17:19:45 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/09/18 15:35:48 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2008/01/20 21:21:59 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/08/30 18:45:11 | 000,000,221 | -HS- | M] () – C:\Users\Lindsay\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2010/11/22 00:03:17 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Users\Lindsay\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< >

========== Alternate Data Streams ==========

@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:0B4227B4

< End of report >




OTL Extras logfile created on: 11/22/2010 12:04:20 AM - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Users\Lindsay\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18975)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 52.00% Memory free
6.00 Gb Paging File | 4.00 Gb Available in Paging File | 71.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 285.94 Gb Total Space | 164.44 Gb Free Space | 57.51% Space Free | Partition Type: NTFS
Drive D: | 12.15 Gb Total Space | 1.66 Gb Free Space | 13.64% Space Free | Partition Type: NTFS

Computer Name: LINDSAY-PC | User Name: Lindsay | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\System32\ieframe.DLL (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1" File not found
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 0
"InternetSettingsDisableNotify" = 0
"AutoUpdateDisableNotify" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = 9F 9E 16 8C DC 5B C8 01 [binary data]
"VistaSp2" = 6A 7E 0D B7 64 49 CB 01 [binary data]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"oobe_av" = 1

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{5A35565C-0943-410B-B1C5-EBE0DA6D5C25}" = lport=3724 | protocol=6 | dir=in | name=blizzard downloader: 3724 |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{00D88320-4C4B-49E6-8A3F-54DF121A0E53}" = dir=in | app=c:\program files (x86)\cyberlink\powerdirector\pdr.exe |
"{1BC87895-F206-4202-BE90-9D06D9499264}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{2406E467-F1EA-4B30-AB4E-2CFCFC1D8C9E}" = protocol=6 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{3080317B-4A2F-4BD9-A859-6A462095D66B}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg10\avgmfapx.exe |
"{4C9FED23-7E4D-4A49-956A-31379C8D475B}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg10\avgdiagex.exe |
"{523E8830-D405-4712-B8C7-7551000FFA5C}" = protocol=17 | dir=in | app=c:\world of warcraft\wow-3.2.0-enus-downloader.exe |
"{60184DF6-58E0-4394-8D74-F6AE42F37E0B}" = protocol=6 | dir=in | app=c:\program files\ventrilo\ventrilo.exe |
"{6E492E28-E326-4C20-9098-0119D1849BC7}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg10\avgnsa.exe |
"{7D2F8723-983F-4125-9DE9-1B855A73294B}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg10\avgdiagex.exe |
"{88F3A97A-F4EF-4594-B5DF-7264F35D6C15}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{8C35C451-880E-415D-8A89-9053710FD4B4}" = protocol=17 | dir=in | app=c:\program files\ventrilo\ventrilo.exe |
"{968D5540-34C7-421C-8C14-A36A7B8E2A22}" = protocol=17 | dir=in | app=c:\world of warcraft\wow-3.2.0.10192-to-3.3.0.10958-enus-downloader.exe |
"{B26C17B5-03B9-40C4-B770-F20139420ADA}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg10\avgemca.exe |
"{B3ACB925-5335-4C03-B9EF-FD8C9AF6FB4E}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg10\avgnsa.exe |
"{BFA79DE1-BE1D-4706-B25E-CAF5CA87822F}" = protocol=6 | dir=in | app=c:\world of warcraft\wow-3.2.0-enus-downloader.exe |
"{C279D25C-D14F-4AD8-B585-58EF9FDC7D16}" = protocol=6 | dir=in | app=c:\world of warcraft\wow-3.2.0.10192-to-3.3.0.10958-enus-downloader.exe |
"{CF8E486C-34EC-4F9F-B52E-FF317ED7B76F}" = protocol=17 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{D8D8BDDF-DB34-4B28-B47E-1CE9A555B05C}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{F119002E-639B-4024-97F8-6F26C4A855EE}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg10\avgmfapx.exe |
"{F2179FB3-9A5C-4974-AF75-8202938656D5}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg10\avgemca.exe |
"TCP Query User{7A0E67E2-F39F-47B6-A23E-4AB79C142C72}C:\world of warcraft\launcher.exe" = protocol=6 | dir=in | app=c:\world of warcraft\launcher.exe |
"UDP Query User{0E101820-35F7-4591-BDC9-D3D502837582}C:\world of warcraft\launcher.exe" = protocol=17 | dir=in | app=c:\world of warcraft\launcher.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{319B58E8-4C80-4912-8EA7-24A9658120C6}" = AVG 2011
"{350AA351-21FA-3270-8B7A-835434E766AD}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022
"{41BF0DE4-5BAE-4B88-AFD3-86A30B222186}" = Bonjour
"{5BF8A577-B334-49BE-A7B2-349C1F1B0C58}" = AVG 2011
"{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{963BFE7E-C350-4346-B43C-B02358306A45}" = Apple Mobile Device Support
"{B6EFD9A5-2ECE-4C22-BAEC-D16E73EA2013}" = iTunes
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}" = Ventrilo Client for Windows x64
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"AVG" = AVG 2011
"CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200C14F1" = Soft Data Fax Modem with SmartCP
"HP Photosmart Essential" = HP Photosmart Essential 3.0
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"NVIDIA Drivers" = NVIDIA Drivers

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{09633A5E-3089-41A8-9FF1-382171423C5D}" = PSSWCORE
"{15B8AFD9-92E9-4E86-96D9-83FAC510B82E}" = HPPhotoSmartPhotobookWebPack1
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe
"{22F761D1-8063-4170-ADF7-2D2F47834CA9}" = VideoToolkit01
"{254C37AA-6B72-4300-84F6-98A82419187E}" = Hewlett-Packard Active Check for Health Check
"{26A24AE4-039D-4CA4-87B4-2F83216021FF}" = Java™ 6 Update 21
"{2A0F36F1-75CA-49F4-A20C-8D875537F18C}" = Belkin Wireless G Plus MIMO USB Network Adapter
"{2FDBBCEA-62DB-45F4-B6E5-0E1FB2A1F29D}" = Visual C++ 8.0 Runtime Setup Package (x64)
"{305D4B08-5807-4475-B1C8-D54685534864}" = LightScribeTemplateLabeler
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java™ SE Runtime Environment 6 Update 1
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{50316C0A-CC2A-460A-9EA5-F486E54AC17D}_is1" = AVG PC Tuneup 2011
"{55979C41-7D6A-49CC-B591-64AC1BBE2C8B}" = HP Picasso Media Center Add-In
"{58A8F951-2335-4142-94F5-87EC3CF1DB3C}" = Dynex G Wireless Desktop Card Setup
"{5DAA9C36-8F8B-462F-8CCA-E205BC3751F5}" = HP Active Support Library
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = Hewlett-Packard Asset Agent for Health Check
"{6B976ADF-8AE8-434E-B282-A06C7F624D2F}" = Python 2.5.2
"{7F10292C-A190-4176-A665-A1ED3478DF86}" = LightScribe System Software
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{97ABD26A-3249-46CB-B2E2-F66E64B2E480}" = HP Demo
"{9DBA770F-BF73-4D39-B1DF-6035D95268FC}" = HP Customer Feedback
"{A0640EC2-B97E-4FC1-AD14-227C9E386BB4}" = HP Recovery Manager RSS
"{AC76BA86-7AD7-1033-7B44-A82000000003}" = Adobe Reader 8.2.5
"{C27C82E4-9C53-4D76-9ED3-A01A3D5EE679}" = HP Customer Experience Enhancements
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{C8FD5BC1-92EF-4C15-92A9-F9AC7F61985F}" = HP Update
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}" = HP Photosmart Essential 2.5
"{E535C94A-B87F-4182-BEA8-1E9322078D3E}" = Cards_Calendar_OrderGift_DoMorePlugout
"{E7004147-2CCA-431C-AA05-2AB166B9785D}" = QuickTime
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{f32502b5-5b64-4882-bf61-77f23edcac4f}" = HP Total Care Advisor
"{FA3B34BE-4246-4062-90A3-34CBBEA12B72}" = HPTCSSetup
"{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}" = Visual Studio 2008 x64 Redistributables
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"DivX Setup.divx.com" = DivX Setup
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"PC-Doctor for Windows" = Hardware Diagnostic Tools
"uTorrent" = µTorrent
"WildTangent hp Master Uninstall" = My HP Games
"World of Warcraft" = World of Warcraft

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 11/7/2010 11:38:35 PM | Computer Name = Lindsay-PC | Source = Bonjour Service | ID = 100
Description = 460: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

Error - 11/7/2010 11:38:35 PM | Computer Name = Lindsay-PC | Source = Bonjour Service | ID = 100
Description = 416: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

Error - 11/7/2010 11:38:35 PM | Computer Name = Lindsay-PC | Source = Bonjour Service | ID = 100
Description = 400: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

Error - 11/7/2010 11:42:59 PM | Computer Name = Lindsay-PC | Source = Bonjour Service | ID = 100
Description = Client application bug: DNSServiceResolve(BZDN1579092460-QkxaMDAwMjkzMTU4OTs4REFEejlEQkMzcEFFQTRDQUVE._bzdn._tcp.local.)
active for over two minutes. This places considerable burden on the network.

Error - 11/8/2010 2:39:44 AM | Computer Name = Lindsay-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 11/8/2010 2:39:44 AM | Computer Name = Lindsay-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 1092

Error - 11/8/2010 2:39:44 AM | Computer Name = Lindsay-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 1092

Error - 11/8/2010 2:39:45 AM | Computer Name = Lindsay-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 11/8/2010 2:39:45 AM | Computer Name = Lindsay-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 2091

Error - 11/8/2010 2:39:45 AM | Computer Name = Lindsay-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 2091

[ System Events ]
Error - 9/7/2010 10:03:41 PM | Computer Name = Lindsay-PC | Source = Service Control Manager | ID = 7031
Description =

Error - 9/7/2010 10:05:28 PM | Computer Name = Lindsay-PC | Source = Service Control Manager | ID = 7032
Description =

Error - 9/7/2010 10:05:31 PM | Computer Name = Lindsay-PC | Source = Service Control Manager | ID = 7031
Description =

Error - 9/8/2010 9:44:12 PM | Computer Name = Lindsay-PC | Source = DCOM | ID = 10005
Description =

Error - 9/8/2010 9:44:12 PM | Computer Name = Lindsay-PC | Source = Service Control Manager | ID = 7009
Description =

Error - 9/8/2010 9:44:12 PM | Computer Name = Lindsay-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 9/29/2010 1:13:55 AM | Computer Name = Lindsay-PC | Source = Service Control Manager | ID = 7031
Description =

Error - 10/3/2010 8:40:51 PM | Computer Name = Lindsay-PC | Source = Tcpip | ID = 4199
Description = The system detected an address conflict for IP address 192.168.2.2
with the system having network hardware address 00-22-48-91-2D-4C. Network operations
on this system may be disrupted as a result.

Error - 10/6/2010 8:42:51 PM | Computer Name = Lindsay-PC | Source = DCOM | ID = 10010
Description =

Error - 10/16/2010 1:50:14 AM | Computer Name = Lindsay-PC | Source = Service Control Manager | ID = 7031
Description =


< End of report >




Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 1:02:15 AM, on 11/22/2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18975)
Boot mode: Normal

Running processes:
C:\hp\support\hpsysdrv.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
C:\Program Files (x86)\AVG\AVG10\avgtray.exe
C:\Program Files (x86)\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
C:\hp\kbd\kbd.exe
C:\Program Files (x86)\AVG\AVG PC Tuneup 2011\boostspeed.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG10\avgssie.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG10\avgtray.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\RunOnce: [NSSInstallation] "C:\Program Files (x86)\DivX\Symantec\scstubinstaller.exe" /runonce
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: CurseClientStartup.ccip
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgpp.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: XAudioService - Unknown owner - C:\Windows\system32\DRIVERS\xaudio64.exe (file missing)

–
End of file - 7917 bytes









DDS (Ver_10-11-10.01) - NTFS_AMD64
Run by [removed] at 0:52:19.37 on Mon 11/22/2010
Internet Explorer: 8.0.6001.18975
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2940.1230 [GMT -6:00]

SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

============== Running Processes ===============

C:\PROGRA~2\AVG\AVG10\avgchsva.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\rundll32.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe
C:\Program Files (x86)\Bonjour\mDNSResponder.exe
C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\DRIVERS\xaudio64.exe
C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\Program Files (x86)\AVG\AVG10\avgnsa.exe
C:\Program Files (x86)\AVG\AVG10\avgemca.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\WINDOWS\System32\rundll32.exe
C:\hp\support\hpsysdrv.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
C:\Program Files (x86)\AVG\AVG10\avgtray.exe
C:\Program Files (x86)\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
C:\hp\kbd\kbd.exe
c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\PROGRA~2\AVG\AVG10\avgrsa.exe
C:\Program Files (x86)\AVG\AVG10\avgcsrva.exe
C:\Program Files (x86)\AVG\AVG PC Tuneup 2011\boostspeed.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Windows\system32\Dwm.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows NT\Accessories\wordpad.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Users\Lindsay\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FCE16CNV\dds[2].scr
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=84&bd=Pavilion&pf=cndt
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=84&bd=Pavilion&pf=cndt
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=84&bd=Pavilion&pf=cndt
uInternet Settings,ProxyOverride = *.local
mWinlogon: Userinit=userinit.exe
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - C:\Program Files (x86)\AVG\AVG10\avgssie.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
mRun: [hpsysdrv] c:\hp\support\hpsysdrv.exe
mRun: [KBD] C:\HP\KBD\KbdStub.EXE
mRun: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [HP Software Update] c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
mRun: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG10\avgtray.exe
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRunOnce: [NSSInstallation] "C:\Program Files (x86)\DivX\Symantec\scstubinstaller.exe" /runonce
StartupFolder: C:\Users\Lindsay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgpp.dll
BHO-X64: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG10\avgssiea.dll
BHO-X64: WormRadar.com IESiteBlocker.NavFilter - No File
mRun-x64: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun-x64: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
mRun-x64: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit

============= SERVICES / DRIVERS ===============

R0 AVGIDSEH;AVGIDSEH;C:\WINDOWS\System32\drivers\AVGIDSEH.sys [2010-9-13 27216]
R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\WINDOWS\System32\drivers\avgrkx64.sys [2010-9-7 30288]
R1 Avgldx64;AVG AVI Loader Driver;C:\WINDOWS\System32\drivers\avgldx64.sys [2010-9-7 305232]
R1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\WINDOWS\System32\drivers\avgmfx64.sys [2010-9-7 41040]
R1 Avgtdia;AVG TDI Driver;C:\WINDOWS\System32\drivers\avgtdia.sys [2010-9-7 381008]
R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [2010-10-11 6104656]
R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe [2010-9-10 265400]
R3 AVGIDSDriver;AVGIDSDriver;C:\WINDOWS\System32\drivers\AVGIDSDriver.sys [2010-8-19 133712]
R3 AVGIDSFilter;AVGIDSFilter;C:\WINDOWS\System32\drivers\AVGIDSFilter.sys [2010-8-19 35920]
R3 CAXHWBS2;CAXHWBS2;C:\WINDOWS\System32\drivers\CAXHWBS2.sys [2008-7-31 411136]
R3 netr7364;Belkin Wireless G Plus MIMO USB Network Adapter Driver for Vista;C:\WINDOWS\System32\drivers\netr7364.sys [2010-8-29 311296]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 FontCache;Windows Font Cache Service;C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 27648]
S3 PerfHost;Performance Counter DLL Host;C:\WINDOWS\SysWOW64\perfhost.exe [2008-1-20 19968]
S3 USBAAPL64;Apple Mobile USB Driver;C:\WINDOWS\System32\drivers\usbaapl64.sys [2010-4-19 50688]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-3-18 1020768]
S4 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;C:\WINDOWS\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [2010-8-29 89920]

=============== File Associations ===============

JSEFile=C:\Windows\SysWOW64\WScript.exe "%1" %*

=============== Created Last 30 ================

2010-11-22 05:56:58 388096 —-a-r- C:\Users\Lindsay\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-11-22 05:56:58 ——– d—–w- C:\Program Files (x86)\Trend Micro
2010-11-22 05:40:30 ——– d—–w- C:\Program Files\iPod
2010-11-22 05:40:28 ——– d—–w- C:\Program Files\iTunes
2010-11-22 05:40:28 ——– d—–w- C:\Program Files (x86)\iTunes
2010-11-22 05:12:31 ——– d—–w- C:\Users\Lindsay\AppData\Roaming\AVG
2010-11-12 02:09:44 ——– d—–w- C:\Program Files\Ventrilo
2010-11-12 02:08:56 ——– d—–w- C:\Program Files (x86)\Common Files\Wise Installation Wizard
2010-11-11 02:16:41 2409784 —-a-w- C:\Program Files\Windows Mail\OESpamFilter.dat
2010-11-11 02:16:41 2409784 —-a-w- C:\Program Files (x86)\Windows Mail\OESpamFilter.dat
2010-10-30 01:20:53 1927680 —-a-w- C:\Windows\System32\gameux.dll
2010-10-30 01:20:53 1696256 —-a-w- C:\Windows\SysWow64\gameux.dll
2010-10-30 01:20:52 32256 —-a-w- C:\Windows\System32\Apphlpdm.dll
2010-10-30 01:20:52 28672 —-a-w- C:\Windows\SysWow64\Apphlpdm.dll
2010-10-30 01:20:51 4240384 —-a-w- C:\Windows\SysWow64\GameUXLegacyGDFs.dll
2010-10-30 01:20:51 4240384 —-a-w- C:\Windows\System32\GameUXLegacyGDFs.dll

==================== Find3M ====================

2010-09-19 20:22:26 423656 —-a-w- C:\Windows\SysWow64\deployJava1.dll
2010-09-13 21:27:46 27216 —-a-w- C:\Windows\System32\drivers\AVGIDSEH.sys
2010-09-13 14:32:37 8147968 —-a-w- C:\Windows\System32\wmploc.DLL
2010-09-13 13:56:41 8147456 —-a-w- C:\Windows\SysWow64\wmploc.DLL
2010-09-08 16:17:46 94208 —-a-w- C:\Windows\SysWow64\QuickTimeVR.qtx
2010-09-08 16:17:46 69632 —-a-w- C:\Windows\SysWow64\QuickTime.qts
2010-09-08 06:41:05 1147904 —-a-w- C:\Windows\System32\wininet.dll
2010-09-08 06:36:53 56832 —-a-w- C:\Windows\System32\licmgr10.dll
2010-09-08 06:36:38 1538560 —-a-w- C:\Windows\System32\inetcpl.cpl
2010-09-08 06:36:24 132096 —-a-w- C:\Windows\System32\iesysprep.dll
2010-09-08 06:36:23 77312 —-a-w- C:\Windows\System32\iesetup.dll
2010-09-08 06:01:28 916480 —-a-w- C:\Windows\SysWow64\wininet.dll
2010-09-08 05:57:18 43520 —-a-w- C:\Windows\SysWow64\licmgr10.dll
2010-09-08 05:57:05 1469440 —-a-w- C:\Windows\SysWow64\inetcpl.cpl
2010-09-08 05:56:53 71680 —-a-w- C:\Windows\SysWow64\iesetup.dll
2010-09-08 05:56:53 109056 —-a-w- C:\Windows\SysWow64\iesysprep.dll
2010-09-08 05:36:07 479232 —-a-w- C:\Windows\System32\html.iec
2010-09-08 05:04:36 385024 —-a-w- C:\Windows\SysWow64\html.iec
2010-09-08 04:51:18 162816 —-a-w- C:\Windows\System32\ieUnatt.exe
2010-09-08 04:49:56 1638912 —-a-w- C:\Windows\System32\mshtml.tlb
2010-09-08 04:26:46 133632 —-a-w- C:\Windows\SysWow64\ieUnatt.exe
2010-09-08 04:25:15 1638912 —-a-w- C:\Windows\SysWow64\mshtml.tlb
2010-09-07 08:48:58 381008 —-a-w- C:\Windows\System32\drivers\avgtdia.sys
2010-09-07 08:48:56 41040 —-a-w- C:\Windows\System32\drivers\avgmfx64.sys
2010-09-07 08:48:52 305232 —-a-w- C:\Windows\System32\drivers\avgldx64.sys
2010-09-07 08:48:50 30288 —-a-w- C:\Windows\System32\drivers\avgrkx64.sys
2010-09-06 18:28:38 179712 —-a-w- C:\Windows\System32\srvsvc.dll
2010-09-06 18:28:38 12288 —-a-w- C:\Windows\System32\sscore.dll
2010-09-06 18:27:03 17920 —-a-w- C:\Windows\System32\netevent.dll
2010-09-06 16:20:29 9728 —-a-w- C:\Windows\SysWow64\sscore.dll
2010-09-06 16:19:06 17920 —-a-w- C:\Windows\SysWow64\netevent.dll
2010-09-06 15:34:14 451584 —-a-w- C:\Windows\System32\drivers\srv.sys
2010-09-06 15:33:51 175104 —-a-w- C:\Windows\System32\drivers\srv2.sys
2010-09-06 15:33:49 145920 —-a-w- C:\Windows\System32\drivers\srvnet.sys
2010-08-31 17:27:07 633856 —-a-w- C:\Windows\System32\comctl32.dll
2010-08-31 15:46:37 954752 —-a-w- C:\Windows\SysWow64\mfc40.dll
2010-08-31 15:46:37 954288 —-a-w- C:\Windows\SysWow64\mfc40u.dll
2010-08-31 15:44:31 531968 —-a-w- C:\Windows\SysWow64\comctl32.dll
2010-08-31 14:57:39 2753024 —-a-w- C:\Windows\System32\win32k.sys
2010-08-26 17:46:52 189952 —-a-w- C:\Windows\System32\t2embed.dll
2010-08-26 17:40:08 100352 —-a-w- C:\Windows\apppatch\AppPatch64\acspecfc.dll
2010-08-26 17:40:07 331776 —-a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll
2010-08-26 17:40:07 284672 —-a-w- C:\Windows\apppatch\AppPatch64\AcGenral.dll
2010-08-26 16:37:45 157184 —-a-w- C:\Windows\SysWow64\t2embed.dll
2010-08-26 16:33:06 173056 —-a-w- C:\Windows\apppatch\AcXtrnal.dll
2010-08-26 16:33:04 542720 —-a-w- C:\Windows\apppatch\AcLayers.dll
2010-08-26 16:33:04 458752 —-a-w- C:\Windows\apppatch\AcSpecfc.dll
2010-08-26 16:33:04 2159616 —-a-w- C:\Windows\apppatch\AcGenral.dll

============= FINISH: 0:52:51.63 ===============
Hello dekete and welcome to WhatTheTech. Please follow these guidelines while we work on your PC:
  • Malware removal is a sometimes lengthy and tedious process. Please stick with the thread until I’ve given you the “All clear.” Absence of symptoms does not mean your machine is clean!
  • Please do not run any scans or install/uninstall any applications without being directed to do so.
  • Please follow my instructions carefully and in the order they are posted.
  • Any underlined text in my posts indicates a clickable link.
  • You should print any instructions I give you for ease of use and reference.
  • If you have any questions at all, please stop and ask before proceeding.
🖼Click to load external image (Posted Image) P2P - I see you have P2P software (uTorrent) installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to malware infections. Please see this post for more information. I recommend that you uninstall these now. You can do so via Control Panel >> Add or Remove Programs. If you choose to keep these applications, please do not use them until our fixes at WTT are complete.

🖼Click to load external image (Posted Image) Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
    O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
    O33 - MountPoints2\{1e8f068d-b2c4-11df-8443-806e6f6e6963}\Shell - "" = AutoRun
    O33 - MountPoints2\{1e8f068d-b2c4-11df-8443-806e6f6e6963}\Shell\AutoRun\command - "" = F:\SetupAssistant.exe – File not found
    :Commands
    [EmptyFlash]
    [EmptyTemp]
    [Purity]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, it will reboot when it is done and produce a log
🖼Click to load external image (Posted Image) Please download Malwarebytes' Anti-Malware to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform Quick Scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please post the results.
Please include the following in your next post:
  • MBAM log
  • OTL Fix log
I went out of town and my last log was closed :(. Here is what was requested I do and my info from that will follow:

Hello dekete and welcome to WhatTheTech. Please follow these guidelines while we work on your PC:

•Malware removal is a sometimes lengthy and tedious process. Please stick with the thread until I’ve given you the “All clear.” Absence of symptoms does not mean your machine is clean!
•Please do not run any scans or install/uninstall any applications without being directed to do so.
•Please follow my instructions carefully and in the order they are posted.
•Any underlined text in my posts indicates a clickable link.
•You should print any instructions I give you for ease of use and reference.
•If you have any questions at all, please stop and ask before proceeding.

Run OTL.exe

•Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

CODE:OTL
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O33 - MountPoints2\{1e8f068d-b2c4-11df-8443-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{1e8f068d-b2c4-11df-8443-806e6f6e6963}\Shell\AutoRun\command - "" = F:\SetupAssistant.exe – File not found
:Commands
[EmptyFlash]
[EmptyTemp]
[Purity]

•Then click the Run Fix button at the top
•Let the program run unhindered, it will reboot when it is done and produce a log

Please download Malwarebytes' Anti-Malware to your desktop.

•Double-click mbam-setup.exe and follow the prompts to install the program.
•At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
•If an update is found, it will download and install the latest version.
•Once the program has loaded, select Perform Quick Scan, then click Scan.
•When the scan is complete, click OK, then Show Results to view the results.
•Be sure that everything is checked, and click Remove Selected.
•When completed, a log will open in Notepad. Please post the results.

Please include the following in your next post:

•MBAM log
•OTL Fix log



Here is the info from that:


Malwarebytes' Anti-Malware 1.50
www.malwarebytes.org

Database version: 5304

Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18975

12/12/2010 11:36:14 PM
mbam-log-2010-12-12 (23-36-14).txt

Scan type: Quick scan
Objects scanned: 148512
Time elapsed: 3 minute(s), 1 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


—————– OTL LOG———————-

All processes killed
========== OTL ==========
Starting removal of ActiveX control {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
C:\Windows\Downloaded Program Files\gp.inf not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ms-itss\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0A9007C0-4076-11D3-8789-0000F8105754}\ not found.
File {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1e8f068d-b2c4-11df-8443-806e6f6e6963}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1e8f068d-b2c4-11df-8443-806e6f6e6963}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1e8f068d-b2c4-11df-8443-806e6f6e6963}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1e8f068d-b2c4-11df-8443-806e6f6e6963}\ not found.
File F:\SetupAssistant.exe not found.
========== COMMANDS ==========

[EMPTYFLASH]

User: All Users

User: Default

User: Default User

User: Lindsay
->Flash cache emptied: 611 bytes

User: Public

Total Flash Files Cleaned = 0.00 mb


[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Lindsay
->Temp folder emptied: 936557 bytes
->Temporary Internet Files folder emptied: 176704765 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 366 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 13790469071 bytes

Total Files Cleaned = 13,321.00 mb


OTL by OldTimer - Version 3.2.17.3 log created on 12122010_232335

Files\Folders moved on Reboot…
File\Folder C:\Users\Lindsay\AppData\Local\Temp\~DFA977.tmp not found!
File\Folder C:\Users\Lindsay\AppData\Local\Temp\~DFA97C.tmp not found!
File\Folder C:\Users\Lindsay\AppData\Local\Temp\~DFA9CE.tmp not found!
File\Folder C:\Users\Lindsay\AppData\Local\Temp\~DFA9D3.tmp not found!
File\Folder C:\Users\Lindsay\AppData\Local\Temp\~DFA9FA.tmp not found!
File\Folder C:\Users\Lindsay\AppData\Local\Temp\~DFA9FF.tmp not found!
C:\Users\Lindsay\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MJLK4JLE\iframe[1].htm moved successfully.
File\Folder C:\Users\Lindsay\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MJLK4JLE\like[3].htm not found!
C:\Users\Lindsay\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I133SW3A\index[1].htm moved successfully.
File\Folder C:\Users\Lindsay\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6Q2E8VI\iframe[1].htm not found!
File\Folder C:\Users\Lindsay\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5ESFE013\iframe[1].htm not found!

Registry entries deleted on Reboot…



New Hijiack this log:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:41:48 PM, on 12/12/2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18975)
Boot mode: Normal

Running processes:
C:\hp\support\hpsysdrv.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
C:\Program Files (x86)\AVG\AVG10\avgtray.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\hp\kbd\kbd.exe
C:\Windows\SysWOW64\NOTEPAD.EXE
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf=cndt
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf=cndt
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf=cndt
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG10\avgssie.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG10\avgtray.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /install /silent
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: CurseClientStartup.ccip
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgpp.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: XAudioService - Unknown owner - C:\Windows\system32\DRIVERS\xaudio64.exe (file missing)

–
End of file - 7619 bytes


Thanks!
dekete:

I merged your two thread to keep all of the information in one place. If you are going to be unable to respond within 5 days again, please let me know in advance and I'll leave the thread open.

Is youur computer running any better? Please do this next:

🖼Click to load external image (Posted Image) Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system.

Java™ 6 Update 21 can be updated from the Java control panel Start > Control Panel (Classic View) > Java (looks like a coffee cup) > Update Tab > Update Now. An update should begin; follow the prompts. If it does not, let me know.

Once the install is complete…

Go into the Control Panel and double-click the Java Icon. (looks like a coffee cup)
  • On the General tab, under Temporary Internet Files, click the Settings button.
  • Next, click on the Delete Files button
  • There are two options in the window to clear the cache - Leave BOTH Checked
    • Applications and Applets
    • Trace and Log Files
  • Click OK on Delete Temporary Files Window
Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.
🖼Click to load external image (Posted Image) Please download MBRCheck.exe to your desktop.
  • Be sure to disable your security programs
  • Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A small window should open on your desktop
  • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
  • If nothing unusual is found just press Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your deskop. Please post the contents of that file.
🖼Click to load external image (Posted Image) Please run ESET Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Do Not place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.
Please include the following in your next post:
  • ESET log
  • MBRCheck log
  • How is your computer running now?
Everything seems to be working quicker! Thanks. When I boot up my computer I still have a lot of black screen (like it's not quite loading up right), but it doesnt seem to be hurting anything. ESETSmartInstaller@High as CAB hook log: OnlineScanner64.ocx - registred OK OnlineScanner.ocx - registred OK # version=7 # iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339) # OnlineScanner.ocx=1.0.0.6419 # api_version=3.0.2 # EOSSerial=6bc0b6cd2fee8140bb8c6f959899b141 # end=finished # remove_checked=true # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2010-12-20 07:31:31 # local_time=2010-12-20 01:31:31 (-0600, Central Standard Time) # country="United States" # lang=1033 # osver=6.0.6002 NT Service Pack 2 # compatibility_mode=512 16777215 100 0 1547193 1547193 0 0 # compatibility_mode=1032 16777213 100 88 0 50440665 0 0 # compatibility_mode=5892 16776574 100 56 4996455 129469317 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=160980 # found=0 # cleaned=0 # scan_time=2880 MBRCheck, version 1.2.3 © 2010, AD Command-line: Windows Version: Windows Vista Home Premium Edition Windows Information: Service Pack 2 (build 6002), 64-bit Base Board Manufacturer: FOXCONN BIOS Manufacturer: Phoenix Technologies, LTD System Manufacturer: HP-Pavilion System Product Name: FK792AA-ABA a6600f Logical Drives Mask: 0x0000003c Kernel Drivers (total 145): 0x01C65000 \SystemRoot\system32\ntoskrnl.exe 0x01C1F000 \SystemRoot\system32\hal.dll 0x0060B000 \SystemRoot\system32\kdcom.dll 0x00615000 \SystemRoot\system32\mcupdate_GenuineIntel.dll 0x00650000 \SystemRoot\system32\PSHED.dll 0x00664000 \SystemRoot\system32\CLFS.SYS 0x006C1000 \SystemRoot\system32\CI.dll 0x00802000 \SystemRoot\system32\drivers\Wdf01000.sys 0x008DC000 \SystemRoot\system32\drivers\WDFLDR.SYS 0x008EA000 \SystemRoot\system32\drivers\acpi.sys 0x00940000 \SystemRoot\system32\drivers\WMILIB.SYS 0x00949000 \SystemRoot\system32\drivers\msisadrv.sys 0x00953000 \SystemRoot\system32\drivers\pci.sys 0x00983000 \SystemRoot\System32\drivers\partmgr.sys 0x00998000 \SystemRoot\system32\drivers\volmgr.sys 0x00773000 \SystemRoot\System32\drivers\volmgrx.sys 0x009AC000 \SystemRoot\system32\drivers\pciide.sys 0x009B3000 \SystemRoot\system32\drivers\PCIIDEX.SYS 0x009C3000 \SystemRoot\System32\drivers\mountmgr.sys 0x009D6000 \SystemRoot\system32\drivers\atapi.sys 0x007D9000 \SystemRoot\system32\drivers\ataport.SYS 0x00A09000 \SystemRoot\system32\drivers\fltmgr.sys 0x00A50000 \SystemRoot\system32\drivers\fileinfo.sys 0x00A64000 \SystemRoot\System32\Drivers\ksecdd.sys 0x00C01000 \SystemRoot\system32\drivers\ndis.sys 0x00AEB000 \SystemRoot\system32\drivers\msrpc.sys 0x00B3B000 \SystemRoot\system32\drivers\NETIO.SYS 0x00E0C000 \SystemRoot\System32\drivers\tcpip.sys 0x00F82000 \SystemRoot\System32\drivers\fwpkclnt.sys 0x01004000 \SystemRoot\System32\Drivers\Ntfs.sys 0x01184000 \SystemRoot\system32\drivers\volsnap.sys 0x011C8000 \SystemRoot\System32\Drivers\spldr.sys 0x011D0000 \SystemRoot\System32\Drivers\mup.sys 0x00FAE000 \SystemRoot\System32\drivers\ecache.sys 0x011E2000 \SystemRoot\system32\drivers\disk.sys 0x00DC4000 \SystemRoot\system32\drivers\CLASSPNP.SYS 0x011F6000 \SystemRoot\system32\drivers\crcdisk.sys 0x00FDA000 \SystemRoot\system32\DRIVERS\avgrkx64.sys 0x00FE4000 \SystemRoot\system32\DRIVERS\AVGIDSEH.Sys 0x00B94000 \SystemRoot\system32\DRIVERS\tunnel.sys 0x00BA0000 \SystemRoot\system32\DRIVERS\tunmp.sys 0x00BA9000 \SystemRoot\system32\DRIVERS\intelppm.sys 0x00BBC000 \SystemRoot\system32\DRIVERS\i8042prt.sys 0x00BD2000 \SystemRoot\system32\DRIVERS\mouclass.sys 0x00BDE000 \SystemRoot\system32\DRIVERS\PS2.sys 0x00BE7000 \SystemRoot\system32\DRIVERS\kbdclass.sys 0x00BF5000 \SystemRoot\system32\DRIVERS\usbohci.sys 0x02004000 \SystemRoot\system32\DRIVERS\USBPORT.SYS 0x0204A000 \SystemRoot\system32\DRIVERS\usbehci.sys 0x0205B000 \SystemRoot\system32\DRIVERS\HDAudBus.sys 0x02148000 \SystemRoot\system32\DRIVERS\CAXHWBS2.sys 0x021B8000 \SystemRoot\system32\DRIVERS\ks.sys 0x02208000 \SystemRoot\system32\DRIVERS\CAX_DP.sys 0x02408000 \SystemRoot\system32\DRIVERS\CAX_CNXT.sys 0x024D3000 \SystemRoot\system32\drivers\modem.sys 0x024E2000 \SystemRoot\system32\DRIVERS\ohci1394.sys 0x024F4000 \SystemRoot\system32\DRIVERS\1394BUS.SYS 0x02504000 \SystemRoot\system32\DRIVERS\cdrom.sys 0x02520000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys 0x0260F000 \SystemRoot\system32\DRIVERS\nvmfdx64.sys 0x02805000 \SystemRoot\system32\DRIVERS\nvlddmkm.sys 0x03208000 \SystemRoot\System32\drivers\dxgkrnl.sys 0x032EB000 \SystemRoot\System32\drivers\watchdog.sys 0x032FB000 \SystemRoot\system32\DRIVERS\wmiacpi.sys 0x03304000 \SystemRoot\system32\DRIVERS\msiscsi.sys 0x0333D000 \SystemRoot\system32\DRIVERS\storport.sys 0x0339A000 \SystemRoot\system32\DRIVERS\TDI.SYS 0x033A7000 \SystemRoot\system32\DRIVERS\rasl2tp.sys 0x033CA000 \SystemRoot\system32\DRIVERS\ndistapi.sys 0x03125000 \SystemRoot\system32\DRIVERS\ndiswan.sys 0x033D6000 \SystemRoot\system32\DRIVERS\raspppoe.sys 0x03156000 \SystemRoot\system32\DRIVERS\raspptp.sys 0x033E6000 \SystemRoot\system32\DRIVERS\rassstp.sys 0x03174000 \SystemRoot\system32\DRIVERS\termdd.sys 0x033FE000 \SystemRoot\system32\DRIVERS\swenum.sys 0x03187000 \SystemRoot\system32\DRIVERS\mssmbios.sys 0x03192000 \SystemRoot\system32\DRIVERS\umbus.sys 0x031A2000 \SystemRoot\system32\DRIVERS\usbhub.sys 0x031EA000 \SystemRoot\System32\Drivers\NDProxy.SYS 0x03407000 \SystemRoot\system32\drivers\RTKVHD64.sys 0x0356F000 \SystemRoot\system32\drivers\portcls.sys 0x035AA000 \SystemRoot\system32\drivers\drmk.sys 0x035CD000 \SystemRoot\system32\drivers\ksthunk.sys 0x035D3000 \SystemRoot\system32\DRIVERS\avgmfx64.sys 0x035E2000 \SystemRoot\System32\Drivers\Fs_Rec.SYS 0x035EC000 \SystemRoot\System32\Drivers\Null.SYS 0x0277B000 \SystemRoot\System32\drivers\vga.sys 0x02789000 \SystemRoot\System32\drivers\VIDEOPRT.SYS 0x035F5000 \SystemRoot\System32\DRIVERS\RDPCDD.sys 0x027AE000 \SystemRoot\system32\drivers\rdpencdd.sys 0x027B7000 \SystemRoot\System32\Drivers\Msfs.SYS 0x027C2000 \SystemRoot\System32\Drivers\Npfs.SYS 0x027D3000 \SystemRoot\System32\DRIVERS\rasacd.sys 0x027DC000 \SystemRoot\system32\DRIVERS\tdx.sys 0x0252D000 \SystemRoot\system32\DRIVERS\smb.sys 0x02548000 \SystemRoot\system32\DRIVERS\avgtdia.sys 0x025A9000 \SystemRoot\System32\DRIVERS\netbt.sys 0x0237C000 \SystemRoot\system32\drivers\afd.sys 0x0360A000 \SystemRoot\system32\DRIVERS\netr7364.sys 0x0365C000 \SystemRoot\system32\DRIVERS\pacer.sys 0x0367A000 \SystemRoot\system32\DRIVERS\netbios.sys 0x03689000 \SystemRoot\system32\DRIVERS\wanarp.sys 0x036A4000 \SystemRoot\system32\DRIVERS\rdbss.sys 0x036F1000 \SystemRoot\system32\drivers\nsiproxy.sys 0x036FD000 \SystemRoot\System32\Drivers\dfsc.sys 0x0371A000 \SystemRoot\system32\DRIVERS\avgldx64.sys 0x03769000 \SystemRoot\system32\DRIVERS\usbccgp.sys 0x03785000 \SystemRoot\system32\DRIVERS\USBD.SYS 0x03787000 \SystemRoot\system32\drivers\usbaudio.sys 0x037A0000 \SystemRoot\system32\DRIVERS\hidusb.sys 0x037A9000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS 0x037BB000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS 0x037C3000 \SystemRoot\System32\Drivers\crashdmp.sys 0x037D1000 \SystemRoot\System32\Drivers\dump_dumpata.sys 0x037DD000 \SystemRoot\System32\Drivers\dump_atapi.sys 0x000B0000 \SystemRoot\System32\win32k.sys 0x037E5000 \SystemRoot\System32\drivers\Dxapi.sys 0x025ED000 \SystemRoot\system32\DRIVERS\monitor.sys 0x00490000 \SystemRoot\System32\TSDDD.dll 0x00630000 \SystemRoot\System32\cdd.dll 0x009DE000 \SystemRoot\system32\drivers\luafv.sys 0x023E7000 \SystemRoot\system32\DRIVERS\lltdio.sys 0x07A0C000 \SystemRoot\system32\DRIVERS\nwifi.sys 0x07A40000 \SystemRoot\system32\DRIVERS\ndisuio.sys 0x07A4B000 \SystemRoot\system32\DRIVERS\rspndr.sys 0x07A63000 \SystemRoot\system32\drivers\spsys.sys 0x07AFD000 \SystemRoot\system32\drivers\HTTP.sys 0x07BA0000 \SystemRoot\System32\DRIVERS\srvnet.sys 0x07BC9000 \SystemRoot\system32\DRIVERS\bowser.sys 0x07C08000 \SystemRoot\System32\drivers\mpsdrv.sys 0x07C22000 \SystemRoot\system32\drivers\mrxdav.sys 0x07C49000 \SystemRoot\system32\DRIVERS\mrxsmb.sys 0x07C72000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys 0x07CBB000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys 0x07CDA000 \SystemRoot\System32\DRIVERS\srv2.sys 0x07D0C000 \SystemRoot\System32\DRIVERS\srv.sys 0x07DA0000 \SystemRoot\system32\DRIVERS\AVGIDSFilter.Sys 0x07DAC000 \SystemRoot\system32\DRIVERS\mdmxsdk.sys 0x08204000 \SystemRoot\system32\drivers\peauth.sys 0x082BA000 \SystemRoot\System32\Drivers\secdrv.SYS 0x082C5000 \SystemRoot\System32\drivers\tcpipreg.sys 0x082D5000 \SystemRoot\system32\DRIVERS\xaudio64.sys 0x082DD000 \SystemRoot\system32\DRIVERS\AVGIDSDriver.Sys 0x0830B000 \SystemRoot\system32\DRIVERS\cdfs.sys 0x76E20000 \WINDOWS\System32\ntdll.dll Processes (total 54): 0 System Idle Process 4 System 452 C:\WINDOWS\System32\smss.exe 828 csrss.exe 900 C:\WINDOWS\System32\wininit.exe 912 csrss.exe 948 C:\WINDOWS\System32\services.exe 964 C:\WINDOWS\System32\lsass.exe 972 C:\WINDOWS\System32\lsm.exe 292 C:\WINDOWS\System32\winlogon.exe 788 C:\WINDOWS\System32\svchost.exe 844 C:\WINDOWS\System32\nvvsvc.exe 928 C:\WINDOWS\System32\svchost.exe 744 C:\WINDOWS\System32\svchost.exe 1040 C:\WINDOWS\System32\svchost.exe 1080 C:\WINDOWS\System32\svchost.exe 1140 C:\WINDOWS\System32\audiodg.exe 1188 C:\WINDOWS\System32\svchost.exe 1212 C:\WINDOWS\System32\SLsvc.exe 1304 C:\WINDOWS\System32\rundll32.exe 1328 C:\WINDOWS\System32\svchost.exe 1464 C:\WINDOWS\System32\svchost.exe 1688 C:\WINDOWS\System32\spoolsv.exe 1712 C:\WINDOWS\System32\svchost.exe 1948 C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 1996 C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe 2024 C:\Program Files (x86)\Bonjour\mDNSResponder.exe 1092 C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe 1512 C:\WINDOWS\System32\svchost.exe 1924 C:\WINDOWS\System32\svchost.exe 696 C:\WINDOWS\System32\svchost.exe 1536 C:\WINDOWS\System32\SearchIndexer.exe 2236 C:\WINDOWS\System32\drivers\XAudio64.exe 2608 C:\WINDOWS\System32\taskeng.exe 1372 C:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Service.exe 3020 C:\WINDOWS\System32\taskeng.exe 3528 C:\WINDOWS\System32\dwm.exe 3392 C:\WINDOWS\explorer.exe 3660 C:\WINDOWS\System32\rundll32.exe 3672 C:\hp\support\hpsysdrv.exe 2752 C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe 3236 C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe 3712 C:\Program Files (x86)\AVG\AVG10\avgtray.exe 4076 C:\Program Files (x86)\iTunes\iTunesHelper.exe 3704 C:\Program Files\iPod\bin\iPodService.exe 664 C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe 2448 C:\hp\KBD\kbd.exe 3216 C:\WINDOWS\System32\msiexec.exe 3800 C:\Program Files (x86)\Internet Explorer\iexplore.exe 3172 C:\Program Files (x86)\Internet Explorer\iexplore.exe 1552 C:\Program Files (x86)\Internet Explorer\iexplore.exe 2068 C:\WINDOWS\System32\SearchProtocolHost.exe 3208 C:\WINDOWS\System32\SearchFilterHost.exe 584 C:\Users\Lindsay\Desktop\MBRCheck.exe \\.\C: –> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS) \\.\D: –> \\.\PhysicalDrive0 at offset 0x00000047`7c258000 (NTFS) PhysicalDrive0 Model Number: SAMSUNGHD320KJ, Rev: CP100-13 Size Device Name MBR Status ——————————————– 298 GB \\.\PhysicalDrive0 Hewlett-Packard MBR code detected SHA1: F362CE084BC77B454330005C1657154A64FB9456
dekete:

Your logs all look good! Now I have another update and some very important cleanup for you to take care of:

🖼Click to load external image (Posted Image) Your Adobe reader needs to be updated. Please visit Adobe's site and grab the newest version. Be sure to watch for and uncheck any boxes offering to install other software.

🖼Click to load external image (Posted Image) Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.
  • Manually delete any remaining logs or tools.
🖼Click to load external image (Posted Image) Finally, I'd like to make a couple of suggestions to help you stay clean in the future:
  • Restart any anti-malware programs that we disabled while we were cleaning your machine.
  • Keep your antivirus application current and updated. Also, hang on to MBAM. Scan with them at least weekly.
  • Avoid using P2P programs. Refer back to my earlier post for more information.
  • Please carefully review the information in the Security - Best Practices and Prevention forum located HERE
Please post once more so I know you are all set and I can close this thread. Good luck and stay safe!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI