Jump to content


Photo

Big Problems forced to create new user on Vista


  • This topic is locked This topic is locked
21 replies to this topic

#1 eltiburon

eltiburon

    Member

  • Full Member
  • Pip
  • 13 posts

Posted 30 January 2010 - 11:47 AM

Hi guys,

For the past few days I have been having big problems with my laptop, running Vista. It would freeze right after boot at the desktop, not allowing me access to any programs. I was able to run in safe mode...for a while, before it froze again. I rebooted again in safe mode and was able to create a new user account, which is what I am using. I have a lot of antivirus/malware programs installed antivir, avg, malwarebytes. But even in my new user account, I am unable to complete a full system scan without the program or computer freezing up after an hour or so. I am posting my hijackthis log for your convenience.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:32:59 PM, on 1/30/2010
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18882)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Synaptics\SynTP\SynTPStart.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\Digital Imaging\bin\HpqSRmon.exe
C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Program Files\Common Files\AOL\1216788419\ee\aolsoftware.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\Program Files\AVG\AVG9\avgtray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\wuauclt.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.h...ilion&pf=laptop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.h...ilion&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.h...ilion&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.h...ilion&pf=laptop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: Verizon Broadband Toolbar - {4E7BD74F-2B8D-469E-8CB0-AB60BB9AAE22} - C:\PROGRA~1\VOL_TO~1\VOL_TO~1.DLL (file missing)
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: HP Print Clips - {FFFFFFFF-FF12-44C5-91EC-068E3AA1B2D7} - c:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Verizon Broadband Toolbar - {4E7BD74F-2B8D-469E-8CB0-AB60BB9AAE22} - C:\PROGRA~1\VOL_TO~1\VOL_TO~1.DLL (file missing)
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [OnScreenDisplay] C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" update "Software\CyberLink\YouCam\1.0"
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [WAWifiMessage] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1216788419\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [HPADVISOR] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe autoRun
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Vongo Tray.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: HP Smart Select - {58ECB495-38F0-49cb-A538-10282ABF65E7} - c:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgemc.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
O23 - Service: Biometric Authentication Service (DpHost) - Unknown owner - C:\Program Files\DigitalPersona\Bin\DpHostW.exe (file missing)
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: Google Update Service (gupdate1ca26c983b7a8b0) (gupdate1ca26c983b7a8b0) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: Vongo Service - Starz Entertainment Group LLC - C:\Program Files\Vongo\VongoService.exe

--
End of file - 11427 bytes

Thanks in advance.

#2 SWI Support Robot

SWI Support Robot

    Helper robot

  • SWI Bot
  • PipPipPipPipPip
  • 23,533 posts

Posted 02 February 2010 - 12:52 AM

Welcome to SWI. We apologize for the delay; our helpers have been very busy.

If you have not received help after 3 days, please CLICK HERE, and post a link to your log and the date it was originally posted.

Thank you for your patience.


[this is an automated reply]
This is an automated message. It does not count as help.

#3 lance_yien

lance_yien

    Forum Deity

  • Retired Staff
  • PipPipPipPipPip
  • 2,442 posts

Posted 10 February 2010 - 09:14 AM

Hello eltiburon and welcome to SWI.

I'm lance_yien and will be helping you.

Your log doesn't seem to show any infection.

- I can see that you are running 2 antivirus programs: "AVG" and "Avira- AntiVir Desktop".

Running more than one resident protection program of the same type (antivirus, firewall or antispyware program) at the same time can result in unwanted conflict.
This can reduce the effectiveness of all your programs individually and may slowdown your computer.


I suggest you uninstall (or disable) one of them:

- To uninstall a program, please go to Start => Control Panel => Add or Remove Programs, select the program and click "Remove"

- To disable AVG's Resident Shield, please run the program => Tools -> Advanced settings and then click on Resident Shield in the tree menu. Uncheck the Enable Resident Shield option, click Apply.

- To disable Avira- Antivir, please right-click its icon in the system tray and untick "AntiVir Guard enable".
--

Please, print out these instructions or copy them to a Notepad file for an easer reading and download, to your Desktop:

  • CCleaner (freeware) from here.
  • Security Check by screen317 from here or here.
--

- Please run the CCleaner installer by double clicking ccsetup....exe, and uncheck the option to install Yahoo toolbar (unless you want Yahoo toolbar).
Once installed, run CCleaner.

The following should be selected by default, if not, please select:

Posted Image

Then please click Posted Image and choose Posted Image

Please uncheck Posted Image

Then go back to Posted Image and click Posted Image to run it.

- Now, please use your Disk Defragmenter.

- Finally, please double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
A Notepad document should open automatically called checkup.txt

Please post the contents of that document and let me know how your computer is functioning now.

LY

Edited by lance_yien, 11 February 2010 - 12:07 AM.

EI | SWI | ZEBULON | Posted Image | Posted Image

My help is free, but if you wish to help keep these forums running please consider a donation. Please, see here for details.

#4 eltiburon

eltiburon

    Member

  • Full Member
  • Pip
  • 13 posts

Posted 10 February 2010 - 11:26 PM

Hi, thanks for the help. I disenabled AVG. I ran ccleaner. I then tried running a defrag and the computer froze. Then I tried running a defrag using Smart Defrag and the computer froze again. Please be advised that this is all in my second windows user account. My original user account will still omly boot up properly in safe mode.

Here is my security check log:

Results of screen317's Security Check version 0.99.1
Windows Vista Service Pack 1 (UAC is enabled)
Out of date service pack!!
``````````````````````````````
Antivirus/Firewall Check:

Windows Firewall Enabled!
AVG Free 9.0
Avira AntiVir Personal - Free Antivirus
Antivirus up to date!
``````````````````````````````
Anti-malware/Other Utilities Check:

HijackThis 2.0.2
CCleaner
Java™ 6 Update 17
Java™ 6 Update 2
Out of date Java installed!
Adobe Flash Player 10
Adobe Reader 8.1.3
Out of date Adobe Reader installed!
``````````````````````````````
Process Check:
objlist.exe by Laurent

AVG avgwdsvc.exe
AVG avgtray.exe
AVG avgrsx.exe
AVG avgnsx.exe
AVG avgemc.exe
AVG avgemc.exe
Avira Antivir avgnt.exe
Avira Antivir avguard.exe
``````````````````````````````
DNS Vulnerability Check:

GREAT! (Not vulnerable to DNS cache poisoning)

`````````End of Log```````````

Again, thanks for the help.

#5 lance_yien

lance_yien

    Forum Deity

  • Retired Staff
  • PipPipPipPipPip
  • 2,442 posts

Posted 11 February 2010 - 02:34 AM

Hello eltiburon,

Please login with Administrator privileges, print out these instructions or copy them to a Notepad file for an easer reading and download to your Desktop:

  • Malwarebytes Anti-Malware from here or here
  • ComboFix© by sUBs from here or here

- Please make sure you are connected to the Internet and:

  • Double-click on Download_mbam-setup.exe to install the application.
  • When the installation begins, follow the prompts and do not make any changes to default settings.
  • When installation has finished, make sure you leave both of these checked:

    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
  • MBAM will automatically start and you will be asked to update the program before performing a scan. If an update is found, the program will automatically update itself. Press the OK button to close that box and continue.
    If you encounter any problems while downloading the updates, please manually download them from here and just double-click on mbam-rules.exe to install.
  • On the Scanner tab:

    • Make sure the "Perform Quick Scan" option is selected.
    • Then click on the Scan button.
  • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.
  • Back at the main Scanner screen, click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad and you may be prompted to restart your computer (see Note below).
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply and exit MBAM.

Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

For complete or visual instructions on installing and running Malwarebytes Anti-Malware, please see here

- Now, please familiarize yourself with ComboFix here before running it.
I recommend you print out the information from this page or copy them to a Notepad file as well.

Please ensure you have disabled all anti virus and anti malware programs and run ComboFix.

Notes:

  • It is very important that you have the Windows Recovery Console installed because without it, ComboFix shall not attempt the fixing of some serious infections.
    It's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Please, DO NOT click ComboFix's window while it is running. This may cause it to hang.

Finally, please double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
A Notepad document should open automatically called checkup.txt

Please post the contents of Malwarebytes Anti-Malware log and C:\ComboFix.txt with a fresh HijackThis log.

LY
EI | SWI | ZEBULON | Posted Image | Posted Image

My help is free, but if you wish to help keep these forums running please consider a donation. Please, see here for details.

#6 eltiburon

eltiburon

    Member

  • Full Member
  • Pip
  • 13 posts

Posted 11 February 2010 - 02:51 PM

Hi Lance,

I did everything you said. I logged in as Administrator. The malwarebytes worked. I tried running ComboFix several times and it kept hanging at process 2 causing me to hard reboot my system.

Anyway, here are my logs for Malware and HiJack

Malwarebytes' Anti-Malware 1.44
Database version: 3726
Windows 6.0.6001 Service Pack 1
Internet Explorer 8.0.6001.18882

2/11/2010 2:30:21 PM
mbam-log-2010-02-11 (14-30-21).txt

Scan type: Quick Scan
Objects scanned: 135572
Time elapsed: 11 minute(s), 21 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:46:32 PM, on 2/11/2010
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18882)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPStart.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\HP\Digital Imaging\bin\HpqSRmon.exe
C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Program Files\Common Files\AOL\1216788419\ee\aolsoftware.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\Vongo\Tray.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.h...ilion&pf=laptop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.h...ilion&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.h...ilion&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.h...ilion&pf=laptop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Verizon Broadband Toolbar - {4E7BD74F-2B8D-469E-8CB0-AB60BB9AAE22} - (no file)
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: HP Print Clips - {FFFFFFFF-FF12-44C5-91EC-068E3AA1B2D7} - c:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Verizon Broadband Toolbar - {4E7BD74F-2B8D-469E-8CB0-AB60BB9AAE22} - (no file)
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [OnScreenDisplay] C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" update "Software\CyberLink\YouCam\1.0"
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [WAWifiMessage] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1216788419\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [HPADVISOR] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe autoRun
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - Global Startup: Vongo Tray.lnk = ?
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: HP Smart Select - {58ECB495-38F0-49cb-A538-10282ABF65E7} - c:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
O23 - Service: Biometric Authentication Service (DpHost) - Unknown owner - C:\Program Files\DigitalPersona\Bin\DpHostW.exe (file missing)
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: Google Update Service (gupdate1ca26c983b7a8b0) (gupdate1ca26c983b7a8b0) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: Vongo Service - Starz Entertainment Group LLC - C:\Program Files\Vongo\VongoService.exe

--
End of file - 10242 bytes

Again, thanks again.

#7 eltiburon

eltiburon

    Member

  • Full Member
  • Pip
  • 13 posts

Posted 11 February 2010 - 08:06 PM

I forgot to add the latest Security Check Log, here it is:


Results of screen317's Security Check version 0.99.1
Windows Vista Service Pack 1 (UAC is enabled)
Out of date service pack!!
``````````````````````````````
Antivirus/Firewall Check:

Windows Firewall Enabled!
Avira AntiVir Personal - Free Antivirus
WMIC entry does not exist for antivirus; attempting automatic update.
Avira updated!
``````````````````````````````
Anti-malware/Other Utilities Check:

HijackThis 2.0.2
CCleaner
Java™ 6 Update 17
Java™ 6 Update 2
Out of date Java installed!
Adobe Flash Player 10
Adobe Reader 8.1.3
Out of date Adobe Reader installed!
``````````````````````````````
Process Check:
objlist.exe by Laurent

Windows Defender MSASCui.exe
``````````````````````````````
DNS Vulnerability Check:

GREAT! (Not vulnerable to DNS cache poisoning)

`````````End of Log```````````

#8 lance_yien

lance_yien

    Forum Deity

  • Retired Staff
  • PipPipPipPipPip
  • 2,442 posts

Posted 12 February 2010 - 09:44 AM

Hello eltiburon,

Your Malwarebytes' Anti-Malware log seems clean.

... I tried running ComboFix several times and it kept hanging at process 2 causing me to hard reboot my system.


Sorry, I don't understand. What happens exactly?

Please, try running ComboFix in Safe Mode. (DO NOT click ComboFix's window while it is running. This may cause it to hang).
--

Please, print out these instructions or copy them to a Notepad file for an easer reading and download OTL by OldTimer to your Desktop from here or here

Close all windows and double click OTL.exe to run OTL. Click Run Scan and let the program run uninterrupted.

It will produce two logs for you, one will pop up - OTL.txt, the other will be saved on your Desktop - Extras.txt. Post both logs in this thread.

Please post both logs and C:\ComboFix.txt (if run successfully). You may need to use two posts to get it all in.

Also, please let me know when the problem actually started. Did you install a new device, software, or drivers??..

LY

Edited by lance_yien, 16 February 2010 - 03:50 AM.

EI | SWI | ZEBULON | Posted Image | Posted Image

My help is free, but if you wish to help keep these forums running please consider a donation. Please, see here for details.

#9 eltiburon

eltiburon

    Member

  • Full Member
  • Pip
  • 13 posts

Posted 15 February 2010 - 03:09 PM

This is how the problem started:

I woke up one day and went over to my laptop to check my e-mail and saw that my user was logged out of Vista which was not normal. When I logged back in, the desktop froze and I was unable to open any programs. I entered safe mode and attempted to restart the system from an earlier point. Every time I did this, the computer would freeze. So, I created a new user account and this gave me functionality, but my original user account still does not work properly. This is about the long and short of the problem. I did not add any new software or hardware. About 2 months ago I bought an iPod and started using ITunes. That is about it.


Now onto your last post's instructions.

Even in safe mode I am unable to get combo fix to work, it freezes up without me clicking or touching the computer. I tried in safe mode too. I disabled all virus protection before hand too. Here are the other two logs you asked for:

OTL logfile created on: 2/15/2010 3:39:08 PM - Run 1
OTL by OldTimer - Version 3.1.28.0 Folder = C:\Users\Garrett Gambino.Garrett-PC\Downloads
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18882)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 53.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 72.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 220.67 Gb Total Space | 117.50 Gb Free Space | 53.25% Space Free | Partition Type: NTFS
Drive D: | 12.22 Gb Total Space | 1.82 Gb Free Space | 14.87% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: GARRETT-PC
Current User Name: Garrett Gambino
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2010/02/15 15:38:33 | 000,549,376 | ---- | M] (OldTimer Tools) -- C:\Users\Garrett Gambino.Garrett-PC\Downloads\OTL.exe
PRC - [2010/01/22 19:16:42 | 000,141,608 | ---- | M] (Apple Inc.) -- C:\Program Files\iTunes\iTunesHelper.exe
PRC - [2010/01/22 19:16:30 | 000,545,576 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe
PRC - [2010/01/06 04:00:34 | 000,908,248 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2009/11/01 19:05:34 | 000,136,176 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Update\1.2.183.13\GoogleCrashHandler.exe
PRC - [2009/10/11 04:17:36 | 000,149,280 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jusched.exe
PRC - [2009/08/28 19:42:54 | 000,144,672 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
PRC - [2009/07/21 13:34:33 | 000,185,089 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2009/05/27 17:00:32 | 000,211,488 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvvsvc.exe
PRC - [2009/05/13 15:48:22 | 000,108,289 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2009/03/02 12:08:47 | 000,209,153 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2008/12/12 11:17:38 | 000,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe
PRC - [2008/10/29 01:29:41 | 002,927,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2008/10/15 01:04:34 | 000,039,792 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
PRC - [2008/06/16 08:02:28 | 000,094,208 | ---- | M] (Hewlett-Packard) -- c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Service.exe
PRC - [2008/06/02 02:55:22 | 000,080,896 | ---- | M] (Hewlett-Packard) -- C:\Program Files\HP\Digital Imaging\bin\HpqSRmon.exe
PRC - [2008/04/15 16:54:42 | 000,354,840 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2008/04/15 16:54:40 | 000,178,712 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2008/03/28 02:06:00 | 000,095,528 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
PRC - [2008/03/28 02:05:00 | 001,045,800 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
PRC - [2008/01/19 02:38:38 | 001,008,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MSASCui.exe
PRC - [2007/10/01 19:10:48 | 001,783,136 | ---- | M] (Hewlett-Packard) -- C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
PRC - [2007/09/30 22:34:54 | 000,271,760 | ---- | M] () -- C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
PRC - [2007/09/30 22:34:54 | 000,112,016 | ---- | M] () -- C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
PRC - [2007/09/30 22:34:14 | 000,181,544 | ---- | M] (CyberLink Corp.) -- C:\Program Files\HP\QuickPlay\QPService.exe
PRC - [2007/09/19 17:31:34 | 000,202,032 | ---- | M] ( Hewlett-Packard Development Company, L.P.) -- C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
PRC - [2007/09/15 03:29:10 | 000,102,400 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\SynTPStart.exe
PRC - [2007/09/13 11:47:52 | 000,480,560 | ---- | M] (Hewlett-Packard Development Company, L.P.) -- C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
PRC - [2007/09/04 16:54:20 | 000,554,320 | ---- | M] ( Hewlett-Packard Development Company, L.P.) -- C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
PRC - [2007/08/23 17:40:48 | 000,079,136 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files\Common Files\LightScribe\LSSrvc.exe
PRC - [2007/08/23 17:36:30 | 000,455,968 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
PRC - [2007/08/17 08:27:00 | 004,702,208 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe
PRC - [2007/05/16 13:43:06 | 000,677,432 | R--- | M] () -- C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
PRC - [2007/05/08 16:24:20 | 000,054,840 | ---- | M] (Hewlett-Packard) -- C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
PRC - [2007/01/17 08:34:18 | 000,634,880 | ---- | M] (Motorola Inc.) -- C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
PRC - [2007/01/09 05:25:30 | 000,272,024 | ---- | M] () -- C:\Program Files\CyberLink\Shared Files\RichVideo.exe
PRC - [2007/01/08 18:53:06 | 000,311,296 | ---- | M] (Hewlett-Packard Development Company, L.P.) -- C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
PRC - [2006/10/23 07:50:35 | 000,046,640 | R--- | M] (AOL LLC) -- C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
PRC - [2006/09/25 19:52:48 | 000,050,736 | ---- | M] (America Online, Inc.) -- C:\Program Files\Common Files\AOL\1216788419\ee\aolsoftware.exe
PRC - [2006/05/02 18:41:28 | 000,135,168 | ---- | M] (Hewlett-Packard Development Company, L.P.) -- C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe


========== Modules (SafeList) ==========

MOD - [2010/02/15 15:38:33 | 000,549,376 | ---- | M] (OldTimer Tools) -- C:\Users\Garrett Gambino.Garrett-PC\Downloads\OTL.exe
MOD - [2008/01/19 02:26:34 | 001,684,480 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Auto | Stopped] -- -- (PEVSystemStart)
SRV - File not found [Auto | Stopped] -- -- (DpHost)
SRV - [2010/02/04 22:41:37 | 000,326,792 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2010/01/22 19:16:30 | 000,545,576 | ---- | M] (Apple Inc.) [On_Demand | Running] -- C:\Program Files\iPod\bin\iPodService.exe -- (iPod Service)
SRV - [2009/08/28 19:42:54 | 000,144,672 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -- (Apple Mobile Device)
SRV - [2009/08/26 22:50:07 | 000,133,104 | ---- | M] (Google Inc.) [Auto | Stopped] -- C:\Program Files\Google\Update\GoogleUpdate.exe -- (gupdate1ca26c983b7a8b0) Google Update Service (gupdate1ca26c983b7a8b0)
SRV - [2009/07/21 13:34:33 | 000,185,089 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2009/05/27 17:00:32 | 000,211,488 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Windows\System32\nvvsvc.exe -- (nvsvc)
SRV - [2009/05/13 15:48:22 | 000,108,289 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2009/03/25 06:46:47 | 000,183,280 | ---- | M] (Google) [Auto | Stopped] -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe -- (gusvc)
SRV - [2008/12/12 11:17:38 | 000,238,888 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files\Bonjour\mDNSResponder.exe -- (Bonjour Service)
SRV - [2008/11/04 01:06:28 | 000,441,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv)
SRV - [2008/06/16 08:02:28 | 000,094,208 | ---- | M] (Hewlett-Packard) [Auto | Running] -- c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe -- (HP Health Check Service)
SRV - [2008/05/05 17:25:46 | 000,165,416 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe -- (GameConsoleService)
SRV - [2008/04/15 16:54:42 | 000,354,840 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON) Intel®
SRV - [2008/01/19 02:38:24 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007/09/30 22:34:54 | 000,271,760 | ---- | M] () [Auto | Running] -- C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe -- (QPCapSvc) QuickPlay Background Capture Service (QBCS)
SRV - [2007/09/30 22:34:54 | 000,112,016 | ---- | M] () [Auto | Running] -- C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe -- (QPSched) QuickPlay Task Scheduler (QTS)
SRV - [2007/08/31 14:15:06 | 000,176,128 | ---- | M] (Starz Entertainment Group LLC) [On_Demand | Stopped] -- C:\Program Files\Vongo\VongoService.exe -- (Vongo Service)
SRV - [2007/08/23 17:40:48 | 000,079,136 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- C:\Program Files\Common Files\LightScribe\LSSrvc.exe -- (LightScribeService)
SRV - [2007/03/05 13:30:06 | 000,110,592 | ---- | M] (Hewlett-Packard Development Company, L.P.) [On_Demand | Stopped] -- C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe -- (Com4Qlb)
SRV - [2007/01/09 05:25:30 | 000,272,024 | ---- | M] () [Auto | Running] -- C:\Program Files\CyberLink\Shared Files\RichVideo.exe -- (RichVideo) Cyberlink RichVideo Service(CRVS)
SRV - [2006/11/02 07:35:29 | 000,013,312 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\ehome\ehstart.dll -- (ehstart)
SRV - [2006/10/26 17:03:08 | 000,145,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose)
SRV - [2006/10/23 07:50:35 | 000,046,640 | R--- | M] (AOL LLC) [Auto | Running] -- C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe -- (AOL ACS)
SRV - [2006/05/02 18:41:28 | 000,135,168 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Auto | Running] -- C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe -- (hpqwmiex)
SRV - [2005/04/04 00:41:10 | 000,069,632 | ---- | M] (Macrovision Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe -- (IDriverT)


========== Driver Services (SafeList) ==========

DRV - [2010/02/15 15:10:51 | 000,031,744 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Users\Garrett\AppData\Local\Temp\catchme.sys -- (catchme)
DRV - [2009/11/25 11:19:02 | 000,056,816 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2009/08/28 19:42:52 | 000,040,448 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\usbaapl.sys -- (USBAAPL)
DRV - [2009/08/19 13:35:00 | 009,787,488 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2009/05/18 14:17:00 | 000,026,600 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV - [2009/05/11 09:12:24 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2009/05/09 00:14:20 | 000,014,736 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nuidfltr.sys -- (NuidFltr)
DRV - [2009/03/30 09:33:07 | 000,096,104 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb)
DRV - [2009/02/13 11:35:05 | 000,011,608 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Program Files\Avira\AntiVir Desktop\avgio.sys -- (avgio)
DRV - [2008/04/15 16:53:44 | 000,312,344 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\iaStor.sys -- (iaStor)
DRV - [2008/03/28 02:06:00 | 000,199,472 | ---- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\SynTP.sys -- (SynTP)
DRV - [2007/09/17 18:17:36 | 000,098,816 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtlh86.sys -- (RTL8169)
DRV - [2007/08/28 18:47:36 | 000,146,560 | ---- | M] (AuthenTec, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atswpdrv.sys -- (ATSWPDRV) AuthenTec TruePrint USB Driver (SwipeSensor)
DRV - [2007/08/22 13:44:18 | 001,950,552 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\RTKVHDA.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2007/07/11 13:30:22 | 000,007,168 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HpqRemHid.sys -- (HpqRemHid)
DRV - [2007/06/28 10:09:56 | 002,222,080 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\NETw4v32.sys -- (NETw4v32) Intel®
DRV - [2007/06/18 20:12:04 | 000,016,768 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HpqKbFiltr.sys -- (HpqKbFiltr)
DRV - [2007/04/03 12:59:42 | 000,098,568 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s616obex.sys -- (s616obex)
DRV - [2007/04/03 12:59:40 | 000,100,360 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s616mgmt.sys -- (s616mgmt) Sony Ericsson Device 616 USB WMC Device Management Drivers (WDM)
DRV - [2007/04/03 12:59:38 | 000,108,680 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s616mdm.sys -- (s616mdm)
DRV - [2007/04/03 12:59:36 | 000,015,112 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s616mdfl.sys -- (s616mdfl)
DRV - [2007/04/03 12:59:30 | 000,083,208 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s616bus.sys -- (s616bus) Sony Ericsson Device 616 driver (WDM)
DRV - [2007/03/22 01:02:04 | 000,037,376 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rixdptsk.sys -- (rismxdp)
DRV - [2007/02/24 17:42:22 | 000,039,936 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimmptsk.sys -- (rimmptsk)
DRV - [2007/01/23 19:40:20 | 000,042,496 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimsptsk.sys -- (rimsptsk)
DRV - [2007/01/17 08:38:52 | 000,983,936 | ---- | M] (Motorola Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\smserial.sys -- (smserial)
DRV - [2006/11/02 04:51:45 | 000,900,712 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ql2300.sys -- (ql2300)
DRV - [2006/11/02 04:51:38 | 000,420,968 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adp94xx.sys -- (adp94xx)
DRV - [2006/11/02 04:51:34 | 000,316,520 | ---- | M] (Emulex) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\elxstor.sys -- (elxstor)
DRV - [2006/11/02 04:51:32 | 000,297,576 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adpahci.sys -- (adpahci)
DRV - [2006/11/02 04:51:25 | 000,235,112 | ---- | M] (ULi Electronics Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\uliahci.sys -- (uliahci)
DRV - [2006/11/02 04:51:25 | 000,232,040 | ---- | M] (Intel Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iastorv.sys -- (iaStorV)
DRV - [2006/11/02 04:51:00 | 000,147,048 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adpu320.sys -- (adpu320)
DRV - [2006/11/02 04:50:45 | 000,115,816 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ulsata2.sys -- (ulsata2)
DRV - [2006/11/02 04:50:41 | 000,112,232 | ---- | M] (VIA Technologies Inc.,Ltd) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\vsmraid.sys -- (vsmraid)
DRV - [2006/11/02 04:50:35 | 000,106,088 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ql40xx.sys -- (ql40xx)
DRV - [2006/11/02 04:50:35 | 000,098,408 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ulsata.sys -- (UlSata)
DRV - [2006/11/02 04:50:35 | 000,098,408 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adpu160m.sys -- (adpu160m)
DRV - [2006/11/02 04:50:24 | 000,088,680 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nvraid.sys -- (nvraid)
DRV - [2006/11/02 04:50:19 | 000,045,160 | ---- | M] (IBM Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nfrd960.sys -- (nfrd960)
DRV - [2006/11/02 04:50:17 | 000,041,576 | ---- | M] (Intel Corp./ICP vortex GmbH) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iirsp.sys -- (iirsp)
DRV - [2006/11/02 04:50:16 | 000,071,784 | ---- | M] (Silicon Integrated Systems) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sisraid4.sys -- (SiSRaid4)
DRV - [2006/11/02 04:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nvstor.sys -- (nvstor)
DRV - [2006/11/02 04:50:11 | 000,071,272 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\djsvs.sys -- (aic78xx)
DRV - [2006/11/02 04:50:10 | 000,067,688 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\arcsas.sys -- (arcsas)
DRV - [2006/11/02 04:50:10 | 000,065,640 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\lsi_scsi.sys -- (LSI_SCSI)
DRV - [2006/11/02 04:50:10 | 000,038,504 | ---- | M] (Silicon Integrated Systems Corp.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sisraid2.sys -- (SiSRaid2)
DRV - [2006/11/02 04:50:10 | 000,037,480 | ---- | M] (Hewlett-Packard Company) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\hpcisss.sys -- (HpCISSs)
DRV - [2006/11/02 04:50:09 | 000,067,688 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\arc.sys -- (arc)
DRV - [2006/11/02 04:50:09 | 000,035,944 | ---- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iteraid.sys -- (iteraid)
DRV - [2006/11/02 04:50:07 | 000,035,944 | ---- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iteatapi.sys -- (iteatapi)
DRV - [2006/11/02 04:50:05 | 000,065,640 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\lsi_sas.sys -- (LSI_SAS)
DRV - [2006/11/02 04:50:05 | 000,035,944 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\symc8xx.sys -- (Symc8xx)
DRV - [2006/11/02 04:50:04 | 000,065,640 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\lsi_fc.sys -- (LSI_FC)
DRV - [2006/11/02 04:50:03 | 000,034,920 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sym_u3.sys -- (Sym_u3)
DRV - [2006/11/02 04:49:59 | 000,033,384 | ---- | M] (LSI Logic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\mraid35x.sys -- (Mraid35x)
DRV - [2006/11/02 04:49:56 | 000,031,848 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sym_hi.sys -- (Sym_hi)
DRV - [2006/11/02 04:49:53 | 000,028,776 | ---- | M] (LSI Logic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\megasas.sys -- (megasas)
DRV - [2006/11/02 04:49:30 | 000,017,512 | ---- | M] (VIA Technologies, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\viaide.sys -- (viaide)
DRV - [2006/11/02 04:49:28 | 000,016,488 | ---- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\cmdide.sys -- (cmdide)
DRV - [2006/11/02 04:49:20 | 000,014,952 | ---- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\aliide.sys -- (aliide)
DRV - [2006/11/02 03:25:24 | 000,071,808 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\brserid.sys -- (Brserid) Brother MFC Serial Port Interface Driver (WDM)
DRV - [2006/11/02 03:24:47 | 000,011,904 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brusbser.sys -- (BrUsbSer)
DRV - [2006/11/02 03:24:46 | 000,005,248 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brfiltup.sys -- (BrFiltUp)
DRV - [2006/11/02 03:24:45 | 000,013,568 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brfiltlo.sys -- (BrFiltLo)
DRV - [2006/11/02 03:24:44 | 000,062,336 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\brserwdm.sys -- (BrSerWdm)
DRV - [2006/11/02 03:24:44 | 000,012,160 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\brusbmdm.sys -- (BrUsbMdm)
DRV - [2006/11/02 02:41:50 | 000,987,648 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VSTDPV3.SYS -- (HSF_DPV)
DRV - [2006/11/02 02:41:49 | 000,200,704 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VSTAZL3.SYS -- (HSFHWAZL)
DRV - [2006/11/02 02:41:48 | 000,654,336 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VSTCNXT3.SYS -- (winachsf)
DRV - [2006/11/02 02:36:50 | 000,020,608 | ---- | M] (N-trig Innovative Technologies) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ntrigdigi.sys -- (ntrigdigi)
DRV - [2006/11/02 02:30:54 | 000,163,328 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\e100b325.sys -- (E100B) Intel®
DRV - [2006/11/02 02:30:54 | 000,117,760 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\E1G60I32.sys -- (E1G60) Intel®
DRV - [2006/11/02 02:30:53 | 000,464,384 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\BCMWL6.SYS -- (BCM43XV)
DRV - [2006/11/02 01:37:21 | 000,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\secdrv.sys -- (secdrv)
DRV - [2006/11/01 15:18:15 | 000,033,588 | ---- | M] (America Online, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\wanatw4.sys -- (wanatw) WAN Miniport (ATW)
DRV - [2006/10/18 21:10:57 | 001,380,864 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\igdkmd32.sys -- (ialm)
DRV - [2004/06/09 18:42:38 | 000,015,429 | ---- | M] ( ) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\Sacm2A.sys -- (USBCM)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.h...ilion&pf=laptop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.h...ilion&pf=laptop

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.h...ilion&pf=laptop
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.h...ilion&pf=laptop
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultthis.engineName: "Search Powered by Google"
FF - prefs.js..browser.search.defaulturl: "http://search.condui...={searchTerms}"
FF - prefs.js..browser.search.selectedEngine: "Search Powered by Google"
FF - prefs.js..browser.startup.homepage: "http://thechumslick.com"
FF - prefs.js..extensions.enabledItems: toolbar@alexa.com:1.4.7
FF - prefs.js..extensions.enabledItems: {a7c6cf7f-112c-4500-a7ea-39801a327e5f}:1.0.7
FF - prefs.js..extensions.enabledItems: {9BAE5926-8513-417d-8E47-774955A7C60D}:1.1.1d
FF - prefs.js..extensions.enabledItems: foxyproxy@eric.h.jung:2.18.1
FF - prefs.js..extensions.enabledItems: {31c7d459-9cc3-44f2-9dca-fc11795309b4}:2.5.6.0
FF - prefs.js..extensions.enabledItems: quickdrag@mozilla.ktechcomputing.com:2.0.2.1
FF - prefs.js..extensions.enabledItems: smartwebprinting@hp.com:4.60
FF - prefs.js..keyword.URL: "http://recovery.alex...word&location="


FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Program Files\Real\RealPlayer\browserrecord [2008/12/10 04:35:19 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/02/11 16:21:27 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.7\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/02/11 14:12:46 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.7\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/01/10 00:21:00 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.14\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2009/12/25 03:39:19 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.14\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2009/12/25 03:39:18 | 000,000,000 | ---D | M]

[2010/01/28 14:55:25 | 000,000,000 | ---D | M] -- C:\Users\Garrett Gambino.Garrett-PC\AppData\Roaming\mozilla\Extensions
[2010/02/15 14:06:34 | 000,000,000 | ---D | M] -- C:\Users\Garrett Gambino.Garrett-PC\AppData\Roaming\mozilla\Firefox\Profiles\rg5bgv30.default\extensions
[2010/02/01 17:54:39 | 000,000,000 | ---D | M] (IObitCom Toolbar) -- C:\Users\Garrett Gambino.Garrett-PC\AppData\Roaming\mozilla\Firefox\Profiles\rg5bgv30.default\extensions\{31c7d459-9cc3-44f2-9dca-fc11795309b4}
[2010/01/29 23:02:06 | 000,000,000 | ---D | M] (FireFTP button) -- C:\Users\Garrett Gambino.Garrett-PC\AppData\Roaming\mozilla\Firefox\Profiles\rg5bgv30.default\extensions\{9BAE5926-8513-417d-8E47-774955A7C60D}
[2010/01/29 23:02:07 | 000,000,000 | ---D | M] (FireFTP) -- C:\Users\Garrett Gambino.Garrett-PC\AppData\Roaming\mozilla\Firefox\Profiles\rg5bgv30.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}
[2010/01/29 23:02:12 | 000,000,000 | ---D | M] -- C:\Users\Garrett Gambino.Garrett-PC\AppData\Roaming\mozilla\Firefox\Profiles\rg5bgv30.default\extensions\foxyproxy@eric.h.jung
[2010/01/29 23:02:07 | 000,000,000 | ---D | M] -- C:\Users\Garrett Gambino.Garrett-PC\AppData\Roaming\mozilla\Firefox\Profiles\rg5bgv30.default\extensions\quickdrag@mozilla.ktechcomputing.com
[2010/02/11 18:03:14 | 000,000,000 | ---D | M] -- C:\Users\Garrett Gambino.Garrett-PC\AppData\Roaming\mozilla\Firefox\Profiles\rg5bgv30.default\extensions\toolbar@alexa.com
[2009/12/19 22:34:36 | 000,000,907 | ---- | M] () -- C:\Users\Garrett Gambino.Garrett-PC\AppData\Roaming\Mozilla\FireFox\Profiles\rg5bgv30.default\searchplugins\conduit.xml
[2010/02/12 23:13:02 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2008/06/18 02:43:04 | 000,086,016 | ---- | M] (Coupons, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll

O1 HOSTS File: ([2006/09/18 16:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Verizon Broadband Toolbar) - {4E7BD74F-2B8D-469E-8CB0-AB60BB9AAE22} - Reg Error: Value error. File not found
O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No CLSID value found.
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (Verizon Broadband Toolbar) - {4E7BD74F-2B8D-469E-8CB0-AB60BB9AAE22} - Reg Error: Value error. File not found
O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [HostManager] C:\Program Files\Common Files\AOL\1216788419\ee\aolsoftware.exe (America Online, Inc.)
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard)
O4 - HKLM..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\HpqSRmon.exe (Hewlett-Packard)
O4 - HKLM..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [OnScreenDisplay] C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe ( Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [QlbCtrl] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe ( Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [QPService] C:\Program Files\HP\QuickPlay\QPService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe (Motorola Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UCam_Menu] C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [WAWifiMessage] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [HPADVISOR] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe (Hewlett-Packard)
O4 - HKCU..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe (Hewlett-Packard Company)
O4 - HKCU..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Garrett Gambino.Garrett-PC\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Garrett Gambino.Garrett-PC\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/11/27 02:38:30 | 000,000,074 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2005/09/11 10:18:54 | 000,000,340 | -HS- | M] () - D:\AUTOMODE -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] -- "%1" %*
O35 - exefile [open] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/02/15 15:19:33 | 000,000,000 | --SD | C] -- C:\ComboFix
[2010/02/15 15:19:13 | 000,212,480 | ---- | C] (SteelWerX) -- C:\Windows\SWXCACLS.exe
[2010/02/15 15:19:12 | 000,000,000 | ---D | C] -- C:\32788R22FWJFW
[2010/02/12 23:25:56 | 000,000,000 | --SD | C] -- C:\Users\Garrett Gambino.Garrett-PC\Desktop\ComboFix
[2010/02/11 18:03:19 | 000,000,000 | ---D | C] -- C:\Users\Garrett Gambino.Garrett-PC\AppData\Roaming\HPAppData
[2010/02/11 15:07:20 | 000,161,792 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2010/02/11 15:07:20 | 000,031,232 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2010/02/11 15:07:19 | 000,136,704 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2010/02/11 14:55:57 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2010/02/11 14:37:13 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010/02/10 13:10:03 | 003,597,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
[2010/02/10 13:10:03 | 003,546,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
[2010/02/10 13:09:49 | 001,314,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\quartz.dll
[2010/02/10 13:09:49 | 000,082,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mciavi32.dll
[2010/02/10 13:09:49 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\avicap32.dll
[2010/02/10 13:09:48 | 000,123,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msvfw32.dll
[2010/02/10 13:09:48 | 000,091,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\avifil32.dll
[2010/02/08 00:35:52 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2010/02/02 19:58:51 | 000,000,000 | ---D | C] -- C:\bf433aea21884a84a9ea4711912ececd
[2010/02/02 19:56:39 | 000,000,000 | ---D | C] -- C:\f270c6d5cd235a6d892d36
[2010/02/02 19:24:16 | 000,000,000 | ---D | C] -- C:\Windows\System32\EventProviders
[2010/02/02 19:12:48 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2010/02/02 17:32:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Office Genuine Advantage
[2010/02/02 17:32:12 | 000,000,000 | ---D | C] -- C:\Users\Garrett Gambino.Garrett-PC\Office Genuine Advantage
[2010/01/31 15:36:49 | 000,000,000 | ---D | C] -- C:\Users\Garrett Gambino.Garrett-PC\AppData\Local\Adobe
[2010/01/30 17:12:25 | 000,000,000 | ---D | C] -- C:\Program Files\Conduit
[2010/01/30 17:12:22 | 000,000,000 | ---D | C] -- C:\Program Files\IObitCom
[2010/01/30 17:11:28 | 000,000,000 | ---D | C] -- C:\Users\Garrett Gambino.Garrett-PC\AppData\Roaming\IObit
[2010/01/30 17:11:28 | 000,000,000 | ---D | C] -- C:\Program Files\IObit
[2010/01/30 12:04:53 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2010/01/29 23:34:55 | 000,000,000 | ---D | C] -- C:\ProgramData\WindowsSearch
[2010/01/29 21:47:24 | 000,096,104 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avipbb.sys
[2010/01/29 21:47:24 | 000,056,816 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avgntflt.sys
[2010/01/29 21:47:23 | 000,028,520 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\ssmdrv.sys
[2010/01/29 21:47:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira
[2010/01/29 21:47:21 | 000,000,000 | ---D | C] -- C:\Program Files\Avira
[2010/01/29 21:28:09 | 000,000,000 | ---D | C] -- C:\Users\Garrett Gambino.Garrett-PC\AppData\Roaming\PandoraRecovery
[2010/01/29 18:51:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Downloaded Installations
[2010/01/29 17:44:20 | 000,000,000 | ---D | C] -- C:\Users\Garrett Gambino.Garrett-PC\AppData\Roaming\Malwarebytes
[2010/01/29 03:13:46 | 000,000,000 | ---D | C] -- C:\Users\Garrett Gambino.Garrett-PC\AppData\Local\Apple
[2010/01/29 03:01:09 | 000,000,000 | ---D | C] -- C:\88684033d6dc950f95
[2010/01/28 17:26:50 | 000,000,000 | ---D | C] -- C:\Users\Garrett Gambino.Garrett-PC\AppData\Roaming\Apple Computer
[2010/01/28 17:26:50 | 000,000,000 | ---D | C] -- C:\Users\Garrett Gambino.Garrett-PC\AppData\Local\Apple Computer
[2010/01/28 14:57:11 | 000,000,000 | ---D | C] -- C:\Users\Garrett Gambino.Garrett-PC\AppData\Roaming\Adobe
[2010/01/28 14:56:37 | 000,000,000 | ---D | C] -- C:\Users\Garrett Gambino.Garrett-PC\AppData\Local\AVG Security Toolbar
[2010/01/28 14:56:16 | 000,156,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\t2embed.dll
[2010/01/28 14:56:14 | 000,072,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\fontsub.dll
[2010/01/28 14:56:03 | 000,000,000 | ---D | C] -- C:\Users\Garrett Gambino.Garrett-PC\AppData\Local\Hewlett-Packard
[2010/01/28 14:55:40 | 001,469,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2010/01/28 14:55:40 | 000,594,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2010/01/28 14:55:40 | 000,387,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
[2010/01/28 14:55:40 | 000,164,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2010/01/28 14:55:39 | 001,638,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2010/01/28 14:55:39 | 000,184,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
[2010/01/28 14:55:39 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
[2010/01/28 14:55:39 | 000,133,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2010/01/28 14:55:39 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll
[2010/01/28 14:55:39 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
[2010/01/28 14:55:39 | 000,055,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
[2010/01/28 14:55:39 | 000,055,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
[2010/01/28 14:55:39 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2010/01/28 14:55:39 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
[2010/01/28 14:55:05 | 000,000,000 | ---D | C] -- C:\Users\Garrett Gambino.Garrett-PC\AppData\Local\Mozilla
[2010/01/28 14:55:04 | 000,000,000 | ---D | C] -- C:\Users\Garrett Gambino.Garrett-PC\AppData\Roaming\Mozilla
[2010/01/28 14:48:07 | 000,000,000 | ---D | C] -- C:\Users\Garrett Gambino.Garrett-PC\AppData\Roaming\Hewlett-Packard
[2010/01/28 14:46:55 | 000,000,000 | ---D | C] -- C:\Users\Garrett Gambino.Garrett-PC\AppData\Local\AOL
[2010/01/28 14:46:30 | 000,000,000 | ---D | C] -- C:\Users\Garrett Gambino.Garrett-PC\AppData\Local\QuickPlay
[2010/01/28 14:46:19 | 000,000,000 | ---D | C] -- C:\Users\Garrett Gambino.Garrett-PC\AppData\Roaming\Real
[2010/01/28 14:46:02 | 000,000,000 | ---D | C] -- C:\Users\Garrett Gambino.Garrett-PC\AppData\Roaming\DigitalPersona
[2010/01/28 14:46:02 | 000,000,000 | ---D | C] -- C:\Users\Garrett Gambino.Garrett-PC\AppData\Local\DigitalPersona
[2010/01/28 14:46:00 | 000,000,000 | ---D | C] -- C:\Users\Garrett Gambino.Garrett-PC\AppData\Roaming\Macrovision
[2010/01/28 14:45:28 | 000,000,000 | R--D | C] -- C:\Users\Garrett Gambino.Garrett-PC\Searches
[2010/01/28 14:45:15 | 000,000,000 | ---D | C] -- C:\Users\Garrett Gambino.Garrett-PC\AppData\Roaming\Identities
[2010/01/28 14:45:12 | 000,000,000 | R--D | C] -- C:\Users\Garrett Gambino.Garrett-PC\Contacts
[2010/01/28 14:44:58 | 000,000,000 | ---D | C] -- C:\Users\Garrett Gambino.Garrett-PC\AppData\Local\VirtualStore
[2010/01/28 14:44:52 | 000,000,000 | -HSD | C] -- C:\Users\Garrett Gambino\AppData\Local\Temporary Internet Files
[2010/01/28 14:44:52 | 000,000,000 | -HSD | C] -- C:\Users\Garrett Gambino.Garrett-PC\Templates
[2010/01/28 14:44:52 | 000,000,000 | -HSD | C] -- C:\Users\Garrett Gambino.Garrett-PC\Start Menu
[2010/01/28 14:44:52 | 000,000,000 | -HSD | C] -- C:\Users\Garrett Gambino.Garrett-PC\SendTo
[2010/01/28 14:44:52 | 000,000,000 | -HSD | C] -- C:\Users\Garrett Gambino.Garrett-PC\Recent
[2010/01/28 14:44:52 | 000,000,000 | -HSD | C] -- C:\Users\Garrett Gambino.Garrett-PC\PrintHood
[2010/01/28 14:44:52 | 000,000,000 | -HSD | C] -- C:\Users\Garrett Gambino.Garrett-PC\NetHood
[2010/01/28 14:44:52 | 000,000,000 | -HSD | C] -- C:\Users\Garrett Gambino.Garrett-PC\Documents\My Videos
[2010/01/28 14:44:52 | 000,000,000 | -HSD | C] -- C:\Users\Garrett Gambino.Garrett-PC\Documents\My Pictures
[2010/01/28 14:44:52 | 000,000,000 | -HSD | C] -- C:\Users\Garrett Gambino.Garrett-PC\Documents\My Music
[2010/01/28 14:44:52 | 000,000,000 | -HSD | C] -- C:\Users\Garrett Gambino.Garrett-PC\My Documents
[2010/01/28 14:44:52 | 000,000,000 | -HSD | C] -- C:\Users\Garrett Gambino.Garrett-PC\Local Settings
[2010/01/28 14:44:52 | 000,000,000 | -HSD | C] -- C:\Users\Garrett Gambino\AppData\Local\History
[2010/01/28 14:44:52 | 000,000,000 | -HSD | C] -- C:\Users\Garrett Gambino.Garrett-PC\Cookies
[2010/01/28 14:44:52 | 000,000,000 | -HSD | C] -- C:\Users\Garrett Gambino\AppData\Local\Application Data
[2010/01/28 14:44:52 | 000,000,000 | -HSD | C] -- C:\Users\Garrett Gambino.Garrett-PC\Application Data
[2010/01/28 14:44:49 | 000,000,000 | --SD | C] -- C:\Users\Garrett Gambino\AppData\Roaming\Microsoft
[2010/01/28 14:44:49 | 000,000,000 | R--D | C] -- C:\Users\Garrett Gambino.Garrett-PC\Videos
[2010/01/28 14:44:49 | 000,000,000 | R--D | C] -- C:\Users\Garrett Gambino.Garrett-PC\Saved Games
[2010/01/28 14:44:49 | 000,000,000 | R--D | C] -- C:\Users\Garrett Gambino.Garrett-PC\Pictures
[2010/01/28 14:44:49 | 000,000,000 | R--D | C] -- C:\Users\Garrett Gambino.Garrett-PC\Music
[2010/01/28 14:44:49 | 000,000,000 | R--D | C] -- C:\Users\Garrett Gambino.Garrett-PC\Links
[2010/01/28 14:44:49 | 000,000,000 | R--D | C] -- C:\Users\Garrett Gambino.Garrett-PC\Favorites
[2010/01/28 14:44:49 | 000,000,000 | R--D | C] -- C:\Users\Garrett Gambino.Garrett-PC\Downloads
[2010/01/28 14:44:49 | 000,000,000 | R--D | C] -- C:\Users\Garrett Gambino.Garrett-PC\Documents
[2010/01/28 14:44:49 | 000,000,000 | R--D | C] -- C:\Users\Garrett Gambino.Garrett-PC\Desktop
[2010/01/28 14:44:49 | 000,000,000 | -H-D | C] -- C:\Users\Garrett Gambino.Garrett-PC\AppData
[2010/01/28 14:44:49 | 000,000,000 | ---D | C] -- C:\Users\Garrett Gambino\AppData\Local\Temp
[2010/01/28 14:44:49 | 000,000,000 | ---D | C] -- C:\Users\Garrett Gambino\AppData\Local\Microsoft Help
[2010/01/28 14:44:49 | 000,000,000 | ---D | C] -- C:\Users\Garrett Gambino\AppData\Local\Microsoft
[2010/01/28 14:44:49 | 000,000,000 | ---D | C] -- C:\Users\Garrett Gambino\AppData\Roaming\Media Center Programs
[2010/01/28 14:44:49 | 000,000,000 | ---D | C] -- C:\Users\Garrett Gambino\AppData\Roaming\Macromedia
[2009/07/29 21:35:22 | 000,015,429 | ---- | C] ( ) -- C:\Windows\System32\drivers\Sacm2A.sys

========== Files - Modified Within 30 Days ==========

[2010/02/15 15:39:22 | 001,835,008 | ---- | M] () -- C:\Users\Garrett Gambino.Garrett-PC\NTUSER.DAT
[2010/02/15 15:38:59 | 000,000,422 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{F6AC1609-10BD-4C75-8CA3-C636473A7640}.job
[2010/02/15 15:36:02 | 000,000,868 | ---- | M] () -- C:\Windows\tasks\Google Software Updater.job
[2010/02/15 15:34:48 | 000,000,162 | ---- | M] () -- C:\Users\Public\Documents\hpqp.ini
[2010/02/15 15:34:09 | 000,065,973 | ---- | M] () -- C:\ProgramData\nvModes.dat
[2010/02/15 15:34:09 | 000,065,973 | ---- | M] () -- C:\ProgramData\nvModes.001
[2010/02/15 15:34:07 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/02/15 15:33:51 | 000,003,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/02/15 15:33:50 | 000,003,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/02/15 15:33:36 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010/02/15 15:33:33 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010/02/15 15:09:04 | 000,000,680 | ---- | M] () -- C:\Users\Garrett Gambino.Garrett-PC\AppData\Local\d3d9caps.dat
[2010/02/15 14:52:37 | 000,524,288 | -HS- | M] () -- C:\Users\Garrett Gambino.Garrett-PC\NTUSER.DAT{d750467f-1740-11df-bc91-00038a000015}.TMContainer00000000000000000001.regtrans-ms
[2010/02/15 14:52:37 | 000,065,536 | -HS- | M] () -- C:\Users\Garrett Gambino.Garrett-PC\NTUSER.DAT{d750467f-1740-11df-bc91-00038a000015}.TM.blf
[2010/02/15 14:52:35 | 001,868,319 | -H-- | M] () -- C:\Users\Garrett Gambino.Garrett-PC\AppData\Local\IconCache.db
[2010/02/15 14:15:00 | 000,000,916 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-177710785-2220449698-3202377136-1000UA.job
[2010/02/15 14:12:01 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/02/14 19:15:00 | 000,000,864 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-177710785-2220449698-3202377136-1000Core.job
[2010/02/13 00:29:08 | 000,038,445 | ---- | M] () -- C:\Users\Garrett Gambino.Garrett-PC\Desktop\HUNG 12.14.07.docx
[2010/02/12 22:24:51 | 000,002,349 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Vongo Tray.lnk
[2010/02/12 19:56:54 | 000,172,443 | ---- | M] () -- C:\Users\Garrett Gambino.Garrett-PC\Desktop\EE Form Fiction - PWI-639941.docx
[2010/02/12 00:39:22 | 000,443,356 | ---- | M] () -- C:\Users\Garrett Gambino.Garrett-PC\Desktop\02092010_Sink the Kamkara_MS.docx
[2010/02/11 16:22:10 | 000,023,094 | ---- | M] () -- C:\Windows\hpqins15.dat
[2010/02/11 16:20:48 | 000,017,387 | ---- | M] () -- C:\Users\Garrett Gambino.Garrett-PC\Desktop\2.10.10-bacon.jpg
[2010/02/11 16:13:21 | 000,044,496 | ---- | M] () -- C:\Users\Garrett Gambino.Garrett-PC\Desktop\2.10.10-notabite.jpg
[2010/02/11 15:06:30 | 003,855,831 | R--- | M] () -- C:\Users\Garrett Gambino.Garrett-PC\Desktop\ComboFix(2).exe
[2010/02/11 14:56:50 | 000,524,288 | -HS- | M] () -- C:\Users\Garrett Gambino.Garrett-PC\NTUSER.DAT{d750467f-1740-11df-bc91-00038a000015}.TMContainer00000000000000000002.regtrans-ms
[2010/02/11 14:54:29 | 000,524,288 | -HS- | M] () -- C:\Users\Garrett Gambino.Garrett-PC\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms
[2010/02/11 14:54:29 | 000,065,536 | -HS- | M] () -- C:\Users\Garrett Gambino.Garrett-PC\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf
[2010/02/09 15:03:46 | 000,000,162 | -H-- | M] () -- C:\Users\Garrett Gambino.Garrett-PC\Desktop\~$mbino, Garrett-Invoice 43_2-22-10.docx
[2010/02/09 15:03:45 | 000,014,822 | ---- | M] () -- C:\Users\Garrett Gambino.Garrett-PC\Desktop\Gambino, Garrett-Invoice 43_2-22-10.docx
[2010/02/09 03:37:39 | 000,065,233 | ---- | M] () -- C:\Users\Garrett Gambino.Garrett-PC\Desktop\OBAMA.jpg
[2010/02/09 01:38:59 | 000,169,583 | ---- | M] () -- C:\Users\Garrett Gambino.Garrett-PC\Desktop\EE Form Fiction - PWI-835765.docx
[2010/02/08 18:54:42 | 000,000,162 | -H-- | M] () -- C:\Users\Garrett Gambino.Garrett-PC\Desktop\~$052010_The day the sun shed bloody tears_MS (Autosaved).docx
[2010/02/08 16:45:13 | 000,000,162 | -H-- | M] () -- C:\Users\Garrett Gambino.Garrett-PC\Desktop\~$ver Copy Marketing Text-Editorial - 193843.docx
[2010/02/08 16:45:05 | 000,000,162 | -H-- | M] () -- C:\Users\Garrett Gambino.Garrett-PC\Desktop\~$ Form Fiction - PWI-835765.docx
[2010/02/08 15:16:46 | 000,034,968 | ---- | M] () -- C:\Users\Garrett Gambino.Garrett-PC\Desktop\Cover Copy Marketing Text-Editorial - 193843.docx
[2010/02/08 00:37:02 | 000,001,804 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2010/02/08 00:16:22 | 000,000,404 | ---- | M] () -- C:\Windows\tasks\SmartDefrag.job
[2010/02/06 18:16:07 | 000,027,604 | ---- | M] () -- C:\Users\Garrett Gambino.Garrett-PC\Desktop\2.6.10-gw2.jpg
[2010/02/06 18:13:04 | 000,028,607 | ---- | M] () -- C:\Users\Garrett Gambino.Garrett-PC\Desktop\2.6.10-gw.jpg
[2010/02/04 15:10:29 | 000,037,221 | ---- | M] () -- C:\Users\Garrett Gambino.Garrett-PC\Desktop\2.4.10-sorry.jpg
[2010/02/03 14:45:45 | 000,000,162 | -H-- | M] () -- C:\Users\Garrett Gambino.Garrett-PC\Desktop\~$ Form Fiction - PWI-728091x.docx
[2010/02/03 14:04:39 | 000,000,162 | -H-- | M] () -- C:\Users\Garrett Gambino.Garrett-PC\Desktop\~$ Form Fiction - PWI-728091.docx
[2010/02/02 21:14:58 | 000,056,445 | ---- | M] () -- C:\Users\Garrett Gambino.Garrett-PC\Desktop\2.2.10-thecove.jpg
[2010/02/02 19:20:35 | 000,085,328 | ---- | M] () -- C:\Users\Garrett Gambino.Garrett-PC\AppData\Local\GDIPFONTCACHEV1.DAT
[2010/02/02 19:17:58 | 000,339,352 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2010/02/02 19:14:26 | 000,009,646 | ---- | M] () -- C:\Users\Garrett Gambino.Garrett-PC\Documents\cc_20100202_191354.reg
[2010/02/02 19:12:49 | 000,001,670 | ---- | M] () -- C:\Users\Garrett Gambino.Garrett-PC\Desktop\CCleaner.lnk
[2010/02/02 17:32:12 | 000,000,162 | -H-- | M] () -- C:\Users\Garrett Gambino.Garrett-PC\Desk

#10 lance_yien

lance_yien

    Forum Deity

  • Retired Staff
  • PipPipPipPipPip
  • 2,442 posts

Posted 16 February 2010 - 11:22 AM

Hello eltiburon

Your logs show that IObitCom Toolbar and Conduit "Community Toolbar" are installed on your computer. They are reputed to modify the default IE URL search hook and to have a certain trackware functionality.

I recommend you uninstall any program relayted to IObit from the "Control Panel" => "Add or Remove Programs":

Conduit
IObitCom
IObit
Advanced SystemCare
...


To remove every last trace of the entries of IObit programs left behind please download BitRemover to your Desktop from here and run it.

Then, please run OTL. Copy and paste these lines in the "Custom Scans/Fixes" window (under the light green bar):

:otl

[2010/02/01 17:54:39 | 000,000,000 | ---D | M] (IObitCom Toolbar) -- C:\Users\Garrett Gambino.Garrett-PC\AppData\Roaming\mozilla\Firefox\Profiles\rg5bgv30.default\extensions\{31c7d459-9cc3-44f2-9dca-fc11795309b4}
[2009/12/19 22:34:36 | 000,000,907 | ---- | M] () -- C:\Users\Garrett Gambino.Garrett-PC\AppData\Roaming\Mozilla\FireFox\Profiles\rg5bgv30.default\searchplugins\conduit.xml
O2 - BHO: (Verizon Broadband Toolbar) - {4E7BD74F-2B8D-469E-8CB0-AB60BB9AAE22} - Reg Error: Value error. File not found
O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Verizon Broadband Toolbar) - {4E7BD74F-2B8D-469E-8CB0-AB60BB9AAE22} - Reg Error: Value error. File not found
O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
[2010/01/30 17:12:25 | 000,000,000 | ---D | C] -- C:\Program Files\Conduit
[2010/01/30 17:12:22 | 000,000,000 | ---D | C] -- C:\Program Files\IObitCom
[2010/01/30 17:11:28 | 000,000,000 | ---D | C] -- C:\Users\Garrett Gambino.Garrett-PC\AppData\Roaming\IObit
[2010/01/30 17:11:28 | 000,000,000 | ---D | C] -- C:\Program Files\IObit
[2010/01/30 17:12:22 | 000,001,014 | ---- | M] () -- C:\Users\Public\Desktop\Advanced SystemCare.lnk


Now, click the red Run Fix button.

If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.
A fix log in Notepad will appear and saved on your Desktop.

Please close OTL and post the contents of this fix log.

LY
EI | SWI | ZEBULON | Posted Image | Posted Image

My help is free, but if you wish to help keep these forums running please consider a donation. Please, see here for details.

#11 eltiburon

eltiburon

    Member

  • Full Member
  • Pip
  • 13 posts

Posted 16 February 2010 - 02:21 PM

I did it like you said. Here is my fix log:

========== OTL ==========
C:\Users\Garrett Gambino.Garrett-PC\AppData\Roaming\mozilla\Firefox\Profiles\rg5bgv30.default\extensions\{31c7d459-9cc3-44f2-9dca-fc11795309b4}\searchplugin folder moved successfully.
C:\Users\Garrett Gambino.Garrett-PC\AppData\Roaming\mozilla\Firefox\Profiles\rg5bgv30.default\extensions\{31c7d459-9cc3-44f2-9dca-fc11795309b4}\META-INF folder moved successfully.
C:\Users\Garrett Gambino.Garrett-PC\AppData\Roaming\mozilla\Firefox\Profiles\rg5bgv30.default\extensions\{31c7d459-9cc3-44f2-9dca-fc11795309b4}\lib folder moved successfully.
C:\Users\Garrett Gambino.Garrett-PC\AppData\Roaming\mozilla\Firefox\Profiles\rg5bgv30.default\extensions\{31c7d459-9cc3-44f2-9dca-fc11795309b4}\defaults folder moved successfully.
C:\Users\Garrett Gambino.Garrett-PC\AppData\Roaming\mozilla\Firefox\Profiles\rg5bgv30.default\extensions\{31c7d459-9cc3-44f2-9dca-fc11795309b4}\components folder moved successfully.
Folder move failed. C:\Users\Garrett Gambino.Garrett-PC\AppData\Roaming\mozilla\Firefox\Profiles\rg5bgv30.default\extensions\{31c7d459-9cc3-44f2-9dca-fc11795309b4}\chrome scheduled to be moved on reboot.
Folder move failed. C:\Users\Garrett Gambino.Garrett-PC\AppData\Roaming\mozilla\Firefox\Profiles\rg5bgv30.default\extensions\{31c7d459-9cc3-44f2-9dca-fc11795309b4} scheduled to be moved on reboot.
C:\Users\Garrett Gambino.Garrett-PC\AppData\Roaming\Mozilla\FireFox\Profiles\rg5bgv30.default\searchplugins\conduit.xml moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4E7BD74F-2B8D-469E-8CB0-AB60BB9AAE22}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4E7BD74F-2B8D-469E-8CB0-AB60BB9AAE22}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{4E7BD74F-2B8D-469E-8CB0-AB60BB9AAE22} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4E7BD74F-2B8D-469E-8CB0-AB60BB9AAE22}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}\ not found.
Folder C:\Program Files\Conduit\ not found.
Folder C:\Program Files\IObitCom\ not found.
C:\Users\Garrett Gambino.Garrett-PC\AppData\Roaming\IObit\SmartRAM folder moved successfully.
C:\Users\Garrett Gambino.Garrett-PC\AppData\Roaming\IObit\InternetBooster folder moved successfully.
C:\Users\Garrett Gambino.Garrett-PC\AppData\Roaming\IObit folder moved successfully.
C:\Program Files\IObit\Game Booster\Language folder moved successfully.
C:\Program Files\IObit\Game Booster folder moved successfully.
C:\Program Files\IObit folder moved successfully.
C:\Users\Public\Desktop\Advanced SystemCare.lnk moved successfully.

OTL by OldTimer - Version 3.1.28.0 log created on 02162010_150139

Files\Folders moved on Reboot...
C:\Users\Garrett Gambino.Garrett-PC\AppData\Roaming\mozilla\Firefox\Profiles\rg5bgv30.default\extensions\{31c7d459-9cc3-44f2-9dca-fc11795309b4}\chrome folder moved successfully.
C:\Users\Garrett Gambino.Garrett-PC\AppData\Roaming\mozilla\Firefox\Profiles\rg5bgv30.default\extensions\{31c7d459-9cc3-44f2-9dca-fc11795309b4} folder moved successfully.

Registry entries deleted on Reboot...

What should I try next?

Again, thanks for the help.

#12 lance_yien

lance_yien

    Forum Deity

  • Retired Staff
  • PipPipPipPipPip
  • 2,442 posts

Posted 17 February 2010 - 03:31 AM

... What should I try next?


Do you still have the same problem?

LY

Edited by lance_yien, 17 February 2010 - 03:31 AM.

EI | SWI | ZEBULON | Posted Image | Posted Image

My help is free, but if you wish to help keep these forums running please consider a donation. Please, see here for details.

#13 eltiburon

eltiburon

    Member

  • Full Member
  • Pip
  • 13 posts

Posted 17 February 2010 - 01:31 PM

Unfortunately the problems remain. I am unable to boot up in my original user account. It freezes at desktop. I am also unable to successfully complete a defrag without the machine freezing.

#14 lance_yien

lance_yien

    Forum Deity

  • Retired Staff
  • PipPipPipPipPip
  • 2,442 posts

Posted 20 February 2010 - 08:13 AM

Hello eltiburon,

Sorry for the delay!

1- Please update:

  • Your Windows Vista to Service Pack 2.
    Windows Vista Service Pack 2 (SP2) contains all the updates released since SP1 plus support for new types of hardware and emerging hardware standards.
    It is now available via Windows Update or as a standalone installation here.

    Next, please go to http://windowsupdate.microsoft.com and download all the "critical updates" for Windows.

    Also, please enable Automatic Updates by clicking Start => All Programs => Windows Update. In the navigation pane, click "Change settings" and select "Automatic (recommended) Automatically download recommended updates for my computer and install them". I cannot stress enough how important this is.
  • Your version of Java is out of date too. Please download to your Desktop the newest version from here.

    It's important that you uninstall older versions of Java. They can leave holes and vulnerabilities on your computer.

    Please, go to Start => Control Panel double-click on the Software icon => Add or Remove programs.
    Search in the list for all previous installed versions of Java (J2SE Runtime Environment.... ).
    They should have this icon next to them: Posted Image
    Select each in turn and click Remove.

    Now install the newest version.
  • Your version of Adobe Acrobat Reader, please uninstall this program and install the latest version from here (make sure to uncheck the install McAfee Security Scan option).

2- If your problems remain:

DRV - [2004/06/09 18:42:38 | 000,015,429 | ---- | M] ( ) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\Sacm2A.sys -- (USBCM)


sacm2a.sys is a Scientific-Atlanta USB cable modem driver

The solution for users with the same problem was to connect the cable modem via Ethernet cable rather than USB. Please try!

Please let me know how the updates went and if you still have any issues.

LY
EI | SWI | ZEBULON | Posted Image | Posted Image

My help is free, but if you wish to help keep these forums running please consider a donation. Please, see here for details.

#15 eltiburon

eltiburon

    Member

  • Full Member
  • Pip
  • 13 posts

Posted 21 February 2010 - 03:52 PM

I updated Vista to service pack 2. Then the computer froze at boot and it took me two hour to get it going again. But I got it going. I updated Java and Acrobat.

I am using a laptop and connected to a router. The router is connected to a modem with a network cable. The only USB involved is my wireless mouse USB. There is no USB involved with my internet connection.

#16 lance_yien

lance_yien

    Forum Deity

  • Retired Staff
  • PipPipPipPipPip
  • 2,442 posts

Posted 23 February 2010 - 04:33 AM

Hello eltiburon,

Lets try the following:

Please, print out these instructions or copy them to a Notepad file for an easer reading.

- Please run the CA PC Security and Performance Scanner here (I suggest you create a free account).
When the tests are complete, a results page will pop up. Copy and paste the URL of the Results screen in your next reply.

- Now, please download DDS Scanning Tool by sUBs to your Desktop from here or here.
Please ensure you have disabled all anti virus and anti malware programs and double click dds.scr to run the tool. Nothing will be deleted. It will just give me some additional information.

Posted Image

When done, DDS will open two (2) logs (DDS.txt and Attach.txt). Save both reports to your desktop and post their contents.

Please post the contents of the DDS.txt and Attach.txt logs with the URL of the Results screen. You may need to use two posts to get it all in.

LY
EI | SWI | ZEBULON | Posted Image | Posted Image

My help is free, but if you wish to help keep these forums running please consider a donation. Please, see here for details.

#17 eltiburon

eltiburon

    Member

  • Full Member
  • Pip
  • 13 posts

Posted 24 February 2010 - 02:43 AM

Hi, I followed the first link to PC Pitstop. I signed up for the free account, but did not see the CA PC Security and Performance Scanners you mentioned. I ran an optimizer scan and the other one, but they both required a paid account to fix the issues. There was no results URL

Here are the other two log lists from the DDS scan.

First the DDS.txt


DDS (Ver_09-12-01.01) - NTFSx86
Run by Garrett Gambino at 3:36:10.57 on Wed 02/24/2010
Internet Explorer: 8.0.6001.18882 BrowserJavaVersion: 1.6.0_18
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2046.1115 [GMT -5:00]

SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Google\Update\1.2.183.13\GoogleCrashHandler.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\nvvsvc.exe
c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\Dwm.exe
C:\Program Files\Synaptics\SynTP\SynTPStart.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\HP\Digital Imaging\bin\HpqSRmon.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\AOL\1216788419\ee\aolsoftware.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Steam\Steam.exe
C:\Program Files\Common Files\Steam\SteamService.exe
C:\Program Files\Windows Mail\WinMail.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Garrett Gambino.Garrett-PC\Downloads\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop
mURLSearchHooks: H - No File
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
EB: HP Smart Web Printing: {555d4d79-4bd2-4094-a395-cfc534424a05} - c:\program files\hp\digital imaging\smart web printing\hpswp_bho.dll
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
uRun: [HPADVISOR] c:\program files\hewlett-packard\hp advisor\HPAdvisor.exe autoRun
uRun: [LightScribe Control Panel] c:\program files\common files\lightscribe\LightScribeControlPanel.exe -hidden
mRun: [SynTPStart] c:\program files\synaptics\syntp\SynTPStart.exe
mRun: [SMSERIAL] c:\program files\motorola\smserial\sm56hlpr.exe
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe
mRun: [QPService] "c:\program files\hp\quickplay\QPService.exe"
mRun: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
mRun: [OnScreenDisplay] c:\program files\hewlett-packard\hp quicktouch\HPKBDAPP.exe
mRun: [UCam_Menu] "c:\program files\cyberlink\youcam\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\youcam" update "software\cyberlink\youcam\1.0"
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [hpqSRMon] c:\program files\hp\digital imaging\bin\hpqSRMon.exe
mRun: [HP Health Check Scheduler] c:\program files\hewlett-packard\hp health check\HPHC_Scheduler.exe
mRun: [hpWirelessAssistant] c:\program files\hewlett-packard\hp wireless assistant\HPWAMain.exe
mRun: [WAWifiMessage] c:\program files\hewlett-packard\hp wireless assistant\WiFiMsg.exe
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [HostManager] c:\program files\common files\aol\1216788419\ee\AOLSoftware.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [PC Pitstop Optimize Reminder] c:\program files\pcpitstop\optimize3\Reminder-Optimize3.exe
mRunOnce: [GrpConv] grpconv.exe -o
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\vongot~1.lnk - c:\windows\installer\{8c3ae2d1-854d-4650-a73d-c7cc7ee36b80}\NewShortcut2_DB7E00C96DEF489A8112D8F81614F45A.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {A27C56D2-3F58-4ABB-AA31-1168EDA6636F} - hxxp://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} - hxxp://utilities.pcpitstop.com/Optimize3/pcpitstop2.dll
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe"

================= FIREFOX ===================

FF - ProfilePath - c:\users\garret~1.gar\appdata\roaming\mozilla\firefox\profiles\rg5bgv30.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2384137&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Search Powered by Google
FF - prefs.js: browser.startup.homepage - hxxp://thechumslick.com
FF - prefs.js: keyword.URL - hxxp://recovery.alexa.com/helper/?aid=WO8tb1Jik800a%2F&plugin=spkyf-1.4.7&reason=keyword&location=
FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpClipBook.dll
FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpClipBookDB.dll
FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpNeoLogger.dll
FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpSaturn.dll
FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpSmartSelect.dll
FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpSmartWebPrinting.dll
FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpSWPOperation.dll
FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpXPLogging.dll
FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpXPMTC.dll
FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpXPMTL.dll
FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpXREStub.dll
FF - component: c:\users\garrett gambino.garrett-pc\appdata\roaming\mozilla\firefox\profiles\rg5bgv30.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\winnt_x86-msvc\components\ipc.dll
FF - plugin: c:\progra~1\meadco~1\npmeadax.dll
FF - plugin: c:\program files\download manager\npfpdlm.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\google updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\google\update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\plugins\nphpclipbook.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - truec:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

============= SERVICES / DRIVERS ===============

R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2010-1-29 11608]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2010-1-29 108289]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2010-1-29 185089]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2010-1-29 56816]
S2 gupdate1ca26c983b7a8b0;Google Update Service (gupdate1ca26c983b7a8b0);c:\program files\google\update\GoogleUpdate.exe [2009-8-26 133104]
S2 PEVSystemStart;PEVSystemStart;c:\combofix\PEV.cfxxe [2010-2-15 261632]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-6-24 21504]
S4 PCPitstop Scheduling;PCPitstop Scheduling;c:\program files\pcpitstop\PCPitstopScheduleService.exe [2010-2-24 85504]

=============== Created Last 30 ================

2010-02-24 08:14:56 0 d-----w- c:\users\garret~1.gar\appdata\roaming\PCPitstop
2010-02-24 08:02:44 0 d-----w- c:\program files\MeadCo Neptune
2010-02-24 07:56:26 0 d-----w- c:\programdata\PCPitstop
2010-02-24 07:56:25 0 d-----w- c:\program files\PCPitstop
2010-02-24 04:42:07 2048 ----a-w- c:\windows\system32\tzres.dll
2010-02-24 04:10:46 471552 ----a-w- c:\windows\system32\secproc.dll
2010-02-24 04:10:45 518144 ----a-w- c:\windows\system32\RMActivate.exe
2010-02-24 04:10:33 152064 ----a-w- c:\windows\system32\secproc_ssp.dll
2010-02-24 04:10:32 347136 ----a-w- c:\windows\system32\RMActivate_ssp.exe
2010-02-24 04:10:17 471552 ----a-w- c:\windows\system32\secproc_isv.dll
2010-02-24 04:10:16 526336 ----a-w- c:\windows\system32\RMActivate_isv.exe
2010-02-24 04:10:00 346624 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2010-02-24 04:10:00 152576 ----a-w- c:\windows\system32\secproc_ssp_isv.dll
2010-02-24 04:09:51 332288 ----a-w- c:\windows\system32\msdrm.dll
2010-02-24 04:07:16 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2010-02-24 04:07:15 1696256 ----a-w- c:\windows\system32\gameux.dll
2010-02-24 04:07:02 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2010-02-22 19:29:35 0 d-----w- C:\32788R22FWJFW(0)
2010-02-21 00:29:05 0 d-----w- c:\program files\Windows Portable Devices
2010-02-21 00:28:39 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2010-02-21 00:25:14 81920 ----a-w- c:\windows\system32\wpdbusenum.dll
2010-02-21 00:23:37 4096 ----a-w- c:\windows\system32\oleaccrc.dll
2010-02-21 00:23:36 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
2010-02-21 00:23:36 234496 ----a-w- c:\windows\system32\oleacc.dll
2010-02-20 23:38:47 0 d-----w- c:\programdata\Sun
2010-02-20 18:20:25 0 d-----w- c:\windows\system32\eu-ES
2010-02-20 18:20:25 0 d-----w- c:\windows\system32\ca-ES
2010-02-20 18:20:23 0 d-----w- c:\windows\system32\vi-VN
2010-02-16 20:01:39 0 d-----w- C:\_OTL
2010-02-15 20:19:33 0 d-s---w- C:\ComboFix
2010-02-11 21:21:01 23094 ----a-w- c:\windows\hpqins15.dat
2010-02-11 20:07:20 77312 ----a-w- c:\windows\MBR.exe
2010-02-11 20:07:20 261632 ----a-w- c:\windows\PEV.exe
2010-02-11 20:07:20 161792 ----a-w- c:\windows\SWREG.exe
2010-02-11 20:07:19 98816 ----a-w- c:\windows\sed.exe
2010-02-11 19:55:50 65536 --sha-w- c:\users\garrett gambino.garrett-pc\NTUSER.DAT{d750467f-1740-11df-bc91-00038a000015}.TM.blf
2010-02-11 19:55:50 524288 --sha-w- c:\users\garrett gambino.garrett-pc\NTUSER.DAT{d750467f-1740-11df-bc91-00038a000015}.TMContainer00000000000000000002.regtrans-ms
2010-02-11 19:55:50 524288 --sha-w- c:\users\garrett gambino.garrett-pc\NTUSER.DAT{d750467f-1740-11df-bc91-00038a000015}.TMContainer00000000000000000001.regtrans-ms
2010-02-10 18:10:02 3600456 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-10 18:10:02 3548216 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-02-08 05:35:52 0 d-----w- c:\program files\iPod
2010-02-03 00:58:51 0 d-----w- C:\bf433aea21884a84a9ea4711912ececd
2010-02-03 00:56:39 0 d-----w- C:\f270c6d5cd235a6d892d36
2010-02-03 00:24:16 0 d-----w- c:\windows\system32\EventProviders
2010-02-03 00:12:48 0 d-----w- c:\program files\CCleaner
2010-02-02 22:32:15 0 d-----w- c:\programdata\Office Genuine Advantage
2010-02-02 22:32:12 0 d-----w- c:\users\garrett gambino.garrett-pc\Office Genuine Advantage
2010-01-31 22:25:20 38165 ----a-w- c:\users\garrett gambino.garrett-pc\sharkytooth2.jpg
2010-01-31 22:25:06 32681 ----a-w- c:\users\garrett gambino.garrett-pc\sharkytooth.jpg
2010-01-31 21:11:13 98818 ----a-w- c:\users\garrett gambino.garrett-pc\EE Form Fiction - PWI-768845.docx
2010-01-30 17:04:53 0 d-----w- c:\program files\Trend Micro
2010-01-30 04:34:55 0 d-----w- c:\programdata\WindowsSearch
2010-01-30 02:47:24 56816 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-01-30 02:47:21 0 d-----w- c:\programdata\Avira
2010-01-30 02:47:21 0 d-----w- c:\program files\Avira
2010-01-30 02:28:09 0 d-----w- c:\users\garret~1.gar\appdata\roaming\PandoraRecovery
2010-01-29 23:51:56 0 d-----w- c:\programdata\Downloaded Installations
2010-01-29 22:44:20 0 d-----w- c:\users\garret~1.gar\appdata\roaming\Malwarebytes
2010-01-29 08:01:09 0 d-----w- C:\88684033d6dc950f95
2010-01-28 19:56:16 156672 ----a-w- c:\windows\system32\t2embed.dll
2010-01-28 19:56:14 72704 ----a-w- c:\windows\system32\fontsub.dll
2010-01-28 19:46:02 0 d-----w- c:\users\garret~1.gar\appdata\roaming\DigitalPersona
2010-01-28 19:46:00 0 d-----w- c:\users\garret~1.gar\appdata\roaming\Macrovision

==================== Find3M ====================

2010-02-24 05:30:08 65973 ----a-w- c:\programdata\nvModes.dat
2010-02-21 00:28:54 665600 ----a-w- c:\windows\inf\drvindex.dat
2010-02-21 00:28:54 51200 ----a-w- c:\windows\inf\infpub.dat
2010-02-21 00:28:53 86016 ----a-w- c:\windows\inf\infstor.dat
2010-02-21 00:28:53 143360 ----a-w- c:\windows\inf\infstrng.dat
2010-02-20 23:37:57 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-02-20 17:51:00 37665 ----a-w- c:\windows\fonts\GlobalUserInterface.CompositeFont
2010-01-14 16:12:06 181120 ------w- c:\windows\system32\MpSigStub.exe
2010-01-07 21:07:14 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 21:07:04 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-02 06:38:20 916480 ----a-w- c:\windows\system32\wininet.dll
2010-01-02 06:32:33 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-01-02 06:32:33 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-01-02 04:57:00 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-12-04 18:30:05 12288 ----a-w- c:\windows\system32\tsbyuv.dll
2009-12-04 18:29:41 1314816 ----a-w- c:\windows\system32\quartz.dll
2009-12-04 18:28:52 22528 ----a-w- c:\windows\system32\msyuv.dll
2009-12-04 18:28:51 31744 ----a-w- c:\windows\system32\msvidc32.dll
2009-12-04 18:28:51 123904 ----a-w- c:\windows\system32\msvfw32.dll
2009-12-04 18:28:49 13312 ----a-w- c:\windows\system32\msrle32.dll
2009-12-04 18:28:27 82944 ----a-w- c:\windows\system32\mciavi32.dll
2009-12-04 18:28:21 50176 ----a-w- c:\windows\system32\iyuv_32.dll
2009-12-04 18:27:12 91136 ----a-w- c:\windows\system32\avifil32.dll
2009-07-08 18:15:01 174 --sha-w- c:\program files\desktop.ini
2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfc.dat

============= FINISH: 3:38:50.64 ===============

Next, the attach.txt


UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-12-01.01)

Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 1/15/2008 9:40:44 PM
System Uptime: 2/23/2010 11:47:06 PM (4 hours ago)

Motherboard: Quanta | | 30CB
Processor: Intel® Core™2 Duo CPU T5450 @ 1.66GHz | U2E1 | 1000/667mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 221 GiB total, 103.138 GiB free.
D: is FIXED (NTFS) - 12 GiB total, 1.817 GiB free.
E: is CDROM ()

==== Disabled Device Manager Items =============

==== System Restore Points ===================


==== Installed Programs ======================

Activation Assistant for the 2007 Microsoft Office suites
ActiveCheck component for HP Active Support Library
Adobe Flash Player 10 Plugin
Adobe Flash Player ActiveX
Adobe Reader 9.3
Adobe Shockwave Player
AIM 6
AnswerWorks 4.0 Runtime - English
AOL Uninstaller (Choose which Products to Remove)
Apple Application Support
Apple Mobile Device Support
Apple Software Update
AuthenTec Fingerprint Sensor Minimum Install
AutoUpdate
Avira AntiVir Personal - Free Antivirus
Bonjour
Cards_Calendar_OrderGift_DoMorePlugout
CCleaner
Champions Online
Compatibility Pack for the 2007 Office system
Coupon Printer for Windows
CyberLink YouCam
DivX Codec
DivX Content Uploader
DivX Converter
DivX Player
DivX Web Player
Download Manager 2.3.9
DVD Suite
EA Download Manager
ESU for Microsoft Vista
Exterminate3
Game Booster
Google Earth
Google Talk Plugin
Google Update Helper
Google Updater
Hauppauge MCE XP/Vista Software Encoder (2.0.25149)
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
HP Active Support Library
HP Customer Experience Enhancements
HP Doc Viewer
HP Easy Setup - Frontend
HP Help and Support
HP Photosmart Essential 2.5
HP Quick Launch Buttons 6.30 E1
HP QuickPlay 3.6
HP QuickTouch 1.00 C4
HP Smart Web Printing 4.60
HP Total Care Advisor
HP Update
HP User Guides 0088
HP Wireless Assistant
HPAsset component for HP Active Support Library
HPNetworkAssistant
HPPhotoSmartDiscLabel_PaperLabel
HPPhotoSmartDiscLabel_PrintOnDisc
HPPhotoSmartDiscLabel_Tattoo
HPPhotoSmartDiscLabelContent1
hpphotosmartdisclabelplugin
HPPhotoSmartPhotobookHolidayPack1
HPPhotoSmartPhotobookModernPack1
HPPhotoSmartPhotobookPlayfulPack1
HPPhotoSmartPhotobookScrapbookPack1
HPPhotoSmartPhotobookWebPack1
Intel® Matrix Storage Manager
iTunes
Java Auto Updater
Java™ 6 Update 18
LabelPrint
LightScribe System Software 1.10.13.1
Malwarebytes' Anti-Malware
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft .NET Framework 3.5 SP1
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Excel MUI (English) 2007
Microsoft Office Home and Student 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Works
mIRC
Motorola SM56 Data Fax Modem
Mozilla Firefox (3.5.8)
Mozilla Thunderbird (2.0.0.14)
MSCU for Microsoft Vista
MSN
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB941833)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
muvee autoProducer 6.1
My HP Games
NVIDIA Drivers
NVIDIA PhysX
OGA Notifier 2.0.0048.0
Paint Shop Pro 7 Anniversary Edition
PandoraRecovery (Remove Only)
PC Matic 1.0.0.0
PC Pitstop Optimize3 3.0
Power2Go
PowerDirector
PSSWCORE
QuickPlay SlingPlayer 0.4.4
QuickTime
RealPlayer
Realtek 8169 PCI, 8168 and 8101E PCIe Ethernet Network Card Driver for Windows Vista
Realtek High Definition Audio Driver
Rhapsody Player Engine
RICOH R5C83x/84x Flash Media Controller Driver Ver.3.51.01
RTC Client API v1.2
Scientific-Atlanta WebSTAR 2000 series Cable Modem
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB973704)
Security Update for Microsoft Office Excel 2007 (KB973593)
Security Update for Microsoft Office PowerPoint 2007 (KB957789)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB969613)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Slingbox Flash Tour
SlingPlayer
Smart Defrag
SmartWebPrinting
SoulSeek 157 NS 13c
Steam
Synaptics Pointing Device Driver
System Requirements Lab
The Lord of the Rings Online™: Shadows of Angmar™ v07.12.30.54
TurboTax Deluxe 2007
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office InfoPath 2007 (KB976416)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 (KB974561)
Update for Microsoft Office Word 2007 Help (KB963665)
Verizon Broadband Toolbar
VideoToolkit01
Viewpoint Media Player
VLC media player 1.0.3
VoiceOver Kit
Vongo
Warhammer Online - Age of Reckoning
WeatherBug Gadget
Windows Media Player Firefox Plugin
Yahoo! Toolbar

==== End Of File ===========================

#18 eltiburon

eltiburon

    Member

  • Full Member
  • Pip
  • 13 posts

Posted 01 March 2010 - 04:01 PM

Bumpity Bump.

Here is a bit more info on my issue. The computer tends to freeze when it goes into sleep mode after 10 or 15 minutes on inactivity, or when switching users. It freaks me out that I am unable to complete a full defrag without the computer locking up.

#19 eltiburon

eltiburon

    Member

  • Full Member
  • Pip
  • 13 posts

Posted 08 March 2010 - 01:34 AM

Double-Bump.

Are we all stumped?

#20 nasdaq

nasdaq

    Forum Deity

  • Global Moderator
  • PipPipPipPipPip
  • 49,347 posts

Posted 08 March 2010 - 01:51 PM

Hi,

I'm nasdaq, your helper has not been on line since Feb. 25 for reasons that are unknown to us.

I will take over this topic until his return.

If your primary account is damaged it may be very difficult to restore it if we can.


Did you recently tried to run a chkdsk? If not please do so.
Instructions will be found here.
http://www.windows-h...sta-chkdsk.html
===

For now I would like to see if you have a rootkit infection. Please run these tools.

===

Download GMER Rootkit Scanner from here.

Uninstall any CD emulation software before you run GMER, Daemon Tools and Daemon Tools Lite
Alcohol 120% and 52%
AstroBurn
. If any of these emulation software are installed.

Please download SPTD-installer and double-click it to run. Select uninstall to remove the program.

See this FAQ is you need additional information.
http://www.duplexsecure.com/faq/

These can be reinstalled later.

  • Extract the contents of the GMER zipped file to your Desktop.
  • Double-click on GMER.exe to run it.
  • If it gives you a warning about rootkit activity and asks if you want to run a full scan, click NO, and then use the following settings.
  • In the right panel, you will see several boxes that have been checked. Ensure the following are UNCHECKED:
    • Sections
    • IAT/EAT
    • Drives/Partition other than your Systemdrive (the drive you have Windows installed on)
    • Show All (don't miss unchecking this one)
  • Then click the Scan button & wait for it to finish.
  • When its finished, click on the Save button, and in the File name area, type in "gmer.txt".
  • Save it to a convenient location such as your Desktop and post the contents of the log.

===

Before suggesting a fix, we Need to check for Rootkits with RootRepeal
  • Download RootRepeal from the following location and save it to your desktop.
  • Extract RootRepeal.exe from the archive (If you did not use the "Direct Download" mirror).
  • Open Posted Image on your desktop.
  • Click the Posted Image tab.
  • Click the Posted Image button.
  • Check all seven boxes: Posted Image
  • Push Ok
  • Check the box for your main system drive (Usually C:), and press Ok.
  • Allow RootRepeal to run a scan of your system. This may take some time.
  • Once the scan completes, push the Posted Image button. Save the log to your desktop, using a distinctive name, such as RootRepeal.txt. Include this report in your next reply, please.

nasdaq

Favorite tools: [ SpywareBlaster ] [ Spybot ] [ AdAware ] [ HijackThis ]
[ Housecall online virus scan ] [ Bitdefender online virus scan ]
[ AVG antivirus ] [ Sunbelt Personal Firewall ] [ ZoneAlarm firewall ]

My help is free, but if we have helped you in anyway,please considerDonating ,
see this topic for details.
We need members like you.

========
Shouldn't water be worth more than diamonds?
Adam Smith Glasgow, 1760

#21 eltiburon

eltiburon

    Member

  • Full Member
  • Pip
  • 13 posts

Posted 09 March 2010 - 01:43 PM

I tried the Chkdsk four times and the computer froze up on me each time...arrgh.

I will try the next steps in your last post.

Thanks for getting back to me.

#22 nasdaq

nasdaq

    Forum Deity

  • Global Moderator
  • PipPipPipPipPip
  • 49,347 posts

Posted 24 March 2010 - 08:10 AM

Glad we could help. :)

If you need this topic reopened, please tell the moderating team by replying here with the address of the thread. This applies only to the original topic starter. Everyone else please begin a New Topic.
nasdaq

Favorite tools: [ SpywareBlaster ] [ Spybot ] [ AdAware ] [ HijackThis ]
[ Housecall online virus scan ] [ Bitdefender online virus scan ]
[ AVG antivirus ] [ Sunbelt Personal Firewall ] [ ZoneAlarm firewall ]

My help is free, but if we have helped you in anyway,please considerDonating ,
see this topic for details.
We need members like you.

========
Shouldn't water be worth more than diamonds?
Adam Smith Glasgow, 1760




Member of UNITE
Support SpywareInfo Forum - click the button