This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Am I infected? [Solved]

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My accounts were compromised not too long ago on a website. I am wondering whether or not I have been infected with some type of malware? Perhaps something is lurking and broadcasting my private information?

Here are the results of the OTL scan:

OTL logfile created on: 4/22/2012 7:04:17 PM - Run 1
OTL by OldTimer - Version 3.2.34.0 Folder = H:\antimalware
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 1.68 Gb Available Physical Memory | 55.85% Memory free
6.00 Gb Paging File | 4.63 Gb Available in Paging File | 77.25% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 58.50 Gb Total Space | 7.27 Gb Free Space | 12.42% Space Free | Partition Type: NTFS
Drive D: | 106.67 Gb Total Space | 105.08 Gb Free Space | 98.51% Space Free | Partition Type: NTFS
Drive E: | 67.61 Gb Total Space | 66.05 Gb Free Space | 97.68% Space Free | Partition Type: NTFS
Drive G: | 90.18 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive H: | 3.78 Gb Total Space | 0.14 Gb Free Space | 3.62% Space Free | Partition Type: FAT32

Computer Name: INI-PC | User Name: Ini | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - H:\antimalware\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Ask.com\Updater\Updater.exe (Ask)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - G:\WINDOWS\IronKey.exe (IronKey, Inc.)
PRC - C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe (CANON INC.)
PRC - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (COMODO)
PRC - C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO)
PRC - C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe (Motorola Inc.)
PRC - C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe (ASUS)
PRC - C:\Program Files\ASUS\ATK Hotkey\HControl.exe (ASUS)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Windows\System32\StikyNot.exe (Microsoft Corporation)
PRC - C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe (ASUS)
PRC - C:\Program Files\ASUS\ATK Hotkey\ATKOSD.exe (ASUS)
PRC - C:\Program Files\ASUS\ATK Hotkey\AsLdrSrv.exe (ASUS)
PRC - C:\Program Files\ASUS\ATK Hotkey\WDC.exe (ASUS)
PRC - C:\Program Files\ATKGFNEX\GFNEXSrv.exe ()
PRC - C:\Program Files\SpywareGuard\sgmain.exe ()
PRC - C:\Program Files\SpywareGuard\sgbhp.exe ()


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\Windows\System32\Macromed\Flash\NPSWF32.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - G:\WINDOWS\zlib1.dll ()
MOD - G:\WINDOWS\ikvip.dll ()
MOD - C:\Program Files\Adobe\Reader 9.0\Reader\ViewerPS.dll ()
MOD - C:\Program Files\SpywareGuard\sgmain.exe ()
MOD - C:\Program Files\SpywareGuard\sgbhp.exe ()
MOD - C:\Program Files\SpywareGuard\dlprotect.dll ()


========== Win32 Services (SafeList) ==========

SRV - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (BITCOMET_HELPER_SERVICE) – C:\Program Files\BitComet\tools\BitCometService.exe (www.BitComet.com)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (cmdAgent) – C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (COMODO)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) – C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (ASLDRService) – C:\Program Files\ASUS\ATK Hotkey\AsLdrSrv.exe (ASUS)
SRV - (ATKGFNEXSrv) – C:\Program Files\ATKGFNEX\GFNEXSrv.exe ()


========== Driver Services (SafeList) ==========

DRV - (aswSnx) – C:\Windows\System32\drivers\aswSnx.sys (AVAST Software)
DRV - (aswSP) – C:\Windows\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswRdr) – C:\Windows\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (aswTdi) – C:\Windows\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswMonFlt) – C:\Windows\System32\drivers\aswMonFlt.sys (AVAST Software)
DRV - (aswFsBlk) – C:\Windows\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (cmdGuard) – C:\Windows\System32\drivers\cmdGuard.sys (COMODO)
DRV - (inspect) – C:\Windows\System32\drivers\inspect.sys (COMODO)
DRV - (cmdHlp) – C:\Windows\System32\drivers\cmdhlp.sys (COMODO)
DRV - (AVerFx2hbtv) – C:\Windows\System32\drivers\AVerFx2hbtv.sys (AVerMedia TECHNOLOGIES, Inc.)
DRV - (smserial) – C:\Windows\System32\drivers\smserial.sys (Motorola Inc.)
DRV - (vmbus) – C:\Windows\system32\DRIVERS\vmbus.sys (Microsoft Corporation)
DRV - (storflt) – C:\Windows\system32\DRIVERS\vmstorfl.sys (Microsoft Corporation)
DRV - (storvsc) – C:\Windows\system32\DRIVERS\storvsc.sys (Microsoft Corporation)
DRV - (vwifimp) – C:\Windows\System32\drivers\vwifimp.sys (Microsoft Corporation)
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (s3cap) – C:\Windows\system32\DRIVERS\vms3cap.sys (Microsoft Corporation)
DRV - (VMBusHID) – C:\Windows\system32\DRIVERS\VMBusHID.sys (Microsoft Corporation)
DRV - (TPM) – C:\Windows\System32\drivers\tpm.sys (Microsoft Corporation)
DRV - (netw5v32) Intel® – C:\Windows\System32\drivers\netw5v32.sys (Intel Corporation)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (MTsensor) – C:\Windows\System32\drivers\ATKACPI.sys (ASUS)
DRV - (netr28u) – C:\Windows\System32\drivers\netr28u.sys (Ralink Technology Corp.)
DRV - (ASMMAP) – C:\Program Files\ATKGFNEX\ASMMAP.sys ()
DRV - (rismxdp) – C:\Windows\System32\drivers\rixdptsk.sys (REDC)
DRV - (rimmptsk) – C:\Windows\System32\drivers\rimmptsk.sys (REDC)
DRV - (rimsptsk) – C:\Windows\System32\drivers\rimsptsk.sys (REDC)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.google.com/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/?babsrc=HP_ss&am;…000001561524eae
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = F1 39 FC B3 F6 38 CB 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{91607fa7-3c2f-4f90-93e3-d5337a6b0ac2}: "URL" = playbryte/search/redirect/?type=default&user;_id=ff21076b-39b0-4b88-ba9f-5f1dca62f0e7&query;={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "https://mail.google.com/mail/?shva=1#inbox"
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:4.2.0.5198
FF - prefs.js..extensions.enabledItems: [removed]:0.2.4.1
FF - prefs.js..extensions.enabledItems: vshareus@toolbar:1.0.0
FF - prefs.js..extensions.enabledItems: [removed]:1.11
FF - prefs.js..extensions.enabledItems: {86095750-AD15-46d8-BF32-C0789F7E6A32}:1.0.75
FF - prefs.js..extensions.enabledItems: [removed]:3.11.3.15590
FF - prefs.js..network.proxy.type: 0


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@pages.tvunetworks.com/WebPlayer: C:\Windows\system32\TVUAx\npTVUAx.dll (TVU networks)
FF - HKLM\Software\MozillaPlugins\@qq.com/QzoneMusic: C:\Program Files\Tencent\QQMusic\npQzoneMusic.dll (Tencent)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Ini\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Ini\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/04/22 18:59:51 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/03/05 02:08:43 | 000,000,000 | —D | M]

[2010/07/09 21:58:11 | 000,000,000 | —D | M] (No name found) – C:\Users\Ini\AppData\Roaming\Mozilla\Extensions
[2012/03/05 02:08:43 | 000,000,000 | —D | M] (No name found) – C:\Users\Ini\AppData\Roaming\Mozilla\Firefox\Profiles\emea68ub.default\extensions
[2012/03/05 02:08:44 | 000,000,000 | —D | M] (BitComet Video Downloader) – C:\Users\Ini\AppData\Roaming\Mozilla\Firefox\Profiles\emea68ub.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}
[2012/01/02 02:41:07 | 000,000,000 | —D | M] (Browse For Change) – C:\Users\Ini\AppData\Roaming\Mozilla\Firefox\Profiles\emea68ub.default\extensions\[removed]
[2012/01/02 09:59:33 | 000,000,000 | —D | M] (Babylon) – C:\Users\Ini\AppData\Roaming\Mozilla\Firefox\Profiles\emea68ub.default\extensions\[removed]
[2011/07/27 07:22:55 | 000,000,000 | —D | M] (TVU Web Player) – C:\Users\Ini\AppData\Roaming\Mozilla\Firefox\Profiles\emea68ub.default\extensions\[removed]
[2012/01/02 02:41:28 | 000,000,000 | —D | M] (PlayBryte) – C:\Users\Ini\AppData\Roaming\Mozilla\Firefox\Profiles\emea68ub.default\extensions\[removed]
[2012/01/02 02:40:39 | 000,000,000 | —D | M] (Yontoo) – C:\Users\Ini\AppData\Roaming\Mozilla\Firefox\Profiles\emea68ub.default\extensions\[removed]
[2010/12/22 17:32:22 | 000,000,000 | —D | M] ("AutocompletePro - Your handy search suggestions tool") – C:\Users\Ini\AppData\Roaming\Mozilla\Firefox\Profiles\emea68ub.default\extensions\[removed]
[2011/12/20 22:50:21 | 000,000,000 | —D | M] (Ask Toolbar) – C:\Users\Ini\AppData\Roaming\Mozilla\Firefox\Profiles\emea68ub.default\extensions\[removed]
[2010/10/16 20:17:41 | 000,000,000 | —D | M] (vShare Plugin) – C:\Users\Ini\AppData\Roaming\Mozilla\Firefox\Profiles\emea68ub.default\extensions\vshareus@toolbar
[2012/01/25 19:14:48 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/07/09 22:11:04 | 000,000,000 | —D | M] (Skype extension for Firefox) – C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
() (No name found) – C:\USERS\INI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EMEA68UB.DEFAULT\EXTENSIONS\{86095750-AD15-46D8-BF32-C0789F7E6A32}.XPI
[2012/04/22 18:59:50 | 000,097,208 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/11/03 02:59:20 | 000,917,816 | —- | M] (BitComet) – C:\Program Files\mozilla firefox\plugins\npBitCometAgent.dll
[2011/03/18 15:32:12 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
[2011/10/03 06:06:04 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/03/18 15:32:14 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npMozCouponPrinter.dll
[2010/09/10 02:19:24 | 000,305,152 | —- | M] ( ) – C:\Program Files\mozilla firefox\plugins\npuuseep.dll
[2012/04/22 18:59:48 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/04/22 18:59:48 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Ini\AppData\Local\Google\Chrome\Application\18.0.1025.162\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Ini\AppData\Local\Google\Chrome\Application\18.0.1025.162\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Ini\AppData\Local\Google\Chrome\Application\18.0.1025.162\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\Ini\AppData\Local\Google\Chrome\User Data\PepperFlash\11.1.31.203\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: 56ICANPlugin (Enabled) = C:\Users\Ini\AppData\Local\Google\Chrome\User Data\Default\Extensions\igcnieghjaijfgekdbamdgbaicckhelo\1.0.0.1_0\np56icanplugin.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.290.11 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U29 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: BitCometAgent (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npBitCometAgent.dll
CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npMozCouponPrinter.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: npruntime scriptable example plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npuuseep.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\Microsoft\Office Live\npOLW.dll
CHR - plugin: QQMusic (Enabled) = C:\Program Files\Tencent\QQMusic\npQzoneMusic.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Ini\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: TVU Web Player for FireFox (Enabled) = C:\Windows\system32\TVUAx\npTVUAx.dll
CHR - Extension: PlayBryte = C:\Users\Ini\AppData\Local\Google\Chrome\User Data\Default\Extensions\akbkdomfdgaijlahpfcnhaifemjfdfnh\1.0_0\
CHR - Extension: YouTube = C:\Users\Ini\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\Ini\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: AutocompletePro plugin for chrome = C:\Users\Ini\AppData\Local\Google\Chrome\User Data\Default\Extensions\defdhglnppeioeflggkmglipcecffkhk\1.0_1\
CHR - Extension: Browse For Change = C:\Users\Ini\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkappjlcaehkpnjgompookobajdjkkfm\1.0_0\
CHR - Extension: 56icanplugin = C:\Users\Ini\AppData\Local\Google\Chrome\User Data\Default\Extensions\igcnieghjaijfgekdbamdgbaicckhelo\1.0.0.1_0\
CHR - Extension: Yontoo = C:\Users\Ini\AppData\Local\Google\Chrome\User Data\Default\Extensions\niapdbllcanepiiimjjndipklodoedlc\1.0.2_0\
CHR - Extension: Gmail = C:\Users\Ini\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2009/06/10 17:39:37 | 000,000,824 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (AC-Pro) - {0FB6A909-6086-458F-BD92-1F8EE10042A0} - C:\Program Files\AutocompletePro\AutocompletePro.dll (SimplyGen)
O2 - BHO: (BitComet Helper) - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.5.4.11.dll (BitComet)
O2 - BHO: (SpywareGuardDLBLOCK.CBrowserHelper) - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll ()
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (Yontoo) - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files\Yontoo\YontooIEClient.dll (Yontoo LLC)
O3 - HKLM\..\Toolbar: (no name) - {06C7AD57-B655-418D-9AB8-9526A6D2E052} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {b278d9f8-0fa9-465e-9938-0c392605d8e3} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files\Ask.com\Updater\Updater.exe (Ask)
O4 - HKLM..\Run: [ATKOSD2] C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe (ASUS)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO)
O4 - HKLM..\Run: [HControlUser] C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe (ASUS)
O4 - HKLM..\Run: [iBryte browseforchange Desktop] C:\Program Files\iBryte\browseforchange\ibrytedesktop.exe File not found
O4 - HKLM..\Run: [iBryte playbryte Desktop] C:\Program Files\iBryte\playbryte\ibrytedesktop.exe File not found
O4 - HKLM..\Run: [IJNetworkScanUtility] C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe (CANON INC.)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe (Motorola Inc.)
O4 - HKCU..\Run: [eMuleAutoStart] C:\Program Files\easyMule\eMule.exe -AutoStart File not found
O4 - HKCU..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe (Microsoft Corporation)
O4 - Startup: C:\Users\Ini\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Epson all-in-one Registration.lnk = File not found
O4 - Startup: C:\Users\Ini\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8 - Extra context menu item: &使用BitComet下載 - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
O8 - Extra context menu item: &使用BitComet下載全部連結 - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - C:\Program Files\BitComet\tools\BitCometBHO_1.5.4.11.dll (BitComet)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlcdnet.asus.com/pub/ASUS/misc/dlm-…vex-2.2.5.0.cab (DLM Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{57B3753B-2457-4488-A559-ACAC8A1E45BE}: DhcpNameServer = [removed] [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{CAE96C25-6A77-4807-A3AB-8730E398450F}: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EE17E30D-C3B6-4F35-AA76-C57780891970}: DhcpNameServer = [removed] [removed] [removed]
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - AppInit_DLLs: (C:\Windows\system32\guard32.dll) - C:\Windows\System32\guard32.dll (COMODO)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {81559C35-8464-49F7-BB0E-07A383BEF910} - C:\Program Files\SpywareGuard\spywareguard.dll ()
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 17:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2010/11/13 17:58:46 | 000,000,074 | R— | M] () - G:\AUTORUN.INF – [ CDFS ]
O32 - Unable to obtain root file information for disk H:\
O33 - MountPoints2\{cc134bba-8cc5-11e1-b1b6-90e6ba69a22d}\Shell - "" = AutoRun
O33 - MountPoints2\{cc134bba-8cc5-11e1-b1b6-90e6ba69a22d}\Shell\AutoRun\command - "" = G:\IronKey.exe – [2010/11/13 17:58:46 | 000,341,336 | R— | M] (IronKey Inc.)
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.ac3acm - C:\Windows\System32\ac3acm.acm (fccHandler)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\Windows\System32\lameACM.acm (http://www.mp3dev.org/)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - C:\Windows\System32\ff_vfw.dll ()
Drivers32: vidc.XVID - C:\Windows\System32\xvidvfw.dll ()
Drivers32: VIDC.YV12 - C:\Windows\System32\yv12vfw.dll (www.helixcommunity.org)
Drivers32: wave1 - C:\Windows\System32\serwvdrv.dll (Microsoft Corporation)
Drivers32: wave2 - C:\Windows\System32\serwvdrv.dll (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/04/17 18:51:09 | 000,000,000 | —D | C] – C:\Users\Ini\Desktop\Originals
[2012/04/13 03:07:57 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2012/04/13 03:07:55 | 001,799,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2012/04/13 03:07:54 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2012/04/13 03:07:53 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2012/04/13 03:07:53 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2012/04/13 03:07:51 | 001,427,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2012/04/13 03:07:29 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2012/04/13 03:00:54 | 003,958,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2012/04/13 03:00:52 | 003,902,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2012/04/12 00:23:18 | 000,000,000 | —D | C] – C:\Users\Ini\Desktop\pic
[2012/03/28 07:11:42 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MP560 series

========== Files - Modified Within 30 Days ==========

[2012/04/22 19:04:36 | 000,014,816 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/04/22 19:04:36 | 000,014,816 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/04/22 19:03:00 | 000,000,900 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-16478551-3455753284-2568791741-1000UA.job
[2012/04/22 18:57:05 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/04/22 18:56:57 | 2415,321,088 | -HS- | M] () – C:\hiberfil.sys
[2012/04/22 18:31:43 | 000,001,067 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/04/22 18:31:09 | 000,624,178 | —- | M] () – C:\Windows\System32\perfh009.dat
[2012/04/22 18:31:09 | 000,386,040 | —- | M] () – C:\Windows\System32\prfh0404.dat
[2012/04/22 18:31:09 | 000,369,938 | —- | M] () – C:\Windows\System32\prfh0804.dat
[2012/04/22 18:31:09 | 000,106,522 | —- | M] () – C:\Windows\System32\perfc009.dat
[2012/04/22 18:31:09 | 000,104,382 | —- | M] () – C:\Windows\System32\prfc0804.dat
[2012/04/22 18:31:09 | 000,099,468 | —- | M] () – C:\Windows\System32\prfc0404.dat
[2012/04/22 00:44:42 | 000,000,470 | —- | M] () – C:\Users\Ini\AppData\Roaming\Poladroid prefs.plist
[2012/04/22 00:44:20 | 000,233,733 | —- | M] () – C:\Users\Ini\Desktop\4537087038_ab8b3fb923_z.jpg
[2012/04/22 00:42:41 | 000,056,320 | -H– | M] () – C:\Users\Ini\Desktop\photothumb.db
[2012/04/22 00:39:47 | 000,161,454 | —- | M] () – C:\Users\Ini\Desktop\5688969793_d0f51e5f60_z.jpg
[2012/04/22 00:36:53 | 000,238,719 | —- | M] () – C:\Users\Ini\Desktop\IMG_0679.JPG
[2012/04/22 00:36:01 | 000,218,958 | —- | M] () – C:\Users\Ini\Desktop\IMG_0674.JPG
[2012/04/22 00:33:55 | 000,218,362 | —- | M] () – C:\Users\Ini\Desktop\IMG_0575.JPG
[2012/04/20 13:03:00 | 000,000,848 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-16478551-3455753284-2568791741-1000Core.job
[2012/04/12 22:43:14 | 000,002,385 | —- | M] () – C:\Users\Ini\Desktop\Google Chrome.lnk
[2012/04/04 15:56:40 | 000,022,344 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys

========== Files Created - No Company Name ==========

[2012/04/22 00:40:49 | 000,233,733 | —- | C] () – C:\Users\Ini\Desktop\4537087038_ab8b3fb923_z.jpg
[2012/04/22 00:39:46 | 000,161,454 | —- | C] () – C:\Users\Ini\Desktop\5688969793_d0f51e5f60_z.jpg
[2012/04/22 00:31:57 | 000,238,719 | —- | C] () – C:\Users\Ini\Desktop\IMG_0679.JPG
[2012/04/22 00:31:52 | 000,218,958 | —- | C] () – C:\Users\Ini\Desktop\IMG_0674.JPG
[2012/04/22 00:31:30 | 000,218,362 | —- | C] () – C:\Users\Ini\Desktop\IMG_0575.JPG
[2011/12/09 13:51:01 | 000,087,552 | —- | C] () – C:\Windows\System32\cpwmon2k.dll
[2011/11/30 21:53:45 | 000,013,931 | —- | C] () – C:\Windows\System32\RaCoInst.dat
[2010/11/19 01:15:41 | 000,000,470 | —- | C] () – C:\Users\Ini\AppData\Roaming\Poladroid prefs.plist
[2010/07/13 00:21:09 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2010/07/11 13:19:05 | 000,073,220 | —- | C] () – C:\Windows\System32\EPPICPrinterDB.dat
[2010/07/11 13:19:05 | 000,031,053 | —- | C] () – C:\Windows\System32\EPPICPattern131.dat
[2010/07/11 13:19:05 | 000,029,114 | —- | C] () – C:\Windows\System32\EPPICPattern1.dat
[2010/07/11 13:19:05 | 000,027,417 | —- | C] () – C:\Windows\System32\EPPICPattern121.dat
[2010/07/11 13:19:05 | 000,021,021 | —- | C] () – C:\Windows\System32\EPPICPattern3.dat
[2010/07/11 13:19:05 | 000,015,670 | —- | C] () – C:\Windows\System32\EPPICPattern5.dat
[2010/07/11 13:19:05 | 000,013,280 | —- | C] () – C:\Windows\System32\EPPICPattern2.dat
[2010/07/11 13:19:05 | 000,010,673 | —- | C] () – C:\Windows\System32\EPPICPattern4.dat
[2010/07/11 13:19:05 | 000,004,943 | —- | C] () – C:\Windows\System32\EPPICPattern6.dat
[2010/07/11 13:19:05 | 000,001,140 | —- | C] () – C:\Windows\System32\EPPICPresetData_PT.dat
[2010/07/11 13:19:05 | 000,001,140 | —- | C] () – C:\Windows\System32\EPPICPresetData_BP.dat
[2010/07/11 13:19:05 | 000,001,137 | —- | C] () – C:\Windows\System32\EPPICPresetData_ES.dat
[2010/07/11 13:19:05 | 000,001,130 | —- | C] () – C:\Windows\System32\EPPICPresetData_FR.dat
[2010/07/11 13:19:05 | 000,001,130 | —- | C] () – C:\Windows\System32\EPPICPresetData_CF.dat
[2010/07/11 13:19:05 | 000,001,104 | —- | C] () – C:\Windows\System32\EPPICPresetData_EN.dat
[2010/07/11 13:19:05 | 000,000,097 | —- | C] () – C:\Windows\System32\PICSDK.ini
[2010/07/11 13:17:03 | 000,000,044 | —- | C] () – C:\Windows\EPNX410.ini
[2010/07/09 22:34:31 | 000,386,040 | —- | C] () – C:\Windows\System32\prfh0404.dat
[2010/07/09 22:34:31 | 000,369,938 | —- | C] () – C:\Windows\System32\prfh0804.dat
[2010/07/09 22:34:31 | 000,117,840 | —- | C] () – C:\Windows\System32\prfi0404.dat
[2010/07/09 22:34:31 | 000,111,310 | —- | C] () – C:\Windows\System32\prfi0804.dat
[2010/07/09 22:34:31 | 000,104,382 | —- | C] () – C:\Windows\System32\prfc0804.dat
[2010/07/09 22:34:31 | 000,099,468 | —- | C] () – C:\Windows\System32\prfc0404.dat
[2010/07/09 22:34:31 | 000,031,548 | —- | C] () – C:\Windows\System32\prfd0804.dat
[2010/07/09 22:34:31 | 000,031,548 | —- | C] () – C:\Windows\System32\prfd0404.dat
[2010/07/09 21:58:06 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat
[2010/07/09 21:30:17 | 000,165,376 | —- | C] () – C:\Windows\System32\unrar.dll
[2010/07/09 21:30:17 | 000,000,038 | —- | C] () – C:\Windows\avisplitter.ini
[2010/07/09 21:30:12 | 000,650,752 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2010/07/09 21:30:12 | 000,240,640 | —- | C] () – C:\Windows\System32\xvidvfw.dll
[2010/07/09 21:30:11 | 000,108,032 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2010/07/09 21:00:08 | 000,000,017 | —- | C] () – C:\Users\Ini\AppData\Local\resmon.resmoncfg

========== LOP Check ==========

[2010/07/27 00:02:57 | 000,000,000 | —D | M] – C:\Users\Ini\AppData\Roaming\acccore
[2011/03/24 05:23:11 | 000,000,000 | —D | M] – C:\Users\Ini\AppData\Roaming\Amazon
[2012/01/02 02:39:59 | 000,000,000 | —D | M] – C:\Users\Ini\AppData\Roaming\Babylon
[2012/03/14 12:51:04 | 000,000,000 | —D | M] – C:\Users\Ini\AppData\Roaming\BitComet
[2010/11/04 22:20:42 | 000,000,000 | —D | M] – C:\Users\Ini\AppData\Roaming\EPSON
[2010/12/02 08:09:07 | 000,000,000 | —D | M] – C:\Users\Ini\AppData\Roaming\ICAClient
[2012/01/02 02:49:26 | 000,000,000 | —D | M] – C:\Users\Ini\AppData\Roaming\InfraRecorder
[2011/04/21 17:17:22 | 000,000,000 | —D | M] – C:\Users\Ini\AppData\Roaming\KKman
[2010/07/11 13:30:05 | 000,000,000 | —D | M] – C:\Users\Ini\AppData\Roaming\Leadertech
[2011/03/20 00:30:20 | 000,000,000 | —D | M] – C:\Users\Ini\AppData\Roaming\Maxthon2
[2012/04/21 02:12:20 | 000,000,000 | —D | M] – C:\Users\Ini\AppData\Roaming\MxBoost
[2010/09/20 03:54:41 | 000,000,000 | —D | M] – C:\Users\Ini\AppData\Roaming\PCMan
[2010/07/09 20:36:31 | 000,000,000 | —D | M] – C:\Users\Ini\AppData\Roaming\PeaZip
[2011/05/26 23:19:04 | 000,000,000 | —D | M] – C:\Users\Ini\AppData\Roaming\PhotoScape
[2010/10/15 14:45:11 | 000,000,000 | —D | M] – C:\Users\Ini\AppData\Roaming\QQMusicUpdate
[2011/10/22 09:22:58 | 000,000,000 | —D | M] – C:\Users\Ini\AppData\Roaming\reading.udn.com
[2010/08/31 21:55:21 | 000,000,000 | —D | M] – C:\Users\Ini\AppData\Roaming\StreamTorrent
[2011/12/21 10:05:57 | 000,000,000 | —D | M] – C:\Users\Ini\AppData\Roaming\TeamViewer
[2011/03/23 23:02:15 | 000,000,000 | —D | M] – C:\Users\Ini\AppData\Roaming\Tencent
[2011/02/12 01:32:05 | 000,000,000 | —D | M] – C:\Users\Ini\AppData\Roaming\Trillian
[2011/04/21 17:16:49 | 000,000,000 | —D | M] – C:\Users\Ini\AppData\Roaming\uTorrent
[2012/03/26 23:17:11 | 000,032,640 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/06/10 17:42:20 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/06/10 17:42:20 | 000,000,010 | —- | M] () – C:\config.sys
[2012/04/22 18:56:57 | 2415,321,088 | -HS- | M] () – C:\hiberfil.sys
[2010/07/27 00:02:45 | 000,000,694 | -H– | M] () – C:\IPH.PH
[2012/04/22 18:57:03 | 3220,430,848 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2009/07/14 00:52:25 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 00:52:25 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 00:52:25 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 00:52:25 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 17:31:19 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2010/04/24 06:00:00 | 000,027,648 | —- | M] (CANON INC.) – C:\Windows\system32\spool\prtprocs\w32x86\CNMPDA0.DLL
[2010/04/24 06:00:00 | 000,070,656 | —- | M] (CANON INC.) – C:\Windows\system32\spool\prtprocs\w32x86\CNMPPA0.DLL
[2009/07/13 21:15:35 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 19:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\msonpppr.dll
[2009/07/13 21:16:19 | 000,029,696 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\winprint.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2011/09/06 16:45:29 | 000,041,184 | —- | M] (AVAST Software) – C:\Windows\avastSS.scr

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 00:41:57 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/03/02 23:56:52 | 000,000,221 | -HS- | M] () – C:\Users\Ini\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/02/19 05:15:29 | 002,245,264 | —- | M] () – C:\Users\Ini\Desktop\PPLiveLiteCompleteSetup.exe
[2009/07/13 05:04:46 | 005,132,288 | —- | M] () – C:\Users\Ini\Desktop\prime95.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-04-20 14:36:06

========== Files - Unicode (All) ==========
[2011/10/22 09:22:47 | 000,000,320 | —- | M] ()(C:\Users\Ini\Desktop\udn ?????.appref-ms) – C:\Users\Ini\Desktop\udn 數位閱讀網.appref-ms
[2011/10/22 09:22:47 | 000,000,320 | —- | C] ()(C:\Users\Ini\Desktop\udn ?????.appref-ms) – C:\Users\Ini\Desktop\udn 數位閱讀網.appref-ms
[2011/01/21 02:20:06 | 000,010,390 | —- | M] ()(C:\Users\Ini\Documents\???.docx) – C:\Users\Ini\Documents\蜘蛛俠.docx
[2011/01/21 02:20:05 | 000,010,390 | —- | C] ()(C:\Users\Ini\Documents\???.docx) – C:\Users\Ini\Documents\蜘蛛俠.docx
[2010/12/19 18:27:08 | 000,051,972 | —- | M] ()(C:\Users\Ini\Desktop\???? _ Roller Boogie - 25_365 - 4_52 Music & Blythe _ Flickr - ????!.htm) – C:\Users\Ini\Desktop\全部尺寸 _ Roller Boogie - 25_365 - 4_52 Music & Blythe _ Flickr - 相片分享!.htm
[2010/12/19 18:27:07 | 000,000,000 | —D | M](C:\Users\Ini\Desktop\???? _ Roller Boogie - 25_365 - 4_52 Music & Blythe _ Flickr - ????!_files) – C:\Users\Ini\Desktop\全部尺寸 _ Roller Boogie - 25_365 - 4_52 Music & Blythe _ Flickr - 相片分享!_files
[2010/12/19 18:27:07 | 000,000,000 | —D | C](C:\Users\Ini\Desktop\???? _ Roller Boogie - 25_365 - 4_52 Music & Blythe _ Flickr - ????!_files) – C:\Users\Ini\Desktop\全部尺寸 _ Roller Boogie - 25_365 - 4_52 Music & Blythe _ Flickr - 相片分享!_files
[2010/12/19 18:27:06 | 000,051,972 | —- | C] ()(C:\Users\Ini\Desktop\???? _ Roller Boogie - 25_365 - 4_52 Music & Blythe _ Flickr - ????!.htm) – C:\Users\Ini\Desktop\全部尺寸 _ Roller Boogie - 25_365 - 4_52 Music & Blythe _ Flickr - 相片分享!.htm
[2010/10/15 14:44:32 | 000,001,097 | —- | M] ()(C:\Users\Public\Desktop\QQ??.lnk) – C:\Users\Public\Desktop\QQ音乐.lnk
[2010/10/15 14:44:32 | 000,001,097 | —- | C] ()(C:\Users\Public\Desktop\QQ??.lnk) – C:\Users\Public\Desktop\QQ音乐.lnk
(C:\Users\Ini\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\????) – C:\Users\Ini\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\聯合線上

< End of report >

——————— Extras below —————————————

OTL Extras logfile created on: 4/22/2012 7:04:17 PM - Run 1
OTL by OldTimer - Version 3.2.34.0 Folder = H:\antimalware
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 1.68 Gb Available Physical Memory | 55.85% Memory free
6.00 Gb Paging File | 4.63 Gb Available in Paging File | 77.25% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 58.50 Gb Total Space | 7.27 Gb Free Space | 12.42% Space Free | Partition Type: NTFS
Drive D: | 106.67 Gb Total Space | 105.08 Gb Free Space | 98.51% Space Free | Partition Type: NTFS
Drive E: | 67.61 Gb Total Space | 66.05 Gb Free Space | 97.68% Space Free | Partition Type: NTFS
Drive G: | 90.18 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive H: | 3.78 Gb Total Space | 0.14 Gb Free Space | 3.62% Space Free | Partition Type: FAT32

Computer Name: INI-PC | User Name: Ini | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PeaZip] – Reg Error: Value error.
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\iBryte\browseforchange\ibrytedesktop.exe" = C:\Program Files\iBryte\browseforchange\ibrytedesktop.exe:*:Enabled:iBryteDesktop
"C:\Program Files\iBryte\playbryte\ibrytedesktop.exe" = C:\Program Files\iBryte\playbryte\ibrytedesktop.exe:*:Enabled:iBryteDesktop


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}" = Windows Live ID Sign-in Assistant
"{086D343F-8E78-4AFC-81AC-D6D414AFD8AC}_is1" = Core Temp version 0.99.8
"{0EDBEB2B-7C8D-42E6-8312-0F84394A3223}" = Windows Media Center Add-in for Silverlight
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP560_series" = Canon MP560 series MP Drivers
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2624B969-7135-4EB1-B0F6-2D8C397B45F7}_is1" = Media Player Classic - Home Cinema v. 1.3.1249.0
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 29
"{28DA7D8B-F9A4-4F18-8AA0-551B1E084D0D}" = Ralink RT2870 Wireless LAN Card
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{3B05F2FB-745B-4012-ADF2-439F36B2E70B}" = ATKOSD2
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{59F6A514-9813-47A3-948C-8A155460CC2A}" = RICOH R5C83x/84x Flash Media Controller Driver Ver.3.51.01
"{5A2BC38A-406C-4A5B-BF45-6991F9A05325}_is1" = PeaZip 3.2.1
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{69995C7A-062A-4A90-A4DF-8C22895DF522}" = iTunes
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6A3F9D74-BB80-4451-8CA1-4B3A857F1359}" = Apple Application Support
"{7C05592D-424B-46CB-B505-E0013E8E75C9}" = ATK Hotkey
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{889DF117-14D1-44EE-9F31-C5FB5D47F68B}" = Yontoo 1.10.02
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D318C86-AF4C-409F-A6AC-7183FF4CF424}" = Internet TV for Windows Media Center
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.6
"{AC76BA86-7AD7-2447-0000-900000000003}" = Chinese Simplified Fonts Support For Adobe Reader 9
"{AC76BA86-7AD7-2448-0000-900000000003}" = Chinese Traditional Fonts Support For Adobe Reader 9
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{C0B165DC-F037-483F-B1C9-D89D91529CEB}" = Citrix XenApp Web Plugin
"{C23CD6DA-1958-43A5-ADD0-59396572E02E}" = Apple Mobile Device Support
"{C6579A65-9CAE-4B31-8B6B-3306E0630A66}" = Apple Software Update
"{C9E14402-3631-4182-B377-6B0DFB1C0339}" = QuickTime
"{CAEAD1E4-A15F-4249-A1B6-9D42080C7361}" = Adobe Photoshop Lightroom 3.4
"{CC6B1BB4-4E06-4A5B-A166-B371B551324B}" = COMODO Internet Security
"{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}" = PlayReady PC Runtime x86
"{CFF8B8E8-E086-4DE0-935F-FE22CAB54F80}" = Microsoft Search Enhancement Pack
"{D03482C5-9AD8-496D-B388-692AE04C93AF}" = Bonjour
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D3D54F3E-C5C3-443D-978F-87A72E5616E8}" = ATK Generic Function Service
"{D7E04009-B191-4E9D-9D2D-1BBE57BD8A42}" = VistaFeaturePack
"{E2D09AC2-4153-4817-AAEB-24F92A8BCE88}" = Windows Media Center Add-in for Flash
"{E34ACF2A-38BA-3348-90F6-B76A34647AB0}" = Microsoft .NET Framework 4 Client Profile CHT Language Pack
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{E8FF78D0-4D1C-4B2D-AC80-670F135F5461}" = Poladroid
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5
"{FE0646A7-19D0-41B4-A2BB-2C35D644270D}" = Windows Live OneCare safety scanner
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"AutocompletePro3_is1" = AutocompletePro
"avast" = avast! Free Antivirus
"BitComet" = BitComet(比特彗星) 1.31
"Canon_IJ_Network_Scan_UTILITY" = Canon IJ Network Scan Utility
"Canon_IJ_Network_UTILITY" = Canon IJ Network Tool
"Coupon Printer for Windows5.0.0.1" = Coupon Printer for Windows
"CutePDF Writer Installation" = CutePDF Writer 2.8
"ENTERPRISE" = Microsoft Office Enterprise 2007
"iBryte_browseforchange" = Browse For Change
"ImgBurn" = ImgBurn
"InfraRecorder" = InfraRecorder
"InstallShield_{D7E04009-B191-4E9D-9D2D-1BBE57BD8A42}" = VistaFeaturePack
"KLiteCodecPack_is1" = K-Lite Codec Pack 6.1.0 (Full)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.61.0.1400
"Maxthon2" = Maxthon2
"MetaFrame Presentation Server Web Client for Win32" = MetaFrame Presentation Server Web Client for Win32
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile CHT Language Pack" = Microsoft .NET Framework 4 Client Profile 繁體中文語言套件
"Mozilla Firefox 11.0 (x86 en-US)" = Mozilla Firefox 11.0 (x86 en-US)
"NVIDIA Drivers" = NVIDIA Drivers
"PhotoScape" = PhotoScape
"QQMusic" = QQ音乐 2010
"SMSERIAL" = Motorola SM56 Speakerphone Modem
"SpywareBlaster_is1" = SpywareBlaster 4.3
"SpywareGuard_is1" = SpywareGuard v2.2
"StreamTorrent 1.0" = StreamTorrent 1.0
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"VLC media player" = VLC media player 1.1.2
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"WinLiveSuite_Wave3" = Windows Live Essentials
"Xvid Video Codec 1.3.1" = Xvid Video Codec

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{79A765E1-C399-405B-85AF-466F52E918B0}" = Ask Toolbar Updater
"7e71a2cfde898e63" = udn 數位閱讀網
"Amazon Kindle For PC" = Amazon Kindle For PC
"blinkx beat" = blinkx beat
"Google Chrome" = Google Chrome

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 4/12/2012 12:43:08 PM | Computer Name = Ini-PC | Source = Bonjour Service | ID = 100
Description = 472: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

Error - 4/12/2012 12:43:08 PM | Computer Name = Ini-PC | Source = Bonjour Service | ID = 100
Description = 480: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

Error - 4/12/2012 12:43:08 PM | Computer Name = Ini-PC | Source = Bonjour Service | ID = 100
Description = 488: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

Error - 4/16/2012 9:00:42 AM | Computer Name = Ini-PC | Source = Bonjour Service | ID = 100
Description = 472: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

Error - 4/16/2012 9:00:42 AM | Computer Name = Ini-PC | Source = Bonjour Service | ID = 100
Description = 480: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

Error - 4/16/2012 9:00:42 AM | Computer Name = Ini-PC | Source = Bonjour Service | ID = 100
Description = 488: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

Error - 4/17/2012 10:21:22 PM | Computer Name = Ini-PC | Source = Bonjour Service | ID = 100
Description = 296: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

Error - 4/17/2012 10:21:22 PM | Computer Name = Ini-PC | Source = Bonjour Service | ID = 100
Description = 428: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

Error - 4/17/2012 10:21:22 PM | Computer Name = Ini-PC | Source = Bonjour Service | ID = 100
Description = 432: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

Error - 4/18/2012 1:49:54 PM | Computer Name = Ini-PC | Source = Application Error | ID = 1000
Description = Faulting application name: iexplore.exe, version: 9.0.8112.16421,
time stamp: 0x4d76255d Faulting module name: ntdll.dll, version: 6.1.7600.16915,
time stamp: 0x4ec49caf Exception code: 0xc0000005 Fault offset: 0x00055401 Faulting
process id: 0x1720 Faulting application start time: 0x01cd1d8ba6a3da17 Faulting application
path: C:\Program Files\Internet Explorer\iexplore.exe Faulting module path: C:\Windows\SYSTEM32\ntdll.dll
Report
Id: e75f94d8-897e-11e1-b21d-90e6ba69a22d

[ Media Center Events ]
Error - 2/6/2012 5:30:12 PM | Computer Name = Ini-PC | Source = MCUpdate | ID = 0
Description = 4:30:12 PM - Failed to retrieve Directory (Error: Unable to connect
to the remote server)

Error - 2/6/2012 5:31:15 PM | Computer Name = Ini-PC | Source = MCUpdate | ID = 0
Description = 4:30:54 PM - Failed to retrieve ClientUpdate (Error: Unable to connect
to the remote server)

Error - 2/6/2012 5:31:57 PM | Computer Name = Ini-PC | Source = MCUpdate | ID = 0
Description = 4:31:36 PM - Failed to retrieve NetTV (Error: Unable to connect to
the remote server)

Error - 2/6/2012 5:32:40 PM | Computer Name = Ini-PC | Source = MCUpdate | ID = 0
Description = 4:32:18 PM - Failed to retrieve MCEClientUX (Error: Unable to connect
to the remote server)

Error - 2/6/2012 5:33:22 PM | Computer Name = Ini-PC | Source = MCUpdate | ID = 0
Description = 4:33:01 PM - Failed to retrieve SportsSchedule (Error: Unable to connect
to the remote server)

Error - 2/6/2012 5:34:04 PM | Computer Name = Ini-PC | Source = MCUpdate | ID = 0
Description = 4:33:43 PM - Failed to retrieve SportsV2 (Error: Unable to connect
to the remote server)

Error - 2/6/2012 5:34:46 PM | Computer Name = Ini-PC | Source = MCUpdate | ID = 0
Description = 4:34:25 PM - Failed to retrieve Broadband (Error: Unable to connect
to the remote server)

Error - 2/6/2012 5:35:22 PM | Computer Name = Ini-PC | Source = MCUpdate | ID = 0
Description = 4:35:07 PM - Failed to retrieve EpgListings (Error: Unable to connect
to the remote server)

Error - 4/8/2012 8:17:03 AM | Computer Name = Ini-PC | Source = MCUpdate | ID = 0
Description = 8:16:44 AM - Error connecting to the internet. 8:16:44 AM - Unable
to contact server..

Error - 4/18/2012 12:43:16 PM | Computer Name = Ini-PC | Source = MCUpdate | ID = 0
Description = 12:42:55 PM - Failed to retrieve SportsSchedule (Error: Unable to
connect to the remote server)

[ OSession Events ]
Error - 11/24/2010 12:40:45 AM | Computer Name = Ini-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 2
seconds with 0 seconds of active time. This session ended with a crash.

Error - 12/14/2011 3:46:23 PM | Computer Name = Ini-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 1
seconds with 0 seconds of active time. This session ended with a crash.

Error - 12/26/2011 2:45:31 PM | Computer Name = Ini-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 5
seconds with 0 seconds of active time. This session ended with a crash.

Error - 12/31/2011 10:27:57 PM | Computer Name = Ini-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 2
seconds with 0 seconds of active time. This session ended with a crash.

Error - 12/31/2011 10:30:56 PM | Computer Name = Ini-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 2
seconds with 0 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 4/7/2012 11:56:01 PM | Computer Name = Ini-PC | Source = volsnap | ID = 393252
Description = The shadow copies of volume C: were aborted because the shadow copy
storage could not grow due to a user imposed limit.

Error - 4/10/2012 12:05:01 PM | Computer Name = Ini-PC | Source = DCOM | ID = 10016
Description =

Error - 4/13/2012 3:08:38 AM | Computer Name = Ini-PC | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the Windows
Search service to connect.

Error - 4/13/2012 3:08:38 AM | Computer Name = Ini-PC | Source = Service Control Manager | ID = 7000
Description = The Windows Search service failed to start due to the following error:
%%1053

Error - 4/13/2012 11:50:29 AM | Computer Name = Ini-PC | Source = volsnap | ID = 393252
Description = The shadow copies of volume C: were aborted because the shadow copy
storage could not grow due to a user imposed limit.

Error - 4/14/2012 12:08:54 PM | Computer Name = Ini-PC | Source = volsnap | ID = 393252
Description = The shadow copies of volume C: were aborted because the shadow copy
storage could not grow due to a user imposed limit.

Error - 4/17/2012 8:45:42 PM | Computer Name = Ini-PC | Source = volsnap | ID = 393252
Description = The shadow copies of volume C: were aborted because the shadow copy
storage could not grow due to a user imposed limit.

Error - 4/18/2012 2:09:56 PM | Computer Name = Ini-PC | Source = Schannel | ID = 36887
Description = The following fatal alert was received: 20.

Error - 4/18/2012 2:09:56 PM | Computer Name = Ini-PC | Source = Schannel | ID = 36887
Description = The following fatal alert was received: 20.

Error - 4/20/2012 11:35:31 AM | Computer Name = Ini-PC | Source = volsnap | ID = 393252
Description = The shadow copies of volume C: were aborted because the shadow copy
storage could not grow due to a user imposed limit.


< End of report >
Hi nicolo,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

As we work through your logs. Please remember to run any tools by Right-clicking on the icon and selecting Run As Administrator….

Only some adware and foistware showing. Let's try this:

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://forums.whatthetech.com/How_Disable_…ams_t96260.html

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Hi here are the results of the scan: ComboFix 12-04-28.01 - Ini 04/29/2012 1:33.1.2 - x86 Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.3071.1488 [GMT -4:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} FW: COMODO Firewall *Enabled* {5F676F4C-DD6D-A47C-12D6-C449366C71EE} SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: COMODO Defense+ *Enabled/Updated* {DC3D0F8D-B138-AAAA-0339-560EB3387C28} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files\AutocompletePro c:\program files\AutocompletePro\64\AutocompletePro64.dll c:\program files\AutocompletePro\AutocompletePro.dll c:\program files\AutocompletePro\chrome\autocompleteprochrome.crx c:\program files\AutocompletePro\FireFoxExtension.exe c:\program files\AutocompletePro\InstTracker.exe c:\program files\AutocompletePro\[removed]\chrome.manifest c:\program files\AutocompletePro\[removed]\chrome\content\browserOverlay.xul c:\program files\AutocompletePro\[removed]\chrome\content\options.js c:\program files\AutocompletePro\[removed]\chrome\content\options.xul c:\program files\AutocompletePro\[removed]\chrome\content\utils.js c:\program files\AutocompletePro\[removed]\defaults\preferences\predictad.js c:\program files\AutocompletePro\[removed]\install.rdf c:\program files\AutocompletePro\unins000.dat c:\program files\AutocompletePro\unins000.exe c:\program files\Blinkx c:\program files\Blinkx\blinkx.ico c:\program files\Blinkx\blinkxss.exe c:\program files\Blinkx\blinkxstop.exe c:\program files\Blinkx\lang.dll c:\program files\Blinkx\templates\beat.ico c:\program files\Blinkx\templates\index.html c:\program files\Blinkx\templates\noflash.html c:\program files\Blinkx\templates\offline.html c:\program files\Blinkx\templates\offline.swf c:\program files\Blinkx\templates\uninstall.exe c:\users\Ini\AppData\Roaming\Mozilla\Firefox\Profiles\emea68ub.default\weave\toFetch c:\users\Ini\AppData\Roaming\Mozilla\Firefox\Profiles\emea68ub.default\weave\toFetch\clients.json c:\users\Ini\AppData\Roaming\Mozilla\Firefox\Profiles\emea68ub.default\weave\toFetch\tabs.json c:\windows\system32\bdaplgin.ax c:\windows\system32\cero.rs c:\windows\system32\csrr.rs c:\windows\system32\esrb.rs c:\windows\system32\g711codc.ax c:\windows\system32\grb.rs c:\windows\system32\iac25_32.ax c:\windows\system32\ir41_32.ax c:\windows\system32\ivfsrc.ax c:\windows\system32\ksproxy.ax c:\windows\system32\kstvtune.ax c:\windows\system32\Kswdmcap.ax c:\windows\system32\ksxbar.ax c:\windows\system32\Mpeg2Data.ax c:\windows\system32\mpg2splt.ax c:\windows\system32\MSDvbNP.ax c:\windows\system32\MSNP.ax c:\windows\system32\MVDetection.ax c:\windows\system32\oflc.rs c:\windows\system32\pegi-fi.rs c:\windows\system32\pegi-pt.rs c:\windows\system32\pegi.rs c:\windows\system32\pegibbfc.rs c:\windows\system32\psisrndr.ax c:\windows\system32\usk.rs c:\windows\system32\VBICodec.ax c:\windows\system32\vbisurf.ax c:\windows\system32\vidcap.ax c:\windows\system32\WEB.rs c:\windows\system32\WSTPager.ax c:\windows\system32\xvid.ax . . ((((((((((((((((((((((((( Files Created from 2012-03-28 to 2012-04-29 ))))))))))))))))))))))))))))))) . . 2012-04-29 05:46 . 2012-04-29 05:46 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-04-29 05:38 . 2012-04-29 05:38 56200 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{3A501844-5E28-414F-B9BB-3444E7F8C9CC}\offreg.dll 2012-04-27 17:01 . 2012-04-13 07:36 6734704 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{3A501844-5E28-414F-B9BB-3444E7F8C9CC}\mpengine.dll 2012-04-22 22:59 . 2012-04-22 22:59 592824 —-a-w- c:\program files\Mozilla Firefox\gkmedias.dll 2012-04-22 22:59 . 2012-04-22 22:59 44472 —-a-w- c:\program files\Mozilla Firefox\mozglue.dll 2012-04-13 07:01 . 2012-03-01 05:53 19312 —-a-w- c:\windows\system32\drivers\fs_rec.sys 2012-04-13 07:01 . 2012-03-01 05:49 172544 —-a-w- c:\windows\system32\wintrust.dll 2012-04-13 07:01 . 2012-03-01 05:40 5120 —-a-w- c:\windows\system32\wmi.dll 2012-04-13 07:01 . 2012-03-01 05:45 158720 —-a-w- c:\windows\system32\imagehlp.dll 2012-04-13 07:00 . 2012-03-06 05:59 3958128 —-a-w- c:\windows\system32\ntkrnlpa.exe 2012-04-13 07:00 . 2012-03-06 05:59 3902320 —-a-w- c:\windows\system32\ntoskrnl.exe . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-04-04 19:56 . 2011-03-03 06:14 22344 —-a-w- c:\windows\system32\drivers\mbam.sys 2012-03-02 18:13 . 2012-03-02 18:13 86528 —-a-w- c:\windows\system32\iesysprep.dll 2012-03-02 18:13 . 2012-03-02 18:13 76800 —-a-w- c:\windows\system32\SetIEInstalledDate.exe 2012-03-02 18:13 . 2012-03-02 18:13 74752 —-a-w- c:\windows\system32\RegisterIEPKEYs.exe 2012-03-02 18:13 . 2012-03-02 18:13 74752 —-a-w- c:\windows\system32\iesetup.dll 2012-03-02 18:13 . 2012-03-02 18:13 63488 —-a-w- c:\windows\system32\tdc.ocx 2012-03-02 18:13 . 2012-03-02 18:13 48640 —-a-w- c:\windows\system32\mshtmler.dll 2012-03-02 18:13 . 2012-03-02 18:13 420864 —-a-w- c:\windows\system32\vbscript.dll 2012-03-02 18:13 . 2012-03-02 18:13 367104 —-a-w- c:\windows\system32\html.iec 2012-03-02 18:13 . 2012-03-02 18:13 23552 —-a-w- c:\windows\system32\licmgr10.dll 2012-03-02 18:13 . 2012-03-02 18:13 161792 —-a-w- c:\windows\system32\msls31.dll 2012-03-02 18:13 . 2012-03-02 18:13 152064 —-a-w- c:\windows\system32\wextract.exe 2012-03-02 18:13 . 2012-03-02 18:13 150528 —-a-w- c:\windows\system32\iexpress.exe 2012-03-02 18:13 . 2012-03-02 18:13 142848 —-a-w- c:\windows\system32\ieUnatt.exe 2012-03-02 18:13 . 2012-03-02 18:13 11776 —-a-w- c:\windows\system32\mshta.exe 2012-03-02 18:13 . 2012-03-02 18:13 110592 —-a-w- c:\windows\system32\IEAdvpack.dll 2012-03-02 18:13 . 2012-03-02 18:13 35840 —-a-w- c:\windows\system32\imgutil.dll 2012-03-02 18:13 . 2012-03-02 18:13 101888 —-a-w- c:\windows\system32\admparse.dll 2012-02-23 14:18 . 2010-07-10 01:24 237072 ——w- c:\windows\system32\MpSigStub.exe 2012-02-15 05:44 . 2012-03-14 13:25 826368 —-a-w- c:\windows\system32\rdpcore.dll 2012-02-15 04:22 . 2012-03-14 13:25 177152 —-a-w- c:\windows\system32\drivers\rdpwd.sys 2012-02-15 04:22 . 2012-03-14 13:25 24064 —-a-w- c:\windows\system32\drivers\tdtcp.sys 2012-02-10 05:41 . 2012-03-14 13:26 1074176 —-a-w- c:\windows\system32\DWrite.dll 2012-02-10 05:41 . 2012-03-14 13:26 218624 —-a-w- c:\windows\system32\d3d10_1core.dll 2012-02-10 05:41 . 2012-03-14 13:26 161792 —-a-w- c:\windows\system32\d3d10_1.dll 2012-02-10 05:41 . 2012-03-14 13:26 1170944 —-a-w- c:\windows\system32\d3d10warp.dll 2012-02-10 05:41 . 2012-03-14 13:26 739840 —-a-w- c:\windows\system32\d2d1.dll 2012-02-07 15:02 . 2012-02-07 15:02 1070352 —-a-w- c:\windows\system32\MSCOMCTL.OCX 2012-02-06 22:56 . 2011-12-08 23:07 737072 —-a-w- c:\programdata\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore-2\Microsoft.MediaCenter.Sports.UI.dll 2012-02-06 22:46 . 2011-12-08 22:57 4283672 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\markup.dll 2012-02-06 22:45 . 2011-12-08 22:56 42776 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM-2\StartResources.dll 2012-02-03 04:01 . 2012-03-14 13:26 2341376 —-a-w- c:\windows\system32\win32k.sys 2012-04-22 22:59 . 2011-03-25 01:22 97208 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}] 2011-12-14 20:51 1514152 —-a-w- c:\program files\Ask.com\GenericAskToolbar.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2011-12-14 1514152] . [HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1] [HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd] . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser] "{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2011-12-14 1514152] . [HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1] [HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2011-09-06 20:45 122512 —-a-w- c:\program files\Alwil Software\Avast5\ashShell.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RESTART_STICKY_NOTES"="c:\windows\System32\StikyNot.exe" [2009-07-14 354304] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-07-02 13789728] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-08-28 1557800] "ATKOSD2"="c:\program files\ASUS\ATKOSD2\ATKOSD2.exe" [2009-08-17 6859392] "HControlUser"="c:\program files\ASUS\ATK Hotkey\HControlUser.exe" [2009-06-19 105016] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-09-07 37296] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040] "COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2010-06-01 2039240] "SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2009-10-26 1458176] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-07-05 421888] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-08-19 421736] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696] "ApnUpdater"="c:\program files\Ask.com\Updater\Updater.exe" [2011-12-14 1398440] "IJNetworkScanUtility"="c:\program files\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe" [2010-08-23 206240] . c:\users\Ini\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Epson all-in-one Registration.lnk - f:\common\EpsonReg\EpsonReg.exe [N/A] OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680] SpywareGuard.lnk - c:\program files\SpywareGuard\sgmain.exe [2003-8-29 360448] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\windows\System32\guard32.dll . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R3 AVerFx2hbtv;AVerMedia H826 USB Hybrid Tuner;c:\windows\system32\drivers\AVerFx2hbtv.sys [2009-12-08 437888] R3 BITCOMET_HELPER_SERVICE;BitComet Disk Boost Service;c:\program files\BitComet\tools\BitCometService.exe [2010-12-28 1296728] R3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-13 14336] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-07-10 1343400] S1 aswSnx;aswSnx; [x] S1 aswSP;aswSP; [x] S1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\DRIVERS\cmdguard.sys [2010-06-04 224240] S1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\DRIVERS\cmdhlp.sys [2010-06-01 30112] S1 VWiFiFlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128] S2 aswFsBlk;aswFsBlk; [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2011-09-06 54616] S3 netr28u;RT2870 USB Wireless LAN Card Driver for Vista;c:\windows\system32\DRIVERS\netr28u.sys [2009-03-03 710144] S3 netw5v32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\netw5v32.sys [2009-07-13 4231168] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-11-17 232448] . . Contents of the 'Scheduled Tasks' folder . 2012-04-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-16478551-3455753284-2568791741-1000Core.job - c:\users\Ini\AppData\Local\Google\Update\GoogleUpdate.exe [2011-05-13 01:00] . 2012-04-29 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-16478551-3455753284-2568791741-1000UA.job - c:\users\Ini\AppData\Local\Google\Update\GoogleUpdate.exe [2011-05-13 01:00] . . ——- Supplementary Scan ——- . uStart Page = hxxp://search.babylon.com/?babsrc=HP_ss&affID=108844&mntrId=2a623e14000000000000001561524eae uInternet Settings,ProxyOverride = *.local IE: &??BitComet?? - c:\program files\BitComet\BitComet.exe/AddLink.htm IE: &??BitComet?????? - c:\program files\BitComet\BitComet.exe/AddAllLink.htm IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = 192.168.0.1 FF - ProfilePath - c:\users\Ini\AppData\Roaming\Mozilla\Firefox\Profiles\emea68ub.default\ FF - prefs.js: browser.startup.homepage - hxxps://mail.google.com/mail/?shva=1#inbox FF - prefs.js: network.proxy.type - 0 FF - user.js: extensions.BabylonToolbar_i.id - 2a623e14000000000000001561524eae FF - user.js: extensions.BabylonToolbar_i.hardId - 2a623e14000000000000001561524eae FF - user.js: extensions.BabylonToolbar_i.instlDay - 15341 FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17 FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17 FF - user.js: extensions.BabylonToolbar_i.vrsnTs - [removed]:40 FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar FF - user.js: extensions.BabylonToolbar_i.aflt - babsst FF - user.js: extensions.BabylonToolbar_i.smplGrp - none FF - user.js: extensions.BabylonToolbar_i.tlbrId - base FF - user.js: extensions.BabylonToolbar_i.newTab - false FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=108844 FF - user.js: extensions.BabylonToolbar_i.babExt - FF - user.js: extensions.BabylonToolbar_i.srcExt - ss FF - user.js: extensions.BabylonToolbar_i.instlRef - sst FF - user.js: extentions.y2layers.installId - dcb5cbec-2d2e-43ac-9cd2-1f6fae9fdf09 FF - user.js: extentions.y2layers.defaultEnableAppsList - PageRage,PageRageGlobal,PageRageTeases,Buzzdock,BuzzdockTease,PageRage,PageRageG lobal, . - - - - ORPHANS REMOVED - - - - . Toolbar-{06C7AD57-B655-418D-9AB8-9526A6D2E052} - (no file) HKCU-Run-eMuleAutoStart - c:\program files\easyMule\eMule.exe HKLM-Run-iBryte browseforchange Desktop - c:\program files\iBryte\browseforchange\ibrytedesktop.exe HKLM-Run-iBryte playbryte Desktop - c:\program files\iBryte\playbryte\ibrytedesktop.exe AddRemove-AutocompletePro3_is1 - c:\program files\AutocompletePro\unins000.exe AddRemove-blinkx beat - c:\program files\Blinkx\templates\uninstall.exe . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 "MSCurrentCountry"=dword:000000b5 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ——————— DLLs Loaded Under Running Processes ——————— . - - - - - - - > 'winlogon.exe'(1192) c:\windows\system32\guard32.dll . - - - - - - - > 'lsass.exe'(572) c:\windows\system32\guard32.dll . Completion time: 2012-04-29 01:52:33 ComboFix-quarantined-files.txt 2012-04-29 05:52 . Pre-Run: 12,310,425,600 bytes free Post-Run: 14,126,092,288 bytes free . - - End Of File - - 8BF60B6C96096BBE84A13AE3BD7A002A
nicolo,

BitComet
You have BitComet, a P2P/file sharing programs installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it.

References for the risk of these programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx
http://www.techweb.com/wire/160500554
http://www.internetworldstats.com/articles/art053.htm


I would recommend that you uninstall BitComet, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.

If you wish to keep it, please do not use it until your computer is cleaned.

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    Firefox::
    FF - ProfilePath - c:\users\Ini\AppData\Roaming\Mozilla\Firefox\Profiles\emea68ub.default\
    FF - user.js: extensions.BabylonToolbar_i.id - 2a623e14000000000000001561524eae
    FF - user.js: extensions.BabylonToolbar_i.hardId - 2a623e14000000000000001561524eae
    FF - user.js: extensions.BabylonToolbar_i.instlDay - 15341
    FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17
    FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17
    FF - user.js: extensions.BabylonToolbar_i.vrsnTs - [removed]:40
    FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon
    FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar
    FF - user.js: extensions.BabylonToolbar_i.aflt - babsst
    FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
    FF - user.js: extensions.BabylonToolbar_i.tlbrId - base
    FF - user.js: extensions.BabylonToolbar_i.newTab - false
    FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=108844
    FF - user.js: extensions.BabylonToolbar_i.babExt -
    FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
    FF - user.js: extensions.BabylonToolbar_i.instlRef - sst
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
I'm sorry TomK, please do not close this topic just yet. A relative removed the laptop in question for their personal purposes so I'm trying to get it back to conclude the ComboFix procedures. Please kindly bear with me.
Ok finally…here are the results after CFScript was used… ComboFix 12-05-03.03 - Ini 05/03/2012 23:29:28.2.2 - x86 Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.3071.2008 [GMT -4:00] Running from: c:\users\[removed]\Downloads\ComboFix.exe Command switches used :: c:\users\Ini\Desktop\CFScript.txt AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} FW: COMODO Firewall *Disabled* {5F676F4C-DD6D-A47C-12D6-C449366C71EE} SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: COMODO Defense+ *Disabled/Updated* {DC3D0F8D-B138-AAAA-0339-560EB3387C28} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((( Files Created from 2012-04-04 to 2012-05-04 ))))))))))))))))))))))))))))))) . . 2012-05-04 03:41 . 2012-05-04 03:41 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-05-04 02:53 . 2012-04-13 07:36 6734704 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{AE0F3628-5AEC-420D-B2F1-713880FAF09B}\mpengine.dll 2012-04-22 22:59 . 2012-04-22 22:59 592824 —-a-w- c:\program files\Mozilla Firefox\gkmedias.dll 2012-04-22 22:59 . 2012-04-22 22:59 44472 —-a-w- c:\program files\Mozilla Firefox\mozglue.dll 2012-04-13 07:01 . 2012-03-01 05:53 19312 —-a-w- c:\windows\system32\drivers\fs_rec.sys 2012-04-13 07:01 . 2012-03-01 05:49 172544 —-a-w- c:\windows\system32\wintrust.dll 2012-04-13 07:01 . 2012-03-01 05:40 5120 —-a-w- c:\windows\system32\wmi.dll 2012-04-13 07:01 . 2012-03-01 05:45 158720 —-a-w- c:\windows\system32\imagehlp.dll 2012-04-13 07:00 . 2012-03-06 05:59 3958128 —-a-w- c:\windows\system32\ntkrnlpa.exe 2012-04-13 07:00 . 2012-03-06 05:59 3902320 —-a-w- c:\windows\system32\ntoskrnl.exe . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-04-04 19:56 . 2011-03-03 06:14 22344 —-a-w- c:\windows\system32\drivers\mbam.sys 2012-03-02 18:13 . 2012-03-02 18:13 86528 —-a-w- c:\windows\system32\iesysprep.dll 2012-03-02 18:13 . 2012-03-02 18:13 76800 —-a-w- c:\windows\system32\SetIEInstalledDate.exe 2012-03-02 18:13 . 2012-03-02 18:13 74752 —-a-w- c:\windows\system32\RegisterIEPKEYs.exe 2012-03-02 18:13 . 2012-03-02 18:13 74752 —-a-w- c:\windows\system32\iesetup.dll 2012-03-02 18:13 . 2012-03-02 18:13 63488 —-a-w- c:\windows\system32\tdc.ocx 2012-03-02 18:13 . 2012-03-02 18:13 48640 —-a-w- c:\windows\system32\mshtmler.dll 2012-03-02 18:13 . 2012-03-02 18:13 420864 —-a-w- c:\windows\system32\vbscript.dll 2012-03-02 18:13 . 2012-03-02 18:13 367104 —-a-w- c:\windows\system32\html.iec 2012-03-02 18:13 . 2012-03-02 18:13 23552 —-a-w- c:\windows\system32\licmgr10.dll 2012-03-02 18:13 . 2012-03-02 18:13 161792 —-a-w- c:\windows\system32\msls31.dll 2012-03-02 18:13 . 2012-03-02 18:13 152064 —-a-w- c:\windows\system32\wextract.exe 2012-03-02 18:13 . 2012-03-02 18:13 150528 —-a-w- c:\windows\system32\iexpress.exe 2012-03-02 18:13 . 2012-03-02 18:13 142848 —-a-w- c:\windows\system32\ieUnatt.exe 2012-03-02 18:13 . 2012-03-02 18:13 11776 —-a-w- c:\windows\system32\mshta.exe 2012-03-02 18:13 . 2012-03-02 18:13 110592 —-a-w- c:\windows\system32\IEAdvpack.dll 2012-03-02 18:13 . 2012-03-02 18:13 35840 —-a-w- c:\windows\system32\imgutil.dll 2012-03-02 18:13 . 2012-03-02 18:13 101888 —-a-w- c:\windows\system32\admparse.dll 2012-02-23 14:18 . 2010-07-10 01:24 237072 ——w- c:\windows\system32\MpSigStub.exe 2012-02-15 05:44 . 2012-03-14 13:25 826368 —-a-w- c:\windows\system32\rdpcore.dll 2012-02-15 04:22 . 2012-03-14 13:25 177152 —-a-w- c:\windows\system32\drivers\rdpwd.sys 2012-02-15 04:22 . 2012-03-14 13:25 24064 —-a-w- c:\windows\system32\drivers\tdtcp.sys 2012-02-10 05:41 . 2012-03-14 13:26 1074176 —-a-w- c:\windows\system32\DWrite.dll 2012-02-10 05:41 . 2012-03-14 13:26 218624 —-a-w- c:\windows\system32\d3d10_1core.dll 2012-02-10 05:41 . 2012-03-14 13:26 161792 —-a-w- c:\windows\system32\d3d10_1.dll 2012-02-10 05:41 . 2012-03-14 13:26 1170944 —-a-w- c:\windows\system32\d3d10warp.dll 2012-02-10 05:41 . 2012-03-14 13:26 739840 —-a-w- c:\windows\system32\d2d1.dll 2012-02-07 15:02 . 2012-02-07 15:02 1070352 —-a-w- c:\windows\system32\MSCOMCTL.OCX 2012-02-06 22:56 . 2011-12-08 23:07 737072 —-a-w- c:\programdata\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore-2\Microsoft.MediaCenter.Sports.UI.dll 2012-02-06 22:46 . 2011-12-08 22:57 4283672 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\markup.dll 2012-02-06 22:45 . 2011-12-08 22:56 42776 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM-2\StartResources.dll 2012-04-22 22:59 . 2011-03-25 01:22 97208 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}] 2011-12-14 20:51 1514152 —-a-w- c:\program files\Ask.com\GenericAskToolbar.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2011-12-14 1514152] . [HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1] [HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd] . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser] "{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2011-12-14 1514152] . [HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1] [HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2011-09-06 20:45 122512 —-a-w- c:\program files\Alwil Software\Avast5\ashShell.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RESTART_STICKY_NOTES"="c:\windows\System32\StikyNot.exe" [2009-07-14 354304] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-07-02 13789728] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-08-28 1557800] "ATKOSD2"="c:\program files\ASUS\ATKOSD2\ATKOSD2.exe" [2009-08-17 6859392] "HControlUser"="c:\program files\ASUS\ATK Hotkey\HControlUser.exe" [2009-06-19 105016] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-09-07 37296] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040] "COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2010-06-01 2039240] "SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2009-10-26 1458176] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-07-05 421888] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-08-19 421736] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696] "ApnUpdater"="c:\program files\Ask.com\Updater\Updater.exe" [2011-12-14 1398440] "IJNetworkScanUtility"="c:\program files\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe" [2010-08-23 206240] . c:\users\Ini\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Epson all-in-one Registration.lnk - f:\common\EpsonReg\EpsonReg.exe [N/A] OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680] SpywareGuard.lnk - c:\program files\SpywareGuard\sgmain.exe [2003-8-29 360448] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\windows\System32\guard32.dll . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R3 AVerFx2hbtv;AVerMedia H826 USB Hybrid Tuner;c:\windows\system32\drivers\AVerFx2hbtv.sys [2009-12-08 437888] R3 BITCOMET_HELPER_SERVICE;BitComet Disk Boost Service;c:\program files\BitComet\tools\BitCometService.exe [2010-12-28 1296728] R3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-13 14336] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-07-10 1343400] S1 aswSnx;aswSnx; [x] S1 aswSP;aswSP; [x] S1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\DRIVERS\cmdguard.sys [2010-06-04 224240] S1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\DRIVERS\cmdhlp.sys [2010-06-01 30112] S1 VWiFiFlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128] S2 aswFsBlk;aswFsBlk; [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2011-09-06 54616] S3 netr28u;RT2870 USB Wireless LAN Card Driver for Vista;c:\windows\system32\DRIVERS\netr28u.sys [2009-03-03 710144] S3 netw5v32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\netw5v32.sys [2009-07-13 4231168] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-11-17 232448] . . Contents of the 'Scheduled Tasks' folder . 2012-05-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-16478551-3455753284-2568791741-1000Core.job - c:\users\Ini\AppData\Local\Google\Update\GoogleUpdate.exe [2011-05-13 01:00] . 2012-05-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-16478551-3455753284-2568791741-1000UA.job - c:\users\Ini\AppData\Local\Google\Update\GoogleUpdate.exe [2011-05-13 01:00] . . ——- Supplementary Scan ——- . uStart Page = hxxp://search.babylon.com/?babsrc=HP_ss&affID=108844&mntrId=2a623e14000000000000001561524eae uInternet Settings,ProxyOverride = *.local IE: &??BitComet?? - c:\program files\BitComet\BitComet.exe/AddLink.htm IE: &??BitComet?????? - c:\program files\BitComet\BitComet.exe/AddAllLink.htm IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = 192.168.0.1 FF - ProfilePath - c:\users\Ini\AppData\Roaming\Mozilla\Firefox\Profiles\emea68ub.default\ FF - prefs.js: browser.startup.homepage - hxxps://mail.google.com/mail/?shva=1#inbox FF - prefs.js: network.proxy.type - 0 FF - user.js: extentions.y2layers.installId - dcb5cbec-2d2e-43ac-9cd2-1f6fae9fdf09 FF - user.js: extentions.y2layers.defaultEnableAppsList - PageRage,PageRageGlobal,PageRageTeases,Buzzdock,BuzzdockTease,PageRage,PageRageG lobal, . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 "MSCurrentCountry"=dword:000000b5 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2012-05-03 23:46:03 ComboFix-quarantined-files.txt 2012-05-04 03:46 ComboFix2.txt 2012-04-29 05:52 . Pre-Run: 13,528,276,992 bytes free Post-Run: 13,401,923,584 bytes free . - - End Of File - - F24427C132FB23610407ED1EF210A0A6
Good.

Let's get an online scan.

ESET Online Scanner:

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Vista users: You will need to to right-click on the either the IE or FF icon in the Start Menu or Quick Launch Bar on the Taskbar and select Run as Administrator from the context menu.

  • Please go here then click on: [external image: Posted Image]

    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.

  • Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: [external image: Posted Image]
  • The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on: [external image: Posted Image]
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.

Note: Do not forget to re-enable your Anti-Virus application after running the above scan!
TomK: Is it possible that NO log file appears after Eset is run? I'm not sure why but there is no generated log file after the scan. Am I doing something wrong?
Don't know if your instructions are wrong but the log file at C:\Program Files\ESET\EsetOnlineScanner\log.txt contains nothing but: ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK The results of the scan however: C:\Program Files\Yontoo\YontooIEClient.dll a variant of Win32/Adware.Yontoo.A application C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll a variant of Win32/Adware.Yontoo.B application C:\ProgramData\Tarma Installer\{DE3B7BF9-0770-4104-BC0B-B1CCCCE2F053}\_Setupx.dll a variant of Win32/Adware.Yontoo.B application C:\Users\All Users\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll a variant of Win32/Adware.Yontoo.B application C:\Users\All Users\Tarma Installer\{DE3B7BF9-0770-4104-BC0B-B1CCCCE2F053}\_Setupx.dll a variant of Win32/Adware.Yontoo.B application C:\Users\Ini\AppData\Local\Babylon\Setup\MyBabylonTB.exe Win32/Toolbar.Babylon application C:\Users\Ini\Downloads\SoftonicDownloader_for_stream-torrent.exe a variant of Win32/SoftonicDownloader.A application
It appears that I need to adjust my instructions as they have changed how the scanner works as well as the report.

Anyhow…


COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    File::
    C:\Users\Ini\Downloads\SoftonicDownloader_for_stream-torrent.exe 
    
    Folder::
    C:\Program Files\Yontoo
    C:\ProgramData\Tarma Installer
    C:\Users\All Users\Tarma Installer
    C:\Users\Ini\AppData\Local\Babylon
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
Here you go: ComboFix 12-05-13.03 - Ini 05/13/2012 19:24:16.3.2 - x86 Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.3071.2126 [GMT -4:00] Running from: c:\users\[removed]\Downloads\ComboFix.exe Command switches used :: c:\users\Ini\Desktop\CFScript.txt AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} FW: COMODO Firewall *Disabled* {5F676F4C-DD6D-A47C-12D6-C449366C71EE} SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: COMODO Defense+ *Disabled/Updated* {DC3D0F8D-B138-AAAA-0339-560EB3387C28} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . FILE :: "c:\users\Ini\Downloads\SoftonicDownloader_for_stream-torrent.exe" . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files\Yontoo c:\program files\Yontoo\YontooIEClient.dll c:\programdata\Tarma Installer c:\programdata\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setup.dll c:\programdata\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll c:\programdata\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.dat c:\programdata\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.exe c:\programdata\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.ico c:\programdata\Tarma Installer\{DE3B7BF9-0770-4104-BC0B-B1CCCCE2F053}\_Setup.dll c:\programdata\Tarma Installer\{DE3B7BF9-0770-4104-BC0B-B1CCCCE2F053}\_Setupx.dll c:\programdata\Tarma Installer\{DE3B7BF9-0770-4104-BC0B-B1CCCCE2F053}\Setup.dat c:\programdata\Tarma Installer\{DE3B7BF9-0770-4104-BC0B-B1CCCCE2F053}\Setup.exe c:\programdata\Tarma Installer\{DE3B7BF9-0770-4104-BC0B-B1CCCCE2F053}\Setup.ico c:\users\All Users\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setup.dll c:\users\All Users\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll c:\users\All Users\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.dat c:\users\All Users\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.exe c:\users\All Users\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.ico c:\users\All Users\Tarma Installer\{DE3B7BF9-0770-4104-BC0B-B1CCCCE2F053}\_Setup.dll c:\users\All Users\Tarma Installer\{DE3B7BF9-0770-4104-BC0B-B1CCCCE2F053}\_Setupx.dll c:\users\All Users\Tarma Installer\{DE3B7BF9-0770-4104-BC0B-B1CCCCE2F053}\Setup.dat c:\users\All Users\Tarma Installer\{DE3B7BF9-0770-4104-BC0B-B1CCCCE2F053}\Setup.exe c:\users\All Users\Tarma Installer\{DE3B7BF9-0770-4104-BC0B-B1CCCCE2F053}\Setup.ico c:\users\Ini\AppData\Local\Babylon c:\users\Ini\AppData\Local\Babylon\Setup\bab033.tbinst.dat c:\users\Ini\AppData\Local\Babylon\Setup\bab091.norecovericon.dat c:\users\Ini\AppData\Local\Babylon\Setup\Babylon.dat c:\users\Ini\AppData\Local\Babylon\Setup\BabylonTB.xpi c:\users\Ini\AppData\Local\Babylon\Setup\HtmlScreens\common.js c:\users\Ini\AppData\Local\Babylon\Setup\HtmlScreens\eula.html c:\users\Ini\AppData\Local\Babylon\Setup\HtmlScreens\page2.css c:\users\Ini\AppData\Local\Babylon\Setup\HtmlScreens\page2.html c:\users\Ini\AppData\Local\Babylon\Setup\HtmlScreens\page2.js c:\users\Ini\AppData\Local\Babylon\Setup\HtmlScreens\page2Lrg.css c:\users\Ini\AppData\Local\Babylon\Setup\HtmlScreens\page9.html c:\users\Ini\AppData\Local\Babylon\Setup\HtmlScreens\pBar.gif c:\users\Ini\AppData\Local\Babylon\Setup\HtmlScreens\Thumbs.db c:\users\Ini\AppData\Local\Babylon\Setup\HtmlScreens\title2.png c:\users\Ini\AppData\Local\Babylon\Setup\HtmlScreens\toolBar.jpg c:\users\Ini\AppData\Local\Babylon\Setup\MyBabylonTB.exe c:\users\Ini\AppData\Local\Babylon\Setup\Setup-tbmntr903-9.0.3.23.zpb c:\users\Ini\AppData\Local\Babylon\Setup\Setup.exe c:\users\Ini\AppData\Local\Babylon\Setup\SetupStrings.dat c:\users\Ini\AppData\Local\Babylon\Setup\sqlite3.dll c:\users\Ini\AppData\Local\Babylon\Setup\Welcome.html . . ((((((((((((((((((((((((( Files Created from 2012-04-13 to 2012-05-13 ))))))))))))))))))))))))))))))) . . 2012-05-13 23:35 . 2012-05-13 23:35 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-05-13 02:29 . 2012-05-13 02:29 ——– d—–w- c:\program files\Safari 2012-05-13 02:27 . 2012-05-13 02:27 ——– d—–w- c:\program files\iPod 2012-05-13 02:27 . 2012-05-13 02:27 ——– d—–w- c:\program files\iTunes 2012-05-13 02:21 . 2012-05-13 02:21 ——– d—–w- c:\program files\Bonjour 2012-05-12 05:15 . 2012-04-13 07:36 6734704 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{7B25DC35-BA60-4369-9CAB-268474E4070A}\mpengine.dll 2012-05-10 03:40 . 2012-05-10 03:40 ——– d—–w- c:\program files\ESET 2012-05-05 12:17 . 2012-05-05 12:17 ——– d—–w- c:\program files\Mozilla Maintenance Service 2012-05-05 12:17 . 2012-05-05 12:17 157352 —-a-w- c:\program files\Mozilla Firefox\maintenanceservice_installer.exe 2012-05-05 12:17 . 2012-05-05 12:17 129976 —-a-w- c:\program files\Mozilla Firefox\maintenanceservice.exe 2012-04-22 22:59 . 2012-05-05 12:17 588728 —-a-w- c:\program files\Mozilla Firefox\gkmedias.dll 2012-04-22 22:59 . 2012-05-05 12:17 43960 —-a-w- c:\program files\Mozilla Firefox\mozglue.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-04-04 19:56 . 2011-03-03 06:14 22344 —-a-w- c:\windows\system32\drivers\mbam.sys 2012-03-02 18:13 . 2012-03-02 18:13 86528 —-a-w- c:\windows\system32\iesysprep.dll 2012-03-02 18:13 . 2012-03-02 18:13 76800 —-a-w- c:\windows\system32\SetIEInstalledDate.exe 2012-03-02 18:13 . 2012-03-02 18:13 74752 —-a-w- c:\windows\system32\RegisterIEPKEYs.exe 2012-03-02 18:13 . 2012-03-02 18:13 74752 —-a-w- c:\windows\system32\iesetup.dll 2012-03-02 18:13 . 2012-03-02 18:13 63488 —-a-w- c:\windows\system32\tdc.ocx 2012-03-02 18:13 . 2012-03-02 18:13 48640 —-a-w- c:\windows\system32\mshtmler.dll 2012-03-02 18:13 . 2012-03-02 18:13 420864 —-a-w- c:\windows\system32\vbscript.dll 2012-03-02 18:13 . 2012-03-02 18:13 367104 —-a-w- c:\windows\system32\html.iec 2012-03-02 18:13 . 2012-03-02 18:13 23552 —-a-w- c:\windows\system32\licmgr10.dll 2012-03-02 18:13 . 2012-03-02 18:13 161792 —-a-w- c:\windows\system32\msls31.dll 2012-03-02 18:13 . 2012-03-02 18:13 152064 —-a-w- c:\windows\system32\wextract.exe 2012-03-02 18:13 . 2012-03-02 18:13 150528 —-a-w- c:\windows\system32\iexpress.exe 2012-03-02 18:13 . 2012-03-02 18:13 142848 —-a-w- c:\windows\system32\ieUnatt.exe 2012-03-02 18:13 . 2012-03-02 18:13 11776 —-a-w- c:\windows\system32\mshta.exe 2012-03-02 18:13 . 2012-03-02 18:13 110592 —-a-w- c:\windows\system32\IEAdvpack.dll 2012-03-02 18:13 . 2012-03-02 18:13 35840 —-a-w- c:\windows\system32\imgutil.dll 2012-03-02 18:13 . 2012-03-02 18:13 101888 —-a-w- c:\windows\system32\admparse.dll 2012-03-01 05:53 . 2012-04-13 07:01 19312 —-a-w- c:\windows\system32\drivers\fs_rec.sys 2012-03-01 05:49 . 2012-04-13 07:01 172544 —-a-w- c:\windows\system32\wintrust.dll 2012-03-01 05:45 . 2012-04-13 07:01 158720 —-a-w- c:\windows\system32\imagehlp.dll 2012-03-01 05:40 . 2012-04-13 07:01 5120 —-a-w- c:\windows\system32\wmi.dll 2012-02-28 01:18 . 2012-04-13 07:07 1799168 —-a-w- c:\windows\system32\jscript9.dll 2012-02-28 01:11 . 2012-04-13 07:07 1427456 —-a-w- c:\windows\system32\inetcpl.cpl 2012-02-28 01:11 . 2012-04-13 07:07 1127424 —-a-w- c:\windows\system32\wininet.dll 2012-02-28 01:03 . 2012-04-13 07:07 2382848 —-a-w- c:\windows\system32\mshtml.tlb 2012-02-23 14:18 . 2010-07-10 01:24 237072 ——w- c:\windows\system32\MpSigStub.exe 2012-02-15 15:01 . 2012-02-15 15:01 4547944 —-a-w- c:\windows\system32\usbaaplrc.dll 2012-02-15 15:01 . 2012-02-15 15:01 43520 —-a-w- c:\windows\system32\drivers\usbaapl.sys 2012-02-15 05:44 . 2012-03-14 13:25 826368 —-a-w- c:\windows\system32\rdpcore.dll 2012-02-15 04:22 . 2012-03-14 13:25 177152 —-a-w- c:\windows\system32\drivers\rdpwd.sys 2012-02-15 04:22 . 2012-03-14 13:25 24064 —-a-w- c:\windows\system32\drivers\tdtcp.sys 2012-05-05 12:17 . 2011-03-25 01:22 97208 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}] 2011-12-14 20:51 1514152 —-a-w- c:\program files\Ask.com\GenericAskToolbar.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2011-12-14 1514152] . [HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1] [HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd] . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser] "{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2011-12-14 1514152] . [HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1] [HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2011-09-06 20:45 122512 —-a-w- c:\program files\Alwil Software\Avast5\ashShell.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-07-02 13789728] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-08-28 1557800] "ATKOSD2"="c:\program files\ASUS\ATKOSD2\ATKOSD2.exe" [2009-08-17 6859392] "HControlUser"="c:\program files\ASUS\ATK Hotkey\HControlUser.exe" [2009-06-19 105016] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-09-07 37296] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040] "COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2010-06-01 2039240] "SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2009-10-26 1458176] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696] "ApnUpdater"="c:\program files\Ask.com\Updater\Updater.exe" [2011-12-14 1398440] "IJNetworkScanUtility"="c:\program files\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe" [2010-08-23 206240] "APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-21 59240] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-03-27 421736] . c:\users\Ini\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Epson all-in-one Registration.lnk - f:\common\EpsonReg\EpsonReg.exe [N/A] OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680] SpywareGuard.lnk - c:\program files\SpywareGuard\sgmain.exe [2003-8-29 360448] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\windows\System32\guard32.dll . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R3 AVerFx2hbtv;AVerMedia H826 USB Hybrid Tuner;c:\windows\system32\drivers\AVerFx2hbtv.sys [2009-12-08 437888] R3 BITCOMET_HELPER_SERVICE;BitComet Disk Boost Service;c:\program files\BitComet\tools\BitCometService.exe [2010-12-28 1296728] R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [2012-05-05 129976] R3 netw5v32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\netw5v32.sys [2009-07-13 4231168] R3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-13 14336] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-07-10 1343400] S1 aswSnx;aswSnx; [x] S1 aswSP;aswSP; [x] S1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\DRIVERS\cmdguard.sys [2010-06-04 224240] S1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\DRIVERS\cmdhlp.sys [2010-06-01 30112] S1 VWiFiFlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128] S2 aswFsBlk;aswFsBlk; [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2011-09-06 54616] S3 netr28u;RT2870 USB Wireless LAN Card Driver for Vista;c:\windows\system32\DRIVERS\netr28u.sys [2009-03-03 710144] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-11-17 232448] . . Contents of the 'Scheduled Tasks' folder . 2012-05-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-16478551-3455753284-2568791741-1000Core.job - c:\users\Ini\AppData\Local\Google\Update\GoogleUpdate.exe [2011-05-13 01:00] . 2012-05-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-16478551-3455753284-2568791741-1000UA.job - c:\users\Ini\AppData\Local\Google\Update\GoogleUpdate.exe [2011-05-13 01:00] . . ——- Supplementary Scan ——- . uStart Page = hxxp://search.babylon.com/?babsrc=HP_ss&affID=108844&mntrId=2a623e14000000000000001561524eae uInternet Settings,ProxyOverride = *.local IE: &??BitComet?? - c:\program files\BitComet\BitComet.exe/AddLink.htm IE: &??BitComet?????? - c:\program files\BitComet\BitComet.exe/AddAllLink.htm IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = 192.168.0.1 FF - ProfilePath - c:\users\Ini\AppData\Roaming\Mozilla\Firefox\Profiles\emea68ub.default\ FF - prefs.js: browser.startup.homepage - hxxps://mail.google.com/mail/?shva=1#inbox FF - prefs.js: network.proxy.type - 0 FF - user.js: extentions.y2layers.installId - dcb5cbec-2d2e-43ac-9cd2-1f6fae9fdf09 FF - user.js: extentions.y2layers.defaultEnableAppsList - PageRage,PageRageGlobal,PageRageTeases,Buzzdock,BuzzdockTease,PageRage,PageRageG lobal, . - - - - ORPHANS REMOVED - - - - . AddRemove-{889DF117-14D1-44EE-9F31-C5FB5D47F68B} - c:\progra~2\TARMAI~1\{889DF~1\Setup.exe . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 "MSCurrentCountry"=dword:000000b5 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2012-05-13 19:39:53 ComboFix-quarantined-files.txt 2012-05-13 23:39 ComboFix2.txt 2012-05-04 03:46 ComboFix3.txt 2012-04-29 05:52 . Pre-Run: 13,244,342,272 bytes free Post-Run: 13,231,357,952 bytes free . - - End Of File - - ED65FEE33A1FECA165C3BB19BE553B77

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI