This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Searchqu removal [Solved]

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello, guys from WaththeTech.
As many others before me, I also need your help to get rid of the Searchqu virus.

OTL.Txt


OTL logfile created on: 17/12/2011 19:49:33 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Alberto\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000C0A | Country: España | Language: ESN | Date Format: dd/MM/yyyy

3,00 Gb Total Physical Memory | 1,64 Gb Available Physical Memory | 54,55% Memory free
6,23 Gb Paging File | 4,53 Gb Available in Paging File | 72,78% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 76,19 Gb Total Space | 27,08 Gb Free Space | 35,55% Space Free | Partition Type: NTFS
Drive D: | 11,35 Gb Total Space | 2,16 Gb Free Space | 18,99% Space Free | Partition Type: NTFS
Drive F: | 145,34 Gb Total Space | 89,35 Gb Free Space | 61,48% Space Free | Partition Type: NTFS

Computer Name: LAPTOP-DE-BERTO | User Name: Alberto | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Alberto\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Users\Alberto\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc)
PRC - C:\Users\Alberto\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
PRC - C:\Users\Alberto\Desktop\KeyState.exe (Paul Heinrich)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Program Files\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Bandoo Media, inc)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
PRC - C:\Program Files\DivX\DivX Plus Web Player\DDMService.exe (DivX, LLC)
PRC - C:\ProgramData\DatacardService\DCService.exe ()
PRC - C:\ProgramData\DatacardService\DCSHelper.exe (Huawei Technologies Co., Ltd.)
PRC - C:\Program Files\Common Files\Firebird\bin\fb_inet_server.exe (Firebird Project)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Users\Alberto\AppData\Roaming\MTN Online\ouc.exe (Huawei Technologies Co., Ltd.)
PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH)
PRC - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqste08.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqbam08.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqgpc01.exe (Hewlett-Packard)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Program Files\Synaptics\SynTP\SynTPStart.exe (Synaptics, Inc.)
PRC - C:\WINDOWS\System32\WTablet\Pen_TabletUser.exe (Wacom Technology, Corp.)
PRC - C:\WINDOWS\System32\Pen_Tablet.exe (Wacom Technology, Corp.)
PRC - C:\Apache2\bin\Apache.exe (Apache Software Foundation)
PRC - C:\MySQL\bin\mysqld-nt.exe ()
PRC - C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe ()
PRC - C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe (Hewlett-Packard)


========== Modules (No Company Name) ==========

MOD - C:\Users\Alberto\AppData\Local\Google\Chrome\Application\16.0.912.63\ppGoogleNaClPluginChrome.dll ()
MOD - C:\Users\Alberto\AppData\Local\Google\Chrome\Application\16.0.912.63\pdf.dll ()
MOD - C:\Users\Alberto\AppData\Local\Google\Chrome\Application\16.0.912.63\avutil-51.dll ()
MOD - C:\Users\Alberto\AppData\Local\Google\Chrome\Application\16.0.912.63\avformat-53.dll ()
MOD - C:\Users\Alberto\AppData\Local\Google\Chrome\Application\16.0.912.63\avcodec-53.dll ()
MOD - C:\Users\Alberto\AppData\Local\Google\Chrome\Application\16.0.912.63\gcswf32.dll ()
MOD - C:\Users\Alberto\AppData\Local\Google\Chrome\APPLIC~1\160912~1.63\gcswf32.dll ()
MOD - C:\Program Files\DivX\DivX Update\DivXUpdateCheck.dll ()
MOD - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files\WinRAR\RarExt.dll ()
MOD - C:\Program Files\Hp\QuickPlay\Kernel\TV\CLTinyDB.dll ()
MOD - C:\Program Files\Hp\QuickPlay\Kernel\TV\CLCapEngine.dll ()
MOD - C:\Program Files\Hp\QuickPlay\Kernel\TV\CLSchMgr.dll ()
MOD - C:\Program Files\Hp\QuickPlay\Kernel\TV\CLCapSvcps.dll ()
MOD - C:\Program Files\Hp\QuickPlay\Kernel\common\MCEMediaStatus.dll ()
MOD - C:\Program Files\Common Files\LightScribe\QtGui4.dll ()
MOD - C:\Program Files\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll ()
MOD - C:\Program Files\Common Files\LightScribe\QtCore4.dll ()
MOD - C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnfps.dll ()
MOD - C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe ()


========== Win32 Services (SafeList) ==========

SRV - (Akamai) – c:\program files\common files\akamai/netsession_win_b427739.dll ()
SRV - (AntiVirService) – C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (AntiVirSchedulerService) – C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (DCService.exe) – C:\ProgramData\DatacardService\DCService.exe ()
SRV - (FirebirdServerDefaultInstance) – C:\Program Files\Common Files\Firebird\bin\fb_inet_server.exe (Firebird Project)
SRV - (HPSLPSVC) – C:\Program Files\Hewlett-Packard\Digital Imaging\bin\HPSLPSVC32.DLL (Hewlett-Packard Co.)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (Macromedia Licensing Service) – C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe ()
SRV - (hpqddsvc) – C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqddsvc.dll (Hewlett-Packard Co.)
SRV - (hpqcxs08) – C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqcxs08.dll (Hewlett-Packard Co.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (TabletServicePen) – C:\WINDOWS\System32\Pen_Tablet.exe (Wacom Technology, Corp.)
SRV - (Com4Qlb) – C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe (Hewlett-Packard Development Company, L.P.)
SRV - (Apache2) – C:\Apache2\bin\Apache.exe (Apache Software Foundation)
SRV - (MySql) – C:\MySQL\bin\mysqld-nt.exe ()


========== Driver Services (SafeList) ==========

DRV - (FNETURPX) – C:\WINDOWS\System32\drivers\FNETURPX.SYS (FNet Co., Ltd.)
DRV - (avipbb) – C:\WINDOWS\System32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) – C:\WINDOWS\System32\drivers\avgntflt.sys (Avira GmbH)
DRV - (ewusbnet) – C:\WINDOWS\System32\drivers\ewusbnet.sys (Huawei Technologies Co., Ltd.)
DRV - (hwdatacard) – C:\WINDOWS\System32\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (huawei_enumerator) – C:\WINDOWS\System32\drivers\ew_jubusenum.sys (Huawei Technologies Co., Ltd.)
DRV - (ew_hwusbdev) – C:\WINDOWS\System32\drivers\ew_hwusbdev.sys (Huawei Technologies Co., Ltd.)
DRV - (ssmdrv) – C:\WINDOWS\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (avgio) – C:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (USBModem) – C:\WINDOWS\System32\drivers\lgusbmodem.sys (LG Electronics Inc.)
DRV - (usbbus) – C:\WINDOWS\System32\drivers\lgusbbus.sys (LG Electronics Inc.)
DRV - (UsbDiag) – C:\WINDOWS\System32\drivers\lgusbdiag.sys (LG Electronics Inc.)
DRV - (athr) – C:\WINDOWS\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (nvlddmkm) – C:\WINDOWS\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (HdAudAddService) – C:\WINDOWS\System32\drivers\CHDART.sys (Conexant Systems Inc.)
DRV - (HpqRemHid) – C:\WINDOWS\System32\drivers\HpqRemHid.sys (Hewlett-Packard Development Company, L.P.)
DRV - (XAudio) – C:\WINDOWS\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (HpqKbFiltr) – C:\WINDOWS\System32\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (rismxdp) – C:\WINDOWS\System32\drivers\rixdptsk.sys (REDC)
DRV - (NVENETFD) – C:\WINDOWS\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (rimmptsk) – C:\WINDOWS\System32\drivers\rimmptsk.sys (REDC)
DRV - (nvsmu) – C:\WINDOWS\System32\drivers\nvsmu.sys (NVIDIA Corporation)
DRV - (wacommousefilter) – C:\WINDOWS\System32\drivers\wacommousefilter.sys (Wacom Technology)
DRV - (wacomvhid) – C:\WINDOWS\System32\drivers\wacomvhid.sys (Wacom Technology)
DRV - (WacomVKHid) – C:\WINDOWS\System32\drivers\WacomVKHid.sys (Wacom Technology)
DRV - (rimsptsk) – C:\WINDOWS\System32\drivers\rimsptsk.sys (REDC)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.searchqu.com/406
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Search Results"
FF - prefs.js..browser.search.order.1: "Search Results"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://www.searchqu.com/406"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.0.900
FF - prefs.js..extensions.enabledItems: {6904342A-8307-11DF-A508-4AE2DFD72085}:2.1.0.900
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..keyword.URL: "http://dts.search-results.com/sr?src=ffb&appid=102&systemid=406&q="
FF - prefs.js..keyword.enabled: false

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.0: C:\Users\Alberto\AppData\Roaming\Facebook\npfbplugin_1_0_0.dll ( )
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Alberto\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Alberto\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Hewlett-Packard\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/12/06 20:16:21 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\html5video [2010/12/30 08:58:37 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files\DivX\DivX Plus Web Player\firefox\wpa [2010/12/30 08:58:37 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/11/11 18:49:48 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/10/28 06:47:39 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Hewlett-Packard\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/12/06 20:16:21 | 000,000,000 | —D | M]

[2011/07/01 22:18:48 | 000,000,000 | —D | M] (No name found) – C:\Users\Alberto\AppData\Roaming\mozilla\Extensions
[2010/02/18 21:39:24 | 000,000,000 | —D | M] (No name found) – C:\Users\Alberto\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2010/10/08 20:26:59 | 000,000,000 | —D | M] (No name found) – C:\Users\Alberto\AppData\Roaming\mozilla\Extensions\[removed]
[2011/08/04 18:46:56 | 000,000,000 | —D | M] (No name found) – C:\Users\Alberto\AppData\Roaming\mozilla\Firefox\Profiles\9wozrfnp.default\extensions
[2011/03/26 12:31:57 | 000,000,000 | —D | M] (Fissa) – C:\Users\Alberto\AppData\Roaming\mozilla\Firefox\Profiles\9wozrfnp.default\extensions\@FissaPlugin
[2011/07/01 22:17:52 | 000,002,501 | —- | M] () – C:\Users\Alberto\AppData\Roaming\Mozilla\Firefox\Profiles\9wozrfnp.default\searchplugins\SearchResults.xml
[2011/11/12 12:02:06 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/10/30 11:29:09 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
[2011/11/11 18:49:47 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/10/03 05:06:04 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/09/29 06:09:58 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/09/29 06:09:58 | 000,003,996 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\drae.xml
[2011/09/29 06:09:58 | 000,001,143 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay-es.xml
[2011/09/29 06:09:58 | 000,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia-es.xml
[2011/09/29 06:09:58 | 000,001,102 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo-es.xml

========== Chrome ==========

CHR - default_search_provider: Search Results (Enabled)
CHR - default_search_provider: search_url = http://dts.search-results.com/sr?src=crb&a…q={searchTerms}
CHR - default_search_provider: suggest_url =
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Alberto\AppData\Local\Google\Chrome\Application\16.0.912.63\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U26 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: DivX Web Player (Enabled) = C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Alberto\AppData\Local\Google\Chrome\Application\16.0.912.63\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Alberto\AppData\Local\Google\Chrome\Application\16.0.912.63\pdf.dll
CHR - plugin: DivX Player Netscape Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npDivxPlayerPlugin.dll
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: MetaStream 3 Plugin (Enabled) = C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Alberto\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Facebook Plugin (Enabled) = C:\Users\Alberto\AppData\Roaming\Facebook\npfbplugin_1_0_0.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:\Users\Alberto\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.2_0\
CHR - Extension: B\u00FAsqueda de Google = C:\Users\Alberto\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.14_0\
CHR - Extension: B\u00FAsqueda de Google = C:\Users\Alberto\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.16_0\
CHR - Extension: DivX HiQ = C:\Users\Alberto\AppData\Local\Google\Chrome\User Data\Default\Extensions\fnjbmmemklcjgepojigaapkoodmkgbae\2.1.0.900_0\
CHR - Extension: \u003Cvideo\u003E de HTML5 de DivX Plus Web Player = C:\Users\Alberto\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.0.900_0\
CHR - Extension: Gmail = C:\Users\Alberto\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\6.1.4_0\

O1 HOSTS File: ([2003/06/20 13:11:12 | 000,000,056 | —- | M]) - C:\WINDOWS\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost first_virtualhost second_virtualhost
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\Hewlett-Packard\Digital Imaging\smart web printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (DivX Plus Web Player HTML5 ) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No CLSID value found.
O2 - BHO: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Program Files\Windows iLivid Toolbar\Datamngr\ToolBar\searchqudtx.dll ()
O2 - BHO: (UrlHelper Class) - {A40DC6C5-79D0-4ca8-A185-8FF989AF1115} - C:\Program Files\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Bandoo Media, inc)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\Hewlett-Packard\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Program Files\Windows iLivid Toolbar\Datamngr\ToolBar\searchqudtx.dll ()
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [AdobeCS4ServiceManager] C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [DATAMNGR] C:\Program Files\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Bandoo Media, inc)
O4 - HKLM..\Run: [DivX Download Manager] C:\Program Files\DivX\DivX Plus Web Player\DDmService.exe (DivX, LLC)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe File not found
O4 - HKLM..\Run: [hpqSRMon] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\HpqSRmon.exe (Hewlett-Packard)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvSvc] C:\Windows\System32\nvsvc.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe (Hewlett-Packard)
O4 - HKLM..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [AdobeBridge] File not found
O4 - HKCU..\Run: [Akamai NetSession Interface] C:\Users\Alberto\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc)
O4 - HKCU..\Run: [HPAdvisor] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe autoRun File not found
O4 - HKCU..\Run: [HW_OPENEYE_OUC_MTN Online] C:\Program Files\MTN Online\UpdateDog\ouc.exe (Huawei Technologies Co., Ltd.)
O4 - HKCU..\Run: [uTorrent] C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O4 - Startup: C:\Users\Alberto\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Alberto\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Users\Alberto\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\KeyState.lnk = C:\Users\Alberto\Desktop\KeyState.exe (Paul Heinrich)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O9 - Extra Button: Mostrar u ocultar HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\Hewlett-Packard\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{230D4951-C929-409D-9EBE-B27FDC570E79}: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AD40F387-3E50-4C9D-81A9-1E5158CEA54D}: DhcpNameServer = 10.0.0.2
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E9343E97-8C5C-42D2-ADC6-4ED724C705C2}: DhcpNameServer = [removed] [removed]
O20 - AppInit_DLLs: (c:\progra~1\wi371a~1\datamngr\datamngr.dll) -c:\Program Files\Windows iLivid Toolbar\Datamngr\datamngr.dll (Bandoo Media, inc)
O20 - AppInit_DLLs: (c:\progra~1\wi371a~1\datamngr\iebho.dll) -c:\Program Files\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Bandoo Media, inc)
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\WINDOWS\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: F:\Pictures\screensavers\fotolia-bosque.jpg
O24 - Desktop BackupWallPaper: F:\Pictures\screensavers\fotolia-bosque.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 22:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2005/09/11 16:18:54 | 000,000,340 | -HS- | M] () - D:\AUTOMODE – [ NTFS ]
O33 - MountPoints2\{1347a04c-c80a-11e0-8b2b-001e6869fb6b}\Shell - "" = AutoRun
O33 - MountPoints2\{1347a04c-c80a-11e0-8b2b-001e6869fb6b}\Shell\AutoRun\command - "" = H:\AutoRun.exe
O33 - MountPoints2\{1347a058-c80a-11e0-8b2b-001e6869fb6b}\Shell - "" = AutoRun
O33 - MountPoints2\{1347a058-c80a-11e0-8b2b-001e6869fb6b}\Shell\AutoRun\command - "" = H:\AutoRun.exe
O33 - MountPoints2\{1347a072-c80a-11e0-8b2b-001e6869fb6b}\Shell - "" = AutoRun
O33 - MountPoints2\{1347a072-c80a-11e0-8b2b-001e6869fb6b}\Shell\AutoRun\command - "" = H:\AutoRun.exe
O33 - MountPoints2\{1347a07e-c80a-11e0-8b2b-001e101fb681}\Shell - "" = AutoRun
O33 - MountPoints2\{1347a07e-c80a-11e0-8b2b-001e101fb681}\Shell\AutoRun\command - "" = H:\AutoRun.exe
O33 - MountPoints2\{171c20ae-c58b-11e0-856d-001e6869fb6b}\Shell - "" = AutoRun
O33 - MountPoints2\{171c20ae-c58b-11e0-856d-001e6869fb6b}\Shell\AutoRun\command - "" = H:\AutoRun.exe
O33 - MountPoints2\{2514a73f-d30a-11df-844f-001e6869fb6b}\Shell - "" = Autorun
O33 - MountPoints2\{2514a73f-d30a-11df-844f-001e6869fb6b}\Shell\downloadsb\command - "" = C:\Windows\explorer.exe – [2009/04/11 07:27:36 | 002,926,592 | —- | M] (Microsoft Corporation)
O33 - MountPoints2\{9b1c0f6f-fa4b-11de-9388-001e6869fb6b}\Shell - "" = AutoRun
O33 - MountPoints2\{9b1c0f6f-fa4b-11de-9388-001e6869fb6b}\Shell\AutoRun\command - "" = G:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{9b1c0f8e-fa4b-11de-9388-001e6869fb6b}\Shell - "" = AutoRun
O33 - MountPoints2\{9b1c0f8e-fa4b-11de-9388-001e6869fb6b}\Shell\AutoRun\command - "" = G:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{aa0a7ba3-c4f5-11e0-a7b1-001e6869fb6b}\Shell - "" = AutoRun
O33 - MountPoints2\{aa0a7ba3-c4f5-11e0-a7b1-001e6869fb6b}\Shell\AutoRun\command - "" = H:\AutoRun.exe
O33 - MountPoints2\{aa0a7bd3-c4f5-11e0-a7b1-001e6869fb6b}\Shell - "" = AutoRun
O33 - MountPoints2\{aa0a7bd3-c4f5-11e0-a7b1-001e6869fb6b}\Shell\AutoRun\command - "" = H:\AutoRun.exe
O33 - MountPoints2\{ef7e7748-c4fc-11e0-b46d-001e6869fb6b}\Shell - "" = AutoRun
O33 - MountPoints2\{ef7e7748-c4fc-11e0-b46d-001e6869fb6b}\Shell\AutoRun\command - "" = H:\AutoRun.exe
O33 - MountPoints2\{efdf5fc6-f068-11de-8860-001e6869fb6b}\Shell - "" = AutoRun
O33 - MountPoints2\{efdf5fc6-f068-11de-8860-001e6869fb6b}\Shell\AutoRun\command - "" = G:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{efdf5fcb-f068-11de-8860-001e6869fb6b}\Shell - "" = AutoRun
O33 - MountPoints2\{efdf5fcb-f068-11de-8860-001e6869fb6b}\Shell\AutoRun\command - "" = I:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\H\Shell - "" = AutoRun
O33 - MountPoints2\H\Shell\AutoRun\command - "" = H:\AutoRun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\WINDOWS\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - File not found
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.yv12 - C:\Windows\System32\DivX.dll (DivX, Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/12/17 19:45:27 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Users\Alberto\Desktop\OTL.exe
[2011/12/15 07:02:06 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2011/12/15 07:02:04 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2011/12/15 07:02:04 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2011/12/15 07:02:03 | 001,798,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2011/12/15 07:02:03 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2011/12/15 07:01:59 | 001,427,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2011/12/14 18:35:23 | 003,602,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2011/12/14 18:35:22 | 003,550,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2011/12/14 18:35:19 | 002,043,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2011/12/14 18:35:17 | 000,429,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EncDec.dll
[2011/12/14 18:35:13 | 000,049,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\csrsrv.dll
[2011/12/14 18:35:04 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[2011/12/12 17:30:29 | 000,000,000 | —D | C] – C:\ProgramData\FNET
[2011/12/12 17:29:41 | 000,007,936 | —- | C] (FNet Co., Ltd.) – C:\Windows\System32\drivers\FNETURPX.SYS
[2011/12/12 17:29:29 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Clone EX
[2011/12/12 17:29:25 | 000,000,000 | —D | C] – C:\Program Files\PcCloneEX
[2011/12/06 18:16:02 | 000,000,000 | —D | C] – F:\Documents\PROJECTS
[2011/12/06 11:00:08 | 000,000,000 | —D | C] – C:\Users\Alberto\aqbanking
[1 C:\Windows\System32\drivers\*.tmp files -> C:\Windows\System32\drivers\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/12/17 19:45:02 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Alberto\Desktop\OTL.exe
[2011/12/17 19:09:00 | 000,001,118 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-546974084-4041679086-764574024-1000UA.job
[2011/12/17 18:04:47 | 000,003,168 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/12/17 18:04:47 | 000,003,168 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/12/17 12:17:17 | 000,050,673 | —- | M] () – F:\Documents\Mis cuentas.gnucash.20110516201003.gnucash
[2011/12/17 12:17:16 | 000,050,293 | —- | M] () – F:\Documents\Mis cuentas.gnucash.20110516201003.gnucash.20111217121716.gnucash
[2011/12/17 12:12:29 | 009,979,732 | —- | M] () – C:\Windows\System32\perfh00A.dat
[2011/12/17 12:12:28 | 003,422,770 | —- | M] () – C:\Windows\System32\perfc00A.dat
[2011/12/17 12:12:27 | 003,514,340 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/12/17 12:12:25 | 002,904,386 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/12/17 12:08:15 | 000,027,525 | —- | M] () – C:\Users\Alberto\AppData\Roaming\nvModes.001
[2011/12/17 12:06:12 | 000,000,163 | —- | M] () – C:\Users\Public\Documents\hpqp.ini
[2011/12/17 12:04:45 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/12/16 17:43:57 | 000,000,413 | —- | M] () – C:\Users\Alberto\Desktop\BORRAR.lnk
[2011/12/16 17:19:34 | 000,002,683 | —- | M] () – C:\Users\Alberto\Desktop\Outlook 2007.lnk
[2011/12/15 08:24:14 | 002,308,720 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2011/12/15 08:19:09 | 000,050,035 | —- | M] () – F:\Documents\Mis cuentas.gnucash.20110516201003.gnucash.20111215081909.gnucash
[2011/12/15 08:09:00 | 000,001,066 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-546974084-4041679086-764574024-1000Core.job
[2011/12/13 21:21:16 | 000,049,890 | —- | M] () – F:\Documents\Mis cuentas.gnucash.20110516201003.gnucash.20111213212116.gnucash
[2011/12/13 16:43:19 | 000,049,644 | —- | M] () – F:\Documents\Mis cuentas.gnucash.20110516201003.gnucash.20111213164319.gnucash
[2011/12/12 22:30:34 | 000,122,880 | —- | M] () – C:\Users\Alberto\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/12/12 20:58:13 | 000,049,373 | —- | M] () – F:\Documents\Mis cuentas.gnucash.20110516201003.gnucash.20111212205813.gnucash
[2011/12/12 17:30:24 | 000,001,653 | —- | M] () – C:\Users\Public\Desktop\PC Clone EX.LNK
[2011/12/12 17:29:41 | 000,007,936 | —- | M] (FNet Co., Ltd.) – C:\Windows\System32\drivers\FNETURPX.SYS
[2011/12/07 07:09:35 | 000,000,932 | —- | M] () – C:\Users\Alberto\Desktop\Dropbox.lnk
[2011/12/07 07:09:35 | 000,000,912 | —- | M] () – C:\Users\Alberto\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2011/12/06 11:33:38 | 000,003,120 | —- | M] () – C:\Windows\System32\ALLFSAF8a.ocx
[2011/12/06 11:33:30 | 000,002,036 | —- | M] () – C:\Users\Public\Desktop\Style Builder 2.lnk
[2011/12/06 11:33:30 | 000,001,950 | —- | M] () – C:\Users\Public\Desktop\LayOut 3.lnk
[2011/12/06 11:33:29 | 000,001,869 | —- | M] () – C:\Users\Public\Desktop\Google SketchUp 8.lnk
[2011/12/06 11:02:54 | 000,000,218 | —- | M] () – C:\Users\Alberto\.recently-used.xbel
[2011/12/06 10:43:37 | 000,001,815 | —- | M] () – C:\Users\Public\Desktop\GnuCash.lnk
[2011/12/05 17:46:21 | 000,000,296 | —- | M] () – C:\Users\Alberto\Desktop\Descargas.lnk
[2011/12/04 16:32:22 | 000,000,431 | —- | M] () – C:\Users\Alberto\Desktop\PROJECTS.lnk
[2011/12/03 20:57:15 | 000,000,362 | —- | M] () – C:\Users\Alberto\Desktop\MUSICA.lnk
[2011/11/23 14:37:27 | 002,043,904 | —- | M] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2011/11/17 22:31:08 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[1 C:\Windows\System32\drivers\*.tmp files -> C:\Windows\System32\drivers\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/12/17 12:17:16 | 000,050,293 | —- | C] () – F:\Documents\Mis cuentas.gnucash.20110516201003.gnucash.20111217121716.gnucash
[2011/12/16 17:43:57 | 000,000,413 | —- | C] () – C:\Users\Alberto\Desktop\BORRAR.lnk
[2011/12/15 08:19:09 | 000,050,035 | —- | C] () – F:\Documents\Mis cuentas.gnucash.20110516201003.gnucash.20111215081909.gnucash
[2011/12/13 21:21:16 | 000,049,890 | —- | C] () – F:\Documents\Mis cuentas.gnucash.20110516201003.gnucash.20111213212116.gnucash
[2011/12/13 16:43:19 | 000,049,644 | —- | C] () – F:\Documents\Mis cuentas.gnucash.20110516201003.gnucash.20111213164319.gnucash
[2011/12/12 20:58:13 | 000,049,373 | —- | C] () – F:\Documents\Mis cuentas.gnucash.20110516201003.gnucash.20111212205813.gnucash
[2011/12/12 17:30:24 | 000,001,653 | —- | C] () – C:\Users\Public\Desktop\PC Clone EX.LNK
[2011/12/06 11:33:38 | 000,003,120 | —- | C] () – C:\Windows\System32\ALLFSAF8a.ocx
[2011/12/06 11:33:30 | 000,002,036 | —- | C] () – C:\Users\Public\Desktop\Style Builder 2.lnk
[2011/12/06 11:33:30 | 000,001,950 | —- | C] () – C:\Users\Public\Desktop\LayOut 3.lnk
[2011/12/06 11:02:54 | 000,000,218 | —- | C] () – C:\Users\Alberto\.recently-used.xbel
[2011/12/05 17:46:21 | 000,000,296 | —- | C] () – C:\Users\Alberto\Desktop\Descargas.lnk
[2011/12/04 16:32:22 | 000,000,431 | —- | C] () – C:\Users\Alberto\Desktop\PROJECTS.lnk
[2011/12/03 20:57:15 | 000,000,362 | —- | C] () – C:\Users\Alberto\Desktop\MUSICA.lnk
[2011/08/05 18:15:57 | 000,116,224 | —- | C] () – C:\Windows\System32\pdfcmnnt.dll
[2011/07/01 18:16:58 | 000,000,196 | —- | C] () – C:\Windows\System32\cpuz.ini
[2011/03/10 08:59:28 | 002,525,238 | —- | C] () – C:\Users\Alberto\AppData\Local\[j0002]-[p08].bmp
[2010/12/06 20:08:07 | 000,231,562 | —- | C] () – C:\Windows\hpoins43.dat.temp
[2010/12/06 19:49:44 | 000,231,686 | —- | C] () – C:\Windows\hpoins43.dat
[2010/12/06 19:08:07 | 000,000,113 | —- | C] () – C:\Windows\PhotoImpression.ini
[2010/12/06 13:40:03 | 000,000,601 | —- | C] () – C:\Windows\hpomdl43.dat.temp
[2010/11/14 19:41:03 | 000,128,396 | -H– | C] () – C:\Windows\System32\mlfcache.dat
[2010/05/28 20:18:41 | 000,019,456 | —- | C] () – C:\Users\Alberto\AppData\Local\WebpageIcons.db
[2010/05/19 18:10:37 | 000,007,592 | —- | C] () – C:\Users\Alberto\AppData\Local\d3d9caps.dat
[2010/03/11 17:50:32 | 000,078,245 | —- | C] () – C:\Windows\hpqins05.dat
[2010/03/08 20:11:48 | 000,162,174 | —- | C] () – C:\Windows\hpoins21.dat.temp
[2010/03/08 20:11:48 | 000,008,138 | —- | C] () – C:\Windows\hpomdl21.dat.temp
[2010/02/18 21:39:24 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat
[2010/01/31 17:10:51 | 000,000,056 | -H– | C] () – C:\Windows\System32\ezsidmv.dat
[2010/01/29 22:11:51 | 000,000,601 | —- | C] () – C:\Windows\hpomdl43.dat
[2010/01/10 21:22:38 | 000,019,582 | —- | C] () – C:\Windows\hpqins13.dat
[2009/12/22 12:41:28 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/12/22 12:41:28 | 000,107,612 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2009/12/21 19:38:38 | 000,164,807 | —- | C] () – C:\Windows\hpoins21.dat
[2009/12/21 16:59:16 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2009/12/20 17:35:54 | 000,122,880 | —- | C] () – C:\Users\Alberto\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/12/20 14:50:11 | 004,244,744 | —- | C] () – C:\Windows\System32\qtp-mt334.dll
[2009/12/20 14:50:11 | 000,247,560 | —- | C] () – C:\Windows\System32\prgiso.dll
[2009/12/20 14:50:11 | 000,013,576 | —- | C] () – C:\Windows\System32\wnaspi32.dll
[2009/12/20 14:40:04 | 000,027,525 | —- | C] () – C:\Users\Alberto\AppData\Roaming\nvModes.001
[2009/12/20 14:39:45 | 000,027,525 | —- | C] () – C:\Users\Alberto\AppData\Roaming\nvModes.dat
[2008/03/21 22:08:49 | 000,016,480 | —- | C] () – C:\Windows\System32\rixdicon.dll
[2008/03/21 22:04:38 | 000,001,732 | —- | C] () – C:\Windows\System32\drivers\nvphy.bin
[2008/02/25 06:55:57 | 000,336,930 | —- | C] () – C:\Windows\System32\perfi00A.dat
[2008/02/25 06:55:56 | 009,979,732 | —- | C] () – C:\Windows\System32\perfh00A.dat
[2008/02/25 06:55:56 | 003,422,770 | —- | C] () – C:\Windows\System32\perfc00A.dat
[2008/02/25 06:55:56 | 000,040,258 | —- | C] () – C:\Windows\System32\perfd00A.dat
[2007/09/05 19:26:30 | 000,007,262 | —- | C] () – C:\Windows\hpomdl21.dat
[2006/11/02 13:57:28 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 13:47:37 | 002,308,720 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 13:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 11:33:01 | 003,514,340 | —- | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 11:33:01 | 002,904,386 | —- | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 11:33:01 | 000,287,440 | —- | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 11:33:01 | 000,030,674 | —- | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 11:25:21 | 000,061,440 | —- | C] () – C:\Windows\System32\igfxTMM.dll
[2006/11/02 11:23:21 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2006/11/02 09:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/02 09:19:00 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/02 08:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 08:25:31 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2006/03/09 23:58:00 | 001,060,424 | —- | C] () – C:\Windows\System32\WdfCoInstaller01000.dll
[2004/05/18 16:10:30 | 000,000,172 | —- | C] () – C:\Windows\my.ini
[2004/03/25 09:33:48 | 000,040,620 | —- | C] () – C:\Windows\php.ini
[2000/04/14 16:50:02 | 000,343,040 | —- | C] () – C:\Windows\System32\Lffpx7.dll
[1998/06/11 14:08:06 | 000,095,232 | —- | C] () – C:\Windows\System32\Lfkodak.dll

========== LOP Check ==========

[2011/04/23 09:19:34 | 000,000,000 | —D | M] – C:\Users\Alberto\AppData\Roaming\BalsamiqMockupsForDesktop.EDE15CF69E11F7F7D45B5430C7D37CC6C3545E3C.1
[2011/04/05 16:06:36 | 000,000,000 | —D | M] – C:\Users\Alberto\AppData\Roaming\Blender Foundation
[2010/12/06 19:05:01 | 000,000,000 | —D | M] – C:\Users\Alberto\AppData\Roaming\Carpeta de carga de Share-to-Web
[2009/12/21 23:32:09 | 000,000,000 | —D | M] – C:\Users\Alberto\AppData\Roaming\com.adobe.ExMan
[2011/12/17 17:00:28 | 000,000,000 | —D | M] – C:\Users\Alberto\AppData\Roaming\Dropbox
[2010/01/18 10:10:19 | 000,000,000 | —D | M] – C:\Users\Alberto\AppData\Roaming\Facebook
[2011/03/26 12:31:54 | 000,000,000 | —D | M] – C:\Users\Alberto\AppData\Roaming\FissaSearch
[2011/05/07 16:30:51 | 000,000,000 | —D | M] – C:\Users\Alberto\AppData\Roaming\GetRightToGo
[2011/12/06 11:01:21 | 000,000,000 | —D | M] – C:\Users\Alberto\AppData\Roaming\gtk-2.0
[2010/03/26 18:42:13 | 000,000,000 | —D | M] – C:\Users\Alberto\AppData\Roaming\LG Electronics
[2010/12/30 08:58:42 | 000,000,000 | —D | M] – C:\Users\Alberto\AppData\Roaming\Local
[2011/08/13 15:58:47 | 000,000,000 | —D | M] – C:\Users\Alberto\AppData\Roaming\MTN Online
[2011/03/26 12:31:06 | 000,000,000 | —D | M] – C:\Users\Alberto\AppData\Roaming\OfferBox
[2011/10/26 19:08:07 | 000,000,000 | —D | M] – C:\Users\Alberto\AppData\Roaming\pdfforge
[2010/10/08 20:26:55 | 000,000,000 | —D | M] – C:\Users\Alberto\AppData\Roaming\Philips-Songbird
[2011/03/01 23:01:54 | 000,000,000 | —D | M] – C:\Users\Alberto\AppData\Roaming\Quark
[2011/12/10 02:03:14 | 000,000,000 | —D | M] – C:\Users\Alberto\AppData\Roaming\Spotify
[2010/02/18 21:39:23 | 000,000,000 | —D | M] – C:\Users\Alberto\AppData\Roaming\Thunderbird
[2011/12/17 19:56:54 | 000,000,000 | —D | M] – C:\Users\Alberto\AppData\Roaming\uTorrent
[2009/12/24 11:34:14 | 000,000,000 | —D | M] – C:\Users\Alberto\AppData\Roaming\Vodafone
[2011/08/05 01:00:00 | 000,000,338 | —- | M] () – C:\Windows\Tasks\Quark Updater.job
[2011/12/16 18:09:58 | 000,032,580 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2006/09/18 22:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/04/11 07:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2006/09/18 22:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2010/02/16 14:38:39 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2008/02/24 23:23:46 | 000,000,360 | -H– | M] () – C:\IPH.PH
[2010/12/06 19:16:42 | 000,000,000 | —- | M] () – C:\Log.txt
[2010/02/16 14:38:39 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/02/29 16:44:34 | 000,052,576 | —- | M] () – C:\orange.bmp
[2011/12/17 12:04:38 | 3534,274,560 | -HS- | M] () – C:\pagefile.sys
[2011/11/25 17:59:43 | 000,000,000 | —- | M] () – C:\Tech_Vista.log
[1 C:\*.tmp files -> C:\*.tmp -> ]

< %systemroot%\Fonts\*.com >
[2006/11/02 13:37:12 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 13:37:12 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 13:37:12 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2010/01/01 21:35:51 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/09/18 22:37:34 | 000,000,065 | -H– | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/04/16 14:08:20 | 000,312,832 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\hpfpp70v.dll
[2007/03/15 15:32:10 | 000,274,944 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\hpzpp5ha.dll
[2008/01/18 23:34:30 | 000,089,600 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\HPZPPLHN.DLL
[2006/11/02 13:35:48 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 19:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\msonpppr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/12/20 23:24:09 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2006/11/02 11:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2006/11/02 11:34:05 | 000,020,480 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2006/11/02 11:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 11:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 11:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/04/25 05:29:17 | 000,000,716 | -HS- | M] () – C:\Users\Alberto\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/10/19 21:07:55 | 000,354,304 | —- | M] (Paul Heinrich) – C:\Users\Alberto\Desktop\KeyState.exe
[2011/12/17 19:45:02 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Alberto\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-12-17 11:11:46

========== Alternate Data Streams ==========

@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:9C4887B2

< End of report >
And Extras.Txt


OTL Extras logfile created on: 17/12/2011 19:49:33 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Alberto\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000C0A | Country: España | Language: ESN | Date Format: dd/MM/yyyy

3,00 Gb Total Physical Memory | 1,64 Gb Available Physical Memory | 54,55% Memory free
6,23 Gb Paging File | 4,53 Gb Available in Paging File | 72,78% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 76,19 Gb Total Space | 27,08 Gb Free Space | 35,55% Space Free | Partition Type: NTFS
Drive D: | 11,35 Gb Total Space | 2,16 Gb Free Space | 18,99% Space Free | Partition Type: NTFS
Drive F: | 145,34 Gb Total Space | 89,35 Gb Free Space | 61,48% Space Free | Partition Type: NTFS

Computer Name: LAPTOP-DE-BERTO | User Name: Alberto | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.js [@ = Reg Error: Value error.] – Reg Error: Key error. File not found

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Google\Chrome\Application\chrome.exe" – "%1"
https [open] – "C:\Program Files\Google\Chrome\Application\chrome.exe" – "%1"
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
jsfile – Reg Error: Value error.
jsfile [open] – Reg Error: Value error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 0
"InternetSettingsDisableNotify" = 0
"AutoUpdateDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\S-1-5-21-546974084-4041679086-764574024-1000]
"EnableNotifications" = 1
"EnableNotificationsRef" = 2

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{04774858-7CB0-49AC-9342-4C228DC5366F}" = lport=139 | protocol=6 | dir=in | app=system |
"{0786ABA5-C501-44B1-B532-60184F6522E6}" = rport=139 | protocol=6 | dir=out | app=system |
"{171DFBBA-0299-494F-AA8E-3AE7FE9FDB0B}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |
"{1D1149AC-B6EB-4841-B712-2D25580465A9}" = lport=51001 | protocol=6 | dir=in | name=adobe version cue cs4 server |
"{21750A71-7673-4D0A-BEDB-E8AD1FD904E1}" = lport=5000 | protocol=17 | dir=in | name=akamai netsession interface |
"{2B09341B-AAB9-45B7-962A-844F65FEB4CD}" = lport=52328 | protocol=6 | dir=in | name=akamai netsession interface |
"{380FF4A6-72F2-4988-ACE2-85A839DD0554}" = lport=3704 | protocol=6 | dir=in | name=adobe version cue cs4 server |
"{434F6E8B-56E5-4379-825A-3157F3C66966}" = lport=138 | protocol=17 | dir=in | app=system |
"{4DD8B6E8-F0BD-462B-96C7-BB6A6FAFD841}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{5AEBCC83-DDA2-40CC-92AC-1C9435999CA7}" = rport=138 | protocol=17 | dir=out | app=system |
"{6B7A56C1-2BE9-4C24-B19A-94728A5345D4}" = rport=137 | protocol=17 | dir=out | app=system |
"{89C9DE60-AC23-4858-BA40-07255E247700}" = lport=3703 | protocol=6 | dir=in | name=adobe version cue cs4 server |
"{8A4067B1-78D3-4C58-A1B8-60C70536A442}" = lport=5353 | protocol=6 | dir=in | name=adobe csi cs4 |
"{966EC4A6-082C-485C-BE9A-75876F1C40FE}" = rport=445 | protocol=6 | dir=out | app=system |
"{98D76532-4865-47F0-BFA5-4B4E2314160C}" = lport=445 | protocol=6 | dir=in | app=system |
"{9A763BD3-3C10-450E-883C-B69FA29C682F}" = lport=5353 | protocol=6 | dir=in | name=adobe csi cs4 |
"{A30DA301-0307-4CFC-92FE-B4E28E55077B}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{BC08E43D-F99C-4C20-9F35-EEB7FC983103}" = rport=427 | protocol=17 | dir=in | svc=hpslpsvc | app=c:\windows\system32\svchost.exe |
"{CBF9717A-279B-4F92-A8D3-1C794AD528EC}" = lport=51000 | protocol=6 | dir=in | name=adobe version cue cs4 server |
"{DCF1B851-6A8E-4377-893D-EF65E40BBEEE}" = lport=137 | protocol=17 | dir=in | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0024FEFD-0888-4232-BE69-2A66A0EB3402}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{00B258B9-FB13-40A7-94A3-6CD732662F65}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{01EFE09A-7C77-4D06-9539-DACADA83E8F8}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{0230F1CD-9B46-495E-A8E3-3E37C4A8B3BC}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{05170512-D682-456F-8310-557B0FD753B7}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{060C25E1-CCB4-449C-A5EB-24A3CAA201DD}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{0A81F3E3-C924-4C3A-9C08-2E89CE181DEB}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{0BFE4E6B-86D7-4E17-8BE3-2A12C99CFD17}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{0D777E58-75CA-4BC8-9BA0-4FC74A0771A1}" = dir=in | app=c:\program files\hewlett-packard\digital imaging\bin\hpqtra08.exe |
"{0EE6417A-678C-4CE0-9A88-5B49264A7C34}" = protocol=6 | dir=in | app=c:\program files\spotify\spotify.exe |
"{148AB5B7-50D2-4CAB-A067-B32EB10D23D7}" = dir=in | app=c:\program files\itunes\itunes.exe |
"{15DACB7C-D05D-4D48-88DD-BE1DED65BCDC}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{17243352-E78C-4B15-9FAD-CCDF16CC4CCE}" = protocol=6 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
"{1AC3088F-1140-46A3-9A3E-00D3B4493A96}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{1AF6E9D6-91B0-423D-B582-CA9FFBA5A937}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{1C7D0873-9645-4A2A-B3CF-5A7D5446D0B4}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{1C91A224-3CA0-4BDC-B0BB-C00BF4F1DDD3}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{1EB9BA19-C20F-49C6-AC6B-62B994F441B1}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{1EDB8083-15F3-4729-8BB2-09B4D1C025D0}" = protocol=17 | dir=in | app=c:\program files\common files\adobe\cs4servicemanager\cs4servicemanager.exe |
"{1F5BBA05-4B56-401D-A160-D37AC6EFA3E9}" = dir=in | app=c:\program files\hewlett-packard\digital imaging\bin\hpqste08.exe |
"{1FB6FA2E-24EF-4161-AF72-293C5E465810}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{2072A10B-9CF0-4445-8CA9-69C2EFB4990A}" = protocol=6 | dir=in | app=c:\program files\gnucash\bin\gconfd-2.exe |
"{2209F96F-4F6B-44EB-A80C-7A2DDF37E2B4}" = protocol=6 | dir=in | app=c:\program files\windows ilivid toolbar\datamngr\toolbar\dtuser.exe |
"{2330F67D-C1F0-4AC4-86DE-916C36DBF512}" = protocol=6 | dir=in | app=c:\program files\spotify\spotify.exe |
"{23EAEB21-6AD7-4EBE-87C4-4DA7BC70C9F6}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{2497EFF0-D2D5-40F7-80FC-BA8337235303}" = dir=in | app=c:\program files\common files\hp\digital imaging\bin\hpqphotocrm.exe |
"{24E26D10-BCB1-4764-8734-DCBEA10E4272}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{24F1B1FE-F8A2-48F9-A3E7-B45DF09385DE}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{25148023-1BD1-47CE-B171-EFB548F8E1D0}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{252B36A1-D74A-45FD-9E4D-BDD04F7B5D60}" = dir=in | app=c:\program files\hewlett-packard\digital imaging\bin\hpqusgm.exe |
"{25A6B0E6-7B8E-4F2C-977C-321144CBEB0B}" = dir=in | app=c:\program files\hewlett-packard\digital imaging\bin\hpofxs08.exe |
"{25BF8927-5AE5-45C6-B56B-CFE5E9005555}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{264A7B2A-3D8D-48C2-8F0F-017529239E67}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{276B7654-F59A-43AE-898F-82C2D4D4E453}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{283A8F80-AE98-4096-A0C2-D8C7D531AC2F}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{2A9BFA92-CDDB-41F6-8F2C-824F8B9C6F65}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{2E2835D0-5A83-4BEB-B7C7-0B1E447C713E}" = protocol=17 | dir=in | app=c:\program files\gnucash\bin\gnucash.exe |
"{2E490276-5F1C-4168-8C58-E6C1012E115B}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{2E62DCFE-14CB-4EE7-9D4C-987D60AA8A3C}" = dir=in | app=c:\program files\hewlett-packard\digital imaging\bin\hpzwiz01.exe |
"{2E8CA1EF-0DF5-4618-B1C1-3614EC1A4361}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{31F74801-D605-4AF2-A507-0E393221E9A6}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{3479FEFE-38AF-4E25-A79F-09036AAF57F3}" = protocol=6 | dir=in | app=c:\program files\gnucash\bin\gnucash.exe |
"{37C94DC7-F501-4945-87FC-F7827BF3806D}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{39377090-E02C-4C5B-84B8-47EC0DF361EA}" = dir=in | app=c:\program files\hewlett-packard\digital imaging\bin\hpqnrs08.exe |
"{3A157657-A0A9-4D19-979B-65F690F204E2}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{3A6960A9-80B0-4AB3-A901-F9085342AADD}" = dir=in | app=c:\program files\hewlett-packard\digital imaging\bin\hpoews01.exe |
"{3D73E8B8-0663-46C3-B3B5-955AE234F94F}" = protocol=17 | dir=in | app=c:\program files\skype\plugin manager\skypepm.exe |
"{3F53030F-228B-4A7F-8959-80F5B4049A22}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{44E6EE9D-DC7D-4FBE-AB58-90B963CA4E73}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{472AF15A-BF87-4F90-AB24-4602EE555CB7}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{47A6D20F-C154-4610-A057-3CDEFB77AC24}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{49F9DB7F-B867-40F7-8D50-E8C672C35CEE}" = dir=in | app=c:\program files\skype\plugin manager\skypepm.exe |
"{4B79771D-26A4-4677-ADF5-70C51679AFB6}" = dir=in | app=c:\program files\hewlett-packard\digital imaging\bin\hpqgpc01.exe |
"{4EDCB310-B5B2-4380-8954-6C930BDD02B7}" = protocol=17 | dir=in | app=c:\users\alberto\appdata\roaming\dropbox\bin\dropbox.exe |
"{4EEE66D2-DF0B-4044-A54B-6DEDB5DD4963}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{4F776FB2-E318-4B39-9CC9-D31599BAEB02}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{501DC593-0C87-425A-B23F-A7E7902ECD01}" = protocol=17 | dir=in | app=c:\program files\spotify\spotify.exe |
"{5167F66F-10B7-49CE-B7C8-E2262D4CC983}" = protocol=6 | dir=in | app=c:\program files\skype\plugin manager\skypepm.exe |
"{54C78131-3AE6-4848-B235-CE9911D92BA6}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe |
"{559FB0F2-BB97-481F-A94D-1FCBAA412E32}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{57736938-39EF-4B1B-87C6-C3B23D3FC241}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{58621808-09D8-41DA-85E0-B20C33D233FB}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{5870C801-3B71-4A79-A139-C73F70FBA6BC}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{5BFF083B-3DA3-404A-ACFE-31A8E2E1BE4B}" = protocol=17 | dir=in | app=c:\program files\gnucash\bin\gconfd-2.exe |
"{60ACAEB6-AA2C-48B4-98D7-9AED60373E2B}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{619AE312-FEC7-4F5B-82CC-83E5E6241BE5}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{619E1910-D858-4B5A-8094-1B672D998FDC}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{65BD867E-ACDC-449A-A1B2-1A4B11746AC1}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{66C7DF21-7132-4179-8096-394CE603AED5}" = dir=in | app=c:\program files\hewlett-packard\digital imaging\bin\hpfccopy.exe |
"{676860E5-76DE-4BFE-A84E-3EAB55F88835}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{68A8A545-1586-49F4-8803-F95A9C65325E}" = dir=in | app=e:\setup\hpznui01.exe |
"{699AC186-A5EB-44BF-A205-EBF8A5DB474D}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{69ADFCE9-FCD3-47AC-8029-B9FA76F58738}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{6B316FD3-B7B3-49DA-925E-3C440BF7A5B1}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{6B7975E6-043A-42F0-A2DC-B7757B2D3688}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{6BD9B1E0-CF84-44EC-967C-45E87F375E38}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{6C041564-B73A-490F-B96C-882F3119B9CC}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{7124FB36-FEB1-4CD3-9581-DA0C200C1B6B}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{72725CD0-78F3-45AB-8B09-621D395022CA}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{72950585-96B7-4D13-8BFF-8B17EAE96BBE}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{72CFC26F-08AF-4283-A727-176B583870AA}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{731C566C-DA74-4F04-B1CE-D15BEBCCF10C}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{73B6A8EB-BDAC-445B-A628-BF4D439E8117}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{7466D46D-CB23-442E-81D0-0E4867C9F4FA}" = protocol=17 | dir=in | app=c:\program files\skype\plugin manager\skypepm.exe |
"{77C67DDA-5A84-4B64-95DF-85C8A9AC4529}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{7A1FC6E3-89FF-4B39-81E1-94CF582C5D73}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{7AC4885E-BDB2-4555-BCEE-A222B43FD9E6}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{7B2168B4-19B6-4256-87FA-9394E02F8E6A}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{7B218AB0-921D-4CD7-816C-EDE7DDBE32DC}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{7D060F8D-16BA-4C3F-AB54-A33AA54CE6CC}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{7E7565E8-DFCC-4489-95A6-F0C76E5527FA}" = dir=in | app=c:\program files\hp\quickplay\qp.exe |
"{80E59E20-4891-485F-AEAC-F7E23043FD0C}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{8179CC40-3CC5-4929-A7ED-2AC4962C079C}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{8347B4E0-E7EF-4B5B-966C-E729CE645984}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{875407F6-E6F6-4034-B8FD-F693EB5F8427}" = protocol=17 | dir=in | app=c:\program files\common files\adobe\adobe version cue cs4\server\bin\versioncuecs4.exe |
"{89350A76-B1BC-4102-837E-BE6D78BFAFF6}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{89E3AF95-FFF2-447D-9DE7-1C6CE67D8B2C}" = dir=in | app=c:\program files\hewlett-packard\digital imaging\bin\hpqsudi.exe |
"{8A086669-A735-48FC-AEC6-C0BFE2348E51}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{8C1FBE7E-A09D-4C21-8F5C-C7EFBB9713BC}" = protocol=6 | dir=in | app=c:\program files\common files\adobe\cs4servicemanager\cs4servicemanager.exe |
"{8D587E27-55EE-4FA7-AA10-FDB8E97EB562}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{8DAB76C5-539A-40B6-AC4A-E078C74DF12E}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{8DF3D7BD-120F-4602-9D6F-45413D896880}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{91B3B0F8-2262-4366-950D-F9DD8AD9AFB0}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{93DAB036-91EB-4FD8-BE17-202D48AF4DFD}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{93F59DB8-FD9E-480F-B737-8DD10AB06749}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{952ECCBC-211C-472D-AE6F-9ABCAE23037D}" = protocol=17 | dir=in | app=c:\program files\spotify\spotify.exe |
"{96E500DB-15A4-4070-998D-AF095F2AB42D}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{97D2D64F-173A-45B1-901E-D154E543A4DA}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{986AD672-D72C-4641-ACF6-6D1DC971488F}" = dir=in | app=c:\program files\hp\quickplay\qpservice.exe |
"{99982D07-5C16-464A-BD27-6FA2B6ED81A9}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{99D83F30-69E4-4E63-8CD9-D65851EC245A}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{9A6E4676-C584-4ADD-A1F1-B6D6840CAE2C}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{9C25476F-957B-4DE9-82AE-536E62DEA64B}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{9D170591-2916-4A22-BF12-BA227BA4418D}" = dir=in | app=c:\program files\hewlett-packard\digital imaging\bin\hpqpse.exe |
"{9D5DBC77-F9F7-49F8-8822-B825A06C9F6E}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{9D8525B8-78D5-4A43-ADD2-DFEDF2836D1A}" = dir=in | app=c:\program files\hewlett-packard\digital imaging\bin\hpqgplgtupl.exe |
"{9E4A2D55-246D-478B-A5E5-AF6050C47ABE}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{9E4B4EDE-6495-43EA-B31A-249E5E6E0F73}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{9EAA9A09-0EB7-4BE1-A9E2-D5023B32612D}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{9FAD1309-9244-4E15-AD84-C35B65E640B1}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{A12E9835-1B3D-4685-B98E-0547A173ED2D}" = protocol=6 | dir=in | app=c:\users\alberto\appdata\roaming\dropbox\bin\dropbox.exe |
"{A1393EB5-4F90-4FAE-8745-D11159E96EEC}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{A1435520-3281-41B8-A9F7-9CE3556E0392}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{A1B7B7C2-7E0C-4039-9D0E-A45011C386B9}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{A33E10B2-D4BB-4867-B672-CF5E136175E7}" = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{A6790C66-9BFD-4824-B31D-068625233BF9}" = dir=in | app=c:\program files\hewlett-packard\digital imaging\bin\hpqpsapp.exe |
"{AA797D67-0370-4EE4-B2A2-B537A22928F5}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{AB56CA49-14BA-4FF4-8B95-3F28C24FEDCC}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{AD3090F5-0557-4790-8BE6-7889E0C8CEDE}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{AF03E6AA-2124-449C-9C3E-1310D4120518}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{B19FDC68-577A-4A1B-9B07-D0A0C897CB03}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{B2A402E1-0830-45C3-91B7-89CEB060B1D5}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{B2E4703D-A6AB-4417-A9DC-B32C5EA14C66}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{B5893D18-CB42-4924-8A4D-751CE40ED8E0}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{B592C261-CF08-450A-B783-C2A0E75F564D}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{B96C627F-2FD1-46EE-991C-BF4B76C53C5E}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{BBEEC4B3-0875-49C0-A668-DE05BA8395FE}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{BC537AA8-75B9-4D7D-B453-9090B5EACE23}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{BD1842B3-7EB5-431E-832C-4AB01B8737A4}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{BDF1DA00-22BA-4BF0-9C79-537927F1B260}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{BF7E915C-4D01-4BD5-BB9E-C43245C988C9}" = dir=in | app=c:\program files\hewlett-packard\digital imaging\smart web printing\smartwebprintexe.exe |
"{C19B18E9-67A8-42D1-A76E-DC74FDA6A55E}" = protocol=17 | dir=in | app=c:\program files\windows ilivid toolbar\datamngr\toolbar\dtuser.exe |
"{C2738390-36A0-4265-937D-A90F1E8F5A01}" = dir=in | app=c:\program files\hewlett-packard\digital imaging\bin\hposfx08.exe |
"{C4D59FBE-EC50-48DC-9A1D-BB251222155E}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{C695B291-A3BA-41DF-9AB4-172F94048285}" = dir=in | app=c:\program files\hewlett-packard\digital imaging\bin\hpqfxt08.exe |
"{C6C2B64A-B8DE-45A8-9E25-4288DE64D51B}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{C77E1D66-208B-4929-BCB9-0EF7C20AAF14}" = dir=in | app=c:\program files\hewlett-packard\digital imaging\bin\hpqusgh.exe |
"{C8A42CAE-73A1-484F-B87D-F6C24BB64A1B}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{C8DFA4CC-70DC-451D-A3A7-30C6ADCAA13F}" = dir=in | app=c:\program files\hewlett-packard\digital imaging\bin\hpqcopy2.exe |
"{C98D93ED-F8F2-496C-8FDB-437C4DE2816B}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{CAA545A0-8EBC-4AA8-B84F-8376742A9ED8}" = protocol=6 | dir=in | app=c:\program files\common files\adobe\adobe version cue cs4\server\bin\versioncuecs4.exe |
"{CD57CDD2-D15A-4599-8CA4-032440A79C68}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{CF359DB5-FCFE-4640-B90D-EEA829BD63F0}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{CFD37F82-5CCA-493E-907C-157E268B478F}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{D0F06D48-3712-4B19-AEEF-A6444451C7D6}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{D242F84D-22A7-47E3-B52A-98972061E63E}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{D2A78866-1883-44B4-88C8-BDEFC8FC7184}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{D30291F2-DA23-42B1-9F77-C7BF4A904B5A}" = dir=in | app=c:\program files\hewlett-packard\digital imaging\bin\hposid01.exe |
"{D705A2E2-84CC-4704-B338-B038B2BA8CDB}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{D86371A0-52FC-46BC-8025-26B0F327E273}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{D8BF1C94-D8F6-4D18-B2FF-FDA87A4498D0}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{D91033E8-A671-4C58-9D9C-AABE4A900D92}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{D9307626-9E0C-4AEC-9A8E-2FBCD0044ABA}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{DB6682FF-5429-4E2D-8245-CCE0A14CD28E}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{DC18BB6E-DCD7-467E-B9C3-F73EA7F750BE}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{DC59F460-9C56-49BF-A5E3-DAB808D0C391}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{DE7D4D3F-9E36-46E6-81A8-C1943E15EFD5}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{DF2BCCBC-F5CD-4A9A-B4CB-64DE419CC0F8}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{DF7EADF6-5128-4ED5-BC4D-AEB8A3CA38AB}" = dir=in | app=c:\program files\hewlett-packard\digital imaging\bin\hpqkygrp.exe |
"{E0327613-22A7-4B83-B279-A9EA268EAF6D}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{E0F73DA4-6C61-4481-9DCD-1BE5B765EECF}" = protocol=6 | dir=in | app=c:\program files\common files\adobe\cs4servicemanager\cs4servicemanager.exe |
"{E2B48E6C-AA73-4B7A-BC58-24A4FE2A94F1}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{E7B21244-5CFE-43D3-A80F-D78F95F9FF05}" = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{E7F0577A-C989-49E6-836A-3493E41EE0B3}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{E83D4FB0-B985-4E9F-AAD1-013C15171F9B}" = dir=in | app=c:\program files\hewlett-packard\digital imaging\bin\hpiscnapp.exe |
"{E8F7D0FA-A67A-4B61-AEBB-38F9F7DE84A7}" = protocol=17 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
"{EA0EC383-314B-4CF8-BBA1-3D87ECCDF930}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{EA60AE6B-3696-489B-AEE6-0A6E790D33A7}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{EA738E7C-B971-4C46-BF44-62A95BCA6254}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{EB2CFED0-A0A7-49E2-BB9A-825B19C997F9}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{EF74FF49-6033-4F25-B91B-491360D4DD6C}" = protocol=17 | dir=in | app=c:\program files\common files\adobe\cs4servicemanager\cs4servicemanager.exe |
"{F3FB3C21-4A44-467D-9639-FCED6F2F1005}" = dir=in | app=c:\program files\hewlett-packard\digital imaging\bin\hpofxm08.exe |
"{F4C524ED-9FF4-4BE6-842A-6BB86E056941}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{F5287FBC-3946-44BD-837B-E44574A5F899}" = protocol=6 | dir=in | app=c:\program files\skype\plugin manager\skypepm.exe |
"{F622180F-910A-4CD1-9658-DD0B3B5A1B96}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{F762BB5C-4E9C-4539-A2C5-1B7282702D0C}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"TCP Query User{0A5CB26D-45BB-4C18-B469-13D4DE6557A2}C:\program files\electric rain\swift 3d\version 5.00\program\swift3d.exe" = protocol=6 | dir=in | app=c:\program files\electric rain\swift 3d\version 5.00\program\swift3d.exe |
"TCP Query User{1D5A5BB6-13B7-4EDC-BE7E-A6F36F79589C}C:\program files\mytorrentclient\halite.exe" = protocol=6 | dir=in | app=c:\program files\mytorrentclient\halite.exe |
"TCP Query User{1ED454B7-4CA8-44DB-A365-FA67772737B5}C:\program files\java\jre1.6.0_02\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre1.6.0_02\bin\javaw.exe |
"TCP Query User{34A403F0-4A0D-42E4-81D6-785183B9CA36}C:\program files\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |
"TCP Query User{5EF8BBA4-8981-441F-85EB-03B7C2070937}C:\program files\mozilla firefox\plugin-container.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\plugin-container.exe |
"TCP Query User{62A6B732-EDD6-453E-8811-EB5CB96BB142}C:\program files\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"TCP Query User{68002FAC-A365-4ADA-9FBC-DF85BCED41AF}C:\program files\adobe\adobe dreamweaver cs4\dreamweaver.exe" = protocol=6 | dir=in | app=c:\program files\adobe\adobe dreamweaver cs4\dreamweaver.exe |
"TCP Query User{6D79F608-0D28-4644-B4F2-9C8BF144DE00}C:\program files\macromedia\freehand mx\freehand mx.exe" = protocol=6 | dir=in | app=c:\program files\macromedia\freehand mx\freehand mx.exe |
"TCP Query User{71A5B2FB-36C8-413C-B65D-5E5157483EF2}F:\3dsmax6\3dsmax.exe" = protocol=6 | dir=in | app=f:\3dsmax6\3dsmax.exe |
"TCP Query User{859638E5-92C8-46E9-8265-BE79014DCCF7}C:\users\alberto\appdata\local\akamai\netsession_win.exe" = protocol=6 | dir=in | app=c:\users\alberto\appdata\local\akamai\netsession_win.exe |
"TCP Query User{88D6F33E-60C1-4B7A-876E-BBD1DDC1F36F}C:\users\alberto\appdata\local\mediaget2\mediaget.exe" = protocol=6 | dir=in | app=c:\users\alberto\appdata\local\mediaget2\mediaget.exe |
"TCP Query User{9D630E6F-05B7-4D3B-B2E6-BF84A8E3FF4B}C:\users\alberto\appdata\local\akamai\netsession_win.exe" = protocol=6 | dir=in | app=c:\users\alberto\appdata\local\akamai\netsession_win.exe |
"UDP Query User{1022C294-390B-47DA-9966-3ADA36508EAE}C:\program files\macromedia\freehand mx\freehand mx.exe" = protocol=17 | dir=in | app=c:\program files\macromedia\freehand mx\freehand mx.exe |
"UDP Query User{1ADE7D30-839B-4F38-BD07-25BF90006341}C:\program files\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |
"UDP Query User{2A40386B-109D-4A47-9652-10C077FF9504}C:\program files\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"UDP Query User{2ACB0BBA-7600-494F-B36B-530E80EFEC81}F:\3dsmax6\3dsmax.exe" = protocol=17 | dir=in | app=f:\3dsmax6\3dsmax.exe |
"UDP Query User{4AFBEB78-17C5-42A0-BA40-294A4F0D6FD9}C:\users\alberto\appdata\local\akamai\netsession_win.exe" = protocol=17 | dir=in | app=c:\users\alberto\appdata\local\akamai\netsession_win.exe |
"UDP Query User{5E10C91C-D46D-4C59-8966-9E16E65B82E4}C:\program files\java\jre1.6.0_02\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre1.6.0_02\bin\javaw.exe |
"UDP Query User{6E8AC5F4-4236-4486-A793-97BD2FEC7B0A}C:\program files\electric rain\swift 3d\version 5.00\program\swift3d.exe" = protocol=17 | dir=in | app=c:\program files\electric rain\swift 3d\version 5.00\program\swift3d.exe |
"UDP Query User{7CE3660A-D098-4C9C-9A96-D9B7FEF8D48D}C:\users\alberto\appdata\local\akamai\netsession_win.exe" = protocol=17 | dir=in | app=c:\users\alberto\appdata\local\akamai\netsession_win.exe |
"UDP Query User{D0FFEC42-9FF3-4983-899F-746A7A048238}C:\program files\adobe\adobe dreamweaver cs4\dreamweaver.exe" = protocol=17 | dir=in | app=c:\program files\adobe\adobe dreamweaver cs4\dreamweaver.exe |
"UDP Query User{D43EB358-FA77-45C7-B323-6EE4EAF6AEBD}C:\program files\mytorrentclient\halite.exe" = protocol=17 | dir=in | app=c:\program files\mytorrentclient\halite.exe |
"UDP Query User{E21DF4D3-CCD9-4626-84B3-0CA254622620}C:\users\alberto\appdata\local\mediaget2\mediaget.exe" = protocol=17 | dir=in | app=c:\users\alberto\appdata\local\mediaget2\mediaget.exe |
"UDP Query User{F1FCF998-F801-40DE-A5C7-E179F7697C72}C:\program files\mozilla firefox\plugin-container.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\plugin-container.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"{05308C4E-7285-4066-BAE3-6B50DA6ED755}" = Adobe Update Manager CS4
"{054EFA56-2AC1-48F4-A883-0AB89874B972}" = Adobe Extension Manager CS4
"{06A1D88C-E102-4527-AF70-29FFD7AF215A}" = Scan
"{07DF7C56-3523-4D00-9D19-4D0B636B3BF0}" = Adobe Flash CS4 STI-es
"{082702D5-5DD8-4600-BCE5-48B15174687F}" = HP Doc Viewer
"{086D343F-8E78-4AFC-81AC-D6D414AFD8AC}_is1" = Core Temp version 0.99.8
"{097CDB1E-07C9-40F1-9972-F0F9F3A287E4}" = Network
"{098727E1-775A-4450-B573-3F441F1CA243}" = kuler
"{098A2A49-7CF3-4F08-A38D-FB879117152A}" = Adobe Color NA Extra Settings CS4
"{0D6013AB-A0C7-41DC-973C-E93129C9A29F}" = Adobe Color JA Extra Settings CS4
"{0D67A4E4-5BE0-4C9A-8AD8-AB552B433F23}" = Adobe Setup
"{0DC0E85F-36E4-463B-B3EA-4CD8ED2222A1}" = Adobe Color EU Recommended Settings CS4
"{0F723FC1-7606-4867-866C-CE80AD292DAF}" = Adobe CSI CS4
"{11BB336F-0E58-4977-B866-F24FA334616B}" = HP Active Support Library
"{12A76360-388E-4B27-ABEB-D5FC5378DD2A}" = HPPhotoSmartPhotobookWebPack1
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{1458BB78-1DC5-4BC0-B9A3-2B644F5A8105}" = DeviceDiscovery
"{14AFE241-FC6E-4FDB-BCA0-7AD6F4974171}" = Adobe Setup
"{150B6201-E9E6-4DFB-960E-CCBD53FBDDED}" = HPProductAssistant
"{15BF7AAF-846C-4A6D-80E1-5D1FC7FB461B}" = Adobe SGM CS4
"{1618734A-3957-4ADD-8199-F973763109A8}" = Adobe Anchor Service CS4
"{16E16F01-2E2D-4248-A42F-76261C147B6C}" = Adobe Drive CS4
"{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}" = AdobeColorCommonSetRGB
"{195F2C6C-A343-4b10-B1A4-3F00AB9E9DD9}" = Fax
"{1BDC9633-895B-4842-BCB6-8FA1EC2A3C5A}" = Adobe Shockwave Player
"{1DCA3EAA-6EB5-4563-A970-EA14D75037BA}" = Adobe InDesign CS4
"{1E04CB54-AF4E-4AC3-B4B7-C0A160BE57F1}" = Adobe InDesign CS4 Icon Handler
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{20B30DC1-E423-4939-B51D-05C58B0F9BBB}" = HP Photosmart All-In-One Driver Software 10.0 Rel .2
"{254C37AA-6B72-4300-84F6-98A82419187E}" = Hewlett-Packard Active Check
"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java™ 6 Update 29
"{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Atheros Driver Installation Program
"{28EDCE9C-3304-4331-8AB3-F3EBE94C35B4}" = HP Help and Support
"{292F0F52-B62D-4E71-921B-89A682402201}" = Toolbox
"{2BAF2B96-7560-48B4-87D4-10178DDBE217}" = Adobe InDesign CS4 Application Feature Set Files (Roman)
"{2FB9EA69-51D4-4913-9AD5-762C034DE811}" = Status
"{30C8AA56-4088-426F-91D1-0EDFD3A25678}" = Adobe Dreamweaver CS4
"{3127F76D-5335-4AC7-BD1E-2F5247A23C24}" = iTunes
"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java™ 6 Update 2
"{32939827-d8e5-470a-b126-870db3c69fdf}" = Python 2.7.1
"{34BFB099-07B2-4E95-A673-7362D60866A2}" = PSSWCORE
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.30 E1
"{35D94F92-1D3A-43C5-8605-EA268B1A7BD9}" = PDF Settings CS4
"{3700194C-C5DD-439A-BE06-A66960CA4C70}" = MSVCSetup
"{39F6E2B4-CFE8-C30A-66E8-489651F0F34C}" = Adobe Media Player
"{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}" = Adobe XMP Panels CS4
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3D2C9DE6-9ADE-4252-A241-E43723B0CE02}" = Adobe Color - Photoshop Specific CS4
"{3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}" = Adobe WinSoft Linguistics Plugin
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{43509E18-076E-40FE-AF38-CA5ED400A5A9}" = Pixel Bender Toolkit
"{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP QuickPlay 3.6
"{4943EFF5-229F-435D-BEA9-BE3CAEA783A7}" = Adobe Service Manager Extension
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A52555C-032A-4083-BDD9-6A85ABFB39A8}" = Adobe SING CS4
"{4BD271AB-66E2-4D58-AF88-80FE3B0770C4}" = Fissa
"{4CACFCD9-F71B-413A-8DF5-1A6419D5CDC6}" = Cards_Calendar_OrderGift_DoMorePlugout
"{4D49757C-367A-4333-BDB3-68966162B14E}" = HP User Guides 0087
"{537DB9D6-1AB1-4CE9-8DE7-312256B49A98}" = PS_AIO_06_C4700_SW_Min
"{59F6A514-9813-47A3-948C-8A155460CC2A}" = RICOH R5C83x/84x Flash Media Controller Driver Ver.3.51.01
"{5DCF0E4B-F8EA-4229-A0BD-5CA6D4AFB749}" = SolutionCenter
"{60DB5894-B5A1-4B62-B0F3-669A22C0EE5D}" = Adobe Dynamiclink Support
"{60FFB3E0-6D5B-4D73-AE5B-07E58B83AF0C}" = 32 Bit HP CIO Components Installer
"{63C24A08-70F3-4C8E-B9FB-9F21A903801D}" = Adobe Color Video Profiles CS CS4
"{63E5CDBF-8214-4F03-84F8-CD3CE48639AD}" = Adobe Photoshop CS4 Support
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = Hewlett-Packard Asset Agent for Health Check
"{679EC478-3FF9-4987-B2FF-C2C2B27532A2}" = DocProc
"{67F0E67A-8E93-4C2C-B29D-47C48262738A}" = Adobe Device Central CS4
"{681B698F-C997-42C3-B184-B489C6CA24C9}" = HPPhotoSmartDiscLabelContent1
"{68243FF8-83CA-466B-B2B8-9F99DA5479C4}" = AdobeColorCommonSetCMYK
"{68550918-63B5-4762-85CB-3C160AA4B213}" = HP Photosmart C4700 All-in-One Driver Software 14.0 Rel. 6
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6C1E7AA1-44E9-446D-AAB2-0DE6D9EFEAB1}" = Safari
"{6E6D6046-EF2F-41D5-B9F4-B3EA6BA72E0C}" = ESU for Microsoft Vista
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{748F4870-8350-11D3-B0BF-080009FB4A19}" = HP Share-to-Web
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7B63B2922B174135AFC0E1377DD81EC2}" =
"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
"{7CC7BDD5-6F10-4724-96A1-EAC7D9F2831C}" = Adobe InDesign CS4 Common Base Files
"{7DC4A410-9986-4329-9E5D-687B2C42CA39}" = HP QuickTouch 1.00 C4
"{8153ED9A-C94A-426E-9880-5E6775C08B62}" = Apple Mobile Device Support
"{8186FF34-D389-4B7E-9A2F-C197585BCFBD}" = Adobe Media Encoder CS4 Importer
"{818ABC3C-635C-4651-8183-D0E9640B7DD1}" = HP Update
"{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}" = Adobe Type Support CS4
"{83877DB1-8B77-45BC-AB43-2BAC22E093E0}" = Adobe Bridge CS4
"{842B4B72-9E8F-4962-B3C1-1C422A5C4434}" = Suite Shared Configuration CS4
"{85758591-7152-4FC6-984B-417284D14142}" = Google SketchUp Pro 8
"{87532CAB-7932-4F84-8937-823337622807}" = Adobe Illustrator CS4
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A85DEAD-7C1F-4368-881C-72AC74CB2E91}" = UnloadSupport
"{8B4AE751-7055-4518-87B0-E148A8D50D0A}" = Macromedia FreeHand MX
"{8BF2C401-02CE-424D-BC26-6C4F9FB446B6}" = Macromedia Flash 8 Video Encoder
"{8CE08C3C-8FF4-45D9-925E-4F3CE2D7FA7D}" = Adobe Setup
"{8EE94FD8-5F52-4463-A340-185D16328158}" = WebReg
"{8FF6F5CA-4E30-4E3B-B951-204CAAA2716A}" = SmartWebPrinting
"{90120000-0015-0C0A-0000-0000000FF1CE}" = Microsoft Office Access MUI (Spanish) 2007
"{90120000-0015-0C0A-0000-0000000FF1CE}_ENTERPRISE_{91A7F72A-3273-4C1E-8BE0-BC9DD0D9345C}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0C0A-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Spanish) 2007
"{90120000-0016-0C0A-0000-0000000FF1CE}_ENTERPRISE_{91A7F72A-3273-4C1E-8BE0-BC9DD0D9345C}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0C0A-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Spanish) 2007
"{90120000-0018-0C0A-0000-0000000FF1CE}_ENTERPRISE_{91A7F72A-3273-4C1E-8BE0-BC9DD0D9345C}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0C0A-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Spanish) 2007
"{90120000-0019-0C0A-0000-0000000FF1CE}_ENTERPRISE_{91A7F72A-3273-4C1E-8BE0-BC9DD0D9345C}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0C0A-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Spanish) 2007
"{90120000-001A-0C0A-0000-0000000FF1CE}_ENTERPRISE_{91A7F72A-3273-4C1E-8BE0-BC9DD0D9345C}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0C0A-0000-0000000FF1CE}" = Microsoft Office Word MUI (Spanish) 2007
"{90120000-001B-0C0A-0000-0000000FF1CE}_ENTERPRISE_{91A7F72A-3273-4C1E-8BE0-BC9DD0D9345C}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0403-0000-0000000FF1CE}" = Microsoft Office Proof (Catalan) 2007
"{90120000-001F-0403-0000-0000000FF1CE}_ENTERPRISE_{4B47C31E-46B0-462B-BEE4-DC383B6A1F2A}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0416-0000-0000000FF1CE}" = Microsoft Office Proof (Portuguese (Brazil)) 2007
"{90120000-001F-0416-0000-0000000FF1CE}_ENTERPRISE_{75EBE365-7FC5-4720-A7D3-804BF550D1BC}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-042D-0000-0000000FF1CE}" = Microsoft Office Proof (Basque) 2007
"{90120000-001F-042D-0000-0000000FF1CE}_ENTERPRISE_{042190ED-F17C-4A8D-95D8-87A37B4095BD}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0456-0000-0000000FF1CE}" = Microsoft Office Proof (Galician) 2007
"{90120000-001F-0456-0000-0000000FF1CE}_ENTERPRISE_{D3064ADE-5D4C-4AA4-8F71-C63D87D4A263}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0C0A-0000-0000000FF1CE}" = Microsoft Office Proofing (Spanish) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0044-0C0A-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Spanish) 2007
"{90120000-0044-0C0A-0000-0000000FF1CE}_ENTERPRISE_{91A7F72A-3273-4C1E-8BE0-BC9DD0D9345C}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0C0A-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Spanish) 2007
"{90120000-006E-0C0A-0000-0000000FF1CE}_ENTERPRISE_{6113C11D-BACA-4D8E-8002-03C8D06FD5E6}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0C0A-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Spanish) 2007
"{90120000-00A1-0C0A-0000-0000000FF1CE}_ENTERPRISE_{91A7F72A-3273-4C1E-8BE0-BC9DD0D9345C}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0C0A-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Spanish) 2007
"{90120000-00BA-0C0A-0000-0000000FF1CE}_ENTERPRISE_{91A7F72A-3273-4C1E-8BE0-BC9DD0D9345C}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{92E4A65F-7007-3357-A69A-167F71A337BD}" = Microsoft .NET Framework 3.5 Language Pack SP1 - esn
"{931AB7EA-3656-4BB7-864D-022B09E3DD67}" = Adobe Linguistics CS4
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{94D398EB-D2FD-4FD1-B8C4-592635E8A191}" = Adobe CMaps CS4
"{9885A11E-60E4-417C-B58B-8B31B21C0B8A}" = HP Easy Setup - Frontend
"{993960EE-CA4D-443F-8F88-E24260DD5FD2}" = LG PC Suite
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9CB5747B-9A31-4FC9-B5B8-8ECD1EF347B1}" = Adobe Flash CS4 Extension - Flash Lite STI es
"{A07840FC-CE63-4CB8-8030-EF4B9805925A}" = HPPhotoSmartDiscLabel_PaperLabel
"{A83279FD-CA4B-4206-9535-90974DE76654}" = Apple Application Support
"{A8D93648-9F7F-407D-915C-62044644C3DA}" = MSI to redistribute MS VS2005 CRT libraries
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5
"{AC35A885-0F8F-4857-B7DA-6E8DFB43E6B3}" = HPSSupply
"{AC76BA86-7AD7-1034-7B44-A94000000001}" = Adobe Reader 9.4.6 - Español
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{ADFB9653-F44C-460C-BF58-189CC552DFFE}" = hpphotosmartdisclabelplugin
"{AFF7E080-1974-45BF-9310-10DE1A1F5ED0}" = Adobe AIR
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B29AD377-CC12-490A-A480-1452337C618D}" = Connect
"{B4E91E95-A5BA-4E50-A465-DB7EFEB176E8}" = HPPhotoSmartDiscLabel_PrintOnDisc
"{B5978DF3-8A04-4F22-AF67-8CCE52E04B13}" = C4700
"{B65BA85C-0A27-4BC0-A22D-A66F0E5B9494}" = Adobe Photoshop CS4
"{B7FB6B99-C93C-4818-825B-37EF4B64C80C}" = PS_AIO_02_Software
"{BB3447F6-9553-4AA9-960E-0DB5310C5779}" = GPBaseService2
"{BB4E33EC-8181-4685-96F7-8554293DEC6A}" = Adobe Output Module
"{BD0E2B92-3814-46F0-893B-4612EA010C7E}" = HP Customer Experience Enhancements
"{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations
"{C14337B6-7777-4643-A0B0-B054EF10F59D}" = c5200_Help
"{C3ABE126-2BB2-4246-BFE1-6797679B3579}" = LG USB Modem driver
"{c4549405-195f-4450-8865-6be9dc5ad136}" = PS_AIO_02_Software_Min
"{C52E3EC1-048C-45E1-8D53-10B0C6509683}" = Adobe Default Language CS4
"{C68BF996-C440-46f5-AFCF-A0CE584AB95C}" = C5200
"{CA1CA5F8-7500-45C5-9D4C-47D13FBC92D2}" = Adobe Setup
"{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget
"{CBAE4F50-9FC9-4557-AB36-9826DF3C103C}" = HP Wireless Assistant
"{CC4A73BF-938E-4C19-A553-853C035C9BA1}" = LightScribe System Software 1.10.13.1
"{CC75AB5C-2110-4A7F-AF52-708680D22FE8}" = Photoshop Camera Raw
"{cd0b9359-b716-4fd0-8e0a-09b3e312e8a4}" = PS_AIO_02_Software
"{CD31E63D-47FD-491C-8117-CF201D0AFAB5}" = TrayApp
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D25BDCF5-19F6-4d9e-B9C9-273FE81446C4}" = PS_AIO_02_ProductContext
"{D360FA88-17C8-4F14-B67F-13AAF9607B12}" = MarketResearch
"{D64BC2CF-0F12-47d7-B412-B4F3FD684253}" = HP Photosmart All-In-One Software 9.0
"{D79113E7-274C-470B-BD46-01B10219DF6A}" = HPPhotosmartEssential
"{DEB90B8E-0DCB-48CE-B90E-8842A2BD643E}" = Adobe Media Encoder CS4
"{E08DC77E-D09A-4e36-8067-D6DBBCC5F8DC}" = VideoToolkit01
"{E4848436-0345-47E2-B648-8B522FCDA623}" = Adobe Photoshop CS4
"{E517094C-06B6-419F-8FFD-EF4F57972130}" = QuickTransfer
"{E96DA799-C0DF-44d7-AE41-D8312824B898}" = C5200_doccd
"{EED50C97-C79E-4149-BD82-7C5A22437708}" = Adobe Setup
"{EF0D2E55-6FE2-4e35-BE22-A742E85D84E3}" = PS_AIO_02_Software_min
"{F0E64E2E-3A60-40D8-A55D-92F6831875DA}" = Adobe Search for Help
"{F443F171-B49B-4645-915C-580E7ED79992}" = Macromedia Extension Manager
"{F6E99614-F042-4459-82B7-8B38B2601356}" = Adobe Flash CS4
"{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}" = Adobe ExtendScript Toolkit CS4
"{F93C84A6-0DC6-42AF-89FA-776F7C377353}" = Adobe PDF Library Files CS4
"{FA0FF682-CC70-4C57-93CD-E276F3E7537E}" = BufferChm
"{FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}" = Adobe Fonts All
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"1&1 Acceso directo" = 1&1 Acceso directo
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe_2a31ae7a5c43ff52d8577782dd34e04" = Adobe Illustrator CS4
"Adobe_353cd491d53335f3a31abdf7f7e6832" = Adobe InDesign CS4
"Adobe_a68eec966ce913ddaa63251dc82ed31" = Adobe Flash CS4 Professional
"Adobe_acce07fd2c8fe7f9e3f26243e626578" = Adobe Dreamweaver CS4
"Adobe_faf656ef605427ee2f42989c3ad31b8" = Adobe Photoshop CS4
"Akamai" = Akamai NetSession Interface Service
"ApachePHPMySQL 1.1" = ApachePHPMySQL 1.1
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"Blender" = Blender (remove only)
"Canon RAW Codec" = Canon RAW Codec
"CNXT_AUDIO_HDA" = Conexant HD Audio
"CNXT_MODEM_HDA_HSF" = HDAUDIO Soft Data Fax Modem with SmartCP
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"DivX Setup.divx.com" = Instalación de DivX
"ENTERPRISE" = Microsoft Office Enterprise 2007
"FBDBServer_2_5_is1" = Firebird 2.5.0.26074 (Win32)
"GnuCash_is1" = GnuCash 2.4.8
"Hauppauge MCE2005 Software Encoder" = Hauppauge MCE XP/Vista Software Encoder (2.0.25149)
"HP Imaging Device Functions" = HP Imaging Device Functions 14.0
"HP Photosmart Essential" = HP Photosmart Essential 3.5
"HP Smart Web Printing" = HP Smart Web Printing 4.60
"HP Solution Center & Imaging Support Tools" = HP Solution Center 14.0
"HPExtendedCapabilities" = HP Customer Participation Program 14.0
"HPOCR" = OCR Software by I.R.I.S. 10.0
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"JDownloader" = JDownloader
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 Language Pack SP1 - esn" = Paquete de idioma de Microsoft .NET Framework 3.5 SP1 - esn
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Mozilla Firefox 8.0 (x86 es-ES)" = Mozilla Firefox 8.0 (x86 es-ES)
"MTN F@stLink" = MTN Online
"NVIDIA Drivers" = NVIDIA Drivers
"PcCloneEX" = PcCloneEX
"Pen Tablet Driver" = Pen Tablet
"Searchqu 406 MediaBar" = Windows iLivid Toolbar
"Shop for HP Supplies" = Shop for HP Supplies
"Software de impresión de fotografías HP" = Software de impresión de fotografías HP
"Spotify" = Spotify
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"uTorrent" = µTorrent
"ViewpointMediaPlayer" = Viewpoint Media Player
"VirtualCloneDrive" = VirtualCloneDrive
"WinRAR archiver" = Compresor WinRAR

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Akamai" = Akamai NetSession Interface
"Dropbox" = Dropbox
"Facebook Plug-In" = Facebook Plug-In
"Google Chrome" = Google Chrome

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 15/12/2010 3:55:59 | Computer Name = Laptop-de-Berto | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 15/12/2010 3:55:59 | Computer Name = Laptop-de-Berto | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 26333

Error - 15/12/2010 3:55:59 | Computer Name = Laptop-de-Berto | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 26333

Error - 15/12/2010 3:56:00 | Computer Name = Laptop-de-Berto | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 15/12/2010 3:56:00 | Computer Name = Laptop-de-Berto | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 27363

Error - 15/12/2010 3:56:00 | Computer Name = Laptop-de-Berto | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 27363

Error - 15/12/2010 3:56:01 | Computer Name = Laptop-de-Berto | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 15/12/2010 3:56:01 | Computer Name = Laptop-de-Berto | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 28424

Error - 15/12/2010 3:56:01 | Computer Name = Laptop-de-Berto | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 28424

Error - 15/12/2010 12:59:55 | Computer Name = Laptop-de-Berto | Source = VMCService | ID = 0
Description = conflictManagerTypeValue

[ OSession Events ]
Error - 31/08/2011 4:15:12 | Computer Name = Laptop-de-Berto | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6300.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 7
seconds with 0 seconds of active time. This session ended with a crash.

Error - 01/09/2011 3:46:27 | Computer Name = Laptop-de-Berto | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6300.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 6
seconds with 0 seconds of active time. This session ended with a crash.

Error - 08/12/2011 13:38:05 | Computer Name = Laptop-de-Berto | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6562.5003, Microsoft Office Version: 12.0.6425.1000. This session lasted 8
seconds with 0 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 15/12/2011 2:07:17 | Computer Name = Laptop-de-Berto | Source = Service Control Manager | ID = 7009
Description =

Error - 15/12/2011 2:07:17 | Computer Name = Laptop-de-Berto | Source = Service Control Manager | ID = 7000
Description =

Error - 15/12/2011 3:24:40 | Computer Name = Laptop-de-Berto | Source = Service Control Manager | ID = 7000
Description =

Error - 15/12/2011 17:04:14 | Computer Name = Laptop-de-Berto | Source = Service Control Manager | ID = 7000
Description =

Error - 16/12/2011 1:53:25 | Computer Name = Laptop-de-Berto | Source = Service Control Manager | ID = 7000
Description =

Error - 16/12/2011 1:53:28 | Computer Name = Laptop-de-Berto | Source = Service Control Manager | ID = 7022
Description =

Error - 16/12/2011 1:53:29 | Computer Name = Laptop-de-Berto | Source = Service Control Manager | ID = 7001
Description =

Error - 16/12/2011 11:00:05 | Computer Name = Laptop-de-Berto | Source = netbt | ID = 4321
Description = No se pudo registrar el nombre "WORKGROUP :1d" en la interfaz
con dirección IP 192.168.1.34. El equipo la con dirección IP 192.168.1.35 no admite
el nombre reclamado por este equipo.

Error - 16/12/2011 11:00:16 | Computer Name = Laptop-de-Berto | Source = Service Control Manager | ID = 7000
Description =

Error - 17/12/2011 7:05:56 | Computer Name = Laptop-de-Berto | Source = Service Control Manager | ID = 7000
Description =


< End of report >


Thank you in advance for your help.
Hello albertomachin and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:
  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

I am looking at your log now and will reply with instructions shortly

Satchfan
Hello again albertomachin

P2P - I see you have P2P software, (uTorrent), installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infection. If your computer is infected, it almost certainly contributed to your current situation.

Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are more often than not, infected. The bad guys use P2P file-sharing as a major conduit to spread their wares.

Please see this topic for more information:

Perils of P2P File Sharing.

I would strongly recommend that you uninstall it now. You can do so via Control Panel, Programs, and then Programs and Features.

Should you decide to keep it, please don’t use it until we have finished up here.

===================================================

Uninstall the following programs, if present:

Searchqu 406 MediaBar
all versions of Java or JRE runtime except version 29

1. Click Start, Control Panel, Programs, and then Programs and Features.
2. Click on Searchqu 406 MediaBar and then Uninstall. Repeat for the other progrms
===================================================

Run OTL
  • Double click on the icon to run it.
  • Copy/paste ALL the following text written inside the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    PRC - C:\Program Files\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Bandoo Media, inc)
    FF - prefs.js..browser.startup.homepage: "http://www.searchqu.com/406"
    O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No CLSID value found
    O2 - BHO: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Program Files\Windows iLivid Toolbar\Datamngr\ToolBar\searchqudtx.dll ()
    O2 - BHO: (UrlHelper Class) - {A40DC6C5-79D0-4ca8-A185-8FF989AF1115} - C:\Program Files\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Bandoo Media, inc)
    O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found
    O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Program Files\Windows iLivid Toolbar\Datamngr\ToolBar\searchqudtx.dll ()
    O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
    O4 - HKLM..\Run: [] File not found
    O4 - HKLM..\Run: [DATAMNGR] C:\Program Files\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Bandoo Media, inc)
    O20 - AppInit_DLLs: (c:\progra~1\wi371a~1\datamngr\datamngr.dll) -c:\Program Files\Windows iLivid Toolbar\Datamngr\datamngr.dll (Bandoo Media, inc)
    O20 - AppInit_DLLs: (c:\progra~1\wi371a~1\datamngr\iebho.dll) -c:\Program Files\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Bandoo Media, inc)
    O33 - MountPoints2\{1347a04c-c80a-11e0-8b2b-001e6869fb6b}\Shell - "" = AutoRun
    O33 - MountPoints2\{1347a04c-c80a-11e0-8b2b-001e6869fb6b}\Shell\AutoRun\command - "" = H:\AutoRun.exe
    O33 - MountPoints2\{1347a058-c80a-11e0-8b2b-001e6869fb6b}\Shell - "" = AutoRun
    O33 - MountPoints2\{1347a058-c80a-11e0-8b2b-001e6869fb6b}\Shell\AutoRun\command - "" = H:\AutoRun.exe
    O33 - MountPoints2\{1347a072-c80a-11e0-8b2b-001e6869fb6b}\Shell - "" = AutoRun
    O33 - MountPoints2\{1347a072-c80a-11e0-8b2b-001e6869fb6b}\Shell\AutoRun\command - "" = H:\AutoRun.exe
    O33 - MountPoints2\{1347a07e-c80a-11e0-8b2b-001e101fb681}\Shell - "" = AutoRun
    O33 - MountPoints2\{1347a07e-c80a-11e0-8b2b-001e101fb681}\Shell\AutoRun\command - "" = H:\AutoRun.exe
    O33 - MountPoints2\{171c20ae-c58b-11e0-856d-001e6869fb6b}\Shell - "" = AutoRun
    O33 - MountPoints2\{171c20ae-c58b-11e0-856d-001e6869fb6b}\Shell\AutoRun\command - "" = H:\AutoRun.exe
    O33 - MountPoints2\{2514a73f-d30a-11df-844f-001e6869fb6b}\Shell - "" = Autorun
    O33 - MountPoints2\{2514a73f-d30a-11df-844f-001e6869fb6b}\Shell\downloadsb\command - "" = C:\Windows\explorer.exe – [2009/04/11 07:27:36 | 002,926,592 | —- | M] (Microsoft Corporation)
    O33 - MountPoints2\{9b1c0f6f-fa4b-11de-9388-001e6869fb6b}\Shell - "" = AutoRun
    O33 - MountPoints2\{9b1c0f6f-fa4b-11de-9388-001e6869fb6b}\Shell\AutoRun\command - "" = G:\setup_vmc_lite.exe /checkApplicationPresence
    O33 - MountPoints2\{9b1c0f8e-fa4b-11de-9388-001e6869fb6b}\Shell - "" = AutoRun
    O33 - MountPoints2\{9b1c0f8e-fa4b-11de-9388-001e6869fb6b}\Shell\AutoRun\command - "" = G:\setup_vmc_lite.exe /checkApplicationPresence
    O33 - MountPoints2\{aa0a7ba3-c4f5-11e0-a7b1-001e6869fb6b}\Shell - "" = AutoRun
    O33 - MountPoints2\{aa0a7ba3-c4f5-11e0-a7b1-001e6869fb6b}\Shell\AutoRun\command - "" = H:\AutoRun.exe
    O33 - MountPoints2\{aa0a7bd3-c4f5-11e0-a7b1-001e6869fb6b}\Shell - "" = AutoRun
    O33 - MountPoints2\{aa0a7bd3-c4f5-11e0-a7b1-001e6869fb6b}\Shell\AutoRun\command - "" = H:\AutoRun.exe
    O33 - MountPoints2\{ef7e7748-c4fc-11e0-b46d-001e6869fb6b}\Shell - "" = AutoRun
    O33 - MountPoints2\{ef7e7748-c4fc-11e0-b46d-001e6869fb6b}\Shell\AutoRun\command - "" = H:\AutoRun.exe
    O33 - MountPoints2\{efdf5fc6-f068-11de-8860-001e6869fb6b}\Shell - "" = AutoRun
    O33 - MountPoints2\{efdf5fc6-f068-11de-8860-001e6869fb6b}\Shell\AutoRun\command - "" = G:\setup_vmc_lite.exe /checkApplicationPresence
    O33 - MountPoints2\{efdf5fcb-f068-11de-8860-001e6869fb6b}\Shell - "" = AutoRun
    O33 - MountPoints2\{efdf5fcb-f068-11de-8860-001e6869fb6b}\Shell\AutoRun\command - "" = I:\setup_vmc_lite.exe /checkApplicationPresence
    O33 - MountPoints2\H\Shell - "" = AutoRun
    O33 - MountPoints2\H\Shell\AutoRun\command - "" = H:\AutoRun.exe
    
    :Reg
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{2209F96F-4F6B-44EB-A80C-7A2DDF37E2B4}" =- 
    "{C19B18E9-67A8-42D1-A76E-DC74FDA6A55E}" =-
    
    :Files
    ipconfig /flushdns /c
    
    :Commands
    [resethosts]
    [emptyflash]
    [purity]
    [emptytemp]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log (don't check the boxes beside LOP Check or Purity this time)
===================================================

Download and run ComboFix

Download ComboFix from the following location:

Link

* IMPORTANT !!! Save ComboFix.exe to your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue its malware removal procedures.

    [external image: Posted Image]


    Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

    [external image: Posted Image]


    Click on Yes, to continue scanning for malware.
Note: Do not mouse-click combofix's window while it is running. That may cause it to stall.

When finished, it will produce a log. Please include the ComboFix.txt in your next reply. It can be found at C:\ComboFix.txt


Logs to include in the next post:

OTL fix log
New OTL log
ComboFix.txt


Satchfan
Thank you for your help, Satchfan.

Yeah, you're right. Downloading stuff may bring the viruses back, that's why I've uninstalled uTorrent.

This is the OTL fix log:

All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
No active process named datamngrUI.exe was found!
Prefs.js: "http://www.searchqu.com/406" removed from browser.startup.homepage
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{99079a25-328f-4bd4-be04-00955acaa0a7}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{99079a25-328f-4bd4-be04-00955acaa0a7}\ deleted successfully.
C:\Program Files\Windows iLivid Toolbar\Datamngr\ToolBar\searchqudtx.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}\ deleted successfully.
C:\Program Files\Windows iLivid Toolbar\Datamngr\IEBHO.dll moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{99079a25-328f-4bd4-be04-00955acaa0a7} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{99079a25-328f-4bd4-be04-00955acaa0a7}\ not found.
File C:\Program Files\Windows iLivid Toolbar\Datamngr\ToolBar\searchqudtx.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\10 deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\DATAMNGR deleted successfully.
C:\Program Files\Windows iLivid Toolbar\Datamngr\datamngrUI.exe moved successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:c:\progra~1\wi371a~1\datamngr\datamngr.dll deleted successfully.
File pInit_DLLs: (c:\progra~1\wi371a~1\datamngr\datamngr.dll) -c:\Program Files\Windows iLivid Toolbar\Datamngr\datamngr.dll not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:c:\progra~1\wi371a~1\datamngr\iebho.dll deleted successfully.
File pInit_DLLs: (c:\progra~1\wi371a~1\datamngr\iebho.dll) -c:\Program Files\Windows iLivid Toolbar\Datamngr\IEBHO.dll not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1347a04c-c80a-11e0-8b2b-001e6869fb6b}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1347a04c-c80a-11e0-8b2b-001e6869fb6b}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1347a04c-c80a-11e0-8b2b-001e6869fb6b}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1347a04c-c80a-11e0-8b2b-001e6869fb6b}\ not found.
File H:\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1347a058-c80a-11e0-8b2b-001e6869fb6b}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1347a058-c80a-11e0-8b2b-001e6869fb6b}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1347a058-c80a-11e0-8b2b-001e6869fb6b}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1347a058-c80a-11e0-8b2b-001e6869fb6b}\ not found.
File H:\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1347a072-c80a-11e0-8b2b-001e6869fb6b}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1347a072-c80a-11e0-8b2b-001e6869fb6b}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1347a072-c80a-11e0-8b2b-001e6869fb6b}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1347a072-c80a-11e0-8b2b-001e6869fb6b}\ not found.
File H:\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1347a07e-c80a-11e0-8b2b-001e101fb681}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1347a07e-c80a-11e0-8b2b-001e101fb681}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1347a07e-c80a-11e0-8b2b-001e101fb681}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1347a07e-c80a-11e0-8b2b-001e101fb681}\ not found.
File H:\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{171c20ae-c58b-11e0-856d-001e6869fb6b}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{171c20ae-c58b-11e0-856d-001e6869fb6b}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{171c20ae-c58b-11e0-856d-001e6869fb6b}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{171c20ae-c58b-11e0-856d-001e6869fb6b}\ not found.
File H:\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2514a73f-d30a-11df-844f-001e6869fb6b}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2514a73f-d30a-11df-844f-001e6869fb6b}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2514a73f-d30a-11df-844f-001e6869fb6b}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2514a73f-d30a-11df-844f-001e6869fb6b}\ not found.
Item C:\WINDOWS\explorer.exe is whitelisted and cannot be moved.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9b1c0f6f-fa4b-11de-9388-001e6869fb6b}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9b1c0f6f-fa4b-11de-9388-001e6869fb6b}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9b1c0f6f-fa4b-11de-9388-001e6869fb6b}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9b1c0f6f-fa4b-11de-9388-001e6869fb6b}\ not found.
File G:\setup_vmc_lite.exe /checkApplicationPresence not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9b1c0f8e-fa4b-11de-9388-001e6869fb6b}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9b1c0f8e-fa4b-11de-9388-001e6869fb6b}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9b1c0f8e-fa4b-11de-9388-001e6869fb6b}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9b1c0f8e-fa4b-11de-9388-001e6869fb6b}\ not found.
File G:\setup_vmc_lite.exe /checkApplicationPresence not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{aa0a7ba3-c4f5-11e0-a7b1-001e6869fb6b}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{aa0a7ba3-c4f5-11e0-a7b1-001e6869fb6b}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{aa0a7ba3-c4f5-11e0-a7b1-001e6869fb6b}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{aa0a7ba3-c4f5-11e0-a7b1-001e6869fb6b}\ not found.
File H:\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{aa0a7bd3-c4f5-11e0-a7b1-001e6869fb6b}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{aa0a7bd3-c4f5-11e0-a7b1-001e6869fb6b}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{aa0a7bd3-c4f5-11e0-a7b1-001e6869fb6b}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{aa0a7bd3-c4f5-11e0-a7b1-001e6869fb6b}\ not found.
File H:\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ef7e7748-c4fc-11e0-b46d-001e6869fb6b}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ef7e7748-c4fc-11e0-b46d-001e6869fb6b}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ef7e7748-c4fc-11e0-b46d-001e6869fb6b}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ef7e7748-c4fc-11e0-b46d-001e6869fb6b}\ not found.
File H:\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{efdf5fc6-f068-11de-8860-001e6869fb6b}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{efdf5fc6-f068-11de-8860-001e6869fb6b}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{efdf5fc6-f068-11de-8860-001e6869fb6b}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{efdf5fc6-f068-11de-8860-001e6869fb6b}\ not found.
File G:\setup_vmc_lite.exe /checkApplicationPresence not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{efdf5fcb-f068-11de-8860-001e6869fb6b}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{efdf5fcb-f068-11de-8860-001e6869fb6b}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{efdf5fcb-f068-11de-8860-001e6869fb6b}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{efdf5fcb-f068-11de-8860-001e6869fb6b}\ not found.
File I:\setup_vmc_lite.exe /checkApplicationPresence not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\H\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\H\ not found.
File H:\AutoRun.exe not found.
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{2209F96F-4F6B-44EB-A80C-7A2DDF37E2B4} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2209F96F-4F6B-44EB-A80C-7A2DDF37E2B4}\ not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{C19B18E9-67A8-42D1-A76E-DC74FDA6A55E} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C19B18E9-67A8-42D1-A76E-DC74FDA6A55E}\ not found.
========== FILES ==========
< ipconfig /flushdns /c >
Configuraci¢n IP de Windows
Se vaci¢ correctamente la cach‚ de resoluci¢n de DNS.
C:\Users\Alberto\Desktop\cmd.bat deleted successfully.
C:\Users\Alberto\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYFLASH]

User: Alberto
->Flash cache emptied: 185775 bytes

User: All Users

User: Default
->Flash cache emptied: 56466 bytes

User: Default User
->Flash cache emptied: 0 bytes

User: Public

Total Flash Files Cleaned = 0,00 mb


[EMPTYTEMP]

User: Alberto
->Temp folder emptied: 26215353 bytes
->Java cache emptied: 1287258 bytes
->FireFox cache emptied: 697136461 bytes
->Google Chrome cache emptied: 271347094 bytes
->Apple Safari cache emptied: 16384 bytes
->Flash cache emptied: 0 bytes

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 279440 bytes
Windows Temp folder emptied: 95940355 bytes
RecycleBin emptied: 391568 bytes

Total Files Cleaned = 1.042,00 mb


OTL by OldTimer - Version 3.2.31.0 log created on 12182011_164303

Files\Folders moved on Reboot…

Registry entries deleted on Reboot…


I'll post the rest in a second.
Here's the OTL log:


OTL logfile created on: 18/12/2011 17:05:25 - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Alberto\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000C0A | Country: España | Language: ESN | Date Format: dd/MM/yyyy

3,00 Gb Total Physical Memory | 1,70 Gb Available Physical Memory | 56,58% Memory free
6,22 Gb Paging File | 4,88 Gb Available in Paging File | 78,40% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 76,19 Gb Total Space | 27,04 Gb Free Space | 35,49% Space Free | Partition Type: NTFS
Drive D: | 11,35 Gb Total Space | 2,16 Gb Free Space | 18,99% Space Free | Partition Type: NTFS
Drive F: | 145,34 Gb Total Space | 89,35 Gb Free Space | 61,48% Space Free | Partition Type: NTFS

Computer Name: LAPTOP-DE-BERTO | User Name: Alberto | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Alberto\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Users\Alberto\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc)
PRC - C:\Users\Alberto\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
PRC - C:\Users\Alberto\Desktop\KeyState.exe (Paul Heinrich)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files\DivX\DivX Plus Web Player\DDMService.exe (DivX, LLC)
PRC - C:\ProgramData\DatacardService\DCService.exe ()
PRC - C:\ProgramData\DatacardService\DCSHelper.exe (Huawei Technologies Co., Ltd.)
PRC - C:\Program Files\Common Files\Firebird\bin\fb_inet_server.exe (Firebird Project)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Users\Alberto\AppData\Roaming\MTN Online\ouc.exe (Huawei Technologies Co., Ltd.)
PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH)
PRC - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqste08.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqbam08.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqgpc01.exe (Hewlett-Packard)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Program Files\Synaptics\SynTP\SynTPStart.exe (Synaptics, Inc.)
PRC - C:\WINDOWS\System32\WTablet\Pen_TabletUser.exe (Wacom Technology, Corp.)
PRC - C:\WINDOWS\System32\Pen_Tablet.exe (Wacom Technology, Corp.)
PRC - C:\Apache2\bin\Apache.exe (Apache Software Foundation)
PRC - C:\MySQL\bin\mysqld-nt.exe ()
PRC - C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe ()
PRC - C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe (Hewlett-Packard)


========== Modules (No Company Name) ==========

MOD - C:\Users\Alberto\AppData\Local\Google\Chrome\Application\16.0.912.63\ppGoogleNaClPluginChrome.dll ()
MOD - C:\Users\Alberto\AppData\Local\Google\Chrome\Application\16.0.912.63\pdf.dll ()
MOD - C:\Users\Alberto\AppData\Local\Google\Chrome\Application\16.0.912.63\avutil-51.dll ()
MOD - C:\Users\Alberto\AppData\Local\Google\Chrome\Application\16.0.912.63\avformat-53.dll ()
MOD - C:\Users\Alberto\AppData\Local\Google\Chrome\Application\16.0.912.63\avcodec-53.dll ()
MOD - C:\Program Files\DivX\DivX Update\DivXUpdateCheck.dll ()
MOD - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
MOD - C:\Program Files\WinRAR\RarExt.dll ()
MOD - C:\Program Files\Hp\QuickPlay\Kernel\TV\CLTinyDB.dll ()
MOD - C:\Program Files\Hp\QuickPlay\Kernel\TV\CLCapEngine.dll ()
MOD - C:\Program Files\Hp\QuickPlay\Kernel\TV\CLSchMgr.dll ()
MOD - C:\Program Files\Hp\QuickPlay\Kernel\TV\CLCapSvcps.dll ()
MOD - C:\Program Files\Hp\QuickPlay\Kernel\common\MCEMediaStatus.dll ()
MOD - C:\Program Files\Common Files\LightScribe\QtGui4.dll ()
MOD - C:\Program Files\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll ()
MOD - C:\Program Files\Common Files\LightScribe\QtCore4.dll ()
MOD - C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnfps.dll ()
MOD - C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe ()


========== Win32 Services (SafeList) ==========

SRV - (Akamai) – c:\program files\common files\akamai/netsession_win_b427739.dll ()
SRV - (AntiVirService) – C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (AntiVirSchedulerService) – C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (DCService.exe) – C:\ProgramData\DatacardService\DCService.exe ()
SRV - (FirebirdServerDefaultInstance) – C:\Program Files\Common Files\Firebird\bin\fb_inet_server.exe (Firebird Project)
SRV - (HPSLPSVC) – C:\Program Files\Hewlett-Packard\Digital Imaging\bin\HPSLPSVC32.DLL (Hewlett-Packard Co.)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (Macromedia Licensing Service) – C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe ()
SRV - (hpqddsvc) – C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqddsvc.dll (Hewlett-Packard Co.)
SRV - (hpqcxs08) – C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqcxs08.dll (Hewlett-Packard Co.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (TabletServicePen) – C:\WINDOWS\System32\Pen_Tablet.exe (Wacom Technology, Corp.)
SRV - (Com4Qlb) – C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe (Hewlett-Packard Development Company, L.P.)
SRV - (Apache2) – C:\Apache2\bin\Apache.exe (Apache Software Foundation)
SRV - (MySql) – C:\MySQL\bin\mysqld-nt.exe ()


========== Driver Services (SafeList) ==========

DRV - (FNETURPX) – C:\WINDOWS\System32\drivers\FNETURPX.SYS (FNet Co., Ltd.)
DRV - (avipbb) – C:\WINDOWS\System32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) – C:\WINDOWS\System32\drivers\avgntflt.sys (Avira GmbH)
DRV - (ewusbnet) – C:\WINDOWS\System32\drivers\ewusbnet.sys (Huawei Technologies Co., Ltd.)
DRV - (hwdatacard) – C:\WINDOWS\System32\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (huawei_enumerator) – C:\WINDOWS\System32\drivers\ew_jubusenum.sys (Huawei Technologies Co., Ltd.)
DRV - (ew_hwusbdev) – C:\WINDOWS\System32\drivers\ew_hwusbdev.sys (Huawei Technologies Co., Ltd.)
DRV - (ssmdrv) – C:\WINDOWS\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (avgio) – C:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (USBModem) – C:\WINDOWS\System32\drivers\lgusbmodem.sys (LG Electronics Inc.)
DRV - (usbbus) – C:\WINDOWS\System32\drivers\lgusbbus.sys (LG Electronics Inc.)
DRV - (UsbDiag) – C:\WINDOWS\System32\drivers\lgusbdiag.sys (LG Electronics Inc.)
DRV - (athr) – C:\WINDOWS\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (nvlddmkm) – C:\WINDOWS\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (HdAudAddService) – C:\WINDOWS\System32\drivers\CHDART.sys (Conexant Systems Inc.)
DRV - (HpqRemHid) – C:\WINDOWS\System32\drivers\HpqRemHid.sys (Hewlett-Packard Development Company, L.P.)
DRV - (XAudio) – C:\WINDOWS\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (HpqKbFiltr) – C:\WINDOWS\System32\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (rismxdp) – C:\WINDOWS\System32\drivers\rixdptsk.sys (REDC)
DRV - (NVENETFD) – C:\WINDOWS\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (rimmptsk) – C:\WINDOWS\System32\drivers\rimmptsk.sys (REDC)
DRV - (nvsmu) – C:\WINDOWS\System32\drivers\nvsmu.sys (NVIDIA Corporation)
DRV - (wacommousefilter) – C:\WINDOWS\System32\drivers\wacommousefilter.sys (Wacom Technology)
DRV - (wacomvhid) – C:\WINDOWS\System32\drivers\wacomvhid.sys (Wacom Technology)
DRV - (WacomVKHid) – C:\WINDOWS\System32\drivers\WacomVKHid.sys (Wacom Technology)
DRV - (rimsptsk) – C:\WINDOWS\System32\drivers\rimsptsk.sys (REDC)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.searchqu.com/406
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Search Results"
FF - prefs.js..browser.search.order.1: "Search Results"
FF - prefs.js..browser.startup.homepage: ""
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.0.900
FF - prefs.js..extensions.enabledItems: {6904342A-8307-11DF-A508-4AE2DFD72085}:2.1.0.900
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..keyword.URL: "http://dts.search-results.com/sr?src=ffb&appid=102&systemid=406&q="
FF - prefs.js..keyword.enabled: false

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.0: C:\Users\Alberto\AppData\Roaming\Facebook\npfbplugin_1_0_0.dll ( )
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Alberto\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Alberto\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Hewlett-Packard\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/12/06 20:16:21 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\html5video [2010/12/30 08:58:37 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files\DivX\DivX Plus Web Player\firefox\wpa [2010/12/30 08:58:37 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/11/11 18:49:48 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/10/28 06:47:39 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Hewlett-Packard\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/12/06 20:16:21 | 000,000,000 | —D | M]

[2011/07/01 22:18:48 | 000,000,000 | —D | M] (No name found) – C:\Users\Alberto\AppData\Roaming\mozilla\Extensions
[2010/02/18 21:39:24 | 000,000,000 | —D | M] (No name found) – C:\Users\Alberto\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2010/10/08 20:26:59 | 000,000,000 | —D | M] (No name found) – C:\Users\Alberto\AppData\Roaming\mozilla\Extensions\[removed]
[2011/08/04 18:46:56 | 000,000,000 | —D | M] (No name found) – C:\Users\Alberto\AppData\Roaming\mozilla\Firefox\Profiles\9wozrfnp.default\extensions
[2011/03/26 12:31:57 | 000,000,000 | —D | M] (Fissa) – C:\Users\Alberto\AppData\Roaming\mozilla\Firefox\Profiles\9wozrfnp.default\extensions\@FissaPlugin
[2011/07/01 22:17:52 | 000,002,501 | —- | M] () – C:\Users\Alberto\AppData\Roaming\Mozilla\Firefox\Profiles\9wozrfnp.default\searchplugins\SearchResults.xml
[2011/11/12 12:02:06 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/10/30 11:29:09 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
[2011/11/11 18:49:47 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/10/03 05:06:04 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/09/29 06:09:58 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/09/29 06:09:58 | 000,003,996 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\drae.xml
[2011/09/29 06:09:58 | 000,001,143 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay-es.xml
[2011/09/29 06:09:58 | 000,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia-es.xml
[2011/09/29 06:09:58 | 000,001,102 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo-es.xml

========== Chrome ==========

CHR - default_search_provider: Search Results (Enabled)
CHR - default_search_provider: search_url = http://dts.search-results.com/sr?src=crb&a…q={searchTerms}
CHR - default_search_provider: suggest_url =
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Alberto\AppData\Local\Google\Chrome\Application\16.0.912.63\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U26 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: DivX Web Player (Enabled) = C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Alberto\AppData\Local\Google\Chrome\Application\16.0.912.63\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Alberto\AppData\Local\Google\Chrome\Application\16.0.912.63\pdf.dll
CHR - plugin: DivX Player Netscape Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npDivxPlayerPlugin.dll
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: MetaStream 3 Plugin (Enabled) = C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Alberto\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Facebook Plugin (Enabled) = C:\Users\Alberto\AppData\Roaming\Facebook\npfbplugin_1_0_0.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:\Users\Alberto\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.2_0\
CHR - Extension: B\u00FAsqueda de Google = C:\Users\Alberto\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.16_0\
CHR - Extension: DivX HiQ = C:\Users\Alberto\AppData\Local\Google\Chrome\User Data\Default\Extensions\fnjbmmemklcjgepojigaapkoodmkgbae\2.1.0.900_0\
CHR - Extension: \u003Cvideo\u003E de HTML5 de DivX Plus Web Player = C:\Users\Alberto\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.0.900_0\
CHR - Extension: Gmail = C:\Users\Alberto\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\6.1.4_0\

O1 HOSTS File: ([2011/12/18 16:43:13 | 000,000,098 | —- | M]) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\Hewlett-Packard\Digital Imaging\smart web printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (DivX Plus Web Player HTML5 ) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\Hewlett-Packard\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O4 - HKLM..\Run: [AdobeCS4ServiceManager] C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [DivX Download Manager] C:\Program Files\DivX\DivX Plus Web Player\DDmService.exe (DivX, LLC)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe File not found
O4 - HKLM..\Run: [hpqSRMon] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\HpqSRmon.exe (Hewlett-Packard)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvSvc] C:\Windows\System32\nvsvc.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe (Hewlett-Packard)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" File not found
O4 - HKLM..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [AdobeBridge] File not found
O4 - HKCU..\Run: [Akamai NetSession Interface] C:\Users\Alberto\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc)
O4 - HKCU..\Run: [HPAdvisor] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe autoRun File not found
O4 - HKCU..\Run: [HW_OPENEYE_OUC_MTN Online] C:\Program Files\MTN Online\UpdateDog\ouc.exe (Huawei Technologies Co., Ltd.)
O4 - Startup: C:\Users\Alberto\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Alberto\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Users\Alberto\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\KeyState.lnk = C:\Users\Alberto\Desktop\KeyState.exe (Paul Heinrich)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O9 - Extra 'Tools' menuitem : Consola de Sun Java - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_29.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Mostrar u ocultar HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\Hewlett-Packard\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{230D4951-C929-409D-9EBE-B27FDC570E79}: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AD40F387-3E50-4C9D-81A9-1E5158CEA54D}: DhcpNameServer = 10.0.0.2
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E9343E97-8C5C-42D2-ADC6-4ED724C705C2}: DhcpNameServer = [removed] [removed]
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\WINDOWS\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: F:\Pictures\screensavers\fotolia-bosque.jpg
O24 - Desktop BackupWallPaper: F:\Pictures\screensavers\fotolia-bosque.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 22:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2005/09/11 16:18:54 | 000,000,340 | -HS- | M] () - D:\AUTOMODE – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/12/18 16:43:03 | 000,000,000 | —D | C] – C:\_OTL
[2011/12/18 10:27:03 | 000,000,000 | —D | C] – F:\Documents\DivX Movies
[2011/12/17 19:45:27 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Users\Alberto\Desktop\OTL.exe
[2011/12/15 07:02:06 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2011/12/15 07:02:04 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2011/12/15 07:02:04 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2011/12/15 07:02:03 | 001,798,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2011/12/15 07:02:03 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2011/12/15 07:01:59 | 001,427,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2011/12/14 18:35:23 | 003,602,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2011/12/14 18:35:22 | 003,550,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2011/12/14 18:35:19 | 002,043,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2011/12/14 18:35:17 | 000,429,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EncDec.dll
[2011/12/14 18:35:13 | 000,049,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\csrsrv.dll
[2011/12/14 18:35:04 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[2011/12/12 17:30:29 | 000,000,000 | —D | C] – C:\ProgramData\FNET
[2011/12/12 17:29:41 | 000,007,936 | —- | C] (FNet Co., Ltd.) – C:\Windows\System32\drivers\FNETURPX.SYS
[2011/12/12 17:29:29 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Clone EX
[2011/12/12 17:29:25 | 000,000,000 | —D | C] – C:\Program Files\PcCloneEX
[2011/12/06 18:16:02 | 000,000,000 | —D | C] – F:\Documents\PROJECTS
[2011/12/06 11:00:08 | 000,000,000 | —D | C] – C:\Users\Alberto\aqbanking

========== Files - Modified Within 30 Days ==========

[2011/12/18 17:09:00 | 000,001,118 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-546974084-4041679086-764574024-1000UA.job
[2011/12/18 17:00:33 | 010,010,860 | —- | M] () – C:\Windows\System32\perfh00A.dat
[2011/12/18 17:00:32 | 003,524,512 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/12/18 17:00:32 | 003,433,986 | —- | M] () – C:\Windows\System32\perfc00A.dat
[2011/12/18 17:00:32 | 002,914,174 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/12/18 16:56:54 | 000,000,163 | —- | M] () – C:\Users\Public\Documents\hpqp.ini
[2011/12/18 16:55:06 | 000,027,525 | —- | M] () – C:\Users\Alberto\AppData\Roaming\nvModes.001
[2011/12/18 16:53:20 | 000,003,168 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/12/18 16:53:20 | 000,003,168 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/12/18 16:53:13 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/12/18 16:43:13 | 000,000,098 | —- | M] () – C:\Windows\System32\drivers\etc\Hosts
[2011/12/17 19:45:02 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Alberto\Desktop\OTL.exe
[2011/12/17 12:17:17 | 000,050,673 | —- | M] () – F:\Documents\Mis cuentas.gnucash.20110516201003.gnucash
[2011/12/17 12:17:16 | 000,050,293 | —- | M] () – F:\Documents\Mis cuentas.gnucash.20110516201003.gnucash.20111217121716.gnucash
[2011/12/16 17:43:57 | 000,000,413 | —- | M] () – C:\Users\Alberto\Desktop\BORRAR.lnk
[2011/12/16 17:19:34 | 000,002,683 | —- | M] () – C:\Users\Alberto\Desktop\Outlook 2007.lnk
[2011/12/15 08:24:14 | 002,308,720 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2011/12/15 08:19:09 | 000,050,035 | —- | M] () – F:\Documents\Mis cuentas.gnucash.20110516201003.gnucash.20111215081909.gnucash
[2011/12/15 08:09:00 | 000,001,066 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-546974084-4041679086-764574024-1000Core.job
[2011/12/13 21:21:16 | 000,049,890 | —- | M] () – F:\Documents\Mis cuentas.gnucash.20110516201003.gnucash.20111213212116.gnucash
[2011/12/13 16:43:19 | 000,049,644 | —- | M] () – F:\Documents\Mis cuentas.gnucash.20110516201003.gnucash.20111213164319.gnucash
[2011/12/12 22:30:34 | 000,122,880 | —- | M] () – C:\Users\Alberto\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/12/12 20:58:13 | 000,049,373 | —- | M] () – F:\Documents\Mis cuentas.gnucash.20110516201003.gnucash.20111212205813.gnucash
[2011/12/12 17:30:24 | 000,001,653 | —- | M] () – C:\Users\Public\Desktop\PC Clone EX.LNK
[2011/12/12 17:29:41 | 000,007,936 | —- | M] (FNet Co., Ltd.) – C:\Windows\System32\drivers\FNETURPX.SYS
[2011/12/07 07:09:35 | 000,000,932 | —- | M] () – C:\Users\Alberto\Desktop\Dropbox.lnk
[2011/12/07 07:09:35 | 000,000,912 | —- | M] () – C:\Users\Alberto\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2011/12/06 11:33:38 | 000,003,120 | —- | M] () – C:\Windows\System32\ALLFSAF8a.ocx
[2011/12/06 11:33:30 | 000,002,036 | —- | M] () – C:\Users\Public\Desktop\Style Builder 2.lnk
[2011/12/06 11:33:30 | 000,001,950 | —- | M] () – C:\Users\Public\Desktop\LayOut 3.lnk
[2011/12/06 11:33:29 | 000,001,869 | —- | M] () – C:\Users\Public\Desktop\Google SketchUp 8.lnk
[2011/12/06 11:02:54 | 000,000,218 | —- | M] () – C:\Users\Alberto\.recently-used.xbel
[2011/12/06 10:43:37 | 000,001,815 | —- | M] () – C:\Users\Public\Desktop\GnuCash.lnk
[2011/12/05 17:46:21 | 000,000,296 | —- | M] () – C:\Users\Alberto\Desktop\Descargas.lnk
[2011/12/04 16:32:22 | 000,000,431 | —- | M] () – C:\Users\Alberto\Desktop\PROJECTS.lnk
[2011/12/03 20:57:15 | 000,000,362 | —- | M] () – C:\Users\Alberto\Desktop\MUSICA.lnk
[2011/11/23 14:37:27 | 002,043,904 | —- | M] (Microsoft Corporation) – C:\Windows\System32\win32k.sys

========== Files Created - No Company Name ==========

[2011/12/17 12:17:16 | 000,050,293 | —- | C] () – F:\Documents\Mis cuentas.gnucash.20110516201003.gnucash.20111217121716.gnucash
[2011/12/16 17:43:57 | 000,000,413 | —- | C] () – C:\Users\Alberto\Desktop\BORRAR.lnk
[2011/12/15 08:19:09 | 000,050,035 | —- | C] () – F:\Documents\Mis cuentas.gnucash.20110516201003.gnucash.20111215081909.gnucash
[2011/12/13 21:21:16 | 000,049,890 | —- | C] () – F:\Documents\Mis cuentas.gnucash.20110516201003.gnucash.20111213212116.gnucash
[2011/12/13 16:43:19 | 000,049,644 | —- | C] () – F:\Documents\Mis cuentas.gnucash.20110516201003.gnucash.20111213164319.gnucash
[2011/12/12 20:58:13 | 000,049,373 | —- | C] () – F:\Documents\Mis cuentas.gnucash.20110516201003.gnucash.20111212205813.gnucash
[2011/12/12 17:30:24 | 000,001,653 | —- | C] () – C:\Users\Public\Desktop\PC Clone EX.LNK
[2011/12/06 11:33:38 | 000,003,120 | —- | C] () – C:\Windows\System32\ALLFSAF8a.ocx
[2011/12/06 11:33:30 | 000,002,036 | —- | C] () – C:\Users\Public\Desktop\Style Builder 2.lnk
[2011/12/06 11:33:30 | 000,001,950 | —- | C] () – C:\Users\Public\Desktop\LayOut 3.lnk
[2011/12/06 11:02:54 | 000,000,218 | —- | C] () – C:\Users\Alberto\.recently-used.xbel
[2011/12/05 17:46:21 | 000,000,296 | —- | C] () – C:\Users\Alberto\Desktop\Descargas.lnk
[2011/12/04 16:32:22 | 000,000,431 | —- | C] () – C:\Users\Alberto\Desktop\PROJECTS.lnk
[2011/12/03 20:57:15 | 000,000,362 | —- | C] () – C:\Users\Alberto\Desktop\MUSICA.lnk
[2011/08/05 18:15:57 | 000,116,224 | —- | C] () – C:\Windows\System32\pdfcmnnt.dll
[2011/07/01 18:16:58 | 000,000,196 | —- | C] () – C:\Windows\System32\cpuz.ini
[2011/03/10 08:59:28 | 002,525,238 | —- | C] () – C:\Users\Alberto\AppData\Local\[j0002]-[p08].bmp
[2010/12/06 20:08:07 | 000,231,562 | —- | C] () – C:\Windows\hpoins43.dat.temp
[2010/12/06 19:49:44 | 000,231,686 | —- | C] () – C:\Windows\hpoins43.dat
[2010/12/06 19:08:07 | 000,000,113 | —- | C] () – C:\Windows\PhotoImpression.ini
[2010/12/06 13:40:03 | 000,000,601 | —- | C] () – C:\Windows\hpomdl43.dat.temp
[2010/11/14 19:41:03 | 000,128,396 | -H– | C] () – C:\Windows\System32\mlfcache.dat
[2010/05/28 20:18:41 | 000,019,456 | —- | C] () – C:\Users\Alberto\AppData\Local\WebpageIcons.db
[2010/05/19 18:10:37 | 000,007,592 | —- | C] () – C:\Users\Alberto\AppData\Local\d3d9caps.dat
[2010/03/11 17:50:32 | 000,078,245 | —- | C] () – C:\Windows\hpqins05.dat
[2010/03/08 20:11:48 | 000,162,174 | —- | C] () – C:\Windows\hpoins21.dat.temp
[2010/03/08 20:11:48 | 000,008,138 | —- | C] () – C:\Windows\hpomdl21.dat.temp
[2010/02/18 21:39:24 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat
[2010/01/31 17:10:51 | 000,000,056 | -H– | C] () – C:\Windows\System32\ezsidmv.dat
[2010/01/29 22:11:51 | 000,000,601 | —- | C] () – C:\Windows\hpomdl43.dat
[2010/01/10 21:22:38 | 000,019,582 | —- | C] () – C:\Windows\hpqins13.dat
[2009/12/22 12:41:28 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/12/22 12:41:28 | 000,107,612 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2009/12/21 19:38:38 | 000,164,807 | —- | C] () – C:\Windows\hpoins21.dat
[2009/12/21 16:59:16 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2009/12/20 17:35:54 | 000,122,880 | —- | C] () – C:\Users\Alberto\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/12/20 14:50:11 | 004,244,744 | —- | C] () – C:\Windows\System32\qtp-mt334.dll
[2009/12/20 14:50:11 | 000,247,560 | —- | C] () – C:\Windows\System32\prgiso.dll
[2009/12/20 14:50:11 | 000,013,576 | —- | C] () – C:\Windows\System32\wnaspi32.dll
[2009/12/20 14:40:04 | 000,027,525 | —- | C] () – C:\Users\Alberto\AppData\Roaming\nvModes.001
[2009/12/20 14:39:45 | 000,027,525 | —- | C] () – C:\Users\Alberto\AppData\Roaming\nvModes.dat
[2008/03/21 22:08:49 | 000,016,480 | —- | C] () – C:\Windows\System32\rixdicon.dll
[2008/03/21 22:04:38 | 000,001,732 | —- | C] () – C:\Windows\System32\drivers\nvphy.bin
[2008/02/25 06:55:57 | 000,336,930 | —- | C] () – C:\Windows\System32\perfi00A.dat
[2008/02/25 06:55:56 | 010,010,860 | —- | C] () – C:\Windows\System32\perfh00A.dat
[2008/02/25 06:55:56 | 003,433,986 | —- | C] () – C:\Windows\System32\perfc00A.dat
[2008/02/25 06:55:56 | 000,040,258 | —- | C] () – C:\Windows\System32\perfd00A.dat
[2007/09/05 19:26:30 | 000,007,262 | —- | C] () – C:\Windows\hpomdl21.dat
[2006/11/02 13:57:28 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 13:47:37 | 002,308,720 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 13:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 11:33:01 | 003,524,512 | —- | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 11:33:01 | 002,914,174 | —- | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 11:33:01 | 000,287,440 | —- | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 11:33:01 | 000,030,674 | —- | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 11:25:21 | 000,061,440 | —- | C] () – C:\Windows\System32\igfxTMM.dll
[2006/11/02 11:23:21 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2006/11/02 09:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/02 09:19:00 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/02 08:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 08:25:31 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2006/03/09 23:58:00 | 001,060,424 | —- | C] () – C:\Windows\System32\WdfCoInstaller01000.dll
[2004/05/18 16:10:30 | 000,000,172 | —- | C] () – C:\Windows\my.ini
[2004/03/25 09:33:48 | 000,040,620 | —- | C] () – C:\Windows\php.ini
[2000/04/14 16:50:02 | 000,343,040 | —- | C] () – C:\Windows\System32\Lffpx7.dll
[1998/06/11 14:08:06 | 000,095,232 | —- | C] () – C:\Windows\System32\Lfkodak.dll

========== Alternate Data Streams ==========

@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:9C4887B2

< End of report >





And here ComboFix.txt:


ComboFix 11-12-17.05 - Alberto 18/12/2011 17:28:00.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.34.3082.18.3071.1838 [GMT 1:00]
Running from: C:\Users\[removed]\Desktop\ComboFix.exe
AV: AntiVir Desktop *Disabled/Outdated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Disabled/Outdated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\ProgramData\ntuser.dat
C:\Users\Alberto\AppData\Roaming\Local
C:\Users\Alberto\AppData\Roaming\Local\Temp\DDM\Settings\0.ddi
C:\Users\Alberto\AppData\Roaming\Local\Temp\DDM\Settings\1.ddi
C:\Users\Alberto\AppData\Roaming\Local\Temp\DDM\Settings\1u8sdndl16t33.avi.ddr
C:\Users\Alberto\AppData\Roaming\Local\Temp\DDM\Settings\805.avi.ddr
C:\Users\Alberto\AppData\Roaming\Local\Temp\DDM\Settings\Inception_Trailer_592.divx(2).ddr
C:\Users\Alberto\AppData\Roaming\Local\Temp\DDM\Settings\Inception_Trailer_592.divx.ddr
C:\Users\Alberto\AppData\Roaming\Local\Temp\DDM\Settings\settings.ddi
C:\Users\Alberto\AppData\Roaming\Local\Temp\DDM\Settings\Temporary Downloaded Files\1u8sdndl16t33.avi.ddp
C:\Users\Alberto\AppData\Roaming\Local\Temp\DDM\Settings\Temporary Downloaded Files\805(2).avi
C:\Users\Alberto\AppData\Roaming\Local\Temp\DDM\Settings\Temporary Downloaded Files\805(3).avi
C:\Users\Alberto\AppData\Roaming\Local\Temp\DDM\Settings\Temporary Downloaded Files\805.avi
C:\Users\Alberto\AppData\Roaming\Local\Temp\DDM\Settings\Temporary Downloaded Files\805.avi.ddp
C:\Users\Alberto\AppData\Roaming\Local\Temp\DDM\Settings\Temporary Downloaded Files\Inception_Trailer_592(2).divx
C:\Users\Alberto\AppData\Roaming\Local\Temp\DDM\Settings\Temporary Downloaded Files\Inception_Trailer_592.divx
C:\Users\Alberto\AppData\Roaming\OfferBox
C:\Users\Alberto\AppData\Roaming\OfferBox\config.dat
C:\Users\Alberto\AppData\Roaming\OfferBox\config.xml
C:\Windows\My.ini
C:\Windows\system32\AutoRun.inf
C:\Windows\system32\KBL.LOG


((((((((((((((((((((((((( Files Created from 2011-11-18 to 2011-12-18 )))))))))))))))))))))))))))))))


2011-12-18 16:46:47 . 2011-12-18 16:46:47 56200 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{9ED79A73-682C-40D7-8538-4C908AD594C5}\offreg.dll
2011-12-18 16:44:28 . 2011-12-18 16:44:28 ——– d—–w- C:\Users\Default\AppData\Local\temp
2011-12-18 15:43:03 . 2011-12-18 15:43:03 ——– d—–w- C:\_OTL
2011-12-17 11:11:25 . 2011-11-21 10:47:38 6823496 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{9ED79A73-682C-40D7-8538-4C908AD594C5}\mpengine.dll
2011-12-15 06:01:59 . 2011-11-03 22:40:21 1427456 —-a-w- C:\Windows\system32\inetcpl.cpl
2011-12-14 17:35:23 . 2011-10-27 08:01:53 3602816 —-a-w- C:\Windows\system32\ntkrnlpa.exe
2011-12-14 17:35:22 . 2011-10-27 08:01:53 3550080 —-a-w- C:\Windows\system32\ntoskrnl.exe
2011-12-14 17:35:19 . 2011-11-23 13:37:27 2043904 —-a-w- C:\Windows\system32\win32k.sys
2011-12-14 17:35:17 . 2011-10-14 16:02:19 429056 —-a-w- C:\Windows\system32\EncDec.dll
2011-12-14 17:35:16 . 2011-11-08 12:10:10 2409784 —-a-w- C:\Program Files\Windows Mail\OESpamFilter.dat
2011-12-14 17:35:13 . 2011-10-25 15:56:04 49152 —-a-w- C:\Windows\system32\csrsrv.dll
2011-12-14 17:35:04 . 2011-11-08 14:42:19 2048 —-a-w- C:\Windows\system32\tzres.dll
2011-12-12 16:30:29 . 2011-12-12 16:30:29 ——– d—–w- C:\ProgramData\FNET
2011-12-12 16:29:41 . 2011-12-12 16:29:41 7936 —-a-w- C:\Windows\system32\drivers\FNETURPX.SYS
2011-12-12 16:29:25 . 2011-12-12 16:29:39 ——– d—–w- C:\Program Files\PcCloneEX
2011-12-12 16:27:51 . 2011-12-12 16:27:51 303236 —-a-w- C:\Program Files\Common Files\InstallShield\Professional\RunTime\10\00\Intel32\setup.dll
2011-12-12 16:27:51 . 2011-12-12 16:27:51 180356 —-a-w- C:\Program Files\Common Files\InstallShield\Professional\RunTime\10\00\Intel32\iGdi.dll
2011-12-06 10:00:08 . 2011-12-06 10:00:08 ——– d—–w- C:\Users\Alberto\aqbanking
.


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2011-11-17 21:31:08 . 2011-05-17 14:26:25 414368 —-a-w- C:\Windows\system32\FlashPlayerCPLApp.cpl
2011-10-24 12:29:02 . 2011-10-24 12:29:02 94208 —-a-w- C:\Windows\system32\QuickTimeVR.qtx
2011-10-24 12:29:02 . 2011-10-24 12:29:02 69632 —-a-w- C:\Windows\system32\QuickTime.qts
2011-10-03 04:06:03 . 2010-11-11 17:02:55 472808 —-a-w- C:\Windows\system32\deployJava1.dll
2011-09-20 21:02:55 . 2011-11-09 15:52:09 905088 —-a-w- C:\Windows\system32\drivers\tcpip.sys
2011-11-11 17:49:47 . 2011-03-22 17:10:41 134104 —-a-w- C:\Program Files\mozilla firefox\components\browsercomps.dll
2007-10-31 13:45:34 12288 –sh–w- C:\Windows\Twunk_16.dll
2007-10-31 13:45:34 12288 –sh–w- C:\Windows\Twunk_32.dll
Hi. I updated and run ComboFix again to get a new full log, because yesterday I think I stopped CF before it had finished.
This is the new log:


ComboFix 11-12-18.02 - Alberto 19/12/2011 7:49.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.34.3082.18.3071.1964 [GMT 1:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: AntiVir Desktop *Disabled/Outdated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Disabled/Outdated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
—- Previous Run ——-
.
c:\programdata\ntuser.dat
c:\users\Alberto\AppData\Roaming\Local\Temp\DDM\Settings\0.ddi
c:\users\Alberto\AppData\Roaming\Local\Temp\DDM\Settings\1.ddi
c:\users\Alberto\AppData\Roaming\Local\Temp\DDM\Settings\1u8sdndl16t33.avi.ddr
c:\users\Alberto\AppData\Roaming\Local\Temp\DDM\Settings\805.avi.ddr
c:\users\Alberto\AppData\Roaming\Local\Temp\DDM\Settings\Inception_Trailer_592.divx(2).ddr
c:\users\Alberto\AppData\Roaming\Local\Temp\DDM\Settings\Inception_Trailer_592.divx.ddr
c:\users\Alberto\AppData\Roaming\Local\Temp\DDM\Settings\settings.ddi
c:\users\Alberto\AppData\Roaming\Local\Temp\DDM\Settings\Temporary Downloaded Files\1u8sdndl16t33.avi.ddp
c:\users\Alberto\AppData\Roaming\Local\Temp\DDM\Settings\Temporary Downloaded Files\805(2).avi
c:\users\Alberto\AppData\Roaming\Local\Temp\DDM\Settings\Temporary Downloaded Files\805(3).avi
c:\users\Alberto\AppData\Roaming\Local\Temp\DDM\Settings\Temporary Downloaded Files\805.avi
c:\users\Alberto\AppData\Roaming\Local\Temp\DDM\Settings\Temporary Downloaded Files\805.avi.ddp
c:\users\Alberto\AppData\Roaming\Local\Temp\DDM\Settings\Temporary Downloaded Files\Inception_Trailer_592(2).divx
c:\users\Alberto\AppData\Roaming\Local\Temp\DDM\Settings\Temporary Downloaded Files\Inception_Trailer_592.divx
c:\users\Alberto\AppData\Roaming\OfferBox\config.dat
c:\users\Alberto\AppData\Roaming\OfferBox\config.xml
c:\windows\My.ini
c:\windows\system32\AutoRun.inf
c:\windows\system32\KBL.LOG
.
.
((((((((((((((((((((((((( Files Created from 2011-11-19 to 2011-12-19 )))))))))))))))))))))))))))))))
.
.
2011-12-19 07:27 . 2011-12-19 07:27 ——– d—–w- c:\users\Default\AppData\Local\temp
2011-12-19 05:48 . 2011-12-19 05:48 56200 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{9ED79A73-682C-40D7-8538-4C908AD594C5}\offreg.dll
2011-12-18 15:43 . 2011-12-18 15:43 ——– d—–w- C:\_OTL
2011-12-17 11:11 . 2011-11-21 10:47 6823496 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{9ED79A73-682C-40D7-8538-4C908AD594C5}\mpengine.dll
2011-12-15 06:01 . 2011-11-03 22:40 1427456 —-a-w- c:\windows\system32\inetcpl.cpl
2011-12-14 17:35 . 2011-10-27 08:01 3602816 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-12-14 17:35 . 2011-10-27 08:01 3550080 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-12-14 17:35 . 2011-11-23 13:37 2043904 —-a-w- c:\windows\system32\win32k.sys
2011-12-14 17:35 . 2011-10-14 16:02 429056 —-a-w- c:\windows\system32\EncDec.dll
2011-12-14 17:35 . 2011-11-08 12:10 2409784 —-a-w- c:\program files\Windows Mail\OESpamFilter.dat
2011-12-14 17:35 . 2011-10-25 15:56 49152 —-a-w- c:\windows\system32\csrsrv.dll
2011-12-14 17:35 . 2011-11-08 14:42 2048 —-a-w- c:\windows\system32\tzres.dll
2011-12-12 16:30 . 2011-12-12 16:30 ——– d—–w- c:\programdata\FNET
2011-12-12 16:29 . 2011-12-12 16:29 7936 —-a-w- c:\windows\system32\drivers\FNETURPX.SYS
2011-12-12 16:29 . 2011-12-12 16:29 ——– d—–w- c:\program files\PcCloneEX
2011-12-12 16:27 . 2011-12-12 16:27 303236 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\00\Intel32\setup.dll
2011-12-12 16:27 . 2011-12-12 16:27 180356 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\00\Intel32\iGdi.dll
2011-12-06 10:00 . 2011-12-06 10:00 ——– d—–w- c:\users\Alberto\aqbanking
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-17 21:31 . 2011-05-17 14:26 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-24 12:29 . 2011-10-24 12:29 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx
2011-10-24 12:29 . 2011-10-24 12:29 69632 —-a-w- c:\windows\system32\QuickTime.qts
2011-10-03 04:06 . 2010-11-11 17:02 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-09-20 21:02 . 2011-11-09 15:52 905088 —-a-w- c:\windows\system32\drivers\tcpip.sys
2011-11-11 17:49 . 2011-03-22 17:10 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2007-10-31 13:45 12288 –sh–w- c:\windows\Twunk_16.dll
2007-10-31 13:45 12288 –sh–w- c:\windows\Twunk_32.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\users\Alberto\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\users\Alberto\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\users\Alberto\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\users\Alberto\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2007-08-23 455968]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-18 125952]
"HW_OPENEYE_OUC_MTN Online"="c:\program files\MTN Online\UpdateDog\ouc.exe" [2010-03-16 110592]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-10-13 17351304]
"Akamai NetSession Interface"="c:\users\Alberto\AppData\Local\Akamai\netsession_win.exe" [2011-12-06 3305248]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-18 202240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-09-15 102400]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2007-09-30 181544]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-09-19 202032]
"OnScreenDisplay"="c:\program files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe" [2007-09-04 554320]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-08-16 218408]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-09-13 480560]
"WAWifiMessage"="c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-08 311296]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-08-17 281768]
"VirtualCloneDrive"="c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2009-05-26 85160]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2010-11-08 611712]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-09-19 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-09-19 8497696]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-09-19 81920]
"hpqSRMon"="c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqSRMon.exe" [2008-08-20 150016]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-09-07 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"Share-to-Web Namespace Daemon"="c:\program files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2001-07-03 57344]
"DivX Download Manager"="c:\program files\DivX\DivX Plus Web Player\DDmService.exe" [2010-12-08 63360]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-11-12 421736]
.
c:\users\Alberto\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Alberto\AppData\Roaming\Dropbox\bin\Dropbox.exe [2011-12-5 24242056]
KeyState.lnk - c:\users\Alberto\Desktop\KeyState.exe [2011-10-19 354304]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe [2009-11-18 275072]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-546974084-4041679086-764574024-1000]
"EnableNotifications"=dword:00000001
"EnableNotificationsRef"=dword:00000002
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 DCService.exe;DCService.exe;c:\programdata\DatacardService\DCService.exe [2010-09-29 249856]
R3 ALSysIO;ALSysIO;c:\users\Alberto\AppData\Local\Temp\ALSysIO.sys [x]
R3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;c:\windows\system32\DRIVERS\ew_hwusbdev.sys [2010-07-27 102784]
R3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\DRIVERS\ewusbnet.sys [2010-08-27 116736]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S1 FNETURPX;FNETURPX;c:\windows\system32\drivers\FNETURPX.SYS [2011-12-12 7936]
S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2008-01-18 21504]
S2 AntiVirSchedulerService;Avira AntiVir Programador;c:\program files\Avira\AntiVir Desktop\sched.exe [2011-05-03 136360]
S2 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance;c:\program files\Common Files\Firebird\bin\fb_inet_server.exe [2010-09-17 3727360]
S2 TabletServicePen;TabletServicePen;c:\windows\system32\Pen_Tablet.exe [2007-09-07 1373480]
S3 huawei_enumerator;huawei_enumerator;c:\windows\system32\DRIVERS\ew_jubusenum.sys [2010-07-27 72832]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
Akamai REG_MULTI_SZ Akamai
HPService REG_MULTI_SZ HPSLPSVC
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2007-08-23 16:34 451872 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
.
2011-12-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-546974084-4041679086-764574024-1000Core.job
- c:\users\Alberto\AppData\Local\Google\Update\GoogleUpdate.exe [2010-11-07 23:39]
.
2011-12-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-546974084-4041679086-764574024-1000UA.job
- c:\users\Alberto\AppData\Local\Google\Update\GoogleUpdate.exe [2010-11-07 23:39]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.searchqu.com/406
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=es_es&c=81&bd=Pavilion&pf=laptop
uInternet Settings,ProxyOverride = *.local
IE: E&xportar a Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = [removed] [removed]
FF - ProfilePath - c:\users\Alberto\AppData\Roaming\Mozilla\Firefox\Profiles\9wozrfnp.default\
FF - prefs.js: keyword.URL - hxxp://dts.search-results.com/sr?src=ffb&appid=102&systemid=406&q=
FF - prefs.js: keyword.enabled - false
.
- - - - ORPHANS REMOVED - - - -
.
HKCU-Run-HPAdvisor - c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
HKCU-Run-AdobeBridge - (no file)
HKLM-Run-HP Health Check Scheduler - [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
HKLM-Run-SunJavaUpdateSched - c:\program files\Java\jre6\bin\jusched.exe
AddRemove-{7B63B2922B174135AFC0E1377DD81EC2} - c:\program files\DivX\DivXCodecUninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-19 08:27
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …
.
[0] 0x6F433D6F
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Akamai]
"ServiceDll"="c:\program files\common files\akamai/netsession_win_b427739.dll"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'Explorer.exe'(3744)
c:\users\Alberto\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
c:\program files\Hewlett-Packard\HP Share-to-Web\HPGS2WNS.DLL
c:\program files\Hewlett-Packard\HP Share-to-Web\S2WNSRES.DLL
c:\program files\Hewlett-Packard\HP Share-to-Web\HPGS2WNFPS.DLL
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
.
Completion time: 2011-12-19 08:31:05
ComboFix-quarantined-files.txt 2011-12-19 07:31
.
Pre-Run: 30.247.292.928 bytes libres
Post-Run: 30.175.617.024 bytes libres
.
- - End Of File - - 3CE7D83094245D0A290A1B3F9168A618


Thank you again.
Hi Alberto

Search plugins

Check if the search plugins are still showing up in Firefox:
  • click on Tools, Add-ons then on the Plugins tab
  • if it is there, click on Searchqu and then on Disable
====================================================

Open ComboFix

Please do the following:
  • close any open browsers.
  • close/disable all anti virus and anti malware programs so that they do not interfere with the running of ComboFix.
  • open notepad and copy/paste the text in the codebox below into it:
Firefox::
FF - ProfilePath - c:\users\Alberto\AppData\Roaming\Mozilla\Firefox\Profiles\9wozrfnp.default\
uStart Page = hxxp://www.searchqu.com/406

Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe

[external image: Posted Image]

Referring to the picture above, drag CFScript into ComboFix.exe

When finished, it produces a log at C:\ComboFix.txt. Post the contents of Combofix.txt in your next reply.

====================================================

Run Malwarebytes’ Anti-Malware

I noticed that you had MBAM on your system: if you no longer have it, you can download it from here:
  • start Malwarebytes-Anti-Malware and update it, (“Update” tab}
  • once it is updated, click on “Scanner” tab, select Perform quick scan, then click Scan.
  • when the scan is complete, click OK, then Show Results to view the results.
  • be sure that everything is checked, and click Remove Selected.
  • when removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • the log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • copy and paste the contents of that report in your next reply and exit MBAM.
NOTE: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

Please tell what problems remain

Thanks

Satchfan
Hi again, Satchfan, and thank you for your fast replies.



This is ComboFix.txt:

ComboFix 11-12-18.02 - Alberto 19/12/2011 15:12:21.3.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.34.3082.18.3071.1888 [GMT 1:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\Alberto\Desktop\CFScript.txt
AV: AntiVir Desktop *Disabled/Outdated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Disabled/Outdated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Files Created from 2011-11-19 to 2011-12-19 )))))))))))))))))))))))))))))))
.
.
2011-12-19 14:49 . 2011-12-19 14:49 ——– d—–w- c:\users\Default\AppData\Local\temp
2011-12-19 13:35 . 2011-12-19 13:35 56200 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{9ED79A73-682C-40D7-8538-4C908AD594C5}\offreg.dll
2011-12-18 15:43 . 2011-12-18 15:43 ——– d—–w- C:\_OTL
2011-12-17 11:11 . 2011-11-21 10:47 6823496 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{9ED79A73-682C-40D7-8538-4C908AD594C5}\mpengine.dll
2011-12-15 06:01 . 2011-11-03 22:40 1427456 —-a-w- c:\windows\system32\inetcpl.cpl
2011-12-14 17:35 . 2011-10-27 08:01 3602816 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-12-14 17:35 . 2011-10-27 08:01 3550080 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-12-14 17:35 . 2011-11-23 13:37 2043904 —-a-w- c:\windows\system32\win32k.sys
2011-12-14 17:35 . 2011-10-14 16:02 429056 —-a-w- c:\windows\system32\EncDec.dll
2011-12-14 17:35 . 2011-11-08 12:10 2409784 —-a-w- c:\program files\Windows Mail\OESpamFilter.dat
2011-12-14 17:35 . 2011-10-25 15:56 49152 —-a-w- c:\windows\system32\csrsrv.dll
2011-12-14 17:35 . 2011-11-08 14:42 2048 —-a-w- c:\windows\system32\tzres.dll
2011-12-12 16:30 . 2011-12-12 16:30 ——– d—–w- c:\programdata\FNET
2011-12-12 16:29 . 2011-12-12 16:29 7936 —-a-w- c:\windows\system32\drivers\FNETURPX.SYS
2011-12-12 16:29 . 2011-12-12 16:29 ——– d—–w- c:\program files\PcCloneEX
2011-12-12 16:27 . 2011-12-12 16:27 303236 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\00\Intel32\setup.dll
2011-12-12 16:27 . 2011-12-12 16:27 180356 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\00\Intel32\iGdi.dll
2011-12-06 10:00 . 2011-12-06 10:00 ——– d—–w- c:\users\Alberto\aqbanking
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-17 21:31 . 2011-05-17 14:26 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-24 12:29 . 2011-10-24 12:29 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx
2011-10-24 12:29 . 2011-10-24 12:29 69632 —-a-w- c:\windows\system32\QuickTime.qts
2011-10-03 04:06 . 2010-11-11 17:02 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-09-20 21:02 . 2011-11-09 15:52 905088 —-a-w- c:\windows\system32\drivers\tcpip.sys
2011-11-11 17:49 . 2011-03-22 17:10 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2007-10-31 13:45 12288 –sh–w- c:\windows\Twunk_16.dll
2007-10-31 13:45 12288 –sh–w- c:\windows\Twunk_32.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\users\Alberto\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\users\Alberto\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\users\Alberto\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\users\Alberto\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2007-08-23 455968]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-18 125952]
"HW_OPENEYE_OUC_MTN Online"="c:\program files\MTN Online\UpdateDog\ouc.exe" [2010-03-16 110592]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-10-13 17351304]
"Akamai NetSession Interface"="c:\users\Alberto\AppData\Local\Akamai\netsession_win.exe" [2011-12-06 3305248]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-18 202240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-09-15 102400]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2007-09-30 181544]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-09-19 202032]
"OnScreenDisplay"="c:\program files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe" [2007-09-04 554320]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-08-16 218408]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-09-13 480560]
"WAWifiMessage"="c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-08 311296]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-08-17 281768]
"VirtualCloneDrive"="c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2009-05-26 85160]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2010-11-08 611712]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-09-19 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-09-19 8497696]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-09-19 81920]
"hpqSRMon"="c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqSRMon.exe" [2008-08-20 150016]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-09-07 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"Share-to-Web Namespace Daemon"="c:\program files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2001-07-03 57344]
"DivX Download Manager"="c:\program files\DivX\DivX Plus Web Player\DDmService.exe" [2010-12-08 63360]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-11-12 421736]
.
c:\users\Alberto\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Alberto\AppData\Roaming\Dropbox\bin\Dropbox.exe [2011-12-5 24242056]
KeyState.lnk - c:\users\Alberto\Desktop\KeyState.exe [2011-10-19 354304]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe [2009-11-18 275072]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-546974084-4041679086-764574024-1000]
"EnableNotifications"=dword:00000001
"EnableNotificationsRef"=dword:00000002
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 DCService.exe;DCService.exe;c:\programdata\DatacardService\DCService.exe [2010-09-29 249856]
R3 ALSysIO;ALSysIO;c:\users\Alberto\AppData\Local\Temp\ALSysIO.sys [x]
R3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;c:\windows\system32\DRIVERS\ew_hwusbdev.sys [2010-07-27 102784]
R3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\DRIVERS\ewusbnet.sys [2010-08-27 116736]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S1 FNETURPX;FNETURPX;c:\windows\system32\drivers\FNETURPX.SYS [2011-12-12 7936]
S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2008-01-18 21504]
S2 AntiVirSchedulerService;Avira AntiVir Programador;c:\program files\Avira\AntiVir Desktop\sched.exe [2011-05-03 136360]
S2 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance;c:\program files\Common Files\Firebird\bin\fb_inet_server.exe [2010-09-17 3727360]
S2 TabletServicePen;TabletServicePen;c:\windows\system32\Pen_Tablet.exe [2007-09-07 1373480]
S3 huawei_enumerator;huawei_enumerator;c:\windows\system32\DRIVERS\ew_jubusenum.sys [2010-07-27 72832]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
Akamai REG_MULTI_SZ Akamai
HPService REG_MULTI_SZ HPSLPSVC
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2007-08-23 16:34 451872 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
.
2011-12-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-546974084-4041679086-764574024-1000Core.job
- c:\users\Alberto\AppData\Local\Google\Update\GoogleUpdate.exe [2010-11-07 23:39]
.
2011-12-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-546974084-4041679086-764574024-1000UA.job
- c:\users\Alberto\AppData\Local\Google\Update\GoogleUpdate.exe [2010-11-07 23:39]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.searchqu.com/406
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=es_es&c=81&bd=Pavilion&pf=laptop
uInternet Settings,ProxyOverride = *.local
IE: E&xportar a Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = [removed] [removed]
FF - ProfilePath - c:\users\Alberto\AppData\Roaming\Mozilla\Firefox\Profiles\9wozrfnp.default\
FF - prefs.js: keyword.URL - hxxp://dts.search-results.com/sr?src=ffb&appid=102&systemid=406&q=
FF - prefs.js: keyword.enabled - false
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-19 15:49
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Akamai]
"ServiceDll"="c:\program files\common files\akamai/netsession_win_b427739.dll"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'Explorer.exe'(3772)
c:\users\Alberto\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
c:\program files\Hewlett-Packard\HP Share-to-Web\HPGS2WNS.DLL
c:\program files\Hewlett-Packard\HP Share-to-Web\S2WNSRES.DLL
c:\program files\Hewlett-Packard\HP Share-to-Web\HPGS2WNFPS.DLL
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
.
Completion time: 2011-12-19 15:53:21
ComboFix-quarantined-files.txt 2011-12-19 14:53
ComboFix2.txt 2011-12-19 07:31
.
Pre-Run: 30.086.451.200 bytes libres
Post-Run: 30.049.112.064 bytes libres
.
- - End Of File - - B572640C0B8922D4B7646B9248E8D609



And this is the MBAM log. I'm afraid it's in spanish, but is says it couldn't found any infected file:

Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Versión de la Base de Datos: 8397

Windows 6.0.6002 Service Pack 2
Internet Explorer 9.0.8112.16421

19/12/2011 16:29:47
mbam-log-2011-12-19 (16-29-47).txt

Tipos de Análisis: Análisis Rápido
Objetos examinados: 181700
Tiempo transcurrido: 3 minuto(s), 47 segundo(s)

Procesos en Memoria Infectados: 0
Módulos de Memoria Infectados: 0
Claves del Registro Infectadas: 0
Valores del Registro Infectados: 0
Elementos de Datos del Registro Infectados: 0
Carpetas Infectadas: 0
Archivos Infectados: 0

Procesos en Memoria Infectados:
(No se han detectado elementos maliciosos)

Módulos de Memoria Infectados:
(No se han detectado elementos maliciosos)

Claves del Registro Infectadas:
(No se han detectado elementos maliciosos)

Valores del Registro Infectados:
(No se han detectado elementos maliciosos)

Elementos de Datos del Registro Infectados:
(No se han detectado elementos maliciosos)

Carpetas Infectadas:
(No se han detectado elementos maliciosos)

Archivos Infectados:
(No se han detectado elementos maliciosos)



Does this mean Searqu is gone?
Cheers.

Does this mean Searchqu is gone?

I'm not sure. Did you follow the instructions to disable the Searchqu plugin because Searchqu is still showing as your start page?

Please do the following:
  • Open Firefox
  • Click on Tools, Options, General and see what is entered as your home page.
  • If it is Searchqu, in the “Home page” box type in your home page of choice: eg http://www.google.co.uk/
Restart Firefox and then send a new DDS log

Thanks

Satchfan
Hi. Sorry, yesterday I meant to tell you what I did but then I actually forgot. When you told me to disable the Searchqu plugin in Firefox, I actually couldn't do it cause I couldn't find it. I think I already disabled it a few months ago, so now it's not there anymore. Now, after changing that setting, Searchqu does not appear as my Home Page in Firefox anymore, which is good. However, both in Ffox and Chrome it's the search engine that I have by default. I only installed OTL and ComboFIx, so, when you ask me for a DDS log, can it be an OTL one? I'm going to run OTL again and post the result just in case this is also useful. Thank you for your help, Satchfan.
This is the new OTL log:


OTL logfile created on: 20/12/2011 8:14:55 - Run 3
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Alberto\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000C0A | Country: España | Language: ESN | Date Format: dd/MM/yyyy

3,00 Gb Total Physical Memory | 1,99 Gb Available Physical Memory | 66,25% Memory free
6,23 Gb Paging File | 4,86 Gb Available in Paging File | 78,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 76,19 Gb Total Space | 27,51 Gb Free Space | 36,11% Space Free | Partition Type: NTFS
Drive D: | 11,35 Gb Total Space | 2,16 Gb Free Space | 19,02% Space Free | Partition Type: NTFS
Drive F: | 145,34 Gb Total Space | 89,35 Gb Free Space | 61,47% Space Free | Partition Type: NTFS

Computer Name: LAPTOP-DE-BERTO | User Name: Alberto | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Alberto\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Users\Alberto\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc)
PRC - C:\Users\Alberto\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
PRC - C:\Users\Alberto\Desktop\KeyState.exe (Paul Heinrich)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files\DivX\DivX Plus Web Player\DDMService.exe (DivX, LLC)
PRC - C:\ProgramData\DatacardService\DCService.exe ()
PRC - C:\ProgramData\DatacardService\DCSHelper.exe (Huawei Technologies Co., Ltd.)
PRC - C:\Program Files\Common Files\Firebird\bin\fb_inet_server.exe (Firebird Project)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Users\Alberto\AppData\Roaming\MTN Online\ouc.exe (Huawei Technologies Co., Ltd.)
PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH)
PRC - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqste08.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqbam08.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqgpc01.exe (Hewlett-Packard)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Synaptics\SynTP\SynTPStart.exe (Synaptics, Inc.)
PRC - C:\WINDOWS\System32\WTablet\Pen_TabletUser.exe (Wacom Technology, Corp.)
PRC - C:\WINDOWS\System32\Pen_Tablet.exe (Wacom Technology, Corp.)
PRC - C:\Apache2\bin\Apache.exe (Apache Software Foundation)
PRC - C:\MySQL\bin\mysqld-nt.exe ()
PRC - C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe ()
PRC - C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe (Hewlett-Packard)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\DivX\DivX Update\DivXUpdateCheck.dll ()
MOD - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files\WinRAR\RarExt.dll ()
MOD - C:\Program Files\Hp\QuickPlay\Kernel\TV\CLTinyDB.dll ()
MOD - C:\Program Files\Hp\QuickPlay\Kernel\TV\CLCapEngine.dll ()
MOD - C:\Program Files\Hp\QuickPlay\Kernel\TV\CLSchMgr.dll ()
MOD - C:\Program Files\Hp\QuickPlay\Kernel\TV\CLCapSvcps.dll ()
MOD - C:\Program Files\Hp\QuickPlay\Kernel\common\MCEMediaStatus.dll ()
MOD - C:\Program Files\Common Files\LightScribe\QtGui4.dll ()
MOD - C:\Program Files\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll ()
MOD - C:\Program Files\Common Files\LightScribe\QtCore4.dll ()
MOD - C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnfps.dll ()
MOD - C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe ()


========== Win32 Services (SafeList) ==========

SRV - (Akamai) – c:\program files\common files\akamai/netsession_win_b427739.dll ()
SRV - (AntiVirService) – C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (AntiVirSchedulerService) – C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (DCService.exe) – C:\ProgramData\DatacardService\DCService.exe ()
SRV - (FirebirdServerDefaultInstance) – C:\Program Files\Common Files\Firebird\bin\fb_inet_server.exe (Firebird Project)
SRV - (HPSLPSVC) – C:\Program Files\Hewlett-Packard\Digital Imaging\bin\HPSLPSVC32.DLL (Hewlett-Packard Co.)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (Macromedia Licensing Service) – C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe ()
SRV - (hpqddsvc) – C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqddsvc.dll (Hewlett-Packard Co.)
SRV - (hpqcxs08) – C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqcxs08.dll (Hewlett-Packard Co.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (TabletServicePen) – C:\WINDOWS\System32\Pen_Tablet.exe (Wacom Technology, Corp.)
SRV - (Com4Qlb) – C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe (Hewlett-Packard Development Company, L.P.)
SRV - (Apache2) – C:\Apache2\bin\Apache.exe (Apache Software Foundation)
SRV - (MySql) – C:\MySQL\bin\mysqld-nt.exe ()


========== Driver Services (SafeList) ==========

DRV - (FNETURPX) – C:\WINDOWS\System32\drivers\FNETURPX.SYS (FNet Co., Ltd.)
DRV - (avipbb) – C:\WINDOWS\System32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) – C:\WINDOWS\System32\drivers\avgntflt.sys (Avira GmbH)
DRV - (ewusbnet) – C:\WINDOWS\System32\drivers\ewusbnet.sys (Huawei Technologies Co., Ltd.)
DRV - (hwdatacard) – C:\WINDOWS\System32\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (huawei_enumerator) – C:\WINDOWS\System32\drivers\ew_jubusenum.sys (Huawei Technologies Co., Ltd.)
DRV - (ew_hwusbdev) – C:\WINDOWS\System32\drivers\ew_hwusbdev.sys (Huawei Technologies Co., Ltd.)
DRV - (ssmdrv) – C:\WINDOWS\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (avgio) – C:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (USBModem) – C:\WINDOWS\System32\drivers\lgusbmodem.sys (LG Electronics Inc.)
DRV - (usbbus) – C:\WINDOWS\System32\drivers\lgusbbus.sys (LG Electronics Inc.)
DRV - (UsbDiag) – C:\WINDOWS\System32\drivers\lgusbdiag.sys (LG Electronics Inc.)
DRV - (athr) – C:\WINDOWS\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (nvlddmkm) – C:\WINDOWS\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (HdAudAddService) – C:\WINDOWS\System32\drivers\CHDART.sys (Conexant Systems Inc.)
DRV - (HpqRemHid) – C:\WINDOWS\System32\drivers\HpqRemHid.sys (Hewlett-Packard Development Company, L.P.)
DRV - (XAudio) – C:\WINDOWS\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (HpqKbFiltr) – C:\WINDOWS\System32\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (rismxdp) – C:\WINDOWS\System32\drivers\rixdptsk.sys (REDC)
DRV - (NVENETFD) – C:\WINDOWS\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (rimmptsk) – C:\WINDOWS\System32\drivers\rimmptsk.sys (REDC)
DRV - (nvsmu) – C:\WINDOWS\System32\drivers\nvsmu.sys (NVIDIA Corporation)
DRV - (wacommousefilter) – C:\WINDOWS\System32\drivers\wacommousefilter.sys (Wacom Technology)
DRV - (wacomvhid) – C:\WINDOWS\System32\drivers\wacomvhid.sys (Wacom Technology)
DRV - (WacomVKHid) – C:\WINDOWS\System32\drivers\WacomVKHid.sys (Wacom Technology)
DRV - (rimsptsk) – C:\WINDOWS\System32\drivers\rimsptsk.sys (REDC)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.searchqu.com/406
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Search Results"
FF - prefs.js..browser.search.order.1: "Search Results"
FF - prefs.js..browser.startup.homepage: "http://www.google.com"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.0.900
FF - prefs.js..extensions.enabledItems: {6904342A-8307-11DF-A508-4AE2DFD72085}:2.1.0.900
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..keyword.URL: "http://dts.search-results.com/sr?src=ffb&appid=102&systemid=406&q="
FF - prefs.js..keyword.enabled: false

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.0: C:\Users\Alberto\AppData\Roaming\Facebook\npfbplugin_1_0_0.dll ( )
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Alberto\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Alberto\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Hewlett-Packard\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/12/06 20:16:21 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\html5video [2010/12/30 08:58:37 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files\DivX\DivX Plus Web Player\firefox\wpa [2010/12/30 08:58:37 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/11/11 18:49:48 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/10/28 06:47:39 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Hewlett-Packard\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/12/06 20:16:21 | 000,000,000 | —D | M]

[2011/07/01 22:18:48 | 000,000,000 | —D | M] (No name found) – C:\Users\Alberto\AppData\Roaming\mozilla\Extensions
[2010/02/18 21:39:24 | 000,000,000 | —D | M] (No name found) – C:\Users\Alberto\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2010/10/08 20:26:59 | 000,000,000 | —D | M] (No name found) – C:\Users\Alberto\AppData\Roaming\mozilla\Extensions\[removed]
[2011/08/04 18:46:56 | 000,000,000 | —D | M] (No name found) – C:\Users\Alberto\AppData\Roaming\mozilla\Firefox\Profiles\9wozrfnp.default\extensions
[2011/03/26 12:31:57 | 000,000,000 | —D | M] (Fissa) – C:\Users\Alberto\AppData\Roaming\mozilla\Firefox\Profiles\9wozrfnp.default\extensions\@FissaPlugin
[2011/07/01 22:17:52 | 000,002,501 | —- | M] () – C:\Users\Alberto\AppData\Roaming\Mozilla\Firefox\Profiles\9wozrfnp.default\searchplugins\SearchResults.xml
[2011/11/12 12:02:06 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/10/30 11:29:09 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
[2011/11/11 18:49:47 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/10/03 05:06:04 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/09/29 06:09:58 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/09/29 06:09:58 | 000,003,996 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\drae.xml
[2011/09/29 06:09:58 | 000,001,143 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay-es.xml
[2011/09/29 06:09:58 | 000,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia-es.xml
[2011/09/29 06:09:58 | 000,001,102 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo-es.xml

========== Chrome ==========

CHR - default_search_provider: Search Results (Enabled)
CHR - default_search_provider: search_url = http://dts.search-results.com/sr?src=crb&a…q={searchTerms}
CHR - default_search_provider: suggest_url =
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Alberto\AppData\Local\Google\Chrome\Application\16.0.912.63\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U26 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: DivX Web Player (Enabled) = C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Alberto\AppData\Local\Google\Chrome\Application\16.0.912.63\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Alberto\AppData\Local\Google\Chrome\Application\16.0.912.63\pdf.dll
CHR - plugin: DivX Player Netscape Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npDivxPlayerPlugin.dll
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: MetaStream 3 Plugin (Enabled) = C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Alberto\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Facebook Plugin (Enabled) = C:\Users\Alberto\AppData\Roaming\Facebook\npfbplugin_1_0_0.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:\Users\Alberto\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.2_0\
CHR - Extension: B\u00FAsqueda de Google = C:\Users\Alberto\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.16_0\
CHR - Extension: DivX HiQ = C:\Users\Alberto\AppData\Local\Google\Chrome\User Data\Default\Extensions\fnjbmmemklcjgepojigaapkoodmkgbae\2.1.0.900_0\
CHR - Extension: \u003Cvideo\u003E de HTML5 de DivX Plus Web Player = C:\Users\Alberto\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.0.900_0\
CHR - Extension: Gmail = C:\Users\Alberto\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\6.1.4_0\

O1 HOSTS File: ([2011/12/18 17:47:46 | 000,000,027 | —- | M]) - C:\WINDOWS\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\Hewlett-Packard\Digital Imaging\smart web printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (DivX Plus Web Player HTML5 ) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\Hewlett-Packard\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O4 - HKLM..\Run: [AdobeCS4ServiceManager] C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [DivX Download Manager] C:\Program Files\DivX\DivX Plus Web Player\DDmService.exe (DivX, LLC)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [hpqSRMon] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\HpqSRmon.exe (Hewlett-Packard)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvSvc] C:\Windows\System32\nvsvc.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe (Hewlett-Packard)
O4 - HKLM..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe (Synaptics, Inc.)
O4 - HKCU..\Run: [Akamai NetSession Interface] C:\Users\Alberto\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc)
O4 - HKCU..\Run: [HW_OPENEYE_OUC_MTN Online] C:\Program Files\MTN Online\UpdateDog\ouc.exe (Huawei Technologies Co., Ltd.)
O4 - Startup: C:\Users\Alberto\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Alberto\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Users\Alberto\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\KeyState.lnk = C:\Users\Alberto\Desktop\KeyState.exe (Paul Heinrich)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Mostrar u ocultar HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\Hewlett-Packard\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{230D4951-C929-409D-9EBE-B27FDC570E79}: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AD40F387-3E50-4C9D-81A9-1E5158CEA54D}: DhcpNameServer = 10.0.0.2
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E9343E97-8C5C-42D2-ADC6-4ED724C705C2}: DhcpNameServer = [removed] [removed]
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\WINDOWS\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: F:\Pictures\screensavers\fotolia-bosque.jpg
O24 - Desktop BackupWallPaper: F:\Pictures\screensavers\fotolia-bosque.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 22:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2005/09/11 16:18:54 | 000,000,340 | -HS- | M] () - D:\AUTOMODE – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/12/19 15:52:31 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2011/12/19 15:08:41 | 000,000,000 | —D | C] – C:\ComboFix
[2011/12/18 17:25:18 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2011/12/18 17:25:18 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2011/12/18 17:25:18 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2011/12/18 17:25:14 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2011/12/18 17:25:09 | 000,000,000 | —D | C] – C:\Qoobox
[2011/12/18 17:24:55 | 000,000,000 | R–D | C] – C:\Users\Alberto\Videos
[2011/12/18 17:18:53 | 004,344,515 | R— | C] (Swearware) – C:\Users\Alberto\Desktop\ComboFix.exe
[2011/12/18 16:43:03 | 000,000,000 | —D | C] – C:\_OTL
[2011/12/18 10:27:03 | 000,000,000 | —D | C] – F:\Documents\DivX Movies
[2011/12/17 19:45:27 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Users\Alberto\Desktop\OTL.exe
[2011/12/15 07:02:06 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2011/12/15 07:02:04 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2011/12/15 07:02:04 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2011/12/15 07:02:03 | 001,798,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2011/12/15 07:02:03 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2011/12/15 07:01:59 | 001,427,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2011/12/14 18:35:23 | 003,602,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2011/12/14 18:35:22 | 003,550,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2011/12/14 18:35:19 | 002,043,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2011/12/14 18:35:17 | 000,429,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EncDec.dll
[2011/12/14 18:35:13 | 000,049,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\csrsrv.dll
[2011/12/14 18:35:04 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[2011/12/12 17:30:29 | 000,000,000 | —D | C] – C:\ProgramData\FNET
[2011/12/12 17:29:41 | 000,007,936 | —- | C] (FNet Co., Ltd.) – C:\Windows\System32\drivers\FNETURPX.SYS
[2011/12/12 17:29:29 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Clone EX
[2011/12/12 17:29:25 | 000,000,000 | —D | C] – C:\Program Files\PcCloneEX
[2011/12/06 18:16:02 | 000,000,000 | —D | C] – F:\Documents\PROJECTS
[2011/12/06 11:00:08 | 000,000,000 | —D | C] – C:\Users\Alberto\aqbanking

========== Files - Modified Within 30 Days ==========

[2011/12/20 08:09:00 | 000,001,118 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-546974084-4041679086-764574024-1000UA.job
[2011/12/20 08:09:00 | 000,001,066 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-546974084-4041679086-764574024-1000Core.job
[2011/12/20 06:58:37 | 010,073,116 | —- | M] () – C:\Windows\System32\perfh00A.dat
[2011/12/20 06:58:36 | 003,456,418 | —- | M] () – C:\Windows\System32\perfc00A.dat
[2011/12/20 06:58:35 | 003,540,242 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/12/20 06:58:35 | 002,929,136 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/12/20 06:54:14 | 000,027,525 | —- | M] () – C:\Users\Alberto\AppData\Roaming\nvModes.001
[2011/12/20 06:53:04 | 000,000,163 | —- | M] () – C:\Users\Public\Documents\hpqp.ini
[2011/12/20 06:51:26 | 000,003,168 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/12/20 06:51:26 | 000,003,168 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/12/20 06:51:19 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/12/19 16:24:31 | 000,000,873 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/12/19 09:10:55 | 000,050,853 | —- | M] () – F:\Documents\Mis cuentas.gnucash.20110516201003.gnucash
[2011/12/19 09:10:54 | 000,050,673 | —- | M] () – F:\Documents\Mis cuentas.gnucash.20110516201003.gnucash.20111219091054.gnucash
[2011/12/19 07:44:38 | 004,344,515 | R— | M] (Swearware) – C:\Users\Alberto\Desktop\ComboFix.exe
[2011/12/18 17:47:46 | 000,000,027 | —- | M] () – C:\Windows\System32\drivers\etc\hosts
[2011/12/17 19:45:02 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Alberto\Desktop\OTL.exe
[2011/12/17 12:17:16 | 000,050,293 | —- | M] () – F:\Documents\Mis cuentas.gnucash.20110516201003.gnucash.20111217121716.gnucash
[2011/12/16 17:43:57 | 000,000,413 | —- | M] () – C:\Users\Alberto\Desktop\BORRAR.lnk
[2011/12/16 17:19:34 | 000,002,683 | —- | M] () – C:\Users\Alberto\Desktop\Outlook 2007.lnk
[2011/12/15 08:24:14 | 002,308,720 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2011/12/15 08:19:09 | 000,050,035 | —- | M] () – F:\Documents\Mis cuentas.gnucash.20110516201003.gnucash.20111215081909.gnucash
[2011/12/13 21:21:16 | 000,049,890 | —- | M] () – F:\Documents\Mis cuentas.gnucash.20110516201003.gnucash.20111213212116.gnucash
[2011/12/13 16:43:19 | 000,049,644 | —- | M] () – F:\Documents\Mis cuentas.gnucash.20110516201003.gnucash.20111213164319.gnucash
[2011/12/12 22:30:34 | 000,122,880 | —- | M] () – C:\Users\Alberto\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/12/12 20:58:13 | 000,049,373 | —- | M] () – F:\Documents\Mis cuentas.gnucash.20110516201003.gnucash.20111212205813.gnucash
[2011/12/12 17:30:24 | 000,001,653 | —- | M] () – C:\Users\Public\Desktop\PC Clone EX.LNK
[2011/12/12 17:29:41 | 000,007,936 | —- | M] (FNet Co., Ltd.) – C:\Windows\System32\drivers\FNETURPX.SYS
[2011/12/07 07:09:35 | 000,000,932 | —- | M] () – C:\Users\Alberto\Desktop\Dropbox.lnk
[2011/12/07 07:09:35 | 000,000,912 | —- | M] () – C:\Users\Alberto\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2011/12/06 11:33:38 | 000,003,120 | —- | M] () – C:\Windows\System32\ALLFSAF8a.ocx
[2011/12/06 11:33:30 | 000,002,036 | —- | M] () – C:\Users\Public\Desktop\Style Builder 2.lnk
[2011/12/06 11:33:30 | 000,001,950 | —- | M] () – C:\Users\Public\Desktop\LayOut 3.lnk
[2011/12/06 11:33:29 | 000,001,869 | —- | M] () – C:\Users\Public\Desktop\Google SketchUp 8.lnk
[2011/12/06 11:02:54 | 000,000,218 | —- | M] () – C:\Users\Alberto\.recently-used.xbel
[2011/12/06 10:43:37 | 000,001,815 | —- | M] () – C:\Users\Public\Desktop\GnuCash.lnk
[2011/12/05 17:46:21 | 000,000,296 | —- | M] () – C:\Users\Alberto\Desktop\Descargas.lnk
[2011/12/04 16:32:22 | 000,000,431 | —- | M] () – C:\Users\Alberto\Desktop\PROJECTS.lnk
[2011/12/03 20:57:15 | 000,000,362 | —- | M] () – C:\Users\Alberto\Desktop\MUSICA.lnk
[2011/11/23 14:37:27 | 002,043,904 | —- | M] (Microsoft Corporation) – C:\Windows\System32\win32k.sys

========== Files Created - No Company Name ==========

[2011/12/19 09:10:54 | 000,050,673 | —- | C] () – F:\Documents\Mis cuentas.gnucash.20110516201003.gnucash.20111219091054.gnucash
[2011/12/18 17:25:18 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2011/12/18 17:25:18 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2011/12/18 17:25:18 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2011/12/18 17:25:18 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2011/12/18 17:25:18 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2011/12/17 12:17:16 | 000,050,293 | —- | C] () – F:\Documents\Mis cuentas.gnucash.20110516201003.gnucash.20111217121716.gnucash
[2011/12/16 17:43:57 | 000,000,413 | —- | C] () – C:\Users\Alberto\Desktop\BORRAR.lnk
[2011/12/15 08:19:09 | 000,050,035 | —- | C] () – F:\Documents\Mis cuentas.gnucash.20110516201003.gnucash.20111215081909.gnucash
[2011/12/13 21:21:16 | 000,049,890 | —- | C] () – F:\Documents\Mis cuentas.gnucash.20110516201003.gnucash.20111213212116.gnucash
[2011/12/13 16:43:19 | 000,049,644 | —- | C] () – F:\Documents\Mis cuentas.gnucash.20110516201003.gnucash.20111213164319.gnucash
[2011/12/12 20:58:13 | 000,049,373 | —- | C] () – F:\Documents\Mis cuentas.gnucash.20110516201003.gnucash.20111212205813.gnucash
[2011/12/12 17:30:24 | 000,001,653 | —- | C] () – C:\Users\Public\Desktop\PC Clone EX.LNK
[2011/12/06 11:33:38 | 000,003,120 | —- | C] () – C:\Windows\System32\ALLFSAF8a.ocx
[2011/12/06 11:33:30 | 000,002,036 | —- | C] () – C:\Users\Public\Desktop\Style Builder 2.lnk
[2011/12/06 11:33:30 | 000,001,950 | —- | C] () – C:\Users\Public\Desktop\LayOut 3.lnk
[2011/12/06 11:02:54 | 000,000,218 | —- | C] () – C:\Users\Alberto\.recently-used.xbel
[2011/12/05 17:46:21 | 000,000,296 | —- | C] () – C:\Users\Alberto\Desktop\Descargas.lnk
[2011/12/04 16:32:22 | 000,000,431 | —- | C] () – C:\Users\Alberto\Desktop\PROJECTS.lnk
[2011/12/03 20:57:15 | 000,000,362 | —- | C] () – C:\Users\Alberto\Desktop\MUSICA.lnk
[2011/08/05 18:15:57 | 000,116,224 | —- | C] () – C:\Windows\System32\pdfcmnnt.dll
[2011/07/01 18:16:58 | 000,000,196 | —- | C] () – C:\Windows\System32\cpuz.ini
[2011/03/10 08:59:28 | 002,525,238 | —- | C] () – C:\Users\Alberto\AppData\Local\[j0002]-[p08].bmp
[2010/12/06 20:08:07 | 000,231,562 | —- | C] () – C:\Windows\hpoins43.dat.temp
[2010/12/06 19:49:44 | 000,231,686 | —- | C] () – C:\Windows\hpoins43.dat
[2010/12/06 19:08:07 | 000,000,113 | —- | C] () – C:\Windows\PhotoImpression.ini
[2010/12/06 13:40:03 | 000,000,601 | —- | C] () – C:\Windows\hpomdl43.dat.temp
[2010/11/14 19:41:03 | 000,128,396 | -H– | C] () – C:\Windows\System32\mlfcache.dat
[2010/05/28 20:18:41 | 000,019,456 | —- | C] () – C:\Users\Alberto\AppData\Local\WebpageIcons.db
[2010/05/19 18:10:37 | 000,007,592 | —- | C] () – C:\Users\Alberto\AppData\Local\d3d9caps.dat
[2010/03/11 17:50:32 | 000,078,245 | —- | C] () – C:\Windows\hpqins05.dat
[2010/03/08 20:11:48 | 000,162,174 | —- | C] () – C:\Windows\hpoins21.dat.temp
[2010/03/08 20:11:48 | 000,008,138 | —- | C] () – C:\Windows\hpomdl21.dat.temp
[2010/02/18 21:39:24 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat
[2010/01/31 17:10:51 | 000,000,056 | -H– | C] () – C:\Windows\System32\ezsidmv.dat
[2010/01/29 22:11:51 | 000,000,601 | —- | C] () – C:\Windows\hpomdl43.dat
[2010/01/10 21:22:38 | 000,019,582 | —- | C] () – C:\Windows\hpqins13.dat
[2009/12/22 12:41:28 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/12/22 12:41:28 | 000,107,612 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2009/12/21 19:38:38 | 000,164,807 | —- | C] () – C:\Windows\hpoins21.dat
[2009/12/21 16:59:16 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2009/12/20 17:35:54 | 000,122,880 | —- | C] () – C:\Users\Alberto\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/12/20 14:50:11 | 004,244,744 | —- | C] () – C:\Windows\System32\qtp-mt334.dll
[2009/12/20 14:50:11 | 000,247,560 | —- | C] () – C:\Windows\System32\prgiso.dll
[2009/12/20 14:50:11 | 000,013,576 | —- | C] () – C:\Windows\System32\wnaspi32.dll
[2009/12/20 14:40:04 | 000,027,525 | —- | C] () – C:\Users\Alberto\AppData\Roaming\nvModes.001
[2009/12/20 14:39:45 | 000,027,525 | —- | C] () – C:\Users\Alberto\AppData\Roaming\nvModes.dat
[2008/03/21 22:08:49 | 000,016,480 | —- | C] () – C:\Windows\System32\rixdicon.dll
[2008/03/21 22:04:38 | 000,001,732 | —- | C] () – C:\Windows\System32\drivers\nvphy.bin
[2008/02/25 06:55:57 | 000,336,930 | —- | C] () – C:\Windows\System32\perfi00A.dat
[2008/02/25 06:55:56 | 010,073,116 | —- | C] () – C:\Windows\System32\perfh00A.dat
[2008/02/25 06:55:56 | 003,456,418 | —- | C] () – C:\Windows\System32\perfc00A.dat
[2008/02/25 06:55:56 | 000,040,258 | —- | C] () – C:\Windows\System32\perfd00A.dat
[2007/09/05 19:26:30 | 000,007,262 | —- | C] () – C:\Windows\hpomdl21.dat
[2006/11/02 13:57:28 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 13:47:37 | 002,308,720 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 13:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 11:33:01 | 003,540,242 | —- | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 11:33:01 | 002,929,136 | —- | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 11:33:01 | 000,287,440 | —- | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 11:33:01 | 000,030,674 | —- | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 11:25:21 | 000,061,440 | —- | C] () – C:\Windows\System32\igfxTMM.dll
[2006/11/02 11:23:21 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2006/11/02 09:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/02 09:19:00 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/02 08:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 08:25:31 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2006/03/09 23:58:00 | 001,060,424 | —- | C] () – C:\Windows\System32\WdfCoInstaller01000.dll
[2004/03/25 09:33:48 | 000,040,620 | —- | C] () – C:\Windows\php.ini
[2000/04/14 16:50:02 | 000,343,040 | —- | C] () – C:\Windows\System32\Lffpx7.dll
[1998/06/11 14:08:06 | 000,095,232 | —- | C] () – C:\Windows\System32\Lfkodak.dll

========== Alternate Data Streams ==========

@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:9C4887B2

< End of report >


I'll be waiting for your reply. Cheers.

I only installed OTL and ComboFIx, so, when you ask me for a DDS log, can it be an OTL one?

My apologies. Yes, the OTL log was fine.

You;ve done a good job and all seems well apart from Internet Explorer showing the home page as “Searchqu” but we’ll fix that.

Run OTL
  • Double click on the icon to run it.
  • Copy/paste ALL the following text written inside the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.searchqu.com/406
    
    :Commands
    [purity]
    [emptytemp]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log (don't check the boxes beside LOP Check or Purity this time)
========================================================

Run Security Check

Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
Satchfan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI