1. Welcome Guest! In order to create a new topic or reply to an existing one, you must register first. It is easy and free. Click here to sign up now!.
    Dismiss Notice

Logitech Webcam Uninstall Issue

Discussion in 'Malware Removal Help' started by CarolsSis, Nov 18, 2011.

  1. etavares

    etavares Malware Removal Specialist - Moderator

    Joined:
    Aug 6, 2011
    Messages:
    259
    Location:
    USA (GMT -5)
    ARO is a registry cleaner. I do not recommend using registry cleaners. If you do use it, make sure to use a tool like ERUNT to back up your registry first. Merely backing it up yourself via regedit wont' help you if you can't boot up as a result! They often claim increased performance, but an optimized registry doesn't significantly improve performance. I my opinion, the slight possible benefit doesn't justify the downside.

    See here for more information:
    http://www.bleepingcomputer.com/forums/index.php?showtopic=238799&st=0&p=1326578&#entry1326578

    With a clean MBAM scan, if you don't have any symptoms of a virus (redirects in Google searches, unexplained popups, etc.), then you're likely clean. We can dig in if you want. Just let me know.
     
  2. CarolsSis

    CarolsSis Registered Members

    Joined:
    Aug 28, 2011
    Messages:
    206
    Location:
    home
    Operating System:
    Windows Vista Enterprise
    the results of scan I posted in post #1 are the results I received on running ARO, which as run by MISTAKE. The Malware bytes scan says I HAVe NO Infected Files.
    I was never worried that there was any malware. I've not been having the "usual" problems that go with it. I ran Malwarebytes at suggestion given in this forum. Unfortunately, CNET has the silly practice of putting several "buttons" on the same page for different programs, AND None Are Labeled. It is my opinion that if they are directing you to a page for a certain program, that program should be the only one to be accessed from that page. Since it is not, and the buttons are not labeled, it is easy to chose the wrong one, as I did. It was never my intention to run a registry scan, as far as I know they're all junk.
    thanks, everyone for time and effort on my behalf. Don't know where to go from here.
     
  3. CarolsSis

    CarolsSis Registered Members

    Joined:
    Aug 28, 2011
    Messages:
    206
    Location:
    home
    Operating System:
    Windows Vista Enterprise
    I have new info. I went to Control panel>performance info & tools>advanced tools>event viewer> applications. Error 11/15/11, the entry<C:\Program date\microsoft\windows\startmenu\programs\logitech\logitech vid hd.lnk> in the hash map cannot be updated
    context:application>systemIndex catalog> Details: a device attached to the system is not functioning. (0x8007001f) I also copied down another > Error> 11/17/11> System Restore>an unspecified error occurred during system restore(Windows Update) event ID 8209. I believe the Logitech error happened when I was attempting to uninstall it, the vid hd icon is the one removed after un-install attempt. I hope this give enough info to help, because the malware search came up empty. Just out of curiousity, I'm going to plug the camera into the desktop computer, see if it works there. Thanks, everyone for all the help.
     
  4. starbuck

    starbuck Rest In Peace Pete Administrator

    Joined:
    Sep 26, 2009
    Messages:
    3,830
    Location:
    Midlands, UK
    Operating System:
    Windows 10
    CPU:
    AMD Athlon II x2 250 Processor 3.00GHz
    Memory:
    8gb DDR3
    Hard Drive:
    500gb SATA
    Graphics Card:
    ASUS GeForce GTX 960 2gb
    Power Supply:
    650w PowerCool X-Viper
    Couldn't agree more.

    This is to be expected, you uninstalled the program, but it left remains behind.

    Let's see if we can clear these orphan entries for you.

    • Download OTL to your desktop.
      right click on the link and select 'Save Link/Target As'.

      if you have problems, try this download link:
      OTL
    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check
    .

    .
    .

    Now copy the lines in bold below.

    netsvcs
    msconfig
    %SYSTEMDRIVE%\*.*
    %systemroot%\system32\Spool\prtprocs\w32x86\*.dll
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\system32\*.exe /lockedfiles
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\*
    %USERPROFILE%\..|smtmp;true;true;true /FP
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    hklm\software\clients\startmenuinternet|command /rs
    hklm\software\clients\startmenuinternet|command /64 /rs
    CREATERESTOREPOINT


    • right click in the Custom Scans/Fixes window (under the blue bar) and choose Paste.

      .
      .
    • Click the Run Scan button.

      [​IMG]
    • Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them with your next reply.

    Please post both reports in your next reply and we'll have a better idea of how to help.
     
    Last edited by a moderator: Feb 4, 2014
  5. CarolsSis

    CarolsSis Registered Members

    Joined:
    Aug 28, 2011
    Messages:
    206
    Location:
    home
    Operating System:
    Windows Vista Enterprise
    Oh boy, this looks like registry editing. what happens if I screw it up? I tried to be real careful to copy down the info from this morning. and I will do the same here. Thanks, keep your fingers crossed and prayers going up for me on this one.
     
  6. starbuck

    starbuck Rest In Peace Pete Administrator

    Joined:
    Sep 26, 2009
    Messages:
    3,830
    Location:
    Midlands, UK
    Operating System:
    Windows 10
    CPU:
    AMD Athlon II x2 250 Processor 3.00GHz
    Memory:
    8gb DDR3
    Hard Drive:
    500gb SATA
    Graphics Card:
    ASUS GeForce GTX 960 2gb
    Power Supply:
    650w PowerCool X-Viper
    which post was that?
    Posts show that you have posted 3 replies today..... have you posted more than that?
     
  7. CarolsSis

    CarolsSis Registered Members

    Joined:
    Aug 28, 2011
    Messages:
    206
    Location:
    home
    Operating System:
    Windows Vista Enterprise
    no, I failed to see the #2 page number, sorry, still learning this forum too.
    OTL Extras logfile created on: 11/22/2011 6:55:44 PM - Run 1
    OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Janice\Downloads
    Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
    Internet Explorer (Version = 9.0.8112.16421)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    1.99 Gb Total Physical Memory | 1.11 Gb Available Physical Memory | 55.90% Memory free
    4.22 Gb Paging File | 2.94 Gb Available in Paging File | 69.65% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
    Drive C: | 51.14 Gb Total Space | 20.12 Gb Free Space | 39.33% Space Free | Partition Type: NTFS
    Drive D: | 50.89 Gb Total Space | 42.97 Gb Free Space | 84.45% Space Free | Partition Type: NTFS

    Computer Name: JANICEPC | User Name: Janice | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: Current user
    Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

    ========== Extra Registry (SafeList) ==========


    ========== File Associations ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
    .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
    .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)

    ========== Shell Spawning ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [open] -- "%1" %*
    cmdfile [open] -- "%1" %*
    comfile [open] -- "%1" %*
    cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
    exefile [open] -- "%1" %*
    helpfile [open] -- Reg Error: Key error.
    hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
    inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
    piffile [open] -- "%1" %*
    regfile [merge] -- Reg Error: Key error.
    scrfile [config] -- "%1"
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
    scrfile [open] -- "%1" /S
    txtfile [edit] -- Reg Error: Key error.
    Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
    Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
    Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    ========== Security Center Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    "cval" = 1

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiSpyware]
    "DisableMonitoring" = 1

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
    "AntiVirusOverride" = 0
    "AntiSpywareOverride" = 0
    "FirewallOverride" = 0
    "VistaSp1" = Reg Error: Unknown registry data type -- File not found
    "VistaSp2" = Reg Error: Unknown registry data type -- File not found

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

    ========== Firewall Settings ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
    "EnableFirewall" = 1
    "DisableNotifications" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
    "EnableFirewall" = 1
    "DisableNotifications" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
    "EnableFirewall" = 1
    "DisableNotifications" = 0

    ========== Authorized Applications List ==========


    ========== Vista Active Open Ports Exception List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{05EEB18B-D5B9-4828-BE54-9A4E4E016A4F}" = lport=1701 | protocol=17 | dir=in | app=system |
    "{0B8F0C6F-56F6-4FE6-BC88-27AD2997B48E}" = rport=1723 | protocol=6 | dir=out | app=system |
    "{17DC5873-2E73-4C6C-9C7A-AFDDE31504F4}" = rport=139 | protocol=6 | dir=out | app=system |
    "{187351CB-2F50-4337-ACFB-7C2D6162B7B5}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
    "{1D5F956D-E319-4CA6-A1E3-3B1B42945541}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
    "{2D1A4471-4F30-489A-A37F-F8502AE75CE9}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
    "{2F3D7327-6E53-45C2-9D36-1D286F9B338C}" = rport=1701 | protocol=17 | dir=out | app=system |
    "{3893ADD0-E11A-4EB6-9420-6C4E237C6366}" = lport=445 | protocol=6 | dir=in | app=system |
    "{4FADB3B7-539F-4F48-90E5-381516555347}" = lport=139 | protocol=6 | dir=in | app=system |
    "{569B0D6B-D46A-4907-BB53-FB36327C25D7}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
    "{5BA89CCD-308F-4677-AC16-F348205D9596}" = lport=137 | protocol=17 | dir=in | app=system |
    "{74696714-4756-40E1-A3A7-BAA2AB7EE1BA}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=file and printer sharing (spooler service - rpc-epmap) |
    "{7F13A3EA-798B-46FF-AF6C-9FF52F146708}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=c:\windows\system32\svchost.exe |
    "{8BB4A480-1583-4303-9538-698687D2BB2D}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=c:\windows\system32\spoolsv.exe |
    "{901C8821-5AA1-4661-9AA4-FE52812DE6DC}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=c:\windows\system32\svchost.exe |
    "{90605990-BE44-4369-8559-8C6E79A7EE66}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=c:\windows\system32\svchost.exe |
    "{987B535F-1079-4E59-8127-6811161A704A}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=c:\windows\system32\svchost.exe |
    "{B6461911-74F0-4B30-9C2C-436F4071A036}" = lport=1723 | protocol=6 | dir=in | app=system |
    "{BCEFE1CE-1E49-4975-BB07-92D1CD11CD05}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=c:\windows\system32\svchost.exe |
    "{C9F9383B-D725-4712-A896-A1BAABF77AFF}" = rport=445 | protocol=6 | dir=out | app=system |
    "{D1951F89-0D45-4228-AABF-42EDE08BE6BA}" = rport=137 | protocol=17 | dir=out | app=system |
    "{DCE15236-4EC6-47F1-B754-C72ED4C845E7}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=c:\windows\system32\svchost.exe |
    "{F5F02FEF-7858-430A-A3BC-1424EA7F83C8}" = rport=138 | protocol=17 | dir=out | app=system |
    "{F99BFD93-7359-4526-8ED9-84263671A2A5}" = lport=2869 | protocol=6 | dir=in | app=system |
    "{FF1084F7-9740-4697-8888-3AD3E5D01E58}" = lport=138 | protocol=17 | dir=in | app=system |

    ========== Vista Active Application Exception List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{136ECDCB-354B-45CF-B74F-1CD2532D6501}" = protocol=1 | dir=out | name=file and printer sharing (echo request - icmpv4-out) |
    "{585B3550-FEE7-4183-8F73-C4F66DE696B5}" = dir=in | app=c:\program files\acer arcade deluxe\homemedia\homemedia.exe |
    "{6DDEF72E-B18E-4055-B96D-2C793EEAA9FD}" = protocol=6 | dir=out | app=system |
    "{770DE421-4C82-4B08-9FF5-9F44E4A8D86A}" = protocol=58 | dir=out | name=file and printer sharing (echo request - icmpv6-out) |
    "{801AF5B7-7467-49A7-A7C9-9A6216D0B77A}" = protocol=6 | dir=out | svc=upnphost | app=c:\windows\system32\svchost.exe |
    "{C3C63ABA-30D4-4EA9-B23F-568596848C65}" = protocol=6 | dir=out | svc=upnphost | app=c:\windows\system32\svchost.exe |
    "{C9B6218B-4A64-4511-AB51-E77C507D7359}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{CC3EF2CA-B664-44D3-8609-B9B9D76C9741}" = protocol=6 | dir=out | app=c:\windows\system32\wudfhost.exe |
    "{D2E3A7D5-1887-4379-9F8C-A93BB552975F}" = protocol=1 | dir=in | name=file and printer sharing (echo request - icmpv4-in) |
    "{DF2D1B8F-EE18-4751-A35C-A75DA8FC87C3}" = protocol=58 | dir=in | name=file and printer sharing (echo request - icmpv6-in) |
    "{E06EC9EA-32B8-4FEA-9D87-CA7111A5507D}" = dir=in | app=c:\program files\acer arcade deluxe\videomagician\videomagician.exe |
    "{E2554D85-7AED-4FDA-BA26-3A055BD6A5C3}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe |
    "{E82E77A9-2EAB-40F9-9A5C-C543B020A4D8}" = dir=in | app=c:\program files\acer arcade deluxe\acer arcade deluxe\acer arcade deluxe.exe |
    "TCP Query User{070F9828-AFB3-43B9-A035-6846EAAE95A9}C:\program files\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
    "TCP Query User{7958372C-E496-412F-B870-2A7413EA78FB}C:\program files\logitech\vid hd\vid.exe" = protocol=6 | dir=in | app=c:\program files\logitech\vid hd\vid.exe |
    "TCP Query User{BDEEE42F-CC80-4568-8F5D-479526768BEE}C:\program files\logitech\vid hd\vid.exe" = protocol=6 | dir=in | app=c:\program files\logitech\vid hd\vid.exe |
    "UDP Query User{7E1B4235-B5F0-48F2-B5AE-728F41B09904}C:\program files\logitech\vid hd\vid.exe" = protocol=17 | dir=in | app=c:\program files\logitech\vid hd\vid.exe |
    "UDP Query User{CA4311D2-2C7E-4422-A91B-5CD727967B28}C:\program files\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
    "UDP Query User{ECCCF5FD-EE36-43DE-8E39-5F08F2D6A83C}C:\program files\logitech\vid hd\vid.exe" = protocol=17 | dir=in | app=c:\program files\logitech\vid hd\vid.exe |

    ========== HKEY_LOCAL_MACHINE Uninstall List ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{08610298-29AE-445B-B37D-EFBE05802967}" = LWS Pictures And Video
    "{0BF78E88-A7C9-4406-89CF-0BA473BA7821}" = Orion
    "{11316260-6666-467B-AC34-183FCB5D4335}" = Acer Mobility Center Plug-In
    "{116FF17B-1A30-4FC2-9B01-5BC5BD46B0B3}" = Acer eLock Management
    "{138A4072-9E64-46BD-B5F9-DB2BB395391F}" = LWS VideoEffects
    "{15634701-BACE-4449-8B25-1567DA8C9FD3}" = CameraHelperMsi
    "{1577A05B-EE62-4BBC-9DB7-FE748FA44EC2}" = NTI CD & DVD-Maker
    "{1598034D-7147-432C-8CA8-888E0632D124}" = NTI Backup NOW! 4.7
    "{1651216E-E7AD-4250-92A1-FB8ED61391C9}" = LWS Help_main
    "{174A3B31-4C43-43DD-866F-73C9DB887B48}" = LWS Twitter
    "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    "{21DF0294-6B9D-4741-AB6F-B2ABFBD2387E}" = LWS YouTube Plugin
    "{26A24AE4-039D-4CA4-87B4-2F83216026FF}" = Java(TM) 6 Update 29
    "{2D87E961-577B-492B-AD54-1368680FB9A7}" = Bing Maps 3D
    "{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
    "{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = erLT
    "{427967BF-09F8-46D5-9275-37001CCBBA5D}" = Winbond CIR Drivers
    "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
    "{58E5844B-7CE2-413D-83D1-99294BF6C74F}" = Acer ePower Management
    "{59F6A514-9813-47A3-948C-8A155460CC2A}" = RICOH R5C83x/84x Flash Media Controller Driver Ver.3.52.02
    "{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
    "{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
    "{6F76EC3C-34B1-436E-97FB-48C58D7BEDCD}" = LWS Gallery
    "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
    "{71E66D3F-A009-44AB-8784-75E2819BA4BA}" = LWS Motion Detection
    "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
    "{79DD56FC-DB8B-47F5-9C80-78B62E05F9BC}" = Acer ScreenSaver
    "{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110111700}" = Zuma Deluxe
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110113233}" = Bookworm Deluxe
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11029123}" = Bricks of Egypt
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110322783}" = Big Kahuna Reef
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110411970}" = Chuzzle
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111118433}" = Mystery Case Files - Huntsville
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111199750}" = Cake Mania
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111252743}" = Mahjong Escape Ancient China
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111324990}" = Kick N Rush
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111543617}" = Backspin Billiards
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111692950}" = Mahjongg Artifacts
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111771833}" = Jewel Quest Solitaire
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111796363}" = Mystery Solitaire - Secret Island
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111872660}" = Diner Dash Flo on the Go
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112310577}" = Flip Words 2
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112531267}" = Chicken Invaders 3
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112615863}" = Agatha Christie Death on the Nile
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112920767}" = Alice Greenfingers
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113009953}" = Turbo Pizza
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113080210}" = Azada
    "{83C8FA3C-F4EA-46C4-8392-D3CE353738D6}" = LWS Launcher
    "{8937D274-C281-42E4-8CDB-A0B2DF979189}" = LWS Webcam Software
    "{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
    "{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
    "{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
    "{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
    "{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
    "{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    "{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
    "{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    "{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
    "{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
    "{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
    "{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
    "{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
    "{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel(R) Matrix Storage Manager
    "{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
    "{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
    "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
    "{9DAEA76B-E50F-4272-A595-0124E826553D}" = LWS WLM Plugin
    "{A5633652-3795-4829-BB0B-644F0279E279}" = Acer eDataSecurity Management
    "{A83279FD-CA4B-4206-9535-90974DE76654}" = Apple Application Support
    "{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.6
    "{AB6097D9-D722-4987-BD9E-A076E2848EE2}" = Acer Empowering Technology
    "{AC76BA86-7AD7-1033-7B44-A81000000003}" = Adobe Reader 8.1.0
    "{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
    "{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = PowerProducer
    "{BF839132-BD43-4056-ACBF-4377F4A88E2A}" = Acer ePresentation Management
    "{C06554A1-2C1E-4D20-B613-EE62C79927CC}" = Acer eNet Management
    "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
    "{CE386A4E-D0DA-4208-8235-BCE43275C694}" = LightScribe 1.4.142.1
    "{CE65A9A0-9686-45C6-9098-3C9543A412F0}" = Acer eSettings Management
    "{D40EB009-0499-459c-A8AF-C9C110766215}" = Logitech Webcam Software
    "{EED027B7-0DB6-404B-8F45-6DFEE34A0441}" = LWS Video Mask Maker
    "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
    "{FC57FC53-104C-415C-98D7-B05E659461A9}" = Broadcom Gigabit Integrated Controller
    "{FF167195-9EE4-46C0-8CD7-FBA3457E88AB}" = LWS Facebook
    "Acer Assist" = Acer Assist
    "Acer Registration" = Acer Registration
    "Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
    "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
    "Agere Systems Soft Modem" = Agere Systems HDA Modem
    "ARO 2011_is1" = ARO 2011
    "Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
    "GridVista" = Acer GridVista
    "HDMI" = Intel(R) Graphics Media Accelerator Driver
    "HOMESTUDENTR" = Microsoft Office Home and Student 2007
    "InstallShield_{1577A05B-EE62-4BBC-9DB7-FE748FA44EC2}" = NTI CD & DVD-Maker
    "InstallShield_{1598034D-7147-432C-8CA8-888E0632D124}" = NTI Backup NOW! 4.7
    "LManager" = Launch Manager
    "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
    "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
    "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
    "Revo Uninstaller" = Revo Uninstaller 1.93
    "SynTPDeinstKey" = Synaptics Pointing Device Driver
    "YTdetect" = Yahoo! Detect

    ========== Last 10 Event Log Errors ==========

    [ Application Events ]
    Error - 11/15/2011 10:23:05 AM | Computer Name = JanicePC | Source = Windows Search Service | ID = 3013
    Description =

    Error - 11/15/2011 10:23:05 AM | Computer Name = JanicePC | Source = Windows Search Service | ID = 3013
    Description =

    Error - 11/15/2011 10:23:05 AM | Computer Name = JanicePC | Source = Windows Search Service | ID = 3013
    Description =

    Error - 11/15/2011 10:23:05 AM | Computer Name = JanicePC | Source = Windows Search Service | ID = 3013
    Description =

    Error - 11/16/2011 12:10:30 AM | Computer Name = JanicePC | Source = WinMgmt | ID = 10
    Description =

    Error - 11/16/2011 11:09:55 AM | Computer Name = JanicePC | Source = WinMgmt | ID = 10
    Description =

    Error - 11/16/2011 10:09:03 PM | Computer Name = JanicePC | Source = WinMgmt | ID = 10
    Description =

    Error - 11/17/2011 12:58:46 AM | Computer Name = JanicePC | Source = WinMgmt | ID = 10
    Description =

    Error - 11/17/2011 12:12:42 PM | Computer Name = JanicePC | Source = WinMgmt | ID = 10
    Description =

    Error - 11/17/2011 8:46:36 PM | Computer Name = JanicePC | Source = WinMgmt | ID = 10
    Description =

    [ System Events ]
    Error - 8/9/2011 8:19:54 AM | Computer Name = JanicePC | Source = Service Control Manager | ID = 7000
    Description =

    Error - 8/9/2011 8:41:27 AM | Computer Name = JanicePC | Source = ACPI | ID = 327693
    Description = : The embedded controller (EC) did not respond within the specified
    timeout period. This may indicate that there is an error in the EC hardware or
    firmware or that the BIOS is accessing the EC incorrectly. You should check with
    your computer manufacturer for an upgraded BIOS. In some situations, this error
    may cause the computer to function incorrectly.

    Error - 8/9/2011 8:42:45 AM | Computer Name = JanicePC | Source = Service Control Manager | ID = 7000
    Description =

    Error - 8/9/2011 9:08:00 AM | Computer Name = JanicePC | Source = Service Control Manager | ID = 7000
    Description =

    Error - 8/9/2011 9:08:30 PM | Computer Name = JanicePC | Source = Service Control Manager | ID = 7000
    Description =

    Error - 8/10/2011 7:57:33 AM | Computer Name = JanicePC | Source = Service Control Manager | ID = 7000
    Description =

    Error - 8/10/2011 7:57:58 AM | Computer Name = JanicePC | Source = Server | ID = 2505
    Description = The server could not bind to the transport \Device\NetBT_Tcpip_{82447EF1-0445-4ED3-8CE1-220AFC8E058D}
    because another computer on the network has the same name. The server could not
    start.

    Error - 8/10/2011 7:57:58 AM | Computer Name = JanicePC | Source = netbt | ID = 4321
    Description = The name "JANICEPC :20" could not be registered on the interface
    with IP address 0.0.0.0. The computer with the IP address 192.168.1.2 did not allow
    the name to be claimed by this computer.

    Error - 8/10/2011 8:26:49 AM | Computer Name = JanicePC | Source = Service Control Manager | ID = 7000
    Description =

    Error - 8/10/2011 9:19:38 PM | Computer Name = JanicePC | Source = Service Control Manager | ID = 7000
    Description =


    < End of report >
     
  8. starbuck

    starbuck Rest In Peace Pete Administrator

    Joined:
    Sep 26, 2009
    Messages:
    3,830
    Location:
    Midlands, UK
    Operating System:
    Windows 10
    CPU:
    AMD Athlon II x2 250 Processor 3.00GHz
    Memory:
    8gb DDR3
    Hard Drive:
    500gb SATA
    Graphics Card:
    ASUS GeForce GTX 960 2gb
    Power Supply:
    650w PowerCool X-Viper
    Hi CarolsSis

    Don't worry, if anything needs removing we'll do it with a fix that i'll write.
    All you would have to do is to run the fix.
    All very simple.

    You have only posted the 'Extra.txt'
    Can you please post the Main report.

    The Extra.txt was saved here:
    C:\Users\Janice\Downloads

    so the Main.txt will be saved in the same location.
    This is the icon you are looking for: ( it's just called OTL )

    [​IMG]


    Thanks
     
  9. CarolsSis

    CarolsSis Registered Members

    Joined:
    Aug 28, 2011
    Messages:
    206
    Location:
    home
    Operating System:
    Windows Vista Enterprise
    OTL Extras logfile created on: 11/22/2011 6:55:44 PM - Run 1
    OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Janice\Downloads
    Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
    Internet Explorer (Version = 9.0.8112.16421)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    1.99 Gb Total Physical Memory | 1.11 Gb Available Physical Memory | 55.90% Memory free
    4.22 Gb Paging File | 2.94 Gb Available in Paging File | 69.65% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
    Drive C: | 51.14 Gb Total Space | 20.12 Gb Free Space | 39.33% Space Free | Partition Type: NTFS
    Drive D: | 50.89 Gb Total Space | 42.97 Gb Free Space | 84.45% Space Free | Partition Type: NTFS

    Computer Name: JANICEPC | User Name: Janice | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: Current user
    Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

    ========== Extra Registry (SafeList) ==========


    ========== File Associations ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
    .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
    .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)

    ========== Shell Spawning ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [open] -- "%1" %*
    cmdfile [open] -- "%1" %*
    comfile [open] -- "%1" %*
    cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
    exefile [open] -- "%1" %*
    helpfile [open] -- Reg Error: Key error.
    hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
    inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
    piffile [open] -- "%1" %*
    regfile [merge] -- Reg Error: Key error.
    scrfile [config] -- "%1"
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
    scrfile [open] -- "%1" /S
    txtfile [edit] -- Reg Error: Key error.
    Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
    Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
    Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    ========== Security Center Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    "cval" = 1

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiSpyware]
    "DisableMonitoring" = 1

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
    "AntiVirusOverride" = 0
    "AntiSpywareOverride" = 0
    "FirewallOverride" = 0
    "VistaSp1" = Reg Error: Unknown registry data type -- File not found
    "VistaSp2" = Reg Error: Unknown registry data type -- File not found

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

    ========== Firewall Settings ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
    "EnableFirewall" = 1
    "DisableNotifications" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
    "EnableFirewall" = 1
    "DisableNotifications" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
    "EnableFirewall" = 1
    "DisableNotifications" = 0

    ========== Authorized Applications List ==========


    ========== Vista Active Open Ports Exception List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{05EEB18B-D5B9-4828-BE54-9A4E4E016A4F}" = lport=1701 | protocol=17 | dir=in | app=system |
    "{0B8F0C6F-56F6-4FE6-BC88-27AD2997B48E}" = rport=1723 | protocol=6 | dir=out | app=system |
    "{17DC5873-2E73-4C6C-9C7A-AFDDE31504F4}" = rport=139 | protocol=6 | dir=out | app=system |
    "{187351CB-2F50-4337-ACFB-7C2D6162B7B5}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
    "{1D5F956D-E319-4CA6-A1E3-3B1B42945541}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
    "{2D1A4471-4F30-489A-A37F-F8502AE75CE9}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
    "{2F3D7327-6E53-45C2-9D36-1D286F9B338C}" = rport=1701 | protocol=17 | dir=out | app=system |
    "{3893ADD0-E11A-4EB6-9420-6C4E237C6366}" = lport=445 | protocol=6 | dir=in | app=system |
    "{4FADB3B7-539F-4F48-90E5-381516555347}" = lport=139 | protocol=6 | dir=in | app=system |
    "{569B0D6B-D46A-4907-BB53-FB36327C25D7}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
    "{5BA89CCD-308F-4677-AC16-F348205D9596}" = lport=137 | protocol=17 | dir=in | app=system |
    "{74696714-4756-40E1-A3A7-BAA2AB7EE1BA}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=file and printer sharing (spooler service - rpc-epmap) |
    "{7F13A3EA-798B-46FF-AF6C-9FF52F146708}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=c:\windows\system32\svchost.exe |
    "{8BB4A480-1583-4303-9538-698687D2BB2D}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=c:\windows\system32\spoolsv.exe |
    "{901C8821-5AA1-4661-9AA4-FE52812DE6DC}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=c:\windows\system32\svchost.exe |
    "{90605990-BE44-4369-8559-8C6E79A7EE66}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=c:\windows\system32\svchost.exe |
    "{987B535F-1079-4E59-8127-6811161A704A}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=c:\windows\system32\svchost.exe |
    "{B6461911-74F0-4B30-9C2C-436F4071A036}" = lport=1723 | protocol=6 | dir=in | app=system |
    "{BCEFE1CE-1E49-4975-BB07-92D1CD11CD05}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=c:\windows\system32\svchost.exe |
    "{C9F9383B-D725-4712-A896-A1BAABF77AFF}" = rport=445 | protocol=6 | dir=out | app=system |
    "{D1951F89-0D45-4228-AABF-42EDE08BE6BA}" = rport=137 | protocol=17 | dir=out | app=system |
    "{DCE15236-4EC6-47F1-B754-C72ED4C845E7}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=c:\windows\system32\svchost.exe |
    "{F5F02FEF-7858-430A-A3BC-1424EA7F83C8}" = rport=138 | protocol=17 | dir=out | app=system |
    "{F99BFD93-7359-4526-8ED9-84263671A2A5}" = lport=2869 | protocol=6 | dir=in | app=system |
    "{FF1084F7-9740-4697-8888-3AD3E5D01E58}" = lport=138 | protocol=17 | dir=in | app=system |

    ========== Vista Active Application Exception List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{136ECDCB-354B-45CF-B74F-1CD2532D6501}" = protocol=1 | dir=out | name=file and printer sharing (echo request - icmpv4-out) |
    "{585B3550-FEE7-4183-8F73-C4F66DE696B5}" = dir=in | app=c:\program files\acer arcade deluxe\homemedia\homemedia.exe |
    "{6DDEF72E-B18E-4055-B96D-2C793EEAA9FD}" = protocol=6 | dir=out | app=system |
    "{770DE421-4C82-4B08-9FF5-9F44E4A8D86A}" = protocol=58 | dir=out | name=file and printer sharing (echo request - icmpv6-out) |
    "{801AF5B7-7467-49A7-A7C9-9A6216D0B77A}" = protocol=6 | dir=out | svc=upnphost | app=c:\windows\system32\svchost.exe |
    "{C3C63ABA-30D4-4EA9-B23F-568596848C65}" = protocol=6 | dir=out | svc=upnphost | app=c:\windows\system32\svchost.exe |
    "{C9B6218B-4A64-4511-AB51-E77C507D7359}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{CC3EF2CA-B664-44D3-8609-B9B9D76C9741}" = protocol=6 | dir=out | app=c:\windows\system32\wudfhost.exe |
    "{D2E3A7D5-1887-4379-9F8C-A93BB552975F}" = protocol=1 | dir=in | name=file and printer sharing (echo request - icmpv4-in) |
    "{DF2D1B8F-EE18-4751-A35C-A75DA8FC87C3}" = protocol=58 | dir=in | name=file and printer sharing (echo request - icmpv6-in) |
    "{E06EC9EA-32B8-4FEA-9D87-CA7111A5507D}" = dir=in | app=c:\program files\acer arcade deluxe\videomagician\videomagician.exe |
    "{E2554D85-7AED-4FDA-BA26-3A055BD6A5C3}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe |
    "{E82E77A9-2EAB-40F9-9A5C-C543B020A4D8}" = dir=in | app=c:\program files\acer arcade deluxe\acer arcade deluxe\acer arcade deluxe.exe |
    "TCP Query User{070F9828-AFB3-43B9-A035-6846EAAE95A9}C:\program files\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
    "TCP Query User{7958372C-E496-412F-B870-2A7413EA78FB}C:\program files\logitech\vid hd\vid.exe" = protocol=6 | dir=in | app=c:\program files\logitech\vid hd\vid.exe |
    "TCP Query User{BDEEE42F-CC80-4568-8F5D-479526768BEE}C:\program files\logitech\vid hd\vid.exe" = protocol=6 | dir=in | app=c:\program files\logitech\vid hd\vid.exe |
    "UDP Query User{7E1B4235-B5F0-48F2-B5AE-728F41B09904}C:\program files\logitech\vid hd\vid.exe" = protocol=17 | dir=in | app=c:\program files\logitech\vid hd\vid.exe |
    "UDP Query User{CA4311D2-2C7E-4422-A91B-5CD727967B28}C:\program files\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
    "UDP Query User{ECCCF5FD-EE36-43DE-8E39-5F08F2D6A83C}C:\program files\logitech\vid hd\vid.exe" = protocol=17 | dir=in | app=c:\program files\logitech\vid hd\vid.exe |

    ========== HKEY_LOCAL_MACHINE Uninstall List ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{08610298-29AE-445B-B37D-EFBE05802967}" = LWS Pictures And Video
    "{0BF78E88-A7C9-4406-89CF-0BA473BA7821}" = Orion
    "{11316260-6666-467B-AC34-183FCB5D4335}" = Acer Mobility Center Plug-In
    "{116FF17B-1A30-4FC2-9B01-5BC5BD46B0B3}" = Acer eLock Management
    "{138A4072-9E64-46BD-B5F9-DB2BB395391F}" = LWS VideoEffects
    "{15634701-BACE-4449-8B25-1567DA8C9FD3}" = CameraHelperMsi
    "{1577A05B-EE62-4BBC-9DB7-FE748FA44EC2}" = NTI CD & DVD-Maker
    "{1598034D-7147-432C-8CA8-888E0632D124}" = NTI Backup NOW! 4.7
    "{1651216E-E7AD-4250-92A1-FB8ED61391C9}" = LWS Help_main
    "{174A3B31-4C43-43DD-866F-73C9DB887B48}" = LWS Twitter
    "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    "{21DF0294-6B9D-4741-AB6F-B2ABFBD2387E}" = LWS YouTube Plugin
    "{26A24AE4-039D-4CA4-87B4-2F83216026FF}" = Java(TM) 6 Update 29
    "{2D87E961-577B-492B-AD54-1368680FB9A7}" = Bing Maps 3D
    "{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
    "{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = erLT
    "{427967BF-09F8-46D5-9275-37001CCBBA5D}" = Winbond CIR Drivers
    "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
    "{58E5844B-7CE2-413D-83D1-99294BF6C74F}" = Acer ePower Management
    "{59F6A514-9813-47A3-948C-8A155460CC2A}" = RICOH R5C83x/84x Flash Media Controller Driver Ver.3.52.02
    "{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
    "{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
    "{6F76EC3C-34B1-436E-97FB-48C58D7BEDCD}" = LWS Gallery
    "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
    "{71E66D3F-A009-44AB-8784-75E2819BA4BA}" = LWS Motion Detection
    "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
    "{79DD56FC-DB8B-47F5-9C80-78B62E05F9BC}" = Acer ScreenSaver
    "{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110111700}" = Zuma Deluxe
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110113233}" = Bookworm Deluxe
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11029123}" = Bricks of Egypt
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110322783}" = Big Kahuna Reef
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110411970}" = Chuzzle
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111118433}" = Mystery Case Files - Huntsville
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111199750}" = Cake Mania
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111252743}" = Mahjong Escape Ancient China
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111324990}" = Kick N Rush
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111543617}" = Backspin Billiards
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111692950}" = Mahjongg Artifacts
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111771833}" = Jewel Quest Solitaire
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111796363}" = Mystery Solitaire - Secret Island
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111872660}" = Diner Dash Flo on the Go
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112310577}" = Flip Words 2
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112531267}" = Chicken Invaders 3
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112615863}" = Agatha Christie Death on the Nile
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112920767}" = Alice Greenfingers
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113009953}" = Turbo Pizza
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113080210}" = Azada
    "{83C8FA3C-F4EA-46C4-8392-D3CE353738D6}" = LWS Launcher
    "{8937D274-C281-42E4-8CDB-A0B2DF979189}" = LWS Webcam Software
    "{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
    "{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
    "{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
    "{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
    "{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
    "{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    "{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
    "{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    "{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
    "{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
    "{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
    "{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
    "{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
    "{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel(R) Matrix Storage Manager
    "{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
    "{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
    "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
    "{9DAEA76B-E50F-4272-A595-0124E826553D}" = LWS WLM Plugin
    "{A5633652-3795-4829-BB0B-644F0279E279}" = Acer eDataSecurity Management
    "{A83279FD-CA4B-4206-9535-90974DE76654}" = Apple Application Support
    "{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.6
    "{AB6097D9-D722-4987-BD9E-A076E2848EE2}" = Acer Empowering Technology
    "{AC76BA86-7AD7-1033-7B44-A81000000003}" = Adobe Reader 8.1.0
    "{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
    "{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = PowerProducer
    "{BF839132-BD43-4056-ACBF-4377F4A88E2A}" = Acer ePresentation Management
    "{C06554A1-2C1E-4D20-B613-EE62C79927CC}" = Acer eNet Management
    "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
    "{CE386A4E-D0DA-4208-8235-BCE43275C694}" = LightScribe 1.4.142.1
    "{CE65A9A0-9686-45C6-9098-3C9543A412F0}" = Acer eSettings Management
    "{D40EB009-0499-459c-A8AF-C9C110766215}" = Logitech Webcam Software
    "{EED027B7-0DB6-404B-8F45-6DFEE34A0441}" = LWS Video Mask Maker
    "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
    "{FC57FC53-104C-415C-98D7-B05E659461A9}" = Broadcom Gigabit Integrated Controller
    "{FF167195-9EE4-46C0-8CD7-FBA3457E88AB}" = LWS Facebook
    "Acer Assist" = Acer Assist
    "Acer Registration" = Acer Registration
    "Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
    "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
    "Agere Systems Soft Modem" = Agere Systems HDA Modem
    "ARO 2011_is1" = ARO 2011
    "Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
    "GridVista" = Acer GridVista
    "HDMI" = Intel(R) Graphics Media Accelerator Driver
    "HOMESTUDENTR" = Microsoft Office Home and Student 2007
    "InstallShield_{1577A05B-EE62-4BBC-9DB7-FE748FA44EC2}" = NTI CD & DVD-Maker
    "InstallShield_{1598034D-7147-432C-8CA8-888E0632D124}" = NTI Backup NOW! 4.7
    "LManager" = Launch Manager
    "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
    "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
    "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
    "Revo Uninstaller" = Revo Uninstaller 1.93
    "SynTPDeinstKey" = Synaptics Pointing Device Driver
    "YTdetect" = Yahoo! Detect

    ========== Last 10 Event Log Errors ==========

    [ Application Events ]
    Error - 11/15/2011 10:23:05 AM | Computer Name = JanicePC | Source = Windows Search Service | ID = 3013
    Description =

    Error - 11/15/2011 10:23:05 AM | Computer Name = JanicePC | Source = Windows Search Service | ID = 3013
    Description =

    Error - 11/15/2011 10:23:05 AM | Computer Name = JanicePC | Source = Windows Search Service | ID = 3013
    Description =

    Error - 11/15/2011 10:23:05 AM | Computer Name = JanicePC | Source = Windows Search Service | ID = 3013
    Description =

    Error - 11/16/2011 12:10:30 AM | Computer Name = JanicePC | Source = WinMgmt | ID = 10
    Description =

    Error - 11/16/2011 11:09:55 AM | Computer Name = JanicePC | Source = WinMgmt | ID = 10
    Description =

    Error - 11/16/2011 10:09:03 PM | Computer Name = JanicePC | Source = WinMgmt | ID = 10
    Description =

    Error - 11/17/2011 12:58:46 AM | Computer Name = JanicePC | Source = WinMgmt | ID = 10
    Description =

    Error - 11/17/2011 12:12:42 PM | Computer Name = JanicePC | Source = WinMgmt | ID = 10
    Description =

    Error - 11/17/2011 8:46:36 PM | Computer Name = JanicePC | Source = WinMgmt | ID = 10
    Description =

    [ System Events ]
    Error - 8/9/2011 8:19:54 AM | Computer Name = JanicePC | Source = Service Control Manager | ID = 7000
    Description =

    Error - 8/9/2011 8:41:27 AM | Computer Name = JanicePC | Source = ACPI | ID = 327693
    Description = : The embedded controller (EC) did not respond within the specified
    timeout period. This may indicate that there is an error in the EC hardware or
    firmware or that the BIOS is accessing the EC incorrectly. You should check with
    your computer manufacturer for an upgraded BIOS. In some situations, this error
    may cause the computer to function incorrectly.

    Error - 8/9/2011 8:42:45 AM | Computer Name = JanicePC | Source = Service Control Manager | ID = 7000
    Description =

    Error - 8/9/2011 9:08:00 AM | Computer Name = JanicePC | Source = Service Control Manager | ID = 7000
    Description =

    Error - 8/9/2011 9:08:30 PM | Computer Name = JanicePC | Source = Service Control Manager | ID = 7000
    Description =

    Error - 8/10/2011 7:57:33 AM | Computer Name = JanicePC | Source = Service Control Manager | ID = 7000
    Description =

    Error - 8/10/2011 7:57:58 AM | Computer Name = JanicePC | Source = Server | ID = 2505
    Description = The server could not bind to the transport \Device\NetBT_Tcpip_{82447EF1-0445-4ED3-8CE1-220AFC8E058D}
    because another computer on the network has the same name. The server could not
    start.

    Error - 8/10/2011 7:57:58 AM | Computer Name = JanicePC | Source = netbt | ID = 4321
    Description = The name "JANICEPC :20" could not be registered on the interface
    with IP address 0.0.0.0. The computer with the IP address 192.168.1.2 did not allow
    the name to be claimed by this computer.

    Error - 8/10/2011 8:26:49 AM | Computer Name = JanicePC | Source = Service Control Manager | ID = 7000
    Description =

    Error - 8/10/2011 9:19:38 PM | Computer Name = JanicePC | Source = Service Control Manager | ID = 7000
    Description =


    < End of report >
     
  10. CarolsSis

    CarolsSis Registered Members

    Joined:
    Aug 28, 2011
    Messages:
    206
    Location:
    home
    Operating System:
    Windows Vista Enterprise
    OTL Extras logfile created on: 11/22/2011 6:55:44 PM - Run 1
    OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Janice\Downloads
    Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
    Internet Explorer (Version = 9.0.8112.16421)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    1.99 Gb Total Physical Memory | 1.11 Gb Available Physical Memory | 55.90% Memory free
    4.22 Gb Paging File | 2.94 Gb Available in Paging File | 69.65% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
    Drive C: | 51.14 Gb Total Space | 20.12 Gb Free Space | 39.33% Space Free | Partition Type: NTFS
    Drive D: | 50.89 Gb Total Space | 42.97 Gb Free Space | 84.45% Space Free | Partition Type: NTFS

    Computer Name: JANICEPC | User Name: Janice | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: Current user
    Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

    ========== Extra Registry (SafeList) ==========


    ========== File Associations ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
    .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
    .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)

    ========== Shell Spawning ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [open] -- "%1" %*
    cmdfile [open] -- "%1" %*
    comfile [open] -- "%1" %*
    cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
    exefile [open] -- "%1" %*
    helpfile [open] -- Reg Error: Key error.
    hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
    inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
    piffile [open] -- "%1" %*
    regfile [merge] -- Reg Error: Key error.
    scrfile [config] -- "%1"
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
    scrfile [open] -- "%1" /S
    txtfile [edit] -- Reg Error: Key error.
    Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
    Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
    Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    ========== Security Center Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    "cval" = 1

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiSpyware]
    "DisableMonitoring" = 1

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
    "AntiVirusOverride" = 0
    "AntiSpywareOverride" = 0
    "FirewallOverride" = 0
    "VistaSp1" = Reg Error: Unknown registry data type -- File not found
    "VistaSp2" = Reg Error: Unknown registry data type -- File not found

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

    ========== Firewall Settings ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
    "EnableFirewall" = 1
    "DisableNotifications" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
    "EnableFirewall" = 1
    "DisableNotifications" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
    "EnableFirewall" = 1
    "DisableNotifications" = 0

    ========== Authorized Applications List ==========


    ========== Vista Active Open Ports Exception List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{05EEB18B-D5B9-4828-BE54-9A4E4E016A4F}" = lport=1701 | protocol=17 | dir=in | app=system |
    "{0B8F0C6F-56F6-4FE6-BC88-27AD2997B48E}" = rport=1723 | protocol=6 | dir=out | app=system |
    "{17DC5873-2E73-4C6C-9C7A-AFDDE31504F4}" = rport=139 | protocol=6 | dir=out | app=system |
    "{187351CB-2F50-4337-ACFB-7C2D6162B7B5}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
    "{1D5F956D-E319-4CA6-A1E3-3B1B42945541}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
    "{2D1A4471-4F30-489A-A37F-F8502AE75CE9}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
    "{2F3D7327-6E53-45C2-9D36-1D286F9B338C}" = rport=1701 | protocol=17 | dir=out | app=system |
    "{3893ADD0-E11A-4EB6-9420-6C4E237C6366}" = lport=445 | protocol=6 | dir=in | app=system |
    "{4FADB3B7-539F-4F48-90E5-381516555347}" = lport=139 | protocol=6 | dir=in | app=system |
    "{569B0D6B-D46A-4907-BB53-FB36327C25D7}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
    "{5BA89CCD-308F-4677-AC16-F348205D9596}" = lport=137 | protocol=17 | dir=in | app=system |
    "{74696714-4756-40E1-A3A7-BAA2AB7EE1BA}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=file and printer sharing (spooler service - rpc-epmap) |
    "{7F13A3EA-798B-46FF-AF6C-9FF52F146708}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=c:\windows\system32\svchost.exe |
    "{8BB4A480-1583-4303-9538-698687D2BB2D}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=c:\windows\system32\spoolsv.exe |
    "{901C8821-5AA1-4661-9AA4-FE52812DE6DC}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=c:\windows\system32\svchost.exe |
    "{90605990-BE44-4369-8559-8C6E79A7EE66}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=c:\windows\system32\svchost.exe |
    "{987B535F-1079-4E59-8127-6811161A704A}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=c:\windows\system32\svchost.exe |
    "{B6461911-74F0-4B30-9C2C-436F4071A036}" = lport=1723 | protocol=6 | dir=in | app=system |
    "{BCEFE1CE-1E49-4975-BB07-92D1CD11CD05}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=c:\windows\system32\svchost.exe |
    "{C9F9383B-D725-4712-A896-A1BAABF77AFF}" = rport=445 | protocol=6 | dir=out | app=system |
    "{D1951F89-0D45-4228-AABF-42EDE08BE6BA}" = rport=137 | protocol=17 | dir=out | app=system |
    "{DCE15236-4EC6-47F1-B754-C72ED4C845E7}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=c:\windows\system32\svchost.exe |
    "{F5F02FEF-7858-430A-A3BC-1424EA7F83C8}" = rport=138 | protocol=17 | dir=out | app=system |
    "{F99BFD93-7359-4526-8ED9-84263671A2A5}" = lport=2869 | protocol=6 | dir=in | app=system |
    "{FF1084F7-9740-4697-8888-3AD3E5D01E58}" = lport=138 | protocol=17 | dir=in | app=system |

    ========== Vista Active Application Exception List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{136ECDCB-354B-45CF-B74F-1CD2532D6501}" = protocol=1 | dir=out | name=file and printer sharing (echo request - icmpv4-out) |
    "{585B3550-FEE7-4183-8F73-C4F66DE696B5}" = dir=in | app=c:\program files\acer arcade deluxe\homemedia\homemedia.exe |
    "{6DDEF72E-B18E-4055-B96D-2C793EEAA9FD}" = protocol=6 | dir=out | app=system |
    "{770DE421-4C82-4B08-9FF5-9F44E4A8D86A}" = protocol=58 | dir=out | name=file and printer sharing (echo request - icmpv6-out) |
    "{801AF5B7-7467-49A7-A7C9-9A6216D0B77A}" = protocol=6 | dir=out | svc=upnphost | app=c:\windows\system32\svchost.exe |
    "{C3C63ABA-30D4-4EA9-B23F-568596848C65}" = protocol=6 | dir=out | svc=upnphost | app=c:\windows\system32\svchost.exe |
    "{C9B6218B-4A64-4511-AB51-E77C507D7359}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{CC3EF2CA-B664-44D3-8609-B9B9D76C9741}" = protocol=6 | dir=out | app=c:\windows\system32\wudfhost.exe |
    "{D2E3A7D5-1887-4379-9F8C-A93BB552975F}" = protocol=1 | dir=in | name=file and printer sharing (echo request - icmpv4-in) |
    "{DF2D1B8F-EE18-4751-A35C-A75DA8FC87C3}" = protocol=58 | dir=in | name=file and printer sharing (echo request - icmpv6-in) |
    "{E06EC9EA-32B8-4FEA-9D87-CA7111A5507D}" = dir=in | app=c:\program files\acer arcade deluxe\videomagician\videomagician.exe |
    "{E2554D85-7AED-4FDA-BA26-3A055BD6A5C3}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe |
    "{E82E77A9-2EAB-40F9-9A5C-C543B020A4D8}" = dir=in | app=c:\program files\acer arcade deluxe\acer arcade deluxe\acer arcade deluxe.exe |
    "TCP Query User{070F9828-AFB3-43B9-A035-6846EAAE95A9}C:\program files\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
    "TCP Query User{7958372C-E496-412F-B870-2A7413EA78FB}C:\program files\logitech\vid hd\vid.exe" = protocol=6 | dir=in | app=c:\program files\logitech\vid hd\vid.exe |
    "TCP Query User{BDEEE42F-CC80-4568-8F5D-479526768BEE}C:\program files\logitech\vid hd\vid.exe" = protocol=6 | dir=in | app=c:\program files\logitech\vid hd\vid.exe |
    "UDP Query User{7E1B4235-B5F0-48F2-B5AE-728F41B09904}C:\program files\logitech\vid hd\vid.exe" = protocol=17 | dir=in | app=c:\program files\logitech\vid hd\vid.exe |
    "UDP Query User{CA4311D2-2C7E-4422-A91B-5CD727967B28}C:\program files\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
    "UDP Query User{ECCCF5FD-EE36-43DE-8E39-5F08F2D6A83C}C:\program files\logitech\vid hd\vid.exe" = protocol=17 | dir=in | app=c:\program files\logitech\vid hd\vid.exe |

    ========== HKEY_LOCAL_MACHINE Uninstall List ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{08610298-29AE-445B-B37D-EFBE05802967}" = LWS Pictures And Video
    "{0BF78E88-A7C9-4406-89CF-0BA473BA7821}" = Orion
    "{11316260-6666-467B-AC34-183FCB5D4335}" = Acer Mobility Center Plug-In
    "{116FF17B-1A30-4FC2-9B01-5BC5BD46B0B3}" = Acer eLock Management
    "{138A4072-9E64-46BD-B5F9-DB2BB395391F}" = LWS VideoEffects
    "{15634701-BACE-4449-8B25-1567DA8C9FD3}" = CameraHelperMsi
    "{1577A05B-EE62-4BBC-9DB7-FE748FA44EC2}" = NTI CD & DVD-Maker
    "{1598034D-7147-432C-8CA8-888E0632D124}" = NTI Backup NOW! 4.7
    "{1651216E-E7AD-4250-92A1-FB8ED61391C9}" = LWS Help_main
    "{174A3B31-4C43-43DD-866F-73C9DB887B48}" = LWS Twitter
    "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    "{21DF0294-6B9D-4741-AB6F-B2ABFBD2387E}" = LWS YouTube Plugin
    "{26A24AE4-039D-4CA4-87B4-2F83216026FF}" = Java(TM) 6 Update 29
    "{2D87E961-577B-492B-AD54-1368680FB9A7}" = Bing Maps 3D
    "{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
    "{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = erLT
    "{427967BF-09F8-46D5-9275-37001CCBBA5D}" = Winbond CIR Drivers
    "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
    "{58E5844B-7CE2-413D-83D1-99294BF6C74F}" = Acer ePower Management
    "{59F6A514-9813-47A3-948C-8A155460CC2A}" = RICOH R5C83x/84x Flash Media Controller Driver Ver.3.52.02
    "{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
    "{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
    "{6F76EC3C-34B1-436E-97FB-48C58D7BEDCD}" = LWS Gallery
    "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
    "{71E66D3F-A009-44AB-8784-75E2819BA4BA}" = LWS Motion Detection
    "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
    "{79DD56FC-DB8B-47F5-9C80-78B62E05F9BC}" = Acer ScreenSaver
    "{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110111700}" = Zuma Deluxe
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110113233}" = Bookworm Deluxe
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11029123}" = Bricks of Egypt
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110322783}" = Big Kahuna Reef
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110411970}" = Chuzzle
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111118433}" = Mystery Case Files - Huntsville
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111199750}" = Cake Mania
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111252743}" = Mahjong Escape Ancient China
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111324990}" = Kick N Rush
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111543617}" = Backspin Billiards
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111692950}" = Mahjongg Artifacts
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111771833}" = Jewel Quest Solitaire
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111796363}" = Mystery Solitaire - Secret Island
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111872660}" = Diner Dash Flo on the Go
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112310577}" = Flip Words 2
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112531267}" = Chicken Invaders 3
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112615863}" = Agatha Christie Death on the Nile
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112920767}" = Alice Greenfingers
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113009953}" = Turbo Pizza
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113080210}" = Azada
    "{83C8FA3C-F4EA-46C4-8392-D3CE353738D6}" = LWS Launcher
    "{8937D274-C281-42E4-8CDB-A0B2DF979189}" = LWS Webcam Software
    "{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
    "{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
    "{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
    "{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
    "{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
    "{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    "{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
    "{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    "{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
    "{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
    "{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
    "{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
    "{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
    "{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel(R) Matrix Storage Manager
    "{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
    "{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
    "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
    "{9DAEA76B-E50F-4272-A595-0124E826553D}" = LWS WLM Plugin
    "{A5633652-3795-4829-BB0B-644F0279E279}" = Acer eDataSecurity Management
    "{A83279FD-CA4B-4206-9535-90974DE76654}" = Apple Application Support
    "{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.6
    "{AB6097D9-D722-4987-BD9E-A076E2848EE2}" = Acer Empowering Technology
    "{AC76BA86-7AD7-1033-7B44-A81000000003}" = Adobe Reader 8.1.0
    "{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
    "{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = PowerProducer
    "{BF839132-BD43-4056-ACBF-4377F4A88E2A}" = Acer ePresentation Management
    "{C06554A1-2C1E-4D20-B613-EE62C79927CC}" = Acer eNet Management
    "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
    "{CE386A4E-D0DA-4208-8235-BCE43275C694}" = LightScribe 1.4.142.1
    "{CE65A9A0-9686-45C6-9098-3C9543A412F0}" = Acer eSettings Management
    "{D40EB009-0499-459c-A8AF-C9C110766215}" = Logitech Webcam Software
    "{EED027B7-0DB6-404B-8F45-6DFEE34A0441}" = LWS Video Mask Maker
    "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
    "{FC57FC53-104C-415C-98D7-B05E659461A9}" = Broadcom Gigabit Integrated Controller
    "{FF167195-9EE4-46C0-8CD7-FBA3457E88AB}" = LWS Facebook
    "Acer Assist" = Acer Assist
    "Acer Registration" = Acer Registration
    "Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
    "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
    "Agere Systems Soft Modem" = Agere Systems HDA Modem
    "ARO 2011_is1" = ARO 2011
    "Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
    "GridVista" = Acer GridVista
    "HDMI" = Intel(R) Graphics Media Accelerator Driver
    "HOMESTUDENTR" = Microsoft Office Home and Student 2007
    "InstallShield_{1577A05B-EE62-4BBC-9DB7-FE748FA44EC2}" = NTI CD & DVD-Maker
    "InstallShield_{1598034D-7147-432C-8CA8-888E0632D124}" = NTI Backup NOW! 4.7
    "LManager" = Launch Manager
    "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
    "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
    "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
    "Revo Uninstaller" = Revo Uninstaller 1.93
    "SynTPDeinstKey" = Synaptics Pointing Device Driver
    "YTdetect" = Yahoo! Detect

    ========== Last 10 Event Log Errors ==========

    [ Application Events ]
    Error - 11/15/2011 10:23:05 AM | Computer Name = JanicePC | Source = Windows Search Service | ID = 3013
    Description =

    Error - 11/15/2011 10:23:05 AM | Computer Name = JanicePC | Source = Windows Search Service | ID = 3013
    Description =

    Error - 11/15/2011 10:23:05 AM | Computer Name = JanicePC | Source = Windows Search Service | ID = 3013
    Description =

    Error - 11/15/2011 10:23:05 AM | Computer Name = JanicePC | Source = Windows Search Service | ID = 3013
    Description =

    Error - 11/16/2011 12:10:30 AM | Computer Name = JanicePC | Source = WinMgmt | ID = 10
    Description =

    Error - 11/16/2011 11:09:55 AM | Computer Name = JanicePC | Source = WinMgmt | ID = 10
    Description =

    Error - 11/16/2011 10:09:03 PM | Computer Name = JanicePC | Source = WinMgmt | ID = 10
    Description =

    Error - 11/17/2011 12:58:46 AM | Computer Name = JanicePC | Source = WinMgmt | ID = 10
    Description =

    Error - 11/17/2011 12:12:42 PM | Computer Name = JanicePC | Source = WinMgmt | ID = 10
    Description =

    Error - 11/17/2011 8:46:36 PM | Computer Name = JanicePC | Source = WinMgmt | ID = 10
    Description =

    [ System Events ]
    Error - 8/9/2011 8:19:54 AM | Computer Name = JanicePC | Source = Service Control Manager | ID = 7000
    Description =

    Error - 8/9/2011 8:41:27 AM | Computer Name = JanicePC | Source = ACPI | ID = 327693
    Description = : The embedded controller (EC) did not respond within the specified
    timeout period. This may indicate that there is an error in the EC hardware or
    firmware or that the BIOS is accessing the EC incorrectly. You should check with
    your computer manufacturer for an upgraded BIOS. In some situations, this error
    may cause the computer to function incorrectly.

    Error - 8/9/2011 8:42:45 AM | Computer Name = JanicePC | Source = Service Control Manager | ID = 7000
    Description =

    Error - 8/9/2011 9:08:00 AM | Computer Name = JanicePC | Source = Service Control Manager | ID = 7000
    Description =

    Error - 8/9/2011 9:08:30 PM | Computer Name = JanicePC | Source = Service Control Manager | ID = 7000
    Description =

    Error - 8/10/2011 7:57:33 AM | Computer Name = JanicePC | Source = Service Control Manager | ID = 7000
    Description =

    Error - 8/10/2011 7:57:58 AM | Computer Name = JanicePC | Source = Server | ID = 2505
    Description = The server could not bind to the transport \Device\NetBT_Tcpip_{82447EF1-0445-4ED3-8CE1-220AFC8E058D}
    because another computer on the network has the same name. The server could not
    start.

    Error - 8/10/2011 7:57:58 AM | Computer Name = JanicePC | Source = netbt | ID = 4321
    Description = The name "JANICEPC :20" could not be registered on the interface
    with IP address 0.0.0.0. The computer with the IP address 192.168.1.2 did not allow
    the name to be claimed by this computer.

    Error - 8/10/2011 8:26:49 AM | Computer Name = JanicePC | Source = Service Control Manager | ID = 7000
    Description =

    Error - 8/10/2011 9:19:38 PM | Computer Name = JanicePC | Source = Service Control Manager | ID = 7000
    Description =


    < End of report >
     
  11. starbuck

    starbuck Rest In Peace Pete Administrator

    Joined:
    Sep 26, 2009
    Messages:
    3,830
    Location:
    Midlands, UK
    Operating System:
    Windows 10
    CPU:
    AMD Athlon II x2 250 Processor 3.00GHz
    Memory:
    8gb DDR3
    Hard Drive:
    500gb SATA
    Graphics Card:
    ASUS GeForce GTX 960 2gb
    Power Supply:
    650w PowerCool X-Viper
    Hi CarolsSis

    Please look at what you are posting, this is still the Extras.txt.
    I really need the other report.

    Thanks
     
  12. CarolsSis

    CarolsSis Registered Members

    Joined:
    Aug 28, 2011
    Messages:
    206
    Location:
    home
    Operating System:
    Windows Vista Enterprise
    The txt. logs are both of the ones I have on my downloads page. I thought they looked the same, but posted anyway. I thought it was strange they had the same amount of KB. But the time stamp is 8 minutes different. There is one, like you said, "extras" and I posted it, went back found, OTL, and copied and pasted it also. If they are the same, I have no idea why, but note the difference in time. Now what? Have just double checked my downloads page, these are two of the 4 listed. The OTL also lists "screen saver" twice. It goes to open the program.
     
  13. starbuck

    starbuck Rest In Peace Pete Administrator

    Joined:
    Sep 26, 2009
    Messages:
    3,830
    Location:
    Midlands, UK
    Operating System:
    Windows 10
    CPU:
    AMD Athlon II x2 250 Processor 3.00GHz
    Memory:
    8gb DDR3
    Hard Drive:
    500gb SATA
    Graphics Card:
    ASUS GeForce GTX 960 2gb
    Power Supply:
    650w PowerCool X-Viper
    Ok, let's do this another way:

    Navigate to:
    C:\Users\Janice\Downloads

    The right click on the OTL.scr program.
    Now drag it to the Desktop. ( keeping the right mouse button held in)
    When you are at the Desktop, release the right mouse button.
    You will get a menu come up, select Move Here with the left mouse button.
    The OTL program will now be on your Desktop.
    Using this......

    Double click on OTL to run it.
    • Make sure the boxes next to 'LOP Check' and 'Purity Check' are ticked.
    • Click on Run Scan at the top left hand corner.
    • When done, only one Notepad file will open. Please post the contents of this Notepad file in your next reply.
    Note:
    As you have moved OTL to the Desktop, all the files will now be saved there as well. ( much easier to see)
     
  14. CarolsSis

    CarolsSis Registered Members

    Joined:
    Aug 28, 2011
    Messages:
    206
    Location:
    home
    Operating System:
    Windows Vista Enterprise
    OTL logfile created on: 11/25/2011 4:11:07 PM - Run 2
    OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Janice\Desktop
    Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
    Internet Explorer (Version = 9.0.8112.16421)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    1.99 Gb Total Physical Memory | 1.18 Gb Available Physical Memory | 59.25% Memory free
    4.22 Gb Paging File | 2.90 Gb Available in Paging File | 68.70% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
    Drive C: | 51.14 Gb Total Space | 19.93 Gb Free Space | 38.96% Space Free | Partition Type: NTFS
    Drive D: | 50.89 Gb Total Space | 42.97 Gb Free Space | 84.45% Space Free | Partition Type: NTFS

    Computer Name: JANICEPC | User Name: Janice | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: Current user
    Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

    ========== Processes (SafeList) ==========

    PRC - C:\Users\Janice\Desktop\OTL (1).scr (OldTimer Tools)
    PRC - C:\Windows\System32\Macromed\Flash\FlashUtil11e_ActiveX.exe (Adobe Systems, Inc.)
    PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
    PRC - C:\Users\Janice\AppData\Local\Temp\RtkBtMnt.exe (Realtek Semiconductor Corp.)
    PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH)
    PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
    PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
    PRC - C:\Windows\explorer.exe (Microsoft Corporation)
    PRC - C:\Acer\Empowering Technology\ePower\ePower_DMC.exe (Acer Inc.)
    PRC - C:\Windows\System32\iashost.exe (Microsoft Corporation)
    PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
    PRC - C:\Acer\Empowering Technology\Acer.Empowering.Framework.Supervisor.exe (Acer Inc.)
    PRC - C:\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe (Egis Incorporated)
    PRC - C:\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe (Egis Incorporated)
    PRC - C:\Program Files\Launch Manager\QtZgAcer.EXE (Dritek System Inc.)
    PRC - C:\Acer\Empowering Technology\eNet\eNet Service.exe (Acer Inc.)
    PRC - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe ()
    PRC - C:\Program Files\Synaptics\SynTP\SynTPStart.exe (Synaptics, Inc.)
    PRC - C:\Acer\Mobility Center\MobilityService.exe ()
    PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
    PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
    PRC - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe (Acer Inc.)
    PRC - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe (acer)
    PRC - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe (Acer Inc.)
    PRC - C:\Acer\Empowering Technology\eRecovery\eRAgent.exe (Acer Inc.)
    PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
    PRC - C:\Windows\System32\agrsmsvc.exe (Agere Systems)


    ========== Modules (No Company Name) ==========

    MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\6bc98e9b5eedaa8f71c5454d36a4b772\System.Management.ni.dll ()
    MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\8645de531003807d00822e03986a075d\System.ServiceProcess.ni.dll ()
    MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\e00630ec1e225a2376fdd430645e20f7\System.Web.ni.dll ()
    MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\6d2f689baff5da3df134fdec0742a13c\System.Runtime.Remoting.ni.dll ()
    MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\40da9084d0863e07d7ce55953833b8b0\System.Configuration.ni.dll ()
    MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\c1c06a392871267db27f7cbc40e1c4fb\System.Xml.ni.dll ()
    MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\1363115565fff5a641243a48f396f107\System.Windows.Forms.ni.dll ()
    MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\367c4043efc2f32d843cb588b0dc97fc\System.Drawing.ni.dll ()
    MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\f9c36ea806e77872dce891c77b68fac3\System.ni.dll ()
    MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\b6632a8b2f276a8e31f5b0f6b2006cd1\mscorlib.ni.dll ()
    MOD - C:\Acer\Empowering Technology\Acer.Empowering.Framework.DialogManager.dll ()
    MOD - C:\Acer\Empowering Technology\Acer.Empowering.Framework.PasswordSetting.dll ()
    MOD - C:\Acer\Empowering Technology\eDataSecurity\x86\ShowErrMsg.dll ()
    MOD - C:\Acer\Empowering Technology\eLock\eLockCTL.dll ()
    MOD - C:\Acer\Empowering Technology\eNet\eNetPlugin.dll ()
    MOD - C:\Acer\Empowering Technology\eSettings\eSettings.Plugin.dll ()
    MOD - C:\Acer\Empowering Technology\eSettings\eSettings.Presenter.dll ()
    MOD - C:\Acer\Empowering Technology\eSettings\eSettings.View.dll ()
    MOD - C:\Acer\Empowering Technology\eSettings.Model.ComputerInterfaces.dll ()
    MOD - C:\Acer\Empowering Technology\ePower\SysHook.dll ()
    MOD - C:\Acer\Empowering Technology\ePresentation\ePresentationCTL.dll ()
    MOD - C:\Acer\Empowering Technology\eRecovery\ServiceInterface.dll ()


    ========== Win32 Services (SafeList) ==========

    SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
    SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
    SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
    SRV - (eDataSecurity Service) -- C:\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe (Egis Incorporated)
    SRV - (eNet Service) -- C:\Acer\Empowering Technology\eNet\eNet Service.exe (Acer Inc.)
    SRV - (eSettingsService) -- C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe ()
    SRV - (MobilityService) -- C:\Acer\Mobility Center\MobilityService.exe ()
    SRV - (IAANTMON) Intel(R) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
    SRV - (eLockService) -- C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe (Acer Inc.)
    SRV - (WMIService) -- C:\Acer\Empowering Technology\ePower\ePowerSvc.exe (acer)
    SRV - (eRecoveryService) -- C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe (Acer Inc.)
    SRV - (AgereModemAudio) -- C:\Windows\System32\agrsmsvc.exe (Agere Systems)


    ========== Driver Services (SafeList) ==========

    DRV - (LVRS) -- C:\Windows\System32\drivers\lvrs.sys (Logitech Inc.)
    DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira GmbH)
    DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH)
    DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
    DRV - (athr) -- C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
    DRV - (rimmptsk) -- C:\Windows\System32\drivers\rimmptsk.sys (REDC)
    DRV - (rismxdp) -- C:\Windows\System32\drivers\rixdptsk.sys (REDC)
    DRV - (rimsptsk) -- C:\Windows\System32\drivers\rimsptsk.sys (REDC)
    DRV - (int15) -- C:\Acer\Empowering Technology\eRecovery\int15.sys (Acer, Inc.)
    DRV - (winbondcir) -- C:\Windows\System32\drivers\winbondcir.sys (Winbond Electronics Corporation)
    DRV - (AgereSoftModem) -- C:\Windows\System32\drivers\AGRSM.sys (Agere Systems)
    DRV - (ndiscm) -- C:\Windows\System32\drivers\NetMotCM.sys (Motorola Inc.)


    ========== Standard Registry (SafeList) ==========


    ========== Internet Explorer ==========

    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://en.us.acer.yahoo.com

    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.azstarnet.com/ [binary data]
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.usatoday.com/
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/VirtualEarth3D,version=4.0: C:\Program Files\Virtual Earth 3D\ [2011/10/30 12:12:29 | 000,000,000 | ---D | M]
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)



    O1 HOSTS File: ([2006/09/18 14:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
    O1 - Hosts: 127.0.0.1 localhost
    O1 - Hosts: ::1 localhost
    O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
    O3 - HKLM\..\Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - No CLSID value found.
    O3 - HKLM\..\Toolbar: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll (Egis Incorporated.)
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O3 - HKCU\..\Toolbar\ShellBrowser: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477E-A7DD-396DB0476E29} - C:\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll (Egis Incorporated.)
    O4 - HKLM..\Run: [Acer Assist Launcher] C:\Program Files\Acer\Acer Assist\launcher.exe ()
    O4 - HKLM..\Run: [Acer Product Registration] C:\Program Files\Acer\Acer Registration\ACE1.exe (Leader Technologies)
    O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
    O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
    O4 - HKLM..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe (Egis Incorporated)
    O4 - HKLM..\Run: [eRecoveryService] File not found
    O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe (Intel Corporation)
    O4 - HKLM..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE (Dritek System Inc.)
    O4 - HKLM..\Run: [LWS] C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.)
    O4 - HKLM..\Run: [Monitor] C:\Windows\PixArt\PAC207\Monitor.exe (PixArt Imaging Incorporation)
    O4 - HKLM..\Run: [PAC207_Monitor] C:\Windows\PixArt\PAC207\Monitor.exe (PixArt Imaging Incorporation)
    O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
    O4 - HKLM..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe (Synaptics, Inc.)
    O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
    O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
    O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
    O13 - gopher Prefix: missing
    O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/production/ieawsdc32.cab (Microsoft Office Template and Media Control)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
    O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{82447EF1-0445-4ED3-8CE1-220AFC8E058D}: DhcpNameServer = 192.168.1.1
    O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
    O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
    O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
    O24 - Desktop WallPaper: C:\Users\Janice\Pictures\pair of bobcats.jpg
    O24 - Desktop BackupWallPaper: C:\Users\Janice\Pictures\pair of bobcats.jpg
    O32 - HKLM CDRom: AutoRun - 1
    O32 - AutoRun File - [2006/09/18 14:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
    O34 - HKLM BootExecute: (autocheck autochk *)
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
    O37 - HKLM\...com [@ = comfile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*

    ========== Files/Folders - Created Within 30 Days ==========

    [2011/11/22 17:51:39 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\Janice\Desktop\OTL (1).scr
    [2011/11/20 19:40:35 | 000,000,000 | ---D | C] -- C:\Users\Janice\AppData\Roaming\Sammsoft
    [2011/11/20 19:37:21 | 000,000,000 | ---D | C] -- C:\Users\Janice\AppData\Roaming\Malwarebytes
    [2011/11/20 19:37:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
    [2011/11/20 19:37:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
    [2011/11/20 19:37:05 | 000,022,216 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
    [2011/11/20 19:37:05 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
    [2011/11/19 01:59:15 | 000,000,000 | ---D | C] -- C:\Program Files\VS Revo Group
    [2011/11/19 01:59:15 | 000,000,000 | ---D | C] -- C:\Users\Janice\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
    [2011/11/14 20:19:12 | 000,000,000 | ---D | C] -- C:\Program Files\Skype(40)
    [2011/11/10 18:38:13 | 000,000,000 | ---D | C] -- C:\Users\Janice\AppData\Roaming\Skype
    [2011/11/10 18:38:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
    [2011/11/10 18:38:01 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype
    [2011/11/10 18:37:59 | 000,000,000 | R--D | C] -- C:\Program Files\Skype
    [2011/11/10 18:37:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Skype
    [2011/10/30 17:10:46 | 000,000,000 | ---D | C] -- C:\Users\Janice\AppData\Roaming\Apple Computer
    [2011/10/30 13:05:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
    [2011/10/30 13:05:35 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
    [2011/10/30 13:05:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple Computer
    [2011/10/30 13:04:14 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Apple
    [2011/10/30 13:03:57 | 000,000,000 | ---D | C] -- C:\Users\Janice\AppData\Local\Apple
    [2011/10/30 13:03:55 | 000,000,000 | ---D | C] -- C:\Program Files\Apple Software Update
    [2011/10/30 13:03:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple
    [2011/10/30 12:12:49 | 000,000,000 | ---D | C] -- C:\Users\Janice\AppData\Local\IsolatedStorage
    [2011/10/30 12:12:15 | 000,000,000 | ---D | C] -- C:\Program Files\Virtual Earth 3D
    [2011/08/03 14:08:13 | 000,016,384 | ---- | C] ( ) -- C:\Windows\System32\ClearEvent.exe

    ========== Files - Modified Within 30 Days ==========

    [2011/11/25 15:45:20 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
    [2011/11/25 15:45:20 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
    [2011/11/25 13:45:19 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
    [2011/11/25 13:45:16 | 2137,448,448 | -HS- | M] () -- C:\hiberfil.sys
    [2011/11/23 09:07:56 | 000,001,110 | ---- | M] () -- C:\Users\Janice\Desktop\Get Live PC Help Now.lnk
    [2011/11/22 17:52:09 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Janice\Desktop\OTL (1).scr
    [2011/11/21 20:54:42 | 000,000,186 | ---- | M] () -- C:\Users\Janice\AppData\Roaming\wklnhst.dat
    [2011/11/21 20:53:43 | 000,005,632 | ---- | M] () -- C:\Users\Janice\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2011/11/19 01:59:16 | 000,001,061 | ---- | M] () -- C:\Users\Janice\Desktop\Revo Uninstaller.lnk
    [2011/11/16 19:10:28 | 000,414,368 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
    [2011/11/15 08:01:33 | 000,002,487 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk
    [2011/10/30 12:12:29 | 000,001,891 | ---- | M] () -- C:\Users\Public\Desktop\Bing Maps 3D.lnk

    ========== Files Created - No Company Name ==========

    [2011/11/23 09:07:56 | 000,001,110 | ---- | C] () -- C:\Users\Janice\Desktop\Get Live PC Help Now.lnk
    [2011/11/19 01:59:16 | 000,001,061 | ---- | C] () -- C:\Users\Janice\Desktop\Revo Uninstaller.lnk
    [2011/11/10 18:38:02 | 000,002,487 | ---- | C] () -- C:\Users\Public\Desktop\Skype.lnk
    [2011/10/30 13:03:56 | 000,001,830 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
    [2011/10/30 12:12:29 | 000,001,903 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bing Maps 3D.lnk
    [2011/10/30 12:12:29 | 000,001,891 | ---- | C] () -- C:\Users\Public\Desktop\Bing Maps 3D.lnk
    [2011/08/12 12:20:14 | 000,015,896 | ---- | C] () -- C:\Windows\System32\drivers\iKeyLFT2.dll
    [2011/08/06 17:44:46 | 000,005,632 | ---- | C] () -- C:\Users\Janice\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2011/08/05 15:35:15 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
    [2011/08/05 15:35:15 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
    [2011/08/04 13:10:30 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
    [2011/08/03 15:25:49 | 000,000,186 | ---- | C] () -- C:\Users\Janice\AppData\Roaming\wklnhst.dat
    [2011/08/03 14:43:26 | 000,000,030 | ---- | C] () -- C:\Windows\SETPANEL.INI
    [2011/08/03 14:43:23 | 000,000,092 | ---- | C] () -- C:\Windows\CLEANUP.INI
    [2011/08/03 14:08:13 | 000,016,384 | ---- | C] () -- C:\Windows\System32\LauncheRyAgentUser.exe
    [2011/07/25 23:48:54 | 000,028,418 | ---- | C] () -- C:\Windows\System32\lvcoinst.ini
    [2008/03/14 11:13:07 | 000,001,024 | RH-- | C] () -- C:\Windows\System32\NTIBUN4.dll
    [2008/03/13 23:25:59 | 000,015,656 | ---- | C] () -- C:\Windows\System32\drivers\int15_64.sys
    [2008/03/13 23:25:25 | 000,065,536 | ---- | C] () -- C:\Windows\System32\NATTraversal.dll
    [2008/03/13 22:48:06 | 000,001,132 | ---- | C] () -- C:\Windows\RtDefLvl.ini
    [2008/03/13 22:31:58 | 000,147,456 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1409.dll
    [2008/03/13 22:31:58 | 000,104,636 | ---- | C] () -- C:\Windows\System32\igmedcompkrn.dll
    [2008/03/13 22:31:57 | 001,953,696 | ---- | C] () -- C:\Windows\System32\igklg400.dll
    [2008/03/13 22:31:57 | 001,533,360 | ---- | C] () -- C:\Windows\System32\igklg450.dll
    [2008/03/13 22:31:33 | 001,060,424 | ---- | C] () -- C:\Windows\System32\WdfCoInstaller01000.dll
    [2008/03/13 22:12:57 | 000,000,120 | ---- | C] () -- C:\Windows\Alaunch.ini
    [2008/02/11 19:55:18 | 000,147,456 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1437.dll
    [2008/02/11 19:34:48 | 002,215,364 | ---- | C] () -- C:\Windows\System32\igklg400.bin
    [2008/02/11 19:34:48 | 001,971,732 | ---- | C] () -- C:\Windows\System32\igklg450.bin
    [2008/02/11 19:34:48 | 000,029,932 | ---- | C] () -- C:\Windows\System32\igmedcompkrn.bin
    [2006/11/02 05:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
    [2006/11/02 05:47:37 | 000,295,896 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
    [2006/11/02 05:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
    [2006/11/02 03:33:01 | 000,604,502 | ---- | C] () -- C:\Windows\System32\perfh009.dat
    [2006/11/02 03:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
    [2006/11/02 03:33:01 | 000,104,170 | ---- | C] () -- C:\Windows\System32\perfc009.dat
    [2006/11/02 03:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
    [2006/11/02 03:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
    [2006/11/02 01:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
    [2006/11/02 01:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
    [2006/11/02 00:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
    [2006/11/02 00:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
    [2001/12/26 15:12:30 | 000,065,536 | ---- | C] () -- C:\Windows\System32\multiplex_vcd.dll
    [2001/09/03 22:46:38 | 000,110,592 | ---- | C] () -- C:\Windows\System32\Hmpg12.dll
    [2001/07/30 15:33:56 | 000,118,784 | ---- | C] () -- C:\Windows\System32\HMPV2_ENC.dll
    [2001/07/23 21:04:36 | 000,118,784 | ---- | C] () -- C:\Windows\System32\HMPV2_ENC_MMX.dll

    ========== LOP Check ==========

    [2011/08/03 14:12:04 | 000,000,000 | ---D | M] -- C:\Users\Janice\AppData\Roaming\Acer
    [2008/03/13 23:21:06 | 000,000,000 | ---D | M] -- C:\Users\Janice\AppData\Roaming\Acer GameZone Console
    [2011/08/03 14:12:03 | 000,000,000 | ---D | M] -- C:\Users\Janice\AppData\Roaming\Leadertech
    [2011/11/24 18:32:50 | 000,000,000 | ---D | M] -- C:\Users\Janice\AppData\Roaming\Sammsoft
    [2011/08/03 15:25:50 | 000,000,000 | ---D | M] -- C:\Users\Janice\AppData\Roaming\Template
    [2011/11/25 11:45:16 | 000,032,650 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

    ========== Purity Check ==========


    < End of report >
     
  15. starbuck

    starbuck Rest In Peace Pete Administrator

    Joined:
    Sep 26, 2009
    Messages:
    3,830
    Location:
    Midlands, UK
    Operating System:
    Windows 10
    CPU:
    AMD Athlon II x2 250 Processor 3.00GHz
    Memory:
    8gb DDR3
    Hard Drive:
    500gb SATA
    Graphics Card:
    ASUS GeForce GTX 960 2gb
    Power Supply:
    650w PowerCool X-Viper
    Hi CarolsSis


    Step 1
    Double click on OTL to run it.
    Copy the lines in bold below. (make sure that :Otl is on the first line )


    :eek:tl
    DRV - (LVRS) -- C:\Windows\System32\drivers\lvrs.sys (Logitech Inc.)
    O3 - HKLM\..\Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O4 - HKLM..\Run: [eRecoveryService] File not found
    O4 - HKLM..\Run: [LWS] C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.)

    :Files
    C:\Program Files\Logitech
    ipconfig /flushdns /c

    :commands
    [emptytemp]
    [purity]
    [RESETHOSTS]

    • Return to OTL,
    • right click in the Custom Scans/Fixes window (under the blue bar) and choose Paste.

      .
    • Click the red Run Fix button.

      [​IMG]
    • OTL will reboot your system once the fix has completed.
    • After the reboot, you may need to double click OTL to launch the program and retrieve the log.

    Copy and paste the contents of the OTL log that comes up after the fix in your next reply.

    if you lose the report, there will be a copy here:
    C:\_OTL\MovedFiles


    Step 2
    I'd like you to do an ESET OnlineScan

    You may find it beneficial to close your resident AV program before running the scan.
    • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
      ESET OnlineScan
    • Click the [​IMG] button.
    • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
      • Click on [​IMG] to download the ESET Smart Installer.
        Save it to your desktop.
      • Double click on the [​IMG] icon on your desktop.
    • Check [​IMG]
    • Click the [​IMG] button.
    • Accept any security warnings from your browser.
    • Check [​IMG]
    • Click the Start button.
    • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    • When the scan completes, push [​IMG]
    • Click [​IMG], and save the file to your desktop using a unique name, such as ESETScan.
      Include the contents of this report in your next reply.
    • Click the [​IMG] button.
    • Click [​IMG]
    A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt


    Note:
    It's been found that on some systems the Eset's Online Scan fails during the database download ( around 20% )
    To prevent this happening:
    When the Computer scan settings display shows, click the Advanced option, the place a check next to the following (if it is not already checked):

    Enable Anti-Stealth technology

    [​IMG]


    Step 3
    If you want to try and reinstall the Webcam software now, do so.

    In your next reply, please submit:
    Otl fix report
    Eset scan report
    and let me know if you reinstalled the webcam software.


    Thanks.
     
    Last edited by a moderator: Feb 4, 2014
  16. CarolsSis

    CarolsSis Registered Members

    Joined:
    Aug 28, 2011
    Messages:
    206
    Location:
    home
    Operating System:
    Windows Vista Enterprise
    All processes killed
    ========== OTL ==========
    Error: No service named Logitech Inc. was found to stop!
    Service\Driver key Logitech Inc. not found.
    ========== FILES ==========
    C:\Program Files\Logitech\Vid HD(39)\translations folder moved successfully.
    C:\Program Files\Logitech\Vid HD(39)\sounds folder moved successfully.
    C:\Program Files\Logitech\Vid HD(39)\LU\Ukr folder moved successfully.
    C:\Program Files\Logitech\Vid HD(39)\LU\Trk folder moved successfully.
    C:\Program Files\Logitech\Vid HD(39)\LU\Sve folder moved successfully.
    C:\Program Files\Logitech\Vid HD(39)\LU\Srl folder moved successfully.
    C:\Program Files\Logitech\Vid HD(39)\LU\Slv folder moved successfully.
    C:\Program Files\Logitech\Vid HD(39)\LU\Sky folder moved successfully.
    C:\Program Files\Logitech\Vid HD(39)\LU\Rus folder moved successfully.
    C:\Program Files\Logitech\Vid HD(39)\LU\Rom folder moved successfully.
    C:\Program Files\Logitech\Vid HD(39)\LU\Ptg folder moved successfully.
    C:\Program Files\Logitech\Vid HD(39)\LU\Ptb folder moved successfully.
    C:\Program Files\Logitech\Vid HD(39)\LU\Plk folder moved successfully.
    C:\Program Files\Logitech\Vid HD(39)\LU\Nor folder moved successfully.
    C:\Program Files\Logitech\Vid HD(39)\LU\Nld folder moved successfully.
    C:\Program Files\Logitech\Vid HD(39)\LU\Lvi folder moved successfully.
    C:\Program Files\Logitech\Vid HD(39)\LU\Lth folder moved successfully.
    C:\Program Files\Logitech\Vid HD(39)\LU\Kor folder moved successfully.
    C:\Program Files\Logitech\Vid HD(39)\LU\Jpn folder moved successfully.
    C:\Program Files\Logitech\Vid HD(39)\LU\Ita folder moved successfully.
    C:\Program Files\Logitech\Vid HD(39)\LU\Hun folder moved successfully.
    C:\Program Files\Logitech\Vid HD(39)\LU\Hrv folder moved successfully.
    C:\Program Files\Logitech\Vid HD(39)\LU\Fra folder moved successfully.
    C:\Program Files\Logitech\Vid HD(39)\LU\Fin folder moved successfully.
    C:\Program Files\Logitech\Vid HD(39)\LU\Eti folder moved successfully.
    C:\Program Files\Logitech\Vid HD(39)\LU\Esp folder moved successfully.
    C:\Program Files\Logitech\Vid HD(39)\LU\Esm folder moved successfully.
    C:\Program Files\Logitech\Vid HD(39)\LU\Enu folder moved successfully.
    C:\Program Files\Logitech\Vid HD(39)\LU\Ell folder moved successfully.
    C:\Program Files\Logitech\Vid HD(39)\LU\Deu folder moved successfully.
    C:\Program Files\Logitech\Vid HD(39)\LU\Dan folder moved successfully.
    C:\Program Files\Logitech\Vid HD(39)\LU\Csy folder moved successfully.
    C:\Program Files\Logitech\Vid HD(39)\LU\Cht folder moved successfully.
    C:\Program Files\Logitech\Vid HD(39)\LU\Chs folder moved successfully.
    C:\Program Files\Logitech\Vid HD(39)\LU\Bgr folder moved successfully.
    C:\Program Files\Logitech\Vid HD(39)\LU folder moved successfully.
    C:\Program Files\Logitech\Vid HD(39)\images\lvc folder moved successfully.
    C:\Program Files\Logitech\Vid HD(39)\images folder moved successfully.
    C:\Program Files\Logitech\Vid HD(39) folder moved successfully.
    C:\Program Files\Logitech\LWS\Webcam Software(38) folder moved successfully.
    C:\Program Files\Logitech\LWS\Webcam Software\Microsoft.VC90.CRT folder moved successfully.
    C:\Program Files\Logitech\LWS\Webcam Software\ImageFormats\Microsoft.VC90.CRT folder moved successfully.
    C:\Program Files\Logitech\LWS\Webcam Software\ImageFormats folder moved successfully.
    C:\Program Files\Logitech\LWS\Webcam Software folder moved successfully.
    C:\Program Files\Logitech\LWS\Video Mask Maker(37) folder moved successfully.
    C:\Program Files\Logitech\LWS\Video Mask Maker folder moved successfully.
    C:\Program Files\Logitech\LWS\LU(36)\ukr folder moved successfully.
    C:\Program Files\Logitech\LWS\LU(36)\trk folder moved successfully.
    C:\Program Files\Logitech\LWS\LU(36)\sve folder moved successfully.
    C:\Program Files\Logitech\LWS\LU(36)\srl folder moved successfully.
    C:\Program Files\Logitech\LWS\LU(36)\slv folder moved successfully.
    C:\Program Files\Logitech\LWS\LU(36)\sky folder moved successfully.
    C:\Program Files\Logitech\LWS\LU(36)\rus folder moved successfully.
    C:\Program Files\Logitech\LWS\LU(36)\rom folder moved successfully.
    C:\Program Files\Logitech\LWS\LU(36)\ptg folder moved successfully.
    C:\Program Files\Logitech\LWS\LU(36)\ptb folder moved successfully.
    C:\Program Files\Logitech\LWS\LU(36)\plk folder moved successfully.
    C:\Program Files\Logitech\LWS\LU(36)\nor folder moved successfully.
    C:\Program Files\Logitech\LWS\LU(36)\nld folder moved successfully.
    C:\Program Files\Logitech\LWS\LU(36)\lvi folder moved successfully.
    C:\Program Files\Logitech\LWS\LU(36)\lth folder moved successfully.
    C:\Program Files\Logitech\LWS\LU(36)\kor folder moved successfully.
    C:\Program Files\Logitech\LWS\LU(36)\jpn folder moved successfully.
    C:\Program Files\Logitech\LWS\LU(36)\ita folder moved successfully.
    C:\Program Files\Logitech\LWS\LU(36)\hun folder moved successfully.
    C:\Program Files\Logitech\LWS\LU(36)\hrv folder moved successfully.
    C:\Program Files\Logitech\LWS\LU(36)\fra folder moved successfully.
    C:\Program Files\Logitech\LWS\LU(36)\fin folder moved successfully.
    C:\Program Files\Logitech\LWS\LU(36)\eti folder moved successfully.
    C:\Program Files\Logitech\LWS\LU(36)\esp folder moved successfully.
    C:\Program Files\Logitech\LWS\LU(36)\esm folder moved successfully.
    C:\Program Files\Logitech\LWS\LU(36)\enu folder moved successfully.
    C:\Program Files\Logitech\LWS\LU(36)\ell folder moved successfully.
    C:\Program Files\Logitech\LWS\LU(36)\deu folder moved successfully.
    C:\Program Files\Logitech\LWS\LU(36)\dan folder moved successfully.
    C:\Program Files\Logitech\LWS\LU(36)\csy folder moved successfully.
    C:\Program Files\Logitech\LWS\LU(36)\cht folder moved successfully.
    C:\Program Files\Logitech\LWS\LU(36)\chs folder moved successfully.
    C:\Program Files\Logitech\LWS\LU(36)\bgr folder moved successfully.
    C:\Program Files\Logitech\LWS\LU(36) folder moved successfully.
    C:\Program Files\Logitech\LWS\LU folder moved successfully.
    C:\Program Files\Logitech\LWS\LogiShrd\LWS\LU2.0 folder moved successfully.
    C:\Program Files\Logitech\LWS\LogiShrd\LWS\LU2(35).0\Ukr folder moved successfully.
    C:\Program Files\Logitech\LWS\LogiShrd\LWS\LU2(35).0\Trk folder moved successfully.
    C:\Program Files\Logitech\LWS\LogiShrd\LWS\LU2(35).0\Sve folder moved successfully.
    C:\Program Files\Logitech\LWS\LogiShrd\LWS\LU2(35).0\Srl folder moved successfully.
    C:\Program Files\Logitech\LWS\LogiShrd\LWS\LU2(35).0\Slv folder moved successfully.
    C:\Program Files\Logitech\LWS\LogiShrd\LWS\LU2(35).0\Sky folder moved successfully.
    C:\Program Files\Logitech\LWS\LogiShrd\LWS\LU2(35).0\Rus folder moved successfully.
    C:\Program Files\Logitech\LWS\LogiShrd\LWS\LU2(35).0\Rom folder moved successfully.
    C:\Program Files\Logitech\LWS\LogiShrd\LWS\LU2(35).0\Ptg folder moved successfully.
    C:\Program Files\Logitech\LWS\LogiShrd\LWS\LU2(35).0\Ptb folder moved successfully.
    C:\Program Files\Logitech\LWS\LogiShrd\LWS\LU2(35).0\Plk folder moved successfully.
    C:\Program Files\Logitech\LWS\LogiShrd\LWS\LU2(35).0\Nor folder moved successfully.
    C:\Program Files\Logitech\LWS\LogiShrd\LWS\LU2(35).0\Nld folder moved successfully.
    C:\Program Files\Logitech\LWS\LogiShrd\LWS\LU2(35).0\Lvi folder moved successfully.
    C:\Program Files\Logitech\LWS\LogiShrd\LWS\LU2(35).0\Lth folder moved successfully.
    C:\Program Files\Logitech\LWS\LogiShrd\LWS\LU2(35).0\Kor folder moved successfully.
    C:\Program Files\Logitech\LWS\LogiShrd\LWS\LU2(35).0\Ita folder moved successfully.
    C:\Program Files\Logitech\LWS\LogiShrd\LWS\LU2(35).0\Hun folder moved successfully.
    C:\Program Files\Logitech\LWS\LogiShrd\LWS\LU2(35).0\Hrv folder moved successfully.
    C:\Program Files\Logitech\LWS\LogiShrd\LWS\LU2(35).0\Fra folder moved successfully.
    C:\Program Files\Logitech\LWS\LogiShrd\LWS\LU2(35).0\Fin folder moved successfully.
    C:\Program Files\Logitech\LWS\LogiShrd\LWS\LU2(35).0\Eti folder moved successfully.
    C:\Program Files\Logitech\LWS\LogiShrd\LWS\LU2(35).0\Esp folder moved successfully.
    C:\Program Files\Logitech\LWS\LogiShrd\LWS\LU2(35).0\Esm folder moved successfully.
    C:\Program Files\Logitech\LWS\LogiShrd\LWS\LU2(35).0\Enu folder moved successfully.
    C:\Program Files\Logitech\LWS\LogiShrd\LWS\LU2(35).0\Ell folder moved successfully.
    C:\Program Files\Logitech\LWS\LogiShrd\LWS\LU2(35).0\Deu folder moved successfully.
    C:\Program Files\Logitech\LWS\LogiShrd\LWS\LU2(35).0\Dan folder moved successfully.
    C:\Program Files\Logitech\LWS\LogiShrd\LWS\LU2(35).0\Csy folder moved successfully.
    C:\Program Files\Logitech\LWS\LogiShrd\LWS\LU2(35).0\Cht folder moved successfully.
    C:\Program Files\Logitech\LWS\LogiShrd\LWS\LU2(35).0\Chs folder moved successfully.
    C:\Program Files\Logitech\LWS\LogiShrd\LWS\LU2(35).0\Bgr folder moved successfully.
    C:\Program Files\Logitech\LWS\LogiShrd\LWS\LU2(35).0 folder moved successfully.
    C:\Program Files\Logitech\LWS\LogiShrd\LWS folder moved successfully.
    C:\Program Files\Logitech\LWS\LogiShrd folder moved successfully.
    C:\Program Files\Logitech\LWS\Help folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\zh-TW\scripts\jquery\js folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\zh-TW\scripts\jquery folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\zh-TW\scripts folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\zh-TW folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\zh-CN\scripts\jquery\js folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\zh-CN\scripts\jquery folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\zh-CN\scripts folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\zh-CN folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\tr-TR\scripts\jquery\js folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\tr-TR\scripts\jquery folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\tr-TR\scripts folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\tr-TR folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\sv-SE\scripts\jquery\js folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\sv-SE\scripts\jquery folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\sv-SE\scripts folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\sv-SE folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\ru-RU\scripts\jquery\js folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\ru-RU\scripts\jquery folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\ru-RU\scripts folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\ru-RU folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\pt-BR\scripts\jquery\js folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\pt-BR\scripts\jquery folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\pt-BR\scripts folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\pt-BR folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\pl-PL\scripts\jquery\js folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\pl-PL\scripts\jquery folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\pl-PL\scripts folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\pl-PL folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\nl-NL\scripts\jquery\js folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\nl-NL\scripts\jquery folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\nl-NL\scripts folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\nl-NL folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\nb-NO\scripts\jquery\js folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\nb-NO\scripts\jquery folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\nb-NO\scripts folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\nb-NO folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\ko-KR\scripts\jquery\js folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\ko-KR\scripts\jquery folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\ko-KR\scripts folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\ko-KR folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\ja-JP\scripts\jquery\js folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\ja-JP\scripts\jquery folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\ja-JP\scripts folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\ja-JP folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\it-IT\scripts\jquery\js folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\it-IT\scripts\jquery folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\it-IT\scripts folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\it-IT folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\fr-FR\scripts\jquery\js folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\fr-FR\scripts\jquery folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\fr-FR\scripts folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\fr-FR folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\es-ES\scripts\jquery\js folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\es-ES\scripts\jquery folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\es-ES\scripts folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\es-ES folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\en-US\scripts\jquery\js folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\en-US\scripts\jquery folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\en-US\scripts folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\en-US folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\el-GR\scripts\jquery\js folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\el-GR\scripts\jquery folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\el-GR\scripts folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\el-GR folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\de-DE\scripts\jquery\js folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\de-DE\scripts\jquery folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\de-DE\scripts folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\de-DE folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\da-DK\scripts\jquery\js folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\da-DK\scripts\jquery folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\da-DK\scripts folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore\da-DK folder moved successfully.
    C:\Program Files\Logitech\LWS\GetMore folder moved successfully.
    C:\Program Files\Logitech\LWS folder moved successfully.
    C:\Program Files\Logitech\Ereg folder moved successfully.
    C:\Program Files\Logitech folder moved successfully.
    < ipconfig\flushdns/c >
    C:\Users\Janice\Desktop\cmd.bat deleted successfully.
    C:\Users\Janice\Desktop\cmd.txt deleted successfully.
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: All Users

    User: Default
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 33170 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: Janice
    ->Temp folder emptied: 204433693 bytes
    ->Temporary Internet Files folder emptied: 185375068 bytes
    ->Java cache emptied: 14390 bytes
    ->Flash cache emptied: 3154908 bytes

    User: Public

    User: William
    ->Temp folder emptied: 419806 bytes
    ->Temporary Internet Files folder emptied: 33170 bytes
    ->Flash cache emptied: 75 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 54514572 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
    RecycleBin emptied: 0 bytes

    Total Files Cleaned = 427.00 mb

    C:\Windows\System32\drivers\etc\Hosts moved successfully.
    HOSTS file reset successfully

    OTL by OldTimer - Version 3.2.31.0 log created on 11252011_184811
    Files\Folders moved on Reboot...
    C:\Users\Janice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\CZISFICD\page__st__20[4].htm moved successfully.
    C:\Users\Janice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\ED8654D5-B9F0-4DD9-B3E8-F8F560086FDF.dat moved successfully.
    C:\Users\Janice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\MSIMGSIZ.DAT moved successfully.
    Registry entries deleted on Reboot...
     
  17. CarolsSis

    CarolsSis Registered Members

    Joined:
    Aug 28, 2011
    Messages:
    206
    Location:
    home
    Operating System:
    Windows Vista Enterprise
    I ran the eset, however, I missed the end of your instructions to save the file. It found no Threats. Took 40 minutes to scan, scanned 106,040 files, and no infections. I don't have email for nephew and monitor closely his internet use. Hesitant to reinstall the Logitech software. Unless it was un-installed completely by fix from OTL. Thanks for your time and expertise, I really appreciate it. I checked the icon on desktop for Logitech webcam, I get pop up with header," Launcher_main.exe> Windows cannot find Launcher_main.exe. Make sure you typed the name correctly and try again. " I have Logitech Software in my downloads file. It is listed as LWS 230, application.
     
  18. BeeCeeBee

    BeeCeeBee ADMINISTRATOR IN MEMORY

    Joined:
    Apr 20, 2009
    Messages:
    7,201
    Location:
    New Jersey "Stronger than the Storm"
    Operating System:
    Windows 7
    This topic is being moved to the malware removal forum. For the benefit of members reading this that forum is reserved for the Member who posted the problem and the Malware Removal Team.
     
  19. CarolsSis

    CarolsSis Registered Members

    Joined:
    Aug 28, 2011
    Messages:
    206
    Location:
    home
    Operating System:
    Windows Vista Enterprise
  20. CarolsSis

    CarolsSis Registered Members

    Joined:
    Aug 28, 2011
    Messages:
    206
    Location:
    home
    Operating System:
    Windows Vista Enterprise
    Have downloaded ESet and run it three times. There is no list of threats found, so cannot export file to desktop. I made sure to tick boxes for Scan archive, enable anti-stealth technology, and on last 2, also ticked scan for potentially unsafe applications.
    Scan time, 3rd. try, 54:45 > files scanned, 110634 > infected files, 0. Yes, I did deactivate my antivirus program before running this, all 3 times. Thanks again for all your time and help.
     

Share This Page