This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Virus related keyboard issues [Solved]

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Malwarebytes Anti-Malware 1.60.0.1800 www.malwarebytes.org Database version: v2012.01.24.05 Windows Vista Service Pack 2 x64 NTFS Internet Explorer 8.0.6001.19170 Austin :: AUSTIN-PC [administrator] 1/24/2012 6:18:36 PM mbam-log-2012-01-24 (18-18-36).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 181945 Time elapsed: 4 minute(s), 41 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 1 C:\Users\Austin\Downloads\XvidSetup(1).exe (Adware.Agent) -> Quarantined and deleted successfully. (end)
I can already tell a nice difference in speed =) and I think you inadvertently may have also solved a completely different issue i was having if you wouldnt mind me throwing it by you then!
————-

OTL logfile created on: 1/24/2012 7:00:01 PM - Run 3
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Austin\Desktop
64bit-Windows Vista Ultimate Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19170)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 1.56 Gb Available Physical Memory | 39.15% Memory free
8.17 Gb Paging File | 5.32 Gb Available in Paging File | 65.11% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 222.09 Gb Total Space | 140.89 Gb Free Space | 63.43% Space Free | Partition Type: NTFS
Drive D: | 10.79 Gb Total Space | 1.80 Gb Free Space | 16.69% Space Free | Partition Type: NTFS
Drive E: | 7.82 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive F: | 931.51 Gb Total Space | 824.53 Gb Free Space | 88.52% Space Free | Partition Type: NTFS

Computer Name: AUSTIN-PC | User Name: Austin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Austin\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\SwiftKit\SwiftKit-RS.exe (Bluelight Developments)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - F:\Computer Files\iTunesHelper.exe (Apple Inc.)
PRC - C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files (x86)\Java\jre6\bin\jp2launcher.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files (x86)\Java\jre6\bin\java.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\WINDOWS\SMINST\BLService.exe ()
PRC - C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe (CyberLink)
PRC - C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe ()
PRC - C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe ()
PRC - C:\Program Files (x86)\DigitalPersona\Bin\DpAgent.exe (DigitalPersona, Inc.)
PRC - C:\Program Files (x86)\DigitalPersona\Bin\DpHostW.exe (DigitalPersona, Inc.)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)


========== Modules (No Company Name) ==========

MOD - C:\.jagex_cache_32\runescape\sw3d.dll ()
MOD - C:\.jagex_cache_32\runescape\jagmisc.dll ()
MOD - C:\.jagex_cache_32\runescape\jaclib.dll ()
MOD - C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ()
MOD - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32.dll ()
MOD - C:\Program Files (x86)\Java\jre6\bin\jp2iexp.dll ()
MOD - C:\Program Files (x86)\Java\jre6\bin\jp2native.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMediaLibrary.dll ()
MOD - C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvcPS.dll ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (avast! Antivirus) – C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV:64bit: - (CLPSLS) – C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe (COMODO)
SRV:64bit: - (cmdAgent) – C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (COMODO)
SRV:64bit: - (hpsrv) – C:\Windows\SysNative\Hpservice.exe (Hewlett-Packard Company)
SRV:64bit: - (STacSV) – C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_58be29c0\STacSV64.exe (IDT, Inc.)
SRV:64bit: - (vfsFPService) – C:\Windows\SysNative\vfsFPService.exe (Validity Sensors, Inc.)
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (SolidWorks Licensing Service) – C:\Program Files (x86)\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe (SolidWorks)
SRV - (clr_optimization_v4.0.30319_32) – C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (CoordinatorServiceHost) – F:\Computer Files\SOLIDWORKS\SolidWorks\swScheduler\DTSCoordinatorService.exe (Dassault Systèmes SolidWorks Corp.)
SRV - (Remote Solver for Flow Simulation 2009) – F:\Computer Files\SOLIDWORKS\SolidWorks Flow Simulation\binCFW\StandAloneSlv.exe (Mentor Graphics Corporation)
SRV - (YahooAUService) – C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (Recovery Service for Windows) – C:\WINDOWS\SMINST\BLService.exe ()
SRV - (QPCapSvc) QuickPlay Background Capture Service (QBCS) – C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe ()
SRV - (QPSched) QuickPlay Task Scheduler (QTS) – C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe ()
SRV - (DpHost) – C:\Program Files (x86)\DigitalPersona\Bin\DpHostW.exe (DigitalPersona, Inc.)
SRV - (vfsFPService) – C:\WINDOWS\SysWOW64\vfsFPService.exe (Validity Sensors, Inc.)
SRV - (IAANTMON) Intel® – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (aswSnx) – C:\Windows\SysNative\drivers\aswSnx.sys (AVAST Software)
DRV:64bit: - (aswSP) – C:\Windows\SysNative\drivers\aswSP.sys (AVAST Software)
DRV:64bit: - (aswRdr) – C:\Windows\SysNative\drivers\aswRdr.sys (AVAST Software)
DRV:64bit: - (aswTdi) – C:\Windows\SysNative\drivers\aswTdi.sys (AVAST Software)
DRV:64bit: - (aswMonFlt) – C:\Windows\SysNative\drivers\aswMonFlt.sys (AVAST Software)
DRV:64bit: - (aswFsBlk) – C:\Windows\SysNative\drivers\aswFsBlk.sys (AVAST Software)
DRV:64bit: - (cmderd) – C:\Windows\SysNative\DRIVERS\cmderd.sys (COMODO)
DRV:64bit: - (hpdskflt) – C:\Windows\SysNative\DRIVERS\hpdskflt.sys (Hewlett-Packard Company)
DRV:64bit: - (Accelerometer) – C:\Windows\SysNative\DRIVERS\Accelerometer.sys (Hewlett-Packard Company)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\Drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\DRIVERS\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (WpdUsb) – C:\Windows\SysNative\DRIVERS\wpdusb.sys (Microsoft Corporation)
DRV:64bit: - (STHDA) – C:\Windows\SysNative\DRIVERS\stwrt64.sys (IDT, Inc.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (NETw5v64) Intel® – C:\Windows\SysNative\DRIVERS\NETw5v64.sys (Intel Corporation)
DRV:64bit: - (NVHDA) – C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation)
DRV:64bit: - (RTL8169) – C:\Windows\SysNative\DRIVERS\Rtlh64.sys (Realtek Corporation )
DRV:64bit: - (JMCR) – C:\Windows\SysNative\DRIVERS\jmcr.sys (JMicron Technology Corporation)
DRV:64bit: - (vfs101a) – C:\Windows\SysNative\drivers\vfs101a.sys (Validity Sensors, Inc.)
DRV:64bit: - (enecir) – C:\Windows\SysNative\DRIVERS\enecir.sys (ENE TECHNOLOGY INC.)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\DRIVERS\iaStor.sys (Intel Corporation)
DRV:64bit: - (NETw3v64) Intel® – C:\Windows\SysNative\DRIVERS\NETw3v64.sys (Intel Corporation)
DRV:64bit: - (sdbus) – C:\Windows\SysNative\DRIVERS\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (HpqKbFiltr) – C:\Windows\SysNative\DRIVERS\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV:64bit: - (yukonx64) – C:\Windows\SysNative\DRIVERS\yk60x64.sys (Marvell)
DRV - ({55662437-DA8C-40c0-AADA-2C816A897A49}) – C:\Program Files (x86)\Hewlett-Packard\Media\DVD\000.fcl (Cyberlink Corp.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cnnb
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cnnb
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cnnb
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cnnb

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cnnb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://dm.startnow.com/?src=startpage&…ion=6.0-x64-SP2
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cnnb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Bing"


FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: F:\Computer Files\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2 [2008/09/04 01:13:47 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\DigitalPersona\Bin\FirefoxExt\ [2011/03/22 04:03:36 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2011/12/03 01:59:07 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/01/09 08:02:36 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\DigitalPersona\Bin\firefoxext [2011/03/22 04:03:36 | 000,000,000 | —D | M]

[2011/03/22 14:26:57 | 000,000,000 | —D | M] (No name found) – C:\Users\Austin\AppData\Roaming\Mozilla\Extensions
[2012/01/22 11:19:39 | 000,000,000 | —D | M] (No name found) – C:\Users\Austin\AppData\Roaming\Mozilla\Firefox\Profiles\6qkk5yg9.default\extensions
[2012/01/21 08:38:25 | 000,000,000 | —D | M] (Greasemonkey) – C:\Users\Austin\AppData\Roaming\Mozilla\Firefox\Profiles\6qkk5yg9.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}(24)
[2011/06/09 20:57:11 | 000,002,286 | —- | M] () – C:\Users\Austin\AppData\Roaming\Mozilla\Firefox\Profiles\6qkk5yg9.default\searchplugins\bing-zugo.xml
[2012/01/09 08:02:43 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/01/09 08:02:35 | 000,121,816 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011/09/02 18:25:59 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2010/01/01 03:00:00 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml.old
[2011/11/11 01:07:30 | 000,002,040 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2012/01/24 18:08:49 | 000,000,098 | —- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3:64bit: - HKLM\..\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O4:64bit: - HKLM..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO)
O4:64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe (Hewlett-Packard)
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [CLMLServer for HP TouchSmart] C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe (CyberLink)
O4 - HKLM..\Run: [COMODO] C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLA.exe (COMODO)
O4 - HKLM..\Run: [CPA] C:\Program Files\COMODO\COMODO GeekBuddy\VALA.exe (COMODO)
O4 - HKLM..\Run: [DpAgent] C:\Program Files (x86)\DigitalPersona\Bin\DpAgent.exe (DigitalPersona, Inc.)
O4 - HKLM..\Run: [DVDAgent] C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe (CyberLink Corp.)
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [hpqSRMon] File not found
O4 - HKLM..\Run: [iTunesHelper] F:\Computer Files\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [TSMAgent] C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe (CyberLink Corp.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.76.76 75.75.75.75
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{CFAFBF36-1EA3-43F7-95AC-67DCD91F600D}: DhcpNameServer = 75.75.76.76 75.75.75.75
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap11 - No CLSID value found
O20:64bit: - AppInit_DLLs: (C:\Windows\system32\guard64.dll) - C:\Windows\SysNative\guard64.dll (COMODO)
O20 - AppInit_DLLs: (C:\Windows\SysWOW64\guard32.dll) -C:\WINDOWS\SysWOW64\guard32.dll (COMODO)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) -C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Austin\Pictures\background.jpg
O24 - Desktop BackupWallPaper: C:\Users\Austin\Pictures\background.jpg
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2012/01/24 18:18:09 | 000,000,000 | —D | C] – C:\Users\Austin\AppData\Roaming\Malwarebytes
[2012/01/24 18:17:46 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/01/24 18:17:46 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2012/01/24 18:17:45 | 000,023,152 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2012/01/24 18:17:45 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012/01/24 18:16:43 | 010,847,608 | —- | C] (Malwarebytes Corporation ) – C:\Users\Austin\Desktop\mbam-setup-1.60.0.1800.exe
[2012/01/24 17:03:42 | 000,000,000 | —D | C] – C:\_OTL
[2012/01/24 16:20:05 | 000,000,000 | —D | C] – C:\Users\Austin\AppData\Roaming\WinRAR
[2012/01/24 16:20:05 | 000,000,000 | —D | C] – C:\Users\Austin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
[2012/01/24 16:20:05 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
[2012/01/24 16:19:54 | 000,000,000 | —D | C] – C:\Program Files\WinRAR
[2012/01/24 15:54:44 | 000,000,000 | —D | C] – C:\Program Files (x86)\Sony
[2012/01/24 15:17:07 | 000,000,000 | —D | C] – C:\Windows\SysNative\appmgmt
[2012/01/24 15:06:04 | 000,000,000 | —D | C] – C:\Users\Austin\Documents\OneNote Notebooks
[2012/01/24 14:57:59 | 000,000,000 | —D | C] – C:\Users\Austin\AppData\Roaming\Sony
[2012/01/24 14:57:59 | 000,000,000 | —D | C] – C:\Users\Austin\AppData\Local\Sony
[2012/01/24 03:43:56 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Users\Austin\Desktop\OTL.exe
[2012/01/22 12:14:21 | 000,000,000 | —D | C] – C:\ProgramData\SecTaskMan
[2012/01/22 11:31:41 | 001,689,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\lsasrv.dll
[2012/01/22 11:31:41 | 000,094,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\secur32.dll
[2012/01/20 16:51:00 | 000,000,000 | —D | C] – C:\Users\Austin\AppData\Roaming\Yahoo!
[2012/01/11 19:04:36 | 000,817,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2012/01/11 19:04:36 | 000,726,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2012/01/11 19:04:35 | 001,570,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\quartz.dll
[2012/01/11 19:04:35 | 001,314,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\quartz.dll
[2012/01/11 19:04:35 | 000,497,152 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\qdvd.dll
[2012/01/11 19:04:35 | 000,352,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\qdvd.dll
[2012/01/11 19:04:33 | 001,585,152 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntdll.dll
[2012/01/11 19:04:32 | 000,451,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winsrv.dll
[2012/01/11 19:04:32 | 000,211,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winmm.dll
[2012/01/11 19:04:32 | 000,048,128 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mcicda.dll
[2012/01/11 19:04:32 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mciwave.dll
[2012/01/11 19:04:32 | 000,028,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mciseq.dll
[2012/01/11 19:04:32 | 000,023,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mciseq.dll
[2012/01/11 19:04:31 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\packager.dll
[2012/01/11 19:04:31 | 000,066,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\packager.dll
[2012/01/07 00:37:16 | 000,000,000 | —D | C] – C:\Users\Austin\AppData\Local\{DE1B4FFD-4D8A-483F-A466-800BEF6320CD}
[2012/01/07 00:37:16 | 000,000,000 | —D | C] – C:\Users\Austin\AppData\Local\{1A957AAD-ED2D-4914-8773-FB7DB55882C8}
[2011/12/28 09:49:09 | 000,000,000 | —D | C] – C:\Users\Austin\AppData\Local\{D522E218-9F21-4DB7-9848-5199B20DACE8}
[2011/12/28 09:48:58 | 000,000,000 | —D | C] – C:\Users\Austin\AppData\Local\{01E59063-819C-47B0-A4D6-11E05CF4558B}
[2011/12/28 09:48:43 | 000,000,000 | —D | C] – C:\Users\Austin\Tracing
[2011/12/28 09:39:36 | 000,000,000 | —D | C] – C:\Program Files (x86)\Windows Live
[2011/12/28 09:37:30 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2011/12/28 09:36:36 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Silverlight
[2011/12/28 09:35:07 | 000,000,000 | —D | C] – C:\Users\Austin\AppData\Local\Windows Live
[2011/12/28 09:35:07 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Windows Live

========== Files - Modified Within 30 Days ==========

[2012/01/24 18:56:57 | 001,474,832 | —- | M] () – C:\Windows\SysNative\drivers\sfi.dat
[2012/01/24 18:43:25 | 000,000,032 | —- | M] () – C:\Users\Austin\jagex_cl_runescape_LIVE.dat
[2012/01/24 18:27:16 | 000,003,216 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/01/24 18:27:16 | 000,003,216 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/01/24 18:27:10 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/01/24 18:27:05 | 4292,026,368 | -HS- | M] () – C:\hiberfil.sys
[2012/01/24 18:17:47 | 000,000,948 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/01/24 18:17:17 | 010,847,608 | —- | M] (Malwarebytes Corporation ) – C:\Users\Austin\Desktop\mbam-setup-1.60.0.1800.exe
[2012/01/24 16:20:05 | 000,000,814 | —- | M] () – C:\Users\Public\Desktop\WinRAR.lnk
[2012/01/24 15:06:04 | 000,001,141 | —- | M] () – C:\Users\Austin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
[2012/01/24 03:44:00 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Austin\Desktop\OTL.exe
[2012/01/23 08:03:32 | 000,000,680 | —- | M] () – C:\Users\Austin\AppData\Local\d3d9caps.dat
[2012/01/22 11:05:17 | 591,182,210 | —- | M] () – C:\Windows\MEMORY.DMP
[2012/01/19 07:49:47 | 000,000,338 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForAustin.job
[2012/01/12 03:07:47 | 000,718,604 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/01/12 03:07:47 | 000,604,502 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/01/12 03:07:47 | 000,104,170 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/01/07 00:53:26 | 000,050,910 | —- | M] () – C:\Users\Austin\Documents\cc_20120107_005320.reg
[2012/01/07 00:38:34 | 000,000,770 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2012/01/07 00:34:13 | 000,300,624 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT

========== Files Created - No Company Name ==========

[2012/01/24 18:17:47 | 000,000,948 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/01/24 18:10:46 | 4292,026,368 | -HS- | C] () – C:\hiberfil.sys
[2012/01/24 16:20:05 | 000,000,814 | —- | C] () – C:\Users\Public\Desktop\WinRAR.lnk
[2012/01/24 15:06:04 | 000,001,141 | —- | C] () – C:\Users\Austin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
[2012/01/22 11:05:17 | 591,182,210 | —- | C] () – C:\Windows\MEMORY.DMP
[2012/01/07 00:53:22 | 000,050,910 | —- | C] () – C:\Users\Austin\Documents\cc_20120107_005320.reg
[2011/12/28 09:42:30 | 000,002,079 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk
[2011/12/02 12:43:00 | 000,010,316 | -HS- | C] () – C:\Users\Austin\AppData\Local\051010s8h520l360r552q3vbs5w6
[2011/12/02 12:43:00 | 000,010,316 | -HS- | C] () – C:\ProgramData\051010s8h520l360r552q3vbs5w6
[2011/07/17 19:05:09 | 000,000,000 | —- | C] () – C:\Users\Austin\AppData\Local\Temptable.xml
[2011/07/17 18:25:28 | 000,000,000 | —- | C] () – C:\Windows\eDrawingOfficeAutomator.INI
[2011/06/05 19:31:29 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2011/03/30 22:27:59 | 000,000,680 | —- | C] () – C:\Users\Austin\AppData\Local\d3d9caps.dat
[2011/03/26 05:26:01 | 000,117,248 | —- | C] () – C:\Windows\SysWow64\EhStorAuthn.dll
[2011/03/26 05:25:28 | 000,107,612 | —- | C] () – C:\Windows\SysWow64\StructuredQuerySchema.bin
[2011/03/26 05:24:59 | 000,368,640 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2011/03/23 06:10:36 | 000,018,904 | —- | C] () – C:\Windows\SysWow64\StructuredQuerySchemaTrivial.bin
[2011/03/23 02:35:02 | 000,000,732 | —- | C] () – C:\Users\Austin\AppData\Local\d3d9caps64.dat
[2011/03/22 04:06:54 | 000,111,846 | —- | C] () – C:\ProgramData\nvModes.001
[2011/03/22 04:00:02 | 000,111,846 | —- | C] () – C:\ProgramData\nvModes.dat
[2008/09/04 00:22:45 | 000,000,381 | —- | C] () – C:\ProgramData\hpqp.ini
[2008/09/03 23:46:08 | 000,107,386 | —- | C] () – C:\Windows\hpqins13.dat
[2008/01/20 21:49:10 | 000,060,124 | —- | C] () – C:\Windows\SysWow64\tcpmon.ini
[2007/11/14 18:17:34 | 000,204,800 | —- | C] () – C:\Windows\SysWow64\CogentBioSDK.dll
[2006/11/02 10:35:48 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 07:37:14 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2006/11/02 07:24:17 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2006/11/02 07:18:17 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat
[2006/11/02 04:47:54 | 000,043,131 | —- | C] () – C:\Windows\mib.bin

========== LOP Check ==========

[2011/10/22 22:52:11 | 000,000,000 | —D | M] – C:\Users\Austin\AppData\Roaming\DassaultSystemes
[2011/03/22 08:00:05 | 000,000,000 | —D | M] – C:\Users\Austin\AppData\Roaming\DigitalPersona
[2011/08/13 17:54:33 | 000,000,000 | —D | M] – C:\Users\Austin\AppData\Roaming\IM
[2012/01/24 15:53:16 | 000,000,000 | —D | M] – C:\Users\Austin\AppData\Roaming\Sony
[2011/12/03 02:31:22 | 000,000,000 | —D | M] – C:\Users\Austin\AppData\Roaming\TS3Client
[2012/01/24 16:54:51 | 000,000,000 | —D | M] – C:\Users\Austin\AppData\Roaming\uTorrent
[2012/01/24 18:25:55 | 000,026,712 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



< End of report >
:thumbup:

What other issues are you having ?



ESET Online Scanner
I'd like us to scan your machine with ESET OnlineScan

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the [external image: Posted Image] button.
  • Push [external image: Posted Image]
Please make sure you include the following items in your next post:
The log that was produced after running ESET Online Scanner.
ill give you the rundown on it before i do those next steps so you can think about it, because im completely baffled by this… i run dual screens (laptop n secondary monitor) so my laptop screen seemed to die per se, it would work during part of the boot up, but it seemed like there was no back light. and then sometime through the bootup/login stage it would turn completely off. (had 2 make my secondary my primary) but if i was logged in and at my desktop, if i closed and opened the laptop, the screen would work for like 20 seconds, just enough to drag all my stuff over to the secondary. Pretty much all my friends assumed that it was a hardware malfunction, maybe a loose solder joint or something along those lines. but now today when you had me boot through safe mode it stayed on, and after i ran the programs when i went back to the normal login it is currently still on (kinda too scared to move everything back over to the laptop monitor) have you ever heard of something like that happening, or maybe know some way to test to make sure it wont die on me again? *i am going to read your instructions and start in on that all now*
I dont know whats going on with your monitor, but running it in safemode which basically loads windows with just the basic drivers and it still works leads me to believe you may have a bad driver that needs updating, lets finish up here and make sure your clear from all malware and then I can link you to our windows forum that can help you sort all that out
an hour and 20 mins later and we finally have the results =) dunno what the vegas stuff is, but i can see you were right about the utorrent music, look's like i will be avoiding that one from here out —— C:\Users\Austin\Downloads\Sony vegas pro 11 crack and keygen.rar probably a variant of Win32/Agent.BCOVDCM trojan C:\Users\Austin\Downloads\XvidSetup.exe multiple threats F:\Computer Files\New Music\Legion Of Doom - God is dead.mp3 a variant of WMA/TrojanDownloader.GetCodec.gen trojan F:\Computer Files\New Music\rawkfist(Club RMX).mp3 a variant of WMA/TrojanDownloader.GetCodec.gen trojan F:\Computer Files\Torrents\Sony Vegas Pro 10 Keygen.rar a variant of Win32/Packed.VMProtect.AAD trojan
Lets run this scanner

Download CKScanner by askey127 from Here & save it to your Desktop.
  • Doubleclick CKScanner.exe then click Search For Files
  • When the cursor hourglass disappears, click Save List To File
  • A message box will verify the file saved
  • Please Run this program only once
  • Double-click the CKFiles.txt icon on your desktop then copy/paste the contents in your next reply
CKScanner - Additional Security Risks - These are not necessarily bad c:\users\austin\downloads\keygen.zip c:\users\austin\downloads\rebuilt.keygen.zip c:\users\austin\downloads\sony vegas pro 11 crack and keygen.rar c:\users\austin\downloads\keygen\onenote table of contents.onetoc2 scanner sequence 3.BB.11.NGAPEE —– EOF —–
Let me explain to you in detail how you infected this computer. You downloaded and installed illegal software via the torrents. All Cracked/Keygens are infected, Do the math, why would a site let you download Sony Vegas Pro 10 for free ??. This forum and all the rest of the Malware Removal forums do not support the use of illegal software except for there removal. If I was to continue helping you it could be construed in the eyes of the law as aiding and abetting a crime.

Sony Vegas Pro 10 <–If you want to continue with the cleaning than I need you to uninstall this program via Programs and Features in the Control Panel. After its uninstalled, run CKScanner again and post a NEW log.

If I dont hear back from you in 24 hours, this thread will be closed and no further help will be offered
Hey, I personally didn't install any of that vegas stuff, I am guilty of some music, but like I said I will not be getting utorrent or any downloading program back, this computer I am using is shared by multiple people. I will have a chat with the rest of my family who uses it and make sure that they do not continue to do so. Again, I'm sorry.
I went through and uninstalled it, searched for anything else in my computer that said "vegas" or "keygen" so i believe it is now all gone —————————– CKScanner - Additional Security Risks - These are not necessarily bad scanner sequence 3.RP.11.JMCPBN —– EOF —–
it seems like everything is running a lot faster, is there any free antivirus you would recommend, right now i believe i have comodo and avast, but the avast ran out of the free trial i believe but says that it is still protecting if that makes sense
Why dont you give this one a try, I have not used it myself but have heard a lot of good feedback from people that have installed it and its free

http://windows.microsoft.com/en-GB/windows…rity-essentials


BUT, you should not have two Antivirus programs running, more than one is overkill and can severely hamper system performance so uninstall comodo and avast prior to downloading and installing the new one.

If your still having issues with your monitor you can post here for help, as we just do malware removal on this one

http://forums.whatthetech.com/index.php?showforum=119





Open OTL and click on Clean Up and it will remove programs we used to clean your system along with there backups, any programs that where not removed you can just drag to the trash.


Malwarebytes is the free version and yours to keep and will not be removed


  • How did I get infected in the first place ?
    Read these links and find out how to prevent getting infected again.
  • Tutorial for System Restore <– Do this first to prevent yourself from being reinfected.
  • WhattheTech
  • Grinler BleepingComputer
  • GeeksTo Go
  • Dslreports


Safe Surfn
Ken

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI