This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

vGrabber

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

So I unfortunately installed vGbrabber on my computer. I wasn't paying attention and clicked a download link on an ad instead of the link for the actual file I wanted.

Tried removing the program with Perfect Uninstaller, this did not work, still shows up on my browser.

OTL logfile created on: 7/21/2012 1:23:14 PM - Run 1
OTL by OldTimer - Version 3.2.54.0 Folder = C:\Users\Nick\Downloads
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

7.93 Gb Total Physical Memory | 5.97 Gb Available Physical Memory | 75.27% Memory free
15.87 Gb Paging File | 13.67 Gb Available in Paging File | 86.14% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 451.66 Gb Total Space | 325.67 Gb Free Space | 72.11% Space Free | Partition Type: NTFS
Drive D: | 465.76 Gb Total Space | 36.43 Gb Free Space | 7.82% Space Free | Partition Type: NTFS

Computer Name: NICK-PC | User Name: Nick | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Nick\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_265.exe (Adobe Systems, Inc.)
PRC - C:\Users\Nick\AppData\Local\Audiogalaxy\Audiogalaxy.exe (AG Entertainment Inc)
PRC - C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe (Research In Motion Limited)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files (x86)\Seagate\Seagate Dashboard\MemeoDashboard.exe (Memeo)
PRC - C:\Program Files (x86)\Seagate\Seagate Dashboard\SeagateDashboardService.exe (Memeo)
PRC - C:\Program Files (x86)\Seagate\Seagate Dashboard\HipServAgent\HipServAgent.exe (Axentra Corporation)
PRC - C:\Windows\PLFSetI.exe ()
PRC - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
PRC - C:\Program Files (x86)\Acer Arcade Deluxe\Arcade Movie\ArcadeMovieService.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe (NewTech Infosystems, Inc.)
PRC - C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe (NewTech Infosystems, Inc.)
PRC - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
PRC - C:\Program Files (x86)\Launch Manager\dsiwmis.exe (Dritek System Inc.)
PRC - C:\Program Files (x86)\Launch Manager\LMworker.exe (Dritek System Inc.)
PRC - C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe (Egis Technology Inc.)
PRC - C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Acer Group)
PRC - C:\Program Files (x86)\Acer\Registration\GREGsvc.exe (Acer Incorporated)
PRC - C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe (Egis Technology Inc.)
PRC - C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe (Egis Technology Inc.)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)


========== Modules (No Company Name) ==========

MOD - C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ()
MOD - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_265.dll ()
MOD - C:\Users\Nick\AppData\Local\Audiogalaxy\tag.dll ()
MOD - C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\Memeo.Dashboard.SeagateSharePlusPlugin.dll ()
MOD - C:\Program Files (x86)\Seagate\Seagate Dashboard\Memeo.Progress.dll ()
MOD - C:\Program Files (x86)\Seagate\Seagate Dashboard\HipServAgent\libxml2.dll ()
MOD - C:\Program Files (x86)\Seagate\Seagate Dashboard\HipServAgent\libupnp.dll ()
MOD - C:\Users\Nick\AppData\Local\Audiogalaxy\avcodec-52.dll ()
MOD - C:\Users\Nick\AppData\Local\Audiogalaxy\avformat-52.dll ()
MOD - C:\Users\Nick\AppData\Local\Audiogalaxy\avutil-50.dll ()
MOD - C:\Users\Nick\AppData\Local\Audiogalaxy\sqlite3.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\2552d50492d66f19cfc3bf526df9d515\IAStorUtil.ni.dll ()
MOD - C:\Windows\PLFSetI.exe ()
MOD - C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\sqlite3.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\3871fc2b96345aa6f3be81d9e3c97160\System.Web.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\4bdeb88758dccd625f4703ed77aaf348\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\e71959f4ec6eb386889050ac139835c7\System.ServiceProcess.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\fedf1ba58dced4f0b3f8c457648ceed9\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\ead6be8b410d56b5576b10e56af2c180\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Accessibility\003d2d74243cab7e412d36416bbf0a3d\Accessibility.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\c2f9dd7db911053edcaaadf5fefc500a\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\5dd9f783008543df3e642ff1e99de4e8\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\4b1350e31ff09cc583b34854816d8036\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\5ba3bf5367fc012300c6566f20cb7f54\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\8c1770d45c63cf5c462eeb945ef9aa5d\mscorlib.ni.dll ()
MOD - C:\Users\Nick\AppData\Local\Audiogalaxy\zlib1.dll ()
MOD - C:\Program Files (x86)\Launch Manager\CdDirIo.dll ()
MOD - C:\Program Files (x86)\Epson Software\Event Manager\Assistants\Scan Assistant\ScanEngine.dll ()
MOD - C:\Program Files (x86)\Epson Software\Event Manager\Assistants\Scan Assistant\Satwain.dll ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV:64bit: - (ePowerSvc) – C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe (Acer Incorporated)
SRV:64bit: - (Updater Service) – C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Acer Group)
SRV:64bit: - (TurboBoost) – C:\Program Files\Intel\TurboBoost\TurboBoost.exe (Intel® Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (MozillaMaintenance) – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (FLEXnet Licensing Service) – C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (SeagateDashboardService) – C:\Program Files (x86)\Seagate\Seagate Dashboard\SeagateDashboardService.exe (Memeo)
SRV - (GamesAppService) – C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe (WildTangent, Inc.)
SRV - (NTI IScheduleSvc) – C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe (NewTech Infosystems, Inc.)
SRV - (IAStorDataMgrSvc) Intel® – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
SRV - (DsiWMIService) – C:\Program Files (x86)\Launch Manager\dsiwmis.exe (Dritek System Inc.)
SRV - (MWLService) – C:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.exe (Egis Technology Inc.)
SRV - (GREGService) – C:\Program Files (x86)\Acer\Registration\GREGsvc.exe (Acer Incorporated)
SRV - (UNS) Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (PinnacleUpdateSvc) – C:\Program Files (x86)\KALiNKOsoft\Pinnacle Game Profiler\pinnacle_updater.exe (KALiNKOsoft)


========== Driver Services (SafeList) ==========

DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (AtiHDAudioService) – C:\Windows\SysNative\drivers\AtihdW76.sys (Advanced Micro Devices)
DRV:64bit: - (dg_ssudbus) SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.) – C:\Windows\SysNative\drivers\ssudbus.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV:64bit: - (aswSnx) – C:\Windows\SysNative\drivers\aswSnx.sys (AVAST Software)
DRV:64bit: - (aswSP) – C:\Windows\SysNative\drivers\aswSP.sys (AVAST Software)
DRV:64bit: - (aswTdi) – C:\Windows\SysNative\drivers\aswTdi.sys (AVAST Software)
DRV:64bit: - (aswRdr) – C:\Windows\SysNative\drivers\aswRdr.sys (AVAST Software)
DRV:64bit: - (aswMonFlt) – C:\Windows\SysNative\drivers\aswMonFlt.sys (AVAST Software)
DRV:64bit: - (aswFsBlk) – C:\Windows\SysNative\drivers\aswFsBlk.sys (AVAST Software)
DRV:64bit: - (RimUsb) – C:\Windows\SysNative\drivers\RimUsb_AMD64.sys (Research In Motion Limited)
DRV:64bit: - (RimVSerPort) – C:\Windows\SysNative\drivers\RimSerial_AMD64.sys (Research in Motion Ltd)
DRV:64bit: - (cpuz135) – C:\Windows\SysNative\drivers\cpuz135_x64.sys (CPUID)
DRV:64bit: - (sptd) – C:\Windows\SysNative\drivers\sptd.sys ()
DRV:64bit: - (AtiHdmiService) – C:\Windows\SysNative\drivers\AtiHdmi.sys (ATI Technologies, Inc.)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (BCM43XX) – C:\Windows\SysNative\drivers\BCMWL664.SYS (Broadcom Corporation)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (L1C) – C:\Windows\SysNative\drivers\L1C62x64.sys (Atheros Communications, Inc.)
DRV:64bit: - (archlp) – C:\Windows\SysNative\drivers\ArcHlp.sys ()
DRV:64bit: - (TurboB) – C:\Windows\SysNative\drivers\TurboB.sys ()
DRV:64bit: - (HECIx64) Intel® – C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (NETw5s64) Intel® – C:\Windows\SysNative\drivers\NETw5s64.sys (Intel Corporation)
DRV:64bit: - (xusb21) – C:\Windows\SysNative\drivers\xusb21.sys (Microsoft Corporation)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (ROOTMODEM) – C:\Windows\SysNative\drivers\rootmdm.sys (Microsoft Corporation)
DRV:64bit: - (usb_rndisx) – C:\Windows\SysNative\drivers\usb8023x.sys (Microsoft Corporation)
DRV:64bit: - (xnacc) – C:\Windows\SysNative\drivers\xnacc.sys (Microsoft Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (mwlPSDVDisk) – C:\Windows\SysNative\drivers\mwlPSDVDisk.sys (Egis Technology Inc.)
DRV:64bit: - (mwlPSDFilter) – C:\Windows\SysNative\drivers\mwlPSDFilter.sys (Egis Technology Inc.)
DRV:64bit: - (mwlPSDNServ) – C:\Windows\SysNative\drivers\mwlPSDNserv.sys (Egis Technology Inc.)
DRV:64bit: - (AmUStor) – C:\Windows\SysNative\drivers\AmUStor.sys (Alcor Micro, Corp.)
DRV:64bit: - (VClone) – C:\Windows\SysNative\drivers\VClone.sys (Elaborate Bytes AG)
DRV:64bit: - (dc3d) MS Hardware Device Detection Driver (USB) – C:\Windows\SysNative\drivers\dc3d.sys (Microsoft Corporation)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (Point64) – C:\Windows\SysNative\drivers\point64k.sys (Microsoft Corporation)
DRV:64bit: - (NuidFltr) – C:\Windows\SysNative\drivers\nuidfltr.sys (Microsoft Corporation)
DRV:64bit: - (NTIDrvr) – C:\Windows\SysNative\drivers\NTIDrvr.sys (NewTech Infosystems, Inc.)
DRV:64bit: - (UBHelper) – C:\Windows\SysNative\drivers\UBHelper.sys (NewTech Infosystems Corporation)
DRV:64bit: - (ElbyCDIO) – C:\Windows\SysNative\drivers\ElbyCDIO.sys (Elaborate Bytes AG)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&a;…33z175t5611l293
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&a;…33z175t5611l293
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&a;…33z175t5611l293
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&a;…33z175t5611l293
IE - HKLM\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.)
IE - HKLM\..\SearchScopes,DefaultScope = {67A2568C-7A0A-4EED-AECC-B5405DE63B64}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=ie7&…amp;rlz=1I7ACAW
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&a;…33z175t5611l293
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT3131886
IE - HKCU\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {f9bbf004-6e40-4019-8214-c43a37e1d058} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {67A2568C-7A0A-4EED-AECC-B5405DE63B64}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=ie7&…AW_enCA397CA397
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKCU\..\SearchScopes\{9955E86A-BFBC-4FD8-A4F2-36AF0566592C}: "URL" = http://websearch.ask.com/redirect?client=i…B69F0F3BA9&
IE - HKCU\..\SearchScopes\{E0DFF6C1-817E-4780-BFC1-3ACD1C62970E}: "URL" = http://search.yahoo.com/search?fr=chr-gree…p={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..CT3131886.browser.search.defaultthis.engineName: true
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=386496&ilc=12"
FF - prefs.js..browser.search.selectedEngine: "Vgrabber1 Customized Web Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://search.conduit.com/?ctid=CT3131886&SearchSource=13"
FF - prefs.js..extensions.enabledItems: {ba14329e-9550-4989-b3f2-9732e92d17cc}:2.7.2.0
FF - prefs.js..keyword.URL: "http://search.conduit.com/ResultsExt.aspx?ctid=CT3131886&SearchSource=2&q="
FF - prefs.js..network.proxy.http: "207.62.217.252"
FF - prefs.js..network.proxy.http_port: 3128
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_3_300_265.dll File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_265.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.50917.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@RIM.com/WebSLLauncher,version=1.0: C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ()
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll ()

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/07/19 21:26:36 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/06/05 18:00:25 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/07/19 21:26:36 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/06/05 18:00:25 | 000,000,000 | —D | M]

[2010/09/18 11:59:06 | 000,000,000 | —D | M] (No name found) – C:\Users\Nick\AppData\Roaming\Mozilla\Extensions
[2012/07/21 12:17:42 | 000,000,000 | —D | M] (No name found) – C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions
[2012/07/15 11:39:16 | 000,000,000 | —D | M] (Vuze Remote Community Toolbar) – C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}
[2012/05/21 10:16:39 | 000,000,000 | —D | M] (Greasemonkey) – C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2012/07/21 12:17:45 | 000,000,000 | —D | M] (Vgrabber1) – C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}
[2011/10/06 20:43:06 | 000,002,400 | —- | M] () – C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\searchplugins\askcom.xml
[2012/07/21 12:17:57 | 000,000,911 | —- | M] () – C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\searchplugins\conduit.xml
[2012/02/12 22:33:14 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/07/19 21:26:35 | 000,136,672 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011/04/14 05:08:00 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2012/03/20 20:49:10 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/03/20 20:49:10 | 000,002,040 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2009/06/10 15:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7227.1100\swg64.dll (Google Inc.)
O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Mighty Magoo Text) - {97E74A14-E5F1-40cc-9B0F-0D11946E5469} - C:\Program Files (x86)\Mighty Magoo\mmagootl.dll ()
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll (Google Inc.)
O2 - BHO: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Vuze Remote Toolbar) - {BA14329E-9550-4989-B3F2-9732E92D17CC} - C:\Program Files (x86)\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.)
O4:64bit: - HKLM..\Run: [Acer ePower Management] C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe (Acer Incorporated)
O4:64bit: - HKLM..\Run: [AmIcoSinglun64] C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe (Alcor Micro Corp.)
O4:64bit: - HKLM..\Run: [IntelliPoint] C:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [itype] C:\Program Files\Microsoft IntelliType Pro\itype.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [mwlDaemon] C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe (Egis Technology Inc.)
O4:64bit: - HKLM..\Run: [PLFSetI] C:\Windows\PLFSetI.exe ()
O4:64bit: - HKLM..\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [XboxStat] C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe (Microsoft Corporation)
O4 - HKLM..\Run: [AMD AVT] C:\Windows\SysWow64\cmd.exe (Microsoft Corporation)
O4 - HKLM..\Run: [ArcadeMovieService] C:\Program Files (x86)\Acer Arcade Deluxe\Arcade Movie\ArcadeMovieService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [BackupManagerTray] C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe (NewTech Infosystems, Inc.)
O4 - HKLM..\Run: [EEventManager] C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [EgisTecPMMUpdate] C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [EgisUpdate] C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [MDS_Menu] C:\Program Files (x86)\Acer Arcade Deluxe\MediaShow Espresso\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [NortonOnlineBackupReminder] C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe (Symantec Corporation)
O4 - HKLM..\Run: [RIMBBLaunchAgent.exe] C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe (Research In Motion Limited)
O4 - HKLM..\Run: [Seagate Dashboard] C:\Program Files (x86)\Seagate\Seagate Dashboard\MemeoLauncher.exe ()
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SuiteTray] C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe (Egis Technology Inc.)
O4 - HKCU..\Run: [Audiogalaxy] C:\Users\Nick\AppData\Local\Audiogalaxy\Audiogalaxy.exe (AG Entertainment Inc)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKCU..\Run: [EPSON NX110 Series] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIFBA.EXE /FU "C:\Windows\TEMP\E_S2F8E.tmp" /EF "HKCU" File not found
O4 - HKCU..\Run: [EPSON NX110 Series (Copy 1)] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIFBA.EXE /FU "C:\Windows\TEMP\E_SC995.tmp" /EF "HKCU" File not found
O4 - HKCU..\Run: [Steam] C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Google Sidewiki… - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html File not found
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html File not found
O9 - Extra Button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files (x86)\PokerStars.NET\PokerStarsUpdate.exe (PokerStars)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx (CRLDownloadWrapper Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A60E18E8-E700-4ECD-9E59-2528F1E2D72E}: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)


Drivers32:64bit: msacm.ac3filter - ac3filter64.acm ()
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.ac3filter - C:\Windows\SysWow64\ac3filter.acm ()
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - C:\Program Files (x86)\Combined Community Codec Pack\Filters\FFDShow\ff_vfw.dll ()

CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========

[2012/07/21 12:24:43 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Perfect Uninstaller
[2012/07/21 12:24:42 | 000,000,000 | —D | C] – C:\Program Files\Perfect Uninstaller
[2012/07/21 12:13:55 | 000,000,000 | —D | C] – C:\ProgramData\MediaMonkey
[2012/07/21 12:13:48 | 000,000,000 | —D | C] – C:\Users\Nick\AppData\Roaming\MediaMonkey
[2012/07/12 00:03:19 | 009,822,920 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerInstaller.exe
[2012/06/22 19:56:06 | 000,000,000 | —D | C] – C:\Users\Nick\AppData\Local\Macromedia

========== Files - Modified Within 30 Days ==========

[2012/07/21 13:21:48 | 000,009,696 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/07/21 13:21:48 | 000,009,696 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/07/21 13:21:08 | 000,713,888 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/07/21 13:21:08 | 000,619,642 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/07/21 13:21:08 | 000,107,792 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/07/21 13:14:50 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/07/21 13:14:22 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/07/21 13:14:17 | 2094,395,391 | -HS- | M] () – C:\hiberfil.sys
[2012/07/21 13:02:00 | 000,000,898 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/07/21 12:58:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/07/21 12:30:29 | 000,000,009 | —- | M] () – C:\END
[2012/07/21 12:24:46 | 000,000,042 | —- | M] () – C:\Windows\SysWow64\AK083E209605E394C.lie
[2012/07/21 12:14:06 | 000,001,007 | —- | M] () – C:\Users\Public\Desktop\MediaMonkey.lnk
[2012/07/19 21:26:38 | 000,002,048 | —- | M] () – C:\Users\Nick\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/07/12 19:00:36 | 000,426,184 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2012/07/12 19:00:35 | 000,070,344 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/07/12 00:03:19 | 009,822,920 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerInstaller.exe

========== Files Created - No Company Name ==========

[2012/07/21 12:24:46 | 000,000,042 | —- | C] () – C:\Windows\SysWow64\AK083E209605E394C.lie
[2012/07/21 12:17:47 | 000,000,009 | —- | C] () – C:\END
[2012/07/21 12:14:06 | 000,001,007 | —- | C] () – C:\Users\Public\Desktop\MediaMonkey.lnk
[2012/04/05 19:29:34 | 000,204,952 | —- | C] () – C:\Windows\SysWow64\ativvsvl.dat
[2012/04/05 19:29:34 | 000,157,144 | —- | C] () – C:\Windows\SysWow64\ativvsva.dat
[2012/03/09 14:06:14 | 000,024,576 | —- | C] () – C:\Windows\SysWow64\kdbsdk32.dll
[2012/01/25 20:12:33 | 000,001,534 | —- | C] () – C:\ProgramData\ss.ini
[2011/12/12 21:02:37 | 000,000,533 | —- | C] () – C:\Windows\eReg.dat
[2011/09/12 16:06:16 | 000,003,917 | —- | C] () – C:\Windows\SysWow64\atipblag.dat
[2011/05/21 16:09:39 | 000,010,752 | —- | C] () – C:\Users\Nick\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/03/18 23:40:01 | 000,001,904 | —- | C] () – C:\Windows\CDPlayer.ini
[2011/03/08 19:54:03 | 000,039,270 | —- | C] () – C:\Windows\DIIUnin.dat
[2011/03/03 22:04:20 | 000,000,117 | —- | C] () – C:\Users\Nick\jagex_runescape_preferences2.dat
[2011/03/03 22:02:59 | 000,000,034 | —- | C] () – C:\Users\Nick\jagex_runescape_preferences.dat
[2011/02/16 18:37:10 | 000,102,248 | —- | C] () – C:\Users\Nick\GoToAssistDownloadHelper.exe
[2010/11/04 22:48:43 | 000,000,000 | —- | C] () – C:\Windows\EEventManager.INI
[2010/10/25 22:41:29 | 000,073,220 | —- | C] () – C:\Windows\SysWow64\EPPICPrinterDB.dat
[2010/10/25 22:41:29 | 000,031,053 | —- | C] () – C:\Windows\SysWow64\EPPICPattern131.dat
[2010/10/25 22:41:29 | 000,029,114 | —- | C] () – C:\Windows\SysWow64\EPPICPattern1.dat
[2010/10/25 22:41:29 | 000,027,417 | —- | C] () – C:\Windows\SysWow64\EPPICPattern121.dat
[2010/10/25 22:41:29 | 000,021,021 | —- | C] () – C:\Windows\SysWow64\EPPICPattern3.dat
[2010/10/25 22:41:29 | 000,015,670 | —- | C] () – C:\Windows\SysWow64\EPPICPattern5.dat
[2010/10/25 22:41:29 | 000,013,280 | —- | C] () – C:\Windows\SysWow64\EPPICPattern2.dat
[2010/10/25 22:41:29 | 000,010,673 | —- | C] () – C:\Windows\SysWow64\EPPICPattern4.dat
[2010/10/25 22:41:29 | 000,004,943 | —- | C] () – C:\Windows\SysWow64\EPPICPattern6.dat
[2010/10/25 22:41:29 | 000,001,140 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_PT.dat
[2010/10/25 22:41:29 | 000,001,140 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_BP.dat
[2010/10/25 22:41:29 | 000,001,137 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_ES.dat
[2010/10/25 22:41:29 | 000,001,130 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_FR.dat
[2010/10/25 22:41:29 | 000,001,130 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_CF.dat
[2010/10/25 22:41:29 | 000,001,104 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_EN.dat
[2010/10/25 22:41:29 | 000,000,097 | —- | C] () – C:\Windows\SysWow64\PICSDK.ini
[2010/10/25 22:40:35 | 000,000,071 | —- | C] () – C:\Windows\EPNX110.ini
[2010/09/27 21:02:11 | 000,003,009 | —- | C] () – C:\Windows\SysWow64\SpoonUninstall-dBpoweramp Ogg Vorbis Codec.dat
[2010/09/27 18:03:35 | 000,057,344 | —- | C] () – C:\Windows\SysWow64\ADsSecurity.dll
[2010/09/27 18:03:35 | 000,053,248 | —- | C] () – C:\Windows\SysWow64\zlib.dll
[2010/09/27 18:03:34 | 000,036,864 | —- | C] () – C:\Windows\SysWow64\dxinputdll.dll
[2010/09/27 13:04:51 | 000,003,297 | —- | C] () – C:\Windows\SysWow64\SpoonUninstall-dBpoweramp m4a Codec.dat
[2010/09/27 12:59:09 | 000,003,627 | —- | C] () – C:\Windows\SysWow64\SpoonUninstall-dBpoweramp m4a Nero AAC Encoder.dat
[2010/09/27 12:56:56 | 000,010,105 | —- | C] () – C:\Windows\SysWow64\SpoonUninstall-dBpoweramp DSP Effects.dat
[2010/09/27 12:56:52 | 000,706,224 | —- | C] () – C:\Windows\SysWow64\SpoonUninstall.exe
[2010/09/27 12:56:52 | 000,014,645 | —- | C] () – C:\Windows\SysWow64\SpoonUninstall-dBpoweramp Music Converter.dat
[2010/09/18 11:58:53 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat

========== LOP Check ==========

[2011/02/20 18:42:50 | 000,000,000 | —D | M] – C:\Users\Nick\AppData\Roaming\.minecraft
[2012/07/19 22:12:40 | 000,000,000 | —D | M] – C:\Users\Nick\AppData\Roaming\Azureus
[2011/11/11 17:59:38 | 000,000,000 | —D | M] – C:\Users\Nick\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010/09/22 18:50:23 | 000,000,000 | —D | M] – C:\Users\Nick\AppData\Roaming\DAEMON Tools Lite
[2010/09/28 20:21:09 | 000,000,000 | —D | M] – C:\Users\Nick\AppData\Roaming\dBpoweramp
[2012/05/20 11:12:32 | 000,000,000 | —D | M] – C:\Users\Nick\AppData\Roaming\DVDFab
[2010/12/27 22:11:20 | 000,000,000 | —D | M] – C:\Users\Nick\AppData\Roaming\Epson
[2010/09/27 18:07:59 | 000,000,000 | —D | M] – C:\Users\Nick\AppData\Roaming\KALiNKOsoft
[2010/10/11 13:07:12 | 000,000,000 | —D | M] – C:\Users\Nick\AppData\Roaming\Leadertech
[2011/07/13 21:06:28 | 000,000,000 | —D | M] – C:\Users\Nick\AppData\Roaming\Ludia
[2012/07/21 12:22:34 | 000,000,000 | —D | M] – C:\Users\Nick\AppData\Roaming\MediaMonkey
[2012/05/18 18:31:08 | 000,000,000 | —D | M] – C:\Users\Nick\AppData\Roaming\mkvtoolnix
[2011/05/21 14:57:27 | 000,000,000 | —D | M] – C:\Users\Nick\AppData\Roaming\Research In Motion
[2010/10/11 13:11:02 | 000,000,000 | —D | M] – C:\Users\Nick\AppData\Roaming\Seagate
[2011/01/06 22:46:45 | 000,000,000 | —D | M] – C:\Users\Nick\AppData\Roaming\SystemRequirementsLab
[2011/09/06 21:58:32 | 000,000,000 | —D | M] – C:\Users\Nick\AppData\Roaming\Systweak
[2012/01/25 21:20:37 | 000,000,000 | —D | M] – C:\Users\Nick\AppData\Roaming\TagScanner
[2009/07/13 23:08:49 | 000,029,118 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.* >
[2010/04/21 20:53:16 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2012/07/21 12:30:29 | 000,000,009 | —- | M] () – C:\END
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 08:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 08:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2007/11/07 08:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2012/07/21 13:14:17 | 2094,395,391 | -HS- | M] () – C:\hiberfil.sys
[2007/11/07 08:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe
[2007/11/07 08:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2007/11/07 08:03:18 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 08:03:18 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 08:03:18 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 08:03:18 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 08:03:18 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 08:03:18 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 08:03:18 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2012/07/21 13:14:19 | 4224,184,319 | -HS- | M] () – C:\pagefile.sys
[2010/07/06 19:32:39 | 000,002,264 | —- | M] () – C:\RHDSetup.log
[2007/11/07 08:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 08:09:22 | 001,442,522 | —- | M] () – C:\VC_RED.cab
[2007/11/07 08:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI
[2010/07/06 19:52:42 | 000,000,190 | —- | M] () – C:\Webcam.log

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2011/09/06 14:45:29 | 000,041,184 | —- | M] (AVAST Software) – C:\Windows\avastSS.scr
[2009/07/10 12:15:46 | 000,306,544 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >
[2010/09/18 11:55:09 | 000,001,622 | -HS- | M] () – C:\Users\Nick\AppData\Roaming\Microsoft\LastFlashConfig.wfc

< %PROGRAMFILES%\*.* >
[2009/07/13 22:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/06/20 23:57:47 | 000,000,308 | -HS- | M] () – C:\Users\Nick\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/02/19 17:27:02 | 000,232,501 | —- | M] () – C:\Users\Nick\Desktop\Minecraft.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< %appdata%\Microsoft\Windows\Start Menu\*.* /s >
[2010/09/18 05:56:52 | 000,000,174 | -HS- | M] () – C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini
[2012/06/20 23:57:47 | 000,000,476 | -HS- | M] () – C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\desktop.ini
[2012/06/20 23:57:46 | 000,001,413 | —- | M] () – C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
[2012/06/20 23:57:47 | 000,001,407 | —- | M] () – C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2009/07/13 22:54:27 | 000,001,280 | —- | M] () – C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Command Prompt.lnk
[2009/07/13 22:54:32 | 000,000,678 | -HS- | M] () – C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Desktop.ini
[2009/07/13 22:54:32 | 000,001,304 | —- | M] () – C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk
[2009/07/13 22:49:38 | 000,000,262 | —- | M] () – C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Run.lnk
[2009/07/13 22:49:38 | 000,001,228 | —- | M] () – C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Explorer.lnk
[2009/07/13 22:54:02 | 000,000,704 | -HS- | M] () – C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Desktop.ini
[2009/07/13 22:54:01 | 000,001,358 | —- | M] () – C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Ease of Access.lnk
[2009/07/13 22:54:00 | 000,001,258 | —- | M] () – C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Magnify.lnk
[2009/07/13 22:54:02 | 000,001,262 | —- | M] () – C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Narrator.lnk
[2009/07/13 22:54:00 | 000,001,250 | —- | M] () – C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\On-Screen Keyboard.lnk
[2009/07/13 22:49:38 | 000,000,262 | —- | M] () – C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\computer.lnk
[2009/07/13 22:49:38 | 000,000,262 | —- | M] () – C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Control Panel.lnk
[2012/06/20 23:57:47 | 000,000,738 | -HS- | M] () – C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Desktop.ini
[2012/06/20 23:57:47 | 000,001,457 | —- | M] () – C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk
[2009/07/13 22:54:59 | 000,001,306 | —- | M] () – C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Private Character Editor.lnk
[2010/09/18 05:56:52 | 000,000,174 | -HS- | M] () – C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools\desktop.ini
[2011/06/25 12:32:36 | 000,002,040 | —- | M] () – C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Audiogalaxy\Audiogalaxy.lnk
[2011/06/25 12:32:36 | 000,002,026 | —- | M] () – C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Audiogalaxy\Uninstall.lnk
[2011/03/08 19:57:50 | 000,014,376 | —- | M] () – C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Diablo II\license.txt
[2011/03/08 19:57:50 | 000,000,099 | —- | M] () – C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Diablo II\Register Diablo II - Lord Of Destruction.url
[2012/05/18 18:27:46 | 000,001,198 | —- | M] () – C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory\FormatFactory.lnk
[2012/05/18 18:27:46 | 000,002,126 | —- | M] () – C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory\Help.lnk
[2012/05/18 18:27:47 | 000,000,972 | —- | M] () – C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory\Uninstall.lnk
[2011/02/26 21:01:24 | 000,000,224 | —- | M] () – C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games\American McGee's Alice™.lnk
[2011/03/08 19:59:37 | 000,000,272 | —- | M] () – C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games\Diablo II Expansion Set Lord of Destruction ™.lnk
[2010/09/19 19:31:20 | 000,000,232 | —- | M] () – C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games\Need for Speed Most Wanted™.lnk
[2009/07/13 22:49:38 | 000,000,318 | -HS- | M] () – C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance\Desktop.ini
[2009/07/13 22:49:38 | 000,000,262 | —- | M] () – C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance\Help.lnk
[2011/04/01 19:11:00 | 000,001,217 | —- | M] () – C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StarCraft II\StarCraft II Public Test.lnk
[2010/09/18 05:56:52 | 000,000,174 | -HS- | M] () – C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
[2011/05/01 17:14:06 | 000,000,219 | —- | M] () – C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam\Portal 2.url
[2010/09/30 20:22:55 | 000,000,220 | —- | M] () – C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam\Sid Meier's Civilization V.url
[2010/09/30 20:22:54 | 000,000,931 | —- | M] () – C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam\Steam.lnk
[2010/09/21 21:02:10 | 000,000,996 | —- | M] () – C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\Console RAR manual.lnk
[2010/09/21 21:02:10 | 000,001,015 | —- | M] () – C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\WinRAR help.lnk
[2010/09/21 21:02:10 | 000,001,015 | —- | M] () – C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\WinRAR.lnk

< %programdata%\Microsoft\Windows\Start Menu\*.* /s >

< End of report >
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 2:17:16 PM, on 21/07/2012
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v9.00 (9.00.8112.16446)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe
C:\Windows\PLFSetI.exe
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
C:\Users\Nick\AppData\Local\Audiogalaxy\Audiogalaxy.exe
C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Launch Manager\LManager.exe
C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe
C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe
C:\Program Files (x86)\Acer Arcade Deluxe\Arcade Movie\ArcadeMovieService.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files (x86)\Seagate\Seagate Dashboard\MemeoDashboard.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe
C:\Program Files (x86)\Seagate\Seagate Dashboard\HipServAgent\HipServAgent.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_265.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_265.exe
C:\Users\Nick\Downloads\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&a…33z175t5611l293
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT3131886
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&a…33z175t5611l293
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&a…33z175t5611l293
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\prxtbVuze.dll
R3 - URLSearchHook: (no name) - {f9bbf004-6e40-4019-8214-c43a37e1d058} - (no file)
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Mighty Magoo Text - {97E74A14-E5F1-40cc-9B0F-0D11946E5469} - C:\Program Files (x86)\Mighty Magoo\mmagootl.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll
O2 - BHO: Vuze Remote - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\prxtbVuze.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\prxtbVuze.dll
O3 - Toolbar: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe
O4 - HKLM\..\Run: [SuiteTray] "C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe"
O4 - HKLM\..\Run: [EgisUpdate] "C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe" -d
O4 - HKLM\..\Run: [EgisTecPMMUpdate] "C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [BackupManagerTray] "C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" -h -k
O4 - HKLM\..\Run: [NortonOnlineBackupReminder] "C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED
O4 - HKLM\..\Run: [MDS_Menu] "C:\Program Files (x86)\Acer Arcade Deluxe\MediaShow Espresso\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Acer Arcade Deluxe\MediaShow Espresso" UpdateWithCreateOnce "Software\CyberLink\MediaShow Espresso\5.6"
O4 - HKLM\..\Run: [ArcadeMovieService] "C:\Program Files (x86)\Acer Arcade Deluxe\Arcade Movie\ArcadeMovieService.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [Seagate Dashboard] C:\Program Files (x86)\Seagate\Seagate Dashboard\MemeoLauncher.exe –silent –no_ui
O4 - HKLM\..\Run: [EEventManager] C:\PROGRA~2\EPSONS~1\EVENTM~1\EEventManager.exe
O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [RIMBBLaunchAgent.exe] C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [AMD AVT] Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe" aml
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [EPSON NX110 Series] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIFBA.EXE /FU "C:\Windows\TEMP\E_S2F8E.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [EPSON NX110 Series (Copy 1)] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIFBA.EXE /FU "C:\Windows\TEMP\E_SC995.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [Audiogalaxy] "C:\Users\Nick\AppData\Local\Audiogalaxy\Audiogalaxy.exe" /startup
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files (x86)\PokerStars.NET\PokerStarsUpdate.exe
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: Dritek WMI Service (DsiWMIService) - Dritek System Inc. - C:\Program Files (x86)\Launch Manager\dsiwmis.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Acer ePower Service (ePowerSvc) - Acer Incorporated - C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
O23 - Service: GREGService - Acer Incorporated - C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel® Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel® Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: MyWinLocker Service (MWLService) - Egis Technology Inc. - C:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NTI IScheduleSvc - NewTech Infosystems, Inc. - C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
O23 - Service: NTI Backup Now 5 Backup Service (NTIBackupSvc) - NewTech InfoSystems, Inc. - C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) - NewTech Infosystems, Inc. - C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
O23 - Service: PinnacleUpdate Service (PinnacleUpdateSvc) - KALiNKOsoft - C:\Program Files (x86)\KALiNKOsoft\Pinnacle Game Profiler\pinnacle_updater.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\Cyberlink\Shared files\RichVideo.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Seagate Dashboard Service (SeagateDashboardService) - Memeo - C:\Program Files (x86)\Seagate\Seagate Dashboard\SeagateDashboardService.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: TurboBoost - Intel® Corporation - C:\Program Files\Intel\TurboBoost\TurboBoost.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel® Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
O23 - Service: Updater Service - Acer Group - C:\Program Files\Acer\Acer Updater\UpdaterService.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 15756 bytes
. DDS (Ver_11-03-05.01) - NTFS_AMD64 Run by [removed] at 14:22:13.58 on 21/07/2012 Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_25 Microsoft Windows 7 Home Premium 6.1.7600.0.1252.2.1033.18.8124.5790 [GMT -6:00] . AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\system32\atiesrxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\atieclxx.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Program Files\Alwil Software\Avast5\AvastSvc.exe C:\Windows\system32\WLANExt.exe C:\Windows\system32\conhost.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files (x86)\Bonjour\mDNSResponder.exe C:\Program Files (x86)\Launch Manager\dsiwmis.exe C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe C:\Program Files (x86)\Acer\Registration\GREGsvc.exe C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe C:\Program Files (x86)\Cyberlink\Shared files\RichVideo.exe C:\Program Files (x86)\Seagate\Seagate Dashboard\SeagateDashboardService.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files\Acer\Acer Updater\UpdaterService.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\taskhost.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Windows\PLFSetI.exe C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe C:\Program Files\Microsoft IntelliType Pro\itype.exe C:\Program Files\Microsoft IntelliPoint\ipoint.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\Microsoft IntelliType Pro\dpupdchk.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\wbem\unsecapp.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\Synaptics\SynTP\SynTPHelper.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe C:\Windows\System32\spool\drivers\x64\3\E_IATIFBA.EXE C:\Windows\System32\spool\drivers\x64\3\E_IATIFBA.EXE C:\Users\Nick\AppData\Local\Audiogalaxy\Audiogalaxy.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe C:\Program Files (x86)\Launch Manager\LManager.exe C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Program Files (x86)\Acer Arcade Deluxe\Arcade Movie\ArcadeMovieService.exe C:\Program Files (x86)\iTunes\iTunesHelper.exe C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe C:\Program Files\Alwil Software\Avast5\AvastUI.exe C:\Program Files (x86)\Seagate\Seagate Dashboard\MemeoDashboard.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe C:\Program Files (x86)\Launch Manager\LMworker.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files (x86)\Seagate\Seagate Dashboard\HipServAgent\HipServAgent.exe C:\Program Files\Intel\TurboBoost\TurboBoost.exe C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe C:\Windows\System32\svchost.exe -k secsvcs C:\Program Files (x86)\Mozilla Firefox\firefox.exe C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_265.exe C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_265.exe C:\Windows\SysWOW64\NOTEPAD.EXE C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Users\Nick\Downloads\dds.scr C:\Windows\system32\conhost.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT3131886 uDefault_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=1009&m=aspire_7745g&r=27360910s806l0433z175t5611l293 mDefault_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=1009&m=aspire_7745g&r=27360910s806l0433z175t5611l293 mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=1009&m=aspire_7745g&r=27360910s806l0433z175t5611l293 uInternet Settings,ProxyOverride = *.local uURLSearchHooks: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\prxtbVuze.dll uURLSearchHooks: H - No File mURLSearchHooks: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\prxtbVuze.dll mWinlogon: Userinit=userinit.exe BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO: Mighty Magoo Text: {97e74a14-e5f1-40cc-9b0f-0d11946e5469} - C:\Program Files (x86)\Mighty Magoo\mmagootl.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll BHO: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\prxtbVuze.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll TB: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\prxtbVuze.dll TB: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun uRun: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" uRun: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun uRun: [Steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent uRun: [EPSON NX110 Series] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIFBA.EXE /FU "C:\Windows\TEMP\E_S2F8E.tmp" /EF "HKCU" uRun: [EPSON NX110 Series (Copy 1)] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIFBA.EXE /FU "C:\Windows\TEMP\E_SC995.tmp" /EF "HKCU" uRun: [Audiogalaxy] "C:\Users\Nick\AppData\Local\Audiogalaxy\Audiogalaxy.exe" /startup mRun: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe mRun: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe mRun: [SuiteTray] "C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe" mRun: [EgisUpdate] "C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe" -d mRun: [EgisTecPMMUpdate] "C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe" mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" mRun: [BackupManagerTray] "C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" -h -k mRun: [NortonOnlineBackupReminder] "C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED mRun: [MDS_Menu] "C:\Program Files (x86)\Acer Arcade Deluxe\MediaShow Espresso\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Acer Arcade Deluxe\MediaShow Espresso" UpdateWithCreateOnce "Software\CyberLink\MediaShow Espresso\5.6" mRun: [ArcadeMovieService] "C:\Program Files (x86)\Acer Arcade Deluxe\Arcade Movie\ArcadeMovieService.exe" mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" mRun: [VirtualCloneDrive] "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s mRun: [Seagate Dashboard] C:\Program Files (x86)\Seagate\Seagate Dashboard\MemeoLauncher.exe –silent –no_ui mRun: [EEventManager] C:\PROGRA~2\EPSONS~1\EVENTM~1\EEventManager.exe mRun: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" mRun: [RIMBBLaunchAgent.exe] C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun mRun: [AMD AVT] Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe" aml mPolicies-explorer: NoActiveDesktop = 1 (0x1) mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1) mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 IE: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html IE: {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files (x86)\PokerStars.NET\PokerStarsUpdate.exe IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab DPF: {D821DC4A-0814-435E-9820-661C543A4679} - hxxp://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx BHO-X64: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll BHO-X64: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7227.1100\swg64.dll TB-X64: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll TB-X64: {BA14329E-9550-4989-B3F2-9732E92D17CC} - No File TB-X64: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File mRun-x64: [AmIcoSinglun64] C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe mRun-x64: [mwlDaemon] C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe mRun-x64: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s mRun-x64: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /FORPCEE3 mRun-x64: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe mRun-x64: [PLFSetI] C:\Windows\PLFSetI.exe mRun-x64: [Acer ePower Management] C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe mRun-x64: [XboxStat] "C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun mRun-x64: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe" mRun-x64: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe" . ================= FIREFOX =================== . FF - ProfilePath - C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\ FF - prefs.js: browser.search.selectedEngine - Vgrabber1 Customized Web Search FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT3131886&SearchSource=13 FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3131886&SearchSource=2&q= FF - prefs.js: network.proxy.http - 207.62.217.252 FF - prefs.js: network.proxy.http_port - 3128 FF - prefs.js: network.proxy.type - 0 FF - component: C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}\components\FFExternalAlert.dll FF - component: C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}\components\RadioWMPCore.dll FF - plugin: C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.0.50917.0\npctrlui.dll FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll FF - plugin: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll FF - plugin: C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\plugins\np-mswmp.dll FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_265.dll . ============= SERVICES / DRIVERS =============== . R1 archlp;archlp;C:\Windows\System32\drivers\ArcHlp.sys [2010-9-22 142848] R1 aswSnx;aswSnx;C:\Windows\System32\drivers\aswSnx.sys [2011-9-25 601944] R1 aswSP;aswSP;C:\Windows\System32\drivers\aswSP.sys [2010-10-27 301912] R1 mwlPSDFilter;mwlPSDFilter;C:\Windows\System32\drivers\mwlPSDFilter.sys [2009-6-2 22576] R1 mwlPSDNServ;mwlPSDNServ;C:\Windows\System32\drivers\mwlPSDNserv.sys [2009-6-2 20016] R1 mwlPSDVDisk;mwlPSDVDisk;C:\Windows\System32\drivers\mwlPSDVDisk.sys [2009-6-2 60464] R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\System32\drivers\vwififlt.sys [2009-7-13 59904] R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2012-4-5 236544] R2 aswFsBlk;aswFsBlk;C:\Windows\System32\drivers\aswFsBlk.sys [2010-10-27 24408] R2 aswMonFlt;aswMonFlt;C:\Windows\System32\drivers\aswMonFlt.sys [2010-10-27 65368] R2 avast! Antivirus;avast! Antivirus;C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2011-9-25 44768] R2 cpuz135;cpuz135;C:\Windows\System32\drivers\cpuz135_x64.sys [2011-9-6 21992] R2 DsiWMIService;Dritek WMI Service;C:\Program Files (x86)\Launch Manager\dsiwmis.exe [2010-4-21 325200] R2 ePowerSvc;Acer ePower Service;C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe [2010-7-6 866336] R2 GREGService;GREGService;C:\Program Files (x86)\Acer\Registration\GREGsvc.exe [2010-1-8 23584] R2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-4-21 13336] R2 NTI IScheduleSvc;NTI IScheduleSvc;C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2010-3-8 250368] R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2009-11-5 144640] R2 SeagateDashboardService;Seagate Dashboard Service;C:\Program Files (x86)\Seagate\Seagate Dashboard\SeagateDashboardService.exe [2011-6-1 14088] R2 TurboB;Turbo Boost UI Monitor driver;C:\Windows\System32\drivers\TurboB.sys [2009-11-2 13784] R2 UNS;Intel® Management & Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2010-7-6 2314240] R2 Updater Service;Updater Service;C:\Program Files\Acer\Acer Updater\UpdaterService.exe [2010-4-21 243232] R3 amdkmdag;amdkmdag;C:\Windows\System32\drivers\atikmdag.sys [2012-4-5 11174400] R3 amdkmdap;amdkmdap;C:\Windows\System32\drivers\atikmpag.sys [2012-4-5 343040] R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\System32\drivers\AtihdW76.sys [2012-2-23 95760] R3 HECIx64;Intel® Management Engine Interface;C:\Windows\System32\drivers\HECIx64.sys [2010-7-6 56344] R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;C:\Windows\System32\drivers\L1C62x64.sys [2010-4-21 75304] R3 TurboBoost;TurboBoost;C:\Program Files\Intel\TurboBoost\TurboBoost.exe [2009-11-2 126352] R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\System32\drivers\vwifimp.sys [2009-7-13 17920] S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-9-18 135664] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-6-20 250056] S3 AmUStor;AM USB Stroage Driver;C:\Windows\System32\drivers\AmUStor.sys [2009-5-26 40448] S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);C:\Windows\System32\drivers\ssudbus.sys [2012-6-10 95544] S3 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072] S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-9-18 135664] S3 MozillaMaintenance;Mozilla Maintenance Service;C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-5-8 113120] S3 MWLService;MyWinLocker Service;C:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.exe [2010-2-1 305520] S3 NETw5s64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;C:\Windows\System32\drivers\NETw5s64.sys [2010-4-21 6952960] S3 NTIBackupSvc;NTI Backup Now 5 Backup Service;C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2009-11-5 50432] S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2010-4-19 50688] . =============== Created Last 30 ================ . 2012-07-21 18:24:42 ——– d—–w- C:\Program Files\Perfect Uninstaller 2012-07-21 18:13:55 ——– d—–w- C:\PROGRA~3\MediaMonkey 2012-07-21 18:13:48 ——– d—–w- C:\Users\Nick\AppData\Roaming\MediaMonkey 2012-07-12 06:03:19 9822920 —-a-w- C:\Windows\SysWow64\FlashPlayerInstaller.exe 2012-06-23 01:56:06 ——– d—–w- C:\Users\Nick\AppData\Local\Macromedia . ==================== Find3M ==================== . 2012-07-13 01:00:36 426184 —-a-w- C:\Windows\SysWow64\FlashPlayerApp.exe 2012-07-13 01:00:35 70344 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2012-06-21 05:51:54 982912 —-a-w- C:\Windows\System32\drivers\dxgkrnl.sys . ============= FINISH: 14:22:47.20 ===============
Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 3 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

•Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
•If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
•Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
•Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post



Did you set this proxy.

FF - prefs.js..network.proxy.http: "207.62.217.252"







Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :Otl
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT3131886
    FF - prefs.js..browser.search.selectedEngine: "Vgrabber1 Customized Web Search"
    FF - prefs.js..browser.startup.homepage: "http://search.conduit.com/?ctid=CT3131886&SearchSource=13"
    FF - prefs.js..keyword.URL: "http://search.conduit.com/ResultsExt.aspx?ctid=CT3131886&SearchSource=2&q="
    [2012/07/21 12:17:45 | 000,000,000 | —D | M] (Vgrabber1) – C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}
    O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
    O2 - BHO: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.)
    O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
    O3 - HKLM\..\Toolbar: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.)
    O2 - BHO: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.)
    
    :Commands
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
All processes killed ========== SERVICES/DRIVERS ========== ========== OTL ========== HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully! Prefs.js: "Vgrabber1 Customized Web Search" removed from browser.search.selectedEngine Prefs.js: "http://search.conduit.com/?ctid=CT3131886&SearchSource=13" removed from browser.startup.homepage Prefs.js: "http://search.conduit.com/ResultsExt.aspx?ctid=CT3131886&SearchSource=2&q=" removed from keyword.URL C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\Plugins folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\modules folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\META-INF folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\lib folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\defaults\preferences folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\defaults folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\skin folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\sl folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\lib folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\core folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\wa\WEATHER\js folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\wa\WEATHER\css folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\wa\WEATHER folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\wa\TWITTER\resources folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\wa\TWITTER\js folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\wa\TWITTER\img folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\wa\TWITTER folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\wa\TESTER_POPUP\js folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\wa\TESTER_POPUP folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\wa\TESTER_EMBEDDED\js folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\wa\TESTER_EMBEDDED folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\wa\TESTER_BCAPI\js folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\wa\TESTER_BCAPI\autoTest\spec folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\wa\TESTER_BCAPI\autoTest\lib\jasmine-1.1.0 folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\wa\TESTER_BCAPI\autoTest\lib folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\wa\TESTER_BCAPI\autoTest folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\wa\TESTER_BCAPI folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\wa\SEARCH_IN_NEW_TAB folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\wa\SEARCH\view\style\rsx folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\wa\SEARCH\view\style folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\wa\SEARCH\view\script folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\wa\SEARCH\view folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\wa\SEARCH\resources folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\wa\SEARCH\js folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\wa\SEARCH\Css folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\wa\SEARCH\buildSettings folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\wa\SEARCH folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\wa\RADIO_PLAYER\js\resources folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\wa\RADIO_PLAYER\js folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\wa\RADIO_PLAYER\css\custom-theme folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\wa\RADIO_PLAYER\css folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\wa\RADIO_PLAYER folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\wa\PRICE_GONG\menu_dlg folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\wa\PRICE_GONG\images folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\wa\PRICE_GONG\css\custom-theme folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\wa\PRICE_GONG\css folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\wa\PRICE_GONG\agreement folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\wa\PRICE_GONG folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\wa\Optimizer\js folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\wa\Optimizer folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\wa\NOTIFICATION\js folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\wa\NOTIFICATION\images\light folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\wa\NOTIFICATION\images\dark folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\wa\NOTIFICATION\images folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\wa\NOTIFICATION\css folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\wa\NOTIFICATION folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\wa\MULTI_RSS\js\resources folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\wa\MULTI_RSS\js folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\wa\MULTI_RSS\img folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\wa\MULTI_RSS\css folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\wa\MULTI_RSS folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\wa\HIGHLIGHTER\js folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\wa\HIGHLIGHTER\css folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\wa\HIGHLIGHTER folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\wa\EMAIL_NOTIFIER\js\plugins folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\wa\EMAIL_NOTIFIER\js folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\wa\EMAIL_NOTIFIER\css folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\wa\EMAIL_NOTIFIER folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\wa\APPLICATION_BUTTON\resources folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\wa\APPLICATION_BUTTON\Js folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\wa\APPLICATION_BUTTON folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\wa\404 folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\wa folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\ui\menu\js folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\ui\menu\img folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\ui\menu\css folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\ui\menu folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\ui\gf\img folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\ui\gf\css folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\ui\gf folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\ui\gadgetFrame folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\ui\dlg\ftd\images folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\ui\dlg\ftd folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\ui\dlg folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\ui folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\searchProtector\searchProtectorSettingsDialog\images folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\searchProtector\searchProtectorSettingsDialog folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\searchProtector\SearchProtectorBubbleDialog\images folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\searchProtector\SearchProtectorBubbleDialog folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\searchProtector\js folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\searchProtector folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\options\js\resources folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\options\js folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\options\images folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\options\css folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\options folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\myStuffDialogs folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\features\js\resources folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\features\js folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\features folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\api folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\ac\res folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\ac\img folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\ac\css folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\ac folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\aboutBox\js folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\aboutBox\images folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al\aboutBox folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb\al folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content\tb folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886\content folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome\CT3131886 folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058}\chrome folder moved successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\extensions\{f9bbf004-6e40-4019-8214-c43a37e1d058} folder moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{30F9B915-B755-4826-820B-08FBA6BD249D}\ deleted successfully. C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ba14329e-9550-4989-b3f2-9732e92d17cc}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ba14329e-9550-4989-b3f2-9732e92d17cc}\ deleted successfully. C:\Program Files (x86)\Vuze_Remote\prxtbVuze.dll moved successfully. 64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{30F9B915-B755-4826-820B-08FBA6BD249D} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{30F9B915-B755-4826-820B-08FBA6BD249D}\ not found. File C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{ba14329e-9550-4989-b3f2-9732e92d17cc} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ba14329e-9550-4989-b3f2-9732e92d17cc}\ not found. File C:\Program Files (x86)\Vuze_Remote\prxtbVuze.dll not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ba14329e-9550-4989-b3f2-9732e92d17cc}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ba14329e-9550-4989-b3f2-9732e92d17cc}\ not found. File C:\Program Files (x86)\Vuze_Remote\prxtbVuze.dll not found. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Guest ->Temp folder emptied: 35874027 bytes ->Temporary Internet Files folder emptied: 68867560 bytes ->Java cache emptied: 7140 bytes ->FireFox cache emptied: 30375657 bytes ->Flash cache emptied: 1858 bytes User: Nick ->Temp folder emptied: 1457790486 bytes ->Temporary Internet Files folder emptied: 157671686 bytes ->Java cache emptied: 1138682 bytes ->FireFox cache emptied: 298489211 bytes ->Flash cache emptied: 267534 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 124689435 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 67758 bytes RecycleBin emptied: 30973358992 bytes Total Files Cleaned = 31,613.00 mb OTL by OldTimer - Version 3.2.54.0 log created on 07232012_211116 Files\Folders moved on Reboot… C:\Users\Nick\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. C:\Users\Nick\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NNJ0CWTE\background-banner-middle-v9[1].jpg moved successfully. C:\Users\Nick\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NNJ0CWTE\background_banner_7_en[1].jpg moved successfully. C:\Users\Nick\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NL8E81GD\button-flex-blue2[1].png moved successfully. C:\Users\Nick\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AENKNMIU\background-banner-right-v9[1].jpg moved successfully. C:\Users\Nick\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AENKNMIU\tick-blue[1].png moved successfully. File move failed. C:\Windows\temp\_avast_\Webshlock.txt scheduled to be moved on reboot. File move failed. C:\Windows\temp\dsiwmis.log scheduled to be moved on reboot. PendingFileRenameOperations files… File C:\Users\Nick\AppData\Local\Temp\FXSAPIDebugLogFile.txt not found! File C:\Users\Nick\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NNJ0CWTE\background-banner-middle-v9[1].jpg not found! File C:\Users\Nick\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NNJ0CWTE\background_banner_7_en[1].jpg not found! File C:\Users\Nick\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NL8E81GD\button-flex-blue2[1].png not found! File C:\Users\Nick\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AENKNMIU\background-banner-right-v9[1].jpg not found! File C:\Users\Nick\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AENKNMIU\tick-blue[1].png not found! [2012/07/23 21:16:41 | 000,000,000 | —- | M] () C:\Windows\temp\_avast_\Webshlock.txt : Unable to obtain MD5 [2012/07/23 21:16:48 | 000,000,000 | —- | M] () C:\Windows\temp\dsiwmis.log : Unable to obtain MD5 Registry entries deleted on Reboot…
Download Combofix from either of the links below, and save it to your desktop.

Link 1
Link 2



**Note: It is important that it is saved directly to your desktop**

——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
——————————————————————–

Double click on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
NOTE: If you encounter a message "illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error
ComboFix 12-07-26.04 - Nick 25/07/2012 17:20:36.1.8 - x64 Microsoft Windows 7 Home Premium 6.1.7600.0.1252.2.1033.18.8124.6097 [GMT -6:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . C:\Install.exe c:\program files (x86)\Mighty Magoo c:\program files (x86)\Mighty Magoo\ars.cfg c:\users\Nick\GoToAssistDownloadHelper.exe . c:\windows\SysWow64\user32.dll . . . is infected!! . . ((((((((((((((((((((((((( Files Created from 2012-06-25 to 2012-07-25 ))))))))))))))))))))))))))))))) . . 2012-07-25 23:36 . 2012-07-25 23:36 ——– d—–w- c:\users\Guest\AppData\Local\temp 2012-07-25 23:36 . 2012-07-25 23:36 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-07-24 03:11 . 2012-07-24 03:11 ——– d—–w- C:\_OTL 2012-07-21 18:24 . 2012-07-21 18:24 ——– d—–w- c:\program files\Perfect Uninstaller 2012-07-21 18:13 . 2012-07-21 18:13 ——– d—–w- c:\programdata\MediaMonkey 2012-07-21 18:13 . 2012-07-22 17:50 ——– d—–w- c:\users\Nick\AppData\Roaming\MediaMonkey 2012-07-12 06:03 . 2012-07-12 06:03 9822920 —-a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe 2012-07-04 23:45 . 2012-07-04 23:45 ——– d—–w- c:\users\Guest\AppData\Local\Macromedia . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-07-13 01:00 . 2012-06-21 05:59 426184 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2012-07-13 01:00 . 2011-11-24 19:13 70344 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-06-21 05:53 . 2012-06-21 05:53 91648 —-a-w- c:\windows\system32\SetIEInstalledDate.exe 2012-06-21 05:53 . 2012-06-21 05:53 89088 —-a-w- c:\windows\system32\RegisterIEPKEYs.exe 2012-06-21 05:53 . 2012-06-21 05:53 86528 —-a-w- c:\windows\SysWow64\iesysprep.dll 2012-06-21 05:53 . 2012-06-21 05:53 85504 —-a-w- c:\windows\system32\jsproxy.dll 2012-06-21 05:53 . 2012-06-21 05:53 818688 —-a-w- c:\windows\system32\jscript.dll 2012-06-21 05:53 . 2012-06-21 05:53 76800 —-a-w- c:\windows\SysWow64\SetIEInstalledDate.exe 2012-06-21 05:53 . 2012-06-21 05:53 76800 —-a-w- c:\windows\system32\tdc.ocx 2012-06-21 05:53 . 2012-06-21 05:53 74752 —-a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe 2012-06-21 05:53 . 2012-06-21 05:53 74752 —-a-w- c:\windows\SysWow64\iesetup.dll 2012-06-21 05:53 . 2012-06-21 05:53 65024 —-a-w- c:\windows\system32\pngfilt.dll 2012-06-21 05:53 . 2012-06-21 05:53 63488 —-a-w- c:\windows\SysWow64\tdc.ocx 2012-06-21 05:53 . 2012-06-21 05:53 55296 —-a-w- c:\windows\system32\msfeedsbs.dll 2012-06-21 05:53 . 2012-06-21 05:53 49664 —-a-w- c:\windows\system32\imgutil.dll 2012-06-21 05:53 . 2012-06-21 05:53 48640 —-a-w- c:\windows\SysWow64\mshtmler.dll 2012-06-21 05:53 . 2012-06-21 05:53 48640 —-a-w- c:\windows\system32\mshtmler.dll 2012-06-21 05:53 . 2012-06-21 05:53 420864 —-a-w- c:\windows\SysWow64\vbscript.dll 2012-06-21 05:53 . 2012-06-21 05:53 367104 —-a-w- c:\windows\SysWow64\html.iec 2012-06-21 05:53 . 2012-06-21 05:53 35840 —-a-w- c:\windows\SysWow64\imgutil.dll 2012-06-21 05:53 . 2012-06-21 05:53 267776 —-a-w- c:\windows\system32\ieaksie.dll 2012-06-21 05:53 . 2012-06-21 05:53 248320 —-a-w- c:\windows\system32\ieui.dll 2012-06-21 05:53 . 2012-06-21 05:53 2382848 —-a-w- c:\windows\SysWow64\mshtml.tlb 2012-06-21 05:53 . 2012-06-21 05:53 2382848 —-a-w- c:\windows\system32\mshtml.tlb 2012-06-21 05:53 . 2012-06-21 05:53 23552 —-a-w- c:\windows\SysWow64\licmgr10.dll 2012-06-21 05:53 . 2012-06-21 05:53 2311680 —-a-w- c:\windows\system32\jscript9.dll 2012-06-21 05:53 . 2012-06-21 05:53 222208 —-a-w- c:\windows\system32\msls31.dll 2012-06-21 05:53 . 2012-06-21 05:53 2144768 —-a-w- c:\windows\system32\iertutil.dll 2012-06-21 05:53 . 2012-06-21 05:53 197120 —-a-w- c:\windows\system32\msrating.dll 2012-06-21 05:53 . 2012-06-21 05:53 1800192 —-a-w- c:\windows\SysWow64\jscript9.dll 2012-06-21 05:53 . 2012-06-21 05:53 17807360 —-a-w- c:\windows\system32\mshtml.dll 2012-06-21 05:53 . 2012-06-21 05:53 173056 —-a-w- c:\windows\system32\ieUnatt.exe 2012-06-21 05:53 . 2012-06-21 05:53 163840 —-a-w- c:\windows\system32\ieakui.dll 2012-06-21 05:53 . 2012-06-21 05:53 161792 —-a-w- c:\windows\SysWow64\msls31.dll 2012-06-21 05:53 . 2012-06-21 05:53 160256 —-a-w- c:\windows\system32\ieakeng.dll 2012-06-21 05:53 . 2012-06-21 05:53 152064 —-a-w- c:\windows\SysWow64\wextract.exe 2012-06-21 05:53 . 2012-06-21 05:53 150528 —-a-w- c:\windows\SysWow64\iexpress.exe 2012-06-21 05:53 . 2012-06-21 05:53 149504 —-a-w- c:\windows\system32\occache.dll 2012-06-21 05:53 . 2012-06-21 05:53 145920 —-a-w- c:\windows\system32\iepeers.dll 2012-06-21 05:53 . 2012-06-21 05:53 142848 —-a-w- c:\windows\SysWow64\ieUnatt.exe 2012-06-21 05:53 . 2012-06-21 05:53 1427968 —-a-w- c:\windows\SysWow64\inetcpl.cpl 2012-06-21 05:53 . 2012-06-21 05:53 1392128 —-a-w- c:\windows\system32\wininet.dll 2012-06-21 05:53 . 2012-06-21 05:53 135168 —-a-w- c:\windows\system32\IEAdvpack.dll 2012-06-21 05:53 . 2012-06-21 05:53 1346048 —-a-w- c:\windows\system32\urlmon.dll 2012-06-21 05:53 . 2012-06-21 05:53 12288 —-a-w- c:\windows\system32\mshta.exe 2012-06-21 05:53 . 2012-06-21 05:53 11776 —-a-w- c:\windows\SysWow64\mshta.exe 2012-06-21 05:53 . 2012-06-21 05:53 114176 —-a-w- c:\windows\system32\admparse.dll 2012-06-21 05:53 . 2012-06-21 05:53 1129472 —-a-w- c:\windows\SysWow64\wininet.dll 2012-06-21 05:53 . 2012-06-21 05:53 111616 —-a-w- c:\windows\system32\iesysprep.dll 2012-06-21 05:53 . 2012-06-21 05:53 110592 —-a-w- c:\windows\SysWow64\IEAdvpack.dll 2012-06-21 05:53 . 2012-06-21 05:53 10924032 —-a-w- c:\windows\system32\ieframe.dll 2012-06-21 05:53 . 2012-06-21 05:53 10752 —-a-w- c:\windows\system32\msfeedssync.exe 2012-06-21 05:53 . 2012-06-21 05:53 101888 —-a-w- c:\windows\SysWow64\admparse.dll 2012-06-21 05:53 . 2012-06-21 05:53 96768 —-a-w- c:\windows\system32\mshtmled.dll 2012-06-21 05:53 . 2012-06-21 05:53 89088 —-a-w- c:\windows\system32\ie4uinit.exe 2012-06-21 05:53 . 2012-06-21 05:53 85504 —-a-w- c:\windows\system32\iesetup.dll 2012-06-21 05:53 . 2012-06-21 05:53 82432 —-a-w- c:\windows\system32\icardie.dll 2012-06-21 05:53 . 2012-06-21 05:53 697344 —-a-w- c:\windows\system32\msfeeds.dll 2012-06-21 05:53 . 2012-06-21 05:53 603648 —-a-w- c:\windows\system32\vbscript.dll 2012-06-21 05:53 . 2012-06-21 05:53 534528 —-a-w- c:\windows\system32\ieapfltr.dll 2012-06-21 05:53 . 2012-06-21 05:53 452608 —-a-w- c:\windows\system32\dxtmsft.dll 2012-06-21 05:53 . 2012-06-21 05:53 448512 —-a-w- c:\windows\system32\html.iec 2012-06-21 05:53 . 2012-06-21 05:53 403248 —-a-w- c:\windows\system32\iedkcs32.dll 2012-06-21 05:53 . 2012-06-21 05:53 39936 —-a-w- c:\windows\system32\iernonce.dll 2012-06-21 05:53 . 2012-06-21 05:53 3695416 —-a-w- c:\windows\system32\ieapfltr.dat 2012-06-21 05:53 . 2012-06-21 05:53 30720 —-a-w- c:\windows\system32\licmgr10.dll 2012-06-21 05:53 . 2012-06-21 05:53 282112 —-a-w- c:\windows\system32\dxtrans.dll 2012-06-21 05:53 . 2012-06-21 05:53 249344 —-a-w- c:\windows\system32\webcheck.dll 2012-06-21 05:53 . 2012-06-21 05:53 237056 —-a-w- c:\windows\system32\url.dll 2012-06-21 05:53 . 2012-06-21 05:53 165888 —-a-w- c:\windows\system32\iexpress.exe 2012-06-21 05:53 . 2012-06-21 05:53 160256 —-a-w- c:\windows\system32\wextract.exe 2012-06-21 05:53 . 2012-06-21 05:53 1494528 —-a-w- c:\windows\system32\inetcpl.cpl 2012-06-21 05:53 . 2012-06-21 05:53 103936 —-a-w- c:\windows\system32\inseng.dll 2012-06-21 05:51 . 2012-06-21 05:51 982912 —-a-w- c:\windows\system32\drivers\dxgkrnl.sys 2012-06-21 05:51 . 2012-06-21 05:51 902656 —-a-w- c:\windows\system32\d2d1.dll 2012-06-21 05:51 . 2012-06-21 05:51 739840 —-a-w- c:\windows\SysWow64\d2d1.dll 2012-06-21 05:51 . 2012-06-21 05:51 662528 —-a-w- c:\windows\system32\XpsPrint.dll 2012-06-21 05:51 . 2012-06-21 05:51 470016 —-a-w- c:\windows\system32\XpsGdiConverter.dll 2012-06-21 05:51 . 2012-06-21 05:51 442880 —-a-w- c:\windows\SysWow64\XpsPrint.dll 2012-06-21 05:51 . 2012-06-21 05:51 4068864 —-a-w- c:\windows\system32\mf.dll 2012-06-21 05:51 . 2012-06-21 05:51 320512 —-a-w- c:\windows\system32\d3d10_1core.dll 2012-06-21 05:51 . 2012-06-21 05:51 3181568 —-a-w- c:\windows\SysWow64\mf.dll 2012-06-21 05:51 . 2012-06-21 05:51 283648 —-a-w- c:\windows\SysWow64\XpsGdiConverter.dll 2012-06-21 05:51 . 2012-06-21 05:51 265088 —-a-w- c:\windows\system32\drivers\dxgmms1.sys 2012-06-21 05:51 . 2012-06-21 05:51 257024 —-a-w- c:\windows\system32\mfreadwrite.dll 2012-06-21 05:51 . 2012-06-21 05:51 229888 —-a-w- c:\windows\system32\XpsRasterService.dll 2012-06-21 05:51 . 2012-06-21 05:51 218624 —-a-w- c:\windows\SysWow64\d3d10_1core.dll 2012-06-21 05:51 . 2012-06-21 05:51 206848 —-a-w- c:\windows\system32\mfps.dll 2012-06-21 05:51 . 2012-06-21 05:51 197120 —-a-w- c:\windows\system32\d3d10_1.dll 2012-06-21 05:51 . 2012-06-21 05:51 196608 —-a-w- c:\windows\SysWow64\mfreadwrite.dll 2012-06-21 05:51 . 2012-06-21 05:51 1888256 —-a-w- c:\windows\system32\WMVDECOD.DLL 2012-06-21 05:51 . 2012-06-21 05:51 1863680 —-a-w- c:\windows\system32\ExplorerFrame.dll 2012-06-21 05:51 . 2012-06-21 05:51 1837568 —-a-w- c:\windows\system32\d3d10warp.dll 2012-06-21 05:51 . 2012-06-21 05:51 1619456 —-a-w- c:\windows\SysWow64\WMVDECOD.DLL 2012-06-21 05:51 . 2012-06-21 05:51 161792 —-a-w- c:\windows\SysWow64\d3d10_1.dll 2012-06-21 05:51 . 2012-06-21 05:51 1540608 —-a-w- c:\windows\system32\DWrite.dll 2012-06-21 05:51 . 2012-06-21 05:51 1495040 —-a-w- c:\windows\SysWow64\ExplorerFrame.dll 2012-06-21 05:51 . 2012-06-21 05:51 144384 —-a-w- c:\windows\system32\cdd.dll 2012-06-21 05:51 . 2012-06-21 05:51 135168 —-a-w- c:\windows\SysWow64\XpsRasterService.dll 2012-06-21 05:51 . 2012-06-21 05:51 1170944 —-a-w- c:\windows\SysWow64\d3d10warp.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP] @="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}" [HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}] 2010-02-01 18:03 120176 —-a-w- c:\program files (x86)\EgisTec MyWinLocker\x86\PSDProtect.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1475072] "swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-04-22 39408] "DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696] "Steam"="c:\program files (x86)\Steam\Steam.exe" [2011-08-08 1242448] "Audiogalaxy"="c:\users\Nick\AppData\Local\Audiogalaxy\Audiogalaxy.exe" [2011-12-29 2955496] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "AMD AVT"="start AMD Accelerated Video Transcoding device initialization" [X] "IAStorIcon"="c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe" [2010-03-04 284696] "LManager"="c:\program files (x86)\Launch Manager\LManager.exe" [2010-03-03 1300560] "SuiteTray"="c:\program files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe" [2010-02-01 337264] "EgisUpdate"="c:\program files (x86)\EgisTec IPS\EgisUpdate.exe" [2009-12-25 201512] "EgisTecPMMUpdate"="c:\program files (x86)\EgisTec IPS\PmmUpdate.exe" [2009-12-25 401192] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-28 35696] "BackupManagerTray"="c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" [2010-03-08 260608] "NortonOnlineBackupReminder"="c:\program files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" [2009-07-24 588648] "MDS_Menu"="c:\program files (x86)\Acer Arcade Deluxe\MediaShow Espresso\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504] "ArcadeMovieService"="c:\program files (x86)\Acer Arcade Deluxe\Arcade Movie\ArcadeMovieService.exe" [2010-03-17 124136] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-08-10 421888] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2010-09-01 421160] "VirtualCloneDrive"="c:\program files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2009-05-26 85160] "Seagate Dashboard"="c:\program files (x86)\Seagate\Seagate Dashboard\MemeoLauncher.exe" [2011-06-01 79112] "EEventManager"="c:\progra~2\EPSONS~1\EVENTM~1\EEventManager.exe" [2009-04-07 673616] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-01-07 253672] "RIMBBLaunchAgent.exe"="c:\program files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe" [2011-11-02 90448] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-04-06 641664] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-09-18 135664] R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-21 250056] R3 AmUStor;AM USB Stroage Driver;c:\windows\system32\drivers\AmUStor.SYS [2009-05-27 40448] R3 dc3d;MS Hardware Device Detection Driver (USB);c:\windows\system32\DRIVERS\dc3d.sys [2009-05-21 25992] R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys [2011-10-04 95544] R3 GamesAppService;GamesAppService;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072] R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-09-18 135664] R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-07-20 113120] R3 MWLService;MyWinLocker Service;c:\program files (x86)\EgisTec MyWinLocker\x86\MWLService.exe [2010-02-01 305520] R3 NETw5s64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;c:\windows\system32\DRIVERS\NETw5s64.sys [2009-09-15 6952960] R3 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2009-11-06 50432] R3 Point64;Microsoft IntelliPoint Filter Driver;c:\windows\system32\DRIVERS\point64k.sys [2009-05-09 33160] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2010-04-20 50688] S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-09-23 834544] S1 archlp;archlp;c:\windows\system32\drivers\archlp.sys [2010-01-12 142848] S1 aswSnx;aswSnx; [x] S1 aswSP;aswSP; [x] S1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys [2009-06-03 22576] S1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys [2009-06-03 20016] S1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys [2009-06-03 60464] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2012-04-06 236544] S2 aswFsBlk;aswFsBlk; [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2011-09-06 65368] S2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x64.sys [2010-11-09 21992] S2 DsiWMIService;Dritek WMI Service;c:\program files (x86)\Launch Manager\dsiwmis.exe [2010-03-03 325200] S2 ePowerSvc;Acer ePower Service;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe [2010-03-17 866336] S2 GREGService;GREGService;c:\program files (x86)\Acer\Registration\GREGsvc.exe [2010-01-08 23584] S2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-03-04 13336] S2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2010-03-08 250368] S2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2009-11-06 144640] S2 SeagateDashboardService;Seagate Dashboard Service;c:\program files (x86)\Seagate\Seagate Dashboard\SeagateDashboardService.exe [2011-06-01 14088] S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys [2009-11-02 13784] S2 UNS;Intel® Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2009-10-01 2314240] S2 Updater Service;Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe [2010-01-28 243232] S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2012-04-06 11174400] S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2012-04-06 343040] S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2012-02-23 95760] S3 HECIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2009-09-17 56344] S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [2010-01-18 75304] S3 TurboBoost;TurboBoost;c:\program files\Intel\TurboBoost\TurboBoost.exe [2009-11-02 126352] S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920] . . — Other Services/Drivers In Memory — . *NewlyCreated* - WS2IFSL . Contents of the 'Scheduled Tasks' folder . 2012-07-25 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-21 05:59] . 2012-07-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-09-18 12:05] . 2012-07-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-09-18 12:05] . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2011-09-06 20:45 134384 —-a-w- c:\program files\Alwil Software\Avast5\ashShA64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP] @="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}" [HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}] 2010-02-01 18:06 137584 —-a-w- c:\program files (x86)\EgisTec MyWinLocker\x64\PSDProtect.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "AmIcoSinglun64"="c:\program files (x86)\AmIcoSingLun\AmIcoSinglun64.exe" [2010-02-06 324608] "mwlDaemon"="c:\program files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe" [2010-02-01 349552] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-02-22 10081312] "RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2010-02-22 877600] "PLFSetI"="c:\windows\PLFSetI.exe" [2010-04-29 206208] "Acer ePower Management"="c:\program files\Acer\Acer ePower Management\ePowerTray.exe" [2010-03-17 860704] "XboxStat"="c:\program files\Microsoft Xbox 360 Accessories\XboxStat.exe" [2009-09-30 825184] "itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2009-05-21 2342800] "IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2009-05-26 2314120] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x0 . ——- Supplementary Scan ——- . uStart Page = uLocal Page = c:\windows\system32\blank.htm mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l;=1009&m;=aspire_7745g&r;=27360910s806l0433z175t5611l293 mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: E&xport; to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000 IE: Google Sidewiki… - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html TCP: DhcpNameServer = 192.168.0.1 TCP: Interfaces\{A60E18E8-E700-4ECD-9E59-2528F1E2D72E}\D616A74616D27657563747: DhcpNameServer = 8.8.8.8 4.2.2.2 FF - ProfilePath - c:\users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\ FF - prefs.js: browser.search.selectedEngine - FF - prefs.js: network.proxy.http - 207.62.217.252 FF - prefs.js: network.proxy.http_port - 3128 FF - prefs.js: network.proxy.type - 0 . - - - - ORPHANS REMOVED - - - - . URLSearchHooks-{ba14329e-9550-4989-b3f2-9732e92d17cc} - (no file) URLSearchHooks-{f9bbf004-6e40-4019-8214-c43a37e1d058} - (no file) Toolbar-Locked - (no file) WebBrowser-{BA14329E-9550-4989-B3F2-9732E92D17CC} - (no file) WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file) HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe AddRemove-dBpoweramp DSP Effects - c:\windows\system32\SpoonUninstall.exe AddRemove-dBpoweramp m4a Codec - c:\windows\system32\SpoonUninstall.exe AddRemove-dBpoweramp m4a Nero AAC Encoder - c:\windows\system32\SpoonUninstall.exe AddRemove-dBpoweramp Music Converter - c:\windows\system32\SpoonUninstall.exe AddRemove-dBpoweramp Ogg Vorbis Codec - c:\windows\system32\SpoonUninstall.exe AddRemove-Euro Truck Simulator 1.3 - c:\program files\Euro Truck Simulator\Uninstall.exe AddRemove-MightyMagoo - c:\program files (x86)\Mighty Magoo\mmagooun.exe . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10e.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10e.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}] @Denied: (A 2) (Everyone) @="IFlashBroker3" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files\Alwil Software\Avast5\AvastSvc.exe c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files (x86)\Bonjour\mDNSResponder.exe c:\program files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe c:\program files (x86)\Cyberlink\Shared files\RichVideo.exe c:\program files (x86)\Epson Software\Event Manager\EEventManager.exe c:\program files (x86)\Seagate\Seagate Dashboard\MemeoDashboard.exe c:\program files (x86)\Launch Manager\LMworker.exe c:\program files (x86)\Seagate\Seagate Dashboard\HipServAgent\HipServAgent.exe . ************************************************************************** . Completion time: 2012-07-25 17:44:17 - machine was rebooted ComboFix-quarantined-files.txt 2012-07-25 23:44 . Pre-Run: 366,326,947,840 bytes free Post-Run: 366,103,257,088 bytes free . - - End Of File - - 8243C732BCB5B05B40E97BA4484847E9

Did you set this proxy.

FF - prefs.js..network.proxy.http: "207.62.217.252"

You didn't answer this.

Please download SystemLook from one of the links below and save it to your Desktop.
Link 1
Link 2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :filefind
    *user32.dll*
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

Did you set this proxy.

FF - prefs.js..network.proxy.http: "207.62.217.252"

You didn't answer this.


I honestly don't remember. Off hand, I don't recall doing it.

———————————————————————————————————–

SystemLook 30.07.11 by jpshortstuff
Log created at 18:05 on 27/07/2012 by Nick
Administrator - Elevation successful

========== filefind ==========

Searching for "*user32.dll*"
C:\Windows\erdnt\cache64\user32.dll –a—- 1008640 bytes [23:42 25/07/2012] [01:41 14/07/2009] 72D7B3EA16946E8F0CF7458150031CC6
C:\Windows\erdnt\cache86\user32.dll –a—- 833024 bytes [23:42 25/07/2012] [01:11 14/07/2009] E8B0FFC209E504CB7E79FC24E6C085F0
C:\Windows\System32\user32.dll –a—- 1008640 bytes [23:38 13/07/2009] [01:41 14/07/2009] 72D7B3EA16946E8F0CF7458150031CC6
C:\Windows\System32\en-US\user32.dll.mui –a—- 17920 bytes [05:35 14/07/2009] [02:26 14/07/2009] 7CA57982056C7BCED0B96A892F595802
C:\Windows\SysWOW64\user32.dll –a—- 833024 bytes [23:24 13/07/2009] [01:11 14/07/2009] E8B0FFC209E504CB7E79FC24E6C085F0
C:\Windows\SysWOW64\en-US\user32.dll.mui –a—- 17920 bytes [05:35 14/07/2009] [02:03 14/07/2009] D448B52149F95F1250100F9BD0ED7152
C:\Windows\winsxs\amd64_microsoft-windows-user32.resources_31bf3856ad364e35_6.1.7600.16385_en-us_99f2e97144ce40b4\user32.dll.mui –a—- 17920 bytes [05:35 14/07/2009] [02:26 14/07/2009] 7CA57982056C7BCED0B96A892F595802
C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9\user32.dll –a—- 1008640 bytes [23:38 13/07/2009] [01:41 14/07/2009] 72D7B3EA16946E8F0CF7458150031CC6
C:\Windows\winsxs\Backup\amd64_microsoft-windows-user32.resources_31bf3856ad364e35_6.1.7600.16385_en-us_99f2e97144ce40b4_user32.dll.mui_14652dbb –a—- 17920 bytes [05:37 14/07/2009] [05:37 14/07/2009] 7CA57982056C7BCED0B96A892F595802
C:\Windows\winsxs\Backup\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9_user32.dll_55f4ed20 –a—- 1008640 bytes [02:59 14/07/2009] [02:57 14/07/2009] 72D7B3EA16946E8F0CF7458150031CC6
C:\Windows\winsxs\Backup\wow64_microsoft-windows-user32.resources_31bf3856ad364e35_6.1.7600.16385_en-us_a44793c3792f02af_user32.dll.mui_14652dbb –a—- 17920 bytes [05:37 14/07/2009] [05:37 14/07/2009] D448B52149F95F1250100F9BD0ED7152
C:\Windows\winsxs\Backup\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4_user32.dll_55f4ed20 –a—- 833024 bytes [02:59 14/07/2009] [02:58 14/07/2009] E8B0FFC209E504CB7E79FC24E6C085F0
C:\Windows\winsxs\wow64_microsoft-windows-user32.resources_31bf3856ad364e35_6.1.7600.16385_en-us_a44793c3792f02af\user32.dll.mui –a—- 17920 bytes [05:35 14/07/2009] [02:03 14/07/2009] D448B52149F95F1250100F9BD0ED7152
C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll –a—- 833024 bytes [23:24 13/07/2009] [01:11 14/07/2009] E8B0FFC209E504CB7E79FC24E6C085F0

-= EOF =-
COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    Fcopy:: 
    C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll | c:\windows\SysWow64\user32.dll
    
    Firefox::
    FF - ProfilePath - c:\users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\
    FF - prefs.js: network.proxy.http - 207.62.217.252
    FF - prefs.js: network.proxy.http_port - 3128
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • If you need help to disable your protection programs see here.
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.










Please download Malwarebytes Free from Here or Here

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the log please









Next

ESET Online Scanner
I'd like us to scan your machine with ESET Online Scan

Note: It is recommended to disable on-board anti-virus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your anti-virus along with your anti-spyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is not checked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the Back button.
  • Push Finish
http://www.eset.com/onlinescan/





Also tell me how the computer is running now.
ComboFix 12-07-26.04 - Nick 27/07/2012 21:32:04.2.8 - x64 Microsoft Windows 7 Home Premium 6.1.7600.0.1252.2.1033.18.8124.6101 [GMT -6:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe Command switches used :: c:\users\Nick\Desktop\CFScript.txt AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\windows\SysWow64\userinit.exe . . . is infected!! . . ————— FCopy ————— . c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll –> c:\windows\SysWow64\user32.dll . ((((((((((((((((((((((((( Files Created from 2012-06-28 to 2012-07-28 ))))))))))))))))))))))))))))))) . . 2012-07-28 03:40 . 2012-07-28 03:40 ——– d—–w- c:\users\Guest\AppData\Local\temp 2012-07-28 03:40 . 2012-07-28 03:40 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-07-24 03:11 . 2012-07-24 03:11 ——– d—–w- C:\_OTL 2012-07-21 18:24 . 2012-07-21 18:24 ——– d—–w- c:\program files\Perfect Uninstaller 2012-07-21 18:13 . 2012-07-21 18:13 ——– d—–w- c:\programdata\MediaMonkey 2012-07-21 18:13 . 2012-07-26 01:45 ——– d—–w- c:\users\Nick\AppData\Roaming\MediaMonkey 2012-07-12 06:03 . 2012-07-27 17:50 9821896 —-a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe 2012-07-04 23:45 . 2012-07-04 23:45 ——– d—–w- c:\users\Guest\AppData\Local\Macromedia . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-07-27 17:54 . 2012-06-21 05:59 426184 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2012-07-27 17:54 . 2011-11-24 19:13 70344 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-06-21 05:53 . 2012-06-21 05:53 91648 —-a-w- c:\windows\system32\SetIEInstalledDate.exe 2012-06-21 05:53 . 2012-06-21 05:53 89088 —-a-w- c:\windows\system32\RegisterIEPKEYs.exe 2012-06-21 05:53 . 2012-06-21 05:53 86528 —-a-w- c:\windows\SysWow64\iesysprep.dll 2012-06-21 05:53 . 2012-06-21 05:53 85504 —-a-w- c:\windows\system32\jsproxy.dll 2012-06-21 05:53 . 2012-06-21 05:53 818688 —-a-w- c:\windows\system32\jscript.dll 2012-06-21 05:53 . 2012-06-21 05:53 76800 —-a-w- c:\windows\SysWow64\SetIEInstalledDate.exe 2012-06-21 05:53 . 2012-06-21 05:53 76800 —-a-w- c:\windows\system32\tdc.ocx 2012-06-21 05:53 . 2012-06-21 05:53 74752 —-a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe 2012-06-21 05:53 . 2012-06-21 05:53 74752 —-a-w- c:\windows\SysWow64\iesetup.dll 2012-06-21 05:53 . 2012-06-21 05:53 65024 —-a-w- c:\windows\system32\pngfilt.dll 2012-06-21 05:53 . 2012-06-21 05:53 63488 —-a-w- c:\windows\SysWow64\tdc.ocx 2012-06-21 05:53 . 2012-06-21 05:53 55296 —-a-w- c:\windows\system32\msfeedsbs.dll 2012-06-21 05:53 . 2012-06-21 05:53 49664 —-a-w- c:\windows\system32\imgutil.dll 2012-06-21 05:53 . 2012-06-21 05:53 48640 —-a-w- c:\windows\SysWow64\mshtmler.dll 2012-06-21 05:53 . 2012-06-21 05:53 48640 —-a-w- c:\windows\system32\mshtmler.dll 2012-06-21 05:53 . 2012-06-21 05:53 420864 —-a-w- c:\windows\SysWow64\vbscript.dll 2012-06-21 05:53 . 2012-06-21 05:53 367104 —-a-w- c:\windows\SysWow64\html.iec 2012-06-21 05:53 . 2012-06-21 05:53 35840 —-a-w- c:\windows\SysWow64\imgutil.dll 2012-06-21 05:53 . 2012-06-21 05:53 267776 —-a-w- c:\windows\system32\ieaksie.dll 2012-06-21 05:53 . 2012-06-21 05:53 248320 —-a-w- c:\windows\system32\ieui.dll 2012-06-21 05:53 . 2012-06-21 05:53 2382848 —-a-w- c:\windows\SysWow64\mshtml.tlb 2012-06-21 05:53 . 2012-06-21 05:53 2382848 —-a-w- c:\windows\system32\mshtml.tlb 2012-06-21 05:53 . 2012-06-21 05:53 23552 —-a-w- c:\windows\SysWow64\licmgr10.dll 2012-06-21 05:53 . 2012-06-21 05:53 2311680 —-a-w- c:\windows\system32\jscript9.dll 2012-06-21 05:53 . 2012-06-21 05:53 222208 —-a-w- c:\windows\system32\msls31.dll 2012-06-21 05:53 . 2012-06-21 05:53 2144768 —-a-w- c:\windows\system32\iertutil.dll 2012-06-21 05:53 . 2012-06-21 05:53 197120 —-a-w- c:\windows\system32\msrating.dll 2012-06-21 05:53 . 2012-06-21 05:53 1800192 —-a-w- c:\windows\SysWow64\jscript9.dll 2012-06-21 05:53 . 2012-06-21 05:53 17807360 —-a-w- c:\windows\system32\mshtml.dll 2012-06-21 05:53 . 2012-06-21 05:53 173056 —-a-w- c:\windows\system32\ieUnatt.exe 2012-06-21 05:53 . 2012-06-21 05:53 163840 —-a-w- c:\windows\system32\ieakui.dll 2012-06-21 05:53 . 2012-06-21 05:53 161792 —-a-w- c:\windows\SysWow64\msls31.dll 2012-06-21 05:53 . 2012-06-21 05:53 160256 —-a-w- c:\windows\system32\ieakeng.dll 2012-06-21 05:53 . 2012-06-21 05:53 152064 —-a-w- c:\windows\SysWow64\wextract.exe 2012-06-21 05:53 . 2012-06-21 05:53 150528 —-a-w- c:\windows\SysWow64\iexpress.exe 2012-06-21 05:53 . 2012-06-21 05:53 149504 —-a-w- c:\windows\system32\occache.dll 2012-06-21 05:53 . 2012-06-21 05:53 145920 —-a-w- c:\windows\system32\iepeers.dll 2012-06-21 05:53 . 2012-06-21 05:53 142848 —-a-w- c:\windows\SysWow64\ieUnatt.exe 2012-06-21 05:53 . 2012-06-21 05:53 1427968 —-a-w- c:\windows\SysWow64\inetcpl.cpl 2012-06-21 05:53 . 2012-06-21 05:53 1392128 —-a-w- c:\windows\system32\wininet.dll 2012-06-21 05:53 . 2012-06-21 05:53 135168 —-a-w- c:\windows\system32\IEAdvpack.dll 2012-06-21 05:53 . 2012-06-21 05:53 1346048 —-a-w- c:\windows\system32\urlmon.dll 2012-06-21 05:53 . 2012-06-21 05:53 12288 —-a-w- c:\windows\system32\mshta.exe 2012-06-21 05:53 . 2012-06-21 05:53 11776 —-a-w- c:\windows\SysWow64\mshta.exe 2012-06-21 05:53 . 2012-06-21 05:53 114176 —-a-w- c:\windows\system32\admparse.dll 2012-06-21 05:53 . 2012-06-21 05:53 1129472 —-a-w- c:\windows\SysWow64\wininet.dll 2012-06-21 05:53 . 2012-06-21 05:53 111616 —-a-w- c:\windows\system32\iesysprep.dll 2012-06-21 05:53 . 2012-06-21 05:53 110592 —-a-w- c:\windows\SysWow64\IEAdvpack.dll 2012-06-21 05:53 . 2012-06-21 05:53 10924032 —-a-w- c:\windows\system32\ieframe.dll 2012-06-21 05:53 . 2012-06-21 05:53 10752 —-a-w- c:\windows\system32\msfeedssync.exe 2012-06-21 05:53 . 2012-06-21 05:53 101888 —-a-w- c:\windows\SysWow64\admparse.dll 2012-06-21 05:53 . 2012-06-21 05:53 96768 —-a-w- c:\windows\system32\mshtmled.dll 2012-06-21 05:53 . 2012-06-21 05:53 89088 —-a-w- c:\windows\system32\ie4uinit.exe 2012-06-21 05:53 . 2012-06-21 05:53 85504 —-a-w- c:\windows\system32\iesetup.dll 2012-06-21 05:53 . 2012-06-21 05:53 82432 —-a-w- c:\windows\system32\icardie.dll 2012-06-21 05:53 . 2012-06-21 05:53 697344 —-a-w- c:\windows\system32\msfeeds.dll 2012-06-21 05:53 . 2012-06-21 05:53 603648 —-a-w- c:\windows\system32\vbscript.dll 2012-06-21 05:53 . 2012-06-21 05:53 534528 —-a-w- c:\windows\system32\ieapfltr.dll 2012-06-21 05:53 . 2012-06-21 05:53 452608 —-a-w- c:\windows\system32\dxtmsft.dll 2012-06-21 05:53 . 2012-06-21 05:53 448512 —-a-w- c:\windows\system32\html.iec 2012-06-21 05:53 . 2012-06-21 05:53 403248 —-a-w- c:\windows\system32\iedkcs32.dll 2012-06-21 05:53 . 2012-06-21 05:53 39936 —-a-w- c:\windows\system32\iernonce.dll 2012-06-21 05:53 . 2012-06-21 05:53 3695416 —-a-w- c:\windows\system32\ieapfltr.dat 2012-06-21 05:53 . 2012-06-21 05:53 30720 —-a-w- c:\windows\system32\licmgr10.dll 2012-06-21 05:53 . 2012-06-21 05:53 282112 —-a-w- c:\windows\system32\dxtrans.dll 2012-06-21 05:53 . 2012-06-21 05:53 249344 —-a-w- c:\windows\system32\webcheck.dll 2012-06-21 05:53 . 2012-06-21 05:53 237056 —-a-w- c:\windows\system32\url.dll 2012-06-21 05:53 . 2012-06-21 05:53 165888 —-a-w- c:\windows\system32\iexpress.exe 2012-06-21 05:53 . 2012-06-21 05:53 160256 —-a-w- c:\windows\system32\wextract.exe 2012-06-21 05:53 . 2012-06-21 05:53 1494528 —-a-w- c:\windows\system32\inetcpl.cpl 2012-06-21 05:53 . 2012-06-21 05:53 103936 —-a-w- c:\windows\system32\inseng.dll 2012-06-21 05:51 . 2012-06-21 05:51 982912 —-a-w- c:\windows\system32\drivers\dxgkrnl.sys 2012-06-21 05:51 . 2012-06-21 05:51 902656 —-a-w- c:\windows\system32\d2d1.dll 2012-06-21 05:51 . 2012-06-21 05:51 739840 —-a-w- c:\windows\SysWow64\d2d1.dll 2012-06-21 05:51 . 2012-06-21 05:51 662528 —-a-w- c:\windows\system32\XpsPrint.dll 2012-06-21 05:51 . 2012-06-21 05:51 470016 —-a-w- c:\windows\system32\XpsGdiConverter.dll 2012-06-21 05:51 . 2012-06-21 05:51 442880 —-a-w- c:\windows\SysWow64\XpsPrint.dll 2012-06-21 05:51 . 2012-06-21 05:51 4068864 —-a-w- c:\windows\system32\mf.dll 2012-06-21 05:51 . 2012-06-21 05:51 320512 —-a-w- c:\windows\system32\d3d10_1core.dll 2012-06-21 05:51 . 2012-06-21 05:51 3181568 —-a-w- c:\windows\SysWow64\mf.dll 2012-06-21 05:51 . 2012-06-21 05:51 283648 —-a-w- c:\windows\SysWow64\XpsGdiConverter.dll 2012-06-21 05:51 . 2012-06-21 05:51 265088 —-a-w- c:\windows\system32\drivers\dxgmms1.sys 2012-06-21 05:51 . 2012-06-21 05:51 257024 —-a-w- c:\windows\system32\mfreadwrite.dll 2012-06-21 05:51 . 2012-06-21 05:51 229888 —-a-w- c:\windows\system32\XpsRasterService.dll 2012-06-21 05:51 . 2012-06-21 05:51 218624 —-a-w- c:\windows\SysWow64\d3d10_1core.dll 2012-06-21 05:51 . 2012-06-21 05:51 206848 —-a-w- c:\windows\system32\mfps.dll 2012-06-21 05:51 . 2012-06-21 05:51 197120 —-a-w- c:\windows\system32\d3d10_1.dll 2012-06-21 05:51 . 2012-06-21 05:51 196608 —-a-w- c:\windows\SysWow64\mfreadwrite.dll 2012-06-21 05:51 . 2012-06-21 05:51 1888256 —-a-w- c:\windows\system32\WMVDECOD.DLL 2012-06-21 05:51 . 2012-06-21 05:51 1863680 —-a-w- c:\windows\system32\ExplorerFrame.dll 2012-06-21 05:51 . 2012-06-21 05:51 1837568 —-a-w- c:\windows\system32\d3d10warp.dll 2012-06-21 05:51 . 2012-06-21 05:51 1619456 —-a-w- c:\windows\SysWow64\WMVDECOD.DLL 2012-06-21 05:51 . 2012-06-21 05:51 161792 —-a-w- c:\windows\SysWow64\d3d10_1.dll 2012-06-21 05:51 . 2012-06-21 05:51 1540608 —-a-w- c:\windows\system32\DWrite.dll 2012-06-21 05:51 . 2012-06-21 05:51 1495040 —-a-w- c:\windows\SysWow64\ExplorerFrame.dll 2012-06-21 05:51 . 2012-06-21 05:51 144384 —-a-w- c:\windows\system32\cdd.dll 2012-06-21 05:51 . 2012-06-21 05:51 135168 —-a-w- c:\windows\SysWow64\XpsRasterService.dll 2012-06-21 05:51 . 2012-06-21 05:51 1170944 —-a-w- c:\windows\SysWow64\d3d10warp.dll . . ((((((((((((((((((((((((((((( SnapShot@2012-07-25_23.37.56 ))))))))))))))))))))))))))))))))))))))))) . + 2009-07-14 04:54 . 2012-07-28 03:42 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2009-07-14 04:54 . 2012-07-25 23:38 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2009-07-14 04:54 . 2012-07-25 23:38 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2009-07-14 04:54 . 2012-07-28 03:42 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2009-07-14 04:54 . 2012-07-25 23:38 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2009-07-14 04:54 . 2012-07-28 03:42 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2010-07-07 02:14 . 2012-07-22 02:25 32768 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2010-07-07 02:14 . 2012-07-27 17:50 32768 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2012-07-26 00:21 . 2012-07-27 17:50 49152 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2009-07-14 04:54 . 2012-07-22 02:25 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2009-07-14 04:54 . 2012-07-27 17:50 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2012-07-25 23:37 . 2012-07-25 23:37 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat + 2012-07-28 03:41 . 2012-07-28 03:41 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat - 2012-07-25 23:37 . 2012-07-25 23:37 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat + 2012-07-28 03:41 . 2012-07-28 03:41 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat + 2012-07-27 17:50 . 2012-07-27 17:54 686792 c:\windows\SysWOW64\Macromed\Flash\FlashUtil32_11_3_300_268_Plugin.exe - 2012-06-21 05:59 . 2012-06-21 05:59 250056 c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe + 2012-06-21 05:59 . 2012-07-27 17:54 250056 c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe + 2010-09-29 01:52 . 2012-07-28 00:04 335940 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S4.bin + 2010-09-18 12:30 . 2012-07-28 03:25 386328 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S3.bin + 2012-07-27 17:50 . 2012-07-27 17:54 417992 c:\windows\system32\Macromed\Flash\FlashUtil64_11_3_300_268_Plugin.exe - 2009-07-14 05:01 . 2012-07-25 23:36 307364 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat + 2009-07-14 05:01 . 2012-07-28 03:41 307364 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat + 2012-07-27 17:50 . 2012-07-27 17:54 9465032 c:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_268.dll + 2012-07-27 17:50 . 2012-07-27 17:54 1536712 c:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_268.exe - 2011-06-17 01:18 . 2012-07-21 18:50 1589696 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-2603002203-163824921-1337712861-1000-12288.dat + 2011-06-17 01:18 . 2012-07-28 03:41 1589696 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-2603002203-163824921-1337712861-1000-12288.dat + 2009-07-14 02:34 . 2012-07-28 04:29 10223616 c:\windows\system32\SMI\Store\Machine\schema.dat - 2009-07-14 02:34 . 2012-07-21 21:37 10223616 c:\windows\system32\SMI\Store\Machine\schema.dat + 2012-07-27 17:50 . 2012-07-27 17:54 12315336 c:\windows\system32\Macromed\Flash\NPSWF64_11_3_300_268.dll + 2010-10-02 05:46 . 2012-07-28 03:41 26648676 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-2603002203-163824921-1337712861-1000-8192.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP] @="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}" [HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}] 2010-02-01 18:03 120176 —-a-w- c:\program files (x86)\EgisTec MyWinLocker\x86\PSDProtect.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1475072] "swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-04-22 39408] "DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696] "Steam"="c:\program files (x86)\Steam\Steam.exe" [2011-08-08 1242448] "Audiogalaxy"="c:\users\Nick\AppData\Local\Audiogalaxy\Audiogalaxy.exe" [2011-12-29 2955496] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "AMD AVT"="start AMD Accelerated Video Transcoding device initialization" [X] "IAStorIcon"="c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe" [2010-03-04 284696] "LManager"="c:\program files (x86)\Launch Manager\LManager.exe" [2010-03-03 1300560] "SuiteTray"="c:\program files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe" [2010-02-01 337264] "EgisUpdate"="c:\program files (x86)\EgisTec IPS\EgisUpdate.exe" [2009-12-25 201512] "EgisTecPMMUpdate"="c:\program files (x86)\EgisTec IPS\PmmUpdate.exe" [2009-12-25 401192] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-28 35696] "BackupManagerTray"="c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" [2010-03-08 260608] "NortonOnlineBackupReminder"="c:\program files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" [2009-07-24 588648] "MDS_Menu"="c:\program files (x86)\Acer Arcade Deluxe\MediaShow Espresso\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504] "ArcadeMovieService"="c:\program files (x86)\Acer Arcade Deluxe\Arcade Movie\ArcadeMovieService.exe" [2010-03-17 124136] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-08-10 421888] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2010-09-01 421160] "VirtualCloneDrive"="c:\program files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2009-05-26 85160] "Seagate Dashboard"="c:\program files (x86)\Seagate\Seagate Dashboard\MemeoLauncher.exe" [2011-06-01 79112] "EEventManager"="c:\progra~2\EPSONS~1\EVENTM~1\EEventManager.exe" [2009-04-07 673616] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-01-07 253672] "RIMBBLaunchAgent.exe"="c:\program files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe" [2011-11-02 90448] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-04-06 641664] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon] "Userinit"="c:\windows\explorer.exe," . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-09-18 135664] R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-27 250056] R3 AmUStor;AM USB Stroage Driver;c:\windows\system32\drivers\AmUStor.SYS [2009-05-27 40448] R3 dc3d;MS Hardware Device Detection Driver (USB);c:\windows\system32\DRIVERS\dc3d.sys [2009-05-21 25992] R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys [2011-10-04 95544] R3 GamesAppService;GamesAppService;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072] R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-09-18 135664] R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-07-20 113120] R3 MWLService;MyWinLocker Service;c:\program files (x86)\EgisTec MyWinLocker\x86\MWLService.exe [2010-02-01 305520] R3 NETw5s64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;c:\windows\system32\DRIVERS\NETw5s64.sys [2009-09-15 6952960] R3 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2009-11-06 50432] R3 Point64;Microsoft IntelliPoint Filter Driver;c:\windows\system32\DRIVERS\point64k.sys [2009-05-09 33160] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2010-04-20 50688] S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-09-23 834544] S1 archlp;archlp;c:\windows\system32\drivers\archlp.sys [2010-01-12 142848] S1 aswSnx;aswSnx; [x] S1 aswSP;aswSP; [x] S1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys [2009-06-03 22576] S1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys [2009-06-03 20016] S1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys [2009-06-03 60464] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2012-04-06 236544] S2 aswFsBlk;aswFsBlk; [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2011-09-06 65368] S2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x64.sys [2010-11-09 21992] S2 DsiWMIService;Dritek WMI Service;c:\program files (x86)\Launch Manager\dsiwmis.exe [2010-03-03 325200] S2 ePowerSvc;Acer ePower Service;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe [2010-03-17 866336] S2 GREGService;GREGService;c:\program files (x86)\Acer\Registration\GREGsvc.exe [2010-01-08 23584] S2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-03-04 13336] S2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2010-03-08 250368] S2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2009-11-06 144640] S2 SeagateDashboardService;Seagate Dashboard Service;c:\program files (x86)\Seagate\Seagate Dashboard\SeagateDashboardService.exe [2011-06-01 14088] S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys [2009-11-02 13784] S2 UNS;Intel® Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2009-10-01 2314240] S2 Updater Service;Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe [2010-01-28 243232] S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2012-04-06 11174400] S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2012-04-06 343040] S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2012-02-23 95760] S3 HECIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2009-09-17 56344] S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [2010-01-18 75304] S3 TurboBoost;TurboBoost;c:\program files\Intel\TurboBoost\TurboBoost.exe [2009-11-02 126352] S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920] . . Contents of the 'Scheduled Tasks' folder . 2012-07-28 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-21 17:54] . 2012-07-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-09-18 12:05] . 2012-07-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-09-18 12:05] . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2011-09-06 20:45 134384 —-a-w- c:\program files\Alwil Software\Avast5\ashShA64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP] @="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}" [HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}] 2010-02-01 18:06 137584 —-a-w- c:\program files (x86)\EgisTec MyWinLocker\x64\PSDProtect.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "AmIcoSinglun64"="c:\program files (x86)\AmIcoSingLun\AmIcoSinglun64.exe" [2010-02-06 324608] "mwlDaemon"="c:\program files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe" [2010-02-01 349552] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-02-22 10081312] "RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2010-02-22 877600] "SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU] "PLFSetI"="c:\windows\PLFSetI.exe" [2010-04-29 206208] "Acer ePower Management"="c:\program files\Acer\Acer ePower Management\ePowerTray.exe" [2010-03-17 860704] "XboxStat"="c:\program files\Microsoft Xbox 360 Accessories\XboxStat.exe" [2009-09-30 825184] "itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2009-05-21 2342800] "IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2009-05-26 2314120] . ——- Supplementary Scan ——- . uStart Page = uLocal Page = c:\windows\system32\blank.htm mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l;=1009&m;=aspire_7745g&r;=27360910s806l0433z175t5611l293 mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: E&xport; to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000 IE: Google Sidewiki… - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html TCP: DhcpNameServer = 192.168.0.1 TCP: Interfaces\{A60E18E8-E700-4ECD-9E59-2528F1E2D72E}\D616A74616D27657563747: DhcpNameServer = 8.8.8.8 4.2.2.2 FF - ProfilePath - c:\users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\ng8zyz2w.default\ FF - prefs.js: browser.search.selectedEngine - FF - prefs.js: network.proxy.type - 0 . - - - - ORPHANS REMOVED - - - - . Toolbar-Locked - (no file) WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file) . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10e.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10e.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}] @Denied: (A 2) (Everyone) @="IFlashBroker3" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files\Alwil Software\Avast5\AvastSvc.exe c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files (x86)\Bonjour\mDNSResponder.exe c:\program files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe c:\program files (x86)\Cyberlink\Shared files\RichVideo.exe c:\program files (x86)\Epson Software\Event Manager\EEventManager.exe c:\program files (x86)\Launch Manager\LMworker.exe c:\program files (x86)\Seagate\Seagate Dashboard\MemeoDashboard.exe c:\program files (x86)\Seagate\Seagate Dashboard\HipServAgent\HipServAgent.exe . ************************************************************************** . Completion time: 2012-07-27 22:51:18 - machine was rebooted ComboFix-quarantined-files.txt 2012-07-28 04:51 ComboFix2.txt 2012-07-25 23:44 . Pre-Run: 364,821,774,336 bytes free Post-Run: 364,789,702,656 bytes free . - - End Of File - - E527E9E09BA6C1EDE56D9920DD85C3E7 ———————————————————————————————————————————————————————————————————————————————— Malwarebytes Anti-Malware (Trial) 1.62.0.1300 www.malwarebytes.org Database version: v2012.07.28.01 Windows 7 x64 NTFS Internet Explorer 9.0.8112.16421 Nick :: NICK-PC [administrator] Protection: Disabled 27/07/2012 11:33:56 PM mbam-log-2012-07-27 (23-33-56).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 222539 Time elapsed: 3 minute(s), 38 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 2 HKCR\APPID\MightyMagooText.DLL (PUP.MightyMagoo) -> Quarantined and deleted successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MightyMagoo (PUP.MightyMagoo) -> Quarantined and deleted successfully. Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 1 C:\Users\Nick\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed] (PUP.MightyMagoo) -> Quarantined and deleted successfully. Files Detected: 2 C:\Users\Nick\Downloads\setup.exe (PUP.BundleInstaller.VG) -> Quarantined and deleted successfully. C:\Users\Nick\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed]\chrome.manifest (PUP.MightyMagoo) -> Quarantined and deleted successfully. (end) ———————————————————————————————————————————————————————————————————————————————— ESET did not find anything. Everything seems to running great. Browser also seems much faster.
  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :filefind
    *userinit.exe*
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
SystemLook 30.07.11 by jpshortstuff Log created at 14:04 on 29/07/2012 by Nick Administrator - Elevation successful ========== filefind ========== Searching for "*userinit.exe*" C:\Windows\erdnt\cache64\userinit.exe –a—- 30208 bytes [23:42 25/07/2012] [01:39 14/07/2009] 6F8F1376A13114CC10C0E69274F5A4DE C:\Windows\erdnt\cache86\userinit.exe –a—- 26112 bytes [23:42 25/07/2012] [01:14 14/07/2009] 6DE80F60D7DE9CE6B8C2DDFDF79EF175 C:\Windows\System32\userinit.exe –a—- 30208 bytes [23:50 13/07/2009] [01:39 14/07/2009] 6F8F1376A13114CC10C0E69274F5A4DE C:\Windows\System32\en-US\userinit.exe.mui –a—- 3584 bytes [05:35 14/07/2009] [02:26 14/07/2009] 87AE19DA46FE7D5E293937DD36FF1889 C:\Windows\SysWOW64\userinit.exe –a—- 26112 bytes [23:34 13/07/2009] [01:14 14/07/2009] 6DE80F60D7DE9CE6B8C2DDFDF79EF175 C:\Windows\SysWOW64\en-US\userinit.exe.mui –a—- 3584 bytes [05:35 14/07/2009] [02:03 14/07/2009] EA67C653ECFED02D7DBFB889A908CAA9 C:\Windows\winsxs\amd64_microsoft-windows-userinit.resources_31bf3856ad364e35_6.1.7600.16385_en-us_ebe597d2ec03996d\userinit.exe.mui –a—- 3584 bytes [05:35 14/07/2009] [02:26 14/07/2009] 87AE19DA46FE7D5E293937DD36FF1889 C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe –a—- 30208 bytes [23:50 13/07/2009] [01:39 14/07/2009] 6F8F1376A13114CC10C0E69274F5A4DE C:\Windows\winsxs\x86_microsoft-windows-userinit.resources_31bf3856ad364e35_6.1.7600.16385_en-us_8fc6fc4f33a62837\userinit.exe.mui –a—- 3584 bytes [05:35 14/07/2009] [02:03 14/07/2009] EA67C653ECFED02D7DBFB889A908CAA9 C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe –a—- 26112 bytes [23:34 13/07/2009] [01:14 14/07/2009] 6DE80F60D7DE9CE6B8C2DDFDF79EF175 -= EOF =-
COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    Fcopy:: 
    C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe | c:\windows\SysWow64\userinit.exe
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • If you need help to disable your protection programs see here.
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI