Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Black screen after login windows 7 [Closed]


  • This topic is locked This topic is locked

#1
flipboi15

flipboi15

    New Member

  • Member
  • Pip
  • 5 posts
okay well I became a victim of a virus, after i log into my computer after turning it on, only a Black screen shows. I have to ctrl+alt+delete and open the task manager and start "explorer.exe" manually for the desktop to show up. Things i have done: Malware bytes antivirus, and before i knew about manually running explorer.exe I downloaded the AVG repair disk. Thank you guys.


OTL logfile created on: 25/03/2012 7:24:20 PM - Run 1
OTL by OldTimer - Version 3.2.39.2 Folder = C:\Users\Anthony\Desktop
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

7.98 Gb Total Physical Memory | 6.44 Gb Available Physical Memory | 80.77% Memory free
31.91 Gb Paging File | 30.49 Gb Available in Paging File | 95.56% Paging File free
Paging file location(s): [Binary data over 100 bytes]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 59.53 Gb Total Space | 9.29 Gb Free Space | 15.60% Space Free | Partition Type: NTFS
Drive D: | 100.00 Mb Total Space | 86.24 Mb Free Space | 86.25% Space Free | Partition Type: NTFS
Drive F: | 88.64 Gb Total Space | 2.67 Gb Free Space | 3.01% Space Free | Partition Type: NTFS
Drive G: | 465.66 Gb Total Space | 46.27 Gb Free Space | 9.94% Space Free | Partition Type: NTFS
Drive H: | 78.63 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive I: | 97.66 Gb Total Space | 68.44 Gb Free Space | 70.09% Space Free | Partition Type: NTFS

Computer Name: ANTHONY-PC | User Name: Anthony | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/03/25 19:21:43 | 000,593,920 | ---- | M] (OldTimer Tools) -- C:\Users\Anthony\Desktop\OTL.exe
PRC - [2012/03/25 18:59:25 | 000,388,608 | ---- | M] (Trend Micro Inc.) -- C:\Users\Anthony\Desktop\HijackThis.exe
PRC - [2012/02/29 16:02:00 | 002,348,352 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
PRC - [2012/02/29 13:26:46 | 000,382,272 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2012/02/14 22:27:26 | 000,076,888 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2012/01/13 14:53:18 | 000,652,360 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2011/02/15 03:20:22 | 000,364,544 | ---- | M] () -- G:\Programs\MSI Afterburner\MSIAfterburner.exe


========== Modules (No Company Name) ==========

MOD - [2012/03/21 04:21:12 | 000,429,040 | ---- | M] () -- C:\Users\Anthony\AppData\Local\Google\Chrome\Application\17.0.963.83\ppgooglenaclpluginchrome.dll
MOD - [2012/03/21 04:21:11 | 003,772,912 | ---- | M] () -- C:\Users\Anthony\AppData\Local\Google\Chrome\Application\17.0.963.83\pdf.dll
MOD - [2012/03/21 04:19:37 | 000,122,880 | ---- | M] () -- C:\Users\Anthony\AppData\Local\Google\Chrome\Application\17.0.963.83\avutil-51.dll
MOD - [2012/03/21 04:19:35 | 000,220,672 | ---- | M] () -- C:\Users\Anthony\AppData\Local\Google\Chrome\Application\17.0.963.83\avformat-53.dll
MOD - [2012/03/21 04:19:34 | 001,747,456 | ---- | M] () -- C:\Users\Anthony\AppData\Local\Google\Chrome\Application\17.0.963.83\avcodec-53.dll
MOD - [2012/03/20 23:44:18 | 008,593,056 | ---- | M] () -- C:\Users\Anthony\AppData\Local\Google\Chrome\Application\17.0.963.83\gcswf32.dll
MOD - [2011/02/15 03:20:22 | 000,364,544 | ---- | M] () -- G:\Programs\MSI Afterburner\MSIAfterburner.exe
MOD - [2011/02/15 03:20:08 | 000,061,440 | ---- | M] () -- G:\Programs\MSI Afterburner\RTMUI.dll
MOD - [2011/02/15 03:20:02 | 000,278,528 | ---- | M] () -- G:\Programs\MSI Afterburner\RTHAL.dll
MOD - [2011/02/15 03:19:44 | 000,229,376 | ---- | M] () -- G:\Programs\MSI Afterburner\RTCore.dll
MOD - [2011/02/15 03:19:30 | 000,147,456 | ---- | M] () -- G:\Programs\MSI Afterburner\RTUI.dll
MOD - [2011/02/15 03:19:20 | 000,061,440 | ---- | M] () -- G:\Programs\MSI Afterburner\RTFC.dll
MOD - [2010/07/26 20:37:16 | 000,013,312 | ---- | M] () -- G:\Programs\MSI Afterburner\RTTSH.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2012/01/13 14:53:18 | 000,652,360 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV:64bit: - [2011/12/05 19:11:56 | 000,235,520 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2010/08/12 15:00:20 | 000,133,800 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\Windows\SysNative\IPROSetMonitor.exe -- (Intel® PROSet Monitoring Service)
SRV:64bit: - [2009/07/13 17:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2009/07/13 17:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2012/02/29 16:02:00 | 002,348,352 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService)
SRV - [2012/02/29 13:26:46 | 000,382,272 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2012/02/14 22:27:26 | 000,076,888 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2012/01/31 15:09:34 | 000,158,856 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2011/03/16 10:42:06 | 000,407,336 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009/06/10 13:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)


========== Driver Services (SafeList) ==========

DRV:64bit: - File not found [Kernel | Auto | Stopped] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys -- (AODDriver4.01)
DRV:64bit: - [2012/01/17 04:45:56 | 000,188,224 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA)
DRV:64bit: - [2011/12/10 15:24:08 | 000,023,152 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:64bit: - [2011/11/16 19:31:45 | 000,279,616 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV:64bit: - [2011/11/10 18:32:02 | 000,115,272 | ---- | M] (MotioninJoy) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\MijXfilt.sys -- (MotioninJoyXFilter)
DRV:64bit: - [2011/10/17 09:40:50 | 000,093,712 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:64bit: - [2011/03/10 22:22:41 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/10 22:22:40 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010/11/09 15:35:24 | 000,021,992 | ---- | M] (CPUID) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\cpuz135_x64.sys -- (cpuz135)
DRV:64bit: - [2010/10/19 23:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64) Intel®
DRV:64bit: - [2010/09/21 06:34:18 | 000,313,520 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\e1c62x64.sys -- (e1cexpress) Intel®
DRV:64bit: - [2010/08/19 19:24:34 | 000,074,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\xusb21.sys -- (xusb21)
DRV:64bit: - [2010/02/18 09:18:24 | 000,046,136 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdiox64.sys -- (amdiox64)
DRV:64bit: - [2009/07/13 17:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 17:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 17:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009/07/13 17:47:48 | 000,023,104 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2009/07/13 17:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/07/13 16:09:10 | 000,007,680 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\loop.sys -- (msloop)
DRV:64bit: - [2009/06/10 12:35:42 | 000,187,392 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2009/06/10 12:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 12:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 12:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 12:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009/05/18 13:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV - [2011/07/22 08:26:56 | 000,014,928 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- G:\OLD PC STUFF\Program Files\SUPERAntiSpyware\sasdifsv64.sys -- (SASDIFSV)
DRV - [2011/07/12 13:55:18 | 000,012,368 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- G:\OLD PC STUFF\Program Files\SUPERAntiSpyware\saskutil64.sys -- (SASKUTIL)
DRV - [2010/05/26 16:43:00 | 000,014,648 | ---- | M] () [Kernel | On_Demand | Running] -- G:\Programs\MSI Afterburner\RTCore64.sys -- (RTCore64)
DRV - [2009/07/13 17:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://ca.msn.com/?l...en-ca&OCID=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-ca
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 52 87 03 B1 AE DC CC 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1:9421;*.local;<local>

========== FireFox ==========

FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@esn.me/esnsonar,version=0.70.4: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=1.110.0: C:\Program Files (x86)\Battlelog Web Plugins\1.110.0\npesnlaunch.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nexon.net/NxGame: C:\ProgramData\NexonUS\NGM\npNxGameUS.dll (Nexon)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\Anthony\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Anthony\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Anthony\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Components: G:\Programs\Firefox\components [2012/02/23 00:40:53 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Plugins: G:\Programs\Firefox\plugins [2012/03/04 16:36:37 | 000,000,000 | ---D | M]

[2012/02/23 00:40:59 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Anthony\AppData\Roaming\Mozilla\Extensions

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\Anthony\AppData\Local\Google\Chrome\User Data\PepperFlash\11.1.31.203\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Anthony\AppData\Local\Google\Chrome\Application\17.0.963.83\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Anthony\AppData\Local\Google\Chrome\Application\17.0.963.83\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Anthony\AppData\Local\Google\Chrome\Application\17.0.963.83\pdf.dll
CHR - plugin: Java Deployment Toolkit 6.0.290.11 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U29 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Winamp Application Detector (Enabled) = G:\Programs\Firefox\plugins\npwachk.dll
CHR - plugin: ESN Launch Mozilla Plugin (Enabled) = C:\Program Files (x86)\Battlelog Web Plugins\1.110.0\npesnlaunch.dll
CHR - plugin: ESN Sonar API (Enabled) = C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll
CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Nexon Game Controller (Enabled) = C:\ProgramData\NexonUS\NGM\npNxGameUS.dll
CHR - plugin: Facebook Video Calling Plugin (Enabled) = C:\Users\Anthony\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Anthony\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:\Users\Anthony\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\Anthony\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.18_0\
CHR - Extension: RoboForm Lite = C:\Users\Anthony\AppData\Local\Google\Chrome\User Data\Default\Extensions\kidhjpmgjfbkmcfpfakmdddddgfbhahj\3.0.1_0\
CHR - Extension: Gmail = C:\Users\Anthony\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2009/06/10 13:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [shawnotify] c:\Program Files\Shaw\Update\siuloader.exe (Shaw Cablesystems)
O4 - HKLM..\Run: [UnlockerAssistant] "G:\Programs\Unlocker\UnlockerAssistant.exe" File not found
O4 - HKCU..\Run: [Akamai NetSession Interface] "C:\Users\Anthony\AppData\Local\Akamai\netsession_win.exe" File not found
O4 - HKCU..\Run: [DAEMON Tools Lite] G:\Programs\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKCU..\Run: [Facebook Update] C:\Users\Anthony\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKCU..\Run: [Steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent File not found
O4 - HKCU..\Run: [VeohPlugin] C:\Program Files (x86)\Veoh Networks\VeohWebPlayer\veohwebplayer.exe (Veoh Networks)
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware (cleanup)] C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\cleanup.dll (Malwarebytes Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_29)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0261C4BD-B282-4D98-8000-F70EBFB612D1}: NameServer = 8.8.8.8,8.8.4.4
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\x86\mssconfig.exe) - File not found
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\x86\mssconfig.exe) - File not found
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\x86\mssconfig.exe) - File not found
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\x86\mssconfig.exe) - File not found
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\x86\mssconfig.exe) - File not found
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\x86\mssconfig.exe) - File not found
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\x86\mssconfig.exe) - File not found
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\x86\mssconfig.exe) - File not found
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\x86\mssconfig.exe) - File not found
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\x86\mssconfig.exe) - File not found
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/05/02 11:15:49 | 000,000,000 | ---- | M] () - I:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{c40444f5-4a5f-11e1-957f-ddf6d5704564}\Shell - "" = AutoRun
O33 - MountPoints2\{c40444f5-4a5f-11e1-957f-ddf6d5704564}\Shell\AutoRun\command - "" = H:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2012/03/25 19:21:41 | 000,593,920 | ---- | C] (OldTimer Tools) -- C:\Users\Anthony\Desktop\OTL.exe
[2012/03/25 18:59:24 | 000,388,608 | ---- | C] (Trend Micro Inc.) -- C:\Users\Anthony\Desktop\HijackThis.exe
[2012/03/25 17:25:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012/03/25 17:25:05 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012/03/25 14:43:56 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\x86
[2012/03/25 01:17:50 | 000,000,000 | ---D | C] -- C:\Users\Anthony\AppData\Local\ArcaneMS
[2012/03/23 03:22:36 | 000,000,000 | ---D | C] -- C:\Users\Anthony\Desktop\BT
[2012/03/23 01:56:38 | 000,000,000 | ---D | C] -- C:\ProgramData\NexonUS
[2012/03/22 14:05:44 | 000,000,000 | ---D | C] -- C:\Users\Anthony\AppData\Roaming\PeerNetworking
[2012/03/22 14:01:21 | 000,000,000 | ---D | C] -- C:\Users\Anthony\Documents\Remote Assistance Logs
[2012/03/21 03:57:10 | 000,000,000 | ---D | C] -- C:\ProgramData\DAEMON Tools Lite
[2012/03/21 03:57:08 | 000,000,000 | ---D | C] -- C:\ProgramData\shaw
[2012/03/21 00:37:13 | 000,000,000 | ---D | C] -- C:\Users\Anthony\AppData\Roaming\GetRightToGo
[2012/03/21 00:37:13 | 000,000,000 | ---D | C] -- C:\Users\Anthony\Documents\Downloads
[2012/03/14 11:15:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
[2012/03/14 11:15:10 | 000,068,928 | ---- | C] (Khronos Group) -- C:\Windows\SysNative\OpenCL.dll
[2012/03/14 11:15:10 | 000,061,248 | ---- | C] (Khronos Group) -- C:\Windows\SysWow64\OpenCL.dll
[2012/03/11 23:32:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Geeks3D
[2012/03/10 13:33:01 | 000,000,000 | ---D | C] -- C:\Users\Anthony\AppData\Roaming\Apple Computer
[2012/03/10 13:33:01 | 000,000,000 | ---D | C] -- C:\Users\Anthony\AppData\Local\Apple Computer
[2012/03/10 13:33:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2012/03/10 13:32:50 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\DRVSTORE
[2012/03/10 13:32:44 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2012/03/10 13:32:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes
[2012/03/10 13:32:44 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2012/03/10 13:30:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Apple Software Update
[2012/03/10 13:30:05 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Apple
[2012/03/10 13:30:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Bonjour
[2012/03/10 13:30:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Apple
[2012/03/10 13:20:06 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2012/03/09 11:09:53 | 000,000,000 | ---D | C] -- C:\Users\Anthony\Desktop\What the...
[2012/03/05 07:18:27 | 000,000,000 | ---D | C] -- C:\Users\Anthony\Desktop\CAR UPDATE
[2012/03/04 18:20:47 | 000,000,000 | ---D | C] -- C:\Users\Anthony\Documents\PassMark
[2012/03/04 18:20:40 | 000,000,000 | ---D | C] -- C:\Users\Anthony\AppData\Local\PassMark
[2012/03/04 18:20:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PerformanceTest (64-bit)
[2012/03/03 20:46:32 | 000,000,000 | ---D | C] -- C:\Users\Anthony\AppData\Local\XPlorerSoft™
[2012/03/03 20:42:42 | 000,000,000 | ---D | C] -- C:\Users\Anthony\Desktop\New folder (2)
[2012/02/29 07:25:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Futuremark
[2012/02/29 07:25:21 | 000,000,000 | ---D | C] -- C:\Program Files\Futuremark
[2012/02/29 07:23:45 | 000,000,000 | ---D | C] -- C:\ms
[2012/02/29 07:09:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Core Temp
[2012/02/29 07:09:58 | 000,000,000 | ---D | C] -- C:\Program Files\Core Temp
[2012/02/27 19:52:39 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA
[2 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/03/25 19:21:43 | 000,593,920 | ---- | M] (OldTimer Tools) -- C:\Users\Anthony\Desktop\OTL.exe
[2012/03/25 19:11:52 | 000,014,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/03/25 19:11:52 | 000,014,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/03/25 19:11:18 | 000,778,834 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/03/25 19:11:18 | 000,664,320 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/03/25 19:11:18 | 000,125,056 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/03/25 19:06:49 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/03/25 18:59:25 | 000,388,608 | ---- | M] (Trend Micro Inc.) -- C:\Users\Anthony\Desktop\HijackThis.exe
[2012/03/25 18:55:00 | 000,000,916 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1279799066-2833002333-689170574-1001UA.job
[2012/03/25 17:25:28 | 000,000,914 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/03/25 17:11:00 | 000,274,320 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012/03/25 14:05:05 | 000,000,936 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1279799066-2833002333-689170574-1001UA.job
[2012/03/25 01:15:54 | 000,001,265 | ---- | M] () -- C:\Users\Anthony\Desktop\ArcaneMS - Shortcut.lnk
[2012/03/24 23:05:00 | 000,000,914 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1279799066-2833002333-689170574-1001Core.job
[2012/03/24 20:55:04 | 000,000,864 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1279799066-2833002333-689170574-1001Core.job
[2012/03/23 01:59:15 | 000,001,268 | ---- | M] () -- C:\Users\Anthony\Desktop\ExtaliaMS - Shortcut.lnk
[2012/03/23 01:58:13 | 000,000,226 | ---- | M] () -- C:\Users\Public\Desktop\MapleStory.url
[2012/03/22 14:34:35 | 000,068,115 | ---- | M] () -- C:\Users\Anthony\AppData\Local\RAContactHistory.xml
[2012/03/22 11:11:41 | 000,000,719 | ---- | M] () -- C:\Users\Anthony\Desktop\aran.xpaddercontroller
[2012/03/21 14:07:08 | 000,000,183 | ---- | M] () -- C:\LeechTrain.LTr
[2012/03/21 04:23:57 | 000,001,310 | ---- | M] () -- C:\Users\Anthony\Desktop\MassEffect3 - Shortcut.lnk
[2012/03/21 03:47:15 | 000,000,776 | ---- | M] () -- C:\Users\Public\Desktop\DAEMON Tools Lite.lnk
[2012/03/21 00:41:38 | 000,000,519 | ---- | M] () -- C:\Users\Anthony\Desktop\Xpadder [5.7] - Shortcut.lnk
[2012/03/20 13:40:41 | 000,219,893 | ---- | M] () -- C:\Users\Anthony\Desktop\thrat.jpg
[2012/03/20 13:39:14 | 000,108,230 | ---- | M] () -- C:\Users\Anthony\Desktop\PM.jpg
[2012/03/19 21:42:48 | 000,072,594 | ---- | M] () -- C:\Users\Anthony\Desktop\callmepali.jpg
[2012/03/19 21:38:43 | 000,112,355 | ---- | M] () -- C:\Users\Anthony\Desktop\jeocut.jpg
[2012/03/19 21:34:01 | 000,041,780 | ---- | M] () -- C:\Users\Anthony\Desktop\payment.jpg
[2012/03/19 21:26:18 | 000,511,150 | ---- | M] () -- C:\Users\Anthony\Desktop\jeo.jpg
[2012/03/15 23:14:56 | 000,001,088 | ---- | M] () -- C:\Users\Anthony\Desktop\MapleStory.lnk
[2012/03/15 11:48:31 | 000,026,203 | ---- | M] () -- C:\Users\Anthony\Desktop\im on.htm
[2012/03/11 23:32:37 | 000,000,679 | ---- | M] () -- C:\Users\Anthony\Desktop\FurMark.lnk
[2012/03/10 13:34:11 | 005,017,258 | ---- | M] () -- C:\Users\Anthony\Desktop\danza kaduro.mp3
[2012/03/10 13:33:00 | 000,001,783 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2012/03/04 17:45:45 | 000,282,864 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.xtr
[2012/03/04 17:45:45 | 000,282,864 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2012/03/04 17:45:19 | 000,280,904 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.ex0
[2012/03/04 17:05:41 | 003,379,236 | ---- | M] () -- C:\Users\Anthony\Desktop\starships.mp3
[2012/03/04 16:43:17 | 003,368,741 | ---- | M] () -- C:\Users\Anthony\Desktop\turn me on.mp3
[2012/03/04 16:36:37 | 000,000,637 | ---- | M] () -- C:\Users\Public\Desktop\Winamp.lnk
[2012/03/04 16:36:37 | 000,000,637 | ---- | M] () -- C:\Users\Anthony\Application Data\Microsoft\Internet Explorer\Quick Launch\Winamp.lnk
[2012/03/04 16:18:49 | 000,000,615 | ---- | M] () -- C:\Users\Public\Desktop\µTorrent.lnk
[2012/03/04 16:18:49 | 000,000,615 | ---- | M] () -- C:\Users\Anthony\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk
[2012/02/29 16:02:00 | 000,068,928 | ---- | M] (Khronos Group) -- C:\Windows\SysNative\OpenCL.dll
[2012/02/29 16:02:00 | 000,061,248 | ---- | M] (Khronos Group) -- C:\Windows\SysWow64\OpenCL.dll
[2012/02/29 16:02:00 | 000,011,770 | ---- | M] () -- C:\Windows\SysNative\nvinfo.pb
[2012/02/29 13:26:56 | 000,416,064 | ---- | M] () -- C:\Windows\SysWow64\nvStreaming.exe
[2012/02/29 12:59:29 | 002,515,790 | ---- | M] () -- C:\Windows\SysNative\nvcoproc.bin
[2012/02/29 07:26:01 | 000,001,962 | ---- | M] () -- C:\Users\Public\Desktop\3DMark 11.lnk
[2012/02/29 07:09:58 | 000,000,948 | ---- | M] () -- C:\Users\Anthony\Desktop\Core Temp.lnk
[2 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/03/25 01:15:54 | 000,001,265 | ---- | C] () -- C:\Users\Anthony\Desktop\ArcaneMS - Shortcut.lnk
[2012/03/23 01:59:15 | 000,001,268 | ---- | C] () -- C:\Users\Anthony\Desktop\ExtaliaMS - Shortcut.lnk
[2012/03/23 01:58:13 | 000,000,226 | ---- | C] () -- C:\Users\Public\Desktop\MapleStory.url
[2012/03/22 14:07:02 | 000,068,115 | ---- | C] () -- C:\Users\Anthony\AppData\Local\RAContactHistory.xml
[2012/03/22 01:59:53 | 000,063,488 | ---- | C] () -- C:\Users\Anthony\Desktop\ME3Coalesced.exe
[2012/03/21 14:07:08 | 000,000,183 | ---- | C] () -- C:\LeechTrain.LTr
[2012/03/21 04:23:57 | 000,001,310 | ---- | C] () -- C:\Users\Anthony\Desktop\MassEffect3 - Shortcut.lnk
[2012/03/21 03:47:15 | 000,000,776 | ---- | C] () -- C:\Users\Public\Desktop\DAEMON Tools Lite.lnk
[2012/03/21 00:50:22 | 000,000,719 | ---- | C] () -- C:\Users\Anthony\Desktop\aran.xpaddercontroller
[2012/03/21 00:41:38 | 000,000,519 | ---- | C] () -- C:\Users\Anthony\Desktop\Xpadder [5.7] - Shortcut.lnk
[2012/03/20 13:39:14 | 000,108,230 | ---- | C] () -- C:\Users\Anthony\Desktop\PM.jpg
[2012/03/20 13:34:52 | 000,219,893 | ---- | C] () -- C:\Users\Anthony\Desktop\thrat.jpg
[2012/03/19 21:42:48 | 000,072,594 | ---- | C] () -- C:\Users\Anthony\Desktop\callmepali.jpg
[2012/03/19 21:34:01 | 000,041,780 | ---- | C] () -- C:\Users\Anthony\Desktop\payment.jpg
[2012/03/19 21:31:17 | 000,112,355 | ---- | C] () -- C:\Users\Anthony\Desktop\jeocut.jpg
[2012/03/19 21:26:18 | 000,511,150 | ---- | C] () -- C:\Users\Anthony\Desktop\jeo.jpg
[2012/03/15 11:48:40 | 000,026,203 | ---- | C] () -- C:\Users\Anthony\Desktop\im on.htm
[2012/03/11 23:32:37 | 000,000,679 | ---- | C] () -- C:\Users\Anthony\Desktop\FurMark.lnk
[2012/03/10 13:33:00 | 000,001,783 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2012/03/10 13:30:07 | 000,002,519 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
[2012/03/09 11:07:29 | 005,017,258 | ---- | C] () -- C:\Users\Anthony\Desktop\danza kaduro.mp3
[2012/03/04 17:05:37 | 003,379,236 | ---- | C] () -- C:\Users\Anthony\Desktop\starships.mp3
[2012/03/04 16:43:05 | 003,368,741 | ---- | C] () -- C:\Users\Anthony\Desktop\turn me on.mp3
[2012/03/04 16:36:37 | 000,000,637 | ---- | C] () -- C:\Users\Public\Desktop\Winamp.lnk
[2012/02/29 13:26:56 | 000,416,064 | ---- | C] () -- C:\Windows\SysWow64\nvStreaming.exe
[2012/02/29 07:25:25 | 000,001,962 | ---- | C] () -- C:\Users\Public\Desktop\3DMark 11.lnk
[2012/02/29 07:25:04 | 000,001,088 | ---- | C] () -- C:\Users\Anthony\Desktop\MapleStory.lnk
[2012/02/29 07:09:58 | 000,000,948 | ---- | C] () -- C:\Users\Anthony\Desktop\Core Temp.lnk
[2012/02/27 19:52:29 | 002,515,790 | ---- | C] () -- C:\Windows\SysNative\nvcoproc.bin
[2012/02/27 19:52:18 | 000,011,770 | ---- | C] () -- C:\Windows\SysNative\nvinfo.pb
[2012/02/16 22:18:03 | 000,072,192 | ---- | C] () -- C:\Windows\SysWow64\zlib.dll
[2012/01/29 02:24:55 | 000,001,769 | ---- | C] () -- C:\Windows\Language_trs.ini
[2012/01/02 18:01:28 | 000,764,302 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011/12/13 22:23:02 | 000,109,016 | -H-- | C] () -- C:\Windows\SysWow64\mlfcache.dat
[2011/11/09 22:39:44 | 000,059,904 | ---- | C] () -- C:\Windows\SysWow64\OpenVideo.dll
[2011/11/09 22:39:32 | 000,054,784 | ---- | C] () -- C:\Windows\SysWow64\OVDecode.dll
[2011/11/09 18:36:06 | 000,204,960 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2011/11/09 18:36:06 | 000,157,152 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2011/11/05 18:40:32 | 000,282,864 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2011/11/05 18:40:31 | 000,076,888 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2011/10/25 21:21:34 | 000,056,832 | ---- | C] () -- C:\Windows\SysWow64\OVDecoder.dll
[2011/09/28 17:44:14 | 000,179,271 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
[2011/05/30 22:39:50 | 000,058,368 | ---- | C] () -- C:\Windows\SysWow64\bdmpegv.dll
[2011/05/30 22:38:18 | 000,015,360 | ---- | C] () -- C:\Windows\SysWow64\bdmjpeg.dll

========== LOP Check ==========

[2011/12/17 08:47:37 | 000,000,000 | ---D | M] -- C:\Users\Anthony\AppData\Roaming\2K Sports
[2012/03/21 03:47:21 | 000,000,000 | ---D | M] -- C:\Users\Anthony\AppData\Roaming\DAEMON Tools Lite
[2012/03/21 00:38:35 | 000,000,000 | ---D | M] -- C:\Users\Anthony\AppData\Roaming\GetRightToGo
[2012/01/04 00:31:18 | 000,000,000 | ---D | M] -- C:\Users\Anthony\AppData\Roaming\IDoser
[2011/11/05 20:34:50 | 000,000,000 | ---D | M] -- C:\Users\Anthony\AppData\Roaming\ImgBurn
[2011/12/13 19:41:15 | 000,000,000 | ---D | M] -- C:\Users\Anthony\AppData\Roaming\LolClient
[2011/11/19 00:13:44 | 000,000,000 | ---D | M] -- C:\Users\Anthony\AppData\Roaming\MotioninJoy
[2011/12/10 14:59:06 | 000,000,000 | ---D | M] -- C:\Users\Anthony\AppData\Roaming\Need for Speed World
[2011/11/05 18:08:07 | 000,000,000 | ---D | M] -- C:\Users\Anthony\AppData\Roaming\Origin
[2012/03/22 14:05:44 | 000,000,000 | ---D | M] -- C:\Users\Anthony\AppData\Roaming\PeerNetworking
[2011/11/19 00:15:59 | 000,000,000 | ---D | M] -- C:\Users\Anthony\AppData\Roaming\PunkBuster
[2011/12/14 17:46:18 | 000,000,000 | ---D | M] -- C:\Users\Anthony\AppData\Roaming\QuickStoresToolbar
[2011/12/16 17:55:26 | 000,000,000 | ---D | M] -- C:\Users\Anthony\AppData\Roaming\Systweak
[2012/03/25 18:55:35 | 000,000,000 | ---D | M] -- C:\Users\Anthony\AppData\Roaming\uTorrent
[2012/03/24 23:05:00 | 000,000,914 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1279799066-2833002333-689170574-1001Core.job
[2012/03/25 14:05:05 | 000,000,936 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1279799066-2833002333-689170574-1001UA.job
[2009/07/13 21:08:49 | 000,027,612 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



< End of report >
  • 0

Advertisements


#2
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Hi there and sorry for the delay, could you update me on the current problems please

  • Download RogueKiller and save it on your desktop.
  • Quit all programs
  • Start RogueKiller.exe.
  • Wait until Prescan has finished ...
  • Click on Scan
Posted Image
  • Wait for the end of the scan.
  • The report has been created on the desktop.
  • Click on the Delete button.
Posted Image
  • The report has been created on the desktop.

  • Next click on the ShortcutsFix
    Posted Image
  • The report has been created on the desktop.

Please post: All RKreport.txt text files located on your desktop.

NEXT

Download OTL to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Select All Users
  • Under the Custom Scan box paste this in
    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    consrv.dll
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    /md5stop
    C:\Windows\assembly\tmp\U\*.* /s
    %Temp%\smtmp\1\*.*
    %Temp%\smtmp\2\*.*
    %Temp%\smtmp\3\*.*
    %Temp%\smtmp\4\*.*
    >C:\commands.txt echo list vol /raw /hide /c
    /wait
    >C:\DiskReport.txt diskpart /s C:\commands.txt /raw /hide /c
    /wait
    type c:\diskreport.txt /c
    /wait
    erase c:\commands.txt /hide /c
    /wait
    erase c:\diskreport.txt /hide /c
    CREATERESTOREPOINT
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Post both logs

THEN

Download aswMBR.exe ( 1.8mb ) to your desktop.
Double click the aswMBR.exe to run it Click the "Scan" button to start scan

Posted Image

On completion of the scan click save log, save it to your desktop and post in your next reply

Posted Image
  • 0

#3
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP