This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Yoog infection

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Here is my HJT log. I've run all my spyware,( trend micro, spybot S&D, AVG free edition) and nothing comes up. I reset my mozilla under about:config but that didnt work. Ive unistalled mozilla and all my related files but with the same result. Now it's spread to my Internet Explorer.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:18:45 p.m., on 10/06/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18226)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\HP\Digital Imaging\bin\HpqSRmon.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\iTunes\iTunes.exe
C:\Program Files\Sophos\AutoUpdate\ALMon.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…rio&pf=cnnb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www28.yoog.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…rio&pf=cnnb
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…rio&pf=cnnb
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.student.otago.ac.nz:3128
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: bignetdaddy - {314506e6-db9d-d679-08b6-c16f288ad5c9} - C:\Windows\system32\nseE7A5.dll
O2 - BHO: Sophos Web Content Scanner - {39EA7695-B3F2-4C44-A4BC-297ADA8FD235} - C:\Program Files\Sophos\Sophos Anti-Virus\SophosBHO.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: AOL Toolbar BHO - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: bignetdaddy search enhancer - {AC4A7813-6844-2FF3-D929-DCB471E346AB} - C:\Windows\system32\pihtwcdtsghokinvg.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Warez] "C:\Program Files\Warez\Warez.exe" /minimized
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Global Startup: AutoUpdate Monitor.lnk = C:\Program Files\Sophos\AutoUpdate\ALMon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &AOL Toolbar Search - C:\ProgramData\AOL\ieToolbar\resources\en-NZ\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O13 - Gopher Prefix:
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL,avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Inkjet Printer/Scanner Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Recovery Service for Windows - Unknown owner - C:\Windows\SMINST\BLService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Sophos Anti-Virus status reporter (SAVAdminService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
O23 - Service: Sophos Anti-Virus (SAVService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: Sophos AutoUpdate Service - Sophos Plc - C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 11006 bytes
Hi AlcysaidElsy, :welcome:

My name is SpySentinel and I will be helping you with your malware problem.

You have an infection called Yoog Search:



Windows Defender
  • Open Windows Defender. [external image: Posted Image]
  • Click Tools, and then click General Settings.
  • Under Real-Time Protection options, uncheck the "Real-time protection" check box.
  • Click Save.
  • Go to Start > Control Panel > Security > Windows Defender, at the bottom of the Window Defenders page uncheck under Administrator Options "use Windows Defender" and then Save.
  • (Once you are clean, you can re-enable Windows Defender by placing a check next to "Turn on real-time protection".)


Spybot Search & Destroy TeaTimer
There are two ways to disable TeaTimer

1)
  • Launch Spybot Search & Destroy [external image: Posted Image]
  • In the Menu, Select Mode and choose Advanced Mode
  • Click Yes in the confirmation dialogue box
  • click on Tools to expand the menu. Make sure that Resident is checked and then click Resident in the left pane.
  • In the right pane uncheck Resident "Tea timer" (Protection of over-all system settings) to disable it.
  • Uncheck the TeaTimer box and OK any prompts.
  • If Teatimer gives you a warning that changes were made, click the "Allow Change" box when prompted.
  • Exit Spybot S&D when done.
  • (Once you are clean, you can re-enable Teatimer using the same steps but this time place a check next to "Resident TeaTimer" and check the "TeaTimer" box in System Startup.]

2)
  • Right click the TeaTimer icon in the system Tray [external image: Posted Image]
  • Then click Exit Spybot-S&D Resident
  • (One you are clean you can restart TeaTimer by going to C:\Program Files\Spybot - Search & Destroy, and double clicking on TeaTimer.exe



Before we begin, you should save these instructions in Notepad to your desktop, or print them, for easy reference. Much of our fix will be done in Safe mode, and you will be unable to access this thread at that time. If you have questions at any point, or are unsure of the instructions, feel free to post here and ask for clarification before proceeding.


You are using peer-to-peer programs, specifically LimeWire and Warez.
These are what we call an optional removal. However, anytime you are running any type of peer-to-peer application, you are more prone to infection by malware, and this is probably how you became infected in the first place. The choice to remove them is entirely up to you, but I would strongly recommend that you do.
If you do not want to, please at least refrain from using any peer-to-peer programs for the remainder of my fix.


Step #1

Please re-open HiJackThis and scan. Check the boxes next to all the entries listed below.

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www28.yoog.com/
O2 - BHO: bignetdaddy - {314506e6-db9d-d679-08b6-c16f288ad5c9} - C:\Windows\system32\nseE7A5.dll
O2 - BHO: bignetdaddy search enhancer - {AC4A7813-6844-2FF3-D929-DCB471E346AB} - C:\Windows\system32\pihtwcdtsghokinvg.dll

Now close all windows other than HiJackThis, then click Fix Checked. Close HiJackThis.

After that, Reboot


Step #2

Download Rooter.exe to your desktop
  • Then doubleclick it to start the tool
  • A Notepad file containing the report will open, also found at %systemdrive%\Rooter.txt. Post that here

Step #3

Please download Malwarebytes' Anti-Malware

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.


Step #4

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
you mention that under Spybot under the resident teatimer bit that i should Uncheck the TeaTimer box and OK any prompts, but i can't see any TeaTimer check box
Hi AlcysaidElsy,

Have you tried option #2?

2)
  • Right click the TeaTimer icon in the system Tray
  • Then click Exit Spybot-S&D Resident
  • (One you are clean you can restart TeaTimer by going to C:\Program Files\Spybot - Search & Destroy, and double clicking on TeaTimer.exe
I've tried looking in my system tray for the symbol. If i go to customise and check it as "show" it still doesnt come up in the tray
Hi AlcysaidElsy,

Please go ahead and uninstall Spybot Search & Destroy for now. I will have you install it again once you are clean.

Please go to Start > Control Panel > Add/Remove Programs and remove the following (if present):

Spybot Search & Destroy


Then continue with my other steps.
Here's the rooters report… Rooter.exe (v1.0) by Eric_71 ¨ Microsoft Windows Vista Home Edition (6.0.6001) Service Pack 1 32_bits - x86 Family 6 Model 15 Stepping 13, GenuineIntel ¨ C:\ [Fixed-NTFS] .. ( Total:143315 Mo - Free:78881 Mo ) D:\ [Fixed-NTFS] .. ( Total:9307 Mo - Free:1713 Mo ) E:\ [CD_Rom] ¨ Scan : 19:37.43 Path : C:\Users\Alex\Downloads\Rooter.exe User : Alex ( Administrator -> YES ) ¨ ———————-\\ Processes ¨ Locked [System Process] (0) Locked System (4) Locked smss.exe (420) Locked csrss.exe (552) Locked wininit.exe (596) Locked csrss.exe (608) Locked services.exe (652) Locked lsass.exe (664) Locked lsm.exe (672) Locked winlogon.exe (704) Locked svchost.exe (908) Locked svchost.exe (972) Locked svchost.exe (1120) Locked svchost.exe (1148) Locked svchost.exe (1176) Locked audiodg.exe (1288) Locked SLsvc.exe (1320) Locked svchost.exe (1368) Locked SavService.exe (1488) Locked svchost.exe (1856) ______ C:\Windows\system32\Dwm.exe (200) ______ C:\Windows\Explorer.EXE (208) Locked wlanext.exe (448) Locked spoolsv.exe (800) Locked svchost.exe (968) ______ C:\Windows\system32\taskeng.exe (1480) Locked taskeng.exe (1896) Locked AppleMobileDeviceService.exe (1432) Locked avgwdsvc.exe (1080) Locked BcmSqlStartupSvc.exe (2084) Locked mDNSResponder.exe (2136) ______ C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (2144) ______ C:\Windows\System32\igfxtray.exe (2156) ______ C:\Windows\System32\hkcmd.exe (2184) ______ C:\Windows\System32\igfxpers.exe (2216) ______ C:\Program Files\HP\QuickPlay\QPService.exe (2224) ______ C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe (2328) Locked ijplmsvc.exe (2360) ______ C:\Program Files\HP\Digital Imaging\bin\HpqSRmon.exe (2372) Locked avgrsx.exe (2412) Locked avgnsx.exe (2596) Locked svchost.exe (2748) ______ C:\Windows\system32\igfxsrvc.exe (2760) Locked BLService.exe (2924) ______ C:\Program Files\HP\HP Software Update\hpwuSchd2.exe (2932) Locked RichVideo.exe (3048) ______ C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe (3068) ______ C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe (3104) Locked SAVAdminService.exe (3188) Locked ALsvc.exe (3252) ______ C:\Program Files\iTunes\iTunesHelper.exe (3316) Locked sqlbrowser.exe (3344) Locked sqlwriter.exe (3376) Locked svchost.exe (3412) Locked svchost.exe (3448) Locked SearchIndexer.exe (3484) Locked XAudio.exe (3560) ______ C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE (3892) Locked hpqwmiex.exe (3940) Locked WmiPrvSE.exe (4024) ______ C:\Program Files\AVG\AVG8\avgtray.exe (4080) ______ C:\Program Files\Windows Sidebar\sidebar.exe (1252) ______ C:\Program Files\MSN Messenger\msnmsgr.exe (1228) ______ C:\Program Files\Windows Media Player\wmpnscfg.exe (2152) ______ C:\Program Files\Sophos\AutoUpdate\ALMon.exe (1056) ______ C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE (2244) Locked Com4QLBEx.exe (2644) ______ C:\Program Files\LimeWire\LimeWire.exe (2400) Locked wmpnetwk.exe (3092) Locked iPodService.exe (1636) ______ C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe (2168) ______ C:\Program Files\Windows Sidebar\sidebar.exe (4088) ______ C:\Windows\System32\mobsync.exe (940) Locked SynTPHelper.exe (4664) Locked HPHC_Service.exe (4928) ______ C:\Program Files\Mozilla Firefox\firefox.exe (5308) ______ C:\Windows\system32\wuauclt.exe (3496) ______ C:\Windows\system32\NOTEPAD.EXE (5192) ______ C:\Users\Alex\Downloads\Rooter.exe (2588) ¨ ———————-\\ Device\Harddisk0\ ¨ \Device\Harddisk0 [Sectors : 63 x 512 Bytes] ¨ \Device\Harddisk0\Partition1 –[ MBR ]– (Start_Offset:32256 | Length:150277685760) \Device\Harddisk0\Partition2 (Start_Offset:150277718016 | Length:9760145408) ¨ ———————-\\ Scheduled Tasks ¨ C:\Windows\Tasks\RegCure Program Check.job C:\Windows\Tasks\RegCure.job C:\Windows\Tasks\SA.DAT C:\Windows\Tasks\SCHEDLGU.TXT ¨ ———————-\\ Registry ¨ ¨ ———————-\\ Files & Folders ¨ ———————-\\ Scan completed at 19:37.53 ¨ C:\Rooter$\Rooter_2.txt - (13/06/2009 | 19:37.53) ¨ C:\Rooter$\Rooter_3.txt - (13/06/2009 | 19:38.07)
Heres the MBAM report Malwarebytes' Anti-Malware 1.37 Database version: 2182 Windows 6.0.6001 Service Pack 1 14/06/2009 4:10:30 p.m. mbam-log-2009-06-14 (16-10-30).txt Scan type: Quick Scan Objects scanned: 73955 Time elapsed: 15 minute(s), 49 second(s) Memory Processes Infected: 0 Memory Modules Infected: 1 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: C:\Program Files\Mozilla Firefox\components\660c8237-ec8c-eea3-278e-47902915e48c.dll (Adware.Yoog) -> Delete on reboot. Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: c:\program files\mozilla firefox\components\660c8237-ec8c-eea3-278e-47902915e48c.dll (Adware.Yoog) -> Delete on reboot.
Heres the OTL report

