also @ TechSpot: Qualcomm shows off Mirasol, 1.5-inch panel shipping in products soon

HJT Log

Discussion in 'Virus and Malware Removal' started by circusboy01, Aug 14, 2011.

  1. circusboy01 TechSpot Enthusiast Posts: 666

    Thanks for the harry birthday wish. I'm sure my Avast is up to date.It updates itself. But I'm going to update it now. Before I start the OTL scan.
  2. circusboy01 TechSpot Enthusiast Posts: 666

    Can you tell me what the heck is going on?? Too many things keep disappearing. Now the OTL scan log I did about 15 minutes ago is gone. It should have been post #42 I'm not going to do another scan until you have a chance to find it. Maybe I just missed it But, I thought I looked through pages 1 2 and 3. If you do find it you'll notice only one log again.. Have you done OTL logs in a while? Maybe the merged the two logs together?? On this next post coming up. I'm going to go ahead and give you a step bt step account of how I followed your instructions. Maybe you can catch any mistakes I might have made. It will be like chicken soup.It might not help. But, it couldn't hurt. CB
  3. Broni Malware Annihilator Posts: 39,349   +175

    I don't see it.
    Please redo.
  4. circusboy01 TechSpot Enthusiast Posts: 666

    Download OPTL to desktop. Did that
    Double click on icon to run it. Did that.But,it didnot run it just opened up.(like when you click on any desktop icon.)
    Make sure all other windows are closed. Did that
    Let it run uninterrupted. Can't nothings running. Like I said clicking on icon only opened it up.
    Click the scan all users box Did that.
    Under the custom scan box paste in all the red print you provided. Did that. (sorry for the extra select all turned more things blue than just the red print.)
    click the quick scan button. Did that.
    Do not change any setting. I didn't.
    When is complete lt will open two notepad windows. Copy paste and send them to me one at a time. It only created one log. Which I copy pasted and sent to you.

    Just thought were both logs supposed to come up one right behind, or right beside the other? or was one supposed to come up, and after I send it the other is ,maybe, in a file somewhere that I have to open up before I can send it to you?
  5. circusboy01 TechSpot Enthusiast Posts: 666

    it's there you should be able to find it this time. I say find it . Because it never seems to show up where I think it should.you'll notice. Only one log again
  6. circusboy01 TechSpot Enthusiast Posts: 666

    Hope you find this quicklyI think it's the extrta's log

    Found it in my start menu opened it and this is what I got. Is it the missing second log from Otc?



    OTL Extras logfile created on: 8/20/2011 6:23:42 PM - Run 1
    OTL by OldTimer - Version 3.2.26.5 Folder = C:\Users\Raymond Wayne Solema\Desktop
    64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
    Internet Explorer (Version = 9.0.8112.16421)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    3.97 Gb Total Physical Memory | 3.08 Gb Available Physical Memory | 77.75% Memory free
    7.93 Gb Paging File | 6.53 Gb Available in Paging File | 82.38% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
    Drive C: | 906.34 Gb Total Space | 881.41 Gb Free Space | 97.25% Space Free | Partition Type: NTFS

    Computer Name: COMPZILLA-IV | User Name: Raymond Wayne Solema | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
    Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

    ========== Extra Registry (SafeList) ==========


    ========== File Associations ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
    .url[@ = InternetShortcut] -- C:\windows\SysNative\rundll32.exe (Microsoft Corporation)

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
    .cpl [@ = cplfile] -- C:\windows\SysWow64\control.exe (Microsoft Corporation)

    [HKEY_USERS\S-1-5-21-289670154-1285097819-147057498-1001\SOFTWARE\Classes\<extension>]
    .html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

    ========== Shell Spawning ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [open] -- "%1" %* File not found
    cmdfile [open] -- "%1" %* File not found
    comfile [open] -- "%1" %* File not found
    exefile [open] -- "%1" %* File not found
    helpfile [open] -- Reg Error: Key error.
    htmlfile [edit] -- Reg Error: Key error.
    htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
    inffile [install] -- %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
    InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
    InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
    piffile [open] -- "%1" %* File not found
    regfile [merge] -- Reg Error: Key error.
    scrfile [config] -- "%1" File not found
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l File not found
    scrfile [open] -- "%1" /S File not found
    txtfile [edit] -- Reg Error: Key error.
    Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
    Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [explore] -- Reg Error: Value error.
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [open] -- "%1" %*
    cmdfile [open] -- "%1" %*
    comfile [open] -- "%1" %*
    cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
    exefile [open] -- "%1" %*
    helpfile [open] -- Reg Error: Key error.
    htmlfile [edit] -- Reg Error: Key error.
    piffile [open] -- "%1" %*
    regfile [merge] -- Reg Error: Key error.
    scrfile [config] -- "%1"
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
    scrfile [open] -- "%1" /S
    txtfile [edit] -- Reg Error: Key error.
    Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
    Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [explore] -- Reg Error: Value error.
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    ========== Security Center Settings ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    "cval" = 1
    "FirewallDisableNotify" = 0
    "AntiVirusDisableNotify" = 0
    "UpdatesDisableNotify" = 0

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
    "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
    "AntiVirusOverride" = 0
    "AntiSpywareOverride" = 0
    "FirewallOverride" = 0

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    "FirewallDisableNotify" = 0
    "AntiVirusDisableNotify" = 0
    "UpdatesDisableNotify" = 0

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

    ========== System Restore Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
    "DisableSR" = 0

    ========== Firewall Settings ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
    "DisableNotifications" = 0
    "EnableFirewall" = 1

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
    "DisableNotifications" = 0
    "EnableFirewall" = 1

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
    "DisableNotifications" = 0
    "EnableFirewall" = 1

    ========== Authorized Applications List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


    ========== HKEY_LOCAL_MACHINE Uninstall List ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{007811BF-E310-4285-BFC6-55DB29B3EDDE}" = WinPatrol
    "{46F4D124-20E5-4D12-BE52-EC177A7A4B42}" = Lenovo Rescue System
    "{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}" = Microsoft Visual C++ 2005 Redistributable (x64)
    "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
    "{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
    "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
    "{FBBC4667-2521-4E78-B1BD-8706F774549B}" = Best Buy pc app
    "CCleaner" = CCleaner
    "HDMI" = Intel(R) Graphics Media Accelerator Driver
    "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{0EC766C7-F444-42BF-A05F-4A790F5360EB}" = FanSpeedControl
    "{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
    "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    "{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
    "{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
    "{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
    "{42B21298-C850-4272-AFD9-636CBC005421}" = LXH-JME2207FN Hotkey Driver
    "{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
    "{45970CD1-D599-47D4-938F-3E9800D54ED1}" = Lenovo Driver and Application Installation
    "{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
    "{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
    "{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
    "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8136 8168 8169 Ethernet Driver
    "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
    "{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
    "{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
    "{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader
    "{995F1E2E-F542-4310-8E1D-9926F5A279B3}" = Windows Live Toolbar
    "{9C9CEB9D-53FD-49A7-85D2-FE674F72F24E}" = Microsoft Search Enhancement Pack
    "{A2AE9709-283B-4B48-AA34-729C070A62FB}" = NETGEAR WNA1100 wireless USB 2.0 adapter
    "{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
    "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
    "{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3
    "{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
    "{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
    "{D3063097-EC84-4D21-84A4-9D852E974355}" = LVT
    "{D6C75F0B-3BC1-4FC9-B8C5-3F7E8ED059CA}" = Windows Live Photo Gallery
    "{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
    "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
    "{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
    "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
    "{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
    "{FFB768E4-E427-4553-BC36-A11F5E62A94D}" = Adobe Flash Player 10 ActiveX
    "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
    "avast" = avast! Free Antivirus
    "Belarc Advisor" = Belarc Advisor 8.2
    "InstallShield_{0EC766C7-F444-42BF-A05F-4A790F5360EB}" = FanSpeedControl
    "InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}" = Lenovo Rescue System
    "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.1.1800
    "Mozilla Firefox 6.0 (x86 en-US)" = Mozilla Firefox 6.0 (x86 en-US)
    "Revo Uninstaller" = Revo Uninstaller 1.93
    "SpywareBlaster_is1" = SpywareBlaster 4.4
    "tinySpell_is1" = tinySpell 1.9.40
    "WinLiveSuite_Wave3" = Windows Live Essentials

    ========== HKEY_USERS Uninstall List ==========

    [HKEY_USERS\S-1-5-21-289670154-1285097819-147057498-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "Google Chrome" = Google Chrome

    ========== Last 10 Event Log Errors ==========

    [ Application Events ]
    Error - 8/17/2011 2:17:23 AM | Computer Name = Compzilla-IV | Source = System Restore | ID = 8193
    Description =

    Error - 8/17/2011 3:02:54 AM | Computer Name = Compzilla-IV | Source = System Restore | ID = 8193
    Description =

    Error - 8/17/2011 5:01:35 AM | Computer Name = Compzilla-IV | Source = System Restore | ID = 8193
    Description =

    Error - 8/17/2011 5:48:32 AM | Computer Name = Compzilla-IV | Source = SideBySide | ID = 16842815
    Description = Activation context generation failed for "c:\program files (x86)\spybot
    - search & destroy\DelZip179.dll".Error in manifest or policy file "c:\program
    files (x86)\spybot - search & destroy\DelZip179.dll" on line 8. The value "*" of
    attribute "language" in element "assemblyIdentity" is invalid.

    Error - 8/17/2011 5:48:35 AM | Computer Name = Compzilla-IV | Source = SideBySide | ID = 16842811
    Description = Activation context generation failed for "c:\program files (x86)\microsoft\search
    enhancement pack\search helper\searchhelper.dll".Error in manifest or policy file
    "c:\program files (x86)\microsoft\search enhancement pack\search helper\searchhelper.dll"
    on line 2. Invalid Xml syntax.

    Error - 8/17/2011 5:55:21 AM | Computer Name = Compzilla-IV | Source = System Restore | ID = 8193
    Description =

    Error - 8/17/2011 6:08:35 AM | Computer Name = Compzilla-IV | Source = System Restore | ID = 8193
    Description =

    Error - 8/17/2011 7:14:25 AM | Computer Name = Compzilla-IV | Source = System Restore | ID = 8193
    Description =

    Error - 8/17/2011 7:15:24 AM | Computer Name = Compzilla-IV | Source = Application Error | ID = 1000
    Description = Faulting application name: pev.cfxxe, version: 0.0.0.0, time stamp:
    0x4e06cfe8 Faulting module name: pev.cfxxe, version: 0.0.0.0, time stamp: 0x4e06cfe8
    Exception
    code: 0xc0000417 Fault offset: 0x00081dc9 Faulting process id: 0x209c Faulting application
    start time: 0x01cc5ccef5251c4d Faulting application path: C:\ComboFix\pev.cfxxe Faulting
    module path: C:\ComboFix\pev.cfxxe Report Id: 337f6ba1-c8c2-11e0-a7a7-4437e61e2439

    Error - 8/17/2011 7:16:28 AM | Computer Name = Compzilla-IV | Source = System Restore | ID = 8193
    Description =

    [ System Events ]
    Error - 8/17/2011 7:27:40 AM | Computer Name = Compzilla-IV | Source = Service Control Manager | ID = 7030
    Description = The PEVSystemStart service is marked as an interactive service. However,
    the system is configured to not allow interactive services. This service may not
    function properly.

    Error - 8/17/2011 7:25:00 PM | Computer Name = Compzilla-IV | Source = Service Control Manager | ID = 7023
    Description = The Windows Modules Installer service terminated with the following
    error: %%16405

    Error - 8/17/2011 7:46:34 PM | Computer Name = Compzilla-IV | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
    Description = Installation Failure: Windows failed to install the following update
    with error 0x800706be: Windows Internet Explorer 9 for Windows 7 for x64-based
    Systems.

    Error - 8/17/2011 7:46:34 PM | Computer Name = Compzilla-IV | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
    Description = Installation Failure: Windows failed to install the following update
    with error 0x800706ba: Update for Windows 7 for x64-based Systems (KB2505438).

    Error - 8/17/2011 7:02:21 PM | Computer Name = Compzilla-IV | Source = Service Control Manager | ID = 7030
    Description = The PEVSystemStart service is marked as an interactive service. However,
    the system is configured to not allow interactive services. This service may not
    function properly.

    Error - 8/17/2011 7:03:47 PM | Computer Name = Compzilla-IV | Source = Service Control Manager | ID = 7030
    Description = The PEVSystemStart service is marked as an interactive service. However,
    the system is configured to not allow interactive services. This service may not
    function properly.

    Error - 8/17/2011 7:10:25 PM | Computer Name = Compzilla-IV | Source = Service Control Manager | ID = 7030
    Description = The PEVSystemStart service is marked as an interactive service. However,
    the system is configured to not allow interactive services. This service may not
    function properly.

    Error - 8/17/2011 7:11:49 PM | Computer Name = Compzilla-IV | Source = Service Control Manager | ID = 7030
    Description = The PEVSystemStart service is marked as an interactive service. However,
    the system is configured to not allow interactive services. This service may not
    function properly.

    Error - 8/17/2011 7:19:13 PM | Computer Name = Compzilla-IV | Source = Service Control Manager | ID = 7030
    Description = The PEVSystemStart service is marked as an interactive service. However,
    the system is configured to not allow interactive services. This service may not
    function properly.

    Error - 8/17/2011 7:20:16 PM | Computer Name = Compzilla-IV | Source = Service Control Manager | ID = 7030
    Description = The PEVSystemStart service is marked as an interactive service. However,
    the system is configured to not allow interactive services. This service may not
    function properly.


    < End of report >
     
  7. Broni Malware Annihilator Posts: 39,349   +175

    That's Extras.txt. I still need OTL.txt.
  8. circusboy01 TechSpot Enthusiast Posts: 666

    Broni: don't know if you've seen my first reply to your last post. If you did than this post will make more sense. When said there's no need to run another otl scan. Because the results would be the same. Only one Log.I was thinking alone the lines of The definition of insanity.
    which is Doing the same thing over and over, and expecting different results.
    When I wrote the step by step information on how I tried to follow your instructions It was never
    meant to say that there was anything wrong with your instructions. It was meant to help you pick out and show me.(.If there is any.) mistakes I might have made Didn't do something I should have.
    Did something I shouldn't have.
    Any mistake(S) I might have made . So I can give you 2 proper scan logs.

    Have you found anything wrong in the scans I have sent so far?
    I have sent this info 2 times. But I think, both time the post just went away. I know you have asked for it 2 times so here it is How my Computer is working Downloads take hours, where they used to take minutes, and minutes where they used to take seconds. I've given up on trying to watch a You Tube Video It's about 30 to 50 seconds of Buffering For 3 to 5 seconds of watching. Hope this helps a little CB.
  9. Broni Malware Annihilator Posts: 39,349   +175

    OK let's leave it as it is.

    Run OTL
    • Under the Custom Scans/Fixes box at the bottom, paste in the following

      Code:
      :OTL
      O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
      O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
      O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
      O4:64bit: - HKLM..\Run: [Unattend0000000001{BFA3D12B-66DD-4617-923A-E864BC7D20B5}] File not found
      @Alternate Data Stream - 95 bytes -> C:\ProgramData\Temp:5C321E34
      
      :Commands
      [purity]
      [emptytemp]
      [emptyflash]
      [Reboot]
      
    • Then click the Run Fix button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • You will get a log that shows the results of the fix. Please post it.

    ================================================================

    Last scans...

    1. Download Security Check from HERE, and save it to your Desktop.
    • Double-click SecurityCheck.exe
    • Follow the onscreen instructions inside of the black box.
    • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

      NOTE SecurityCheck may produce some false warning(s), so leave the results reading to me.


    2. Download Temp File Cleaner (TFC)
    • Double click on TFC.exe to run the program.
    • Click on Start button to begin cleaning process.
    • TFC will close all running programs, and it may ask you to restart computer.


    3. Please run a free online scan with the ESET Online Scanner

    • Disable your antivirus program
    • Tick the box next to YES, I accept the Terms of Use
    • Click Start
    • Accept any security warnings from your browser.
    • Check Scan archives
    • Click Start
    • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    • When the scan completes, push List of found threats
    • Click on Export to text file , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
    • NOTE. If Eset won't find any threats, it won't produce any log.
  10. circusboy01 TechSpot Enthusiast Posts: 666

    Here we go again

    Opened OTL Pasted what you wanted under custom scan/fixes. Clicked RunFix
    In less than a second. On the bottom of OTL was "Processing complete", and a window opened up with"The system requires a reboot to finish recovering files
    click OK to reboot . Would not reboot by clicking OK had to use restart..When the PC rebooted there was nothing there but my desktop. I opened up OTL again. But, there was no sign of any Scan logs. Was it all supposed to happen that fast? Because I don't think there was time to create any scan logs. But, if it did where are they?
    Broni I am going to go on to the next scans you want me to run Hopefully I will be sending you some logs,and we can worry about this one after. CB
  11. circusboy01 TechSpot Enthusiast Posts: 666

    Results of screen317's Security Check version 0.99.7
    Windows 7 (UAC is enabled)
    Internet Explorer 8
    ``````````````````````````````
    Antivirus/Firewall Check:

    Windows Firewall Enabled!
    avast! Free Antivirus
    WMI entry may not exist for antivirus; attempting automatic update.
    ```````````````````````````````
    Anti-malware/Other Utilities Check:

    Malwarebytes' Anti-Malware
    Adobe Flash Player 10.3.183.5
    Adobe Reader 9.3
    Out of date Adobe Reader installed!
    Mozilla Firefox (x86 en-US..) Firefox Out of Date!
    ````````````````````````````````
    Process Check:
    objlist.exe by Laurent

    Spybot Teatimer.exe is disabled!
    AVAST Software Avast AvastSvc.exe
    AVAST Software Avast AvastUI.exe
    ``````````End of Log````````````
  12. circusboy01 TechSpot Enthusiast Posts: 666

    TFC : 9.00 mb's of Stuff 2nd scan 0.00 Stuff

    Eset: No Threats Found.
  13. circusboy01 TechSpot Enthusiast Posts: 666

    Broni; iv'e heard that having too many things in your Start Up Menu/Start Program. Can slow a computer down. Here's everything I have in mine. Please show me what I can or should get rid of
    unatlend000000001(bf.a.30... RHDCPL? IntelPoint Superantispyware tinyspell Netgear
    LenovoFSC Adobe Reader Speed Launcher Adobe ARM Avast

    If enough things can be removed maybe it will help. At least a little CB
    ? on 2nd entrance is because I'm not sure if theif the 2nd letter is an H or not.
    Thanks again for bearing with me CB
  14. Broni Malware Annihilator Posts: 39,349   +175

    Disable your AV program and re-run OTL fix.

    I'll address your startups little bit later.
  15. circusboy01 TechSpot Enthusiast Posts: 666

    All processes killed
    Error: Unable to interpret < > in the current context!
    Error: Unable to interpret < > in the current context!
    Error: Unable to interpret < > in the current context!
    ========== OTL ==========
    Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found.
    Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
    Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}\ not found.
    64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Unattend0000000001{BFA3D12B-66DD-4617-923A-E864BC7D20B5} deleted successfully.
    ADS C:\ProgramData\Temp:5C321E34 deleted successfully.
    File rity] not found.
    File ptytemp] not found.
    File ptyflash] not found.
    File boot] not found.

    OTL by OldTimer - Version 3.2.26.5 log created on 08252011_002135

    Files\Folders moved on Reboot...

    Registry entries deleted on Reboot...
  16. circusboy01 TechSpot Enthusiast Posts: 666

    Broni; here's a couple more things that might be useful. Fill free to ignore..
    Usually when you boot up, right before your desktop comes on screen you hear 3 or 4 notes of the Windows music Mine opens up after only one note.

    My Netgear.stick.Connection to the Internet always has 6 to 8 out of 9 dots.
  17. Broni Malware Annihilator Posts: 39,349   +175

    What is Windows music Mine?

    I'm not sure what you're saying.

    Your computer is clean [IMG]

    1. We need to reset system restore to prevent your computer from being accidentally reinfected by using some old restore point(s). We'll create fresh, clean restore point, using following OTL script:

    Run OTL

    • Under the Custom Scans/Fixes box at the bottom, paste in the following:

    Code:
    :OTL
    :Commands
    [purity]
    [emptytemp]
    [EMPTYFLASH]
    [CLEARALLRESTOREPOINTS]
    [Reboot]
    • Then click the Run Fix button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • Post resulting log.

    2. Now, we'll remove all tools, we used during our cleaning process

    Clean up with OTL:

    • Double-click OTL.exe to start the program.
    • Close all other programs apart from OTL as this step will require a reboot
    • On the OTL main screen, press the CLEANUP button
    • Say Yes to the prompt and then allow the program to reboot your computer.

    If you still have any tools or logs leftover on your computer you can go ahead and delete those off of your computer now.

    3. Make sure, Windows Updates are current.

    4. If any Trojan was listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately!

    5. Download, and install WOT (Web OF Trust): http://www.mywot.com/. It'll warn you (in most cases) about dangerous web sites.

    6. Run Malwarebytes "Quick scan" once in a while to assure safety of your computer.

    7. Run Temporary File Cleaner (TFC) weekly.

    8. Download and install Secunia Personal Software Inspector (PSI): http://secunia.com/vulnerability_scanning/personal/. The Secunia PSI is a FREE security tool designed to detect vulnerable and out-dated programs and plug-ins which expose your PC to attacks. Run it weekly.

    9. (optional) If you want to keep all your programs up to date, download and install FileHippo Update Checker.
    The Update Checker will scan your computer for installed software, check the versions and then send this information to FileHippo.com to see if there are any newer releases.

    10. (Windows XP only) Run defrag at your convenience.

    11. When installing\updating ANY program, make sure you always select "Custom " installation, so you can UN-check any possible "drive-by-install" (foistware), like toolbars etc., which may try to install along with the legitimate program. Do NOT click "Next" button without looking at any given page.

    12. Read How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html

    13. Please, let me know, how your computer is doing.
  18. circusboy01 TechSpot Enthusiast Posts: 666

    Oops sorry there should have been a period between music and Mine It's just sound effects that you hear when something happens like your desktop coming on screen, and lots of other things.
    Mine id set to Windows default.
    Going to start following your instructions in just a minute. But, first I need to tell you. Nothings changed. I started to download Audials Radio today. Lost it when I brought my PC back to factory settings The time indicated that it would have taken was over 1 hr. The time it took before I started having the trouble.3 or 4 minutes. Videos are still buffering and buffering and buffering. So my systems clean and nothings fixed?? Oh yea those 6 to 87 out of 9 dots I was talking about They are signal strength. I probably should have said bars but mine are shown in what looks like lit up dots. Going to follow your instructions now
  19. circusboy01 TechSpot Enthusiast Posts: 666

    All processes killed
    Error: Unable to interpret <L> in the current context!
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: All Users

    User: Default
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: Public
    ->Temp folder emptied: 0 bytes

    User: Raymond Wayne Solema
    ->Temp folder emptied: 325469 bytes
    ->Temporary Internet Files folder emptied: 57757706 bytes
    ->FireFox cache emptied: 43524443 bytes
    ->Google Chrome cache emptied: 0 bytes
    ->Flash cache emptied: 566 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32 (64bit) .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 0 bytes
    %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes
    RecycleBin emptied: 0 bytes

    Total Files Cleaned = 97.00 mb


    [EMPTYFLASH]

    User: All Users

    User: Default

    User: Default User

    User: Public

    User: Raymond Wayne Solema
    ->Flash cache emptied: 0 bytes

    Total Flash Files Cleaned = 0.00 mb

    Restore point Set: OTL Restore Point

    OTL by OldTimer - Version 3.2.26.5 log created on 08252011_183609

    Files\Folders moved on Reboot...
    C:\Users\Raymond Wayne Solema\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
    C:\Users\Raymond Wayne Solema\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\INY4EQCO\background-banner-middle-v9[1].jpg moved successfully.
    C:\Users\Raymond Wayne Solema\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7PFIH713\background-banner-right-v9[1].jpg moved successfully.
    C:\Users\Raymond Wayne Solema\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7PFIH713\background_banner_green_50_v9[1].jpg moved successfully.
    File move failed. C:\windows\temp\_avast_\Webshlock.txt scheduled to be moved on reboot.

    Registry entries deleted on Reboot...
  20. Broni Malware Annihilator Posts: 39,349   +175

    Maybe you have some internet connection issues.

    In this forum, we make sure, your computer is free of malware and your computer is clean :)
    Because the access to malware forum is very limited, your best option is to create new topic about your current issue, at Windows section.
    You'll get more attention.