This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Serious Infection-Malware!

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

I am in desperate need, my pc has been acting very odd the last 2-3 days, Its very sluggish and I'm getting lots of 'Not Responding' this is happening on things like firefox and word but also sometimes even my start button and control panel say not responding and I get no icons.

I have not installed anything new in the last week or so and I always defrag my drive weekly and do avg free antivirus scans and malwarebytes antimalware scans every few days. I'm disabled and my pc is my only link to my friends and as its the only pc I have I'm desperately worried about this. please help me.

I even freshly installed Win 7 yesterday hoping that would fix it but no, its the same.

I have followed the instructions in the sticky and downloaded and run OTL with the settings you said. I will post the logs it made.

OTL Extras logfile created on: 04/03/2011 10:48:35 - Run 1
OTL by OldTimer - Version 3.2.22.2 Folder = C:\Users\Steve\Desktop
Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 69.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 82.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 458.92 Gb Total Space | 318.08 Gb Free Space | 69.31% Space Free | Partition Type: NTFS

Computer Name: STEVE-PC | User Name: Steve | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{11083C7A-D0D6-4DA4-8C3A-74B8389EC07B}" = ATI Catalyst Registration
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{26A24AE4-039D-4CA4-87B4-2F83216024FF}" = Java™ 6 Update 24
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{5229C090-842B-1CB0-1676-43E421294B5C}" = AMD Drag and Drop Transcoding
"{5968F27A-66E6-171E-5311-0A74D74AAD9B}" = ATI Catalyst Install Manager
"{5FD89EA1-99C2-40EE-BBF5-20F8991ED756}" = Catalyst Control Center - Branding
"{7ED4E9AB-9B5D-5380-9AB7-2865CA1DA0DB}" = AMD Fuel
"{85092B90-AEB2-2E30-0EF1-432EC61F6BD1}" = Catalyst Control Center InstallProxy
"{86B247F9-1D5E-CCC6-3280-71486D9A4E70}" = ATI Stream SDK v2 Developer
"{8ACC73AA-6511-7C55-B1A9-8E5D1DEAFAA3}" = The Lord of the Rings FREE Trial
"{A276502A-8979-44FB-8090-90CF72F22ABC}" = AVG 2011
"{C7EA1AF1-F908-0832-AA52-5EDBE128FD6B}" = ccc-core-static
"{E9D4FBA9-FB46-A5CE-F52F-516C4B8F0373}" = ccc-utility
"{EB0E062C-575D-8154-2682-C84EF432CCF0}" = Catalyst Control Center Graphics Previews Common
"{EDD7B70D-36D0-694D-AA34-D566A13CE98D}" = WMV9/VC-1 Video Playback
"{EEA54973-AFC8-21C8-1414-246AA9435890}" = CCC Help English
"{F4C68898-EBA5-46A9-82B3-2D30426086BF}" = AVG 2011
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AVG" = AVG 2011
"Bandwidth Monitor_is1" = Bandwidth Monitor
"CPUID HWMonitor_is1" = CPUID HWMonitor 1.17
"MailWasher Free_is1" = MailWasher Free 6.5.4
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"mIRC" = mIRC
"Mozilla Firefox (3.6.14)" = Mozilla Firefox (3.6.14)
"PC Tools Firewall Plus" = PC Tools Firewall Plus 7.0
"Sophos-AntiRootkit" = Sophos Anti-Rootkit 1.5.4

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 03/03/2011 10:17:22 | Computer Name = Steve-PC | Source = MsiInstaller | ID = 10005
Description =

Error - 03/03/2011 10:18:12 | Computer Name = Steve-PC | Source = Microsoft-Windows-CAPI2 | ID = 4110
Description = Failed to add certificate to Third-Party Root Certification Authorities
store with error: A certificate chain could not be built to a trusted root authority.


Error - 03/03/2011 10:18:12 | Computer Name = Steve-PC | Source = Microsoft-Windows-CAPI2 | ID = 4110
Description = Failed to add certificate to Third-Party Root Certification Authorities
store with error: A certificate chain could not be built to a trusted root authority.


Error - 03/03/2011 10:18:12 | Computer Name = Steve-PC | Source = Microsoft-Windows-CAPI2 | ID = 4110
Description = Failed to add certificate to Third-Party Root Certification Authorities
store with error: A certificate chain could not be built to a trusted root authority.


Error - 03/03/2011 10:18:49 | Computer Name = Steve-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Program Files\AVG\AVG10\avgui.exe".
Dependent
Assembly Microsoft.VC90.MFC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 03/03/2011 11:20:31 | Computer Name = Steve-PC | Source = ATIeRecord | ID = 16389
Description = ATI EEU the creation of a class has failed

Error - 03/03/2011 15:32:43 | Computer Name = Steve-PC | Source = EventSystem | ID = 4621
Description =

Error - 03/03/2011 20:44:42 | Computer Name = Steve-PC | Source = VSS | ID = 8194
Description =

Error - 03/03/2011 20:53:20 | Computer Name = Steve-PC | Source = Application Hang | ID = 1002
Description = The program mbam.exe version 1.50.1.3 stopped interacting with Windows
and was closed. To see if more information about the problem is available, check
the problem history in the Action Center control panel. Process ID: 15c8 Start Time:
01cbda06761085ed Termination Time: 20193 Application Path: C:\Program Files\Malwarebytes'
Anti-Malware\mbam.exe Report Id: be56b184-45f9-11e0-a80f-002268099d6c

Error - 03/03/2011 20:53:28 | Computer Name = Steve-PC | Source = Microsoft-Windows-CAPI2 | ID = 4110
Description = Failed to add certificate to Third-Party Root Certification Authorities
store with error: Illegal operation attempted on a registry key that has been marked
for deletion.

[ System Events ]
Error - 03/03/2011 12:25:20 | Computer Name = Steve-PC | Source = Service Control Manager | ID = 7023
Description = The Windows Modules Installer service terminated with the following
error: %%16405

Error - 03/03/2011 20:07:54 | Computer Name = Steve-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 00:06:52 on ?04/?03/?2011 was unexpected.

Error - 04/03/2011 06:36:14 | Computer Name = Steve-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 00:54:55 on ?04/?03/?2011 was unexpected.


< End of report >
OTL logfile created on: 04/03/2011 10:48:35 - Run 1
OTL by OldTimer - Version 3.2.22.2 Folder = C:\Users\Steve\Desktop
Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 69.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 82.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 458.92 Gb Total Space | 318.08 Gb Free Space | 69.31% Space Free | Partition Type: NTFS

Computer Name: STEVE-PC | User Name: Steve | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Steve\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Windows\System32\atieclxx.exe (AMD)
PRC - C:\Windows\System32\atiesrxx.exe (AMD)
PRC - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Advanced Micro Devices, Inc.)
PRC - C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgemcx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe (PC Tools)
PRC - C:\Program Files\PC Tools Firewall Plus\FWService.exe (PC Tools)
PRC - C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe (Advanced Micro Devices)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Windows\System32\conhost.exe (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - C:\Users\Steve\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (AMD External Events Utility) – C:\Windows\System32\atiesrxx.exe (AMD)
SRV - (AMD FUEL Service) – C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Advanced Micro Devices, Inc.)
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (PCToolsFirewallPlus) – C:\Program Files\PC Tools Firewall Plus\FWService.exe (PC Tools)
SRV - (avgwd) – C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (AMD Reservation Manager) – C:\Program Files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe (Advanced Micro Devices)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (atikmdag) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (amdkmdag) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (amdkmdap) – C:\Windows\System32\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV - (Avgldx86) – C:\Windows\System32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (PCTAppEvent) – C:\Windows\System32\drivers\PCTAppEvent.sys (PC Tools)
DRV - (pctplfw) – C:\Windows\System32\drivers\pctplfw.sys (PC Tools)
DRV - (PCTFW-PacketFilter) – C:\Windows\System32\drivers\pctNdis-PacketFilter.sys (PC Tools)
DRV - (AtiHDAudioService) – C:\Windows\System32\drivers\AtihdW73.sys (Advanced Micro Devices)
DRV - (pctgntdi) – C:\Windows\System32\drivers\pctgntdi.sys (PC Tools)
DRV - (Avgtdix) – C:\Windows\System32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (cpuz135) – C:\Windows\System32\drivers\cpuz135_x32.sys (CPUID)
DRV - (AVGIDSEH) – C:\Windows\system32\DRIVERS\AVGIDSEH.Sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgmfx86) – C:\Windows\System32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) – C:\Windows\system32\DRIVERS\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSShim) – C:\Windows\System32\drivers\AVGIDSShim.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSDriver) – C:\Windows\System32\drivers\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSFilter) – C:\Windows\System32\drivers\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV - (pctNdisMP) – C:\Windows\System32\drivers\pctNdis.sys (PC Tools)
DRV - (pctNdis) – C:\Windows\System32\drivers\pctNdis.sys (PC Tools)
DRV - (amdiox86) – C:\Windows\System32\drivers\amdiox86.sys (Advanced Micro Devices)
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://uk.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-gb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 86 A6 96 EF AC D9 CB 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "www.google.com"
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:10.0.0.1178
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24

FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG10\Firefox\ [2011/03/03 14:26:48 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.14\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/03/03 14:18:47 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.14\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/03/03 15:13:50 | 000,000,000 | —D | M]

[2011/03/03 14:18:56 | 000,000,000 | —D | M] (No name found) – C:\Users\Steve\AppData\Roaming\Mozilla\Extensions
[2011/03/03 14:18:56 | 000,000,000 | —D | M] (No name found) – C:\Users\Steve\AppData\Roaming\Mozilla\Firefox\Profiles\pl81vg95.default\extensions
[2011/03/03 15:13:51 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/03/03 15:13:52 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/03/03 14:26:48 | 000,000,000 | —D | M] (AVG Safe Search) – C:\PROGRAM FILES\AVG\AVG10\FIREFOX
[2011/03/03 15:13:38 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2011/02/19 02:22:36 | 000,001,538 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2011/02/19 02:22:36 | 000,000,947 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2011/02/19 02:22:36 | 000,000,769 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2011/02/19 02:22:36 | 000,001,135 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: ([2009/06/10 21:39:37 | 000,000,824 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [00PCTFW] C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe (PC Tools)
O4 - HKLM..\Run: [ATICustomerCare] C:\Program Files\ATI\ATICustomerCare\ATICustomerCare.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 21:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync) - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart) - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)


========== Files/Folders - Created Within 30 Days ==========

[2011/03/04 10:44:59 | 000,581,120 | —- | C] (OldTimer Tools) – C:\Users\Steve\Desktop\OTL.exe
[2011/03/04 00:52:40 | 000,000,000 | —D | C] – C:\Users\Steve\AppData\Roaming\Malwarebytes
[2011/03/04 00:52:35 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2011/03/04 00:52:35 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/03/04 00:52:34 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2011/03/04 00:52:31 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2011/03/04 00:52:31 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/03/04 00:45:33 | 000,000,000 | —D | C] – C:\Users\Steve\AppData\Roaming\RegGenie
[2011/03/04 00:43:47 | 000,000,000 | —D | C] – C:\Program Files\RegGenie
[2011/03/04 00:32:17 | 007,734,208 | —- | C] (Malwarebytes Corporation ) – C:\Users\Steve\Desktop\mbam-setup-1.50.1.1100.exe
[2011/03/04 00:09:17 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sophos
[2011/03/04 00:09:16 | 000,000,000 | —D | C] – C:\Program Files\Sophos
[2011/03/03 21:38:46 | 000,000,000 | —D | C] – C:\Windows\Panther
[2011/03/03 21:30:32 | 000,000,000 | —D | C] – C:\old-windows-old
[2011/03/03 20:35:03 | 000,000,000 | —D | C] – C:\Users\Steve\AppData\Roaming\Rokario
[2011/03/03 20:34:59 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rokario
[2011/03/03 20:34:59 | 000,000,000 | —D | C] – C:\Program Files\Rokario
[2011/03/03 16:42:40 | 000,000,000 | —D | C] – C:\ProgramData\Blizzard Entertainment
[2011/03/03 16:30:02 | 000,000,000 | —D | C] – C:\Games
[2011/03/03 16:28:58 | 000,000,000 | —D | C] – C:\Users\Steve\Desktop\Misc
[2011/03/03 16:28:34 | 000,000,000 | —D | C] – C:\Users\Steve\Desktop\here
[2011/03/03 16:28:03 | 000,000,000 | —D | C] – C:\Program Files\Microsoft.NET
[2011/03/03 16:28:02 | 000,000,000 | —D | C] – C:\Users\Steve\Desktop\3D-Stuff
[2011/03/03 16:22:49 | 000,000,000 | —D | C] – C:\Windows\System32\Wat
[2011/03/03 16:20:38 | 000,295,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationHost.exe
[2011/03/03 16:20:38 | 000,099,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationHostProxy.dll
[2011/03/03 16:20:38 | 000,049,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netfxperf.dll
[2011/03/03 16:15:35 | 000,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\browserchoice.exe
[2011/03/03 16:13:50 | 000,496,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\taskschd.dll
[2011/03/03 16:13:50 | 000,351,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmicmiplugin.dll
[2011/03/03 16:13:50 | 000,305,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\taskcomp.dll
[2011/03/03 16:13:50 | 000,179,712 | —- | C] (Microsoft Corporation) – C:\Windows\System32\schtasks.exe
[2011/03/03 16:13:42 | 000,954,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc40.dll
[2011/03/03 16:13:42 | 000,954,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc40u.dll
[2011/03/03 16:13:39 | 001,037,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\lsasrv.dll
[2011/03/03 16:13:36 | 002,329,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2011/03/03 16:13:35 | 002,614,272 | —- | C] (Microsoft Corporation) – C:\Windows\explorer.exe
[2011/03/03 16:13:33 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[2011/03/03 16:13:23 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rtutils.dll
[2011/03/03 16:13:22 | 000,314,368 | —- | C] (Microsoft Corporation) – C:\Windows\System32\webio.dll
[2011/03/03 16:13:21 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\t2embed.dll
[2011/03/03 16:13:20 | 000,197,632 | —- | C] (Intel® Corporation) – C:\Windows\System32\ir32_32.dll
[2011/03/03 16:13:20 | 000,082,944 | —- | C] (Radius Inc.) – C:\Windows\System32\iccvid.dll
[2011/03/03 16:13:19 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript.dll
[2011/03/03 16:13:19 | 000,428,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vbscript.dll
[2011/03/03 16:13:14 | 000,606,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2011/03/03 16:13:14 | 000,599,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2011/03/03 16:13:14 | 000,381,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2011/03/03 16:13:13 | 000,386,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2011/03/03 16:13:13 | 000,185,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2011/03/03 16:13:13 | 000,064,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2011/03/03 16:13:13 | 000,044,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2011/03/03 16:13:13 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2011/03/03 16:13:12 | 001,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2011/03/03 16:13:09 | 012,625,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmploc.DLL
[2011/03/03 16:13:03 | 001,320,960 | —- | C] (Microsoft Corporation) – C:\Windows\System32\CertEnroll.dll
[2011/03/03 16:13:02 | 000,507,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winload.exe
[2011/03/03 16:13:02 | 000,442,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winresume.exe
[2011/03/03 16:12:57 | 001,328,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\quartz.dll
[2011/03/03 16:12:56 | 000,091,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\avifil32.dll
[2011/03/03 16:12:56 | 000,084,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mciavi32.dll
[2011/03/03 16:10:11 | 003,181,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mf.dll
[2011/03/03 16:10:11 | 001,619,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMVDECOD.DLL
[2011/03/03 16:10:11 | 001,170,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10warp.dll
[2011/03/03 16:10:11 | 001,074,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2011/03/03 16:10:11 | 000,739,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d2d1.dll
[2011/03/03 16:10:11 | 000,218,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1core.dll
[2011/03/03 16:10:10 | 001,495,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ExplorerFrame.dll
[2011/03/03 16:10:10 | 000,442,880 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsPrint.dll
[2011/03/03 16:10:10 | 000,196,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfreadwrite.dll
[2011/03/03 16:10:10 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1.dll
[2011/03/03 16:10:10 | 000,135,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsRasterService.dll
[2011/03/03 16:10:09 | 000,294,400 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\atmfd.dll
[2011/03/03 16:10:09 | 000,288,256 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsGdiConverter.dll
[2011/03/03 16:10:09 | 000,070,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fontsub.dll
[2011/03/03 16:10:09 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\System32\atmlib.dll
[2011/03/03 16:10:07 | 000,204,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\upnp.dll
[2011/03/03 16:10:07 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2011/03/03 16:10:07 | 000,080,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\davclnt.dll
[2011/03/03 16:10:07 | 000,051,200 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wscapi.dll
[2011/03/03 16:10:07 | 000,048,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2011/03/03 16:10:07 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\slwga.dll
[2011/03/03 16:10:06 | 003,957,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2011/03/03 16:10:06 | 003,901,824 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2011/03/03 16:10:05 | 000,369,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\secproc.dll
[2011/03/03 16:10:05 | 000,365,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\secproc_isv.dll
[2011/03/03 16:10:05 | 000,324,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RMActivate_isv.exe
[2011/03/03 16:10:05 | 000,320,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RMActivate.exe
[2011/03/03 16:10:04 | 000,738,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmpmde.dll
[2011/03/03 16:10:04 | 000,280,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RMActivate_ssp.exe
[2011/03/03 16:10:04 | 000,277,504 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RMActivate_ssp_isv.exe
[2011/03/03 16:10:04 | 000,085,504 | —- | C] (Microsoft Corporation) – C:\Windows\System32\secproc_ssp_isv.dll
[2011/03/03 16:10:04 | 000,085,504 | —- | C] (Microsoft Corporation) – C:\Windows\System32\secproc_ssp.dll
[2011/03/03 16:10:02 | 000,101,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\consent.exe
[2011/03/03 16:07:53 | 000,219,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\dxgmms1.sys
[2011/03/03 16:07:53 | 000,107,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cdd.dll
[2011/03/03 15:42:39 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MailWasher Free
[2011/03/03 15:42:37 | 000,000,000 | —D | C] – C:\Users\Steve\AppData\Roaming\MailWasherFree
[2011/03/03 15:42:37 | 000,000,000 | —D | C] – C:\Program Files\FireTrust
[2011/03/03 15:35:27 | 000,021,992 | —- | C] (CPUID) – C:\Windows\System32\drivers\cpuz135_x32.sys
[2011/03/03 15:35:27 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID
[2011/03/03 15:35:26 | 000,000,000 | —D | C] – C:\Program Files\CPUID
[2011/03/03 15:26:47 | 000,000,000 | —D | C] – C:\Program Files\mIRC
[2011/03/03 15:23:50 | 000,000,000 | —D | C] – C:\Users\Steve\AppData\Local\AMD
[2011/03/03 15:23:37 | 000,000,000 | —D | C] – C:\Users\Steve\AppData\Roaming\ATI
[2011/03/03 15:23:37 | 000,000,000 | —D | C] – C:\Users\Steve\AppData\Local\ATI
[2011/03/03 15:23:37 | 000,000,000 | —D | C] – C:\ProgramData\ATI
[2011/03/03 15:23:07 | 000,000,000 | —D | C] – C:\ProgramData\AMD
[2011/03/03 15:21:31 | 000,000,000 | —D | C] – C:\Program Files\Common Files\ATI Technologies
[2011/03/03 15:21:28 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ATI Stream SDK v2
[2011/03/03 15:21:27 | 000,000,000 | —D | C] – C:\Program Files\ATI Stream
[2011/03/03 15:21:18 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center
[2011/03/03 15:20:46 | 000,037,944 | —- | C] (Advanced Micro Devices) – C:\Windows\System32\drivers\amdiox86.sys
[2011/03/03 15:19:42 | 000,000,000 | —D | C] – C:\Program Files\ATI Technologies
[2011/03/03 15:19:38 | 000,000,000 | —D | C] – C:\Program Files\ATI
[2011/03/03 15:15:32 | 000,000,000 | —D | C] – C:\Users\Steve\AppData\Roaming\.minecraft
[2011/03/03 15:14:13 | 000,000,000 | —D | C] – C:\ProgramData\Sun
[2011/03/03 15:14:12 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2011/03/03 15:13:50 | 000,472,808 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\deployJava1.dll
[2011/03/03 15:13:50 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2011/03/03 15:13:50 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2011/03/03 15:13:50 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2011/03/03 15:13:36 | 000,000,000 | —D | C] – C:\Program Files\Java
[2011/03/03 15:13:14 | 000,000,000 | —D | C] – C:\ProgramData\McAfee
[2011/03/03 15:09:43 | 000,000,000 | —D | C] – C:\Users\Steve\AppData\Roaming\Macromedia
[2011/03/03 15:09:43 | 000,000,000 | —D | C] – C:\Users\Steve\AppData\Roaming\Adobe
[2011/03/03 15:09:37 | 000,000,000 | —D | C] – C:\Windows\System32\Macromed
[2011/03/03 15:02:28 | 000,000,000 | —D | C] – C:\Users\Steve\AppData\Roaming\mIRC
[2011/03/03 14:27:17 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG 2011
[2011/03/03 14:26:45 | 000,000,000 | —D | C] – C:\ProgramData\AVG10
[2011/03/03 14:26:45 | 000,000,000 | —D | C] – C:\Windows\System32\drivers\AVG
[2011/03/03 14:26:15 | 000,000,000 | —D | C] – C:\Program Files\AVG
[2011/03/03 14:18:51 | 000,000,000 | —D | C] – C:\Users\Steve\AppData\Roaming\Mozilla
[2011/03/03 14:18:51 | 000,000,000 | —D | C] – C:\Users\Steve\AppData\Local\Mozilla
[2011/03/03 14:18:48 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox
[2011/03/03 14:18:46 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2011/03/03 14:09:07 | 000,000,000 | —D | C] – C:\Users\Steve\AppData\Roaming\AVG10
[2011/03/03 14:08:25 | 000,000,000 | -H-D | C] – C:\ProgramData\Common Files
[2011/03/03 14:08:04 | 000,222,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MpSigStub.exe
[2011/03/03 14:03:22 | 000,000,000 | -HSD | C] – C:\Windows\Installer
[2011/03/03 14:02:27 | 000,000,000 | —D | C] – C:\ProgramData\MFAData
[2011/03/03 13:59:29 | 000,000,000 | —D | C] – C:\Users\Steve\AppData\Roaming\PCToolsFirewallPlus
[2011/03/03 13:58:10 | 000,218,592 | —- | C] (PC Tools) – C:\Windows\System32\drivers\PCTCore.sys
[2011/03/03 13:58:10 | 000,160,448 | —- | C] (PC Tools) – C:\Windows\System32\drivers\PCTAppEvent.sys
[2011/03/03 13:58:09 | 000,249,616 | —- | C] (PC Tools) – C:\Windows\System32\drivers\pctgntdi.sys
[2011/03/03 13:58:09 | 000,102,184 | —- | C] (PC Tools) – C:\Windows\System32\drivers\pctwfpfilter.sys
[2011/03/03 13:56:54 | 000,000,000 | —D | C] – C:\ProgramData\TEMP
[2011/03/03 13:56:52 | 000,089,192 | —- | C] (PC Tools) – C:\Windows\System32\drivers\pctNdis-PacketFilter.sys
[2011/03/03 13:56:52 | 000,057,536 | —- | C] (PC Tools) – C:\Windows\System32\drivers\pctNdis.sys
[2011/03/03 13:56:52 | 000,032,808 | —- | C] (PC Tools) – C:\Windows\System32\drivers\pctNdis-DNS.sys
[2011/03/03 13:56:52 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Tools Firewall Plus
[2011/03/03 13:56:52 | 000,000,000 | —D | C] – C:\Program Files\Common Files\PC Tools
[2011/03/03 13:56:51 | 000,124,992 | —- | C] (PC Tools) – C:\Windows\System32\drivers\pctplfw.sys
[2011/03/03 13:56:50 | 000,000,000 | —D | C] – C:\Program Files\PC Tools Firewall Plus
[2011/03/03 13:52:28 | 000,000,000 | R–D | C] – C:\Users\Steve\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2011/03/03 13:52:28 | 000,000,000 | R–D | C] – C:\Users\Steve\Searches
[2011/03/03 13:52:28 | 000,000,000 | R–D | C] – C:\Users\Steve\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2011/03/03 13:52:28 | 000,000,000 | -H-D | C] – C:\Users\Steve\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2011/03/03 13:52:18 | 000,000,000 | —D | C] – C:\Users\Steve\AppData\Roaming\Identities
[2011/03/03 13:52:17 | 000,000,000 | R–D | C] – C:\Users\Steve\Contacts
[2011/03/03 13:52:11 | 000,000,000 | —D | C] – C:\Users\Steve\AppData\Local\VirtualStore
[2011/03/03 13:52:09 | 000,000,000 | –SD | C] – C:\Users\Steve\AppData\Roaming\Microsoft
[2011/03/03 13:52:09 | 000,000,000 | R–D | C] – C:\Users\Steve\Videos
[2011/03/03 13:52:09 | 000,000,000 | R–D | C] – C:\Users\Steve\Saved Games
[2011/03/03 13:52:09 | 000,000,000 | R–D | C] – C:\Users\Steve\Pictures
[2011/03/03 13:52:09 | 000,000,000 | R–D | C] – C:\Users\Steve\Music
[2011/03/03 13:52:09 | 000,000,000 | R–D | C] – C:\Users\Steve\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2011/03/03 13:52:09 | 000,000,000 | R–D | C] – C:\Users\Steve\Links
[2011/03/03 13:52:09 | 000,000,000 | R–D | C] – C:\Users\Steve\Favorites
[2011/03/03 13:52:09 | 000,000,000 | R–D | C] – C:\Users\Steve\Downloads
[2011/03/03 13:52:09 | 000,000,000 | R–D | C] – C:\Users\Steve\My Documents
[2011/03/03 13:52:09 | 000,000,000 | R–D | C] – C:\Users\Steve\Desktop
[2011/03/03 13:52:09 | 000,000,000 | R–D | C] – C:\Users\Steve\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2011/03/03 13:52:09 | 000,000,000 | -HSD | C] – C:\Users\Steve\AppData\Local\Temporary Internet Files
[2011/03/03 13:52:09 | 000,000,000 | -HSD | C] – C:\Users\Steve\Templates
[2011/03/03 13:52:09 | 000,000,000 | -HSD | C] – C:\Users\Steve\Start Menu
[2011/03/03 13:52:09 | 000,000,000 | -HSD | C] – C:\Users\Steve\SendTo
[2011/03/03 13:52:09 | 000,000,000 | -HSD | C] – C:\Users\Steve\Recent
[2011/03/03 13:52:09 | 000,000,000 | -HSD | C] – C:\Users\Steve\PrintHood
[2011/03/03 13:52:09 | 000,000,000 | -HSD | C] – C:\Users\Steve\NetHood
[2011/03/03 13:52:09 | 000,000,000 | -HSD | C] – C:\Users\Steve\Documents\My Videos
[2011/03/03 13:52:09 | 000,000,000 | -HSD | C] – C:\Users\Steve\Documents\My Pictures
[2011/03/03 13:52:09 | 000,000,000 | -HSD | C] – C:\Users\Steve\Documents\My Music
[2011/03/03 13:52:09 | 000,000,000 | -HSD | C] – C:\Users\Steve\My Documents
[2011/03/03 13:52:09 | 000,000,000 | -HSD | C] – C:\Users\Steve\Local Settings
[2011/03/03 13:52:09 | 000,000,000 | -HSD | C] – C:\Users\Steve\AppData\Local\History
[2011/03/03 13:52:09 | 000,000,000 | -HSD | C] – C:\Users\Steve\Cookies
[2011/03/03 13:52:09 | 000,000,000 | -HSD | C] – C:\Users\Steve\Application Data
[2011/03/03 13:52:09 | 000,000,000 | -HSD | C] – C:\Users\Steve\AppData\Local\Application Data
[2011/03/03 13:52:09 | 000,000,000 | -H-D | C] – C:\Users\Steve\AppData
[2011/03/03 13:52:09 | 000,000,000 | —D | C] – C:\Users\Steve\AppData\Local\Temp
[2011/03/03 13:52:09 | 000,000,000 | —D | C] – C:\Users\Steve\AppData\Local\Microsoft
[2011/03/03 13:52:09 | 000,000,000 | —D | C] – C:\Users\Steve\AppData\Roaming\Media Center Programs
[2011/03/03 13:42:32 | 000,000,000 | —D | C] – C:\Windows\SoftwareDistribution
[2011/03/03 13:40:26 | 000,000,000 | —D | C] – C:\Windows\Prefetch

========== Files - Modified Within 30 Days ==========

[2011/03/04 10:45:00 | 000,581,120 | —- | M] (OldTimer Tools) – C:\Users\Steve\Desktop\OTL.exe
[2011/03/04 10:44:12 | 000,054,016 | —- | M] () – C:\Windows\System32\drivers\uidy.sys
[2011/03/04 10:42:49 | 000,628,024 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/03/04 10:42:49 | 000,110,208 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/03/04 10:41:57 | 107,746,548 | —- | M] () – C:\Windows\System32\drivers\AVG\incavi.avm
[2011/03/04 10:36:09 | 000,267,496 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2011/03/04 10:36:06 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/03/04 10:35:58 | 2616,598,528 | -HS- | M] () – C:\hiberfil.sys
[2011/03/04 00:52:35 | 000,001,071 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/03/04 00:32:27 | 007,734,208 | —- | M] (Malwarebytes Corporation ) – C:\Users\Steve\Desktop\mbam-setup-1.50.1.1100.exe
[2011/03/04 00:11:48 | 000,012,432 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/03/04 00:11:48 | 000,012,432 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/03/04 00:08:56 | 001,376,832 | —- | M] () – C:\Users\Steve\Desktop\sar_15_sfx.exe
[2011/03/03 21:38:34 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2011/03/03 20:39:07 | 000,001,096 | —- | M] () – C:\Users\Steve\Desktop\Launcher - Shortcut.lnk
[2011/03/03 15:42:39 | 000,001,080 | —- | M] () – C:\Users\Steve\Desktop\MailWasher Free.lnk
[2011/03/03 15:35:27 | 000,001,087 | —- | M] () – C:\Users\Public\Desktop\CPUID HWMonitor.lnk
[2011/03/03 15:26:49 | 000,000,913 | —- | M] () – C:\Users\Public\Desktop\mIRC.lnk
[2011/03/03 15:13:37 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\deployJava1.dll
[2011/03/03 15:13:37 | 000,157,472 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2011/03/03 15:13:37 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2011/03/03 15:13:37 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2011/03/03 15:11:14 | 000,270,142 | —- | M] () – C:\Users\Steve\Desktop\Minecraft.exe
[2011/03/03 14:18:48 | 000,001,913 | —- | M] () – C:\Users\Steve\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/03/03 14:18:48 | 000,001,889 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/03/03 14:00:44 | 000,001,411 | —- | M] () – C:\Users\Steve\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/03/03 13:43:09 | 000,041,962 | —- | M] () – C:\Windows\System32\license.rtf
[2011/03/03 13:41:45 | 000,000,000 | —- | M] () – C:\Windows\ativpsrm.bin
[2011/03/03 13:41:13 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2011/02/03 05:45:07 | 000,219,008 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\dxgmms1.sys
[2011/02/02 17:11:20 | 000,222,080 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MpSigStub.exe

========== Files Created - No Company Name ==========

[2011/03/04 10:44:12 | 000,054,016 | —- | C] () – C:\Windows\System32\drivers\uidy.sys
[2011/03/04 10:41:57 | 107,746,548 | —- | C] () – C:\Windows\System32\drivers\AVG\incavi.avm
[2011/03/04 00:52:35 | 000,001,071 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/03/04 00:05:47 | 001,376,832 | —- | C] () – C:\Users\Steve\Desktop\sar_15_sfx.exe
[2011/03/03 20:39:07 | 000,001,096 | —- | C] () – C:\Users\Steve\Desktop\Launcher - Shortcut.lnk
[2011/03/03 15:42:39 | 000,001,080 | —- | C] () – C:\Users\Steve\Desktop\MailWasher Free.lnk
[2011/03/03 15:35:27 | 000,001,087 | —- | C] () – C:\Users\Public\Desktop\CPUID HWMonitor.lnk
[2011/03/03 15:26:49 | 000,000,913 | —- | C] () – C:\Users\Public\Desktop\mIRC.lnk
[2011/03/03 15:11:13 | 000,270,142 | —- | C] () – C:\Users\Steve\Desktop\Minecraft.exe
[2011/03/03 14:18:48 | 000,001,913 | —- | C] () – C:\Users\Steve\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/03/03 14:18:48 | 000,001,889 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/03/03 14:00:44 | 000,001,411 | —- | C] () – C:\Users\Steve\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/03/03 13:53:19 | 000,001,417 | —- | C] () – C:\Users\Steve\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2011/03/03 13:52:09 | 000,000,290 | —- | C] () – C:\Users\Steve\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2011/03/03 13:52:09 | 000,000,272 | —- | C] () – C:\Users\Steve\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2011/03/03 13:42:59 | 000,001,345 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
[2011/03/03 13:42:50 | 000,001,326 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
[2011/03/03 13:41:45 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2011/03/03 13:41:13 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2010/12/21 02:27:20 | 000,003,113 | —- | C] () – C:\Windows\System32\atipblag.dat
[2010/12/17 16:00:44 | 000,227,587 | —- | C] () – C:\Windows\System32\atiicdxx.dat
[2009/07/14 04:57:37 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/14 04:33:53 | 000,267,496 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2009/07/14 02:05:48 | 000,628,024 | —- | C] () – C:\Windows\System32\perfh009.dat
[2009/07/14 02:05:48 | 000,291,294 | —- | C] () – C:\Windows\System32\perfi009.dat
[2009/07/14 02:05:48 | 000,110,208 | —- | C] () – C:\Windows\System32\perfc009.dat
[2009/07/14 02:05:48 | 000,031,548 | —- | C] () – C:\Windows\System32\perfd009.dat
[2009/07/14 02:05:05 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2009/07/14 02:04:11 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2009/07/13 23:55:01 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 23:51:43 | 000,073,728 | —- | C] () – C:\Windows\System32\BthpanContextHandler.dll
[2009/07/13 23:42:10 | 000,064,000 | —- | C] () – C:\Windows\System32\BWContextHandler.dll
[2009/06/10 21:26:10 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat

========== LOP Check ==========

[2011/03/03 15:29:01 | 000,000,000 | —D | M] – C:\Users\Steve\AppData\Roaming\.minecraft
[2011/03/03 14:09:07 | 000,000,000 | —D | M] – C:\Users\Steve\AppData\Roaming\AVG10
[2011/03/03 16:22:40 | 000,000,000 | —D | M] – C:\Users\Steve\AppData\Roaming\MailWasherFree
[2011/03/03 13:59:41 | 000,000,000 | —D | M] – C:\Users\Steve\AppData\Roaming\PCToolsFirewallPlus
[2011/03/04 00:45:33 | 000,000,000 | —D | M] – C:\Users\Steve\AppData\Roaming\RegGenie
[2011/03/03 20:35:03 | 000,000,000 | —D | M] – C:\Users\Steve\AppData\Roaming\Rokario
[2009/07/14 04:53:46 | 000,002,348 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2011/03/03 13:17:41 | 000,076,828 | —- | M] () – C:\aaw7boot.log
[2009/06/10 21:42:20 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/07/14 01:38:58 | 000,383,562 | RHS- | M] () – C:\bootmgr
[2011/03/03 21:38:34 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2009/06/10 21:42:20 | 000,000,010 | —- | M] () – C:\config.sys
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 08:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 08:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2007/11/07 08:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2011/03/04 10:35:58 | 2616,598,528 | -HS- | M] () – C:\hiberfil.sys
[2007/11/07 08:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe
[2007/11/07 08:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2011/03/02 13:18:57 | 000,016,274 | —- | M] () – C:\Install.log.txt
[2007/11/07 08:03:18 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 08:03:18 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 08:03:18 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 08:03:18 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 08:03:18 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 08:03:18 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 08:03:18 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2010/08/15 10:23:12 | 000,000,183 | —- | M] () – C:\LogiSetup.log
[2010/06/30 10:49:12 | 000,000,109 | —- | M] () – C:\mbam-error.txt
[2010/08/15 10:25:08 | 000,499,300 | —- | M] () – C:\MSIInstall.log
[2011/03/04 10:35:58 | 3488,800,768 | -HS- | M] () – C:\pagefile.sys
[2007/11/07 08:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 08:09:22 | 001,442,522 | —- | M] () – C:\VC_RED.cab
[2007/11/07 08:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI

< %systemroot%\Fonts\*.com >
[2009/07/14 04:52:25 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 04:52:25 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 04:52:25 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 04:52:25 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 21:31:19 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/07/14 01:15:35 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll
[2009/07/14 01:16:19 | 000,029,696 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\winprint.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 04:41:57 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/03/03 14:00:44 | 000,000,221 | -HS- | M] () – C:\Users\Steve\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/03/04 00:32:27 | 007,734,208 | —- | M] (Malwarebytes Corporation ) – C:\Users\Steve\Desktop\mbam-setup-1.50.1.1100.exe
[2011/03/03 15:11:14 | 000,270,142 | —- | M] () – C:\Users\Steve\Desktop\Minecraft.exe
[2011/03/04 10:45:00 | 000,581,120 | —- | M] (OldTimer Tools) – C:\Users\Steve\Desktop\OTL.exe
[2011/03/04 00:08:56 | 001,376,832 | —- | M] () – C:\Users\Steve\Desktop\sar_15_sfx.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-03-03 16:29:55

========== Alternate Data Streams ==========

@Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:C31F31E6

< End of report >
Sorry about the delay in responding :(

We look for post with 0 replies, so when you posted to your own log, we assumed you were being helped.


Please do not delete anything unless instructed to.



Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")



I've been seeing some Java infections lately.

Go here and follow the instructions to clear your Java Cache
http://www.java.com/en/download/help/plugin_cache.xml


Next:
Note: Close all browsers before running ATF Cleaner: IE, FireFox, etc.

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

If you use Firefox browser

Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.


It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Next:

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done, DDS.txt will open.
  • Click Yes at the next prompt for Optional Scan.
  • Save both reports to your desktop.
—————————————————

Please Please copy / paste the scan reults.
Thank you for helping. I cleared the java cache via the instructions then I used the ATF cleaner with the settings you told me to. I have tried running the dds file but I get an error. 'This tool does not your support your Operating System' 'Press any key to continue' Which alarms me as the grammar in the message is terrible! Could you please advise me what to do next? (I'm running Windows 7 32bit Home Premium by the way) Thank you
Download RogueKiller to your desktop

  • Quit all running programs
  • For Vista/Seven, right click -> run as administrator, for XP simply run RogueKiller.exe
  • When prompted, type 1 and validate
  • The RKreport.txt shall be generated next to the executable.
  • If the program is blocked, do not hesitate to try several times. If it really does not work (it could happen), rename it to winlogon.exe
Please post the contents of the RKreport.txt in your next Reply.
I'm starting to think you're having hardware issues.

Lets try another scanner.

http://www.eset.eu/online-scanner
Go here to run an online scannner from ESET.
Click the green ESET Online Scanner button.
Read the End User License Agreement and check the box: YES, I accept the Terms of Use.
Click on the Start button next to it.
You may receive an alert on the address bar that "This site might require the following ActiveX control…Click here to install…". Click on that alert and then click Insall ActiveX component.
A new window will appear asking "Do you want to install this software?"".
Answer Yes to download and install the ActiveX controls that allows the scan to run.
Click Start.
Check Remove found threats and Scan potentially unwanted applications.
Click Scan to begin.
If offered the option to get information or buy software. Just close the window.
Wait for the scan to finish
Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
Copy and paste that log as a reply to this topic.
Thanks again. ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6425 # api_version=3.0.2 # EOSSerial=8c9f835b7c244c45bb891568b121609d # end=finished # remove_checked=true # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2011-03-06 10:28:47 # local_time=2011-03-06 10:28:47 (+0000, GMT Standard Time) # country="United Kingdom" # lang=1033 # osver=6.1.7600 NT # compatibility_mode=1032 16777213 100 94 9803 42736696 0 0 # compatibility_mode=2560 16777215 100 0 0 0 0 0 # compatibility_mode=5893 16776574 100 94 288620 51912695 0 0 # compatibility_mode=8192 67108863 100 0 3826 3826 0 0 # scanned=222959 # found=0 # cleaned=0 # scan_time=4244

I am in desperate need, my pc has been acting very odd the last 2-3 days, Its very sluggish and I'm getting lots of 'Not Responding' this is happening on things like firefox and word but also sometimes even my start button and control panel say not responding and I get no icons.

I have not installed anything new in the last week or so and I always defrag my drive weekly and do avg free antivirus scans and malwarebytes antimalware scans every few days. I'm disabled and my pc is my only link to my friends and as its the only pc I have I'm desperately worried about this. please help me.

I even freshly installed Win 7 yesterday hoping that would fix it but no, its the same.

I suggest you start a new topic in our Windows Forum and post the above.

You can also add that we checked for infections but nothing found.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI