Hi CookieGal,
Thank you for your ongoing help.
As per your instructions, I am pasting the OTS notepad logfile below. After that, I will be pasting the latest HJT logfile.
NEW NEWS: Two days ago, I received the following message while I was on my computer, but was offline. I don't know if the below will be a factor in your help to me:
"Media Foundation Protected Pipeline EXE was closed. To help protect your computer, Data Execution Prevention has closed." [end of new news]
==========================
[begin paste OTS logfile]
All Processes Killed
[Registry - Safe List]
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Brows er Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\ not found.
[Registry - Additional Scans - Safe List]
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\QlbCtrl hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ not found.
File not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Sharkbyte hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ not found.
File not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Windows Defender hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ not found.
File not found.
[Files/Folders - Created Within 30 Days]
C:\Windows\System32\drivers\~GLH0013.TMP deleted successfully.
[Files/Folders - Modified Within 30 Days]
C:\Users\Boltons\AppData\Local\Temp\469F5DBD.TMP deleted successfully.
C:\Users\Boltons\AppData\Local\Temp\CFG1FA0.tmp deleted successfully.
C:\Users\Boltons\AppData\Local\Temp\CFGDEAB.tmp deleted successfully.
C:\Users\Boltons\AppData\Local\Temp\CFGF517.tmp deleted successfully.
C:\Users\Boltons\AppData\Local\Temp\IEC341D.tmp deleted successfully.
C:\Users\Boltons\AppData\Local\Temp\nsb1BCA.tmp folder deleted successfully.
C:\Users\Boltons\AppData\Local\Temp\nsi34E9.tmp folder deleted successfully.
C:\Users\Boltons\AppData\Local\Temp\~DF210A.tmp deleted successfully.
C:\Users\Boltons\AppData\Local\Temp\~DF25CB.tmp deleted successfully.
C:\Users\Boltons\AppData\Local\Temp\~DF2F0B.tmp deleted successfully.
C:\Users\Boltons\AppData\Local\Temp\~DF3481.tmp deleted successfully.
C:\Users\Boltons\AppData\Local\Temp\~DF34E0.tmp deleted successfully.
C:\Users\Boltons\AppData\Local\Temp\~DF3A8A.tmp deleted successfully.
C:\Users\Boltons\AppData\Local\Temp\~DF3FF6.tmp deleted successfully.
C:\Users\Boltons\AppData\Local\Temp\~DF482F.tmp deleted successfully.
C:\Users\Boltons\AppData\Local\Temp\~DF4B74.tmp deleted successfully.
C:\Users\Boltons\AppData\Local\Temp\~DF4ED8.tmp deleted successfully.
C:\Users\Boltons\AppData\Local\Temp\~DF5F5D.tmp deleted successfully.
C:\Users\Boltons\AppData\Local\Temp\~DF624E.tmp deleted successfully.
C:\Users\Boltons\AppData\Local\Temp\~DF65E2.tmp deleted successfully.
C:\Users\Boltons\AppData\Local\Temp\~DF6AEF.tmp deleted successfully.
C:\Users\Boltons\AppData\Local\Temp\~DF7EDE.tmp deleted successfully.
C:\Users\Boltons\AppData\Local\Temp\~DF820F.tmp deleted successfully.
C:\Users\Boltons\AppData\Local\Temp\~DF8481.tmp deleted successfully.
C:\Users\Boltons\AppData\Local\Temp\~DF8974.tmp deleted successfully.
C:\Users\Boltons\AppData\Local\Temp\~DF89C4.tmp deleted successfully.
C:\Users\Boltons\AppData\Local\Temp\~DF8A94.tmp deleted successfully.
C:\Users\Boltons\AppData\Local\Temp\~DF8B18.tmp deleted successfully.
C:\Users\Boltons\AppData\Local\Temp\~DF8B4D.tmp deleted successfully.
C:\Users\Boltons\AppData\Local\Temp\~DF8B96.tmp deleted successfully.
C:\Users\Boltons\AppData\Local\Temp\~DF8C02.tmp deleted successfully.
C:\Users\Boltons\AppData\Local\Temp\~DF8C0F.tmp deleted successfully.
C:\Users\Boltons\AppData\Local\Temp\~DF8C58.tmp deleted successfully.
C:\Users\Boltons\AppData\Local\Temp\~DF8D0D.tmp deleted successfully.
C:\Users\Boltons\AppData\Local\Temp\~DF8DCB.tmp deleted successfully.
C:\Users\Boltons\AppData\Local\Temp\~DF8E6E.tmp deleted successfully.
C:\Users\Boltons\AppData\Local\Temp\~DF9010.tmp deleted successfully.
C:\Users\Boltons\AppData\Local\Temp\~DF9044.tmp deleted successfully.
C:\Users\Boltons\AppData\Local\Temp\~DF9078.tmp deleted successfully.
C:\Users\Boltons\AppData\Local\Temp\~DF9FAD.tmp deleted successfully.
C:\Users\Boltons\AppData\Local\Temp\~DFA39D.tmp deleted successfully.
C:\Users\Boltons\AppData\Local\Temp\~DFB7B7.tmp deleted successfully.
C:\Users\Boltons\AppData\Local\Temp\~DFD2DC.tmp deleted successfully.
C:\Users\Boltons\AppData\Local\Temp\~DFD2E1.tmp deleted successfully.
C:\Users\Boltons\AppData\Local\Temp\~DFDD91.tmp deleted successfully.
C:\Users\Boltons\AppData\Local\Temp\~DFE12C.tmp deleted successfully.
C:\Users\Boltons\AppData\Local\Temp\~DFE25A.tmp deleted successfully.
C:\Users\Boltons\AppData\Local\Temp\~DFE28F.tmp deleted successfully.
C:\Users\Boltons\AppData\Local\Temp\~DFE2D8.tmp deleted successfully.
C:\Users\Boltons\AppData\Local\Temp\~DFE321.tmp deleted successfully.
C:\Users\Boltons\AppData\Local\Temp\~DFED41.tmp deleted successfully.
C:\Users\Boltons\AppData\Local\Temp\~DFF17E.tmp deleted successfully.
C:\Users\Boltons\AppData\Local\Temp\~DFF2FE.tmp deleted successfully.
C:\Users\Boltons\AppData\Local\Temp\~DFF955.tmp deleted successfully.
[Empty Temp Folders]
User: All Users
User: Boltons
->Temp folder emptied: 10172358 bytes
->Temporary Internet Files folder emptied: 222696495 bytes
->Java cache emptied: 789626 bytes
->FireFox cache emptied: 80490761 bytes
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Public
User: Working Account
->Temp folder emptied: 279371 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Java cache emptied: 9393 bytes
->FireFox cache emptied: 70501780 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
Windows Temp folder emptied: 1459713 bytes
RecycleBin emptied: 17862939 bytes
Total Files Cleaned = 385.60 mb
< End of fix log >
OTS by OldTimer - Version 3.1.2.1 fix logfile created on 11042009_221035
Files\Folders moved on Reboot...
Registry entries deleted on Reboot...
[end OTS logfile]
========================================
[begin HJT logfile]
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:39:08 PM, on 11/4/2009
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16890)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\notepad.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\System32\rundll32.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Apoint2K\ApMsgFwd.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Users\Boltons\Documents\Computer Software Etc\Utilities\HijackTxhis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://ie.redirect.hp.com/svs/rdr?TY...lion&pf=laptop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about
:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 172.16.1.1:3128
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [cdloader] "C:\Users\Boltons\AppData\Roaming\mjusbsp\cdloader2.exe" MAGICJACK
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O15 - Trusted Zone: *.akamai.net
O15 - Trusted Zone: akamai.avg.com
O15 - Trusted Zone: update.avg.com
O15 - Trusted Zone: akamai.avg.cz
O15 - Trusted Zone: backup.avg.cz
O15 - Trusted Zone: download.avg.cz
O15 - Trusted Zone: files2.avg.cz
O15 - Trusted Zone: akamai.avg.com.edgesuite.net
O15 - Trusted Zone: akamai.avg.cz.edgesuite.net
O15 - Trusted Zone: akamai.grisoft.com.edgesuite.net
O15 - Trusted Zone: akamai.grisoft.cz.edgesuite.net
O15 - Trusted Zone: akamai.grisoft.com
O15 - Trusted Zone: update.grisoft.com
O15 - Trusted Zone: akamai.grisoft.cz
O15 - Trusted Zone: backup.grisoft.cz
O15 - Trusted Zone: download.grisoft.cz
O15 - Trusted Zone: files2.grisoft.cz
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe
O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: stllssvr - Unknown owner - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe (file missing)
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
--
End of file - 5677 bytes
[end HJT logfile]
Thanks again CookieGal............SeaSalt