OTL logfile created on: 14/06/2009 4:39:30 p.m. - Run 1
OTL by OldTimer - Version 2.1.1.0 Folder = C:\Users\Alex\Downloads
Windows Vista Home Basic Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00001409 | Country: New Zealand | Language: ENZ | Date Format: d/MM/yyyy

1.93 Gb Total Physical Memory | 0.86 Gb Available Physical Memory | 44.32% Memory free
4.00 Gb Paging File | 2.91 Gb Available in Paging File | 72.68% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 139.96 Gb Total Space | 77.02 Gb Free Space | 55.03% Space Free | Partition Type: NTFS
Drive D: | 9.09 Gb Total Space | 1.67 Gb Free Space | 18.41% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: ALEX-PC
Current User Name: Alex
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe (Sophos Plc)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (Microsoft Corporation)
PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE ()
PRC - C:\Windows\SMINST\BLService.exe ()
PRC - C:\Program Files\CyberLink\Shared Files\RichVideo.exe ()
PRC - C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe (Sophos Plc)
PRC - C:\Program Files\Sophos\AutoUpdate\ALsvc.exe (Sophos Plc)
PRC - c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)
PRC - C:\Windows\Explorer.EXE (Microsoft Corporation)
PRC - C:\Windows\system32\DRIVERS\xaudio.exe (Conexant Systems, Inc.)
PRC - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
PRC - C:\Windows\System32\igfxtray.exe (Intel Corporation)
PRC - C:\Windows\System32\hkcmd.exe (Intel Corporation)
PRC - C:\Windows\System32\igfxpers.exe (Intel Corporation)
PRC - C:\Program Files\HP\QuickPlay\QPService.exe (CyberLink Corp.)
PRC - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe ( Hewlett-Packard Development Company, L.P.)
PRC - C:\Windows\system32\igfxsrvc.exe (Intel Corporation)
PRC - C:\Program Files\HP\Digital Imaging\bin\HpqSRmon.exe (Hewlett-Packard)
PRC - C:\Program Files\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard)
PRC - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE (CANON INC.)
PRC - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation)
PRC - C:\Windows\system32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\Program Files\MSN Messenger\msnmsgr.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
PRC - C:\Program Files\Sophos\AutoUpdate\ALMon.exe (Sophos Plc)
PRC - C:\Program Files\LimeWire\LimeWire.exe (Lime Wire, LLC)
PRC - C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
PRC - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe ()
PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation)
PRC - C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Synaptics, Inc.)
PRC - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe (Hewlett-Packard)
PRC - C:\Users\Alex\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Win32 Services (SafeList) ==========

SRV - (Apple Mobile Device [Auto | Running]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (avg8wd [Auto | Running]) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (BcmSqlStartupSvc [Auto | Running]) – C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (Microsoft Corporation)
SRV - (Bonjour Service [Auto | Running]) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (Com4QLBEx [On_Demand | Running]) – C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe (Hewlett-Packard Development Company, L.P.)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) – C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (GameConsoleService [On_Demand | Stopped]) – C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (HP Health Check Service [Auto | Running]) – c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe (Hewlett-Packard)
SRV - (hpqwmiex [On_Demand | Running]) – C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe (Hewlett-Packard Development Company, L.P.)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (idsvc [Unknown | Stopped]) – C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (IJPLMSVC [Auto | Running]) – C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE ()
SRV - (iPod Service [On_Demand | Running]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (MSSQL$MSSMLBIZ [On_Demand | Stopped]) – c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe (Microsoft Corporation)
SRV - (MSSQLServerADHelper [Disabled | Stopped]) – c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe (Microsoft Corporation)
SRV - (NetTcpPortSharing [Disabled | Stopped]) – C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (odserv [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (Recovery Service for Windows [Auto | Running]) – C:\Windows\SMINST\BLService.exe ()
SRV - (RichVideo [Auto | Running]) – C:\Program Files\CyberLink\Shared Files\RichVideo.exe ()
SRV - (SAVAdminService [Unknown | Running]) – C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe (Sophos Plc)
SRV - (SAVService [Unknown | Running]) – C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe (Sophos Plc)
SRV - (Sophos AutoUpdate Service [Auto | Running]) – C:\Program Files\Sophos\AutoUpdate\ALsvc.exe (Sophos Plc)
SRV - (SQLBrowser [Auto | Running]) – c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation)
SRV - (SQLWriter [Auto | Running]) – c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)
SRV - (usnjsvc [On_Demand | Stopped]) – C:\Program Files\MSN Messenger\usnsvc.exe (Microsoft Corporation)
SRV - (WinDefend [Auto | Stopped]) – C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SRV - (WMPNetworkSvc [On_Demand | Running]) – C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
SRV - (XAudioService [Auto | Running]) – C:\Windows\system32\DRIVERS\xaudio.exe (Conexant Systems, Inc.)

========== Driver Services (SafeList) ==========

DRV - (adp94xx [Boot | Running]) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (adpahci [Boot | Running]) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (adpu160m [Boot | Running]) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (adpu320 [Boot | Running]) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (aic78xx [Boot | Running]) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (aliide [Boot | Running]) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (arc [Boot | Running]) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (arcsas [Boot | Running]) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (athr [On_Demand | Running]) – C:\Windows\system32\DRIVERS\athr.sys (Atheros Communications, Inc.)
DRV - (AvgLdx86 [System | Running]) – C:\Windows\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86 [System | Running]) – C:\Windows\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgTdiX [System | Running]) – C:\Windows\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (BCM43XV [On_Demand | Stopped]) – C:\Windows\system32\DRIVERS\bcmwl6.sys (Broadcom Corporation)
DRV - (BrFiltLo [On_Demand | Stopped]) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrFiltUp [On_Demand | Stopped]) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (Brserid [On_Demand | Stopped]) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrSerWdm [On_Demand | Stopped]) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm [On_Demand | Stopped]) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (BrUsbSer [On_Demand | Stopped]) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (cmdide [Boot | Running]) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (CnxtHdAudService [On_Demand | Running]) – C:\Windows\system32\drivers\CHDRT32.sys (Conexant Systems Inc.)
DRV - (E1G60 [On_Demand | Stopped]) – C:\Windows\system32\DRIVERS\E1G60I32.sys (Intel Corporation)
DRV - (elxstor [Boot | Running]) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\Windows\system32\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (HpCISSs [Boot | Running]) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (HpqKbFiltr [On_Demand | Running]) – C:\Windows\system32\DRIVERS\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (HSFHWAZL [On_Demand | Stopped]) – C:\Windows\system32\DRIVERS\VSTAZL3.SYS (Conexant Systems, Inc.)
DRV - (HSF_DPV [On_Demand | Running]) – C:\Windows\system32\DRIVERS\HSX_DPV.sys (Conexant Systems, Inc.)
DRV - (HSXHWAZL [On_Demand | Running]) – C:\Windows\system32\DRIVERS\HSXHWAZL.sys (Conexant Systems, Inc.)
DRV - (iaStorV [Boot | Running]) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (igfx [On_Demand | Running]) – C:\Windows\system32\DRIVERS\igdkmd32.sys (Intel Corporation)
DRV - (iirsp [Boot | Running]) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (IntcHdmiAddService [On_Demand | Running]) – C:\Windows\system32\drivers\IntcHdmi.sys (Intel® Corporation)
DRV - (iteatapi [Boot | Running]) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (iteraid [Boot | Running]) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (LSI_FC [Boot | Running]) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (LSI_SAS [Boot | Running]) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (LSI_SCSI [Boot | Running]) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (mdmxsdk [Auto | Running]) – C:\Windows\system32\DRIVERS\mdmxsdk.sys (Conexant)
DRV - (megasas [Boot | Running]) – C:\Windows\system32\drivers\megasas.sys (LSI Corporation)
DRV - (MegaSR [Boot | Running]) – C:\Windows\system32\drivers\megasr.sys (LSI Corporation, Inc.)
DRV - (Mraid35x [Boot | Running]) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (nfrd960 [Boot | Running]) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (ntrigdigi [On_Demand | Stopped]) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (NVENETFD [On_Demand | Stopped]) – C:\Windows\system32\DRIVERS\nvm60x32.sys (NVIDIA Corporation)
DRV - (nvraid [Boot | Running]) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nvstor [Boot | Running]) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (ql2300 [Boot | Running]) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (ql40xx [Boot | Running]) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (RTL8169 [On_Demand | Running]) – C:\Windows\system32\DRIVERS\Rtlh86.sys (Realtek Corporation )
DRV - (RTSTOR [On_Demand | Running]) – C:\Windows\system32\drivers\RTSTOR.SYS (Realtek Semiconductor Corp.)
DRV - (SAVOnAccess [System | Running]) – C:\Windows\system32\DRIVERS\savonaccess.sys (Sophos Plc)
DRV - (secdrv [Auto | Running]) – C:\Windows\System32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (SiSRaid4 [Boot | Running]) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (SophosBootDriver [Disabled | Stopped]) – C:\Windows\system32\DRIVERS\SophosBootDriver.sys (Sophos Plc)
DRV - (Symc8xx [Boot | Running]) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (Sym_hi [Boot | Running]) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (Sym_u3 [Boot | Running]) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (SynTP [On_Demand | Running]) – C:\Windows\system32\DRIVERS\SynTP.sys (Synaptics, Inc.)
DRV - (uliahci [Boot | Running]) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (UlSata [Boot | Running]) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (ulsata2 [Boot | Running]) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (USBAAPL [On_Demand | Stopped]) – C:\Windows\System32\Drivers\usbaapl.sys (Apple, Inc.)
DRV - (viaide [Boot | Running]) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (vsmraid [Boot | Running]) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (winachsf [On_Demand | Running]) – C:\Windows\system32\DRIVERS\HSX_CNXT.sys (Conexant Systems, Inc.)
DRV - (XAudio [Auto | Running]) – C:\Windows\system32\DRIVERS\xaudio.sys (Conexant Systems, Inc.)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…rio&pf=cnnb
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…rio&pf=cnnb
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Local Page = http://start.warez.com/

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…rio&pf=cnnb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 2
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Yoog Search"
FF - prefs.js..browser.search.defaulturl: "http://www28.yoog.com/search.php?q="
FF - prefs.js..browser.search.selectedEngine: "Yoog Search"
FF - prefs.js..browser.startup.homepage: "http://www28.yoog.com/"
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:8.5
FF - prefs.js..extensions.enabledItems: {1d5287d1-8a92-0001-1f31-1cec198018d8}:[removed]
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.10
FF - prefs.js..keyword.URL: "http://www28.yoog.com/search.php?q="

FF - user.js..browser.startup.homepage: "http://www28.yoog.com/"
FF - user.js..browser.search.selectedEngine: "Yoog Search"
FF - user.js..keyword.URL: "http://www28.yoog.com/search.php?q="
FF - user.js..keyword.enabled: true
FF - user.js..browser.search.defaultenginename: "Yoog Search"
FF - user.js..browser.search.defaulturl: "http://www28.yoog.com/search.php?q="

FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\PROGRAM FILES\AVG\AVG8\FIREFOX [2009/06/10 00:07:42 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{1d5287d1-8a92-0001-1f31-1cec198018d8}: C:\PROGRAM FILES\AVG\AVG8\TOOLBARFF [2009/06/10 00:07:42 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/06/14 16:12:27 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/06/10 01:53:10 | 00,000,000 | —D | M]

[2009/03/07 16:42:16 | 00,000,000 | —D | M] – C:\Users\Alex\AppData\Roaming\mozilla\Extensions
[2009/03/07 16:13:47 | 00,000,000 | —D | M] – C:\Users\Alex\AppData\Roaming\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/03/07 16:42:16 | 00,000,000 | —D | M] – C:\Users\Alex\AppData\Roaming\mozilla\Extensions\[removed]
[2009/03/07 16:13:47 | 00,000,000 | —D | M] – C:\Users\Alex\AppData\Roaming\mozilla\Firefox\Profiles\2og0kcbe.default\extensions
[2008/05/05 01:34:38 | 00,001,048 | —- | M] () – C:\Users\Alex\AppData\Roaming\Mozilla\FireFox\Profiles\2og0kcbe.default\searchplugins\WarezSearch.xml
[2009/06/07 01:52:01 | 00,000,242 | —- | M] () – C:\Users\Alex\AppData\Roaming\Mozilla\FireFox\Profiles\2og0kcbe.default\searchplugins\Yoog Search.xml
[2009/06/10 01:53:11 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009/06/10 01:53:11 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/04/24 18:00:58 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/04/24 18:00:58 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2008/01/05 03:36:50 | 00,001,538 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2006/07/06 06:47:38 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2008/01/05 03:36:50 | 00,000,947 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
[2008/03/08 21:35:22 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2008/09/23 07:14:04 | 00,000,759 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
[2008/04/16 16:08:20 | 00,001,706 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2008/03/29 06:11:14 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2008/01/05 03:36:50 | 00,000,831 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: (761 bytes) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (bignetdaddy) - {314506e6-db9d-d679-08b6-c16f288ad5c9} - C:\Windows\system32\nseE7A5.dll ()
O2 - BHO: (Sophos Web Content Scanner) - {39EA7695-B3F2-4C44-A4BC-297ADA8FD235} - C:\Program Files\Sophos\Sophos Anti-Virus\SophosBHO.dll (Sophos Plc)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (AOL Toolbar BHO) - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll (AOL LLC)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - Reg Error: Key error. File not found
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (AVG Security Toolbar) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll (Google Inc.)
O2 - BHO: (bignetdaddy search enhancer) - {AC4A7813-6844-2FF3-D929-DCB471E346AB} - C:\Windows\system32\pihtwcdtsghokinvg.dll ()
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll (AVG Technologies CZ, s.r.o.)
O3 - HKLM\..\Toolbar: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll (AOL LLC)
O3 - HKLM\..\Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll (AOL LLC)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon (CANON INC.)
O4 - HKLM..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon (CANON INC.)
O4 - HKLM..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe (Hewlett-Packard)
O4 - HKLM..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe (Hewlett-Packard)
O4 - HKLM..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [Persistence] C:\Windows\system32\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start ( Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe" (CyberLink Corp.)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide (Microsoft Corporation)
O4 - HKCU..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background (Microsoft Corporation)
O4 - HKCU..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun (Microsoft Corporation)
O4 - HKCU..\Run: [Warez] "C:\Program Files\Warez\Warez.exe" /minimized File not found
O4 - HKCU..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter File not found
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe (Microsoft Corporation)
O4 - Startup: C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe (Lime Wire, LLC)
O4 - Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AutoUpdate Monitor.lnk = C:\Program Files\Sophos\AutoUpdate\ALMon.exe (Sophos Plc)
O4 - Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O8 - Extra context menu item: &AOL Toolbar Search - C:\ProgramData\AOL\ieToolbar\resources\en-NZ\local\search.html ()
O8 - Extra context menu item: Download All by FlashGet - Reg Error: Value error. File not found
O8 - Extra context menu item: Download using FlashGet - Reg Error: Value error. File not found
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [@%SystemRoot%\system32\nlasvc.dll,-1000] - C:\Windows\system32\NLAapi.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [@%SystemRoot%\system32\napinsp.dll,-1000] - C:\Windows\system32\napinsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [@%SystemRoot%\system32\pnrpnsp.dll,-1000] - C:\Windows\system32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [@%SystemRoot%\system32\pnrpnsp.dll,-1001] - C:\Windows\system32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [mdnsNSP] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\microsoft shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL) - C:\Program Files\Sophos\Sophos Anti-Virus\sophos_detoured.dll (Sophos Plc)
O20 - AppInit_DLLs: (avgrsstx.dll) - C:\Windows\system32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\system32\igfxdev.dll (Intel Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/08/02 12:22:25 | 00,000,074 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{fc08863f-fbbb-11dd-a1b6-001f164d6e54}\Shell - "" = AutoRun
O33 - MountPoints2\{fc08863f-fbbb-11dd-a1b6-001f164d6e54}\Shell\AutoRun\command - "" = G:\LaunchU3.exe – File not found
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\Windows\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - * [2009/06/10 01:53:14 | 00,000,000 | —D | M]

========== Files/Folders - Created Within 30 Days ==========

[2009/06/14 15:53:23 | 00,000,818 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/06/14 15:53:18 | 00,040,160 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2009/06/14 15:53:14 | 00,019,096 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2009/06/14 15:53:14 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/06/13 19:30:13 | 00,000,000 | —D | C] – C:\Rooter$
[2009/06/13 00:28:51 | 00,000,000 | —D | C] – C:\ProgramData\Yahoo!
[2009/06/13 00:25:51 | 00,000,000 | —D | C] – C:\Program Files\Yahoo!
[2009/06/11 15:42:58 | 00,000,000 | -H-D | C] – C:\$AVG8.VAULT$
[2009/06/10 16:16:21 | 00,001,874 | —- | C] () – C:\Users\Alex\Desktop\HijackThis.lnk
[2009/06/10 16:16:03 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/06/10 01:53:18 | 00,001,724 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2009/06/10 01:37:22 | 00,000,000 | —D | C] – C:\Users\Alex\AppData\Roaming\Malwarebytes
[2009/06/10 01:36:57 | 00,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2009/06/10 00:08:40 | 00,001,647 | —- | C] () – C:\Users\Public\Desktop\AVG Free 8.5.lnk
[2009/06/10 00:08:31 | 00,011,952 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\avgrsstx.dll
[2009/06/10 00:08:28 | 00,108,552 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgtdix.sys
[2009/06/10 00:08:11 | 00,325,896 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgldx86.sys
[2009/06/10 00:08:09 | 00,027,784 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgmfx86.sys
[2009/06/10 00:08:06 | 37,098,001 | —- | C] () – C:\Windows\System32\drivers\Avg\incavi.avm
[2009/06/10 00:08:06 | 00,434,673 | —- | C] () – C:\Windows\System32\drivers\Avg\miniavi.avg
[2009/06/10 00:08:06 | 00,075,476 | —- | C] () – C:\Windows\System32\drivers\Avg\microavi.avg
[2009/06/10 00:08:05 | 06,061,540 | —- | C] () – C:\Windows\System32\drivers\Avg\avi7.avg
[2009/06/10 00:08:05 | 00,000,000 | —D | C] – C:\Windows\System32\drivers\Avg
[2009/06/10 00:07:40 | 00,000,000 | —D | C] – C:\ProgramData\avg8
[2009/06/10 00:07:40 | 00,000,000 | —D | C] – C:\Program Files\AVG
[2009/06/08 12:01:15 | 00,000,436 | —- | C] () – C:\Windows\tasks\RegCure Program Check.job
[2009/06/08 12:01:11 | 00,000,370 | —- | C] () – C:\Windows\tasks\RegCure.job
[2009/06/08 12:01:06 | 00,000,523 | —- | C] () – C:\Users\Public\Desktop\RegCure.lnk
[2009/06/08 12:01:06 | 00,000,000 | —D | C] – C:\Program Files\RegCure
[2009/06/07 01:50:47 | 00,085,640 | —- | C] () – C:\Windows\System32\d3ed52fb-d2e3-36b6-76e8-9167e41922d3.exe
[2009/06/07 01:50:47 | 00,045,426 | —- | C] () – C:\Windows\System32\pihtwcdtsghokinvg.dll-uninst.exe
[2009/06/06 22:38:33 | 00,376,832 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winhttp.dll
[2009/06/06 22:38:27 | 00,562,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msdtcprx.dll
[2009/06/06 22:38:26 | 00,038,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xolehlp.dll
[2009/06/06 22:38:08 | 00,551,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rpcss.dll
[2009/06/06 22:38:07 | 03,599,328 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2009/06/06 22:38:07 | 03,547,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2009/06/06 22:38:04 | 00,666,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelinesvc.exe
[2009/06/06 22:38:02 | 00,183,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sdohlp.dll
[2009/06/06 22:38:02 | 00,098,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasrecst.dll
[2009/06/06 22:38:02 | 00,054,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasads.dll
[2009/06/06 22:38:02 | 00,044,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasdatastore.dll
[2009/06/06 22:38:02 | 00,026,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelineprxy.dll
[2009/06/06 22:38:02 | 00,017,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iashost.exe
[2009/06/06 22:37:48 | 01,255,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\lsasrv.dll
[2009/06/06 22:37:47 | 00,888,832 | —- | C] (Microsoft Corporation) – C:\Windows\System32\kernel32.dll
[2009/06/06 22:37:46 | 00,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\secur32.dll
[2009/06/06 22:37:45 | 00,024,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\amxread.dll
[2009/06/06 22:37:45 | 00,013,824 | —- | C] (Microsoft Corporation) – C:\Windows\System32\apilogen.dll
[2009/06/06 22:36:55 | 03,580,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.dll
[2009/06/06 22:36:50 | 06,068,736 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieframe.dll
[2009/06/06 22:36:47 | 01,166,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\urlmon.dll
[2009/06/06 22:36:46 | 00,827,392 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wininet.dll
[2009/06/06 22:36:45 | 00,389,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2009/06/06 22:36:45 | 00,270,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iertutil.dll
[2009/06/06 22:36:44 | 00,458,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2009/06/06 22:36:43 | 00,230,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2009/06/06 22:36:43 | 00,102,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\occache.dll
[2009/06/06 22:36:42 | 00,389,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2009/06/06 22:36:42 | 00,026,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2009/06/06 22:36:41 | 00,671,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2009/06/06 22:36:41 | 00,078,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieencode.dll
[2009/06/06 22:36:40 | 01,383,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2009/06/06 22:36:40 | 00,028,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2009/06/01 20:42:04 | 01,351,168 | —- | C] () – C:\Windows\System32\nseE7A5.dll
[2009/05/28 04:59:36 | 00,419,328 | —- | C] () – C:\Windows\System32\pihtwcdtsghokinvg.dll
[2009/04/30 01:45:05 | 00,043,520 | —- | C] () – C:\Windows\System32\CmdLineExt03.dll
[2009/01/28 07:44:52 | 00,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2008/06/13 06:59:22 | 00,147,456 | —- | C] () – C:\Windows\System32\igfxCoIn_v1502.dll
[2008/06/05 05:54:12 | 00,004,608 | —- | C] () – C:\Windows\System32\HdmiCoin.dll
[2006/11/02 22:23:31 | 00,000,219 | —- | C] () – C:\Windows\win.ini
[2006/11/02 22:23:31 | 00,000,219 | —- | C] () – C:\Windows\system.ini
[2006/11/02 19:40:29 | 00,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/03/09 21:58:00 | 01,060,424 | —- | C] () – C:\Windows\System32\WdfCoInstaller01000.dll

========== Files - Modified Within 30 Days ==========

[2009/06/14 16:14:46 | 00,000,286 | —- | M] () – C:\Users\Public\Documents\hpqp.ini
[2009/06/14 16:13:35 | 00,000,436 | —- | M] () – C:\Windows\tasks\RegCure Program Check.job
[2009/06/14 16:13:13 | 00,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2009/06/14 16:12:59 | 00,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2009/06/14 16:12:59 | 00,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2009/06/14 16:12:46 | 00,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2009/06/14 16:12:42 | 20,753,36704 | -HS- | M] () – C:\hiberfil.sys
[2009/06/14 15:53:23 | 00,000,818 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/06/14 15:40:58 | 37,098,001 | —- | M] () – C:\Windows\System32\drivers\Avg\incavi.avm
[2009/06/14 15:39:38 | 00,075,476 | —- | M] () – C:\Windows\System32\drivers\Avg\microavi.avg
[2009/06/14 15:39:03 | 00,000,499 | —- | M] () – C:\Users\Alex\Documents\My Sharing Folders.lnk
[2009/06/11 16:41:44 | 00,756,644 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2009/06/11 16:41:44 | 00,647,086 | —- | M] () – C:\Windows\System32\perfh009.dat
[2009/06/11 16:41:44 | 00,123,374 | —- | M] () – C:\Windows\System32\perfc009.dat
[2009/06/10 16:16:21 | 00,001,874 | —- | M] () – C:\Users\Alex\Desktop\HijackThis.lnk
[2009/06/10 01:53:18 | 00,001,724 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2009/06/10 00:08:40 | 00,001,647 | —- | M] () – C:\Users\Public\Desktop\AVG Free 8.5.lnk
[2009/06/10 00:08:31 | 00,011,952 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\avgrsstx.dll
[2009/06/10 00:08:28 | 00,108,552 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgtdix.sys
[2009/06/10 00:08:11 | 00,325,896 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgldx86.sys
[2009/06/10 00:08:09 | 00,027,784 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgmfx86.sys
[2009/06/10 00:08:06 | 06,061,540 | —- | M] () – C:\Windows\System32\drivers\Avg\avi7.avg
[2009/06/10 00:08:06 | 00,434,673 | —- | M] () – C:\Windows\System32\drivers\Avg\miniavi.avg
[2009/06/08 22:47:41 | 00,000,370 | —- | M] () – C:\Windows\tasks\RegCure.job
[2009/06/08 22:47:21 | 00,386,464 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2009/06/08 12:01:06 | 00,000,523 | —- | M] () – C:\Users\Public\Desktop\RegCure.lnk
[2009/06/07 01:50:47 | 00,085,640 | —- | M] () – C:\Windows\System32\d3ed52fb-d2e3-36b6-76e8-9167e41922d3.exe
[2009/06/07 01:50:47 | 00,045,426 | —- | M] () – C:\Windows\System32\pihtwcdtsghokinvg.dll-uninst.exe
[2009/06/01 20:42:04 | 01,351,168 | —- | M] () – C:\Windows\System32\nseE7A5.dll
[2009/05/28 04:59:36 | 00,419,328 | —- | M] () – C:\Windows\System32\pihtwcdtsghokinvg.dll
[2009/05/26 13:20:08 | 00,040,160 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2009/05/26 13:19:56 | 00,019,096 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys

========== LOP Check ==========

[2009/06/10 01:37:22 | 00,000,000 | —D | M] – C:\Users\Alex\AppData\Roaming
[2009/02/16 15:36:41 | 00,000,000 | —D | M] – C:\Users\Alex\AppData\Roaming\Adobe
[2009/02/05 08:55:27 | 00,000,000 | —D | M] – C:\Users\Alex\AppData\Roaming\Apple Computer
[2009/02/17 15:55:56 | 00,000,000 | —D | M] – C:\Users\Alex\AppData\Roaming\Boomzap
[2009/03/07 19:24:35 | 00,000,000 | —D | M] – C:\Users\Alex\AppData\Roaming\CyberLink
[2009/03/16 06:44:18 | 00,000,000 | —D | M] – C:\Users\Alex\AppData\Roaming\DivX
[2009/03/25 20:14:57 | 00,000,000 | —D | M] – C:\Users\Alex\AppData\Roaming\dvdcss
[2009/06/11 16:31:05 | 00,000,000 | —D | M] – C:\Users\Alex\AppData\Roaming\Google
[2009/02/15 15:45:07 | 00,000,000 | —D | M] – C:\Users\Alex\AppData\Roaming\GTek
[2009/01/27 19:40:14 | 00,000,000 | —D | M] – C:\Users\Alex\AppData\Roaming\Hewlett-Packard
[2009/01/27 19:46:41 | 00,000,000 | —D | M] – C:\Users\Alex\AppData\Roaming\Identities
[2009/06/14 16:15:32 | 00,000,000 | —D | M] – C:\Users\Alex\AppData\Roaming\LimeWire
[2009/02/05 09:35:00 | 00,000,000 | —D | M] – C:\Users\Alex\AppData\Roaming\Macromedia
[2009/06/10 01:37:22 | 00,000,000 | —D | M] – C:\Users\Alex\AppData\Roaming\Malwarebytes
[2009/05/06 17:54:35 | 00,000,000 | –SD | M] – C:\Users\Alex\AppData\Roaming\Microsoft
[2009/01/28 07:42:51 | 00,000,000 | —D | M] – C:\Users\Alex\AppData\Roaming\Microsoft Web Folders
[2009/03/07 16:13:47 | 00,000,000 | —D | M] – C:\Users\Alex\AppData\Roaming\Mozilla
[2009/02/05 09:34:59 | 00,000,000 | —D | M] – C:\Users\Alex\AppData\Roaming\PlayFirst
[2009/03/20 20:31:58 | 00,000,000 | —D | M] – C:\Users\Alex\AppData\Roaming\Red Alert 3
[2009/01/27 19:47:41 | 00,000,000 | —D | M] – C:\Users\Alex\AppData\Roaming\Symantec
[2009/03/16 18:31:31 | 00,000,000 | —D | M] – C:\Users\Alex\AppData\Roaming\vlc
[2009/01/27 19:50:47 | 00,000,000 | —D | M] – C:\Users\Alex\AppData\Roaming\WildTangent
[2009/06/14 16:13:35 | 00,000,436 | —- | M] () – C:\Windows\Tasks\RegCure Program Check.job
[2009/06/08 22:47:41 | 00,000,370 | —- | M] () – C:\Windows\Tasks\RegCure.job
[2009/06/14 16:13:13 | 00,000,006 | -H– | M] () – C:\Windows\Tasks\SA.DAT
[2009/06/14 16:11:50 | 00,032,564 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========

< End of report >

OTL Extras logfile created on: 14/06/2009 4:39:30 p.m. - Run 1
OTL by OldTimer - Version 2.1.1.0 Folder = C:\Users\Alex\Downloads
Windows Vista Home Basic Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00001409 | Country: New Zealand | Language: ENZ | Date Format: d/MM/yyyy

1.93 Gb Total Physical Memory | 0.86 Gb Available Physical Memory | 44.32% Memory free
4.00 Gb Paging File | 2.91 Gb Available in Paging File | 72.68% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 139.96 Gb Total Space | 77.02 Gb Free Space | 55.03% Space Free | Partition Type: NTFS
Drive D: | 9.09 Gb Total Space | 1.67 Gb Free Space | 18.41% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: ALEX-PC
Current User Name: Alex
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 0
"InternetSettingsDisableNotify" = 0
"AutoUpdateDisableNotify" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
Reg Error: Unknown registry data type File not found
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile
"EnableFirewall" = 1
"DisableNotifications" = 0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 1
"DisableNotifications" = 0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile
"EnableFirewall" = 1
"DisableNotifications" = 0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile\GloballyOpenPorts\List

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile\AuthorizedApplications\List]

========== Vista Active Open Ports Exception List ==========

{432C99B8-526B-428D-AE33-F7C0A08C98DA} = LPORT=1900 | PROTOCOL=17 | DIR=IN | APP=SVCHOST.EXE | SVC=SSDPSRV |
{460412BA-0480-4B57-B914-27A70DF77118} = LPORT=2869 | PROTOCOL=6 | DIR=IN | APP=SYSTEM |
{D8D5A821-E6EA-4677-98C7-412B720883CE} = LPORT=6004 | PROTOCOL=17 | DIR=IN | APP=C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE12\OUTLOOK.EXE |

========== Vista Active Application Exception List ==========

{0976D58A-8481-44F5-95D4-121E0FE115E9} = PROTOCOL=6 | DIR=IN | APP=C:\PROGRAM FILES\LIMEWIRE\LIMEWIRE.EXE |
{0EF3AA01-ECC3-49AE-B483-BB2D031E07E0} = DIR=IN | APP=C:\PROGRAM FILES\CYBERLINK\POWERDIRECTOR\PDR.EXE |
{3BF577C1-0816-48BE-9E20-31B8F3C972E7} = PROTOCOL=6 | DIR=IN | APP=C:\PROGRAM FILES\ITUNES\ITUNES.EXE |
{4B1A2E30-98D1-464F-877E-11DABD0AB535} = PROTOCOL=6 | DIR=IN | APP=C:\PROGRAM FILES\BONJOUR\MDNSRESPONDER.EXE |
{4C04752B-919C-46C4-AEBB-C6765AC039D2} = PROTOCOL=17 | DIR=IN | APP=C:\PROGRAM FILES\ITUNES\ITUNES.EXE |
{558F5807-3B25-4A72-952A-8DABF2286F1A} = PROTOCOL=17 | DIR=IN | APP=C:\PROGRAM FILES\BONJOUR\MDNSRESPONDER.EXE |
{658C891F-B985-41AD-8CBE-0194A9ECD266} = DIR=IN | APP=C:\PROGRAM FILES\HP\QUICKPLAY\QPSERVICE.EXE |
{6EE74BAA-5BC2-4DB2-925D-52D7F7372FD0} = DIR=IN | APP=C:\PROGRAM FILES\AVG\AVG8\AVGUPD.EXE |
{832085EE-690D-4E0A-A41F-7D69A794E38E} = PROTOCOL=17 | DIR=IN | APP=C:\PROGRAM FILES\LIMEWIRE\LIMEWIRE.EXE |
{858D5C88-B803-477F-B17D-C8455825B58C} = DIR=IN | APP=C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE |
{A179B3E9-4B6E-4FB1-AFC2-579D188E468A} = DIR=IN | APP=C:\PROGRAM FILES\HP\QUICKPLAY\QP.EXE |
{D84A6ADB-620B-467E-AB34-1B9E42E7A409} = DIR=IN | APP=C:\PROGRAM FILES\AVG\AVG8\AVGNSX.EXE |
{FAAFC026-5AC0-4CB0-B311-2D78DED4DB0E} = DIR=IN | APP=C:\PROGRAM FILES\MSN MESSENGER\LIVECALL.EXE |
TCP Query User{DAE3E825-E9B5-4C10-AEB6-87391E1C738B}C:\program files\warez\warez.exe = PROTOCOL=6 | DIR=IN | APP=C:\PROGRAM FILES\WAREZ\WAREZ.EXE |
TCP Query User{F586DC79-5659-4581-8F8C-690029876C84}C:\program files\limewire\limewire.exe = PROTOCOL=6 | DIR=IN | APP=C:\PROGRAM FILES\LIMEWIRE\LIMEWIRE.EXE |
UDP Query User{B6A78F88-582D-4A57-BA71-D8788AC75DFB}C:\program files\limewire\limewire.exe = PROTOCOL=17 | DIR=IN | APP=C:\PROGRAM FILES\LIMEWIRE\LIMEWIRE.EXE |
UDP Query User{BAA5B8C2-562E-4CEF-9804-75716B94E041}C:\program files\warez\warez.exe = PROTOCOL=17 | DIR=IN | APP=C:\PROGRAM FILES\WAREZ\WAREZ.EXE |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00170409-78E1-11D2-B60F-006097C998E7}" = Microsoft Word 2000 SR-1
"{034759DA-E21A-4795-BFB3-C66D17FAD183}" = Sophos Anti-Virus
"{06E74B9B-631F-4378-BF3A-40D868450C05}" = HPPhotoSmartPhotobookHolidayPack1
"{082702D5-5DD8-4600-BCE5-48B15174687F}" = HP Doc Viewer
"{0E584628-BCA0-51A2-40DB-4FA8845A0A61}" = Search Assistant Bignetdaddy
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP190_series" = Canon MP190 series MP Drivers
"{12A76360-388E-4B27-ABEB-D5FC5378DD2A}" = HPPhotoSmartPhotobookWebPack1
"{15C418EB-7675-42be-B2B3-281952DA014D}" = Sophos AutoUpdate
"{172AEB5E-CBB2-4CDD-A4CF-388600825839}" = HPPhotoSmartPhotobookPlayfulPack1
"{1BDC9633-895B-4842-BCB6-8FA1EC2A3C5A}" = Adobe Shockwave Player
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
"{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}" = QuickTime
"{228C6B46-64E2-404E-898A-EF0830603EF4}" = HPNetworkAssistant
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{254C37AA-6B72-4300-84F6-98A82419187E}" = Hewlett-Packard Active Check for Health Check
"{296D8550-CB06-48E4-9A8B-E5034FB64715}" = Command & Conquer™ Red Alert™ 3
"{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}" = Microsoft SQL Server 2005 Express Edition (MSSMLBIZ)
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{340F521E-3576-4E1A-B75C-EB0ACF751379}" = HP Wireless Assistant
"{34BFB099-07B2-4E95-A673-7362D60866A2}" = PSSWCORE
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.40 F1
"{34DAFDEC-A4B4-488A-A5CD-C91975A6F083}" = MediaRing Talk
"{35F83303-C0C0-46B7-B8A8-ADA7C2AC5645}" = muvee autoProducer 6.1
"{3877C901-7B90-4727-A639-B6ED2DD59D43}" = ESU for Microsoft Vista
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{415B2719-AD3A-4944-B404-C472DB6085B3}" = Cisco EAP-FAST Module
"{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP DVD Play 3.7
"{49672EC2-171B-47B4-8CE7-50D7806360D7}" = Windows Live Sign-in Assistant
"{4CACFCD9-F71B-413A-8DF5-1A6419D5CDC6}" = Cards_Calendar_OrderGift_DoMorePlugout
"{50120000-1105-0000-0000-0000000FF1CE}" = Microsoft Office 2007 Primary Interop Assemblies
"{51E5C397-0AA0-48DD-9CB6-7259AFFDFB0A}" = HP Easy Setup - Frontend
"{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)
"{56B4002F-671C-49F4-984C-C760FE3806B5}" = Microsoft SQL Server VSS Writer
"{571700F0-DB9D-4B3A-B03D-35A14BB5939F}" = Windows Live Messenger
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{669C7BD8-DAA2-49B6-966C-F1E2AAE6B17E}" = Cisco PEAP Module
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = Hewlett-Packard Asset Agent for Health Check
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{83770D14-21B9-44B3-8689-F7B523F94560}" = Cisco LEAP Module
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 8168 8101E 8102E Ethernet Driver
"{89E052B2-5CA5-4B7A-AF0C-28CA2836B030}" = HPPhotoSmartPhotobookModernPack1
"{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}" = Bonjour
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_PROHYBRIDR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_PROHYBRIDR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_PROHYBRIDR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_PROHYBRIDR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_PROHYBRIDR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_PROHYBRIDR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PROHYBRIDR_{3EC77D26-799B-4CD8-914F-C1565E796173}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PROHYBRIDR_{430971B1-C31E-45DA-81E0-72C095BAB72C}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROHYBRIDR_{F7A31780-33C4-4E39-951A-5EC9B91D7BF1}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_PROHYBRIDR_{FAD8A83E-9BAC-4179-9268-A35948034D85}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_PROHYBRIDR_{FAD8A83E-9BAC-4179-9268-A35948034D85}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_PROHYBRIDR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90A40409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office 2003 Web Components
"{91120000-0031-0000-0000-0000000FF1CE}" = Microsoft Office Professional Hybrid 2007
"{91120000-0031-0000-0000-0000000FF1CE}_PROHYBRIDR_{BEE75E01-DD3F-4D5F-B96C-609E6538D419}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9E2CCD5E-1990-4EF2-9B61-32F0BBACC29B}" = HP Active Support Library
"{A07840FC-CE63-4CB8-8030-EF4B9805925A}" = HPPhotoSmartDiscLabel_PaperLabel
"{A939D341-5A04-4E0A-BB55-3E65B386432D}" = Microsoft Office Small Business Connectivity Components
"{AC76BA86-7AD7-1033-7B44-A81200000003}" = Adobe Reader 8.1.2
"{AC95121F-1576-45B8-82F7-3911D27882E6}" = HPPhotoSmartPhotobookScrapbookPack1
"{ADFB9653-F44C-460C-BF58-189CC552DFFE}" = hpphotosmartdisclabelplugin
"{B16DA0F8-26BC-4FFC-9363-1D9F3E6C3E21}" = HP Customer Experience Enhancements
"{B32C4059-6E7A-41EF-AD20-56DF1872B923}" = Business Contact Manager for Outlook 2007 SP1
"{B4E91E95-A5BA-4E50-A465-DB7EFEB176E8}" = HPPhotoSmartDiscLabel_PrintOnDisc
"{B6D0B141-B2BE-4DD0-B08F-B9186F3E36B3}" = HP User Guides 0118
"{BAD0FA60-09CF-4411-AE6A-C2844C8812FA}" = HP Photosmart Essential 2.5
"{BD3DCAB0-3FE5-44FB-90DA-EFB0A2CD1387}" = Works Synchronization
"{BD68F46D-8A82-4664-8E68-F87C55BDEFD4}" = Microsoft SQL Server Native Client
"{C3A32068-8AB1-4327-BB16-BED9C6219DC7}" = Atheros Driver Installation Program
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{C8FD5BC1-92EF-4C15-92A9-F9AC7F61985F}" = HP Update
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{DC24971E-1946-445D-8A82-CE685433FA7D}" = Realtek USB 2.0 Card Reader
"{DD3C88A0-C53C-41D0-A21B-6D021981D23E}" = HPPhotoSmartDiscLabelContent1
"{E05B1C38-AE31-4146-8D47-E5E71BEB8D9E}" = Immortal Cities
"{E08DC77E-D09A-4e36-8067-D6DBBCC5F8DC}" = VideoToolkit01
"{E333CA5F-00ED-4EEF-90E5-6A33A8FE969F}" = HP Help and Support
"{EC4455AB-F155-4CC1-A4C5-88F3777F9886}" = Apple Mobile Device Support
"{ECA1A3B6-898F-4DCE-9F04-714CF3BA126B}" = Adobe Flash Player 10 Plugin
"{f32502b5-5b64-4882-bf61-77f23edcac4f}" = HP Total Care Advisor
"{F5C63795-2708-4D15-BF18-5ABBFF7DFFC8}" = iTunes
"{F636EE9A-F9EC-4606-BCFA-77DD0E210788}" = HPPhotoSmartDiscLabel_Tattoo
"{FAF7F1D7-C0E7-47EA-8AAA-84E4F9EA3C94}" = Works Suite OS Pack
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"AOL Toolbar" = AOL Toolbar 5.0
"AVG8Uninstall" = AVG Free 8.5
"Business Contact Manager" = Business Contact Manager for Outlook 2007 SP1
"CANONIJPLM100" = Inkjet Printer/Scanner Extended Survey Program
"CanonMyPrinter" = Canon My Printer
"CanonSolutionMenu" = Canon Utilities Solution Menu
"CNXT_AUDIO_HDA" = Conexant HD Audio
"CNXT_MODEM_HDAUDIO_HERMOSA_HSF" = HDAUDIO Soft Data Fax Modem with SmartCP
"d3ed52fb-d2e3-36b6-76e8-9167e41922d3" = Contextual Application Bignetdaddy
"Easy-PhotoPrint EX" = Canon Utilities Easy-PhotoPrint EX
"HDMI" = Intel® Graphics Media Accelerator Driver
"HijackThis" = HijackThis 2.0.2
"HP Photosmart Essential" = HP Photosmart Essential 2.5
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"InstallShield_{E05B1C38-AE31-4146-8D47-E5E71BEB8D9E}" = Immortal Cities
"LimeWire" = LimeWire 5.1.1
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft SQL Server 2005" = Microsoft SQL Server 2005
"Mozilla Firefox (3.0.10)" = Mozilla Firefox (3.0.10)
"MP Navigator EX 1.2" = Canon MP Navigator EX 1.2
"PROHYBRIDR" = 2007 Microsoft Office system
"RegCure" = RegCure 1.5.2.7
"SlingMedia.QPSlingPlayer_is1" = QuickPlay SlingPlayer 0.4.6
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"VLC media player" = VLC media player 0.9.8a
"WildTangent hp Master Uninstall" = HP Games
"Works2001Setup" = Microsoft Works 2001 Setup Launcher

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 13/06/2009 3:14:04 a.m. | Computer Name = Alex-PC | Source = Application Hang | ID = 1002
Description = The program firefox.exe version 1.9.0.3399 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: de4 Start Time: 01c9ebf64f7ae657 Termination Time: 103

Error - 13/06/2009 3:24:28 a.m. | Computer Name = Alex-PC | Source = WinMgmt | ID = 10
Description =

Error - 13/06/2009 3:24:35 a.m. | Computer Name = Alex-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 13/06/2009 3:25:02 a.m. | Computer Name = Alex-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 13/06/2009 3:25:46 a.m. | Computer Name = Alex-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 13/06/2009 4:05:06 a.m. | Computer Name = Alex-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 13/06/2009 4:05:06 a.m. | Computer Name = Alex-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 13/06/2009 4:05:06 a.m. | Computer Name = Alex-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 13/06/2009 4:05:06 a.m. | Computer Name = Alex-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 13/06/2009 4:05:06 a.m. | Computer Name = Alex-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

[ System Events ]
Error - 9/06/2009 6:08:38 p.m. | Computer Name = Alex-PC | Source = HTTP | ID = 15016
Description =

Error - 9/06/2009 6:09:29 p.m. | Computer Name = Alex-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 10/06/2009 8:16:13 a.m. | Computer Name = Alex-PC | Source = HTTP | ID = 15016
Description =

Error - 10/06/2009 8:16:41 a.m. | Computer Name = Alex-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 10/06/2009 5:08:06 p.m. | Computer Name = Alex-PC | Source = HTTP | ID = 15016
Description =

Error - 10/06/2009 5:08:51 p.m. | Computer Name = Alex-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 11/06/2009 12:36:41 a.m. | Computer Name = Alex-PC | Source = HTTP | ID = 15016
Description =

Error - 11/06/2009 12:37:09 a.m. | Computer Name = Alex-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 13/06/2009 3:10:37 a.m. | Computer Name = Alex-PC | Source = HTTP | ID = 15016
Description =

Error - 13/06/2009 3:11:46 a.m. | Computer Name = Alex-PC | Source = Service Control Manager | ID = 7000
Description =


< End of report >
Run OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    :OTL
    PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
    PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
    PRC - C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www1.yoog.com/
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www2.yoog.com/
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www3.yoog.com/
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www5.yoog.com/
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www6.yoog.com/
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www7.yoog.com/
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www8.yoog.com/
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www9.yoog.com/
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www10.yoog.com/
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www11.yoog.com/
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www13.yoog.com/
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www14.yoog.com/
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www15.yoog.com/
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www26.yoog.com/
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www27.yoog.com/
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www28.yoog.com/
    FF - prefs.js..browser.search.defaulturl: "http://www28.yoog.com/search.php?q="
    FF - prefs.js..keyword.URL: "http://www28.yoog.com/search.php?q="
    FF - user.js..browser.search.defaulturl: "http://www28.yoog.com/search.php?q="
    FF - user.js..keyword.URL: "http://www28.yoog.com/search.php?q="
    FF - prefs.js..browser.search.defaultenginename: "Yoog Search"
    FF - prefs.js..browser.search.defaulturl: "http://www14.yoog.com/search.php?q="
    FF - prefs.js..browser.search.selectedEngine: "Yoog Search"
    FF - prefs.js..keyword.URL: "http://www14.yoog.com/search.php?q="
    FF - user.js..browser.search.defaultenginename: "Yoog Search"
    FF - user.js..browser.search.defaulturl: "http://www14.yoog.com/search.php?q="
    FF - user.js..browser.search.selectedEngine: "Yoog Search"
    FF - user.js..keyword.URL: "http://www14.yoog.com/search.php?q="
    FF - prefs.js..browser.search.defaulturl: "http://www8.yoog.com/search.php?q="
    FF - prefs.js..keyword.URL: "http://www8.yoog.com/search.php?q="
    FF - user.js..browser.search.defaulturl: "http://www8.yoog.com/search.php?q="
    FF - user.js..keyword.URL: "http://www8.yoog.com/search.php?q="
    FF - prefs.js..browser.search.defaulturl: "http://www15.yoog.com/search.php?q="
    FF - user.js..browser.search.defaulturl: "http://www15.yoog.com/search.php?q="
    FF - user.js..keyword.URL: "http://www5.yoog.com/search.php?q="
    FF - prefs.js..browser.search.defaulturl: "http://www7.yoog.com/search.php?q="
    FF - prefs.js..keyword.URL: "http://www7.yoog.com/search.php?q="
    FF - user.js..browser.search.defaulturl: "http://www7.yoog.com/search.php?q="
    FF - user.js..keyword.URL: "http://www7.yoog.com/search.php?q="
    FF - prefs.js..browser.search.defaulturl: "http://www13.yoog.com/search.php?q="
    FF - prefs.js..keyword.URL: "http://www13.yoog.com/search.php?q="
    FF - user.js..browser.search.defaulturl: "http://www13.yoog.com/search.php?q="
    FF - user.js..keyword.URL: "http://www13.yoog.com/search.php?q="
    FF - prefs.js..browser.search.defaulturl: "http://www3.yoog.com/search.php?q="
    FF - prefs.js..keyword.URL: "http://www3.yoog.com/search.php?q="
    FF - user.js..browser.search.defaulturl: "http://www3.yoog.com/search.php?q="
    FF - user.js..keyword.URL: "http://www3.yoog.com/search.php?q="
    FF - prefs.js..browser.search.defaulturl: "http://www10.yoog.com/search.php?q="
    FF - prefs.js..keyword.URL: "http://www10.yoog.com/search.php?q="
    FF - user.js..browser.search.defaulturl: "http://www10.yoog.com/search.php?q="
    FF - user.js..keyword.URL: "http://www10.yoog.com/search.php?q="
    FF - prefs.js..browser.search.defaulturl: "http://www11.yoog.com/search.php?q="
    FF - prefs.js..keyword.URL: "http://www11.yoog.com/search.php?q="
    FF - user.js..browser.search.defaulturl: "http://www11.yoog.com/search.php?q="
    FF - user.js..keyword.URL: "http://www11.yoog.com/search.php?q="
    FF - prefs.js..browser.search.defaulturl: "http://www2.yoog.com/search.php?q="
    FF - prefs.js..keyword.URL: "http://www2.yoog.com/search.php?q="
    FF - user.js..browser.search.defaulturl: "http://www2.yoog.com/search.php?q="
    FF - user.js..keyword.URL: "http://www2.yoog.com/search.php?q="
    FF - prefs.js..browser.search.defaulturl: "http://www26.yoog.com/search.php?q="
    FF - prefs.js..keyword.URL: "http://www26.yoog.com/search.php?q="
    FF - user.js..browser.search.defaulturl: "http://www26.yoog.com/search.php?q="
    FF - user.js..keyword.URL: "http://www26.yoog.com/search.php?q="
    FF - prefs.js..browser.search.defaulturl: "http://www5.yoog.com/search.php?q="
    FF - prefs.js..keyword.URL: "http://www5.yoog.com/search.php?q="
    FF - user.js..browser.search.defaulturl: "http://www5.yoog.com/search.php?q="
    FF - user.js..keyword.URL: "http://www5.yoog.com/search.php?q="
    FF - prefs.js..browser.search.defaulturl: "http://www1.yoog.com/search.php?q="
    FF - prefs.js..keyword.URL: "http://www1.yoog.com/search.php?q="
    FF - user.js..browser.search.defaulturl: "http://www1.yoog.com/search.php?q="
    FF - user.js..keyword.URL: "http://www1.yoog.com/search.php?q="
    FF - prefs.js..browser.search.defaulturl: "http://www9.yoog.com/search.php?q="
    FF - prefs.js..keyword.URL: "http://www9.yoog.com/search.php?q="
    FF - user.js..browser.search.defaulturl: "http://www9.yoog.com/search.php?q="
    FF - user.js..keyword.URL: "http://www9.yoog.com/search.php?q="
    FF - prefs.js..browser.search.defaulturl: "http://www6.yoog.com/search.php?q="
    FF - prefs.js..keyword.URL: "http://www6.yoog.com/search.php?q="
    FF - user.js..browser.search.defaulturl: "http://www6.yoog.com/search.php?q="
    FF - user.js..keyword.URL: "http://www6.yoog.com/search.php?q="
    FF - prefs.js..browser.search.defaulturl: "http://www27.yoog.com/search.php?q="
    FF - prefs.js..keyword.URL: "http://www27.yoog.com/search.php?q="
    FF - user.js..browser.search.defaulturl: "http://www27.yoog.com/search.php?q="
    FF - user.js..keyword.URL: "http://www27.yoog.com/search.php?q="
    FF - user.js..keyword.enabled: true
    
    :Files
    %ProgramFiles%\IEToolbar
    %ProgramFiles%\Mozilla Firefox\components\nsadzgalore.dll
    %ProgramFiles%\Mozilla Firefox\components\nsadsoftinc.dll
    %ProgramFiles%\Mozilla Firefox\components\nsBrowserOpt.dll
    %ProgramFiles%\Mozilla Firefox\searchplugins\Yoog.xml
    %ProgramFiles%\Mozilla Firefox\components\nsBrowserDc.dll
    %ProgramFiles%\Mozilla Firefox\components\nsdcads.dll
    %APPDATA%\Mozilla\Firefox\Profiles\Yoog Search.xml /s
    %PROGRAMFILES%\Mozilla Firefox\components\mexmgzdhgnvqilpib.dll
    %SystemRoot%\system32\mexmgzdhgnvqilpib.dll
    %PROGRAMFILES%\mozilla firefox\components\zvakwomxas.dll
    %SystemRoot%\system32\zawcukanoit.exe
    %SystemRoot%\System32\lkvwtxiako.dll  
    %SystemRoot%\system32\zvakwomxas.dll
    %SystemRoot%\system32\dgbzetddjouspgzqz.dll
    %SystemRoot%\System32\nsn*.dll
    %SystemRoot%\nmwi*.exe
    %SystemRoot%\system32\nsx*.dll
    %SystemRoot%\system32\nsj*.dll
    %SystemRoot%\system32\nsv*.dll
    %systemroot%\system32\nsf*.dll
    %systemroot%\mutfp*.exe
    %systemroot%\obwu*.exe
    %systemroot%\ntaj*.exe
    %systemroot%\nwuhr*.exe
    %systemroot%\System32\nss*.dll
    %SystemRoot%\system32\*-uninst.exe
    %SystemRoot%\system32\*-remove.exe
    %systemroot%\system32\nsr*.dll
    %systemroot%\reax*.exe
    %systemroot%\giptf*.exe
    %systemroot%\tkoo*.exe
    %systemroot%\axjth*.exe
    %systemroot%\ertbg*.exe
    %systemroot%\jnnmp*.exe
    %systemroot%\bprxe*.exe
    %systemroot%\xwisg*.exe
    %systemroot%\jpng*.exe
    %systemroot%\fhsv*.exe
    %systemroot%\dfmqc*.exe
    %systemroot%\wgfp*.exe
    %systemroot%\gweq*.exe
    %systemroot%\pxwis*.exe
    %systemroot%\fcvmq*.exe
    %systemroot%\System32\hfkxlchuhv.dll
    %systemroot%\System32\nst*.dll
    %systemroot%\dmkv*.exe
    %systemroot%\system32\nseE*.dll
    %systemroot%\system32\pihtwcdtsghokinvg.dll
    %systemroot%\system32\yprhhrqubcbujp.exe
    %systemroot%\system32\ucicolizrhssr.dll
    %systemroot%\system32\hiwdrlnk.exe
    %USERPROFILE%\Start Menu\Programs\Startup\runit_32.lnk
    %PROGRAMFILES%\runit
    %systemroot%\System32\dsygtypzdloyoxivg.exe
    %systemroot%\System32\qdfggdhhofhhylbfx.exe
    %ProgramFiles%\mozilla firefox\components\????????-????-????-????-????????????.dll
    %systemroot%\System32\????????-????-????-????-????????????.exe
    
    :Reg
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b0d2e786-354b-fea1-8de7-883e7524e6d2}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b2fe5f61-3eb4-4e22-7c84-f52993635f52}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{f20e8516-7d08-c1e3-e689-96d39bb42220}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{ad7781e6-d262-25f8-389d-967a6d974748}"=-
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{314506e6-db9d-d679-08b6-c16f288ad5c9}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AC4A7813-6844-2FF3-D929-DCB471E346AB}]
    
    :Commands
    [purity]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
heres the notepad report ========== OTL ========== Process explorer.exe killed successfully! Process firefox.exe killed successfully! No active process named TeaTimer.exe was found! No active process named IEXPLORE.EXE was found! HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully! HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully! HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully! HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully! HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully! HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully! HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully! HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully! HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully! HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully! HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully! HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully! HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully! HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully! HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully! HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully! Prefs.js: "http://www28.yoog.com/search.php?q=" removed from browser.search.defaulturl Prefs.js: "http://www28.yoog.com/search.php?q=" removed from keyword.URL C:\Users\Alex\AppData\Roaming\Mozilla\FireFox\Profiles\2og0kcbe.default\user.js moved successfully. Prefs.js: "Yoog Search" removed from browser.search.defaultenginename Prefs.js: "http://www14.yoog.com/search.php?q=" removed from browser.search.defaulturl Prefs.js: "Yoog Search" removed from browser.search.selectedEngine Prefs.js: "http://www14.yoog.com/search.php?q=" removed from keyword.URL Prefs.js: "http://www8.yoog.com/search.php?q=" removed from browser.search.defaulturl Prefs.js: "http://www8.yoog.com/search.php?q=" removed from keyword.URL Prefs.js: "http://www15.yoog.com/search.php?q=" removed from browser.search.defaulturl Prefs.js: "http://www7.yoog.com/search.php?q=" removed from browser.search.defaulturl Prefs.js: "http://www7.yoog.com/search.php?q=" removed from keyword.URL Prefs.js: "http://www13.yoog.com/search.php?q=" removed from browser.search.defaulturl Prefs.js: "http://www13.yoog.com/search.php?q=" removed from keyword.URL Prefs.js: "http://www3.yoog.com/search.php?q=" removed from browser.search.defaulturl Prefs.js: "http://www3.yoog.com/search.php?q=" removed from keyword.URL Prefs.js: "http://www10.yoog.com/search.php?q=" removed from browser.search.defaulturl Prefs.js: "http://www10.yoog.com/search.php?q=" removed from keyword.URL Prefs.js: "http://www11.yoog.com/search.php?q=" removed from browser.search.defaulturl Prefs.js: "http://www11.yoog.com/search.php?q=" removed from keyword.URL Prefs.js: "http://www2.yoog.com/search.php?q=" removed from browser.search.defaulturl Prefs.js: "http://www2.yoog.com/search.php?q=" removed from keyword.URL Prefs.js: "http://www26.yoog.com/search.php?q=" removed from browser.search.defaulturl Prefs.js: "http://www26.yoog.com/search.php?q=" removed from keyword.URL Prefs.js: "http://www5.yoog.com/search.php?q=" removed from browser.search.defaulturl Prefs.js: "http://www5.yoog.com/search.php?q=" removed from keyword.URL Prefs.js: "http://www1.yoog.com/search.php?q=" removed from browser.search.defaulturl Prefs.js: "http://www1.yoog.com/search.php?q=" removed from keyword.URL Prefs.js: "http://www9.yoog.com/search.php?q=" removed from browser.search.defaulturl Prefs.js: "http://www9.yoog.com/search.php?q=" removed from keyword.URL Prefs.js: "http://www6.yoog.com/search.php?q=" removed from browser.search.defaulturl Prefs.js: "http://www6.yoog.com/search.php?q=" removed from keyword.URL Prefs.js: "http://www27.yoog.com/search.php?q=" removed from browser.search.defaulturl Prefs.js: "http://www27.yoog.com/search.php?q=" removed from keyword.URL ========== FILES ========== File/Folder C:\Program Files\IEToolbar not found. File/Folder C:\Program Files\Mozilla Firefox\components\nsadzgalore.dll not found. File/Folder C:\Program Files\Mozilla Firefox\components\nsadsoftinc.dll not found. File/Folder C:\Program Files\Mozilla Firefox\components\nsBrowserOpt.dll not found. File/Folder C:\Program Files\Mozilla Firefox\searchplugins\Yoog.xml not found. File/Folder C:\Program Files\Mozilla Firefox\components\nsBrowserDc.dll not found. File/Folder C:\Program Files\Mozilla Firefox\components\nsdcads.dll not found. C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\2og0kcbe.default\searchplugins\Yoog Search.xml moved successfully. File/Folder C:\Program Files\Mozilla Firefox\components\mexmgzdhgnvqilpib.dll not found. File/Folder C:\Windows\system32\mexmgzdhgnvqilpib.dll not found. File/Folder C:\Program Files\mozilla firefox\components\zvakwomxas.dll not found. File/Folder C:\Windows\system32\zawcukanoit.exe not found. File/Folder C:\Windows\System32\lkvwtxiako.dll not found. File/Folder C:\Windows\system32\zvakwomxas.dll not found. File/Folder C:\Windows\system32\dgbzetddjouspgzqz.dll not found. File/Folder C:\Windows\System32\nsn*.dll not found. File/Folder C:\Windows\nmwi*.exe not found. File/Folder C:\Windows\system32\nsx*.dll not found. File/Folder C:\Windows\system32\nsj*.dll not found. File/Folder C:\Windows\system32\nsv*.dll not found. File/Folder C:\Windows\system32\nsf*.dll not found. File/Folder C:\Windows\mutfp*.exe not found. File/Folder C:\Windows\obwu*.exe not found. File/Folder C:\Windows\ntaj*.exe not found. File/Folder C:\Windows\nwuhr*.exe not found. File/Folder C:\Windows\System32\nss*.dll not found. C:\Windows\system32\pihtwcdtsghokinvg.dll-uninst.exe moved successfully. File/Folder C:\Windows\system32\*-remove.exe not found. File/Folder C:\Windows\system32\nsr*.dll not found. File/Folder C:\Windows\reax*.exe not found. File/Folder C:\Windows\giptf*.exe not found. File/Folder C:\Windows\tkoo*.exe not found. File/Folder C:\Windows\axjth*.exe not found. File/Folder C:\Windows\ertbg*.exe not found. File/Folder C:\Windows\jnnmp*.exe not found. File/Folder C:\Windows\bprxe*.exe not found. File/Folder C:\Windows\xwisg*.exe not found. File/Folder C:\Windows\jpng*.exe not found. File/Folder C:\Windows\fhsv*.exe not found. File/Folder C:\Windows\dfmqc*.exe not found. File/Folder C:\Windows\wgfp*.exe not found. File/Folder C:\Windows\gweq*.exe not found. File/Folder C:\Windows\pxwis*.exe not found. File/Folder C:\Windows\fcvmq*.exe not found. File/Folder C:\Windows\System32\hfkxlchuhv.dll not found. File/Folder C:\Windows\System32\nst*.dll not found. File/Folder C:\Windows\dmkv*.exe not found. C:\Windows\system32\nseE7A5.dll unregistered successfully. C:\Windows\system32\nseE7A5.dll moved successfully. C:\Windows\system32\pihtwcdtsghokinvg.dll unregistered successfully. C:\Windows\system32\pihtwcdtsghokinvg.dll moved successfully. File/Folder C:\Windows\system32\yprhhrqubcbujp.exe not found. File/Folder C:\Windows\system32\ucicolizrhssr.dll not found. File/Folder C:\Windows\system32\hiwdrlnk.exe not found. File/Folder C:\Users\Alex\Start Menu\Programs\Startup\runit_32.lnk not found. File/Folder C:\Program Files\runit not found. File/Folder C:\Windows\System32\dsygtypzdloyoxivg.exe not found. File/Folder C:\Windows\System32\qdfggdhhofhhylbfx.exe not found. File/Folder C:\Program Files\mozilla firefox\components\????????-????-????-????-????????????.dll not found. C:\Windows\System32\d3ed52fb-d2e3-36b6-76e8-9167e41922d3.exe moved successfully. ========== REGISTRY ========== Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b0d2e786-354b-fea1-8de7-883e7524e6d2}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b0d2e786-354b-fea1-8de7-883e7524e6d2}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b2fe5f61-3eb4-4e22-7c84-f52993635f52}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b2fe5f61-3eb4-4e22-7c84-f52993635f52}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{f20e8516-7d08-c1e3-e689-96d39bb42220}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f20e8516-7d08-c1e3-e689-96d39bb42220}\ not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{ad7781e6-d262-25f8-389d-967a6d974748} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ad7781e6-d262-25f8-389d-967a6d974748}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{314506e6-db9d-d679-08b6-c16f288ad5c9}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{314506e6-db9d-d679-08b6-c16f288ad5c9}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AC4A7813-6844-2FF3-D929-DCB471E346AB}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AC4A7813-6844-2FF3-D929-DCB471E346AB}\ not found. ========== COMMANDS ========== File delete failed. C:\Users\Alex\AppData\Local\Temp\hsperfdata_Alex\3376 scheduled to be deleted on reboot. User's Temp folder emptied. User's Internet Explorer cache folder emptied. User's Temporary Internet Files folder emptied. Windows Temp folder emptied. Temp folders emptied. OTL by OldTimer - Version 2.1.1.0 log created on 06162009_082815 Files moved on Reboot… File C:\Users\Alex\AppData\Local\Temp\hsperfdata_Alex\3376 not found! Registry entries deleted on Reboot…
Hi AlcysaidElsy,


Download and scan with SUPERAntiSpyware Free for Home Users
  • Double-click SUPERAntiSpyware.exe and use the default settings for installation.
  • An icon will be created on your desktop. Double-click that icon to launch the program.
  • If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here.)
  • Under "Configuration and Preferences", click the Preferences button.
  • Click the Scanning Control tab.
  • Under Scanner Options make sure the following are checked (leave all others unchecked):
    • Close browsers before scanning.
    • Scan for tracking cookies.
    • Terminate memory threats before quarantining.
  • Click the "Close" button to leave the control center screen.
  • Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
  • On the left, make sure you check C:\Fixed Drive.
  • On the right, under "Complete Scan", choose Perform Complete Scan.
  • Click "Next" to start the scan. Please be patient while it scans your computer.
  • After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
  • Make sure everything has a checkmark next to it and click "Next".
  • A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
  • If asked if you want to reboot, click "Yes".
  • To retrieve the removal information after reboot, launch SUPERAntispyware again.
    o Click Preferences, then click the Statistics/Logs tab.
    o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
    o If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
    o Please copy and paste the Scan Log results in your next reply.
  • Click Close to exit the program.



Go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI