Solved Laptop slow boot, must be a virus, already stopped unnecessary startup items

how do I go to the next page in techspot threads?
I don't think I understand.

In short rdvgkmd.sys is a legit file but it's missing from your computer. That's why we removed that entry.
 
Oh, never mind, just now appeared at the top and bottom the page 1 and 2 :)

I didn`t find any proper description of it, if was missing could it be an important driver?
Sophos is scanning now
 
Forgot it completely, since is just a service scanner can I run it while sophos is doing his job?
 
Farbar Service Scanner Version: 17-01-2015
Ran by Bruno (administrator) on 18-04-2015 at 05:00:51
Running from "C:\Users\Bruno\Desktop\cleaning"
Microsoft Windows 7 Ultimate Service Pack 1 (X64)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo.com is accessible.


Windows Firewall:
=============

Firewall Disabled Policy:
==================
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall"=DWORD:0


System Restore:
============

System Restore Policy:
========================


Windows Update:
============

Windows Autoupdate Disabled Policy:
============================


Windows Defender:
==============
WinDefend Service is not running. Checking service configuration:
The start type of WinDefend service is OK.
The ImagePath of WinDefend service is OK.
The ServiceDll of WinDefend service is OK.


Windows Defender Disabled Policy:
==========================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
"DisableAntiSpyware"=DWORD:1


Other Services:
==============


File Check:
========
C:\Windows\System32\nsisvc.dll => File is digitally signed
C:\Windows\System32\drivers\nsiproxy.sys => File is digitally signed
C:\Windows\System32\dhcpcore.dll => File is digitally signed
C:\Windows\System32\drivers\afd.sys => File is digitally signed
C:\Windows\System32\drivers\tdx.sys => File is digitally signed
C:\Windows\System32\Drivers\tcpip.sys => File is digitally signed
C:\Windows\System32\dnsrslvr.dll => File is digitally signed
C:\Windows\System32\mpssvc.dll => File is digitally signed
C:\Windows\System32\bfe.dll => File is digitally signed
C:\Windows\System32\drivers\mpsdrv.sys => File is digitally signed
C:\Windows\System32\SDRSVC.dll => File is digitally signed
C:\Windows\System32\vssvc.exe => File is digitally signed
C:\Windows\System32\wuaueng.dll => File is digitally signed
C:\Windows\System32\qmgr.dll => File is digitally signed
C:\Windows\System32\es.dll => File is digitally signed
C:\Windows\System32\cryptsvc.dll => File is digitally signed
C:\Program Files\Windows Defender\MpSvc.dll => File is digitally signed
C:\Windows\System32\ipnathlp.dll => File is digitally signed
C:\Windows\System32\iphlpsvc.dll => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed


**** End of log ****
 
p22003888.gif
 
Found a rdvgkmd.sys backup
Location: C:\Windows\winsxs\amd64_rdvgwddm.inf_31bf3856ad364e35_6.1.7601.17514_none_cd55b5e46cdceae1

Folder files:
21-11-2010 04:23 113.536 rdvgkmd.sys
21-11-2010 04:23 99.712 rdvgumd64.dll
21-11-2010 04:23 52.236 rdvgwddm.inf

EDIT: from .inf, HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-RemoteDesktopServices-vGPU-KModeDriver/Debug

¿RemoteDesktopServices? doesn't seem important xD
...sophos scan still looks the same, I think I'm gonna enable don't sleep app and give a good morning of rest (5:37am here :D, I saw you only come here later so I stayed till this hours)

Thanks so much for your help, hope it starts up fast tomorrow :D
 
Last edited:
Got a BSOD due to an ati driver but is fixed.

Sophos log
2015-04-18 03:39:38.743 Sophos Virus Removal Tool version 2.5.4
2015-04-18 03:39:38.743 Copyright (c) 2009-2014 Sophos Limited. All rights reserved.

2015-04-18 03:39:38.743 This tool will scan your computer for viruses and other threats. If it finds any, it will give you the option to remove them.

2015-04-18 03:39:38.743 Windows version 6.1 SP 1.0 Service Pack 1 build 7601 SM=0x100 PT=0x1 WOW64
2015-04-18 03:39:38.744 Checking for updates...
2015-04-18 03:39:41.368 Update progress: proxy server not available
2015-04-18 03:39:52.741 Option all = no
2015-04-18 03:39:52.742 Option recurse = yes
2015-04-18 03:39:52.742 Option archive = no
2015-04-18 03:39:52.742 Option service = yes
2015-04-18 03:39:52.742 Option confirm = yes
2015-04-18 03:39:52.742 Option sxl = yes
2015-04-18 03:39:52.744 Option max-data-age = 35
2015-04-18 03:39:52.744 Option EnableSafeClean = yes
2015-04-18 03:39:54.102 Option vdl-logging = yes
2015-04-18 03:39:54.129 Customer ID: 094260ca9b3af99f9d4a3909fc47a743
2015-04-18 03:39:54.129 Machine ID: 368190e24e01423bf3bbbc1aebc9f23a
2015-04-18 03:39:54.148 Component SVRTcli.exe version 2.5.4
2015-04-18 03:39:54.148 Component control.dll version 2.5.4
2015-04-18 03:39:54.149 Component SVRTservice.exe version 2.5.4
2015-04-18 03:39:54.149 Component engine\osdp.dll version 1.44.1.2200
2015-04-18 03:39:54.149 Component engine\veex.dll version 3.60.0.2200
2015-04-18 03:39:54.149 Component engine\savi.dll version 8.1.7.2200
2015-04-18 03:39:54.150 Component rkdisk.dll version 1.5.30.0
2015-04-18 03:39:54.150 Version info: Product version 2.5.4
2015-04-18 03:39:54.150 Version info: Detection engine 3.60.0
2015-04-18 03:39:54.150 Version info: Detection data 5.13
2015-04-18 03:39:54.150 Version info: Build date 31-03-2015
2015-04-18 03:39:54.150 Version info: Data files added 264
2015-04-18 03:39:54.150 Version info: Last successful update (not yet updated)
2015-04-18 03:40:05.822 Downloading updates...
2015-04-18 03:40:05.823 Update progress: [I96736] Looking for package C1A903B2-E63E-483b-982D-04BB9C457C60 1.0
2015-04-18 03:40:05.823 Update progress: [I49502] Found supplement SAVIW32 LATEST
2015-04-18 03:40:05.823 Update progress: [I49502] Found supplement IDE514 LATEST
2015-04-18 03:40:05.823 Update progress: [I49502] Found supplement IDE515 LATEST
2015-04-18 03:40:05.823 Update progress: [I49502] Found supplement IDE516 LATEST
2015-04-18 03:40:05.823 Update progress: [I19463] Syncing product C1A903B2-E63E-483b-982D-04BB9C457C60 1
2015-04-18 03:40:05.823 Update progress: [I19463] Syncing product SAVIW32 53
2015-04-18 03:40:17.726 Update progress: [I19463] Syncing product IDE514 161
2015-04-18 03:40:19.090 Installing updates...
2015-04-18 03:40:20.092 Error level 1
2015-04-18 03:40:20.833 Update progress: [I19463] Syncing product IDE515 106
2015-04-18 03:40:20.833 Update progress: [I19463] Syncing product IDE516 1
2015-04-18 03:40:37.120 Update successful
2015-04-18 03:40:53.183 Option all = no
2015-04-18 03:40:53.183 Option recurse = yes
2015-04-18 03:40:53.183 Option archive = no
2015-04-18 03:40:53.183 Option service = yes
2015-04-18 03:40:53.183 Option confirm = yes
2015-04-18 03:40:53.183 Option sxl = yes
2015-04-18 03:40:53.185 Option max-data-age = 35
2015-04-18 03:40:53.185 Option EnableSafeClean = yes
2015-04-18 03:40:53.271 Option vdl-logging = yes
2015-04-18 03:40:53.283 Customer ID: 094260ca9b3af99f9d4a3909fc47a743
2015-04-18 03:40:53.283 Machine ID: 368190e24e01423bf3bbbc1aebc9f23a
2015-04-18 03:40:53.285 Component SVRTcli.exe version 2.5.4
2015-04-18 03:40:53.285 Component control.dll version 2.5.4
2015-04-18 03:40:53.285 Component SVRTservice.exe version 2.5.4
2015-04-18 03:40:53.285 Component engine\osdp.dll version 1.44.1.2200
2015-04-18 03:40:53.285 Component engine\veex.dll version 3.60.0.2200
2015-04-18 03:40:53.285 Component engine\savi.dll version 8.1.7.2200
2015-04-18 03:40:53.285 Component rkdisk.dll version 1.5.30.0
2015-04-18 03:40:53.286 Version info: Product version 2.5.4
2015-04-18 03:40:53.286 Version info: Detection engine 3.60.0
2015-04-18 03:40:53.286 Version info: Detection data 5.13G
2015-04-18 03:40:53.286 Version info: Build date 31-03-2015
2015-04-18 03:40:53.286 Version info: Data files added 264
2015-04-18 03:40:53.286 Version info: Last successful update 18-04-2015 04:40:37

2015-04-18 05:16:33.704 Could not open C:\hiberfil.sys
2015-04-18 05:29:17.688 >>> Virus 'Mal/VMProtBad-A' found in file C:\Program Files (x86)\Football Manager 2015\3dm_ceg.dll
2015-04-18 05:29:17.688 >>> Virus 'Mal/VMProtBad-A' found in file HKU\S-1-5-21-3165724960-2455642747-1710512649-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnPostRedirect
2015-04-18 05:29:17.688 >>> Virus 'Mal/VMProtBad-A' found in file HKU\S-1-5-21-3165724960-2455642747-1710512649-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnPostRedirect
2015-04-18 05:29:17.688 >>> Virus 'Mal/VMProtBad-A' found in file HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnPostRedirect
2015-04-18 05:44:05.289 Could not open C:\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752}
2015-04-18 05:44:05.289 Could not open C:\System Volume Information\{61edd87e-e571-11e4-bc1c-18f46afec9df}{3808876b-c176-4e48-b7ae-04046e6cc752}
2015-04-18 05:44:05.289 Could not open C:\System Volume Information\{83ea3c7b-e445-11e4-bf2b-18f46afec9df}{3808876b-c176-4e48-b7ae-04046e6cc752}
2015-04-18 05:44:05.289 Could not open C:\System Volume Information\{83ea3f05-e445-11e4-bf2b-18f46afec9df}{3808876b-c176-4e48-b7ae-04046e6cc752}
2015-04-18 05:44:05.289 Could not open C:\System Volume Information\{aeceb09e-e56b-11e4-ae52-18f46afec9df}{3808876b-c176-4e48-b7ae-04046e6cc752}
2015-04-18 05:44:05.289 Could not open C:\System Volume Information\{e857cc84-e442-11e4-b5d8-18f46afec9df}{3808876b-c176-4e48-b7ae-04046e6cc752}
2015-04-18 05:46:53.606 Could not open C:\Users\Bruno\AppData\Local\Google\Chrome\User Data\Profile 1\Current Session
2015-04-18 05:46:53.606 Could not open C:\Users\Bruno\AppData\Local\Google\Chrome\User Data\Profile 1\Current Tabs
2015-04-18 05:46:53.666 Could not check C:\Users\Bruno\AppData\Local\Google\Chrome\User Data\Profile 1\Extension Rules\LOCK (virus scan failed)
2015-04-18 05:46:53.676 Could not check C:\Users\Bruno\AppData\Local\Google\Chrome\User Data\Profile 1\Extension State\LOCK (virus scan failed)
2015-04-18 05:46:59.337 Could not check C:\Users\Bruno\AppData\Local\Google\Chrome\User Data\Profile 1\GCM Store\LOCK (virus scan failed)
2015-04-18 05:47:00.937 Could not check C:\Users\Bruno\AppData\Local\Google\Chrome\User Data\Profile 1\Local Extension Settings\pafkbggdmjlpgkdkcbjmhmfcdpncadgh\LOCK (virus scan failed)
2015-04-18 05:47:02.527 Could not check C:\Users\Bruno\AppData\Local\Google\Chrome\User Data\Profile 1\Session Storage\LOCK (virus scan failed)
2015-04-18 06:55:49.323 Sophos Virus Removal Tool version 2.5.4
2015-04-18 06:55:49.323 Copyright (c) 2009-2014 Sophos Limited. All rights reserved.

2015-04-18 06:55:49.323 This tool will scan your computer for viruses and other threats. If it finds any, it will give you the option to remove them.

2015-04-18 06:55:49.323 Windows version 6.1 SP 1.0 Service Pack 1 build 7601 SM=0x100 PT=0x1 WOW64
2015-04-18 06:55:49.323 Checking for updates...
2015-04-18 06:55:52.194 Update progress: proxy server not available
2015-04-18 06:56:24.907 Option all = no
2015-04-18 06:56:24.907 Option recurse = yes
2015-04-18 06:56:24.907 Option archive = no
2015-04-18 06:56:24.907 Option service = yes
2015-04-18 06:56:24.907 Option confirm = yes
2015-04-18 06:56:24.907 Option sxl = yes
2015-04-18 06:56:24.922 Option max-data-age = 35
2015-04-18 06:56:24.922 Option EnableSafeClean = yes
2015-04-18 06:56:25.047 Option vdl-logging = yes
2015-04-18 06:56:25.125 Customer ID: 094260ca9b3af99f9d4a3909fc47a743
2015-04-18 06:56:25.125 Machine ID: 368190e24e01423bf3bbbc1aebc9f23a
2015-04-18 06:56:25.203 Component SVRTcli.exe version 2.5.4
2015-04-18 06:56:25.219 Component control.dll version 2.5.4
2015-04-18 06:56:25.219 Component SVRTservice.exe version 2.5.4
2015-04-18 06:56:25.219 Component engine\osdp.dll version 1.44.1.2200
2015-04-18 06:56:25.219 Component engine\veex.dll version 3.60.0.2200
2015-04-18 06:56:25.219 Component engine\savi.dll version 8.1.7.2200
2015-04-18 06:56:25.234 Component rkdisk.dll version 1.5.30.0
2015-04-18 06:56:25.234 Version info: Product version 2.5.4
2015-04-18 06:56:25.234 Version info: Detection engine 3.60.0
2015-04-18 06:56:25.234 Version info: Detection data 5.13G
2015-04-18 06:56:25.234 Version info: Build date 31-03-2015
2015-04-18 06:56:25.234 Version info: Data files added 264
2015-04-18 06:56:25.234 Version info: Last successful update 18-04-2015 04:40:37
2015-04-18 06:56:46.607 Update not required

2015-04-18 08:37:48.098 Could not open C:\hiberfil.sys
2015-04-18 08:47:45.173 >>> Virus 'Mal/VMProtBad-A' found in file C:\Program Files (x86)\Football Manager 2015\3dm_ceg.dll
2015-04-18 08:47:45.173 >>> Virus 'Mal/VMProtBad-A' found in file HKU\S-1-5-21-3165724960-2455642747-1710512649-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnPostRedirect
2015-04-18 08:47:45.173 >>> Virus 'Mal/VMProtBad-A' found in file HKU\S-1-5-21-3165724960-2455642747-1710512649-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnPostRedirect
2015-04-18 08:47:45.189 >>> Virus 'Mal/VMProtBad-A' found in file HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnPostRedirect
2015-04-18 09:00:49.887 Could not open C:\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752}
2015-04-18 09:00:49.887 Could not open C:\System Volume Information\{61edd87e-e571-11e4-bc1c-18f46afec9df}{3808876b-c176-4e48-b7ae-04046e6cc752}
2015-04-18 09:00:49.887 Could not open C:\System Volume Information\{61edd8b4-e571-11e4-bc1c-18f46afec9df}{3808876b-c176-4e48-b7ae-04046e6cc752}
2015-04-18 09:00:49.887 Could not open C:\System Volume Information\{83ea3c7b-e445-11e4-bf2b-18f46afec9df}{3808876b-c176-4e48-b7ae-04046e6cc752}
2015-04-18 09:00:49.887 Could not open C:\System Volume Information\{83ea3f05-e445-11e4-bf2b-18f46afec9df}{3808876b-c176-4e48-b7ae-04046e6cc752}
2015-04-18 09:00:49.887 Could not open C:\System Volume Information\{aeceb09e-e56b-11e4-ae52-18f46afec9df}{3808876b-c176-4e48-b7ae-04046e6cc752}
2015-04-18 09:00:49.887 Could not open C:\System Volume Information\{e857cc84-e442-11e4-b5d8-18f46afec9df}{3808876b-c176-4e48-b7ae-04046e6cc752}
2015-04-18 09:18:43.169 Could not open C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb
2015-04-18 09:18:43.169 Could not open C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb
2015-04-18 09:18:47.490 Could not open C:\Windows\System32\config\RegBack\DEFAULT
2015-04-18 09:18:47.506 Could not open C:\Windows\System32\config\RegBack\SAM
2015-04-18 09:18:47.506 Could not open C:\Windows\System32\config\RegBack\SECURITY
2015-04-18 09:18:47.506 Could not open C:\Windows\System32\config\RegBack\SOFTWARE
2015-04-18 09:18:47.506 Could not open C:\Windows\System32\config\RegBack\SYSTEM
2015-04-18 09:42:30.960 The following items will be cleaned up:
2015-04-18 09:42:30.960 Mal/VMProtBad-A
2015-04-18 12:24:13.273 Threat 'Mal/VMProtBad-A' has been cleaned up.
2015-04-18 12:24:13.273 File "C:\Program Files (x86)\Football Manager 2015\3dm_ceg.dll" belongs to malware 'Mal/VMProtBad-A'.
2015-04-18 12:24:13.273 File "C:\Program Files (x86)\Football Manager 2015\3dm_ceg.dll" has been cleaned up.
2015-04-18 12:24:13.273 Registry value "HKU\S-1-5-21-3165724960-2455642747-1710512649-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnPostRedirect" belongs to malware 'Mal/VMProtBad-A'.
2015-04-18 12:24:13.273 Registry value "HKU\S-1-5-21-3165724960-2455642747-1710512649-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnPostRedirect" has been cleaned up.
2015-04-18 12:24:13.273 Registry value "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnPostRedirect" belongs to malware 'Mal/VMProtBad-A'.
2015-04-18 12:24:13.273 Registry value "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnPostRedirect" has been cleaned up.
2015-04-18 12:24:13.289 Removal successful
2015-04-18 12:24:13.335 Contents of SafeClean bin directory:
2015-04-18 12:24:13.335 {
2015-04-18 12:24:13.335 RecordID : "0000000000000001",
2015-04-18 12:24:13.335 ItemType : "1",
2015-04-18 12:24:13.335 Location : "C:\Program Files (x86)\Football Manager 2015\",
2015-04-18 12:24:13.335 FileName : "3dm_ceg.dll",
2015-04-18 12:24:13.335 ThreatName : "Mal/VMProtBad-A",
2015-04-18 12:24:13.335 Checksum : "109a7e7ca0038e08bd9b705df15940b881a18076a53250c1cf0ed84892eb4f1e",
2015-04-18 12:24:13.335 TimeStamp : "Sat Apr 18 13:24:07 2015"
2015-04-18 12:24:13.335 }
2015-04-18 12:24:14.131 Error level 0

2015-04-18 12:24:16.175 Scan completed.
2015-04-18 12:24:16.175

------------------------------------------------------------

2015-04-18 15:57:22.343 Sophos Virus Removal Tool version 2.5.4
2015-04-18 15:57:22.343 Copyright (c) 2009-2014 Sophos Limited. All rights reserved.

2015-04-18 15:57:22.343 This tool will scan your computer for viruses and other threats. If it finds any, it will give you the option to remove them.

2015-04-18 15:57:22.343 Windows version 6.1 SP 1.0 Service Pack 1 build 7601 SM=0x100 PT=0x1 WOW64
2015-04-18 15:57:22.343 Checking for updates...
2015-04-18 15:57:27.631 Update progress: proxy server not available
2015-04-18 15:57:46.148 Downloading updates...
2015-04-18 15:57:46.148 Update progress: [I96736] Looking for package C1A903B2-E63E-483b-982D-04BB9C457C60 1.0
2015-04-18 15:57:46.148 Update progress: [I49502] Found supplement SAVIW32 LATEST
2015-04-18 15:57:46.148 Update progress: [I49502] Found supplement IDE514 LATEST
2015-04-18 15:57:46.148 Update progress: [I49502] Found supplement IDE515 LATEST
2015-04-18 15:57:46.148 Update progress: [I49502] Found supplement IDE516 LATEST
2015-04-18 15:57:46.148 Update progress: [I19463] Syncing product C1A903B2-E63E-483b-982D-04BB9C457C60 1
2015-04-18 15:57:46.148 Update progress: [I19463] Syncing product SAVIW32 53
2015-04-18 15:57:46.148 Update progress: [I19463] Syncing product IDE514 161
2015-04-18 15:57:47.225 Update progress: [I19463] Syncing product IDE515 107
2015-04-18 15:57:47.490 Installing updates...
2015-04-18 15:58:04.104 Option all = no
2015-04-18 15:58:05.118 Option recurse = yes
2015-04-18 15:58:05.118 Option archive = no
2015-04-18 15:58:05.118 Option service = yes
2015-04-18 15:58:05.118 Option confirm = yes
2015-04-18 15:58:05.118 Option sxl = yes
2015-04-18 15:58:05.118 Option max-data-age = 35
2015-04-18 15:58:05.118 Option EnableSafeClean = yes
2015-04-18 15:58:05.118 Option vdl-logging = yes
2015-04-18 15:58:05.118 Customer ID: 094260ca9b3af99f9d4a3909fc47a743
2015-04-18 15:58:05.118 Machine ID: 368190e24e01423bf3bbbc1aebc9f23a
2015-04-18 15:58:05.118 Component SVRTcli.exe version 2.5.4
2015-04-18 15:58:05.118 Component control.dll version 2.5.4
2015-04-18 15:58:05.118 Component SVRTservice.exe version 2.5.4
2015-04-18 15:58:05.118 Component engine\osdp.dll version 1.44.1.2200
2015-04-18 15:58:05.118 Component engine\veex.dll version 3.60.0.2200
2015-04-18 15:58:05.118 Component engine\savi.dll version 8.1.7.2200
2015-04-18 15:58:05.118 Component rkdisk.dll version 1.5.30.0
2015-04-18 15:58:05.118 Version info: Product version 2.5.4
2015-04-18 15:58:05.118 Version info: Detection engine 3.60.0
2015-04-18 15:58:05.118 Version info: Detection data 5.13G
2015-04-18 15:58:05.118 Version info: Build date 31-03-2015
2015-04-18 15:58:05.118 Version info: Data files added 264
2015-04-18 15:58:05.118 Version info: Last successful update 18-04-2015 04:40:37
2015-04-18 15:58:05.118 Error level 1
2015-04-18 15:58:05.368 Update progress: [I19463] Syncing product IDE516 1
2015-04-18 15:58:05.430 Update successful
2015-04-18 15:58:15.771 Option all = no
2015-04-18 15:58:16.582 Option recurse = yes
2015-04-18 15:58:16.582 Option archive = no
2015-04-18 15:58:16.582 Option service = yes
2015-04-18 15:58:16.582 Option confirm = yes
2015-04-18 15:58:16.582 Option sxl = yes
2015-04-18 15:58:16.582 Option max-data-age = 35
2015-04-18 15:58:16.582 Option EnableSafeClean = yes
2015-04-18 15:58:16.582 Option vdl-logging = yes
2015-04-18 15:58:16.582 Customer ID: 094260ca9b3af99f9d4a3909fc47a743
2015-04-18 15:58:16.582 Machine ID: 368190e24e01423bf3bbbc1aebc9f23a
2015-04-18 15:58:16.582 Component SVRTcli.exe version 2.5.4
2015-04-18 15:58:16.582 Component control.dll version 2.5.4
2015-04-18 15:58:16.582 Component SVRTservice.exe version 2.5.4
2015-04-18 15:58:16.582 Component engine\osdp.dll version 1.44.1.2200
2015-04-18 15:58:16.582 Component engine\veex.dll version 3.60.0.2200
2015-04-18 15:58:16.582 Component engine\savi.dll version 8.1.7.2200
2015-04-18 15:58:16.582 Component rkdisk.dll version 1.5.30.0
2015-04-18 15:58:16.582 Version info: Product version 2.5.4
2015-04-18 15:58:16.582 Version info: Detection engine 3.60.0
2015-04-18 15:58:16.582 Version info: Detection data 5.13G
2015-04-18 15:58:16.582 Version info: Build date 31-03-2015
2015-04-18 15:58:16.582 Version info: Data files added 265
2015-04-18 15:58:16.582 Version info: Last successful update 18-04-2015 16:58:05
2015-04-18 15:58:16.582 Error level 1

2015-04-18 15:58:16.582 Scan cancelled by user.
2015-04-18 15:58:16.582

------------------------------------------------------------

2015-04-18 15:58:22.121 Sophos Virus Removal Tool version 2.5.4
2015-04-18 15:58:22.121 Copyright (c) 2009-2014 Sophos Limited. All rights reserved.

2015-04-18 15:58:22.121 This tool will scan your computer for viruses and other threats. If it finds any, it will give you the option to remove them.

2015-04-18 15:58:22.121 Windows version 6.1 SP 1.0 Service Pack 1 build 7601 SM=0x100 PT=0x1 WOW64
2015-04-18 15:58:22.121 Checking for updates...
2015-04-18 15:58:24.851 Update progress: proxy server not available
2015-04-18 15:58:26.068 Update not required
2015-04-18 15:58:31.902 Option all = no
2015-04-18 15:58:31.902 Option recurse = yes
2015-04-18 15:58:31.902 Option archive = no
2015-04-18 15:58:31.902 Option service = yes
2015-04-18 15:58:31.902 Option confirm = yes
2015-04-18 15:58:31.902 Option sxl = yes
2015-04-18 15:58:31.918 Option max-data-age = 35
2015-04-18 15:58:31.918 Option EnableSafeClean = yes
2015-04-18 15:58:31.965 Option vdl-logging = yes
2015-04-18 15:58:31.980 Customer ID: 094260ca9b3af99f9d4a3909fc47a743
2015-04-18 15:58:31.980 Machine ID: 368190e24e01423bf3bbbc1aebc9f23a
2015-04-18 15:58:31.980 Component SVRTcli.exe version 2.5.4
2015-04-18 15:58:31.980 Component control.dll version 2.5.4
2015-04-18 15:58:31.980 Component SVRTservice.exe version 2.5.4
2015-04-18 15:58:31.980 Component engine\osdp.dll version 1.44.1.2200
2015-04-18 15:58:31.980 Component engine\veex.dll version 3.60.0.2200
2015-04-18 15:58:31.980 Component engine\savi.dll version 8.1.7.2200
2015-04-18 15:58:31.980 Component rkdisk.dll version 1.5.30.0
2015-04-18 15:58:31.980 Version info: Product version 2.5.4
2015-04-18 15:58:31.980 Version info: Detection engine 3.60.0
2015-04-18 15:58:31.980 Version info: Detection data 5.13G
2015-04-18 15:58:31.980 Version info: Build date 31-03-2015
2015-04-18 15:58:31.980 Version info: Data files added 265
2015-04-18 15:58:31.980 Version info: Last successful update 18-04-2015 16:58:05
2015-04-18 15:58:44.679 Error level 1

2015-04-18 15:58:44.679 Scan completed.
2015-04-18 15:58:44.679

------------------------------------------------------------
 
redtarget.gif
Update Firefox to the current version.

redtarget.gif
Update Adobe Flash Player: http://get.adobe.com/flashplayer/
Make sure you UN-check Yes, install McAfee Security Scan Plus

NOTE 1: Beginning with Adobe Flash Version 11.3, the universal installer includes the 32-bit and 64-bit versions of the Flash Player.
NOTE 2: While installing make sure you UN-check any extra garbage which wants to install alongside.

redtarget.gif
Update your Java version here: https://www.techspot.com/downloads/6463-java-se.html
Alternate download: http://www.java.com/en/download/manual.jsp

Note 1: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.
Note 2: If you're running 64-bit system make sure you install BOTH, 32-bit and 64-bit Java.

==================================

Your computer is clean

1. This step will remove all cleaning tools we used, it'll reset restore points (so you won't get reinfected by accidentally using some older restore point) and it'll make some other minor adjustments...
This is a very crucial step so make sure you don't skip it.
Download
51a5ce45263de-delfix.png
DelFix by Xplode to your desktop. Delfix will delete all the used tools and logfiles.

Double-click Delfix.exe to start the tool.
Make sure the following items are checked:
  • Activate UAC (optional; some users prefer to keep it off)
  • Remove disinfection tools
  • Create registry backup
  • Purge System Restore
  • Reset system settings
Now click "Run" and wait patiently.
Once finished a logfile will be created. You don't have to attach it to your next reply.

2. Make sure Windows Updates are current.

3. If any trojans, rootkits or bootkits were listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately!

4. Check if your browser plugins are up to date.
Firefox - https://www.mozilla.org/en-US/plugincheck/
other browsers: https://browsercheck.qualys.com/ (click on "Scan without installing plugin" and then on "Scan now")

5. Download, and install WOT (Web OF Trust): http://www.mywot.com/. It'll warn you (in most cases) about dangerous web sites.

6. Run Malwarebytes "Quick scan" once in a while to assure safety of your computer.

7. Run Temporary File Cleaner (TFC), AdwCleaner and Junkware Removal Tool (JRT) weekly (you need to redownload these tools since they were removed by DelFix).

8. Download and install Secunia Personal Software Inspector (PSI): https://www.techspot.com/downloads/4898-secunia-personal-software-inspector-psi.html. The Secunia PSI is a FREE security tool designed to detect vulnerable and out-dated programs and plug-ins which expose your PC to attacks. Run it weekly.

9. (optional) If you want to keep all your programs up to date, download and install FileHippo Update Checker.
The Update Checker will scan your computer for installed software, check the versions and then send this information to FileHippo.com to see if there are any newer releases.

10. When installing\updating ANY program, make sure you always select "Custom " installation, so you can UN-check any possible "drive-by-install" (foistware), like toolbars etc., which may try to install along with the legitimate program. Do NOT click "Next" button without looking at any given page.

11. Read:
How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html
Simple and easy ways to keep your computer safe and secure on the Internet: http://www.bleepingcomputer.com/tutorials/keep-your-computer-safe-online/
About those Toolbars and Add-ons - Potentially Unwanted Programs (PUPs) which change your browser settings: http://www.bleepingcomputer.com/for...curity-questions-best-practices/#entry3187642

12. Please, let me know, how your computer is doing.
 
Back