This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

used laptop aquired. runs like crapola

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

i just aquired a used hp from a friend and it runs very slow. i havent ran any clean-up programs yet, but i wanted to see if someone could snoop around and check the overall health of this thing… in the meantime i will do the usual defrag and whatnot. there seems to be a million tool bars on here, which i find annoying, so i imagine it will speed up a tad once i get rid of all that mess… any suggestions will be greatly appreciated. seems like i have used you guys for cleanups at least 100 times in the past 4 years… always happy with the results i get. thank you!
:welcome:

Please download ATF Cleaner by Atribune to your desktop.
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
Your system may start up slower after running ATF Cleaner, this is expected but will be back to normal after the first or second boot up
Please note: If you use online banking or are registered online with any other organizations, ensure you have memorized password and other personal information as removing cookies will temporarily disable the auto-login facility.






Please download Malwarebytes from Here or Here

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the report please







Download DDS from one of the links below to your desktop

Link 1
Link 2

  • Double click the tool to run it.
  • A black Screen will open, just read the contents and do nothing.
  • When the tool finishes, it will open 2 reports, DDS.txt and attach.txt
  • Copy/Paste the contents of 'DDS.txt' into your post.
  • 'attach.txt' should be zipped using Windows native zip utility and attached to your post. Compress and uncompress files (zip files)
Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 6382 Windows 6.0.6002 Service Pack 2 Internet Explorer 8.0.6001.19048 4/17/2011 2:51:35 AM mbam-log-2011-04-17 (02-51-35).txt Scan type: Quick scan Objects scanned: 168039 Time elapsed: 8 minute(s), 54 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 9 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 2 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CLASSES_ROOT\CLSID\{500BCA15-57A7-4eaf-8143-8C619470B13D} (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\TypeLib\{56ACB669-4139-5611-CBBA-F5ACB0F4DB09} (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\XML.XML.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\XML.XML (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{500BCA15-57A7-4EAF-8143-8C619470B13D} (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{500BCA15-57A7-4EAF-8143-8C619470B13D} (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Cognac (Rogue.Multiple) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\ColdWare (Malware.Trace) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: c:\WINDOWS\Tasks\{5b57cf47-0bfa-43c6-acf9-3b3653dcadba}.job (Trojan.FakeAlert) -> Quarantined and deleted successfully. c:\WINDOWS\Tasks\{783af354-b514-42d6-970e-3e8bf0a5279c}.job (Trojan.Downloader) -> Quarantined and deleted successfully. . DDS (Ver_11-03-05.01) - NTFSx86 Run by [removed] at 2:54:10.15 on Sun 04/17/2011 Internet Explorer: 8.0.6001.19048 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3006.1562 [GMT -4:00] . AV: AVG Anti-Virus Free *Enabled/Updated* {0C939084-9E57-CBDB-EA61-0B0C7F62AF82} SP: AVG Anti-Virus Free *Enabled/Updated* {B7F27160-B86D-C455-D0D1-307E04E5E53F} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\nvvsvc.exe C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\rundll32.exe C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Windows\system32\svchost.exe -k bthsvcs C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe C:\Program Files\CyberLink\Shared Files\RichVideo.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files\Viewpoint\Common\ViewpointService.exe C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\DRIVERS\xaudio.exe C:\PROGRA~1\AVG\AVG8\avgemc.exe C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe C:\Program Files\AVG\AVG8\avgcsrvx.exe C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\HP\QuickPlay\QPService.exe C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\HP\Digital Imaging\bin\HpqSRmon.exe C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\AVG\AVG8\avgtray.exe C:\Windows\system32\wbem\wmiprvse.exe C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\vsnp2uvc.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe C:\WINDOWS\ehome\ehtray.exe C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe C:\Windows\system32\wbem\unsecapp.exe C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe C:\Program Files\Memeo\AutoBackup\MemeoBackup.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files\Synaptics\SynTP\SynTPHelper.exe c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe C:\Windows\system32\wuauclt.exe C:\Windows\system32\taskeng.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\PROGRA~1\AVG\AVG8\avgnsx.exe C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe C:\Windows\system32\Macromed\SHOCKW~1\SWHELP~1.EXE C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\system32\msiexec.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Users\Mike\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BND8KE9I\dds[1].scr C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.yahoo.com/ uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop uSearch Page = hxxp://www.google.com uSearch Bar = hxxp://www.yahoo.com/search/ie.html mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop mDefault_Page_URL = hxxp://www.yahoo.com/ mDefault_Search_URL = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll BHO: Yahoo! IE Services Button: {5bab4b5b-68bc-4b02-94d6-2fc0de4a7897} - c:\program files\yahoo!\common\yiesrvc.dll BHO: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No File BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: HP Print Clips: {ffffffff-ff12-44c5-91ec-068e3aa1b2d7} - c:\program files\hp\smart web printing\hpswp_framework.dll TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg8\toolbar\IEToolbar.dll TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe uRun: [LightScribe Control Panel] c:\program files\common files\lightscribe\LightScribeControlPanel.exe -hidden uRun: [HPAdvisor] c:\program files\hewlett-packard\hp advisor\HPAdvisor.exe autoRun uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe uRun: [ISUSPM] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -scheduler uRun: [Yahoo! Pager] "c:\progra~1\yahoo!\messen~1\YAHOOM~1.EXE" -quiet mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [QPService] "c:\program files\hp\quickplay\QPService.exe" mRun: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start mRun: [OnScreenDisplay] c:\program files\hewlett-packard\hp quicktouch\HPKBDAPP.exe mRun: [UCam_Menu] "c:\program files\cyberlink\youcam\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\youcam" update "software\cyberlink\youcam\1.0" mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide mRun: [hpqSRMon] c:\program files\hp\digital imaging\bin\hpqSRMon.exe mRun: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe mRun: [hpWirelessAssistant] c:\program files\hewlett-packard\hp wireless assistant\HPWAMain.exe mRun: [WAWifiMessage] c:\program files\hewlett-packard\hp wireless assistant\WiFiMsg.exe mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [snp2uvc] c:\windows\vsnp2uvc.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [Malwarebytes' Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent StartupFolder: c:\users\mike\appdata\roaming\micros~1\windows\startm~1\programs\startup\memeoa~1.lnk - c:\users\mike\appdata\roaming\microsoft\installer\{6bceb97b-f315-455d-bc2d-565a1a6781e8}\NewShortcut4_51A847D327C24F7797772AF2A4E486ED.exe StartupFolder: c:\users\mike\appdata\roaming\micros~1\windows\startm~1\programs\startup\memeoa~2.lnk - c:\program files\memeo\autosync\MemeoLauncher.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000 IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html IE: Send image to &Bluetooth Device… - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm IE: Send page to &Bluetooth Device… - c:\program files\widcomm\bluetooth software\btsendto_ie.htm IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll IE: {5067A26B-1337-4436-8AFE-EE169C2DA79F} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll IE: {58ECB495-38F0-49cb-A538-10282ABF65E7} - {A93C41D8-01F8-4F8B-B14C-DE20B117E636} - c:\program files\hp\smart web printing\hpswp_extensions.dll IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\program files\yahoo!\common\yiesrvc.dll IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\avg\avg8\toolbar\IEToolbar.dll Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL AppInit_DLLs: c:\progra~1\google\google~2\GOEC62~1.DLL, avgrsstx.dll mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe" . ============= SERVICES / DRIVERS =============== . R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-10-8 335240] R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2008-10-8 27784] R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-3-26 108552] R2 aawservice;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\aawservice.exe [2008-5-12 611664] R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2009-7-14 908056] R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-7-14 297752] R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504] R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2008-9-27 24652] S2 gupdate1ca699c187c768;Google Update Service (gupdate1ca699c187c768);c:\program files\google\update\GoogleUpdate.exe [2009-11-20 133104] S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\avg\avg8\toolbar\ToolbarBroker.exe [2010-10-31 517448] S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\google\google desktop search\GoogleDesktop.exe [2008-8-13 29744] S3 RTL8187;Realtek RTL8187 Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8187.sys [2009-11-4 335872] S4 AutoSyncService;Memeo AutoSync ;"c:\program files\memeo\autosync\memeoservice.exe" –> c:\program files\memeo\autosync\MemeoService.exe [?] . =============== Created Last 30 ================ . 2011-04-17 06:52:31 54016 —-a-w- c:\windows\system32\drivers\phknrn.sys 2011-04-17 06:40:55 ——– d—–w- c:\users\mike\appdata\roaming\Malwarebytes 2011-04-17 06:40:48 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-04-17 06:40:47 ——– d—–w- c:\progra~2\Malwarebytes 2011-04-17 06:40:45 20952 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-04-17 06:40:45 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2011-04-15 17:26:09 6792528 —-a-w- c:\progra~2\microsoft\windows defender\definition updates\{1bb954ba-f9ce-42a0-a547-62298b4d2e22}\mpengine.dll 2011-04-14 22:41:33 274944 —-a-w- c:\windows\system32\schannel.dll 2011-04-14 22:40:59 429056 —-a-w- c:\windows\system32\EncDec.dll 2011-04-14 22:39:03 677888 —-a-w- c:\windows\system32\mstsc.exe 2011-04-14 22:39:03 2067968 —-a-w- c:\windows\system32\mstscax.dll 2011-04-14 22:38:54 168960 —-a-w- c:\program files\windows media player\wmplayer.exe 2011-04-14 22:38:53 8147456 —-a-w- c:\windows\system32\wmploc.DLL 2011-04-14 22:38:34 17920 —-a-w- c:\windows\system32\netevent.dll 2011-04-14 22:38:34 125952 —-a-w- c:\windows\system32\srvsvc.dll 2011-04-14 22:37:07 81920 —-a-w- c:\windows\system32\iccvid.dll 2011-04-14 22:36:46 339968 —-a-w- c:\program files\windows nt\accessories\wordpad.exe 2011-04-14 22:36:46 1316864 —-a-w- c:\windows\system32\ole32.dll 2011-04-14 22:36:44 128000 —-a-w- c:\windows\system32\spoolsv.exe 2011-04-14 22:36:42 157184 —-a-w- c:\windows\system32\t2embed.dll 2011-04-14 22:35:38 867328 —-a-w- c:\windows\system32\wmpmde.dll 2011-04-14 22:33:30 502272 —-a-w- c:\windows\system32\usp10.dll . ==================== Find3M ==================== . 2011-03-10 17:03:51 1162240 —-a-w- c:\windows\system32\mfc42u.dll 2011-03-10 17:03:51 1136640 —-a-w- c:\windows\system32\mfc42.dll 2011-03-03 15:42:03 739328 —-a-w- c:\windows\system32\inetcomm.dll 2011-03-03 13:25:11 2041856 —-a-w- c:\windows\system32\win32k.sys 2011-03-02 15:44:27 86528 —-a-w- c:\windows\system32\dnsrslvr.dll 2011-02-22 14:13:01 288768 —-a-w- c:\windows\system32\XpsGdiConverter.dll 2011-02-22 13:33:12 1068544 —-a-w- c:\windows\system32\DWrite.dll 2011-02-22 13:33:09 797696 —-a-w- c:\windows\system32\FntCache.dll 2011-02-22 06:21:28 916480 —-a-w- c:\windows\system32\wininet.dll 2011-02-22 06:17:08 43520 —-a-w- c:\windows\system32\licmgr10.dll 2011-02-22 06:16:53 1469440 —-a-w- c:\windows\system32\inetcpl.cpl 2011-02-22 06:16:40 71680 —-a-w- c:\windows\system32\iesetup.dll 2011-02-22 06:16:40 109056 —-a-w- c:\windows\system32\iesysprep.dll 2011-02-22 05:20:39 385024 —-a-w- c:\windows\system32\html.iec 2011-02-22 04:43:54 133632 —-a-w- c:\windows\system32\ieUnatt.exe 2011-02-22 04:42:38 1638912 —-a-w- c:\windows\system32\mshtml.tlb 2011-02-17 06:23:50 420864 —-a-w- c:\windows\system32\vbscript.dll 2011-02-16 16:16:37 34304 —-a-w- c:\windows\system32\atmlib.dll 2011-02-16 14:02:23 292864 —-a-w- c:\windows\system32\atmfd.dll 2011-02-02 22:11:20 222080 ——w- c:\windows\system32\MpSigStub.exe 2011-01-20 16:08:16 478720 —-a-w- c:\windows\system32\dxgi.dll 2011-01-20 16:08:06 219648 —-a-w- c:\windows\system32\d3d10_1core.dll 2011-01-20 16:08:06 189952 —-a-w- c:\windows\system32\d3d10core.dll 2011-01-20 16:08:06 160768 —-a-w- c:\windows\system32\d3d10_1.dll 2011-01-20 16:08:06 1029120 —-a-w- c:\windows\system32\d3d10.dll 2011-01-20 16:07:58 37376 —-a-w- c:\windows\system32\cdd.dll 2011-01-20 16:07:42 258048 —-a-w- c:\windows\system32\winspool.drv 2011-01-20 16:07:16 586240 —-a-w- c:\windows\system32\stobject.dll 2011-01-20 16:06:38 2873344 —-a-w- c:\windows\system32\mf.dll 2011-01-20 16:06:35 26112 —-a-w- c:\windows\system32\printfilterpipelineprxy.dll 2011-01-20 16:04:54 98816 —-a-w- c:\windows\system32\mfps.dll 2011-01-20 16:04:54 209920 —-a-w- c:\windows\system32\mfplat.dll 2011-01-20 14:28:38 1554432 —-a-w- c:\windows\system32\xpsservices.dll 2011-01-20 14:27:50 876032 —-a-w- c:\windows\system32\XpsPrint.dll 2011-01-20 14:26:30 667648 —-a-w- c:\windows\system32\printfilterpipelinesvc.exe 2011-01-20 14:25:25 847360 —-a-w- c:\windows\system32\OpcServices.dll 2011-01-20 14:24:26 135680 —-a-w- c:\windows\system32\XpsRasterService.dll 2011-01-20 14:15:10 979456 —-a-w- c:\windows\system32\MFH264Dec.dll 2011-01-20 14:14:39 357376 —-a-w- c:\windows\system32\MFHEAACdec.dll 2011-01-20 14:14:03 302592 —-a-w- c:\windows\system32\mfmp4src.dll 2011-01-20 14:14:03 261632 —-a-w- c:\windows\system32\mfreadwrite.dll 2011-01-20 14:12:46 1172480 —-a-w- c:\windows\system32\d3d10warp.dll 2011-01-20 14:11:34 486400 —-a-w- c:\windows\system32\d3d10level9.dll 2011-01-20 13:47:51 683008 —-a-w- c:\windows\system32\d2d1.dll . ============= FINISH: 2:54:48.04 ===============

Attachments:

Hi,

Viewpoint Media Player <–Not malicious but it installs without your knowledge or consent, its using up system resources and is not needed, you can uninstall anything related to ViewPoint via Programs and Features in the Control Panel.


ESET Online Scanner
I'd like us to scan your machine with ESET OnlineScan

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the [external image: Posted Image] button.
  • Push [external image: Posted Image]
Please make sure you include the following items in your next post:
The log that was produced after running ESET Online Scanner.
i ran the eset scanner but failed to uncheck the remove threats found option. it found 1 threat and removed it, but never produced a scan log. i ran it again as instructed and it found no threats but still did not produce a scan log. i also wanted to obtain a good link to download firefox. not to fond of IE
it is running alot better. i removed all the toolbars and some of the programs i dont use and that also helped speed it up. its not a new computer so i dont expect it to run at the speed of light. but it is much better, especially after the scans you recommended. any other suggestions? and do you have a link for a firefox download?
Glad all is well :thumbup:

I just installed Firefox 4 and it works great
http://www.mozilla.com/en-US/firefox/fx/


Why dont you run this program and let me take a final look

OTL by OldTimer
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Click the "Scan All Users" checkbox.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
OTL Extras logfile created on: 4/17/2011 9:13:28 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Mike\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19048)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 47.00% Memory free
6.00 Gb Paging File | 4.00 Gb Available in Paging File | 73.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 221.08 Gb Total Space | 139.31 Gb Free Space | 63.01% Space Free | Partition Type: NTFS
Drive D: | 11.80 Gb Total Space | 1.98 Gb Free Space | 16.76% Space Free | Partition Type: NTFS

Computer Name: MIKE-PC | User Name: Mike | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-3299488197-778044784-366267875-1000\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 0
"InternetSettingsDisableNotify" = 0
"AutoUpdateDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" = C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{12A77EAE-D612-4BD2-9495-C2B96BDF287C}" = lport=445 | protocol=6 | dir=in | app=system |
"{3747B023-DBE1-443A-825F-77CA265DFF23}" = rport=138 | protocol=17 | dir=out | app=system |
"{4012F776-E39D-477C-BD9E-368350CF8D4D}" = lport=137 | protocol=17 | dir=in | app=system |
"{8DCCB708-6BB4-4840-8227-3EA075CADD85}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{9C1A13F2-FF37-4B33-828E-0FFC005FAED0}" = rport=139 | protocol=6 | dir=out | app=system |
"{AA014E6A-1654-44F6-8B40-97EC201E1F0A}" = rport=137 | protocol=17 | dir=out | app=system |
"{B25AD8C6-ADE2-4C6E-A631-1303A5C1E676}" = lport=138 | protocol=17 | dir=in | app=system |
"{B98276EA-0EF3-4421-B382-1F5C30936C16}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{CBF67B93-B798-43D0-BED4-6603F0499EE6}" = rport=445 | protocol=6 | dir=out | app=system |
"{FBC388A7-026D-46D2-A249-6422FFEE77DD}" = lport=139 | protocol=6 | dir=in | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{065E6D2D-4765-42D1-A258-3F8DA33D6490}" = protocol=6 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
"{1C8C9F33-462B-4081-BA75-697ABF612DB8}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{1C931E93-A41E-4CD3-8EFF-BF930E15C189}" = protocol=17 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
"{287F9304-C322-49A8-B385-2A7176BAB120}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{2A933ED7-A631-4539-96C7-FDEDC7B05A03}" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yserver.exe |
"{2E7D46C1-623E-4359-B3B9-51190C458463}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{2F471510-AFA2-45A6-8287-AED41E468F12}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{317B1B26-EAAE-480A-A8ED-950A3701D4D0}" = protocol=6 | dir=in | app=c:\program files\aim6\aim6.exe |
"{3B2FA866-4202-4DC0-992B-A9BFAAE96D7D}" = protocol=17 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
"{3DF3090D-6268-4BAB-87BD-81DBA986FA56}" = protocol=6 | dir=in | app=c:\program files\aim\aim.exe |
"{44A3DC22-C0B2-4373-ABE8-A3D8512E13B8}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{46FD4038-3A08-43B7-B82A-AD595F87E47E}" = dir=in | app=c:\program files\hp\quickplay\qp.exe |
"{488C171A-F058-4729-9BD8-D304680A1CA1}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{4A933F9E-F1F4-4447-94EC-73109CC469AA}" = protocol=17 | dir=in | app=c:\program files\tencent\qq games\update\update.exe |
"{4ABA226C-6923-44AC-94F0-0DB97D786FC4}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{536D7F0B-FD92-435E-AF4B-5936C13E41D1}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{668E7617-18FE-4F3A-BC36-FF63DC2A4F87}" = dir=in | app=c:\program files\cyberlink\powerdirector\pdr.exe |
"{788A39DF-B575-477B-A928-4070DC6D3C7A}" = protocol=6 | dir=in | app=c:\program files\tencent\qq games\qqgamesd.exe |
"{8483733E-D7CD-49E9-95EA-FE7063F79A69}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{8CF98A2B-00E7-48D1-9E89-EF8A9F11EB5E}" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"{94A277F1-115C-4700-BE9A-69E3D49F90A9}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{95FD1396-40DA-4DD2-8C16-0DE73B59F2D7}" = protocol=6 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
"{99C7A66D-D16F-46E5-9AD2-EEB2F28C60DB}" = protocol=6 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{9DD804DC-0E66-4DA7-8446-C4417C14C21A}" = protocol=6 | dir=in | app=c:\program files\tencent\qq games\update\update.exe |
"{9F5C1D36-7D9B-4FE9-85FB-9E745932A0CE}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{A71E194E-2C2F-4647-BCEC-F8C9A9E4930D}" = protocol=17 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{AC875C3B-6E0F-44D0-A053-E13336D41258}" = protocol=17 | dir=in | app=c:\program files\tencent\qq games\qqgames.exe |
"{AE003CE4-9B71-4105-BC79-568BA0958077}" = dir=in | app=c:\program files\avg\avg8\avgupd.exe |
"{B428A244-7BFB-43FC-AB39-6BE24DCAABD5}" = protocol=17 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{B7846AE1-08E9-4B11-846C-70DF6CCF1E25}" = dir=in | app=c:\program files\avg\avg8\avgemc.exe |
"{BD22AA38-7BC5-4576-B887-DB971105038C}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{C18C4586-7299-47A8-90B0-BD7675DF1F31}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{CC6381AF-7F2B-453D-AB8D-F3724FC477E8}" = protocol=6 | dir=in | app=c:\program files\aim6\aim6.exe |
"{CE619381-43B5-42C5-A2F7-1525864FA38F}" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yserver.exe |
"{CE87D47A-AB92-44B8-AB23-07BBA8C073DA}" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"{D0ECC5AB-7509-46A6-BA7E-9779F7C1DC83}" = protocol=17 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{D3F43D71-BF0F-44ED-B946-59020355C43E}" = protocol=6 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{DDF71AF3-6AE8-41AC-B611-3836347FF39C}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{E0CDEBFA-D962-4D0A-9DB3-BDC67362EF26}" = protocol=17 | dir=in | app=c:\program files\aim\aim.exe |
"{E1FE54EC-049D-41D5-AC41-6494AF3C6273}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{E494C045-02AD-4BDD-82CC-CF666E9105E4}" = protocol=6 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{E4BB53FC-2F63-4498-91AF-58DA5F4E931C}" = protocol=17 | dir=in | app=c:\program files\aim6\aim6.exe |
"{EB9C1CFB-4FEF-4A5A-8641-AF54A034D769}" = protocol=17 | dir=in | app=c:\program files\aim6\aim6.exe |
"{EBF96165-D7B0-45B5-A8EB-191BA668D88E}" = protocol=17 | dir=in | app=c:\program files\tencent\qq games\qqgamesd.exe |
"{ED369ACE-1B91-4FAA-AF00-33C3D3D8F837}" = protocol=6 | dir=in | app=c:\program files\tencent\qq games\qqgames.exe |
"{F2F867A1-2B5B-4CD8-BC69-3B7F4F3EAE5F}" = dir=in | app=c:\program files\hp\quickplay\qpservice.exe |
"TCP Query User{78F41B23-9425-4233-91D2-8EB75BA9114A}C:\program files\yahoo!\messenger\yahoomessenger.exe" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"TCP Query User{7B1DD977-4CF0-4D86-8683-A9A07E9C9F4C}C:\program files\yahoo!\messenger\yserver.exe" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yserver.exe |
"TCP Query User{C63A4F2F-49AF-4FBB-AE63-1B81F2060D1B}C:\program files\red storm entertainment\ravenshield\system\ravenshield.exe" = protocol=6 | dir=in | app=c:\program files\red storm entertainment\ravenshield\system\ravenshield.exe |
"UDP Query User{1BC36F66-7B19-41BD-879E-9350F4D5A937}C:\program files\red storm entertainment\ravenshield\system\ravenshield.exe" = protocol=17 | dir=in | app=c:\program files\red storm entertainment\ravenshield\system\ravenshield.exe |
"UDP Query User{540E6D3E-5365-473E-9E6E-298945EF880F}C:\program files\yahoo!\messenger\yahoomessenger.exe" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"UDP Query User{F63CA9A8-CAA5-4FA3-A122-0966F620BA2D}C:\program files\yahoo!\messenger\yserver.exe" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yserver.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{004B0DCB-4C60-465B-8F01-44B0A4111187}" = SlingPlayer
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"{03D1988F-469F-4843-8E6E-E5FE9D17889D}" = HP Integrated Module with Bluetooth wireless technology 6.0.1.5500
"{06E74B9B-631F-4378-BF3A-40D868450C05}" = HPPhotoSmartPhotobookHolidayPack1
"{082702D5-5DD8-4600-BCE5-48B15174687F}" = HP Doc Viewer
"{082F8ABA-84D5-4837-9DFC-F365D91A07D4}" = HP Smart Web Printing
"{0AB76F69-E761-4CFA-B9B0-A1906B4E9E4B}" = WD Diagnostics
"{0CB9668D-F979-4F31-B8B8-67FE90F929F8}" = Bonjour
"{11BB336F-0E58-4977-B866-F24FA334616B}" = HP Active Support Library
"{12A76360-388E-4B27-ABEB-D5FC5378DD2A}" = HPPhotoSmartPhotobookWebPack1
"{146E206D-7D2C-493A-B431-1F1D16E822AF}" = MobileMe Control Panel
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{172AEB5E-CBB2-4CDD-A4CF-388600825839}" = HPPhotoSmartPhotobookPlayfulPack1
"{1BDC9633-895B-4842-BCB6-8FA1EC2A3C5A}" = Adobe Shockwave Player
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = DVD Suite
"{209CDA54-D390-46A2-A97C-7BF61734418D}" = WeatherBug Gadget
"{20ACB2F8-3BCA-45A8-80A2-9D3CB5C25F43}" = Safari
"{2284D904-C138-4B58-93EC-5C362AB5130A}" = The Sims™ Life Stories
"{228C6B46-64E2-404E-898A-EF0830603EF4}" = HPNetworkAssistant
"{250E9609-E830-43EB-B379-DAB7546A2422}" = muvee autoProducer 6.1
"{254C37AA-6B72-4300-84F6-98A82419187E}" = Hewlett-Packard Active Check
"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java™ 6 Update 20
"{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Atheros Driver Installation Program
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{28EDCE9C-3304-4331-8AB3-F3EBE94C35B4}" = HP Help and Support
"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java™ 6 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{34BFB099-07B2-4E95-A673-7362D60866A2}" = PSSWCORE
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.30 E1
"{38EAC694-0D90-445F-8C17-8B50ADFE3162}" = Slingbox Flash Tour
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP QuickPlay 3.6
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CACFCD9-F71B-413A-8DF5-1A6419D5CDC6}" = Cards_Calendar_OrderGift_DoMorePlugout
"{541DEAC0-5F3D-45E6-B7CB-94ECF3B96748}" = Skype web features
"{59F6A514-9813-47A3-948C-8A155460CC2A}" = RICOH R5C83x/84x Flash Media Controller Driver Ver.3.51.01
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = Hewlett-Packard Asset Agent for Health Check
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6BCEB97B-F315-455D-BC2D-565A1A6781E8}" = Memeo AutoBackup
"{7059BDA7-E1DB-442C-B7A1-6144596720A4}" = HP Update
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7AB3A249-FB81-416B-917A-A2A10E74C503}" = iTunes
"{7DC4A410-9986-4329-9E5D-687B2C42CA39}" = HP QuickTouch 1.00 C4
"{8347A7A5-4AB8-433F-82AA-496B0D189A9B}" = HP User Guides 0088
"{85991ED2-010C-4930-96FA-52F43C2CE98A}" = Apple Mobile Device Support
"{89E052B2-5CA5-4B7A-AF0C-28CA2836B030}" = HPPhotoSmartPhotobookModernPack1
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{9885A11E-60E4-417C-B58B-8B31B21C0B8A}" = HP Easy Setup - Frontend
"{A07840FC-CE63-4CB8-8030-EF4B9805925A}" = HPPhotoSmartDiscLabel_PaperLabel
"{a0fe116e-9a8a-466f-aee0-625cb7c207e3}" = Microsoft Visual C++ 2005 Redistributable - KB2467175
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.6
"{AC95121F-1576-45B8-82F7-3911D27882E6}" = HPPhotoSmartPhotobookScrapbookPack1
"{ADFB9653-F44C-460C-BF58-189CC552DFFE}" = hpphotosmartdisclabelplugin
"{AEC0CEBC-0FC7-4716-8222-1C4A742719B1}" = Samsung Master
"{AF131494-F5D8-45C5-938C-D5F020CF1B0D}" = Tom Clancy's Rainbow Six 3: Raven Shield
"{b02df929-29a7-4fd2-9a70-81a644b635f7}" = HP Total Care Advisor
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B4E91E95-A5BA-4E50-A465-DB7EFEB176E8}" = HPPhotoSmartDiscLabel_PrintOnDisc
"{BAD0FA60-09CF-4411-AE6A-C2844C8812FA}" = HP Photosmart Essential 2.5
"{BD0E2B92-3814-46F0-893B-4612EA010C7E}" = HP Customer Experience Enhancements
"{C4124E95-5061-4776-8D5D-E3D931C778E1}" = Microsoft VC9 runtime libraries
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CBAE4F50-9FC9-4557-AB36-9826DF3C103C}" = HP Wireless Assistant
"{CC4A73BF-938E-4C19-A553-853C035C9BA1}" = LightScribe System Software 1.10.13.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1
"{DAEAFD68-BB4A-4507-A241-C8804D2EA66D}" = Apple Application Support
"{DD3C88A0-C53C-41D0-A21B-6D021981D23E}" = HPPhotoSmartDiscLabelContent1
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E08DC77E-D09A-4e36-8067-D6DBBCC5F8DC}" = VideoToolkit01
"{F5577101-33CC-4711-8235-3A95BCD49DB0}" = EA Link
"{F636EE9A-F9EC-4606-BCFA-77DD0E210788}" = HPPhotoSmartDiscLabel_Tattoo
"{FECA6067-869C-4F32-9F6E-574E1496CE44}" = Memeo AutoSync
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AVG8Uninstall" = AVG Free 8.5
"CNXT_AUDIO_HDA" = Conexant HD Audio
"CNXT_MODEM_HDA_HSF" = HDAUDIO Soft Data Fax Modem with SmartCP
"ESET Online Scanner" = ESET Online Scanner v3
"Google Chrome" = Google Chrome
"Google Desktop" = Google Desktop
"Hauppauge MCE2005 Software Encoder" = Hauppauge MCE XP/Vista Software Encoder (2.0.25149)
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"HP Photosmart Essential" = HP Photosmart Essential 2.5
"HP Smart Web Printing" = HP Smart Web Printing
"InstallShield_{004B0DCB-4C60-465B-8F01-44B0A4111187}" = SlingPlayer
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"InstallShield_{F5577101-33CC-4711-8235-3A95BCD49DB0}" = EA Link
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"NVIDIA Drivers" = NVIDIA Drivers
"Picasa 3" = Picasa 3
"QQ Games" = QQ Games
"royhtfnxhrhyqcavc" = RON Tool Mxlivemedia
"SlingMedia.QPSlingPlayer_is1" = QuickPlay SlingPlayer 0.4.6
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"WildTangent hp Master Uninstall" = My HP Games
"Yahoo! Extras" = Yahoo! Browser Services
"Yahoo! Mail" = Yahoo! Internet Mail
"Yahoo! Messenger" = Yahoo! Messenger
"YInstHelper" = Yahoo! Install Manager

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-3299488197-778044784-366267875-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Antispyware PRO XP 3.1" = Antispyware PRO XP
"Facebook Plug-In" = Facebook Plug-In
"InstallShield_{6BCEB97B-F315-455D-BC2D-565A1A6781E8}" = Memeo AutoBackup
"InstallShield_{FECA6067-869C-4F32-9F6E-574E1496CE44}" = Memeo AutoSync

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 4/17/2011 1:02:42 AM | Computer Name = Mike-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 30797686

Error - 4/17/2011 1:02:43 AM | Computer Name = Mike-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 4/17/2011 1:02:43 AM | Computer Name = Mike-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 30798981

Error - 4/17/2011 1:02:43 AM | Computer Name = Mike-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 30798981

Error - 4/17/2011 1:02:51 AM | Computer Name = Mike-PC | Source = Google Update | ID = 20
Description =

Error - 4/17/2011 2:02:50 AM | Computer Name = Mike-PC | Source = MsiInstaller | ID = 11303
Description =

Error - 4/17/2011 2:42:55 AM | Computer Name = Mike-PC | Source = MsiInstaller | ID = 11303
Description =

Error - 4/17/2011 2:52:59 AM | Computer Name = Mike-PC | Source = MsiInstaller | ID = 11303
Description =

Error - 4/17/2011 3:03:05 AM | Computer Name = Mike-PC | Source = MsiInstaller | ID = 11303
Description =

Error - 4/17/2011 3:09:26 AM | Computer Name = Mike-PC | Source = WinMgmt | ID = 10
Description =

[ Media Center Events ]
Error - 12/26/2009 11:12:41 PM | Computer Name = Mike-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 12/27/2009 12:57:52 AM | Computer Name = Mike-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 12/27/2009 8:02:42 AM | Computer Name = Mike-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 12/27/2009 8:03:15 PM | Computer Name = Mike-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 12/28/2009 8:11:58 PM | Computer Name = Mike-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 12/28/2009 10:10:18 PM | Computer Name = Mike-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 12/29/2009 8:13:22 AM | Computer Name = Mike-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 12/29/2009 8:41:19 PM | Computer Name = Mike-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 3/18/2010 3:13:10 PM | Computer Name = Mike-PC | Source = MCUpdate | ID = 0
Description = Failed to wait on MCUpdate mutex with exception: 'The wait completed
due to an abandoned mutex.'.

Error - 5/1/2010 2:41:07 PM | Computer Name = Mike-PC | Source = MCUpdate | ID = 0
Description = Failed to wait on MCUpdate mutex with exception: 'The wait completed
due to an abandoned mutex.'.

[ System Events ]
Error - 4/16/2011 3:08:24 AM | Computer Name = Mike-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 4/16/2011 3:19:13 AM | Computer Name = Mike-PC | Source = Service Control Manager | ID = 7009
Description =

Error - 4/16/2011 3:19:13 AM | Computer Name = Mike-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 4/16/2011 3:19:13 AM | Computer Name = Mike-PC | Source = Service Control Manager | ID = 7009
Description =

Error - 4/16/2011 3:19:13 AM | Computer Name = Mike-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 4/16/2011 3:35:17 AM | Computer Name = Mike-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 4/16/2011 3:38:18 AM | Computer Name = Mike-PC | Source = DCOM | ID = 10000
Description =

Error - 4/17/2011 3:08:49 AM | Computer Name = Mike-PC | Source = Print | ID = 19
Description = The print spooler failed to share printer Send To OneNote 2007 with
shared resource name Send To OneNote 2007. Error 2114. The printer cannot be used
by others on the network.

Error - 4/17/2011 3:09:26 AM | Computer Name = Mike-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 4/17/2011 3:10:07 AM | Computer Name = Mike-PC | Source = DCOM | ID = 10000
Description =


< End of report >



OTL logfile created on: 4/17/2011 9:13:28 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Mike\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19048)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 47.00% Memory free
6.00 Gb Paging File | 4.00 Gb Available in Paging File | 73.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 221.08 Gb Total Space | 139.31 Gb Free Space | 63.01% Space Free | Partition Type: NTFS
Drive D: | 11.80 Gb Total Space | 1.98 Gb Free Space | 16.76% Space Free | Partition Type: NTFS

Computer Name: MIKE-PC | User Name: Mike | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Mike\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe (Lavasoft)
PRC - C:\WINDOWS\vsnp2uvc.exe (Sonix)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe (Broadcom Corporation.)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)


========== Modules (SafeList) ==========

MOD - C:\Users\Mike\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)


========== Win32 Services (SafeList) ==========

SRV - (AutoSyncService) – File not found
SRV - (AVG Security Toolbar Service) – C:\Program Files\AVG\AVG8\Toolbar\ToolbarBroker.exe ()
SRV - (avg8emc) – C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg8wd) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (aawservice) – C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe (Lavasoft)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (Com4Qlb) – C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe (Hewlett-Packard Development Company, L.P.)


========== Driver Services (SafeList) ==========

DRV - (AvgLdx86) – C:\Windows\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\Windows\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (SNP2UVC) USB2.0 PC Camera (SNP2UVC) – C:\WINDOWS\System32\drivers\snp2uvc.sys ()
DRV - (AvgTdiX) – C:\Windows\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (nvlddmkm) – C:\WINDOWS\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (RTL8187) – C:\WINDOWS\System32\drivers\RTL8187.sys (Realtek Semiconductor Corporation )
DRV - (athr) – C:\WINDOWS\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (HdAudAddService) – C:\WINDOWS\System32\drivers\CHDART.sys (Conexant Systems Inc.)
DRV - (HpqRemHid) – C:\WINDOWS\System32\drivers\HpqRemHid.sys (Hewlett-Packard Development Company, L.P.)
DRV - (XAudio) – C:\WINDOWS\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (HpqKbFiltr) – C:\WINDOWS\System32\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (rismxdp) – C:\WINDOWS\System32\drivers\rixdptsk.sys (REDC)
DRV - (NVENETFD) – C:\WINDOWS\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (rimmptsk) – C:\WINDOWS\System32\drivers\rimmptsk.sys (REDC)
DRV - (nvsmu) – C:\WINDOWS\System32\drivers\nvsmu.sys (NVIDIA Corporation)
DRV - (rimsptsk) – C:\WINDOWS\System32\drivers\rimsptsk.sys (REDC)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html


IE - HKU\.DEFAULT\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-3299488197-778044784-366267875-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop
IE - HKU\S-1-5-21-3299488197-778044784-366267875-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKU\S-1-5-21-3299488197-778044784-366267875-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKU\S-1-5-21-3299488197-778044784-366267875-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 2
IE - HKU\S-1-5-21-3299488197-778044784-366267875-1000\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
IE - HKU\S-1-5-21-3299488197-778044784-366267875-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3299488197-778044784-366267875-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local



O1 HOSTS File: ([2006/09/18 17:41:30 | 000,000,761 | —- | M]) - C:\WINDOWS\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Yahoo! IE Services Button) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No CLSID value found.
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O2 - BHO: (HP Print Clips) - {FFFFFFFF-FF12-44C5-91EC-068E3AA1B2D7} - c:\Program Files\HP\Smart Web Printing\hpswp_framework.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O3 - HKU\S-1-5-21-3299488197-778044784-366267875-1000\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O3 - HKU\S-1-5-21-3299488197-778044784-366267875-1000\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - No CLSID value found.
O3 - HKU\S-1-5-21-3299488197-778044784-366267875-1000\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [HP Health Check Scheduler] File not found
O4 - HKLM..\Run: [HP Software Update] File not found
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [snp2uvc] C:\WINDOWS\vsnp2uvc.exe (Sonix)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-21-3299488197-778044784-366267875-1000..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - Startup: C:\Users\Mike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Memeo AutoBackup Launcher.lnk = C:\Users\Mike\AppData\Roaming\Microsoft\Installer\{6BCEB97B-F315-455D-BC2D-565A1A6781E8}\NewShortcut4_51A847D327C24F7797772AF2A4E486ED.exe (Macrovision Corporation)
O4 - Startup: C:\Users\Mike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Memeo AutoSync Launcher.lnk = File not found
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Send image to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send page to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: HP Smart Select - {58ECB495-38F0-49cb-A538-10282ABF65E7} - c:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.)
O9 - Extra Button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKU\.DEFAULT\..Trusted Ranges: Range1 ([http] in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Ranges: Range1 ([http] in Local intranet)
O15 - HKU\S-1-5-21-3299488197-778044784-366267875-1000\..Trusted Ranges: GD ([http] in Local intranet)
O15 - HKU\S-1-5-21-3299488197-778044784-366267875-1000\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos-beta/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - AppInit_DLLs: (avgrsstx.dll) - C:\Windows\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Mike\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Mike\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/04/24 21:48:01 | 000,000,074 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2005/09/11 11:18:54 | 000,000,340 | -HS- | M] () - D:\AUTOMODE – [ NTFS ]
O33 - MountPoints2\{38e5a98c-686a-11dd-aa8d-ed569a80572c}\Shell\AutoRun\command - "" = F:\wd_windows_tools\setup.exe
O33 - MountPoints2\{402fe811-9474-11de-89ee-0021860682ee}\Shell\AutoRun\command - "" = F:\setupSNK.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\Windows\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/04/17 21:11:26 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Users\Mike\Desktop\OTL.exe
[2011/04/17 14:51:20 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2011/04/17 02:40:55 | 000,000,000 | —D | C] – C:\Users\Mike\AppData\Roaming\Malwarebytes
[2011/04/17 02:40:48 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2011/04/17 02:40:48 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/04/17 02:40:47 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2011/04/17 02:40:45 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2011/04/17 02:40:45 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/04/14 18:42:21 | 001,172,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10warp.dll
[2011/04/14 18:42:21 | 001,068,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2011/04/14 18:42:21 | 001,029,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10.dll
[2011/04/14 18:42:21 | 000,683,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d2d1.dll
[2011/04/14 18:42:21 | 000,486,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10level9.dll
[2011/04/14 18:42:21 | 000,189,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10core.dll
[2011/04/14 18:42:21 | 000,160,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1.dll
[2011/04/14 18:42:20 | 001,554,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xpsservices.dll
[2011/04/14 18:42:20 | 000,847,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\OpcServices.dll
[2011/04/14 18:42:20 | 000,288,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsGdiConverter.dll
[2011/04/14 18:42:20 | 000,219,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1core.dll
[2011/04/14 18:42:12 | 000,292,864 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\atmfd.dll
[2011/04/14 18:42:12 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fontsub.dll
[2011/04/14 18:42:12 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\System32\atmlib.dll
[2011/04/14 18:42:10 | 001,469,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2011/04/14 18:42:10 | 000,387,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2011/04/14 18:42:10 | 000,173,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2011/04/14 18:42:10 | 000,133,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2011/04/14 18:42:10 | 000,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2011/04/14 18:42:10 | 000,055,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2011/04/14 18:42:10 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2011/04/14 18:42:09 | 001,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2011/04/14 18:42:09 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2011/04/14 18:42:09 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2011/04/14 18:42:08 | 000,602,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2011/04/14 18:42:06 | 000,611,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2011/04/14 18:42:06 | 000,385,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2011/04/14 18:42:06 | 000,184,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2011/04/14 18:42:06 | 000,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2011/04/14 18:42:06 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2011/04/14 18:42:06 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2011/04/14 18:41:29 | 003,602,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2011/04/14 18:41:29 | 003,550,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2011/04/14 18:41:22 | 001,162,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc42u.dll
[2011/04/14 18:41:22 | 001,136,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc42.dll
[2011/04/14 18:41:19 | 000,025,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dnscacheugc.exe
[2011/04/14 18:41:06 | 002,041,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2011/04/14 18:41:04 | 001,169,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sdclt.exe
[2011/04/14 18:41:00 | 000,726,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript.dll
[2011/04/14 18:41:00 | 000,420,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vbscript.dll
[2011/04/14 18:40:59 | 000,429,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EncDec.dll
[2011/04/14 18:40:59 | 000,322,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sbe.dll
[2011/04/14 18:40:59 | 000,177,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mpg2splt.ax
[2011/04/14 18:40:59 | 000,153,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sbeio.dll
[2011/04/14 18:40:49 | 000,352,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\taskschd.dll
[2011/04/14 18:40:49 | 000,345,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmicmiplugin.dll
[2011/04/14 18:40:49 | 000,270,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\taskcomp.dll
[2011/04/14 18:40:47 | 000,081,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\consent.exe
[2011/04/14 18:40:42 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[2011/04/14 18:40:22 | 000,413,696 | —- | C] (Microsoft Corporation) – C:\Windows\System32\odbc32.dll
[2011/04/14 18:40:17 | 000,979,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MFH264Dec.dll
[2011/04/14 18:40:17 | 000,135,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsRasterService.dll
[2011/04/14 18:40:16 | 000,876,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsPrint.dll
[2011/04/14 18:40:16 | 000,357,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MFHEAACdec.dll
[2011/04/14 18:40:16 | 000,302,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfmp4src.dll
[2011/04/14 18:40:16 | 000,261,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfreadwrite.dll
[2011/04/14 18:40:15 | 002,873,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mf.dll
[2011/04/14 18:40:15 | 000,478,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxgi.dll
[2011/04/14 18:40:14 | 000,667,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelinesvc.exe
[2011/04/14 18:40:13 | 000,209,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfplat.dll
[2011/04/14 18:40:12 | 000,098,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfps.dll
[2011/04/14 18:40:12 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cdd.dll
[2011/04/14 18:40:12 | 000,026,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelineprxy.dll
[2011/04/14 18:38:53 | 008,147,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmploc.DLL
[2011/04/14 18:38:34 | 000,017,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netevent.dll
[2011/04/14 18:37:07 | 000,081,920 | —- | C] (Radius Inc.) – C:\Windows\System32\iccvid.dll
[2011/04/14 18:36:42 | 000,157,184 | —- | C] (Microsoft Corporation) – C:\Windows\System32\t2embed.dll
[2011/04/14 18:35:38 | 000,867,328 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmpmde.dll
[2007/07/13 07:36:22 | 000,220,184 | —- | C] ( ) – C:\Users\Mike\AppData\Local\Interop.Microsoft.Office.Core.dll
[2007/07/04 21:28:52 | 000,176,128 | —- | C] ( ) – C:\Windows\System32\csnp2uvc.dll
[2005/12/13 17:12:34 | 000,016,384 | —- | C] (Microsoft Corporation) – C:\Users\Mike\AppData\Local\stdole.dll

========== Files - Modified Within 30 Days ==========

[2011/04/17 21:18:00 | 000,000,886 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/04/17 21:11:30 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Users\Mike\Desktop\OTL.exe
[2011/04/17 21:08:34 | 000,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/04/17 21:08:34 | 000,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/04/17 13:58:52 | 000,027,744 | —- | M] () – C:\ProgramData\nvModes.dat
[2011/04/17 13:58:51 | 000,027,744 | —- | M] () – C:\ProgramData\nvModes.001
[2011/04/17 08:58:48 | 074,535,864 | —- | M] () – C:\Windows\System32\drivers\Avg\incavi.avm
[2011/04/17 05:42:07 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/04/17 05:18:00 | 000,000,882 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/04/17 03:15:19 | 000,595,684 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/04/17 03:15:19 | 000,101,350 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/04/17 03:10:32 | 000,000,258 | —- | M] () – C:\Users\Public\Documents\hpqp.ini
[2011/04/17 03:09:37 | 000,002,507 | —- | M] () – C:\Users\Mike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Memeo AutoBackup Launcher.lnk
[2011/04/17 03:07:53 | 3152,920,576 | -HS- | M] () – C:\hiberfil.sys
[2011/04/17 03:06:35 | 000,000,012 | —- | M] () – C:\Windows\bthservsdp.dat
[2011/04/17 03:05:41 | 000,003,332 | —- | M] () – C:\Users\Mike\Desktop\Attach.zip
[2011/04/17 02:40:48 | 000,000,866 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/04/16 03:37:32 | 000,000,680 | —- | M] () – C:\Users\Mike\AppData\Local\d3d9caps.dat
[2011/04/16 03:34:25 | 000,312,336 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2011/04/13 10:43:59 | 000,146,944 | —- | M] () – C:\Users\Mike\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

========== Files Created - No Company Name ==========

[2011/04/17 03:05:41 | 000,003,332 | —- | C] () – C:\Users\Mike\Desktop\Attach.zip
[2011/04/17 02:40:48 | 000,000,866 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/12/29 18:59:39 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/12/29 18:59:39 | 000,107,612 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2009/11/20 00:48:05 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2009/11/19 12:01:34 | 000,765,952 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2009/11/19 12:01:34 | 000,180,224 | —- | C] () – C:\Windows\System32\xvidvfw.dll
[2009/11/19 12:01:34 | 000,008,704 | —- | C] () – C:\Windows\System32\vidccleaner.exe
[2009/08/08 22:32:40 | 000,000,000 | —- | C] () – C:\Users\Mike\AppData\Roaming\wklnhst.dat
[2009/08/03 08:07:42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2009/08/03 08:07:42 | 000,230,768 | —- | C] () – C:\Windows\System32\OGAEXEC.exe
[2009/06/20 21:49:10 | 000,000,021 | —- | C] () – C:\Windows\atid.ini
[2009/06/09 17:16:42 | 003,482,240 | —- | C] () – C:\Windows\System32\drivers\snp2uvc.sys
[2009/03/26 07:48:54 | 000,027,744 | —- | C] () – C:\ProgramData\nvModes.001
[2009/03/26 07:48:45 | 000,027,744 | —- | C] () – C:\ProgramData\nvModes.dat
[2009/02/11 17:45:02 | 000,027,264 | —- | C] () – C:\Windows\System32\drivers\sncduvc.sys
[2008/09/17 19:18:04 | 000,000,016 | —- | C] () – C:\Windows\popcinfo.dat
[2008/09/16 17:09:08 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2008/08/14 05:47:41 | 000,000,680 | —- | C] () – C:\Users\Mike\AppData\Local\d3d9caps.dat
[2008/08/13 07:11:08 | 000,146,944 | —- | C] () – C:\Users\Mike\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/08/08 15:48:24 | 000,027,240 | —- | C] () – C:\Users\Mike\AppData\Roaming\nvModes.001
[2008/08/08 15:48:06 | 000,027,240 | —- | C] () – C:\Users\Mike\AppData\Roaming\nvModes.dat
[2008/08/08 15:41:41 | 000,000,000 | —- | C] () – C:\Windows\PowerReg.dat
[2008/06/04 08:50:37 | 000,016,480 | —- | C] () – C:\Windows\System32\rixdicon.dll
[2008/06/04 08:46:53 | 000,001,732 | —- | C] () – C:\Windows\System32\drivers\nvphy.bin
[2008/06/04 08:43:03 | 000,000,012 | —- | C] () – C:\Windows\bthservsdp.dat
[2008/05/16 11:58:04 | 000,012,632 | —- | C] () – C:\Windows\System32\lsdelete.exe
[2008/04/24 22:03:11 | 000,101,605 | —- | C] () – C:\Windows\hpqins13.dat
[2007/09/05 15:52:04 | 000,389,120 | —- | C] () – C:\Windows\System32\btwhidcs.dll
[2006/11/02 08:57:28 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 08:47:37 | 000,312,336 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 08:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 06:33:01 | 000,595,684 | —- | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 06:33:01 | 000,287,440 | —- | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 06:33:01 | 000,101,350 | —- | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 06:33:01 | 000,030,674 | —- | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 06:23:21 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2006/11/02 04:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/02 04:19:00 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/02 03:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 03:25:31 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2006/05/19 15:39:58 | 000,015,497 | —- | C] () – C:\Windows\snp2uvc.ini
[2006/03/09 05:58:00 | 001,060,424 | —- | C] () – C:\Windows\System32\WdfCoInstaller01000.dll
[2001/11/14 16:56:00 | 001,802,240 | —- | C] () – C:\Windows\System32\lcppn21.dll

========== LOP Check ==========

[2009/04/22 16:37:41 | 000,000,000 | —D | M] – C:\Users\Mike\AppData\Roaming\aAvgApi
[2008/09/27 22:15:19 | 000,000,000 | —D | M] – C:\Users\Mike\AppData\Roaming\acccore
[2010/04/14 00:26:26 | 000,000,000 | —D | M] – C:\Users\Mike\AppData\Roaming\Facebook
[2009/06/20 22:24:37 | 000,000,000 | —D | M] – C:\Users\Mike\AppData\Roaming\QQ Games Plugin
[2009/08/08 22:32:41 | 000,000,000 | —D | M] – C:\Users\Mike\AppData\Roaming\Template
[2008/08/15 17:17:58 | 000,000,000 | —D | M] – C:\Users\Mike\AppData\Roaming\WildTangent
[2011/04/17 03:06:37 | 000,032,542 | —- | M] () – C:\WINDOWS\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



< End of report >
Good Morning,

Its been suggested to bring this computer back like new to do a factory restore , it will reset your computer back to the day it was manufactured, if you want to go that route let me know and I can link you to our forum that can help you.

Looks like they had Norton Antivirus installed at one time and it was removed but seeing remnants of it.

Try running this removal tool and then post a new OTL log

http://service1.symantec.com/SUPPORT/tsgen…005033108162039
there are several options on the link you gave me and im not sure which norton program they had. how do i figure out which removal tool to use? resetting the computer to factory settings is not a problem for me.
If reformatting is what you want to do let me know for sure and I will link you to a windows site to help you, do you have your Windows CD or the Recovery Disk that came with the computer ?

If you decide to stay where you are you can remove these with OTL, most are just leftover entries for Symantec and you can forgo there removal tool .

Open OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :processes
    killallprocesses
    
    :OTL
    O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
    O3 - HKU\S-1-5-21-3299488197-778044784-366267875-1000\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
    O33 - MountPoints2\{402fe811-9474-11de-89ee-0021860682ee}\Shell\AutoRun\command - "" = F:\setupSNK.exe
    
    
    :Services
    
    :Reg
    
    :Files
    
    
    
    
    
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top. <–Not run Scan
  • Let the program run unhindered, reboot when it is done
  • Then post the results of the log it produces.
i think i will skip the reformat. i dont have the recovery disc, and its not running bad enough to merit that drastic a move. the computer is running good but seems to take longer than it should on start up. other than that everything seems to be ok for it to be a used laptop. All processes killed ========== PROCESSES ========== ========== OTL ========== Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\ deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}\ not found. Registry value HKEY_USERS\S-1-5-21-3299488197-778044784-366267875-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{402fe811-9474-11de-89ee-0021860682ee}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{402fe811-9474-11de-89ee-0021860682ee}\ not found. File F:\setupSNK.exe not found. ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== ========== FILES ========== ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Mike ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 140610688 bytes ->Java cache emptied: 14095759 bytes ->FireFox cache emptied: 88170410 bytes ->Google Chrome cache emptied: 6347539 bytes ->Apple Safari cache emptied: 0 bytes ->Flash cache emptied: 149746 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 4373775 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes RecycleBin emptied: 12580112 bytes Total Files Cleaned = 254.00 mb OTL by OldTimer - Version 3.2.22.3 log created on 04182011_191131 Files\Folders moved on Reboot… Registry entries deleted on Reboot…
Hi,

With what we removed already lets run this program and see if there is anything bad to remove we have not detected.

Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
the links you sent me for combo fix are saying they are corrupt…. when i downloaded it didn't give an option to save to desktop.it also told me to uninstall AVG instead of disabling it. ???

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI