This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

searchqu and searchnu406 removal [Solved]

30 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi Yes I do. When I am busy at work I am not available for lengthy computer work like this one. Even this short text takes 10 min due to jumping cursor, disappearance of words and unexpected changes of screen. I shall y trto sort out McAfee today and do those scans. I thought you need 3 days to close. C
Here is OTL fixing : (the next one will follow after disabling McA) All processes killed Error: Unable to interpret in the current context! ========== SERVICES/DRIVERS ========== ========== FILES ========== File\Folder C:\Users\Admin\Downloads\dsobserver.zip not found. File\Folder C:\Users\Admin\Downloads\template.zip not found. File\Folder C:\Users\Christina\Downloads\7zip_Setup.exe not found. File\Folder C:\Users\Christina\Downloads\SoftonicDownloader_for_vit-registry-fix.exe not found. File\Folder D:\CHRISSAMSUNG\Backup Set 2012-03-18 195224\Backup Files 2012-03-18 195224\Backup files 1.zip not found. File\Folder D:\CHRISSAMSUNG\Backup Set 2012-04-03 194033\Backup Files 2012-04-08 190147\Backup files 1.zip not found. File\Folder D:\CHRISSAMSUNG\Backup Set 2012-04-03 194033\Backup Files 2012-04-08 190147\Backup files 3.zip not found. File\Folder D:\CHRISSAMSUNG\Backup Set 2012-04-03 194033\Backup Files 2012-04-08 190147\Backup files 35.zip not found. File\Folder D:\CHRISSAMSUNG\Backup Set 2012-04-03 194033\Backup Files 2012-04-08 190147\Backup files 37.zip not found. File\Folder D:\CHRISSAMSUNG\Backup Set 2012-04-03 194033\Backup Files 2012-04-08 190147\Backup files 4.zip not found. File\Folder D:\CHRISSAMSUNG\Backup Set 2012-04-12 012441\Backup Files 2012-04-12 012441\Backup files 2.zip not found. ========== COMMANDS ========== [EMPTYTEMP] User: Admin ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 0 bytes ->Google Chrome cache emptied: 0 bytes ->Flash cache emptied: 0 bytes User: All Users User: Christina ->Temp folder emptied: 9375080 bytes ->Temporary Internet Files folder emptied: 5342839 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 257177836 bytes ->Google Chrome cache emptied: 0 bytes ->Flash cache emptied: 2530 bytes User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Public ->Temp folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 149382 bytes RecycleBin emptied: 618496 bytes Total Files Cleaned = 260.00 mb OTL by OldTimer - Version 3.2.40.0 log created on 04212012_191535 Files\Folders moved on Reboot… File\Folder C:\Users\Christina\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TIJV9WIY\ADSAdClient31[11].htm not found! Registry entries deleted on Reboot…
Hi
since 6pm tonight I was trying to disable McA in the course of 4 connections and their remote control. Each time they would leave some parts of the software. Finally I lost patience and uninstalled. The most difficult problem now is writing, I feel I could smash the laptop with pleasure .
Here is the scan:

OTL logfile created on: 4/21/2012 10:24:40 PM - Run 5
OTL by OldTimer - Version 3.2.40.0 Folder = C:\Users\Christina\Downloads
Starter Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1013.30 Mb Total Physical Memory | 323.53 Mb Available Physical Memory | 31.93% Memory free
1.99 Gb Paging File | 1.30 Gb Available in Paging File | 65.19% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 88.00 Gb Total Space | 54.33 Gb Free Space | 61.74% Space Free | Partition Type: NTFS
Drive D: | 130.35 Gb Total Space | 70.54 Gb Free Space | 54.12% Space Free | Partition Type: NTFS

Computer Name: CHRISSAMSUNG | User Name: Christina | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Christina\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\TeamViewer\Version6\TeamViewer.exe (TeamViewer GmbH)
PRC - C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe (TeamViewer GmbH)
PRC - C:\Program Files\3 Mobile Broadband\3Connect\BecHelperService.exe ()
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe (TuneUp Software)
PRC - C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe (TuneUp Software)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Program Files\SRS Labs\SRS Premium Sound Control Panel\SRSPremiumPanel.exe (SRS Labs, Inc.)
PRC - C:\Program Files\Samsung\EasySpeedUpManager\EasySpeedUpManager2.exe (Samsung Electronics)
PRC - C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Program Files\PLAY ONLINE\AssistantServices.exe ()
PRC - C:\Windows\System32\PrintIsolationHost.exe (Microsoft Corporation)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\FileZilla FTP Client\fzshellext.dll ()
MOD - C:\Program Files\Samsung\Easy Display Manager\HookDllPS2.dll ()


========== Win32 Services (SafeList) ==========

SRV - (AdobeARMservice) – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (TeamViewer6) – C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe (TeamViewer GmbH)
SRV - (BecHelperService) – C:\Program Files\3 Mobile Broadband\3Connect\BecHelperService.exe ()
SRV - (TuneUp.UtilitiesSvc) – C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe (TuneUp Software)
SRV - (UxTuneUp) – C:\Windows\System32\uxtuneup.dll (TuneUp Software)
SRV - (Samsung UPD Service) – C:\Windows\System32\SUPDSvc.exe (Samsung Electronics CO., LTD.)
SRV - (UI Assistant Service) – C:\Program Files\PLAY ONLINE\AssistantServices.exe ()
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Driver Services (SafeList) ==========

DRV - (mdvrmng) – C:\Windows\System32\drivers\mdvrmng.sys ()
DRV - (ewusbmbb) – C:\Windows\System32\drivers\ewusbwwan.sys (Huawei Technologies Co., Ltd.)
DRV - (hwdatacard) – C:\Windows\System32\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (ew_hwusbdev) – C:\Windows\System32\drivers\ew_hwusbdev.sys (Huawei Technologies Co., Ltd.)
DRV - (huawei_enumerator) – C:\Windows\System32\drivers\ew_jubusenum.sys (Huawei Technologies Co., Ltd.)
DRV - (ew_usbenumfilter) – C:\Windows\System32\drivers\ew_usbenumfilter.sys (Huawei Technologies Co., Ltd.)
DRV - (TuneUpUtilitiesDrv) – C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys (TuneUp Software)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (TsUsbFlt) – C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (rtport) – C:\Windows\System32\drivers\rtport.sys (Windows ® 2003 DDK 3790 provider)
DRV - (yukonw7) – C:\Windows\System32\drivers\yk62x86.sys (Marvell)
DRV - (dc3d) – C:\Windows\System32\drivers\dc3d.sys (Microsoft Corporation)
DRV - (ZTEusbser6k) – C:\Windows\System32\drivers\ZTEusbser6k.sys (ZTE Incorporated)
DRV - (ZTEusbnmea) – C:\Windows\System32\drivers\ZTEusbnmea.sys (ZTE Incorporated)
DRV - (ZTEusbmdm6k) – C:\Windows\System32\drivers\ZTEusbmdm6k.sys (ZTE Incorporated)
DRV - (massfilter) – C:\Windows\System32\drivers\massfilter.sys (ZTE Incorporated)
DRV - (vwifimp) – C:\Windows\System32\drivers\vwifimp.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope =

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://uk.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-GB
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 27 2D 5B 24 CD 1C CD 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MVT: C:\Program Files\McAfee\Supportability\MVT\npmvtplugin.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@yahoo.com/BrowserPlus,version=2.9.8: C:\Users\Christina\AppData\Local\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll (Yahoo! Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012/04/11 23:37:25 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/04/11 23:48:19 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/04/19 11:36:28 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012/04/11 23:37:25 | 000,000,000 | —D | M]

[2011/10/04 01:13:51 | 000,000,000 | —D | M] (No name found) – C:\Users\Christina\AppData\Roaming\Mozilla\Extensions
[2012/04/17 11:31:27 | 000,000,000 | —D | M] (No name found) – C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\l3h69xx6.default\extensions
[2012/04/11 23:40:38 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\l3h69xx6.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2012/04/11 23:40:37 | 000,000,000 | —D | M] ("Xmarks") – C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\l3h69xx6.default\extensions\[removed]
[2012/02/13 16:17:18 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/03/12 11:45:36 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/10/03 06:06:04 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2012/04/11 18:32:03 | 000,003,747 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml
[2012/02/08 18:12:58 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/02/08 18:12:58 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: AVG Secure Search (Enabled)
CHR - default_search_provider: search_url = http://search.avg.com/?d=4e4480f1&v;=7….q={searchTerms}
CHR - default_search_provider: suggest_url = http://suggestqueries.google.com/complete/…q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\18.0.1025.152\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.290.11 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U29 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll
CHR - plugin: Microsoft Office 2003 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFFICE.DLL
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\18.0.1025.152\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\18.0.1025.152\pdf.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Users\Christina\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.40.135.1_0\McChPlg.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll
CHR - plugin: McAfee Virtual Technician (Enabled) = C:\Program Files\McAfee\Supportability\MVT\npmvtplugin.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: BrowserPlus (from Yahoo!) v2.9.8 (Enabled) = C:\Users\Christina\AppData\Local\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll
CHR - plugin: McAfee SecurityCenter (Enabled) = c:\progra~1\mcafee\msc\npmcsn~1.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: SiteAdvisor = C:\Users\Christina\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.41.123.2_0\

O1 HOSTS File: ([2011/06/20 12:20:47 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (W2PBrowser Class) - {AA609D72-8482-4076-8991-8CDAE5B93BCB} - C:\Program Files\Samsung AnyWeb Print\W2PBrowser.dll ()
O4 - HKLM..\Run: [] File not found
O4 - Startup: C:\Users\Christina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Samsung AnyWeb Print - {328ECD19-C167-40eb-A0C7-16FE7634105E} - C:\Program Files\Samsung AnyWeb Print\W2PBrowser.dll ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{CA189E4A-4A04-4742-880D-62407F0217CC}: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D82A697F-63A7-4A2B-9CD7-D1CBBF0B567D}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O35 - HKCU\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2012/04/21 22:28:19 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{6892558C-DC81-470A-85BE-2CCB18F6848A}
[2012/04/21 22:27:56 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{43456941-9D2C-4930-9C5D-C7EF74544F22}
[2012/04/21 22:24:26 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{6C7EEEC2-46C5-4033-93E8-5E78917F7BA1}
[2012/04/21 22:24:13 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{6DA76A72-FE63-4581-B6FA-128F659A8FF7}
[2012/04/21 21:10:21 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{18AECC58-EBBE-4908-A03B-353385D96D8C}
[2012/04/21 21:09:56 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{2A7B61D3-90AC-44AE-AFA2-87A5B611FB36}
[2012/04/21 20:20:25 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{BED26244-67A8-4E24-8B7A-694F692FE217}
[2012/04/21 20:20:13 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{7EF4FEFF-4195-4B90-B704-A4E234D13572}
[2012/04/21 19:22:00 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{8EBDDF4A-4447-4615-AA92-F4500A80104B}
[2012/04/21 19:21:32 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{BC3F252D-6AF7-48DA-931B-684B6A8003E1}
[2012/04/21 19:06:54 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{902EF019-219E-469A-AAAC-BEBF7FD6EAC0}
[2012/04/21 19:06:32 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{F4EAC8DD-3E7B-4214-93BB-A27CA4188D24}
[2012/04/21 18:01:52 | 000,000,000 | —D | C] – C:\Users\Christina\Desktop\obe-lucid-dream-quickstart-www-lucidology-com_files
[2012/04/21 10:22:27 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{975ADCD7-0732-4DA9-809A-6EE3F83DCF0D}
[2012/04/21 10:21:50 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{82B05528-BF3B-452E-9D0C-7D6D64575259}
[2012/04/20 10:28:10 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{B4DFE1EE-8C93-417E-830A-A2688023CD71}
[2012/04/20 10:27:23 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{0EC2CC3D-7F16-4E0F-90CB-47C1CD875FD1}
[2012/04/19 22:34:00 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{E507A3E1-A6ED-44D0-9596-51938B34B725}
[2012/04/19 22:33:34 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{36B4D4B9-2C41-4FAB-8A6C-C30BCDB366BC}
[2012/04/19 15:37:42 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{AB98BAE1-A861-4533-84D5-42955D09F691}
[2012/04/19 15:37:26 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{EE31A02C-91BB-4D10-953D-B9DAD1829B49}
[2012/04/19 11:35:37 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2012/04/18 22:39:05 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{63CBD3F4-81C8-457C-A409-4BF9820AEBA0}
[2012/04/18 22:38:21 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{07D573A2-C17C-4A2E-A407-2FBBE7275332}
[2012/04/18 20:37:36 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{F1F2B18B-8211-472B-B281-206711E4F087}
[2012/04/18 20:37:20 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{A6F03645-0AF1-453A-B1DE-F19DF91B51BF}
[2012/04/18 13:35:39 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{C385A2F8-6574-415B-8687-4A5447CAF2F4}
[2012/04/18 13:35:07 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{6E81434B-B1DF-4C8E-ABE9-39DC724B7289}
[2012/04/18 08:34:23 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{2F0B1D53-0213-4C14-A34A-CDC89784EC01}
[2012/04/18 08:34:09 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{8B722896-69DA-454C-A0F9-8B6BD59DE768}
[2012/04/17 21:23:21 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2012/04/17 19:57:35 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{B8212108-20A6-45AA-97AE-3CCB797CC5D1}
[2012/04/17 19:57:09 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{661A33A4-0C5E-44A4-AEDB-4ECBC3C62EB9}
[2012/04/17 19:28:37 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Roaming\Malwarebytes
[2012/04/17 19:28:21 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/04/17 19:28:02 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2012/04/17 19:27:55 | 000,022,344 | —- | C] (Malwarebytes Corporation) – C:\windows\System32\drivers\mbam.sys
[2012/04/17 19:27:54 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2012/04/17 19:04:58 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{E5C485DF-08A9-4FE8-A53D-0BDC91F116B3}
[2012/04/17 19:04:33 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{3A278787-D700-401C-9966-9D34692F875A}
[2012/04/17 19:00:47 | 000,000,000 | -HSD | C] – C:\found.000
[2012/04/17 12:19:42 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{F35E964A-6FCD-4353-97ED-CA912EB1EB65}
[2012/04/17 12:19:16 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{35592A29-3846-48BF-AF27-211B2EAB1B42}
[2012/04/17 11:30:44 | 000,000,000 | —D | C] – C:\_OTL
[2012/04/17 11:01:51 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{B32618D4-D46F-437C-B795-815FDE4A6B35}
[2012/04/17 11:01:29 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{50120FB6-C762-462B-A028-D6399FF4C31A}
[2012/04/17 00:48:12 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ERUNT
[2012/04/17 00:48:08 | 000,000,000 | —D | C] – C:\Program Files\ERUNT
[2012/04/16 23:32:49 | 000,000,000 | —D | C] – C:\Users\Christina\Desktop\whatthetech navigation
[2012/04/16 19:53:19 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{353ABB58-7BD4-4459-A2EB-C412D6EC8E18}
[2012/04/16 19:52:48 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{44ACE206-2C0F-4A88-9186-E39AADDA6FE7}
[2012/04/14 20:59:07 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{5347E02E-61C4-4A34-82A7-545D2641B3F3}
[2012/04/14 20:58:39 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{022A2F2D-9B12-4D06-B669-A9642629A139}
[2012/04/14 11:21:42 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{56C1D28E-2276-4DB1-9239-EA48F9749018}
[2012/04/14 11:20:55 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{302F11B4-7742-4911-AAB8-C4243746E438}
[2012/04/12 13:10:10 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{DEB12ACD-A165-40D6-B120-B90FF89CF18F}
[2012/04/12 13:09:53 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{8BEAEFC4-BC24-4E9C-A4BA-925BFC01E83B}
[2012/04/12 10:42:36 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{4E38B6BD-FC8A-41F2-92B3-321A33528DBC}
[2012/04/12 10:42:18 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{ADDEEC85-BDAB-4677-ADAC-96F49FBBEC9A}
[2012/04/12 02:13:16 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\windows\System32\mshtml.tlb
[2012/04/12 02:13:11 | 001,799,168 | —- | C] (Microsoft Corporation) – C:\windows\System32\jscript9.dll
[2012/04/12 02:13:08 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\windows\System32\jsproxy.dll
[2012/04/12 02:13:06 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\windows\System32\url.dll
[2012/04/12 02:13:05 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\windows\System32\ieui.dll
[2012/04/12 02:13:03 | 001,427,456 | —- | C] (Microsoft Corporation) – C:\windows\System32\inetcpl.cpl
[2012/04/12 01:26:11 | 003,968,368 | —- | C] (Microsoft Corporation) – C:\windows\System32\ntkrnlpa.exe
[2012/04/12 01:26:07 | 003,913,072 | —- | C] (Microsoft Corporation) – C:\windows\System32\ntoskrnl.exe
[2012/04/12 01:13:14 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{53F44410-0F49-4159-A9F7-59CC9BFFC840}
[2012/04/12 01:00:33 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{366BC4BB-E3D2-4779-8C3E-EF1ED4E083D1}
[2012/04/12 00:59:22 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{129F8187-BA00-4F56-9B40-E66F1178AA51}
[2012/04/11 23:15:03 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{CB62930E-E8B8-4025-A65D-E322529139F8}
[2012/04/11 19:53:01 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC Tuneup 2011
[2012/04/11 18:33:06 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
[2012/04/11 18:32:29 | 000,000,000 | —D | C] – C:\ProgramData\AVG Secure Search
[2012/04/11 18:32:15 | 000,000,000 | —D | C] – C:\Program Files\Common Files\AVG Secure Search
[2012/04/11 18:32:07 | 000,000,000 | —D | C] – C:\Program Files\AVG Secure Search
[2012/04/11 18:26:16 | 000,000,000 | -H-D | C] – C:\$AVG
[2012/04/11 18:26:15 | 000,000,000 | —D | C] – C:\ProgramData\AVG2012
[2012/04/11 16:45:09 | 000,000,000 | —D | C] – C:\Program Files\Common Files\SpeedyPC Software
[2012/04/11 16:45:07 | 000,000,000 | —D | C] – C:\Program Files\SpeedyPC Software
[2012/04/10 21:42:54 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{866CAD26-2E62-4941-BDEC-0923B602D05F}
[2012/04/09 02:12:51 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Roaming\SpeedyPC Software
[2012/04/09 02:12:02 | 000,000,000 | —D | C] – C:\ProgramData\SpeedyPC Software
[2012/04/08 23:19:57 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{76C924EA-6DD3-4D30-8A0B-48AE4858BCD8}
[2012/04/03 21:36:56 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\WinZip
[2012/04/03 20:12:03 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{33EE76A0-7DA3-43AD-AA28-3D14011E35FA}
[2012/04/03 20:11:27 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{4F619680-21D9-4743-AA23-61D6AD6AFDFD}
[2012/04/03 19:37:50 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{6134C62C-6DBF-4C38-B968-D8951F6892BF}
[2012/04/03 19:20:22 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{BC049C4B-D462-49AA-8DBC-5E59C2640EAD}
[2012/04/03 19:19:15 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{78D44058-B568-47E9-A492-E82E66134CEA}
[2012/03/29 20:41:09 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{92341BC9-2B8A-4130-AF99-C38DF4ACE36A}
[2012/03/29 19:37:48 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{75351EA8-4AD7-4C50-89C7-E4901675B152}
[2012/03/26 23:53:31 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{54C4A35C-A82D-4C15-A4B6-0476397D1B3C}
[2012/03/26 23:53:04 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{47D1C48E-CA92-4A51-A53B-A29A2D6F0B0B}
[2012/03/26 11:52:08 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{5A15AD8D-6405-440F-801B-97CD9EC05AA2}
[2012/03/26 11:51:43 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{924EF17F-2F86-4D2B-BABC-EA55463BA947}

========== Files - Modified Within 30 Days ==========

[2012/04/21 22:30:37 | 000,010,592 | -H– | M] () – C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/04/21 22:30:37 | 000,010,592 | -H– | M] () – C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/04/21 22:23:38 | 000,000,888 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/04/21 22:23:08 | 000,067,584 | –S- | M] () – C:\windows\bootstat.dat
[2012/04/21 22:23:03 | 1062,518,784 | -HS- | M] () – C:\hiberfil.sys
[2012/04/21 22:22:32 | 000,000,892 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/04/21 18:01:56 | 000,093,497 | —- | M] () – C:\Users\Christina\Desktop\obe-lucid-dream-quickstart-www-lucidology-com.htm
[2012/04/21 14:14:45 | 002,285,200 | —- | M] () – C:\Users\Christina\Desktop\obe-lucid-dream-quickstart-www-lucidology-com.pdf
[2012/04/21 11:20:32 | 001,029,693 | —- | M] () – C:\Users\Christina\Desktop\22ToolsToTransformYourFear.pdf
[2012/04/21 11:17:10 | 000,519,867 | —- | M] () – C:\Users\Christina\Desktop\MindSurgePop.pdf
[2012/04/19 11:32:08 | 001,353,946 | —- | M] () – C:\Users\Christina\Desktop\ltr from faron sutaria.pdf
[2012/04/17 19:28:22 | 000,001,071 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/04/17 12:24:50 | 000,649,584 | —- | M] () – C:\windows\System32\perfh009.dat
[2012/04/17 12:24:50 | 000,120,746 | —- | M] () – C:\windows\System32\perfc009.dat
[2012/04/17 00:48:37 | 000,001,078 | —- | M] () – C:\Users\Christina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2012/04/17 00:48:13 | 000,000,898 | —- | M] () – C:\Users\Christina\Desktop\NTREGOPT.lnk
[2012/04/17 00:48:13 | 000,000,879 | —- | M] () – C:\Users\Christina\Desktop\ERUNT.lnk
[2012/04/16 14:54:34 | 000,002,290 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2012/04/11 01:35:17 | 000,392,875 | —- | M] () – C:\Users\Christina\Desktop\fru_7steps.pdf
[2012/04/04 15:56:40 | 000,022,344 | —- | M] (Malwarebytes Corporation) – C:\windows\System32\drivers\mbam.sys

========== Files Created - No Company Name ==========

[2012/04/21 18:01:49 | 000,093,497 | —- | C] () – C:\Users\Christina\Desktop\obe-lucid-dream-quickstart-www-lucidology-com.htm
[2012/04/21 14:14:44 | 002,285,200 | —- | C] () – C:\Users\Christina\Desktop\obe-lucid-dream-quickstart-www-lucidology-com.pdf
[2012/04/21 11:20:30 | 001,029,693 | —- | C] () – C:\Users\Christina\Desktop\22ToolsToTransformYourFear.pdf
[2012/04/21 11:17:09 | 000,519,867 | —- | C] () – C:\Users\Christina\Desktop\MindSurgePop.pdf
[2012/04/19 11:32:08 | 001,353,946 | —- | C] () – C:\Users\Christina\Desktop\ltr from faron sutaria.pdf
[2012/04/17 19:28:22 | 000,001,071 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/04/17 00:48:37 | 000,001,078 | —- | C] () – C:\Users\Christina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2012/04/17 00:48:13 | 000,000,898 | —- | C] () – C:\Users\Christina\Desktop\NTREGOPT.lnk
[2012/04/17 00:48:12 | 000,000,879 | —- | C] () – C:\Users\Christina\Desktop\ERUNT.lnk
[2012/04/11 01:35:17 | 000,392,875 | —- | C] () – C:\Users\Christina\Desktop\fru_7steps.pdf
[2011/10/14 11:06:49 | 000,067,156 | —- | C] () – C:\windows\Huawei ModemsUninstall.exe
[2011/10/14 11:06:43 | 000,010,240 | —- | C] () – C:\windows\System32\drivers\mdvrmng.sys
[2011/08/20 00:52:46 | 000,023,128 | —- | C] () – C:\windows\hpqins15.dat
[2011/07/03 20:40:27 | 000,202,283 | —- | C] () – C:\windows\hpoins18.dat
[2011/07/03 20:40:27 | 000,005,355 | —- | C] () – C:\windows\hpomdl18.dat
[2011/06/25 16:30:02 | 000,202,516 | —- | C] () – C:\windows\hpoins18.dat.temp
[2011/06/25 16:30:02 | 000,005,355 | —- | C] () – C:\windows\hpomdl18.dat.temp
[2011/06/04 20:34:36 | 000,000,376 | —- | C] () – C:\windows\ODBC.INI
[2011/01/19 08:42:30 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2011/01/19 08:07:17 | 000,000,000 | —- | C] () – C:\windows\nsreg.dat
[2011/01/17 11:01:21 | 000,120,688 | —- | C] () – C:\windows\Wiainst.exe
[2011/01/17 11:00:36 | 000,552,960 | —- | C] () – C:\windows\System32\SnMinDrv.dll
[2011/01/17 11:00:36 | 000,154,112 | —- | C] () – C:\windows\System32\SNWIAUI.dll
[2011/01/17 11:00:36 | 000,135,168 | —- | C] () – C:\windows\System32\SnImgFlt.dll
[2011/01/17 11:00:36 | 000,094,208 | —- | C] () – C:\windows\System32\SnErHdlr.dll
[2011/01/17 11:00:16 | 000,484,656 | —- | C] () – C:\windows\ssndii.exe
[2011/01/17 10:59:30 | 000,259,888 | —- | C] () – C:\windows\SUPDRun.exe
[2011/01/17 10:59:30 | 000,151,552 | —- | C] () – C:\windows\System32\spd__ci.exe
[2011/01/17 10:59:29 | 000,283,136 | —- | C] () – C:\windows\System32\DscPnt.dll
[2011/01/17 10:59:29 | 000,026,624 | —- | C] () – C:\windows\System32\spd__l.dll
[2010/09/01 11:06:37 | 000,001,064 | —- | C] () – C:\windows\HotFixList.ini
[2010/09/01 10:49:40 | 000,006,656 | —- | C] () – C:\windows\System32\bcmwlrc.dll

========== Alternate Data Streams ==========

@Alternate Data Stream - 137 bytes -> C:\ProgramData\Temp:0B4227B4
@Alternate Data Stream - 136 bytes -> C:\ProgramData\Temp:B63300D1
@Alternate Data Stream - 121 bytes -> C:\ProgramData\Temp:DFC5A2B2
@Alternate Data Stream - 104 bytes -> C:\ProgramData\Temp:D1B5B4F1

< End of report >


Pls let me know when I can reinstall McAfee?
For the time being keep all internet use on the infected computer to only here and to download tools or locations I send you. We will engage your antivirus later once we get your system more stable.

Download Windows Repair (all in one) from this site

Install and then run the program.

On the Start Repairs tab, select Advanced Mode and click Start
[external image: Posted Image]

Select the items Checked in the screen shot below (remove the checks from the rest ) and check Restart System When Finished.

[external image: Posted Image]
———-
Hi,

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://uk.msn.com/?ocid=iehp
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-GB
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 27 2D 5B 24 CD 1C CD 01 [binary data]
    IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
    
    :Files
    ipconfig /flushdns /c
    
    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then run a new scan and post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
———-
OTL logfile created on: 4/22/2012 8:17:40 PM - Run 6
OTL by OldTimer - Version 3.2.40.0 Folder = C:\Users\Christina\Downloads
Starter Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1013.30 Mb Total Physical Memory | 193.29 Mb Available Physical Memory | 19.08% Memory free
1.99 Gb Paging File | 1.16 Gb Available in Paging File | 58.54% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 88.00 Gb Total Space | 55.85 Gb Free Space | 63.47% Space Free | Partition Type: NTFS
Drive D: | 130.35 Gb Total Space | 70.37 Gb Free Space | 53.98% Space Free | Partition Type: NTFS

Computer Name: CHRISSAMSUNG | User Name: Christina | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Christina\Downloads\OTL(1).exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Samsung\Samsung Support Center\SSCKbdHk.exe (SAMSUNG Electronics)
PRC - C:\Program Files\TeamViewer\Version6\TeamViewer.exe (TeamViewer GmbH)
PRC - C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe (TeamViewer GmbH)
PRC - C:\Program Files\3 Mobile Broadband\3Connect\BecHelperService.exe ()
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe (TuneUp Software)
PRC - C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe (TuneUp Software)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Program Files\SRS Labs\SRS Premium Sound Control Panel\SRSPremiumPanel.exe (SRS Labs, Inc.)
PRC - C:\Program Files\Samsung\Samsung Update Plus\SUPBackground.exe (Samsung Electronics)
PRC - C:\Program Files\Samsung\Movie Color Enhancer\MovieColorEnhancer.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Program Files\Samsung\Samsung Recovery Solution 5\WCScheduler.exe (SEC)
PRC - C:\Program Files\Samsung\SamsungFastStart\SmartRestarter.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Program Files\PLAY ONLINE\AssistantServices.exe ()
PRC - C:\Program Files\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Samsung\Movie Color Enhancer\WinCRT.dll ()
MOD - C:\Program Files\Samsung\Samsung Recovery Solution 5\Resdll.dll ()
MOD - C:\Program Files\Samsung\Easy Display Manager\HookDllPS2.dll ()


========== Win32 Services (SafeList) ==========

SRV - (0311831335121373mcinstcleanup) McAfee Application Installer Cleanup (0311831335121373) – C:\Users\CHRIST~1\AppData\Local\Temp\031183~1.EXE C:\PROGRA~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini File not found
SRV - (AdobeARMservice) – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (TeamViewer6) – C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe (TeamViewer GmbH)
SRV - (BecHelperService) – C:\Program Files\3 Mobile Broadband\3Connect\BecHelperService.exe ()
SRV - (TuneUp.UtilitiesSvc) – C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe (TuneUp Software)
SRV - (UxTuneUp) – C:\Windows\System32\uxtuneup.dll (TuneUp Software)
SRV - (Samsung UPD Service) – C:\Windows\System32\SUPDSvc.exe (Samsung Electronics CO., LTD.)
SRV - (UI Assistant Service) – C:\Program Files\PLAY ONLINE\AssistantServices.exe ()
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Driver Services (SafeList) ==========

DRV - (mdvrmng) – C:\Windows\System32\drivers\mdvrmng.sys ()
DRV - (ewusbmbb) – C:\Windows\System32\drivers\ewusbwwan.sys (Huawei Technologies Co., Ltd.)
DRV - (hwdatacard) – C:\Windows\System32\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (ew_hwusbdev) – C:\Windows\System32\drivers\ew_hwusbdev.sys (Huawei Technologies Co., Ltd.)
DRV - (huawei_enumerator) – C:\Windows\System32\drivers\ew_jubusenum.sys (Huawei Technologies Co., Ltd.)
DRV - (ew_usbenumfilter) – C:\Windows\System32\drivers\ew_usbenumfilter.sys (Huawei Technologies Co., Ltd.)
DRV - (TuneUpUtilitiesDrv) – C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys (TuneUp Software)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (TsUsbFlt) – C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (rtport) – C:\Windows\System32\drivers\rtport.sys (Windows ® 2003 DDK 3790 provider)
DRV - (yukonw7) – C:\Windows\System32\drivers\yk62x86.sys (Marvell)
DRV - (dc3d) – C:\Windows\System32\drivers\dc3d.sys (Microsoft Corporation)
DRV - (ZTEusbser6k) – C:\Windows\System32\drivers\ZTEusbser6k.sys (ZTE Incorporated)
DRV - (ZTEusbnmea) – C:\Windows\System32\drivers\ZTEusbnmea.sys (ZTE Incorporated)
DRV - (ZTEusbmdm6k) – C:\Windows\System32\drivers\ZTEusbmdm6k.sys (ZTE Incorporated)
DRV - (massfilter) – C:\Windows\System32\drivers\massfilter.sys (ZTE Incorporated)
DRV - (vwifimp) – C:\Windows\System32\drivers\vwifimp.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope =

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP =
IE - HKCU\..\SearchScopes,DefaultScope =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MVT: C:\Program Files\McAfee\Supportability\MVT\npmvtplugin.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@yahoo.com/BrowserPlus,version=2.9.8: C:\Users\Christina\AppData\Local\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll (Yahoo! Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012/04/11 23:37:25 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/04/11 23:48:19 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/04/19 11:36:28 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012/04/11 23:37:25 | 000,000,000 | —D | M]

[2011/10/04 01:13:51 | 000,000,000 | —D | M] (No name found) – C:\Users\Christina\AppData\Roaming\Mozilla\Extensions
[2012/04/17 11:31:27 | 000,000,000 | —D | M] (No name found) – C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\l3h69xx6.default\extensions
[2012/04/11 23:40:38 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\l3h69xx6.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2012/04/11 23:40:37 | 000,000,000 | —D | M] ("Xmarks") – C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\l3h69xx6.default\extensions\[removed]
[2012/02/13 16:17:18 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/03/12 11:45:36 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/10/03 06:06:04 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2012/04/11 18:32:03 | 000,003,747 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml
[2012/02/08 18:12:58 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/02/08 18:12:58 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: AVG Secure Search (Enabled)
CHR - default_search_provider: search_url = http://search.avg.com/?d=4e4480f1&v;=7….q={searchTerms}
CHR - default_search_provider: suggest_url = http://suggestqueries.google.com/complete/…q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\18.0.1025.152\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.290.11 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U29 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll
CHR - plugin: Microsoft Office 2003 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFFICE.DLL
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\18.0.1025.152\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\18.0.1025.152\pdf.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Users\Christina\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.40.135.1_0\McChPlg.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll
CHR - plugin: McAfee Virtual Technician (Enabled) = C:\Program Files\McAfee\Supportability\MVT\npmvtplugin.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: BrowserPlus (from Yahoo!) v2.9.8 (Enabled) = C:\Users\Christina\AppData\Local\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll
CHR - plugin: McAfee SecurityCenter (Enabled) = c:\progra~1\mcafee\msc\npmcsn~1.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: SiteAdvisor = C:\Users\Christina\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.41.123.2_0\

O1 HOSTS File: ([2012/04/22 20:08:51 | 000,000,098 | —- | M]) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (W2PBrowser Class) - {AA609D72-8482-4076-8991-8CDAE5B93BCB} - C:\Program Files\Samsung AnyWeb Print\W2PBrowser.dll ()
O4 - HKLM..\Run: [] File not found
O4 - Startup: C:\Users\Christina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Samsung AnyWeb Print - {328ECD19-C167-40eb-A0C7-16FE7634105E} - C:\Program Files\Samsung AnyWeb Print\W2PBrowser.dll ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{CA189E4A-4A04-4742-880D-62407F0217CC}: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D82A697F-63A7-4A2B-9CD7-D1CBBF0B567D}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O35 - HKCU\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2012/04/22 20:12:44 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{9163A833-59B4-43CB-9F12-9C4AED32AA82}
[2012/04/22 20:12:33 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{0B100FCF-19D4-4871-B7AF-EF172CA7F52D}
[2012/04/22 16:28:18 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{0B739743-C1F4-4FF4-BB0F-B213725C5B9F}
[2012/04/22 16:28:04 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{54820ACA-EF1C-4BB0-A299-0C925519D435}
[2012/04/22 12:13:19 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{DF13114C-5A3B-4441-A027-39C57758E653}
[2012/04/22 12:12:51 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{B98FBA63-DE18-49EF-9DA7-9BAB94561AAF}
[2012/04/22 11:54:22 | 000,000,000 | —D | C] – C:\Reg_Backup
[2012/04/22 11:54:18 | 000,181,064 | —- | C] (Sysinternals) – C:\windows\PSEXESVC.EXE
[2012/04/22 11:50:42 | 000,000,000 | —D | C] – C:\Tweaking.com_Windows_Repair_Logs
[2012/04/22 11:50:28 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com
[2012/04/22 11:50:02 | 000,000,000 | —D | C] – C:\Program Files\Tweaking.com
[2012/04/22 10:58:17 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{7DCBE4D7-9A7A-4217-87C2-06C9FEF79DEF}
[2012/04/22 00:32:11 | 000,000,000 | —D | C] – C:\Users\Christina\Desktop\Play
[2012/04/22 00:01:44 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/04/22 00:01:09 | 000,022,344 | —- | C] (Malwarebytes Corporation) – C:\windows\System32\drivers\mbam.sys
[2012/04/22 00:01:08 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2012/04/21 23:32:44 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Mcafee
[2012/04/21 23:32:42 | 000,000,000 | —D | C] – C:\Program Files\McAfee.com
[2012/04/21 23:23:34 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{333DF259-F04E-40A8-9ABB-9644FA6AEC50}
[2012/04/21 23:23:18 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{1B898735-5C13-4BDD-986A-69C48B5913E1}
[2012/04/21 22:57:07 | 000,000,000 | —D | C] – C:\Users\Christina\Desktop\lucid
[2012/04/21 22:28:19 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{6892558C-DC81-470A-85BE-2CCB18F6848A}
[2012/04/21 22:27:56 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{43456941-9D2C-4930-9C5D-C7EF74544F22}
[2012/04/21 22:24:26 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{6C7EEEC2-46C5-4033-93E8-5E78917F7BA1}
[2012/04/21 22:24:13 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{6DA76A72-FE63-4581-B6FA-128F659A8FF7}
[2012/04/21 21:10:21 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{18AECC58-EBBE-4908-A03B-353385D96D8C}
[2012/04/21 21:09:56 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{2A7B61D3-90AC-44AE-AFA2-87A5B611FB36}
[2012/04/21 20:20:25 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{BED26244-67A8-4E24-8B7A-694F692FE217}
[2012/04/21 20:20:13 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{7EF4FEFF-4195-4B90-B704-A4E234D13572}
[2012/04/21 19:22:00 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{8EBDDF4A-4447-4615-AA92-F4500A80104B}
[2012/04/21 19:21:32 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{BC3F252D-6AF7-48DA-931B-684B6A8003E1}
[2012/04/21 19:06:54 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{902EF019-219E-469A-AAAC-BEBF7FD6EAC0}
[2012/04/21 19:06:32 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{F4EAC8DD-3E7B-4214-93BB-A27CA4188D24}
[2012/04/21 10:22:27 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{975ADCD7-0732-4DA9-809A-6EE3F83DCF0D}
[2012/04/21 10:21:50 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{82B05528-BF3B-452E-9D0C-7D6D64575259}
[2012/04/20 10:28:10 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{B4DFE1EE-8C93-417E-830A-A2688023CD71}
[2012/04/20 10:27:23 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{0EC2CC3D-7F16-4E0F-90CB-47C1CD875FD1}
[2012/04/19 22:34:00 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{E507A3E1-A6ED-44D0-9596-51938B34B725}
[2012/04/19 22:33:34 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{36B4D4B9-2C41-4FAB-8A6C-C30BCDB366BC}
[2012/04/19 15:37:42 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{AB98BAE1-A861-4533-84D5-42955D09F691}
[2012/04/19 15:37:26 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{EE31A02C-91BB-4D10-953D-B9DAD1829B49}
[2012/04/19 11:35:37 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2012/04/18 22:39:05 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{63CBD3F4-81C8-457C-A409-4BF9820AEBA0}
[2012/04/18 22:38:21 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{07D573A2-C17C-4A2E-A407-2FBBE7275332}
[2012/04/18 20:37:36 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{F1F2B18B-8211-472B-B281-206711E4F087}
[2012/04/18 20:37:20 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{A6F03645-0AF1-453A-B1DE-F19DF91B51BF}
[2012/04/18 13:35:39 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{C385A2F8-6574-415B-8687-4A5447CAF2F4}
[2012/04/18 13:35:07 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{6E81434B-B1DF-4C8E-ABE9-39DC724B7289}
[2012/04/18 08:34:23 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{2F0B1D53-0213-4C14-A34A-CDC89784EC01}
[2012/04/18 08:34:09 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{8B722896-69DA-454C-A0F9-8B6BD59DE768}
[2012/04/17 21:23:21 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2012/04/17 19:57:35 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{B8212108-20A6-45AA-97AE-3CCB797CC5D1}
[2012/04/17 19:57:09 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{661A33A4-0C5E-44A4-AEDB-4ECBC3C62EB9}
[2012/04/17 19:28:37 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Roaming\Malwarebytes
[2012/04/17 19:28:02 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2012/04/17 19:04:58 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{E5C485DF-08A9-4FE8-A53D-0BDC91F116B3}
[2012/04/17 19:04:33 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{3A278787-D700-401C-9966-9D34692F875A}
[2012/04/17 19:00:47 | 000,000,000 | -HSD | C] – C:\found.000
[2012/04/17 12:19:42 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{F35E964A-6FCD-4353-97ED-CA912EB1EB65}
[2012/04/17 12:19:16 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{35592A29-3846-48BF-AF27-211B2EAB1B42}
[2012/04/17 11:30:44 | 000,000,000 | —D | C] – C:\_OTL
[2012/04/17 11:01:51 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{B32618D4-D46F-437C-B795-815FDE4A6B35}
[2012/04/17 11:01:29 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{50120FB6-C762-462B-A028-D6399FF4C31A}
[2012/04/17 00:48:12 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ERUNT
[2012/04/17 00:48:08 | 000,000,000 | —D | C] – C:\Program Files\ERUNT
[2012/04/16 23:32:49 | 000,000,000 | —D | C] – C:\Users\Christina\Desktop\whatthetech navigation
[2012/04/16 19:53:19 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{353ABB58-7BD4-4459-A2EB-C412D6EC8E18}
[2012/04/16 19:52:48 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{44ACE206-2C0F-4A88-9186-E39AADDA6FE7}
[2012/04/14 20:59:07 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{5347E02E-61C4-4A34-82A7-545D2641B3F3}
[2012/04/14 20:58:39 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{022A2F2D-9B12-4D06-B669-A9642629A139}
[2012/04/14 11:21:42 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{56C1D28E-2276-4DB1-9239-EA48F9749018}
[2012/04/14 11:20:55 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{302F11B4-7742-4911-AAB8-C4243746E438}
[2012/04/12 13:10:10 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{DEB12ACD-A165-40D6-B120-B90FF89CF18F}
[2012/04/12 13:09:53 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{8BEAEFC4-BC24-4E9C-A4BA-925BFC01E83B}
[2012/04/12 10:42:36 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{4E38B6BD-FC8A-41F2-92B3-321A33528DBC}
[2012/04/12 10:42:18 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{ADDEEC85-BDAB-4677-ADAC-96F49FBBEC9A}
[2012/04/12 02:13:16 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\windows\System32\mshtml.tlb
[2012/04/12 02:13:11 | 001,799,168 | —- | C] (Microsoft Corporation) – C:\windows\System32\jscript9.dll
[2012/04/12 02:13:08 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\windows\System32\jsproxy.dll
[2012/04/12 02:13:06 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\windows\System32\url.dll
[2012/04/12 02:13:05 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\windows\System32\ieui.dll
[2012/04/12 02:13:03 | 001,427,456 | —- | C] (Microsoft Corporation) – C:\windows\System32\inetcpl.cpl
[2012/04/12 01:26:11 | 003,968,368 | —- | C] (Microsoft Corporation) – C:\windows\System32\ntkrnlpa.exe
[2012/04/12 01:26:07 | 003,913,072 | —- | C] (Microsoft Corporation) – C:\windows\System32\ntoskrnl.exe
[2012/04/12 01:13:14 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{53F44410-0F49-4159-A9F7-59CC9BFFC840}
[2012/04/12 01:00:33 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{366BC4BB-E3D2-4779-8C3E-EF1ED4E083D1}
[2012/04/12 00:59:22 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{129F8187-BA00-4F56-9B40-E66F1178AA51}
[2012/04/11 23:15:03 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{CB62930E-E8B8-4025-A65D-E322529139F8}
[2012/04/11 19:53:01 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC Tuneup 2011
[2012/04/11 18:33:06 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
[2012/04/11 18:32:29 | 000,000,000 | —D | C] – C:\ProgramData\AVG Secure Search
[2012/04/11 18:32:15 | 000,000,000 | —D | C] – C:\Program Files\Common Files\AVG Secure Search
[2012/04/11 18:32:07 | 000,000,000 | —D | C] – C:\Program Files\AVG Secure Search
[2012/04/11 18:26:16 | 000,000,000 | -H-D | C] – C:\$AVG
[2012/04/11 18:26:15 | 000,000,000 | —D | C] – C:\ProgramData\AVG2012
[2012/04/11 16:45:09 | 000,000,000 | —D | C] – C:\Program Files\Common Files\SpeedyPC Software
[2012/04/11 16:45:07 | 000,000,000 | —D | C] – C:\Program Files\SpeedyPC Software
[2012/04/10 21:42:54 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{866CAD26-2E62-4941-BDEC-0923B602D05F}
[2012/04/09 02:12:51 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Roaming\SpeedyPC Software
[2012/04/09 02:12:02 | 000,000,000 | —D | C] – C:\ProgramData\SpeedyPC Software
[2012/04/08 23:19:57 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{76C924EA-6DD3-4D30-8A0B-48AE4858BCD8}
[2012/04/03 21:36:56 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\WinZip
[2012/04/03 20:12:03 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{33EE76A0-7DA3-43AD-AA28-3D14011E35FA}
[2012/04/03 20:11:27 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{4F619680-21D9-4743-AA23-61D6AD6AFDFD}
[2012/04/03 19:37:50 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{6134C62C-6DBF-4C38-B968-D8951F6892BF}
[2012/04/03 19:20:22 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{BC049C4B-D462-49AA-8DBC-5E59C2640EAD}
[2012/04/03 19:19:15 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{78D44058-B568-47E9-A492-E82E66134CEA}
[2012/03/29 20:41:09 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{92341BC9-2B8A-4130-AF99-C38DF4ACE36A}
[2012/03/29 19:37:48 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{75351EA8-4AD7-4C50-89C7-E4901675B152}
[2012/03/26 23:53:31 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{54C4A35C-A82D-4C15-A4B6-0476397D1B3C}
[2012/03/26 23:53:04 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{47D1C48E-CA92-4A51-A53B-A29A2D6F0B0B}
[2012/03/26 11:52:08 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{5A15AD8D-6405-440F-801B-97CD9EC05AA2}
[2012/03/26 11:51:43 | 000,000,000 | —D | C] – C:\Users\Christina\AppData\Local\{924EF17F-2F86-4D2B-BABC-EA55463BA947}

========== Files - Modified Within 30 Days ==========

[2012/04/22 20:22:09 | 000,000,892 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/04/22 20:16:06 | 000,649,584 | —- | M] () – C:\windows\System32\perfh009.dat
[2012/04/22 20:16:06 | 000,120,746 | —- | M] () – C:\windows\System32\perfc009.dat
[2012/04/22 20:15:49 | 000,010,592 | -H– | M] () – C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/04/22 20:15:49 | 000,010,592 | -H– | M] () – C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/04/22 20:11:03 | 000,000,888 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/04/22 20:10:28 | 000,067,584 | –S- | M] () – C:\windows\bootstat.dat
[2012/04/22 20:10:24 | 1062,518,784 | -HS- | M] () – C:\hiberfil.sys
[2012/04/22 20:08:51 | 000,000,098 | —- | M] () – C:\windows\System32\drivers\etc\Hosts
[2012/04/22 12:06:51 | 000,181,064 | —- | M] (Sysinternals) – C:\windows\PSEXESVC.EXE
[2012/04/22 12:06:51 | 000,000,042 | —- | M] () – C:\repairs_running.dat
[2012/04/22 11:50:28 | 000,002,217 | —- | M] () – C:\Users\Public\Desktop\Tweaking.com - Windows Repair (All in One).lnk
[2012/04/17 00:48:37 | 000,001,078 | —- | M] () – C:\Users\Christina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2012/04/16 14:54:34 | 000,002,290 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2012/04/11 01:35:17 | 000,392,875 | —- | M] () – C:\Users\Christina\Desktop\fru_7steps.pdf
[2012/04/04 15:56:40 | 000,022,344 | —- | M] (Malwarebytes Corporation) – C:\windows\System32\drivers\mbam.sys

========== Files Created - No Company Name ==========

[2012/04/22 12:01:08 | 000,000,042 | —- | C] () – C:\repairs_running.dat
[2012/04/22 11:50:28 | 000,002,217 | —- | C] () – C:\Users\Public\Desktop\Tweaking.com - Windows Repair (All in One).lnk
[2012/04/17 00:48:37 | 000,001,078 | —- | C] () – C:\Users\Christina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2012/04/11 01:35:17 | 000,392,875 | —- | C] () – C:\Users\Christina\Desktop\fru_7steps.pdf
[2011/10/14 11:06:49 | 000,067,156 | —- | C] () – C:\windows\Huawei ModemsUninstall.exe
[2011/10/14 11:06:43 | 000,010,240 | —- | C] () – C:\windows\System32\drivers\mdvrmng.sys
[2011/08/20 00:52:46 | 000,023,128 | —- | C] () – C:\windows\hpqins15.dat
[2011/07/03 20:40:27 | 000,202,283 | —- | C] () – C:\windows\hpoins18.dat
[2011/07/03 20:40:27 | 000,005,355 | —- | C] () – C:\windows\hpomdl18.dat
[2011/06/25 16:30:02 | 000,202,516 | —- | C] () – C:\windows\hpoins18.dat.temp
[2011/06/25 16:30:02 | 000,005,355 | —- | C] () – C:\windows\hpomdl18.dat.temp
[2011/06/04 20:34:36 | 000,000,376 | —- | C] () – C:\windows\ODBC.INI
[2011/01/19 08:42:30 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2011/01/19 08:07:17 | 000,000,000 | —- | C] () – C:\windows\nsreg.dat
[2011/01/17 11:01:21 | 000,120,688 | —- | C] () – C:\windows\Wiainst.exe
[2011/01/17 11:00:36 | 000,552,960 | —- | C] () – C:\windows\System32\SnMinDrv.dll
[2011/01/17 11:00:36 | 000,154,112 | —- | C] () – C:\windows\System32\SNWIAUI.dll
[2011/01/17 11:00:36 | 000,135,168 | —- | C] () – C:\windows\System32\SnImgFlt.dll
[2011/01/17 11:00:36 | 000,094,208 | —- | C] () – C:\windows\System32\SnErHdlr.dll
[2011/01/17 11:00:16 | 000,484,656 | —- | C] () – C:\windows\ssndii.exe
[2011/01/17 10:59:30 | 000,259,888 | —- | C] () – C:\windows\SUPDRun.exe
[2011/01/17 10:59:30 | 000,151,552 | —- | C] () – C:\windows\System32\spd__ci.exe
[2011/01/17 10:59:29 | 000,283,136 | —- | C] () – C:\windows\System32\DscPnt.dll
[2011/01/17 10:59:29 | 000,026,624 | —- | C] () – C:\windows\System32\spd__l.dll
[2010/09/01 11:06:37 | 000,001,064 | —- | C] () – C:\windows\HotFixList.ini
[2010/09/01 10:49:40 | 000,006,656 | —- | C] () – C:\windows\System32\bcmwlrc.dll

========== Alternate Data Streams ==========

@Alternate Data Stream - 137 bytes -> C:\ProgramData\Temp:0B4227B4
@Alternate Data Stream - 136 bytes -> C:\ProgramData\Temp:B63300D1
@Alternate Data Stream - 121 bytes -> C:\ProgramData\Temp:DFC5A2B2
@Alternate Data Stream - 104 bytes -> C:\ProgramData\Temp:D1B5B4F1

< End of report >



All processes killed
Error: Unable to interpret in the current context!
========== SERVICES/DRIVERS ==========
========== OTL ==========
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page Redirect Cache| /E : value set successfully!
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page Redirect Cache AcceptLangs| /E : value set successfully!
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page Redirect Cache_TIMESTAMP| /E : value set successfully!
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\Christina\Downloads\cmd.bat deleted successfully.
C:\Users\Christina\Downloads\cmd.txt deleted successfully.
========== COMMANDS ==========
C:\windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: Admin
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: All Users

User: Christina
->Temp folder emptied: 139547422 bytes
->Temporary Internet Files folder emptied: 7815904 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 176156990 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 2013 bytes

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Public
->Temp folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 940704 bytes
RecycleBin emptied: 24738 bytes

Total Files Cleaned = 309.00 mb

Error: Unable to interpret <[Reboot]CODE> in the current context!
========== SERVICES/DRIVERS ==========
========== OTL ==========
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page Redirect Cache| /E : value set successfully!
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page Redirect Cache AcceptLangs| /E : value set successfully!
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page Redirect Cache_TIMESTAMP| /E : value set successfully!
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\Christina\Downloads\cmd.bat deleted successfully.
C:\Users\Christina\Downloads\cmd.txt deleted successfully.
========== COMMANDS ==========
C:\windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: Admin
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: All Users

User: Christina
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 231702 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Public
->Temp folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 10912 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 0.00 mb

Error: Unable to interpret <[Reboot]CODE> in the current context!
========== SERVICES/DRIVERS ==========
========== OTL ==========
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page Redirect Cache| /E : value set successfully!
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page Redirect Cache AcceptLangs| /E : value set successfully!
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page Redirect Cache_TIMESTAMP| /E : value set successfully!
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\Christina\Downloads\cmd.bat deleted successfully.
C:\Users\Christina\Downloads\cmd.txt deleted successfully.
========== COMMANDS ==========
C:\windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: Admin
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: All Users

User: Christina
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 231702 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Public
->Temp folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 10912 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 0.00 mb


OTL by OldTimer - Version 3.2.40.0 log created on 04222012_200705

Files\Folders moved on Reboot…
File\Folder C:\Users\Christina\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UXPVQIHI\ADSAdClient31[1].htm not found!

Registry entries deleted on Reboot…
Download Combofix from either of the links below, and save it to your desktop.
Link 1
Link 2

**Note: It is important that it is saved directly to your desktop**

——————————————————————–

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

——————————————————————–

Right-Click and Run as Administrator on ComboFix.exe & follow the prompts.


Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.

  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
———-
Right clicking does not work, had to be left ComboFix 12-04-22.02 - Christina 23/04/2012 13:12:45.2.2 - x86 Microsoft Windows 7 Starter 6.1.7601.1.1252.44.1033.18.1013.176 [GMT 1:00] Running from: c:\users\[removed]\Downloads\ComboFix.exe . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Christina\GoToAssistDownloadHelper.exe c:\windows\system32\roboot.exe . . ((((((((((((((((((((((((( Files Created from 2012-03-23 to 2012-04-23 ))))))))))))))))))))))))))))))) . . 2012-04-23 12:34 . 2012-04-23 12:34 ——– d—–w- c:\users\Christina\AppData\Local\temp 2012-04-23 12:34 . 2012-04-23 12:34 ——– d—–w- c:\users\Public\AppData\Local\temp 2012-04-23 12:34 . 2012-04-23 12:34 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-04-23 12:34 . 2012-04-23 12:34 ——– d—–w- c:\users\Admin\AppData\Local\temp 2012-04-22 10:54 . 2012-04-22 10:54 ——– d—–w- C:\Reg_Backup 2012-04-22 10:54 . 2012-04-22 11:06 181064 —-a-w- c:\windows\PSEXESVC.EXE 2012-04-22 10:50 . 2012-04-22 11:01 ——– d—–w- C:\Tweaking.com_Windows_Repair_Logs 2012-04-22 10:50 . 2012-04-22 10:50 ——– d—–w- c:\program files\Tweaking.com 2012-04-21 23:01 . 2012-04-04 14:56 22344 —-a-w- c:\windows\system32\drivers\mbam.sys 2012-04-21 23:01 . 2012-04-21 23:01 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2012-04-21 22:32 . 2012-04-22 19:10 ——– d—–w- c:\program files\Common Files\Mcafee 2012-04-21 22:32 . 2012-04-21 22:32 ——– d—–w- c:\program files\McAfee.com 2012-04-17 20:23 . 2012-04-17 20:23 ——– d—–w- c:\program files\ESET 2012-04-17 18:28 . 2012-04-17 18:28 ——– d—–w- c:\users\Christina\AppData\Roaming\Malwarebytes 2012-04-17 18:28 . 2012-04-17 18:28 ——– d—–w- c:\programdata\Malwarebytes 2012-04-17 18:00 . 2012-04-17 18:00 ——– d—–w- C:\found.000 2012-04-17 10:30 . 2012-04-17 10:30 ——– d—–w- C:\_OTL 2012-04-16 23:48 . 2012-04-16 23:48 ——– d—–w- c:\program files\ERUNT 2012-04-12 00:48 . 2012-03-01 05:46 19824 —-a-w- c:\windows\system32\drivers\fs_rec.sys 2012-04-12 00:48 . 2012-03-01 05:37 172544 —-a-w- c:\windows\system32\wintrust.dll 2012-04-12 00:48 . 2012-03-01 05:33 159232 —-a-w- c:\windows\system32\imagehlp.dll 2012-04-12 00:48 . 2012-03-01 05:29 5120 —-a-w- c:\windows\system32\wmi.dll 2012-04-12 00:26 . 2012-03-06 05:59 3968368 —-a-w- c:\windows\system32\ntkrnlpa.exe 2012-04-12 00:26 . 2012-03-06 05:59 3913072 —-a-w- c:\windows\system32\ntoskrnl.exe 2012-04-11 17:32 . 2012-04-11 17:32 ——– d—–w- c:\programdata\AVG Secure Search 2012-04-11 17:32 . 2012-04-11 22:47 ——– d—–w- c:\program files\Common Files\AVG Secure Search 2012-04-11 17:32 . 2012-04-11 22:47 ——– d—–w- c:\program files\AVG Secure Search 2012-04-11 17:26 . 2012-04-11 17:26 ——– d—–w- C:\$AVG 2012-04-11 17:26 . 2012-04-11 22:47 ——– d—–w- c:\programdata\AVG2012 2012-04-11 15:45 . 2012-04-11 15:45 ——– d—–w- c:\program files\Common Files\SpeedyPC Software 2012-04-11 15:45 . 2012-04-11 15:45 ——– d—–w- c:\program files\SpeedyPC Software 2012-04-09 01:12 . 2012-04-09 01:12 ——– d—–w- c:\users\Christina\AppData\Roaming\SpeedyPC Software 2012-04-09 01:12 . 2012-04-11 15:45 ——– d—–w- c:\programdata\SpeedyPC Software 2012-04-04 05:53 . 2012-04-04 05:53 182160 —-a-w- c:\program files\Mozilla Firefox\plugins\nppdf32.dll 2012-04-04 05:53 . 2012-04-04 05:53 182160 —-a-w- c:\program files\Internet Explorer\Plugins\nppdf32.dll 2012-04-03 20:36 . 2012-04-21 14:28 ——– d—–w- c:\users\Christina\AppData\Local\WinZip . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-03-02 11:37 . 2011-05-29 11:29 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-02-17 05:34 . 2012-03-14 16:04 826880 —-a-w- c:\windows\system32\rdpcore.dll 2012-02-17 04:14 . 2012-03-14 16:04 183808 —-a-w- c:\windows\system32\drivers\rdpwd.sys 2012-02-17 04:13 . 2012-03-14 16:04 24576 —-a-w- c:\windows\system32\drivers\tdtcp.sys 2012-02-10 05:38 . 2012-03-14 17:47 1077248 —-a-w- c:\windows\system32\DWrite.dll 2012-02-03 03:54 . 2012-03-14 17:47 2343424 —-a-w- c:\windows\system32\win32k.sys 2012-01-25 05:32 . 2012-03-14 16:05 58880 —-a-w- c:\windows\system32\rdpwsx.dll 2012-01-25 05:32 . 2012-03-14 16:05 129536 —-a-w- c:\windows\system32\rdpcorekmts.dll 2012-01-25 05:27 . 2012-03-14 16:05 8192 —-a-w- c:\windows\system32\rdrmemptylst.exe 2012-03-12 10:45 . 2012-02-13 15:14 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-07-22 150528] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-11-09 142104] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-11-09 174360] "Persistence"="c:\windows\system32\igfxpers.exe" [2011-11-09 150808] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712] . c:\users\Christina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2009-9-20 270336] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . [HKLM\~\startupfolder\C:^Users^Christina^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.3.lnk] backup=c:\windows\pss\OpenOffice.org 3.3.lnk.Startup backupExtension=.Startup HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DATAMNGR HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ApnUpdater] 2011-09-13 11:28 887976 —-a-w- c:\program files\Ask.com\Updater\Updater.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier] 2011-04-20 11:48 58656 —-a-w- c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ETDCtrl] 2010-08-05 18:29 1807240 —-a-w- c:\program files\Elantech\ETDCtrl.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper] 2011-08-19 00:07 421736 —-a-w- c:\program files\iTunes\iTunesHelper.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)] 2010-06-01 10:17 5252408 —-a-w- c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr] 2011-05-13 15:03 4283256 —-a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] 2011-07-05 17:36 421888 —-a-w- c:\program files\QuickTime\QTTask.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl] 2010-09-28 20:22 9734760 ——w- c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UIExec] 2010-04-30 16:24 138584 —-a-w- c:\program files\PLAY ONLINE\UIExec.exe . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" "HP Software Update"=c:\program files\HP\HP Software Update\HPWuSchd2.exe "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime . R2 0311831335121373mcinstcleanup;McAfee Application Installer Cleanup (0311831335121373);c:\users\CHRIST~1\AppData\Local\Temp\031183~1.EXE [x] R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2011-07-29 136176] R3 dc3d;MS Hardware Device Detection Driver;c:\windows\system32\DRIVERS\dc3d.sys [2010-07-01 44432] R3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;c:\windows\system32\DRIVERS\ew_hwusbdev.sys [2011-03-23 102784] R3 ew_usbenumfilter;huawei_CompositeFilter;c:\windows\system32\DRIVERS\ew_usbenumfilter.sys [2011-03-23 11136] R3 ewusbmbb;HUAWEI USB-WWAN miniport;c:\windows\system32\DRIVERS\ewusbwwan.sys [2011-03-23 353280] R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2011-07-29 136176] R3 massfilter;ZTE Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter.sys [2009-10-29 9216] R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 139776] R3 Samsung UPD Service;Samsung UPD Service;c:\windows\System32\SUPDSvc.exe [2010-08-09 131888] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224] S1 SABI;SAMSUNG Kernel Driver For Windows 7;c:\windows\system32\Drivers\SABI.sys [2009-05-28 10752] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128] S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928] S2 BecHelperService;BecHelperService;c:\program files\3 Mobile Broadband\3Connect\BecHelperService.exe [2011-03-23 1740696] S2 TeamViewer6;TeamViewer 6;c:\program files\TeamViewer\Version6\TeamViewer_Service.exe [2011-06-01 2337144] S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe [2011-02-18 1517376] S2 UI Assistant Service;UI Assistant Service;c:\program files\PLAY ONLINE\AssistantServices.exe [2010-04-30 252784] S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [2010-08-10 94208] S3 huawei_enumerator;huawei_enumerator;c:\windows\system32\DRIVERS\ew_jubusenum.sys [2011-03-23 73216] S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys [2010-11-29 10064] S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-13 14336] S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x86.sys [2010-07-08 322336] . . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS FontCache fdrespub AppIDSvc QWAVE wcncsvc HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 HPService REG_MULTI_SZ HPSLPSVC hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc . HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs UxTuneUp . Contents of the 'Scheduled Tasks' folder . 2012-04-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2011-07-29 14:57] . 2012-04-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2011-07-29 14:57] . 2012-01-05 c:\windows\Tasks\vtscheduletask.job - c:\program files\McAfee\Supportability\MVT\MvtApp.exe [2012-02-08 12:14] . . ——- Supplementary Scan ——- . uStart Page = uInternet Settings,ProxyOverride = *.local IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000 IE: {{328ECD19-C167-40eb-A0C7-16FE7634105E} - {94BB0C4C-B957-479A-85E4-42F53B89F681} - c:\program files\Samsung AnyWeb Print\W2PBrowser.dll TCP: DhcpNameServer = 192.168.0.1 FF - ProfilePath - c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\l3h69xx6.default\ FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=IEFM1&q= FF - prefs.js: browser.search.selectedEngine - Ask.com FF - prefs.js: browser.startup.homepage - hxxp://www.searchqu.com/406 FF - prefs.js: keyword.URL - hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=IMH6&o=2463&locale=en_UK&apn_uid=a6febd42-8592-484e-92a6-ef079c7ba986&apn_ptnrs=^A3Z&apn_sauid=CD212536-5A1F-4006-87C7-D6D6E7B46209&apn_dtid=^YYYYYY^YY^GB&atb=sysid%3D406%3Aappid%3D101%3Auc&q= FF - prefs.js: network.proxy.type - 0 FF - user.js: general.useragent.extra.brc - FF - user.js: yahoo.ytff.general.dontshowhpoffer - true FF - user.js: network.http.max-persistent-connections-per-server - 4 FF - user.js: nglayout.initialpaint.delay - 600 FF - user.js: content.notify.interval - 600000 FF - user.js: content.max.tokenizing.time - 1800000 FF - user.js: content.switch.threshold - 600000 . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2012-04-23 13:44:57 ComboFix-quarantined-files.txt 2012-04-23 12:44 . Pre-Run: 59,703,934,976 bytes free Post-Run: 59,605,590,016 bytes free . - - End Of File - - 79997A4C222EAE2BD49DE10F3656285F
Hi,

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:
    ClearJavaCache::
    
    File::
    c:\program files\Ask.com\Updater\Updater.exe
    
    Firefox::
    FF - ProfilePath - c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\l3h69xx6.default\
    FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=IEFM1&q=
    FF - prefs.js: browser.search.selectedEngine - Ask.com
    FF - prefs.js: browser.startup.homepage - hxxp://www.searchqu.com/406
    FF - prefs.js: keyword.URL - hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=IMH6&o=2463&locale=en_UK&apn_uid=a6febd42-8592-484e-92a6-ef079c7ba986&apn_ptnrs=^A3Z&apn_sauid=CD212536-5A1F-4006-87C7-D6D6E7B46209&apn_dtid=^YYYYYY^YY^GB&atb=sysid%3D406%3Aappid%3D101%3Auc&q=
    
    RegLock::
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
    
    Registry::
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DATAMNGR]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ApnUpdater]
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
———-
Something went wrong at first. I had no icon on desktop and went to programs/downloads and opened it by right click and administrator, it opened and I then tried to drag it (notepad) into the box. I terminated it. Second time I did this on the desktop as instructed. The notepad after insertion into the icon opened the scan and all went till the end and without any problem. But the notepad remained on the desktop. Please don't tell me off too much, I am exhausted with the entire process. Chris ComboFix 12-04-22.02 - Christina 23/04/2012 16:49:53.4.2 - x86 Microsoft Windows 7 Starter 6.1.7601.1.1252.44.1033.18.1013.387 [GMT 1:00] Running from: c:\users\[removed]\Downloads\ComboFix.exe Command switches used :: c:\users\Christina\Desktop\CFScript.txt SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . FILE :: "c:\program files\Ask.com\Updater\Updater.exe" . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Admin\AppData\Roaming\ubot c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\l3h69xx6.default\weave\toFetch c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\l3h69xx6.default\weave\toFetch\clients.json c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\l3h69xx6.default\weave\toFetch\tabs.json . . ((((((((((((((((((((((((( Files Created from 2012-03-23 to 2012-04-23 ))))))))))))))))))))))))))))))) . . 2012-04-23 16:02 . 2012-04-23 16:03 ——– d—–w- c:\users\Christina\AppData\Local\temp 2012-04-23 16:02 . 2012-04-23 16:02 ——– d—–w- c:\users\Public\AppData\Local\temp 2012-04-23 16:02 . 2012-04-23 16:02 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-04-23 16:02 . 2012-04-23 16:02 ——– d—–w- c:\users\Admin\AppData\Local\temp 2012-04-22 10:54 . 2012-04-22 10:54 ——– d—–w- C:\Reg_Backup 2012-04-22 10:54 . 2012-04-22 11:06 181064 —-a-w- c:\windows\PSEXESVC.EXE 2012-04-22 10:50 . 2012-04-22 11:01 ——– d—–w- C:\Tweaking.com_Windows_Repair_Logs 2012-04-22 10:50 . 2012-04-22 10:50 ——– d—–w- c:\program files\Tweaking.com 2012-04-21 23:01 . 2012-04-04 14:56 22344 —-a-w- c:\windows\system32\drivers\mbam.sys 2012-04-21 23:01 . 2012-04-21 23:01 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2012-04-21 22:32 . 2012-04-22 19:10 ——– d—–w- c:\program files\Common Files\Mcafee 2012-04-21 22:32 . 2012-04-21 22:32 ——– d—–w- c:\program files\McAfee.com 2012-04-17 20:23 . 2012-04-17 20:23 ——– d—–w- c:\program files\ESET 2012-04-17 18:28 . 2012-04-17 18:28 ——– d—–w- c:\users\Christina\AppData\Roaming\Malwarebytes 2012-04-17 18:28 . 2012-04-17 18:28 ——– d—–w- c:\programdata\Malwarebytes 2012-04-17 18:00 . 2012-04-17 18:00 ——– d—–w- C:\found.000 2012-04-17 10:30 . 2012-04-17 10:30 ——– d—–w- C:\_OTL 2012-04-16 23:48 . 2012-04-16 23:48 ——– d—–w- c:\program files\ERUNT 2012-04-12 00:48 . 2012-03-01 05:46 19824 —-a-w- c:\windows\system32\drivers\fs_rec.sys 2012-04-12 00:48 . 2012-03-01 05:37 172544 —-a-w- c:\windows\system32\wintrust.dll 2012-04-12 00:48 . 2012-03-01 05:33 159232 —-a-w- c:\windows\system32\imagehlp.dll 2012-04-12 00:48 . 2012-03-01 05:29 5120 —-a-w- c:\windows\system32\wmi.dll 2012-04-12 00:26 . 2012-03-06 05:59 3968368 —-a-w- c:\windows\system32\ntkrnlpa.exe 2012-04-12 00:26 . 2012-03-06 05:59 3913072 —-a-w- c:\windows\system32\ntoskrnl.exe 2012-04-11 17:32 . 2012-04-11 17:32 ——– d—–w- c:\programdata\AVG Secure Search 2012-04-11 17:32 . 2012-04-11 22:47 ——– d—–w- c:\program files\Common Files\AVG Secure Search 2012-04-11 17:32 . 2012-04-11 22:47 ——– d—–w- c:\program files\AVG Secure Search 2012-04-11 17:26 . 2012-04-11 17:26 ——– d—–w- C:\$AVG 2012-04-11 15:45 . 2012-04-11 15:45 ——– d—–w- c:\program files\Common Files\SpeedyPC Software 2012-04-11 15:45 . 2012-04-11 15:45 ——– d—–w- c:\program files\SpeedyPC Software 2012-04-09 01:12 . 2012-04-09 01:12 ——– d—–w- c:\users\Christina\AppData\Roaming\SpeedyPC Software 2012-04-09 01:12 . 2012-04-11 15:45 ——– d—–w- c:\programdata\SpeedyPC Software 2012-04-04 05:53 . 2012-04-04 05:53 182160 —-a-w- c:\program files\Mozilla Firefox\plugins\nppdf32.dll 2012-04-04 05:53 . 2012-04-04 05:53 182160 —-a-w- c:\program files\Internet Explorer\Plugins\nppdf32.dll 2012-04-03 20:36 . 2012-04-21 14:28 ——– d—–w- c:\users\Christina\AppData\Local\WinZip . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-03-02 11:37 . 2011-05-29 11:29 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-02-17 05:34 . 2012-03-14 16:04 826880 —-a-w- c:\windows\system32\rdpcore.dll 2012-02-17 04:14 . 2012-03-14 16:04 183808 —-a-w- c:\windows\system32\drivers\rdpwd.sys 2012-02-17 04:13 . 2012-03-14 16:04 24576 —-a-w- c:\windows\system32\drivers\tdtcp.sys 2012-02-10 05:38 . 2012-03-14 17:47 1077248 —-a-w- c:\windows\system32\DWrite.dll 2012-02-03 03:54 . 2012-03-14 17:47 2343424 —-a-w- c:\windows\system32\win32k.sys 2012-01-25 05:32 . 2012-03-14 16:05 58880 —-a-w- c:\windows\system32\rdpwsx.dll 2012-01-25 05:32 . 2012-03-14 16:05 129536 —-a-w- c:\windows\system32\rdpcorekmts.dll 2012-01-25 05:27 . 2012-03-14 16:05 8192 —-a-w- c:\windows\system32\rdrmemptylst.exe 2012-03-12 10:45 . 2012-02-13 15:14 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-07-22 150528] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-11-09 142104] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-11-09 174360] "Persistence"="c:\windows\system32\igfxpers.exe" [2011-11-09 150808] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712] . c:\users\Christina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2009-9-20 270336] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . [HKLM\~\startupfolder\C:^Users^Christina^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.3.lnk] backup=c:\windows\pss\OpenOffice.org 3.3.lnk.Startup backupExtension=.Startup . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier] 2011-04-20 11:48 58656 —-a-w- c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ETDCtrl] 2010-08-05 18:29 1807240 —-a-w- c:\program files\Elantech\ETDCtrl.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper] 2011-08-19 00:07 421736 —-a-w- c:\program files\iTunes\iTunesHelper.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)] 2010-06-01 10:17 5252408 —-a-w- c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr] 2011-05-13 15:03 4283256 —-a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] 2011-07-05 17:36 421888 —-a-w- c:\program files\QuickTime\QTTask.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl] 2010-09-28 20:22 9734760 ——w- c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UIExec] 2010-04-30 16:24 138584 —-a-w- c:\program files\PLAY ONLINE\UIExec.exe . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" "HP Software Update"=c:\program files\HP\HP Software Update\HPWuSchd2.exe "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime . R2 0311831335121373mcinstcleanup;McAfee Application Installer Cleanup (0311831335121373);c:\users\CHRIST~1\AppData\Local\Temp\031183~1.EXE [x] R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2011-07-29 136176] R3 dc3d;MS Hardware Device Detection Driver;c:\windows\system32\DRIVERS\dc3d.sys [2010-07-01 44432] R3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;c:\windows\system32\DRIVERS\ew_hwusbdev.sys [2011-03-23 102784] R3 ew_usbenumfilter;huawei_CompositeFilter;c:\windows\system32\DRIVERS\ew_usbenumfilter.sys [2011-03-23 11136] R3 ewusbmbb;HUAWEI USB-WWAN miniport;c:\windows\system32\DRIVERS\ewusbwwan.sys [2011-03-23 353280] R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2011-07-29 136176] R3 massfilter;ZTE Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter.sys [2009-10-29 9216] R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 139776] R3 Samsung UPD Service;Samsung UPD Service;c:\windows\System32\SUPDSvc.exe [2010-08-09 131888] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224] S1 SABI;SAMSUNG Kernel Driver For Windows 7;c:\windows\system32\Drivers\SABI.sys [2009-05-28 10752] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128] S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928] S2 BecHelperService;BecHelperService;c:\program files\3 Mobile Broadband\3Connect\BecHelperService.exe [2011-03-23 1740696] S2 TeamViewer6;TeamViewer 6;c:\program files\TeamViewer\Version6\TeamViewer_Service.exe [2011-06-01 2337144] S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe [2011-02-18 1517376] S2 UI Assistant Service;UI Assistant Service;c:\program files\PLAY ONLINE\AssistantServices.exe [2010-04-30 252784] S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [2010-08-10 94208] S3 huawei_enumerator;huawei_enumerator;c:\windows\system32\DRIVERS\ew_jubusenum.sys [2011-03-23 73216] S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys [2010-11-29 10064] S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-13 14336] S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x86.sys [2010-07-08 322336] . . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS FontCache fdrespub AppIDSvc QWAVE wcncsvc HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 HPService REG_MULTI_SZ HPSLPSVC hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc . HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs UxTuneUp . Contents of the 'Scheduled Tasks' folder . 2012-04-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2011-07-29 14:57] . 2012-04-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2011-07-29 14:57] . 2012-01-05 c:\windows\Tasks\vtscheduletask.job - c:\program files\McAfee\Supportability\MVT\MvtApp.exe [2012-02-08 12:14] . . ——- Supplementary Scan ——- . uStart Page = uInternet Settings,ProxyOverride = *.local IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000 IE: {{328ECD19-C167-40eb-A0C7-16FE7634105E} - {94BB0C4C-B957-479A-85E4-42F53B89F681} - c:\program files\Samsung AnyWeb Print\W2PBrowser.dll TCP: DhcpNameServer = 192.168.0.1 FF - ProfilePath - c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\l3h69xx6.default\ FF - prefs.js: network.proxy.type - 0 FF - user.js: general.useragent.extra.brc - FF - user.js: yahoo.ytff.general.dontshowhpoffer - true FF - user.js: network.http.max-persistent-connections-per-server - 4 FF - user.js: nglayout.initialpaint.delay - 600 FF - user.js: content.notify.interval - 600000 FF - user.js: content.max.tokenizing.time - 1800000 FF - user.js: content.switch.threshold - 600000 . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2012-04-23 17:09:00 ComboFix-quarantined-files.txt 2012-04-23 16:08 ComboFix2.txt 2012-04-23 12:44 . Pre-Run: 59,832,578,048 bytes free Post-Run: 59,544,727,552 bytes free . - - End Of File - - E7430AC7C3EB695AF2E6FAB12B4F7E1
It really is perfect!!! No searchnu! no jumping cursor, everything smooth and quick. I must admit you are a superior being for me; being able to see anything from a long list of such scans and to prepare an appropriate chunk to feed into a programme iois truly an esoteric knowledge and superior intelligence. Thank you very much. What people give usually in donation?
Hi Chris,

Thank you very much. What people give usually in donation?

You are more than welcome! As for a donation, that is really up to you if you want or your thanks is enough. :)
———-

Let's get some updates on your system…

Please download JavaRa to your desktop and unzip it to its own
folder
  • Run JavaRa.exe (double-click for XP/right-click and Run as Administrator for Vista), pick the language of your choice and click Select. Then
    click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe (double-click for XP/right-click and Run as Administrator for Vista) again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest
    Java Runtime Environment (JRE) version for your computer using the Offline version of either x86 (32bit operating system) or x64 (64bit operating system).
———-

Run another scan with DDS and post both of the new logs.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI