This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

PING.EXE virus

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,
I am assuming that my pc is infected since the process ping.exe has been consuming almost 80%of my cpu. I have googled some stuff, and found a topic here someone complaining about the same thing, however he seemed to have it solved by its own, so there are no removal instructions that can help me. ı have been scanning the computer with lots of anti malware-spyware etc. scanners, and none of them seems to find anything suspicious. I would appreciate it if you can help.

I am posting the logs that OTL has produced:

OTL logfile created on: 19.10.2011 18:51:09 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\blur\Desktop
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 0000041f | Country: Türkiye | Language: TRK | Date Format: dd.MM.yyyy

3,85 Gb Total Physical Memory | 1,99 Gb Available Physical Memory | 51,68% Memory free
7,71 Gb Paging File | 5,49 Gb Available in Paging File | 71,25% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 162,00 Gb Total Space | 123,04 Gb Free Space | 75,95% Space Free | Partition Type: NTFS
Drive D: | 115,99 Gb Total Space | 23,20 Gb Free Space | 20,00% Space Free | Partition Type: NTFS

Computer Name: SHARPEN | User Name: blur | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\blur\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe (ESET)
PRC - C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe ()
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe ()
PRC - C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
PRC - C:\Program Files (x86)\ESET\ESET Online Scanner\OnlineScannerApp.exe (ESET)
PRC - C:\Program Files (x86)\ESET\ESET Online Scanner\OnlineCmdLineScanner.exe ()
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\IObit\IObit Security 360\is360.exe (IObit)
PRC - C:\Program Files (x86)\CyberLink\YouCam\YouCamTray.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe (CyberLink)
PRC - C:\Program Files (x86)\IObit\IObit Security 360\is360tray.exe (IObit)
PRC - C:\Program Files (x86)\IObit\IObit Security 360\is360srv.exe (IObit)
PRC - C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe (Broadcom Corporation.)
PRC - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
PRC - C:\Windows\SysWOW64\PING.EXE (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\1690c0d482ffd8105fc6e573a1d84ed8\System.Management.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Remo#\afb98d0ba0006a3dece48623712f61b1\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\bf5ca252df4083e6c48dc3e9f3273cf5\System.Xaml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\94d1a597707960b7f6f87e96ef69e371\IAStorUtil.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\b2622080e047040fa044dd21a04ff10d\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\6e592e424a204aafeadbe22b6b31b9db\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\3b2cfd85528a27eb71dc41d8067359a1\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\d7a64c28cf0c90e6c48af4f7d6f9ed41\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\130ad4d9719e566ca933ac7158a04203\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\2d5bcbeb9475ef62189f605bcca1cec6\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\abab08afa60a6f06bdde0fcc9649c379\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\a1a82db68b3badc7c27ea1f6579d22c5\mscorlib.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\9565982f271da74fd952906f9b6a88c9\PresentationFramework.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\0d5d26ed41c8fa0c7feb00ef5343299a\PresentationCore.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\d08e6e917f08ef674373576016969a20\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\acf4f694ab9c0b1802e83e5cd726812f\System.Core.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\1924bdaf130f882ceaf9d7b880602d22\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\a4a330e92cbd3457b3f00ae367a4bc5f\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\2807b771372137d41fb8d392a878d0c7\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\b680bfc9e268e756f86980bb47b7d330\PresentationFramework.Aero.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System\f477a17590634925c583632d171e2726\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\e360aa959e1b83be7026670d129c0a93\mscorlib.ni.dll ()
MOD - C:\Users\blur\AppData\Local\Google\Chrome\Application\14.0.835.202\ppgooglenaclpluginchrome.dll ()
MOD - C:\Users\blur\AppData\Local\Google\Chrome\Application\14.0.835.202\pdf.dll ()
MOD - C:\Users\blur\AppData\Local\Google\Chrome\Application\14.0.835.202\avutil-51.dll ()
MOD - C:\Users\blur\AppData\Local\Google\Chrome\Application\14.0.835.202\avformat-53.dll ()
MOD - C:\Users\blur\AppData\Local\Google\Chrome\Application\14.0.835.202\avcodec-53.dll ()
MOD - C:\Users\blur\AppData\Local\Google\Chrome\Application\14.0.835.202\gcswf32.dll ()
MOD - C:\Users\blur\AppData\Local\Temp\3dcf2df1-2a83-477c-a7dd-858967792357\CliSecureRT.dll ()
MOD - C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe ()
MOD - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe ()
MOD - C:\Program Files (x86)\ESET\ESET Online Scanner\OnlineCmdLineScanner.exe ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - \\?\globalroot\systemroot\syswow64\mswsock.DLL ()
MOD - \\.\globalroot\systemroot\syswow64\mswsock.dll ()
MOD - C:\Program Files (x86)\IObit\IObit Security 360\sqlite3.dll ()
MOD - C:\Program Files (x86)\IObit\IObit Security 360\madbasic_.bpl ()
MOD - C:\Program Files (x86)\IObit\IObit Security 360\maddisAsm_.bpl ()
MOD - C:\Program Files (x86)\IObit\IObit Security 360\taskdll.dll ()
MOD - C:\Program Files (x86)\Samsung\Easy Display Manager\HookDllPS2.dll ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (ekrn) – C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe (ESET)
SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (btwdins) – C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Broadcom Corporation.)
SRV:64bit: - (wltrysvc) – C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRYSVC.EXE (Broadcom Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (MBAMService) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (CDMA Device Service) – C:\Program Files (x86)\Samsung\USB Drivers\26_VIA_driver2\amd64\VIAService.exe ()
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (IS360service) – C:\Program Files (x86)\IObit\IObit Security 360\is360srv.exe (IObit)
SRV - (IAStorDataMgrSvc) Intel® – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (dtsoftbus01) – C:\Windows\SysNative\drivers\dtsoftbus01.sys (DT Soft Ltd)
DRV:64bit: - (MBAMProtector) – C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (eamonm) – C:\Windows\SysNative\drivers\eamonm.sys (ESET)
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (btwampfl) – C:\Windows\SysNative\drivers\btwampfl.sys (Broadcom Corporation.)
DRV:64bit: - (btwavdt) – C:\Windows\SysNative\drivers\btwavdt.sys (Broadcom Corporation.)
DRV:64bit: - (btwaudio) – C:\Windows\SysNative\drivers\btwaudio.sys (Broadcom Corporation.)
DRV:64bit: - (btwl2cap) – C:\Windows\SysNative\drivers\btwl2cap.sys (Broadcom Corporation.)
DRV:64bit: - (btwrchid) – C:\Windows\SysNative\drivers\btwrchid.sys (Broadcom Corporation.)
DRV:64bit: - (Impcd) – C:\Windows\SysNative\drivers\Impcd.sys (Intel Corporation)
DRV:64bit: - (AtiHdmiService) – C:\Windows\SysNative\drivers\AtiHdmi.sys (ATI Technologies, Inc.)
DRV:64bit: - (ehdrv) – C:\Windows\SysNative\drivers\ehdrv.sys (ESET)
DRV:64bit: - (epfwwfpr) – C:\Windows\SysNative\drivers\epfwwfpr.sys (ESET)
DRV:64bit: - (dc3d) – C:\Windows\SysNative\drivers\dc3d.sys (Microsoft Corporation)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (dmvsc) – C:\Windows\SysNative\drivers\dmvsc.sys (Microsoft Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbGD) – C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (clwvd) – C:\Windows\SysNative\drivers\clwvd.sys (CyberLink Corporation)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (BCM43XX) – C:\Windows\SysNative\drivers\BCMWL664.SYS (Broadcom Corporation)
DRV:64bit: - (BCM42RLY) – C:\Windows\SysNative\drivers\bcm42rly.sys (Broadcom Corporation)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (yukonw7) – C:\Windows\SysNative\drivers\yk62x64.sys (Marvell)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (SABI) – C:\Windows\SysNative\drivers\SABI.sys (SAMSUNG ELECTRONICS)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://tr.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = tr
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 03 AB 9C 82 DA 8C CC 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.flickr.com/explore"
FF - prefs.js..network.proxy.type: 0

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\blur\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\blur\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\blur\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)

64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\[removed]: C:\PROGRAM FILES\ESET\ESET NOD32 ANTIVIRUS\MOZILLA THUNDERBIRD [2011.10.19 09:33:44 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011.10.09 22:24:28 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\[removed]: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2011.10.19 09:33:44 | 000,000,000 | —D | M]

[2011.08.31 22:13:50 | 000,000,000 | —D | M] (No name found) – C:\Users\blur\AppData\Roaming\Mozilla\Extensions
[2011.09.03 02:29:56 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2011.10.01 13:51:54 | 000,000,000 | —D | M] (Skype Click to Call) – C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2011.09.03 02:29:56 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA}
[2011.09.08 02:22:11 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011.08.30 23:41:12 | 000,001,538 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\amazon-en-GB.xml
[2011.08.30 23:29:49 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2011.08.30 23:41:12 | 000,000,947 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\chambers-en-GB.xml
[2011.08.30 23:41:12 | 000,001,180 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-en-GB.xml
[2011.08.30 23:41:12 | 000,001,135 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-en-GB.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\blur\AppData\Local\Google\Chrome\Application\14.0.835.202\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: Java Deployment Toolkit 6.0.270.7 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U27 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\blur\AppData\Local\Google\Chrome\Application\14.0.835.202\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\blur\AppData\Local\Google\Chrome\Application\14.0.835.202\pdf.dll
CHR - plugin: Skype Toolbars (Enabled) = C:\Users\blur\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.6.0.8312_0\npSkypeChromePlugin.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: Google Update (Enabled) = C:\Users\blur\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Planeto Quiz = C:\Users\blur\AppData\Local\Google\Chrome\User Data\Default\Extensions\caekfgjhgmkgdhbiaikgdbpldepnkchg\1.0.3_0\
CHR - Extension: Skype Click to Call = C:\Users\blur\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.6.0.8312_0\
CHR - Extension: Robot Theme, inspired by Android\u2122 = C:\Users\blur\AppData\Local\Google\Chrome\User Data\Default\Extensions\oeljdmeofcikjblcoehpmdnooimalbmj\0.2.2_0\

Hosts file not found
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O4:64bit: - HKLM..\Run: [Broadcom Wireless Manager UI] C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.EXE (Broadcom Corporation)
O4:64bit: - HKLM..\Run: [egui] C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)
O4:64bit: - HKLM..\Run: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
O4:64bit: - HKLM..\Run: [Logitech Download Assistant] C:\Windows\SysNative\LogiLDA.dll (Logitech, Inc.)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [IObit Security 360] C:\Program Files (x86)\IObit\IObit Security 360\IS360tray.exe (IObit)
O4 - HKLM..\Run: [KiesHelper] C:\Program Files (x86)\Samsung\Kies\KiesHelper.exe (Samsung)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [YouCam Mirage] C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe (CyberLink)
O4 - HKLM..\Run: [YouCam Tray] C:\Program Files (x86)\CyberLink\YouCam\YouCamTray.exe (CyberLink Corp.)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKCU..\Run: [Facebook Update] C:\Users\blur\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKCU..\Run: [KiesPDLR] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe ()
O4 - HKCU..\Run: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O8:64bit: - Extra context menu item: Send image to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8:64bit: - Extra context menu item: Send page to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O8 - Extra context menu item: Send image to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send page to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra Button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra 'Tools' menuitem : @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Send to &Bluetooth Device… - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000009 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000010 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000011 - mmswsock.dll File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_27)
O16 - DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_27)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_27)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5D357BFD-6119-4B9A-867D-DB69E08F676E}: DhcpNameServer = [removed] [removed]
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) -C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011.10.19 18:40:15 | 000,000,000 | —D | C] – C:\Program Files (x86)\ESET
[2011.10.19 18:37:05 | 000,000,000 | —D | C] – C:\_OTL
[2011.10.19 18:21:08 | 000,000,000 | —D | C] – C:\Users\blur\AppData\Local\Facebook
[2011.10.19 18:19:59 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Users\blur\Desktop\OTL.exe
[2011.10.19 18:17:54 | 001,559,856 | —- | C] (Kaspersky Lab ZAO) – C:\Users\blur\Desktop\TDSSKiller.exe
[2011.10.19 17:32:45 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Security 360
[2011.10.19 17:32:43 | 000,000,000 | —D | C] – C:\Users\blur\AppData\Roaming\IObit
[2011.10.19 17:32:41 | 000,000,000 | —D | C] – C:\ProgramData\IObit
[2011.10.19 17:32:38 | 000,000,000 | —D | C] – C:\Program Files (x86)\IObit
[2011.10.19 10:12:27 | 000,000,000 | —D | C] – C:\Users\blur\AppData\Roaming\Malwarebytes
[2011.10.19 10:12:22 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011.10.19 10:12:21 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2011.10.19 10:12:18 | 000,025,416 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2011.10.19 10:12:18 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011.10.19 10:00:02 | 000,000,000 | —D | C] – C:\Users\blur\AppData\Local\ESET
[2011.10.19 09:47:29 | 004,845,856 | —- | C] (Sysinternals - www.sysinternals.com) – C:\Users\blur\Desktop\procexp.exe
[2011.10.19 09:33:44 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET
[2011.10.19 09:33:44 | 000,000,000 | —D | C] – C:\ProgramData\ESET
[2011.10.19 09:33:44 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2011.10.18 22:40:20 | 000,000,000 | —D | C] – C:\Windows\system64
[2011.10.12 21:14:26 | 000,702,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2011.10.12 21:14:26 | 000,247,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2011.10.12 21:14:26 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2011.10.12 21:14:26 | 000,134,144 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2011.10.12 21:14:26 | 000,132,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2011.10.12 21:14:26 | 000,097,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011.10.12 21:14:26 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011.10.12 21:14:02 | 000,613,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\psisdecd.dll
[2011.10.12 21:14:02 | 000,465,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\psisdecd.dll
[2011.10.12 21:14:02 | 000,108,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\psisrndr.ax
[2011.10.12 21:14:02 | 000,075,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\psisrndr.ax
[2011.10.12 21:12:49 | 000,861,696 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleaut32.dll
[2011.10.12 21:12:49 | 000,331,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleacc.dll
[2011.10.09 22:25:13 | 000,000,000 | —D | C] – C:\Users\blur\AppData\Roaming\Apple Computer
[2011.10.09 22:25:13 | 000,000,000 | —D | C] – C:\Users\blur\AppData\Local\Apple Computer
[2011.10.09 22:25:11 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011.10.09 22:25:05 | 000,126,312 | —- | C] (GEAR Software Inc.) – C:\Windows\SysNative\GEARAspi64.dll
[2011.10.09 22:25:05 | 000,107,368 | —- | C] (GEAR Software Inc.) – C:\Windows\SysWow64\GEARAspi.dll
[2011.10.09 22:25:05 | 000,034,152 | —- | C] (GEAR Software Inc.) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys
[2011.10.09 22:25:05 | 000,000,000 | —D | C] – C:\Windows\SysNative\DRVSTORE
[2011.10.09 22:24:53 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2011.10.09 22:24:53 | 000,000,000 | —D | C] – C:\Program Files (x86)\iTunes
[2011.10.09 22:24:53 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2011.10.09 22:24:53 | 000,000,000 | —D | C] – C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
[2011.10.09 22:24:24 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2011.10.09 22:24:21 | 000,000,000 | —D | C] – C:\Program Files (x86)\QuickTime
[2011.10.09 22:24:20 | 000,000,000 | —D | C] – C:\ProgramData\Apple Computer
[2011.10.09 22:24:13 | 000,000,000 | —D | C] – C:\Users\blur\AppData\Local\Apple
[2011.10.09 22:24:11 | 000,000,000 | —D | C] – C:\Program Files (x86)\Apple Software Update
[2011.10.09 22:24:01 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Apple
[2011.10.09 22:23:53 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2011.10.09 22:23:53 | 000,000,000 | —D | C] – C:\Program Files (x86)\Bonjour
[2011.10.09 22:23:47 | 000,000,000 | —D | C] – C:\ProgramData\Apple
[2011.10.09 22:23:47 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Apple
[2011.10.09 22:14:17 | 000,000,000 | —D | C] – C:\Users\blur\Desktop\Docs
[2011.09.26 14:41:33 | 000,000,000 | —D | C] – C:\Program Files\Lexmark
[2011.09.22 02:42:49 | 000,000,000 | —D | C] – C:\Program Files\SAMSUNG
[2011.09.22 02:10:51 | 000,000,000 | —D | C] – C:\Users\blur\AppData\Local\Samsung
[2011.09.22 02:10:35 | 000,000,000 | —D | C] – C:\Users\blur\Documents\samsung
[2011.09.22 02:08:59 | 004,659,712 | —- | C] (Dmitry Streblechenko) – C:\Windows\SysWow64\Redemption.dll
[2011.09.22 02:08:51 | 000,821,824 | —- | C] (Devguru Co., Ltd.) – C:\Windows\SysWow64\dgderapi.dll
[2011.09.22 02:08:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\MarkAny
[2011.09.22 02:08:37 | 000,000,000 | —D | C] – C:\Users\blur\AppData\Roaming\Samsung
[2011.09.22 02:07:47 | 000,000,000 | —D | C] – C:\Users\blur\AppData\Local\Downloaded Installations
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011.10.19 18:26:01 | 000,000,924 | —- | M] () – C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-627378357-1148813155-1286181338-1000UA.job
[2011.10.19 18:26:00 | 000,000,902 | —- | M] () – C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-627378357-1148813155-1286181338-1000Core.job
[2011.10.19 18:19:58 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\blur\Desktop\OTL.exe
[2011.10.19 18:10:00 | 000,000,904 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-627378357-1148813155-1286181338-1000UA.job
[2011.10.19 17:35:51 | 000,022,032 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011.10.19 17:35:51 | 000,022,032 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011.10.19 17:34:00 | 000,001,365 | —- | M] () – C:\Users\blur\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011.10.19 17:33:14 | 000,620,290 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011.10.19 17:33:14 | 000,110,478 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011.10.19 17:32:46 | 000,001,164 | —- | M] () – C:\Users\Public\Desktop\IObit Security 360.lnk
[2011.10.19 17:28:04 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011.10.19 17:27:59 | 3103,387,648 | -HS- | M] () – C:\hiberfil.sys
[2011.10.19 14:53:40 | 000,726,316 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011.10.19 13:55:38 | 001,559,856 | —- | M] (Kaspersky Lab ZAO) – C:\Users\blur\Desktop\TDSSKiller.exe
[2011.10.18 22:52:01 | 000,000,324 | —- | M] () – C:\Windows\tasks\At5.job
[2011.10.18 22:48:01 | 000,000,324 | —- | M] () – C:\Windows\tasks\At4.job
[2011.10.18 22:44:20 | 000,000,324 | —- | M] () – C:\Windows\tasks\At3.job
[2011.10.18 22:40:19 | 000,000,324 | —- | M] () – C:\Windows\tasks\At2.job
[2011.10.18 22:36:18 | 000,000,324 | —- | M] () – C:\Windows\tasks\At1.job
[2011.10.18 22:36:14 | 000,058,668 | -HS- | M] () – C:\Windows\comset32.exe
[2011.10.18 22:10:00 | 000,000,852 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-627378357-1148813155-1286181338-1000Core.job
[2011.10.16 01:42:57 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2011.10.14 17:19:03 | 000,008,041 | —- | M] () – C:\Users\blur\Desktop\Omegle conversation log.html
[2011.10.14 03:45:23 | 000,343,472 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2011.10.05 23:45:47 | 000,095,675 | —- | M] () – C:\Users\blur\Desktop\ff.PNG
[2011.10.04 21:02:10 | 000,901,121 | —- | M] () – C:\Users\blur\Desktop\301Exps.pdf
[2011.09.22 02:09:02 | 000,001,977 | —- | M] () – C:\Users\blur\Application Data\Microsoft\Internet Explorer\Quick Launch\Samsung Kies.lnk
[2011.09.19 22:45:21 | 000,278,899 | —- | M] () – C:\Users\blur\Desktop\Aperture_Science_Portal_Wanted_Ad.png
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011.10.19 18:21:15 | 000,000,924 | —- | C] () – C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-627378357-1148813155-1286181338-1000UA.job
[2011.10.19 18:21:15 | 000,000,902 | —- | C] () – C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-627378357-1148813155-1286181338-1000Core.job
[2011.10.19 17:32:46 | 000,001,164 | —- | C] () – C:\Users\Public\Desktop\IObit Security 360.lnk
[2011.10.18 22:36:14 | 000,058,668 | -HS- | C] () – C:\Windows\comset32.exe
[2011.10.16 01:42:57 | 000,000,000 | -H– | C] () – C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2011.10.14 17:19:07 | 000,008,041 | —- | C] () – C:\Users\blur\Desktop\Omegle conversation log.html
[2011.10.09 22:24:11 | 000,002,519 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
[2011.10.05 23:44:53 | 000,095,675 | —- | C] () – C:\Users\blur\Desktop\ff.PNG
[2011.10.04 21:02:31 | 000,901,121 | —- | C] () – C:\Users\blur\Desktop\301Exps.pdf
[2011.09.22 02:09:02 | 000,001,977 | —- | C] () – C:\Users\blur\Application Data\Microsoft\Internet Explorer\Quick Launch\Samsung Kies.lnk
[2011.09.19 22:45:20 | 000,278,899 | —- | C] () – C:\Users\blur\Desktop\Aperture_Science_Portal_Wanted_Ad.png
[2011.08.31 23:07:54 | 000,165,376 | —- | C] () – C:\Windows\SysWow64\unrar.dll
[2011.08.31 23:07:53 | 000,810,496 | —- | C] () – C:\Windows\SysWow64\xvidcore.dll
[2011.08.31 23:07:53 | 000,183,808 | —- | C] () – C:\Windows\SysWow64\xvidvfw.dll
[2011.08.31 23:07:53 | 000,080,896 | —- | C] () – C:\Windows\SysWow64\ff_vfw.dll
[2011.08.31 23:07:53 | 000,000,038 | —- | C] () – C:\Windows\avisplitter.ini
[2011.08.31 14:11:58 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2011.07.26 17:26:48 | 000,030,568 | —- | C] () – C:\Windows\MusiccityDownload.exe
[2011.07.26 17:26:46 | 000,974,848 | —- | C] () – C:\Windows\SysWow64\cis-2.4.dll
[2011.07.26 17:26:46 | 000,081,920 | —- | C] () – C:\Windows\SysWow64\issacapi_bs-2.3.dll
[2011.07.26 17:26:46 | 000,065,536 | —- | C] () – C:\Windows\SysWow64\issacapi_pe-2.3.dll
[2011.07.26 17:26:46 | 000,057,344 | —- | C] () – C:\Windows\SysWow64\issacapi_se-2.3.dll
[2010.06.16 07:28:58 | 000,002,857 | —- | C] () – C:\Windows\SysWow64\atipblag.dat
[2009.07.14 08:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009.07.14 05:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2009.07.14 05:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2009.07.14 03:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009.07.14 02:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009.07.14 00:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009.06.11 00:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat

========== LOP Check ==========

[2011.10.18 00:09:56 | 000,000,000 | —D | M] – C:\Users\blur\AppData\Roaming\DAEMON Tools Lite
[2011.10.19 17:32:43 | 000,000,000 | —D | M] – C:\Users\blur\AppData\Roaming\IObit
[2011.09.18 14:51:28 | 000,000,000 | —D | M] – C:\Users\blur\AppData\Roaming\Juniper Networks
[2011.09.01 23:54:25 | 000,000,000 | —D | M] – C:\Users\blur\AppData\Roaming\LolClient
[2011.10.07 02:19:54 | 000,000,000 | —D | M] – C:\Users\blur\AppData\Roaming\PhotoScape
[2011.09.22 02:08:37 | 000,000,000 | —D | M] – C:\Users\blur\AppData\Roaming\Samsung
[2011.10.19 09:07:32 | 000,000,000 | —D | M] – C:\Users\blur\AppData\Roaming\uTorrent
[2011.10.18 22:36:18 | 000,000,324 | —- | M] () – C:\Windows\Tasks\At1.job
[2011.10.18 22:40:19 | 000,000,324 | —- | M] () – C:\Windows\Tasks\At2.job
[2011.10.18 22:44:20 | 000,000,324 | —- | M] () – C:\Windows\Tasks\At3.job
[2011.10.18 22:48:01 | 000,000,324 | —- | M] () – C:\Windows\Tasks\At4.job
[2011.10.18 22:52:01 | 000,000,324 | —- | M] () – C:\Windows\Tasks\At5.job
[2011.10.19 18:26:00 | 000,000,902 | —- | M] () – C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-627378357-1148813155-1286181338-1000Core.job
[2011.10.19 18:26:01 | 000,000,924 | —- | M] () – C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-627378357-1148813155-1286181338-1000UA.job
[2009.07.14 08:08:49 | 000,009,814 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========




< End of report >


Extras:

OTL Extras logfile created on: 19.10.2011 18:51:09 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\blur\Desktop
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 0000041f | Country: Türkiye | Language: TRK | Date Format: dd.MM.yyyy

3,85 Gb Total Physical Memory | 1,99 Gb Available Physical Memory | 51,68% Memory free
7,71 Gb Paging File | 5,49 Gb Available in Paging File | 71,25% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 162,00 Gb Total Space | 123,04 Gb Free Space | 75,95% Space Free | Partition Type: NTFS
Drive D: | 115,99 Gb Total Space | 23,20 Gb Free Space | 20,00% Space Free | Partition Type: NTFS

Computer Name: SHARPEN | User Name: blur | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{10E5F3FF-AD93-40C5-A0F5-13B9185DBB12}" = ESET NOD32 Antivirus
"{436E0B79-2CFB-4E5F-9380-E17C1B25D0C5}" = WIDCOMM Bluetooth Software
"{439760BC-7737-4386-9B1D-A90A3E8A22EA}" = Apple Mobile Device Support
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{5635224E-675C-B94C-43EE-70BCD39BF30B}" = ATI Catalyst Install Manager
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8924153C-F29D-3F27-3AAB-389F3B661AD4}" = ccc-utility64
"{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010
"{90140000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2010
"{90140000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010
"{997C9EC4-B53D-479D-81B7-0AEC8D174BA1}" = iTunes
"{CA0D2F09-F811-48D4-843E-C87696C6A9D9}" = Bonjour
"{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"Broadcom Wireless Utility" = Broadcom Wireless Utility
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"WinRAR archiver" = WinRAR 4.00 (64-bit)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01501EBA-EC35-4F9F-8889-3BE346E5DA13}" = MSXML4 Parser
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"{02F3B756-11B3-8077-7FA7-709DDDBAEFD3}" = CCC Help French
"{0620AFAE-46B1-AECB-0D8D-DC6884F72BF5}" = Catalyst Control Center Localization All
"{0DFD17F6-0EFB-3CBA-0692-ED193A6F847A}" = CCC Help Norwegian
"{11060D31-08ED-8F55-BB38-0F194E0FE68E}" = CCC Help German
"{17283B95-21A8-4996-97DA-547A48DB266F}" = Easy Display Manager
"{21F22617-30EA-55D0-C023-574DEFA72935}" = CCC Help English
"{24691EC2-44CA-88CE-D7D8-673C9C21DABB}" = CCC Help Czech
"{26A24AE4-039D-4CA4-87B4-2F83216027FF}" = Java™ 6 Update 27
"{2ABC63E9-8E74-F261-4937-C49438279633}" = ccc-core-static
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel® Rapid Storage Technology
"{41EB4D8C-797B-88DA-9CFD-C265BDEF3BE7}" = CCC Help Greek
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{51C7AD07-C3F6-4635-8E8A-231306D810FE}" = Cisco LEAP Module
"{56FD9B91-F0EE-A2AE-7289-28E3110C0D08}" = CCC Help Swedish
"{58240652-2AC8-80E3-B980-7E6F58D64CB3}" = CCC Help Japanese
"{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}" = Cisco EAP-FAST Module
"{690E2911-8512-65D8-1237-A0E43865F226}" = Catalyst Control Center Graphics Previews Common
"{6C7CF28E-535B-D453-E935-524116E5D8F3}" = CCC Help Portuguese
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"{765DB2B0-943A-1F96-AA98-0DE4BD5ECF98}" = Catalyst Control Center InstallProxy
"{77AA84F1-4A5F-34F6-E9FB-75B234E36748}" = CCC Help Korean
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{90140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{918A9082-6287-4D25-9002-5E5D5E4971CB}" = League of Legends
"{976A7F36-3904-3444-588F-A4A47DA7DAAA}" = CCC Help Hungarian
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9E77CE91-C520-6284-5340-2FED3E34537F}" = CCC Help Chinese Standard
"{A4A3BD6D-F267-199A-F402-AC9D8C6A5A1F}" = CCC Help Thai
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.0)
"{B3575D00-27EF-49C2-B9E0-14B3D954E992}" = Apple Application Support
"{B4E5E04E-3738-2736-4925-267AB9A313B0}" = CCC Help Spanish
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{B6D8DC8C-F077-4631-A221-4D5E1D8E87E7}" = Catalyst Control Center - Branding
"{B7DB6FC7-631D-8767-A3DF-4B1467611D3C}" = CCC Help Turkish
"{BCE95123-10EF-BF71-EFCC-27413278630B}" = CCC Help Italian
"{BD2E478F-C249-FF8B-F544-E22061BA03C5}" = CCC Help Russian
"{C96BDE6D-EA35-1445-1E08-634171AE3C82}" = CCC Help Chinese Traditional
"{C9E14402-3631-4182-B377-6B0DFB1C0339}" = QuickTime
"{D6C630BF-8DBB-4042-8562-DC9A52CB6E7E}" = Intel® Turbo Boost Technology Driver
"{DD048DE6-3FD4-F4C2-A98D-A185CA4D94BA}" = CCC Help Danish
"{DD953122-ECF9-E725-AF9C-BA4C08AAC1B1}" = Catalyst Control Center Graphics Previews Vista
"{E912365F-9F51-C5A0-8153-FEFCFF276608}" = CCC Help Polish
"{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}" = Cisco PEAP Module
"{ED721ABC-423D-4F7D-AEBB-E1E39C388E84}" = Facebook Video Calling 1.0.0.8714
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F6AD00BA-3229-D390-84CA-685BFF2F6C21}" = CCC Help Dutch
"{FEF8EFCC-F745-9EB2-B313-9902D03A4C5D}" = CCC Help Finnish
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"DAEMON Tools Lite" = DAEMON Tools Lite
"ESET Online Scanner" = ESET Online Scanner v3
"GOM Player" = GOM Player
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"InstallShield_{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"IObit Security 360_is1" = IObit Security 360
"Jewel Quest Solitaire III 1.00" = Jewel Quest Solitaire III 1.00
"KLiteCodecPack_is1" = K-Lite Mega Codec Pack 7.0.0
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
"Mozilla Firefox 6.0.2 (x86 en-GB)" = Mozilla Firefox 6.0.2 (x86 en-GB)
"Office14.PROPLUS" = Microsoft Office Professional Plus 2010
"PhotoScape" = PhotoScape
"RiseOfNations 1.0" = Microsoft Rise Of Nations
"uTorrent" = µTorrent

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
"Juniper_Setup_Client" = Juniper Networks Setup Client

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 19.10.2011 03:51:30 | Computer Name = sharpen | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 26146

Error - 19.10.2011 03:53:59 | Computer Name = sharpen | Source = WinMgmt | ID = 10
Description =

Error - 19.10.2011 05:26:22 | Computer Name = sharpen | Source = WinMgmt | ID = 10
Description =

Error - 19.10.2011 07:50:53 | Computer Name = sharpen | Source = WinMgmt | ID = 10
Description =

Error - 19.10.2011 10:24:19 | Computer Name = sharpen | Source = WinMgmt | ID = 10
Description =

Error - 19.10.2011 10:29:53 | Computer Name = sharpen | Source = WinMgmt | ID = 10
Description =

Error - 19.10.2011 10:33:11 | Computer Name = sharpen | Source = Microsoft-Windows-LoadPerf | ID = 3001
Description = The performance counter name string value in the registry is not formatted
correctly. The malformed string is 9340. The first DWORD in the Data section contains
the index value to the malformed string while the second and third DWORDs in the
Data section contain the last valid index values.

Error - 19.10.2011 10:33:11 | Computer Name = sharpen | Source = Microsoft-Windows-LoadPerf | ID = 3011
Description = Unloading the performance counter strings for service WmiApRpl (WmiApRpl)
failed. The first DWORD in the Data section contains the error code.

Error - 19.10.2011 10:33:14 | Computer Name = sharpen | Source = Microsoft-Windows-LoadPerf | ID = 3001
Description = The performance counter name string value in the registry is not formatted
correctly. The malformed string is 9340. The first DWORD in the Data section contains
the index value to the malformed string while the second and third DWORDs in the
Data section contain the last valid index values.

Error - 19.10.2011 11:40:13 | Computer Name = sharpen | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "C:\Users\blur\Downloads\esetsmartinstaller_enu.exe".Error
in manifest or policy file "" on line . A component version required by the application
conflicts with another component version already active. Conflicting components
are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

[ Broadcom Wireless LAN Events ]
Error - 10.10.2011 10:43:31 | Computer Name = sharpen | Source = WLAN-Tray | ID = 0
Description = 17:43:29, Mon, Oct 10, 11 Error - Unable to gain access to user store


[ System Events ]
Error - 19.10.2011 10:24:30 | Computer Name = sharpen | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
service which failed to start because of the following error: %%1068

Error - 19.10.2011 10:27:33 | Computer Name = sharpen | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
service which failed to start because of the following error: %%1068

Error - 19.10.2011 10:28:10 | Computer Name = sharpen | Source = Service Control Manager | ID = 7000
Description = The Windows Firewall Authorization Driver service failed to start
due to the following error: %%183

Error - 19.10.2011 10:28:10 | Computer Name = sharpen | Source = Service Control Manager | ID = 7001
Description = The Windows Firewall service depends on the Windows Firewall Authorization
Driver service which failed to start because of the following error: %%183

Error - 19.10.2011 10:28:14 | Computer Name = sharpen | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = There was an error while attempting to read the local hosts file.

Error - 19.10.2011 10:28:19 | Computer Name = sharpen | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = There was an error while attempting to read the local hosts file.

Error - 19.10.2011 10:28:27 | Computer Name = sharpen | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = There was an error while attempting to read the local hosts file.

Error - 19.10.2011 10:28:27 | Computer Name = sharpen | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = There was an error while attempting to read the local hosts file.

Error - 19.10.2011 10:28:32 | Computer Name = sharpen | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = There was an error while attempting to read the local hosts file.

Error - 19.10.2011 11:28:17 | Computer Name = sharpen | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = There was an error while attempting to read the local hosts file.


< End of report >

Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 3 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

•Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
•If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
•Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
•Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post









Download Combofix from either of the links below, and save it to your desktop.

Link 1
Link 2



**Note: It is important that it is saved directly to your desktop**

——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
——————————————————————–

Double click on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
Ok so i took my pc to a friend of mine who is an IT student and he traced the ping.exe to be pinging hostnoc.com to notify that my pc is available to download their trojan, but because my antivirus was blocking the trojan theyve been sending, it just kept pinging and pinging and something like that. He managed to kill the process, and i havent rebooted since, now i'm running lavasoft adaware which found 3 malwares already, i'll reboot after it finishes and will let you know if it works, and if it doesn't i'll run combofix and post the logs. Thanks for your attention.
Here are the logs from ad aware im posting them just in case, when i run procexp.exe as an admin i can kill the ping.exe process and temporarily block the malware from interfering with my normal daily work, now i have school work i need to do while my computer runs with a normal cpu usage, ill run combofix asap and post the logs. Logfile created: 19.10.2011 21:12:11 Ad-Aware version: 9.5.1 Extended engine: 3 Extended engine version: 3.1.2770 User performing scan: blur *********************** Definitions database information *********************** Lavasoft definition file: 150.598 Genotype definition file version: 2011/10/12 12:14:17 Extended engine definition file: 10809.0 ******************************** Scan results: ********************************* Scan profile name: Full Scan (ID: full) Objects scanned: 179347 Objects detected: 15 Type Detected ========================== Processes…….: 0 Registry entries: 0 Hostfile entries: 0 Files………..: 3 Folders………: 0 LSPs…………: 0 Cookies………: 12 Browser hijacks.: 0 MRU objects…..: 0 Removed items: Description: c:\users\blur\appdata\local\temp\vc_is2.exe Family Name: Trojan.Win32.Generic.pak!cobra Engine: 3 Clean status: Success Item ID: 1 Family ID: 0 MD5: 4374195fb2beecfcf49920f6b8b22857 Description: c:\windows\assembly\temp\kwrd.dll Family Name: Trojan.Win32.Generic!BT Engine: 3 Clean status: Reboot required Item ID: 2 Family ID: 0 MD5: 8ea57e8b69f25aed867066ee413d77ca Description: c:\windows\assembly\temp\u\80000032.@ Family Name: Trojan.Win32.Generic!BT Engine: 3 Clean status: Success Item ID: 2 Family ID: 0 MD5: 56c9ef26f88b447c01252169050ce01b Description: *webtrends* Family Name: Cookies Engine: 1 Clean status: Success Item ID: 599640 Family ID: 0 Description: *atdmt* Family Name: Cookies Engine: 1 Clean status: Success Item ID: 408910 Family ID: 0 Description: *fastclick* Family Name: Cookies Engine: 1 Clean status: Success Item ID: 408869 Family ID: 0 Description: *2o7* Family Name: Cookies Engine: 1 Clean status: Success Item ID: 408943 Family ID: 0 Description: *bs.serving-sys* Family Name: Cookies Engine: 1 Clean status: Success Item ID: 408902 Family ID: 0 Description: *serving-sys* Family Name: Cookies Engine: 1 Clean status: Success Item ID: 409130 Family ID: 0 Description: *atdmt* Family Name: Cookies Engine: 1 Clean status: Success Item ID: 408910 Family ID: 0 Description: *doubleclick* Family Name: Cookies Engine: 1 Clean status: Success Item ID: 408875 Family ID: 0 Description: *webtrends* Family Name: Cookies Engine: 1 Clean status: Success Item ID: 599640 Family ID: 0 Description: *atdmt* Family Name: Cookies Engine: 1 Clean status: Success Item ID: 408910 Family ID: 0 Description: *fastclick* Family Name: Cookies Engine: 1 Clean status: Success Item ID: 408869 Family ID: 0 Description: *2o7* Family Name: Cookies Engine: 1 Clean status: Success Item ID: 408943 Family ID: 0 Scan and cleaning complete: Finished correctly after 4565 seconds *********************************** Settings *********************************** Scan profile: ID: full, enabled:1, value: Full Scan ID: folderstoscan, enabled:1, value: C:\,D:\ ID: useantivirus, enabled:1, value: true ID: sections, enabled:1 ID: scancriticalareas, enabled:1, value: true ID: scanrunningapps, enabled:1, value: true ID: scanregistry, enabled:1, value: true ID: scanlsp, enabled:1, value: true ID: scanads, enabled:1, value: true ID: scanhostsfile, enabled:1, value: true ID: scanmru, enabled:1, value: true ID: scanbrowserhijacks, enabled:1, value: true ID: scantrackingcookies, enabled:1, value: true ID: closebrowsers, enabled:1, value: false ID: filescanningoptions, enabled:1 ID: archives, enabled:1, value: true ID: onlyexecutables, enabled:1, value: false ID: skiplargerthan, enabled:1, value: 20480 ID: scanrootkits, enabled:1, value: true ID: rootkitlevel, enabled:1, value: mild, domain: medium,mild,strict ID: usespywareheuristics, enabled:1, value: true Scan global: ID: global, enabled:1 ID: addtocontextmenu, enabled:1, value: true ID: playsoundoninfection, enabled:1, value: false ID: soundfile, enabled:0, value: N/A Scheduled scan settings: Update settings: ID: updates, enabled:1 ID: launchthreatworksafterscan, enabled:1, value: off, domain: normal,off,silently ID: deffiles, enabled:1, value: downloadandinstall, domain: dontcheck,downloadandinstall ID: licenseandinfo, enabled:1, value: downloadandinstall, domain: dontcheck,downloadandinstall ID: schedules, enabled:1, value: true ID: updatedaily1, enabled:1, value: Daily 1 ID: time, enabled:1, value: Wed Oct 19 21:03:00 2011 ID: frequency, enabled:1, value: daily, domain: daily,monthly,once,systemstart,weekly ID: weekdays, enabled:1 ID: monday, enabled:1, value: false ID: tuesday, enabled:1, value: false ID: wednesday, enabled:1, value: false ID: thursday, enabled:1, value: false ID: friday, enabled:1, value: false ID: saturday, enabled:1, value: false ID: sunday, enabled:1, value: false ID: monthly, enabled:1, value: 1, minvalue: 1, maxvalue: 31 ID: scanprofile, enabled:1, value: ID: auto_deal_with_infections, enabled:1, value: false ID: updatedaily2, enabled:1, value: Daily 2 ID: time, enabled:1, value: Wed Oct 19 03:03:00 2011 ID: frequency, enabled:1, value: daily, domain: daily,monthly,once,systemstart,weekly ID: weekdays, enabled:1 ID: monday, enabled:1, value: false ID: tuesday, enabled:1, value: false ID: wednesday, enabled:1, value: false ID: thursday, enabled:1, value: false ID: friday, enabled:1, value: false ID: saturday, enabled:1, value: false ID: sunday, enabled:1, value: false ID: monthly, enabled:1, value: 1, minvalue: 1, maxvalue: 31 ID: scanprofile, enabled:1, value: ID: auto_deal_with_infections, enabled:1, value: false ID: updatedaily3, enabled:1, value: Daily 3 ID: time, enabled:1, value: Wed Oct 19 09:03:00 2011 ID: frequency, enabled:1, value: daily, domain: daily,monthly,once,systemstart,weekly ID: weekdays, enabled:1 ID: monday, enabled:1, value: false ID: tuesday, enabled:1, value: false ID: wednesday, enabled:1, value: false ID: thursday, enabled:1, value: false ID: friday, enabled:1, value: false ID: saturday, enabled:1, value: false ID: sunday, enabled:1, value: false ID: monthly, enabled:1, value: 1, minvalue: 1, maxvalue: 31 ID: scanprofile, enabled:1, value: ID: auto_deal_with_infections, enabled:1, value: false ID: updatedaily4, enabled:1, value: Daily 4 ID: time, enabled:1, value: Wed Oct 19 15:03:00 2011 ID: frequency, enabled:1, value: daily, domain: daily,monthly,once,systemstart,weekly ID: weekdays, enabled:1 ID: monday, enabled:1, value: false ID: tuesday, enabled:1, value: false ID: wednesday, enabled:1, value: false ID: thursday, enabled:1, value: false ID: friday, enabled:1, value: false ID: saturday, enabled:1, value: false ID: sunday, enabled:1, value: false ID: monthly, enabled:1, value: 1, minvalue: 1, maxvalue: 31 ID: scanprofile, enabled:1, value: ID: auto_deal_with_infections, enabled:1, value: false ID: updateweekly1, enabled:1, value: Weekly ID: time, enabled:1, value: Wed Oct 19 21:03:00 2011 ID: frequency, enabled:1, value: weekly, domain: daily,monthly,once,systemstart,weekly ID: weekdays, enabled:1 ID: monday, enabled:1, value: false ID: tuesday, enabled:1, value: false ID: wednesday, enabled:1, value: true ID: thursday, enabled:1, value: false ID: friday, enabled:1, value: false ID: saturday, enabled:1, value: true ID: sunday, enabled:1, value: false ID: monthly, enabled:1, value: 1, minvalue: 1, maxvalue: 31 ID: scanprofile, enabled:1, value: ID: auto_deal_with_infections, enabled:1, value: false Appearance settings: ID: appearance, enabled:1 ID: skin, enabled:1, value: default.egl, reglocation: HKEY_LOCAL_MACHINE\SOFTWARE\Lavasoft\Ad-Aware\Resource ID: showtrayicon, enabled:1, value: true ID: autoentertainmentmode, enabled:1, value: true ID: guimode, enabled:1, value: mode_advanced, domain: mode_advanced,mode_simple ID: language, enabled:1, value: en, reglocation: HKEY_LOCAL_MACHINE\SOFTWARE\Lavasoft\Ad-Aware\Language Realtime protection settings: ID: realtime, enabled:1 ID: layers, enabled:1 ID: useantivirus, enabled:1, value: true ID: usespywareheuristics, enabled:1, value: true ID: maintainbackup, enabled:1, value: true ID: infomessages, enabled:1, value: onlyimportant, domain: display,dontnotify,onlyimportant ID: modules, enabled:1 ID: processprotection, enabled:1, value: true ID: onaccessprotection, enabled:1, value: true ID: registryprotection, enabled:1, value: true ID: networkprotection, enabled:1, value: true ****************************** System information ****************************** Computer name: SHARPEN Processor name: Intel® Core™ i5 CPU M 480 @ 2.67GHz Processor identifier: Intel64 Family 6 Model 37 Stepping 5 Processor speed: ~2660MHZ Raw info: processorarchitecture 9, processortype 8664, processorlevel 6, processor revision 9477, number of processors 4, processor features: [MMX,SSE,SSE2,SSE3] Physical memory available: 1744605184 bytes Physical memory total: 4137852928 bytes Virtual memory available: 1851633664 bytes Virtual memory total: 2147352576 bytes Memory load: 57% Microsoft Service Pack 1 (build 7601) Windows startup mode: Running processes: PID: 328 name: C:\Windows\System32\smss.exe owner: SYSTEM domain: NT AUTHORITY PID: 460 name: C:\Windows\System32\csrss.exe owner: SYSTEM domain: NT AUTHORITY PID: 532 name: C:\Windows\System32\wininit.exe owner: SYSTEM domain: NT AUTHORITY PID: 556 name: C:\Windows\System32\csrss.exe owner: SYSTEM domain: NT AUTHORITY PID: 608 name: C:\Windows\System32\services.exe owner: SYSTEM domain: NT AUTHORITY PID: 624 name: C:\Windows\System32\lsass.exe owner: SYSTEM domain: NT AUTHORITY PID: 632 name: C:\Windows\System32\lsm.exe owner: SYSTEM domain: NT AUTHORITY PID: 724 name: C:\Windows\System32\winlogon.exe owner: SYSTEM domain: NT AUTHORITY PID: 784 name: C:\Windows\System32\svchost.exe owner: SYSTEM domain: NT AUTHORITY PID: 864 name: C:\Windows\System32\svchost.exe owner: NETWORK SERVICE domain: NT AUTHORITY PID: 944 name: C:\Windows\System32\atiesrxx.exe owner: SYSTEM domain: NT AUTHORITY PID: 992 name: C:\Windows\System32\svchost.exe owner: LOCAL SERVICE domain: NT AUTHORITY PID: 128 name: C:\Windows\System32\svchost.exe owner: SYSTEM domain: NT AUTHORITY PID: 304 name: C:\Windows\System32\svchost.exe owner: SYSTEM domain: NT AUTHORITY PID: 368 name: C:\Windows\System32\svchost.exe owner: LOCAL SERVICE domain: NT AUTHORITY PID: 1128 name: C:\Windows\System32\svchost.exe owner: NETWORK SERVICE domain: NT AUTHORITY PID: 1316 name: C:\Windows\System32\atieclxx.exe owner: SYSTEM domain: NT AUTHORITY PID: 1404 name: C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRYSVC.EXE owner: SYSTEM domain: NT AUTHORITY PID: 1412 name: C:\Windows\System32\wlanext.exe owner: SYSTEM domain: NT AUTHORITY PID: 1420 name: C:\Windows\System32\conhost.exe owner: SYSTEM domain: NT AUTHORITY PID: 1464 name: C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\BCMWLTRY.EXE owner: SYSTEM domain: NT AUTHORITY PID: 1536 name: C:\Windows\System32\spoolsv.exe owner: SYSTEM domain: NT AUTHORITY PID: 1568 name: C:\Windows\System32\svchost.exe owner: LOCAL SERVICE domain: NT AUTHORITY PID: 1616 name: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe owner: SYSTEM domain: NT AUTHORITY PID: 1660 name: C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe owner: SYSTEM domain: NT AUTHORITY PID: 1728 name: C:\Program Files (x86)\Bonjour\mDNSResponder.exe owner: SYSTEM domain: NT AUTHORITY PID: 1752 name: C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe owner: SYSTEM domain: NT AUTHORITY PID: 1808 name: C:\Program Files (x86)\Samsung\USB Drivers\26_VIA_driver2\amd64\VIAService.exe owner: SYSTEM domain: NT AUTHORITY PID: 1848 name: C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe owner: SYSTEM domain: NT AUTHORITY PID: 1984 name: C:\Windows\System32\svchost.exe owner: LOCAL SERVICE domain: NT AUTHORITY PID: 2160 name: C:\Windows\System32\svchost.exe owner: LOCAL SERVICE domain: NT AUTHORITY PID: 2392 name: C:\Windows\System32\taskhost.exe owner: blur domain: sharpen PID: 2488 name: C:\Windows\System32\taskeng.exe owner: blur domain: sharpen PID: 2512 name: C:\Windows\System32\dwm.exe owner: blur domain: sharpen PID: 2540 name: C:\Windows\explorer.exe owner: blur domain: sharpen PID: 2700 name: C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe owner: blur domain: sharpen PID: 2876 name: C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe owner: blur domain: sharpen PID: 2888 name: C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.EXE owner: blur domain: sharpen PID: 2904 name: C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe owner: blur domain: sharpen PID: 2112 name: C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe owner: blur domain: sharpen PID: 2580 name: C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe owner: blur domain: sharpen PID: 2360 name: C:\Program Files\Windows Sidebar\sidebar.exe owner: blur domain: sharpen PID: 2616 name: C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe owner: blur domain: sharpen PID: 3184 name: C:\Windows\System32\svchost.exe owner: LOCAL SERVICE domain: NT AUTHORITY PID: 3212 name: C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe owner: blur domain: sharpen PID: 3232 name: C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe owner: blur domain: sharpen PID: 3316 name: C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe owner: blur domain: sharpen PID: 3716 name: C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe owner: blur domain: sharpen PID: 3512 name: C:\Windows\System32\SearchIndexer.exe owner: SYSTEM domain: NT AUTHORITY PID: 2440 name: C:\Program Files\Windows Media Player\wmpnetwk.exe owner: NETWORK SERVICE domain: NT AUTHORITY PID: 3404 name: C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe owner: blur domain: sharpen PID: 1304 name: C:\Program Files (x86)\CyberLink\YouCam\YouCamTray.exe owner: blur domain: sharpen PID: 2792 name: C:\Program Files (x86)\iTunes\iTunesHelper.exe owner: blur domain: sharpen PID: 1368 name: C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe owner: blur domain: sharpen PID: 4248 name: C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe owner: blur domain: sharpen PID: 4356 name: C:\Program Files\iPod\bin\iPodService.exe owner: SYSTEM domain: NT AUTHORITY PID: 5012 name: C:\Windows\SysWOW64\rundll32.exe owner: blur domain: sharpen PID: 2480 name: C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe owner: blur domain: sharpen PID: 5804 name: C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe owner: LOCAL SERVICE domain: NT AUTHORITY PID: 5888 name: C:\Windows\System32\wuauclt.exe owner: blur domain: sharpen PID: 6000 name: C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe owner: SYSTEM domain: NT AUTHORITY PID: 4128 name: C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe owner: SYSTEM domain: NT AUTHORITY PID: 5380 name: C:\Windows\System32\svchost.exe owner: SYSTEM domain: NT AUTHORITY PID: 2848 name: C:\Program Files (x86)\IObit\IObit Security 360\is360.exe owner: blur domain: sharpen PID: 5416 name: C:\Program Files (x86)\IObit\IObit Security 360\is360tray.exe owner: blur domain: sharpen PID: 5164 name: C:\Program Files (x86)\IObit\IObit Security 360\is360srv.exe owner: SYSTEM domain: NT AUTHORITY PID: 4244 name: C:\Windows\SysWOW64\PING.EXE owner: SYSTEM domain: NT AUTHORITY PID: 3620 name: C:\Windows\System32\conhost.exe owner: SYSTEM domain: NT AUTHORITY PID: 4008 name: C:\Windows\System32\taskhost.exe owner: blur domain: sharpen PID: 4892 name: C:\Users\blur\AppData\Local\Google\Chrome\Application\chrome.exe owner: blur domain: sharpen PID: 4636 name: C:\Users\blur\AppData\Local\Google\Chrome\Application\chrome.exe owner: blur domain: sharpen PID: 3396 name: C:\Users\blur\AppData\Local\Google\Chrome\Application\chrome.exe owner: blur domain: sharpen PID: 1704 name: C:\Users\blur\AppData\Local\Google\Chrome\Application\chrome.exe owner: blur domain: sharpen PID: 4768 name: C:\Users\blur\AppData\Local\Google\Chrome\Application\chrome.exe owner: blur domain: sharpen PID: 4304 name: C:\Users\blur\AppData\Local\Google\Chrome\Application\chrome.exe owner: blur domain: sharpen PID: 3828 name: C:\Users\blur\AppData\Local\Google\Chrome\Application\chrome.exe owner: blur domain: sharpen PID: 2024 name: C:\Users\blur\AppData\Local\Google\Chrome\Application\chrome.exe owner: blur domain: sharpen PID: 4880 name: C:\Users\blur\AppData\Local\Google\Chrome\Application\chrome.exe owner: blur domain: sharpen PID: 3964 name: C:\Windows\SysWOW64\rundll32.exe owner: blur domain: sharpen PID: 5828 name: C:\Users\blur\AppData\Local\Google\Chrome\Application\chrome.exe owner: blur domain: sharpen PID: 4864 name: C:\Windows\System32\msiexec.exe owner: SYSTEM domain: NT AUTHORITY PID: 6428 name: C:\Program Files (x86)\Lavasoft\Ad-Aware\Ad-Aware.exe owner: blur domain: sharpen PID: 7088 name: C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe owner: SYSTEM domain: NT AUTHORITY PID: 6672 name: C:\Windows\System32\wbem\unsecapp.exe owner: SYSTEM domain: NT AUTHORITY PID: 5568 name: C:\Windows\System32\wbem\WmiPrvSE.exe owner: SYSTEM domain: NT AUTHORITY PID: 7020 name: C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe owner: blur domain: sharpen PID: 452 name: C:\Windows\System32\taskeng.exe owner: blur domain: sharpen PID: 6932 name: C:\Windows\System32\taskhost.exe owner: LOCAL SERVICE domain: NT AUTHORITY PID: 7056 name: C:\Windows\SysWOW64\dllhost.exe owner: blur domain: sharpen Startup items: Name: StartCCC imagepath: "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun Name: IAStorIcon imagepath: C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe Name: SunJavaUpdateSched imagepath: "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" Name: Adobe ARM imagepath: "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" Name: BCSSync imagepath: "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices Name: YouCam Mirage imagepath: "C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe" Name: YouCam Tray imagepath: "C:\Program Files (x86)\CyberLink\YouCam\YouCamTray.exe" /s Name: KiesHelper imagepath: C:\Program Files (x86)\Samsung\Kies\KiesHelper.exe /s Name: QuickTime Task imagepath: "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime Name: iTunesHelper imagepath: "C:\Program Files (x86)\iTunes\iTunesHelper.exe" Name: IObit Security 360 imagepath: "C:\Program Files (x86)\IObit\IObit Security 360\IS360tray.exe" /autostart Name: WebCheck imagepath: {E6FB5E20-DE35-11CF-9C87-00AA005127ED} Name: location: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk imagepath: C:\Program Files (x86)\WIDCOMM\Bluetooth Software\BTTray.exe Name: imagepath: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini Bootexecute items: Name: imagepath: autocheck autochk * Running services: Name: AdobeARMservice displayname: Adobe Acrobat Update Service Name: AeLookupSvc displayname: Application Experience Name: AMD External Events Utility displayname: AMD External Events Utility Name: Appinfo displayname: Application Information Name: Apple Mobile Device displayname: Apple Mobile Device Name: AudioEndpointBuilder displayname: Windows Audio Endpoint Builder Name: AudioSrv displayname: Windows Audio Name: BFE displayname: Base Filtering Engine Name: BITS displayname: Background Intelligent Transfer Service Name: Bonjour Service displayname: Bonjour Service Name: bthserv displayname: Bluetooth Support Service Name: btwdins displayname: Bluetooth Service Name: CDMA Device Service displayname: CDMA Device Service Name: CryptSvc displayname: Cryptographic Services Name: CscService displayname: Offline Files Name: DcomLaunch displayname: DCOM Server Process Launcher Name: Dhcp displayname: DHCP Client Name: Dnscache displayname: DNS Client Name: DPS displayname: Diagnostic Policy Service Name: EapHost displayname: Extensible Authentication Protocol Name: ekrn displayname: ESET Service Name: eventlog displayname: Windows Event Log Name: EventSystem displayname: COM+ Event System Name: fdPHost displayname: Function Discovery Provider Host Name: FDResPub displayname: Function Discovery Resource Publication Name: FontCache displayname: Windows Font Cache Service Name: FontCache3.0.0.0 displayname: Windows Presentation Foundation Font Cache 3.0.0.0 Name: gpsvc displayname: Group Policy Client Name: HomeGroupProvider displayname: HomeGroup Provider Name: IAStorDataMgrSvc displayname: Intel® Rapid Storage Technology Name: iphlpsvc displayname: IP Helper Name: iPod Service displayname: iPod Service Name: KeyIso displayname: CNG Key Isolation Name: LanmanServer displayname: Server Name: LanmanWorkstation displayname: Workstation Name: lmhosts displayname: TCP/IP NetBIOS Helper Name: MBAMService displayname: MBAMService Name: MMCSS displayname: Multimedia Class Scheduler Name: msiserver displayname: Windows Installer Name: Netman displayname: Network Connections Name: netprofm displayname: Network List Service Name: NlaSvc displayname: Network Location Awareness Name: nsi displayname: Network Store Interface Service Name: PcaSvc displayname: Program Compatibility Assistant Service Name: PlugPlay displayname: Plug and Play Name: Power displayname: Power Name: ProfSvc displayname: User Profile Service Name: RpcEptMapper displayname: RPC Endpoint Mapper Name: RpcSs displayname: Remote Procedure Call (RPC) Name: SamSs displayname: Security Accounts Manager Name: Schedule displayname: Task Scheduler Name: SENS displayname: System Event Notification Service Name: ShellHWDetection displayname: Shell Hardware Detection Name: Spooler displayname: Print Spooler Name: SSDPSRV displayname: SSDP Discovery Name: stisvc displayname: Windows Image Acquisition (WIA) Name: SysMain displayname: Superfetch Name: TapiSrv displayname: Telephony Name: Themes displayname: Themes Name: TrkWks displayname: Distributed Link Tracking Client Name: upnphost displayname: UPnP Device Host Name: UxSms displayname: Desktop Window Manager Session Manager Name: WdiServiceHost displayname: Diagnostic Service Host Name: WinDefend displayname: Windows Defender Name: WinHttpAutoProxySvc displayname: WinHTTP Web Proxy Auto-Discovery Service Name: Winmgmt displayname: Windows Management Instrumentation Name: Wlansvc displayname: WLAN AutoConfig Name: wltrysvc displayname: Broadcom Wireless LAN Tray Service Name: WMPNetworkSvc displayname: Windows Media Player Network Sharing Service Name: wscsvc displayname: Security Center Name: WSearch displayname: Windows Search Name: wuauserv displayname: Windows Update Name: wudfsvc displayname: Windows Driver Foundation - User-mode Driver Framework Name: IS360service displayname: IS360service Name: Lavasoft Ad-Aware Service displayname: Lavasoft Ad-Aware Service
Combofix took a long time to run, froze several times and scared me a lot but it actually killed the malware. I am posting the logs anyways if anyone else comes up with the same problem, you'll have some opinions about it. Thans a lot for your help, i really apreciate it.

ComboFix 11-10-19.06 - blur 20.10.2011 0:01.1.4 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1254.90.1033.18.3946.2325 [GMT 3:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: Lavasoft Ad-Watch Live! Anti-Virus *Disabled/Updated* {9FF26384-70D4-CE6B-3ECB-E759A6A40116}
SP: Lavasoft Ad-Watch Live! *Disabled/Updated* {24938260-56EE-C1E5-047B-DC2BDD234BAB}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\blur\AppData\Local\Temp\3dcf2df1-2a83-477c-a7dd-858967792357\CliSecureRT.dll
c:\windows\system32\consrv.dll
c:\windows\System64
c:\windows\SysWow64\muzapp.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-09-19 to 2011-10-19 )))))))))))))))))))))))))))))))
.
.
2011-10-19 19:57 . 2011-10-19 19:59 ——– d—–w- c:\program files (x86)\Common Files\Steam
2011-10-19 19:57 . 2011-10-19 20:25 ——– d—–w- c:\program files (x86)\Steam
2011-10-19 19:31 . 2011-10-19 18:08 16432 —-a-w- c:\windows\system32\lsdelete.exe
2011-10-19 18:08 . 2011-10-19 18:08 55384 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-10-19 18:03 . 2011-08-18 12:25 69376 —-a-w- c:\windows\system32\drivers\Lbd.sys
2011-10-19 18:03 . 2011-10-19 18:03 ——– d—–w- c:\programdata\Lavasoft
2011-10-19 18:03 . 2011-10-19 18:03 ——– d—–w- c:\program files (x86)\Lavasoft
2011-10-19 15:40 . 2011-10-19 15:40 ——– d—–w- c:\program files (x86)\ESET
2011-10-19 15:37 . 2011-10-19 15:37 ——– d—–w- C:\_OTL
2011-10-19 15:21 . 2011-10-19 15:21 ——– d—–w- c:\users\blur\AppData\Local\Facebook
2011-10-19 14:32 . 2011-10-19 14:32 ——– d—–w- c:\programdata\IObit
2011-10-19 14:32 . 2011-10-19 14:32 ——– d—–w- c:\program files (x86)\IObit
2011-10-19 07:12 . 2011-10-19 07:12 ——– d—–w- c:\users\blur\AppData\Roaming\Malwarebytes
2011-10-19 07:12 . 2011-10-19 07:12 ——– d—–w- c:\programdata\Malwarebytes
2011-10-19 07:12 . 2011-08-31 14:00 25416 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-10-19 07:00 . 2011-10-19 07:00 ——– d—–w- c:\users\blur\AppData\Local\ESET
2011-10-18 19:36 . 2011-10-18 19:36 58668 –sha-w- c:\windows\comset32.exe
2011-10-18 08:33 . 2011-09-13 00:26 9049936 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{646E594D-EC90-4716-B51F-BD43E7549A68}\mpengine.dll
2011-10-12 18:12 . 2011-08-27 05:37 861696 —-a-w- c:\windows\system32\oleaut32.dll
2011-10-12 18:12 . 2011-08-27 05:37 331776 —-a-w- c:\windows\system32\oleacc.dll
2011-10-12 18:12 . 2011-08-27 04:26 571904 —-a-w- c:\windows\SysWow64\oleaut32.dll
2011-10-12 18:12 . 2011-08-27 04:26 233472 —-a-w- c:\windows\SysWow64\oleacc.dll
2011-10-10 14:28 . 2011-10-10 14:28 ——– d—–w- c:\users\Guest
2011-10-10 08:09 . 2011-10-10 08:09 4550304 —-a-w- c:\program files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\components\SkypeFfComponent.dll
2011-10-09 19:25 . 2011-10-15 22:43 ——– d—–w- c:\users\blur\AppData\Roaming\Apple Computer
2011-10-09 19:25 . 2011-10-09 19:25 ——– d—–w- c:\users\blur\AppData\Local\Apple Computer
2011-10-09 19:25 . 2011-10-19 18:03 ——– dc—-w- c:\windows\system32\DRVSTORE
2011-10-09 19:25 . 2009-05-18 10:17 34152 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2011-10-09 19:25 . 2008-04-17 09:12 126312 —-a-w- c:\windows\system32\GEARAspi64.dll
2011-10-09 19:25 . 2008-04-17 09:12 107368 —-a-w- c:\windows\SysWow64\GEARAspi.dll
2011-10-09 19:23 . 2011-10-09 19:23 ——– d—–w- c:\program files\Bonjour
2011-10-09 19:23 . 2011-10-09 19:23 ——– d—–w- c:\program files (x86)\Bonjour
2011-10-09 19:23 . 2011-10-15 22:42 ——– d—–w- c:\programdata\Apple
2011-10-09 19:23 . 2011-10-09 19:24 ——– d—–w- c:\program files (x86)\Common Files\Apple
2011-09-26 11:42 . 2009-09-06 12:18 80896 —-a-w- c:\windows\system32\Spool\prtprocs\x64\LMACOC4C.DLL
2011-09-26 11:41 . 2011-09-26 11:41 ——– d—–w- c:\program files\Lexmark
2011-09-21 23:42 . 2011-09-21 23:42 ——– d—–w- c:\program files\SAMSUNG
2011-09-21 23:10 . 2011-09-21 23:10 ——– d—–w- c:\users\blur\AppData\Local\Samsung
2011-09-21 23:08 . 2011-07-26 14:26 4659712 —-a-w- c:\windows\SysWow64\Redemption.dll
2011-09-21 23:08 . 2011-09-21 23:08 ——– d—–w- c:\program files (x86)\MarkAny
2011-09-21 23:08 . 2011-07-26 14:26 821824 —-a-w- c:\windows\SysWow64\dgderapi.dll
2011-09-21 23:08 . 2011-09-21 23:08 ——– d—–w- c:\users\blur\AppData\Roaming\Samsung
2011-09-21 23:07 . 2011-09-21 23:07 ——– d—–w- c:\users\blur\AppData\Local\Downloaded Installations
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-09-02 23:29 . 2011-09-02 23:29 472808 —-a-w- c:\windows\SysWow64\deployJava1.dll
2011-09-01 02:08 . 2011-09-01 02:08 404640 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-08-31 21:30 . 2011-08-31 21:30 270912 —-a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2011-08-07 11:34 . 2010-07-07 07:49 278528 —-a-w- c:\windows\SysWow64\Oemdspif.dll
2011-08-07 11:34 . 2010-07-07 07:30 2785792 —-a-w- c:\windows\system32\atiumd6a.dll
2011-08-07 11:34 . 2010-07-07 07:28 3975680 —-a-w- c:\windows\SysWow64\atiumdag.dll
2011-08-07 11:34 . 2010-07-07 07:24 55296 —-a-w- c:\windows\system32\coinst.dll
2011-08-07 11:34 . 2010-07-07 07:23 3058688 —-a-w- c:\windows\SysWow64\atiumdva.dll
2011-08-07 11:34 . 2010-07-07 07:22 5099008 —-a-w- c:\windows\system32\atiumd64.dll
2011-08-07 11:34 . 2010-07-07 07:15 39424 —-a-w- c:\windows\system32\atiuxp64.dll
2011-08-07 11:34 . 2010-07-07 07:15 30208 —-a-w- c:\windows\SysWow64\atiuxpag.dll
2011-08-07 11:34 . 2010-07-07 07:55 15461888 —-a-w- c:\windows\SysWow64\atioglxx.dll
2011-08-07 11:34 . 2010-07-07 07:49 120320 —-a-w- c:\windows\system32\atitmm64.dll
2011-08-07 11:34 . 2010-07-07 07:49 421376 —-a-w- c:\windows\system32\atipdl64.dll
2011-08-07 11:34 . 2010-07-07 07:49 356352 —-a-w- c:\windows\SysWow64\atipdlxx.dll
2011-08-07 11:34 . 2010-07-07 07:14 30208 —-a-w- c:\windows\system32\atiu9p64.dll
2011-08-07 11:34 . 2010-07-07 07:14 22528 —-a-w- c:\windows\SysWow64\atiu9pag.dll
2011-08-07 11:34 . 2010-07-07 08:16 20118528 —-a-w- c:\windows\system32\atio6axx.dll
2011-08-07 11:34 . 2009-02-18 23:55 332288 —-a-w- c:\windows\system32\ATIODE.exe
2011-08-07 11:34 . 2009-02-04 02:52 51200 —-a-w- c:\windows\system32\ATIODCLI.exe
2011-08-07 11:34 . 2010-07-07 08:30 7195648 —-a-w- c:\windows\system32\drivers\atikmdag.sys
2011-08-07 11:34 . 2010-07-07 07:49 12288 —-a-w- c:\windows\system32\atimuixx.dll
2011-08-07 11:34 . 2010-07-07 07:15 265728 —-a-w- c:\windows\system32\drivers\atikmpag.sys
2011-08-07 11:34 . 2010-07-07 07:11 54272 —-a-w- c:\windows\system32\atimpc64.dll
2011-08-07 11:34 . 2010-07-07 07:11 54272 —-a-w- c:\windows\system32\amdpcom64.dll
2011-08-07 11:34 . 2010-07-07 07:11 52736 —-a-w- c:\windows\SysWow64\atimpc32.dll
2011-08-07 11:34 . 2010-07-07 07:11 52736 —-a-w- c:\windows\SysWow64\amdpcom32.dll
2011-08-07 11:34 . 2010-07-07 07:51 462336 —-a-w- c:\windows\system32\atieclxx.exe
2011-08-07 11:34 . 2010-07-07 07:50 203264 —-a-w- c:\windows\system32\atiesrxx.exe
2011-08-07 11:34 . 2010-07-07 07:49 59392 —-a-w- c:\windows\system32\atiedu64.dll
2011-08-07 11:34 . 2010-07-07 07:46 3826688 —-a-w- c:\windows\SysWow64\atidxx32.dll
2011-08-07 11:34 . 2010-07-07 07:37 4463616 —-a-w- c:\windows\system32\atidxx64.dll
2011-08-07 11:34 . 2010-07-07 07:15 14848 —-a-w- c:\windows\system32\atig6pxx.dll
2011-08-07 11:34 . 2010-07-07 07:15 12800 —-a-w- c:\windows\SysWow64\atiglpxx.dll
2011-08-07 11:34 . 2010-07-07 07:15 12800 —-a-w- c:\windows\system32\atiglpxx.dll
2011-08-07 11:34 . 2010-07-07 07:15 18432 —-a-w- c:\windows\system32\atig6txx.dll
2011-08-07 11:34 . 2010-07-07 07:15 16896 —-a-w- c:\windows\SysWow64\atigktxx.dll
2011-08-07 11:34 . 2010-07-07 07:54 513024 —-a-w- c:\windows\SysWow64\aticfx32.dll
2011-08-07 11:34 . 2010-07-07 07:53 594432 —-a-w- c:\windows\system32\aticfx64.dll
2011-08-07 11:34 . 2010-07-07 07:51 446464 —-a-w- c:\windows\system32\ATIDEMGX.dll
2011-08-07 11:34 . 2010-07-07 07:29 51200 —-a-w- c:\windows\system32\aticalrt64.dll
2011-08-07 11:34 . 2010-07-07 07:29 46080 —-a-w- c:\windows\SysWow64\aticalrt.dll
2011-08-07 11:34 . 2010-07-07 07:29 44544 —-a-w- c:\windows\system32\aticalcl64.dll
2011-08-07 11:34 . 2010-07-07 07:29 44032 —-a-w- c:\windows\SysWow64\aticalcl.dll
2011-08-07 11:34 . 2010-07-07 07:29 5378560 —-a-w- c:\windows\system32\aticaldd64.dll
2011-08-07 11:34 . 2010-07-07 07:28 4323840 —-a-w- c:\windows\SysWow64\aticaldd.dll
2011-08-07 11:34 . 2009-05-12 03:35 118784 —-a-w- c:\windows\system32\atibtmon.exe
2011-08-07 11:34 . 2010-07-07 07:54 143360 —-a-w- c:\windows\system32\atiapfxx.exe
2011-08-07 11:34 . 2010-07-07 07:49 43520 —-a-w- c:\windows\SysWow64\ati2edxx.dll
2011-08-07 11:34 . 2010-07-07 07:16 335872 —-a-w- c:\windows\system32\atiadlxx.dll
2011-08-07 11:34 . 2010-07-07 07:16 237568 —-a-w- c:\windows\SysWow64\atiadlxy.dll
2011-08-07 11:34 . 2010-07-07 07:14 53248 —-a-w- c:\windows\system32\drivers\ati2erec.dll
2011-08-07 11:21 . 2011-08-31 11:19 518896 —-a-w- c:\windows\system32\SRSTSX64.dll
2011-08-07 11:21 . 2011-08-31 11:19 2719504 —-a-w- c:\windows\system32\WavesGUILib.dll
2011-08-07 11:21 . 2011-08-31 11:19 155888 —-a-w- c:\windows\system32\SRSWOW64.dll
2011-08-07 11:21 . 2011-08-31 11:19 211184 —-a-w- c:\windows\system32\SRSTSH64.dll
2011-08-07 11:21 . 2011-08-31 11:19 198896 —-a-w- c:\windows\system32\SRSHP64.dll
2011-08-07 11:21 . 2011-08-31 11:19 612384 —-a-w- c:\windows\system32\RTSnMg64.cpl
2011-08-07 11:21 . 2011-08-31 11:19 1943584 —-a-w- c:\windows\system32\RtPgEx64.dll
2011-08-07 11:21 . 2011-08-31 11:19 476192 —-a-w- c:\windows\system32\RtkApi64.dll
2011-08-07 11:21 . 2011-08-31 11:19 332320 —-a-w- c:\windows\system32\RtlCPAPI64.dll
2011-08-07 11:21 . 2011-08-31 11:19 2337440 —-a-w- c:\windows\system32\drivers\RTKVHD64.sys
2011-08-07 11:21 . 2011-08-31 11:19 1660960 —-a-w- c:\windows\system32\RtkAPO64.dll
2011-08-07 11:21 . 2011-08-31 11:19 149536 —-a-w- c:\windows\system32\RtkCfg64.dll
2011-08-07 11:21 . 2011-08-31 11:19 99016 —-a-w- c:\windows\system32\RTEEL64A.dll
2011-08-07 11:21 . 2011-08-31 11:19 76488 —-a-w- c:\windows\system32\RTEEG64A.dll
2011-08-07 11:21 . 2011-08-31 11:19 372936 —-a-w- c:\windows\system32\RTEEP64A.dll
2011-08-07 11:21 . 2011-08-31 11:19 307920 —-a-w- c:\windows\system32\RP3DHT64.dll
2011-08-07 11:21 . 2011-08-31 11:19 307920 —-a-w- c:\windows\system32\RP3DAA64.dll
2011-08-07 11:21 . 2011-08-31 11:19 201928 —-a-w- c:\windows\system32\RTEED64A.dll
2011-08-07 11:21 . 2011-08-31 11:19 1210912 —-a-w- c:\windows\system32\RTCOM64.dll
2011-08-07 11:21 . 2011-08-31 11:19 69664 —-a-w- c:\windows\system32\RCoInst64.dll
2011-08-07 11:21 . 2011-08-31 11:19 325904 —-a-w- c:\windows\system32\MaxxAudioAPO20.dll
2011-08-07 11:21 . 2011-08-31 11:19 2197264 —-a-w- c:\windows\system32\MaxxAudioEQ.dll
2011-08-07 11:21 . 2011-08-31 11:19 331168 —-a-w- c:\windows\system32\FMAPO64.dll
2011-08-07 11:21 . 2011-08-31 11:19 168288 —-a-w- c:\windows\system32\AERTAC64.dll
2011-08-07 11:21 . 2011-08-31 11:19 108960 —-a-w- c:\windows\system32\AERTAR64.dll
2011-08-07 11:21 . 2011-08-31 11:19 1247776 —-a-w- c:\windows\RtlExUpd.dll
2011-08-07 11:21 . 2011-08-31 11:01 340520 —-a-w- c:\windows\system32\drivers\btwampfl.sys
2011-08-07 11:21 . 2011-08-31 11:01 39464 —-a-w- c:\windows\system32\drivers\btwl2cap.sys
2011-08-07 11:21 . 2011-08-31 11:01 21544 —-a-w- c:\windows\system32\drivers\btwrchid.sys
2011-08-07 11:21 . 2011-08-31 11:01 135720 —-a-w- c:\windows\system32\drivers\btwavdt.sys
2011-08-07 11:21 . 2011-08-31 11:01 102440 —-a-w- c:\windows\system32\drivers\btwaudio.sys
2011-08-07 11:17 . 2010-02-26 13:32 158976 —-a-w- c:\windows\system32\drivers\Impcd.sys
2011-08-07 11:16 . 2010-01-28 20:33 116736 —-a-w- c:\windows\system32\drivers\AtiHdmi.sys
2011-07-26 14:26 . 2011-07-26 14:26 90112 —-a-w- c:\windows\MAMCityDownload.ocx
2011-07-26 14:26 . 2011-07-26 14:26 325552 —-a-w- c:\windows\MASetupCaller.dll
2011-07-26 14:26 . 2011-07-26 14:26 30568 —-a-w- c:\windows\MusiccityDownload.exe
2011-07-26 14:26 . 2011-07-26 14:26 974848 —-a-w- c:\windows\SysWow64\cis-2.4.dll
2011-07-26 14:26 . 2011-07-26 14:26 81920 —-a-w- c:\windows\SysWow64\issacapi_bs-2.3.dll
2011-07-26 14:26 . 2011-07-26 14:26 65536 —-a-w- c:\windows\SysWow64\issacapi_pe-2.3.dll
2011-07-26 14:26 . 2011-07-26 14:26 57344 —-a-w- c:\windows\SysWow64\MTXSYNCICON.dll
2011-07-26 14:26 . 2011-07-26 14:26 57344 —-a-w- c:\windows\SysWow64\MK_Lyric.dll
2011-07-26 14:26 . 2011-07-26 14:26 57344 —-a-w- c:\windows\SysWow64\issacapi_se-2.3.dll
2011-07-26 14:26 . 2011-07-26 14:26 569344 —-a-w- c:\windows\SysWow64\muzdecode.ax
2011-07-26 14:26 . 2011-07-26 14:26 491520 —-a-w- c:\windows\SysWow64\muzapp.dll
2011-07-26 14:26 . 2011-07-26 14:26 49152 —-a-w- c:\windows\SysWow64\MaJGUILib.dll
2011-07-26 14:26 . 2011-07-26 14:26 45056 —-a-w- c:\windows\SysWow64\MaXMLProto.dll
2011-07-26 14:26 . 2011-07-26 14:26 45056 —-a-w- c:\windows\SysWow64\MACXMLProto.dll
2011-07-26 14:26 . 2011-07-26 14:26 40960 —-a-w- c:\windows\SysWow64\MTTELECHIP.dll
2011-07-03 06:28 59839 –sh–w- c:\windows\dtmn.exe
2011-07-03 06:28 66044 –sh–w- c:\windows\kdhr.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Pando Media Booster"="c:\program files (x86)\Pando Networks\Media Booster\PMB.exe" [2011-08-31 3077528]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2011-08-02 4910912]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2011-10-13 19550344]
"KiesPDLR"="c:\program files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe" [2011-08-22 20880]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584]
"Facebook Update"="c:\users\blur\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2011-10-19 137536]
"Steam"="c:\program files (x86)\Steam\steam.exe" [2011-10-19 1242448]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-07-06 98304]
"IAStorIcon"="c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe" [2010-04-27 284696]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-01-21 91520]
"YouCam Mirage"="c:\program files (x86)\CyberLink\YouCam\YCMMirage.exe" [2010-08-20 136488]
"YouCam Tray"="c:\program files (x86)\CyberLink\YouCam\YouCamTray.exe" [2010-08-20 162912]
"KiesHelper"="c:\program files (x86)\Samsung\Kies\KiesHelper.exe" [2011-08-22 958352]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-07-05 421888]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-08-18 421736]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2010-4-29 1127712]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 dc3d;MS Hardware Device Detection Driver;c:\windows\system32\DRIVERS\dc3d.sys [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [x]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S1 SABI;SAMSUNG Kernel Driver For Windows 7;c:\windows\system32\Drivers\SABI.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 CDMA Device Service;CDMA Device Service;c:\program files (x86)\Samsung\USB Drivers\26_VIA_driver2\amd64\VIAService.exe [2011-08-02 159232]
S2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-04-27 13336]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files (x86)\Lavasoft\Ad-Aware\AAWService.exe [2011-10-19 2151640]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 btwampfl;Bluetooth AMP USB Filter;c:\windows\system32\drivers\btwampfl.sys [x]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x]
S3 clwvd;CyberLink WebCam Virtual Driver;c:\windows\system32\DRIVERS\clwvd.sys [x]
S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [x]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [x]
.
.
Contents of the 'Scheduled Tasks' folder
.
2011-10-19 c:\windows\Tasks\At2.job
- c:\windows\kdhr.exe [2011-07-03 06:28]
.
2011-10-19 c:\windows\Tasks\At5.job
- c:\windows\dtmn.exe [2011-07-03 06:28]
.
2011-10-19 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-627378357-1148813155-1286181338-1000Core.job
- c:\users\blur\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-10-19 15:21]
.
2011-10-19 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-627378357-1148813155-1286181338-1000UA.job
- c:\users\blur\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-10-19 15:21]
.
2011-10-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-627378357-1148813155-1286181338-1000Core.job
- c:\users\blur\AppData\Local\Google\Update\GoogleUpdate.exe [2011-08-31 19:05]
.
2011-10-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-627378357-1148813155-1286181338-1000UA.job
- c:\users\blur\AppData\Local\Google\Update\GoogleUpdate.exe [2011-08-31 19:05]
.
.
——— x86-64 ———–
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-08-07 10144288]
"Broadcom Wireless Manager UI"="c:\program files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.exe" [2010-04-09 5390336]
"KiesTrayAgent"="c:\program files (x86)\Samsung\Kies\KiesTrayAgent.exe" [2011-08-22 3507088]
"Logitech Download Assistant"="c:\windows\system32\rundll32.exe" [2009-07-14 45568]
"combofix"="c:\combofix\CF3674.3XE" [2010-11-21 345088]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
——- Supplementary Scan ——-
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~2\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~2\MICROS~2\Office14\ONBttnIE.dll/105
IE: Send image to &Bluetooth Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = [removed] [removed]
FF - ProfilePath - c:\users\blur\AppData\Roaming\Mozilla\Firefox\Profiles\eiqg1dj6.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.flickr.com/explore
FF - prefs.js: network.proxy.type - 0
.
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,ab,e4,60,55,55,03,cf,45,9d,f7,7c,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,ab,e4,60,55,55,03,cf,45,9d,f7,7c,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
———————— Other Running Processes ————————
.
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\Bonjour\mDNSResponder.exe
c:\program files (x86)\Lavasoft\Ad-Aware\AAWTray.exe
.
**************************************************************************
.
Completion time: 2011-10-20 00:14:58 - machine was rebooted
ComboFix-quarantined-files.txt 2011-10-19 21:14
.
Pre-Run: 119.490.039.808 bytes free
Post-Run: 119.685.287.936 bytes free
.
- - End Of File - - E78621683151B2FF4B15F4C29FEA8CA8

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :Otl
    [2011.10.18 22:52:01 | 000,000,324 | —- | M] () – C:\Windows\tasks\At5.job
    [2011.10.18 22:48:01 | 000,000,324 | —- | M] () – C:\Windows\tasks\At4.job
    [2011.10.18 22:44:20 | 000,000,324 | —- | M] () – C:\Windows\tasks\At3.job
    [2011.10.18 22:40:19 | 000,000,324 | —- | M] () – C:\Windows\tasks\At2.job
    [2011.10.18 22:36:18 | 000,000,324 | —- | M] () – C:\Windows\tasks\At1.job
    
    :Commands
    [RESETHOSTS]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )






  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.








Also tell me how the computer is running now.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI