This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

winlogon.exe problem and svhost.exe

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello guys,
I have a problem with my laptop. My problem is my laptop has been running so slow. It started when i downloaded some files in youtube, i dont have antivirus installed in my laptop during my download so i dont know whats happening. I just realized i have a virus already because of my computer become slow. My friend send me a antivirus name symantec. When i installed it, i found that all the files i downloaded from youtube were all viruses. during the scan i saw winlogon.exe, which i doesnt downloaded. I click to clean it then my window become blue and has a long message.. After the restart i press to clean the viruses found by symantec but it says its already missing.. and i look at the location, and its really gone. i thought my laptop is good now. But today i saw 2 winlogon.exe in my task manager and the description is oifkfn. So i think this is very suspicious. I need your help guys. Because my laptop is running very slow. The memory is already in full, but only the firefox only opened. If I close the firefox its half, and when i shut down our laptop an error occur. I remember it says " svhost.exe couldn't start successfuly and it has a 0xc000… something.. please guys help me.

i did the step 1 and step 2 in Are you Infected? Need Help?


*FROM OTL


OTL logfile created on: 6/11/2011 6:48:54 PM - Run 1
OTL by OldTimer - Version 3.2.24.0 Folder = C:\Users\Annabel\Desktop
Starter Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1013.42 Mb Total Physical Memory | 96.82 Mb Available Physical Memory | 9.55% Memory free
1.99 Gb Paging File | 1.08 Gb Available in Paging File | 54.26% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 223.23 Gb Total Space | 195.67 Gb Free Space | 87.65% Space Free | Partition Type: NTFS

Computer Name: ANNABEL-PC | User Name: Annabel | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Annabel\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Users\Annabel\AppData\Roaming\winlogon.exe (jv)
PRC - C:\Program Files\Registry Clean Expert\RCHelper.exe (iExpert Software)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\TOSHIBA\TECO\TecoService.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\TECO\Teco.exe (TOSHIBA Corporation)
PRC - C:\Program Files\Realtek\Audio\HDA\RtHDVBg.exe (Realtek Semiconductor)
PRC - C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\Utilities\KeNotify.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe (Realsil Microelectronics Inc.)
PRC - C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe (TOSHIBA Corporation)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation)
PRC - C:\Users\Annabel\AppData\Local\Temp\svhost.exe (Microsoft Corporation)
PRC - C:\Program Files\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)


========== Modules (SafeList) ==========

MOD - C:\Users\Annabel\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (TOSHIBA eco Utility Service) – C:\Program Files\TOSHIBA\TECO\TecoService.exe (TOSHIBA Corporation)
SRV - (TODDSrv) – C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation)
SRV - (TosCoSrv) – C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
SRV - (IconMan_R) – C:\Program Files\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe (Realsil Microelectronics Inc.)
SRV - (TOSHIBA HDD SSD Alert Service) – C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe (TOSHIBA Corporation)
SRV - (TMachInfo) – C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe (TOSHIBA Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (SavRoam) – C:\Program Files\Symantec AntiVirus\SavRoam.exe (symantec)
SRV - (Symantec AntiVirus) – C:\Program Files\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
SRV - (DefWatch) – C:\Program Files\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
SRV - (ccSetMgr) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccEvtMgr) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (LiveUpdate) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_2.EXE (Symantec Corporation)


========== Driver Services (SafeList) ==========

DRV - (NAVEX15) – C:\ProgramData\Symantec\Definitions\VirusDefs\20110611.006\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Symantec\Definitions\VirusDefs\20110611.006\NAVENG.SYS (Symantec Corporation)
DRV - (SymEvent) – C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (RTL8192Ce) – C:\Windows\System32\drivers\rtl8192ce.sys (Realtek Semiconductor Corporation )
DRV - (RSUSBSTOR) – C:\Windows\System32\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV - (LPCFilter) – C:\windows\system32\DRIVERS\LPCFilter.sys (COMPAL ELECTRONIC INC.)
DRV - (tdcmdpst) – C:\Windows\System32\drivers\tdcmdpst.sys (TOSHIBA Corporation.)
DRV - (TVALZ) – C:\windows\system32\DRIVERS\TVALZ_O.SYS (TOSHIBA Corporation)
DRV - (PGEffect) – C:\Windows\System32\drivers\PGEffect.sys (TOSHIBA Corporation)
DRV - (SRTSPL) – C:\Windows\System32\drivers\srtspl.sys (Symantec Corporation)
DRV - (SRTSP) – C:\Windows\System32\drivers\srtsp.sys (Symantec Corporation)
DRV - (SRTSPX) – C:\Windows\System32\drivers\srtspx.sys (Symantec Corporation)
DRV - (SYMTDI) – C:\windows\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (SYMREDRV) – C:\windows\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (SPBBCDrv) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://start.toshiba.com/g/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.jzip.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =

========== FireFox ==========

FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "www.google.com"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.8
FF - prefs.js..extensions.enabledItems: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.1.94
FF - prefs.js..extensions.enabledItems: {6904342A-8307-11DF-A508-4AE2DFD72085}:2.1.1.94
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.9.5
FF - prefs.js..keyword.URL: "http://search.jzip.com/web?src=ffb&systemid;=102&q;="

FF - HKLM\software\mozilla\Firefox\extensions\\{22C7F6C6-8D67-4534-92B5-529A0EC09405}: C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1464\6.6.1079\firefoxextension\
FF - HKLM\software\mozilla\Firefox\extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\html5video [2011/05/16 15:25:33 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files\DivX\DivX Plus Web Player\firefox\wpa [2011/05/16 15:25:34 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/06/05 16:58:05 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/06/09 21:27:21 | 000,000,000 | —D | M]

[2011/06/04 23:17:03 | 000,000,000 | —D | M] (No name found) – C:\Users\Annabel\AppData\Roaming\Mozilla\Extensions
[2011/06/04 22:07:45 | 000,000,000 | —D | M] (No name found) – C:\Users\Annabel\AppData\Roaming\Mozilla\Firefox\Profiles\m6zbg2yl.default\extensions
[2011/06/04 22:06:26 | 000,000,000 | —D | M] (Adblock Plus) – C:\Users\Annabel\AppData\Roaming\Mozilla\Firefox\Profiles\m6zbg2yl.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2011/06/04 22:06:26 | 000,000,000 | —D | M] (Greasemonkey) – C:\Users\Annabel\AppData\Roaming\Mozilla\Firefox\Profiles\m6zbg2yl.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2011/06/08 18:55:46 | 000,001,018 | —- | M] () – C:\Users\Annabel\AppData\Roaming\Mozilla\Firefox\Profiles\m6zbg2yl.default\searchplugins\facebook.xml
[2011/03/15 04:08:57 | 000,005,536 | —- | M] () – C:\Users\Annabel\AppData\Roaming\Mozilla\Firefox\Profiles\m6zbg2yl.default\searchplugins\jZipWebSearch.xml
[2011/03/28 17:15:49 | 000,002,057 | —- | M] () – C:\Users\Annabel\AppData\Roaming\Mozilla\Firefox\Profiles\m6zbg2yl.default\searchplugins\youtube-video-search.xml
[2011/06/09 21:27:26 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/06/09 21:27:27 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
File not found (No name found) –
[2011/04/14 12:26:02 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2011/05/04 04:52:23 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/01/01 04:00:00 | 000,002,252 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\bing.xml
[2011/03/15 04:08:57 | 000,005,536 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\jZipWebSearch.xml

O1 HOSTS File: ([2009/06/10 17:39:37 | 000,000,824 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (no name) - {1CA1377B-DC1D-4A52-9585-6E06050FAC53} - No CLSID value found.
O2 - BHO: (DivX Plus Web Player HTML5 ) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll (Google Inc.)
O2 - BHO: (no name) - {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [00TCrdMain] C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [HWSetup] C:\Program Files\TOSHIBA\Utilities\HWSetup.exe (TOSHIBA Electronics, Inc.)
O4 - HKLM..\Run: [KeNotify] C:\Program Files\TOSHIBA\Utilities\KeNotify.exe (TOSHIBA CORPORATION)
O4 - HKLM..\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RtHDVBg.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SmoothView] C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [SVPWUTIL] C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe (TOSHIBA CORPORATION)
O4 - HKLM..\Run: [Teco] C:\Program Files\TOSHIBA\TECO\Teco.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [ToshibaAppPlace] C:\Program Files\Toshiba\Toshiba App Place\ToshibaAppPlace.exe (Toshiba)
O4 - HKLM..\Run: [ToshibaServiceStation] C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TosNC] C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TosReelTimeMonitor] C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TosSENotify] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TosVolRegulator] C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TPwrMain] C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TWebCamera] C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe (TOSHIBA CORPORATION.)
O4 - HKLM..\Run: [vptray] C:\Program Files\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
O4 - HKCU..\Run: [Critical Core] C:\Users\Annabel\AppData\Roaming\winlogon.exe (jv)
O4 - HKCU..\Run: [HKCU] C:\Users\Annabel\AppData\Roaming\winlog\ctfmon.exe (Microsoft Corporation)
O4 - HKCU..\Run: [RegClean Expert Scheduler] C:\Program Files\Registry Clean Expert\RCHelper.exe (iExpert Software)
O4 - HKCU..\Run: [rundll32] File not found
O4 - Startup: C:\Users\Annabel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\rundll32.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll (Google Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 [removed] [removed]
O18 - Protocol\Handler\tmbp {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - Reg Error: Key error. File not found
O18 - Protocol\Handler\tmpx {0E526CB5-7446-41D1-A403-19BFE95E8C23} - Reg Error: Key error. File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 17:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\windows\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.yv12 - C:\windows\System32\DivX.dll (DivX, Inc.)


========== Files/Folders - Created Within 30 Days ==========

[2011/06/11 18:41:37 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Users\Annabel\Desktop\OTL.exe
[2011/06/09 21:27:42 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2011/06/09 21:27:21 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\windows\System32\javaws.exe
[2011/06/09 21:27:21 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\windows\System32\javaw.exe
[2011/06/09 21:27:21 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\windows\System32\java.exe
[2011/06/04 23:45:31 | 000,000,000 | —D | C] – C:\windows\Minidump
[2011/06/04 23:28:37 | 000,000,000 | —D | C] – C:\Users\Annabel\AppData\Local\Symantec
[2011/06/04 23:27:21 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Symantec Client Security
[2011/06/04 23:27:19 | 000,109,744 | —- | C] (Symantec Corporation) – C:\windows\System32\drivers\SYMEVENT.SYS
[2011/06/04 23:25:54 | 000,466,944 | —- | C] (Microsoft Corporation) – C:\windows\System32\capicom.dll
[2011/06/04 23:25:52 | 000,000,000 | —D | C] – C:\Program Files\Symantec
[2011/06/04 23:25:38 | 000,000,000 | —D | C] – C:\Program Files\Symantec AntiVirus
[2011/06/04 20:19:53 | 000,000,000 | —D | C] – C:\Users\Annabel\AppData\Roaming\iExpert Software
[2011/06/04 20:19:43 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Registry Clean Expert
[2011/06/04 20:19:41 | 000,000,000 | —D | C] – C:\Program Files\Registry Clean Expert
[2011/06/04 17:12:59 | 000,274,432 | RHS- | C] (jv) – C:\Users\Annabel\AppData\Roaming\winlogon.exe
[2011/05/25 19:45:41 | 000,000,000 | —D | C] – C:\Users\Annabel\AppData\Roaming\Registry Mechanic
[2011/05/25 06:58:36 | 000,026,496 | —- | C] (Microsoft Corporation) – C:\windows\System32\drivers\Diskdump.sys
[2011/05/24 02:27:06 | 000,123,904 | —- | C] (Microsoft Corporation) – C:\windows\System32\poqexec.exe
[2011/05/22 18:42:29 | 000,000,000 | —D | C] – C:\Users\Annabel\AppData\Local\DDMSettings
[2011/05/18 22:41:00 | 000,404,640 | —- | C] (Adobe Systems Incorporated) – C:\windows\System32\FlashPlayerCPLApp.cpl
[2011/05/16 18:23:38 | 000,000,000 | —D | C] – C:\ProgramData\TEMP
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]
[1 C:\Users\Annabel\AppData\Local\*.tmp files -> C:\Users\Annabel\AppData\Local\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/06/11 18:58:04 | 000,000,900 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/06/11 18:45:16 | 000,014,304 | -H– | M] () – C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/06/11 18:45:16 | 000,014,304 | -H– | M] () – C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/06/11 18:42:03 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Users\Annabel\Desktop\OTL.exe
[2011/06/11 18:36:49 | 000,000,896 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/06/11 18:36:22 | 000,067,584 | –S- | M] () – C:\windows\bootstat.dat
[2011/06/11 18:35:50 | 796,987,392 | -HS- | M] () – C:\hiberfil.sys
[2011/06/10 23:07:12 | 000,000,444 | -H– | M] () – C:\windows\tasks\Norton Security Scan for Annabel.job
[2011/06/09 04:13:17 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\windows\System32\FlashPlayerCPLApp.cpl
[2011/06/05 21:46:41 | 001,646,568 | —- | M] () – C:\windows\System32\perfh009.dat
[2011/06/05 21:46:41 | 000,460,814 | —- | M] () – C:\windows\System32\perfc009.dat
[2011/06/05 16:58:08 | 000,002,009 | —- | M] () – C:\Users\Annabel\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/06/05 16:58:08 | 000,001,107 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/06/04 23:27:42 | 000,109,744 | —- | M] (Symantec Corporation) – C:\windows\System32\drivers\SYMEVENT.SYS
[2011/06/04 23:27:42 | 000,008,014 | —- | M] () – C:\windows\System32\drivers\SYMEVENT.CAT
[2011/06/04 23:27:42 | 000,000,805 | —- | M] () – C:\windows\System32\drivers\SYMEVENT.INF
[2011/06/04 20:26:26 | 009,412,735 | —- | M] () – C:\Users\Annabel\Documents\registryclean.cab
[2011/06/04 20:19:43 | 000,000,989 | —- | M] () – C:\Users\Annabel\Desktop\Registry Clean Expert.lnk
[2011/06/04 19:30:32 | 000,065,536 | —- | M] () – C:\Users\Annabel\AppData\Roaming\chrtmp
[2011/06/04 17:14:38 | 000,011,729 | -H– | M] () – C:\Users\Annabel\AppData\Roaming\Annabellog.dat
[2011/06/04 16:37:34 | 000,058,158 | —- | M] () – C:\Users\Annabel\AppData\Roaming\Annabel3SQLite3.dll
[2011/06/01 02:21:53 | 000,274,432 | RHS- | M] (jv) – C:\Users\Annabel\AppData\Roaming\winlogon.exe
[2011/05/25 22:53:25 | 000,054,951 | —- | M] () – C:\Users\Annabel\Desktop\RESUME for Teaching.rtf
[2011/05/22 20:25:10 | 000,000,976 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]
[1 C:\Users\Annabel\AppData\Local\*.tmp files -> C:\Users\Annabel\AppData\Local\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/06/04 23:27:19 | 000,008,014 | —- | C] () – C:\windows\System32\drivers\SYMEVENT.CAT
[2011/06/04 23:27:19 | 000,000,805 | —- | C] () – C:\windows\System32\drivers\SYMEVENT.INF
[2011/06/04 22:04:07 | 000,002,009 | —- | C] () – C:\Users\Annabel\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/06/04 20:53:33 | 000,001,119 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2011/06/04 20:53:33 | 000,001,107 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/06/04 20:26:26 | 009,412,735 | —- | C] () – C:\Users\Annabel\Documents\registryclean.cab
[2011/06/04 20:19:43 | 000,000,989 | —- | C] () – C:\Users\Annabel\Desktop\Registry Clean Expert.lnk
[2011/06/04 20:05:19 | 002,240,512 | —- | C] () – C:\Users\Annabel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\rundll32.exe
[2011/06/04 19:31:51 | 000,065,536 | —- | C] () – C:\Users\Annabel\AppData\Roaming\chrtmp
[2011/06/04 16:37:34 | 000,058,158 | —- | C] () – C:\Users\Annabel\AppData\Roaming\Annabel3SQLite3.dll
[2011/05/25 22:53:24 | 000,054,951 | —- | C] () – C:\Users\Annabel\Desktop\RESUME for Teaching.rtf
[2011/04/26 14:23:39 | 000,000,000 | —- | C] () – C:\Users\Annabel\AppData\Local\{8EBAE3F7-EA7B-4775-8283-60355C2B0EBA}
[2011/03/06 20:16:16 | 000,000,013 | RHS- | C] () – C:\windows\System32\drivers\fbd.sys
[2010/12/21 05:39:51 | 000,080,416 | —- | C] () – C:\windows\System32\RtNicProp32.dll
[2010/12/21 05:37:19 | 000,451,072 | —- | C] () – C:\windows\System32\ISSRemoveSP.exe
[2010/12/21 05:34:34 | 000,000,852 | —- | C] () – C:\windows\System32\drivers\RTKHDRC1.dat
[2010/12/21 05:34:34 | 000,000,852 | —- | C] () – C:\windows\System32\drivers\RTKHDRC0.dat
[2010/12/21 05:34:34 | 000,000,712 | —- | C] () – C:\windows\System32\drivers\RTEQEX1.dat
[2010/12/21 05:34:34 | 000,000,712 | —- | C] () – C:\windows\System32\drivers\RTEQEX0.dat
[2010/12/21 05:29:44 | 000,045,056 | —- | C] () – C:\windows\System32\HWS_Ctrl.dll
[2010/03/04 02:36:32 | 000,028,672 | —- | C] () – C:\windows\System32\SPCtl.dll
[2009/07/14 00:57:37 | 000,067,584 | –S- | C] () – C:\windows\bootstat.dat
[2009/07/14 00:33:53 | 000,297,104 | —- | C] () – C:\windows\System32\FNTCACHE.DAT
[2009/07/13 22:05:48 | 001,646,568 | —- | C] () – C:\windows\System32\perfh009.dat
[2009/07/13 22:05:48 | 000,460,814 | —- | C] () – C:\windows\System32\perfc009.dat
[2009/07/13 22:05:48 | 000,291,294 | —- | C] () – C:\windows\System32\perfi009.dat
[2009/07/13 22:05:48 | 000,031,548 | —- | C] () – C:\windows\System32\perfd009.dat
[2009/07/13 22:05:05 | 000,000,741 | —- | C] () – C:\windows\System32\NOISE.DAT
[2009/07/13 22:04:11 | 000,215,943 | —- | C] () – C:\windows\System32\dssec.dat
[2009/07/13 19:55:01 | 000,043,131 | —- | C] () – C:\windows\mib.bin
[2009/07/13 19:51:43 | 000,073,728 | —- | C] () – C:\windows\System32\BthpanContextHandler.dll
[2009/07/13 19:42:10 | 000,064,000 | —- | C] () – C:\windows\System32\BWContextHandler.dll
[2009/06/10 17:26:10 | 000,673,088 | —- | C] () – C:\windows\System32\mlang.dat
[2005/05/26 03:03:23 | 000,011,729 | -H– | C] () – C:\Users\Annabel\AppData\Roaming\Annabellog.dat

========== LOP Check ==========

[2011/06/04 20:19:53 | 000,000,000 | —D | M] – C:\Users\Annabel\AppData\Roaming\iExpert Software
[2011/05/25 19:45:41 | 000,000,000 | —D | M] – C:\Users\Annabel\AppData\Roaming\Registry Mechanic
[2011/03/06 17:57:15 | 000,000,000 | —D | M] – C:\Users\Annabel\AppData\Roaming\Tific
[2011/03/12 08:36:07 | 000,000,000 | —D | M] – C:\Users\Annabel\AppData\Roaming\Toshiba
[2011/03/06 20:15:30 | 000,000,000 | —D | M] – C:\Users\Annabel\AppData\Roaming\WinBatch
[2011/03/06 17:57:41 | 000,000,000 | —D | M] – C:\Users\Annabel\AppData\Roaming\Windows Live Writer
[2005/09/15 08:14:22 | 000,000,000 | RHSD | M] – C:\Users\Annabel\AppData\Roaming\winlog
[2011/05/17 09:08:56 | 000,032,622 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/06/10 17:42:20 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/07/13 21:38:58 | 000,383,562 | RHS- | M] () – C:\bootmgr
[2010/11/05 12:47:18 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2009/06/10 17:42:20 | 000,000,010 | —- | M] () – C:\config.sys
[2011/06/11 18:35:50 | 796,987,392 | -HS- | M] () – C:\hiberfil.sys
[2011/06/11 18:36:04 | 1073,741,824 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2009/07/14 00:52:25 | 000,026,040 | —- | M] () – C:\windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 00:52:25 | 000,026,489 | —- | M] () – C:\windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 00:52:25 | 000,029,779 | —- | M] () – C:\windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 00:52:25 | 000,043,318 | —- | M] () – C:\windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 17:31:19 | 000,000,065 | —- | M] () – C:\windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2006/10/26 23:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\msonpppr.dll
[2009/07/13 21:16:19 | 000,029,696 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\winprint.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2010/09/23 03:32:56 | 000,301,936 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 00:41:57 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/03/06 17:22:51 | 000,000,221 | -HS- | M] () – C:\Users\Annabel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/06/11 18:42:03 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Users\Annabel\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-06-10 21:19:42

========== Alternate Data Streams ==========

@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:D1B5B4F1

< End of report >


And the Second file: Extras


OTL Extras logfile created on: 6/11/2011 6:48:54 PM - Run 1
OTL by OldTimer - Version 3.2.24.0 Folder = C:\Users\Annabel\Desktop
Starter Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1013.42 Mb Total Physical Memory | 96.82 Mb Available Physical Memory | 9.55% Memory free
1.99 Gb Paging File | 1.08 Gb Available in Paging File | 54.26% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 223.23 Gb Total Space | 195.67 Gb Free Space | 87.65% Space Free | Partition Type: NTFS

Computer Name: ANNABEL-PC | User Name: Annabel | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{12688FD7-CB92-4A5B-BEE4-5C8E0574434F}" = Utility Common Driver
"{17504ED4-DB08-40A8-81C2-27D8C01581DA}" = Windows Live Remote Service Resources
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{19A4A990-5343-4FF7-B3B5-6F046C091EDF}" = Windows Live Remote Client
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{227E8782-B2F4-4E97-B0EE-49DE9CC1C0C0}" = Windows Live Remote Service
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216013F0}" = Java™ 6 Update 13
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 26
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{39187A4B-7538-4BE7-8BAD-9E83303793AA}" = Toshiba Book Place
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel® Rapid Storage Technology
"{464B3406-A4D0-4914-910F-7CA4380DCC13}" = Windows Live Remote Client Resources
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform
"{51B4E156-14A5-4904-9AE4-B1AA2A0E46BE}" = TOSHIBA Supervisor Password
"{5279374D-87FE-4879-9385-F17278EBB9D3}" = TOSHIBA Hardware Setup
"{53536479-DFB0-47ED-9D10-43F3708C222D}" = TOSHIBA eco Utility
"{5AF550B4-BB67-4E7E-82F1-2C4300279050}" = ToshibaRegistration
"{5DA0E02F-970B-424B-BF41-513A5018E4C0}" = TOSHIBA Disc Creator
"{5E6F6CF3-BACC-4144-868C-E14622C658F3}" = TOSHIBA Web Camera Application
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{61AD15B2-50DB-4686-A739-14FE180D4429}" = Windows Live ID Sign-in Assistant
"{620BBA5E-F848-4D56-8BDA-584E44584C5E}" = TOSHIBA Flash Cards Support Utility
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6A05FEDF-662E-46BF-8A25-010E3F1C9C69}" = Windows Live UX Platform Language Pack
"{7C9E6E52-EB11-44DB-A761-82D5D873A8D9}" = Symantec AntiVirus
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8CD0B97D-46E9-4293-B467-A24DB96DB6DB}" = TOSHIBA ReelTime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader
"{970472D0-F5F9-4158-A6E3-1AE49EFEF2D3}" = TOSHIBA Application and Driver Installer
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9D3D8C60-A55F-4fed-B2B9-173001290E16}" = Realtek WLAN Driver
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC6569FA-6919-442A-8552-073BE69E247A}" = TOSHIBA Service Station
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.4
"{AF844339-2F8A-4593-81B3-9F4C54038C4E}" = Windows Live MIME IFilter
"{B2FB7DBA-CEEC-41F1-BC23-3323D96290F6}" = TOSHIBA Bulletin Board
"{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}" = TOSHIBA Recovery Media Creator
"{C2A276E3-154E-44DC-AAF1-FFDD7FD30E35}" = TOSHIBA Assist
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C7A4F26F-F9B0-41B2-8659-99181108CDE3}" = TOSHIBA Media Controller
"{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}" = PlayReady PC Runtime x86
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D4322448-B6AF-4316-B859-D8A0E84DCB38}" = TOSHIBA HDD/SSD Alert
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E69992ED-A7F6-406C-9280-1C156417BC49}" = TOSHIBA Quality Application
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{ED3CBA78-488F-4E8C-B33F-8E3BF4DDB4D2}" = Toshiba App Place
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{FBBC4667-2521-4E78-B1BD-8706F774549B}" = Best Buy pc app
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FEDD27A0-B306-45EF-BF58-B527406B42C8}" = TOSHIBA Value Added Package
"7-Zip" = 7-Zip 9.20
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"CCleaner" = CCleaner
"DivX Setup.divx.com" = DivX Setup
"Google Chrome" = Google Chrome
"HDMI" = Intel® Graphics Media Accelerator Driver
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"InstallShield_{12688FD7-CB92-4A5B-BEE4-5C8E0574434F}" = Utility Common Driver
"InstallShield_{51B4E156-14A5-4904-9AE4-B1AA2A0E46BE}" = TOSHIBA Supervisor Password
"InstallShield_{5279374D-87FE-4879-9385-F17278EBB9D3}" = TOSHIBA Hardware Setup
"InstallShield_{53536479-DFB0-47ED-9D10-43F3708C222D}" = TOSHIBA eco Utility
"InstallShield_{620BBA5E-F848-4D56-8BDA-584E44584C5E}" = TOSHIBA Flash Cards Support Utility
"InstallShield_{8CD0B97D-46E9-4293-B467-A24DB96DB6DB}" = TOSHIBA ReelTime
"InstallShield_{B2FB7DBA-CEEC-41F1-BC23-3323D96290F6}" = TOSHIBA Bulletin Board
"InstallShield_{D4322448-B6AF-4316-B859-D8A0E84DCB38}" = TOSHIBA HDD/SSD Alert
"InstallShield_{FEDD27A0-B306-45EF-BF58-B527406B42C8}" = TOSHIBA Value Added Package
"LiveUpdate" = LiveUpdate 3.2 (Symantec Corporation)
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Mozilla Firefox 4.0.1 (x86 en-US)" = Mozilla Firefox 4.0.1 (x86 en-US)
"NSS" = Norton Security Scan
"Registry Clean Expert_is1" = Registry Clean Expert
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"WinLiveSuite" = Windows Live Essentials

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"48e4cff94f039634" = Best Buy pc app
"Yahoo! BrowserPlus" = Yahoo! BrowserPlus 2.9.8

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 6/9/2011 4:13:06 AM | Computer Name = Annabel-PC | Source = Toshiba App Place | ID = 0
Description =

Error - 6/9/2011 4:15:24 AM | Computer Name = Annabel-PC | Source = TOSHIBA Service Station | ID = 0
Description = TSS Load: could not communicate with TMachInfo service

Error - 6/9/2011 6:57:25 AM | Computer Name = Annabel-PC | Source = Toshiba App Place | ID = 0
Description =

Error - 6/9/2011 1:05:50 PM | Computer Name = Annabel-PC | Source = Toshiba App Place | ID = 0
Description =

Error - 6/9/2011 3:01:40 PM | Computer Name = Annabel-PC | Source = Toshiba App Place | ID = 0
Description =

Error - 6/9/2011 3:28:04 PM | Computer Name = Annabel-PC | Source = Toshiba App Place | ID = 0
Description =

Error - 6/9/2011 3:30:21 PM | Computer Name = Annabel-PC | Source = TOSHIBA Service Station | ID = 0
Description = TSS Load: could not communicate with TMachInfo service

Error - 6/9/2011 4:42:13 PM | Computer Name = Annabel-PC | Source = Toshiba App Place | ID = 0
Description =

Error - 6/10/2011 1:48:19 AM | Computer Name = Annabel-PC | Source = Toshiba App Place | ID = 0
Description =

Error - 6/10/2011 9:55:23 AM | Computer Name = Annabel-PC | Source = Toshiba App Place | ID = 0
Description =

[ System Events ]
Error - 5/29/2011 12:25:12 PM | Computer Name = Annabel-PC | Source = RTL8192Ce | ID = 0
Description =

Error - 5/29/2011 12:25:14 PM | Computer Name = Annabel-PC | Source = RTL8192Ce | ID = 0
Description =

Error - 5/29/2011 12:25:14 PM | Computer Name = Annabel-PC | Source = RTL8192Ce | ID = 0
Description =

Error - 5/29/2011 2:13:32 PM | Computer Name = Annabel-PC | Source = RTL8192Ce | ID = 0
Description =

Error - 5/29/2011 2:13:34 PM | Computer Name = Annabel-PC | Source = RTL8192Ce | ID = 0
Description =

Error - 5/29/2011 2:13:34 PM | Computer Name = Annabel-PC | Source = RTL8192Ce | ID = 0
Description =

Error - 5/29/2011 2:14:05 PM | Computer Name = Annabel-PC | Source = RTL8192Ce | ID = 0
Description =

Error - 5/29/2011 2:14:24 PM | Computer Name = Annabel-PC | Source = RTL8192Ce | ID = 0
Description =

Error - 5/29/2011 2:14:26 PM | Computer Name = Annabel-PC | Source = RTL8192Ce | ID = 0
Description =

Error - 5/29/2011 2:14:26 PM | Computer Name = Annabel-PC | Source = RTL8192Ce | ID = 0
Description =


< End of report >
Hi Vince128,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://forums.whatthetech.com/How_Disable_…ams_t96260.html

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
hello Tomk, I just got home. I'm charging the laptop right now to start your instruction. I just want to ask if really winlogon.exe in my taskmanager is a virus or not. Because my brother said its very important and I should not delete it
You should not delete it. It is important. However, malware often uses "real" names. winlogon is one that is frequently used. I suspect that yours is legitimate - but we'll check it out to be sure.

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://forums.whatthetech.com/How_Disable_…ams_t96260.html

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Mr. Tomk heres the result from the Combo Fix ComboFix 11-06-13.01 - Annabel 06/13/2011 16:37:31.1.2 - x86 Microsoft Windows 7 Starter 6.1.7600.0.1252.1.1033.18.1013.330 [GMT -4:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\programdata\xp c:\programdata\xp\EBLib.dll c:\programdata\xp\TPwSav.sys c:\users\Annabel\AppData\Roaming\Annabel3SQLite3.dll c:\users\Annabel\AppData\Roaming\Annabellog.dat c:\users\Annabel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\rundll32.exe c:\users\Annabel\AppData\Roaming\winlog c:\users\Annabel\AppData\Roaming\winlog\ctfmon.exe c:\users\Annabel\AppData\Roaming\winlogon.exe . . ((((((((((((((((((((((((( Files Created from 2011-05-13 to 2011-06-13 ))))))))))))))))))))))))))))))) . . 2011-06-13 21:24 . 2011-06-13 21:24 ——– d—–w- c:\users\Default\AppData\Local\temp 2011-06-13 21:24 . 2011-06-13 21:24 ——– d—–w- c:\users\Annabel\AppData\Local\temp 2011-06-13 20:33 . 2011-06-13 20:33 ——– d—–w- C:\32788R22FWJFW 2011-06-10 21:19 . 2011-05-09 20:46 6962000 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{281D2D53-DDB8-4549-8DDE-36269B3CB175}\mpengine.dll 2011-06-10 01:27 . 2011-06-10 01:27 ——– d—–w- c:\program files\Common Files\Java 2011-06-10 01:27 . 2011-05-04 08:52 476904 —-a-w- c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll 2011-06-05 20:58 . 2011-04-14 16:26 142296 —-a-w- c:\program files\Mozilla Firefox\components\browsercomps.dll 2011-06-05 20:58 . 2011-04-14 16:25 781272 —-a-w- c:\program files\Mozilla Firefox\mozsqlite3.dll 2011-06-05 20:58 . 2011-04-14 16:25 1874904 —-a-w- c:\program files\Mozilla Firefox\mozjs.dll 2011-06-05 20:58 . 2011-04-14 16:25 15832 —-a-w- c:\program files\Mozilla Firefox\mozalloc.dll 2011-06-05 20:58 . 2011-04-14 16:25 465880 —-a-w- c:\program files\Mozilla Firefox\libGLESv2.dll 2011-06-05 20:58 . 2011-04-14 16:25 89048 —-a-w- c:\program files\Mozilla Firefox\libEGL.dll 2011-06-05 20:58 . 2010-01-01 08:00 1974616 —-a-w- c:\program files\Mozilla Firefox\D3DCompiler_42.dll 2011-06-05 20:58 . 2010-01-01 08:00 1892184 —-a-w- c:\program files\Mozilla Firefox\d3dx9_42.dll 2011-06-05 03:28 . 2011-06-05 03:28 ——– d—–w- c:\users\Annabel\AppData\Local\Symantec 2011-06-05 03:27 . 2011-06-05 03:27 109744 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS 2011-06-05 03:25 . 2011-06-05 03:27 ——– d—–w- c:\program files\Symantec 2011-06-05 03:25 . 2011-06-05 03:25 ——– d—–w- c:\program files\Symantec AntiVirus 2011-06-05 00:19 . 2011-06-05 00:19 ——– d—–w- c:\users\Annabel\AppData\Roaming\iExpert Software 2011-06-05 00:19 . 2011-06-05 00:19 ——– d—–w- c:\program files\Registry Clean Expert 2011-05-25 23:45 . 2011-05-25 23:45 ——– d—–w- c:\users\Annabel\AppData\Roaming\Registry Mechanic 2011-05-25 10:58 . 2011-04-22 19:36 26496 —-a-w- c:\windows\system32\drivers\Diskdump.sys 2011-05-24 06:27 . 2011-04-09 05:56 123904 —-a-w- c:\windows\system32\poqexec.exe 2011-05-22 22:42 . 2011-05-22 22:42 ——– d—–w- c:\users\Annabel\AppData\Local\DDMSettings 2011-05-19 02:41 . 2011-06-09 08:13 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-05-04 08:52 . 2010-11-05 01:30 472808 —-a-w- c:\windows\system32\deployJava1.dll 2011-04-26 18:23 . 2011-04-26 18:23 0 —ha-w- c:\users\Annabel\AppData\Local\BITF749.tmp 2011-04-26 05:58 . 2011-04-26 05:58 499712 —-a-w- c:\windows\system32\msvcp71.dll 2011-04-26 05:58 . 2011-04-26 05:58 348160 —-a-w- c:\windows\system32\msvcr71.dll 2011-04-09 06:13 . 2011-05-11 20:08 3957632 —-a-w- c:\windows\system32\ntkrnlpa.exe 2011-04-09 06:13 . 2011-05-11 20:08 3901824 —-a-w- c:\windows\system32\ntoskrnl.exe 2011-04-14 16:26 . 2011-06-05 20:58 142296 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-11-05 39408] "RegClean Expert Scheduler"="c:\program files\Registry Clean Expert\RCHelper.exe" [2011-05-03 606592] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-10-01 141848] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-10-01 173592] "Persistence"="c:\windows\system32\igfxpers.exe" [2010-10-01 150552] "SVPWUTIL"="c:\program files\TOSHIBA\Utilities\SVPWUTIL.exe" [2010-03-04 352256] "HWSetup"="c:\program files\TOSHIBA\Utilities\HWSetup.exe" [2010-03-05 425984] "KeNotify"="c:\program files\TOSHIBA\Utilities\KeNotify.exe" [2010-09-14 35440] "TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2010-09-28 521640] "SmoothView"="c:\program files\Toshiba\SmoothView\SmoothView.exe" [2009-07-28 460088] "00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2010-05-09 742776] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2010-11-17 9874024] "RtHDVBg"="c:\program files\Realtek\Audio\HDA\RtHDVBg.exe" [2010-11-11 1522280] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2010-03-11 1697064] "Teco"="c:\program files\TOSHIBA\TECO\Teco.exe" [2010-11-12 1349032] "ToshibaServiceStation"="c:\program files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" [2009-10-06 1294136] "TWebCamera"="c:\program files\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" [2010-05-02 2454840] "ToshibaAppPlace"="c:\program files\Toshiba\Toshiba App Place\ToshibaAppPlace.exe" [2010-09-23 552960] "TosVolRegulator"="c:\program files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe" [2009-11-11 22840] "TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe" [2010-02-06 611672] "TosReelTimeMonitor"="c:\program files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe" [2010-07-10 31648] "TosNC"="c:\program files\Toshiba\BulletinBoard\TosNcCore.exe" [2010-04-23 467816] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288] "DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-03-21 1230704] "ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-11-22 107112] "vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2006-11-28 134808] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696] . c:\users\Annabel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-27 98632] . c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Best Buy pc app.lnk - c:\programdata\Best Buy pc app\ClickOnceSetup.exe [2010-6-24 9216] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Best Buy pc app] c:\users\Annabel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Best Buy\Best Buy pc app.appref-ms [X] . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-11-05 136176] R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2010-11-05 136176] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2010-07-21 194664] R3 SavRoam;SavRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [2006-11-28 122008] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128] S2 IconMan_R;IconMan_R;c:\program files\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe [2010-08-05 1809920] S2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\TOSHIBA\TECO\TecoService.exe [2010-11-12 189880] S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2011-05-16 105592] S3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys [2009-06-23 24064] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2010-10-07 322664] S3 RTL8192Ce;Realtek Wireless LAN 802.11n PCI-E NIC Driver;c:\windows\system32\DRIVERS\rtl8192Ce.sys [2010-10-19 999016] S3 TMachInfo;TMachInfo;c:\program files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2009-10-06 51512] S3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2010-02-06 111960] . . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS FontCache fdrespub AppIDSvc QWAVE wcncsvc . Contents of the 'Scheduled Tasks' folder . 2011-06-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-11-05 01:41] . 2011-06-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-11-05 01:41] . 2011-06-11 c:\windows\Tasks\Norton Security Scan for Annabel.job - c:\progra~1\NORTON~2\Engine\310~1.21\Nss.exe [2011-04-05 14:02] . . ——- Supplementary Scan ——- . uStart Page = hxxp://search.jzip.com/ uInternet Settings,ProxyOverride = IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000 IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html TCP: DhcpNameServer = 192.168.1.1 [removed] [removed] FF - ProfilePath - c:\users\Annabel\AppData\Roaming\Mozilla\Firefox\Profiles\m6zbg2yl.default\ FF - prefs.js: browser.startup.homepage - www.google.com FF - prefs.js: keyword.URL - hxxp://search.jzip.com/web?src=ffb&systemid=102&q= . - - - - ORPHANS REMOVED - - - - . Toolbar-Locked - (no file) Toolbar-10 - (no file) HKCU-Run-Critical Core - c:\users\Annabel\AppData\Roaming\winlogon.exe . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2011-06-13 17:30:47 ComboFix-quarantined-files.txt 2011-06-13 21:30 . Pre-Run: 210,550,865,920 bytes free Post-Run: 210,480,418,816 bytes free . - - End Of File - - 52DC95D9EBB0DC1DEA9E02C7632591C6
Vince128,

You did have an "odd" version of winlogon.exe that was orphaned.

You have a program called Registry Clean Expert installed. I recommend you uninstall it. I do not recommend that you ever run any of the so called "registry cleaner/optimizer" programs. They are very unlikely to ever do any good… but they quite often cause great harm.

Let's get an online scan to see if we've missed anything.

ESET Online Scanner:

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Vista users: You will need to to right-click on the either the IE or FF icon in the Start Menu or Quick Launch Bar on the Taskbar and select Run as Administrator from the context menu.

  • Please go here then click on: [external image: Posted Image]

    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.

  • Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: [external image: Posted Image]
  • The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on: [external image: Posted Image]
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.

Note: Do not forget to re-enable your Anti-Virus application after running the above scan!
ok im scanning it right now.. hey mr. tomk.. some files deleted are viruses? because i found c:\programdata\xp\TPwSav.sys were our computer file.. TOshiba.. idk if its ok to delete it
The legitimate version of that file would not be found where this was found. It would be located at c:\windows\system32\drivers\TPwSav.sys.

Have a look here and here for a little information on the "bogus" version of that file.
mr. tomk. sorry the scan is so long and not finished yet.. the scan detected 1 threat.. imma put it after the scan is finished..

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI