This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

infected/hijacked laptop

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

:thumbup:

Run these in order please


Please download ATF Cleaner by Atribune to your desktop.
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
Your system may start up slower after running ATF Cleaner, this is expected but will be back to normal after the first or second boot up
Please note: If you use online banking or are registered online with any other organizations, ensure you have memorized password and other personal information as removing cookies will temporarily disable the auto-login facility.





Please download Malwarebytes from Here or Here

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the report please






OTL by OldTimer
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Click the "Scan All Users" checkbox.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 6470

Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.19019

4/29/2011 7:29:32 AM
mbam-log-2011-04-29 (07-29-32).txt

Scan type: Quick scan
Objects scanned: 147397
Time elapsed: 2 minute(s), 54 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)




OTL logfile created on: 4/29/2011 7:37:09 AM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Nikki\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19019)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 61.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 86.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 231.42 Gb Total Space | 169.25 Gb Free Space | 73.13% Space Free | Partition Type: NTFS

Computer Name: NIKKI-PC | User Name: Nikki | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Nikki\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe (TOSHIBA Corporation)
PRC - C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation)
PRC - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe ()
PRC - C:\TOSHIBA\IVP\ISM\pinger.exe ()
PRC - C:\Windows\System32\agrsmsvc.exe (Agere Systems)
PRC - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)


========== Modules (SafeList) ==========

MOD - C:\Users\Nikki\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (CLTNetCnService) – File not found
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (SprintRcAppSvc) – C:\Program Files\Sprint\Sprint SmartView\RcAppSvc.exe (PCTEL)
SRV - (CASprint) – C:\Program Files\Sprint\Sprint SmartView\ConAppsSvc.exe (PCTEL)
SRV - (TNaviSrv) – C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe (TOSHIBA Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (TosCoSrv) – C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
SRV - (ConfigFree Service) – C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
SRV - (TOSHIBA SMART Log Service) – C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe (TOSHIBA Corporation)
SRV - (TODDSrv) – C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation)
SRV - (jswpsapi) – C:\Program Files\Jumpstart\jswpsapi.exe (Atheros Communications, Inc.)
SRV - (Swupdtmr) – c:\TOSHIBA\IVP\swupdate\swupdtmr.exe ()
SRV - (GameConsoleService) – C:\Program Files\TOSHIBA Games\TOSHIBA Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (pinger) – C:\TOSHIBA\IVP\ISM\pinger.exe ()
SRV - (AgereModemAudio) – C:\Windows\System32\agrsmsvc.exe (Agere Systems)
SRV - (UleadBurningHelper) – C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)


========== Driver Services (SafeList) ==========

DRV - (SWNC5E00) Sierra Wireless MUX NDIS Driver (#00) – C:\Windows\System32\drivers\SWNC5E00.sys (Sierra Wireless Inc.)
DRV - (swmx00) Sierra Wireless USB MUX Driver (#00) – C:\Windows\System32\drivers\swmx00.sys (Sierra Wireless Inc.)
DRV - (swmsflt) – C:\Windows\System32\drivers\swmsflt.sys ()
DRV - (Nmea) – C:\Windows\System32\drivers\pctnullport.sys (PCTEL Inc.)
DRV - (PCTINDIS5) – C:\Windows\System32\PCTINDIS5.sys (PCTEL Inc.)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (tos_sps32) – C:\Windows\system32\DRIVERS\tos_sps32.sys (TOSHIBA Corporation)
DRV - (RTL8169) – C:\Windows\System32\drivers\Rtlh86.sys (Realtek Corporation )
DRV - (UVCFTR) – C:\Windows\System32\drivers\UVCFTR_S.SYS (Chicony Electronics Co., Ltd.)
DRV - (TVALZ) – C:\Windows\system32\DRIVERS\TVALZ_O.SYS (TOSHIBA Corporation)
DRV - (PCASp50) – C:\Windows\System32\drivers\PCASp50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (NWADI) – C:\Windows\System32\drivers\NWADIenum.sys (Novatel Wireless Inc)
DRV - (jswpslwf) – C:\Windows\System32\drivers\jswpslwf.sys (Atheros Communications, Inc.)
DRV - (atikmdag) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (AgereSoftModem) – C:\Windows\System32\drivers\AGRSM.sys (Agere Systems)
DRV - (FwLnk) – C:\Windows\System32\drivers\FwLnk.sys (TOSHIBA Corporation)
DRV - (KR10I) – C:\Windows\system32\drivers\kr10i.sys (TOSHIBA CORPORATION)
DRV - (KR10N) – C:\Windows\system32\drivers\kr10n.sys (TOSHIBA CORPORATION)
DRV - (AtiPcie) ATI PCI Express (3GIO) – C:\Windows\system32\DRIVERS\AtiPcie.sys (ATI Technologies Inc.)
DRV - (tdcmdpst) – C:\Windows\System32\drivers\tdcmdpst.sys (TOSHIBA Corporation.)
DRV - (Cdralw2k) – C:\Windows\System32\drivers\cdralw2k.sys (Sonic Solutions)
DRV - (Cdr4_xp) – C:\Windows\System32\drivers\cdr4_xp.sys (Sonic Solutions)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-3108643506-636927696-2022615235-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?ilc=1
IE - HKU\S-1-5-21-3108643506-636927696-2022615235-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3108643506-636927696-2022615235-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com/?ilc=1"
FF - prefs.js..network.proxy.type: 0


FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/12/22 22:29:36 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/02/19 14:34:52 | 000,000,000 | —D | M]

[2010/07/11 03:31:02 | 000,000,000 | —D | M] (No name found) – C:\Users\Nikki\AppData\Roaming\Mozilla\Extensions
[2011/02/23 23:59:43 | 000,000,000 | —D | M] (No name found) – C:\Users\Nikki\AppData\Roaming\Mozilla\Firefox\Profiles\k4l2ljw5.default\extensions
[2010/08/11 02:37:37 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Nikki\AppData\Roaming\Mozilla\Firefox\Profiles\k4l2ljw5.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/07/11 03:29:26 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2011/04/24 06:22:50 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - File not found
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [00TCrdMain] C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [MFARestart] C:\ProgramData\MFAData\pack\avgrunasx.exe ()
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Sprint SmartView] C:\Program Files\Sprint\Sprint SmartView\SprintSV.exe (Sprint)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKU\S-1-5-21-3108643506-636927696-2022615235-1000..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKLM..\RunOnce: [AvgUninstallURL] C:\Windows\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKU\S-1-5-21-3108643506-636927696-2022615235-1000..\RunOnce: [FlashPlayerUpdate] C:\Windows\System32\Macromed\Flash\FlashUtil10l_Plugin.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Users\Nikki\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Sticky Notes.lnk = C:\Windows\System32\StikyNot.exe (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-21-3108643506-636927696-2022615235-1000\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-21-3108643506-636927696-2022615235-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll (Sun Microsystems, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 17:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKU\S-1-5-21-3108643506-636927696-2022615235-1000\…exe [@ = exefile] – Reg Error: Key error. File not found

========== Files/Folders - Created Within 30 Days ==========

[2011/04/29 07:35:27 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Users\Nikki\Desktop\OTL.exe
[2011/04/29 07:25:33 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2011/04/29 07:25:33 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/04/29 07:25:30 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2011/04/29 07:25:30 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/04/29 07:24:36 | 007,734,208 | —- | C] (Malwarebytes Corporation ) – C:\Users\Nikki\Desktop\mbam-setup-1.50.1.1100.exe
[2011/04/29 07:22:22 | 000,050,688 | —- | C] (Atribune.org) – C:\Users\Nikki\Desktop\ATF-Cleaner.exe
[2011/04/24 13:07:07 | 000,000,000 | —D | C] – C:\Users\Nikki\Documents\LOC_GER
[2011/04/24 06:24:45 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2011/04/24 06:24:43 | 000,000,000 | —D | C] – C:\Windows\temp
[2011/04/24 06:24:42 | 000,000,000 | —D | C] – C:\Users\Nikki\AppData\Local\temp
[2011/04/24 06:13:33 | 000,161,792 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2011/04/24 06:13:33 | 000,136,704 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2011/04/24 06:13:33 | 000,031,232 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2011/04/24 06:13:25 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2011/04/24 06:13:04 | 000,212,480 | —- | C] (SteelWerX) – C:\Windows\SWXCACLS.exe
[2011/04/24 06:07:24 | 000,000,000 | —D | C] – C:\Qoobox
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/04/29 07:35:28 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Users\Nikki\Desktop\OTL.exe
[2011/04/29 07:25:34 | 000,000,917 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/04/29 07:24:44 | 007,734,208 | —- | M] (Malwarebytes Corporation ) – C:\Users\Nikki\Desktop\mbam-setup-1.50.1.1100.exe
[2011/04/29 07:22:36 | 000,050,688 | —- | M] (Atribune.org) – C:\Users\Nikki\Desktop\ATF-Cleaner.exe
[2011/04/29 05:52:46 | 000,003,744 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/04/29 05:52:46 | 000,003,744 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/04/28 23:57:32 | 000,604,502 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/04/28 23:57:32 | 000,104,170 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/04/28 23:53:36 | 000,000,434 | —- | M] () – C:\Windows\System32\drivers\etc\hosts.ics
[2011/04/28 23:52:49 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/04/28 22:56:24 | 000,000,422 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{A0685C0D-F3D6-46E3-BCD8-ED50FC5E8D7C}.job
[2011/04/24 13:20:15 | 002,883,584 | -HS- | M] () – C:\Users\Nikki\ntuser.bak
[2011/04/24 13:19:20 | 000,000,363 | —- | M] () – C:\Users\Nikki\Desktop\Regfix.reg
[2011/04/24 13:17:43 | 000,000,288 | —- | M] () – C:\Users\Nikki\Desktop\notepad - Shortcut.lnk
[2011/04/24 12:39:21 | 000,000,272 | —- | M] () – C:\Users\Nikki\Desktop\erunt - Shortcut.lnk
[2011/04/24 06:22:50 | 000,000,027 | —- | M] () – C:\Windows\System32\drivers\etc\hosts
[2011/04/24 06:05:47 | 000,000,293 | —- | M] () – C:\Users\Nikki\Desktop\ComboFix - Shortcut.lnk
[2011/04/23 23:24:02 | 000,002,207 | —- | M] () – C:\Users\Nikki\Desktop\Attach.zip
[2011/04/23 23:18:15 | 000,000,272 | —- | M] () – C:\Users\Nikki\Desktop\dds - Shortcut.lnk
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/04/29 07:25:34 | 000,000,917 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/04/28 23:06:39 | 000,001,122 | —- | C] () – C:\Users\Nikki\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
[2011/04/24 13:19:20 | 000,000,363 | —- | C] () – C:\Users\Nikki\Desktop\Regfix.reg
[2011/04/24 13:17:43 | 000,000,288 | —- | C] () – C:\Users\Nikki\Desktop\notepad - Shortcut.lnk
[2011/04/24 12:39:21 | 000,000,272 | —- | C] () – C:\Users\Nikki\Desktop\erunt - Shortcut.lnk
[2011/04/24 06:13:33 | 000,256,512 | —- | C] () – C:\Windows\PEV.exe
[2011/04/24 06:13:33 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2011/04/24 06:13:33 | 000,089,088 | —- | C] () – C:\Windows\MBR.exe
[2011/04/24 06:13:33 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2011/04/24 06:13:33 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2011/04/24 06:05:47 | 000,000,293 | —- | C] () – C:\Users\Nikki\Desktop\ComboFix - Shortcut.lnk
[2011/04/23 23:24:02 | 000,002,207 | —- | C] () – C:\Users\Nikki\Desktop\Attach.zip
[2011/04/23 23:18:15 | 000,000,272 | —- | C] () – C:\Users\Nikki\Desktop\dds - Shortcut.lnk
[2010/07/03 16:54:18 | 000,107,612 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2010/07/03 16:52:31 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | —- | C] () – C:\Windows\System32\OGAEXEC.exe
[2009/03/02 17:15:50 | 000,000,322 | —- | C] () – C:\Users\Nikki\AppData\Roaming\wklnhst.dat
[2009/02/04 07:17:48 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2009/02/03 16:22:36 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2009/02/03 16:11:13 | 000,007,680 | —- | C] () – C:\Users\Nikki\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/02/03 05:39:04 | 000,000,013 | RHS- | C] () – C:\Windows\System32\drivers\fbd.sys
[2009/02/03 05:39:04 | 000,000,004 | RHS- | C] () – C:\Windows\System32\drivers\taishop.sys
[2008/08/27 04:08:53 | 000,128,113 | —- | C] () – C:\Windows\System32\csellang.ini
[2008/08/27 04:08:53 | 000,045,056 | —- | C] () – C:\Windows\System32\csellang.dll
[2008/08/27 04:08:53 | 000,010,150 | —- | C] () – C:\Windows\System32\tosmreg.ini
[2008/08/27 04:08:53 | 000,007,671 | —- | C] () – C:\Windows\System32\cseltbl.ini
[2008/03/05 15:41:58 | 000,024,840 | —- | C] () – C:\Windows\System32\drivers\swmsflt.sys
[2008/02/13 14:15:06 | 000,000,000 | —- | C] () – C:\Windows\NDSTray.INI
[2008/02/12 22:23:20 | 000,204,800 | —- | C] () – C:\Windows\System32\IVIresizeW7.dll
[2008/02/12 22:23:20 | 000,200,704 | —- | C] () – C:\Windows\System32\IVIresizeA6.dll
[2008/02/12 22:23:20 | 000,192,512 | —- | C] () – C:\Windows\System32\IVIresizeP6.dll
[2008/02/12 22:23:20 | 000,192,512 | —- | C] () – C:\Windows\System32\IVIresizeM6.dll
[2008/02/12 22:23:20 | 000,188,416 | —- | C] () – C:\Windows\System32\IVIresizePX.dll
[2008/02/12 22:23:20 | 000,020,480 | —- | C] () – C:\Windows\System32\IVIresize.dll
[2008/02/12 18:28:00 | 000,157,040 | —- | C] () – C:\Windows\fdbpinger.exe
[2008/01/28 21:01:42 | 000,057,344 | —- | C] () – C:\Windows\System32\SmartFaceVCapt.dll
[2008/01/28 21:01:06 | 000,471,040 | —- | C] () – C:\Windows\System32\SmartFaceVCP.dll
[2008/01/28 20:53:02 | 006,701,056 | —- | C] () – C:\Windows\System32\FaceHI.dll
[2008/01/28 20:53:02 | 000,995,328 | —- | C] () – C:\Windows\System32\FaceRec.dll
[2008/01/28 20:53:02 | 000,126,976 | —- | C] () – C:\Windows\System32\SmartFaceVCtrl.dll
[2008/01/28 20:52:28 | 000,094,208 | —- | C] () – C:\Windows\System32\IppLib.dll
[2007/07/28 01:26:30 | 000,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2007/07/28 01:01:12 | 003,107,788 | —- | C] () – C:\Windows\System32\atiumdva.dat
[2007/02/20 18:39:10 | 000,144,773 | —- | C] () – C:\Windows\System32\atiicdxx.dat
[2006/11/02 08:57:28 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 08:47:37 | 000,326,168 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 08:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 06:33:01 | 000,604,502 | —- | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 06:33:01 | 000,287,440 | —- | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 06:33:01 | 000,104,170 | —- | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 06:33:01 | 000,030,674 | —- | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 06:23:21 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2006/11/02 04:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/02 04:19:00 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/02 03:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 03:25:31 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2006/03/09 12:58:00 | 001,060,424 | —- | C] () – C:\Windows\System32\WdfCoInstaller01000.dll

========== LOP Check ==========

[2010/09/30 01:52:58 | 000,000,000 | —D | M] – C:\Users\Nikki\AppData\Roaming\Amazon
[2009/05/27 18:45:42 | 000,000,000 | —D | M] – C:\Users\Nikki\AppData\Roaming\Template
[2009/12/09 17:47:57 | 000,000,000 | —D | M] – C:\Users\Nikki\AppData\Roaming\TOSHIBA
[2009/03/18 15:09:53 | 000,000,000 | —D | M] – C:\Users\Nikki\AppData\Roaming\WildTangent
[2009/02/03 16:15:01 | 000,000,000 | —D | M] – C:\Users\Nikki\AppData\Roaming\WinBatch
[2010/10/30 19:40:34 | 000,000,000 | —D | M] – C:\Users\Nikki\AppData\Roaming\Zeon
[2011/04/28 23:52:01 | 000,032,550 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2011/04/28 22:56:24 | 000,000,422 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{A0685C0D-F3D6-46E3-BCD8-ED50FC5E8D7C}.job

========== Purity Check ==========



< End of report >
OTL Extras logfile created on: 4/29/2011 7:37:09 AM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Nikki\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19019)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 61.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 86.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 231.42 Gb Total Space | 169.25 Gb Free Space | 73.13% Space Free | Partition Type: NTFS

Computer Name: NIKKI-PC | User Name: Nikki | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-3108643506-636927696-2022615235-1000\SOFTWARE\Classes\]
.exe [@ = exefile] – Reg Error: Key error. File not found
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\TOSHIBA\ivp\NetInt\Netint.exe" = C:\TOSHIBA\ivp\NetInt\Netint.exe:*:Enabled:NIE - Toshiba Software Upgrades Engine – (TOSHIBA Corporation)
"C:\TOSHIBA\Ivp\ISM\pinger.exe" = C:\TOSHIBA\Ivp\ISM\pinger.exe:*:Enabled:Toshiba Software Upgrades Pinger – ()


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{008D69EB-70FF-46AB-9C75-924620DF191A}" = TOSHIBA Speech System SR Engine(U.S.) Version1.0
"{03240EBA-04F2-4652-BC7F-B055902BDCD3}" = Memeo AutoBackup
"{062ABD24-47F8-D865-BCB6-A724A94BC9A5}" = CCC Help Japanese
"{06F2B3DC-74F4-300D-D41A-B21B46101CA2}" = Skins
"{0A573F30-FB63-9A85-2E6E-39E1AC5366D0}" = Catalyst Control Center Localization Hungarian
"{0A9F311E-A4B9-4808-1D1C-0B2E7705A735}" = Catalyst Control Center Localization Spanish
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0F15A965-99BA-BC9D-5A00-D7E1E7B2AE7F}" = Catalyst Control Center Localization French
"{12B3A009-A080-4619-9A2A-C6DB151D8D67}" = TOSHIBA Assist
"{14FEF8C7-0EB1-47F2-6A13-D43171D4DFBB}" = Catalyst Control Center Localization Greek
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{1A258E63-8DF5-4ADB-9832-38A0121D65EB}" = AVG 2011
"{1D4D4C5C-6771-A416-0FC9-167F47C4D977}" = Catalyst Control Center Localization Polish
"{1E32C2AB-9722-5F41-7BDE-24B5AFD2BCE6}" = CCC Help Spanish
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{206FD69B-F9FE-4164-81BD-D52552BC9C23}" = GearDrvs
"{21AEC16B-1C21-81B4-DA88-2235CC1F7E39}" = Catalyst Control Center Localization Japanese
"{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Atheros Driver Installation Program
"{288306FF-D5B5-7398-0617-E52F625C6797}" = CCC Help Norwegian
"{2883F6F5-0509-43F3-868C-D50330DD9DD3}" = TOSHIBA Hardware Setup
"{2A981294-F14C-4F0F-9627-D793270922F8}" = Bonjour
"{308B6AEA-DE50-4666-996D-0FA461719D6B}" = Apple Mobile Device Support
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{37C866E4-AA67-4725-9E95-A39968DD7960}" = Camera Assistant Software for Toshiba
"{397AC65E-CB4A-29C2-ACF9-D04444438971}" = Catalyst Control Center Localization Thai
"{3B96A467-811C-F9FE-B8D6-3BC952025F44}" = Catalyst Control Center Localization Dutch
"{3BEEC9AD-FA8F-B413-6BBC-8B5DC7C8E08F}" = Catalyst Control Center Localization Portuguese
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3FBF6F99-8EC6-41B4-8527-0A32241B5496}" = TOSHIBA Speech System TTS Engine(U.S.) Version1.0
"{425A2BC2-AA64-4107-9C29-484245BBEA05}" = TOSHIBA Software Upgrades
"{45ECDC05-71AC-6372-2A17-4139B6296F4F}" = ccc-core-static
"{480C3278-56A7-3F05-3829-6DC5D4B0CB06}" = CCC Help Portuguese
"{4B1E87C3-00DE-4898-8E39-E390AAEF2391}" = TOSHIBA Supervisor Password
"{4CA4D9FC-212C-9F69-E760-DB4BEB34FEB5}" = CCC Help Thai
"{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform
"{4DE0D937-FEB0-0D89-C8D6-35F600300BD4}" = CCC Help French
"{526B6DD3-0C43-2C13-7DF8-44D20D4E9853}" = CCC Help English
"{544587B1-B057-F0B3-7B19-6898ADBED9AC}" = Catalyst Control Center Localization Czech
"{571C0874-A931-EEFE-E89D-8F912F633B9F}" = CCC Help Danish
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5DA0E02F-970B-424B-BF41-513A5018E4C0}" = TOSHIBA Disc Creator
"{5DD4FCBD-A3C1-4155-9E17-4161C70AAABA}" = Segoe UI
"{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center
"{61AD15B2-50DB-4686-A739-14FE180D4429}" = Windows Live ID Sign-in Assistant
"{63427619-C918-6F3C-7318-11DDA4975241}" = ATI Catalyst Install Manager
"{63A6E9A9-A190-46D4-9430-2DB28654AFD8}" = Norton 360
"{648B4A01-F609-1D4E-556C-0F18B54E9E1C}" = Catalyst Control Center Localization Italian
"{64F18837-72CE-DC38-899C-260AF20F979A}" = CCC Help Swedish
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69C82DDB-3FBC-EBEC-AE0A-3ABF1F3BD39B}" = CCC Help Polish
"{6A05FEDF-662E-46BF-8A25-010E3F1C9C69}" = Windows Live UX Platform Language Pack
"{6C530FF7-F6F2-FD4C-0CFC-49AD3E7244A9}" = Catalyst Control Center Localization Turkish
"{6C5F3BDC-0A1B-4436-A696-5939629D5C31}" = TOSHIBA DVD PLAYER
"{6CA2BE46-A562-8CA4-1C33-CC2681B2DDA1}" = CCC Help Finnish
"{6DBBEC03-716B-7954-873A-B782100831C5}" = Catalyst Control Center Graphics Full New
"{70BCBA77-83D9-2075-1F99-69D65C44B422}" = Catalyst Control Center Graphics Full Existing
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{78C6A78A-8B03-48C8-A47C-78BA1FCA2307}" = TOSHIBA ConfigFree
"{78E6BC53-F765-2629-C028-9F3CD49F70D4}" = CCC Help Chinese Standard
"{7ECE1045-66CB-2A70-7EAE-BE508AF95CF2}" = Catalyst Control Center Graphics Previews Vista
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{81F93FA5-BA87-322F-2166-4D1F0FFE196E}" = CCC Help Greek
"{8376FC56-5456-DFF9-5C36-FAB3DE39F5DF}" = Catalyst Control Center Localization Norwegian
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{85B3880D-F0D2-A50C-1464-7EF646A1D21D}" = Catalyst Control Center Localization Danish
"{881F5DE8-9367-4B81-A325-E91BBC6472F9}" = iTunes
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169, 8168, 8101E and 8102E Ethernet Network Card Driver for Windows Vista
"{890EF3F8-742F-46BD-9E8E-084B3A1F4364}" = QuickBooks Financial Center
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8D0957A4-8EE7-E273-0BFC-9B235BEAA41A}" = CCC Help Dutch
"{8D44F868-DA59-B1BF-CC33-58B0AF8E2E39}" = Catalyst Control Center Localization Chinese Traditional
"{8DCE550C-CA43-4E82-92DF-FFC4A48F5BE1}" = Napster Burn Engine
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}_STANDARDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}_STANDARDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_STANDARDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}_STANDARDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}_STANDARDR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}_STANDARDR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}_STANDARDR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}_STANDARDR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}_STANDARDR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0012-0000-0000-0000000FF1CE}" = Microsoft Office Standard 2007
"{91120000-0012-0000-0000-0000000FF1CE}_STANDARDR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0012-0000-0000-0000000FF1CE}_STANDARDR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9A3F65CA-78FA-4749-004B-23743CF642D1}" = Catalyst Control Center Localization Korean
"{9FE35071-CAB2-4E79-93E7-BFC6A2DC5C5D}" = CD/DVD Drive Acoustic Silencer
"{A5B13934-D1C9-D33B-982E-BB09A19C0F90}" = Catalyst Control Center Localization Finnish
"{A60F4402-4CCE-E695-64C6-F0636ACC347F}" = CCC Help Italian
"{A91A0484-8087-A838-9BA6-03374BE3F2CE}" = Catalyst Control Center Localization Russian
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AA725670-A7B4-D1B0-4EF5-F4B2E418C9F4}" = Catalyst Control Center Localization German
"{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.3
"{ADBE6E56-60E7-7FC3-467A-827987BE09CE}" = Catalyst Control Center Localization Swedish
"{B0BCDCBD-863D-4CAB-BF68-8D1F6B1BDC13}" = Atheros Wi-Fi Protected Setup Library
"{B1819DF7-D6B1-27AA-3A3B-6560C348C386}" = Catalyst Control Center Core Implementation
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B5FDA445-CAC4-4BA6-A8FB-A7212BD439DE}" = Microsoft XML Parser
"{B9CD69C2-D14E-C499-C18B-7342E5FE245E}" = Catalyst Control Center Localization Chinese Standard
"{BBBCAE4B-B416-4182-A6F2-438180894A81}" = Napster
"{C53D16CC-E56F-47B8-906E-70AAF8EABB4F}" = Toshiba Registration
"{C730E42C-935A-45BB-A0C5-37E5234D111B}" = TOSHIBA Face Recognition
"{CB84F0F2-927B-458D-9DC5-87832E3DC653}" = GearDrvs
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D58A1E94-9EEA-4C6E-B9FB-D7C63DC6C941}" = Catalyst Control Center - Branding
"{D8F9F4CB-41A1-CF15-39A2-75F28E0B9991}" = CCC Help Korean
"{DC24971E-1946-445D-8A82-CE685433FA7D}" = Realtek USB 2.0 Card Reader
"{DDA258BA-57D9-A76C-84CB-F19571A45FC8}" = ccc-utility
"{DF73BEDD-8A09-A6E2-462B-3BDF398BAFB2}" = CCC Help Czech
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E70A3EE1-067D-8C6C-1C89-9F3A1BA4CF2C}" = Catalyst Control Center Graphics Light
"{E87A8D96-5795-A788-18A2-3BCC20B09E7C}" = CCC Help Chinese Traditional
"{EB295AF7-C2D1-D911-9E62-F288874B96F4}" = CCC Help Turkish
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{EBCD5E4C-F14A-B147-39FE-906F75AC4ACE}" = CCC Help Russian
"{EE033C1F-443E-41EC-A0E2-559B539A4E4D}" = TOSHIBA Speech System Applications
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F214EAA4-A069-4BAF-9DA4-4DB8BEEDE485}" = DVD MovieFactory for TOSHIBA
"{F36D6137-FD4C-1F67-7B2A-815BB05BB825}" = CCC Help German
"{F4F4F84E-804F-4E9A-84D7-C34283F0088F}" = RealUpgrade 1.0
"{F84C1DC6-4B39-1A34-AD6E-A6EE49A3DD78}" = CCC Help Hungarian
"{FC516A10-B335-4FB5-8EA2-0DB8E57E044C}" = Sprint SmartView
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FEDD27A0-B306-45EF-BF58-B527406B42C8}" = TOSHIBA Value Added Package
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"InstallShield_{03240EBA-04F2-4652-BC7F-B055902BDCD3}" = Memeo AutoBackup
"InstallShield_{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center
"InstallShield_{C730E42C-935A-45BB-A0C5-37E5234D111B}" = TOSHIBA Face Recognition
"InstallShield_{FEDD27A0-B306-45EF-BF58-B527406B42C8}" = TOSHIBA Value Added Package
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Mozilla Firefox (3.6.13)" = Mozilla Firefox (3.6.13)
"RealPlayer 12.0" = RealPlayer
"STANDARDR" = Microsoft Office Standard 2007
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"TOSHIBA Software Modem" = TOSHIBA Software Modem
"UnityWebPlayer" = Unity Web Player
"WildTangent toshiba Master Uninstall" = TOSHIBA Games
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"WinLiveSuite" = Windows Live Essentials
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Software Update" = Yahoo! Software Update

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-3108643506-636927696-2022615235-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Amazon Kindle For PC" = Amazon Kindle For PC v1.1

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 11/11/2009 3:08:31 PM | Computer Name = Nikki-PC | Source = WinMgmt | ID = 10
Description =

Error - 11/11/2009 3:12:02 PM | Computer Name = Nikki-PC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 7.0.6001.18319, time stamp
0x4a966702, faulting module unknown, version 0.0.0.0, time stamp 0x00000000, exception
code 0xc0000005, fault offset 0x8bd2abff, process id 0x774, application start time
0x01ca63026716e1cc.

Error - 11/11/2009 9:11:20 PM | Computer Name = Nikki-PC | Source = Application Hang | ID = 1002
Description = The program iexplore.exe version 7.0.6001.18319 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 2450 Start Time: 01ca6330e6a277fc Termination Time: 0

Error - 11/11/2009 9:13:05 PM | Computer Name = Nikki-PC | Source = Application Hang | ID = 1002
Description = The program iexplore.exe version 7.0.6001.18319 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: b14 Start Time: 01ca63350ae5c69c Termination Time: 0

Error - 11/11/2009 11:04:38 PM | Computer Name = Nikki-PC | Source = WinMgmt | ID = 10
Description =

Error - 11/12/2009 9:34:04 AM | Computer Name = Nikki-PC | Source = WinMgmt | ID = 10
Description =

Error - 11/12/2009 10:21:39 AM | Computer Name = Nikki-PC | Source = EventSystem | ID = 4621
Description =

Error - 11/12/2009 12:51:43 PM | Computer Name = Nikki-PC | Source = WinMgmt | ID = 10
Description =

Error - 11/12/2009 1:15:58 PM | Computer Name = Nikki-PC | Source = Application Error | ID = 1000
Description = Faulting application AcroRd32.exe, version 8.1.0.137, time stamp 0x46444e37,
faulting module unknown, version 0.0.0.0, time stamp 0x00000000, exception code
0xc0000005, fault offset 0x3030302e, process id 0x1cc0, application start time 0x01ca63bbc988276c.

Error - 11/12/2009 4:19:50 PM | Computer Name = Nikki-PC | Source = WinMgmt | ID = 10
Description =

[ OSession Events ]
Error - 9/24/2009 7:32:36 PM | Computer Name = Nikki-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6504.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 1
seconds with 0 seconds of active time. This session ended with a crash.

Error - 9/7/2010 10:05:50 AM | Computer Name = Nikki-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6535.5005, Microsoft Office Version: 12.0.6425.1000. This session lasted 81
seconds with 0 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 7/4/2010 3:07:38 AM | Computer Name = Nikki-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 7/4/2010 3:12:31 AM | Computer Name = Nikki-PC | Source = Service Control Manager | ID = 7009
Description =

Error - 7/4/2010 3:12:31 AM | Computer Name = Nikki-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 7/4/2010 3:13:30 AM | Computer Name = Nikki-PC | Source = Service Control Manager | ID = 7009
Description =

Error - 7/4/2010 3:13:30 AM | Computer Name = Nikki-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 7/4/2010 3:13:30 AM | Computer Name = Nikki-PC | Source = Service Control Manager | ID = 7009
Description =

Error - 7/4/2010 3:13:30 AM | Computer Name = Nikki-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 7/4/2010 3:34:05 AM | Computer Name = Nikki-PC | Source = HTTP | ID = 15016
Description =

Error - 7/4/2010 3:34:25 AM | Computer Name = Nikki-PC | Source = Service Control Manager | ID = 7026
Description =

Error - 7/5/2010 1:15:24 PM | Computer Name = Nikki-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 4:43:32 PM on 7/4/2010 was unexpected.


< End of report >
Looks fine malwarewise, the only thing I see wrong is an entry for Symantec, have you tried to uninstall this at one time ? Any browser redirects or unwanted pop up windows ?
i do believe i tryed to uninstall the symantec before, but i kept getting some notice saying it couldnt remove all of it or something. i dont see anything related to it in the uninstall section. i'd love to have it gone if you got any suggestions. i re-installed AVG and updated it. did some browsing and everything seems to be running pretty good. no pop-ups or anything annoying. im still puzzled as to what started all this anyways. i recently got married, and a week before the wedding, i tryed to download a torrent program to get some wedding music, then everything went crazy! for some reason the appearance is still different from the typical vista theme, i never changed it, but it looks like the windows xp theme. not that i care but its just puzzling how that happened. so whats next chief?
i tryed to download a torrent program to get some wedding music,
This was most likely how you got infected, that file your downloading is from an unknown source and malware writers have been in tune this and using File Sharing as a way to infect you. You should stay away from any form of File Sharing, personally I would never allow any programs like these on any of my systems.

Congrats on getting married by the way :) My best wishes to you and your new wife.

You can try running this removal tool from Norton, it will remove whatever the uninstall did not.

Norton Removal Tool
http://service1.symantec.com/SUPPORT/tsgen…005033108162039

I am seeing only one marker in your OTL log for Norton and its running as a service using up system resources, it may have to do with you not able to access the internet previously .

Run the tool , reboot and then run OTL and lets see if its gone
everytime i reboot, im getting a notice from AVG that says a system restart is required in order to continue with the installation. AVG is installed and running correctly, so i dont know what all thats about. heres the new otl log.


OTL logfile created on: 4/29/2011 11:37:29 AM - Run 2
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Nikki\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19019)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 72.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 88.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 231.42 Gb Total Space | 169.29 Gb Free Space | 73.15% Space Free | Partition Type: NTFS

Computer Name: NIKKI-PC | User Name: Nikki | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Program Files\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Users\Nikki\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe (TOSHIBA Corporation)
PRC - C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation)
PRC - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe ()
PRC - C:\TOSHIBA\IVP\ISM\pinger.exe ()
PRC - C:\Windows\System32\agrsmsvc.exe (Agere Systems)
PRC - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)


========== Modules (SafeList) ==========

MOD - C:\Windows\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
MOD - C:\Users\Nikki\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (avg9wd) – C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (SprintRcAppSvc) – C:\Program Files\Sprint\Sprint SmartView\RcAppSvc.exe (PCTEL)
SRV - (CASprint) – C:\Program Files\Sprint\Sprint SmartView\ConAppsSvc.exe (PCTEL)
SRV - (TNaviSrv) – C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe (TOSHIBA Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (TosCoSrv) – C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
SRV - (ConfigFree Service) – C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
SRV - (TOSHIBA SMART Log Service) – C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe (TOSHIBA Corporation)
SRV - (TODDSrv) – C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation)
SRV - (jswpsapi) – C:\Program Files\Jumpstart\jswpsapi.exe (Atheros Communications, Inc.)
SRV - (Swupdtmr) – c:\TOSHIBA\IVP\swupdate\swupdtmr.exe ()
SRV - (GameConsoleService) – C:\Program Files\TOSHIBA Games\TOSHIBA Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (pinger) – C:\TOSHIBA\IVP\ISM\pinger.exe ()
SRV - (AgereModemAudio) – C:\Windows\System32\agrsmsvc.exe (Agere Systems)
SRV - (UleadBurningHelper) – C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)


========== Driver Services (SafeList) ==========

DRV - (AvgTdiX) – C:\Windows\System32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\Windows\System32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\Windows\System32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (SWNC5E00) Sierra Wireless MUX NDIS Driver (#00) – C:\Windows\System32\drivers\SWNC5E00.sys (Sierra Wireless Inc.)
DRV - (swmx00) Sierra Wireless USB MUX Driver (#00) – C:\Windows\System32\drivers\swmx00.sys (Sierra Wireless Inc.)
DRV - (swmsflt) – C:\Windows\System32\drivers\swmsflt.sys ()
DRV - (Nmea) – C:\Windows\System32\drivers\pctnullport.sys (PCTEL Inc.)
DRV - (PCTINDIS5) – C:\Windows\System32\PCTINDIS5.sys (PCTEL Inc.)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (tos_sps32) – C:\Windows\system32\DRIVERS\tos_sps32.sys (TOSHIBA Corporation)
DRV - (RTL8169) – C:\Windows\System32\drivers\Rtlh86.sys (Realtek Corporation )
DRV - (UVCFTR) – C:\Windows\System32\drivers\UVCFTR_S.SYS (Chicony Electronics Co., Ltd.)
DRV - (TVALZ) – C:\Windows\system32\DRIVERS\TVALZ_O.SYS (TOSHIBA Corporation)
DRV - (PCASp50) – C:\Windows\System32\drivers\PCASp50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (NWADI) – C:\Windows\System32\drivers\NWADIenum.sys (Novatel Wireless Inc)
DRV - (jswpslwf) – C:\Windows\System32\drivers\jswpslwf.sys (Atheros Communications, Inc.)
DRV - (atikmdag) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (AgereSoftModem) – C:\Windows\System32\drivers\AGRSM.sys (Agere Systems)
DRV - (FwLnk) – C:\Windows\System32\drivers\FwLnk.sys (TOSHIBA Corporation)
DRV - (KR10I) – C:\Windows\system32\drivers\kr10i.sys (TOSHIBA CORPORATION)
DRV - (KR10N) – C:\Windows\system32\drivers\kr10n.sys (TOSHIBA CORPORATION)
DRV - (AtiPcie) ATI PCI Express (3GIO) – C:\Windows\system32\DRIVERS\AtiPcie.sys (ATI Technologies Inc.)
DRV - (tdcmdpst) – C:\Windows\System32\drivers\tdcmdpst.sys (TOSHIBA Corporation.)
DRV - (Cdralw2k) – C:\Windows\System32\drivers\cdralw2k.sys (Sonic Solutions)
DRV - (Cdr4_xp) – C:\Windows\System32\drivers\cdr4_xp.sys (Sonic Solutions)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-3108643506-636927696-2022615235-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?ilc=1
IE - HKU\S-1-5-21-3108643506-636927696-2022615235-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3108643506-636927696-2022615235-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com/?ilc=1"
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.872
FF - prefs.js..network.proxy.type: 0


FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox [2011/04/29 09:47:06 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/12/22 22:29:36 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/02/19 14:34:52 | 000,000,000 | —D | M]

[2010/07/11 03:31:02 | 000,000,000 | —D | M] (No name found) – C:\Users\Nikki\AppData\Roaming\Mozilla\Extensions
[2011/04/29 10:04:07 | 000,000,000 | —D | M] (No name found) – C:\Users\Nikki\AppData\Roaming\Mozilla\Firefox\Profiles\k4l2ljw5.default\extensions
[2010/08/11 02:37:37 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Nikki\AppData\Roaming\Mozilla\Firefox\Profiles\k4l2ljw5.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/07/11 03:29:26 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/04/29 09:47:06 | 000,000,000 | —D | M] (AVG Safe Search) – C:\PROGRAM FILES\AVG\AVG9\FIREFOX

O1 HOSTS File: ([2011/04/24 06:22:50 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [00TCrdMain] C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [MFARestart] C:\ProgramData\MFAData\pack\avgrunasx.exe ()
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Sprint SmartView] C:\Program Files\Sprint\Sprint SmartView\SprintSV.exe (Sprint)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\RunOnce: [AvgUninstallURL] C:\Windows\System32\cmd.exe (Microsoft Corporation)
O4 - Startup: C:\Users\Nikki\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Sticky Notes.lnk = C:\Windows\System32\StikyNot.exe (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-21-3108643506-636927696-2022615235-1000\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-21-3108643506-636927696-2022615235-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll (Sun Microsystems, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - AppInit_DLLs: (avgrsstx.dll) - C:\Windows\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 17:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKU\S-1-5-21-3108643506-636927696-2022615235-1000\…exe [@ = exefile] – Reg Error: Key error. File not found

========== Files/Folders - Created Within 30 Days ==========

[2011/04/29 09:49:20 | 000,000,000 | -H-D | C] – C:\ProgramData\Common Files
[2011/04/29 09:49:19 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG Free 9.0
[2011/04/29 09:49:17 | 000,012,536 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\avgrsstx.dll
[2011/04/29 09:49:15 | 000,243,024 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgtdix.sys
[2011/04/29 09:49:05 | 000,216,400 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgldx86.sys
[2011/04/29 09:49:02 | 000,029,584 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgmfx86.sys
[2011/04/29 09:49:01 | 000,000,000 | —D | C] – C:\Windows\System32\drivers\Avg
[2011/04/29 07:35:27 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Users\Nikki\Desktop\OTL.exe
[2011/04/29 07:25:33 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2011/04/29 07:25:33 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/04/29 07:25:30 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2011/04/29 07:25:30 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/04/29 07:24:36 | 007,734,208 | —- | C] (Malwarebytes Corporation ) – C:\Users\Nikki\Desktop\mbam-setup-1.50.1.1100.exe
[2011/04/29 07:22:22 | 000,050,688 | —- | C] (Atribune.org) – C:\Users\Nikki\Desktop\ATF-Cleaner.exe
[2011/04/24 13:07:07 | 000,000,000 | —D | C] – C:\Users\Nikki\Documents\LOC_GER
[2011/04/24 06:24:45 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2011/04/24 06:24:43 | 000,000,000 | —D | C] – C:\Windows\temp
[2011/04/24 06:24:42 | 000,000,000 | —D | C] – C:\Users\Nikki\AppData\Local\temp
[2011/04/24 06:13:33 | 000,161,792 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2011/04/24 06:13:33 | 000,136,704 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2011/04/24 06:13:33 | 000,031,232 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2011/04/24 06:13:25 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2011/04/24 06:13:04 | 000,212,480 | —- | C] (SteelWerX) – C:\Windows\SWXCACLS.exe
[2011/04/24 06:07:24 | 000,000,000 | —D | C] – C:\Qoobox
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/04/29 11:41:11 | 000,604,502 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/04/29 11:41:11 | 000,104,170 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/04/29 11:35:26 | 000,000,434 | —- | M] () – C:\Windows\System32\drivers\etc\hosts.ics
[2011/04/29 11:35:09 | 000,003,744 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/04/29 11:35:09 | 000,003,744 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/04/29 11:35:02 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/04/29 11:29:43 | 000,932,400 | —- | M] () – C:\Users\Nikki\Desktop\Norton_Removal_Tool.exe
[2011/04/29 09:49:19 | 000,012,536 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\avgrsstx.dll
[2011/04/29 09:49:19 | 000,001,658 | —- | M] () – C:\Users\Public\Desktop\AVG Free 9.0.lnk
[2011/04/29 09:49:17 | 000,243,024 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgtdix.sys
[2011/04/29 09:49:05 | 000,216,400 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgldx86.sys
[2011/04/29 09:49:04 | 000,029,584 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgmfx86.sys
[2011/04/29 09:49:02 | 075,311,071 | —- | M] () – C:\Windows\System32\drivers\Avg\incavi.avm
[2011/04/29 09:49:02 | 000,113,461 | —- | M] () – C:\Windows\System32\drivers\Avg\iavichjw.avm
[2011/04/29 07:35:28 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Users\Nikki\Desktop\OTL.exe
[2011/04/29 07:25:34 | 000,000,917 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/04/29 07:24:44 | 007,734,208 | —- | M] (Malwarebytes Corporation ) – C:\Users\Nikki\Desktop\mbam-setup-1.50.1.1100.exe
[2011/04/29 07:22:36 | 000,050,688 | —- | M] (Atribune.org) – C:\Users\Nikki\Desktop\ATF-Cleaner.exe
[2011/04/28 22:56:24 | 000,000,422 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{A0685C0D-F3D6-46E3-BCD8-ED50FC5E8D7C}.job
[2011/04/24 13:20:15 | 002,883,584 | -HS- | M] () – C:\Users\Nikki\ntuser.bak
[2011/04/24 13:19:20 | 000,000,363 | —- | M] () – C:\Users\Nikki\Desktop\Regfix.reg
[2011/04/24 13:17:43 | 000,000,288 | —- | M] () – C:\Users\Nikki\Desktop\notepad - Shortcut.lnk
[2011/04/24 12:39:21 | 000,000,272 | —- | M] () – C:\Users\Nikki\Desktop\erunt - Shortcut.lnk
[2011/04/24 06:22:50 | 000,000,027 | —- | M] () – C:\Windows\System32\drivers\etc\hosts
[2011/04/24 06:05:47 | 000,000,293 | —- | M] () – C:\Users\Nikki\Desktop\ComboFix - Shortcut.lnk
[2011/04/23 23:24:02 | 000,002,207 | —- | M] () – C:\Users\Nikki\Desktop\Attach.zip
[2011/04/23 23:18:15 | 000,000,272 | —- | M] () – C:\Users\Nikki\Desktop\dds - Shortcut.lnk
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/04/29 11:29:40 | 000,932,400 | —- | C] () – C:\Users\Nikki\Desktop\Norton_Removal_Tool.exe
[2011/04/29 09:49:19 | 000,001,658 | —- | C] () – C:\Users\Public\Desktop\AVG Free 9.0.lnk
[2011/04/29 09:49:02 | 000,113,461 | —- | C] () – C:\Windows\System32\drivers\Avg\iavichjw.avm
[2011/04/29 09:49:01 | 075,311,071 | —- | C] () – C:\Windows\System32\drivers\Avg\incavi.avm
[2011/04/29 07:25:34 | 000,000,917 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/04/28 23:06:39 | 000,001,122 | —- | C] () – C:\Users\Nikki\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
[2011/04/24 13:19:20 | 000,000,363 | —- | C] () – C:\Users\Nikki\Desktop\Regfix.reg
[2011/04/24 13:17:43 | 000,000,288 | —- | C] () – C:\Users\Nikki\Desktop\notepad - Shortcut.lnk
[2011/04/24 12:39:21 | 000,000,272 | —- | C] () – C:\Users\Nikki\Desktop\erunt - Shortcut.lnk
[2011/04/24 06:13:33 | 000,256,512 | —- | C] () – C:\Windows\PEV.exe
[2011/04/24 06:13:33 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2011/04/24 06:13:33 | 000,089,088 | —- | C] () – C:\Windows\MBR.exe
[2011/04/24 06:13:33 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2011/04/24 06:13:33 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2011/04/24 06:05:47 | 000,000,293 | —- | C] () – C:\Users\Nikki\Desktop\ComboFix - Shortcut.lnk
[2011/04/23 23:24:02 | 000,002,207 | —- | C] () – C:\Users\Nikki\Desktop\Attach.zip
[2011/04/23 23:18:15 | 000,000,272 | —- | C] () – C:\Users\Nikki\Desktop\dds - Shortcut.lnk
[2010/07/03 16:54:18 | 000,107,612 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2010/07/03 16:52:31 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | —- | C] () – C:\Windows\System32\OGAEXEC.exe
[2009/03/02 17:15:50 | 000,000,322 | —- | C] () – C:\Users\Nikki\AppData\Roaming\wklnhst.dat
[2009/02/04 07:17:48 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2009/02/03 16:22:36 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2009/02/03 16:11:13 | 000,007,680 | —- | C] () – C:\Users\Nikki\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/02/03 05:39:04 | 000,000,013 | RHS- | C] () – C:\Windows\System32\drivers\fbd.sys
[2009/02/03 05:39:04 | 000,000,004 | RHS- | C] () – C:\Windows\System32\drivers\taishop.sys
[2008/08/27 04:08:53 | 000,128,113 | —- | C] () – C:\Windows\System32\csellang.ini
[2008/08/27 04:08:53 | 000,045,056 | —- | C] () – C:\Windows\System32\csellang.dll
[2008/08/27 04:08:53 | 000,010,150 | —- | C] () – C:\Windows\System32\tosmreg.ini
[2008/08/27 04:08:53 | 000,007,671 | —- | C] () – C:\Windows\System32\cseltbl.ini
[2008/03/05 15:41:58 | 000,024,840 | —- | C] () – C:\Windows\System32\drivers\swmsflt.sys
[2008/02/13 14:15:06 | 000,000,000 | —- | C] () – C:\Windows\NDSTray.INI
[2008/02/12 22:23:20 | 000,204,800 | —- | C] () – C:\Windows\System32\IVIresizeW7.dll
[2008/02/12 22:23:20 | 000,200,704 | —- | C] () – C:\Windows\System32\IVIresizeA6.dll
[2008/02/12 22:23:20 | 000,192,512 | —- | C] () – C:\Windows\System32\IVIresizeP6.dll
[2008/02/12 22:23:20 | 000,192,512 | —- | C] () – C:\Windows\System32\IVIresizeM6.dll
[2008/02/12 22:23:20 | 000,188,416 | —- | C] () – C:\Windows\System32\IVIresizePX.dll
[2008/02/12 22:23:20 | 000,020,480 | —- | C] () – C:\Windows\System32\IVIresize.dll
[2008/02/12 18:28:00 | 000,157,040 | —- | C] () – C:\Windows\fdbpinger.exe
[2008/01/28 21:01:42 | 000,057,344 | —- | C] () – C:\Windows\System32\SmartFaceVCapt.dll
[2008/01/28 21:01:06 | 000,471,040 | —- | C] () – C:\Windows\System32\SmartFaceVCP.dll
[2008/01/28 20:53:02 | 006,701,056 | —- | C] () – C:\Windows\System32\FaceHI.dll
[2008/01/28 20:53:02 | 000,995,328 | —- | C] () – C:\Windows\System32\FaceRec.dll
[2008/01/28 20:53:02 | 000,126,976 | —- | C] () – C:\Windows\System32\SmartFaceVCtrl.dll
[2008/01/28 20:52:28 | 000,094,208 | —- | C] () – C:\Windows\System32\IppLib.dll
[2007/07/28 01:26:30 | 000,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2007/07/28 01:01:12 | 003,107,788 | —- | C] () – C:\Windows\System32\atiumdva.dat
[2007/02/20 18:39:10 | 000,144,773 | —- | C] () – C:\Windows\System32\atiicdxx.dat
[2006/11/02 08:57:28 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 08:47:37 | 000,326,168 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 08:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 06:33:01 | 000,604,502 | —- | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 06:33:01 | 000,287,440 | —- | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 06:33:01 | 000,104,170 | —- | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 06:33:01 | 000,030,674 | —- | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 06:23:21 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2006/11/02 04:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/02 04:19:00 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/02 03:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 03:25:31 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat

========== LOP Check ==========

[2010/09/30 01:52:58 | 000,000,000 | —D | M] – C:\Users\Nikki\AppData\Roaming\Amazon
[2009/05/27 18:45:42 | 000,000,000 | —D | M] – C:\Users\Nikki\AppData\Roaming\Template
[2009/12/09 17:47:57 | 000,000,000 | —D | M] – C:\Users\Nikki\AppData\Roaming\TOSHIBA
[2009/03/18 15:09:53 | 000,000,000 | —D | M] – C:\Users\Nikki\AppData\Roaming\WildTangent
[2009/02/03 16:15:01 | 000,000,000 | —D | M] – C:\Users\Nikki\AppData\Roaming\WinBatch
[2010/10/30 19:40:34 | 000,000,000 | —D | M] – C:\Users\Nikki\AppData\Roaming\Zeon
[2011/04/29 11:33:52 | 000,032,550 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2011/04/28 22:56:24 | 000,000,422 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{A0685C0D-F3D6-46E3-BCD8-ED50FC5E8D7C}.job

========== Purity Check ==========



< End of report >
Looks like you ran the tool, the norton service is gone. Try uninstalling AVG and then reinstall it. I am not really fond of this program, appears to be one problem after another
do you have a better free anti-virus program that you recommend? you the expert here so im open to something new if it will protect my computer better…
i uninstalled AVG, then on reboot, surprise! i got the reboot error notice from AVG again. plus i still have AVG shortcuts on my desktop. is there an AVG removal tool like the one you gave me for norton?
That did the trick. everything seems to be good to go now. my wife hasnt had any compliants about its performance… imagine that;) do we need to run anything else?
Looks like your good to go :)

Open OTL and click on Clean Up and it will remove programs we used to clean your system along with there backups


  • How did I get infected in the first place ?
    Read these links and find out how to prevent getting infected again.
  • Tutorial for System Restore <– Do this first to prevent yourself from being reinfected.
  • WhattheTech
  • Grinler BleepingComputer
  • GeeksTo Go
  • Dslreports





Safe Surfn
Ken
i cant thank you enough ken. i will definatly show my appreciation and donate to the site. many of you have been very helpful over the years, and i will always come back here for help with my computer issues. thank you once again! Tony

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI