This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Google Redirect [Solved]

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Greetings,

I'm getting a problem with Google redirects. Every time I open up Chrome it redirects to the searchnu.com/406 page. While searching through the forums I downloaded some of the tools needed and compiled logs. I used OTL and aswMBR. I'll first post the logs for OTL since that was on the pinned topics.

OTL Log


OTL logfile created on: 4/4/2012 3:44:30 PM - Run 1
OTL by OldTimer - Version 3.2.39.2 Folder = C:UsersVolkanDownloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.86 Gb Total Physical Memory | 1.68 Gb Available Physical Memory | 43.57% Memory free
7.73 Gb Paging File | 5.43 Gb Available in Paging File | 70.32% Paging File free
Paging file location(s): ?:pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:Windows | %ProgramFiles% = C:Program Files (x86)
Drive C: | 446.23 Gb Total Space | 9.22 Gb Free Space | 2.07% Space Free | Partition Type: NTFS
Drive E: | 92.84 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: VOLKAN-PC | User Name: Volkan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:UsersVolkanDownloadsOTL.exe (OldTimer Tools)
PRC - C:UsersVolkanDownloadsaswMBR.exe (AVAST Software)
PRC - C:Program Files (x86)Common FilesAVG Secure SearchvToolbarUpdater10.2.0ToolbarUpdater.exe ()
PRC - C:Program Files (x86)AVG Secure Searchvprot.exe ()
PRC - C:Program Files (x86)Searchqu ToolbarDatamngrdatamngrUI.exe (Bandoo Media, inc)
PRC - C:UsersVolkanAppDataRoamingDropboxbinDropbox.exe (Dropbox, Inc.)
PRC - C:Program Files (x86)AVGAVG2012avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:Program Files (x86)AVGAVG2012avgfws.exe (AVG Technologies CZ, s.r.o.)
PRC - C:Program Files (x86)AVGAVG2012AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:Program Files (x86)SteamSteam.exe (Valve Corporation)
PRC - C:Program Files (x86)AVGAVG2012avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:Program Files (x86)DAEMON Tools LiteDTLite.exe (DT Soft Ltd)
PRC - C:Program Files (x86)DAEMON Tools LiteDTShellHlp.exe (DT Soft Ltd)
PRC - C:Program Files (x86)AVGAVG PC Tuneup 2011BoostSpeed.exe (AVG)
PRC - C:Program Files (x86)Winampwinampa.exe (Nullsoft, Inc.)
PRC - C:Program Files (x86)ASUSWireless Console 3wcourier.exe ()
PRC - C:Program Files (x86)ASUSATK HotkeyHControl.exe (ASUS)
PRC - C:Program Files (x86)ASUSATKOSD2ATKOSD2.exe (ASUS)
PRC - C:Program Files (x86)IntelIntel® Management Engine ComponentsUNSUNS.exe (Intel Corporation)
PRC - C:Program Files (x86)IntelIntel® Management Engine ComponentsLMSLMS.exe (Intel Corporation)
PRC - C:Program Files (x86)ASUSControlDeckControlDeckStartUp.exe ()
PRC - C:Program Files (x86)ASUSATK MediaDMedia.exe (ASUS)
PRC - C:Program Files (x86)ASUSASUS Data Security ManagerADSMTray.exe (ASUSTek Computer Inc.)
PRC - C:Program Files (x86)ASUSATK HotkeyHControlUser.exe (ASUS)
PRC - C:Program Files (x86)ASUSATK HotkeyATKOSD.exe (ASUS)
PRC - C:Program Files (x86)ASUSATK HotkeyAsLdrSrv.exe (ASUS)
PRC - C:Program Files (x86)ASUSSmartLogonsensorsrv.exe (ASUS)
PRC - C:Program Files (x86)Common FilesAdobeUpdater6Adobe_Updater.exe (Adobe Systems Incorporated)
PRC - C:Program Files (x86)CreativeSB AudigyVolume PanelVolPanlu.exe (Creative Technology Ltd)
PRC - C:Program Files (x86)ASUSATK HotkeyWDC.exe (ASUS)
PRC - C:Program Files (x86)Yahoo!SoftwareUpdateYahooAUService.exe (Yahoo! Inc.)
PRC - C:Program Files (x86)CreativeMediaSource5MtdAcqu.exe (Creative Technology Ltd)
PRC - C:Program Files (x86)ASUSATK HotkeyKBFiltr.exe (ASUS)
PRC - C:Program Files (x86)ASUSASUS Data Security ManagerADSMSrv.exe (ASUSTek Computer Inc.)
PRC - C:Program Files (x86)ASUSASUS Live UpdateALU.exe ()
PRC - C:Program FilesATKGFNEXGFNEXSrv.exe ()


========== Modules (No Company Name) ==========

MOD - C:UsersVolkanAppDataLocalGoogleChromeApplication18.0.1025.142ppgooglena
clpluginchrome.dll ()
MOD - C:UsersVolkanAppDataLocalGoogleChromeApplication18.0.1025.142pdf.dll ()
MOD - C:UsersVolkanAppDataLocalGoogleChromeApplication18.0.1025.142avutil-51.dll ()
MOD - C:UsersVolkanAppDataLocalGoogleChromeApplication18.0.1025.142avformat-53.dll ()
MOD - C:UsersVolkanAppDataLocalGoogleChromeApplication18.0.1025.142avcodec-53.dll ()
MOD - C:UsersVolkanAppDataLocalGoogleChromeApplication18.0.1025.142gcswf32.dl
l ()
MOD - C:Program Files (x86)Steambinlibcef.dll ()
MOD - C:Program Files (x86)Steambinavcodec-53.dll ()
MOD - C:Program Files (x86)Steambinchromehtml.dll ()
MOD - C:Program Files (x86)Steambinavformat-53.dll ()
MOD - C:Program Files (x86)Steambinavutil-51.dll ()
MOD - C:Program Files (x86)AVG Secure Searchvprot.exe ()
MOD - C:Program Files (x86)Common FilesAppleApple Application Supportzlib1.dll ()
MOD - C:Program Files (x86)Common FilesAppleApple Application Supportlibxml2.dll ()
MOD - C:Program Files (x86)AVGAVG PC Tuneup 2011madExcept_.bpl ()
MOD - C:Program Files (x86)AVGAVG PC Tuneup 2011madBasic_.bpl ()
MOD - C:Program Files (x86)AVGAVG PC Tuneup 2011madDisAsm_.bpl ()
MOD - C:Program Files (x86)Yahoo!Messengeryui.dll ()
MOD - C:Program Files (x86)ASUSWireless Console 3wcourier.exe ()
MOD - C:Program Files (x86)ASUSControlDeckControlDeckStartUp.exe ()
MOD - C:WindowsSysWOW64msjetoledb40.dll ()
MOD - C:WindowsSysWOW64APOMngr.DLL ()
MOD - C:WindowsSysWOW64CmdRtr.DLL ()
MOD - C:Program Files (x86)ASUSASUS Live UpdateALU.exe ()
MOD - C:Program Files (x86)ASUSASUS Data Security ManagerShlExtx86OverlayIconShlExt.dll ()
MOD - C:Program Files (x86)ASUSASUS Data Security ManagerShlExtx86OverlayIconShlExt1.dll ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (AFBAgent) – C:WindowsSysNativeFBAgent.exe (ASUSTeK Computer Inc.)
SRV:64bit: - (WinDefend) – C:Program FilesWindows DefenderMpSvc.dll (Microsoft Corporation)
SRV:64bit: - (ATKGFNEXSrv) – C:Program FilesATKGFNEXGFNEXSrv.exe ()
SRV - (vToolbarUpdater10.2.0) – C:Program Files (x86)Common FilesAVG Secure SearchvToolbarUpdater10.2.0ToolbarUpdater.exe ()
SRV - (avgfws) – C:Program Files (x86)AVGAVG2012avgfws.exe (AVG Technologies CZ, s.r.o.)
SRV - (AVGIDSAgent) – C:Program Files (x86)AVGAVG2012AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (Steam Client Service) – C:Program Files (x86)Common FilesSteamSteamService.exe (Valve Corporation)
SRV - (avgwd) – C:Program Files (x86)AVGAVG2012avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (clr_optimization_v4.0.30319_32) – C:WindowsMicrosoft.NETFrameworkv4.0.30319mscorsvw.exe (Microsoft Corporation)
SRV - (Creative ALchemy AL6 Licensing Service) – C:Program Files (x86)Common FilesCreative Labs SharedServiceAL6Licensing.exe (Creative Labs)
SRV - (Creative Audio Engine Licensing Service) – C:Program Files (x86)Common FilesCreative Labs SharedServiceCTAELicensing.exe (Creative Labs)
SRV - (UNS) Intel® – C:Program Files (x86)IntelIntel® Management Engine ComponentsUNSUNS.exe (Intel Corporation)
SRV - (LMS) Intel® – C:Program Files (x86)IntelIntel® Management Engine ComponentsLMSLMS.exe (Intel Corporation)
SRV - (ASLDRService) – C:Program Files (x86)ASUSATK HotkeyAsLdrSrv.exe (ASUS)
SRV - (clr_optimization_v2.0.50727_32) – C:WindowsMicrosoft.NETFrameworkv2.0.50727mscorsvw.exe (Microsoft Corporation)
SRV - (YahooAUService) – C:Program Files (x86)Yahoo!SoftwareUpdateYahooAUService.exe (Yahoo! Inc.)
SRV - (ADSMService) – C:Program Files (x86)ASUSASUS Data Security ManagerADSMSrv.exe (ASUSTek Computer Inc.)


========== Driver Services (SafeList) ==========

DRV:64bit: - (Avgldx64) – C:WindowsSysNativedriversavgldx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgrkx64) – C:WindowsSysNativedriversavgrkx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgmfx64) – C:WindowsSysNativedriversavgmfx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (USBAAPL64) – C:WindowsSysNativedriversusbaapl64.sys (Apple, Inc.)
DRV:64bit: - (Avgtdia) – C:WindowsSysNativedriversavgtdia.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (AVGIDSFilter) – C:WindowsSysNativedriversAVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (AVGIDSDriver) – C:WindowsSysNativedriversAVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (AVGIDSEH) – C:WindowsSysNativedriversAVGIDSEH.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (dtsoftbus01) – C:WindowsSysNativedriversdtsoftbus01.sys (DT Soft Ltd)
DRV:64bit: - (Avgfwfd) – C:WindowsSysNativedriversavgfwd6a.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (amdsata) – C:WindowsSysNativedriversamdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:WindowsSysNativedriversamdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) – C:WindowsSysNativedriversHpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) – C:WindowsSysNativedriversTsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (sdbus) – C:WindowsSysNativedriverssdbus.sys (Microsoft Corporation)
DRV:64bit: - (ivusb) – C:WindowsSysNativedriversivusb.sys (Initio Corporation)
DRV:64bit: - (atksgt) – C:WindowsSysNativedriversatksgt.sys ()
DRV:64bit: - (lirsgt) – C:WindowsSysNativedriverslirsgt.sys ()
DRV:64bit: - (AsDsm) – C:WindowsSysNativedriversAsDsm.sys (ASUSTek Computer Inc)
DRV:64bit: - (Impcd) – C:WindowsSysNativedriversImpcd.sys (Intel Corporation)
DRV:64bit: - (athr) – C:WindowsSysNativedriversathrx.sys (Atheros Communications, Inc.)
DRV:64bit: - (iaStor) – C:WindowsSysNativedriversiaStor.sys (Intel Corporation)
DRV:64bit: - (HECIx64) Intel® – C:WindowsSysNativedriversHECIx64.sys (Intel Corporation)
DRV:64bit: - (NVHDA) – C:WindowsSysNativedriversnvhda64v.sys (NVIDIA Corporation)
DRV:64bit: - (SynTP) – C:WindowsSysNativedriversSynTP.sys (Synaptics Incorporated)
DRV:64bit: - (kbfiltr) – C:WindowsSysNativedriverskbfiltr.sys ( )
DRV:64bit: - (amdsbs) – C:WindowsSysNativedriversamdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:WindowsSysNativedriverslsi_sas2.sys (LSI Corporation)
DRV:64bit: - (Fs_Rec) – C:WindowsSysNativedriversfs_rec.sys (Microsoft Corporation)
DRV:64bit: - (stexstor) – C:WindowsSysNativedriversstexstor.sys (Promise Technology)
DRV:64bit: - (ROOTMODEM) – C:WindowsSysNativedriversrootmdm.sys (Microsoft Corporation)
DRV:64bit: - (rixdpcie) – C:WindowsSysNativedriversrixdpe64.sys (REDC)
DRV:64bit: - (rimspci) – C:WindowsSysNativedriversrimspe64.sys (REDC)
DRV:64bit: - (L1C) NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20) – C:WindowsSysNativedriversL1C62x64.sys (Atheros Communications, Inc.)
DRV:64bit: - (SiSGbeLH) – C:WindowsSysNativedriversSiSG664.sys (Silicon Integrated Systems Corp.)
DRV:64bit: - (ebdrv) – C:WindowsSysNativedriversevbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:WindowsSysNativedriversbxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:WindowsSysNativedriversb57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:WindowsSysNativedrivershcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (SNP2UVC) USB2.0 PC Camera (SNP2UVC) – C:WindowsSysNativedriverssnp2uvc.sys ()
DRV:64bit: - (GEARAspiWDM) – C:WindowsSysNativedriversGEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (MTsensor) – C:WindowsSysNativedriversATK64AMD.sys (ASUS)
DRV:64bit: - (WimFltr) – C:WindowsSysNativedriversWimFltr.sys (Microsoft Corporation)
DRV:64bit: - (WDC_SAM) – C:WindowsSysNativedriverswdcsam64.sys (Western Digital Technologies)
DRV:64bit: - (ASMMAP64) – C:Program FilesATKGFNEXASMMAP64.sys ()
DRV:64bit: - (pnetmdm) – C:WindowsSysNativedriverspnetmdm64.sys (June Fabrics Technology)
DRV - (rak) – C:GameSoftnyxGameRakionISBinrakion64.sys ()
DRV - (WIMMount) – C:WindowsSysWOW64driverswimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM..SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
IE:64bit: - HKLM..SearchScopes{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE:64bit: - HKLM..SearchScopes{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-results.com/sr?src=ieb&a;…q={searchTerms}
IE - HKLMSOFTWAREMicrosoftInternet ExplorerMain,Local Page = C:WindowsSysWOW64blank.htm
IE - HKLM..SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
IE - HKLM..SearchScopes{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM..SearchScopes{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-results.com/sr?src=ieb&a;…q={searchTerms}

IE - HKCUSOFTWAREMicrosoftInternet ExplorerMain,Default_Page_URL = http://asus.msn.com
IE - HKCUSOFTWAREMicrosoftInternet ExplorerMain,Start Page = http://www.searchnu.com/406
IE - HKCU..SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
IE - HKCU..SearchScopes{7E65B2BD-2537-4C83-80B9-684114C9DB60}: "URL" = http://search.avg.com/route/?d=$instd…=b&ychte;=aa
IE - HKCU..SearchScopes{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://isearch.avg.com/search?cid={B973330…mp;d=2012-01-12 17:28:15&v;=9.0.0.23&sap;=dsp&q;={searchTerms}
IE - HKCU..SearchScopes{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-results.com/sr?src=ieb&a;…q={searchTerms}
IE - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings: "ProxyEnable" = 0
IE - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings: "ProxyOverride" = *.local


========== FireFox ==========

FF:64bit: - [removed]/GENUINE: disabled File not found
FF - [removed]/FlashPlayer: C:Windowssystem32MacromedFlashNPSWF32.dll ()
FF - [removed]/iTunes,version=: File not found
FF - [removed]/iTunes,version=1.0: C:Program Files (x86)iTunesMozilla Pluginsnpitunes.dll ()
FF - [removed]/fpdlm: C:Program Files (x86)Download Managernpfpdlm.dll (IGN Entertainment)
FF - [removed]/YahooMessengerStatePlugin;version=1.0.0.6: C:Program Files (x86)Yahoo!SharednpYState.dll (Yahoo! Inc.)
FF - [removed]/GENUINE: disabled File not found
FF - [removed]/NpCtrl,version=1.0: c:Program Files (x86)Microsoft Silverlight4.1.10111.0npctrl.dll ( Microsoft Corporation)
FF - [removed]/OfficeLive,version=1.3: C:Program Files (x86)MicrosoftOffice LivenpOLW.dll (Microsoft Corp.)
FF - [removed]/PandoWebPlugin: C:Program Files (x86)Pando NetworksMedia BoosternpPandoWebPlugin.dll File not found
FF - [removed]/GoogleTalkPlugin: C:UsersVolkanAppDataRoamingMozillapluginsnpgoogletalk.dll (Google)
FF - [removed]/O3DPlugin: C:UsersVolkanAppDataRoamingMozillapluginsnpgtpo3dautoplugin.dll ()
FF - [removed]/Google Update;version=3: C:UsersVolkanAppDataLocalGoogleUpdate1.3.21.111npGoogleUpdate3.dll (Google Inc.)
FF - [removed]/Google Update;version=9: C:UsersVolkanAppDataLocalGoogleUpdate1.3.21.111npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINEsoftwaremozillaFirefoxExtensions{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:Program Files (x86)AVGAVG2012Firefox4 [2012/02/01 09:50:03 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINEsoftwaremozillaFirefoxExtensionsavg@toolbar: C:ProgramDataAVG Secure Search10.2.0.3 [2012/03/13 06:44:51 | 000,000,000 | —D | M]


========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chr
o
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:UsersVolkanAppDataLocalGoogleChromeApplication18.0.1025.142ppGoogleNa
ClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Disabled) = C:UsersVolkanAppDataLocalGoogleChromeApplication18.0.1025.142pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:UsersVolkanAppDataLocalGoogleChromeApplication18.0.1025.142gcswf32.dl
l
CHR - plugin: Shockwave Flash (Disabled) = C:UsersVolkanAppDataLocalGoogleChromeUser DataPepperFlash11.1.31.203pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:Windowssystem32MacromedFlashNPSWF32.dll
CHR - plugin: AVG Internet Security (Enabled) = C:UsersVolkanAppDataLocalGoogleChromeUser DataDefaultExtensionsjmfkcklnlgedgbglfkkgedjfmejoahla12.0.0.1901_0plugins/avgnpss.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:Program Files (x86)AdobeReader 9.0ReaderBrowsernppdf32.dll
CHR - plugin: QuickTime Plug-in 7.6.8 (Enabled) = C:Program Files (x86)QuickTimepluginsnpqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.8 (Enabled) = C:Program Files (x86)QuickTimepluginsnpqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.8 (Enabled) = C:Program Files (x86)QuickTimepluginsnpqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.8 (Enabled) = C:Program Files (x86)QuickTimepluginsnpqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.8 (Enabled) = C:Program Files (x86)QuickTimepluginsnpqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.8 (Enabled) = C:Program Files (x86)QuickTimepluginsnpqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.8 (Enabled) = C:Program Files (x86)QuickTimepluginsnpqtplugin7.dll
CHR - plugin: Google Talk Plugin (Enabled) = C:UsersVolkanAppDataRoamingMozillapluginsnpgoogletalk.dll
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:UsersVolkanAppDataRoamingMozillapluginsnpgtpo3dautoplugin.dll
CHR - plugin: IGN Download Manager Plug-in (Enabled) = C:Program Files (x86)Download Managernpfpdlm.dll
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:Program Files (x86)MicrosoftOffice LivenpOLW.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:Program Files (x86)iTunesMozilla Pluginsnpitunes.dll
CHR - plugin: Google Update (Enabled) = C:UsersVolkanAppDataLocalGoogleUpdate1.3.21.111npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:Program Files (x86)Microsoft Silverlight4.1.10111.0npctrl.dll
CHR - Extension: YouTube = C:UsersVolkanAppDataLocalGoogleChromeUser DataDefaultExtensionsblpcfgokakmgnkcojhhkbfbldkacnbeo4.2.5_0
CHR - Extension: Google Search = C:UsersVolkanAppDataLocalGoogleChromeUser DataDefaultExtensionscoobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0
CHR - Extension: AVG Safe Search = C:UsersVolkanAppDataLocalGoogleChromeUser DataDefaultExtensionsjmfkcklnlgedgbglfkkgedjfmejoahla12.0.0.1901_0
CHR - Extension: Gmail = C:UsersVolkanAppDataLocalGoogleChromeUser DataDefaultExtensionspjkljhegncpnkpknbcohdijeoejaedia7_0

O1 HOSTS File: ([2009/06/10 16:00:26 | 000,000,824 | —- | M]) - C:WindowsSysNativedriversetchosts
O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:Program Files (x86)AVGAVG2012avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2:64bit: - BHO: (DataMngr) - {9D717F81-9148-4f12-8568-69135F087DB0} - C:Program Files (x86)Searchqu ToolbarDatamngrx64BrowserConnection.dll (Bandoo Media, inc)
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:Program Files (x86)Yahoo!CompanionInstallscpnyt.dll (Yahoo! Inc.)
O2 - BHO: (PE_IE_Helper Class) - {0941C58F-E461-4E03-BD7D-44C27392ADE1} - C:Program Files (x86)IBMLotus FormsViewer3.5PEhelper.dll (IBM Corporation)
O2 - BHO: (Winamp Toolbar Loader) - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:Program Files (x86)Winamp Toolbarwinamptb.dll (AOL LLC.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:Program Files (x86)AVGAVG2012avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:Program Files (x86)AVG Secure Search10.2.0.3AVG Secure Search_toolbar.dll ()
O2 - BHO: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:Program Files (x86)Searchqu ToolbarDatamngrToolBarsearchqudtx.dll ()
O2 - BHO: (DataMngr) - {9D717F81-9148-4f12-8568-69135F087DB0} - C:Program Files (x86)Searchqu ToolbarDatamngrBrowserConnection.dll (Bandoo Media, inc)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:Program Files (x86)Yahoo!CompanionInstallscpnYTSingleInstance.dll (Yahoo! Inc)
O3:64bit: - HKLM..Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:Program Files (x86)DAEMON Tools ToolbarDTToolbar64.dll ()
O3:64bit: - HKLM..Toolbar: (no name) - 10 - No CLSID value found.
O3:64bit: - HKLM..Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM..Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:Program Files (x86)DAEMON Tools ToolbarDTToolbar.dll ()
O3 - HKLM..Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:Program Files (x86)AVG Secure Search10.2.0.3AVG Secure Search_toolbar.dll ()
O3 - HKLM..Toolbar: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:Program Files (x86)Searchqu ToolbarDatamngrToolBarsearchqudtx.dll ()
O3 - HKLM..Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKLM..Toolbar: (Winamp Toolbar) - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:Program Files (x86)Winamp Toolbarwinamptb.dll (AOL LLC.)
O3 - HKLM..Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:Program Files (x86)Yahoo!CompanionInstallscpnyt.dll (Yahoo! Inc.)
O3 - HKLM..Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM..Toolbar: (no name) - Locked - No CLSID value found.
O3:64bit: - HKCU..ToolbarWebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:Program Files (x86)DAEMON Tools ToolbarDTToolbar64.dll ()
O3 - HKCU..ToolbarWebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:Program Files (x86)DAEMON Tools ToolbarDTToolbar.dll ()
O3 - HKCU..ToolbarWebBrowser: (Winamp Toolbar) - {EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} - C:Program Files (x86)Winamp Toolbarwinamptb.dll (AOL LLC.)
O4:64bit: - HKLM..Run: [NvCplDaemon] C:WindowsSysNativeNvCpl.dll (NVIDIA Corporation)
O4:64bit: - HKLM..Run: [RunDLLEntry] C:WindowsSysNativeAmbRunE.DLL (Creative Technology Ltd.)
O4 - HKLM..Run: [APSDaemon] C:Program Files (x86)Common FilesAppleApple Application SupportAPSDaemon.exe (Apple Inc.)
O4 - HKLM..Run: [ATKMEDIA] C:Program Files (x86)ASUSATK MediaDMedia.exe (ASUS)
O4 - HKLM..Run: [ATKOSD2] C:Program Files (x86)ASUSATKOSD2ATKOSD2.exe (ASUS)
O4 - HKLM..Run: [AVG_TRAY] C:Program Files (x86)AVGAVG2012avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..Run: [DATAMNGR] C:Program Files (x86)Searchqu ToolbarDatamngrdatamngrUI.exe (Bandoo Media, inc)
O4 - HKLM..Run: [HControlUser] C:Program Files (x86)ASUSATK HotkeyHControlUser.exe (ASUS)
O4 - HKLM..Run: [ROC_roc_dec12] C:Program Files (x86)AVG Secure SearchROC_roc_dec12.exe ()
O4 - HKLM..Run: [Setwallpaper] c:programdataSetWallpaper.cmd File not found
O4 - HKLM..Run: [UpdReg] C:WindowsUpdreg.EXE (Creative Technology Ltd.)
O4 - HKLM..Run: [VolPanel] C:Program Files (x86)CreativeSB AudigyVolume PanelVolPanlu.exe (Creative Technology Ltd)
O4 - HKLM..Run: [vProt] C:Program Files (x86)AVG Secure Searchvprot.exe ()
O4 - HKLM..Run: [WinampAgent] C:Program Files (x86)Winampwinampa.exe (Nullsoft, Inc.)
O4 - HKCU..Run: [AdobeUpdater6] C:Program Files (x86)Common FilesAdobeUpdater6Adobe_Updater.exe (Adobe Systems Incorporated)
O4 - HKCU..Run: [DAEMON Tools Lite] C:Program Files (x86)DAEMON Tools LiteDTLite.exe (DT Soft Ltd)
O4 - HKCU..Run: [igndlm.exe] C:Program Files (x86)Download ManagerDLM.exe (IGN Entertainment)
O4 - HKCU..Run: [Messenger (Yahoo!)] C:Program Files (x86)Yahoo!MessengerYahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..Run: [MtdAcqu] C:Program Files (x86)CreativeMediaSource5MtdAcqu.exe (Creative Technology Ltd)
O4 - HKCU..Run: [Steam] C:Program Files (x86)Steamsteam.exe (Valve Corporation)
O4 - Startup: C:UsersVolkanAppDataRoamingMicrosoftWindowsStart MenuProgramsStartupCurseClientStartup.ccip ()
O4 - Startup: C:UsersVolkanAppDataRoamingMicrosoftWindowsStart MenuProgramsStartupDropbox.lnk = C:UsersVolkanAppDataRoamingDropboxbinDropbox.exe (Dropbox, Inc.)
O6 - HKLMSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoActiveDesktop = 1
O6 - HKLMSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoActiveDesktopChanges = 1
O6 - HKLMSOFTWAREMicrosoftWindowsCurrentVersionpoliciesSystem: ConsentPromptBehaviorAdmin = 0
O6 - HKLMSOFTWAREMicrosoftWindowsCurrentVersionpoliciesSystem: ConsentPromptBehaviorUser = 3
O6 - HKLMSOFTWAREMicrosoftWindowsCurrentVersionpoliciesSystem: EnableLUA = 0
O6 - HKLMSOFTWAREMicrosoftWindowsCurrentVersionpoliciesSystem: PromptOnSecureDesktop = 0
O7 - HKCUSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoDriveTypeAutoRun = 145
O8:64bit: - Extra context menu item: &Winamp; Search - C:ProgramDataWinamp ToolbarieToolbarresourcesen-USlocalsearch.html ()
O8 - Extra context menu item: &Winamp; Search - C:ProgramDataWinamp ToolbarieToolbarresourcesen-USlocalsearch.html ()
O10:64bit: - NameSpace_Catalog5Catalog_Entries64\000000000009 [] - C:Program FilesBonjourmdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5Catalog_Entries\000000000009 [] - C:Program Files (x86)BonjourmdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.10.115.cab (CDownloadCtrl Object)
O17 - HKLMSystemCCSServicesTcpipParameters: DhcpNameServer = [removed] [removed] 8.8.8.8
O17 - HKLMSystemCCSServicesTcpipParametersInterfaces{7AC941EC-0C5F-4530-BBD1-FA97F3A4F429}: DhcpNameServer = [removed] [removed] 8.8.8.8
O18:64bit: - ProtocolHandlerlinkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:Program Files (x86)AVGAVG2012avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:64bit: - ProtocolHandlerms-help - No CLSID value found
O18:64bit: - ProtocolHandlerms-itss - No CLSID value found
O18:64bit: - ProtocolHandlerskype4com - No CLSID value found
O18:64bit: - ProtocolHandlerviprotocol - No CLSID value found
O18 - ProtocolHandlerlinkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:Program Files (x86)AVGAVG2012avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - ProtocolHandlerskype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:Program Files (x86)Common FilesSkypeSkype4COM.dll (Skype Technologies)
O18 - ProtocolHandlerviprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:Program Files (x86)Common FilesAVG Secure SearchViProtocolInstaller10.2.0ViProtocol.dll ()
O20:64bit: - AppInit_DLLs: (C:PROGRA~2SEARCH~1Datamngrx64datamngr.dll) - C:Program Files (x86)Searchqu ToolbarDatamngrx64datamngr.dll (Bandoo Media, inc)
O20:64bit: - AppInit_DLLs: (C:PROGRA~2SEARCH~1Datamngrx64IEBHO.dll) - C:Program Files (x86)Searchqu ToolbarDatamngrx64IEBHO.dll (Bandoo Media, inc)
O20 - AppInit_DLLs: (C:PROGRA~2SEARCH~1Datamngrdatamngr.dll) - C:Program Files (x86)Searchqu ToolbarDatamngrdatamngr.dll (Bandoo Media, inc)
O20 - AppInit_DLLs: (C:PROGRA~2SEARCH~1DatamngrIEBHO.dll) - C:Program Files (x86)Searchqu ToolbarDatamngrIEBHO.dll (Bandoo Media, inc)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:Windowsexplorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:Windowssystem32userinit.exe) - C:WindowsSysNativeuserinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:WindowsSysNativeSystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:WindowsSysWow64explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:WindowsSysWow64userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/07/19 13:26:16 | 000,000,154 | RH– | M] () - E:autorun.inf – [ CDFS ]
O33 - MountPoints2{03aed25d-1c59-11df-84b7-806e6f6e6963}Shell - "" = AutoRun
O33 - MountPoints2{03aed25d-1c59-11df-84b7-806e6f6e6963}ShellAutoRuncommand - "" = E:Setup.exe – [2011/07/19 12:46:16 | 040,002,168 | R— | M] (Cisco Consumer Products LLC)
O33 - MountPoints2{a6952f05-a80b-11e0-a0d8-e0cb4efe75dc}Shell - "" = AutoRun
O33 - MountPoints2{a6952f05-a80b-11e0-a0d8-e0cb4efe75dc}ShellAutoRuncommand - "" = G:AutoRun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:PROGRA~2AVGAVG2012avgrsa.exe /sync /restart)
O35:64bit: - HKLM..comfile [open] – "%1" %*
O35:64bit: - HKLM..exefile [open] – "%1" %*
O35 - HKLM..comfile [open] – "%1" %*
O35 - HKLM..exefile [open] – "%1" %*
O37:64bit: - HKLM…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM…exe [@ = exefile] – "%1" %*
O37 - HKLM…com [@ = comfile] – "%1" %*
O37 - HKLM…exe [@ = exefile] – "%1" %*


Drivers32:64bit: msacm.l3acm - C:WindowsSystem32l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:WindowsSysWOW64l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:WindowsSysWow64iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/04/03 14:12:32 | 000,000,000 | —D | C] – C:UsersVolkanDesktopFlorence And The Machine - Lungs [2009]
[2012/04/03 13:58:05 | 000,000,000 | R–D | C] – C:UsersVolkanDropbox
[2012/04/03 13:56:14 | 000,000,000 | —D | C] – C:ProgramDataboost_interprocess
[2012/04/03 13:56:10 | 000,000,000 | —D | C] – C:UsersVolkanAppDataRoamingMicrosoftWindowsStart MenuProgramsDropbox
[2012/04/03 13:55:38 | 000,000,000 | —D | C] – C:UsersVolkanAppDataRoamingDropbox
[2012/03/31 17:50:12 | 000,000,000 | —D | C] – C:UsersVolkanDesktopFallen
[2012/03/31 17:41:32 | 000,000,000 | —D | C] – C:UsersVolkanAppDataLocalIlivid Player
[2012/03/31 17:30:28 | 000,000,000 | —D | C] – C:Program Files (x86)Searchqu Toolbar
[2012/03/29 07:32:42 | 000,000,000 | —D | C] – C:UsersVolkanAppDataRoamingMozilla
[2012/03/24 21:23:39 | 000,000,000 | —D | C] – C:UsersVolkanAppDataLocalTERA
[2012/03/22 14:15:41 | 000,000,000 | —D | C] – C:WindowsPCHEALTH
[2012/03/14 23:06:01 | 000,000,000 | —D | C] – C:UsersVolkanDesktopSoilwork - Stabbing The Drama (2005)
[2012/03/14 03:04:07 | 005,559,152 | —- | C] (Microsoft Corporation) – C:WindowsSysNativentoskrnl.exe
[2012/03/14 03:04:06 | 003,968,368 | —- | C] (Microsoft Corporation) – C:WindowsSysWow64ntkrnlpa.exe
[2012/03/14 03:04:06 | 003,913,584 | —- | C] (Microsoft Corporation) – C:WindowsSysWow64ntoskrnl.exe
[2012/03/14 02:13:26 | 001,544,192 | —- | C] (Microsoft Corporation) – C:WindowsSysNativeDWrite.dll
[2012/03/14 02:12:33 | 000,149,504 | —- | C] (Microsoft Corporation) – C:WindowsSysNativerdpcorekmts.dll
[2012/03/14 02:12:33 | 000,077,312 | —- | C] (Microsoft Corporation) – C:WindowsSysNativerdpwsx.dll
[2012/03/14 02:12:33 | 000,009,216 | —- | C] (Microsoft Corporation) – C:WindowsSysNativerdrmemptylst.exe
[2012/03/14 02:12:31 | 001,031,680 | —- | C] (Microsoft Corporation) – C:WindowsSysNativerdpcore.dll
[2012/03/14 02:12:31 | 000,826,880 | —- | C] (Microsoft Corporation) – C:WindowsSysWow64rdpcore.dll
[2012/03/11 16:13:22 | 000,000,000 | —D | C] – C:UsersVolkanDesktopNero - Welcome Reality (Deluxe Edition)
[2012/03/11 16:11:44 | 000,000,000 | —D | C] – C:UsersVolkanDesktopUKF Dubstep 2011
[2012/03/08 09:20:20 | 000,000,000 | —D | C] – C:UsersVolkanAppDataRoamingPureEdge
[2012/03/08 09:19:53 | 000,000,000 | —D | C] – C:ProgramDataMicrosoftWindowsStart MenuProgramsIBM Lotus Forms Viewer 3.5
[2012/03/08 09:19:40 | 000,000,000 | —D | C] – C:ProgramDataPureEdge
[2012/03/08 09:19:38 | 000,000,000 | —D | C] – C:Program Files (x86)IBM
[9 C:Windows*.tmp files -> C:Windows*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/04/04 15:46:03 | 000,010,240 | -H– | M] () – C:WindowsSysNative7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/04/04 15:46:03 | 000,010,240 | -H– | M] () – C:WindowsSysNative7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/04/04 15:37:54 | 000,000,512 | —- | M] () – C:UsersVolkanDesktopMBR.dat
[2012/04/04 15:31:50 | 000,415,060 | —- | M] () – C:WindowsSysNativedriversAVGiavichjg.avm
[2012/04/04 15:28:48 | 000,000,912 | —- | M] () – C:WindowstasksGoogleUpdateTaskUserS-1-5-21-4220897269-1764641617-2706767991-1001UA.job
[2012/04/04 15:28:39 | 000,067,584 | –S- | M] () – C:Windowsbootstat.dat
[2012/04/04 12:34:21 | 000,740,046 | —- | M] () – C:WindowsSysNativePerfStringBackup.INI
[2012/04/04 12:34:21 | 000,633,180 | —- | M] () – C:WindowsSysNativeperfh009.dat
[2012/04/04 12:34:21 | 000,110,782 | —- | M] () – C:WindowsSysNativeperfc009.dat
[2012/04/04 12:29:14 | 000,001,826 | —- | M] () – C:WindowsSysNativeAutoRunFilter.ini
[2012/04/04 12:27:57 | 000,065,536 | —- | M] () – C:WindowsSysNativeIkeext.etl
[2012/04/04 12:27:32 | 3112,058,880 | -HS- | M] () – C:hiberfil.sys
[2012/04/04 12:21:24 | 000,623,705 | —- | M] () – C:WindowsSysNativedriversAVGiavifw.avm
[2012/04/04 06:54:08 | 093,598,011 | —- | M] () – C:WindowsSysNativedriversAVGincavi.avm
[2012/04/04 05:54:00 | 000,000,860 | —- | M] () – C:WindowstasksGoogleUpdateTaskUserS-1-5-21-4220897269-1764641617-2706767991-1001Core.job
[2012/04/03 13:58:05 | 000,001,045 | —- | M] () – C:UsersVolkanDesktopDropbox.lnk
[2012/04/03 13:56:17 | 000,001,025 | —- | M] () – C:UsersVolkanAppDataRoamingMicrosoftWindowsStart MenuProgramsStartupDropbox.lnk
[2012/03/30 09:55:48 | 000,002,411 | —- | M] () – C:UsersVolkanDesktopGoogle Chrome.lnk
[2012/03/22 18:48:49 | 000,045,056 | —- | M] () – C:WindowsSysNativeacovcnt.exe
[2012/03/22 18:21:55 | 000,000,258 | RHS- | M] () – C:ProgramDatantuser.pol
[2012/03/14 03:23:35 | 000,001,557 | —- | M] () – C:WindowsSysNativeServiceFilter.ini
[2012/03/14 03:22:09 | 000,342,832 | —- | M] () – C:WindowsSysNativeFNTCACHE.DAT
[9 C:Windows*.tmp files -> C:Windows*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/04/04 15:37:54 | 000,000,512 | —- | C] () – C:UsersVolkanDesktopMBR.dat
[2012/04/03 13:58:05 | 000,001,045 | —- | C] () – C:UsersVolkanDesktopDropbox.lnk
[2012/04/03 13:56:17 | 000,001,025 | —- | C] () – C:UsersVolkanAppDataRoamingMicrosoftWindowsStart MenuProgramsStartupDropbox.lnk
[2012/01/13 00:29:26 | 000,144,384 | -H– | C] () – C:WindowsSysWow64mlfcache.dat
[2012/01/03 18:29:46 | 000,000,040 | —- | C] () – C:ProgramDatara3.ini
[2011/10/26 17:09:18 | 000,000,258 | RHS- | C] () – C:ProgramDatantuser.pol
[2011/08/09 20:04:57 | 000,000,056 | -H– | C] () – C:WindowsSysWow64ezsidmv.dat
[2011/05/22 04:23:27 | 000,108,114 | —- | C] () – C:WindowsWar3Unin.dat
[2011/04/09 10:55:28 | 000,179,261 | —- | C] () – C:WindowsSysWow64xlive.dll.cat
[2010/10/10 21:00:10 | 000,000,262 | —- | C] () – C:Windows{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}_WiseFW.ini
[2010/09/12 17:11:03 | 000,000,094 | —- | C] () – C:UsersVolkanAppDataLocalfusioncache.dat
[2010/08/07 16:36:24 | 000,743,594 | —- | C] () – C:WindowsSysWow64PerfStringBackup.INI

========== LOP Check ==========

[2010/09/29 20:16:02 | 000,000,000 | —D | M] – C:UsersVolkanAppDataRoamingAcreon
[2011/02/15 12:11:53 | 000,000,000 | —D | M] – C:UsersVolkanAppDataRoamingAVG
[2012/01/12 18:26:46 | 000,000,000 | —D | M] – C:UsersVolkanAppDataRoamingAVG2012
[2012/01/03 02:50:40 | 000,000,000 | —D | M] – C:UsersVolkanAppDataRoamingCommand & Conquer 3 Tiberium Wars
[2011/07/07 08:08:53 | 000,000,000 | —D | M] – C:UsersVolkanAppDataRoamingDAEMON Tools Lite
[2012/04/04 15:53:00 | 000,000,000 | —D | M] – C:UsersVolkanAppDataRoamingDropbox
[2012/02/15 18:52:26 | 000,000,000 | —D | M] – C:UsersVolkanAppDataRoamingEnMasse
[2011/04/27 12:59:23 | 000,000,000 | —D | M] – C:UsersVolkanAppDataRoamingFreeAudioPack
[2011/08/10 16:18:30 | 000,000,000 | —D | M] – C:UsersVolkanAppDataRoaminggo
[2011/08/10 13:49:43 | 000,000,000 | —D | M] – C:UsersVolkanAppDataRoamingLolClient
[2012/03/08 09:20:27 | 000,000,000 | —D | M] – C:UsersVolkanAppDataRoamingPureEdge
[2012/01/03 11:33:26 | 000,000,000 | —D | M] – C:UsersVolkanAppDataRoamingRed Alert 3
[2012/03/01 08:00:52 | 000,000,000 | —D | M] – C:UsersVolkanAppDataRoamingRotMG.Production
[2012/04/04 12:24:54 | 000,000,000 | —D | M] – C:UsersVolkanAppDataRoaminguTorrent
[2011/10/20 15:00:00 | 000,032,624 | —- | M] () – C:WindowsTasksSCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%*.* >
[2009/06/15 06:11:59 | 000,000,054 | —- | M] () – C:AdobeReader.log
[2009/12/04 09:06:31 | 002,097,152 | -H– | M] () – C:BIOS.BIN
[2011/03/10 11:27:26 | 000,000,667 | —- | M] () – C:BnetLog.txt
[2010/11/20 07:40:07 | 000,383,786 | RHS- | M] () – C:bootmgr
[2009/07/29 01:03:37 | 000,008,192 | RHS- | M] () – C:BOOTSECT.BAK
[2010/02/18 02:08:03 | 000,015,827 | —- | M] () – C:devlist.txt
[2010/02/18 02:08:03 | 000,000,009 | —- | M] () – C:Finish.log
[2009/11/27 03:32:01 | 000,000,018 | —- | M] () – C:G60Jx_WIN7.10
[2012/04/04 12:27:32 | 3112,058,880 | -HS- | M] () – C:hiberfil.sys
[2010/02/18 01:49:53 | 000,458,380 | —- | M] () – C:if.log
[2010/02/18 02:20:38 | 001,609,467 | —- | M] () – C:inject.log.txt
[2012/04/04 12:27:38 | 4149,415,936 | -HS- | M] () – C:pagefile.sys
[2010/02/17 10:42:24 | 000,000,105 | —- | M] () – C:Pass.txt
[2010/01/07 22:49:43 | 000,000,339 | —- | M] () – C:Patch_Win7.log
[2009/11/10 23:04:13 | 000,000,012 | —- | M] () – C:RECOVERY.DAT
[2010/02/18 01:46:26 | 000,002,114 | —- | M] () – C:RHDSetup.log
[2010/02/18 01:51:23 | 000,000,086 | —- | M] () – C:setup.log
[2006/05/14 03:22:24 | 000,000,005 | —- | M] () – C:store.log
[2010/02/18 02:03:35 | 000,000,170 | —- | M] () – C:SumHidd.txt
[2010/02/18 02:03:00 | 000,000,098 | —- | M] () – C:SumOS.txt
[2009/09/16 13:04:46 | 000,000,024 | —- | M] () – C:v82.txt

< %systemroot%Fonts*.com >
[2009/07/14 00:32:31 | 000,026,040 | —- | M] () – C:WindowsFontsGlobalMonospace.CompositeFont
[2009/07/14 00:32:31 | 000,026,489 | —- | M] () – C:WindowsFontsGlobalSansSerif.CompositeFont
[2009/07/14 00:32:31 | 000,029,779 | —- | M] () – C:WindowsFontsGlobalSerif.CompositeFont
[2009/07/14 00:32:31 | 000,043,318 | —- | M] () – C:WindowsFontsGlobalUserInterface.CompositeFont

< %systemroot%Fonts*.dll >

< %systemroot%Fonts*.ini >
[2009/06/10 15:49:50 | 000,000,065 | —- | M] () – C:WindowsFontsdesktop.ini

< %systemroot%Fonts*.ini2 >

< %systemroot%Fonts*.exe >

< %systemroot%system32spoolprtprocsw32x86*.* >

< %systemroot%REPAIR*.bak1 >

< %systemroot%REPAIR*.ini >

< %systemroot%system32*.jpg >

< %systemroot%*.jpg >
[2010/02/18 01:48:10 | 000,039,426 | —- | M] () – C:WindowsAsCD_Stage138.jpg
[2010/02/18 01:48:30 | 000,042,538 | —- | M] () – C:WindowsAsCD_Stage156.jpg
[9 C:Windows*.tmp files -> C:Windows*.tmp -> ]

< %systemroot%*.png >

< %systemroot%*.scr >

< %systemroot%*._sy >

< %APPDATA%AdobeUpdate*.* >

< %ALLUSERSPROFILE%Favorites*.* >

< %APPDATA%Microsoft*.* >

< %PROGRAMFILES%*.* >
[2009/07/13 23:54:24 | 000,000,174 | -HS- | M] () – C:Program Files (x86)desktop.ini

< %APPDATA%Update*.* >

< %systemroot%*. /mp /s >

< %systemroot%System32config*.sav >

< %PROGRAMFILES%bak. /s >

< %systemroot%system32bak. /s >

< %ALLUSERSPROFILE%Start Menu*.lnk /x >

< %systemroot%system32configsystemprofile*.dat /x >

< %systemroot%*.config >

< %systemroot%system32*.db >

< %PROGRAMFILES%Internet Explorer*.dat >

< %APPDATA%MicrosoftInternet ExplorerQuick Launch*.lnk /x >
[2010/07/09 19:09:07 | 000,000,221 | -HS- | M] () – C:UsersVolkanAppDataRoamingMicrosoftInternet ExplorerQuick Launchdesktop.ini

< %USERPROFILE%Desktop*.exe >
[2011/03/17 11:49:24 | 011,193,664 | —- | M] (DT Soft Ltd.) – C:UsersVolkanDesktopDTLite4402-0131.exe
[2010/12/14 15:08:26 | 629,399,943 | —- | M] (Softnyx co.,ltd. ) – C:UsersVolkanDesktopRIS_Ver110613_XfsVer673.exe
[2004/02/28 18:32:50 | 199,394,291 | —- | M] () – C:UsersVolkanDesktopWorms World Party.exe

< %PROGRAMFILES%Common Files*.* >

< %systemroot%*.src >
[2006/05/18 22:53:01 | 000,013,022 | —- | M] () – C:Windowssnp2uvc.src
[9 C:Windows*.tmp files -> C:Windows*.tmp -> ]

< %systemroot%install*.* >

< %systemroot%system32DLL*.* >

< %systemroot%system32HelpFiles*.* >

< %systemroot%system32rundll*.* >

< %systemroot%winn32*.* >

< %systemroot%Java*.* >

< %systemroot%system32test*.* >

< %systemroot%system32Rundll32*.* >

< %systemroot%AppPatchCustom*.* >

< HKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftWindowsWindowsUpdateAU >

< HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionWindowsUpdateAuto UpdateResultsInstall|LastSuccessTime /rs >

========== Alternate Data Streams ==========

@Alternate Data Stream - 124 bytes -> C:ProgramDataTEMP:0B4227B4

< End of report >

And here are the OTL extras.


OTL Extras logfile created on: 4/4/2012 3:44:30 PM - Run 1
OTL by OldTimer - Version 3.2.39.2 Folder = C:UsersVolkanDownloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.86 Gb Total Physical Memory | 1.68 Gb Available Physical Memory | 43.57% Memory free
7.73 Gb Paging File | 5.43 Gb Available in Paging File | 70.32% Paging File free
Paging file location(s): ?:pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:Windows | %ProgramFiles% = C:Program Files (x86)
Drive C: | 446.23 Gb Total Space | 9.22 Gb Free Space | 2.07% Space Free | Partition Type: NTFS
Drive E: | 92.84 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: VOLKAN-PC | User Name: Volkan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINESOFTWAREClasses]
.url[@ = InternetShortcut] – C:WindowsSysNativerundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINESOFTWAREClasses]
.cpl [@ = cplfile] – C:WindowsSysWow64control.exe (Microsoft Corporation)

[HKEY_CURRENT_USERSOFTWAREClasses]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINESOFTWAREClassesshell[command]command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%System32InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:WindowsSystem32rundll32.exe" "C:WindowsSystem32ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:WindowsSystem32rundll32.exe" "C:WindowsSystem32mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%system32rundll32.exe %SystemRoot%system32shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:Program Files (x86)VideoLANVLCvlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:Program Files (x86)VideoLANVLCvlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Directory [Winamp.Bookmark] – "C:Program Files (x86)Winampwinamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] – "C:Program Files (x86)Winampwinamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] – "C:Program Files (x86)Winampwinamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] – %SystemRoot%Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINESOFTWAREClassesshell[command]command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%System32control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%System32InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%system32rundll32.exe %SystemRoot%system32shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:Program Files (x86)VideoLANVLCvlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:Program Files (x86)VideoLANVLCvlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Directory [Winamp.Bookmark] – "C:Program Files (x86)Winampwinamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] – "C:Program Files (x86)Winampwinamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] – "C:Program Files (x86)Winampwinamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] – %SystemRoot%Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity Center]
"cval" = 1
"AutoUpdateDisableNotify" = 1

64bit: [HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoring]

64bit: [HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterSvc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterSvcVol]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity Center]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterSvc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyDomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyStandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyPublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstall]
"{015C5B35-B678-451C-9AEE-821E8D69621C}_is1" = PeerBlock 1.1 (r518)
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{13F4A7F3-EABC-4261-AF6B-1317777F0755}" = Fast Boot
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{75104836-CAC7-444E-A39E-3F54151942F5}" = Apple Mobile Device Support
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{91EFE3A1-585E-4F66-B5F6-F118F56C4C47}" = ASUS Power4Gear Hybrid
"{9B48B0AC-C813-4174-9042-476A887592C7}" = Windows Live ID Sign-in Assistant
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B6D40BDA-5023-438D-B347-BE870E5F6F10}" = AVG 2012
"{D050583D-5CEC-47B1-88AA-8B328CAA8621}" = AVG 2012
"{D66F0C3C-24F2-4463-9E2F-4381E5C40A26}" = iTunes
"{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148
"{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}" = Ventrilo Client for Windows x64
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"AVG" = AVG 2012
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"NVIDIA Drivers" = NVIDIA Drivers
"PeerGuardian_is1" = PeerGuardian 2.0
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"UDK-b3e3cfad-06c3-4404-80cf-283ca9f8b291" = Sanctum Demo

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{022CBB38-CEF0-42BA-906A-A49BEFAE0BEE}" = RICOH R5U230 Media Driver ver.2.05.02.02
"{02A10468-2F1C-447C-AD8E-4DEDDEA25AE2}" = Medieval II Total War : Kingdoms : Crusades
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{06585B02-F20D-4AB2-9A64-86EF2AE0F8F0}" = ASUS AI Recovery
"{0969AF05-4FF6-4C00-9406-43599238DE0D}" = ASUS Splendid Video Enhancement Technology
"{0FCDA0F8-F3E5-402E-B9B6-13CB2B01182B}" = TERA
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{1A655D51-1423-48A3-B748-8F5A0BE294C8}" = Microsoft Visual J# .NET Redistributable Package 1.1
"{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}" = ASUS LifeFrame3
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{20FDF948-C8ED-4543-A539-F7F4AEF5AFA2}" = Wireless Console 3
"{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Atheros Client Installation Program
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{2B653229-9854-4989-B780-D978F5F13EAB}" = FEAR
"{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Atheros Communications Inc.® AR81Family Gigabit/Fast Ethernet Driver
"{343666E2-A059-48AC-AD67-230BF74E2DB2}" = Apple Application Support
"{38F8D823-008D-4E5A-BBCE-867A86C2BF2B}" = Sound Blaster Audigy HD
"{3B05F2FB-745B-4012-ADF2-439F36B2E70B}" = ATKOSD2
"{4CB0307C-565E-4441-86BE-0DF2E4FB828C}" = Microsoft Games for Windows Marketplace
"{50316C0A-CC2A-460A-9EA5-F486E54AC17D}_is1" = AVG PC Tuneup 2011
"{51D386C4-0227-46A9-AC45-61F0A50E7AFF}" = Rome - Total War
"{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3
"{5B65EF64-1DFA-414A-8C94-7BB726158E21}" = ControlDeck
"{60D6618B-153F-4353-8185-908E676E5888}" = ASUS FancyStart
"{614F6133-1897-3CB9-859A-F2A19FBE8D4A}" = Google Talk Plugin
"{64452561-169F-4A36-A2FF-B5E118EC65F5}" = ASUS SmartLogon
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel® Management Engine Components
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{75983B66-804C-40D1-BA13-64DAF652A6F1}" = Medieval II Total War : Kingdoms : Americas
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7AEE1963-7001-4C37-BC20-2FAEB74AA41C}" = Medieval II Total War : Kingdoms : Teutonic
"{7C05592D-424B-46CB-B505-E0013E8E75C9}" = ATK Hotkey
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{888DD888-82BE-4D85-BCB2-2E042CD3E844}" = Tom Clancy's Splinter Cell Chaos Theory
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8F21291E-0444-4B1D-B9F9-4370A73E346D}" = WinFlash
"{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002A-0409-1000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0116-0409-1000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{92606477-9366-4D3B-8AE3-6BE4B29727AB}" = League of Legends
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A0BBF7AB-2F47-47DC-BB02-4C826F2BC73C}" = IBM Lotus Forms Viewer 3.5.1
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{AC76BA86-7AD7-FFFF-7B44-A91000000001}" = Adobe Reader 9.1 MUI
"{B5A5627C-0173-4DB2-ADA8-740479370F67}" = Express Gate
"{B83FC356-B7C0-441F-8A4D-D71E088E7974}" = NVIDIA PhysX
"{B93EEE50-9C8F-45DF-95E4-3D85A6E242F3}" = DarksidersInstaller
"{BEEFC4F8-2909-48B3-AFAA-55D3533FDEDD}" = Creative MediaSource 5
"{BFA90209-7AFF-4DB6-8E4B-E57305751AD7}" = Unreal Tournament 3
"{C0698BDA-0D29-40EE-8570-A31106DF9AB1}" = Medieval II Total War
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CEDDEE73-3D36-41C2-AA40-29355D9FBD63}" = Medieval II Total War : Kingdoms : Britannia
"{D1E5870E-E3E5-4475-98A6-ADD614524ADF}" = ATK Media
"{D3D54F3E-C5C3-443D-978F-87A72E5616E8}" = ATK Generic Function Service
"{D6C630BF-8DBB-4042-8562-DC9A52CB6E7E}" = Intel® Turbo Boost Technology Driver
"{E633D396-5188-4E9D-8F6B-BFB8BF3467E8}" = Skype™ 5.0
"{E657B243-9AD4-4ECC-BE81-4CCF8D667FD0}" = ASUS Live Update
"{E7004147-2CCA-431C-AA05-2AB166B9785D}" = QuickTime
"{EC8BD21F-0CA0-4BBF-97D9-4A52B30041A1}" = ASUS Virtual Camera
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F138762F-5A1F-4CF0-A5E1-1588EF6088A4}" = The Witcher Enhanced Edition
"{F20C1251-1D0A-4944-B2AE-678581B33B19}" = Neverwinter Nights 2
"{F2508213-9989-4E85-A078-72BE483917EF}" = Microsoft Games for Windows - LIVE Redistributable
"{FA2092C5-7979-412D-A962-6485274AE1EE}" = ASUS Data Security Manager
"{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}" = Visual Studio 2008 x64 Redistributables
"{FD69C8CB-6964-432C-98AB-A5A09ED50EEA}" = Barbarian Invasion
"{FDD810CA-D5E3-40E9-AB7B-36440B0D41EF}" = Windows Live Sync
"12bbe590-c890-11d9-9669-0800200c9a66_is1" = The Lord of the Rings Online™ v03.02.03.8013
"1602 A.D." = 1602 A.D.
"7-Zip" = 7-Zip 4.65
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"ASUS AP Bank_is1" = ASUS AP Bank
"ASUS_ScreenSaver_GSeries" = ASUS_ScreenSaver_GSeries
"Cisco Connect" = Cisco Connect
"DAEMON Tools Lite" = DAEMON Tools Lite
"DAEMON Tools Toolbar" = DAEMON Tools Toolbar
"Diablo II" = Diablo II
"Download Manager" = Download Manager 2.3.10
"Free Mp3 Wma Converter_is1" = Free Mp3 Wma Converter V 1.95
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"OpenAL" = OpenAL
"Peggle Deluxe 1.0" = Peggle Deluxe 1.0
"Rakion International_is1" = Rakion International
"Searchqu Toolbar" = Searchqu Toolbar
"ST6UNST #1" = Hero Editor V1.04
"Steam App 17480" = Command and Conquer: Red Alert 3
"Steam App 200210" = Realm of the Mad God
"Steam App 20570" = Warhammer® 40,000™: Dawn of War® II – Chaos Rising™
"Steam App 2200" = Quake III Arena
"Steam App 2350" = Quake III: Team Arena
"Steam App 240" = Counter-Strike: Source
"Steam App 24790" = Command and Conquer 3: Tiberium Wars
"Steam App 24800" = Command and Conquer: Red Alert 3 - Uprising
"Steam App 40100" = Supreme Commander 2
"Steam App 440" = Team Fortress 2
"Steam App 4560" = Company of Heroes
"Steam App 50620" = Darksiders
"Steam App 55150" = Warhammer 40,000 Space Marine
"Steam App 56400" = Warhammer® 40,000®: Dawn of War® II – Retribution™
"Steam App 570" = Dota 2
"Steam App 61310" = Fractal
"Steam App 8930" = Sid Meier's Civilization V
"Steam App 91600" = Sanctum
"Steam App 9340" = Company of Heroes: Opposing Fronts
"UnrealTournament" = Unreal Tournament G.O.T.Y. Edition
"uTorrent" = µTorrent
"VLC media player" = VLC media player 1.1.5
"Warcraft III" = Warcraft III
"Winamp" = Winamp
"Winamp Toolbar" = Winamp Toolbar
"World of Warcraft" = World of Warcraft
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Software Update" = Yahoo! Software Update

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionUninstall]
"090215de958f1060" = Curse Client
"Dropbox" = Dropbox
"Game Organizer" = EasyBits GO
"Google Chrome" = Google Chrome
"InstallShield_{BFA90209-7AFF-4DB6-8E4B-E57305751AD7}" = Unreal Tournament 3
"Warcraft III" = Warcraft III: All Products
"Winamp Detect" = Winamp Detector Plug-in

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 1/2/2012 8:07:48 PM | Computer Name = Volkan-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 185953519

Error - 1/2/2012 8:32:23 PM | Computer Name = Volkan-PC | Source = Customer Experience Improvement Program | ID = 1008
Description =

Error - 1/2/2012 10:15:14 PM | Computer Name = Volkan-PC | Source = Customer Experience Improvement Program | ID = 1008
Description =

Error - 1/3/2012 5:18:40 AM | Computer Name = Volkan-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:Program Files (x86)Common
FilesAdobe AIRVersions1.0Adobe AIR.dll".Error in manifest or policy file "c:Program
Files (x86)Common FilesAdobe AIRVersions1.0Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.

Error - 1/3/2012 9:36:08 AM | Computer Name = Volkan-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 1/3/2012 9:36:08 AM | Computer Name = Volkan-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 1139

Error - 1/3/2012 9:36:08 AM | Computer Name = Volkan-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 1139

Error - 1/3/2012 9:36:09 AM | Computer Name = Volkan-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 1/3/2012 9:36:09 AM | Computer Name = Volkan-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 2169

Error - 1/3/2012 9:36:09 AM | Computer Name = Volkan-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 2169

[ Media Center Events ]
Error - 11/24/2011 9:28:49 AM | Computer Name = Volkan-PC | Source = MCUpdate | ID = 0
Description = 7:28:49 AM - Error connecting to the internet. 7:28:49 AM - Unable
to contact server..

Error - 11/24/2011 9:28:55 AM | Computer Name = Volkan-PC | Source = MCUpdate | ID = 0
Description = 7:28:54 AM - Error connecting to the internet. 7:28:54 AM - Unable
to contact server..

Error - 11/24/2011 10:28:59 AM | Computer Name = Volkan-PC | Source = MCUpdate | ID = 0
Description = 8:28:59 AM - Error connecting to the internet. 8:28:59 AM - Unable
to contact server..

Error - 11/24/2011 10:29:05 AM | Computer Name = Volkan-PC | Source = MCUpdate | ID = 0
Description = 8:29:04 AM - Error connecting to the internet. 8:29:04 AM - Unable
to contact server..

Error - 12/9/2011 4:22:53 PM | Computer Name = Volkan-PC | Source = MCUpdate | ID = 0
Description = 2:22:53 PM - Error connecting to the internet. 2:22:53 PM - Unable
to contact server..

Error - 12/9/2011 4:23:26 PM | Computer Name = Volkan-PC | Source = MCUpdate | ID = 0
Description = 2:23:22 PM - Error connecting to the internet. 2:23:22 PM - Unable
to contact server..

Error - 12/14/2011 3:15:52 PM | Computer Name = Volkan-PC | Source = MCUpdate | ID = 0
Description = 1:15:52 PM - Error connecting to the internet. 1:15:52 PM - Unable
to contact server..

Error - 12/14/2011 3:16:05 PM | Computer Name = Volkan-PC | Source = MCUpdate | ID = 0
Description = 1:15:58 PM - Error connecting to the internet. 1:15:58 PM - Unable
to contact server..

Error - 12/14/2011 4:16:10 PM | Computer Name = Volkan-PC | Source = MCUpdate | ID = 0
Description = 2:16:10 PM - Error connecting to the internet. 2:16:10 PM - Unable
to contact server..

Error - 12/14/2011 4:16:16 PM | Computer Name = Volkan-PC | Source = MCUpdate | ID = 0
Description = 2:16:15 PM - Error connecting to the internet. 2:16:15 PM - Unable
to contact server..

[ System Events ]
Error - 3/22/2012 7:21:40 PM | Computer Name = Volkan-PC | Source = Application Popup | ID = 875
Description = Driver atksgt.sys has been blocked from loading.

Error - 3/22/2012 7:21:40 PM | Computer Name = Volkan-PC | Source = Service Control Manager | ID = 7000
Description = The atksgt service failed to start due to the following error: %%1275

Error - 3/22/2012 7:48:53 PM | Computer Name = Volkan-PC | Source = Disk | ID = 262155
Description = The driver detected a controller error on DeviceHarddisk1DR1.

Error - 3/22/2012 7:48:55 PM | Computer Name = Volkan-PC | Source = Disk | ID = 262155
Description = The driver detected a controller error on DeviceHarddisk1DR1.

Error - 3/29/2012 2:21:48 PM | Computer Name = Volkan-PC | Source = iaStor | ID = 262153
Description = The device, DeviceIdeiaStor0, did not respond within the timeout
period.

Error - 3/29/2012 2:22:01 PM | Computer Name = Volkan-PC | Source = iaStor | ID = 262153
Description = The device, DeviceIdeiaStor0, did not respond within the timeout
period.

Error - 4/3/2012 4:02:26 PM | Computer Name = Volkan-PC | Source = ACPI | ID = 327693
Description = : The embedded controller (EC) did not respond within the specified
timeout period. This may indicate that there is an error in the EC hardware or
firmware or that the BIOS is accessing the EC incorrectly. You should check with
your computer manufacturer for an upgraded BIOS. In some situations, this error
may cause the computer to function incorrectly.

Error - 4/3/2012 4:02:26 PM | Computer Name = Volkan-PC | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the Windows
Error Reporting Service service to connect.

Error - 4/4/2012 1:27:56 PM | Computer Name = Volkan-PC | Source = Application Popup | ID = 875
Description = Driver atksgt.sys has been blocked from loading.

Error - 4/4/2012 1:27:56 PM | Computer Name = Volkan-PC | Source = Service Control Manager | ID = 7000
Description = The atksgt service failed to start due to the following error: %%1275


< End of report >
Please do the following:

  • Hold down the Windows key and press R to open a run box
  • type the following text into the run box

    appwiz.cpl

  • This will open your Programs And Features
  • A list of installed programs will populate
  • Remove the following program:
"Searchqu 406 MediaBar"
I did as you instructed but when I open Chrome it still redirects me to the searchnu.com/406 page. Anything else I can try?
Next:

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.


(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time.

Next:

Download ComboFix from one of these locations:

Link 1
Link 2 If using this link, Right Click and select Save As.


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

  • Double click on ComboFix.exe & follow the prompts.

    Notes: Combofix will run without the Recovery Console installed. Skip the Recovery Console part if you're running Vista or Windows 7.

    Note: If you have XP SP3, use the XP SP2 package.
    If Vista or Windows 7, skip the Recovery Console part

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt using Copy / Paste in your next reply.


Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.

Please do not attach the scan results from Combofx. Use copy/paste.

Also please describe how your computer behaves at the moment.
Here's the log from ComboFix ComboFix 12-04-06.03 - Volkan 04/06/2012 11:49:00.1.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3957.2056 [GMT -5:00] Running from: c:\users\[removed]\Downloads\ComboFix.exe AV: AVG Internet Security 2012 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0} FW: AVG Firewall *Enabled* {621CC794-9486-F902-D092-0484E8EA828B} SP: AVG Internet Security 2012 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Volkan\AppData\Local\._Revolution_ c:\users\Volkan\Readme - www.jamendo.com .txt . . ((((((((((((((((((((((((( Files Created from 2012-03-06 to 2012-04-06 ))))))))))))))))))))))))))))))) . . 2012-04-06 17:02 . 2012-04-06 17:02 ——– d—–w- c:\users\Mcx1-VOLKAN-PC\AppData\Local\temp 2012-04-06 17:02 . 2012-04-06 17:02 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-04-03 18:58 . 2012-04-06 17:08 ——– d—–r- c:\users\Volkan\Dropbox 2012-04-03 18:56 . 2012-04-03 18:56 ——– d—–w- c:\programdata\boost_interprocess 2012-04-03 18:55 . 2012-04-06 17:08 ——– d—–w- c:\users\Volkan\AppData\Roaming\Dropbox 2012-03-31 22:41 . 2012-03-31 22:41 ——– d—–w- c:\users\Volkan\AppData\Local\Ilivid Player 2012-03-25 02:23 . 2012-03-25 02:23 ——– d—–w- c:\users\Volkan\AppData\Local\TERA 2012-03-22 19:15 . 2012-03-22 19:15 ——– d—–w- c:\windows\PCHEALTH 2012-03-14 08:04 . 2011-11-19 15:20 5559152 —-a-w- c:\windows\system32\ntoskrnl.exe 2012-03-14 07:13 . 2012-02-03 04:34 3145728 —-a-w- c:\windows\system32\win32k.sys 2012-03-14 07:13 . 2012-02-10 06:36 1544192 —-a-w- c:\windows\system32\DWrite.dll 2012-03-14 07:13 . 2012-02-10 05:38 1077248 —-a-w- c:\windows\SysWow64\DWrite.dll 2012-03-14 07:12 . 2012-01-25 06:38 77312 —-a-w- c:\windows\system32\rdpwsx.dll 2012-03-14 07:12 . 2012-01-25 06:38 149504 —-a-w- c:\windows\system32\rdpcorekmts.dll 2012-03-14 07:12 . 2012-01-25 06:33 9216 —-a-w- c:\windows\system32\rdrmemptylst.exe 2012-03-14 07:12 . 2012-02-17 06:38 1031680 —-a-w- c:\windows\system32\rdpcore.dll 2012-03-14 07:12 . 2012-02-17 04:58 210944 —-a-w- c:\windows\system32\drivers\rdpwd.sys 2012-03-14 07:12 . 2012-02-17 04:57 23552 —-a-w- c:\windows\system32\drivers\tdtcp.sys 2012-03-08 14:20 . 2012-03-08 14:20 ——– d—–w- c:\users\Volkan\AppData\Roaming\PureEdge 2012-03-08 14:19 . 2012-03-08 14:20 ——– d—–w- c:\programdata\PureEdge 2012-03-08 14:19 . 2012-03-08 14:19 ——– d—–w- c:\program files (x86)\IBM . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-03-22 23:48 . 2010-11-12 17:08 45056 —-a-w- c:\windows\system32\acovcnt.exe 2012-02-26 10:21 . 2012-02-26 10:21 162664 —-a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10140.bin 2012-02-17 05:34 . 2012-03-14 07:12 826880 —-a-w- c:\windows\SysWow64\rdpcore.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}] 2012-03-13 11:44 1869152 —-a-w- c:\program files (x86)\AVG Secure Search\10.2.0.3\AVG Secure Search_toolbar.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar] "{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files (x86)\AVG Secure Search\10.2.0.3\AVG Secure Search_toolbar.dll" [2012-03-13 1869152] . [HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}] [HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj.1] [HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj] . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1] @="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}" [HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}] 2007-06-02 01:08 143360 —-a-w- c:\program files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt1.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2012-02-14 22:58 94208 —-a-w- c:\users\Volkan\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2012-02-14 22:58 94208 —-a-w- c:\users\Volkan\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2012-02-14 22:58 94208 —-a-w- c:\users\Volkan\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2012-02-14 22:58 94208 —-a-w- c:\users\Volkan\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Steam"="c:\program files (x86)\Steam\steam.exe" [2011-08-08 1242448] "MtdAcqu"="c:\program files (x86)\Creative\MediaSource5\MtdAcqu.exe" [2008-10-30 278528] "igndlm.exe"="c:\program files (x86)\Download Manager\DLM.exe" [2009-10-27 1103216] "Messenger (Yahoo!)"="c:\progra~2\Yahoo!\Messenger\YahooMessenger.exe" [2010-06-01 5252408] "DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2011-01-20 1305408] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "HControlUser"="c:\program files (x86)\ASUS\ATK Hotkey\HControlUser.exe" [2009-06-19 105016] "ATKOSD2"="c:\program files (x86)\ASUS\ATKOSD2\ATKOSD2.exe" [2009-10-09 6937216] "ATKMEDIA"="c:\program files (x86)\ASUS\ATK Media\DMedia.exe" [2009-08-20 170624] "VolPanel"="c:\program files (x86)\Creative\SB Audigy\Volume Panel\VolPanlu.exe" [2008-12-30 237693] "UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-09-08 421888] "WinampAgent"="c:\program files (x86)\Winamp\winampa.exe" [2010-07-12 74752] "AVG_TRAY"="c:\program files (x86)\AVG\AVG2012\avgtray.exe" [2012-01-24 2416480] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-11-02 59240] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-12-08 421736] "vProt"="c:\program files (x86)\AVG Secure Search\vprot.exe" [2012-03-13 982880] "ROC_roc_dec12"="c:\program files (x86)\AVG Secure Search\ROC_roc_dec12.exe" [2012-01-30 928096] . c:\users\Volkan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ CurseClientStartup.ccip [2011-6-29 0] Dropbox.lnk - c:\users\Volkan\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-2-14 24246216] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ FancyStart daemon.lnk - c:\windows\Installer\{60D6618B-153F-4353-8185-908E676E5888}\_DCE9A4DB2A5F2786140FA3.exe [2010-2-18 12862] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~2\AVG\AVG2012\avgrsa.exe /sync /restart . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2010-02-18 79360] R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2010-02-18 79360] R3 ivusb;Initio Driver for USB Default Controller;c:\windows\system32\DRIVERS\ivusb.sys [x] R3 pnetmdm;PdaNet Modem;c:\windows\system32\DRIVERS\pnetmdm64.sys [x] R3 rak;rak;c:\game\SoftnyxGame\RakionIS\Bin\rakion64.sys [2011-06-24 40056] R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam64.sys [x] S0 AVGIDSEH;AVGIDSEH;c:\windows\system32\DRIVERS\AVGIDSEH.Sys [x] S0 Avgrkx64;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx64.sys [x] S1 Avgfwfd;AVG network filter service;c:\windows\system32\DRIVERS\avgfwd6a.sys [x] S1 Avgldx64;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx64.sys [x] S1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\DRIVERS\avgmfx64.sys [x] S1 Avgtdia;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdia.sys [x] S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S2 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe [x] S2 ASMMAP64;ASMMAP64;c:\program files\ATKGFNEX\ASMMAP64.sys [2007-07-24 14904] S2 avgfws;AVG Firewall;c:\program files (x86)\AVG\AVG2012\avgfws.exe [2011-11-23 2391832] S2 AVGIDSAgent;AVGIDSAgent;c:\program files (x86)\AVG\AVG2012\AVGIDSAgent.exe [2011-10-12 4433248] S2 avgwd;AVG WatchDog;c:\program files (x86)\AVG\AVG2012\avgwdsvc.exe [2011-08-02 192776] S2 rimspci;rimspci;c:\windows\system32\DRIVERS\rimspe64.sys [x] S2 rixdpcie;rixdpcie;c:\windows\system32\DRIVERS\rixdpe64.sys [x] S2 UNS;Intel® Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2009-10-01 2314240] S2 vToolbarUpdater10.2.0;vToolbarUpdater10.2.0;c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\10.2.0\ToolbarUpdater.exe [2012-03-13 918880] S3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\AVGIDSDriver.Sys [x] S3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\DRIVERS\AVGIDSFilter.Sys [x] S3 HECIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x] S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [x] S3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20);c:\windows\system32\DRIVERS\L1C62x64.sys [x] S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x] S3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x] S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x] . . — Other Services/Drivers In Memory — . *NewlyCreated* - WS2IFSL . Contents of the 'Scheduled Tasks' folder . 2012-04-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4220897269-1764641617-2706767991-1001Core.job - c:\users\Volkan\AppData\Local\Google\Update\GoogleUpdate.exe [2010-11-21 19:05] . 2012-04-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4220897269-1764641617-2706767991-1001UA.job - c:\users\Volkan\AppData\Local\Google\Update\GoogleUpdate.exe [2010-11-21 19:05] . . ——— x86-64 ———– . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1] @="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}" [HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}] 2007-06-02 00:52 159744 —-a-w- c:\program files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x64\OverlayIconShlExt1_64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2012-02-14 22:58 97792 —-a-w- c:\users\Volkan\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2012-02-14 22:58 97792 —-a-w- c:\users\Volkan\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2012-02-14 22:58 97792 —-a-w- c:\users\Volkan\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2012-02-14 22:58 97792 —-a-w- c:\users\Volkan\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-10-03 16395880] "RunDLLEntry"="c:\windows\system32\RunDLL32.exe" [2009-07-14 45568] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x1 . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.searchnu.com/406 mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: &Winamp Search - c:\programdata\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = [removed] [removed] 8.8.8.8 Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\10.2.0\ViProtocol.dll . - - - - ORPHANS REMOVED - - - - . Toolbar-Locked - (no file) Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file) Toolbar-10 - (no file) Wow6432Node-HKLM-Run-Setwallpaper - c:\programdata\SetWallpaper.cmd Toolbar-Locked - (no file) Toolbar-10 - (no file) WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file) WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file) WebBrowser-{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - (no file) HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe AddRemove-ASUS_ScreenSaver_GSeries - c:\windows\system32\ASUS_ScreenSaver_GSeries.scr . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11e_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11e_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files (x86)\ASUS\ATK Hotkey\ASLDRSrv.exe c:\program files\ATKGFNEX\GFNEXSrv.exe c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files (x86)\AVG\AVG PC Tuneup 2011\BoostSpeed.exe c:\program files (x86)\ASUS\SmartLogon\sensorsrv.exe c:\program files (x86)\ASUS\ControlDeck\ControlDeckStartUp.exe c:\program files (x86)\ASUS\Wireless Console 3\wcourier.exe c:\program files (x86)\ASUS\ASUS Live Update\ALU.exe c:\program files (x86)\ASUS\ATK Hotkey\HControl.exe c:\program files (x86)\ASUS\ATK Hotkey\ATKOSD.exe c:\program files (x86)\ASUS\ATK Hotkey\KBFiltr.exe c:\program files (x86)\ASUS\ATK Hotkey\WDC.exe c:\program files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe c:\program files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe c:\program files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe c:\program files (x86)\DAEMON Tools Lite\DTShellHlp.exe c:\program files (x86)\Yahoo!\Messenger\ymsgr_tray.exe c:\program files (x86)\Winamp\winamp.exe c:\program files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe c:\program files (x86)\Common Files\Apple\Mobile Device Support\SyncServer.exe . ************************************************************************** . Completion time: 2012-04-06 12:16:42 - machine was rebooted ComboFix-quarantined-files.txt 2012-04-06 17:16 . Pre-Run: 11,373,412,352 bytes free Post-Run: 10,914,533,376 bytes free . - - End Of File - - 4AE2E3D6AA0747740DAB47875E88FCB3 As far as how my computer is behaving, it's a little sluggish when trying to open webpages and some programs like Steam. Other than a general slowness I haven't really noticed anything too out of the ordinary.
Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

KillAll::

DDS::
uStart Page = hxxp://www.searchnu.com/406

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe


Then post the results log using Copy / Paste


Also please describe how your computer behaves at the moment.
Here's the next log. ComboFix 12-04-06.03 - Volkan 04/06/2012 16:04:24.2.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3957.2180 [GMT -5:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe Command switches used :: c:\users\Volkan\Desktop\CFScript.txt AV: AVG Internet Security 2012 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0} FW: AVG Firewall *Enabled* {621CC794-9486-F902-D092-0484E8EA828B} SP: AVG Internet Security 2012 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((( Files Created from 2012-03-06 to 2012-04-06 ))))))))))))))))))))))))))))))) . . 2012-04-06 21:15 . 2012-04-06 21:15 ——– d—–w- c:\users\Mcx1-VOLKAN-PC\AppData\Local\temp 2012-04-06 21:15 . 2012-04-06 21:15 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-04-03 18:58 . 2012-04-06 17:08 ——– d—–r- c:\users\Volkan\Dropbox 2012-04-03 18:56 . 2012-04-03 18:56 ——– d—–w- c:\programdata\boost_interprocess 2012-04-03 18:55 . 2012-04-06 17:08 ——– d—–w- c:\users\Volkan\AppData\Roaming\Dropbox 2012-03-31 22:41 . 2012-03-31 22:41 ——– d—–w- c:\users\Volkan\AppData\Local\Ilivid Player 2012-03-25 02:23 . 2012-03-25 02:23 ——– d—–w- c:\users\Volkan\AppData\Local\TERA 2012-03-22 19:15 . 2012-03-22 19:15 ——– d—–w- c:\windows\PCHEALTH 2012-03-14 08:04 . 2011-11-19 15:20 5559152 —-a-w- c:\windows\system32\ntoskrnl.exe 2012-03-14 08:04 . 2011-11-19 14:50 3968368 —-a-w- c:\windows\SysWow64\ntkrnlpa.exe 2012-03-14 08:04 . 2011-11-19 14:50 3913584 —-a-w- c:\windows\SysWow64\ntoskrnl.exe 2012-03-14 07:13 . 2012-02-03 04:34 3145728 —-a-w- c:\windows\system32\win32k.sys 2012-03-14 07:13 . 2012-02-10 06:36 1544192 —-a-w- c:\windows\system32\DWrite.dll 2012-03-14 07:13 . 2012-02-10 05:38 1077248 —-a-w- c:\windows\SysWow64\DWrite.dll 2012-03-14 07:12 . 2012-01-25 06:38 77312 —-a-w- c:\windows\system32\rdpwsx.dll 2012-03-14 07:12 . 2012-01-25 06:38 149504 —-a-w- c:\windows\system32\rdpcorekmts.dll 2012-03-14 07:12 . 2012-01-25 06:33 9216 —-a-w- c:\windows\system32\rdrmemptylst.exe 2012-03-14 07:12 . 2012-02-17 06:38 1031680 —-a-w- c:\windows\system32\rdpcore.dll 2012-03-14 07:12 . 2012-02-17 05:34 826880 —-a-w- c:\windows\SysWow64\rdpcore.dll 2012-03-14 07:12 . 2012-02-17 04:58 210944 —-a-w- c:\windows\system32\drivers\rdpwd.sys 2012-03-14 07:12 . 2012-02-17 04:57 23552 —-a-w- c:\windows\system32\drivers\tdtcp.sys 2012-03-08 14:20 . 2012-03-08 14:20 ——– d—–w- c:\users\Volkan\AppData\Roaming\PureEdge 2012-03-08 14:19 . 2012-03-08 14:20 ——– d—–w- c:\programdata\PureEdge 2012-03-08 14:19 . 2012-03-08 14:19 ——– d—–w- c:\program files (x86)\IBM . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-04-06 21:18 . 2010-11-12 17:08 45056 —-a-w- c:\windows\system32\acovcnt.exe 2012-02-26 10:21 . 2012-02-26 10:21 162664 —-a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10140.bin . . ((((((((((((((((((((((((((((( SnapShot@2012-04-06_17.07.28 ))))))))))))))))))))))))))))))))))))))))) . - 2009-07-14 04:54 . 2012-04-04 20:31 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2009-07-14 04:54 . 2012-04-06 17:06 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2009-07-14 04:54 . 2012-04-04 20:31 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2009-07-14 04:54 . 2012-04-06 17:06 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2009-07-14 04:54 . 2012-04-04 20:31 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2009-07-14 04:54 . 2012-04-06 17:06 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2010-07-10 03:14 . 2012-04-06 21:19 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2010-07-10 03:14 . 2012-04-06 17:09 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2010-07-10 03:14 . 2012-04-06 17:09 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2010-07-10 03:14 . 2012-04-06 21:19 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2010-07-10 03:14 . 2012-04-06 21:19 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2010-07-10 03:14 . 2012-04-06 17:09 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2010-07-10 00:04 . 2012-04-06 17:09 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2010-07-10 00:04 . 2012-04-06 21:19 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2010-07-10 00:04 . 2012-04-06 21:19 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2010-07-10 00:04 . 2012-04-06 17:09 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2012-04-06 17:06 . 2012-04-06 17:06 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat + 2012-04-06 21:17 . 2012-04-06 21:17 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat - 2012-04-06 17:06 . 2012-04-06 17:06 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat + 2012-04-06 21:17 . 2012-04-06 21:17 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat + 2010-07-10 01:46 . 2012-04-06 20:47 272680 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S3.bin - 2009-07-14 02:36 . 2012-04-04 17:34 633180 c:\windows\system32\perfh009.dat + 2009-07-14 02:36 . 2012-04-06 17:13 633180 c:\windows\system32\perfh009.dat + 2009-07-14 02:36 . 2012-04-06 17:13 110782 c:\windows\system32\perfc009.dat - 2009-07-14 02:36 . 2012-04-04 17:34 110782 c:\windows\system32\perfc009.dat - 2009-07-14 05:01 . 2012-04-06 17:04 309036 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat + 2009-07-14 05:01 . 2012-04-06 21:16 309036 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat + 2011-08-10 21:21 . 2012-04-06 21:16 1284136 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-4220897269-1764641617-2706767991-1001-12288.dat - 2011-08-10 21:21 . 2012-04-06 17:04 1284136 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-4220897269-1764641617-2706767991-1001-12288.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}] 2012-03-13 11:44 1869152 —-a-w- c:\program files (x86)\AVG Secure Search\10.2.0.3\AVG Secure Search_toolbar.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar] "{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files (x86)\AVG Secure Search\10.2.0.3\AVG Secure Search_toolbar.dll" [2012-03-13 1869152] . [HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}] [HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj.1] [HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj] . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1] @="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}" [HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}] 2007-06-02 01:08 143360 —-a-w- c:\program files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt1.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2012-02-14 22:58 94208 —-a-w- c:\users\Volkan\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2012-02-14 22:58 94208 —-a-w- c:\users\Volkan\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2012-02-14 22:58 94208 —-a-w- c:\users\Volkan\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2012-02-14 22:58 94208 —-a-w- c:\users\Volkan\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Steam"="c:\program files (x86)\Steam\steam.exe" [2011-08-08 1242448] "MtdAcqu"="c:\program files (x86)\Creative\MediaSource5\MtdAcqu.exe" [2008-10-30 278528] "igndlm.exe"="c:\program files (x86)\Download Manager\DLM.exe" [2009-10-27 1103216] "Messenger (Yahoo!)"="c:\progra~2\Yahoo!\Messenger\YahooMessenger.exe" [2010-06-01 5252408] "DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2011-01-20 1305408] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "HControlUser"="c:\program files (x86)\ASUS\ATK Hotkey\HControlUser.exe" [2009-06-19 105016] "ATKOSD2"="c:\program files (x86)\ASUS\ATKOSD2\ATKOSD2.exe" [2009-10-09 6937216] "ATKMEDIA"="c:\program files (x86)\ASUS\ATK Media\DMedia.exe" [2009-08-20 170624] "VolPanel"="c:\program files (x86)\Creative\SB Audigy\Volume Panel\VolPanlu.exe" [2008-12-30 237693] "UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-09-08 421888] "WinampAgent"="c:\program files (x86)\Winamp\winampa.exe" [2010-07-12 74752] "AVG_TRAY"="c:\program files (x86)\AVG\AVG2012\avgtray.exe" [2012-01-24 2416480] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-11-02 59240] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-12-08 421736] "vProt"="c:\program files (x86)\AVG Secure Search\vprot.exe" [2012-03-13 982880] "ROC_roc_dec12"="c:\program files (x86)\AVG Secure Search\ROC_roc_dec12.exe" [2012-01-30 928096] . c:\users\Volkan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ CurseClientStartup.ccip [2011-6-29 0] Dropbox.lnk - c:\users\Volkan\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-2-14 24246216] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ FancyStart daemon.lnk - c:\windows\Installer\{60D6618B-153F-4353-8185-908E676E5888}\_DCE9A4DB2A5F2786140FA3.exe [2010-2-18 12862] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~2\AVG\AVG2012\avgrsa.exe /sync /restart . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2010-02-18 79360] R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2010-02-18 79360] R3 ivusb;Initio Driver for USB Default Controller;c:\windows\system32\DRIVERS\ivusb.sys [x] R3 pnetmdm;PdaNet Modem;c:\windows\system32\DRIVERS\pnetmdm64.sys [x] R3 rak;rak;c:\game\SoftnyxGame\RakionIS\Bin\rakion64.sys [2011-06-24 40056] R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam64.sys [x] S0 AVGIDSEH;AVGIDSEH;c:\windows\system32\DRIVERS\AVGIDSEH.Sys [x] S0 Avgrkx64;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx64.sys [x] S1 Avgfwfd;AVG network filter service;c:\windows\system32\DRIVERS\avgfwd6a.sys [x] S1 Avgldx64;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx64.sys [x] S1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\DRIVERS\avgmfx64.sys [x] S1 Avgtdia;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdia.sys [x] S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S2 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe [x] S2 ASMMAP64;ASMMAP64;c:\program files\ATKGFNEX\ASMMAP64.sys [2007-07-24 14904] S2 avgfws;AVG Firewall;c:\program files (x86)\AVG\AVG2012\avgfws.exe [2011-11-23 2391832] S2 AVGIDSAgent;AVGIDSAgent;c:\program files (x86)\AVG\AVG2012\AVGIDSAgent.exe [2011-10-12 4433248] S2 avgwd;AVG WatchDog;c:\program files (x86)\AVG\AVG2012\avgwdsvc.exe [2011-08-02 192776] S2 rimspci;rimspci;c:\windows\system32\DRIVERS\rimspe64.sys [x] S2 rixdpcie;rixdpcie;c:\windows\system32\DRIVERS\rixdpe64.sys [x] S2 UNS;Intel® Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2009-10-01 2314240] S2 vToolbarUpdater10.2.0;vToolbarUpdater10.2.0;c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\10.2.0\ToolbarUpdater.exe [2012-03-13 918880] S3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\AVGIDSDriver.Sys [x] S3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\DRIVERS\AVGIDSFilter.Sys [x] S3 HECIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x] S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [x] S3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20);c:\windows\system32\DRIVERS\L1C62x64.sys [x] S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x] S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x] . . Contents of the 'Scheduled Tasks' folder . 2012-04-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4220897269-1764641617-2706767991-1001Core.job - c:\users\Volkan\AppData\Local\Google\Update\GoogleUpdate.exe [2010-11-21 19:05] . 2012-04-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4220897269-1764641617-2706767991-1001UA.job - c:\users\Volkan\AppData\Local\Google\Update\GoogleUpdate.exe [2010-11-21 19:05] . . ——— x86-64 ———– . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1] @="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}" [HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}] 2007-06-02 00:52 159744 —-a-w- c:\program files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x64\OverlayIconShlExt1_64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2012-02-14 22:58 97792 —-a-w- c:\users\Volkan\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2012-02-14 22:58 97792 —-a-w- c:\users\Volkan\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2012-02-14 22:58 97792 —-a-w- c:\users\Volkan\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2012-02-14 22:58 97792 —-a-w- c:\users\Volkan\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-10-03 16395880] "SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU] "RunDLLEntry"="c:\windows\system32\RunDLL32.exe" [2009-07-14 45568] . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: &Winamp Search - c:\programdata\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = [removed] [removed] 8.8.8.8 Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\10.2.0\ViProtocol.dll . - - - - ORPHANS REMOVED - - - - . Toolbar-Locked - (no file) Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file) Toolbar-10 - (no file) WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file) WebBrowser-{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - (no file) . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11e_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11e_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files (x86)\ASUS\ATK Hotkey\ASLDRSrv.exe c:\program files\ATKGFNEX\GFNEXSrv.exe c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe c:\program files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe c:\program files (x86)\ASUS\ControlDeck\ControlDeckStartUp.exe c:\program files (x86)\ASUS\ASUS Live Update\ALU.exe c:\program files (x86)\AVG\AVG PC Tuneup 2011\BoostSpeed.exe c:\program files (x86)\ASUS\Wireless Console 3\wcourier.exe c:\program files (x86)\ASUS\SmartLogon\sensorsrv.exe c:\program files (x86)\ASUS\ATK Hotkey\HControl.exe c:\program files (x86)\ASUS\ATK Hotkey\ATKOSD.exe c:\program files (x86)\ASUS\ATK Hotkey\KBFiltr.exe c:\program files (x86)\ASUS\ATK Hotkey\WDC.exe c:\program files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe c:\program files (x86)\Yahoo!\Messenger\ymsgr_tray.exe c:\program files (x86)\DAEMON Tools Lite\DTShellHlp.exe . ************************************************************************** . Completion time: 2012-04-06 16:26:18 - machine was rebooted ComboFix-quarantined-files.txt 2012-04-06 21:26 ComboFix2.txt 2012-04-06 17:16 . Pre-Run: 10,988,929,024 bytes free Post-Run: 10,909,011,968 bytes free . - - End Of File - - DFDDE39CF9E4B01EDD662F5268702945
Good job Posted Image

The following will implement some cleanup procedures as well as reset System Restore points:

For XP:
  • Click START run
  • Now type ComboFix /Uninstall in the runbox and click OK. Note the space between the X and the /, it needs to be there.

For Vista / Windows 7
  • Click START Search
  • Now type ComboFix /Uninstall in the runbox and click OK. Note the space between the X and the /, it needs to be there.


Here's my usual all clean post

To be on the safe side, I would also change all my passwords.

This infection appears to have been cleaned, but as the malware could be configured to run any program a remote attacker requires, it's impossible to be 100% sure that any machine is clean.


Log looks good :D


  • Update your AntiVirus Software - It is imperative that you update your Antivirus software at least once a week
    (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

  • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer.
    Without a firewall your computer is succeptible to being hacked and taken over.
    I am very serious about this and see it happen almost every day with my clients.
    Simply using a Firewall in its default configuration can lower your risk greatly.
  • Securing Your Web Browser
    This paper will help you configure your web browser for safer internet surfing.

  • Using a secure browser plugin M86 SecureBrowsing makes it safe to search, surf and socialize online. This free browser plug-in displays security icons next to links on search engines and social networking sites like Facebook, Twitter and LinkedIn, so you'll know which pages are safe and which ones to avoid.

    •Free browser plug-in for Internet Explorer and Firefox
    •Real-time safety ratings
    •Ideal for Facebook, Twitter and LinkedIn

  • JAVA Click this link and click on the Free JAVA Download

  • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly.
    This will ensure your computer has always the latest security updates available installed on your computer.
    If there are new updates to install, install them immediately, reboot your computer, and revisit the site
    until there are no more critical updates.

Only run one Anti-Virus and Firewall program.


I would suggest you read:
PC Safety and Security–What Do I Need?.
How to Prevent Malware:
When I opened Chrome up it still directed me to the searchnu.com/406 page. It was still directing me from Chrome because the page was still saved as the default home page. If the logs look good then I should be alright then?
I did and I don't get anymore redirects. Sorry, I forgot to answer your question on how my computer was running. It seems to be running fine now. Greatly appreciate the help.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI