This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trojan horse Hider.MPR [Solved]

19 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello.

Today my computer was infected by what AVG identified as "Trojan horse Hider.MPR". The symptoms I have noticed are that it has deleted Malwarebytes and will not let me re-install it, as well as blocking my access to the websites of anti-virus software. Doing a google search I have found that this forum has helped with similar cases recently, and I would highly appreciate help to remove this trojan. I have attached the OTL logs,

Thank you very much in advance.

OTL.exe:

OTL logfile created on: 01/08/2012 11:21:45 - Run 1
OTL by OldTimer - Version 3.2.55.0 Folder = C:\Users\admin\Desktop
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.25 Gb Total Physical Memory | 2.10 Gb Available Physical Memory | 64.60% Memory free
6.50 Gb Paging File | 5.09 Gb Available in Paging File | 78.37% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 345.48 Gb Total Space | 79.44 Gb Free Space | 22.99% Space Free | Partition Type: NTFS
Drive D: | 585.94 Gb Total Space | 76.21 Gb Free Space | 13.01% Space Free | Partition Type: NTFS
Drive E: | 630.48 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive K: | 100.00 Mb Total Space | 61.68 Mb Free Space | 61.68% Space Free | Partition Type: NTFS

Computer Name: ADMIN-PC | User Name: admin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\admin\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Windows\System32\atieclxx.exe (AMD)
PRC - C:\Windows\System32\atiesrxx.exe (AMD)
PRC - C:\Program Files\AVG\AVG10\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe ()
PRC - C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\3\3Connect\BecHelperService.exe ()
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll ()
MOD - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe ()
MOD - C:\Program Files\WinRAR\RarExt.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\de8525cc2e6327337e1c6917352bfe16\WindowsFormsIntegration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\1762137638019a091020b3baf52f6de3\System.Core.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\39f5a71b5185d267b0f55cd4cea26d6b\PresentationFramework.Aero.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\3871fc2b96345aa6f3be81d9e3c97160\System.Web.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\4bdeb88758dccd625f4703ed77aaf348\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\68e5eeb3c6ef18ba2dc1ad70eb74aeee\PresentationFramework.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\fedf1ba58dced4f0b3f8c457648ceed9\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\ead6be8b410d56b5576b10e56af2c180\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\7ce9d463a5d343fe74d6f181f9226cab\UIAutomationProvider.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\7b459c5815af8123e4bf30d4e05bba65\PresentationCore.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\c2f9dd7db911053edcaaadf5fefc500a\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\5dd9f783008543df3e642ff1e99de4e8\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\4b1350e31ff09cc583b34854816d8036\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\5ba3bf5367fc012300c6566f20cb7f54\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\8c1770d45c63cf5c462eeb945ef9aa5d\mscorlib.ni.dll ()


========== Win32 Services (SafeList) ==========

SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (AMD External Events Utility) – C:\Windows\System32\atiesrxx.exe (AMD)
SRV - (Steam Client Service) – C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (avgwd) – C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (SwitchBoard) – C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (BecHelperService) – C:\Program Files\3\3Connect\BecHelperService.exe ()
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) – C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (a5ze59yi) – File not found
DRV - (MBAMSwissArmy) – C:\Windows\System32\drivers\mbamswissarmy.sys (Malwarebytes Corporation)
DRV - (atikmdag) – C:\Windows\System32\drivers\atikmdag.sys (Advanced Micro Devices, Inc.)
DRV - (amdkmdag) – C:\Windows\System32\drivers\atikmdag.sys (Advanced Micro Devices, Inc.)
DRV - (amdkmdap) – C:\Windows\System32\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV - (AtiHDAudioService) – C:\Windows\System32\drivers\AtihdW73.sys (Advanced Micro Devices)
DRV - (AVGIDSDriver) – C:\Windows\System32\drivers\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgtdix) – C:\Windows\System32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) – C:\Windows\System32\drivers\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgmfx86) – C:\Windows\System32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSEH) – C:\Windows\System32\drivers\AVGIDSEH.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSShim) – C:\Windows\System32\drivers\AVGIDSShim.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSFilter) – C:\Windows\System32\drivers\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgldx86) – C:\Windows\System32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (sptd) – C:\Windows\System32\drivers\sptd.sys ()
DRV - (AtiHdmiService) – C:\Windows\System32\drivers\AtiHdmi.sys (ATI Technologies, Inc.)
DRV - (hwdatacard) – C:\Windows\System32\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (vmbus) – C:\Windows\System32\drivers\vmbus.sys (Microsoft Corporation)
DRV - (storflt) – C:\Windows\System32\drivers\vmstorfl.sys (Microsoft Corporation)
DRV - (storvsc) – C:\Windows\System32\drivers\storvsc.sys (Microsoft Corporation)
DRV - (USB_RNDIS) – C:\Windows\System32\drivers\usb8023.sys (Microsoft Corporation)
DRV - (s3cap) – C:\Windows\System32\drivers\vms3cap.sys (Microsoft Corporation)
DRV - (VMBusHID) – C:\Windows\System32\drivers\VMBusHID.sys (Microsoft Corporation)
DRV - (NVENETFD) – C:\Windows\System32\drivers\nvm62x32.sys (NVIDIA Corporation)
DRV - (speedfan) – C:\Windows\System32\speedfan.sys (Windows ® 2000 DDK provider)
DRV - (libusb0) – C:\Windows\System32\drivers\libusb0.sys ()
DRV - (giveio) – C:\Windows\System32\giveio.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://uk.msn.com/?ocid=OIE9HP
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://uk.msn.com/?ocid=OIE9HP
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.startup.homepage: "www.google.com"
FF - prefs.js..extensions.enabledItems: [removed]:3.76
FF - prefs.js..extensions.enabledItems: {9f08cb5a-76b1-4bcf-aff9-90e1a5d60b1e}:3.76
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_3_300_268.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.1: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1: C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.50401.0\npctrl.dll ( Microsoft Corporation)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\admin\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\admin\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG10\Firefox4\ [2012/03/10 10:29:01 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/07/30 20:26:48 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/05/01 10:52:43 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/07/30 20:26:48 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/05/01 10:52:43 | 000,000,000 | —D | M]

[2010/04/18 16:12:25 | 000,000,000 | —D | M] (No name found) – C:\Users\admin\AppData\Roaming\Mozilla\Extensions
[2012/07/27 11:42:18 | 000,000,000 | —D | M] (No name found) – C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\lriehx76.default\extensions
[2010/04/18 17:25:44 | 000,000,000 | —D | M] (Noia 2.0 (eXtreme)) – C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\lriehx76.default\extensions\{9f08cb5a-76b1-4bcf-aff9-90e1a5d60b1e}
[2010/04/18 17:36:03 | 000,000,000 | —D | M] (Noia 2.0 eXtreme OPT) – C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\lriehx76.default\extensions\[removed]
[2011/05/01 10:52:44 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/07/27 11:42:18 | 000,146,901 | —- | M] () (No name found) – C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LRIEHX76.DEFAULT\EXTENSIONS\[removed]
[2012/07/30 20:26:48 | 000,136,672 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/07/30 20:26:46 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/07/30 20:26:46 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - homepage: http://www.google.com
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}sourceid=chrome&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl;={language}&q;={searchTerms}
CHR - homepage: http://www.google.com
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\admin\AppData\Local\Google\Chrome\Application\20.0.1132.57\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.0.50401.0\npctrl.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\admin\AppData\Local\Google\Chrome\Application\20.0.1132.57\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\admin\AppData\Local\Google\Chrome\Application\20.0.1132.57\pdf.dll
CHR - plugin: AVG Internet Security (Enabled) = C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\10.0.0.1409_0\plugins/avgnpss.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Google Update (Enabled) = C:\Users\admin\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin

Hosts file not found
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5.5ServiceManager] "C:\Program Files\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin File not found
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKCU..\Run: [YbaVilmo] C:\Users\admin\AppData\Local\quijxldx\ybavilmo.exe File not found
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware1\mbamgui.exe (Malwarebytes Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
O13 - gopher Prefix: missing
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7D5F0FB2-DDEB-46DB-B0CD-70EF4AD61DB8}: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Users\admin\AppData\Local\Temp\qgxqknlu.exe) - C:\Users\admin\AppData\Local\Temp\qgxqknlu.exe ()
O20 - HKLM Winlogon: UserInit - (C:\Users\admin\AppData\Local\quijxldx\ybavilmo.exe) - C:\Users\admin\AppData\Local\quijxldx\ybavilmo.exe File not found
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 22:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2007/10/03 14:53:35 | 000,000,027 | R— | M] () - E:\AUTORUN.inf – [ CDFS ]
O33 - MountPoints2\{37d8467d-b85a-11dc-a882-0016b6958e71}\Shell - "" = AutoRun
O33 - MountPoints2\{37d8467d-b85a-11dc-a882-0016b6958e71}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{37d84685-b85a-11dc-a882-0016b6958e71}\Shell - "" = AutoRun
O33 - MountPoints2\{37d84685-b85a-11dc-a882-0016b6958e71}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{56e4ea90-bd0c-11e1-a454-0016b6958e71}\Shell - "" = AutoRun
O33 - MountPoints2\{56e4ea90-bd0c-11e1-a454-0016b6958e71}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{8edbe8c9-b8aa-11dc-9c02-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{8edbe8c9-b8aa-11dc-9c02-806e6f6e6963}\Shell\AutoRun\command - "" = E:\start.exe – [2011/05/11 14:22:50 | 005,347,764 | R— | M] ()
O33 - MountPoints2\{c830f1d7-2ed7-11e0-90b1-0016b6958e71}\Shell - "" = AutoRun
O33 - MountPoints2\{c830f1d7-2ed7-11e0-90b1-0016b6958e71}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{c830f1e0-2ed7-11e0-90b1-0016b6958e71}\Shell - "" = AutoRun
O33 - MountPoints2\{c830f1e0-2ed7-11e0-90b1-0016b6958e71}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{c830f1ea-2ed7-11e0-90b1-0016b6958e71}\Shell - "" = AutoRun
O33 - MountPoints2\{c830f1ea-2ed7-11e0-90b1-0016b6958e71}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O35 - HKCU\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.ffds - C:\Program Files\Combined Community Codec Pack\Filters\FFDShow\ff_vfw.dll ()

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/08/01 11:18:03 | 000,597,504 | —- | C] (OldTimer Tools) – C:\Users\admin\Desktop\OTL.exe
[2012/08/01 10:02:53 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware1
[2012/08/01 09:38:49 | 000,040,776 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2012/07/30 11:29:35 | 000,000,000 | —D | C] – C:\Program Files\Empire Total War
[2012/07/29 13:44:05 | 000,000,000 | —D | C] – C:\ProgramData\Sun
[2012/07/29 13:44:04 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2012/07/29 13:43:43 | 000,000,000 | —D | C] – C:\Program Files\Oracle
[2012/07/29 13:43:08 | 000,772,544 | —- | C] (Oracle Corporation) – C:\Windows\System32\npDeployJava1.dll
[2012/07/29 13:43:08 | 000,687,544 | —- | C] (Oracle Corporation) – C:\Windows\System32\deployJava1.dll
[2012/07/29 13:43:08 | 000,227,760 | —- | C] (Oracle Corporation) – C:\Windows\System32\javaws.exe
[2012/07/29 13:43:00 | 000,174,064 | —- | C] (Oracle Corporation) – C:\Windows\System32\javaw.exe
[2012/07/29 13:43:00 | 000,174,064 | —- | C] (Oracle Corporation) – C:\Windows\System32\java.exe
[2012/07/29 13:42:51 | 000,000,000 | —D | C] – C:\Program Files\Java
[2012/07/27 18:34:20 | 000,000,000 | —D | C] – C:\Games
[2012/07/15 15:23:43 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games for Windows Marketplace
[2012/07/14 18:24:39 | 000,000,000 | —D | C] – C:\Users\admin\AppData\Roaming\GFT Global Markets UK
[2012/07/13 20:42:48 | 000,000,000 | —D | C] – C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GFT Global Markets UK
[2012/07/13 20:42:40 | 000,000,000 | —D | C] – C:\Users\admin\AppData\Roaming\InstallShield Installation Information
[2012/07/13 20:42:31 | 000,000,000 | —D | C] – C:\Program Files\DealBook 360
[2012/07/13 20:42:10 | 000,000,000 | —D | C] – C:\Users\admin\Documents\{95EA60FC-B631-470C-98A7-B6EC973B6AA8}
[2012/07/10 17:24:49 | 000,000,000 | —D | C] – C:\Users\admin\AppData\Local\PunkBuster
[2012/07/10 17:23:48 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tom Clancys Ghost Recon Future Soldier
[2012/07/10 16:50:05 | 000,000,000 | —D | C] – C:\Users\admin\AppData\Local\Ubisoft Game Launcher
[2012/07/10 16:50:05 | 000,000,000 | —D | C] – C:\Users\admin\Documents\Ubisoft
[2012/07/05 11:34:52 | 000,000,000 | —D | C] – C:\Users\admin\Desktop\sr-tws2fots3-Mbb
[2012/07/02 22:24:55 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SEGA
[2012/07/02 22:03:00 | 000,000,000 | —D | C] – C:\Program Files\SEGA
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/08/01 11:18:05 | 000,597,504 | —- | M] (OldTimer Tools) – C:\Users\admin\Desktop\OTL.exe
[2012/08/01 11:12:00 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-233920906-1137161095-2195176289-1000UA.job
[2012/08/01 09:43:11 | 000,016,816 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/08/01 09:43:11 | 000,016,816 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/08/01 09:43:02 | 000,040,776 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2012/08/01 09:41:34 | 102,660,437 | —- | M] () – C:\Windows\System32\drivers\AVG\incavi.avm
[2012/08/01 09:41:16 | 000,615,122 | —- | M] () – C:\Windows\System32\perfh009.dat
[2012/08/01 09:41:16 | 000,103,496 | —- | M] () – C:\Windows\System32\perfc009.dat
[2012/08/01 09:35:56 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/08/01 09:35:55 | 2616,635,392 | -HS- | M] () – C:\hiberfil.sys
[2012/08/01 09:35:05 | 000,000,000 | —- | M] () – C:\Users\admin\MS.EXE
[2012/07/31 15:12:00 | 000,000,856 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-233920906-1137161095-2195176289-1000Core.job
[2012/07/31 12:25:41 | 000,001,436 | —- | M] () – C:\Users\admin\Desktop\Empire - Shortcut.lnk
[2012/07/30 20:26:50 | 000,001,990 | —- | M] () – C:\Users\admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/07/29 18:11:15 | 000,300,082 | —- | M] () – C:\Windows\System32\drivers\AVG\iavichjg.avm
[2012/07/29 13:42:52 | 000,174,064 | —- | M] (Oracle Corporation) – C:\Windows\System32\javaw.exe
[2012/07/29 13:42:52 | 000,174,064 | —- | M] (Oracle Corporation) – C:\Windows\System32\java.exe
[2012/07/28 10:14:05 | 000,426,184 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerApp.exe
[2012/07/28 10:14:05 | 000,070,344 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2012/07/15 15:25:00 | 000,002,063 | —- | M] () – C:\Users\Public\Desktop\Street Fighter X Tekken.lnk
[2012/07/13 20:42:48 | 000,001,891 | —- | M] () – C:\Users\admin\Desktop\DealBook 360.lnk
[2012/07/12 23:09:32 | 000,002,397 | —- | M] () – C:\Users\admin\Desktop\Google Chrome.lnk
[2012/07/10 17:26:30 | 000,139,848 | —- | M] () – C:\Windows\System32\drivers\PnkBstrK.sys
[2012/07/10 17:23:48 | 000,001,343 | —- | M] () – C:\Users\Public\Desktop\Tom Clancys Ghost Recon Future Soldier.lnk
[2012/07/10 17:23:48 | 000,001,313 | —- | M] () – C:\Users\Public\Desktop\Launcher.lnk
[2012/07/10 16:20:13 | 005,103,702 | —- | M] () – C:\Users\admin\Desktop\Elder Alexander - Come Into My Trading Room - A Complete Guide To Trading.pdf
[2012/07/05 22:06:48 | 000,227,760 | —- | M] (Oracle Corporation) – C:\Windows\System32\javaws.exe
[2012/07/05 22:06:30 | 000,772,544 | —- | M] (Oracle Corporation) – C:\Windows\System32\npDeployJava1.dll
[2012/07/05 22:06:20 | 000,687,544 | —- | M] (Oracle Corporation) – C:\Windows\System32\deployJava1.dll
[2012/07/02 22:24:57 | 000,002,219 | —- | M] () – C:\Users\Public\Desktop\Total War Shogun 2 - Fall Of The Samurai.lnk
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/08/01 09:34:22 | 000,000,000 | —- | C] () – C:\Users\admin\MS.EXE
[2012/07/31 12:25:41 | 000,001,436 | —- | C] () – C:\Users\admin\Desktop\Empire - Shortcut.lnk
[2012/07/15 15:25:00 | 000,002,063 | —- | C] () – C:\Users\Public\Desktop\Street Fighter X Tekken.lnk
[2012/07/13 20:42:48 | 000,001,891 | —- | C] () – C:\Users\admin\Desktop\DealBook 360.lnk
[2012/07/10 17:23:48 | 000,001,343 | —- | C] () – C:\Users\Public\Desktop\Tom Clancys Ghost Recon Future Soldier.lnk
[2012/07/10 17:23:48 | 000,001,313 | —- | C] () – C:\Users\Public\Desktop\Launcher.lnk
[2012/07/10 16:20:12 | 005,103,702 | —- | C] () – C:\Users\admin\Desktop\Elder Alexander - Come Into My Trading Room - A Complete Guide To Trading.pdf
[2012/07/02 22:24:57 | 000,002,219 | —- | C] () – C:\Users\Public\Desktop\Total War Shogun 2 - Fall Of The Samurai.lnk
[2011/11/10 03:28:32 | 000,204,960 | —- | C] () – C:\Windows\System32\ativvsvl.dat
[2011/11/10 03:28:32 | 000,157,152 | —- | C] () – C:\Windows\System32\ativvsva.dat
[2011/11/09 23:39:44 | 000,059,904 | —- | C] () – C:\Windows\System32\OpenVideo.dll
[2011/11/09 23:39:32 | 000,054,784 | —- | C] () – C:\Windows\System32\OVDecode.dll
[2011/10/21 20:30:14 | 000,243,168 | —- | C] () – C:\Windows\System32\atiicdxx.dat
[2011/09/13 00:06:16 | 000,003,917 | —- | C] () – C:\Windows\System32\atipblag.dat
[2011/05/30 09:45:54 | 000,001,346 | -HS- | C] () – C:\Users\admin\AppData\Local\k53phh05m63xl61w50p78u3805prg
[2011/05/30 09:45:54 | 000,001,346 | -HS- | C] () – C:\ProgramData\k53phh05m63xl61w50p78u3805prg
[2011/05/24 14:55:52 | 000,001,282 | -HS- | C] () – C:\Users\admin\AppData\Local\r5cnhmt1xy5he7n0d7u4763g4srw2d7mjik11wa
[2011/05/24 14:55:52 | 000,001,282 | -HS- | C] () – C:\ProgramData\r5cnhmt1xy5he7n0d7u4763g4srw2d7mjik11wa
[2011/05/04 17:36:27 | 000,033,792 | —- | C] () – C:\Windows\System32\drivers\libusb0.sys
[2011/04/09 18:55:28 | 000,179,261 | —- | C] () – C:\Windows\System32\xlive.dll.cat
[2011/02/07 18:21:29 | 000,139,848 | —- | C] () – C:\Windows\System32\drivers\PnkBstrK.sys
[2011/02/07 18:21:28 | 000,022,328 | —- | C] () – C:\Users\admin\AppData\Roaming\PnkBstrK.sys
[2011/02/07 18:21:05 | 000,282,696 | —- | C] () – C:\Windows\System32\PnkBstrB.exe
[2011/02/07 18:21:04 | 002,337,865 | —- | C] () – C:\Windows\System32\pbsvc.exe
[2011/02/07 18:21:04 | 000,076,888 | —- | C] () – C:\Windows\System32\PnkBstrA.exe
[2011/02/02 15:25:21 | 000,071,259 | —- | C] () – C:\Windows\Huawei ModemsUninstall.exe
[2010/04/24 15:24:45 | 000,007,617 | —- | C] () – C:\Users\admin\AppData\Local\Resmon.ResmonCfg

========== LOP Check ==========

[2010/10/13 17:17:49 | 000,000,000 | —D | M] – C:\Users\admin\AppData\Roaming\AVG10
[2010/04/20 20:44:01 | 000,000,000 | —D | M] – C:\Users\admin\AppData\Roaming\AVG9
[2012/07/31 23:16:30 | 000,000,000 | —D | M] – C:\Users\admin\AppData\Roaming\Azureus
[2012/06/22 22:21:36 | 000,000,000 | —D | M] – C:\Users\admin\AppData\Roaming\Birdstep Technology
[2011/02/02 13:58:04 | 000,000,000 | —D | M] – C:\Users\admin\AppData\Roaming\CCTV
[2010/05/08 13:36:51 | 000,000,000 | —D | M] – C:\Users\admin\AppData\Roaming\DAEMON Tools Lite
[2012/07/14 18:24:39 | 000,000,000 | —D | M] – C:\Users\admin\AppData\Roaming\GFT Global Markets UK
[2011/05/02 12:47:22 | 000,000,000 | —D | M] – C:\Users\admin\AppData\Roaming\Leadertech
[2012/07/28 18:24:44 | 000,000,000 | —D | M] – C:\Users\admin\AppData\Roaming\The Creative Assembly
[2012/07/10 17:24:49 | 000,000,000 | —D | M] – C:\Users\admin\AppData\Roaming\Ubisoft
[2012/01/02 11:58:32 | 000,032,630 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.* >
[2009/06/10 22:42:20 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/06/10 22:42:20 | 000,000,010 | —- | M] () – C:\config.sys
[2012/08/01 09:35:55 | 2616,635,392 | -HS- | M] () – C:\hiberfil.sys
[2012/08/01 09:35:59 | 3488,849,920 | -HS- | M] () – C:\pagefile.sys
[2011/06/07 19:31:38 | 000,067,234 | —- | M] () – C:\TDSSKiller.2.5.4.0_07.06.2011_19.29.43_log.txt
[2011/06/28 11:11:32 | 000,000,412 | —- | M] () – C:\TDSSKiller.2.5.4.0_28.06.2011_11.11.26_log.txt
[2011/06/28 11:12:58 | 000,067,196 | —- | M] () – C:\TDSSKiller.2.5.6.0_28.06.2011_11.12.28_log.txt

< %systemroot%\Fonts\*.com >
[2009/07/14 05:52:25 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 05:52:25 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 05:52:25 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 05:52:25 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 22:31:19 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/07/14 02:15:35 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2003/06/18 18:31:48 | 000,018,944 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\mdippr.dll
[2009/07/14 02:16:19 | 000,029,696 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\winprint.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 05:41:57 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2009/07/14 05:46:35 | 000,000,442 | -HS- | M] () – C:\ProgramData\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/06/15 21:41:42 | 000,000,221 | -HS- | M] () – C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2012/08/01 11:18:05 | 000,597,504 | —- | M] (OldTimer Tools) – C:\Users\admin\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< End of report >

Extras.txt

OTL Extras logfile created on: 01/08/2012 11:21:45 - Run 1
OTL by OldTimer - Version 3.2.55.0 Folder = C:\Users\admin\Desktop
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.25 Gb Total Physical Memory | 2.10 Gb Available Physical Memory | 64.60% Memory free
6.50 Gb Paging File | 5.09 Gb Available in Paging File | 78.37% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 345.48 Gb Total Space | 79.44 Gb Free Space | 22.99% Space Free | Partition Type: NTFS
Drive D: | 585.94 Gb Total Space | 76.21 Gb Free Space | 13.01% Space Free | Partition Type: NTFS
Drive E: | 630.48 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive K: | 100.00 Mb Total Space | 61.68 Mb Free Space | 61.68% Space Free | Partition Type: NTFS

Computer Name: ADMIN-PC | User Name: admin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [Bridge] – C:\Program Files\Adobe\Adobe Bridge CS5.1\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{1056CB0D-C0F2-46B9-ACE6-0C6CB026650B}" = lport=139 | protocol=6 | dir=in | app=system |
"{12CAF737-A6A7-4AE6-A197-BD1709BEBF42}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{30F2C8C2-6D10-4B51-848A-B93404657F7C}" = lport=10243 | protocol=6 | dir=in | app=system |
"{3DAA414F-14EC-4525-8ABF-C0B095B7DFD1}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{449CEC2C-A4B0-4CFD-81F0-E4D2079E0AF1}" = lport=445 | protocol=6 | dir=in | app=system |
"{4C04EA5A-6DA5-46B0-BF45-8C302C8D87D3}" = lport=138 | protocol=17 | dir=in | app=system |
"{510CA54F-DBCF-48F1-9262-8C3A6909FFEF}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{5324B86A-200C-4E4C-AB7C-B03EDCBB8364}" = rport=10243 | protocol=6 | dir=out | app=system |
"{54DEE81B-5C9E-444F-A038-4C82FA073B25}" = rport=138 | protocol=17 | dir=out | app=system |
"{58623E4E-9E2F-4DFA-ACFE-A74E903BD3D8}" = rport=139 | protocol=6 | dir=out | app=system |
"{6DA6FFC7-AF57-4CF4-8DD0-854C1D994EBA}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{7BA58E92-3FC1-40E0-8AD3-C5028535C205}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{8127278E-C08A-4A1C-9200-7AE6F76784C7}" = rport=445 | protocol=6 | dir=out | app=system |
"{841D3A9B-C572-410B-9ADD-EA2E1C74CF22}" = rport=137 | protocol=17 | dir=out | app=system |
"{C1E80AF8-73D3-4B39-A6E1-06B7F0623665}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{C6BE400F-8CC9-4B51-9DDB-D55FDF010E6D}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{D21AC86A-BB03-4F6B-A7E6-6828F0F47FB3}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{D352FE9E-ACE3-4491-83C4-D02272F73A05}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{DAC142F8-F153-4A09-AAE6-E4694538C8C1}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{DD07801B-533B-4C9F-B844-D0969EC51581}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{E72BA4FD-11EF-4EFF-BC57-13DE7988D5FA}" = lport=2869 | protocol=6 | dir=in | app=system |
"{E8C82B5D-B6E9-40CD-A53F-5B1659D70C1E}" = lport=137 | protocol=17 | dir=in | app=system |
"{E96AED15-F984-4F38-95A5-FD34F96E9064}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{00E07A7A-C186-40E6-9B20-810C34EE51DB}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{0696F3C0-409B-4DF9-B47A-65BA696D0652}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{0B687452-9CC6-4D9E-8DD4-B378A7B3C1B6}" = protocol=6 | dir=in | app=c:\program files\electronic arts\crytek\crysis\bin32\crysis.exe |
"{0E599CBC-D4B6-47C8-BCDD-24CB782C0A83}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgnsx.exe |
"{10412460-BF11-424E-90D3-491B3596E79B}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{10D4FA99-DD21-4F89-B5A2-816A7BEBBEE8}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgdiagex.exe |
"{116CA83B-053A-4DB3-9B1A-3CCA00503560}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{14136D7F-9613-4D77-891A-0D50CE0CC761}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{28AA893B-E0B1-44C6-B5BB-D1BECCCC2A22}" = protocol=6 | dir=in | app=c:\program files\vuze\azureus.exe |
"{2934CB79-1BDF-4D16-833A-25C5CF3CA477}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{2B44124B-59DA-4352-A7E3-074A53F3E424}" = protocol=17 | dir=in | app=c:\program files\ubisoft\assassin's creed ii\assassinscreediigame.exe |
"{2DA5E8DF-BFA6-49BF-A1BF-ADE7EB0D8A41}" = protocol=6 | dir=out | app=system |
"{2FD79F93-FC6A-4581-A7D7-9F44197E09FE}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgmfapx.exe |
"{33F8F290-F769-4B93-9A88-D45360E18DCB}" = protocol=17 | dir=in | app=c:\program files\ubisoft\rayman origins\gu.exe |
"{3EAF91A1-C3C9-4C73-B0B7-D3A0DC00B265}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{41DA06DE-DB47-448A-B1E1-D8EA5D43930E}" = protocol=6 | dir=in | app=c:\program files\mass effect 2\binaries\masseffect2.exe |
"{5026F011-51D7-4414-A134-0B36430DADAE}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstrb.exe |
"{562133CD-045C-4FC8-9F48-8A27AC1E1065}" = protocol=17 | dir=in | app=c:\program files\capcom\street fighter x tekken\sftk.exe |
"{580A2934-8B2F-4884-A2A0-EA23D1F9C3A8}" = protocol=6 | dir=in | app=c:\program files\starcraft ii\starcraft ii.exe |
"{5F683CA0-0943-4443-B0E2-CD56A8B0A314}" = protocol=17 | dir=in | app=c:\program files\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe |
"{62BC4610-7AB7-43C3-9BF5-16799114CDF6}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{63EDF1FE-F931-4BED-94F5-9BE7F8D65467}" = protocol=6 | dir=in | app=c:\program files\capcom\street fighter x tekken\sftk.exe |
"{66DCDF5D-724F-49BA-B3A4-EEEF69682AF1}" = protocol=17 | dir=in | app=c:\program files\ubisoft\assassin's creed ii\uplaybrowser.exe |
"{672FC72E-5600-43C2-9E76-FF876485A952}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{6B8E7184-771A-4ACF-84E4-814A5F85AD22}" = protocol=6 | dir=in | app=c:\program files\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe |
"{714A9F3D-6BA1-4314-8352-5B13F90CE878}" = protocol=17 | dir=in | app=c:\program files\electronic arts\crytek\crysis\bin32\crysis.exe |
"{75041B5F-8227-4E8E-9F3C-1D7CB794175E}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{7920A973-6D55-4B97-9F22-312B18275E9C}" = protocol=17 | dir=in | app=c:\program files\steam\steam.exe |
"{7A62DCE8-C783-48FE-BBFF-A313F817C16D}" = protocol=17 | dir=in | app=c:\program files\ubisoft\tom clancy's splinter cell conviction\src\system\conviction_game.exe |
"{81AB85A6-87F8-4950-A331-0FFBFDDA81BA}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstra.exe |
"{81EDB921-90EC-4C6F-98B4-CB4E76AB7EC7}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{8599D214-CC62-406F-AD9C-C48A347DA38B}" = protocol=17 | dir=in | app=c:\program files\starcraft ii\starcraft ii.exe |
"{85C93922-11C8-468A-8730-42C96A61816B}" = protocol=6 | dir=in | app=c:\program files\ubisoft\assassin's creed ii\assassinscreediigame.exe |
"{860FD613-E939-4FDE-A9A1-C1A39C3313E0}" = protocol=17 | dir=in | app=c:\program files\ubisoft\tom clancy's rainbow six vegas 2\binaries\r6vegas2_game.exe |
"{8A835190-3A22-4D8A-9239-DD76ACF9FF51}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgmfapx.exe |
"{8ADDC0CE-74DC-4675-B53B-0CA466B4EA96}" = protocol=6 | dir=in | app=c:\program files\ubisoft\rayman origins\rayman origins.exe |
"{935CD21E-4285-4CCC-A1DA-B5398A4BF5C1}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{94C675B1-B18D-4532-BE1B-3289B02CEA10}" = protocol=6 | dir=in | app=c:\program files\eidos\batman arkham asylum\binaries\shippingpc-bmgame.exe |
"{9870AE7E-AEB6-4BE1-8EA6-49136DF061B2}" = protocol=17 | dir=in | app=c:\program files\mass effect 2\masseffect2launcher.exe |
"{9E14572C-240A-425C-8D57-3AF9D9ABD757}" = protocol=6 | dir=in | app=c:\program files\mass effect 2\masseffect2launcher.exe |
"{9EBC1499-3E2D-4DC9-87CF-7A16F3D5FF82}" = protocol=17 | dir=in | app=c:\program files\ubisoft\tom clancy's splinter cell conviction\src\system\gu.exe |
"{A7560770-3521-4CDC-8A49-BD2E98A1006F}" = protocol=6 | dir=in | app=c:\program files\ubisoft\tom clancy's splinter cell conviction\src\system\gu.exe |
"{ADC3B086-C149-46FE-B14E-6D1A695D33A5}" = dir=in | app=c:\program files\windows live\contacts\wlcomm.exe |
"{B002EC54-42B0-4A8E-B05E-17567EF3FB77}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgdiagex.exe |
"{B2300AC7-7FC2-4DE0-905F-DC7341C4CC7D}" = protocol=6 | dir=in | app=c:\program files\ubisoft\rayman origins\gu.exe |
"{B2E736BB-26E8-416F-8178-ACB6FD00F635}" = protocol=17 | dir=in | app=c:\program files\electronic arts\crytek\crysis\bin32\crysisdedicatedserver.exe |
"{B6C908E2-69E7-43FC-A0EF-B65857E66A1C}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgnsx.exe |
"{B797A13E-EFE0-44BE-91A0-962BDAF35533}" = protocol=6 | dir=in | app=c:\program files\ubisoft\assassin's creed ii\assassinscreedii.exe |
"{B897FA9B-F43F-462C-924E-6397A7FC0864}" = protocol=17 | dir=in | app=c:\program files\capcom\streetfighteriv\streetfighteriv.exe |
"{BD2A84FF-40A2-472F-8C25-40FA3CB48997}" = protocol=17 | dir=in | app=c:\program files\ubisoft\assassin's creed ii\assassinscreedii.exe |
"{BF0FC106-49C1-4731-BA7E-EBA3FD51D73A}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{C13FF132-E542-4454-B38C-056521C28DE5}" = protocol=6 | dir=in | app=c:\program files\ubisoft\tom clancy's splinter cell conviction\src\system\conviction_game.exe |
"{C3E8BBD2-F90A-4434-93D3-ABB27A09EE9A}" = protocol=17 | dir=in | app=c:\program files\mass effect 2\binaries\masseffect2.exe |
"{C56F79D7-0AF1-4FE7-BE29-28296F8EAF0A}" = protocol=17 | dir=in | app=c:\program files\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe |
"{C5863203-694F-4945-8640-6C1F3E600B39}" = protocol=17 | dir=in | app=c:\program files\ubisoft\tom clancy's rainbow six vegas 2\binaries\r6vegas2_launcher.exe |
"{CC01AFB4-380B-4DB6-B0C5-9A13D3715937}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstra.exe |
"{CDB12467-93B8-432B-BE35-C7285FD68200}" = protocol=6 | dir=in | app=c:\program files\ubisoft\assassin's creed ii\uplaybrowser.exe |
"{CE6A0E3D-D0F3-4715-B4E3-04E9C0821A9F}" = protocol=6 | dir=in | app=c:\program files\ubisoft\tom clancy's rainbow six vegas 2\binaries\r6vegas2_game.exe |
"{D32F7042-897C-4304-B83D-EF198B329BE2}" = protocol=6 | dir=in | app=c:\program files\steam\steam.exe |
"{D565F38C-2B28-4450-B56C-61BD612111E2}" = protocol=6 | dir=in | app=c:\program files\electronic arts\crytek\crysis\bin32\crysisdedicatedserver.exe |
"{D6B39834-B149-4FB8-935E-3E63D4F09B08}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgemcx.exe |
"{D7964361-3D26-40B0-93AC-DFC76028A6DC}" = protocol=17 | dir=in | app=c:\program files\vuze\azureus.exe |
"{D827F8DC-05EB-489C-A368-4A9A75AC8C7E}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgemcx.exe |
"{D8D41E5C-6CF3-4CC6-A4EC-501E3A4F5726}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{D93801CC-E7B7-4895-AD46-EEA634653A80}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{DDC2800E-CCC3-4739-947A-B744C2448B22}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{ED6F2645-BF4F-495D-B3D8-D4560B959D80}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstrb.exe |
"{EE1852D1-16DF-4F52-B7E8-E51A23969BBA}" = protocol=17 | dir=in | app=c:\program files\eidos\batman arkham asylum\binaries\shippingpc-bmgame.exe |
"{F28BC803-5C9E-4C08-8B07-0C9380E49E2A}" = protocol=17 | dir=in | app=c:\program files\ubisoft\rayman origins\rayman origins.exe |
"{F50D1A4A-1F4B-4AB2-B5AF-CDF263D3EAE1}" = protocol=6 | dir=in | app=c:\program files\capcom\streetfighteriv\streetfighteriv.exe |
"{F8B9E5E9-0564-444F-9393-181B32145FAB}" = protocol=6 | dir=in | app=c:\program files\ubisoft\tom clancy's rainbow six vegas 2\binaries\r6vegas2_launcher.exe |
"{FC190340-3864-46D3-8231-93EF08C44BFB}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{FFEBC032-CF89-42BE-B22B-96F952A30E20}" = protocol=6 | dir=in | app=c:\program files\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe |
"TCP Query User{025A34BE-9AE8-445B-8AB3-8BDCB9F74055}C:\users\admin\documents\resident evil 5\re5dx9.exe" = protocol=6 | dir=in | app=c:\users\admin\documents\resident evil 5\re5dx9.exe |
"TCP Query User{14ADF898-EED2-4342-A031-FBA2A0A476C1}C:\program files\vuze\azureus.exe" = protocol=6 | dir=in | app=c:\program files\vuze\azureus.exe |
"TCP Query User{2ACDF48F-C17E-49E3-92E8-DF2DBFFBAA68}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"TCP Query User{3F6646F5-ACC0-4A2C-9C6A-63E89CD5E399}C:\program files\mozilla firefox\plugin-container.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\plugin-container.exe |
"TCP Query User{47C42166-CF51-437D-8E13-8EE8894FFB79}C:\program files\electronic arts\crytek\crysis 2\bin32\crysis2.exe" = protocol=6 | dir=in | app=c:\program files\electronic arts\crytek\crysis 2\bin32\crysis2.exe |
"TCP Query User{47EE4EB6-85E6-41D0-85EA-4884A3CDD8D4}C:\program files\starcraft ii\versions\base15405\sc2.exe" = protocol=6 | dir=in | app=c:\program files\starcraft ii\versions\base15405\sc2.exe |
"TCP Query User{5F8B4855-23DE-4E88-9E42-D67C06A42301}C:\program files\valve\portal 2\portal2.exe" = protocol=6 | dir=in | app=c:\program files\valve\portal 2\portal2.exe |
"TCP Query User{7896C5EA-E6BE-43C5-A2BD-B9C0AAF198D2}C:\users\admin\documents\resident evil 5\re5dx10.exe" = protocol=6 | dir=in | app=c:\users\admin\documents\resident evil 5\re5dx10.exe |
"TCP Query User{80998376-9A59-4C4E-93DE-D853CBAF4321}C:\program files\2k games\gearbox software\borderlands\binaries\borderlands.exe" = protocol=6 | dir=in | app=c:\program files\2k games\gearbox software\borderlands\binaries\borderlands.exe |
"TCP Query User{8C38BC70-E552-4239-AD30-A6833BBF5DC8}C:\program files\starcraft ii\support\blizzarddownloader.exe" = protocol=6 | dir=in | app=c:\program files\starcraft ii\support\blizzarddownloader.exe |
"TCP Query User{9A6EBCA0-9C95-4175-A104-BB0F5A95421A}C:\program files\black_box\batman arkham city\binaries\win32\batmanac.exe" = protocol=6 | dir=in | app=c:\program files\black_box\batman arkham city\binaries\win32\batmanac.exe |
"TCP Query User{9E8DA122-3DD8-4353-9398-37D075A766BD}C:\program files\ubisoft\tom clancy's rainbow six vegas 2\binaries\r6vegas2_game.exe" = protocol=6 | dir=in | app=c:\program files\ubisoft\tom clancy's rainbow six vegas 2\binaries\r6vegas2_game.exe |
"TCP Query User{A78973E4-31E7-4652-8B5C-7603289B4060}C:\program files\steam\steamapps\anaccident93\team fortress 2\hl2.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\anaccident93\team fortress 2\hl2.exe |
"TCP Query User{D44B9326-429D-4F0B-A924-2227AFFDCEE3}C:\program files\ea sports\fifa 11\game\fifa.exe" = protocol=6 | dir=in | app=c:\program files\ea sports\fifa 11\game\fifa.exe |
"TCP Query User{EAE209E3-5E87-4BE6-9D3F-DBF55E3A4D7B}C:\program files\black_box\tom clancys ghost recon future soldier\future soldier.exe" = protocol=6 | dir=in | app=c:\program files\black_box\tom clancys ghost recon future soldier\future soldier.exe |
"UDP Query User{02AD098D-BC81-4C71-A6E6-9B85F48275DB}C:\users\admin\documents\resident evil 5\re5dx10.exe" = protocol=17 | dir=in | app=c:\users\admin\documents\resident evil 5\re5dx10.exe |
"UDP Query User{0983756F-324D-4527-BE7A-6DF37CFF4772}C:\users\admin\documents\resident evil 5\re5dx9.exe" = protocol=17 | dir=in | app=c:\users\admin\documents\resident evil 5\re5dx9.exe |
"UDP Query User{2F16EAF8-4B06-4B27-B4AE-02900A1B2609}C:\program files\black_box\batman arkham city\binaries\win32\batmanac.exe" = protocol=17 | dir=in | app=c:\program files\black_box\batman arkham city\binaries\win32\batmanac.exe |
"UDP Query User{4C84F035-97E4-402D-8499-19373FC163FD}C:\program files\starcraft ii\support\blizzarddownloader.exe" = protocol=17 | dir=in | app=c:\program files\starcraft ii\support\blizzarddownloader.exe |
"UDP Query User{5AFB2399-06C7-49D7-9EBA-D54E002BE3FA}C:\program files\vuze\azureus.exe" = protocol=17 | dir=in | app=c:\program files\vuze\azureus.exe |
"UDP Query User{5DFB4BA0-B15A-4C26-A95D-CAEC661C940D}C:\program files\ubisoft\tom clancy's rainbow six vegas 2\binaries\r6vegas2_game.exe" = protocol=17 | dir=in | app=c:\program files\ubisoft\tom clancy's rainbow six vegas 2\binaries\r6vegas2_game.exe |
"UDP Query User{6E04B303-8DA7-4D48-8A84-B1BC67CAB2D6}C:\program files\steam\steamapps\anaccident93\team fortress 2\hl2.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\anaccident93\team fortress 2\hl2.exe |
"UDP Query User{78EE6AF0-738B-46C8-856B-C3550D6D6BB8}C:\program files\valve\portal 2\portal2.exe" = protocol=17 | dir=in | app=c:\program files\valve\portal 2\portal2.exe |
"UDP Query User{8B041094-BFEA-49C9-8DEF-138D8D37EDEB}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"UDP Query User{8E90A9C8-02C5-4A2B-99EE-8C004D7BC98C}C:\program files\starcraft ii\versions\base15405\sc2.exe" = protocol=17 | dir=in | app=c:\program files\starcraft ii\versions\base15405\sc2.exe |
"UDP Query User{B7084028-A329-4CE8-ADA3-784BA9380A35}C:\program files\mozilla firefox\plugin-container.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\plugin-container.exe |
"UDP Query User{B9914264-F849-4EE7-87CC-C77539F1A53A}C:\program files\ea sports\fifa 11\game\fifa.exe" = protocol=17 | dir=in | app=c:\program files\ea sports\fifa 11\game\fifa.exe |
"UDP Query User{D07FD94F-7A83-4E81-A2EC-5E9B625B0BAE}C:\program files\black_box\tom clancys ghost recon future soldier\future soldier.exe" = protocol=17 | dir=in | app=c:\program files\black_box\tom clancys ghost recon future soldier\future soldier.exe |
"UDP Query User{E76FCC47-A761-4338-8B96-65E0A1CF07D6}C:\program files\2k games\gearbox software\borderlands\binaries\borderlands.exe" = protocol=17 | dir=in | app=c:\program files\2k games\gearbox software\borderlands\binaries\borderlands.exe |
"UDP Query User{E9BFC136-F593-4E3D-88C0-D7AE0CEAA5D1}C:\program files\electronic arts\crytek\crysis 2\bin32\crysis2.exe" = protocol=17 | dir=in | app=c:\program files\electronic arts\crytek\crysis 2\bin32\crysis2.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{000E79B7-E725-4F01-870A-C12942B7F8E4}" = Crysis®
"{0215A652-E081-4B09-9333-DC85AAB67FFA}" = Adobe Dreamweaver CS5.5
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{05CAF469-9765-8FBF-10AD-FD621091824A}" = CCC Help English
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{1111706F-666A-4037-7777-211328764D10}" = JavaFX 2.1.1
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{26A24AE4-039D-4CA4-87B4-2F83217005FF}" = Java™ 7 Update 5
"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
"{2ECA81CA-D932-4AD3-AD59-BF5CCF099C83}" = Catalyst Control Center - Branding
"{3521BDBD-D453-5D9F-AA55-44B75D214629}" = Adobe Community Help
"{3FEA6CD1-EA13-4CE7-A74E-A74A4A0A7B5C}" = FIFA 11
"{43430FA5-AF68-4A2D-A7D4-891000008200}" = Street Fighter X Tekken
"{46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB}" = Adobe AIR
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CB0307C-565E-4441-86BE-0DF2E4FB828C}" = Microsoft Games for Windows Marketplace
"{4E1D0591-14F7-736E-143A-62DC3E552A1A}" = Catalyst Control Center InstallProxy
"{4E79A60F-15D2-4BEC-91AD-E41EC42E61B0}" = Batman: Arkham Asylum
"{52B65911-1559-4ED5-9461-46957FDD48CD}" = Borderlands
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{59ABBDF0-E1E5-48AF-85FB-F523A08C3490}" = STREET FIGHTER IV
"{6033673D-2530-4587-8AD0-EB059FC263F9}" = Crysis® 2
"{629F65FB-7F3C-4D66-A1C0-20722744B7B6}" = Star Wars® Knights of the Old Republic® II: The Sith Lords™
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6D87CAD9-9B94-4421-A439-B25F8DE14575}" = Tom Clancy's Ghost Recon Future Soldier
"{6D8DDB4A-C263-40DE-BA16-AFDAD159D59A}" = Tom Clancy's Splinter Cell Conviction
"{6F64A42C-6D93-6788-EB4F-07CC066DE194}" = Catalyst Control Center Graphics Previews Common
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{75D84EF7-0D8C-4e70-B3FA-7B42A5D4E0EB}" = Mass Effect 2
"{75D84EF7-0D8C-4e70-TCGRFS-7B42A5D4E0EB}_is1" = Tom Clancys Ghost Recon Future Soldier version 1.02
"{76D1FBEB-FBBF-0D1E-BB0A-CAA0D19E2C7F}" = ccc-utility
"{7B9CC60A-9B81-46A3-A953-76B6BF9EEC97}" = Age of Empires III
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{8570BEE8-0CA3-4977-9AB1-80ED93F0513C}" = Assassin's Creed II
"{888F1505-C2B3-4FDE-835D-36353EBD4754}" = Ubisoft Game Launcher
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8ACC73AA-6511-7C55-B1A9-8E5D1DEAFAA3}" = The Lord of the Rings FREE Trial
"{8B7IL77L-LKS1-AC3-BATAC-18CD6E6334R1}_is1" = Batman Arkham City version 1.0
"{8D8B8115-40C1-A707-B7DA-599514076A81}" = Catalyst Control Center
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{9158FF30-78D7-40EF-B83E-451AC5334640}" = Adobe Photoshop CS5.1
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A25FF1C0-80B6-4B8B-A551-DC525697A408}" = AMD APP SDK Runtime
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{A899DA1F-D626-401C-8651-F2921E3B4CB3}" = 3Connect
"{A942958E-AF92-7901-861B-7F373A1B6ABA}" = AMD Catalyst Install Manager
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5
"{AC76BA86-7AD7-1033-7B44-A90000000001}" = Adobe Reader 9
"{B6D38690-755E-4F40-A35A-23F8BC2B86AC}" = Microsoft_VC90_MFCLOC_x86
"{B7F293A4-8666-6410-36F4-E47EB2029CCB}" = AMD Drag and Drop Transcoding
"{BDE646E8-86E0-50E1-37BC-0AEBB2185D76}" = Adobe Widget Browser
"{C5C1C0F0-D62F-4DBF-81D4-D7EF397C228B}" = NVIDIA PhysX
"{C6150D8A-86ED-41D3-87BB-F3BB51B0B77F}" = Windows Live ID Sign-in Assistant
"{C7DEE429-4C9B-4126-894F-50B4F54FF196}" = inSSIDer
"{C7EEF2B9-8C16-4A04-B98D-B1A952A47E55}" = Linksys Wireless-G USB Network Adapter
"{C8FC7066-4457-4365-9BDF-4E439BF703C8}" = AVG 2011
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{DDD9B4E6-EEB7-4030-B141-F0E0C5429851}" = YVD
"{DE491AB9-1D47-4FED-A8F5-4D4325B2EB4B}" = Rayman Origins
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E533E637-FB3E-4F28-8B18-449CC9AB7235}" = AVG 2011
"{E56B8E1D-8E90-46DC-AE55-EBA87ED69A5F}" = DealBook 360
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F2508213-9989-4E85-A078-72BE483917EF}" = Microsoft Games for Windows - LIVE Redistributable
"{F48756D1-A348-2DA5-B59B-DF39F293F750}" = AMD Media Foundation Decoders
"{FD416706-875C-4B0B-A23A-9E740DAE029E}" = Tom Clancy's Rainbow Six Vegas 2
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"8461-7759-5462-8226" = Vuze
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"AVG" = AVG 2011
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"com.adobe.WidgetBrowser.E7BED6E5DDA59983786DD72EBFA46B1598278E07.1" = Adobe Widget Browser
"Combined Community Codec Pack_is1" = Combined Community Codec Pack 2009-09-09
"Comical_is1" = Comical 0.8
"Crusader Kings II_is1" = Crusader Kings II
"DirectVobSub" = DirectVobSub (remove only)
"Driving Theory Test Professional v3.0.0.0_is1" = Driving Theory Test Professional v3.0.0.0
"EVEREST Ultimate Edition_is1" = EVEREST Ultimate Edition v5.50
"Huawei Modems" = Huawei modem
"InstallShield_{7B9CC60A-9B81-46A3-A953-76B6BF9EEC97}" = Age of Empires III
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.62.0.1300
"Mozilla Firefox 14.0.1 (x86 en-US)" = Mozilla Firefox 14.0.1 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"Postal 2_is1" = Portal 2
"PunkBusterSvc" = PunkBuster Services
"SpeedFan" = SpeedFan (remove only)
"StarCraft II" = StarCraft II
"Steam App 440" = Team Fortress 2
"Total War Shogun 2 - Fall Of The Samurai_is1" = Total War Shogun 2 - Fall Of The Samurai
"VLC media player" = VLC media player 1.1.5
"WinDjView" = WinDjView 1.0.3
"WinLiveSuite" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"CCTVPlayer" = CCTV Player Uninstall
"Google Chrome" = Google Chrome
"InstallShield_{E56B8E1D-8E90-46DC-AE55-EBA87ED69A5F}" = DealBook 360

[ System Events ]
Error - 01/08/2012 04:36:05 | Computer Name = admin-PC | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = There was an error while attempting to read the local hosts file.

Error - 01/08/2012 04:36:07 | Computer Name = admin-PC | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = There was an error while attempting to read the local hosts file.

Error - 01/08/2012 04:36:10 | Computer Name = admin-PC | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = There was an error while attempting to read the local hosts file.

Error - 01/08/2012 04:36:17 | Computer Name = admin-PC | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = There was an error while attempting to read the local hosts file.

Error - 01/08/2012 04:42:59 | Computer Name = admin-PC | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = There was an error while attempting to read the local hosts file.

Error - 01/08/2012 04:43:31 | Computer Name = admin-PC | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = There was an error while attempting to read the local hosts file.

Error - 01/08/2012 04:43:33 | Computer Name = admin-PC | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = There was an error while attempting to read the local hosts file.

Error - 01/08/2012 04:43:34 | Computer Name = admin-PC | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = There was an error while attempting to read the local hosts file.

Error - 01/08/2012 05:55:02 | Computer Name = admin-PC | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = There was an error while attempting to read the local hosts file.

Error - 01/08/2012 06:13:24 | Computer Name = admin-PC | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = There was an error while attempting to read the local hosts file.


< End of report >
:welcome:

You need to go to a know clean computer and download Malwarebytes , transfer it to a flash drive or CD and install it on the infected computer, although I still see parts of it installed. Download and install it and if it wont run then follow the instructions for Chameleon



Please download Malwarebytes from Here or Here

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the report please





Running Malwarebytes using Chameleon


Go to Start > All Programs> Malwarebytes Antimalware > Tools > Malwarebytes Antimalware Chameleon and it will take you to this page
[external image: Posted Image]

Then click on the first link to run Malwarebytes and if wont run try the next one until one of them runs
Hi Ken, thanks for helping. This morning I tried to run Malwarebytes but I think it was suddenly deleted mid-scan by an virus. AVG caused some problems with re-installing but I managed to get it re-installed and managed to run it through Chameleon. I believe the problem still isn't over as Google Chrome still closes itself as soon as I open it. Here is the log: Malwarebytes Anti-Malware 1.62.0.1300 www.malwarebytes.org Database version: v2012.08.01.08 Windows 7 x86 NTFS Internet Explorer 9.0.8112.16421 admin :: ADMIN-PC [administrator] 01/08/2012 22:45:21 mbam-log-2012-08-01 (22-45-21).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 188153 Time elapsed: 6 minute(s), 5 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 1 HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON|Userinit (Hijack.Userinit) -> Bad: (C:\Windows\system32\userinit.exe,,C:\Users\admin\AppData\Local\Temp\qgxqknlu.exe,C:\Users\admin\AppData\Local\quijxldx\ybavilmo.exe) Good: (userinit.exe) -> Quarantined and repaired successfully. Folders Detected: 0 (No malicious items detected) Files Detected: 1 C:\Users\admin\MS.EXE (Trojan.Agent) -> Quarantined and deleted successfully. (end)
Great


Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
I ran combo fix and it mentioned deleting several files on the command prompt. It rebooted my PC but upon turning itself back on I got a blue screen. As a result Combofix did not produce a log. The problem appears not to have been cleared. Should I run Combofix again in hope of getting a log?
No, no need to run it . Have you checked here for a log C:\ComboFix.txt


ESET Online Scanner
I'd like us to scan your machine with ESET OnlineScan

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the [external image: Posted Image] button.
  • Push [external image: Posted Image]
Please make sure you include the following items in your next post:
The log that was produced after running ESET Online Scanner.
Ken, there isn't a log for Combofix in that directory. I also can't follow the next instructions as: 1) The ESET Online Scanner page is one of the many anti-malware websites that are blocked on all browsers by this infection, so I get a "page cannot be displayed". 2) I downloaded the installer from another computer and copied it over. However when I run it and press start (step 5) it tells me "Can not get update. Is proxy configured?" AVG has been disabled so I'm not sure what the problem is. Thanks.
Go ahead and run Combofix again, but drag your copy to the trash and download a fresh updated copy


Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
I've tried ComboFix a further two times but each time it finishes the scan, says it deleted some files, reboots, and almost immediately after getting to the desktop I get a blue screen. I don't manage to get a log. Any suggestions? It always seems to delete the files in the AppData/Local/temp folder, and now I can see a suspicious .exe, .dll and some .txt s in that folder. Would deleting them manually help?
Lets check for a rootkit

Download aswMBR.exe ( 511KB ) to your desktop.

Double click the aswMBR.exe to run it

Click the "Scan" button to start scan
[external image: Posted Image]

On completion of the scan click save log, save it to your desktop and post in your next reply
[external image: Posted Image]
It asked if I wanted to install Avast Antivirus. I clicked no, but let me know if I should have chosen otherwise. aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software Run date: 2012-08-02 18:45:28 —————————– 18:45:28.841 OS Version: Windows 6.1.7600 18:45:28.841 Number of processors: 4 586 0x170A 18:45:28.841 ComputerName: ADMIN-PC UserName: admin 18:45:30.198 Initialize success 18:46:15.096 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000070 18:46:15.096 Disk 0 Vendor: Hitachi_ JP4O Size: 953869MB BusType: 8 18:46:15.112 Disk 0 MBR read successfully 18:46:15.112 Disk 0 MBR scan 18:46:15.112 Disk 0 Windows 7 default MBR code 18:46:15.112 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048 18:46:15.128 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 353768 MB offset 206848 18:46:15.143 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 599999 MB offset 724723712 18:46:15.143 Disk 0 scanning sectors +1953521664 18:46:15.190 Disk 0 scanning C:\Windows\system32\drivers 18:46:18.606 Service scanning 18:46:24.924 Service sptd C:\Windows\System32\Drivers\sptd.sys **LOCKED** 32 18:46:27.810 Modules scanning 18:46:34.534 Disk 0 trace - called modules: 18:46:34.550 ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x9db5e1f8]<< 18:46:34.565 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x9eb78030] 18:46:34.565 3 CLASSPNP.SYS[a4a9c59e] -> nt!IofCallDriver -> \Device\00000070[0x9db06c78] 18:46:34.565 \Driver\nvstor[0x9e897850] -> IRP_MJ_CREATE -> 0x9db5e1f8 18:46:34.581 Scan finished successfully 18:46:53.394 Disk 0 MBR has been saved successfully to "C:\Users\admin\Desktop\MBR.dat" 18:46:53.394 The log file has been saved successfully to "C:\Users\admin\Desktop\aswMBR.txt"
Looks ok


Open OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :processes
    killallprocesses
    
    :OTL
    O4 - HKCU..\Run: [YbaVilmo] C:\Users\admin\AppData\Local\quijxldx\ybavilmo.exe File not found
    O20 - HKLM Winlogon: UserInit - (C:\Users\admin\AppData\Local\Temp\qgxqknlu.exe) - C:\Users\admin\AppData\Local\Temp\qgxqknlu.exe ()
    O20 - HKLM Winlogon: UserInit - (C:\Users\admin\AppData\Local\quijxldx\ybavilmo.exe) - C:\Users\admin\AppData\Local\quijxldx\ybavilmo.exe File not found
    
    
    :Services
    
    :Reg
    
    :Files
    ipconfig /flushdns /c
    
    
    :Commands
    [purity]
    [resethosts]
    [CLEARALLRESTOREPOINTS]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top. <–Not run Scan
  • Let the program run unhindered, reboot when it is done
  • Then post the results of the log it produces

Then run OTL again to scan and post a new log please
The file qgxqknlu.exe keeps coming back after deletion I think.

Fix Log:
All processes killed
========== PROCESSES ==========
========== OTL ==========
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\YbaVilmo deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Users\admin\AppData\Local\Temp\qgxqknlu.exe deleted successfully.
C:\Users\admin\AppData\Local\temp\qgxqknlu.exe moved successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Users\admin\AppData\Local\quijxldx\ybavilmo.exe deleted successfully.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\admin\Desktop\cmd.bat deleted successfully.
C:\Users\admin\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
Restore point Set: OTL Restore Point

[EMPTYTEMP]

User: admin
->Temp folder emptied: 294537 bytes
->Temporary Internet Files folder emptied: 2708218670 bytes
->Java cache emptied: 51168 bytes
->FireFox cache emptied: 104114185 bytes
->Google Chrome cache emptied: 12831105 bytes
->Flash cache emptied: 124469 bytes

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 56502 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 155648 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 356 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 37756815 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 2,731.00 mb


OTL by OldTimer - Version 3.2.55.0 log created on 08032012_101432

Files\Folders moved on Reboot…

PendingFileRenameOperations files…

Registry entries deleted on Reboot…

Scan log:

OTL logfile created on: 03/08/2012 10:23:59 - Run 2
OTL by OldTimer - Version 3.2.55.0 Folder = C:\Users\admin\Desktop
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.25 Gb Total Physical Memory | 2.29 Gb Available Physical Memory | 70.48% Memory free
6.50 Gb Paging File | 5.40 Gb Available in Paging File | 83.18% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 345.48 Gb Total Space | 89.51 Gb Free Space | 25.91% Space Free | Partition Type: NTFS
Drive D: | 585.94 Gb Total Space | 76.00 Gb Free Space | 12.97% Space Free | Partition Type: NTFS
Drive E: | 630.48 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive K: | 100.00 Mb Total Space | 61.68 Mb Free Space | 61.68% Space Free | Partition Type: NTFS

Computer Name: ADMIN-PC | User Name: admin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\admin\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Windows\System32\atieclxx.exe (AMD)
PRC - C:\Windows\System32\atiesrxx.exe (AMD)
PRC - C:\Program Files\AVG\AVG10\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe ()
PRC - C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\3\3Connect\BecHelperService.exe ()
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll ()
MOD - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\de8525cc2e6327337e1c6917352bfe16\WindowsFormsIntegration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\1762137638019a091020b3baf52f6de3\System.Core.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\39f5a71b5185d267b0f55cd4cea26d6b\PresentationFramework.Aero.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\3871fc2b96345aa6f3be81d9e3c97160\System.Web.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\4bdeb88758dccd625f4703ed77aaf348\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\68e5eeb3c6ef18ba2dc1ad70eb74aeee\PresentationFramework.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\fedf1ba58dced4f0b3f8c457648ceed9\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\ead6be8b410d56b5576b10e56af2c180\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\7ce9d463a5d343fe74d6f181f9226cab\UIAutomationProvider.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\7b459c5815af8123e4bf30d4e05bba65\PresentationCore.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\c2f9dd7db911053edcaaadf5fefc500a\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\5dd9f783008543df3e642ff1e99de4e8\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\4b1350e31ff09cc583b34854816d8036\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\5ba3bf5367fc012300c6566f20cb7f54\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\8c1770d45c63cf5c462eeb945ef9aa5d\mscorlib.ni.dll ()


========== Win32 Services (SafeList) ==========

SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (AMD External Events Utility) – C:\Windows\System32\atiesrxx.exe (AMD)
SRV - (Steam Client Service) – C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (avgwd) – C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (SwitchBoard) – C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (BecHelperService) – C:\Program Files\3\3Connect\BecHelperService.exe ()
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) – C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (Micorsoft Windows Service) – C:\Users\admin\AppData\Local\Temp\gmbdilfb.sys File not found
DRV - (catchme) – C:\Users\admin\AppData\Local\Temp\catchme.sys File not found
DRV - (aju8w7g2) – File not found
DRV - (AtiHDAudioService) – C:\Windows\System32\drivers\AtihdW73.sys (Advanced Micro Devices)
DRV - (atikmdag) – C:\Windows\System32\drivers\atikmdag.sys (Advanced Micro Devices, Inc.)
DRV - (amdkmdag) – C:\Windows\System32\drivers\atikmdag.sys (Advanced Micro Devices, Inc.)
DRV - (amdkmdap) – C:\Windows\System32\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV - (AVGIDSDriver) – C:\Windows\System32\drivers\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgtdix) – C:\Windows\System32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) – C:\Windows\System32\drivers\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgmfx86) – C:\Windows\System32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSEH) – C:\Windows\System32\drivers\AVGIDSEH.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSShim) – C:\Windows\System32\drivers\AVGIDSShim.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSFilter) – C:\Windows\System32\drivers\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgldx86) – C:\Windows\System32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (sptd) – C:\Windows\System32\drivers\sptd.sys ()
DRV - (AtiHdmiService) – C:\Windows\System32\drivers\AtiHdmi.sys (ATI Technologies, Inc.)
DRV - (hwdatacard) – C:\Windows\System32\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (vmbus) – C:\Windows\System32\drivers\vmbus.sys (Microsoft Corporation)
DRV - (storflt) – C:\Windows\System32\drivers\vmstorfl.sys (Microsoft Corporation)
DRV - (storvsc) – C:\Windows\System32\drivers\storvsc.sys (Microsoft Corporation)
DRV - (USB_RNDIS) – C:\Windows\System32\drivers\usb8023.sys (Microsoft Corporation)
DRV - (s3cap) – C:\Windows\System32\drivers\vms3cap.sys (Microsoft Corporation)
DRV - (VMBusHID) – C:\Windows\System32\drivers\VMBusHID.sys (Microsoft Corporation)
DRV - (NVENETFD) – C:\Windows\System32\drivers\nvm62x32.sys (NVIDIA Corporation)
DRV - (speedfan) – C:\Windows\System32\speedfan.sys (Windows ® 2000 DDK provider)
DRV - (libusb0) – C:\Windows\System32\drivers\libusb0.sys ()
DRV - (giveio) – C:\Windows\System32\giveio.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://uk.msn.com/?ocid=OIE9HP
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.startup.homepage: "www.google.com"
FF - prefs.js..extensions.enabledItems: [removed]:3.76
FF - prefs.js..extensions.enabledItems: {9f08cb5a-76b1-4bcf-aff9-90e1a5d60b1e}:3.76
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_3_300_268.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.1: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1: C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.50401.0\npctrl.dll ( Microsoft Corporation)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\admin\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\admin\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG10\Firefox4\ [2012/03/10 10:29:01 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/07/30 20:26:48 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/05/01 10:52:43 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/07/30 20:26:48 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/05/01 10:52:43 | 000,000,000 | —D | M]

[2010/04/18 16:12:25 | 000,000,000 | —D | M] (No name found) – C:\Users\admin\AppData\Roaming\Mozilla\Extensions
[2012/07/27 11:42:18 | 000,000,000 | —D | M] (No name found) – C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\lriehx76.default\extensions
[2010/04/18 17:25:44 | 000,000,000 | —D | M] (Noia 2.0 (eXtreme)) – C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\lriehx76.default\extensions\{9f08cb5a-76b1-4bcf-aff9-90e1a5d60b1e}
[2010/04/18 17:36:03 | 000,000,000 | —D | M] (Noia 2.0 eXtreme OPT) – C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\lriehx76.default\extensions\[removed]
[2011/05/01 10:52:44 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/07/27 11:42:18 | 000,146,901 | —- | M] () (No name found) – C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LRIEHX76.DEFAULT\EXTENSIONS\[removed]
[2012/07/30 20:26:48 | 000,136,672 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/07/30 20:26:46 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/07/30 20:26:46 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - homepage: http://www.google.com
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}sourceid=chrome&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl;={language}&q;={searchTerms}
CHR - homepage: http://www.google.com
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\admin\AppData\Local\Google\Chrome\Application\20.0.1132.57\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.0.50401.0\npctrl.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\admin\AppData\Local\Google\Chrome\Application\20.0.1132.57\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\admin\AppData\Local\Google\Chrome\Application\20.0.1132.57\pdf.dll
CHR - plugin: AVG Internet Security (Enabled) = C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\10.0.0.1409_0\plugins/avgnpss.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Google Update (Enabled) = C:\Users\admin\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin

O1 HOSTS File: ([2012/08/03 10:14:33 | 000,000,098 | —- | M]) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5.5ServiceManager] "C:\Program Files\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin File not found
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKCU..\Run: [YbaVilmo] C:\Users\admin\AppData\Local\quijxldx\ybavilmo.exe File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7D5F0FB2-DDEB-46DB-B0CD-70EF4AD61DB8}: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (c:\windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Users\admin\AppData\Local\quijxldx\ybavilmo.exe) - C:\Users\admin\AppData\Local\quijxldx\ybavilmo.exe File not found
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 22:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2007/10/03 14:53:35 | 000,000,027 | R— | M] () - E:\AUTORUN.inf – [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O35 - HKCU\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2012/08/03 10:14:32 | 000,000,000 | —D | C] – C:\_OTL
[2012/08/02 18:44:05 | 004,731,392 | —- | C] (AVAST Software) – C:\Users\admin\Desktop\aswMBR.exe
[2012/08/02 18:24:44 | 000,000,000 | —D | C] – C:\$RECYCLE.BIN
[2012/08/02 18:23:11 | 000,000,000 | —D | C] – C:\Windows\temp
[2012/08/02 18:23:11 | 000,000,000 | —D | C] – C:\Users\admin\AppData\Local\temp
[2012/08/02 18:16:38 | 000,000,000 | —D | C] – C:\ComboFix
[2012/08/02 18:15:40 | 004,722,680 | R— | C] (Swearware) – C:\Users\admin\Desktop\ComboFix.exe
[2012/08/02 13:10:34 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2012/08/02 13:10:20 | 002,322,184 | —- | C] (ESET) – C:\Users\admin\Desktop\esetsmartinstaller_enu.exe
[2012/08/02 10:15:32 | 000,000,000 | —D | C] – C:\Program Files\AMD APP
[2012/08/02 10:14:38 | 000,000,000 | —D | C] – C:\AMD
[2012/08/02 09:47:49 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2012/08/02 09:47:49 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2012/08/02 09:47:49 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2012/08/02 09:46:43 | 000,000,000 | —D | C] – C:\Qoobox
[2012/08/02 09:46:33 | 000,000,000 | —D | C] – C:\Windows\erdnt
[2012/08/01 11:18:03 | 000,597,504 | —- | C] (OldTimer Tools) – C:\Users\admin\Desktop\OTL.exe
[2012/08/01 10:02:53 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware1
[2012/07/30 11:29:35 | 000,000,000 | —D | C] – C:\Program Files\Empire Total War
[2012/07/29 13:44:05 | 000,000,000 | —D | C] – C:\ProgramData\Sun
[2012/07/29 13:44:04 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2012/07/29 13:43:43 | 000,000,000 | —D | C] – C:\Program Files\Oracle
[2012/07/29 13:43:08 | 000,772,544 | —- | C] (Oracle Corporation) – C:\Windows\System32\npDeployJava1.dll
[2012/07/29 13:43:08 | 000,687,544 | —- | C] (Oracle Corporation) – C:\Windows\System32\deployJava1.dll
[2012/07/29 13:43:08 | 000,227,760 | —- | C] (Oracle Corporation) – C:\Windows\System32\javaws.exe
[2012/07/29 13:43:00 | 000,174,064 | —- | C] (Oracle Corporation) – C:\Windows\System32\javaw.exe
[2012/07/29 13:43:00 | 000,174,064 | —- | C] (Oracle Corporation) – C:\Windows\System32\java.exe
[2012/07/29 13:42:51 | 000,000,000 | —D | C] – C:\Program Files\Java
[2012/07/27 18:34:20 | 000,000,000 | —D | C] – C:\Games
[2012/07/15 15:23:43 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games for Windows Marketplace
[2012/07/14 18:24:39 | 000,000,000 | —D | C] – C:\Users\admin\AppData\Roaming\GFT Global Markets UK
[2012/07/13 20:42:48 | 000,000,000 | —D | C] – C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GFT Global Markets UK
[2012/07/13 20:42:40 | 000,000,000 | —D | C] – C:\Users\admin\AppData\Roaming\InstallShield Installation Information
[2012/07/13 20:42:31 | 000,000,000 | —D | C] – C:\Program Files\DealBook 360
[2012/07/13 20:42:10 | 000,000,000 | —D | C] – C:\Users\admin\Documents\{95EA60FC-B631-470C-98A7-B6EC973B6AA8}
[2012/07/10 17:24:49 | 000,000,000 | —D | C] – C:\Users\admin\AppData\Local\PunkBuster
[2012/07/10 17:23:48 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tom Clancys Ghost Recon Future Soldier
[2012/07/10 16:50:05 | 000,000,000 | —D | C] – C:\Users\admin\AppData\Local\Ubisoft Game Launcher
[2012/07/10 16:50:05 | 000,000,000 | —D | C] – C:\Users\admin\Documents\Ubisoft
[2012/07/05 11:34:52 | 000,000,000 | —D | C] – C:\Users\admin\Desktop\sr-tws2fots3-Mbb

========== Files - Modified Within 30 Days ==========

[2012/08/03 10:26:00 | 000,016,816 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/08/03 10:26:00 | 000,016,816 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/08/03 10:23:09 | 000,615,122 | —- | M] () – C:\Windows\System32\perfh009.dat
[2012/08/03 10:23:09 | 000,103,496 | —- | M] () – C:\Windows\System32\perfc009.dat
[2012/08/03 10:18:43 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/08/03 10:18:41 | 2616,635,392 | -HS- | M] () – C:\hiberfil.sys
[2012/08/03 10:14:33 | 000,000,098 | —- | M] () – C:\Windows\System32\drivers\etc\Hosts
[2012/08/03 10:12:03 | 102,883,599 | —- | M] () – C:\Windows\System32\drivers\AVG\incavi.avm
[2012/08/03 10:12:03 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-233920906-1137161095-2195176289-1000UA.job
[2012/08/02 18:46:53 | 000,000,512 | —- | M] () – C:\Users\admin\Desktop\MBR.dat
[2012/08/02 18:44:54 | 004,731,392 | —- | M] (AVAST Software) – C:\Users\admin\Desktop\aswMBR.exe
[2012/08/02 18:26:14 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2012/08/02 18:26:14 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2012/08/02 18:26:05 | 249,397,189 | —- | M] () – C:\Windows\MEMORY.DMP
[2012/08/02 18:15:53 | 004,722,680 | R— | M] (Swearware) – C:\Users\admin\Desktop\ComboFix.exe
[2012/08/02 15:12:00 | 000,000,856 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-233920906-1137161095-2195176289-1000Core.job
[2012/08/01 11:18:05 | 000,597,504 | —- | M] (OldTimer Tools) – C:\Users\admin\Desktop\OTL.exe
[2012/07/31 12:25:41 | 000,001,436 | —- | M] () – C:\Users\admin\Desktop\Empire - Shortcut.lnk
[2012/07/30 20:26:50 | 000,001,990 | —- | M] () – C:\Users\admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/07/29 18:11:15 | 000,300,082 | —- | M] () – C:\Windows\System32\drivers\AVG\iavichjg.avm
[2012/07/29 13:42:52 | 000,174,064 | —- | M] (Oracle Corporation) – C:\Windows\System32\javaw.exe
[2012/07/29 13:42:52 | 000,174,064 | —- | M] (Oracle Corporation) – C:\Windows\System32\java.exe
[2012/07/28 10:14:05 | 000,426,184 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerApp.exe
[2012/07/28 10:14:05 | 000,070,344 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2012/07/15 15:25:00 | 000,002,063 | —- | M] () – C:\Users\Public\Desktop\Street Fighter X Tekken.lnk
[2012/07/13 20:42:48 | 000,001,891 | —- | M] () – C:\Users\admin\Desktop\DealBook 360.lnk
[2012/07/12 23:09:32 | 000,002,397 | —- | M] () – C:\Users\admin\Desktop\Google Chrome.lnk
[2012/07/10 17:26:30 | 000,139,848 | —- | M] () – C:\Windows\System32\drivers\PnkBstrK.sys
[2012/07/10 17:23:48 | 000,001,343 | —- | M] () – C:\Users\Public\Desktop\Tom Clancys Ghost Recon Future Soldier.lnk
[2012/07/10 17:23:48 | 000,001,313 | —- | M] () – C:\Users\Public\Desktop\Launcher.lnk
[2012/07/10 16:20:13 | 005,103,702 | —- | M] () – C:\Users\admin\Desktop\Elder Alexander.pdf
[2012/07/05 22:06:48 | 000,227,760 | —- | M] (Oracle Corporation) – C:\Windows\System32\javaws.exe
[2012/07/05 22:06:30 | 000,772,544 | —- | M] (Oracle Corporation) – C:\Windows\System32\npDeployJava1.dll
[2012/07/05 22:06:20 | 000,687,544 | —- | M] (Oracle Corporation) – C:\Windows\System32\deployJava1.dll

========== Files Created - No Company Name ==========

[2012/08/02 18:46:53 | 000,000,512 | —- | C] () – C:\Users\admin\Desktop\MBR.dat
[2012/08/02 18:26:14 | 000,000,000 | RHS- | C] () – C:\MSDOS.SYS
[2012/08/02 18:26:14 | 000,000,000 | RHS- | C] () – C:\IO.SYS
[2012/08/02 09:47:49 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2012/08/02 09:47:49 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2012/08/02 09:47:49 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2012/08/02 09:47:49 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2012/08/02 09:47:49 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2012/07/31 12:25:41 | 000,001,436 | —- | C] () – C:\Users\admin\Desktop\Empire - Shortcut.lnk
[2012/07/15 15:25:00 | 000,002,063 | —- | C] () – C:\Users\Public\Desktop\Street Fighter X Tekken.lnk
[2012/07/13 20:42:48 | 000,001,891 | —- | C] () – C:\Users\admin\Desktop\DealBook 360.lnk
[2012/07/10 17:23:48 | 000,001,343 | —- | C] () – C:\Users\Public\Desktop\Tom Clancys Ghost Recon Future Soldier.lnk
[2012/07/10 17:23:48 | 000,001,313 | —- | C] () – C:\Users\Public\Desktop\Launcher.lnk
[2012/07/10 16:20:12 | 005,103,702 | —- | C] () – C:\Users\admin\Desktop\Elder Alexander - Come Into My Trading Room - A Complete Guide To Trading.pdf
[2012/06/11 13:50:42 | 000,159,232 | —- | C] () – C:\Windows\System32\clinfo.exe
[2011/11/10 03:28:32 | 000,204,960 | —- | C] () – C:\Windows\System32\ativvsvl.dat
[2011/11/10 03:28:32 | 000,157,152 | —- | C] () – C:\Windows\System32\ativvsva.dat
[2011/10/21 20:30:14 | 000,243,168 | —- | C] () – C:\Windows\System32\atiicdxx.dat
[2011/09/13 00:06:16 | 000,003,917 | —- | C] () – C:\Windows\System32\atipblag.dat
[2011/05/30 09:45:54 | 000,001,346 | -HS- | C] () – C:\Users\admin\AppData\Local\k53phh05m63xl61w50p78u3805prg
[2011/05/30 09:45:54 | 000,001,346 | -HS- | C] () – C:\ProgramData\k53phh05m63xl61w50p78u3805prg
[2011/05/24 14:55:52 | 000,001,282 | -HS- | C] () – C:\Users\admin\AppData\Local\r5cnhmt1xy5he7n0d7u4763g4srw2d7mjik11wa
[2011/05/24 14:55:52 | 000,001,282 | -HS- | C] () – C:\ProgramData\r5cnhmt1xy5he7n0d7u4763g4srw2d7mjik11wa
[2011/05/04 17:36:27 | 000,033,792 | —- | C] () – C:\Windows\System32\drivers\libusb0.sys
[2011/04/09 18:55:28 | 000,179,261 | —- | C] () – C:\Windows\System32\xlive.dll.cat
[2011/02/07 18:21:29 | 000,139,848 | —- | C] () – C:\Windows\System32\drivers\PnkBstrK.sys
[2011/02/07 18:21:28 | 000,022,328 | —- | C] () – C:\Users\admin\AppData\Roaming\PnkBstrK.sys
[2011/02/07 18:21:05 | 000,282,696 | —- | C] () – C:\Windows\System32\PnkBstrB.exe
[2011/02/07 18:21:04 | 002,337,865 | —- | C] () – C:\Windows\System32\pbsvc.exe
[2011/02/07 18:21:04 | 000,076,888 | —- | C] () – C:\Windows\System32\PnkBstrA.exe
[2011/02/02 15:25:21 | 000,071,259 | —- | C] () – C:\Windows\Huawei ModemsUninstall.exe
[2010/04/24 15:24:45 | 000,007,617 | —- | C] () – C:\Users\admin\AppData\Local\Resmon.ResmonCfg

< End of report >
If it wont go away we can try something else

Open OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :processes
    killallprocesses
    
    :OTL
    O4 - HKCU..\Run: [YbaVilmo] C:\Users\admin\AppData\Local\quijxldx\ybavilmo.exe File not found
    O20 - HKLM Winlogon: UserInit - (C:\Users\admin\AppData\Local\quijxldx\ybavilmo.exe) - C:\Users\admin\AppData\Local\quijxldx\ybavilmo.exe File not found
    [2011/05/30 09:45:54 | 000,001,346 | -HS- | C] () – C:\Users\admin\AppData\Local\k53phh05m63xl61w50p78u3805prg
    [2011/05/30 09:45:54 | 000,001,346 | -HS- | C] () – C:\ProgramData\k53phh05m63xl61w50p78u3805prg
    [2011/05/24 14:55:52 | 000,001,282 | -HS- | C] () – C:\Users\admin\AppData\Local\r5cnhmt1xy5he7n0d7u4763g4srw2d7mjik11wa
    [2011/05/24 14:55:52 | 000,001,282 | -HS- | C] () – C:\ProgramData\r5cnhmt1xy5he7n0d7u4763g4srw2d7mjik11wa
    
    
    :Services
    
    :Reg
    
    :Files
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top. <–Not run Scan
  • Let the program run unhindered, reboot when it is done
  • Then post the results of the log it produces

Then scan again with OTL and post a new log please
Problem seems still there.
—

All processes killed
========== PROCESSES ==========
========== OTL ==========
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\YbaVilmo deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Users\admin\AppData\Local\quijxldx\ybavilmo.exe deleted successfully.
C:\Users\admin\AppData\Local\k53phh05m63xl61w50p78u3805prg moved successfully.
C:\ProgramData\k53phh05m63xl61w50p78u3805prg moved successfully.
C:\Users\admin\AppData\Local\r5cnhmt1xy5he7n0d7u4763g4srw2d7mjik11wa moved successfully.
C:\ProgramData\r5cnhmt1xy5he7n0d7u4763g4srw2d7mjik11wa moved successfully.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
========== COMMANDS ==========

[EMPTYTEMP]

User: admin
->Temp folder emptied: 95922 bytes
->Temporary Internet Files folder emptied: 37294 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 45756837 bytes
->Google Chrome cache emptied: 5124067 bytes
->Flash cache emptied: 2177 bytes

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 49.00 mb


OTL by OldTimer - Version 3.2.55.0 log created on 08032012_124756

Files\Folders moved on Reboot…

PendingFileRenameOperations files…

Registry entries deleted on Reboot…
———————–

OTL logfile created on: 03/08/2012 12:58:25 - Run 3
OTL by OldTimer - Version 3.2.55.0 Folder = C:\Users\admin\Desktop
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.25 Gb Total Physical Memory | 2.33 Gb Available Physical Memory | 71.80% Memory free
6.50 Gb Paging File | 5.45 Gb Available in Paging File | 83.90% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 345.48 Gb Total Space | 88.89 Gb Free Space | 25.73% Space Free | Partition Type: NTFS
Drive D: | 585.94 Gb Total Space | 76.00 Gb Free Space | 12.97% Space Free | Partition Type: NTFS
Drive E: | 630.48 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive K: | 100.00 Mb Total Space | 61.68 Mb Free Space | 61.68% Space Free | Partition Type: NTFS

Computer Name: ADMIN-PC | User Name: admin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\admin\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Windows\System32\atieclxx.exe (AMD)
PRC - C:\Windows\System32\atiesrxx.exe (AMD)
PRC - C:\Program Files\AVG\AVG10\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe ()
PRC - C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\3\3Connect\BecHelperService.exe ()
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll ()
MOD - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\de8525cc2e6327337e1c6917352bfe16\WindowsFormsIntegration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\1762137638019a091020b3baf52f6de3\System.Core.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\39f5a71b5185d267b0f55cd4cea26d6b\PresentationFramework.Aero.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\3871fc2b96345aa6f3be81d9e3c97160\System.Web.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\4bdeb88758dccd625f4703ed77aaf348\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\68e5eeb3c6ef18ba2dc1ad70eb74aeee\PresentationFramework.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\fedf1ba58dced4f0b3f8c457648ceed9\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\ead6be8b410d56b5576b10e56af2c180\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\7ce9d463a5d343fe74d6f181f9226cab\UIAutomationProvider.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\7b459c5815af8123e4bf30d4e05bba65\PresentationCore.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\c2f9dd7db911053edcaaadf5fefc500a\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\5dd9f783008543df3e642ff1e99de4e8\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\4b1350e31ff09cc583b34854816d8036\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\5ba3bf5367fc012300c6566f20cb7f54\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\8c1770d45c63cf5c462eeb945ef9aa5d\mscorlib.ni.dll ()


========== Win32 Services (SafeList) ==========

SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (AMD External Events Utility) – C:\Windows\System32\atiesrxx.exe (AMD)
SRV - (Steam Client Service) – C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (avgwd) – C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (SwitchBoard) – C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (BecHelperService) – C:\Program Files\3\3Connect\BecHelperService.exe ()
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) – C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (Micorsoft Windows Service) – C:\Users\admin\AppData\Local\Temp\gmbdilfb.sys File not found
DRV - (catchme) – C:\Users\admin\AppData\Local\Temp\catchme.sys File not found
DRV - (aqbc5pyw) – File not found
DRV - (AtiHDAudioService) – C:\Windows\System32\drivers\AtihdW73.sys (Advanced Micro Devices)
DRV - (atikmdag) – C:\Windows\System32\drivers\atikmdag.sys (Advanced Micro Devices, Inc.)
DRV - (amdkmdag) – C:\Windows\System32\drivers\atikmdag.sys (Advanced Micro Devices, Inc.)
DRV - (amdkmdap) – C:\Windows\System32\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV - (AVGIDSDriver) – C:\Windows\System32\drivers\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgtdix) – C:\Windows\System32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) – C:\Windows\System32\drivers\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgmfx86) – C:\Windows\System32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSEH) – C:\Windows\System32\drivers\AVGIDSEH.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSShim) – C:\Windows\System32\drivers\AVGIDSShim.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSFilter) – C:\Windows\System32\drivers\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgldx86) – C:\Windows\System32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (sptd) – C:\Windows\System32\drivers\sptd.sys ()
DRV - (AtiHdmiService) – C:\Windows\System32\drivers\AtiHdmi.sys (ATI Technologies, Inc.)
DRV - (hwdatacard) – C:\Windows\System32\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (vmbus) – C:\Windows\System32\drivers\vmbus.sys (Microsoft Corporation)
DRV - (storflt) – C:\Windows\System32\drivers\vmstorfl.sys (Microsoft Corporation)
DRV - (storvsc) – C:\Windows\System32\drivers\storvsc.sys (Microsoft Corporation)
DRV - (USB_RNDIS) – C:\Windows\System32\drivers\usb8023.sys (Microsoft Corporation)
DRV - (s3cap) – C:\Windows\System32\drivers\vms3cap.sys (Microsoft Corporation)
DRV - (VMBusHID) – C:\Windows\System32\drivers\VMBusHID.sys (Microsoft Corporation)
DRV - (NVENETFD) – C:\Windows\System32\drivers\nvm62x32.sys (NVIDIA Corporation)
DRV - (speedfan) – C:\Windows\System32\speedfan.sys (Windows ® 2000 DDK provider)
DRV - (libusb0) – C:\Windows\System32\drivers\libusb0.sys ()
DRV - (giveio) – C:\Windows\System32\giveio.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://uk.msn.com/?ocid=OIE9HP
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.startup.homepage: "www.google.com"
FF - prefs.js..extensions.enabledItems: [removed]:3.76
FF - prefs.js..extensions.enabledItems: {9f08cb5a-76b1-4bcf-aff9-90e1a5d60b1e}:3.76
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_3_300_268.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.1: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1: C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.50401.0\npctrl.dll ( Microsoft Corporation)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\admin\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\admin\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG10\Firefox4\ [2012/03/10 10:29:01 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/07/30 20:26:48 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/05/01 10:52:43 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/07/30 20:26:48 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/05/01 10:52:43 | 000,000,000 | —D | M]

[2010/04/18 16:12:25 | 000,000,000 | —D | M] (No name found) – C:\Users\admin\AppData\Roaming\Mozilla\Extensions
[2012/07/27 11:42:18 | 000,000,000 | —D | M] (No name found) – C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\lriehx76.default\extensions
[2010/04/18 17:25:44 | 000,000,000 | —D | M] (Noia 2.0 (eXtreme)) – C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\lriehx76.default\extensions\{9f08cb5a-76b1-4bcf-aff9-90e1a5d60b1e}
[2010/04/18 17:36:03 | 000,000,000 | —D | M] (Noia 2.0 eXtreme OPT) – C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\lriehx76.default\extensions\[removed]
[2011/05/01 10:52:44 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/07/27 11:42:18 | 000,146,901 | —- | M] () (No name found) – C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LRIEHX76.DEFAULT\EXTENSIONS\[removed]
[2012/07/30 20:26:48 | 000,136,672 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/07/30 20:26:46 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/07/30 20:26:46 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - homepage: http://www.google.com
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}sourceid=chrome&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl;={language}&q;={searchTerms}
CHR - homepage: http://www.google.com
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\admin\AppData\Local\Google\Chrome\Application\20.0.1132.57\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.0.50401.0\npctrl.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\admin\AppData\Local\Google\Chrome\Application\20.0.1132.57\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\admin\AppData\Local\Google\Chrome\Application\20.0.1132.57\pdf.dll
CHR - plugin: AVG Internet Security (Enabled) = C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\10.0.0.1409_0\plugins/avgnpss.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Google Update (Enabled) = C:\Users\admin\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin

O1 HOSTS File: ([2012/08/03 10:14:33 | 000,000,098 | —- | M]) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5.5ServiceManager] "C:\Program Files\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin File not found
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKCU..\Run: [YbaVilmo] C:\Users\admin\AppData\Local\quijxldx\ybavilmo.exe File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7D5F0FB2-DDEB-46DB-B0CD-70EF4AD61DB8}: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (c:\windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Users\admin\AppData\Local\quijxldx\ybavilmo.exe) - C:\Users\admin\AppData\Local\quijxldx\ybavilmo.exe File not found
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 22:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2007/10/03 14:53:35 | 000,000,027 | R— | M] () - E:\AUTORUN.inf – [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O35 - HKCU\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2012/08/03 10:14:32 | 000,000,000 | —D | C] – C:\_OTL
[2012/08/02 18:44:05 | 004,731,392 | —- | C] (AVAST Software) – C:\Users\admin\Desktop\aswMBR.exe
[2012/08/02 18:24:44 | 000,000,000 | —D | C] – C:\$RECYCLE.BIN
[2012/08/02 18:23:11 | 000,000,000 | —D | C] – C:\Windows\temp
[2012/08/02 18:23:11 | 000,000,000 | —D | C] – C:\Users\admin\AppData\Local\temp
[2012/08/02 18:16:38 | 000,000,000 | —D | C] – C:\ComboFix
[2012/08/02 18:15:40 | 004,722,680 | R— | C] (Swearware) – C:\Users\admin\Desktop\ComboFix.exe
[2012/08/02 13:10:34 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2012/08/02 13:10:20 | 002,322,184 | —- | C] (ESET) – C:\Users\admin\Desktop\esetsmartinstaller_enu.exe
[2012/08/02 10:15:32 | 000,000,000 | —D | C] – C:\Program Files\AMD APP
[2012/08/02 10:14:38 | 000,000,000 | —D | C] – C:\AMD
[2012/08/02 09:47:49 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2012/08/02 09:47:49 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2012/08/02 09:47:49 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2012/08/02 09:46:43 | 000,000,000 | —D | C] – C:\Qoobox
[2012/08/02 09:46:33 | 000,000,000 | —D | C] – C:\Windows\erdnt
[2012/08/01 11:18:03 | 000,597,504 | —- | C] (OldTimer Tools) – C:\Users\admin\Desktop\OTL.exe
[2012/08/01 10:02:53 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware1
[2012/07/30 11:29:35 | 000,000,000 | —D | C] – C:\Program Files\Empire Total War
[2012/07/29 13:44:05 | 000,000,000 | —D | C] – C:\ProgramData\Sun
[2012/07/29 13:44:04 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2012/07/29 13:43:43 | 000,000,000 | —D | C] – C:\Program Files\Oracle
[2012/07/29 13:43:08 | 000,772,544 | —- | C] (Oracle Corporation) – C:\Windows\System32\npDeployJava1.dll
[2012/07/29 13:43:08 | 000,687,544 | —- | C] (Oracle Corporation) – C:\Windows\System32\deployJava1.dll
[2012/07/29 13:43:08 | 000,227,760 | —- | C] (Oracle Corporation) – C:\Windows\System32\javaws.exe
[2012/07/29 13:43:00 | 000,174,064 | —- | C] (Oracle Corporation) – C:\Windows\System32\javaw.exe
[2012/07/29 13:43:00 | 000,174,064 | —- | C] (Oracle Corporation) – C:\Windows\System32\java.exe
[2012/07/29 13:42:51 | 000,000,000 | —D | C] – C:\Program Files\Java
[2012/07/27 18:34:20 | 000,000,000 | —D | C] – C:\Games
[2012/07/15 15:23:43 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games for Windows Marketplace
[2012/07/14 18:24:39 | 000,000,000 | —D | C] – C:\Users\admin\AppData\Roaming\GFT Global Markets UK
[2012/07/13 20:42:48 | 000,000,000 | —D | C] – C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GFT Global Markets UK
[2012/07/13 20:42:40 | 000,000,000 | —D | C] – C:\Users\admin\AppData\Roaming\InstallShield Installation Information
[2012/07/13 20:42:31 | 000,000,000 | —D | C] – C:\Program Files\DealBook 360
[2012/07/13 20:42:10 | 000,000,000 | —D | C] – C:\Users\admin\Documents\{95EA60FC-B631-470C-98A7-B6EC973B6AA8}
[2012/07/10 17:24:49 | 000,000,000 | —D | C] – C:\Users\admin\AppData\Local\PunkBuster
[2012/07/10 17:23:48 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tom Clancys Ghost Recon Future Soldier
[2012/07/10 16:50:05 | 000,000,000 | —D | C] – C:\Users\admin\AppData\Local\Ubisoft Game Launcher
[2012/07/10 16:50:05 | 000,000,000 | —D | C] – C:\Users\admin\Documents\Ubisoft
[2012/07/05 11:34:52 | 000,000,000 | —D | C] – C:\Users\admin\Desktop\sr-tws2fots3-Mbb

========== Files - Modified Within 30 Days ==========

[2012/08/03 13:03:44 | 000,016,816 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/08/03 13:03:44 | 000,016,816 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/08/03 13:02:54 | 000,615,122 | —- | M] () – C:\Windows\System32\perfh009.dat
[2012/08/03 13:02:54 | 000,103,496 | —- | M] () – C:\Windows\System32\perfc009.dat
[2012/08/03 12:56:31 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/08/03 12:56:29 | 2616,635,392 | -HS- | M] () – C:\hiberfil.sys
[2012/08/03 12:12:00 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-233920906-1137161095-2195176289-1000UA.job
[2012/08/03 10:14:33 | 000,000,098 | —- | M] () – C:\Windows\System32\drivers\etc\Hosts
[2012/08/03 10:12:03 | 102,883,599 | —- | M] () – C:\Windows\System32\drivers\AVG\incavi.avm
[2012/08/02 18:46:53 | 000,000,512 | —- | M] () – C:\Users\admin\Desktop\MBR.dat
[2012/08/02 18:44:54 | 004,731,392 | —- | M] (AVAST Software) – C:\Users\admin\Desktop\aswMBR.exe
[2012/08/02 18:26:14 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2012/08/02 18:26:14 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2012/08/02 18:26:05 | 249,397,189 | —- | M] () – C:\Windows\MEMORY.DMP
[2012/08/02 18:15:53 | 004,722,680 | R— | M] (Swearware) – C:\Users\admin\Desktop\ComboFix.exe
[2012/08/02 15:12:00 | 000,000,856 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-233920906-1137161095-2195176289-1000Core.job
[2012/08/01 11:18:05 | 000,597,504 | —- | M] (OldTimer Tools) – C:\Users\admin\Desktop\OTL.exe
[2012/07/31 12:25:41 | 000,001,436 | —- | M] () – C:\Users\admin\Desktop\Empire - Shortcut.lnk
[2012/07/30 20:26:50 | 000,001,990 | —- | M] () – C:\Users\admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/07/29 18:11:15 | 000,300,082 | —- | M] () – C:\Windows\System32\drivers\AVG\iavichjg.avm
[2012/07/29 13:42:52 | 000,174,064 | —- | M] (Oracle Corporation) – C:\Windows\System32\javaw.exe
[2012/07/29 13:42:52 | 000,174,064 | —- | M] (Oracle Corporation) – C:\Windows\System32\java.exe
[2012/07/28 10:14:05 | 000,426,184 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerApp.exe
[2012/07/28 10:14:05 | 000,070,344 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2012/07/15 15:25:00 | 000,002,063 | —- | M] () – C:\Users\Public\Desktop\Street Fighter X Tekken.lnk
[2012/07/13 20:42:48 | 000,001,891 | —- | M] () – C:\Users\admin\Desktop\DealBook 360.lnk
[2012/07/12 23:09:32 | 000,002,397 | —- | M] () – C:\Users\admin\Desktop\Google Chrome.lnk
[2012/07/10 17:26:30 | 000,139,848 | —- | M] () – C:\Windows\System32\drivers\PnkBstrK.sys
[2012/07/10 17:23:48 | 000,001,343 | —- | M] () – C:\Users\Public\Desktop\Tom Clancys Ghost Recon Future Soldier.lnk
[2012/07/10 17:23:48 | 000,001,313 | —- | M] () – C:\Users\Public\Desktop\Launcher.lnk
[2012/07/10 16:20:13 | 005,103,702 | —- | M] () – C:\Users\admin\Desktop\Elder Alexander.pdf
[2012/07/05 22:06:48 | 000,227,760 | —- | M] (Oracle Corporation) – C:\Windows\System32\javaws.exe
[2012/07/05 22:06:30 | 000,772,544 | —- | M] (Oracle Corporation) – C:\Windows\System32\npDeployJava1.dll
[2012/07/05 22:06:20 | 000,687,544 | —- | M] (Oracle Corporation) – C:\Windows\System32\deployJava1.dll

========== Files Created - No Company Name ==========

[2012/08/02 18:46:53 | 000,000,512 | —- | C] () – C:\Users\admin\Desktop\MBR.dat
[2012/08/02 18:26:14 | 000,000,000 | RHS- | C] () – C:\MSDOS.SYS
[2012/08/02 18:26:14 | 000,000,000 | RHS- | C] () – C:\IO.SYS
[2012/08/02 09:47:49 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2012/08/02 09:47:49 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2012/08/02 09:47:49 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2012/08/02 09:47:49 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2012/08/02 09:47:49 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2012/07/31 12:25:41 | 000,001,436 | —- | C] () – C:\Users\admin\Desktop\Empire - Shortcut.lnk
[2012/07/15 15:25:00 | 000,002,063 | —- | C] () – C:\Users\Public\Desktop\Street Fighter X Tekken.lnk
[2012/07/13 20:42:48 | 000,001,891 | —- | C] () – C:\Users\admin\Desktop\DealBook 360.lnk
[2012/07/10 17:23:48 | 000,001,343 | —- | C] () – C:\Users\Public\Desktop\Tom Clancys Ghost Recon Future Soldier.lnk
[2012/07/10 17:23:48 | 000,001,313 | —- | C] () – C:\Users\Public\Desktop\Launcher.lnk
[2012/07/10 16:20:12 | 005,103,702 | —- | C] () – C:\Users\admin\Desktop\Elder Alexander - Come Into My Trading Room - A Complete Guide To Trading.pdf
[2012/06/11 13:50:42 | 000,159,232 | —- | C] () – C:\Windows\System32\clinfo.exe
[2011/11/10 03:28:32 | 000,204,960 | —- | C] () – C:\Windows\System32\ativvsvl.dat
[2011/11/10 03:28:32 | 000,157,152 | —- | C] () – C:\Windows\System32\ativvsva.dat
[2011/10/21 20:30:14 | 000,243,168 | —- | C] () – C:\Windows\System32\atiicdxx.dat
[2011/09/13 00:06:16 | 000,003,917 | —- | C] () – C:\Windows\System32\atipblag.dat
[2011/05/04 17:36:27 | 000,033,792 | —- | C] () – C:\Windows\System32\drivers\libusb0.sys
[2011/04/09 18:55:28 | 000,179,261 | —- | C] () – C:\Windows\System32\xlive.dll.cat
[2011/02/07 18:21:29 | 000,139,848 | —- | C] () – C:\Windows\System32\drivers\PnkBstrK.sys
[2011/02/07 18:21:28 | 000,022,328 | —- | C] () – C:\Users\admin\AppData\Roaming\PnkBstrK.sys
[2011/02/07 18:21:05 | 000,282,696 | —- | C] () – C:\Windows\System32\PnkBstrB.exe
[2011/02/07 18:21:04 | 002,337,865 | —- | C] () – C:\Windows\System32\pbsvc.exe
[2011/02/07 18:21:04 | 000,076,888 | —- | C] () – C:\Windows\System32\PnkBstrA.exe
[2011/02/02 15:25:21 | 000,071,259 | —- | C] () – C:\Windows\Huawei ModemsUninstall.exe
[2010/04/24 15:24:45 | 000,007,617 | —- | C] () – C:\Users\admin\AppData\Local\Resmon.ResmonCfg

< End of report >

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI