This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Mystart by Incredibar infected - Help hugely appreciated! [Solved]

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I downloaded a program called freeyoutubedownload from cnet and have since been infected by my browsers (Chrome) redirecting to Mystart by Incredibar after any search I do. I have spent hours trying to run various scans (malwarebytes, ccleaner, avg, elan, superspyware), uninstalling suspicious programs, but it never goes away. After I unistalled something called ETDWare PS/2-X64 7.0.6.5_WHQL I could no longer connect to the internet so I did a system restore, I cant get online again, but Mystart by Incredibar is still here. So, that is where I am up to. I'm on Windows 7. Any help to get rid of this awful infection would be massively appreciated.
Hello TheStrawMan and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:
  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

I will reply with instructions shortly

Satchfan
Hello again TheStrawMan

Download and run OTL
  • download OTL to your desktop.
  • double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • click Scan all users.
  • under Custom Scan paste this in


    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    consrv.dll
    /md5stop
    CREATERESTOREPOINT

  • click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan won’t take long.
  • when the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • you may need two posts to fit them both in.
OTL.txt
Extras.txt


Thanks

Satchfan
Thank you for replying and helping.

First of all, I think that I might have fixed the problem by running a superantispyware and a spybot scan in safe mode and also a system restore. However, im not an expert and there may still be issues on the machine, so here is the OTL results as requested.


OTL logfile created on: 10/06/2012 17:14:43 - Run 1
OTL by OldTimer - Version 3.2.48.0 Folder = C:\Users\James\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

5.68 Gb Total Physical Memory | 4.10 Gb Available Physical Memory | 72.22% Memory free
11.36 Gb Paging File | 9.58 Gb Available in Paging File | 84.40% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 678.54 Gb Total Space | 602.04 Gb Free Space | 88.73% Space Free | Partition Type: NTFS

Computer Name: JAMES-PC | User Name: James | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/06/10 17:11:55 | 000,596,480 | —- | M] (OldTimer Tools) – C:\Users\James\Desktop\OTL (1).exe
PRC - [2012/06/04 09:00:33 | 000,058,288 | —- | M] (Absolute Software Corp.) – C:\Windows\SysWOW64\rpcnet.exe
PRC - [2012/01/24 17:24:26 | 002,416,480 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files (x86)\AVG\AVG2012\avgtray.exe
PRC - [2012/01/03 14:10:50 | 000,815,512 | —- | M] (Adobe Systems Inc.) – C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
PRC - [2012/01/03 06:10:42 | 000,063,928 | —- | M] (Adobe Systems Incorporated) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011/11/23 02:36:24 | 002,391,832 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files (x86)\AVG\AVG2012\avgfws.exe
PRC - [2011/10/12 06:25:22 | 004,433,248 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe
PRC - [2011/08/02 06:09:08 | 000,192,776 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe
PRC - [2011/05/12 16:59:00 | 000,249,648 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
PRC - [2011/04/22 17:44:14 | 000,244,624 | —- | M] (Acer Incorporated) – C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe
PRC - [2011/01/18 03:52:26 | 000,039,528 | —- | M] (Acer Incorporated) – C:\Program Files (x86)\Packard Bell\Registration\GREGsvc.exe
PRC - [2010/09/30 03:06:46 | 000,169,408 | —- | M] (Adobe Systems Incorporated) – C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe
PRC - [2010/08/10 10:06:16 | 000,975,952 | —- | M] (Dritek System Inc.) – C:\Program Files (x86)\Launch Manager\LManager.exe
PRC - [2010/08/10 10:06:16 | 000,321,104 | —- | M] (Dritek System Inc.) – C:\Program Files (x86)\Launch Manager\dsiwmis.exe
PRC - [2010/08/10 10:06:16 | 000,305,744 | —- | M] (Dritek System Inc.) – C:\Program Files (x86)\Launch Manager\LMworker.exe
PRC - [2010/06/28 23:23:24 | 000,263,936 | —- | M] (NewTech Infosystems, Inc.) – C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\BackupManagerTray.exe
PRC - [2010/06/28 23:23:06 | 000,255,744 | —- | M] (NewTech Infosystems, Inc.) – C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\IScheduleSvc.exe
PRC - [2010/05/04 20:07:22 | 000,503,080 | —- | M] (Nero AG) – C:\Program Files (x86)\Nero\Update\NASvc.exe
PRC - [2010/04/13 17:57:58 | 000,013,336 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
PRC - [2010/03/18 05:57:02 | 002,320,920 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
PRC - [2010/03/18 05:56:56 | 000,268,824 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
PRC - [2009/01/26 15:31:16 | 002,144,088 | RHS- | M] (Safer Networking Limited) – C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe


========== Modules (No Company Name) ==========

MOD - [2010/06/28 23:20:54 | 000,465,576 | —- | M] () – C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\sqlite3.dll
MOD - [2009/05/20 07:02:04 | 000,072,200 | —- | M] () – C:\Program Files (x86)\Launch Manager\CdDirIo.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2011/04/22 17:44:14 | 000,244,624 | —- | M] (Acer Incorporated) [Auto | Running] – C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe – (Live Updater Service)
SRV:64bit: - [2011/01/05 15:23:58 | 000,867,712 | —- | M] (Acer Incorporated) [Auto | Running] – C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe – (ePowerSvc)
SRV:64bit: - [2009/07/14 02:41:27 | 001,011,712 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2012/06/04 09:00:33 | 000,058,288 | —- | M] (Absolute Software Corp.) [Auto | Running] – C:\Windows\SysWOW64\rpcnet.exe – (rpcnet) Remote Procedure Call (RPC)
SRV - [2012/01/03 06:10:42 | 000,063,928 | —- | M] (Adobe Systems Incorporated) [Auto | Running] – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe – (AdobeARMservice)
SRV - [2011/11/23 02:36:24 | 002,391,832 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files (x86)\AVG\AVG2012\avgfws.exe – (avgfws)
SRV - [2011/10/12 06:25:22 | 004,433,248 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe – (AVGIDSAgent)
SRV - [2011/08/02 06:09:08 | 000,192,776 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe – (avgwd)
SRV - [2011/06/07 12:25:12 | 000,191,752 | —- | M] (Microsoft Corporation.) [On_Demand | Stopped] – C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE – (BBSvc)
SRV - [2011/05/12 16:59:00 | 000,249,648 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE – (BBUpdate)
SRV - [2011/01/18 03:52:26 | 000,039,528 | —- | M] (Acer Incorporated) [Auto | Running] – C:\Program Files (x86)\Packard Bell\Registration\GREGsvc.exe – (GREGService)
SRV - [2010/10/12 18:59:12 | 000,206,072 | —- | M] (WildTangent, Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe – (GamesAppService)
SRV - [2010/09/30 03:06:46 | 000,169,408 | —- | M] (Adobe Systems Incorporated) [Auto | Running] – C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe – (AdobeActiveFileMonitor9.0)
SRV - [2010/08/10 10:06:16 | 000,321,104 | —- | M] (Dritek System Inc.) [Auto | Running] – C:\Program Files (x86)\Launch Manager\dsiwmis.exe – (DsiWMIService)
SRV - [2010/06/28 23:23:06 | 000,255,744 | —- | M] (NewTech Infosystems, Inc.) [Auto | Running] – C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\IScheduleSvc.exe – (NTI IScheduleSvc)
SRV - [2010/05/04 20:07:22 | 000,503,080 | —- | M] (Nero AG) [Auto | Running] – C:\Program Files (x86)\Nero\Update\NASvc.exe – (NAUpdate) @C:\Program Files (x86)
SRV - [2010/04/13 17:57:58 | 000,013,336 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe – (IAStorDataMgrSvc) Intel®
SRV - [2010/03/18 14:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2010/03/18 05:57:02 | 002,320,920 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe – (UNS) Intel®
SRV - [2010/03/18 05:56:56 | 000,268,824 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe – (LMS) Intel®
SRV - [2009/06/10 22:23:09 | 000,066,384 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)
SRV - [2009/04/16 15:40:02 | 000,237,568 | —- | M] (SMServer) [On_Demand | Stopped] – C:\Windows\SysWOW64\snmvtsvc.exe – (SMServer)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2012/03/01 07:46:16 | 000,023,408 | —- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] – C:\Windows\SysNative\drivers\fs_rec.sys – (Fs_Rec)
DRV:64bit: - [2012/02/14 13:56:49 | 000,283,200 | —- | M] (DT Soft Ltd) [Kernel | System | Running] – C:\Windows\SysNative\drivers\dtsoftbus01.sys – (dtsoftbus01)
DRV:64bit: - [2011/12/20 03:46:50 | 000,029,184 | —- | M] (http://libusb-win32.sourceforge.net) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\libusb0.sys – (libusb0)
DRV:64bit: - [2011/12/14 14:43:22 | 000,029,288 | —- | M] (Wondershare) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\WsAudio_DeviceS(5).sys – (WsAudio_DeviceS(5)) WsAudio_DeviceS(5)
DRV:64bit: - [2011/12/14 14:43:22 | 000,029,288 | —- | M] (Wondershare) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\WsAudio_DeviceS(4).sys – (WsAudio_DeviceS(4)) WsAudio_DeviceS(4)
DRV:64bit: - [2011/12/14 14:43:22 | 000,029,288 | —- | M] (Wondershare) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\WsAudio_DeviceS(3).sys – (WsAudio_DeviceS(3)) WsAudio_DeviceS(3)
DRV:64bit: - [2011/12/14 14:43:22 | 000,029,288 | —- | M] (Wondershare) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\WsAudio_DeviceS(2).sys – (WsAudio_DeviceS(2)) WsAudio_DeviceS(2)
DRV:64bit: - [2011/12/14 14:43:22 | 000,029,288 | —- | M] (Wondershare) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\WsAudio_DeviceS(1).sys – (WsAudio_DeviceS(1)) WsAudio_DeviceS(1)
DRV:64bit: - [2011/10/07 06:23:46 | 000,283,728 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\Windows\SysNative\drivers\avgldx64.sys – (Avgldx64)
DRV:64bit: - [2011/09/13 06:30:08 | 000,037,456 | —- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] – C:\Windows\SysNative\drivers\avgrkx64.sys – (Avgrkx64)
DRV:64bit: - [2011/08/08 06:08:58 | 000,046,672 | —- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] – C:\Windows\SysNative\drivers\avgmfx64.sys – (Avgmfx64)
DRV:64bit: - [2011/07/14 06:35:47 | 000,107,904 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2011/07/14 06:35:47 | 000,027,008 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2011/07/11 01:14:36 | 000,375,376 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\Windows\SysNative\drivers\avgtdia.sys – (Avgtdia)
DRV:64bit: - [2011/07/11 01:14:08 | 000,029,776 | —- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\AVGIDSFilter.sys – (AVGIDSFilter)
DRV:64bit: - [2011/07/11 01:14:06 | 000,120,400 | —- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\AVGIDSDriver.sys – (AVGIDSDriver)
DRV:64bit: - [2011/07/11 01:14:06 | 000,026,704 | —- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\AVGIDSEH.sys – (AVGIDSEH)
DRV:64bit: - [2011/06/02 04:37:32 | 002,750,464 | —- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\athrx.sys – (athr)
DRV:64bit: - [2011/05/23 01:03:28 | 000,048,992 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\Windows\SysNative\drivers\avgfwd6a.sys – (Avgfwfd)
DRV:64bit: - [2011/01/13 04:17:30 | 000,122,624 | —- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\zghsmdm.sys – (zghsmdm)
DRV:64bit: - [2010/11/21 04:24:33 | 000,059,392 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV:64bit: - [2010/11/21 04:23:47 | 000,078,720 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2010/11/21 04:23:47 | 000,031,232 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbGD.sys – (TsUsbGD)
DRV:64bit: - [2010/10/18 07:24:46 | 000,038,424 | —- | M] (Google Inc) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\androidusb.sys – (androidusb)
DRV:64bit: - [2010/09/22 02:47:10 | 000,243,712 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\RtsUStor.sys – (RSUSBSTOR)
DRV:64bit: - [2010/07/20 01:10:40 | 010,603,904 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\igdkmd64.sys – (igfx)
DRV:64bit: - [2010/06/21 10:45:56 | 000,287,232 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\IntcDAud.sys – (IntcDAud) Intel®
DRV:64bit: - [2010/04/13 17:44:22 | 000,540,696 | —- | M] (Intel Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\iaStor.sys – (iaStor)
DRV:64bit: - [2010/04/13 11:15:04 | 000,135,560 | —- | M] (ELAN Microelectronic Corp.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\ETD.sys – (ETD)
DRV:64bit: - [2010/03/19 03:00:00 | 000,055,856 | —- | M] (Sonic Solutions) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\PxHlpa64.sys – (PxHlpa64)
DRV:64bit: - [2010/02/27 00:32:14 | 000,158,976 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Impcd.sys – (Impcd)
DRV:64bit: - [2009/09/17 06:54:54 | 000,056,344 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\HECIx64.sys – (HECIx64) Intel®
DRV:64bit: - [2009/07/14 02:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009/07/14 02:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009/07/14 02:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009/06/10 21:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009/06/10 21:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009/06/10 21:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009/06/10 21:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:64bit: - [2009/05/06 00:46:08 | 000,018,432 | —- | M] (NewTech Infosystems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\NTIDrvr.sys – (NTIDrvr)
DRV:64bit: - [2009/05/06 00:46:08 | 000,016,896 | —- | M] (NewTech Infosystems Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\UBHelper.sys – (UBHelper)
DRV:64bit: - [2009/04/16 13:18:40 | 000,033,264 | —- | M] (Windows ® Codename Longhorn DDK provider) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\SndTAudio.sys – (SndTAudio)
DRV - [2011/05/25 20:35:20 | 000,021,504 | —- | M] (http://libusb-win32.sourceforge.net) [Kernel | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\libusb0.sys – (libusb0)
DRV - [2009/07/14 02:19:10 | 000,019,008 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\wimmount.sys – (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://packardbell.msn.com
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://packardbell.msn.com
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://packardbell.msn.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://packardbell.msn.com
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-3138994264-2375581868-3546105074-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://packardbell.msn.com
IE - HKU\S-1-5-21-3138994264-2375581868-3546105074-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://packardbell.msn.com
IE - HKU\S-1-5-21-3138994264-2375581868-3546105074-1001\..\URLSearchHook: {687578b9-7132-4a7a-80e4-30ee31099e03} - No CLSID value found
IE - HKU\S-1-5-21-3138994264-2375581868-3546105074-1001\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-3138994264-2375581868-3546105074-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.0: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Acrobat: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\James\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\James\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2012/03/01 15:33:49 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files (x86)\AVG\AVG2012\Firefox4\ [2012/04/16 14:48:53 | 000,000,000 | —D | M]

[2012/04/07 09:45:18 | 000,000,000 | —D | M] (No name found) – C:\Users\James\AppData\Roaming\Mozilla\Firefox\extensions
[2012/04/07 09:45:18 | 000,000,000 | —D | M] (uTorrentControl2 Community Toolbar) – C:\Users\James\AppData\Roaming\Mozilla\Firefox\extensions\{687578b9-7132-4a7a-80e4-30ee31099e03}
[2012/04/18 15:34:25 | 000,000,000 | —D | M] (No name found) – C:\Users\James\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions
[2012/06/09 13:17:19 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms},
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\James\AppData\Local\Google\Chrome\Application\19.0.1084.52\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\James\AppData\Local\Google\Chrome\Application\19.0.1084.52\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\James\AppData\Local\Google\Chrome\Application\19.0.1084.52\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\James\AppData\Local\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll
CHR - plugin: AVG Internet Security (Enabled) = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.1901_0\plugins/avgnpss.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:\Users\James\AppData\Local\Google\Chrome\Application\plugins\npMozCouponPrinter.dll
CHR - plugin: Java™ Platform SE 6 U31 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: VLC Web Plugin (Enabled) = C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
CHR - plugin: WildTangent Games App Presence Detector (Enabled) = C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Google Update (Enabled) = C:\Users\James\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - Extension: YouTube = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: AVG Safe Search = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.1901_0\
CHR - Extension: Gmail = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2012/03/01 15:27:50 | 000,001,805 | R— | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 3dns.adobe.com 3dns-1.adobe.com 3dns-2.adobe.com 3dns-3.adobe.com 3dns-4.adobe.com activate.adobe.com activate-sea.adobe.com activate-sjc0.adobe.com activate.wip.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip1.adobe.com activate.wip2.adobe.com activate.wip3.adobe.com activate.wip4.adobe.com adobe-dns.adobe.com adobe-dns-1.adobe.com adobe-dns-2.adobe.com adobe-dns-3.adobe.com adobe-dns-4.adobe.com
O1 - Hosts: 127.0.0.1 adobeereg.com practivate.adobe practivate.adobe.com practivate.adobe.newoa practivate.adobe.ntp practivate.adobe.ipp ereg.adobe.com ereg.wip.adobe.com ereg.wip1.adobe.com
O1 - Hosts: 127.0.0.1 ereg.wip2.adobe.com ereg.wip3.adobe.com ereg.wip4.adobe.com hl2rcv.adobe.com wip.adobe.com wip1.adobe.com wip2.adobe.com wip3.adobe.com wip4.adobe.com
O1 - Hosts: 127.0.0.1 www.adobeereg.com wwis-dubc1-vip60.adobe.com www.wip.adobe.com www.wip1.adobe.com
O1 - Hosts: 127.0.0.1 www.wip2.adobe.com www.wip3.adobe.com www.wip4.adobe.com wwis-dubc1-vip60.adobe.com crl.verisign.net CRL.VERISIGN.NET ood.opsource.net
O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (TBSB01620 Class) - {58124A0B-DC32-4180-9BFF-E0E21AE34026} - C:\Program Files (x86)\IMinent Toolbar\tbcore3.dll ()
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Yontoo) - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files (x86)\Yontoo\YontooIEClient.dll (Yontoo LLC)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (IMinent Toolbar) - {977AE9CC-AF83-45E8-9E03-E2798216E2D5} - C:\Program Files (x86)\IMinent Toolbar\tbcore3.dll ()
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-3138994264-2375581868-3546105074-1001\..\Toolbar\WebBrowser: (no name) - {687578B9-7132-4A7A-80E4-30EE31099E03} - No CLSID value found.
O3 - HKU\S-1-5-21-3138994264-2375581868-3546105074-1001\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O4:64bit: - HKLM..\Run: [Acer ePower Management] C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerTray.exe (Acer Incorporated)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [ETDWare] C:\Program Files\Elantech\ETDCtrl.exe (ELAN Microelectronic Corp.)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [BackupManagerTray] C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\BackupManagerTray.exe (NewTech Infosystems, Inc.)
O4 - HKLM..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-3138994264-2375581868-3546105074-1001..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9 - Extra Button: Rip YouTube File - {38E51477-DDB4-4aed-9D61-D0C193E10749} - C:\Program Files (x86)\SoundTaxi\YouTubeRipper.dll ()
O9 - Extra 'Tools' menuitem : Rip YouTube file embedded in this page - {38E51477-DDB4-4aed-9D61-D0C193E10749} - C:\Program Files (x86)\SoundTaxi\YouTubeRipper.dll ()
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{64F0CD7F-97D9-4C18-93BC-2553B7B7A955}: DhcpNameServer = [removed] [removed]
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{3dca13b9-56ee-11e1-9d7f-b870f4fd1c19}\Shell - "" = AutoRun
O33 - MountPoints2\{3dca13b9-56ee-11e1-9d7f-b870f4fd1c19}\Shell\AutoRun\command - "" = E:\SETUP.EXE
O33 - MountPoints2\{3dca13b9-56ee-11e1-9d7f-b870f4fd1c19}\Shell\configure\command - "" = E:\SETUP.EXE
O33 - MountPoints2\{3dca13b9-56ee-11e1-9d7f-b870f4fd1c19}\Shell\install\command - "" = E:\SETUP.EXE
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~2\AVG\AVG2012\avgrsa.exe /sync /restart)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)


CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/06/10 17:11:53 | 000,596,480 | —- | C] (OldTimer Tools) – C:\Users\James\Desktop\OTL (1).exe
[2012/06/10 14:18:58 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy
[2012/06/10 14:18:54 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2012/06/10 14:18:54 | 000,000,000 | —D | C] – C:\Program Files (x86)\Spybot - Search & Destroy
[2012/06/10 12:25:31 | 000,000,000 | —D | C] – C:\Windows\pss
[2012/06/09 17:49:12 | 000,000,000 | —D | C] – C:\ComboFix
[2012/06/09 17:49:10 | 000,000,000 | —D | C] – C:\Qoobox
[2012/06/09 17:35:34 | 000,000,000 | —D | C] – C:\Users\James\AppData\Local\Adobe
[2012/06/09 16:22:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\ESET
[2012/06/09 15:11:45 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2012/06/09 14:31:07 | 000,000,000 | —D | C] – C:\Windows\SysNative\Macromed
[2012/06/09 13:20:04 | 000,000,000 | —D | C] – C:\Users\James\Documents\Downloads
[2012/06/09 13:18:45 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free YouTube Downloader
[2012/06/09 13:18:43 | 000,000,000 | —D | C] – C:\Users\James\AppData\Roaming\OpenCandy
[2012/06/09 13:18:43 | 000,000,000 | —D | C] – C:\Program Files (x86)\Free YouTube Downloader
[2012/06/09 13:17:19 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2012/06/09 13:17:17 | 000,000,000 | —D | C] – C:\Program Files\Web Assistant
[2012/05/31 13:09:18 | 000,000,000 | —D | C] – C:\ProgramData\Soulseek
[2012/05/31 13:09:04 | 000,000,000 | —D | C] – C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Soulseek NS
[2012/05/31 13:09:04 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Soulseek NS
[2012/05/31 13:09:03 | 000,000,000 | —D | C] – C:\Program Files (x86)\SoulseekNS
[2012/05/26 13:46:20 | 000,000,000 | —D | C] – C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Joboshare
[2012/05/26 13:46:17 | 000,000,000 | —D | C] – C:\Program Files (x86)\Joboshare
[2012/05/16 21:28:29 | 000,000,000 | —D | C] – C:\Program Files (x86)\IMinent Toolbar
[2012/05/12 00:46:08 | 001,544,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\DWrite.dll
[2012/05/12 00:46:06 | 005,559,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2012/05/12 00:46:06 | 003,968,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2012/05/12 00:46:06 | 003,913,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe

========== Files - Modified Within 30 Days ==========

[2012/06/10 17:11:55 | 000,596,480 | —- | M] (OldTimer Tools) – C:\Users\James\Desktop\OTL (1).exe
[2012/06/10 16:27:00 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3138994264-2375581868-3546105074-1001UA.job
[2012/06/10 15:23:16 | 000,016,976 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/06/10 15:23:16 | 000,016,976 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/06/10 15:21:10 | 000,726,316 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/06/10 15:21:10 | 000,628,808 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/06/10 15:21:10 | 000,110,960 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/06/10 15:16:05 | 000,017,920 | —- | M] () – C:\Windows\SysNative\rpcnetp.exe
[2012/06/10 15:16:02 | 000,058,288 | —- | M] (Absolute Software Corp.) – C:\Windows\SysWow64\rpcnet.dll
[2012/06/10 15:16:02 | 000,017,920 | —- | M] () – C:\Windows\SysWow64\rpcnetp.dll
[2012/06/10 15:15:52 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/06/10 15:15:50 | 277,901,311 | -HS- | M] () – C:\hiberfil.sys
[2012/06/10 15:15:47 | 000,017,920 | —- | M] () – C:\Windows\SysWow64\rpcnetp.exe
[2012/06/10 14:18:59 | 000,001,274 | —- | M] () – C:\Users\James\Desktop\Spybot - Search & Destroy.lnk
[2012/06/10 12:12:34 | 000,000,834 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2012/06/10 11:05:15 | 000,326,525 | —- | M] () – C:\Windows\SysNative\drivers\AVG\iavichjg.avm
[2012/06/10 10:27:00 | 000,000,856 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3138994264-2375581868-3546105074-1001Core.job
[2012/06/10 10:06:36 | 100,143,439 | —- | M] () – C:\Windows\SysNative\drivers\AVG\incavi.avm
[2012/06/09 10:57:12 | 000,013,517 | —- | M] () – C:\Users\James\Documents\Backup of Journal.wbk
[2012/06/04 09:00:40 | 000,013,160 | —- | M] (Absolute Software Corp.) – C:\Windows\SysWow64\Upgrd.exe
[2012/06/04 09:00:33 | 000,058,288 | —- | M] (Absolute Software Corp.) – C:\Windows\SysWow64\rpcnet.exe
[2012/05/30 18:09:44 | 000,016,565 | —- | M] () – C:\Users\James\Documents\Backup of Court.wbk
[2012/05/30 12:11:01 | 000,000,972 | —- | M] () – C:\Users\Public\Desktop\calibre - E-book management.lnk
[2012/05/29 00:44:32 | 000,625,911 | —- | M] () – C:\Windows\SysNative\drivers\AVG\iavifw.avm
[2012/05/27 16:24:04 | 000,037,480 | —- | M] () – C:\Users\James\Documents\Journal1.dotx
[2012/05/26 13:46:20 | 000,001,192 | —- | M] () – C:\Users\James\Desktop\Joboshare DVD Creator.lnk
[2012/05/24 13:05:08 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2012/05/16 21:33:49 | 000,000,866 | —- | M] () – C:\Windows\SysWow64\InstallUtil.InstallLog
[2012/05/12 09:50:09 | 000,305,592 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT

========== Files Created - No Company Name ==========

[2012/06/10 14:18:59 | 000,001,274 | —- | C] () – C:\Users\James\Desktop\Spybot - Search & Destroy.lnk
[2012/05/30 18:09:43 | 000,016,565 | —- | C] () – C:\Users\James\Documents\Backup of Court.wbk
[2012/05/27 16:37:50 | 000,013,517 | —- | C] () – C:\Users\James\Documents\Backup of Journal.wbk
[2012/05/27 16:24:03 | 000,037,480 | —- | C] () – C:\Users\James\Documents\Journal1.dotx
[2012/05/26 13:46:20 | 000,001,192 | —- | C] () – C:\Users\James\Desktop\Joboshare DVD Creator.lnk
[2012/05/24 13:05:08 | 000,000,000 | -H– | C] () – C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2012/05/16 21:27:21 | 000,000,866 | —- | C] () – C:\Windows\SysWow64\InstallUtil.InstallLog
[2012/05/08 00:26:40 | 000,000,466 | —- | C] () – C:\Windows\wininit.ini
[2012/04/08 17:03:24 | 000,155,136 | —- | C] () – C:\Windows\SysWow64\AI_ContextMenu.dll
[2012/02/17 13:58:10 | 000,000,016 | —- | C] () – C:\Windows\popcinfo.dat
[2011/09/14 13:05:44 | 000,870,560 | —- | C] () – C:\Windows\SysWow64\igkrng575.bin
[2011/09/14 13:05:44 | 000,208,896 | —- | C] () – C:\Windows\SysWow64\iglhsip32.dll
[2011/09/14 13:05:44 | 000,143,360 | —- | C] () – C:\Windows\SysWow64\iglhcp32.dll
[2011/09/14 13:05:44 | 000,104,796 | —- | C] () – C:\Windows\SysWow64\igfcg575m.bin
[2011/09/14 13:05:43 | 000,127,868 | —- | C] () – C:\Windows\SysWow64\igcompkrng575.bin
[2011/09/14 12:14:21 | 000,017,920 | —- | C] () – C:\Windows\SysWow64\rpcnetp.dll
[2011/09/14 12:13:30 | 000,017,920 | —- | C] () – C:\Windows\SysWow64\rpcnetp.exe

========== Custom Scans ==========

< %SYSTEMDRIVE%\*.exe >

< MD5 for: EXPLORER.EXE >
[2011/07/14 06:30:29 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2011/07/14 06:30:29 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\explorer.exe
[2011/07/14 06:30:29 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/07/14 06:30:29 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/21 04:24:25 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2011/07/14 06:30:29 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\SysWOW64\explorer.exe
[2011/07/14 06:30:29 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2010/11/21 04:24:11 | 002,872,320 | —- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe

< MD5 for: SVCHOST.EXE >
[2012/04/04 15:56:38 | 000,199,240 | —- | M] () MD5=097D0E812D7A9A3101CE46CB2BE0474D – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
[2009/07/14 02:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\SysWOW64\svchost.exe
[2009/07/14 02:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2009/07/14 02:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\SysNative\svchost.exe
[2009/07/14 02:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe

< MD5 for: USERINIT.EXE >
[2010/11/21 04:23:55 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\SysWOW64\userinit.exe
[2010/11/21 04:23:55 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2010/11/21 04:24:28 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\SysNative\userinit.exe
[2010/11/21 04:24:28 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe

< MD5 for: WINLOGON.EXE >
[2012/04/04 15:56:38 | 000,199,240 | —- | M] () MD5=097D0E812D7A9A3101CE46CB2BE0474D – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2010/11/21 04:24:29 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\SysNative\winlogon.exe
[2010/11/21 04:24:29 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe

< End of report >
Second report:




OTL Extras logfile created on: 10/06/2012 17:14:43 - Run 1
OTL by OldTimer - Version 3.2.48.0 Folder = C:\Users\James\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

5.68 Gb Total Physical Memory | 4.10 Gb Available Physical Memory | 72.22% Memory free
11.36 Gb Paging File | 9.58 Gb Available in Paging File | 84.40% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 678.54 Gb Total Space | 602.04 Gb Free Space | 88.73% Space Free | Partition Type: NTFS

Computer Name: JAMES-PC | User Name: James | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0B035800-BB65-4BB1-A7CB-1619CE334E59}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{0D68ECA9-A421-4926-85F0-2EB83D966557}" = lport=139 | protocol=6 | dir=in | app=system |
"{1176E420-0C84-4466-9B2E-D20A504C5A68}" = rport=445 | protocol=6 | dir=out | app=system |
"{2FA5BB27-1CEC-4D58-B96F-AA3B30702A42}" = rport=138 | protocol=17 | dir=out | app=system |
"{3D070535-FB40-44BB-8B51-DE8A367D0601}" = rport=10243 | protocol=6 | dir=out | app=system |
"{4521EDD3-40C4-4DC3-99AA-3CB54EFF9CEA}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{4C29F6A8-8B53-4CCA-B562-3F2B96908C87}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{5C91D4B6-D11D-4B2F-AC06-DB35B1D53887}" = lport=137 | protocol=17 | dir=in | app=system |
"{619F7B16-1956-44B6-B6C7-A121013E292C}" = lport=2869 | protocol=6 | dir=in | app=system |
"{6938E1C0-4ACB-4337-9FCF-2D74C715521C}" = lport=445 | protocol=6 | dir=in | app=system |
"{83A03FA4-5051-45A9-AED7-1732C45B2BAE}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{85993BFD-DECA-429A-9176-932FFE6DF97B}" = lport=2869 | protocol=6 | dir=in | app=system |
"{913070EB-DFF7-4CF9-AB1C-85CBA47E2015}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{95760AE0-F095-4914-8A43-B389238F774F}" = lport=138 | protocol=17 | dir=in | app=system |
"{9B28C6C8-0A90-4B41-BE89-CB32D0156B5D}" = rport=137 | protocol=17 | dir=out | app=system |
"{9B7A10E0-6748-472C-BD12-89161207A0BE}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{9DAAF96A-6C47-4889-B668-1CD55EB00603}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{A6D6E5B5-5EB5-4733-A19F-0573177C5B9B}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{BBA38E9C-8ED4-4F39-BDCC-62BB56B2D26C}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{C42192DC-7852-4647-B8B0-C103C1BF8A64}" = rport=139 | protocol=6 | dir=out | app=system |
"{C46CC945-0D5B-4E38-8745-223B04EC4952}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{CC0C5770-863B-41DC-B84E-902B26B46B8F}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{E4FBF8EE-5E74-4031-9BAE-39C14A99762D}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{EAB4B02E-9AD2-4FB3-974F-8A30E6DE24D4}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{ED4B06FF-6B86-440A-B7C8-93A4338FACD8}" = lport=10243 | protocol=6 | dir=in | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{051734F2-1B72-4262-A35A-71900F51AA0B}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{0AD05555-327F-45DE-9949-5D9B94CAF3F4}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{19B70427-AD36-48B4-9E83-FF8CAFAD151C}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{1F30B39C-DAE5-49ED-9EF8-20411D90A36F}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{2077ED36-9E67-4E9E-813F-24D8EEA54002}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{258124CA-ED59-4EE8-A235-AC7BF2423896}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{29227AF3-4FA9-4102-BAED-BAEDFDCBCCDC}" = dir=in | app=c:\program files (x86)\windows live\messenger\wlcsdk.exe |
"{2FE054BB-971C-4A13-BC45-1AEEE9F0C171}" = dir=in | app=c:\program files (x86)\windows live\sync\windowslivesync.exe |
"{3253EF97-23E1-454C-B758-B891DA4D6A91}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{4A9EC890-1ECB-411E-8B68-7DC7D8BAD397}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgmfapx.exe |
"{515FD0EF-938F-4DDA-A5E8-E37186CCDF19}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgwdsvc.exe |
"{59545D33-21BF-44A0-93C1-C4A45B355FD5}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{5D7F1865-1F42-4315-8085-B7309868AE99}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{628F8266-EB25-4D27-BCEE-AABAC835BCC3}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgemca.exe |
"{631C9D2C-EEDC-4C4C-8BF4-AF0489881349}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{6DA25AD9-6543-4032-B830-526D3F99FB1A}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{7A142FED-5CB9-48E2-B480-4F066C04A7A4}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{7B041BD0-93AE-452F-9BFF-760B432CA316}" = protocol=17 | dir=in | app=c:\program files\hp\hp deskjet 1000 j110 series\bin\usbsetup.exe |
"{852878A8-D0CD-4B86-A92F-75ED25AF4CAC}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgmfapx.exe |
"{87F3E935-A8BA-4836-80F4-1D4375C0B16D}" = protocol=17 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{8F6E6BB7-B682-4414-803B-A5996FF33D03}" = protocol=6 | dir=in | app=c:\program files\hp\hp deskjet 1000 j110 series\bin\usbsetup.exe |
"{954CF93D-8A2F-4B82-8689-6E0E31E4F013}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgnsa.exe |
"{9BBB4036-20D5-402A-8D18-7653D763187D}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{9C9B4CE9-F3CD-41E8-A1A5-801673F84368}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{9D0AD471-CB5D-4872-91D7-C2734F971006}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{A2BD320A-315A-4192-810E-A0BC88C749B6}" = protocol=6 | dir=in | app=c:\program files (x86)\tribler\tribler.exe |
"{A961731F-A11D-4373-99B0-DC324A0006D9}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgemca.exe |
"{A9C90200-A366-46E3-B473-CB3BB4D6231D}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{ABF9E06E-3321-4CBC-9775-64CD04CB338D}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{B5DCABDF-901E-49C0-AD76-17D61DE31072}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgdiagex.exe |
"{C1947A6F-F1D9-420C-AEDF-FBEE875A3904}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{C2B94D8D-EE36-49C6-A58F-601E9011789F}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgnsa.exe |
"{C8365AF2-3DAF-4479-808B-2B6236DE34F8}" = protocol=6 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{CAF53583-BD23-427E-B544-E16CE5F5643D}" = protocol=17 | dir=in | app=c:\program files (x86)\tribler\tribler.exe |
"{E18EB922-0CD8-4155-9651-F5F4DFA49BF0}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{E428AEC0-3B49-4283-90A4-14A875D6D103}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgwdsvc.exe |
"{EB4D8C40-3B1F-405C-B399-BD91931AC308}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{FC72E9E6-130E-408A-A5B7-554FB55927F5}" = protocol=6 | dir=out | app=system |
"{FFAA7F0D-95BD-4049-8AC3-DD4EBF3AD830}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgdiagex.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1A570BFA-D775-47EE-8071-06E9559C14F5}" = HP Deskjet 1000 J110 series Product Improvement Study
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{883B114D-BD3E-498F-9DAD-5E4A8E1C43BA}" = HP Deskjet 1000 J110 series Basic Device Software
"{889DF117-14D1-44EE-9F31-C5FB5D47F68B}" = Yontoo 1.10.02
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{BFF4A9FB-75F3-4162-84CD-16CE48C19173}" = AVG 2012
"{D050583D-5CEC-47B1-88AA-8B328CAA8621}" = AVG 2012
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"AVG" = AVG 2012
"CCleaner" = CCleaner
"Elantech" = ETDWare PS/2-x64 7.0.6.5_WHQL
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"WinRAR archiver" = WinRAR 4.10 (64-bit)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{007F778D-F15C-4EAB-AE92-071D21FAF632}" = Adobe Photoshop Elements 9
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = Video Web Camera
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2436F2A8-4B7E-4B6C-AE4E-604C84AA6A4F}" = Nero Core Components 10
"{25175695-4B20-4298-9F34-C2C57CD277B3}" = Elements STI Installer
"{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java™ 6 Update 31
"{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App" = Update Installer for WildTangent Games App
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{33643918-7957-4839-92C7-EA96CB621A98}" = Nero Express 10 Help (CHM)
"{34490F4E-48D0-492E-8249-B48BECF0537C}" = Nero DiscSpeed 10
"{3DB0448D-AD82-4923-B305-D001E521A964}" = Packard Bell Power Management
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel® Rapid Storage Technology
"{433EACD8-4747-4A6A-826A-FFA9F39B0D40}" = Elements 9 Organizer
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{523B2B1B-D8DB-4B41-90FF-C4D799E2758A}" = Nero ControlCenter 10 Help (CHM)
"{531336A9-55EB-4367-8064-7180849D5676}" = calibre
"{5335DADB-34BA-4AE8-A519-648D78498846}" = Skype™ 5.3
"{62BF4BD3-B1F6-4FA2-8388-CC0647ACBF86}" = Nero Multimedia Suite 10 Essentials
"{64EF903E-D00A-414C-94A4-FBA368FFCDC9}" = Packard Bell Social Networks
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel® Management Engine Components
"{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}" = Nero Update
"{6DFB899F-17A2-48F0-A533-ED8D6866CF38}" = Nero Control Center 10
"{70550193-1C22-445C-8FA4-564E155DB1A7}" = Nero Express 10
"{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-packardbell" = WildTangent Games App (Packard Bell Games)
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{72B776E5-4530-4C4B-9453-751DF87D9D93}" = Backup Manager Basic
"{7F811A54-5A09-4579-90E1-C93498E230D9}" = Packard Bell Recovery Management
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-001B-0000-0000-0000000FF1CE}" = Microsoft Office Word 2007
"{90120000-001B-0000-0000-0000000FF1CE}_WORD_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_WORD_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_WORD_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_WORD_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_WORD_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002A-0000-1000-0000000FF1CE}_WORD_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002A-0409-1000-0000000FF1CE}_WORD_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_WORD_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_WORD_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0116-0409-1000-0000000FF1CE}_WORD_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9F479685-180E-4C05-9400-D59292A1B29C}" = Windows Live Movie Maker
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A76AA284-E52D-47E6-9E4F-B85DBF8E35C3}" = IMinent Toolbar
"{AC76BA86-1033-F400-7760-000000000005}" = Adobe Acrobat X Pro - English, Français, Deutsch
"{AC76BA86-7AD7-FFFF-7B44-AA0000000001}" = Adobe Reader X (10.1.3) MUI
"{AFE499B5-FCC4-45E6-A1A5-3C51AE0E539B}" = Mobipocket Creator 4.2
"{B0069CFA-5BB9-4C03-B1C6-89CE290E5AFE}" = HP Update
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{C18A0418-442A-4186-AF98-D08F5054A2FC}" = Nero DiscSpeed 10 Help (CHM)
"{C28D96C0-6A90-459E-A077-A6706F4EC0FC}" = Bing Bar
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D3E5A972-9A15-427D-AE78-8181A5FD943C}" = eBay Worldwide
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{DDDFCC77-7F9C-45E9-B38E-721BA599BA0C}" = HP Deskjet 1000 J110 series Help
"{E2AE009D-37E5-4724-A6B8-0ED6A6BA4F68}" = Elements STI Installer
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{EB9955F8-467C-47FC-90F8-12CD5DF684C3}" = Adobe Premiere Elements 9
"{EE171732-BEB4-4576-887D-CB62727F01CA}" = Packard Bell Updater
"{EE39FFBD-544E-49E4-A999-6819828EAE91}" = Windows Live Photo Gallery
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel® Graphics Media Accelerator Driver
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F302F4F0-588D-6501-1ACF-BE3FDCC9135D}" = Adobe Community Help
"{F6117F9C-ADB5-4590-9BE4-12C7BEC28702}" = Nero StartSmart 10 Help (CHM)
"{F61D489E-6C44-49AC-AD02-7DA8ACA73A65}" = Nero StartSmart 10
"{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel® Control Center
"{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}" = Visual Studio 2008 x64 Redistributables
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Photoshop Elements 9" = Adobe Photoshop Elements 9
"Aimersoft Video Converter Ultimate_is1" = Aimersoft Video Converter Ultimate(Build [removed])
"AudibleManager" = AudibleManager
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"Coupon Printer for Windows5.0.0.0" = Coupon Printer for Windows
"DAEMON Tools Lite" = DAEMON Tools Lite
"Digital Editions" = Adobe Digital Editions
"ESET Online Scanner" = ESET Online Scanner v3
"HP Photo Creations" = HP Photo Creations
"Identity Card" = Identity Card
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = Video Web Camera
"InstallShield_{64EF903E-D00A-414C-94A4-FBA368FFCDC9}" = Packard Bell Social Networks
"InstallShield_{72B776E5-4530-4C4B-9453-751DF87D9D93}" = Packard Bell MyBackup
"Joboshare DVD Creator" = Joboshare DVD Creator
"KindleDRMRemoval" = Kindle DRM Removal
"Kobo" = Kobo
"LManager" = Launch Manager
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.61.0.1400
"Packard Bell Registration" = Packard Bell Registration
"Packard Bell Screensaver" = Packard Bell ScreenSaver
"Packard Bell Welcome Center" = Welcome Center
"PremElem90" = Adobe Premiere Elements 9
"SopCast" = SopCast 3.4.8
"Soulseek2" = SoulSeek 157 NS 13e
"SoundTaxi_is1" = SoundTaxi 3.8.2
"Tribler" = Tribler (remove only)
"uTorrent" = µTorrent
"VLC media player" = VLC media player 2.0.0
"WildTangent packardbell Master Uninstall" = Packard Bell Games
"WinLiveSuite_Wave3" = Windows Live Essentials
"WORD" = Microsoft Office Word 2007
"WTA-132c4467-9078-44a1-b7b7-b661de748ab7" = FATE
"WTA-4c35347b-c41b-42d4-aeae-5be978bb4ebe" = Penguins!
"WTA-4ea4a547-0be0-426d-8eeb-5724e68bc3b3" = Jewel Match 3
"WTA-4fe5f0ce-8f29-4a10-b40b-b546f3dda7ce" = Agatha Christie - Death on the Nile
"WTA-62e8d4ab-12e8-41e2-a129-957ff2bf88d5" = Mystery of Mortlake Mansion
"WTA-72924641-946e-4b3f-be1a-9a3ec591e107" = Plants vs. Zombies - Game of the Year
"WTA-737c5dc4-9587-47cd-a4ef-eb6ef4005eb7" = Insaniquarium Deluxe
"WTA-891f2d62-8e23-425f-987f-cd89dd96afea" = Jewel Quest Solitaire
"WTA-a0fbbae1-dfc1-444d-9473-39633ad9ee28" = Bejeweled 2 Deluxe
"WTA-adb9eebd-a5b2-4df3-9f0f-a02c2aad8ceb" = Virtual Villagers 4 - The Tree of Life
"WTA-b0fdb84d-2b3c-4f7f-b9a3-b8facdcc0b11" = John Deere Drive Green
"WTA-b4bfc51c-4c88-4531-bd81-75e67e8f11fa" = Zuma Deluxe
"WTA-c83298f3-0c65-49ff-95be-43a115f0cb7b" = Final Drive: Nitro
"WTA-e3eaf757-d47d-442a-a5cd-f2b1eafeab74" = Slingo Deluxe
"WTA-ee992678-d176-4ee1-8515-c88c3a0ed866" = Wedding Dash
"WTA-f2e4be6c-6937-4f19-9128-45dead63792b" = Chuzzle Deluxe
"WTA-f74e78b2-be27-4f63-905b-754bcb326860" = Polar Bowler
"WTA-fd6818a4-32c1-4d70-b558-83a63413e5a5" = Crazy Chicken Kart 2
"WTA-ffc979ee-1efc-431e-ad35-0994ba7d7e26" = Torchlight

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-3138994264-2375581868-3546105074-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Amazon Kindle" = Amazon Kindle
"Google Chrome" = Google Chrome

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 17/04/2012 19:17:50 | Computer Name = James-PC | Source = WinMgmt | ID = 10
Description =

Error - 18/04/2012 03:45:02 | Computer Name = James-PC | Source = WinMgmt | ID = 10
Description =

Error - 18/04/2012 04:55:10 | Computer Name = James-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "C:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "C:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.

Error - 18/04/2012 04:56:01 | Computer Name = James-PC | Source = SideBySide | ID = 16842787
Description = Activation context generation failed for "c:\program files (x86)\windows
live\photo gallery\MovieMaker.Exe".Error in manifest or policy file "c:\program
files (x86)\windows live\photo gallery\WLMFDS.DLL" on line 8. Component identity
found in manifest does not match the identity of the component requested. Reference
is WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition
is WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Please use
sxstrace.exe for detailed diagnosis.

Error - 19/04/2012 03:40:53 | Computer Name = James-PC | Source = WinMgmt | ID = 10
Description =

Error - 19/04/2012 05:31:32 | Computer Name = James-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "C:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "C:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.

Error - 19/04/2012 05:32:24 | Computer Name = James-PC | Source = SideBySide | ID = 16842787
Description = Activation context generation failed for "c:\program files (x86)\windows
live\photo gallery\MovieMaker.Exe".Error in manifest or policy file "c:\program
files (x86)\windows live\photo gallery\WLMFDS.DLL" on line 8. Component identity
found in manifest does not match the identity of the component requested. Reference
is WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition
is WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Please use
sxstrace.exe for detailed diagnosis.

Error - 19/04/2012 11:50:28 | Computer Name = James-PC | Source = WinMgmt | ID = 10
Description =

Error - 20/04/2012 03:36:20 | Computer Name = James-PC | Source = WinMgmt | ID = 10
Description =

Error - 20/04/2012 05:01:16 | Computer Name = James-PC | Source = WinMgmt | ID = 10
Description =

[ System Events ]
Error - 09/06/2012 13:40:34 | Computer Name = James-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068

Error - 09/06/2012 13:40:40 | Computer Name = James-PC | Source = DCOM | ID = 10005
Description =

Error - 09/06/2012 13:40:47 | Computer Name = James-PC | Source = DCOM | ID = 10005
Description =

Error - 09/06/2012 13:40:49 | Computer Name = James-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068

Error - 09/06/2012 13:40:49 | Computer Name = James-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068

Error - 09/06/2012 13:40:49 | Computer Name = James-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068

Error - 09/06/2012 13:40:49 | Computer Name = James-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068

Error - 09/06/2012 13:40:49 | Computer Name = James-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068

Error - 09/06/2012 13:40:49 | Computer Name = James-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068

Error - 09/06/2012 13:40:55 | Computer Name = James-PC | Source = DCOM | ID = 10005
Description =


< End of report >
Hi TheStrawMan

P2P - I see you have P2P software, (uTorrent and Soulseek2), installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infection. If your computer is infected, it almost certainly contributed to your current situation.

Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are more often than not, infected. The bad guys use P2P file-sharing as a major conduit to spread their wares.

Please see this topic for more information:

Perils of P2P File Sharing.

I would strongly recommend that you uninstall them now.

Should you decide to keep them, please don’t use them until we have finished.

===================================================

I see you have run Eset online scan and ComboFix.

While you may see ComboFix being used quite often without incident, the tool should not be run unsupervised (as stated in the Disclaimer that is first displayed by ComboFix when you run the tool)

ComboFix is a very powerful tool which, when improperly used, could render your machine a doorstop.

If you ever have a problem in the future I strongly advise you not to run this again unsupervised.

===================================================

Run OTL
  • double click on the icon to run it.
  • copy/paste ALL the following text written inside the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    IE - HKU\S-1-5-21-3138994264-2375581868-3546105074-1001\..\URLSearchHook: {687578b9-7132-4a7a-80e4-30ee31099e03} - No CLSID value found 
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
    O2 - BHO: (Yontoo) - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files (x86)\Yontoo\YontooIEClient.dll (Yontoo LLC)
    O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O3 - HKU\S-1-5-21-3138994264-2375581868-3546105074-1001\..\Toolbar\WebBrowser: (no name) - {687578B9-7132-4A7A-80E4-30EE31099E03} - No CLSID value found
    O3 - HKU\S-1-5-21-3138994264-2375581868-3546105074-1001\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found
    
    :Commands
    [purity]
    [emptytemp]
    [Reboot]

  • click the Run Fix button at the top
  • let the program run unhindered, reboot when it is done
  • post a new OTL log (don't check the boxes beside LOP Check or Purity this time)
Logs to include in the next post:

OTL fix log
New OTL log


Please also include the ComboFix log from when you ran it. ComboFix logs are located at c:\combofix.txt, older logs are at c:\qoobox\combofix2.txt, c:\qoobox\ComboFix3.txt etc

Thanks

Satchfan
Thanks again for the instructions and your help. Fix log: All processes killed ========== SERVICES/DRIVERS ========== ========== OTL ========== Registry value HKEY_USERS\S-1-5-21-3138994264-2375581868-3546105074-1001\Software\Microsoft\Internet Explorer\URLSearchHooks\\{687578b9-7132-4a7a-80e4-30ee31099e03} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{687578b9-7132-4a7a-80e4-30ee31099e03}\ not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}\ deleted successfully. C:\Program Files (x86)\Yontoo\YontooIEClient.dll moved successfully. 64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully. Registry value HKEY_USERS\S-1-5-21-3138994264-2375581868-3546105074-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{687578B9-7132-4A7A-80E4-30EE31099E03} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{687578B9-7132-4A7A-80E4-30EE31099E03}\ not found. Registry value HKEY_USERS\S-1-5-21-3138994264-2375581868-3546105074-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}\ not found. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 41620 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: James ->Temp folder emptied: 5374676 bytes ->Temporary Internet Files folder emptied: 5573974 bytes ->Java cache emptied: 560375 bytes ->Google Chrome cache emptied: 273858512 bytes ->Flash cache emptied: 167238 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 91591 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50333 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 272.00 mb OTL by OldTimer - Version 3.2.48.0 log created on 06102012_235500 Files\Folders moved on Reboot… C:\Users\James\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. File\Folder C:\Users\James\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U102KM1D\ADSAdClient31[1].htm not found! File\Folder C:\Users\James\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U102KM1D\direct;auc.5823759742071145402;ai.231981027.277258950;ac.1339330068-21679762;wi.234;hi.60;cp.0[1].htm not found! File\Folder C:\Users\James\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U102KM1D\tt[2].htm not found! File move failed. C:\Windows\temp\dsiwmis.log scheduled to be moved on reboot. Registry entries deleted on Reboot…
New OTL log (I checked scan all users but not LOP or purity)






OTL logfile created on: 11/06/2012 00:11:48 - Run 2
OTL by OldTimer - Version 3.2.48.0 Folder = C:\Users\James\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

5.68 Gb Total Physical Memory | 4.08 Gb Available Physical Memory | 71.90% Memory free
11.36 Gb Paging File | 9.73 Gb Available in Paging File | 85.69% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 678.54 Gb Total Space | 604.42 Gb Free Space | 89.08% Space Free | Partition Type: NTFS

Computer Name: JAMES-PC | User Name: James | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/06/10 17:11:55 | 000,596,480 | —- | M] (OldTimer Tools) – C:\Users\James\Desktop\OTL (1).exe
PRC - [2012/06/04 09:00:33 | 000,058,288 | —- | M] (Absolute Software Corp.) – C:\Windows\SysWOW64\rpcnet.exe
PRC - [2012/01/24 17:24:26 | 002,416,480 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files (x86)\AVG\AVG2012\avgtray.exe
PRC - [2012/01/03 14:10:50 | 000,815,512 | —- | M] (Adobe Systems Inc.) – C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
PRC - [2012/01/03 06:10:42 | 000,063,928 | —- | M] (Adobe Systems Incorporated) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011/11/23 02:36:24 | 002,391,832 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files (x86)\AVG\AVG2012\avgfws.exe
PRC - [2011/10/12 06:25:22 | 004,433,248 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe
PRC - [2011/08/02 06:09:08 | 000,192,776 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe
PRC - [2011/05/12 16:59:00 | 000,249,648 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
PRC - [2011/04/22 17:44:14 | 000,244,624 | —- | M] (Acer Incorporated) – C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe
PRC - [2011/01/18 03:52:26 | 000,039,528 | —- | M] (Acer Incorporated) – C:\Program Files (x86)\Packard Bell\Registration\GREGsvc.exe
PRC - [2010/09/30 03:06:46 | 000,169,408 | —- | M] (Adobe Systems Incorporated) – C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe
PRC - [2010/08/10 10:06:16 | 000,975,952 | —- | M] (Dritek System Inc.) – C:\Program Files (x86)\Launch Manager\LManager.exe
PRC - [2010/08/10 10:06:16 | 000,321,104 | —- | M] (Dritek System Inc.) – C:\Program Files (x86)\Launch Manager\dsiwmis.exe
PRC - [2010/08/10 10:06:16 | 000,305,744 | —- | M] (Dritek System Inc.) – C:\Program Files (x86)\Launch Manager\LMworker.exe
PRC - [2010/06/28 23:23:24 | 000,263,936 | —- | M] (NewTech Infosystems, Inc.) – C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\BackupManagerTray.exe
PRC - [2010/06/28 23:23:06 | 000,255,744 | —- | M] (NewTech Infosystems, Inc.) – C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\IScheduleSvc.exe
PRC - [2010/05/04 20:07:22 | 000,503,080 | —- | M] (Nero AG) – C:\Program Files (x86)\Nero\Update\NASvc.exe
PRC - [2010/04/13 17:57:58 | 000,013,336 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
PRC - [2010/03/18 05:57:02 | 002,320,920 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
PRC - [2010/03/18 05:56:56 | 000,268,824 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
PRC - [2009/01/26 15:31:16 | 002,144,088 | RHS- | M] (Safer Networking Limited) – C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe


========== Modules (No Company Name) ==========

MOD - [2010/06/28 23:20:54 | 000,465,576 | —- | M] () – C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\sqlite3.dll
MOD - [2009/05/20 07:02:04 | 000,072,200 | —- | M] () – C:\Program Files (x86)\Launch Manager\CdDirIo.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2011/04/22 17:44:14 | 000,244,624 | —- | M] (Acer Incorporated) [Auto | Running] – C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe – (Live Updater Service)
SRV:64bit: - [2011/01/05 15:23:58 | 000,867,712 | —- | M] (Acer Incorporated) [Auto | Running] – C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe – (ePowerSvc)
SRV:64bit: - [2009/07/14 02:41:27 | 001,011,712 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2012/06/04 09:00:33 | 000,058,288 | —- | M] (Absolute Software Corp.) [Auto | Running] – C:\Windows\SysWOW64\rpcnet.exe – (rpcnet) Remote Procedure Call (RPC)
SRV - [2012/01/03 06:10:42 | 000,063,928 | —- | M] (Adobe Systems Incorporated) [Auto | Running] – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe – (AdobeARMservice)
SRV - [2011/11/23 02:36:24 | 002,391,832 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files (x86)\AVG\AVG2012\avgfws.exe – (avgfws)
SRV - [2011/10/12 06:25:22 | 004,433,248 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe – (AVGIDSAgent)
SRV - [2011/08/02 06:09:08 | 000,192,776 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe – (avgwd)
SRV - [2011/06/07 12:25:12 | 000,191,752 | —- | M] (Microsoft Corporation.) [On_Demand | Stopped] – C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE – (BBSvc)
SRV - [2011/05/12 16:59:00 | 000,249,648 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE – (BBUpdate)
SRV - [2011/01/18 03:52:26 | 000,039,528 | —- | M] (Acer Incorporated) [Auto | Running] – C:\Program Files (x86)\Packard Bell\Registration\GREGsvc.exe – (GREGService)
SRV - [2010/10/12 18:59:12 | 000,206,072 | —- | M] (WildTangent, Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe – (GamesAppService)
SRV - [2010/09/30 03:06:46 | 000,169,408 | —- | M] (Adobe Systems Incorporated) [Auto | Running] – C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe – (AdobeActiveFileMonitor9.0)
SRV - [2010/08/10 10:06:16 | 000,321,104 | —- | M] (Dritek System Inc.) [Auto | Running] – C:\Program Files (x86)\Launch Manager\dsiwmis.exe – (DsiWMIService)
SRV - [2010/06/28 23:23:06 | 000,255,744 | —- | M] (NewTech Infosystems, Inc.) [Auto | Running] – C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\IScheduleSvc.exe – (NTI IScheduleSvc)
SRV - [2010/05/04 20:07:22 | 000,503,080 | —- | M] (Nero AG) [Auto | Running] – C:\Program Files (x86)\Nero\Update\NASvc.exe – (NAUpdate) @C:\Program Files (x86)
SRV - [2010/04/13 17:57:58 | 000,013,336 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe – (IAStorDataMgrSvc) Intel®
SRV - [2010/03/18 14:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2010/03/18 05:57:02 | 002,320,920 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe – (UNS) Intel®
SRV - [2010/03/18 05:56:56 | 000,268,824 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe – (LMS) Intel®
SRV - [2009/06/10 22:23:09 | 000,066,384 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)
SRV - [2009/04/16 15:40:02 | 000,237,568 | —- | M] (SMServer) [On_Demand | Stopped] – C:\Windows\SysWOW64\snmvtsvc.exe – (SMServer)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2012/03/01 07:46:16 | 000,023,408 | —- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] – C:\Windows\SysNative\drivers\fs_rec.sys – (Fs_Rec)
DRV:64bit: - [2012/02/14 13:56:49 | 000,283,200 | —- | M] (DT Soft Ltd) [Kernel | System | Running] – C:\Windows\SysNative\drivers\dtsoftbus01.sys – (dtsoftbus01)
DRV:64bit: - [2011/12/20 03:46:50 | 000,029,184 | —- | M] (http://libusb-win32.sourceforge.net) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\libusb0.sys – (libusb0)
DRV:64bit: - [2011/12/14 14:43:22 | 000,029,288 | —- | M] (Wondershare) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\WsAudio_DeviceS(5).sys – (WsAudio_DeviceS(5)) WsAudio_DeviceS(5)
DRV:64bit: - [2011/12/14 14:43:22 | 000,029,288 | —- | M] (Wondershare) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\WsAudio_DeviceS(4).sys – (WsAudio_DeviceS(4)) WsAudio_DeviceS(4)
DRV:64bit: - [2011/12/14 14:43:22 | 000,029,288 | —- | M] (Wondershare) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\WsAudio_DeviceS(3).sys – (WsAudio_DeviceS(3)) WsAudio_DeviceS(3)
DRV:64bit: - [2011/12/14 14:43:22 | 000,029,288 | —- | M] (Wondershare) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\WsAudio_DeviceS(2).sys – (WsAudio_DeviceS(2)) WsAudio_DeviceS(2)
DRV:64bit: - [2011/12/14 14:43:22 | 000,029,288 | —- | M] (Wondershare) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\WsAudio_DeviceS(1).sys – (WsAudio_DeviceS(1)) WsAudio_DeviceS(1)
DRV:64bit: - [2011/10/07 06:23:46 | 000,283,728 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\Windows\SysNative\drivers\avgldx64.sys – (Avgldx64)
DRV:64bit: - [2011/09/13 06:30:08 | 000,037,456 | —- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] – C:\Windows\SysNative\drivers\avgrkx64.sys – (Avgrkx64)
DRV:64bit: - [2011/08/08 06:08:58 | 000,046,672 | —- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] – C:\Windows\SysNative\drivers\avgmfx64.sys – (Avgmfx64)
DRV:64bit: - [2011/07/14 06:35:47 | 000,107,904 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2011/07/14 06:35:47 | 000,027,008 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2011/07/11 01:14:36 | 000,375,376 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\Windows\SysNative\drivers\avgtdia.sys – (Avgtdia)
DRV:64bit: - [2011/07/11 01:14:08 | 000,029,776 | —- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\AVGIDSFilter.sys – (AVGIDSFilter)
DRV:64bit: - [2011/07/11 01:14:06 | 000,120,400 | —- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\AVGIDSDriver.sys – (AVGIDSDriver)
DRV:64bit: - [2011/07/11 01:14:06 | 000,026,704 | —- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\AVGIDSEH.sys – (AVGIDSEH)
DRV:64bit: - [2011/06/02 04:37:32 | 002,750,464 | —- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\athrx.sys – (athr)
DRV:64bit: - [2011/05/23 01:03:28 | 000,048,992 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\Windows\SysNative\drivers\avgfwd6a.sys – (Avgfwfd)
DRV:64bit: - [2011/01/13 04:17:30 | 000,122,624 | —- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\zghsmdm.sys – (zghsmdm)
DRV:64bit: - [2010/11/21 04:24:33 | 000,059,392 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV:64bit: - [2010/11/21 04:23:47 | 000,078,720 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2010/11/21 04:23:47 | 000,031,232 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbGD.sys – (TsUsbGD)
DRV:64bit: - [2010/10/18 07:24:46 | 000,038,424 | —- | M] (Google Inc) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\androidusb.sys – (androidusb)
DRV:64bit: - [2010/09/22 02:47:10 | 000,243,712 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\RtsUStor.sys – (RSUSBSTOR)
DRV:64bit: - [2010/07/20 01:10:40 | 010,603,904 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\igdkmd64.sys – (igfx)
DRV:64bit: - [2010/06/21 10:45:56 | 000,287,232 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\IntcDAud.sys – (IntcDAud) Intel®
DRV:64bit: - [2010/04/13 17:44:22 | 000,540,696 | —- | M] (Intel Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\iaStor.sys – (iaStor)
DRV:64bit: - [2010/04/13 11:15:04 | 000,135,560 | —- | M] (ELAN Microelectronic Corp.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\ETD.sys – (ETD)
DRV:64bit: - [2010/03/19 03:00:00 | 000,055,856 | —- | M] (Sonic Solutions) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\PxHlpa64.sys – (PxHlpa64)
DRV:64bit: - [2010/02/27 00:32:14 | 000,158,976 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Impcd.sys – (Impcd)
DRV:64bit: - [2009/09/17 06:54:54 | 000,056,344 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\HECIx64.sys – (HECIx64) Intel®
DRV:64bit: - [2009/07/14 02:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009/07/14 02:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009/07/14 02:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009/06/10 21:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009/06/10 21:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009/06/10 21:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009/06/10 21:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:64bit: - [2009/05/06 00:46:08 | 000,018,432 | —- | M] (NewTech Infosystems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\NTIDrvr.sys – (NTIDrvr)
DRV:64bit: - [2009/05/06 00:46:08 | 000,016,896 | —- | M] (NewTech Infosystems Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\UBHelper.sys – (UBHelper)
DRV:64bit: - [2009/04/16 13:18:40 | 000,033,264 | —- | M] (Windows ® Codename Longhorn DDK provider) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\SndTAudio.sys – (SndTAudio)
DRV - [2011/05/25 20:35:20 | 000,021,504 | —- | M] (http://libusb-win32.sourceforge.net) [Kernel | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\libusb0.sys – (libusb0)
DRV - [2009/07/14 02:19:10 | 000,019,008 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\wimmount.sys – (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://packardbell.msn.com
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://packardbell.msn.com
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://packardbell.msn.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://packardbell.msn.com
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-3138994264-2375581868-3546105074-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://packardbell.msn.com
IE - HKU\S-1-5-21-3138994264-2375581868-3546105074-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://packardbell.msn.com
IE - HKU\S-1-5-21-3138994264-2375581868-3546105074-1001\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-3138994264-2375581868-3546105074-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.0: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Acrobat: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\James\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\James\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2012/03/01 15:33:49 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files (x86)\AVG\AVG2012\Firefox4\ [2012/04/16 14:48:53 | 000,000,000 | —D | M]

[2012/04/07 09:45:18 | 000,000,000 | —D | M] (No name found) – C:\Users\James\AppData\Roaming\Mozilla\Firefox\extensions
[2012/04/07 09:45:18 | 000,000,000 | —D | M] (uTorrentControl2 Community Toolbar) – C:\Users\James\AppData\Roaming\Mozilla\Firefox\extensions\{687578b9-7132-4a7a-80e4-30ee31099e03}
[2012/04/18 15:34:25 | 000,000,000 | —D | M] (No name found) – C:\Users\James\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions
[2012/06/09 13:17:19 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms},
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\James\AppData\Local\Google\Chrome\Application\19.0.1084.52\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\James\AppData\Local\Google\Chrome\Application\19.0.1084.52\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\James\AppData\Local\Google\Chrome\Application\19.0.1084.52\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\James\AppData\Local\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll
CHR - plugin: AVG Internet Security (Enabled) = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.1901_0\plugins/avgnpss.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:\Users\James\AppData\Local\Google\Chrome\Application\plugins\npMozCouponPrinter.dll
CHR - plugin: Java™ Platform SE 6 U31 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: VLC Web Plugin (Enabled) = C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
CHR - plugin: WildTangent Games App Presence Detector (Enabled) = C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Google Update (Enabled) = C:\Users\James\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - Extension: YouTube = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: AVG Safe Search = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.1901_0\
CHR - Extension: Gmail = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2012/03/01 15:27:50 | 000,001,805 | R— | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 3dns.adobe.com 3dns-1.adobe.com 3dns-2.adobe.com 3dns-3.adobe.com 3dns-4.adobe.com activate.adobe.com activate-sea.adobe.com activate-sjc0.adobe.com activate.wip.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip1.adobe.com activate.wip2.adobe.com activate.wip3.adobe.com activate.wip4.adobe.com adobe-dns.adobe.com adobe-dns-1.adobe.com adobe-dns-2.adobe.com adobe-dns-3.adobe.com adobe-dns-4.adobe.com
O1 - Hosts: 127.0.0.1 adobeereg.com practivate.adobe practivate.adobe.com practivate.adobe.newoa practivate.adobe.ntp practivate.adobe.ipp ereg.adobe.com ereg.wip.adobe.com ereg.wip1.adobe.com
O1 - Hosts: 127.0.0.1 ereg.wip2.adobe.com ereg.wip3.adobe.com ereg.wip4.adobe.com hl2rcv.adobe.com wip.adobe.com wip1.adobe.com wip2.adobe.com wip3.adobe.com wip4.adobe.com
O1 - Hosts: 127.0.0.1 www.adobeereg.com wwis-dubc1-vip60.adobe.com www.wip.adobe.com www.wip1.adobe.com
O1 - Hosts: 127.0.0.1 www.wip2.adobe.com www.wip3.adobe.com www.wip4.adobe.com wwis-dubc1-vip60.adobe.com crl.verisign.net CRL.VERISIGN.NET ood.opsource.net
O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (TBSB01620 Class) - {58124A0B-DC32-4180-9BFF-E0E21AE34026} - C:\Program Files (x86)\IMinent Toolbar\tbcore3.dll ()
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (IMinent Toolbar) - {977AE9CC-AF83-45E8-9E03-E2798216E2D5} - C:\Program Files (x86)\IMinent Toolbar\tbcore3.dll ()
O4:64bit: - HKLM..\Run: [Acer ePower Management] C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerTray.exe (Acer Incorporated)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [ETDWare] C:\Program Files\Elantech\ETDCtrl.exe (ELAN Microelectronic Corp.)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [BackupManagerTray] C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\BackupManagerTray.exe (NewTech Infosystems, Inc.)
O4 - HKLM..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-3138994264-2375581868-3546105074-1001..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9 - Extra Button: Rip YouTube File - {38E51477-DDB4-4aed-9D61-D0C193E10749} - C:\Program Files (x86)\SoundTaxi\YouTubeRipper.dll ()
O9 - Extra 'Tools' menuitem : Rip YouTube file embedded in this page - {38E51477-DDB4-4aed-9D61-D0C193E10749} - C:\Program Files (x86)\SoundTaxi\YouTubeRipper.dll ()
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{64F0CD7F-97D9-4C18-93BC-2553B7B7A955}: DhcpNameServer = [removed] [removed]
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{3dca13b9-56ee-11e1-9d7f-b870f4fd1c19}\Shell - "" = AutoRun
O33 - MountPoints2\{3dca13b9-56ee-11e1-9d7f-b870f4fd1c19}\Shell\AutoRun\command - "" = E:\SETUP.EXE
O33 - MountPoints2\{3dca13b9-56ee-11e1-9d7f-b870f4fd1c19}\Shell\configure\command - "" = E:\SETUP.EXE
O33 - MountPoints2\{3dca13b9-56ee-11e1-9d7f-b870f4fd1c19}\Shell\install\command - "" = E:\SETUP.EXE
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~2\AVG\AVG2012\avgrsa.exe /sync /restart)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2012/06/10 23:55:00 | 000,000,000 | —D | C] – C:\_OTL
[2012/06/10 17:11:53 | 000,596,480 | —- | C] (OldTimer Tools) – C:\Users\James\Desktop\OTL (1).exe
[2012/06/10 14:18:58 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy
[2012/06/10 14:18:54 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2012/06/10 14:18:54 | 000,000,000 | —D | C] – C:\Program Files (x86)\Spybot - Search & Destroy
[2012/06/10 12:25:31 | 000,000,000 | —D | C] – C:\Windows\pss
[2012/06/09 17:49:12 | 000,000,000 | —D | C] – C:\ComboFix
[2012/06/09 17:49:10 | 000,000,000 | —D | C] – C:\Qoobox
[2012/06/09 17:35:34 | 000,000,000 | —D | C] – C:\Users\James\AppData\Local\Adobe
[2012/06/09 16:22:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\ESET
[2012/06/09 15:11:45 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2012/06/09 14:31:07 | 000,000,000 | —D | C] – C:\Windows\SysNative\Macromed
[2012/06/09 13:20:04 | 000,000,000 | —D | C] – C:\Users\James\Documents\Downloads
[2012/06/09 13:18:45 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free YouTube Downloader
[2012/06/09 13:18:43 | 000,000,000 | —D | C] – C:\Users\James\AppData\Roaming\OpenCandy
[2012/06/09 13:18:43 | 000,000,000 | —D | C] – C:\Program Files (x86)\Free YouTube Downloader
[2012/06/09 13:17:19 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2012/06/09 13:17:17 | 000,000,000 | —D | C] – C:\Program Files\Web Assistant
[2012/05/31 13:09:18 | 000,000,000 | —D | C] – C:\ProgramData\Soulseek
[2012/05/31 13:09:04 | 000,000,000 | —D | C] – C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Soulseek NS
[2012/05/31 13:09:04 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Soulseek NS
[2012/05/31 13:09:03 | 000,000,000 | —D | C] – C:\Program Files (x86)\SoulseekNS
[2012/05/26 13:46:20 | 000,000,000 | —D | C] – C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Joboshare
[2012/05/26 13:46:17 | 000,000,000 | —D | C] – C:\Program Files (x86)\Joboshare
[2012/05/16 21:28:29 | 000,000,000 | —D | C] – C:\Program Files (x86)\IMinent Toolbar
[2012/05/12 00:46:08 | 001,544,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\DWrite.dll
[2012/05/12 00:46:06 | 005,559,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2012/05/12 00:46:06 | 003,968,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2012/05/12 00:46:06 | 003,913,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe

========== Files - Modified Within 30 Days ==========

[2012/06/11 00:03:50 | 000,016,976 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/06/11 00:03:50 | 000,016,976 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/06/11 00:01:05 | 000,726,316 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/06/11 00:01:05 | 000,628,808 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/06/11 00:01:05 | 000,110,960 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/06/10 23:56:41 | 000,058,288 | —- | M] (Absolute Software Corp.) – C:\Windows\SysWow64\rpcnet.dll
[2012/06/10 23:56:41 | 000,017,920 | —- | M] () – C:\Windows\SysWow64\rpcnetp.dll
[2012/06/10 23:56:35 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/06/10 23:56:33 | 277,901,311 | -HS- | M] () – C:\hiberfil.sys
[2012/06/10 23:56:27 | 000,017,920 | —- | M] () – C:\Windows\SysWow64\rpcnetp.exe
[2012/06/10 23:56:27 | 000,017,920 | —- | M] () – C:\Windows\SysNative\rpcnetp.exe
[2012/06/10 23:28:00 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3138994264-2375581868-3546105074-1001UA.job
[2012/06/10 23:06:21 | 100,160,397 | —- | M] () – C:\Windows\SysNative\drivers\AVG\incavi.avm
[2012/06/10 23:05:57 | 000,335,691 | —- | M] () – C:\Windows\SysNative\drivers\AVG\iavichjg.avm
[2012/06/10 17:11:55 | 000,596,480 | —- | M] (OldTimer Tools) – C:\Users\James\Desktop\OTL (1).exe
[2012/06/10 14:18:59 | 000,001,274 | —- | M] () – C:\Users\James\Desktop\Spybot - Search & Destroy.lnk
[2012/06/10 12:12:34 | 000,000,834 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2012/06/10 10:27:00 | 000,000,856 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3138994264-2375581868-3546105074-1001Core.job
[2012/06/09 10:57:12 | 000,013,517 | —- | M] () – C:\Users\James\Documents\Backup of Journal.wbk
[2012/06/04 09:00:40 | 000,013,160 | —- | M] (Absolute Software Corp.) – C:\Windows\SysWow64\Upgrd.exe
[2012/06/04 09:00:33 | 000,058,288 | —- | M] (Absolute Software Corp.) – C:\Windows\SysWow64\rpcnet.exe
[2012/05/30 18:09:44 | 000,016,565 | —- | M] () – C:\Users\James\Documents\Backup of Court.wbk
[2012/05/30 12:11:01 | 000,000,972 | —- | M] () – C:\Users\Public\Desktop\calibre - E-book management.lnk
[2012/05/29 00:44:32 | 000,625,911 | —- | M] () – C:\Windows\SysNative\drivers\AVG\iavifw.avm
[2012/05/27 16:24:04 | 000,037,480 | —- | M] () – C:\Users\James\Documents\Journal1.dotx
[2012/05/26 13:46:20 | 000,001,192 | —- | M] () – C:\Users\James\Desktop\Joboshare DVD Creator.lnk
[2012/05/24 13:05:08 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2012/05/16 21:33:49 | 000,000,866 | —- | M] () – C:\Windows\SysWow64\InstallUtil.InstallLog
[2012/05/12 09:50:09 | 000,305,592 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT

========== Files Created - No Company Name ==========

[2012/06/10 14:18:59 | 000,001,274 | —- | C] () – C:\Users\James\Desktop\Spybot - Search & Destroy.lnk
[2012/05/30 18:09:43 | 000,016,565 | —- | C] () – C:\Users\James\Documents\Backup of Court.wbk
[2012/05/27 16:37:50 | 000,013,517 | —- | C] () – C:\Users\James\Documents\Backup of Journal.wbk
[2012/05/27 16:24:03 | 000,037,480 | —- | C] () – C:\Users\James\Documents\Journal1.dotx
[2012/05/26 13:46:20 | 000,001,192 | —- | C] () – C:\Users\James\Desktop\Joboshare DVD Creator.lnk
[2012/05/24 13:05:08 | 000,000,000 | -H– | C] () – C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2012/05/16 21:27:21 | 000,000,866 | —- | C] () – C:\Windows\SysWow64\InstallUtil.InstallLog
[2012/05/08 00:26:40 | 000,000,466 | —- | C] () – C:\Windows\wininit.ini
[2012/04/08 17:03:24 | 000,155,136 | —- | C] () – C:\Windows\SysWow64\AI_ContextMenu.dll
[2012/02/17 13:58:10 | 000,000,016 | —- | C] () – C:\Windows\popcinfo.dat
[2011/09/14 13:05:44 | 000,870,560 | —- | C] () – C:\Windows\SysWow64\igkrng575.bin
[2011/09/14 13:05:44 | 000,208,896 | —- | C] () – C:\Windows\SysWow64\iglhsip32.dll
[2011/09/14 13:05:44 | 000,143,360 | —- | C] () – C:\Windows\SysWow64\iglhcp32.dll
[2011/09/14 13:05:44 | 000,104,796 | —- | C] () – C:\Windows\SysWow64\igfcg575m.bin
[2011/09/14 13:05:43 | 000,127,868 | —- | C] () – C:\Windows\SysWow64\igcompkrng575.bin
[2011/09/14 12:14:21 | 000,017,920 | —- | C] () – C:\Windows\SysWow64\rpcnetp.dll
[2011/09/14 12:13:30 | 000,017,920 | —- | C] () – C:\Windows\SysWow64\rpcnetp.exe

< End of report >
I'm unsure why I ran ComboFix in the first place, however the only log I can find is the following, I hope this is correct. I have a Qoobox folder, but see no text files within. ComboFix 12-06-09.01 - James 09/06/2012 17:50:51.1.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.5815.4403 [GMT 1:00] Running from: C:\Users\[removed]\Downloads\ComboFix.exe AV: AVG Internet Security Business Edition 2012 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0} FW: AVG Firewall *Disabled* {621CC794-9486-F902-D092-0484E8EA828B} SP: AVG Internet Security Business Edition 2012 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} Two things ive noticed seem to be persistent are Coupon printer for windows and yontoo and both show up in my list of programs, I wont attempt to uninstall anything of course, as per instructions. I also will not run ComboFix again. Should I remove it? Thanks again.
Thanks for the logs.

Two things ive noticed seem to be persistent are Coupon printer for windows and yontoo and both show up in my list of programs, I wont attempt to uninstall anything of course, as per instructions.

I see Coupon Printer in your installed programs but not Yontoo but if you say they are both there you can go ahead and uninstall them.

also will not run ComboFix again. Should I remove it?

We’ll deal with uninstalling it later. BTW, that was only the header of the ComboFix log, not the full log. If you have the full log, please send it with the one requested below.

Spybot TeaTimer

Please disable this program and leave it disabled until we are done as it can interfere with some of the tools we use.
  • launch Spybot S&D, go to the Mode menu and make sure "Advanced Mode" is selected.
  • on the left hand side, click on Tools, then click on the Resident Icon in the list.
  • uncheck the Resident TeaTimer (Protection of overall system settings) active box.
  • click on the System Startup icon in the List
  • uncheck the "TeaTimer" box and click OK at any prompts.
  • if Teatimer gives you a warning that changes were made, click Allow Change when prompted.
  • exit Spybot S&D.
(When we are finished, you can re-enable Teatimer using the same steps but this time place a check next to "Resident TeaTimer" and check the "TeaTimer" box in System Startup).

Please disable this program and leave it disabled until we are finished.

=============================================

Run ComboFix

Delete the version of ComboFix you have here:

C:\Users\James\Downloads\ComboFix.exe

Download a new version which MUST be saved directly to your desktop.

You can download the new version from one of the following locations:

Link 1
Link 2

**Note: It MUST be saved directly to your desktop. Choose save as and then make sure you choose Desktop

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

Double click on ComboFix.exe & follow the prompts.
  • when finished, it will produce a report.
  • please post the C:\ComboFix.txt for further review.
Satchfan

I see Coupon Printer in your installed programs but not Yontoo but if you say they are both there you can go ahead and uninstall them.


- Attempts to uninstall either results in error messages, presumably because they have been partially removed, im not sure.

- I remember now that I did not complete the scan when I ran ComboFix previously, that will be why I do not have a log for it.

- I disabled Spybot TeaTimer, however I did not see it in the system startup list, hopefully that will be ok since it was disabled in the recovery list

- Anyway, thanks again, and here is the new ComboFix log:



ComboFix 12-06-10.01 - James 11/06/2012 9:35.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.5815.4347 [GMT 1:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: AVG Internet Security Business Edition 2012 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
FW: AVG Firewall *Disabled* {621CC794-9486-F902-D092-0484E8EA828B}
SP: AVG Internet Security Business Edition 2012 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
—- Previous Run ——-
.
c:\program files (x86)\IMinent Toolbar\tbHElper.dll
c:\program files\Web Assistant\ExTEnsion32.dll
c:\users\James\Documents\~WRL0003.tmp
.
.
((((((((((((((((((((((((( Files Created from 2012-05-11 to 2012-06-11 )))))))))))))))))))))))))))))))
.
.
2012-06-11 08:39 . 2012-06-11 08:39 ——– d—–w- c:\users\Default\AppData\Local\temp
2012-06-10 22:55 . 2012-06-10 22:55 ——– d—–w- C:\_OTL
2012-06-10 13:18 . 2012-06-10 14:01 ——– d—–w- c:\programdata\Spybot - Search & Destroy
2012-06-10 13:18 . 2012-06-10 13:18 ——– d—–w- c:\program files (x86)\Spybot - Search & Destroy
2012-06-09 16:35 . 2012-06-09 16:35 ——– d—–w- c:\users\James\AppData\Local\Adobe
2012-06-09 15:22 . 2012-06-09 15:22 ——– d—–w- c:\program files (x86)\ESET
2012-06-09 14:11 . 2012-06-10 00:21 ——– d—–w- c:\program files\SUPERAntiSpyware
2012-06-09 13:31 . 2012-06-10 00:20 ——– d—–w- c:\windows\system32\Macromed
2012-06-09 12:18 . 2012-06-10 09:00 ——– d—–w- c:\program files (x86)\Free YouTube Downloader
2012-06-09 12:18 . 2012-06-10 09:00 ——– d—–w- c:\users\James\AppData\Roaming\OpenCandy
2012-06-09 12:17 . 2012-06-10 09:02 ——– d—–w- c:\program files\Web Assistant
2012-05-31 12:09 . 2012-05-31 12:09 ——– d—–w- c:\programdata\Soulseek
2012-05-31 12:09 . 2012-05-31 12:09 ——– d—–w- c:\program files (x86)\SoulseekNS
2012-05-26 12:46 . 2012-05-26 12:46 ——– d—–w- c:\program files (x86)\Joboshare
2012-05-16 20:28 . 2012-06-10 09:00 ——– d—–w- c:\program files (x86)\IMinent Toolbar
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-06-11 08:40 . 2012-02-09 15:40 58288 —-a-w- c:\windows\SysWow64\rpcnet.dll
2012-06-11 08:40 . 2011-09-14 11:14 17920 —-a-w- c:\windows\SysWow64\rpcnetp.dll
2012-06-11 08:40 . 2011-09-14 11:13 17920 —-a-w- c:\windows\SysWow64\rpcnetp.exe
2012-06-11 08:40 . 2011-09-14 11:13 17920 —-a-w- c:\windows\system32\rpcnetp.exe
2012-06-04 08:00 . 2012-02-09 15:39 13160 —-a-w- c:\windows\SysWow64\Upgrd.exe
2012-06-04 08:00 . 2012-02-09 15:40 58288 ——w- c:\windows\SysWow64\rpcnet.exe
2012-04-04 14:56 . 2012-02-15 11:29 24904 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-03-31 06:05 . 2012-05-11 23:46 5559664 —-a-w- c:\windows\system32\ntoskrnl.exe
2012-03-31 04:39 . 2012-05-11 23:46 3968368 —-a-w- c:\windows\SysWow64\ntkrnlpa.exe
2012-03-31 04:39 . 2012-05-11 23:46 3913072 —-a-w- c:\windows\SysWow64\ntoskrnl.exe
2012-03-31 03:10 . 2012-05-11 23:46 3146240 —-a-w- c:\windows\system32\win32k.sys
2012-03-30 11:35 . 2012-05-11 23:45 1918320 —-a-w- c:\windows\system32\drivers\tcpip.sys
2012-03-17 07:58 . 2012-05-11 23:45 75120 —-a-w- c:\windows\system32\drivers\partmgr.sys
2012-03-15 18:21 . 2012-03-15 18:21 255352 —-a-w- c:\windows\SysWow64\awrdscdc.ax
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{58124A0B-DC32-4180-9BFF-E0E21AE34026}]
2010-07-02 08:54 2607872 —-a-w- c:\program files (x86)\IMinent Toolbar\tbcore3.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{977AE9CC-AF83-45E8-9E03-E2798216E2D5}"= "c:\program files (x86)\IMinent Toolbar\tbcore3.dll" [2010-07-02 2607872]
.
[HKEY_CLASSES_ROOT\clsid\{977ae9cc-af83-45e8-9e03-e2798216e2d5}]
[HKEY_CLASSES_ROOT\TBSB01620.TBSB01620.3]
[HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}]
[HKEY_CLASSES_ROOT\TBSB01620.TBSB01620]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"BackupManagerTray"="c:\program files (x86)\NewTech Infosystems\Packard Bell MyBackup\BackupManagerTray.exe" [2010-06-28 263936]
"LManager"="c:\program files (x86)\Launch Manager\LManager.exe" [2010-08-10 975952]
"HP Software Update"="c:\program files (x86)\Hp\HP Software Update\HPWuSchd2.exe" [2010-06-09 49208]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"Adobe Acrobat Speed Launcher"="c:\program files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe" [2012-01-03 36760]
"Acrobat Assistant 8.0"="c:\program files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe" [2012-01-03 815512]
"AVG_TRAY"="c:\program files (x86)\AVG\AVG2012\avgtray.exe" [2012-01-24 2416480]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~2\AVG\AVG2012\avgrsa.exe /sync /restart
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 androidusb;ADB Interface Driver;c:\windows\system32\Drivers\androidusb.sys [x]
R3 AVGIDSAgent;AVGIDSAgent;c:\program files (x86)\AVG\AVG2012\AVGIDSAgent.exe [2011-10-12 4433248]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\AVGIDSDriver.Sys [x]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\DRIVERS\AVGIDSFilter.Sys [x]
R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-06-07 191752]
R3 GamesAppService;GamesAppService;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
R3 k57nd60a;Broadcom NetLink ™ Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys [x]
R3 libusb0;libusb-win32 - Kernel Driver, Version 1.2.4.0;c:\windows\system32\drivers\libusb0.sys [2011-12-20 29184]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\System32\Drivers\RtsUStor.sys [x]
R3 SMServer;SMServer;c:\windows\SysWOW64\snmvtsvc.exe [2009-04-16 237568]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R3 zghsmdm;ZTE General Handset USB Modem Proprietary;c:\windows\system32\DRIVERS\zghsmdm.sys [x]
S0 AVGIDSEH;AVGIDSEH;c:\windows\system32\DRIVERS\AVGIDSEH.Sys [x]
S0 Avgrkx64;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx64.sys [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x]
S1 Avgfwfd;AVG network filter service;c:\windows\system32\DRIVERS\avgfwd6a.sys [x]
S1 Avgldx64;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx64.sys [x]
S1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\DRIVERS\avgmfx64.sys [x]
S1 Avgtdia;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdia.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AdobeActiveFileMonitor9.0;Adobe Active File Monitor V9;c:\program files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe [2010-09-30 169408]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
S2 avgfws;AVG Firewall;c:\program files (x86)\AVG\AVG2012\avgfws.exe [2011-11-23 2391832]
S2 avgwd;AVG WatchDog;c:\program files (x86)\AVG\AVG2012\avgwdsvc.exe [2011-08-02 192776]
S2 BBUpdate;BBUpdate;c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE [2011-05-12 249648]
S2 DsiWMIService;Dritek WMI Service;c:\program files (x86)\Launch Manager\dsiwmis.exe [2010-08-10 321104]
S2 ePowerSvc;Acer ePower Service;c:\program files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe [2011-01-05 867712]
S2 GREGService;GREGService;c:\program files (x86)\Packard Bell\Registration\GREGsvc.exe [2011-01-18 39528]
S2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-04-13 13336]
S2 Live Updater Service;Live Updater Service;c:\program files\Packard Bell\Packard Bell Updater\UpdaterService.exe [2011-04-22 244624]
S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2010-05-04 503080]
S2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NewTech Infosystems\Packard Bell MyBackup\IScheduleSvc.exe [2010-06-28 255744]
S2 UNS;Intel® Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2010-03-18 2320920]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [x]
S3 HECIx64;Intel® Management Engine Interface;c:\windows\system32\drivers\HECIx64.sys [x]
S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [x]
S3 IntcDAud;Intel® Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [x]
S3 SndTAudio;SndTAudio;c:\windows\system32\drivers\SndTAudio.sys [x]
S3 WsAudio_DeviceS(1);WsAudio_DeviceS(1);c:\windows\system32\drivers\WsAudio_DeviceS(1).sys [x]
S3 WsAudio_DeviceS(2);WsAudio_DeviceS(2);c:\windows\system32\drivers\WsAudio_DeviceS(2).sys [x]
S3 WsAudio_DeviceS(3);WsAudio_DeviceS(3);c:\windows\system32\drivers\WsAudio_DeviceS(3).sys [x]
S3 WsAudio_DeviceS(4);WsAudio_DeviceS(4);c:\windows\system32\drivers\WsAudio_DeviceS(4).sys [x]
S3 WsAudio_DeviceS(5);WsAudio_DeviceS(5);c:\windows\system32\drivers\WsAudio_DeviceS(5).sys [x]
.
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - WS2IFSL
.
Contents of the 'Scheduled Tasks' folder
.
2012-06-10 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3138994264-2375581868-3546105074-1001Core.job
- c:\users\James\AppData\Local\Google\Update\GoogleUpdate.exe [2012-02-09 15:17]
.
2012-06-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3138994264-2375581868-3546105074-1001UA.job
- c:\users\James\AppData\Local\Google\Update\GoogleUpdate.exe [2012-02-09 15:17]
.
.
——— X64 Entries ———–
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-07-23 161304]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-07-23 386584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-07-23 415256]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-06-22 10920552]
"Acer ePower Management"="c:\program files\Packard Bell\Packard Bell Power Management\ePowerTray.exe" [2011-01-05 860040]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-09-16 497648]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://packardbell.msn.com
uLocal Page = c:\windows\system32\blank.htm
mStart Page = hxxp://packardbell.msn.com
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = [removed] [removed]
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-Run-ETDWare - c:\program files (x86)\Elantech\ETDCtrl.exe
.
.
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11f_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11f_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11f.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11f.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11f.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11f.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
———————— Other Running Processes ————————
.
c:\program files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
c:\windows\SysWOW64\rpcnet.exe
.
**************************************************************************
.
Completion time: 2012-06-11 09:44:49 - machine was rebooted
ComboFix-quarantined-files.txt 2012-06-11 08:44
.
Pre-Run: 648,826,433,536 bytes free
Post-Run: 648,523,841,536 bytes free
.
- - End Of File - - AFE726527AF8E2D50195EBED39B857FD
While I have a look at your CF log, let’s see if there are any remnants of the two undesiables. :)

Please download SystemLook from one of the links below and save it to your Desktop.

Download Mirror #1
Download Mirror #2
  • double-click SystemLook.exe to run it.
  • copy the content of the following codebox into the main textfield - please make sure you include the colon, (:), at the beginning.:

    :filefind
    *Yontoo*
    *Coupon Printer*
    
    :folderfind
    *Yontoo*
    *Coupon Printer*
    
    :Regfind
    *Yontoo*
    *Coupon Printer*

  • click the Look button to start the scan.
  • when finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

Satchfan
Ok, here is the SystemLook log for the coupon and yontoo. In my control panel list of programs yontoo shows up as Yontoo 1.10.0.2, if that is in any way relevant! SystemLook 30.07.11 by jpshortstuff Log created at 10:54 on 11/06/2012 by James Administrator - Elevation successful WARNING: SystemLook running under WOW64. Use SystemLook_x64 for accurate results. ========== filefind ========== Searching for "*Yontoo*" C:\_OTL\MovedFiles\06102012_235500\C_Program Files (x86)\Yontoo\YontooIEClient.dll –a—- 792864 bytes [14:34 18/04/2012] [00:40 27/03/2012] 6016D8B234681299012D09D161F52574 Searching for "*Coupon Printer*" C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Coupons\Uninstall Coupon Printer for Windows.lnk –a—- 2083 bytes [15:35 17/02/2012] [15:35 17/02/2012] 69E51CB9DE033FE1ADF8FEF7FE3E3766 C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Coupons\Uninstall Coupon Printer for Windows.lnk –a—- 2083 bytes [15:35 17/02/2012] [15:35 17/02/2012] 69E51CB9DE033FE1ADF8FEF7FE3E3766 ========== folderfind ========== Searching for "*Yontoo*" C:\Program Files (x86)\Yontoo d—— [14:34 18/04/2012] C:\_OTL\MovedFiles\06102012_235500\C_Program Files (x86)\Yontoo d—— [22:55 10/06/2012] Searching for "*Coupon Printer*" No folders found. ========== Regfind ========== Searching for "*Yontoo*" No data found. Searching for "*Coupon Printer*" No data found. -= EOF =-
Thanks for the SystemLook log.

Open ComboFix

Please do the following:
  • close any open browsers.
  • close/disable all anti virus and anti malware programs so that they do not interfere with the running of ComboFix.
  • open notepad and copy/paste the text in the codebox below into it:
Folder::
C:\Program Files (x86)\Yontoo
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Coupons 
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Coupons

Registry::
[-HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{58124A0B-DC32-4180-9BFFE0E21AE34026}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{977AE9CC-AF83-45E8-9E03-E2798216E2D5}"=-
[-HKEY_CLASSES_ROOT\clsid\{977ae9cc-af83-45e8-9e03-e2798216e2d5}]

Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe

[external image: Posted Image]

Referring to the picture above, drag CFScript into ComboFix.exe

When finished, it produces a log at C:\ComboFix.txt. Post the contents of Combofix.txt in your next reply.

=============================================

Run Malwarebytes’ Anti-Malware

I noticed that you had MBAM on your system: if you no longer have it, you can download it from here:
  • start Malwarebytes-Anti-Malware and update it, (“Update” tab}
  • once it is updated, click on “Scanner” tab, select Perform quick scan, then click Scan.
  • when the scan is complete, click OK, then Show Results to view the results.
  • be sure that everything is checked, and click Remove Selected.
  • when removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • the log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • copy and paste the contents of that report in your next reply and exit MBAM.
NOTE: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

Logs to include with the next post:

ComboFix.txt
Mbam.txt


Can you tell me if there are any oustanding problems.

Satchfan
Ok, bit of a problem with the first part of this last step. I ran ComboFix and it seemed to be doing everything properly but then went to a blue screen and it seemed to be hung, displaying 'Attempting to create a new system restore point'. I left it for about 2 hours but it didnt progress so I quit off it. Consequently there is no log file. I looked in the Qoobox folder and see no new log in there either. I tried to run it again, thinking it would do a normal scan to produce a log but it did the same thing. Not sure why, would it have to be reinstalled to get a new log? Anyway, I continued to do the Mbam scan and that happily came back with no malware detected and here is the log: Malwarebytes Anti-Malware 1.61.0.1400 www.malwarebytes.org Database version: v2012.06.11.04 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 James :: JAMES-PC [administrator] 11/06/2012 14:07:54 mbam-log-2012-06-11 (14-07-54).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 206656 Time elapsed: 2 minute(s), 17 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI