This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Searchqu

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I just recently realized that my computer is infected with searchqu and i am unable to change my homepage. i've looked through some other posts and downloaded OTL here are the results. any help will be much appreciated.

OTL logfile created on: 6/4/2011 4:18:31 AM - Run 3
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Users\Hung\Downloads
64bit- Home Premium Edition Service Pack 3 (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

8.00 Gb Total Physical Memory | 6.04 Gb Available Physical Memory | 75.56% Memory free
15.99 Gb Paging File | 13.84 Gb Available in Paging File | 86.52% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931.41 Gb Total Space | 319.30 Gb Free Space | 34.28% Space Free | Partition Type: NTFS
Drive D: | 4.36 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive E: | 6.15 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive H: | 7.49 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: HUNG-PC | User Name: Hung | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Hung\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Discordia, LTD)
PRC - C:\Windows\SysWOW64\PnkBstrA.exe ()
PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Windows Media Player\wmplayer.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinService.exe (Affinegy, Inc.)
PRC - C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinSetup.exe (Affinegy, Inc.)
PRC - C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe (Affinegy, Inc.)
PRC - C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
PRC - C:\ASUS.SYS\config\DVMExportService.exe (DeviceVM, Inc.)
PRC - C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe ()
PRC - C:\Program Files (x86)\Common Files\LogiShrd\LQCVFX\COCIManager.exe ()
PRC - C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe (Logitech Inc.)
PRC - C:\Windows\DAODx.exe ()
PRC - C:\Program Files (x86)\MagicDisc\MagicDisc.exe (MagicISO, Inc.)
PRC - C:\Program Files (x86)\VentSrv\ventrilo_srv.exe ()
PRC - C:\Program Files (x86)\VentSrv\ventrilo_svc.exe ()
PRC - C:\Program Files (x86)\RocketDock\RocketDock.exe ()
PRC - C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (Rocket Division Software)


========== Modules (SafeList) ==========

MOD - C:\Users\Hung\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files (x86)\RocketDock\RocketDock.dll ()
Hi Systemerr0r,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

What you posted isn't even half of the OTL log.

Please look on your c: drive for a folder called OTL or _OTL. In that folder should be .txt files that are copies of your logs. Please open them and post the complete logs here.
OTL logfile created on: 6/4/2011 4:18:31 AM - Run 3
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Users\Hung\Downloads
64bit- Home Premium Edition Service Pack 3 (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

8.00 Gb Total Physical Memory | 6.04 Gb Available Physical Memory | 75.56% Memory free
15.99 Gb Paging File | 13.84 Gb Available in Paging File | 86.52% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931.41 Gb Total Space | 319.30 Gb Free Space | 34.28% Space Free | Partition Type: NTFS
Drive D: | 4.36 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive E: | 6.15 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive H: | 7.49 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: HUNG-PC | User Name: Hung | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Hung\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Discordia, LTD)
PRC - C:\Windows\SysWOW64\PnkBstrA.exe ()
PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Windows Media Player\wmplayer.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinService.exe (Affinegy, Inc.)
PRC - C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinSetup.exe (Affinegy, Inc.)
PRC - C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe (Affinegy, Inc.)
PRC - C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
PRC - C:\ASUS.SYS\config\DVMExportService.exe (DeviceVM, Inc.)
PRC - C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe ()
PRC - C:\Program Files (x86)\Common Files\LogiShrd\LQCVFX\COCIManager.exe ()
PRC - C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe (Logitech Inc.)
PRC - C:\Windows\DAODx.exe ()
PRC - C:\Program Files (x86)\MagicDisc\MagicDisc.exe (MagicISO, Inc.)
PRC - C:\Program Files (x86)\VentSrv\ventrilo_srv.exe ()
PRC - C:\Program Files (x86)\VentSrv\ventrilo_svc.exe ()
PRC - C:\Program Files (x86)\RocketDock\RocketDock.exe ()
PRC - C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (Rocket Division Software)


========== Modules (SafeList) ==========

MOD - C:\Users\Hung\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files (x86)\RocketDock\RocketDock.dll ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (wlcrasvc) – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV:64bit: - (LVPrcS64) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (Hamachi2Svc) – C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (LogMeIn Inc.)
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (PnkBstrA) – C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (Stereo Service) – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (MBAMService) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (Futuremark SystemInfo Service) – C:\Program Files (x86)\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe (Futuremark Corporation)
SRV - (AfaService) – C:\Windows\SysWOW64\afasrv64.exe ()
SRV - (AffinegyService) – C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinService.exe (Affinegy, Inc.)
SRV - (rpcapd) Remote Packet Capture Protocol v.0 (experimental) – C:\Program Files (x86)\WinPcap\rpcapd.exe (CACE Technologies, Inc.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (McComponentHostService) – C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (DvmMDES) – C:\ASUS.SYS\config\DVMExportService.exe (DeviceVM, Inc.)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (Ventrilo) – C:\Program Files (x86)\VentSrv\ventrilo_svc.exe ()
SRV - (StarWindServiceAE) – C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (Rocket Division Software)
SRV - (libusbd) – C:\Windows\SysWOW64\libusbd-nt.exe (http://libusb-win32.sourceforge.net)


========== Driver Services (SafeList) ==========

DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (atksgt) – C:\Windows\SysNative\drivers\atksgt.sys ()
DRV:64bit: - (lirsgt) – C:\Windows\SysNative\drivers\lirsgt.sys ()
DRV:64bit: - (MBAMProtector) – C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (sptd) – C:\Windows\SysNative\drivers\sptd.sys ()
DRV:64bit: - (NVHDA) – C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation)
DRV:64bit: - (fssfltr) – C:\Windows\SysNative\drivers\fssfltr.sys (Microsoft Corporation)
DRV:64bit: - (cpuz134) – C:\Windows\SysNative\drivers\cpuz134_x64.sys (Windows ® Win 7 DDK provider)
DRV:64bit: - (NPF) – C:\Windows\SysNative\drivers\npf.sys (CACE Technologies, Inc.)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (WmVirHid) – C:\Windows\SysNative\drivers\WmVirHid.sys (Logitech Inc.)
DRV:64bit: - (WmBEnum) – C:\Windows\SysNative\drivers\WmBEnum.sys (Logitech Inc.)
DRV:64bit: - (WmXlCore) – C:\Windows\SysNative\drivers\WmXlCore.sys (Logitech Inc.)
DRV:64bit: - (WmFilter) – C:\Windows\SysNative\drivers\WmFilter.sys (Logitech Inc.)
DRV:64bit: - (LGVirHid) – C:\Windows\SysNative\drivers\LGVirHid.sys (Logitech Inc.)
DRV:64bit: - (LGBusEnum) – C:\Windows\SysNative\drivers\LGBusEnum.sys (Logitech Inc.)
DRV:64bit: - (LVPr2Mon) – C:\Windows\SysNative\drivers\LVPr2M64.sys ()
DRV:64bit: - (LVPr2M64) – C:\Windows\SysNative\drivers\LVPr2M64.sys ()
DRV:64bit: - (LVUVC64) QuickCam Communicate Deluxe(UVC) – C:\Windows\SysNative\drivers\lvuvc64.sys (Logitech Inc.)
DRV:64bit: - (LVRS64) – C:\Windows\SysNative\drivers\lvrs64.sys (Logitech Inc.)
DRV:64bit: - (MTsensor) – C:\Windows\SysNative\drivers\ASACPI.sys ()
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (xnacc) – C:\Windows\SysNative\drivers\xnacc.sys (Microsoft Corporation)
DRV:64bit: - (Ntfs) – C:\Windows\SysNative\wbem\ntfs.mof ()
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (hamachi) – C:\Windows\SysNative\drivers\hamachi.sys (LogMeIn, Inc.)
DRV:64bit: - (mcdbus) – C:\Windows\SysNative\drivers\mcdbus.sys (MagicISO, Inc.)
DRV - (mcdbus) – C:\Windows\SysWOW64\drivers\mcdbus.sys (MagicISO, Inc.)
DRV - (speedfan) – C:\Windows\SysWOW64\speedfan.sys (Windows ® Server 2003 DDK provider)
DRV - (libusb0) – C:\Windows\SysWOW64\drivers\libusb0.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\URLSearchHook: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\tbBit1.dll (Conduit Ltd.)

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = F0 0E 83 88 7C C7 CB 01 [binary data]
IE - HKCU\..\URLSearchHook: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\tbBit1.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Web Search"
FF - prefs.js..browser.search.order.1: "Web Search"
FF - prefs.js..browser.search.selectedEngine: "Web Search"
FF - prefs.js..browser.startup.homepage: "http://www.searchqu.com/406"
FF - prefs.js..extensions.enabledItems: [removed]:3.6.7
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:5.3.0.7280
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.6
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: [removed]:3.3.101
FF - prefs.js..extensions.enabledItems: [removed]:0.2.4
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: [removed]:1.1
FF - prefs.js..extensions.enabledItems: [removed]:[removed]
FF - prefs.js..extensions.enabledItems: {5c8bfb7c-9a54-11dc-8314-0800200c9a66}:3.6.7
FF - prefs.js..extensions.enabledItems: [removed]:1.3.1


FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/01/18 05:36:16 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{4bcdbfd0-fa26-11de-8a39-0800200c9a66}: C:\Users\Hung\AppData\Roaming\Mozilla\FireFox\{4bcdbfd0-fa26-11de-8a39-0800200c9a66} [2011/03/11 12:09:38 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/06/04 03:18:31 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/05/01 18:18:50 | 000,000,000 | —D | M]

[2011/05/01 15:52:04 | 000,000,000 | —D | M] (No name found) – C:\Users\Hung\AppData\Roaming\Mozilla\Extensions
[2011/02/16 02:07:37 | 000,000,000 | —D | M] (No name found) – C:\Users\Hung\AppData\Roaming\Mozilla\Extensions\[removed]
[2011/06/04 04:04:31 | 000,000,000 | —D | M] (No name found) – C:\Users\Hung\AppData\Roaming\Mozilla\Firefox\Profiles\q6qgx2pp.default\extensions
[2010/11/10 01:19:51 | 000,000,000 | —D | M] (Aero Fox XL) – C:\Users\Hung\AppData\Roaming\Mozilla\Firefox\Profiles\q6qgx2pp.default\extensions\{5c8bfb7c-9a54-11dc-8314-0800200c9a66}
[2011/04/03 10:38:31 | 000,000,000 | —D | M] (BitTorrentBar Community Toolbar) – C:\Users\Hung\AppData\Roaming\Mozilla\Firefox\Profiles\q6qgx2pp.default\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}
[2011/05/01 15:52:02 | 000,000,000 | —D | M] (Searchqu Toolbar) – C:\Users\Hung\AppData\Roaming\Mozilla\Firefox\Profiles\q6qgx2pp.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}
[2011/01/12 19:42:52 | 000,000,000 | —D | M] (ActiveGS) – C:\Users\Hung\AppData\Roaming\Mozilla\Firefox\Profiles\q6qgx2pp.default\extensions\[removed]
[2011/04/03 10:38:31 | 000,000,000 | —D | M] (Conduit Engine) – C:\Users\Hung\AppData\Roaming\Mozilla\Firefox\Profiles\q6qgx2pp.default\extensions\[removed]
[2010/11/10 01:19:55 | 000,000,000 | —D | M] (Virtus Search Opt-in) – C:\Users\Hung\AppData\Roaming\Mozilla\Firefox\Profiles\q6qgx2pp.default\extensions\[removed]
[2011/04/05 14:52:44 | 000,000,000 | —D | M] (SkyFex Remote Desktop) – C:\Users\Hung\AppData\Roaming\Mozilla\Firefox\Profiles\q6qgx2pp.default\extensions\[removed]
[2010/11/10 01:19:55 | 000,000,000 | —D | M] (No name found) – C:\Users\Hung\AppData\Roaming\Mozilla\Firefox\Profiles\q6qgx2pp.default\extensions\[removed]\chrome
[2010/11/10 01:19:51 | 000,000,000 | —D | M] (No name found) – C:\Users\Hung\AppData\Roaming\Mozilla\Firefox\Profiles\q6qgx2pp.default\extensions\{5c8bfb7c-9a54-11dc-8314-0800200c9a66}\chrome\win\mozapps\extensions
[2011/06/04 03:18:31 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/05/11 08:01:08 | 000,000,000 | —D | M] (Skype extension) – C:\Program Files (x86)\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2010/12/18 03:07:45 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2011/01/29 16:57:57 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
File not found (No name found) –
() (No name found) – C:\USERS\HUNG\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\Q6QGX2PP.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
() (No name found) – C:\USERS\HUNG\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\Q6QGX2PP.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\USERS\HUNG\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\Q6QGX2PP.DEFAULT\EXTENSIONS\[removed]
[2011/04/14 09:26:02 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\Mozilla Firefox\components\browsercomps.dll
[2009/11/06 09:37:19 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files (x86)\Mozilla Firefox\plugins\npCouponPrinter.dll
[2010/11/12 19:53:06 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
[2009/11/06 09:37:20 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files (x86)\Mozilla Firefox\plugins\npMozCouponPrinter.dll
[2010/01/01 01:00:00 | 000,002,252 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\bing.xml

O1 HOSTS File: ([2011/06/04 03:31:28 | 000,000,027 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (UrlHelper Class) - {A40DC6C5-79D0-4ca8-A185-8FF989AF1115} - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\IEBHO.dll (Discordia, LTD)
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - File not found
O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\ConduitEngi0.dll (Conduit Ltd.)
O2 - BHO: (E-Zsoft VideoDownloaderToolBar) - {4322A444-92F8-4C3E-BD4C-013BA51E2871} - C:\Program Files (x86)\Versalsoft\InternetDownload\VDTB.dll ()
O2 - BHO: (BitTorrentBar Toolbar) - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\tbBit1.dll (Conduit Ltd.)
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O4:64bit: - HKLM..\Run: [Launch LCore] C:\Program Files\Logitech Gaming Software\LCore.exe (Logitech Inc.)
O4:64bit: - HKLM..\Run: [Start WingMan Profiler] C:\Program Files\Logitech\Gaming Software\LWEMon.exe (Logitech Inc.)
O4:64bit: - HKLM..\Run: [USBestCR] C:\Program Files (x86)\cardicon\iconcs55926.exe ()
O4 - HKLM..\Run: [amd_dc_opt] C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe (AMD)
O4 - HKLM..\Run: [DATAMNGR] C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Discordia, LTD)
O4 - HKLM..\Run: [InstaLAN] C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe (Affinegy, Inc.)
O4 - HKLM..\Run: [InternetDownload_upgrade] C:\Program Files (x86)\Versalsoft\InternetDownload\InternetDownload.exe (Internet Downloader)
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe ()
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [USBestCR] C:\Program Files (x86)\cardicon\iconcs55926.exe ()
O4 - HKCU..\Run: [AlcoholAutomount] C:\Program Files (x86)\Alcohol Soft\Alcohol 120\axcmd.exe (Alcohol Soft Development Team)
O4 - HKCU..\Run: [RocketDock] C:\Program Files (x86)\RocketDock\RocketDock.exe ()
O4 - Startup: C:\Users\Hung\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MagicDisc.lnk = C:\Program Files (x86)\MagicDisc\MagicDisc.exe (MagicISO, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:64bit: - Extra context menu item: Download by Versalsoft Internet Download - C:\Program Files (x86)\Versalsoft\InternetDownload\adddownload.htm ()
O8 - Extra context menu item: Download by Versalsoft Internet Download - C:\Program Files (x86)\Versalsoft\InternetDownload\adddownload.htm ()
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} http://messenger.zone.msn.com/binary/Solit…wn.cab56986.cab (Solitaire Showdown Class)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/MessengerGam…1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - Reg Error: Key error. File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\x64\datamngr.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\datamngr.dll (Discordia, LTD)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\x64\IEBHO.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\IEBHO.dll (Discordia, LTD)
O20 - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\datamngr.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngr.dll (Discordia, LTD)
O20 - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\IEBHO.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Discordia, LTD)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/03/23 14:50:24 | 000,000,061 | R— | M] () - H:\autorun.inf – [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = ComFile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/06/04 04:12:17 | 000,000,000 | —D | C] – C:\_OTL
[2011/06/04 03:32:30 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2011/06/04 02:58:00 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2011/06/04 02:58:00 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2011/06/04 02:58:00 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2011/06/04 02:57:55 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2011/06/04 02:57:52 | 000,000,000 | —D | C] – C:\Qoobox
[2011/06/04 01:29:10 | 000,000,000 | —D | C] – C:\Users\Hung\Documents\The Witcher 2
[2011/06/04 01:26:51 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Witcher 2
[2011/06/04 01:25:07 | 000,000,000 | —D | C] – C:\Users\Hung\Documents\witcher2saves
[2011/06/04 01:12:27 | 000,000,000 | —D | C] – C:\Program Files (x86)\The Witcher 2
[2011/06/04 00:48:09 | 000,000,000 | —D | C] – C:\Users\Hung\AppData\Local\{6ED49774-2113-472B-BE33-AF90A2EA4D50}
[2011/06/03 12:47:24 | 000,000,000 | —D | C] – C:\Users\Hung\AppData\Local\{ACE872A5-2A67-4778-BBB5-1BC6F45AD109}
[2011/06/03 00:46:23 | 000,000,000 | —D | C] – C:\Users\Hung\AppData\Local\{8248B709-7CBA-4947-9EB1-F793B09DBC6C}
[2011/06/02 12:45:34 | 000,000,000 | —D | C] – C:\Users\Hung\AppData\Local\{BFEFD427-532E-4A7E-A577-22D7044D9FA1}
[2011/06/02 04:27:51 | 000,033,856 | -H– | C] (LogMeIn, Inc.) – C:\Windows\SysNative\hamachi.sys
[2011/06/02 04:27:49 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
[2011/06/01 19:22:49 | 000,000,000 | —D | C] – C:\Users\Hung\AppData\Local\{5067E859-1C7E-42EC-BD48-ED16E7F2FF6F}
[2011/06/01 07:22:02 | 000,000,000 | —D | C] – C:\Users\Hung\AppData\Local\{1E6212A6-DFBD-48D4-9189-23F9F1610C73}
[2011/05/31 22:13:37 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UBCD4Win
[2011/05/31 22:12:05 | 000,000,000 | —D | C] – C:\UBCD4Win
[2011/05/31 16:38:27 | 000,000,000 | —D | C] – C:\Users\Hung\AppData\Local\{882EE9E8-007C-4C6E-8F9E-FF3905DDD367}
[2011/05/30 10:14:10 | 000,000,000 | —D | C] – C:\Users\Hung\AppData\Local\{79EA267F-6EB8-4B19-9E7A-0C93578AB8C2}
[2011/05/29 22:13:15 | 000,000,000 | —D | C] – C:\Users\Hung\AppData\Local\{7A4B53ED-3C0A-4211-B08D-A70BFB67C488}
[2011/05/28 21:08:40 | 000,000,000 | —D | C] – C:\Users\Hung\Documents\Witcher 2
[2011/05/28 21:08:40 | 000,000,000 | —D | C] – C:\Users\Hung\AppData\Local\The Witcher 2
[2011/05/28 13:41:44 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Witcher 2 Assassins of Kings
[2011/05/28 13:28:10 | 000,000,000 | —D | C] – C:\Program Files (x86)\Black_Box
[2011/05/27 23:57:49 | 000,000,000 | —D | C] – C:\Users\Hung\AppData\Local\{86803E9E-C984-4F66-A7B9-09EE54F0EC3E}
[2011/05/26 19:56:48 | 000,000,000 | —D | C] – C:\Users\Hung\AppData\Local\{ABE57FE4-4596-4422-BD0E-10CD30D154AA}
[2011/05/24 17:37:20 | 000,027,008 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\Diskdump.sys
[2011/05/24 17:23:08 | 000,000,000 | —D | C] – C:\Users\Hung\AppData\Local\{7E5115D5-4622-4BB4-ABBA-732D6F9C591A}
[2011/05/23 16:37:45 | 000,000,000 | —D | C] – C:\Users\Hung\AppData\Local\{21F3DEBE-476E-465A-93F0-0D44B2881877}
[2011/05/23 14:48:26 | 000,000,000 | -HSD | C] – C:\ProgramData\DSS
[2011/05/23 14:47:53 | 000,000,000 | —D | C] – C:\Users\Hung\AppData\Roaming\Lionhead Studios
[2011/05/23 14:31:24 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Games
[2011/05/21 21:37:54 | 000,123,904 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\poqexec.exe
[2011/05/21 21:37:53 | 000,142,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\poqexec.exe
[2011/05/20 21:21:51 | 000,000,000 | —D | C] – C:\Users\Hung\AppData\Local\{6C28E554-7DE3-4F54-9925-739CE9C854E0}
[2011/05/19 22:02:28 | 000,000,000 | —D | C] – C:\Users\Hung\AppData\Local\{D75D10AE-38AD-4A36-B334-D3996AC8F3CC}
[2011/05/19 22:01:58 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Java
[2011/05/19 22:01:28 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaws.exe
[2011/05/19 22:01:28 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaw.exe
[2011/05/19 22:01:28 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\java.exe
[2011/05/19 22:01:18 | 000,000,000 | —D | C] – C:\Program Files (x86)\Java
[2011/05/19 21:06:06 | 000,000,000 | —D | C] – C:\Users\Hung\AppData\Local\{FB670D1A-96D5-4F5A-B90A-2CD859A2FB12}
[2011/05/19 18:31:32 | 000,000,000 | —D | C] – C:\Users\Hung\AppData\Local\{7765174F-3D75-4125-8270-0BAC97C9F088}
[2011/05/17 19:21:22 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nexon
[2011/05/17 19:17:58 | 000,000,000 | —D | C] – C:\ProgramData\NexonUS
[2011/05/17 19:17:58 | 000,000,000 | —D | C] – C:\Nexon
[2011/05/17 15:52:33 | 000,000,000 | —D | C] – C:\Users\Hung\AppData\Local\{6F676026-1AE9-47EA-B13D-E4439958079A}
[2011/05/17 15:02:01 | 000,000,000 | —D | C] – C:\Users\Hung\AppData\Local\PMB Files
[2011/05/17 15:01:55 | 000,000,000 | —D | C] – C:\Program Files (x86)\Pando Networks
[2011/05/16 14:47:02 | 000,000,000 | —D | C] – C:\Users\Hung\AppData\Local\{1597536A-8FDC-4493-B5DB-34C0E85B2C4A}
[2011/05/16 00:22:14 | 000,000,000 | —D | C] – C:\Users\Hung\AppData\Local\{5E84BAF1-A4C8-42C1-87C6-09CBF9056D44}
[2011/05/15 12:21:28 | 000,000,000 | —D | C] – C:\Users\Hung\AppData\Local\{312729FF-C473-4E24-B739-CA3D969E5D2B}
[2011/05/14 20:19:47 | 000,000,000 | —D | C] – C:\Users\Hung\AppData\Local\{2F78CC7C-FDBB-45C4-88BF-2550EF0B22BA}
[2011/05/11 19:05:16 | 000,000,000 | —D | C] – C:\Users\Hung\AppData\Local\{CDE01BDF-8B09-48D9-9D32-AD1FB32776BC}
[2011/05/11 12:40:44 | 005,509,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2011/05/11 12:40:43 | 003,957,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2011/05/11 12:40:43 | 003,901,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2011/05/11 12:40:42 | 000,324,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\usbport.sys
[2011/05/11 12:40:42 | 000,007,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\usbd.sys
[2011/05/09 11:55:36 | 000,000,000 | —D | C] – C:\Users\Hung\AppData\Local\{6A636286-F0A9-46BF-81E8-2485D14919C1}
[2011/05/08 23:54:39 | 000,000,000 | —D | C] – C:\Users\Hung\AppData\Local\{6C385415-00ED-4E8A-B8B3-CD61802287EF}
[2011/05/08 11:53:53 | 000,000,000 | —D | C] – C:\Users\Hung\AppData\Local\{3292C414-05BA-4C61-B1F2-C76EBD76D571}
[2011/05/06 16:50:17 | 000,000,000 | —D | C] – C:\Users\Hung\AppData\Local\{2508E6DA-BD82-4A71-AD2D-C014288A96D3}
[2011/05/06 03:00:33 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games for Windows Marketplace
[2011/05/05 15:32:46 | 000,000,000 | —D | C] – C:\Users\Hung\AppData\Local\{C5E3B68D-643F-44FF-8E26-897353E9DE47}

========== Files - Modified Within 30 Days ==========

[2011/06/04 04:18:50 | 000,778,278 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/06/04 04:18:50 | 000,659,802 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/06/04 04:18:50 | 000,120,730 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/06/04 04:13:42 | 000,000,000 | —- | M] () – C:\Windows\SysNative\drivers\lvuvc.hs
[2011/06/04 04:13:40 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/06/04 04:13:36 | 2146,050,047 | -HS- | M] () – C:\hiberfil.sys
[2011/06/04 04:13:00 | 000,000,177 | -H– | M] () – C:\dvmexp.idx
[2011/06/04 03:45:00 | 000,000,904 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3223617834-2195742709-1650146780-1000UA.job
[2011/06/04 03:39:58 | 000,015,024 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/06/04 03:39:58 | 000,015,024 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/06/04 03:31:28 | 000,000,027 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2011/06/04 03:18:32 | 000,001,102 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/06/04 01:26:51 | 000,000,828 | —- | M] () – C:\Users\Public\Desktop\Start The Witcher 2.lnk
[2011/06/03 16:45:00 | 000,000,852 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3223617834-2195742709-1650146780-1000Core.job
[2011/05/31 22:13:37 | 000,001,325 | —- | M] () – C:\Users\Public\Desktop\UBCD4Win.lnk
[2011/05/26 18:39:42 | 000,002,358 | —- | M] () – C:\Users\Hung\Desktop\Google Chrome.lnk
[2011/05/19 22:01:18 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\deployJava1.dll
[2011/05/19 22:01:18 | 000,157,472 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaws.exe
[2011/05/19 22:01:18 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaw.exe
[2011/05/19 22:01:18 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\java.exe
[2011/05/17 19:21:22 | 000,000,204 | —- | M] () – C:\Users\Public\Desktop\MapleStory.url

========== Files Created - No Company Name ==========

[2011/06/04 03:18:32 | 000,001,114 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2011/06/04 03:18:32 | 000,001,102 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/06/04 02:58:00 | 000,256,512 | —- | C] () – C:\Windows\PEV.exe
[2011/06/04 02:58:00 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2011/06/04 02:58:00 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2011/06/04 02:58:00 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2011/06/04 02:58:00 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2011/06/04 01:26:51 | 000,000,828 | —- | C] () – C:\Users\Public\Desktop\Start The Witcher 2.lnk
[2011/05/31 22:13:37 | 000,001,325 | —- | C] () – C:\Users\Public\Desktop\UBCD4Win.lnk
[2011/05/17 19:21:22 | 000,000,204 | —- | C] () – C:\Users\Public\Desktop\MapleStory.url
[2011/04/21 21:13:11 | 000,033,792 | —- | C] () – C:\Windows\SysWow64\drivers\libusb0.sys
[2011/04/20 02:22:21 | 000,000,021 | —- | C] () – C:\Users\Hung\AppData\Roaming\.dolphinx64wd
[2011/04/09 18:55:28 | 000,179,261 | —- | C] () – C:\Windows\SysWow64\xlive.dll.cat
[2011/01/28 20:29:04 | 000,268,952 | —- | C] () – C:\Windows\SysWow64\PnkBstrB.exe
[2011/01/28 20:29:03 | 003,360,624 | —- | C] () – C:\Windows\SysWow64\pbsvc.exe
[2011/01/28 20:29:03 | 000,075,136 | —- | C] () – C:\Windows\SysWow64\PnkBstrA.exe
[2011/01/18 05:33:02 | 000,171,902 | —- | C] () – C:\Windows\hpoins37.dat
[2011/01/18 05:33:02 | 000,000,558 | —- | C] () – C:\Windows\hpomdl37.dat
[2011/01/11 02:22:59 | 000,000,533 | —- | C] () – C:\Windows\eReg.dat
[2011/01/07 21:34:41 | 000,765,362 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2010/12/02 12:31:21 | 000,000,000 | —- | C] () – C:\Windows\PowerReg.dat
[2010/11/17 21:46:15 | 000,000,056 | -H– | C] () – C:\Windows\SysWow64\ezsidmv.dat
[2010/11/11 17:29:32 | 000,000,262 | —- | C] () – C:\Windows\{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}_WiseFW.ini
[2010/11/10 23:37:15 | 000,004,096 | —- | C] () – C:\Windows\d3dx.dat
[2010/11/10 21:10:28 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat
[2010/11/10 20:54:06 | 000,073,728 | —- | C] () – C:\Windows\SysWow64\afasrv64.exe
[2010/11/10 20:13:57 | 000,001,769 | —- | C] () – C:\Windows\Language_trs.ini
[2010/11/10 20:13:51 | 000,029,196 | —- | C] () – C:\Windows\Ascd_tmp.ini
[2010/06/25 10:03:12 | 000,053,299 | —- | C] () – C:\Windows\SysWow64\pthreadVC.dll
[2009/07/13 22:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/13 19:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 19:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2009/07/13 17:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 16:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 14:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 14:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat
[2009/04/02 05:30:14 | 000,010,296 | —- | C] () – C:\Windows\SysWow64\drivers\ASUSHWIO.SYS
[2009/03/29 23:32:40 | 000,032,768 | R— | C] () – C:\Windows\DAODx.exe
[2008/12/01 19:32:32 | 000,362,029 | —- | C] () – C:\Windows\SysWow64\sqlite3.dll

< End of report >
Systemerr0r,

Double click on OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Processes

:OTL
PRC - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Discordia, LTD)
IE - HKLM\..\URLSearchHook: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\tbBit1.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\tbBit1.dll (Conduit Ltd.)
FF - prefs.js..browser.search.defaultenginename: "Web Search"
FF - prefs.js..browser.search.order.1: "Web Search"
FF - prefs.js..browser.search.selectedEngine: "Web Search"
FF - prefs.js..browser.startup.homepage: "http://www.searchqu.com/406"
FF - HKLM\software\mozilla\Firefox\Extensions\\{4bcdbfd0-fa26-11de-8a39-0800200c9a66}: C:\Users\Hung\AppData\Roaming\Mozilla\FireFox\{4bcdbfd0-fa26-11de-8a39-0800200c9a66} [2011/03/11 12:09:38 | 000,000,000 | —D | M]
[2011/05/01 15:52:02 | 000,000,000 | —D | M] (Searchqu Toolbar) – C:\Users\Hung\AppData\Roaming\Mozilla\Firefox\Profiles\q6qgx2pp.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}
O2:64bit: - BHO: (UrlHelper Class) - {A40DC6C5-79D0-4ca8-A185-8FF989AF1115} - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\IEBHO.dll (Discordia, LTD)
O4 - HKLM..\Run: [DATAMNGR] C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Discordia, LTD)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\x64\datamngr.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\datamngr.dll (Discordia, LTD)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\x64\IEBHO.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\IEBHO.dll (Discordia, LTD)
O20 - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\datamngr.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngr.dll (Discordia, LTD)
O20 - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\IEBHO.dll) - C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Discordia, LTD)

:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
  • Reboot your computer
Please post the OTL log.
All processes killed ========== PROCESSES ========== ========== OTL ========== No active process named Program Files was found! Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{88c7f2aa-f93f-432c-8f0e-b7d85967a527} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}\ not found. File C:\Program Files (x86)\BitTorrentBar\tbBit1.dll not found. Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{88c7f2aa-f93f-432c-8f0e-b7d85967a527} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}\ not found. File C:\Program Files (x86)\BitTorrentBar\tbBit1.dll not found. Prefs.js: "Web Search" removed from browser.search.defaultenginename Prefs.js: "Web Search" removed from browser.search.order.1 Prefs.js: "Web Search" removed from browser.search.selectedEngine Prefs.js: "http://www.searchqu.com/406" removed from browser.startup.homepage Registry value HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4bcdbfd0-fa26-11de-8a39-0800200c9a66} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4bcdbfd0-fa26-11de-8a39-0800200c9a66}\ not found. File C:\Users\Hung\AppData\Roaming\Mozilla\FireFox\{4bcdbfd0-fa26-11de-8a39-0800200c9a66} not found. Folder C:\Users\Hung\AppData\Roaming\Mozilla\Firefox\Profiles\q6qgx2pp.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\ not found. 64bit-Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}\ not found. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}\ not found. File C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\IEBHO.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\DATAMNGR not found. File C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngrUI.exe not found. 64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\PROGRA~2\WI3C8A~1\Datamngr\x64\datamngr.dll deleted successfully. File C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\datamngr.dll not found. 64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\PROGRA~2\WI3C8A~1\Datamngr\x64\IEBHO.dll deleted successfully. File C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\x64\IEBHO.dll not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\PROGRA~2\WI3C8A~1\Datamngr\datamngr.dll deleted successfully. File C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngr.dll not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\PROGRA~2\WI3C8A~1\Datamngr\IEBHO.dll deleted successfully. File C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\IEBHO.dll not found. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Hung ->Temp folder emptied: 1333226 bytes ->Temporary Internet Files folder emptied: 2293636 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 43946719 bytes ->Google Chrome cache emptied: 375204995 bytes ->Flash cache emptied: 2537 bytes User: Public ->Temp folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 314834 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 0 bytes %systemroot%\sysnative\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 0 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 403.00 mb OTL by OldTimer - Version 3.2.23.0 log created on 06062011_001153 Files\Folders moved on Reboot… C:\Users\Hung\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. File\Folder C:\Users\Hung\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1YTWXZT8\ADSAdClient31[3].txt not found! C:\Users\Hung\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1YTWXZT8\GRedirectCA4GUNQX.htm moved successfully. File move failed. C:\Windows\temp\logishrd\LVPrcInj01.dll scheduled to be moved on reboot. File move failed. C:\Windows\temp\logishrd\LVPrcInj02.dll scheduled to be moved on reboot. Registry entries deleted on Reboot…
i actually ran it once already this was the 2nd time i ran it. i was unable to find the log after i ran it the first time. it said it removed all the things you listed but i accidently closed the log and was unable to find it. unfortunately searchqu is still on my comp
Systemerr0r,

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://forums.whatthetech.com/How_Disable_…ams_t96260.html

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
ComboFix 11-06-06.03 - Hung 06/07/2011 0:45.3.6 - x64 Microsoft Windows 7 Home Premium 6.1.7600.3.1252.1.1033.18.8190.6009 [GMT -7:00] Running from: c:\users\[removed]\Downloads\ComboFix.exe SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Hung\AppData\Local\Temp\~6B82.tmp c:\users\Hung\AppData\Local\Temp\1.tmp\F_IN_BOX.dll c:\windows\TEMP\logishrd\LVPrcInj01.dll . . . . Failed to delete c:\windows\TEMP\logishrd\LVPrcInj02.dll . . . . Failed to delete . . ((((((((((((((((((((((((( Files Created from 2011-05-07 to 2011-06-07 ))))))))))))))))))))))))))))))) . . 2011-06-07 07:50 . 2011-06-07 07:50 ——– d—–w- c:\users\Default\AppData\Local\temp 2011-06-07 00:22 . 2011-06-07 00:23 ——– d—–w- c:\users\Hung\AppData\Local\{36813C50-C86D-4EA8-8F61-E63BEA259EDF} 2011-06-06 13:20 . 2011-06-06 13:20 ——– d—–w- c:\users\Hung\AppData\Roaming\LolClient 2011-06-06 12:34 . 2011-06-06 12:36 ——– d—–w- c:\users\Hung\AppData\Roaming\Synthesia 2011-06-06 12:29 . 2011-06-06 12:29 ——– d—–w- C:\Riot Games 2011-06-06 12:21 . 2011-06-06 12:22 ——– d—–w- c:\users\Hung\AppData\Local\{8437FFB6-D5F6-4DD9-856F-A043390E4AFB} 2011-06-06 12:12 . 2011-06-06 13:30 ——– d—–w- c:\programdata\PMB Files 2011-06-06 10:43 . 2011-06-06 11:16 ——– d—–w- C:\video_output 2011-06-06 10:40 . 2011-06-06 10:52 ——– d—–w- c:\program files (x86)\FLV to AVI MPEG WMV 3GP MP4 iPod Converter 2011-06-06 00:21 . 2011-06-06 00:21 ——– d—–w- c:\users\Hung\AppData\Local\{0608AB12-1258-4F9D-843C-38D2C30D7B30} 2011-06-05 12:20 . 2011-06-05 12:20 ——– d—–w- c:\users\Hung\AppData\Local\{6B3714B0-F0EB-4D7F-B368-64A50A3D656C} 2011-06-04 19:49 . 2011-06-04 19:49 ——– d—–w- c:\users\Hung\AppData\Local\{F94B69D2-B3C8-4BB7-A6E4-49121071535D} 2011-06-04 11:12 . 2011-06-04 11:12 ——– d—–w- C:\_OTL 2011-06-04 08:12 . 2011-06-04 08:32 ——– d—–w- c:\program files (x86)\The Witcher 2 2011-06-04 07:48 . 2011-06-04 07:48 ——– d—–w- c:\users\Hung\AppData\Local\{6ED49774-2113-472B-BE33-AF90A2EA4D50} 2011-06-03 19:47 . 2011-06-03 19:47 ——– d—–w- c:\users\Hung\AppData\Local\{ACE872A5-2A67-4778-BBB5-1BC6F45AD109} 2011-06-03 10:12 . 2011-05-09 22:00 8718160 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{8FAFE472-7F5F-48C6-855E-7BCDDF725F77}\mpengine.dll 2011-06-03 07:46 . 2011-06-03 07:47 ——– d—–w- c:\users\Hung\AppData\Local\{8248B709-7CBA-4947-9EB1-F793B09DBC6C} 2011-06-02 19:45 . 2011-06-02 19:45 ——– d—–w- c:\users\Hung\AppData\Local\{BFEFD427-532E-4A7E-A577-22D7044D9FA1} 2011-06-02 11:27 . 2009-03-19 00:35 33856 —ha-w- c:\windows\system32\hamachi.sys 2011-06-02 02:22 . 2011-06-02 02:23 ——– d—–w- c:\users\Hung\AppData\Local\{5067E859-1C7E-42EC-BD48-ED16E7F2FF6F} 2011-06-01 14:22 . 2011-06-01 14:22 ——– d—–w- c:\users\Hung\AppData\Local\{1E6212A6-DFBD-48D4-9189-23F9F1610C73} 2011-06-01 05:12 . 2011-06-01 05:15 ——– d—–w- C:\UBCD4Win 2011-05-31 23:38 . 2011-05-31 23:38 ——– d—–w- c:\users\Hung\AppData\Local\{882EE9E8-007C-4C6E-8F9E-FF3905DDD367} 2011-05-30 17:14 . 2011-05-31 05:15 ——– d—–w- c:\users\Hung\AppData\Local\{79EA267F-6EB8-4B19-9E7A-0C93578AB8C2} 2011-05-30 05:13 . 2011-05-30 05:13 ——– d—–w- c:\users\Hung\AppData\Local\{7A4B53ED-3C0A-4211-B08D-A70BFB67C488} 2011-05-29 04:08 . 2011-05-29 04:08 ——– d—–w- c:\users\Hung\AppData\Local\The Witcher 2 2011-05-28 20:28 . 2011-05-28 20:28 ——– d—–w- c:\program files (x86)\Black_Box 2011-05-28 06:57 . 2011-05-28 18:58 ——– d—–w- c:\users\Hung\AppData\Local\{86803E9E-C984-4F66-A7B9-09EE54F0EC3E} 2011-05-27 02:56 . 2011-05-27 02:57 ——– d—–w- c:\users\Hung\AppData\Local\{ABE57FE4-4596-4422-BD0E-10CD30D154AA} 2011-05-25 00:37 . 2011-04-22 20:18 27008 —-a-w- c:\windows\system32\drivers\Diskdump.sys 2011-05-25 00:23 . 2011-05-25 00:23 ——– d—–w- c:\users\Hung\AppData\Local\{7E5115D5-4622-4BB4-ABBA-732D6F9C591A} 2011-05-23 23:37 . 2011-05-23 23:38 ——– d—–w- c:\users\Hung\AppData\Local\{21F3DEBE-476E-465A-93F0-0D44B2881877} 2011-05-23 21:48 . 2011-05-23 21:48 ——– d-sh–w- c:\programdata\DSS 2011-05-23 21:47 . 2011-05-23 21:47 ——– d—–w- c:\users\Hung\AppData\Roaming\Lionhead Studios 2011-05-23 21:31 . 2011-05-23 21:31 ——– d—–w- c:\program files (x86)\Microsoft Games 2011-05-22 04:37 . 2011-04-09 05:56 123904 —-a-w- c:\windows\SysWow64\poqexec.exe 2011-05-22 04:37 . 2011-04-09 06:58 142336 —-a-w- c:\windows\system32\poqexec.exe 2011-05-21 04:21 . 2011-05-21 04:22 ——– d—–w- c:\users\Hung\AppData\Local\{6C28E554-7DE3-4F54-9925-739CE9C854E0} 2011-05-20 05:02 . 2011-05-20 05:02 ——– d—–w- c:\users\Hung\AppData\Local\{D75D10AE-38AD-4A36-B334-D3996AC8F3CC} 2011-05-20 05:01 . 2011-05-20 05:01 ——– d—–w- c:\program files (x86)\Common Files\Java 2011-05-20 05:01 . 2011-05-20 05:01 ——– d—–w- c:\program files (x86)\Java 2011-05-20 04:06 . 2011-05-20 04:06 ——– d—–w- c:\users\Hung\AppData\Local\{FB670D1A-96D5-4F5A-B90A-2CD859A2FB12} 2011-05-20 01:31 . 2011-05-20 01:31 ——– d—–w- c:\users\Hung\AppData\Local\{7765174F-3D75-4125-8270-0BAC97C9F088} 2011-05-18 02:17 . 2011-05-18 02:17 ——– d—–w- c:\programdata\NexonUS 2011-05-18 02:17 . 2011-05-18 02:17 ——– d—–w- C:\Nexon 2011-05-17 22:52 . 2011-05-17 22:52 ——– d—–w- c:\users\Hung\AppData\Local\{6F676026-1AE9-47EA-B13D-E4439958079A} 2011-05-17 22:02 . 2011-06-06 13:30 ——– d—–w- c:\users\Hung\AppData\Local\PMB Files 2011-05-17 22:01 . 2011-05-17 22:01 ——– d—–w- c:\program files (x86)\Pando Networks 2011-05-16 21:47 . 2011-05-16 21:47 ——– d—–w- c:\users\Hung\AppData\Local\{1597536A-8FDC-4493-B5DB-34C0E85B2C4A} 2011-05-16 07:22 . 2011-05-16 07:22 ——– d—–w- c:\users\Hung\AppData\Local\{5E84BAF1-A4C8-42C1-87C6-09CBF9056D44} 2011-05-15 19:21 . 2011-05-15 19:21 ——– d—–w- c:\users\Hung\AppData\Local\{312729FF-C473-4E24-B739-CA3D969E5D2B} 2011-05-15 03:19 . 2011-05-15 03:20 ——– d—–w- c:\users\Hung\AppData\Local\{2F78CC7C-FDBB-45C4-88BF-2550EF0B22BA} 2011-05-12 02:05 . 2011-05-12 02:05 ——– d—–w- c:\users\Hung\AppData\Local\{CDE01BDF-8B09-48D9-9D32-AD1FB32776BC} 2011-05-11 19:40 . 2011-04-09 06:45 5509504 —-a-w- c:\windows\system32\ntoskrnl.exe 2011-05-11 19:40 . 2011-04-09 06:13 3957632 —-a-w- c:\windows\SysWow64\ntkrnlpa.exe 2011-05-11 19:40 . 2011-04-09 06:13 3901824 —-a-w- c:\windows\SysWow64\ntoskrnl.exe 2011-05-11 19:40 . 2011-03-25 03:23 343040 —-a-w- c:\windows\system32\drivers\usbhub.sys 2011-05-11 19:40 . 2011-03-25 03:23 98816 —-a-w- c:\windows\system32\drivers\usbccgp.sys 2011-05-11 19:40 . 2011-03-25 03:23 324608 —-a-w- c:\windows\system32\drivers\usbport.sys 2011-05-11 19:40 . 2011-03-25 03:22 52224 —-a-w- c:\windows\system32\drivers\usbehci.sys 2011-05-11 19:40 . 2011-03-25 03:22 25600 —-a-w- c:\windows\system32\drivers\usbohci.sys 2011-05-11 19:40 . 2011-03-25 03:22 30720 —-a-w- c:\windows\system32\drivers\usbuhci.sys 2011-05-11 19:40 . 2011-03-25 03:22 7936 —-a-w- c:\windows\system32\drivers\usbd.sys 2011-05-09 18:55 . 2011-05-09 18:56 ——– d—–w- c:\users\Hung\AppData\Local\{6A636286-F0A9-46BF-81E8-2485D14919C1} 2011-05-09 06:54 . 2011-05-09 06:55 ——– d—–w- c:\users\Hung\AppData\Local\{6C385415-00ED-4E8A-B8B3-CD61802287EF} 2011-05-08 18:53 . 2011-05-08 18:54 ——– d—–w- c:\users\Hung\AppData\Local\{3292C414-05BA-4C61-B1F2-C76EBD76D571} . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-05-20 05:01 . 2010-12-18 10:07 472808 —-a-w- c:\windows\SysWow64\deployJava1.dll 2011-04-20 06:48 . 2011-04-20 06:49 521448 —-a-w- c:\windows\system32\deployJava1.dll 2011-04-10 01:55 . 2011-04-10 01:55 15453336 —-a-w- c:\windows\SysWow64\xlive.dll 2011-04-10 01:55 . 2011-04-10 01:55 13642904 —-a-w- c:\windows\SysWow64\xlivefnt.dll 2011-03-31 21:48 . 2011-03-31 21:48 86016 —-a-w- c:\windows\SysWow64\frapsvid.dll 2011-03-31 21:48 . 2011-03-31 21:48 84992 —-a-w- c:\windows\system32\frapsv64.dll 2011-03-20 05:22 . 2011-01-29 03:31 268952 —-a-w- c:\windows\SysWow64\PnkBstrB.xtr 2011-03-20 05:22 . 2011-01-29 03:29 268952 —-a-w- c:\windows\SysWow64\PnkBstrB.exe 2011-03-20 05:06 . 2011-01-29 03:29 268952 —-a-w- c:\windows\SysWow64\PnkBstrB.ex0 2011-03-19 00:12 . 2011-01-29 03:29 75136 —-a-w- c:\windows\SysWow64\PnkBstrA.exe 2011-03-12 12:03 . 2011-04-28 12:37 662528 —-a-w- c:\windows\system32\XpsPrint.dll 2011-03-12 11:31 . 2011-04-28 12:37 442880 —-a-w- c:\windows\SysWow64\XpsPrint.dll 2011-03-11 06:23 . 2011-04-28 12:36 187264 —-a-w- c:\windows\system32\drivers\storport.sys 2011-03-11 06:23 . 2011-04-28 12:36 1657216 —-a-w- c:\windows\system32\drivers\ntfs.sys 2011-03-11 06:23 . 2011-04-28 12:36 166272 —-a-w- c:\windows\system32\drivers\nvstor.sys 2011-03-11 06:23 . 2011-04-28 12:36 148352 —-a-w- c:\windows\system32\drivers\nvraid.sys 2011-03-11 06:23 . 2011-04-28 12:36 410496 —-a-w- c:\windows\system32\drivers\iaStorV.sys 2011-03-11 06:22 . 2011-04-28 12:36 107904 —-a-w- c:\windows\system32\drivers\amdsata.sys 2011-03-11 06:22 . 2011-04-28 12:36 27008 —-a-w- c:\windows\system32\drivers\amdxata.sys 2011-03-11 06:19 . 2011-04-15 19:24 1395712 —-a-w- c:\windows\system32\mfc42.dll 2011-03-11 06:19 . 2011-04-15 19:24 1359872 —-a-w- c:\windows\system32\mfc42u.dll 2011-03-11 06:18 . 2011-04-28 12:36 2566144 —-a-w- c:\windows\system32\esent.dll 2011-03-11 06:15 . 2011-04-28 12:36 96768 —-a-w- c:\windows\system32\fsutil.exe 2011-03-11 05:40 . 2011-04-15 19:24 1164288 —-a-w- c:\windows\SysWow64\mfc42u.dll 2011-03-11 05:40 . 2011-04-15 19:24 1137664 —-a-w- c:\windows\SysWow64\mfc42.dll 2011-03-11 05:39 . 2011-04-28 12:36 1686016 —-a-w- c:\windows\SysWow64\esent.dll 2011-03-11 05:37 . 2011-04-28 12:36 74240 —-a-w- c:\windows\SysWow64\fsutil.exe . . ((((((((((((((((((((((((((((( SnapShot@2011-06-04_10.08.17 ))))))))))))))))))))))))))))))))))))))))) . + 2010-11-11 03:37 . 2011-06-05 12:13 44994 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin + 2009-07-14 05:10 . 2011-06-06 07:14 29764 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin - 2009-07-14 05:10 . 2011-06-04 10:09 29764 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin + 2010-11-11 03:06 . 2011-06-06 07:14 13454 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3223617834-2195742709-1650146780-1000_UserData.bin - 2010-11-11 03:08 . 2011-06-04 10:08 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2010-11-11 03:08 . 2011-06-07 07:45 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2010-11-11 03:08 . 2011-06-04 10:08 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2010-11-11 03:08 . 2011-06-07 07:45 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2011-06-07 13:30 . 2011-06-07 13:30 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat - 2011-06-04 10:07 . 2011-06-04 10:07 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat - 2011-06-04 10:07 . 2011-06-04 10:07 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat + 2011-06-07 13:30 . 2011-06-07 13:30 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat + 2011-06-07 13:30 . 2009-10-07 09:46 131608 c:\windows\Temp\logishrd\LVPrcInj02.dll - 2011-06-04 10:08 . 2009-10-07 09:46 131608 c:\windows\Temp\logishrd\LVPrcInj02.dll + 2011-06-07 13:30 . 2009-10-07 09:47 109080 c:\windows\Temp\logishrd\LVPrcInj01.dll - 2011-06-04 10:08 . 2009-10-07 09:47 109080 c:\windows\Temp\logishrd\LVPrcInj01.dll - 2009-07-14 02:36 . 2011-06-03 19:16 659802 c:\windows\system32\perfh009.dat + 2009-07-14 02:36 . 2011-06-06 07:17 659802 c:\windows\system32\perfh009.dat - 2009-07-14 02:36 . 2011-06-03 19:16 120730 c:\windows\system32\perfc009.dat + 2009-07-14 02:36 . 2011-06-06 07:17 120730 c:\windows\system32\perfc009.dat + 2009-07-14 05:01 . 2011-06-07 07:50 388160 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat - 2009-07-14 05:01 . 2011-06-04 10:07 388160 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat + 2009-07-14 02:34 . 2011-06-06 18:27 10223616 c:\windows\system32\SMI\Store\Machine\schema.dat - 2009-07-14 02:34 . 2011-06-04 06:28 10223616 c:\windows\system32\SMI\Store\Machine\schema.dat + 2010-11-11 17:28 . 2011-06-07 07:50 11837788 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3223617834-2195742709-1650146780-1000-12288.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}] 2011-01-18 12:38 3911776 —-a-w- c:\program files (x86)\ConduitEngine\ConduitEngi0.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1475072] "RocketDock"="c:\program files (x86)\RocketDock\RocketDock.exe" [2007-09-02 495616] "AlcoholAutomount"="c:\program files (x86)\Alcohol Soft\Alcohol 120\axcmd.exe" [2009-09-18 205976] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "USBestCR"="c:\program files (x86)\cardicon\iconcs55926.exe" [2010-11-11 7373312] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288] "LogitechQuickCamRibbon"="c:\program files\Logitech\Logitech WebCam Software\LWS.exe" [2009-10-14 2793304] "HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2009-11-19 54576] "GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072] "Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2010-12-21 443728] "InternetDownload_upgrade"="c:\program files (x86)\Versalsoft\InternetDownload\InternetDownload.exe" [2010-03-09 394752] "InstaLAN"="c:\program files (x86)\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe" [2010-07-29 1485208] "amd_dc_opt"="c:\program files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2008-07-22 77824] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-01-07 253672] "LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2011-05-26 1951112] . c:\users\Hung\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ MagicDisc.lnk - c:\program files (x86)\MagicDisc\MagicDisc.exe [2010-11-13 576000] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2009-11-18 275072] McAfee Security Scan Plus.lnk - c:\program files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "mixer3"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R3 Asushwio;Asushwio;d:\bin\64bit\Asushwio.sys [x] R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys [x] R3 Futuremark SystemInfo Service;Futuremark SystemInfo Service;c:\program files (x86)\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe [2010-12-15 128928] R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184] S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x] S2 cpuz134;cpuz134;c:\windows\system32\drivers\cpuz134_x64.sys [x] S2 DvmMDES;DeviceVM Meta Data Export Service;c:\asus.sys\config\DVMExportService.exe [2009-10-16 319488] S2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [2011-05-26 2275720] S2 LVPrcS64;Process Monitor;c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe [2009-10-07 191000] S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2010-12-21 363344] S2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [x] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-01-08 378984] S3 ALSysIO;ALSysIO;c:\users\Hung\AppData\Local\Temp\ALSysIO64.sys [x] S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys [x] S3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys [x] S3 LVPr2M64;Logitech LVPr2M64 Driver;c:\windows\system32\DRIVERS\LVPr2M64.sys [x] S3 LVRS64;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs64.sys [x] S3 LVUVC64;QuickCam Communicate Deluxe(UVC);c:\windows\system32\DRIVERS\lvuvc64.sys [x] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x] S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc . Contents of the 'Scheduled Tasks' folder . 2011-06-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3223617834-2195742709-1650146780-1000Core.job - c:\users\Hung\AppData\Local\Google\Update\GoogleUpdate.exe [2011-02-03 07:18] . 2011-06-07 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3223617834-2195742709-1650146780-1000UA.job - c:\users\Hung\AppData\Local\Google\Update\GoogleUpdate.exe [2011-02-03 07:18] . . ——— x86-64 ———– . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "USBestCR"="c:\program files (x86)\cardicon\iconcs55926.exe" [2010-11-11 7373312] "Launch LCore"="c:\program files\Logitech Gaming Software\LCore.exe" [2010-11-16 104008] "Start WingMan Profiler"="c:\program files\Logitech\Gaming Software\LWEMon.exe" [2010-06-15 190536] . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://yahoo.com/ mLocal Page = c:\windows\SysWOW64\blank.htm mSearch Bar = hxxp://www.google.com IE: Download by Versalsoft Internet Download - c:\program files (x86)\Versalsoft\InternetDownload\adddownload.htm IE: E&xport to Microsoft Excel - c:\progra~2\MIF5BA~1\Office12\EXCEL.EXE/3000 FF - ProfilePath - c:\users\Hung\AppData\Roaming\Mozilla\Firefox\Profiles\q6qgx2pp.default\ FF - prefs.js: browser.search.selectedEngine - FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/ FF - user.js: network.protocol-handler.warn-external.dnupdate - false . - - - - ORPHANS REMOVED - - - - . BHO-{88c7f2aa-f93f-432c-8f0e-b7d85967a527} - (no file) . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\S-1-5-21-3223617834-2195742709-1650146780-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.Email.1" . [HKEY_USERS\S-1-5-21-3223617834-2195742709-1650146780-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.VCard.1" . [HKEY_USERS\S-1-5-21-3223617834-2195742709-1650146780-1000\Software\SecuROM\License information*] "datasecu"=hex:89,91,39,b0,2e,cb,e9,8b,fb,57,ff,45,02,9d,6d,d6,85,5d,f1,a6,9a, 8e,af,6d,24,fa,fe,97,fc,c0,38,60,73,24,0b,83,30,c9,d1,5e,c1,1c,82,5c,50,47,\ "rkeysecu"=hex:80,12,ab,e0,73,94,54,9a,64,a5,b4,02,d7,88,92,10 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10m_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10m_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10m.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10m.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10m.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10m.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files (x86)\Belkin\Router Setup and Monitor\BelkinService.exe c:\program files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe c:\windows\SysWOW64\PnkBstrA.exe c:\program files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe c:\program files (x86)\VentSrv\ventrilo_svc.exe c:\program files (x86)\VentSrv\ventrilo_srv.exe c:\windows\DAODx.exe c:\program files (x86)\Belkin\Router Setup and Monitor\BelkinSetup.exe c:\program files (x86)\Windows Media Player\wmplayer.exe c:\program files (x86)\Common Files\Logishrd\LQCVFX\COCIManager.exe c:\users\Hung\AppData\Local\Google\Chrome\Application\chrome.exe c:\windows\SysWOW64\rundll32.exe c:\users\Hung\AppData\Local\Google\Chrome\Application\chrome.exe c:\users\Hung\AppData\Local\Google\Chrome\Application\chrome.exe . ************************************************************************** . Completion time: 2011-06-07 06:35:21 - machine was rebooted ComboFix-quarantined-files.txt 2011-06-07 13:35 ComboFix2.txt 2011-06-04 10:35 . Pre-Run: 310,630,252,544 bytes free Post-Run: 310,352,637,952 bytes free . - - End Of File - - D0F01BF2F736D9BCC0FC6D45310915A6
Systemerr0r,

ESET Online Scanner:

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Vista users: You will need to to right-click on the either the IE or FF icon in the Start Menu or Quick Launch Bar on the Taskbar and select Run as Administrator from the context menu.

  • Please go here then click on: [external image: Posted Image]

    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.

  • Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: [external image: Posted Image]
  • The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on: [external image: Posted Image]
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.

Note: Do not forget to re-enable your Anti-Virus application after running the above scan!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI