This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Computer slow to respond/"not responding" [Solved]

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

As of late my computer has been really slow to respond. I often get "not responding" messages on Firefox, for example. It will clear itself up after a few agonizing seconds (usually, say, 5 seconds, but sometimes 30-60). I know that I don't have the newest/fastest machine ever built, but it hasn't always been like this. I'd appreciate your help seeing if there are any infections.

Thank you for your help. Here is the HijackThis log (fwiw, I ran this under the Admin user instead of any of the normal users):

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:53:45 PM, on 10/2/2012
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16450)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Highresolution Enterprises\X-Mouse Button Control\XMouseButtonControl.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\System32\ico.exe
C:\Windows\System32\Pmxmiced.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\System32\wpcumi.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Windows\vVX6000.exe
C:\Boinc\boincmgr.exe
C:\Boinc\boinctray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Real\RealPlayer\Update\realsched.exe
C:\Program Files\HP\HP Software Update\hpwuschd2.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
C:\Program Files\Software Informer\softinfo.exe
C:\Program Files\HP\HP Officejet 6700\Bin\ScanToPCActivationApp.exe
C:\Program Files\MozyHome\mozystat.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Admin\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qwest.live.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qwest.live.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://qwest.live.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Qwest
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {0A87E45F-537A-40B4-B812-E2544C21A09F} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: LastPass Vault - {95D9ECF5-2A4D-4550-BE49-70D42F71296E} - C:\Program Files\LastPass\LPToolbar.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
O3 - Toolbar: LastPass Toolbar - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files\LastPass\LPToolbar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [PMX Daemon] ICO.EXE
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [WPCUMI] C:\Windows\system32\WpcUmi.exe
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [VX6000] C:\Windows\vVX6000.exe
O4 - HKLM\..\Run: [USB2Check] RUNDLL32.EXE "C:\Windows\system32\PCLECoInst.dll",CheckUSBController
O4 - HKLM\..\Run: [USBToolTip] "C:\Program Files\Pinnacle\Shared Files\\Programs\USBTip\USBTip.exe"
O4 - HKLM\..\Run: [boincmgr] "C:\Boinc\boincmgr.exe" /a /s
O4 - HKLM\..\Run: [boinctray] "C:\Boinc\boinctray.exe"
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TkBellExe] "c:\program files\real\realplayer\Update\realsched.exe" -osboot
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [avast] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jaureg.exe" -u auto-update
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe"
O4 - HKCU\..\Run: [LaunchList] C:\Program Files\Pinnacle\Studio 11\LaunchList2.exe
O4 - HKCU\..\Run: [Software Informer] "C:\Program Files\Software Informer\softinfo.exe" -autorun
O4 - HKCU\..\Run: [HP Officejet 6700 (NET)] "C:\Program Files\HP\HP Officejet 6700\Bin\ScanToPCActivationApp.exe" -deviceID "CN25J3G0QN05RQ:NW" -scfn "HP Officejet 6700 (NET)" -AutoStart 1
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-2127996226-1381386841-1715129570-1007\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'boinc_master')
O4 - HKUS\S-1-5-21-2127996226-1381386841-1715129570-1007\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet (User 'boinc_master')
O4 - HKUS\S-1-5-21-2127996226-1381386841-1715129570-1007\..\Run: [Software Informer] "C:\Program Files\Software Informer\softinfo.exe" -autorun (User 'boinc_master')
O4 - HKUS\S-1-5-21-2127996226-1381386841-1715129570-1007\..\Run: [fsm] (User 'boinc_master')
O4 - S-1-5-21-2127996226-1381386841-1715129570-1007 Startup: Install LastPass FF RunOnce.lnk = C:\Program Files\Common Files\lpuninstall.exe (User 'boinc_master')
O4 - S-1-5-21-2127996226-1381386841-1715129570-1007 Startup: Install LastPass IE RunOnce.lnk = C:\Program Files\Common Files\lpuninstall.exe (User 'boinc_master')
O4 - S-1-5-21-2127996226-1381386841-1715129570-1007 User Startup: Install LastPass FF RunOnce.lnk = C:\Program Files\Common Files\lpuninstall.exe (User 'boinc_master')
O4 - S-1-5-21-2127996226-1381386841-1715129570-1007 User Startup: Install LastPass IE RunOnce.lnk = C:\Program Files\Common Files\lpuninstall.exe (User 'boinc_master')
O4 - Startup: Monitor Ink Alerts - HP Officejet 6700 (Network).lnk = ?
O4 - Global Startup: AVer HID Receiver.lnk = C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe
O4 - Global Startup: AVerQuick.lnk = C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerQuick.exe
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: MozyHome Status.lnk = C:\Program Files\MozyHome\mozystat.exe
O4 - Global Startup: Secunia PSI Tray.lnk = C:\Program Files\Secunia\PSI\psi_tray.exe
O4 - Global Startup: WDDMStatus.lnk = C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe
O4 - Global Startup: WDSmartWare.lnk = C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe
O4 - Global Startup: ZDWLan Utility.lnk = C:\Program Files\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\ZDWlan.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: LastPass - file://C:\Users\Admin\AppData\LocalLow\LastPass\context.html?cmd=lastpass
O8 - Extra context menu item: LastPass Fill Forms - file://C:\Users\Admin\AppData\LocalLow\LastPass\context.html?cmd=fillforms
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~3\Office14\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: LastPass - {43699cd0-e34f-11de-8a39-0800200c9a66} - C:\Program Files\LastPass\LPToolbar.dll
O9 - Extra 'Tools' menuitem: LastPass - {43699cd0-e34f-11de-8a39-0800200c9a66} - C:\Program Files\LastPass\LPToolbar.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Qwest Live - {A5AC7E90-4FCC-4525-8C81-3706621C8671} - http://qwest.live.com (file missing) (HKCU)
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} - http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.4.5.cab
O16 - DPF: {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} (DellSystemLite.Scanner) - http://support.dell.com/systemprofiler/DellSystemLite.CAB
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Windows\system32\AERTSrv.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: AVerRemote - AVerMedia - C:\Program Files\Common Files\AVerMedia\Service\AVerRemote.exe
O23 - Service: AVerScheduleService - Unknown owner - C:\Program Files\Common Files\AVerMedia\Service\AVerScheduleService.exe
O23 - Service: WORLDC~1|World Community Grid (BOINC) - World Community Grid - C:\Boinc\boinc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: MozyHome Backup Service (mozybackup) - Mozy, Inc. - C:\Program Files\MozyHome\mozybackup.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PCLEPCI - Pinnacle Systems GmbH - C:\Windows\system32\drivers\pclepci.sys
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: Secunia PSI Agent - Secunia - C:\Program Files\Secunia\PSI\PSIA.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - Unknown owner - C:\Program Files\Dell Support Center\bin\sprtsvc.exe (file missing)
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
O23 - Service: ASUS Virtual MFP Service (UsbService) - Unknown owner - C:\Program Files\ASUS\Printer Utilities\UsbService.exe
O23 - Service: WD SmartWare Drive Manager (WDDMService) - WDC - C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe
O23 - Service: WD SmartWare Background Service (WDSmartWareBackgroundService) - Memeo - C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
O23 - Service: XMouseButton Launcher - Highresolution Enterprises - C:\Program Files\Highresolution Enterprises\X-Mouse Button Control\XMouseButtonSvc.exe

–
End of file - 16106 bytes
Hello and welcome to What the Tech.

My name is Michael and I will be helping you with your computer problems.


Please keep the following points in mind:
  • Malware research is often a time consuming process and sometimes multiple tools/methods will have to be employed before an infection is completely dealt with. Please be patient during the process of removal.
  • Read my instructions carefully before carrying them out. Also, consider printing out any instructions in case you lose your Internet connection.
  • If you have any questions, please ask before carrying out a fix. Clearing up any confusion beforehand will save time in the long run. That said, I will try to post instructions as clearly and concisely as possible.
  • Please reply to this thread. Do not start a new topic, and do not request help on other forums during the course of the cleaning process.
  • If you do not reply after three (3) days, your thread will be closed.
IMPORTANT NOTE: Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.


  • OTL

    Download OTL to your desktop.

  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Select All Users
  • Under the Custom Scan box paste this in
    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    /md5stop
    %systemroot%\*. /rp /s
    DRIVES
    CREATERESTOREPOINT
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan won't take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Post both logs

[*]aswMBR


Please download aswMBR and save it to your desktop.

  • Double click aswMBR.exe to start the tool.
  • When prompted to download virus definitions, please do so.
  • Click Scan. Note: Do NOT attempt any Fix yet.
  • When the scan completes, click Save log, save it to your desktop and post it in your next reply.
  • There should also be another file that is created on your desktop named MBR.dat. Please right-click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well.
First of all, thanks for your help, Michael.

Secondly, attached are the two OTL logs, the aswMBR log, & the zipped MBR.dat.

Oh, a couple of things about aswMBR.exe. It did not prompt me to download the virus definitions. Also, and I know I'm being very "anal" on this point, the default was a "quick scan", so I went with it. That's all just "fyi" so that you know what's going on & whether I missed a step or something.

Thank you,
###
Thanks for those logs. Please work your way through the following steps:

  • TDSSKiller

    Please download TDSSKiller.zip

    • Extract it to your desktop
    • Double click TDSSKiller.exe
    • When the window opens, click on Change parameters
    • Under ”Additional options”, put a check mark in the box next to “Detect TDLFS file system”
    • Click OK
    • Press Start Scan
      • IMPORTANT: As we are only looking for a log of what is on the machine right now, choose to Skip whatever is found
      • Then click Continue
    • Copy and paste the log in your next reply
      • A copy of the log will be saved automatically to the root of the drive (typically C:\)
  • ComboFix

    Refer to the ComboFix User's Guide


    • Download ComboFix from HERE.

      * IMPORTANT !!! Place ComboFix.exe on your Desktop
    • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with ComboFix.
      You can get help on disabling your protection programs here
    • Double click on ComboFix.exe & follow the prompts.
    • Your desktop may go blank. This is normal. It will return when ComboFix is done. ComboFix may reboot your machine. This is normal.
    • When finished, it shall produce a log for you. Post that log in your next reply

      Note:
      Do not mouse click ComboFix's window whilst it's running. That may cause it to stall.


      ———————————————————————————————
    • Ensure your AntiVirus and AntiSpyware applications are re-enabled.

      ———————————————————————————————

    NOTE: If you encounter a message "illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error.
Thanks. If you would, please copy and paste the logs from now on instead of attaching.

  • AdwCleaner

    Download AdwCleaner from here and save it to your desktop.

    • Run AdwCleaner and select Delete
    • Once done it will ask to reboot, allow the reboot
    • On reboot a log will be produced, please attach the content of the log to your next reply
  • Malwarebytes' Anti-Malware

    I see you already have MBAM on your computer. Please do the following:

    • Once the program has loaded, click the Update tab and Check for Updates.
    • Click the Scanner tab, select Perform quick scan, then click Scan.
    • When the scan is complete, click OK, then Show Results to view the results.
    • Be sure that everything is checked, and click Remove Selected.
    • When completed, a log will open in Notepad. This log is saved by MBAM and can be viewed by clicking the Logs tab.
    • Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log. Please paste the results in your next reply.
    • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
  • ESET Online Scanner

    Please disable any real-time security programs such as your anti-virus before proceeding with this scan.

    • Open Internet Explorer.
    • Download ESET Online Scanner.
    • Put a checkmark in the checkbox next to YES, I accept the Terms of Use.
    • Click Start.
    • When prompted by your web browser, click Install.
    • Uncheck Remove found threats.
    • Check Scan archives.
    • Click Start and let the scanner finish downloading virus signatures. The scan will begin afterward.
    • When the scan completes, click List of found threats.
    • Click Export to text file… and save the file to your desktop. Post it in your next reply.
    • Click Back.
    • Click Finish.
Here are the results of those scans:

AdwCleaner

# AdwCleaner v2.003 - Logfile created 10/06/2012 at 13:32:21
# Updated 23/09/2012 by Xplode
# Operating system : Windows Vista ™ Home Premium Service Pack 2 (32 bits)
# User : Admin - HOME-PC
# Boot Mode : Normal
# Running from : C:\Users\Admin\Desktop\AdwCleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

Folder Deleted : C:\Program Files\Free Offers from Freeze.com
Folder Deleted : C:\Users\Admin\AppData\Roaming\OpenCandy

***** [Registry] *****

Key Deleted : HKCU\Software\AppDataLow\AskToolbarInfo
Key Deleted : HKCU\Software\AppDataLow\Software\AskToolbar
Key Deleted : HKCU\Software\Ask.com
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Key Deleted : HKLM\Software\Freeze.com
Key Deleted : HKLM\Software\Informer Technologies, Inc.\OpenCandy

***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16421

Restored : [HKCU\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Restored : [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Restored : [HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Restored : [HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Restored : [HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Restored : [HKU\S-1-5-21-2127996226-1381386841-1715129570-1007\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]

-\\ Mozilla Firefox v15.0.1 (en-US)

Profile name : default
File : C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\2u5n2yy2.default\prefs.js

Deleted : user_pref("extensions.asktb.cbid", "QA");
Deleted : user_pref("extensions.asktb.default-channel-url-mask", "hxxp://www.ask.com/web?q={query}&o={o}&l={l}[…]
Deleted : user_pref("extensions.asktb.dtid", "YYYYYYYYUS");
Deleted : user_pref("extensions.asktb.fresh-install", false);
Deleted : user_pref("extensions.asktb.l", "dis");
Deleted : user_pref("extensions.asktb.last-config-req", "1287857999989");
Deleted : user_pref("extensions.asktb.locale", "en_US");
Deleted : user_pref("extensions.asktb.o", "102400");
Deleted : user_pref("extensions.asktb.overlay-reloaded-using-restart", true);
Deleted : user_pref("extensions.asktb.qsrc", "2871");
Deleted : user_pref("extensions.asktb.r", "6");
Deleted : user_pref("extensions.asktb.search-suggestions-enabled", true);

Profile name : default
File : C:\Users\Marianne\AppData\Roaming\Mozilla\Firefox\Profiles\mvssqwue.default\prefs.js

[OK] File is clean.

*************************

AdwCleaner[S1].txt - [2878 octets] - [06/10/2012 13:32:21]

########## EOF - C:\AdwCleaner[S1].txt - [2938 octets] ##########


Malwarebytes

Malwarebytes Anti-Malware 1.65.0.1400
www.malwarebytes.org

Database version: v2012.10.06.05

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
Admin :: HOME-PC [administrator]

10/6/2012 1:43:45 PM
mbam-log-2012-10-06 (13-43-45).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 261021
Time elapsed: 9 minute(s), 1 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)


ESET - "No Threats Found"


Thanks,
###
Java is out of date

Open up your Start menu and start typing programs and features until the applet appears so you can open it. Find and remove any instances of Java.

Now go to here to download the latest Java installer. Go through the installation process.

Clear Java cache

Go into the Control Panel and double-click the Java icon (looks like a coffee cup). If you do not see the icon, switch to Classic View.

  • On the General tab, under Temporary Internet Files, click the Settings button.
  • Next, click on the Delete Files button
  • Leave the default boxes checked
  • Click OK on Delete Files and Applications window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • You may now close the Java control panel.

NEXT:

Your events log indicated some problems with your file system. Please do the following:

Open up your start menu and type cmd. Right-click cmd and select Run as administrator.

At the command prompt, type chkdsk c: /r (note the spaces) and then hit Enter. Agree to run chkdsk on next startup, and then reboot.

Please let me know how your PC is running after the chkdsk runs.

Are you still with me, 1695814?

Yes, thank you.

I've updated the java.

The chkdsk took quite a while to run.

Then, because of other obligations, I was unable to do anything computer-related yesterday & until now today.

Let me give it a whirl & I'll report back no later than tomorrow on how things are going.

Thanks a bunch,
###
I would say that things are pretty much back to normal. I haven't experienced any agonizing slow downs as before.

Interestingly, however, today a windows message popped up:

[yellow triangle w/ "!"] Do you want to change the color scheme to improve performance?
The current color scheme, Windows Vista Aero, is using most of its dedicated memory, which can result in slower computer performance. To free up some memory for better computer performance, try closing some open window or changing the color scheme to Windows Vista Basic.
[green arrow] Keep the current color scheme
[green arrow] Change the color scheme to Windows Vista Basic


For now, I chose "Keep the current color scheme".

Is there anything else that you'd like me to do?
Please run OTL again using the instructions from earlier. It should only produce one log this time. Copy and paste its contents in your next reply (no need to use a quote box).
Here's the OTL.txt:

OTL logfile created on: 10/9/2012 8:21:19 PM - Run 2
OTL by OldTimer - Version 3.2.70.2 Folder = C:\Users\Admin\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 0.89 Gb Available Physical Memory | 44.42% Memory free
4.23 Gb Paging File | 2.49 Gb Available in Paging File | 58.94% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 222.78 Gb Total Space | 70.73 Gb Free Space | 31.75% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 6.15 Gb Free Space | 61.54% Space Free | Partition Type: NTFS
Drive G: | 442.98 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
Drive H: | 930.86 Gb Total Space | 788.33 Gb Free Space | 84.69% Space Free | Partition Type: NTFS

Computer Name: HOME-PC | User Name: Admin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/10/04 19:31:48 | 000,601,088 | —- | M] (OldTimer Tools) – C:\Users\Admin\Desktop\OTL.exe
PRC - [2012/08/21 04:12:26 | 004,282,728 | —- | M] (AVAST Software) – C:\Program Files\Alwil Software\Avast5\AvastUI.exe
PRC - [2012/08/21 04:12:25 | 000,044,808 | —- | M] (AVAST Software) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
PRC - [2012/08/02 12:43:22 | 004,528,528 | —- | M] (Mozy, Inc.) – C:\Program Files\MozyHome\mozystat.exe
PRC - [2012/07/27 15:51:26 | 000,063,960 | —- | M] (Adobe Systems Incorporated) – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012/07/17 07:40:36 | 000,296,056 | —- | M] (RealNetworks, Inc.) – C:\Program Files\Real\RealPlayer\Update\realsched.exe
PRC - [2012/06/23 10:49:02 | 000,865,792 | —- | M] (Highresolution Enterprises) – C:\Program Files\Highresolution Enterprises\X-Mouse Button Control\XMouseButtonControl.exe
PRC - [2012/06/23 10:48:50 | 000,073,216 | —- | M] (Highresolution Enterprises) – C:\Program Files\Highresolution Enterprises\X-Mouse Button Control\XMouseButtonSvc.exe
PRC - [2012/06/06 04:39:34 | 000,843,264 | —- | M] () – C:\Boinc\Data\projects\www.worldcommunitygrid.org\wcgrid_gfam_vina_prod_x86.exe.6.12
PRC - [2012/06/06 04:39:32 | 000,507,904 | —- | M] () – C:\Boinc\Data\projects\www.worldcommunitygrid.org\wcgrid_gfam_vina_6.12_windows_intelx86
PRC - [2011/12/13 23:09:20 | 001,215,816 | —- | M] (PC-Doctor, Inc.) – C:\Program Files\Dell Support Center\pcdrcui.exe
PRC - [2011/12/13 20:36:04 | 000,158,208 | —- | M] (PC-Doctor, Inc.) – C:\Program Files\Dell Support Center\pcdrsysinfosoftware.p5x
PRC - [2011/09/09 16:01:16 | 001,804,648 | —- | M] (Hewlett-Packard Co.) – C:\Program Files\HP\HP Officejet 6700\Bin\ScanToPCActivationApp.exe
PRC - [2011/09/09 15:49:30 | 000,643,944 | —- | M] (Hewlett-Packard Co.) – C:\Program Files\HP\HP Officejet 6700\Bin\HPNetworkCommunicator.exe
PRC - [2011/07/14 12:43:42 | 002,875,461 | —- | M] (Informer Technologies, Inc.) – C:\Program Files\Software Informer\softinfo.exe
PRC - [2011/04/22 07:21:10 | 000,247,728 | —- | M] (TomTom) – C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
PRC - [2011/04/22 07:21:10 | 000,092,592 | —- | M] (TomTom) – C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
PRC - [2011/03/04 13:36:13 | 001,253,376 | —- | M] (The Scripps Research Institute and IBM Corporation) – C:\Boinc\Data\projects\www.worldcommunitygrid.org\wcg_hfcc_autodock_6.40_windows_intelx86
PRC - [2010/12/21 07:04:30 | 000,987,704 | —- | M] (Secunia) – C:\Program Files\Secunia\PSI\psia.exe
PRC - [2010/09/23 19:59:44 | 004,543,232 | —- | M] (World Community Grid) – C:\Boinc\boincmgr.exe
PRC - [2010/09/23 19:59:42 | 000,058,112 | —- | M] (Space Sciences Laboratory) – C:\Boinc\boinctray.exe
PRC - [2010/09/23 19:59:40 | 000,537,344 | —- | M] (World Community Grid) – C:\Boinc\boinc.exe
PRC - [2010/08/10 08:37:22 | 000,217,088 | R— | M] () – C:\Program Files\ASUS\Printer Utilities\UsbService.exe
PRC - [2010/05/20 15:27:24 | 000,139,632 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft LifeCam\MSCamS32.exe
PRC - [2010/01/29 01:04:26 | 000,764,784 | —- | M] (Microsoft Corporation
) – C:\Windows\vVX6000.exe
PRC - [2010/01/21 17:24:08 | 000,110,592 | —- | M] (WDC) – C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe
PRC - [2009/06/16 09:58:08 | 000,020,480 | —- | M] (Memeo) – C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe
PRC - [2009/04/11 01:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) – C:\Windows\explorer.exe
PRC - [2008/07/14 05:42:22 | 000,409,600 | R— | M] () – C:\Program Files\Common Files\AVerMedia\Service\AVerScheduleService.exe
PRC - [2008/06/06 11:41:22 | 000,352,256 | R— | M] (AVerMedia) – C:\Program Files\Common Files\AVerMedia\Service\AVerRemote.exe
PRC - [2008/01/17 07:22:20 | 004,907,008 | —- | M] (Realtek Semiconductor) – C:\Windows\RtHDVCpl.exe
PRC - [2007/12/05 06:17:24 | 000,077,824 | —- | M] (Andrea Electronics Corporation) – C:\Windows\System32\AERTSrv.exe
PRC - [2007/09/12 18:27:24 | 000,554,352 | —- | M] (Symantec Corporation) – C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
PRC - [2007/03/15 11:09:36 | 000,460,784 | —- | M] (Gteko Ltd.) – C:\Program Files\DellSupport\DSAgnt.exe
PRC - [2007/03/12 18:30:14 | 000,517,768 | —- | M] (Symantec Corporation) – C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
PRC - [2006/11/23 15:13:38 | 000,126,976 | —- | M] (Primax Electronics Ltd.) – C:\Windows\System32\pmxmiced.exe
PRC - [2006/11/08 14:01:54 | 000,049,152 | —- | M] (Primax Electronics Ltd.) – C:\Windows\System32\ico.exe
PRC - [2006/11/02 07:35:35 | 000,176,128 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wpcumi.exe


========== Modules (No Company Name) ==========

MOD - [2012/06/14 04:06:31 | 012,433,920 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\f2691cfa7671cdc58179e56ba9227591\System.Windows.Forms.ni.dll
MOD - [2012/06/14 04:06:20 | 001,592,320 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\18f9789aa214c657113e676b3a9015aa\System.Drawing.ni.dll
MOD - [2012/06/14 04:06:02 | 014,329,856 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\7343fbab1ba137db2f8b284047ef3f3c\PresentationFramework.ni.dll
MOD - [2012/06/14 04:05:29 | 012,219,392 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\7b6293b0c23321c255c2530aea8e32bb\PresentationCore.ni.dll
MOD - [2012/05/12 04:43:36 | 000,971,264 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\bd76aaaa03ddc15d1840207b5a480644\System.Configuration.ni.dll
MOD - [2012/05/12 04:41:36 | 005,450,752 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\d2630342a066a7cb9056d9eb6157687a\System.Xml.ni.dll
MOD - [2012/05/12 04:36:18 | 002,295,296 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\0f2b877ed16daa577f95be735a63d19c\System.Core.ni.dll
MOD - [2012/05/12 04:36:08 | 000,368,128 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\c8c3ab08933fef9fb6657da871395c46\PresentationFramework.Aero.ni.dll
MOD - [2012/05/12 04:35:23 | 003,325,952 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\54426ee1881b42af5b090e223f43823c\WindowsBase.ni.dll
MOD - [2012/05/12 04:35:18 | 007,953,408 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System\28d633338fc8d29f8af31935ef7d001b\System.ni.dll
MOD - [2012/05/12 04:35:08 | 011,492,352 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\af9c9e9d7e0523cd444f8b551baa9cbf\mscorlib.ni.dll
MOD - [2011/12/13 20:36:04 | 000,483,328 | —- | M] () – C:\Program Files\Dell Support Center\libAsapiCSharp.dll
MOD - [2011/12/13 20:36:04 | 000,098,304 | —- | M] () – C:\Program Files\Dell Support Center\libCSharpCommonCS.dll
MOD - [2011/12/13 20:36:04 | 000,086,016 | —- | M] () – C:\Program Files\Dell Support Center\libTonopahClientCSharp.dll
MOD - [2011/12/13 20:36:04 | 000,040,960 | —- | M] () – C:\Program Files\Dell Support Center\libDataStoreCSharp.dll
MOD - [2011/12/13 20:36:04 | 000,019,456 | —- | M] () – C:\Program Files\Dell Support Center\pcdcsharpcommon.dll
MOD - [2011/12/13 20:36:04 | 000,012,800 | —- | M] () – C:\Program Files\Dell Support Center\libGapiCSharp.dll
MOD - [2011/06/24 22:56:36 | 000,087,328 | —- | M] () – C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/06/24 22:56:14 | 001,241,888 | —- | M] () – C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011/04/08 14:56:03 | 000,026,192 | —- | M] () – C:\ProgramData\PCDr\5907\Downloads\4804ced5-915b-48a3-a465-b8a5e02714bf.dll
MOD - [2011/04/08 13:27:10 | 000,026,192 | —- | M] () – C:\ProgramData\PCDr\5907\Downloads\378deb7f-049e-4a5e-83b2-5381dcd9e928.dll
MOD - [2011/04/08 13:12:56 | 000,026,704 | —- | M] () – C:\ProgramData\PCDr\5907\Downloads\62d1f0b0-bc9a-4f6c-bad7-93b19a91276a.dll
MOD - [2011/04/08 12:57:00 | 000,026,192 | —- | M] () – C:\ProgramData\PCDr\5907\Downloads\934f6059-2d35-4bd9-a130-a17cb5563507.dll
MOD - [2011/04/08 12:28:00 | 000,026,704 | —- | M] () – C:\ProgramData\PCDr\5907\Downloads\173c4dd2-e93c-4725-b006-db1d8f465192.dll
MOD - [2011/04/08 11:59:03 | 000,026,192 | —- | M] () – C:\ProgramData\PCDr\5907\Downloads\739db3eb-d3cd-4c86-a6ea-01a49984fa3b.dll
MOD - [2011/04/06 19:24:19 | 000,026,192 | —- | M] () – C:\ProgramData\PCDr\5907\Downloads\ddb9fe5d-525c-4d5d-ac37-0bd10f2864f8.dll
MOD - [2011/04/06 19:09:39 | 000,026,192 | —- | M] () – C:\ProgramData\PCDr\5907\Downloads\7bd83798-7a02-4f50-83a2-b91cabcbd1f9.dll
MOD - [2011/03/24 12:41:34 | 000,719,440 | —- | M] () – C:\ProgramData\PCDr\5907\Downloads\a61f44a8-21a3-4c4a-a04b-993dfb73bf96.dll
MOD - [2011/03/17 00:11:16 | 004,297,568 | —- | M] () – C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
MOD - [2010/10/20 15:45:26 | 008,801,120 | —- | M] () – C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll
MOD - [2006/10/26 16:21:22 | 000,056,056 | —- | M] () – C:\Windows\System32\DLAAPI_W.DLL


========== Services (SafeList) ==========

SRV - File not found [Auto | Stopped] – C:\Program Files\Dell Support Center\bin\sprtsvc.exe /service /p dellsupportcenter – (sprtsvc_dellsupportcenter)
SRV - [2012/10/08 12:53:30 | 000,250,808 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe – (AdobeFlashPlayerUpdateSvc)
SRV - [2012/09/05 20:26:40 | 000,114,144 | —- | M] (Mozilla Foundation) [On_Demand | Stopped] – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe – (MozillaMaintenance)
SRV - [2012/08/21 04:12:25 | 000,044,808 | —- | M] (AVAST Software) [Auto | Running] – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe – (avast! Antivirus)
SRV - [2012/07/27 15:51:26 | 000,063,960 | —- | M] (Adobe Systems Incorporated) [Auto | Running] – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe – (AdobeARMservice)
SRV - [2012/06/23 10:48:50 | 000,073,216 | —- | M] (Highresolution Enterprises) [Auto | Running] – C:\Program Files\Highresolution Enterprises\X-Mouse Button Control\XMouseButtonSvc.exe – (XMouseButton Launcher)
SRV - [2011/06/12 11:15:00 | 031,125,880 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Microsoft Office\Office14\GROOVE.EXE – (Microsoft SharePoint Workspace Audit Service)
SRV - [2011/04/22 07:21:10 | 000,092,592 | —- | M] (TomTom) [Auto | Running] – C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe – (TomTomHOMEService)
SRV - [2010/12/21 07:04:30 | 000,987,704 | —- | M] (Secunia) [Auto | Running] – C:\Program Files\Secunia\PSI\psia.exe – (Secunia PSI Agent)
SRV - [2010/09/23 19:59:40 | 000,537,344 | —- | M] (World Community Grid) [Auto | Running] – C:\Boinc\boinc.exe – (BOINC)
SRV - [2010/08/10 08:37:22 | 000,217,088 | R— | M] () [Auto | Running] – C:\Program Files\ASUS\Printer Utilities\UsbService.exe – (UsbService)
SRV - [2010/05/20 15:27:24 | 000,139,632 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Microsoft LifeCam\MSCamS32.exe – (MSCamSvc)
SRV - [2010/01/21 17:24:08 | 000,110,592 | —- | M] (WDC) [Auto | Running] – C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe – (WDDMService)
SRV - [2009/06/16 09:58:08 | 000,020,480 | —- | M] (Memeo) [Auto | Running] – C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe – (WDSmartWareBackgroundService)
SRV - [2008/07/14 05:42:22 | 000,409,600 | R— | M] () [Auto | Running] – C:\Program Files\Common Files\AVerMedia\Service\AVerScheduleService.exe – (AVerScheduleService)
SRV - [2008/06/06 11:41:22 | 000,352,256 | R— | M] (AVerMedia) [Auto | Running] – C:\Program Files\Common Files\AVerMedia\Service\AVerRemote.exe – (AVerRemote)
SRV - [2008/01/19 02:38:24 | 000,272,952 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2007/12/05 06:17:24 | 000,077,824 | —- | M] (Andrea Electronics Corporation) [Auto | Running] – C:\Windows\System32\AERTSrv.exe – (AERTFilters)
SRV - [2007/09/12 18:27:24 | 002,999,664 | —- | M] (Symantec Corporation) [On_Demand | Stopped] – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_2.EXE – (LiveUpdate)
SRV - [2007/09/12 18:27:24 | 000,554,352 | —- | M] (Symantec Corporation) [Auto | Running] – C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe – (Automatic LiveUpdate Scheduler)
SRV - [2007/03/19 11:44:44 | 000,070,656 | —- | M] () [On_Demand | Stopped] – C:\Program Files\DellSupport\brkrsvc.exe – (DSBrokerService)
SRV - [2007/03/12 18:30:14 | 000,517,768 | —- | M] (Symantec Corporation) [Auto | Running] – C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe – (LiveUpdate Notice Service)
SRV - [2005/02/09 12:59:00 | 000,014,165 | —- | M] (Pinnacle Systems GmbH) [Auto | Stopped] – C:\Windows\System32\drivers\Pclepci.sys – (PCLEPCI)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] – System32\Drivers\ZDPSp60.sys – (ZDPSp60)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\Windows\system32\ZDPNDIS4.SYS – (ZDPNDIS4)
DRV - File not found [Kernel | On_Demand | Stopped] – system32\DRIVERS\emOEM.sys – (USB28xxOEM)
DRV - File not found [Kernel | On_Demand | Stopped] – system32\DRIVERS\emBDA.sys – (USB28xxBGA)
DRV - File not found [Kernel | On_Demand | Stopped] – system32\DRIVERS\nwlnkfwd.sys – (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] – system32\DRIVERS\nwlnkflt.sys – (NwlnkFlt)
DRV - File not found [Kernel | Unavailable | Unknown] – system32\DRIVERS\msfwhlpr.sys – (MSFWHLPR)
DRV - File not found [Kernel | On_Demand | Stopped] – system32\DRIVERS\ipinip.sys – (IpInIp)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\Users\Admin\AppData\Local\Temp\catchme.sys – (catchme)
DRV - File not found [Kernel | Auto | Stopped] – System32\Drivers\Ca1528av.sys – (Ca1528av)
DRV - File not found [Kernel | On_Demand | Stopped] – System32\Drivers\Bulk1528.sys – (Bulk1528)
DRV - File not found [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\blbdrive.sys – (blbdrive)
DRV - [2012/08/21 04:13:15 | 000,729,752 | —- | M] (AVAST Software) [File_System | System | Running] – C:\Windows\System32\drivers\aswSnx.sys – (aswSnx)
DRV - [2012/08/21 04:13:15 | 000,355,632 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\Windows\System32\drivers\aswSP.sys – (aswSP)
DRV - [2012/08/21 04:13:15 | 000,054,232 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\Windows\System32\drivers\aswTdi.sys – (aswTdi)
DRV - [2012/08/21 04:13:14 | 000,058,680 | —- | M] (AVAST Software) [File_System | Auto | Running] – C:\Windows\System32\drivers\aswMonFlt.sys – (aswMonFlt)
DRV - [2012/08/21 04:13:14 | 000,035,928 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\Windows\System32\drivers\aswRdr.sys – (aswRdr)
DRV - [2012/08/21 04:13:13 | 000,021,256 | —- | M] (AVAST Software) [File_System | Auto | Running] – C:\Windows\System32\drivers\aswFsBlk.sys – (aswFsBlk)
DRV - [2011/12/13 20:36:04 | 000,021,744 | —- | M] (PC-Doctor, Inc.) [Kernel | On_Demand | Running] – c:\Program Files\Dell Support Center\pcdsrvc.pkms – (PCDSRVC{E9D79540-57D5953E-06020101}_0)
DRV - [2010/09/01 03:30:58 | 000,015,544 | —- | M] (Secunia) [File_System | On_Demand | Stopped] – C:\Windows\System32\drivers\psi_mf.sys – (PSI)
DRV - [2010/03/24 05:23:16 | 011,614,760 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\nvlddmkm.sys – (nvlddmkm)
DRV - [2010/03/10 09:17:26 | 000,024,216 | —- | M] (Initio Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\ivusb.sys – (ivusb)
DRV - [2010/01/29 01:04:28 | 002,074,480 | —- | M] (Microsoft Corporation
) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\VX6000Xp.sys – (VX6000)
DRV - [2009/12/08 08:37:02 | 000,437,888 | —- | M] (AVerMedia TECHNOLOGIES, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\AVerFx2hbtv.sys – (AVerFx2hbtv)
DRV - [2009/03/02 14:12:10 | 000,038,400 | —- | M] (Samsung Electronics Co., Ltd.) [Kernel | Auto | Stopped] – C:\Windows\System32\drivers\DgivEcp.sys – (DgiVecp)
DRV - [2009/03/02 14:12:10 | 000,005,120 | —- | M] (Samsung Electronics) [Kernel | Auto | Running] – C:\Windows\System32\drivers\SSPORT.sys – (SSPORT)
DRV - [2009/02/13 12:02:52 | 000,011,520 | —- | M] (Western Digital Technologies) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\wdcsam.sys – (WDC_SAM)
DRV - [2007/12/16 21:25:04 | 000,066,432 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\vuhub.sys – (vuhub)
DRV - [2007/08/09 18:12:30 | 000,110,624 | —- | M] (NVIDIA Corporation) [Kernel | Boot | Running] – C:\Windows\System32\drivers\nvstor32.sys – (nvstor32)
DRV - [2007/06/29 12:25:14 | 000,045,344 | —- | M] (FotoNation Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\CoachVid.sys – (CoachVid)
DRV - [2007/06/29 12:25:14 | 000,010,752 | —- | M] (FotoNation Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\CoachAud.sys – (CoachAud)
DRV - [2007/05/09 09:37:54 | 000,434,176 | —- | M] (Pinnacle a division of Avid Technology, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\MarvinAVS.sys – (PinnacleMarvinAVS)
DRV - [2007/03/23 06:09:16 | 000,129,832 | —- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] – C:\Windows\System32\drivers\nvrd32.sys – (nvrd32)
DRV - [2007/03/15 08:57:30 | 001,059,112 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\nvmfdx32.sys – (NVENETFD)
DRV - [2007/02/25 11:10:48 | 000,005,376 | –S- | M] (Gteko Ltd.) [Kernel | Auto | Running] – C:\Windows\System32\drivers\dsunidrv.sys – (dsunidrv)
DRV - [2007/02/08 20:05:30 | 000,028,120 | —- | M] (Roxio) [File_System | System | Running] – C:\Windows\System32\drivers\DLARTL_M.SYS – (DLARTL_M)
DRV - [2007/02/08 20:05:30 | 000,012,856 | —- | M] (Roxio) [File_System | System | Running] – C:\Windows\System32\drivers\DLACDBHM.SYS – (DLACDBHM)
DRV - [2007/01/23 10:11:38 | 000,441,472 | —- | M] (Pinnacle Systems) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\MarvinUsb.sys – (PinnacleMarvinUsb)
DRV - [2007/01/04 10:07:00 | 000,171,520 | —- | M] (Pinnacle Systems GmbH) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\MarvinBus.sys – (MarvinBus)
DRV - [2006/11/02 02:36:43 | 002,028,032 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\atikmdag.sys – (R300)
DRV - [2006/11/02 02:30:55 | 000,200,704 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\e1e6032.sys – (e1express)
DRV - [2006/10/26 16:22:02 | 000,009,400 | —- | M] (Roxio) [File_System | Auto | Running] – C:\Windows\System32\DLA\DLADResM.SYS – (DLADResM)
DRV - [2006/10/26 16:21:34 | 000,094,648 | —- | M] (Roxio) [File_System | Auto | Running] – C:\Windows\System32\DLA\DLAUDFAM.SYS – (DLAUDFAM)
DRV - [2006/10/26 16:21:34 | 000,035,096 | —- | M] (Roxio) [File_System | Auto | Running] – C:\Windows\System32\DLA\DLABMFSM.SYS – (DLABMFSM)
DRV - [2006/10/26 16:21:32 | 000,097,848 | —- | M] (Roxio) [File_System | Auto | Running] – C:\Windows\System32\DLA\DLAUDF_M.SYS – (DLAUDF_M)
DRV - [2006/10/26 16:21:30 | 000,026,296 | —- | M] (Roxio) [File_System | Auto | Running] – C:\Windows\System32\DLA\DLAOPIOM.SYS – (DLAOPIOM)
DRV - [2006/10/26 16:21:28 | 000,032,472 | —- | M] (Roxio) [File_System | Auto | Running] – C:\Windows\System32\DLA\DLABOIOM.SYS – (DLABOIOM)
DRV - [2006/10/26 16:21:26 | 000,014,520 | —- | M] (Roxio) [File_System | Auto | Running] – C:\Windows\System32\DLA\DLAPoolM.SYS – (DLAPoolM)
DRV - [2006/10/26 16:21:24 | 000,104,536 | —- | M] (Roxio) [File_System | Auto | Running] – C:\Windows\System32\DLA\DLAIFS_M.SYS – (DLAIFS_M)
DRV - [2006/10/19 16:29:32 | 000,019,008 | —- | M] (Primax Electronics Ltd.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\pmxusblf.sys – (pmxusblf)
DRV - [2006/10/19 16:27:56 | 000,023,232 | —- | M] (Primax Electronics Ltd.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\pmxmouse.sys – (pmxmouse)
DRV - [2006/10/18 13:08:18 | 000,258,048 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\HSXHWBS2.sys – (HSXHWBS2)
DRV - [2006/10/05 16:07:28 | 000,004,736 | —- | M] (Gteko Ltd.) [Kernel | On_Demand | Running] – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys – (DSproct)
DRV - [2006/08/04 19:39:10 | 000,008,192 | —- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] – C:\Windows\System32\drivers\XAudio.sys – (XAudio)
DRV - [2006/03/01 10:24:16 | 000,290,816 | —- | M] (ZyDAS Technology Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\ZD1211U.sys – (ZD1211U(ZyDAS)
DRV - [2004/10/25 13:40:58 | 000,017,664 | —- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\ZDPSp50.sys – (ZDPSp50)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = Reg Error: Variant error.
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://qwest.live.com
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…amp;rlz=1I7DKUS

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKCU\..\SearchScopes\{AB79D3B4-AEDB-428a-B504-BAC00521A1C7}: "URL" = http://www.google-feed.net/results.php?q={…D=2&PID=STV
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ;*.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "GoogleFeed.net"
FF - prefs.js..browser.search.selectedEngine: "GoogleFeed.net"
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledAddons: [removed]:6.0
FF - prefs.js..extensions.enabledAddons: [removed]:2012.07.08.17
FF - prefs.js..extensions.enabledAddons: {97E22097-9A2F-45b1-8DAF-36AD648C7EF4}:15.0.4
FF - prefs.js..extensions.enabledAddons: [removed]:7.0.1466
FF - prefs.js..extensions.enabledAddons: [removed]:2.0.0
FF - prefs.js..extensions.enabledAddons: [removed]:4.1.3
FF - prefs.js..extensions.enabledItems: [removed]:5.0.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: [removed]:1.73.0
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_4_402_278.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.4.53: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.4.53: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.4.53: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.4.53: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=15.0.4.53: c:\program files\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@unity3d.com/UnityPlayer: C:\Program Files\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.1.11: C:\Program Files\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\[removed]/YahooActiveXPluginBridge;version=1.0.0.1: C:\PROGRA~1\Yahoo!\Common\npyaxmpb.dll File not found
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Admin\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{97E22097-9A2F-45b1-8DAF-36AD648C7EF4}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012/07/17 07:45:20 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Alwil Software\Avast5\WebRep\FF [2012/09/06 20:06:46 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/09/27 21:30:05 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/09/27 21:08:45 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 15.0\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2012/09/27 21:53:40 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 15.0\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins

[2010/05/31 15:00:25 | 000,000,000 | —D | M] (No name found) – C:\Users\Admin\AppData\Roaming\Mozilla\Extensions
[2010/05/31 15:00:25 | 000,000,000 | —D | M] (No name found) – C:\Users\Admin\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2010/02/19 19:26:20 | 000,000,000 | —D | M] (No name found) – C:\Users\Admin\AppData\Roaming\Mozilla\Extensions\[removed]
[2012/10/01 20:52:48 | 000,000,000 | —D | M] (No name found) – C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\2u5n2yy2.default\extensions
[2010/04/30 20:44:22 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\2u5n2yy2.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012/07/16 20:44:35 | 000,000,000 | —D | M] (United States English Spellchecker) – C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\2u5n2yy2.default\extensions\[removed]
[2012/10/01 20:52:48 | 000,000,000 | —D | M] ("Xmarks") – C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\2u5n2yy2.default\extensions\[removed]
[2012/09/27 21:51:07 | 000,000,000 | —D | M] (LastPass) – C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\2u5n2yy2.default\extensions\[removed]
[2012/10/01 20:52:02 | 000,000,000 | —D | M] (No name found) – C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\2u5n2yy2.default\extensions\trash
[2012/07/16 21:10:20 | 000,163,080 | —- | M] () (No name found) – C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\2u5n2yy2.default\extensions\[removed]
[2009/11/14 09:11:09 | 000,000,003 | —- | M] () – C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\2u5n2yy2.default\searchplugins\GoogleFeed.xml
[2012/10/07 19:50:26 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/09/06 20:06:46 | 000,000,000 | —D | M] (avast! WebRep) – C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST5\WEBREP\FF
[2012/07/17 07:45:20 | 000,000,000 | —D | M] (RealPlayer Browser Record Plugin) – C:\PROGRAMDATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
[2012/09/05 20:27:05 | 000,266,720 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/07/17 07:42:08 | 000,129,144 | —- | M] (RealPlayer) – C:\Program Files\mozilla firefox\plugins\nprpplugin.dll
[2010/03/31 11:09:22 | 010,437,264 | —- | M] (PDFTron Systems Inc.) – C:\Program Files\mozilla firefox\plugins\PDFNetC.dll
[2010/04/08 13:36:02 | 000,107,760 | —- | M] () – C:\Program Files\mozilla firefox\plugins\ScorchPDFWrapper.dll
[2012/09/05 20:26:22 | 000,002,465 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/09/05 20:26:22 | 000,002,253 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2012/10/05 19:25:39 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (no name) - {0A87E45F-537A-40B4-B812-E2544C21A09F} - No CLSID value found.
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (LastPass Vault) - {95D9ECF5-2A4D-4550-BE49-70D42F71296E} - C:\Program Files\LastPass\LPToolbar.dll ()
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll (Dell Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (LastPass Toolbar) - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files\LastPass\LPToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No CLSID value found.
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avast] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)
O4 - HKLM..\Run: [boincmgr] C:\Boinc\boincmgr.exe (World Community Grid)
O4 - HKLM..\Run: [boinctray] C:\Boinc\boinctray.exe (Space Sciences Laboratory)
O4 - HKLM..\Run: [LifeCam] C:\Program Files\Microsoft LifeCam\LifeExp.exe (Microsoft Corporation)
O4 - HKLM..\Run: [PMX Daemon] C:\Windows\System32\ico.exe (Primax Electronics Ltd.)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Symantec PIF AlertEng] C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (Symantec Corporation)
O4 - HKLM..\Run: [TkBellExe] c:\program files\real\realplayer\Update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [USB2Check] C:\Windows\System32\PCLECoInst.dll (Pinnacle Systems)
O4 - HKLM..\Run: [USBToolTip] C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe (Pinnacle Systems GmbH)
O4 - HKLM..\Run: [VX6000] C:\Windows\vVX6000.exe (Microsoft Corporation
)
O4 - HKLM..\Run: [WPCUMI] C:\Windows\System32\wpcumi.exe (Microsoft Corporation)
O4 - HKCU..\Run: [DellSupport] C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
O4 - HKCU..\Run: [HP Officejet 6700 (NET)] C:\Program Files\HP\HP Officejet 6700\Bin\ScanToPCActivationApp.exe (Hewlett-Packard Co.)
O4 - HKCU..\Run: [LaunchList] C:\Program Files\Pinnacle\Studio 11\LaunchList2.exe (Pinnacle Systems)
O4 - HKCU..\Run: [Software Informer] C:\Program Files\Software Informer\softinfo.exe (Informer Technologies, Inc.)
O4 - HKCU..\Run: [TomTomHOME.exe] C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: LastPass - file://C:\Users\Admin\AppData\LocalLow\LastPass\context.html?cmd=lastpass File not found
O8 - Extra context menu item: LastPass Fill Forms - file://C:\Users\Admin\AppData\LocalLow\LastPass\context.html?cmd=fillforms File not found
O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: LastPass - {43699cd0-e34f-11de-8a39-0800200c9a66} - C:\Program Files\LastPass\LPToolbar.dll ()
O9 - Extra 'Tools' menuitem : LastPass - {43699cd0-e34f-11de-8a39-0800200c9a66} - C:\Program Files\LastPass\LPToolbar.dll ()
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.4.5.cab (Reg Error: Unable to open value key)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Unable to open value key)
O16 - DPF: {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} http://support.dell.com/systemprofiler/DellSystemLite.CAB (DellSystemLite.Scanner)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Unable to open value key)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7653E6A1-5749-4CF5-B9C8-C5C67D00E752}: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8C2D2A42-495E-4352-B6FC-4B86185E4601}: DhcpNameServer = 192.168.2.1 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B2DF5B9D-D397-4D17-9055-0D155FF548A8}: DhcpNameServer = [removed] [removed]
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\inspiron_DT_1152x864_03.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\inspiron_DT_1152x864_03.jpg
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/05/25 12:19:29 | 000,000,121 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2010/01/28 15:00:27 | 000,000,088 | —- | M] () - G:\autorun.inf – [ UDF ]
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

CREATERESTOREPOINT
System Restore Service not available.

========== Files/Folders - Created Within 30 Days ==========

[2012/10/07 20:07:55 | 000,000,000 | -HSD | C] – C:\found.000
[2012/10/07 19:58:24 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2012/10/05 19:30:43 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2012/10/05 19:30:35 | 000,000,000 | —D | C] – C:\Windows\temp
[2012/10/05 19:30:35 | 000,000,000 | —D | C] – C:\Users\Admin\AppData\Local\temp
[2012/10/05 19:05:59 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2012/10/05 19:05:59 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2012/10/05 19:05:59 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2012/10/05 19:05:44 | 000,000,000 | —D | C] – C:\Qoobox
[2012/10/05 19:04:54 | 000,000,000 | —D | C] – C:\Windows\erdnt
[2012/10/05 18:52:53 | 004,762,471 | R— | C] (Swearware) – C:\Users\Admin\Desktop\ComboFix.exe
[2012/10/04 19:31:21 | 004,731,392 | —- | C] (AVAST Software) – C:\Users\Admin\Desktop\aswMBR.exe
[2012/10/04 19:30:53 | 000,601,088 | —- | C] (OldTimer Tools) – C:\Users\Admin\Desktop\OTL.exe
[2012/10/02 21:51:50 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\Admin\Desktop\HiJackThis.exe
[2012/09/27 22:04:54 | 000,000,000 | —D | C] – C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
[2012/09/27 21:30:17 | 000,000,000 | —D | C] – C:\ProgramData\Mozilla
[2012/09/27 21:30:16 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Maintenance Service
[2012/09/27 19:15:10 | 000,000,000 | —D | C] – C:\Users\Admin\Desktop\Kati ja Anna
[2012/09/17 20:21:23 | 000,000,000 | —D | C] – C:\Users\Admin\AppData\Roaming\PictureMover
[2012/09/17 19:25:14 | 002,212,440 | —- | C] (Kaspersky Lab ZAO) – C:\Users\Admin\Desktop\TDSSKiller.exe
[2011/01/01 14:07:15 | 010,974,280 | —- | C] (LastPass) – C:\Program Files\Common Files\lpuninstall.exe
[2010/01/31 21:36:39 | 008,653,312 | —- | C] (Dell, Inc. ) – C:\Users\Admin\AppData\Roaming\DataSafeDotNet.exe
[2007/07/20 18:56:57 | 011,718,184 | —- | C] (World Community Grid ) – C:\Users\Admin\wcg_boinc_5.8.15_windows_intelx86.exe
[3 C:\*.tmp files -> C:\*.tmp -> ]
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/10/09 20:20:30 | 000,000,506 | —- | M] () – C:\Windows\tasks\SystemToolsDailyTest.job
[2012/10/09 20:14:48 | 000,071,218 | —- | M] () – C:\ProgramData\nvModes.001
[2012/10/09 20:12:46 | 000,071,221 | —- | M] () – C:\ProgramData\nvModes.dat
[2012/10/09 19:36:02 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/10/09 19:26:05 | 000,003,696 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/10/09 19:26:04 | 000,003,696 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/10/09 19:22:26 | 000,005,484 | —- | M] () – C:\Windows\mozy.blk
[2012/10/09 19:22:26 | 000,002,416 | —- | M] () – C:\Windows\mozy.flt
[2012/10/07 23:24:34 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/10/07 23:24:25 | 187,627,764 | —- | M] () – C:\Windows\MEMORY.DMP
[2012/10/06 13:36:35 | 000,000,564 | —- | M] () – C:\Windows\tasks\PCDoctorBackgroundMonitorTask.job
[2012/10/06 13:31:39 | 000,513,501 | —- | M] () – C:\Users\Admin\Desktop\AdwCleaner.exe
[2012/10/05 19:25:39 | 000,000,027 | —- | M] () – C:\Windows\System32\drivers\etc\hosts
[2012/10/05 18:54:54 | 002,212,440 | —- | M] (Kaspersky Lab ZAO) – C:\Users\Admin\Desktop\TDSSKiller.exe
[2012/10/05 18:53:41 | 004,762,471 | R— | M] (Swearware) – C:\Users\Admin\Desktop\ComboFix.exe
[2012/10/05 18:52:35 | 002,193,278 | —- | M] () – C:\Users\Admin\Desktop\tdsskiller.zip
[2012/10/04 20:12:06 | 000,000,120 | —- | M] () – C:\Users\Admin\Desktop\MBR.zip
[2012/10/04 20:11:29 | 000,000,512 | —- | M] () – C:\Users\Admin\Desktop\MBR.dat
[2012/10/04 19:31:54 | 004,731,392 | —- | M] (AVAST Software) – C:\Users\Admin\Desktop\aswMBR.exe
[2012/10/04 19:31:48 | 000,601,088 | —- | M] (OldTimer Tools) – C:\Users\Admin\Desktop\OTL.exe
[2012/10/03 18:28:11 | 000,640,408 | —- | M] () – C:\Windows\System32\perfh009.dat
[2012/10/03 18:28:11 | 000,118,660 | —- | M] () – C:\Windows\System32\perfc009.dat
[2012/10/02 21:51:56 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Admin\Desktop\HiJackThis.exe
[2012/09/27 21:51:17 | 010,974,280 | —- | M] (LastPass) – C:\Program Files\Common Files\lpuninstall.exe
[2012/09/27 21:30:33 | 000,000,872 | —- | M] () – C:\Users\Admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/09/23 07:32:53 | 000,536,056 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[3 C:\*.tmp files -> C:\*.tmp -> ]
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/10/07 23:24:25 | 187,627,764 | —- | C] () – C:\Windows\MEMORY.DMP
[2012/10/06 13:31:32 | 000,513,501 | —- | C] () – C:\Users\Admin\Desktop\AdwCleaner.exe
[2012/10/05 19:05:59 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2012/10/05 19:05:59 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2012/10/05 19:05:59 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2012/10/05 19:05:59 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2012/10/05 19:05:59 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2012/10/05 18:52:08 | 002,193,278 | —- | C] () – C:\Users\Admin\Desktop\tdsskiller.zip
[2012/10/04 20:12:06 | 000,000,120 | —- | C] () – C:\Users\Admin\Desktop\MBR.zip
[2012/10/04 20:11:29 | 000,000,512 | —- | C] () – C:\Users\Admin\Desktop\MBR.dat
[2012/07/16 20:47:11 | 000,000,057 | —- | C] () – C:\ProgramData\Ament.ini
[2012/06/27 21:39:03 | 000,014,115 | —- | C] () – C:\Windows\twspmm.ini
[2012/04/14 21:32:47 | 000,000,931 | —- | C] () – C:\Users\Admin\AppData\Roaming\ofx2csv.ini
[2012/01/21 17:39:08 | 000,000,064 | —- | C] () – C:\Windows\qwimp.ini
[2012/01/21 17:22:08 | 000,000,372 | —- | C] () – C:\Windows\intuprof.ini
[2011/07/19 19:52:00 | 000,022,723 | —- | C] () – C:\Windows\System32\SSGR3l3.dll
[2011/05/28 17:39:51 | 000,066,432 | —- | C] () – C:\Windows\System32\drivers\vuhub.sys
[2011/02/09 23:03:48 | 000,000,314 | —- | C] () – C:\Windows\primopdf.ini
[2011/01/01 14:34:37 | 000,000,611 | —- | C] () – C:\Windows\eReg.dat
[2010/11/13 10:31:25 | 000,000,675 | —- | C] () – C:\Windows\EReg072.dat
[2010/04/13 19:34:24 | 000,071,218 | —- | C] () – C:\ProgramData\nvModes.001
[2010/04/13 18:51:05 | 000,071,221 | —- | C] () – C:\ProgramData\nvModes.dat
[2009/12/22 11:52:37 | 000,000,040 | —- | C] () – C:\Users\Admin\AppData\Roaming\cdr.ini
[2009/11/27 17:39:23 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2009/03/09 19:58:29 | 000,695,642 | —- | C] () – C:\Users\Admin\AppData\Roaming\unins000.exe
[2009/03/09 19:58:29 | 000,001,870 | —- | C] () – C:\Users\Admin\AppData\Roaming\unins000.dat
[2008/06/25 06:56:47 | 000,001,356 | —- | C] () – C:\Users\Admin\AppData\Local\d3d9caps.dat
[2008/05/20 07:24:32 | 000,734,762 | —- | C] () – C:\Users\Admin\AppData\Roaming\datasafeupdate.msi
[2007/09/01 14:02:56 | 000,004,933 | —- | C] () – C:\Users\Admin\AppData\Roaming\SmarThruOptions.xml
[2007/07/31 19:29:47 | 000,000,000 | —- | C] () – C:\Users\Admin\AppData\Roaming\wklnhst.dat
[2007/07/20 14:47:48 | 000,008,362 | —- | C] () – C:\ProgramData\LUUnInstall.LiveUpdate
[2007/07/14 14:28:38 | 000,000,632 | RHS- | C] () – C:\Users\Admin\ntuser.pol
[2007/07/14 12:58:11 | 000,032,256 | —- | C] () – C:\Users\Admin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

========== ZeroAccess Check ==========

[2006/11/02 07:54:22 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/08 12:47:00 | 011,586,048 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2009/04/11 01:28:19 | 000,614,912 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2009/04/11 01:28:25 | 000,347,648 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2008/06/10 21:08:58 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\ACAMPREF
[2010/04/14 21:02:42 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\ChessBase
[2007/10/19 21:17:18 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\DataSafeOnline
[2007/07/14 13:04:04 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Earthlink
[2011/10/26 18:08:57 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Highresolution Enterprises
[2010/02/01 22:07:13 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\IObit
[2007/08/18 19:05:33 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\PC Magazine Utilities
[2011/07/19 09:10:59 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\PCDr
[2012/09/17 20:21:53 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\PictureMover
[2012/10/09 20:18:34 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Software Informer
[2007/07/31 19:29:47 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Template
[2008/05/19 21:21:48 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Tenebril
[2010/05/31 15:00:21 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Thunderbird
[2010/02/19 19:26:13 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\TomTom
[2010/01/30 18:03:05 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Ulead Systems
[2010/11/27 18:38:46 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Western Digital

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.exe >

< MD5 for: EXPLORER.EXE >
[2008/10/29 01:20:29 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_4f83bb287ccdb7e3\explorer.exe
[2008/10/29 01:29:41 | 002,927,104 | —- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_5177ca9879e978e8\explorer.exe
[2008/10/29 22:59:17 | 002,927,616 | —- | M] (Microsoft Corporation) MD5=50BA5850147410CDE89C523AD3BC606E – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_51e4f8c7931bd1e1\explorer.exe
[2007/11/13 23:52:33 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=6D06CD98D954FE87FB2DB8108793B399 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16549_none_4fac29707cae347a\explorer.exe
[2007/11/13 23:52:32 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=BD06F0BF753BC704B653C3A50F89D362 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20668_none_501f261995dcf2cf\explorer.exe
[2009/04/11 01:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 – C:\Windows\erdnt\cache\explorer.exe
[2009/04/11 01:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 – C:\Windows\explorer.exe
[2009/04/11 01:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_53a0201e76de3a0b\explorer.exe
[2008/10/27 21:15:02 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=E7156B0B74762D9DE0E66BDCDE06E5FB – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_5033cb5995cd990b\explorer.exe
[2006/11/02 04:45:07 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=FD8C53FB002217F6F888BCF6F5D7084D – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16386_none_4f7de5167cd15deb\explorer.exe
[2008/01/19 02:33:10 | 002,927,104 | —- | M] (Microsoft Corporation) MD5=FFA764631CB70A30065C12EF8E174F9F – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_51b4a71279bc6ebf\explorer.exe

< MD5 for: SVCHOST.EXE >
[2006/11/02 04:45:47 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=10DA15933D582D2FEDCF705EFE394B09 – C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.0.6000.16386_none_b38497a50862ad11\svchost.exe
[2008/01/19 02:33:32 | 000,021,504 | —- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF – C:\Windows\erdnt\cache\svchost.exe
[2008/01/19 02:33:32 | 000,021,504 | —- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF – C:\Windows\System32\svchost.exe
[2008/01/19 02:33:32 | 000,021,504 | —- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF – C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.0.6001.18000_none_b5bb59a1054dbde5\svchost.exe
[2012/09/07 17:04:42 | 000,218,696 | —- | M] () MD5=4E0D8C9F83B7FD82393F7D8CCC27E7AE – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\svchost.exe

< MD5 for: USERINIT.EXE >
[2008/01/19 02:33:33 | 000,025,088 | —- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 – C:\Windows\erdnt\cache\userinit.exe
[2008/01/19 02:33:33 | 000,025,088 | —- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 – C:\Windows\System32\userinit.exe
[2008/01/19 02:33:33 | 000,025,088 | —- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
[2006/11/02 04:45:50 | 000,024,576 | —- | M] (Microsoft Corporation) MD5=22027835939F86C3E47AD8E3FBDE3D11 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6000.16386_none_d9f1f819d4c4e737\userinit.exe

< MD5 for: WINLOGON.EXE >
[2012/09/07 17:04:42 | 000,218,696 | —- | M] () MD5=4E0D8C9F83B7FD82393F7D8CCC27E7AE – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009/04/11 01:28:13 | 000,314,368 | —- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 – C:\Windows\erdnt\cache\winlogon.exe
[2009/04/11 01:28:13 | 000,314,368 | —- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 – C:\Windows\System32\winlogon.exe
[2009/04/11 01:28:13 | 000,314,368 | —- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2006/11/02 04:45:57 | 000,308,224 | —- | M] (Microsoft Corporation) MD5=9F75392B9128A91ABAFB044EA350BAAD – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6000.16386_none_6d8c3f1ad8066b21\winlogon.exe
[2008/01/19 02:33:37 | 000,314,880 | —- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe

< %systemroot%\*. /rp /s >

========== Drive Information ==========

Physical Drives
—————

Drive: \\\\.\\PHYSICALDRIVE0 - Fixed hard disk media
Interface type: IDE
Media Type: Fixed hard disk media
Model: WDC WD25 00JS-75NCB3 SCSI Disk Device
Partitions: 3
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE1 - External hard disk media
Interface type: USB
Media Type: External hard disk media
Model: WD My Book 1111 USB Device
Partitions: 1
Status: OK
Status Info: 0

Partitions
—————

DeviceID: Disk #0, Partition #0
PartitionType: Unknown
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 55.00MB
Starting Offset: 32256
Hidden sectors: 0


DeviceID: Disk #0, Partition #1
PartitionType: Installable File System
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 10.00GB
Starting Offset: 57671680
Hidden sectors: 0


DeviceID: Disk #0, Partition #2
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 223.00GB
Starting Offset: 10795089920
Hidden sectors: 0


DeviceID: Disk #1, Partition #0
PartitionType: Installable File System
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 931.00GB
Starting Offset: 1048576
Hidden sectors: 0


< End of report >

It did not open an Extras.Txt
IMPORTANT: Download a fresh copy of OTL from here and save it to your desktop, replacing your current version of OTL.

THEN:

Run OTL.exe.
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL.

    :OTL
    FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
    FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
    O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll (Dell Inc.)
    
    :Commands
    [purity]
    [resethosts]
    [emptytemp]

  • Click the Run Fix button.
  • OTL will now process the instructions.
  • When finished a box will open asking you to open the fix log, click OK.
  • The fix log will open.
  • Copy/Paste the log in your next reply please.
Note: If necessary, OTL may reboot your computer, or request that you do so. If it does, please go ahead and reboot your machine. After rebooting, open up Windows Explorer (Windows Key +E) and navigate to C:\_OTL\MovedFiles. Within, you should find a .log file with the format mmddyyyy_hhmmss, which represents the date and time the fix was run. Please copy and paste the contents of that file, making sure Word Wrap is off beforehand, if necessary.

NEXT:

Please download Farbar Service Scanner and run it on the computer with the issue.
  • Check all boxes.
  • Press "Scan".
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please post the log in your next reply.
Here is the OTL log: All processes killed ========== OTL ========== Prefs.js: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20 removed from extensions.enabledItems Prefs.js: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22 removed from extensions.enabledItems Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CA6319C0-31B7-401E-A518-A07C3DB8F777}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CA6319C0-31B7-401E-A518-A07C3DB8F777}\ not found. File C:\Program Files\BAE\BAE.dll not found. ========== COMMANDS ========== C:\Windows\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully [EMPTYTEMP] User: Admin ->Temp folder emptied: 36573 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 8002977 bytes ->Flash cache emptied: 0 bytes User: All Users User: boinc_master ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Kati ja Anna ->Temp folder emptied: 0 bytes User: Marianne ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 7585115 bytes ->Java cache emptied: 24006757 bytes ->FireFox cache emptied: 73149388 bytes ->Flash cache emptied: 254512 bytes User: Public ->Temp folder emptied: 0 bytes %systemdrive% .tmp files removed: 38231881 bytes %systemroot% .tmp files removed: 724 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 66902 bytes RecycleBin emptied: 8192 bytes Total Files Cleaned = 144.00 mb OTL by OldTimer - Version 3.2.69.0 log created on 10102012_202406 Files\Folders moved on Reboot… File move failed. C:\Windows\temp\_avast_\Webshlock.txt scheduled to be moved on reboot. PendingFileRenameOperations files… Registry entries deleted on Reboot… Here is the Farbar scan: Farbar Service Scanner Version: 07-10-2012 Ran by [removed] (administrator) on 10-10-2012 at 20:41:58 Running from "C:\Users\Admin\Desktop" Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) Boot Mode: Normal **************************************************************** Internet Services: ============ Connection Status: ============== Localhost is accessible. LAN connected. Google IP is accessible. Google.com is accessible. Yahoo IP is accessible. Yahoo.com is accessible. Windows Firewall: ============= Firewall Disabled Policy: ================== System Restore: ============ System Restore Disabled Policy: ======================== Security Center: ============ Windows Update: ============ Windows Autoupdate Disabled Policy: ============================ Windows Defender: ============== WinDefend Service is not running. Checking service configuration: The start type of WinDefend service is set to Demand. The default start type is Auto. The ImagePath of WinDefend service is OK. The ServiceDll of WinDefend service is OK. Other Services: ============== File Check: ======== C:\Windows\system32\nsisvc.dll => MD5 is legit C:\Windows\system32\Drivers\nsiproxy.sys => MD5 is legit C:\Windows\system32\dhcpcsvc.dll => MD5 is legit C:\Windows\system32\Drivers\afd.sys => MD5 is legit C:\Windows\system32\Drivers\tdx.sys => MD5 is legit C:\Windows\system32\Drivers\tcpip.sys => MD5 is legit C:\Windows\system32\dnsrslvr.dll => MD5 is legit C:\Windows\system32\mpssvc.dll => MD5 is legit C:\Windows\system32\bfe.dll => MD5 is legit C:\Windows\system32\Drivers\mpsdrv.sys => MD5 is legit C:\Windows\system32\SDRSVC.dll => MD5 is legit C:\Windows\system32\vssvc.exe => MD5 is legit C:\Windows\system32\wscsvc.dll => MD5 is legit C:\Windows\system32\wbem\WMIsvc.dll => MD5 is legit C:\Windows\system32\wuaueng.dll => MD5 is legit C:\Windows\system32\qmgr.dll => MD5 is legit C:\Windows\system32\es.dll => MD5 is legit C:\Windows\system32\cryptsvc.dll [2012-10-09 22:50] - [2012-06-01 19:02] - 0133120 ___AC (Microsoft Corporation) F1E8C34892336D33EDDCDFE44E474F64 C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit C:\Windows\system32\ipnathlp.dll [2008-04-17 22:07] - [2008-01-19 02:34] - 0288256 ____A (Microsoft Corporation) E1499BD0FF76B1B2FBBF1AF339D91165 C:\Windows\system32\svchost.exe => MD5 is legit C:\Windows\system32\rpcss.dll => MD5 is legit **** End of log ****

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI