This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trojan.JS.PornPopUp.a (v) Cannot Remove [Solved]

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

About 2 and a half weeks ago I was on an adult site when I noticed my computer acting glitchy. I ran Ad-aware free and it came back with MANY tracking cookies and Trojan.JS.PornPopUp.a (v). Ad-aware removed all the cookies but was only able to quarantine this trojan. Inside the quarantine log of ad-aware it shows Trojan.JS.PornPopUp.a (v) and then off to the right under object it has 3 other things which appear to end with .htm Each time I did a smart scan or full scan with ad-aware free it would show between 2 and 10 tracking cookies and would remove them but they would somehow reappear within the next scan or scan after. My internet browsing is slowed and takes time to load when I type anything into google search bar. My computer seemed to get stuck 2 times during a webpage loading when I opened multiple webpage tabs which resulted in me force turning off my computer. I have turned off third party cookies in my internet browser and I have ran pcdoctor (but didnt do anything cause it needed registration so i deleted it) / superantispyware / a registry cleaner that needed payment so i never had it modify anything / malwarebytes / spybot search and destroy / Avast / ATF cleaner and have now loaded comodo firewall, all of these ones have not detected anything. As of right now 2 weeks after the initial quarantine my internet is still slow when typing into google search and yesterday was when it froze when i had multiple internet tabs open. The only good thing is I havnt had adaware pick up any new tracking cookies in a few days. Thankyou for taking the time to read this, greatly appreciated. I have downloaded and used OTL:

OTL logfile created on: 1/17/2012 9:15:08 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Kevin\Desktop\Movies
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.06 Gb Available Physical Memory | 68.81% Memory free
5.99 Gb Paging File | 4.61 Gb Available in Paging File | 76.89% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 465.75 Gb Total Space | 325.00 Gb Free Space | 69.78% Space Free | Partition Type: NTFS
Drive D: | 466.99 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: KEVIN-PC | User Name: Kevin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Kevin\Desktop\Movies\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
PRC - C:\Windows\SysWOW64\Macromed\Flash\FlashUtil11e_ActiveX.exe (Adobe Systems, Inc.)
PRC - C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe ()


========== Modules (No Company Name) ==========

MOD - C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (cmdAgent) – C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (COMODO)
SRV:64bit: - (avast! Antivirus) – C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV:64bit: - (AMD FUEL Service) – C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Advanced Micro Devices, Inc.)
SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (aswSnx) – C:\Windows\SysNative\drivers\aswSnx.sys (AVAST Software)
DRV:64bit: - (aswSP) – C:\Windows\SysNative\drivers\aswSP.sys (AVAST Software)
DRV:64bit: - (aswRdr) – C:\Windows\SysNative\drivers\aswRdr.sys (AVAST Software)
DRV:64bit: - (aswTdi) – C:\Windows\SysNative\drivers\aswTdi.sys (AVAST Software)
DRV:64bit: - (aswMonFlt) – C:\Windows\SysNative\drivers\aswMonFlt.sys (AVAST Software)
DRV:64bit: - (aswFsBlk) – C:\Windows\SysNative\drivers\aswFsBlk.sys (AVAST Software)
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (AODDriver4.01) – C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys (Advanced Micro Devices)
DRV:64bit: - (AtiHDAudioService) – C:\Windows\SysNative\drivers\AtihdW76.sys (Advanced Micro Devices)
DRV:64bit: - (Lbd) – C:\Windows\SysNative\drivers\Lbd.sys (Lavasoft AB)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdiox64) – C:\Windows\SysNative\drivers\amdiox64.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek Corporation )
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.youtube.com/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://ca.msn.com/iat/us_ca.aspx
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 28 99 7B 8F 7B 8C CB 01 [binary data]
IE - HKCU\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - No CLSID value found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)



O1 HOSTS File: ([2012/01/03 08:36:01 | 000,440,010 | R— | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 127.0.0.1 123fporn.info
O1 - Hosts: 15127 more lines…
O2:64bit: - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2 - BHO: (BitComet Helper) - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files (x86)\BitComet\tools\BitCometBHO_1.4.12.6.dll (BitComet)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll File not found
O2 - BHO: (QuickNet BHO) - {EA5CA8B6-9B9C-4994-A7A1-947B6C631BE7} - C:\Program Files (x86)\RegTweaker\key.dll File not found
O2 - BHO: (ChromeFrame BHO) - {ECB3C477-1A0A-44BD-BB57-78F9EFE34FA7} - C:\Program Files (x86)\Google\Chrome Frame\Application\16.0.912.75\npchrome_frame.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O4:64bit: - HKLM..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: &D;&ownload; &with; BitComet - C:\Program Files (x86)\BitComet\BitComet.exe (www.BitComet.com)
O8:64bit: - Extra context menu item: &D;&ownload; all with BitComet - C:\Program Files (x86)\BitComet\BitComet.exe (www.BitComet.com)
O8 - Extra context menu item: &D;&ownload; &with; BitComet - C:\Program Files (x86)\BitComet\BitComet.exe (www.BitComet.com)
O8 - Extra context menu item: &D;&ownload; all with BitComet - C:\Program Files (x86)\BitComet\BitComet.exe (www.BitComet.com)
O9 - Extra Button: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll File not found
O9 - Extra 'Tools' menuitem : Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll File not found
O9 - Extra Button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - C:\Program Files (x86)\BitComet\tools\BitCometBHO_1.4.12.6.dll (BitComet)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{136C5C7F-EA71-4010-8009-CCCBCCC58A75}: DhcpNameServer = [removed] [removed] [removed]
O18:64bit: - Protocol\Handler\gcf - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18 - Protocol\Handler\gcf {9875BFAF-B04D-445E-8A69-BE36838CDE3E} - C:\Program Files (x86)\Google\Chrome Frame\Application\16.0.912.75\npchrome_frame.dll (Google Inc.)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll File not found
O20:64bit: - AppInit_DLLs: (C:\Windows\system32\guard64.dll) - C:\Windows\SysNative\guard64.dll (COMODO)
O20 - AppInit_DLLs: (C:\Windows\SysWOW64\guard32.dll) -C:\Windows\SysWOW64\guard32.dll (COMODO)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) -C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/11/22 04:02:06 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2004/08/24 14:38:10 | 000,000,000 | —D | M] - D:\Autorun – [ CDFS ]
O32 - AutoRun File - [2004/10/05 16:11:42 | 000,180,224 | R— | M] () - D:\Autorun.exe – [ CDFS ]
O32 - AutoRun File - [2004/08/24 14:57:32 | 000,000,042 | R— | M] () - D:\Autorun.inf – [ CDFS ]
O33 - MountPoints2\{45d293ba-f87e-11df-b997-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{45d293ba-f87e-11df-b997-806e6f6e6963}\Shell\AutoRun\command - "" = D:\Autorun.exe – [2004/10/05 16:11:42 | 000,180,224 | R— | M] ()
O33 - MountPoints2\{883f24b5-33c9-11e1-9092-6cf049db36d2}\Shell - "" = AutoRun
O33 - MountPoints2\{883f24b5-33c9-11e1-9092-6cf049db36d2}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (lsdelete)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)

Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/01/17 20:25:33 | 000,000,000 | —D | C] – C:\Users\Kevin\AppData\Local\AMD
[2012/01/15 10:43:57 | 000,000,000 | —D | C] – C:\ProgramData\PC Tools
[2012/01/15 10:43:45 | 000,000,000 | —D | C] – C:\ProgramData\TEMP
[2012/01/15 10:42:13 | 000,000,000 | —D | C] – C:\Users\Kevin\AppData\Roaming\GetRightToGo
[2012/01/14 01:14:32 | 000,000,000 | —D | C] – C:\Users\Kevin\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2012/01/14 01:14:30 | 000,000,000 | —D | C] – C:\ProgramData\Adobe
[2012/01/14 01:14:27 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Adobe AIR
[2012/01/14 01:14:27 | 000,000,000 | —D | C] – C:\Program Files (x86)\Adobe
[2012/01/13 23:15:42 | 000,000,000 | —D | C] – C:\Users\Kevin\AppData\Roaming\gtk-2.0
[2012/01/13 23:14:58 | 000,000,000 | —D | C] – C:\Users\Kevin\.thumbnails
[2012/01/13 23:13:39 | 000,000,000 | —D | C] – C:\Users\Kevin\Documents\gegl-0.0
[2012/01/13 23:13:39 | 000,000,000 | —D | C] – C:\Users\Kevin\.gimp-2.6
[2012/01/13 23:13:23 | 000,000,000 | —D | C] – C:\Program Files (x86)\GIMP-2.0
[2012/01/10 19:36:56 | 001,328,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\quartz.dll
[2012/01/10 19:36:55 | 001,572,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\quartz.dll
[2012/01/10 19:36:54 | 000,514,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\qdvd.dll
[2012/01/10 19:36:54 | 000,366,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\qdvd.dll
[2012/01/10 19:36:51 | 000,852,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2012/01/10 19:36:50 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2012/01/10 19:36:48 | 001,739,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntdll.dll
[2012/01/10 19:36:44 | 000,077,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\packager.dll
[2012/01/10 19:36:44 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\packager.dll
[2012/01/07 23:32:18 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\COMODO
[2012/01/07 23:32:06 | 000,000,000 | —D | C] – C:\ProgramData\Comodo
[2012/01/07 23:32:01 | 000,000,000 | —D | C] – C:\Program Files\COMODO
[2012/01/05 14:06:15 | 000,000,000 | —D | C] – C:\Users\Kevin\AppData\Roaming\vlc
[2012/01/02 22:41:24 | 000,000,000 | —D | C] – C:\Users\Kevin\Documents\RCT3
[2012/01/02 22:41:24 | 000,000,000 | —D | C] – C:\Users\Kevin\AppData\Roaming\Atari
[2012/01/02 22:37:51 | 000,000,000 | —D | C] – C:\Users\Kevin\AppData\Roaming\Leadertech
[2012/01/02 22:37:35 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\PocketSoft
[2012/01/02 22:34:03 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Atari
[2012/01/02 22:33:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\Atari
[2012/01/02 22:09:28 | 000,000,000 | —D | C] – C:\sh4ldr
[2012/01/02 22:09:28 | 000,000,000 | —D | C] – C:\Program Files\Enigma Software Group
[2012/01/02 22:08:32 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Wise Installation Wizard
[2012/01/01 22:16:00 | 000,000,000 | R–D | C] – C:\Users\Kevin\Desktop\Diablo 3 Related
[2012/01/01 22:15:10 | 000,000,000 | —D | C] – C:\Users\Kevin\Desktop\Virus Killing Tools
[2012/01/01 20:24:12 | 000,024,408 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswFsBlk.sys
[2012/01/01 20:24:12 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Free Antivirus
[2012/01/01 20:24:11 | 000,304,472 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswSP.sys
[2012/01/01 20:24:09 | 000,042,328 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswRdr.sys
[2012/01/01 20:24:08 | 000,058,712 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswTdi.sys
[2012/01/01 20:24:07 | 000,591,192 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswSnx.sys
[2012/01/01 20:24:04 | 000,066,904 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswMonFlt.sys
[2012/01/01 20:24:03 | 000,256,960 | —- | C] (AVAST Software) – C:\Windows\SysNative\aswBoot.exe
[2012/01/01 20:23:00 | 000,041,184 | —- | C] (AVAST Software) – C:\Windows\avastSS.scr
[2012/01/01 20:22:59 | 000,199,816 | —- | C] (AVAST Software) – C:\Windows\SysWow64\aswBoot.exe
[2012/01/01 20:22:53 | 000,000,000 | —D | C] – C:\ProgramData\AVAST Software
[2012/01/01 20:22:53 | 000,000,000 | —D | C] – C:\Program Files\AVAST Software
[2012/01/01 16:15:38 | 000,000,000 | —D | C] – C:\Windows\pss
[2012/01/01 02:59:54 | 000,000,000 | —D | C] – C:\Users\Kevin\AppData\Roaming\SUPERAntiSpyware.com
[2012/01/01 02:45:07 | 000,000,000 | —D | C] – C:\Users\Kevin\AppData\Roaming\Malwarebytes
[2012/01/01 02:45:00 | 000,023,152 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2012/01/01 02:45:00 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/01/01 02:45:00 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012/01/01 02:45:00 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2012/01/01 00:48:05 | 000,000,000 | —D | C] – C:\Users\Kevin\Desktop\Kijiji
[2011/12/31 22:09:33 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2011/12/25 08:09:33 | 000,000,000 | —D | C] – C:\Users\Kevin\AppData\Local\ElevatedDiagnostics
[2011/12/23 20:43:14 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Warcraft III
[2011/12/23 20:43:14 | 000,000,000 | —D | C] – C:\Program Files (x86)\Warcraft III
[2011/12/19 18:59:16 | 000,022,696 | —- | C] (COMODO) – C:\Windows\SysNative\drivers\cmderd.sys
[2011/12/19 18:58:58 | 000,041,200 | —- | C] (COMODO) – C:\Windows\SysNative\cmdcsr.dll
[2011/12/19 18:58:56 | 000,389,840 | —- | C] (COMODO) – C:\Windows\SysNative\guard64.dll
[2011/12/19 18:58:56 | 000,301,224 | —- | C] (COMODO) – C:\Windows\SysWow64\guard32.dll
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/01/17 21:15:22 | 000,000,896 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/01/17 21:15:00 | 000,000,892 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/01/17 21:11:12 | 000,000,210 | —- | M] () – C:\Users\Kevin\Desktop\Are you Infected Need Help.url
[2012/01/17 20:54:08 | 000,000,178 | —- | M] () – C:\Users\Kevin\Desktop\What the Tech Free Tech Support.url
[2012/01/17 20:41:12 | 000,017,168 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/01/17 20:41:12 | 000,017,168 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/01/17 20:39:09 | 000,726,444 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/01/17 20:39:09 | 000,624,162 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/01/17 20:39:09 | 000,106,538 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/01/17 20:34:04 | 000,000,408 | —- | M] () – C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2012/01/17 20:33:46 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/01/17 20:33:45 | 2413,993,984 | -HS- | M] () – C:\hiberfil.sys
[2012/01/17 12:19:42 | 001,796,618 | —- | M] () – C:\Windows\SysNative\drivers\Cat.DB
[2012/01/16 22:12:54 | 000,000,064 | —- | M] () – C:\Windows\SysWow64\rp_stats.dat
[2012/01/16 22:12:54 | 000,000,044 | —- | M] () – C:\Windows\SysWow64\rp_rules.dat
[2012/01/15 10:57:38 | 000,281,792 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2012/01/03 08:36:01 | 000,440,010 | R— | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2012/01/02 22:38:16 | 000,002,106 | —- | M] () – C:\Users\Public\Desktop\RollerCoaster Tycoon® 3.lnk
[2012/01/01 20:24:04 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\config.nt
[2011/12/24 11:25:00 | 000,001,931 | —- | M] () – C:\Users\Kevin\Desktop\Diablo II - Lord of Destruction.lnk
[2011/12/23 21:49:17 | 000,001,247 | —- | M] () – C:\Users\Public\Desktop\Warcraft III - The Frozen Throne.lnk
[2011/12/23 20:45:13 | 000,001,079 | —- | M] () – C:\Users\Kevin\Desktop\Warcraft III World Editor.lnk
[2011/12/23 20:43:39 | 000,001,049 | —- | M] () – C:\Users\Public\Desktop\Warcraft III.lnk
[2011/12/19 18:59:16 | 000,022,696 | —- | M] (COMODO) – C:\Windows\SysNative\drivers\cmderd.sys
[2011/12/19 18:58:58 | 000,041,200 | —- | M] (COMODO) – C:\Windows\SysNative\cmdcsr.dll
[2011/12/19 18:58:56 | 000,389,840 | —- | M] (COMODO) – C:\Windows\SysNative\guard64.dll
[2011/12/19 18:58:56 | 000,301,224 | —- | M] (COMODO) – C:\Windows\SysWow64\guard32.dll
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/01/17 21:11:12 | 000,000,210 | —- | C] () – C:\Users\Kevin\Desktop\Are you Infected Need Help.url
[2012/01/17 20:54:08 | 000,000,178 | —- | C] () – C:\Users\Kevin\Desktop\What the Tech Free Tech Support.url
[2012/01/17 12:19:14 | 001,796,618 | —- | C] () – C:\Windows\SysNative\drivers\Cat.DB
[2012/01/17 09:16:33 | 000,000,408 | —- | C] () – C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2012/01/02 22:38:16 | 000,002,106 | —- | C] () – C:\Users\Public\Desktop\RollerCoaster Tycoon® 3.lnk
[2012/01/02 22:37:35 | 000,197,120 | —- | C] () – C:\Windows\patchw32.dll
[2012/01/01 20:24:03 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\config.nt
[2011/12/23 20:44:52 | 000,001,247 | —- | C] () – C:\Users\Public\Desktop\Warcraft III - The Frozen Throne.lnk
[2011/12/23 20:43:14 | 000,001,079 | —- | C] () – C:\Users\Kevin\Desktop\Warcraft III World Editor.lnk
[2011/12/23 20:43:14 | 000,001,049 | —- | C] () – C:\Users\Public\Desktop\Warcraft III.lnk
[2011/12/03 17:24:47 | 000,000,000 | —- | C] () – C:\Users\Kevin\AppData\Local\{19223625-99C8-414E-9011-CA00236268E0}
[2011/10/25 21:21:48 | 000,056,832 | —- | C] () – C:\Windows\SysWow64\OpenVideo.dll
[2011/10/25 21:21:34 | 000,056,832 | —- | C] () – C:\Windows\SysWow64\OVDecoder.dll
[2011/10/25 18:38:38 | 000,204,952 | —- | C] () – C:\Windows\SysWow64\ativvsvl.dat
[2011/10/25 18:38:38 | 000,157,144 | —- | C] () – C:\Windows\SysWow64\ativvsva.dat
[2011/09/20 10:18:58 | 000,000,410 | —- | C] () – C:\Windows\BRWMARK.INI
[2011/09/20 10:18:58 | 000,000,034 | —- | C] () – C:\Windows\SysWow64\BD7030.DAT
[2011/09/12 15:06:16 | 000,003,917 | —- | C] () – C:\Windows\SysWow64\atipblag.dat
[2011/05/29 17:42:45 | 000,000,064 | —- | C] () – C:\Windows\SysWow64\rp_stats.dat
[2011/05/29 17:42:45 | 000,000,044 | —- | C] () – C:\Windows\SysWow64\rp_rules.dat
[2011/04/09 17:55:28 | 000,179,261 | —- | C] () – C:\Windows\SysWow64\xlive.dll.cat
[2011/03/02 22:10:55 | 000,021,840 | —- | C] () – C:\Windows\SysWow64\SIntfNT.dll
[2011/03/02 22:10:55 | 000,017,212 | —- | C] () – C:\Windows\SysWow64\SIntf32.dll
[2011/03/02 22:10:55 | 000,012,067 | —- | C] () – C:\Windows\SysWow64\SIntf16.dll
[2011/03/02 22:01:43 | 000,039,683 | —- | C] () – C:\Windows\DIIUnin.dat
[2011/02/09 08:22:17 | 000,000,295 | —- | C] () – C:\Windows\EReg072.dat
[2010/11/25 01:36:10 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2009/07/13 22:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/13 19:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 19:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2009/07/13 17:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 16:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 14:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 14:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat
[2005/01/17 06:10:16 | 000,045,056 | —- | C] () – C:\Windows\SysWow64\BRTCPCON.DLL
[2004/08/09 06:00:42 | 000,000,114 | —- | C] () – C:\Windows\SysWow64\BRLMW03A.INI

========== LOP Check ==========

[2011/12/31 22:38:16 | 000,000,000 | —D | M] – C:\Users\Kevin\AppData\Roaming\.minecraft
[2012/01/02 22:41:24 | 000,000,000 | —D | M] – C:\Users\Kevin\AppData\Roaming\Atari
[2012/01/17 21:14:39 | 000,000,000 | —D | M] – C:\Users\Kevin\AppData\Roaming\BitComet
[2012/01/14 01:14:32 | 000,000,000 | —D | M] – C:\Users\Kevin\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2012/01/17 20:32:53 | 000,000,000 | —D | M] – C:\Users\Kevin\AppData\Roaming\GetRightToGo
[2012/01/14 13:31:14 | 000,000,000 | —D | M] – C:\Users\Kevin\AppData\Roaming\gtk-2.0
[2012/01/02 22:37:51 | 000,000,000 | —D | M] – C:\Users\Kevin\AppData\Roaming\Leadertech
[2011/07/25 10:27:21 | 000,000,000 | —D | M] – C:\Users\Kevin\AppData\Roaming\LolClient
[2011/07/22 22:18:02 | 000,000,000 | —D | M] – C:\Users\Kevin\AppData\Roaming\Magic Set Editor
[2012/01/17 20:34:04 | 000,000,408 | —- | M] () – C:\Windows\Tasks\Ad-Aware Update (Weekly).job
[2011/12/28 21:01:34 | 000,032,562 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2012/01/17 20:33:44 | 000,035,420 | —- | M] () – C:\aaw7boot.log
[2010/11/22 04:02:06 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/11/22 03:57:43 | 000,000,211 | -H– | M] () – C:\Boot.BAK
[2010/11/25 03:24:15 | 000,000,355 | RHS- | M] () – C:\Boot.ini.saved
[2009/07/13 18:38:58 | 000,383,562 | RHS- | M] () – C:\bootmgr
[2010/11/25 03:24:16 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2010/11/22 04:02:06 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/12/23 23:06:38 | 000,203,836 | RHS- | M] () – C:\grldr
[2012/01/17 20:33:45 | 2413,993,984 | -HS- | M] () – C:\hiberfil.sys
[2010/11/22 04:02:06 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/11/22 04:02:06 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008/04/13 14:13:04 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/04/13 16:01:44 | 000,250,048 | RHS- | M] () – C:\ntldr
[2012/01/17 20:33:45 | 3218,661,376 | -HS- | M] () – C:\pagefile.sys
[2010/12/23 23:06:39 | 000,000,000 | RHS- | M] () – C:\winx.ld

< %systemroot%\Fonts\*.com >
[2009/07/13 22:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/13 22:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/13 22:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/13 22:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 13:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2011/11/28 11:01:25 | 000,041,184 | —- | M] (AVAST Software) – C:\Windows\avastSS.scr
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/13 21:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/11/25 01:34:20 | 000,000,221 | -HS- | M] () – C:\Users\Kevin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/09/15 20:31:38 | 000,270,142 | —- | M] () – C:\Users\Kevin\Desktop\Minecraft - Digdug22.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

========== Alternate Data Streams ==========

@Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:DFC5A2B2

< End of report >
OTL Extras logfile created on: 1/17/2012 9:15:08 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Kevin\Desktop\Movies
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.06 Gb Available Physical Memory | 68.81% Memory free
5.99 Gb Paging File | 4.61 Gb Available in Paging File | 76.89% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 465.75 Gb Total Space | 325.00 Gb Free Space | 69.78% Space Free | Partition Type: NTFS
Drive D: | 466.99 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: KEVIN-PC | User Name: Kevin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htafile [open] – "%1" %*
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1"
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1"
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htafile [open] – "%1" %*
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1"
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1"
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{015C5B35-B678-451C-9AEE-821E8D69621C}_is1" = PeerBlock 1.1 (r518)
"{4BE9F0B8-FF3D-5CAA-9BF2-CB6F3DF75D3B}" = ccc-utility64
"{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime
"{52FB2985-F3AD-DAA7-7645-4E38A5B96E17}" = AMD Catalyst Install Manager
"{67303AC9-A9BA-E413-0001-AAC1C812947C}" = AMD Fuel
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{9B48B0AC-C813-4174-9042-476A887592C7}" = Windows Live ID Sign-in Assistant
"{B69A7CBA-9139-7ACB-7564-4CD5D8C36E26}" = AMD Drag and Drop Transcoding
"{D6AB1F5B-FED6-49A9-9747-327BD28FB3C7}" = COMODO Internet Security
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{FA54C4B1-98E3-AEFA-7254-C4038DC739AF}" = AMD Media Foundation Decoders
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX 64-bit
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{19A492A0-888F-44A0-9B21-D91700763F62}" = Catalyst Control Center - Branding
"{1BF82343-8EE6-8B76-90CF-31059B9D1842}" = CCC Help English
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{26A24AE4-039D-4CA4-87B4-2F83216022FF}" = Java™ 6 Update 29
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CB0307C-565E-4441-86BE-0DF2E4FB828C}" = Microsoft Games for Windows Marketplace
"{70C3CC75-9E14-D215-8FAD-5ABEAE3125D9}" = AMD VISION Engine Control Center
"{79F86C69-2B17-4368-9234-472A23639E16}" = Ad-Aware
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{907B4640-266B-4A21-92FB-CD1A86CD0F63}" = RollerCoaster Tycoon® 3
"{92606477-9366-4D3B-8AE3-6BE4B29727AB}" = League of Legends
"{974C4B12-4D02-4879-85E0-61C95CC63E9E}" = Fallout 3
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Click to Call with Skype
"{E9A1960E-7756-2299-C700-DC7CA6EDD6E4}" = Catalyst Control Center InstallProxy
"{E9D98510-A8B6-E39C-B8BA-BA9A511E040C}" = Catalyst Control Center Graphics Previews Common
"{F2508213-9989-4E85-A078-72BE483917EF}" = Microsoft Games for Windows - LIVE Redistributable
"{FE23D063-934D-4829-A0D8-00634CE79B4A}" = Adobe AIR
"Adobe AIR" = Adobe AIR
"avast" = avast! Free Antivirus
"BitComet" = BitComet 1.25
"Diablo II" = Diablo II
"Google Chrome Frame" = Google Chrome Frame
"Magic Set Editor 2_is1" = Magic Set Editor 2.0.0
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.60.0.1800
"ST6UNST #1" = Hero Editor V1.04
"StarCraft II" = StarCraft II
"Steam App 10" = Counter-Strike
"Steam App 30" = Day of Defeat
"Warcraft III" = Warcraft III
"WinGimp-2.0_is1" = GIMP 2.6.11
"WinRAR archiver" = WinRAR 4.01 (32-bit)
"World of Warcraft" = World of Warcraft

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 1/11/2012 2:16:47 PM | Computer Name = Kevin-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\program files (x86)\spybot
- search & destroy\DelZip179.dll".Error in manifest or policy file "c:\program
files (x86)\spybot - search & destroy\DelZip179.dll" on line 8. The value "*" of
attribute "language" in element "assemblyIdentity" is invalid.

Error - 1/12/2012 1:33:37 PM | Computer Name = Kevin-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\program files (x86)\spybot
- search & destroy\DelZip179.dll".Error in manifest or policy file "c:\program
files (x86)\spybot - search & destroy\DelZip179.dll" on line 8. The value "*" of
attribute "language" in element "assemblyIdentity" is invalid.

Error - 1/13/2012 2:03:09 PM | Computer Name = Kevin-PC | Source = Application Error | ID = 1000
Description = Faulting application name: iexplore.exe, version: 8.0.7600.16912,
time stamp: 0x4eb4a5ea Faulting module name: Flash11e.ocx, version: 11.1.102.55,
time stamp: 0x4eaf89fc Exception code: 0xc0000005 Fault offset: 0x00001959 Faulting
process id: 0x1304 Faulting application start time: 0x01ccd215ca87ab76 Faulting application
path: C:\Program Files (x86)\Internet Explorer\iexplore.exe Faulting module path:
C:\Windows\SysWOW64\Macromed\Flash\Flash11e.ocx Report Id: d9743fda-3e10-11e1-a224-6cf049db36d2

Error - 1/13/2012 2:29:59 PM | Computer Name = Kevin-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\program files (x86)\spybot
- search & destroy\DelZip179.dll".Error in manifest or policy file "c:\program
files (x86)\spybot - search & destroy\DelZip179.dll" on line 8. The value "*" of
attribute "language" in element "assemblyIdentity" is invalid.

Error - 1/14/2012 7:17:14 AM | Computer Name = Kevin-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\program files (x86)\spybot
- search & destroy\DelZip179.dll".Error in manifest or policy file "c:\program
files (x86)\spybot - search & destroy\DelZip179.dll" on line 8. The value "*" of
attribute "language" in element "assemblyIdentity" is invalid.

Error - 1/15/2012 1:58:25 PM | Computer Name = Kevin-PC | Source = pctsSvc.exe | ID = 0
Description =

Error - 1/16/2012 9:34:59 PM | Computer Name = Kevin-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\program files (x86)\spybot
- search & destroy\DelZip179.dll".Error in manifest or policy file "c:\program
files (x86)\spybot - search & destroy\DelZip179.dll" on line 8. The value "*" of
attribute "language" in element "assemblyIdentity" is invalid.

Error - 1/17/2012 12:46:36 AM | Computer Name = Kevin-PC | Source = Application Error | ID = 1000
Description = Faulting application name: RCT3.exe, version: 3.0.12.38, time stamp:
0x00000000 Faulting module name: RCT3.exe, version: 3.0.12.38, time stamp: 0x00000000
Exception
code: 0xc0000005 Fault offset: 0x001fd077 Faulting process id: 0xbd8 Faulting application
start time: 0x01ccd4cfc2a8081d Faulting application path: C:\Program Files (x86)\Atari\RollerCoaster
Tycoon® 3\RCT3.exe Faulting module path: C:\Program Files (x86)\Atari\RollerCoaster
Tycoon® 3\RCT3.exe Report Id: 3c53de8f-40c6-11e1-a80c-6cf049db36d2

Error - 1/17/2012 12:46:34 PM | Computer Name = Kevin-PC | Source = BugSplat | ID = 1
Description =

Error - 1/17/2012 12:51:23 PM | Computer Name = Kevin-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\program files (x86)\spybot
- search & destroy\DelZip179.dll".Error in manifest or policy file "c:\program
files (x86)\spybot - search & destroy\DelZip179.dll" on line 8. The value "*" of
attribute "language" in element "assemblyIdentity" is invalid.

[ System Events ]
Error - 1/17/2012 11:23:39 PM | Computer Name = Kevin-PC | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
service which failed to start because of the following error: %%1068

Error - 1/17/2012 11:23:39 PM | Computer Name = Kevin-PC | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
service which failed to start because of the following error: %%1068

Error - 1/17/2012 11:23:40 PM | Computer Name = Kevin-PC | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
service which failed to start because of the following error: %%1068

Error - 1/17/2012 11:23:40 PM | Computer Name = Kevin-PC | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
service which failed to start because of the following error: %%1068

Error - 1/17/2012 11:23:40 PM | Computer Name = Kevin-PC | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
service which failed to start because of the following error: %%1068

Error - 1/17/2012 11:23:40 PM | Computer Name = Kevin-PC | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
service which failed to start because of the following error: %%1068

Error - 1/17/2012 11:23:40 PM | Computer Name = Kevin-PC | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
service which failed to start because of the following error: %%1068

Error - 1/17/2012 11:23:40 PM | Computer Name = Kevin-PC | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
service which failed to start because of the following error: %%1068

Error - 1/17/2012 11:25:41 PM | Computer Name = Kevin-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
TfFsMon TfSysMon

Error - 1/17/2012 11:34:05 PM | Computer Name = Kevin-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
TfFsMon TfSysMon


< End of report >
Hi Kevin2244,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Let's give this a try:

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://forums.whatthetech.com/How_Disable_…ams_t96260.html

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Hello Tomk thankyou very much for your guidance in this process, greatly appreciate what your doing for me thankyou. I ran combofix and heres what it showed: ComboFix 12-01-21.02 - Kevin 01/22/2012 2:30.1.2 - x64 Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.3070.1915 [GMT -7:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: Lavasoft Ad-Watch Live! Anti-Virus *Enabled/Updated* {9FF26384-70D4-CE6B-3ECB-E759A6A40116} SP: Lavasoft Ad-Watch Live! *Enabled/Updated* {24938260-56EE-C1E5-047B-DC2BDD234BAB} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\windows\ST6UNST.000 c:\windows\SysWow64\ijl11.dll . . ((((((((((((((((((((((((( Files Created from 2011-12-22 to 2012-01-22 ))))))))))))))))))))))))))))))) . . 2012-01-22 09:35 . 2012-01-22 09:35 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-01-20 15:55 . 2012-01-06 05:15 8602168 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{97087B4E-3886-4193-97A3-FE2F6C52CDD0}\mpengine.dll 2012-01-18 03:25 . 2012-01-18 03:25 ——– d—–w- c:\users\Kevin\AppData\Local\AMD 2012-01-15 17:43 . 2012-01-18 03:31 ——– d—–w- c:\programdata\PC Tools 2012-01-15 17:42 . 2012-01-18 03:32 ——– d—–w- c:\users\Kevin\AppData\Roaming\GetRightToGo 2012-01-14 08:14 . 2012-01-14 08:14 ——– d—–w- c:\users\Kevin\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant 2012-01-14 08:14 . 2012-01-14 08:14 ——– d—–w- c:\program files (x86)\Common Files\Adobe AIR 2012-01-14 06:15 . 2012-01-20 20:48 ——– d—–w- c:\users\Kevin\AppData\Roaming\gtk-2.0 2012-01-14 06:14 . 2012-01-14 06:14 ——– d—–w- c:\users\Kevin\.thumbnails 2012-01-14 06:13 . 2012-01-21 21:02 ——– d—–w- c:\users\Kevin\.gimp-2.6 2012-01-14 06:13 . 2012-01-14 06:13 ——– d—–w- c:\program files (x86)\GIMP-2.0 2012-01-11 02:36 . 2011-10-26 04:28 1328640 —-a-w- c:\windows\SysWow64\quartz.dll 2012-01-11 02:36 . 2011-10-26 05:22 1572864 —-a-w- c:\windows\system32\quartz.dll 2012-01-11 02:36 . 2011-10-26 05:22 366592 —-a-w- c:\windows\system32\qdvd.dll 2012-01-11 02:36 . 2011-10-26 04:28 514560 —-a-w- c:\windows\SysWow64\qdvd.dll 2012-01-11 02:36 . 2011-11-17 07:14 1739160 —-a-w- c:\windows\system32\ntdll.dll 2012-01-11 02:36 . 2011-11-17 05:41 1292592 —-a-w- c:\windows\SysWow64\ntdll.dll 2012-01-11 02:36 . 2011-11-19 15:07 77312 —-a-w- c:\windows\system32\packager.dll 2012-01-11 02:36 . 2011-11-19 14:06 67072 —-a-w- c:\windows\SysWow64\packager.dll 2012-01-05 21:06 . 2012-01-05 21:06 ——– d—–w- c:\users\Kevin\AppData\Roaming\vlc 2012-01-03 05:41 . 2012-01-03 05:41 ——– d—–w- c:\users\Kevin\AppData\Roaming\Atari 2012-01-03 05:37 . 2012-01-03 05:37 ——– d—–w- c:\users\Kevin\AppData\Roaming\Leadertech 2012-01-03 05:37 . 2012-01-03 05:37 ——– d—–w- c:\program files (x86)\Common Files\PocketSoft 2012-01-03 05:37 . 2002-02-28 01:50 197120 —-a-w- c:\windows\patchw32.dll 2012-01-03 05:33 . 2012-01-03 05:33 ——– d—–w- c:\program files (x86)\Atari 2012-01-03 05:32 . 2002-12-05 21:10 155648 —-a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iuser.dll 2012-01-03 05:32 . 2002-12-02 22:22 5632 —-a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0701\Intel32\DotNetInstaller.exe 2012-01-03 05:32 . 2002-12-02 20:33 57344 —-a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0701\Intel32\ctor.dll 2012-01-03 05:32 . 2002-12-02 20:33 237568 —-a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iscript.dll 2012-01-03 05:32 . 2012-01-03 05:32 163972 —-a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iGdi.dll 2012-01-03 05:32 . 2002-12-05 21:12 692224 —-a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iKernel.dll 2012-01-03 05:32 . 2012-01-03 05:32 282756 —-a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0701\Intel32\setup.dll 2012-01-03 05:09 . 2012-01-07 06:28 ——– d—–w- C:\sh4ldr 2012-01-03 05:09 . 2012-01-03 05:09 ——– d—–w- c:\program files\Enigma Software Group 2012-01-03 05:08 . 2012-01-07 06:27 ——– d—–w- c:\windows\89A072791DB3485AB1DF584DF86774B9.TMP 2012-01-03 05:08 . 2012-01-03 05:08 ——– d—–w- c:\program files (x86)\Common Files\Wise Installation Wizard 2012-01-02 03:24 . 2011-11-28 18:01 256960 —-a-w- c:\windows\system32\aswBoot.exe 2012-01-02 03:22 . 2012-01-22 09:01 ——– d—–w- c:\programdata\AVAST Software 2012-01-01 09:59 . 2012-01-01 09:59 ——– d—–w- c:\users\Kevin\AppData\Roaming\SUPERAntiSpyware.com 2012-01-01 09:45 . 2012-01-01 09:45 ——– d—–w- c:\users\Kevin\AppData\Roaming\Malwarebytes 2012-01-01 09:45 . 2012-01-01 09:45 ——– d—–w- c:\program files (x86)\Malwarebytes' Anti-Malware 2012-01-01 09:45 . 2012-01-01 09:45 ——– d—–w- c:\programdata\Malwarebytes 2012-01-01 09:45 . 2011-12-10 22:24 23152 —-a-w- c:\windows\system32\drivers\mbam.sys 2012-01-01 05:09 . 2012-01-08 04:34 ——– d—–w- c:\program files\SUPERAntiSpyware 2011-12-25 15:09 . 2011-12-25 15:09 ——– d—–w- c:\users\Kevin\AppData\Local\ElevatedDiagnostics 2011-12-24 03:43 . 2011-12-24 03:45 ——– d—–w- c:\program files (x86)\Warcraft III . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-11-24 05:00 . 2011-12-15 14:17 3141632 —-a-w- c:\windows\system32\win32k.sys 2011-11-16 03:33 . 2011-06-12 16:22 414368 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2011-11-15 21:29 . 2010-11-25 08:54 270720 ——w- c:\windows\system32\MpSigStub.exe 2011-11-05 05:26 . 2011-12-15 14:17 1197568 —-a-w- c:\windows\system32\wininet.dll 2011-11-05 05:23 . 2011-12-15 14:17 57856 —-a-w- c:\windows\system32\licmgr10.dll 2011-11-05 05:17 . 2011-12-15 14:17 2048 —-a-w- c:\windows\system32\tzres.dll 2011-11-05 04:35 . 2011-12-15 14:17 981504 —-a-w- c:\windows\SysWow64\wininet.dll 2011-11-05 04:34 . 2011-12-15 14:17 44544 —-a-w- c:\windows\SysWow64\licmgr10.dll 2011-11-05 04:30 . 2011-12-15 14:17 2048 —-a-w- c:\windows\SysWow64\tzres.dll 2011-11-05 04:07 . 2011-12-15 14:17 482816 —-a-w- c:\windows\system32\html.iec 2011-11-05 03:28 . 2011-12-15 14:17 386048 —-a-w- c:\windows\SysWow64\html.iec 2011-11-05 03:25 . 2011-12-15 14:17 1638912 —-a-w- c:\windows\system32\mshtml.tlb 2011-11-05 02:55 . 2011-12-15 14:17 1638912 —-a-w- c:\windows\SysWow64\mshtml.tlb 2011-10-26 05:19 . 2011-12-15 14:18 43520 —-a-w- c:\windows\system32\csrsrv.dll 2011-10-26 04:21 . 2011-10-26 04:21 66560 —-a-w- c:\windows\system32\OpenVideo64.dll 2011-10-26 04:21 . 2011-10-26 04:21 56832 —-a-w- c:\windows\SysWow64\OpenVideo.dll 2011-10-26 04:21 . 2011-10-26 04:21 66560 —-a-w- c:\windows\system32\OVDecoder64.dll 2011-10-26 04:21 . 2011-10-26 04:21 56832 —-a-w- c:\windows\SysWow64\OVDecoder.dll 2011-10-26 04:21 . 2011-10-26 04:21 16991744 —-a-w- c:\windows\system32\amdocl64.dll 2011-10-26 04:20 . 2011-10-26 04:20 13950464 —-a-w- c:\windows\SysWow64\amdocl.dll 2011-10-26 04:19 . 2011-10-26 04:19 51200 —-a-w- c:\windows\system32\OpenCL.dll 2011-10-26 04:19 . 2011-10-26 04:19 44032 —-a-w- c:\windows\SysWow64\OpenCL.dll 2011-10-26 03:05 . 2011-10-26 03:05 10496512 —-a-w- c:\windows\system32\drivers\atikmdag.sys 2011-10-26 02:16 . 2011-10-26 02:16 24866816 —-a-w- c:\windows\system32\atio6axx.dll 2011-10-26 02:06 . 2011-10-26 02:06 159744 —-a-w- c:\windows\system32\atiapfxx.exe 2011-10-26 02:05 . 2010-10-27 10:55 748544 —-a-w- c:\windows\SysWow64\aticfx32.dll 2011-10-26 02:04 . 2010-10-27 10:54 892416 —-a-w- c:\windows\system32\aticfx64.dll 2011-10-26 02:01 . 2011-10-26 02:01 466944 —-a-w- c:\windows\system32\ATIDEMGX.dll 2011-10-26 02:01 . 2011-10-26 02:01 517120 —-a-w- c:\windows\system32\atieclxx.exe 2011-10-26 02:00 . 2011-10-26 02:00 204288 —-a-w- c:\windows\system32\atiesrxx.exe 2011-10-26 01:59 . 2011-10-26 01:59 18757120 —-a-w- c:\windows\SysWow64\atioglxx.dll 2011-10-26 01:59 . 2011-10-26 01:59 120320 —-a-w- c:\windows\system32\atitmm64.dll 2011-10-26 01:59 . 2011-10-26 01:59 423424 —-a-w- c:\windows\system32\atipdl64.dll 2011-10-26 01:59 . 2011-10-26 01:59 356352 —-a-w- c:\windows\SysWow64\atipdlxx.dll 2011-10-26 01:59 . 2011-10-26 01:59 278528 —-a-w- c:\windows\SysWow64\Oemdspif.dll 2011-10-26 01:58 . 2011-10-26 01:58 21504 —-a-w- c:\windows\system32\atimuixx.dll 2011-10-26 01:58 . 2011-10-26 01:58 59392 —-a-w- c:\windows\system32\atiedu64.dll 2011-10-26 01:58 . 2011-10-26 01:58 43520 —-a-w- c:\windows\SysWow64\ati2edxx.dll 2011-10-26 01:55 . 2011-10-26 01:55 4292096 —-a-w- c:\windows\SysWow64\atidxx32.dll 2011-10-26 01:46 . 2010-10-27 10:38 5041664 —-a-w- c:\windows\system32\atidxx64.dll 2011-10-26 01:43 . 2011-10-26 01:43 1113088 —-a-w- c:\windows\system32\atiumd6v.dll 2011-10-26 01:43 . 2011-10-26 01:43 1828864 —-a-w- c:\windows\SysWow64\atiumdmv.dll 2011-10-26 01:43 . 2011-10-26 01:43 4044288 —-a-w- c:\windows\system32\atiumd6a.dll 2011-10-26 01:38 . 2011-10-26 01:38 51200 —-a-w- c:\windows\system32\aticalrt64.dll 2011-10-26 01:38 . 2011-10-26 01:38 46080 —-a-w- c:\windows\SysWow64\aticalrt.dll 2011-10-26 01:38 . 2011-10-26 01:38 44544 —-a-w- c:\windows\system32\aticalcl64.dll 2011-10-26 01:38 . 2011-10-26 01:38 44032 —-a-w- c:\windows\SysWow64\aticalcl.dll 2011-10-26 01:38 . 2011-10-26 01:38 9978880 —-a-w- c:\windows\system32\aticaldd64.dll 2011-10-26 01:35 . 2010-10-27 10:28 4353536 —-a-w- c:\windows\SysWow64\atiumdag.dll 2011-10-26 01:34 . 2011-10-26 01:34 8449024 —-a-w- c:\windows\SysWow64\aticaldd.dll 2011-10-26 01:32 . 2010-10-27 09:50 4189184 —-a-w- c:\windows\SysWow64\atiumdva.dll 2011-10-26 01:29 . 2011-10-26 01:29 5510144 —-a-w- c:\windows\system32\atiumd64.dll 2011-10-26 01:29 . 2010-10-27 10:15 58880 —-a-w- c:\windows\system32\coinst.dll 2011-10-26 01:22 . 2011-10-26 01:22 486912 —-a-w- c:\windows\system32\atiadlxx.dll 2011-10-26 01:22 . 2011-10-26 01:22 339968 —-a-w- c:\windows\SysWow64\atiadlxy.dll 2011-10-26 01:22 . 2011-10-26 01:22 17408 —-a-w- c:\windows\system32\atig6pxx.dll 2011-10-26 01:22 . 2011-10-26 01:22 14336 —-a-w- c:\windows\SysWow64\atiglpxx.dll 2011-10-26 01:22 . 2011-10-26 01:22 14336 —-a-w- c:\windows\system32\atiglpxx.dll 2011-10-26 01:22 . 2011-10-26 01:22 39936 —-a-w- c:\windows\system32\atig6txx.dll 2011-10-26 01:22 . 2011-10-26 01:22 32768 —-a-w- c:\windows\SysWow64\atigktxx.dll 2011-10-26 01:21 . 2011-10-26 01:21 326656 —-a-w- c:\windows\system32\drivers\atikmpag.sys 2011-10-26 01:21 . 2010-10-27 10:13 40960 —-a-w- c:\windows\system32\atiuxp64.dll 2011-10-26 01:21 . 2011-10-26 01:21 31744 —-a-w- c:\windows\SysWow64\atiuxpag.dll 2011-10-26 01:21 . 2010-10-27 10:13 38912 —-a-w- c:\windows\system32\atiu9p64.dll 2011-10-26 01:20 . 2010-10-27 10:13 29184 —-a-w- c:\windows\SysWow64\atiu9pag.dll 2011-10-26 01:20 . 2011-10-26 01:20 53248 —-a-w- c:\windows\system32\drivers\ati2erec.dll 2011-10-26 01:16 . 2011-10-26 01:16 54784 —-a-w- c:\windows\system32\atimpc64.dll 2011-10-26 01:16 . 2011-10-26 01:16 54784 —-a-w- c:\windows\system32\amdpcom64.dll 2011-10-26 01:15 . 2011-10-26 01:15 53760 —-a-w- c:\windows\SysWow64\atimpc32.dll 2011-10-26 01:15 . 2011-10-26 01:15 53760 —-a-w- c:\windows\SysWow64\amdpcom32.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Pando Media Booster"="c:\program files (x86)\Pando Networks\Media Booster\PMB.exe" [2011-07-25 3077528] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-10-26 343168] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service] @="Service" . R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [x] R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [x] R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-11-25 136176] R3 esgiguard;esgiguard;c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys [x] R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-11-25 136176] R3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [x] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x] S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2011-10-26 361984] S2 AODDriver4.01;AODDriver4.01;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [2011-06-24 55424] S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files (x86)\Lavasoft\Ad-Aware\AAWService.exe [2011-09-02 2152152] S3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys [x] S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x] S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x] S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x] . . Contents of the 'Scheduled Tasks' folder . 2012-01-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-11-25 08:40] . 2012-01-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-11-25 08:40] . . ——— x86-64 ———– . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x1 . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.google.com/ mLocal Page = c:\windows\SysWOW64\blank.htm IE: &D&ownload &with BitComet - c:\program files (x86)\BitComet\BitComet.exe/AddLink.htm IE: &D&ownload all with BitComet - c:\program files (x86)\BitComet\BitComet.exe/AddAllLink.htm TCP: DhcpNameServer = [removed] [removed] [removed] . - - - - ORPHANS REMOVED - - - - . BHO-{EA5CA8B6-9B9C-4994-A7A1-947B6C631BE7} - c:\program files (x86)\RegTweaker\key.dll . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11e_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11e_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2012-01-22 02:39:40 - machine was rebooted ComboFix-quarantined-files.txt 2012-01-22 09:39 . Pre-Run: 349,401,645,056 bytes free Post-Run: 349,186,535,424 bytes free . - - End Of File - - D53BD7A408F362505EB9F2D0950834A1
Let's see what an online scan can find:

ESET Online Scanner:

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Vista users: You will need to to right-click on the either the IE or FF icon in the Start Menu or Quick Launch Bar on the Taskbar and select Run as Administrator from the context menu.

  • Please go here then click on: [external image: Posted Image]

    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.

  • Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: [external image: Posted Image]
  • The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on: [external image: Posted Image]
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.

Note: Do not forget to re-enable your Anti-Virus application after running the above scan!
I did the Eset online scanner and it came back nothing found out of 180 000 files scanned, here is the log file from eset online scanner folder: ESETSmartInstaller@High as CAB hook log: OnlineScanner64.ocx - registred OK OnlineScanner.ocx - registred OK
I havnt opened multiple tabs in Internet explorer yet to test if it freezes but I have noticed everything seems to run as good as befor. My concern is the quarantined Trojan in adaware still appears in quarantine. I would like to use the Internet for an hour and see if i get flooded with those spyware cookies again from just visiting YouTube and deviant art. I have noticed for awhile even befor this trojan that when i shutdown the comp it shows a force task shutdown screen for a brief second then dissapears, wondering if thats a problem or something i can live with? Do you have any recommendations to block spyware cookies instead of just deleting them? Thankyou for all your help I will test my comp tonight and see how it's performing then give my final verdict. Thanks again
Just got home, befor doing anything else i ran smart scan from adaware to see if any cookies and it showed i had Trojan Generic. I havnt visited any adult sites since recieving the initial trojan and i havnt been to any other website other then deviant art and youtube which is why im thinking the pornpopup trojan in quarantine has made me suceptible to more trojans even though its quarantined. I removed it using adaware but im scared as to how another trojan got on when i havnt visited any sites or downloaded anything since this process. After everything you had me do i had disabled all my internet securities and then after the scans put them back into use, maybe it somehow got in through an open window while i was doing that?
Ad-aware removed the Generic Trojan and now the js pornpopup trojan out of quarantine yesterday and today i ran malwarebytes and it came back clean. The problem is how in 1 day does a trojan get on when all ive done is go youtube and deviant art and never downloaded anything? My computer must be open to attacks even though i have adaware and internet security on and im not going anyplace unsafe. Malwarebytes Anti-Malware 1.60.0.1800 www.malwarebytes.org Database version: v2012.01.25.06 Windows 7 x64 NTFS Internet Explorer 8.0.7600.16385 Kevin :: KEVIN-PC [administrator] 1/25/2012 5:44:02 PM mbam-log-2012-01-25 (17-44-02).txt Scan type: Full scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 340628 Time elapsed: 36 minute(s), 32 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end)
Internet explorer seems to take 20+ seconds to load my homescreen and sometimes the tabs take that long as well. sometimes i get a flash of a white box over images when scrolling down on a screen. Inbetween combofix and that new generic trojan that appeared for no reason was when my computer worked perfectly.
It never clearly shows the entire file name just the beginning and so I got adaware to delete it. The name said generic Trojan, I've only opened emails that I knew were safe so I don't know how it got on. Not sure if it was in java. How would I get it to show the entire path next time? It only ever shows the beginning and end of the path never the middle.
Can you quarantine the file? Then look in the quarantine and see what the file is called. As far as changes after you ran ComboFix…. Did you play Diablo after running CF and prior to the trojan being flagged?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI