This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Search Nu Hijack [Closed]

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

All my browsers on the computer have been going to searchnu.com Just want to get rid of it

HAve attached the OTL.txt file

Thank you in advance



OTL logfile created on: 05/04/2012 8:56:08 PM - Run 2
OTL by OldTimer - Version 3.2.39.2 Folder = C:\Users\Amish\Downloads
Windows Vista Home Premium Edition (Version = 6.0.6000) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6000.17037)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

2.87 Gb Total Physical Memory | 1.59 Gb Available Physical Memory | 55.19% Memory free
5.95 Gb Paging File | 4.62 Gb Available in Paging File | 77.65% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 456.91 Gb Total Space | 46.39 Gb Free Space | 10.15% Space Free | Partition Type: NTFS
Drive D: | 8.85 Gb Total Space | 1.21 Gb Free Space | 13.64% Space Free | Partition Type: NTFS
Drive F: | 1863.01 Gb Total Space | 839.07 Gb Free Space | 45.04% Space Free | Partition Type: NTFS
Drive T: | 931.51 Gb Total Space | 0.65 Gb Free Space | 0.07% Space Free | Partition Type: NTFS

Computer Name: DAD | User Name: Amish | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Amish\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Windows\System32\Macromed\Flash\FlashUtil10e.exe (Adobe Systems, Inc.)
PRC - C:\Windows\System32\jureg.exe (Sun Microsystems, Inc.)
PRC - C:\Users\Public\Documents\Symantec\NortonProtectionMemo.exe (Symantec Corporation)
PRC - C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe (Acronis)
PRC - C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
PRC - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
PRC - C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\X-Rite\ColorMunki Photo\Tools\ColorMunki Photo Tray.exe ()
PRC - C:\Program Files\Common Files\X-Rite\InstrumentService\colormunki\ColorMunki.exe ()
PRC - C:\Program Files\Common Files\X-Rite\InstrumentService\wnoted.exe ()
PRC - C:\Program Files\Photodex\ProShowProducer\scsiaccess.exe ()
PRC - C:\Program Files\Adobe\Adobe Photoshop Lightroom 1.4\apdproxy.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
PRC - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe ()
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Program Files\Snapfish Picture Mover\SnapfishMediaDetector.exe ()
PRC - C:\hp\support\hpsysdrv.exe (Hewlett-Packard Company)
PRC - C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe (OsdMaestro)
PRC - C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
PRC - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
PRC - c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe (Symantec Corporation)
PRC - C:\Windows\System32\schtasks.exe (Microsoft Corporation)
PRC - C:\Windows\System32\conime.exe (Microsoft Corporation)
PRC - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\acrotray.exe (Adobe Systems Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\WinRAR\RarExt.dll ()
MOD - C:\Program Files\Acronis\TrueImageHome\fox.dll ()
MOD - C:\Program Files\X-Rite\ColorMunki Photo\Tools\ColorMunki Photo Tray.exe ()
MOD - C:\Program Files\Common Files\X-Rite\InstrumentService\colormunki\ColorMunki.exe ()
MOD - C:\Program Files\Common Files\X-Rite\InstrumentService\colormunki\colormunki.dll ()
MOD - C:\Program Files\Common Files\X-Rite\InstrumentService\colormunki\XRiteDevice.dll ()
MOD - C:\Program Files\Common Files\X-Rite\InstrumentService\wnoted.exe ()
MOD - C:\Program Files\X-Rite\ColorMunki Photo\Tools\QtGui4.dll ()
MOD - C:\Program Files\X-Rite\ColorMunki Photo\Tools\QtCore4.dll ()
MOD - C:\Program Files\X-Rite\ColorMunki Photo\Tools\imageformats\qtiff4.dll ()
MOD - C:\Program Files\X-Rite\ColorMunki Photo\Tools\imageformats\qjpeg4.dll ()
MOD - C:\Program Files\Snapfish Picture Mover\SnapfishMediaDetector.exe ()


========== Win32 Services (SafeList) ==========

SRV - (Steam Client Service) – C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (AcrSch2Svc) – C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
SRV - (ScsiAccess) – C:\Program Files\Photodex\ProShowProducer\scsiaccess.exe ()
SRV - (LiveUpdate Notice Service) – C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (Symantec Corporation)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (Symantec Core LC) – C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe ()
SRV - (LiveUpdate) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_2.EXE (Symantec Corporation)
SRV - (Automatic LiveUpdate Scheduler) – C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (ISPwdSvc) – c:\Program Files\Norton Internet Security\isPwdSvc.exe (Symantec Corporation)
SRV - (comHost) – c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe (Symantec Corporation)
SRV - (LiveUpdate Notice Ex) – c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (CLTNetCnService) – c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccSetMgr) – c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccEvtMgr) – c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (SymAppCore) – c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe (Symantec Corporation)


========== Driver Services (SafeList) ==========

DRV - (NwlnkFwd) – system32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – system32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) – system32\DRIVERS\ipinip.sys File not found
DRV - (blbdrive) – C:\Windows\system32\drivers\blbdrive.sys File not found
DRV - (timounter) – C:\Windows\System32\drivers\timntr.sys (Acronis)
DRV - (tifsfilter) – C:\Windows\System32\drivers\tifsfilt.sys (Acronis)
DRV - (snapman) – C:\Windows\System32\drivers\snapman.sys (Acronis)
DRV - (tdrpman) – C:\Windows\System32\drivers\tdrpman.sys (Acronis)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (IDSvix86) – C:\ProgramData\Symantec\Definitions\SymcData\idsdefs\20080208.001\IDSvix86.sys (Symantec Corporation)
DRV - (NAVEX15) – C:\ProgramData\Symantec\Definitions\VirusDefs\20071210.002\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Symantec\Definitions\VirusDefs\20071210.002\NAVENG.SYS (Symantec Corporation)
DRV - (colormunki) – C:\Windows\System32\drivers\colormunki.sys (Thesycon GmbH, Germany)
DRV - (nvstor32) – C:\Windows\System32\drivers\nvstor32.sys (NVIDIA Corporation)
DRV - (SymEvent) – C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\Windows\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (SRTSPL) – C:\Windows\System32\drivers\srtspl.sys (Symantec Corporation)
DRV - (SRTSPX) – C:\Windows\System32\drivers\srtspx.sys (Symantec Corporation)
DRV - (SRTSP) – C:\Windows\System32\drivers\srtsp.sys (Symantec Corporation)
DRV - (SYMTDI) – C:\Windows\System32\drivers\symtdi.sys (Symantec Corporation)
DRV - (SYMFW) – C:\Windows\System32\drivers\symfw.sys (Symantec Corporation)
DRV - (SYMIDS) – C:\Windows\System32\drivers\symids.sys (Symantec Corporation)
DRV - (SYMNDISV) – C:\Windows\System32\drivers\symndisv.sys (Symantec Corporation)
DRV - (SYMREDRV) – C:\Windows\System32\drivers\symredrv.sys (Symantec Corporation)
DRV - (SYMDNS) – C:\Windows\System32\drivers\symdns.sys (Symantec Corporation)
DRV - (SPBBCDrv) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (HSXHWBS2) – C:\Windows\System32\drivers\HSXHWBS2.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) – C:\Windows\System32\drivers\HSX_DP.sys (Conexant Systems, Inc.)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (PdiPorts) – C:\Windows\System32\drivers\PdiPorts.sys (Portrait Displays, Inc.)
DRV - (WSDPrintDevice) – C:\Windows\System32\drivers\WSDPrint.sys (Microsoft Corporation)
DRV - (WSDScan) – C:\Windows\System32\drivers\WSDScan.sys (Microsoft Corporation)
DRV - (Ps2) – C:\Windows\System32\drivers\PS2.sys (Hewlett-Packard Company)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
IE - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
IE - HKLM\..\SearchScopes\{2A17C834-32F5-4A4F-8D13-9EE1899F5364}: "URL" = http://search.live.com/results.aspx?q={sea…amp;FORM=HVDCS7
IE - HKLM\..\SearchScopes\{828E4B64-759B-4F32-A907-4FE331004BD4}: "URL" = http://www.ask.com/web?q={searchTerms}&l=dis&o=cahpd
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-results.com/sr?src=ieb&a…q={searchTerms}
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2A59}: "URL" = http://search.imesh.com/web?src=ieb&sy…q={searchTerms}
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2801948
IE - HKLM\..\SearchScopes\{D0BDB87D-C866-450A-989C-A28A5866DC64}: "URL" = http://ca.search.yahoo.com/search?p={searc…&fr=hp-pvdt

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.searchqu.com/406
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {37483b40-c254-4a72-bda4-22ee90182c1e} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
IE - HKCU\..\SearchScopes\{2A17C834-32F5-4A4F-8D13-9EE1899F5364}: "URL" = http://search.live.com/results.aspx?q={sea…amp;FORM=HVDCS7
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…soft:{language}
IE - HKCU\..\SearchScopes\{828E4B64-759B-4F32-A907-4FE331004BD4}: "URL" = http://www.ask.com/web?q={searchTerms}&l=dis&o=cahpd
IE - HKCU\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-results.com/sr?src=ieb&a…q={searchTerms}
IE - HKCU\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2A59}: "URL" = http://search.imesh.com/web?src=ieb&sy…q={searchTerms}
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2801948
IE - HKCU\..\SearchScopes\{D0BDB87D-C866-450A-989C-A28A5866DC64}: "URL" = http://ca.search.yahoo.com/search?p={searc…&fr=hp-pvdt
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.50917.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/RhapsodyPlayerEngine,version=1.0: C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 3.1.17\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2012/01/23 20:49:18 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 3.1.17\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2011/03/07 09:56:27 | 000,000,000 | —D | M]

[2012/03/28 17:38:24 | 000,000,000 | —D | M] (No name found) – C:\Users\Amish\AppData\Roaming\Mozilla\Extensions
[2011/07/18 10:13:35 | 000,000,000 | —D | M] (No name found) – C:\Users\Amish\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2010/09/15 04:50:38 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2010/08/12 04:21:14 | 000,002,486 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\iMeshWebSearch.xml
[2012/01/29 16:18:07 | 000,002,519 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\Search_Results.xml

O1 HOSTS File: ([2006/09/18 17:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Reg Error: Value error.) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBHO.dll (Symantec Corporation)
O2 - BHO: (UrlHelper Class) - {474597C5-AB09-49d6-A4D5-2E8D7341384E} - C:\PROGRA~1\IMESHA~1\MediaBar\Datamngr\IEBHO.dll File not found
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found.
O2 - BHO: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~1\WI371A~1\Datamngr\ToolBar\searchqudtx.dll File not found
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Show Norton Toolbar) - {90222687-F593-4738-B738-FBEE9C7B26DF} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~1\WI371A~1\Datamngr\ToolBar\searchqudtx.dll File not found
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {37483B40-C254-4A72-BDA4-22EE90182C1E} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Acronis Scheduler2 Service] C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
O4 - HKLM..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe (Acronis)
O4 - HKLM..\Run: [Adobe Photo Downloader] C:\Program Files\Adobe\Adobe Photoshop Lightroom 1.4\apdproxy.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ccApp] c:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [KBD] C:\hp\KBD\KbdStub.exe ()
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvSvc] C:\Windows\System32\nvsvc.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [OsdMaestro] C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe (OsdMaestro)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SNM] C:\Program Files\SpyNoMore\SNM.exe /startup File not found
O4 - HKLM..\Run: [SunJavaUpdateReg] C:\Windows\System32\jureg.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [Symantec PIF AlertEng] C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (Symantec Corporation)
O4 - HKLM..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [wnoted] C:\Program Files\Common Files\X-Rite\InstrumentService\wnoted.exe ()
O4 - HKCU..\Run: [NCH Swift Sound] C:\Users\Amish\AppData\Roaming\975DAD.exe (Provtech Limited)
O4 - HKCU..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKLM..\RunOnce: [Launcher] C:\Windows\SMINST\Launcher.exe (soft thinks)
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Append to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\PLUGINS\NPDocBox.dll (Intertrust Technologies, Inc.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{762A9203-78A2-4D67-B599-AEB6871A31F2}: DhcpNameServer = [removed]
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img27.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img27.jpg
O30 - LSA: Authentication Packages - (relog_ap) - C:\Windows\System32\relog_ap.dll (Acronis)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/08/23 23:40:52 | 000,000,074 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{158a4bd8-dc66-11dc-bb47-001d60c20cf8}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe wa6.vbs
O33 - MountPoints2\{5897d8fc-7080-11dd-8ee9-001d60c20cf8}\Shell\AutoRun\command - "" = F:\ – File not found
O33 - MountPoints2\{5897d8fc-7080-11dd-8ee9-001d60c20cf8}\Shell\explore\Command - "" = F:\RECYCLER\INFO.exe
O33 - MountPoints2\{5897d8fc-7080-11dd-8ee9-001d60c20cf8}\Shell\open\Command - "" = F:\RECYCLER\INFO.exe
O33 - MountPoints2\{65af461b-cda4-11dd-be1e-001d60c20cf8}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe wa6.vbs
O33 - MountPoints2\{e3e98251-57e8-11de-861f-001d60c20cf8}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe wa6.vbs
O33 - MountPoints2\{eccede6f-7cd8-11de-b2b6-001d60c20cf8}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe wa6.vbs
O33 - MountPoints2\{efd80d14-a8f1-11e0-80c2-001d60c20cf8}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe wa6.vbs
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2012/03/28 15:42:30 | 000,000,000 | —D | C] – C:\Program Files\Image Finder
[2012/03/28 15:36:14 | 000,000,000 | —D | C] – C:\Users\Amish\Desktop\DHARA

========== Files - Modified Within 30 Days ==========

[2012/04/05 21:00:00 | 000,000,420 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{6ED5FB7D-A7C0-4A74-AAD6-796CE0857E7B}.job
[2012/04/05 20:53:50 | 000,622,906 | —- | M] () – C:\Windows\System32\perfh009.dat
[2012/04/05 20:53:50 | 000,108,122 | —- | M] () – C:\Windows\System32\perfc009.dat
[2012/04/05 20:51:39 | 000,000,418 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{C605F679-9461-4FE7-895D-46EB09FD9008}.job
[2012/04/05 20:47:28 | 000,000,880 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/04/05 20:47:28 | 000,000,378 | —- | M] () – C:\Windows\tasks\Registry Reviver-Amish-Startup.job
[2012/04/05 20:47:19 | 000,003,456 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/04/05 20:47:19 | 000,003,456 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/04/05 20:47:14 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/03/28 17:26:23 | 000,002,255 | —- | M] () – C:\Users\Amish\Application Data\Microsoft\Internet Explorer\Quick Launch\iTunes.lnk
[2012/03/28 17:09:23 | 000,000,884 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/03/28 15:42:30 | 000,000,794 | —- | M] () – C:\Users\Public\Desktop\Image Finder.lnk
[2012/03/26 21:34:58 | 000,000,546 | —- | M] () – C:\Windows\tasks\Norton Internet Security - Run Full System Scan - Amish.job

========== Files Created - No Company Name ==========

[2012/03/28 15:42:30 | 000,000,806 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Image Finder.lnk
[2012/03/28 15:42:30 | 000,000,794 | —- | C] () – C:\Users\Public\Desktop\Image Finder.lnk
[2012/02/11 14:32:13 | 000,002,048 | —- | C] () – C:\Users\Amish\AppData\Roaming\Photobook Designer Prefs
[2012/02/01 13:38:13 | 000,001,152 | —- | C] () – C:\Windows\System32\windrv.sys
[2011/01/13 18:34:54 | 000,102,400 | —- | C] () – C:\Windows\RegBootClean.exe
[2011/01/13 17:54:36 | 000,000,036 | —- | C] () – C:\Users\Amish\AppData\Local\housecall.guid.cache

========== LOP Check ==========

[2007/12/29 17:21:18 | 000,000,000 | —D | M] – C:\Users\Amish\AppData\Roaming\.BitTornado
[2007/12/14 01:41:19 | 000,000,000 | —D | M] – C:\Users\Amish\AppData\Roaming\Anthropics
[2011/03/07 09:56:25 | 000,000,000 | —D | M] – C:\Users\Amish\AppData\Roaming\InterTrust
[2010/12/13 16:38:32 | 000,000,000 | —D | M] – C:\Users\Amish\AppData\Roaming\MusicNet
[2008/08/29 03:48:15 | 000,000,000 | —D | M] – C:\Users\Amish\AppData\Roaming\MyPublisher
[2010/12/14 17:28:15 | 000,000,000 | —D | M] – C:\Users\Amish\AppData\Roaming\NCH Swift Sound
[2008/05/20 14:57:13 | 000,000,000 | —D | M] – C:\Users\Amish\AppData\Roaming\Netscape
[2008/09/12 15:07:40 | 000,000,000 | —D | M] – C:\Users\Amish\AppData\Roaming\Nikon
[2012/02/11 14:31:44 | 000,000,000 | —D | M] – C:\Users\Amish\AppData\Roaming\Photobook Designer
[2008/05/20 14:56:39 | 000,000,000 | —D | M] – C:\Users\Amish\AppData\Roaming\Photodex
[2010/12/14 01:39:14 | 000,000,000 | —D | M] – C:\Users\Amish\AppData\Roaming\Recordpad
[2009/07/12 12:20:44 | 000,000,000 | —D | M] – C:\Users\Amish\AppData\Roaming\SiteBuilder.1092AF29A5D2D6F129EC9E969ADB342C4F09EC7B.1
[2007/12/10 21:53:55 | 000,000,000 | —D | M] – C:\Users\Amish\AppData\Roaming\Snapfish
[2011/01/13 18:34:47 | 000,000,000 | -HSD | M] – C:\Users\Amish\AppData\Roaming\SystemProc
[2011/07/18 10:13:34 | 000,000,000 | —D | M] – C:\Users\Amish\AppData\Roaming\Thunderbird
[2008/07/27 09:10:57 | 000,000,000 | —D | M] – C:\Users\Amish\AppData\Roaming\Vso
[2012/04/05 20:47:28 | 000,000,378 | —- | M] () – C:\Windows\Tasks\Registry Reviver-Amish-Startup.job
[2012/03/28 17:41:36 | 000,032,608 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2012/04/05 21:00:00 | 000,000,420 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{6ED5FB7D-A7C0-4A74-AAD6-796CE0857E7B}.job
[2012/04/05 20:51:39 | 000,000,418 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{C605F679-9461-4FE7-895D-46EB09FD9008}.job

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 216 bytes -> C:\ProgramData\TEMP:1957F8A9

< End of report >

Attachments:

:welcome:

Please just copy and paste the logs we ask for into your reply in lew of attaching them unless your asked to attach a report, its easier for us to analyze.


I would like you to download and run Malwarebytes, besure everything is checked for removal including Whitesmoke if it finds it , post the log please



Please download Malwarebytes from Here or Here

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the report please





Then run OTL this way and post a new log please, you can skip the download instructions unless you have already removed OTL

OTL by OldTimer
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Click the "Scan All Users" checkbox.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI