This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Computer just begininnng to slow down [Solved]

19 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have used Malwarebytes for years with no incidences. As of late, it starts popping up on the lower right hand side saying trial period is up,. Well, I have had it for years, so what trial. This board and I cleaned up my machine getting rid of a virus a few weeks ago just so you would know. I have unintalled it and gone to recommended sites and reinstalled it. Neither site indicated anything about it being a trial version. The malwarebytes would work for a couple of days and then quit and now it only works a day or two after installation and quite. Any ideqs?
:welcome:

Other users have reported the same thing, it may be a glitch in the program, what I would do is to completely uninstall it from your computer and download and install the latest version here
http://www.malwarebytes.org/products/malwarebytes_free/


The Pro Version offers a Protection Moduale, it will block access to known bad sites, the cost is minimal, a one time small fee and you own the program, no yearly fee, just store your key code and if you should sell this computer you can uninstall it and reinstall it on your new one with the same key code, but this of course is up to you. I currently have 3 systems up and running and have the pro version on all 3, wont go online without it.

http://www.malwarebytes.org/products/malwarebytes_pro/
I have worked with the tech team on this forum on cleaning up my computer of all viruses, which seems to still be okay,. But I just wanted to say my computer has just started slowing up and this is where it usually starts and then it stalls to a halt. All the websites, not one in particular, takes a little longer to open, things take a little longer to pop up on the screen. I sometimes get where it is so slow, I will turn the computer off and start again. This does help some. I have downloaded pictures, a few photo programs, not much else. I deleted a few programs with the uninstall with the program, and one with revo, but did not do anything when it suggested, with the registry. Now is there something I can do at this point…….to stop whatever is slowing it down…in its tracks. I do run malwarebytes and clean the cache periodically, but that doesn't do much, certainly not as much as when it was first cleaned. I went to a site given to me of programs not to download which was very helpful. I will always check that from now on. That list also suggested downloading Spyware blaster, which I did. I have been very careful with it, Yahoo is still a pain, but I can deal with that. Just want to know what to do now to prevent it from getting in such a bad way as before. Thanks.
I downloaded the malwarebytes from your link and this one only lasted 1 day. I really don't want to have to pay for a program that I had free since forever. Is there a program as good as malwarebytes that is free? Thanks.
It did run fun until we worked on it to get rid of the viruses. Ever since then, malwarebytes won't stay on. Is there some place you can on my computer to see if I accidentally got rid of something I shouldn't have?
I merged your other topic with this one, what we are going to do is have you run a couple of scans and see if there is any malware present

Download DDS from one of the links below to your desktop

Link 1
Link 2

  • Double click the tool to run it.
  • A black Screen will open, just read the contents and do nothing.
  • When the tool finishes, it will open 2 reports, DDS.txt and attach.txt
  • Copy/Paste the contents of 'DDS.txt' into your post.
  • 'attach.txt' should be zipped using Windows native zip utility and attached to your post. Compress and uncompress files (zip files)





aswMBR Log

Important! Please do not perform any fix options offered in aswMBR

Please download aswMBR to your desktop.


  • Double click the aswMBR icon to run it.
  • Click the Scan button to start scan.
  • If you are asked to update the Avast Virus database please allow it to do so.
  • When it finishes, press the Save Log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]
. DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 8.0.7601.17514 BrowserJavaVersion: 10.5.0 Run by [removed] at 20:59:51 on 2012-09-29 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3037.1980 [GMT -4:00] . AV: Microsoft Security Essentials *Enabled/Updated* {B140BF4E-23BB-4198-90AB-A51A4C60A69C} SP: Microsoft Security Essentials *Enabled/Updated* {0A215EAA-0581-4E16-AA1B-9E6837E7EC21} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Program Files\Microsoft Security Client\MsMpEng.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\system32\taskhost.exe C:\Program Files\ShadowExplorer\sesvc.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\system32\WUDFHost.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe C:\Program Files\Microsoft Security Client\msseces.exe C:\Windows\System32\hkcmd.exe C:\Windows\System32\igfxpers.exe C:\Program Files\Creative Home\Hallmark Card Studio 2012 Deluxe\Planner\PLNRnote.exe C:\Program Files\Microsoft Office2010\Office14\ONENOTEM.EXE C:\Windows\system32\SearchIndexer.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Windows\system32\svchost.exe -k SDRSVC C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE C:\Program Files\Macrium\Reflect\ReflectService.exe C:\Program Files\Microsoft Security Client\NisSrv.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_278.exe C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_278.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\conhost.exe C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uStart Page = mStart Page = hxxp://www.yahoo.com/?ilc=8&fr=mkg029 BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre7\bin\ssv.dll BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\mi4066~1\office14\URLREDIR.DLL BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre7\bin\jp2ssv.dll BHO: Yontoo: {fd72061e-9fde-484d-a58a-0bab4151cad8} - c:\program files\yontoo\YontooIEClient.dll mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe StartupFolder: c:\users\patty\appdata\roaming\micros~1\windows\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office2010\office14\ONENOTEM.EXE StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\eventp~1.lnk - c:\program files\creative home\hallmark card studio 2012 deluxe\planner\PLNRnote.exe mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office2010\office14\ONBttnIE.dll IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office2010\office14\ONBttnIELinkedNotes.dll DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://pcpitstop.com/betapit/PCPitStop.CAB DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab TCP: DhcpNameServer = [removed] [removed] [removed] TCP: Interfaces\{B3E4F083-98BF-476A-B54A-CA975B5E2AAD} : DhcpNameServer = [removed] [removed] [removed] Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL Notify: igfxcui - igfxdev.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\mi4066~1\office14\GROOVEEX.DLL . ================= FIREFOX =================== . FF - ProfilePath - c:\users\patty\appdata\roaming\mozilla\firefox\profiles\791mcddo.default-1346059307542\ FF - prefs.js: browser.startup.homepage - hxxp://us.mg5.mail.yahoo.com/neo/launch?.rand=dfcgl1kd68nre FF - plugin: c:\progra~1\mi4066~1\office14\NPAUTHZ.DLL FF - plugin: c:\progra~1\mi4066~1\office14\NPSPWRAP.DLL FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll FF - plugin: c:\program files\canon\easy-photoprint ex\NPEZFFPI.DLL FF - plugin: c:\program files\google\picasa3\npPicasa3.dll FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll FF - plugin: c:\program files\microsoft silverlight\4.1.10329.0\npctrlui.dll FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll FF - plugin: c:\users\patty\appdata\local\yahoo!\browserplus\2.9.8\plugins\npybrowserplus_2.9.8.dll FF - plugin: c:\users\patty\appdata\roaming\mozilla\firefox\profiles\791mcddo.default-1346059307542\extensions\{195a3098-0bd5-4e90-ae22-ba1c540afd1e}\plugins\npGarmin.dll FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_4_402_278.dll FF - plugin: c:\windows\system32\npDeployJava1.dll FF - plugin: c:\windows\system32\npmproxy.dll . —- FIREFOX POLICIES —- FF - user.js: extentions.y2layers.installId - af1784e8-9e4a-41b1-bda7-c43b2b63fbdf FF - user.js: extentions.y2layers.defaultEnableAppsList - Buzzdock,Buzzdock, FF - user.js: extensions.autoDisableScopes - 14 FF - user.js: security.csp.enable - false . ============= SERVICES / DRIVERS =============== . R0 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2012-8-30 193552] R0 pssnap;Paramount Software Snapshot Filter;c:\windows\system32\drivers\pssnap.sys [2012-9-25 16064] R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\common files\adobe\arm\1.0\armsvc.exe [2012-7-27 63960] R2 MBAMScheduler;MBAMScheduler;c:\program files\malwarebytes' anti-malware\mbamscheduler.exe [2012-9-27 399432] R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2012-9-27 676936] R2 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2011-4-27 99272] R2 ReflectService.exe;Macrium Reflect Image Mounting Service;c:\program files\macrium\reflect\ReflectService.exe [2012-9-25 224960] R2 sesvc;ShadowExplorer Service;c:\program files\shadowexplorer\sesvc.exe [2012-9-5 9216] R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-9-27 22856] R3 NisSrv;Microsoft Network Inspection;c:\program files\microsoft security client\NisSrv.exe [2012-9-12 287824] R3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000] R3 PSMounterEx;Macrium Reflect Image Explorer Driver;c:\windows\system32\drivers\psmounterex.sys [2012-9-25 54464] R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2011-6-10 394856] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-8-26 250288] S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888] S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\microsoft office2010\office14\GROOVE.EXE [2011-6-12 31125880] S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\mozilla maintenance service\maintenanceservice.exe [2012-5-10 113120] S3 PSMounter;Macrium Reflect Image Explorer Service;c:\windows\system32\drivers\psmounter.sys [2012-8-21 53952] S3 PSVolAcc;PSVolAcc;c:\windows\system32\drivers\PSVolAcc.sys [2012-9-25 12992] S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2012-2-12 52224] S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2010-9-1 1343400] . =============== Created Last 30 ================ . 2012-09-29 17:51:44 740784 —-a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{4d707080-597a-49ad-926d-4f6d2ed9fedc}\gapaengine.dll 2012-09-29 17:51:27 6980552 —-a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{5cb87ea4-bf91-4baf-865b-e2130125d5ec}\mpengine.dll 2012-09-29 00:34:43 118784 —-a-w- c:\windows\system32\MSSTDFMT.DLL 2012-09-29 00:34:25 ——– d—–w- c:\program files\SpywareBlaster 2012-09-28 07:14:16 514560 —-a-w- c:\windows\system32\qdvd.dll 2012-09-28 03:43:31 6980552 —-a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll 2012-09-27 23:07:38 22856 —-a-w- c:\windows\system32\drivers\mbam.sys 2012-09-27 23:07:38 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2012-09-26 15:39:42 245760 —-a-w- c:\windows\system32\OxpsConverter.exe 2012-09-25 14:31:50 54464 —-a-w- c:\windows\system32\drivers\psmounterex.sys 2012-09-25 14:31:50 16064 —-a-w- c:\windows\system32\drivers\pssnap.sys 2012-09-25 14:31:50 12992 —-a-w- c:\windows\system32\drivers\PSVolAcc.sys 2012-09-25 03:46:57 ——– d—–w- c:\programdata\WeCareReminder 2012-09-25 03:46:34 ——– d—–w- c:\users\patty\appdata\roaming\PhotoScape 2012-09-24 18:06:35 ——– d—–w- c:\users\patty\appdata\roaming\Scribus 2012-09-24 18:05:41 ——– d—–w- c:\program files\Scribus 1.4.1 2012-09-22 19:07:47 ——– d—–w- c:\users\patty\appdata\local\Deployment 2012-09-16 21:58:25 ——– d—–w- c:\users\patty\New folder (6) 2012-09-16 21:58:24 ——– d—–w- c:\users\patty\New folder (5) 2012-09-16 21:58:24 ——– d—–w- c:\users\patty\New folder (4) 2012-09-13 21:21:20 ——– d-sh–w- C:\$RECYCLE.BIN 2012-09-12 13:48:31 712048 —-a-w- c:\windows\system32\drivers\ndis.sys 2012-09-12 13:48:31 33280 —-a-w- c:\windows\system32\drivers\RNDISMP.sys 2012-09-12 13:48:31 240496 —-a-w- c:\windows\system32\drivers\netio.sys 2012-09-12 13:48:31 1292144 —-a-w- c:\windows\system32\drivers\tcpip.sys 2012-09-12 13:48:30 490496 —-a-w- c:\windows\system32\d3d10level9.dll 2012-09-12 13:48:30 187760 —-a-w- c:\windows\system32\drivers\FWPKCLNT.SYS 2012-09-08 22:41:23 ——– d—–w- c:\users\patty\appdata\local\LogMeIn Rescue Applet 2012-09-08 17:57:07 ——– d—–w- c:\program files\Yontoo 2012-09-08 02:20:58 ——– d—–w- c:\users\patty\2nd batch to burn 2012-09-08 02:15:19 ——– d—–w- c:\users\patty\new pics to burn 2012-09-07 22:47:21 ——– d—–w- c:\users\patty\appdata\roaming\Auslogics 2012-09-07 17:42:10 ——– d—–w- c:\program files\Auslogics 2012-09-05 15:27:03 ——– d—–w- c:\users\patty\Cindys camping 2012-09-01 18:44:05 ——– d—–w- c:\users\patty\appdata\local\temp 2012-09-01 15:57:28 ——– d—–w- c:\users\patty\appdata\local\Avanquest North America 2012-08-31 13:43:12 4278384 —-a-w- c:\programdata\microsoft\ehome\packages\mceclientux\updateablemarkup-2\markup.dll 2012-08-31 13:42:58 42776 —-a-w- c:\programdata\microsoft\ehome\packages\mceclientux\dsm-2\StartResources.dll 2012-08-31 02:03:50 193552 —-a-w- c:\windows\system32\drivers\MpFilter.sys . ==================== Find3M ==================== . 2012-09-19 14:55:05 73136 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-09-19 14:55:05 696240 —-a-w- c:\windows\system32\FlashPlayerApp.exe 2012-08-31 02:03:50 99272 —-a-w- c:\windows\system32\drivers\NisDrvWFP.sys 2012-08-24 16:57:48 981504 —-a-w- c:\windows\system32\wininet.dll 2012-08-24 15:20:39 1638912 —-a-w- c:\windows\system32\mshtml.tlb 2012-08-21 03:33:19 53952 —-a-w- c:\windows\system32\drivers\psmounter.sys 2012-07-18 17:47:53 2345984 —-a-w- c:\windows\system32\win32k.sys 2012-07-06 02:06:30 772544 —-a-w- c:\windows\system32\npDeployJava1.dll 2012-07-06 02:06:20 687544 —-a-w- c:\windows\system32\deployJava1.dll 2012-07-04 21:14:34 41984 —-a-w- c:\windows\system32\browcli.dll 2012-07-04 21:14:34 102912 —-a-w- c:\windows\system32\browser.dll 2011-11-16 19:20:55 584192 —-a-w- c:\program files\OTL.exe . ============= FINISH: 21:00:36.41 ===============
aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software Run date: 2012-09-29 21:12:01 —————————– 21:12:01.965 OS Version: Windows 6.1.7601 Service Pack 1 21:12:01.965 Number of processors: 2 586 0x170A 21:12:01.981 ComputerName: PATTI-PC UserName: Patty 21:12:03.588 Initialize success 21:13:08.511 AVAST engine defs: 12092901 21:13:18.916 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 21:13:18.932 Disk 0 Vendor: WDC_WD3200AAKS-75L9A0 01.03E01 Size: 305245MB BusType: 11 21:13:18.947 Disk 0 MBR read successfully 21:13:18.947 Disk 0 MBR scan 21:13:18.947 Disk 0 Windows 7 default MBR code 21:13:18.963 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048 21:13:18.979 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 305143 MB offset 206848 21:13:18.994 Disk 0 scanning sectors +625139712 21:13:19.072 Disk 0 scanning C:\Windows\system32\drivers 21:13:27.980 Service scanning 21:13:45.265 Modules scanning 21:13:51.988 Disk 0 trace - called modules: 21:13:52.019 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll ataport.SYS PCIIDEX.SYS msahci.sys 21:13:52.019 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8659d030] 21:13:52.019 3 CLASSPNP.SYS[8b7b459e] -> nt!IofCallDriver -> [0x860bb368] 21:13:52.035 5 ACPI.sys[8b2bf3d4] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0x860b4030] 21:13:53.049 AVAST engine scan C:\Windows 21:13:54.765 AVAST engine scan C:\Windows\system32 21:15:43.606 AVAST engine scan C:\Windows\system32\drivers 21:15:52.639 AVAST engine scan C:\Users\Patty 21:16:26.756 Disk 0 MBR has been saved successfully to "C:\Users\Patty\Desktop\MBR.dat" 21:16:26.756 The log file has been saved successfully to "C:\Users\Patty\Desktop\answer log.txt" 21:17:43.081 Disk 0 MBR has been saved successfully to "C:\Users\Patty\Desktop\MBR.dat" 21:17:43.081 The log file has been saved successfully to "C:\Users\Patty\Desktop\aswMBR.txt"
I have visited your website and read the info. I want to keep my computer clean. Would you suggest me installing all those programs you suggested and running them frequently? I have heard it both ways," too much spyware programs conflict with one another" and "you can-never have enuf safety programs" I don't think I have much of anything. And now my registry will never get clean since I don't use revo or the registry in c Cleaner. Will a full registry slow down your computer or cause problems?. I tried deleting this post because I remember all of you telling me "one thing at a time", but it won't delete. Just ignore it for now, ok :o
Your doing fine, dont worry about the posts.

See if you can uninstall this via Programs and Features in the Control Panel
c:\program files\yontoo


This is what I am concerned about, it could be a trojan or it maybe harmless
c:\windows\system32\qdvd.dll

When were done we can go over what programs to keep and not to keep


You need to enable windows to show all files and folders, instructions Here

Go to VirusTotal and submit this file for analysis, just use the browse feature and then Send File, if it says this file has been checked before, have them recheck it. When the scan is done just copy and paste the link back to this forum for me to see.

c:\windows\system32\qdvd.dll <– This file

If the site is busy you can try this one
http://virusscan.jotti.org/en
Not following you, did you check that file at VirusTotal, when it done checking , copy and past the link from the scan into this thread so I can see it
Is this what you wanted: [ArcaVir] 2012-09-30 Found nothing [F-Secure Anti-Virus] 2012-09-30 Found nothing [Avast! antivirus] 2012-09-30 Found nothing [G DATA] 2012-09-30 Found nothing [Grisoft AVG Anti-Virus] 2012-09-30 Found nothing [Ikarus] 2012-09-30 Found nothing [Avira AntiVir] 2012-09-30 Found nothing [Kaspersky Anti-Virus] 2012-09-30 Found nothing [Softwin BitDefender] 2012-09-30 Found nothing [Panda Antivirus] 2012-09-30 Found nothing [ClamAV] 2012-09-30 Found nothing [Quick Heal] 2012-09-30 Found nothing [CPsecure] 2012-09-30 Found nothing [Sophos] 2012-09-30 Found nothing [Dr.Web] 2012-09-30 Found nothing [VirusBlokAda VBA32] 2012-09-29 Found nothing [ESET] 2012-09-30 Found nothing [VirusBuster] 2012-09-30 Found nothing [Frisk F-Prot Antivirus] 2012-09-29 Found nothing

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI