This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Virus related keyboard issues [Solved]

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, I'm assuming that this is due to a virus, but my major situation is as follows: On occasion (not every attempt) if i'm typing "n" or "m" (may happen on other keys, just haven't noticed it) it will replace it with random characters like ";" or ".3" or it will do a combo of both and automatically hit "enter". If anyone has a resolution or reasoning for why this is happening it would be appreciated! Thanks.
:welcome: Before we check for malware, read this over and see if it helps This phenomenon can occur in some gaming and IM environments when the NUMLOCK key is active. Clicking the NUMLOCK key to OFF, can solve the problem. On some machines a combination of Fn key plus NUMLOCK produces (2) two lock alert lights to activate. Turning off Fn+Numlock, followed by turning off NUMLOCK alone, may remove the problem. The free version of Comcast Constant Guard can also produce this problem. Best solution might be to uninstall Constant Guard if present. The "problem" does not affect Microsoft Office utilities, nor major browsers, but does in some games and IM's. Let me know if it did
It seems to have stopped, I'm assuming you are correct, so thank you =) But while I have your attention, would you help me out a bit more, my computer's speed has drastically dropped compared to what it was a few months ago, (also have a usb port that isnt reading/working, but i am assuming that is a hardware issue)… as for the speed, I read the pinned topic and downloaded otl, i can run it and get you the feedback, or if another program works better for you/me, let me know. Thanks a ton already.
:thumbup:

Outside of the speed, are you experiencing any browser redirects to sites you did not choose ?

This will check for a rootkit

Download aswMBR.exe ( 511KB ) to your desktop.

Double click the aswMBR.exe to run it

Click the "Scan" button to start scan
[external image: Posted Image]

On completion of the scan click save log, save it to your desktop and post in your next reply
[external image: Posted Image]




Right now I prefer a DDS log in lew of OTL

Download DDS from one of the links below to your desktop

Link 1
Link 2

  • Double click the tool to run it.
  • A black Screen will open, just read the contents and do nothing.
  • When the tool finishes, it will open 2 reports, DDS.txt and attach.txt
  • Copy/Paste the contents of 'DDS.txt' into your post.
  • 'attach.txt' should be zipped using Windows native zip utility and attached to your post. Compress and uncompress files (zip files)
I attempted both downloads, and for some reason when it finishes the downloads, they seem to be doing one of either 2 things - deleting themselves as they finish, or not completing at all, it will not allow me to open either of them or find the host folders, i watched my downloads folder, and as they finish, they just disappear… it was working properly last night when i downloaded otr, i am unsure why it is not working today….
Sorry about all the confusion and holdup, this is the otl file, i'm running it again because it did not give me the 2nd document to send


OTL logfile created on: 1/24/2012 1:57:23 PM - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Austin\Desktop
64bit-Windows Vista Ultimate Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19170)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 1.67 Gb Available Physical Memory | 41.81% Memory free
8.19 Gb Paging File | 5.74 Gb Available in Paging File | 70.09% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 222.09 Gb Total Space | 141.21 Gb Free Space | 63.58% Space Free | Partition Type: NTFS
Drive D: | 10.79 Gb Total Space | 1.80 Gb Free Space | 16.69% Space Free | Partition Type: NTFS
Drive E: | 7.82 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive F: | 931.51 Gb Total Space | 824.74 Gb Free Space | 88.54% Space Free | Partition Type: NTFS

Computer Name: AUSTIN-PC | User Name: Austin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Austin\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - F:\Computer Files\iTunesHelper.exe (Apple Inc.)
PRC - C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\Windows\SMINST\BLService.exe ()
PRC - C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe (CyberLink)
PRC - C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe ()
PRC - C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe ()
PRC - C:\Program Files (x86)\DigitalPersona\Bin\DpAgent.exe (DigitalPersona, Inc.)
PRC - C:\Program Files (x86)\DigitalPersona\Bin\DpHostW.exe (DigitalPersona, Inc.)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ()
MOD - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMediaLibrary.dll ()
MOD - C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvcPS.dll ()
MOD - C:\Program Files (x86)\Cyberlink\Shared files\richvideops.dll ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (avast! Antivirus) – C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV:64bit: - (CLPSLS) – C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe (COMODO)
SRV:64bit: - (cmdAgent) – C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (COMODO)
SRV:64bit: - (hpsrv) – C:\Windows\SysNative\Hpservice.exe (Hewlett-Packard Company)
SRV:64bit: - (STacSV) – C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_58be29c0\STacSV64.exe (IDT, Inc.)
SRV:64bit: - (vfsFPService) – C:\Windows\SysNative\vfsFPService.exe (Validity Sensors, Inc.)
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (SolidWorks Licensing Service) – C:\Program Files (x86)\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe (SolidWorks)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (CoordinatorServiceHost) – F:\Computer Files\SOLIDWORKS\SolidWorks\swScheduler\DTSCoordinatorService.exe (Dassault Systèmes SolidWorks Corp.)
SRV - (Remote Solver for Flow Simulation 2009) – F:\Computer Files\SOLIDWORKS\SolidWorks Flow Simulation\binCFW\StandAloneSlv.exe (Mentor Graphics Corporation)
SRV - (YahooAUService) – C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (Recovery Service for Windows) – C:\Windows\SMINST\BLService.exe ()
SRV - (QPCapSvc) QuickPlay Background Capture Service (QBCS) – C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe ()
SRV - (QPSched) QuickPlay Task Scheduler (QTS) – C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe ()
SRV - (DpHost) – C:\Program Files (x86)\DigitalPersona\Bin\DpHostW.exe (DigitalPersona, Inc.)
SRV - (vfsFPService) – C:\Windows\SysWow64\vfsFPService.exe (Validity Sensors, Inc.)
SRV - (IAANTMON) Intel® – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Intel Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (aswSnx) – C:\Windows\SysNative\drivers\aswSnx.sys (AVAST Software)
DRV:64bit: - (aswSP) – C:\Windows\SysNative\drivers\aswSP.sys (AVAST Software)
DRV:64bit: - (aswRdr) – C:\Windows\SysNative\drivers\aswRdr.sys (AVAST Software)
DRV:64bit: - (aswTdi) – C:\Windows\SysNative\drivers\aswTdi.sys (AVAST Software)
DRV:64bit: - (aswMonFlt) – C:\Windows\SysNative\drivers\aswMonFlt.sys (AVAST Software)
DRV:64bit: - (aswFsBlk) – C:\Windows\SysNative\drivers\aswFsBlk.sys (AVAST Software)
DRV:64bit: - (cmderd) – C:\Windows\SysNative\DRIVERS\cmderd.sys (COMODO)
DRV:64bit: - (hpdskflt) – C:\Windows\SysNative\DRIVERS\hpdskflt.sys (Hewlett-Packard Company)
DRV:64bit: - (Accelerometer) – C:\Windows\SysNative\DRIVERS\Accelerometer.sys (Hewlett-Packard Company)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\Drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\DRIVERS\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (WpdUsb) – C:\Windows\SysNative\DRIVERS\wpdusb.sys (Microsoft Corporation)
DRV:64bit: - (STHDA) – C:\Windows\SysNative\DRIVERS\stwrt64.sys (IDT, Inc.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (NETw5v64) Intel® – C:\Windows\SysNative\DRIVERS\NETw5v64.sys (Intel Corporation)
DRV:64bit: - (NVHDA) – C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation)
DRV:64bit: - (RTL8169) – C:\Windows\SysNative\DRIVERS\Rtlh64.sys (Realtek Corporation )
DRV:64bit: - (JMCR) – C:\Windows\SysNative\DRIVERS\jmcr.sys (JMicron Technology Corporation)
DRV:64bit: - (vfs101a) – C:\Windows\SysNative\drivers\vfs101a.sys (Validity Sensors, Inc.)
DRV:64bit: - (enecir) – C:\Windows\SysNative\DRIVERS\enecir.sys (ENE TECHNOLOGY INC.)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\DRIVERS\iaStor.sys (Intel Corporation)
DRV:64bit: - (NETw3v64) Intel® – C:\Windows\SysNative\DRIVERS\NETw3v64.sys (Intel Corporation)
DRV:64bit: - (sdbus) – C:\Windows\SysNative\DRIVERS\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (HpqKbFiltr) – C:\Windows\SysNative\DRIVERS\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV:64bit: - (yukonx64) – C:\Windows\SysNative\DRIVERS\yk60x64.sys (Marvell)
DRV - ({55662437-DA8C-40c0-AADA-2C816A897A49}) – C:\Program Files (x86)\Hewlett-Packard\Media\DVD\000.fcl (Cyberlink Corp.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cnnb
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cnnb
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cnnb
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cnnb

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cnnb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://dm.startnow.com/?src=startpage&…ion=6.0-x64-SP2
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cnnb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Bing"
FF - prefs.js..browser.startup.homepage: "http://dm.startnow.com/?src=startpage&provider=bing&provider_name=bing&provider_code=Z055&partner_id=195&product_id=611&affiliate_id=&channel=dm6&toolbar_id=200&toolbar_version=2.1.0&install_country=US&install_date=20110610&user_guid=0A29010C08BC483F992DFD6954A0B42A&machine_id=a9deb37df0268c45420423f4ae4d00fa&browser=FF&os=win&os_version=6.0-x64-SP2"
FF - prefs.js..keyword.URL: "http://dm.startnow.com/s/?src=addrbar&provider=bing&provider_name=bing&provider_code=Z055&partner_id=195&product_id=611&affiliate_id=&channel=dm6&toolbar_id=200&toolbar_version=2.1.0&install_country=US&install_date=20110610&user_guid=0A29010C08BC483F992DFD6954A0B42A&machine_id=a9deb37df0268c45420423f4ae4d00fa&browser=FF&os=win&os_version=6.0-x64-SP2&q="
FF - prefs.js..network.proxy.type: 0


FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: F:\Computer Files\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2 [2008/09/04 01:13:47 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\DigitalPersona\Bin\FirefoxExt\ [2011/03/22 04:03:36 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2011/12/03 01:59:07 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/01/09 08:02:36 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\DigitalPersona\Bin\firefoxext [2011/03/22 04:03:36 | 000,000,000 | —D | M]

[2011/03/22 14:26:57 | 000,000,000 | —D | M] (No name found) – C:\Users\Austin\AppData\Roaming\Mozilla\Extensions
[2012/01/22 11:19:39 | 000,000,000 | —D | M] (No name found) – C:\Users\Austin\AppData\Roaming\Mozilla\Firefox\Profiles\6qkk5yg9.default\extensions
[2012/01/21 08:38:25 | 000,000,000 | —D | M] (Greasemonkey) – C:\Users\Austin\AppData\Roaming\Mozilla\Firefox\Profiles\6qkk5yg9.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}(24)
[2011/06/09 20:57:11 | 000,002,286 | —- | M] () – C:\Users\Austin\AppData\Roaming\Mozilla\Firefox\Profiles\6qkk5yg9.default\searchplugins\bing-zugo.xml
[2012/01/09 08:02:43 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/01/09 08:02:35 | 000,121,816 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011/09/02 18:25:59 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2010/01/01 03:00:00 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml.old
[2011/11/11 01:07:30 | 000,002,040 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2006/09/18 16:37:24 | 000,000,761 | —- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3:64bit: - HKLM\..\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O4:64bit: - HKLM..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO)
O4:64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe (Hewlett-Packard)
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [CLMLServer for HP TouchSmart] C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe (CyberLink)
O4 - HKLM..\Run: [COMODO] C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLA.exe (COMODO)
O4 - HKLM..\Run: [CPA] C:\Program Files\COMODO\COMODO GeekBuddy\VALA.exe (COMODO)
O4 - HKLM..\Run: [DpAgent] C:\Program Files (x86)\DigitalPersona\Bin\dpagent.exe (DigitalPersona, Inc.)
O4 - HKLM..\Run: [DVDAgent] C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe (CyberLink Corp.)
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [hpqSRMon] File not found
O4 - HKLM..\Run: [iTunesHelper] F:\Computer Files\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [TSMAgent] C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe (CyberLink Corp.)
O4 - HKCU..\Run: [uTorrent] F:\Computer Files\uTorrent.exe (BitTorrent, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O8:64bit: - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.76.76 75.75.75.75
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{CFAFBF36-1EA3-43F7-95AC-67DCD91F600D}: DhcpNameServer = 75.75.76.76 75.75.75.75
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap11 - No CLSID value found
O20:64bit: - AppInit_DLLs: (C:\Windows\system32\guard64.dll) - C:\Windows\SysNative\guard64.dll (COMODO)
O20 - AppInit_DLLs: (C:\Windows\SysWOW64\guard32.dll) -C:\WINDOWS\SysWOW64\guard32.dll (COMODO)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) -C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Austin\Pictures\background.jpg
O24 - Desktop BackupWallPaper: C:\Users\Austin\Pictures\background.jpg
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{f1ccc931-5463-11e0-9f3b-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{f1ccc931-5463-11e0-9f3b-806e6f6e6963}\Shell\AutoRun\command - "" = E:\sldim\sldim.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)

Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\WINDOWS\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:\Windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/01/24 03:43:56 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Users\Austin\Desktop\OTL.exe
[2012/01/22 12:14:21 | 000,000,000 | —D | C] – C:\ProgramData\SecTaskMan
[2012/01/22 12:14:10 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Security Task Manager
[2012/01/22 12:14:08 | 000,000,000 | —D | C] – C:\Program Files (x86)\Security Task Manager
[2012/01/22 11:31:41 | 001,689,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\lsasrv.dll
[2012/01/22 11:31:41 | 000,094,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\secur32.dll
[2012/01/20 16:51:00 | 000,000,000 | —D | C] – C:\Users\Austin\AppData\Roaming\Yahoo!
[2012/01/11 19:04:36 | 000,817,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2012/01/11 19:04:36 | 000,726,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2012/01/11 19:04:35 | 001,570,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\quartz.dll
[2012/01/11 19:04:35 | 001,314,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\quartz.dll
[2012/01/11 19:04:35 | 000,497,152 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\qdvd.dll
[2012/01/11 19:04:35 | 000,352,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\qdvd.dll
[2012/01/11 19:04:33 | 001,585,152 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntdll.dll
[2012/01/11 19:04:32 | 000,451,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winsrv.dll
[2012/01/11 19:04:32 | 000,211,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winmm.dll
[2012/01/11 19:04:32 | 000,048,128 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mcicda.dll
[2012/01/11 19:04:32 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mciwave.dll
[2012/01/11 19:04:32 | 000,028,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mciseq.dll
[2012/01/11 19:04:32 | 000,023,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mciseq.dll
[2012/01/11 19:04:31 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\packager.dll
[2012/01/11 19:04:31 | 000,066,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\packager.dll
[2012/01/07 00:37:16 | 000,000,000 | —D | C] – C:\Users\Austin\AppData\Local\{DE1B4FFD-4D8A-483F-A466-800BEF6320CD}
[2012/01/07 00:37:16 | 000,000,000 | —D | C] – C:\Users\Austin\AppData\Local\{1A957AAD-ED2D-4914-8773-FB7DB55882C8}
[2011/12/28 09:49:09 | 000,000,000 | —D | C] – C:\Users\Austin\AppData\Local\{D522E218-9F21-4DB7-9848-5199B20DACE8}
[2011/12/28 09:48:58 | 000,000,000 | —D | C] – C:\Users\Austin\AppData\Local\{01E59063-819C-47B0-A4D6-11E05CF4558B}
[2011/12/28 09:48:43 | 000,000,000 | —D | C] – C:\Users\Austin\Tracing
[2011/12/28 09:39:36 | 000,000,000 | —D | C] – C:\Program Files (x86)\Windows Live
[2011/12/28 09:37:30 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2011/12/28 09:36:36 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Silverlight
[2011/12/28 09:35:07 | 000,000,000 | —D | C] – C:\Users\Austin\AppData\Local\Windows Live
[2011/12/28 09:35:07 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Windows Live
[2011/12/25 16:57:20 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/12/25 16:56:48 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2011/12/25 16:56:46 | 000,000,000 | —D | C] – C:\Program Files\iTunes

========== Files - Modified Within 30 Days ==========

[2012/01/24 14:03:03 | 001,474,832 | —- | M] () – C:\Windows\SysNative\drivers\sfi.dat
[2012/01/24 13:32:57 | 000,003,216 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/01/24 13:32:57 | 000,003,216 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/01/24 11:12:17 | 000,000,032 | —- | M] () – C:\Users\Austin\jagex_cl_runescape_LIVE.dat
[2012/01/24 07:33:04 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/01/24 03:44:00 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Austin\Desktop\OTL.exe
[2012/01/23 08:03:32 | 000,000,680 | —- | M] () – C:\Users\Austin\AppData\Local\d3d9caps.dat
[2012/01/23 03:17:44 | 4292,026,368 | -HS- | M] () – C:\hiberfil.sys
[2012/01/22 11:05:17 | 591,182,210 | —- | M] () – C:\Windows\MEMORY.DMP
[2012/01/19 07:49:47 | 000,000,338 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForAustin.job
[2012/01/12 03:07:47 | 000,718,604 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/01/12 03:07:47 | 000,604,502 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/01/12 03:07:47 | 000,104,170 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/01/07 00:53:26 | 000,050,910 | —- | M] () – C:\Users\Austin\Documents\cc_20120107_005320.reg
[2012/01/07 00:38:34 | 000,000,770 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2012/01/07 00:34:13 | 000,300,624 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2011/12/25 16:57:20 | 000,001,440 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk

========== Files Created - No Company Name ==========

[2012/01/22 11:05:17 | 591,182,210 | —- | C] () – C:\Windows\MEMORY.DMP
[2012/01/07 00:53:22 | 000,050,910 | —- | C] () – C:\Users\Austin\Documents\cc_20120107_005320.reg
[2011/12/28 09:42:30 | 000,002,079 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk
[2011/12/25 16:57:20 | 000,001,440 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2011/12/02 12:43:00 | 000,010,316 | -HS- | C] () – C:\Users\Austin\AppData\Local\051010s8h520l360r552q3vbs5w6
[2011/12/02 12:43:00 | 000,010,316 | -HS- | C] () – C:\ProgramData\051010s8h520l360r552q3vbs5w6
[2011/07/17 19:05:09 | 000,000,000 | —- | C] () – C:\Users\Austin\AppData\Local\Temptable.xml
[2011/07/17 18:25:28 | 000,000,000 | —- | C] () – C:\Windows\eDrawingOfficeAutomator.INI
[2011/06/05 19:31:29 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2011/03/30 22:27:59 | 000,000,680 | —- | C] () – C:\Users\Austin\AppData\Local\d3d9caps.dat
[2011/03/26 05:26:01 | 000,117,248 | —- | C] () – C:\Windows\SysWow64\EhStorAuthn.dll
[2011/03/26 05:25:28 | 000,107,612 | —- | C] () – C:\Windows\SysWow64\StructuredQuerySchema.bin
[2011/03/26 05:24:59 | 000,368,640 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2011/03/23 06:10:36 | 000,018,904 | —- | C] () – C:\Windows\SysWow64\StructuredQuerySchemaTrivial.bin
[2011/03/23 02:35:02 | 000,000,732 | —- | C] () – C:\Users\Austin\AppData\Local\d3d9caps64.dat
[2011/03/22 04:06:54 | 000,111,846 | —- | C] () – C:\ProgramData\nvModes.001
[2011/03/22 04:00:02 | 000,111,846 | —- | C] () – C:\ProgramData\nvModes.dat
[2008/09/04 00:22:45 | 000,000,381 | —- | C] () – C:\ProgramData\hpqp.ini
[2008/09/03 23:46:08 | 000,107,386 | —- | C] () – C:\Windows\hpqins13.dat
[2008/01/20 21:49:10 | 000,060,124 | —- | C] () – C:\Windows\SysWow64\tcpmon.ini
[2007/11/14 18:17:34 | 000,204,800 | —- | C] () – C:\Windows\SysWow64\CogentBioSDK.dll
[2006/11/02 10:35:48 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 07:37:14 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2006/11/02 07:24:17 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2006/11/02 07:18:17 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat
[2006/11/02 04:47:54 | 000,043,131 | —- | C] () – C:\Windows\mib.bin

========== LOP Check ==========

[2011/10/22 22:52:11 | 000,000,000 | —D | M] – C:\Users\Austin\AppData\Roaming\DassaultSystemes
[2011/03/22 08:00:05 | 000,000,000 | —D | M] – C:\Users\Austin\AppData\Roaming\DigitalPersona
[2011/08/13 17:54:33 | 000,000,000 | —D | M] – C:\Users\Austin\AppData\Roaming\IM
[2011/12/03 02:31:22 | 000,000,000 | —D | M] – C:\Users\Austin\AppData\Roaming\TS3Client
[2012/01/23 08:04:15 | 000,000,000 | —D | M] – C:\Users\Austin\AppData\Roaming\uTorrent
[2012/01/23 03:16:35 | 000,025,960 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/04/11 01:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2012/01/23 03:17:44 | 4292,026,368 | -HS- | M] () – C:\hiberfil.sys
[2006/12/02 01:37:14 | 000,904,704 | —- | M] (Microsoft Corporation) – C:\msdia80.dll
[2012/01/23 03:17:42 | 310,644,735 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2006/11/02 10:05:44 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 10:05:44 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 10:05:44 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2011/04/01 21:47:51 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/09/18 16:35:48 | 000,000,065 | -H– | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2011/11/28 13:01:25 | 000,041,184 | —- | M] (AVAST Software) – C:\Windows\avastSS.scr

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2008/01/20 22:21:14 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/04/02 20:26:12 | 000,000,286 | -HS- | M] () – C:\Users\Austin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2012/01/24 03:44:00 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Austin\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< End of report >
You have a few things that need to go, want to point out that if you use any of the Torrents or any type of File Sharing your going to infect your computer big time.



Open OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :processes
    killallprocesses
    
    
    ClearJavaCache::
    
    :OTL
    FF - prefs.js..browser.startup.homepage: "http://dm.startnow.com/?
    FF - prefs.js..keyword.URL: "http://dm.startnow.com/s/?
    O4 - HKCU..\Run: [uTorrent] F:\Computer Files\uTorrent.exe (BitTorrent, Inc.)
    O33 - MountPoints2\{f1ccc931-5463-11e0-9f3b-806e6f6e6963}\Shell - "" = AutoRun
    O33 - MountPoints2\{f1ccc931-5463-11e0-9f3b-806e6f6e6963}\Shell\AutoRun\command - "" = E:\sldim\sldim.exe
    
    :Services
    
    :Reg
    
    :Files
    ipconfig /flushdns /c
    
    
    :Commands
    [purity]
    [resethosts]
    [CLEARALLRESTOREPOINTS]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top. <–Not run Scan
  • Let the program run unhindered, reboot when it is done
  • Then post the results of the log it produces.
  • Then run a new scan and post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )






Please download Malwarebytes from Here or Here

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the report please
Give it another 20 minutes or so, if your system is real dirty with temp files and such it may take awhile. If after about a half hour or more, why dont you just close it out and then try running it in Safemode

To Enter Safemode
  • Go to Start> Shut off your Computer> Restart
  • As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly,
    this will bring up a menu.
  • Use the Up and Down Arrow Keys to scroll up to Safemode
  • Then press the Enter Key on your Keyboard
Tutorial if you need it How to boot into Safemode
i attempted to restart because it popped a quick error up early last attempt, it came back up saying it could not create the file c:/….../cmd.bat.
OTL is complete, i figured i would give you this to review while i worked on the second step
———–



All processes killed
========== PROCESSES ==========
No active process named ClearJavaCache:: was found!
========== OTL ==========
Prefs.js: "http://dm.startnow.com/? removed from browser.startup.homepage
Prefs.js: "http://dm.startnow.com/s/? removed from keyword.URL
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\uTorrent deleted successfully.
F:\Computer Files\uTorrent.exe moved successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f1ccc931-5463-11e0-9f3b-806e6f6e6963}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f1ccc931-5463-11e0-9f3b-806e6f6e6963}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f1ccc931-5463-11e0-9f3b-806e6f6e6963}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f1ccc931-5463-11e0-9f3b-806e6f6e6963}\ not found.
File E:\sldim\sldim.exe not found.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Could not flush the DNS Resolver Cache: Function failed during execution.
C:\Users\Austin\Desktop\cmd.bat deleted successfully.
C:\Users\Austin\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot.
HOSTS file reset successfully
Error creating restore point.

[EMPTYTEMP]

User: All Users

User: Austin
->Temp folder emptied: 206910280 bytes
->Temporary Internet Files folder emptied: 47751757 bytes
->Java cache emptied: 450795753 bytes
->FireFox cache emptied: 65587737 bytes
->Flash cache emptied: 10838 bytes

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 17994475 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 11258520 bytes
RecycleBin emptied: 353989205 bytes

Total Files Cleaned = 1,101.00 mb


OTL by OldTimer - Version 3.2.31.0 log created on 01242012_180848

Files\Folders moved on Reboot…
File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot.
C:\Users\Austin\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

Registry entries deleted on Reboot…
OTL is complete, i figured i would give you this to review while i worked on the second step
———–



All processes killed
========== PROCESSES ==========
No active process named ClearJavaCache:: was found!
========== OTL ==========
Prefs.js: "http://dm.startnow.com/? removed from browser.startup.homepage
Prefs.js: "http://dm.startnow.com/s/? removed from keyword.URL
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\uTorrent deleted successfully.
F:\Computer Files\uTorrent.exe moved successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f1ccc931-5463-11e0-9f3b-806e6f6e6963}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f1ccc931-5463-11e0-9f3b-806e6f6e6963}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f1ccc931-5463-11e0-9f3b-806e6f6e6963}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f1ccc931-5463-11e0-9f3b-806e6f6e6963}\ not found.
File E:\sldim\sldim.exe not found.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Could not flush the DNS Resolver Cache: Function failed during execution.
C:\Users\Austin\Desktop\cmd.bat deleted successfully.
C:\Users\Austin\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot.
HOSTS file reset successfully
Error creating restore point.

[EMPTYTEMP]

User: All Users

User: Austin
->Temp folder emptied: 206910280 bytes
->Temporary Internet Files folder emptied: 47751757 bytes
->Java cache emptied: 450795753 bytes
->FireFox cache emptied: 65587737 bytes
->Flash cache emptied: 10838 bytes

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 17994475 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 11258520 bytes
RecycleBin emptied: 353989205 bytes

Total Files Cleaned = 1,101.00 mb


OTL by OldTimer - Version 3.2.31.0 log created on 01242012_180848

Files\Folders moved on Reboot…
File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot.
C:\Users\Austin\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

Registry entries deleted on Reboot…
OTL is complete, i figured i would give you this to review while i worked on the second step
———–



All processes killed
========== PROCESSES ==========
No active process named ClearJavaCache:: was found!
========== OTL ==========
Prefs.js: "http://dm.startnow.com/? removed from browser.startup.homepage
Prefs.js: "http://dm.startnow.com/s/? removed from keyword.URL
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\uTorrent deleted successfully.
F:\Computer Files\uTorrent.exe moved successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f1ccc931-5463-11e0-9f3b-806e6f6e6963}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f1ccc931-5463-11e0-9f3b-806e6f6e6963}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f1ccc931-5463-11e0-9f3b-806e6f6e6963}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f1ccc931-5463-11e0-9f3b-806e6f6e6963}\ not found.
File E:\sldim\sldim.exe not found.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Could not flush the DNS Resolver Cache: Function failed during execution.
C:\Users\Austin\Desktop\cmd.bat deleted successfully.
C:\Users\Austin\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot.
HOSTS file reset successfully
Error creating restore point.

[EMPTYTEMP]

User: All Users

User: Austin
->Temp folder emptied: 206910280 bytes
->Temporary Internet Files folder emptied: 47751757 bytes
->Java cache emptied: 450795753 bytes
->FireFox cache emptied: 65587737 bytes
->Flash cache emptied: 10838 bytes

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 17994475 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 11258520 bytes
RecycleBin emptied: 353989205 bytes

Total Files Cleaned = 1,101.00 mb


OTL by OldTimer - Version 3.2.31.0 log created on 01242012_180848

Files\Folders moved on Reboot…
File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot.
C:\Users\Austin\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

Registry entries deleted on Reboot…

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI