This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Weird Laptop functions [Solved]

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Something is wrong with my old laptop. A few minutes ago random keys(usually next to or the key my pointer is on) and mouse clicks are being registered when I type and click with Windows On-Screen keyboard.
It seems to stop and start randomly,I fear something is exploiting my laptop (or my mouse is broken? I'm using the laptop's mousepad) . It uses Windows Vista Home Premium.
OTL Log

OTL logfile created on: 8/10/2012 11:03:59 PM - Run 1
OTL by OldTimer - Version 3.2.56.0 Folder = C:\Users\Kiki Wiki\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.37 Gb Total Physical Memory | 1.60 Gb Available Physical Memory | 47.30% Memory free
6.99 Gb Paging File | 4.84 Gb Available in Paging File | 69.32% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 147.58 Gb Total Space | 78.11 Gb Free Space | 52.92% Space Free | Partition Type: NTFS

Computer Name: KIKIWIKI-PC | User Name: Kiki Wiki | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/08/10 23:03:12 | 000,596,480 | —- | M] (OldTimer Tools) – C:\Users\Kiki Wiki\Downloads\OTL.exe
PRC - [2012/07/19 09:28:23 | 000,913,888 | —- | M] (Mozilla Corporation) – C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2012/07/03 13:46:44 | 000,655,944 | —- | M] (Malwarebytes Corporation) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012/07/03 13:46:44 | 000,462,920 | —- | M] (Malwarebytes Corporation) – C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012/03/26 17:08:12 | 000,931,200 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2012/03/26 17:03:40 | 000,011,552 | —- | M] (Microsoft Corporation) – c:\Program Files\Microsoft Security Client\MsMpEng.exe
PRC - [2012/01/03 06:10:42 | 000,063,928 | —- | M] (Adobe Systems Incorporated) – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011/09/08 17:48:34 | 005,554,552 | —- | M] (Wacom Technology, Corp.) – C:\Program Files\Tablet\Pen\Pen_Tablet.exe
PRC - [2011/09/08 17:48:34 | 003,281,272 | —- | M] (Wacom Technology, Corp.) – C:\Program Files\Tablet\Pen\Pen_TouchUser.exe
PRC - [2011/09/08 17:48:34 | 001,485,176 | —- | M] (Wacom Technology, Corp.) – C:\Program Files\Tablet\Pen\Pen_TabletUser.exe
PRC - [2011/09/08 17:48:34 | 000,451,960 | —- | M] (Wacom Technology, Corp.) – C:\Program Files\Tablet\Pen\Pen_TouchService.exe
PRC - [2011/07/28 16:08:12 | 001,259,376 | —- | M] () – C:\Program Files\DivX\DivX Update\DivXUpdate.exe
PRC - [2010/12/21 05:04:30 | 000,987,704 | —- | M] (Secunia) – C:\Program Files\Secunia\PSI\psia.exe
PRC - [2010/12/21 05:04:30 | 000,399,416 | —- | M] (Secunia) – C:\Program Files\Secunia\PSI\sua.exe
PRC - [2010/12/21 05:04:30 | 000,291,896 | —- | M] (Secunia) – C:\Program Files\Secunia\PSI\psi_tray.exe
PRC - [2009/04/10 23:27:38 | 002,926,592 | —- | M] (Microsoft Corporation) – C:\Windows\explorer.exe
PRC - [2008/12/18 14:32:52 | 000,049,152 | —- | M] (Advanced Micro Devices Inc.) – C:\Program Files\ATI\ATI.ACE\Core-Static\MOM.exe
PRC - [2008/12/18 13:19:44 | 000,049,152 | —- | M] (ATI Technologies Inc.) – C:\Program Files\ATI\ATI.ACE\Core-Static\CCC.exe
PRC - [2007/06/05 14:04:42 | 000,009,216 | —- | M] (Agere Systems) – C:\Windows\System32\agrsmsvc.exe


========== Modules (No Company Name) ==========

MOD - [2012/08/02 10:25:30 | 009,465,032 | —- | M] () – C:\Windows\System32\Macromed\Flash\NPSWF32_11_3_300_270.dll
MOD - [2012/07/19 09:28:06 | 002,003,424 | —- | M] () – C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2012/07/17 13:02:20 | 000,970,240 | —- | M] () – C:\Users\Kiki Wiki\AppData\Roaming\Mozilla\Firefox\Profiles\ibtx2mq3.default\extensions\[removed]\platform\WINNT_x86-msvc\components\lpxpcom.dll
MOD - [2012/06/12 12:04:44 | 011,820,032 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\508b444db523c5cf20ff12c7f440837b\System.Web.ni.dll
MOD - [2012/06/12 11:46:22 | 012,433,920 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\f2691cfa7671cdc58179e56ba9227591\System.Windows.Forms.ni.dll
MOD - [2012/06/12 11:46:04 | 001,592,320 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\18f9789aa214c657113e676b3a9015aa\System.Drawing.ni.dll
MOD - [2012/05/08 18:48:04 | 000,771,584 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\846b9cf2756fdd15f704c9bab9c70b6f\System.Runtime.Remoting.ni.dll
MOD - [2012/05/08 18:47:26 | 000,971,264 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\bd76aaaa03ddc15d1840207b5a480644\System.Configuration.ni.dll
MOD - [2012/05/08 18:47:22 | 000,025,600 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\Accessibility\1b337cf9a031145849bc48c11b2cfe58\Accessibility.ni.dll
MOD - [2012/05/08 18:40:36 | 005,450,752 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\d2630342a066a7cb9056d9eb6157687a\System.Xml.ni.dll
MOD - [2012/05/08 18:37:32 | 007,953,408 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System\28d633338fc8d29f8af31935ef7d001b\System.ni.dll
MOD - [2012/05/08 18:37:21 | 011,492,352 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\af9c9e9d7e0523cd444f8b551baa9cbf\mscorlib.ni.dll
MOD - [2011/10/21 17:27:14 | 001,728,512 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager.Graphics.Wizard\2.0.3693.42460__90ba9c70f846762e\CLI.Aspect.DisplaysManager.Graphics.Wizard.dll
MOD - [2011/10/21 17:27:14 | 000,364,544 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Wizard\2.0.3693.42522__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Wizard.dll
MOD - [2011/10/21 17:27:14 | 000,290,816 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime\2.0.3693.42442__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.dll
MOD - [2011/10/21 17:27:14 | 000,204,800 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Wizard\2.0.3693.42461__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Wizard.dll
MOD - [2011/10/21 17:27:14 | 000,077,824 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Runtime\2.0.3693.42517__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Runtime.dll
MOD - [2011/10/21 17:27:14 | 000,040,960 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard\2.0.3693.42456__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.dll
MOD - [2011/10/21 17:27:14 | 000,036,864 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Runtime\2.0.3693.42486__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Runtime.dll
MOD - [2011/10/21 17:27:14 | 000,020,480 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Runtime\2.0.3693.42451__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Runtime.dll
MOD - [2011/10/21 17:27:14 | 000,011,776 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Caste.HydraVision.Runtime\2.0.3693.42552__90ba9c70f846762e\CLI.Caste.HydraVision.Runtime.dll
MOD - [2011/10/21 17:27:14 | 000,008,704 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Caste.HydraVision.Shared\2.0.3693.42552__90ba9c70f846762e\CLI.Caste.HydraVision.Shared.dll
MOD - [2011/10/21 17:27:14 | 000,007,680 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Caste.HydraVision.Wizard\2.0.3693.42556__90ba9c70f846762e\CLI.Caste.HydraVision.Wizard.dll
MOD - [2011/10/21 17:27:14 | 000,007,680 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Caste.HydraVision.Dashboard\2.0.3693.42552__90ba9c70f846762e\CLI.Caste.HydraVision.Dashboard.dll
MOD - [2011/10/21 17:27:13 | 000,491,520 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Wizard\2.0.3693.42537__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Wizard.dll
MOD - [2011/10/21 17:27:13 | 000,139,264 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Welcome.Graphics.Dashboard\2.0.3693.42537__90ba9c70f846762e\CLI.Aspect.Welcome.Graphics.Dashboard.dll
MOD - [2011/10/21 17:27:13 | 000,073,728 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard\2.0.3693.42450__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.dll
MOD - [2011/10/21 17:27:13 | 000,069,632 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Runtime\2.0.3693.42499__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Runtime.dll
MOD - [2011/10/21 17:27:12 | 000,364,544 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Dashboard\2.0.3693.42504__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Dashboard.dll
MOD - [2011/10/21 17:27:12 | 000,094,208 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Wizard\2.0.3693.42504__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Wizard.dll
MOD - [2011/10/21 17:27:12 | 000,061,440 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Runtime\2.0.3693.42503__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Runtime.dll
MOD - [2011/10/21 17:27:12 | 000,045,056 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Aspect.PowerPlayDPPE.Graphics.Runtime\2.0.3693.42536__90ba9c70f846762e\CLI.Aspect.PowerPlayDPPE.Graphics.Runtime.dll
MOD - [2011/10/21 17:27:10 | 000,405,504 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Wizard\2.0.3693.42512__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Wizard.dll
MOD - [2011/10/21 17:27:09 | 000,811,008 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Dashboard\2.0.3693.42488__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Dashboard.dll
MOD - [2011/10/21 17:27:09 | 000,798,720 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Dashboard\2.0.3693.42518__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Dashboard.dll
MOD - [2011/10/21 17:27:09 | 000,712,704 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager.Graphics.Dashboard\2.0.3693.42452__90ba9c70f846762e\CLI.Aspect.DisplaysManager.Graphics.Dashboard.dll
MOD - [2011/10/21 17:27:09 | 000,589,824 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Dashboard\2.0.3693.42462__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Dashboard.dll
MOD - [2011/10/21 17:27:09 | 000,307,200 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Wizard\2.0.3693.42466__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Wizard.dll
MOD - [2011/10/21 17:27:09 | 000,225,280 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Dashboard\2.0.3693.42462__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Dashboard.dll
MOD - [2011/10/21 17:27:09 | 000,126,976 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Dashboard\2.0.3693.42496__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Dashboard.dll
MOD - [2011/10/21 17:27:09 | 000,081,920 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Runtime\2.0.3693.42487__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Runtime.dll
MOD - [2011/10/21 17:27:09 | 000,040,960 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Runtime\2.0.3693.42466__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Runtime.dll
MOD - [2011/10/21 17:27:09 | 000,036,864 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Runtime\2.0.3693.42496__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Runtime.dll
MOD - [2011/10/21 17:27:08 | 000,438,272 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Dashboard\2.0.3693.42487__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Dashboard.dll
MOD - [2011/10/21 17:27:08 | 000,401,408 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Dashboard\2.0.3693.42498__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Dashboard.dll
MOD - [2011/10/21 17:27:08 | 000,065,536 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Runtime\2.0.3693.42486__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Runtime.dll
MOD - [2011/10/21 17:27:08 | 000,040,960 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Runtime\2.0.3693.42487__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Runtime.dll
MOD - [2011/10/21 17:27:08 | 000,032,768 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Runtime\2.0.3693.42497__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Runtime.dll
MOD - [2011/10/21 17:27:08 | 000,020,480 | —- | M] () – C:\Windows\assembly\GAC_MSIL\AEM.Plugin.Hotkeys.Shared\2.0.3309.28617__90ba9c70f846762e\AEM.Plugin.Hotkeys.Shared.dll
MOD - [2011/10/21 17:27:08 | 000,020,480 | —- | M] () – C:\Windows\assembly\GAC_MSIL\AEM.Actions.CCAA.Shared\2.0.3309.28608__90ba9c70f846762e\AEM.Actions.CCAA.Shared.dll
MOD - [2011/10/21 17:27:08 | 000,016,384 | —- | M] () – C:\Windows\assembly\GAC_MSIL\AEM.Plugin.WinMessages.Shared\2.0.3309.28629__90ba9c70f846762e\AEM.Plugin.WinMessages.Shared.dll
MOD - [2011/10/21 17:27:08 | 000,016,384 | —- | M] () – C:\Windows\assembly\GAC_MSIL\AEM.Plugin.EEU.Shared\2.0.3309.28627__90ba9c70f846762e\AEM.Plugin.EEU.Shared.dll
MOD - [2011/10/21 17:27:07 | 000,028,672 | —- | M] () – C:\Windows\assembly\GAC_MSIL\NEWAEM.Foundation\2.0.3309.28603__90ba9c70f846762e\NEWAEM.Foundation.dll
MOD - [2011/10/21 17:27:07 | 000,016,384 | —- | M] () – C:\Windows\assembly\GAC_MSIL\AEM.Plugin.REG.Shared\2.0.3309.28645__90ba9c70f846762e\AEM.Plugin.REG.Shared.dll
MOD - [2011/10/21 17:27:07 | 000,016,384 | —- | M] () – C:\Windows\assembly\GAC_MSIL\AEM.Plugin.GD.Shared\2.0.3309.28647__90ba9c70f846762e\AEM.Plugin.GD.Shared.dll
MOD - [2011/10/21 17:27:07 | 000,016,384 | —- | M] () – C:\Windows\assembly\GAC_MSIL\AEM.Plugin.DPPE.Shared\2.0.3309.28647__90ba9c70f846762e\AEM.Plugin.DPPE.Shared.dll
MOD - [2011/10/21 17:27:07 | 000,007,168 | —- | M] () – C:\Windows\assembly\GAC_MSIL\atixclib\1.0.0.0__90ba9c70f846762e\atixclib.dll
MOD - [2011/10/21 17:27:06 | 000,073,728 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Foundation\2.0.3309.28604__90ba9c70f846762e\CLI.Foundation.dll
MOD - [2011/10/21 17:27:06 | 000,061,440 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Shared\2.0.3309.28618__90ba9c70f846762e\CLI.Caste.Graphics.Shared.dll
MOD - [2011/10/21 17:27:06 | 000,045,056 | —- | M] () – C:\Windows\assembly\GAC_MSIL\DEM.Graphics.I0601\2.0.2573.17685__90ba9c70f846762e\DEM.Graphics.I0601.dll
MOD - [2011/10/21 17:27:06 | 000,032,768 | —- | M] () – C:\Windows\assembly\GAC_MSIL\LOG.Foundation\2.0.3309.28601__90ba9c70f846762e\LOG.Foundation.dll
MOD - [2011/10/21 17:27:06 | 000,028,672 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Foundation.XManifest\2.0.3309.28669__90ba9c70f846762e\CLI.Foundation.XManifest.dll
MOD - [2011/10/21 17:27:06 | 000,020,480 | —- | M] () – C:\Windows\assembly\GAC_MSIL\DEM.OS.I0602\2.0.3309.28630__90ba9c70f846762e\DEM.OS.I0602.dll
MOD - [2011/10/21 17:27:06 | 000,020,480 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Component.Wizard.Shared\2.0.3309.28620__90ba9c70f846762e\CLI.Component.Wizard.Shared.dll
MOD - [2011/10/21 17:27:06 | 000,020,480 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared\2.0.3309.28617__90ba9c70f846762e\CLI.Component.Dashboard.Shared.dll
MOD - [2011/10/21 17:27:06 | 000,020,480 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Component.Client.Shared\2.0.3309.28611__90ba9c70f846762e\CLI.Component.Client.Shared.dll
MOD - [2011/10/21 17:27:06 | 000,016,384 | —- | M] () – C:\Windows\assembly\GAC_MSIL\MOM.Foundation\2.0.3309.28626__90ba9c70f846762e\MOM.Foundation.dll
MOD - [2011/10/21 17:27:06 | 000,016,384 | —- | M] () – C:\Windows\assembly\GAC_MSIL\DEM.OS\2.0.3309.28645__90ba9c70f846762e\DEM.OS.dll
MOD - [2011/10/21 17:27:06 | 000,016,384 | —- | M] () – C:\Windows\assembly\GAC_MSIL\DEM.Graphics.I0706\2.0.2743.23304__90ba9c70f846762e\DEM.Graphics.I0706.dll
MOD - [2011/10/21 17:27:06 | 000,016,384 | —- | M] () – C:\Windows\assembly\GAC_MSIL\DEM.Graphics\2.0.3309.28630__90ba9c70f846762e\DEM.Graphics.dll
MOD - [2011/10/21 17:27:06 | 000,016,384 | —- | M] () – C:\Windows\assembly\GAC_MSIL\DEM.Foundation\2.0.2573.17684__90ba9c70f846762e\DEM.Foundation.dll
MOD - [2011/10/21 17:27:06 | 000,016,384 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Component.Runtime.Shared\2.0.3309.28617__90ba9c70f846762e\CLI.Component.Runtime.Shared.dll
MOD - [2011/10/21 17:27:06 | 000,016,384 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard.Shared\2.0.3309.28631__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.Shared.dll
MOD - [2011/10/21 17:27:05 | 000,053,248 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Shared\2.0.3309.28636__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Shared.dll
MOD - [2011/10/21 17:27:05 | 000,040,960 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Shared\2.0.3309.28644__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Shared.dll
MOD - [2011/10/21 17:27:05 | 000,028,672 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Aspect.PowerPlayDPPE.Graphics.Shared\2.0.3309.28644__90ba9c70f846762e\CLI.Aspect.PowerPlayDPPE.Graphics.Shared.dll
MOD - [2011/10/21 17:27:05 | 000,016,384 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard.Shared\2.0.3309.28630__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.Shared.dll
MOD - [2011/10/21 17:27:04 | 000,065,536 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Shared\2.0.3309.28636__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Shared.dll
MOD - [2011/10/21 17:27:04 | 000,053,248 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Shared\2.0.3309.28634__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Shared.dll
MOD - [2011/10/21 17:27:04 | 000,053,248 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Shared\2.0.3309.28634__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Shared.dll
MOD - [2011/10/21 17:27:04 | 000,049,152 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Shared\2.0.3309.28634__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Shared.dll
MOD - [2011/10/21 17:27:04 | 000,040,960 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Shared\2.0.3309.28636__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Shared.dll
MOD - [2011/10/21 17:27:04 | 000,032,768 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Shared\2.0.3309.28624__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Shared.dll
MOD - [2011/10/21 17:27:04 | 000,028,672 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Shared\2.0.3309.28632__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Shared.dll
MOD - [2011/10/21 17:27:04 | 000,028,672 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Shared\2.0.3309.28630__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Shared.dll
MOD - [2011/10/21 17:27:04 | 000,024,576 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Shared\2.0.3309.28635__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Shared.dll
MOD - [2011/10/21 17:27:04 | 000,020,480 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Shared\2.0.3309.28630__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Shared.dll
MOD - [2011/10/21 17:27:03 | 000,503,808 | —- | M] () – C:\Windows\assembly\GAC_MSIL\ResourceManagement.Foundation.Implementation\2.0.3693.42564__90ba9c70f846762e\ResourceManagement.Foundation.Implementation.dll
MOD - [2011/10/21 17:27:03 | 000,106,496 | —- | M] () – C:\Windows\assembly\GAC_MSIL\MOM.Implementation\2.0.3693.42531__90ba9c70f846762e\MOM.Implementation.dll
MOD - [2011/10/21 17:27:03 | 000,045,056 | —- | M] () – C:\Windows\assembly\GAC_MSIL\AEM.Plugin.Source.Kit.Server\2.0.3693.42545__90ba9c70f846762e\AEM.Plugin.Source.Kit.Server.dll
MOD - [2011/10/21 17:27:03 | 000,032,768 | —- | M] () – C:\Windows\assembly\GAC_MSIL\LOG.Foundation.Private\2.0.3309.28614__90ba9c70f846762e\LOG.Foundation.Private.dll
MOD - [2011/10/21 17:27:03 | 000,028,672 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Aspect.CustomFormats.Graphics.Shared\2.0.3309.28627__90ba9c70f846762e\CLI.Aspect.CustomFormats.Graphics.Shared.dll
MOD - [2011/10/21 17:27:03 | 000,024,576 | —- | M] () – C:\Windows\assembly\GAC_MSIL\ACE.Graphics.DisplaysManager.Shared\2.0.2573.17685__90ba9c70f846762e\ACE.Graphics.DisplaysManager.Shared.dll
MOD - [2011/10/21 17:27:03 | 000,020,480 | —- | M] () – C:\Windows\assembly\GAC_MSIL\ResourceManagement.Foundation.Private\2.0.3309.28612__90ba9c70f846762e\ResourceManagement.Foundation.Private.dll
MOD - [2011/10/21 17:27:03 | 000,020,480 | —- | M] () – C:\Windows\assembly\GAC_MSIL\APM.Foundation\2.0.3309.28626__90ba9c70f846762e\APM.Foundation.dll
MOD - [2011/10/21 17:27:03 | 000,016,384 | —- | M] () – C:\Windows\assembly\GAC_MSIL\AEM.Server.Shared\2.0.3309.28617__90ba9c70f846762e\AEM.Server.Shared.dll
MOD - [2011/10/21 17:27:03 | 000,014,848 | —- | M] () – C:\Windows\assembly\GAC_MSIL\AxInterop.WBOCXLib\1.0.0.0__90ba9c70f846762e\AxInterop.WBOCXLib.dll
MOD - [2011/10/21 17:27:03 | 000,013,312 | —- | M] () – C:\Windows\assembly\GAC\Interop.WBOCXLib\1.0.0.0__90ba9c70f846762e\Interop.WBOCXLib.dll
MOD - [2011/10/21 17:27:03 | 000,007,168 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Component.Runtime.Extension.EEU\2.0.3693.42437__90ba9c70f846762e\CLI.Component.Runtime.Extension.EEU.dll
MOD - [2011/10/21 17:27:02 | 000,544,768 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Component.Systemtray\2.0.3693.42525__90ba9c70f846762e\CLI.Component.Systemtray.dll
MOD - [2011/10/21 17:27:02 | 000,405,504 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Component.Wizard\2.0.3693.42455__90ba9c70f846762e\CLI.Component.Wizard.dll
MOD - [2011/10/21 17:27:02 | 000,081,920 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Component.Runtime\2.0.3693.42440__90ba9c70f846762e\CLI.Component.Runtime.dll
MOD - [2011/10/21 17:27:02 | 000,061,440 | —- | M] () – C:\Windows\assembly\GAC_MSIL\LOG.Foundation.Implementation\2.0.3693.42530__90ba9c70f846762e\LOG.Foundation.Implementation.dll
MOD - [2011/10/21 17:27:02 | 000,057,344 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Component.SkinFactory\2.0.3693.42441__90ba9c70f846762e\CLI.Component.SkinFactory.dll
MOD - [2011/10/21 17:27:02 | 000,045,056 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Component.Runtime.Shared.Private\2.0.3309.28628__90ba9c70f846762e\CLI.Component.Runtime.Shared.Private.dll
MOD - [2011/10/21 17:27:02 | 000,040,960 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Foundation.Private\2.0.3309.28608__90ba9c70f846762e\CLI.Foundation.Private.dll
MOD - [2011/10/21 17:27:02 | 000,024,576 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Component.Wizard.Shared.Private\2.0.3309.28627__90ba9c70f846762e\CLI.Component.Wizard.Shared.Private.dll
MOD - [2011/10/21 17:27:02 | 000,020,480 | —- | M] () – C:\Windows\assembly\GAC_MSIL\LOG.Foundation.Implementation.Private\2.0.3309.28626__90ba9c70f846762e\LOG.Foundation.Implementation.Private.dll
MOD - [2011/10/21 17:27:01 | 001,142,784 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Component.Dashboard\2.0.3693.42446__90ba9c70f846762e\CLI.Component.Dashboard.dll
MOD - [2011/10/21 17:27:01 | 000,081,920 | —- | M] () – C:\Windows\assembly\GAC_MSIL\ATIDEMOS\2.0.3693.42440__90ba9c70f846762e\ATIDEMOS.dll
MOD - [2011/10/21 17:27:01 | 000,040,960 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Component.Client.Shared.Private\2.0.3309.28621__90ba9c70f846762e\CLI.Component.Client.Shared.Private.dll
MOD - [2011/10/21 17:27:01 | 000,032,768 | —- | M] () – C:\Windows\assembly\GAC_MSIL\ATICCCom\2.0.0.0__90ba9c70f846762e\ATICCCom.dll
MOD - [2011/10/21 17:27:01 | 000,028,672 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CCC.Implementation\2.0.3693.42531__90ba9c70f846762e\CCC.Implementation.dll
MOD - [2011/10/21 17:27:01 | 000,020,480 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared.Private\2.0.3309.28624__90ba9c70f846762e\CLI.Component.Dashboard.Shared.Private.dll
MOD - [2011/10/21 17:27:01 | 000,020,480 | —- | M] () – C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime.Shared.Private\2.0.3309.28637__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.Shared.Private.dll
MOD - [2011/10/21 17:27:00 | 000,061,440 | —- | M] () – C:\Windows\assembly\GAC_MSIL\APM.Server\2.0.3693.42439__90ba9c70f846762e\APM.Server.dll
MOD - [2011/10/21 17:27:00 | 000,045,056 | —- | M] () – C:\Windows\assembly\GAC_MSIL\AEM.Server\2.0.3693.42438__90ba9c70f846762e\AEM.Server.dll
MOD - [2011/09/08 17:48:36 | 000,962,936 | —- | M] () – C:\Program Files\Tablet\Pen\libxml2.dll
MOD - [2011/07/28 16:09:42 | 000,096,112 | —- | M] () – C:\Program Files\DivX\DivX Update\DivXUpdateCheck.dll
MOD - [2011/07/28 16:08:12 | 001,259,376 | —- | M] () – C:\Program Files\DivX\DivX Update\DivXUpdate.exe
MOD - [2010/12/04 19:38:04 | 001,242,112 | —- | M] () – C:\Program Files\ManyCam\Bin\opencv_imgproc220.dll
MOD - [2010/12/04 19:38:02 | 002,010,624 | —- | M] () – C:\Program Files\ManyCam\Bin\opencv_core220.dll
MOD - [2010/02/10 22:30:38 | 000,159,744 | —- | M] () – C:\Windows\System32\atitmmxx.dll
MOD - [2009/11/24 13:36:36 | 000,016,384 | R— | M] () – C:\Program Files\ATI\ATI.ACE\Branding\Branding.dll
MOD - [2009/07/10 13:27:20 | 000,141,312 | —- | M] () – C:\Program Files\WinRAR\RarExt.dll


========== Win32 Services (SafeList) ==========

SRV - [2012/08/02 10:25:34 | 000,250,056 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe – (AdobeFlashPlayerUpdateSvc)
SRV - [2012/07/19 09:28:22 | 000,113,120 | —- | M] (Mozilla Foundation) [On_Demand | Stopped] – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe – (MozillaMaintenance)
SRV - [2012/07/13 13:28:36 | 000,160,944 | R— | M] (Skype Technologies) [Auto | Stopped] – C:\Program Files\Skype\Updater\Updater.exe – (SkypeUpdate)
SRV - [2012/07/03 13:46:44 | 000,655,944 | —- | M] (Malwarebytes Corporation) [Auto | Running] – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe – (MBAMService)
SRV - [2012/03/26 17:03:40 | 000,214,952 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – c:\Program Files\Microsoft Security Client\NisSrv.exe – (NisSrv)
SRV - [2012/03/26 17:03:40 | 000,011,552 | —- | M] (Microsoft Corporation) [Auto | Running] – c:\Program Files\Microsoft Security Client\MsMpEng.exe – (MsMpSvc)
SRV - [2012/01/03 06:10:42 | 000,063,928 | —- | M] (Adobe Systems Incorporated) [Auto | Running] – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe – (AdobeARMservice)
SRV - [2011/09/08 17:48:34 | 005,554,552 | —- | M] (Wacom Technology, Corp.) [Auto | Running] – C:\Program Files\Tablet\Pen\Pen_Tablet.exe – (TabletServicePen)
SRV - [2011/09/08 17:48:34 | 000,451,960 | —- | M] (Wacom Technology, Corp.) [Auto | Running] – C:\Program Files\Tablet\Pen\Pen_TouchService.exe – (TouchServicePen)
SRV - [2011/06/13 22:09:22 | 000,267,568 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Microsoft Fix it Center\Matsvc.exe – (MatSvc)
SRV - [2010/12/21 05:04:30 | 000,987,704 | —- | M] (Secunia) [Auto | Running] – C:\Program Files\Secunia\PSI\psia.exe – (Secunia PSI Agent)
SRV - [2010/12/21 05:04:30 | 000,399,416 | —- | M] (Secunia) [Auto | Running] – C:\Program Files\Secunia\PSI\sua.exe – (Secunia Update Agent)
SRV - [2010/05/23 14:28:00 | 003,518,368 | —- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] – C:\Windows\System32\GameMon.des – (npggsvc)
SRV - [2010/02/19 13:37:14 | 000,517,096 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe – (SwitchBoard)
SRV - [2008/01/18 23:38:26 | 000,272,952 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2007/06/05 14:04:42 | 000,009,216 | —- | M] (Agere Systems) [Auto | Running] – C:\Windows\System32\agrsmsvc.exe – (AgereModemAudio)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] – – (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] – – (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys – (Lavasoft Kernexplorer)
DRV - File not found [Kernel | On_Demand | Stopped] – – (IpInIp)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\EagleNT.sys – (EagleNT)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\Program Files\ATI Technologies\ATI.ACE\Fuel\i386\AODDriver2.sys – (AODDriver4.0)
DRV - File not found [Kernel | On_Demand | Stopped] – – (amdiox86)
DRV - [2012/08/10 23:07:19 | 000,040,776 | —- | M] (Malwarebytes Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\mbamswissarmy.sys – (MBAMSwissArmy)
DRV - [2012/08/10 06:23:32 | 000,029,904 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{BC1F62DA-3CF4-4FA5-B39B-D9F91F5416CF}\MpKsl81d03f9c.sys – (MpKsl81d03f9c)
DRV - [2012/07/03 13:46:44 | 000,022,344 | —- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] – C:\Windows\System32\drivers\mbam.sys – (MBAMProtector)
DRV - [2012/03/20 20:44:12 | 000,074,112 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\NisDrvWFP.sys – (NisDrv)
DRV - [2012/03/18 17:54:51 | 000,013,232 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\System32\apf003.sys – (apf003)
DRV - [2012/02/22 03:34:36 | 000,022,400 | —- | M] (ManyCam LLC) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\mcaudrv.sys – (mcaudrv_simple)
DRV - [2012/01/10 23:11:20 | 000,032,000 | —- | M] (ManyCam LLC) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\mcvidrv.sys – (ManyCam)
DRV - [2011/11/23 14:58:11 | 000,010,872 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\System32\apf001.sys – (apf001)
DRV - [2010/10/05 13:26:00 | 000,014,120 | —- | M] (Wacom Technology) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\wacomvhid.sys – (wacomvhid)
DRV - [2010/09/02 20:51:27 | 000,691,696 | —- | M] () [Kernel | Boot | Running] – C:\Windows\System32\drivers\sptd.sys – (sptd)
DRV - [2010/09/01 01:30:58 | 000,015,544 | —- | M] (Secunia) [File_System | On_Demand | Running] – C:\Windows\System32\drivers\psi_mf.sys – (PSI)
DRV - [2010/06/23 09:21:32 | 000,259,176 | —- | M] (Realtek ) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\Rtlh86.sys – (RTL8169)
DRV - [2010/06/22 19:47:58 | 000,032,768 | —- | M] (AnchorFree Inc) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\taphss.sys – (taphss)
DRV - [2010/02/11 00:42:22 | 004,450,816 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\atikmdag.sys – (atikmdag)
DRV - [2009/11/06 12:53:58 | 001,227,776 | —- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\athr.sys – (athr)
DRV - [2009/08/27 16:06:32 | 000,016,168 | —- | M] (Wacom Technology) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\wacmoumonitor.sys – (wacmoumonitor)
DRV - [2009/06/19 21:44:14 | 000,290,816 | —- | M] (Texas Instruments) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\tifm21.sys – (tifm21)
DRV - [2009/04/10 21:42:54 | 000,031,616 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\winusb.sys – (WinUSB)
DRV - [2009/03/18 16:35:40 | 000,026,176 | -H– | M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\hamachi.sys – (hamachi)
DRV - [2008/12/09 15:26:50 | 000,020,392 | —- | M] (EldoS Corporation) [Kernel | System | Running] – C:\Windows\System32\drivers\elrawdsk.sys – (ElRawDisk)
DRV - [2008/03/26 12:31:26 | 000,034,128 | —- | M] (DemoForge, LLC) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\dfmirage.sys – (dfmirage)
DRV - [2007/11/09 05:00:52 | 000,023,640 | —- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] – C:\Windows\System32\drivers\TVALZ_O.SYS – (TVALZ)
DRV - [2007/06/05 14:04:40 | 001,161,888 | —- | M] (Agere Systems) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\AGRSM.sys – (AgereSoftModem)
DRV - [2007/02/16 12:12:36 | 000,011,312 | —- | M] (Wacom Technology) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\wacommousefilter.sys – (wacommousefilter)
DRV - [2005/09/04 20:21:06 | 000,362,944 | —- | M] (NETGEAR, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\WG11TND5.sys – (AR5523)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = F8 03 3D F8 BC 42 CD 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\SearchScopes,DefaultScope = {95B7759C-8C7F-4BF1-B163-73684A933233}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://isearch.avg.com/search?cid={31A11F0…mp;d=2012-07-06 10:43:36&v;=11.1.0.12&sap;=dsp&q;={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://go.microsoft.com/fwlink/?LinkId=69157"
FF - prefs.js..extensions.enabledItems: [removed]:1.1.0.20
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3
FF - prefs.js..extensions.enabledItems: {0b457cAA-602d-484a-8fe7-c1d894a011ba}:0.88
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.9.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20110323
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1
FF - prefs.js..extensions.enabledItems: [removed]:0.8.2


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_3_300_270.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: File not found
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.1: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1: C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.3: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/wpi,version=1.0: C:\Program Files\Microsoft\Web Platform Installer\\npwpidetector.dll ()
FF - HKLM\Software\MozillaPlugins\@nexon.net/NxGame: File not found
FF - HKLM\Software\MozillaPlugins\@ogplanet.com/npOGPPlugin: C:\Windows\system32\npOGPPlugin.dll (OGPlanet)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: File not found
FF - HKLM\Software\MozillaPlugins\@virtools.com/3DviaPlayer: C:\Program Files\Virtools\3D Life Player\npvirtools.dll (Dassault Systèmes)
FF - HKLM\Software\MozillaPlugins\@wacom.com/wacom-plugin,version=1.1.0.3: C:\Program Files\TabletPlugins\npwacom.dll File not found
FF - HKLM\Software\MozillaPlugins\@wacom.com/wacom-plugin,version=1.1.0.5: C:\Program Files\TabletPlugins\npwacom.dll File not found
FF - HKLM\Software\MozillaPlugins\@wacom.com/wtPlugin,version=2.0.0.1: C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll (Wacom)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\wacom.com/WacomTabletPlugin: C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll (Wacom)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012/08/02 10:18:43 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/07/19 09:28:24 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/08/03 11:27:33 | 000,000,000 | —D | M]

[2010/06/22 13:57:06 | 000,000,000 | —D | M] (No name found) – C:\Users\Kiki Wiki\AppData\Roaming\Mozilla\Extensions
[2010/06/22 13:57:06 | 000,000,000 | —D | M] (No name found) – C:\Users\Kiki Wiki\AppData\Roaming\Mozilla\Extensions\[removed]
[2012/08/07 20:42:44 | 000,000,000 | —D | M] (No name found) – C:\Users\Kiki Wiki\AppData\Roaming\Mozilla\Firefox\Profiles\ibtx2mq3.default\extensions
[2012/07/21 09:41:16 | 000,000,000 | —D | M] (FireShot) – C:\Users\Kiki Wiki\AppData\Roaming\Mozilla\Firefox\Profiles\ibtx2mq3.default\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba}
[2012/05/18 10:09:08 | 000,000,000 | —D | M] (WOT) – C:\Users\Kiki Wiki\AppData\Roaming\Mozilla\Firefox\Profiles\ibtx2mq3.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2011/11/19 22:13:32 | 000,000,000 | —D | M] ("Free YouTube Download (Free Studio) Menu") – C:\Users\Kiki Wiki\AppData\Roaming\Mozilla\Firefox\Profiles\ibtx2mq3.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2012/08/03 11:31:52 | 000,000,000 | —D | M] (Greasemonkey) – C:\Users\Kiki Wiki\AppData\Roaming\Mozilla\Firefox\Profiles\ibtx2mq3.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2012/07/10 15:03:11 | 000,000,000 | —D | M] (Microsoft Choice Guard) – C:\Users\Kiki Wiki\AppData\Roaming\Mozilla\Firefox\Profiles\ibtx2mq3.default\extensions\ChoiceGuard@Microsoft
[2012/07/23 19:07:18 | 000,000,000 | —D | M] (Ghostery) – C:\Users\Kiki Wiki\AppData\Roaming\Mozilla\Firefox\Profiles\ibtx2mq3.default\extensions\[removed]
[2012/07/08 12:34:01 | 000,000,000 | —D | M] (OneClickDownloader) – C:\Users\Kiki Wiki\AppData\Roaming\Mozilla\Firefox\Profiles\ibtx2mq3.default\extensions\[removed]
[2012/07/25 10:24:46 | 000,000,000 | —D | M] (LastPass) – C:\Users\Kiki Wiki\AppData\Roaming\Mozilla\Firefox\Profiles\ibtx2mq3.default\extensions\[removed]
[2010/12/24 12:28:48 | 000,001,820 | —- | M] () – C:\Users\Kiki Wiki\AppData\Roaming\Mozilla\Firefox\Profiles\ibtx2mq3.default\searchplugins\bing.xml
[2012/06/13 22:19:39 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/06/12 16:21:20 | 000,000,000 | —D | M] (Skype Click to Call) – C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012/06/13 22:05:24 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
[2012/08/02 10:18:43 | 000,000,000 | —D | M] (DivX Plus Web Player HTML5 ) – C:\PROGRAM FILES\DIVX\DIVX PLUS WEB PLAYER\FIREFOX\DIVXHTML5
[2012/07/30 13:48:16 | 000,526,190 | —- | M] () (No name found) – C:\USERS\KIKI WIKI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IBTX2MQ3.DEFAULT\EXTENSIONS\{73A6FE31-595D-460B-A920-FCC0F8843232}.XPI
[2012/04/15 14:34:49 | 000,022,573 | —- | M] () (No name found) – C:\USERS\KIKI WIKI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IBTX2MQ3.DEFAULT\EXTENSIONS\{987311C6-B504-4AA2-90BF-60CC49808D42}.XPI
[2012/04/07 12:50:06 | 000,138,614 | —- | M] () (No name found) – C:\USERS\KIKI WIKI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IBTX2MQ3.DEFAULT\EXTENSIONS\{D40F5E7B-D2CF-4856-B441-CC613EEFFBE3}.XPI
[2012/06/21 09:35:16 | 000,109,964 | —- | M] () (No name found) – C:\USERS\KIKI WIKI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IBTX2MQ3.DEFAULT\EXTENSIONS\[removed]
[2012/02/23 14:43:36 | 000,164,722 | —- | M] () (No name found) – C:\USERS\KIKI WIKI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IBTX2MQ3.DEFAULT\EXTENSIONS\[removed]
[2011/06/30 03:19:09 | 000,330,316 | —- | M] () (No name found) – C:\USERS\KIKI WIKI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\IBTX2MQ3.DEFAULT\EXTENSIONS\[removed]
[2009/06/24 10:35:59 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2012/07/19 09:28:24 | 000,136,672 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2009/09/24 23:02:40 | 000,098,304 | —- | M] (OGPlanet Inc.) – C:\Program Files\mozilla firefox\plugins\npOGPPlugin.dll
[2012/07/19 09:28:02 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/07/19 09:28:02 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2010/12/28 23:33:16 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (DivX Plus Web Player HTML5 ) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No CLSID value found.
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS6ServiceManager] C:\Program Files\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKCU..\Run: [DeSmuMe] C:\Users\Kiki Wiki\Desktop\DeSmuME - Shortcut.lnk ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideFastUserSwitching = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O8 - Extra context menu item: Free YouTube Download - C:\Users\Kiki Wiki\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm ()
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Kiki Wiki\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Save YouTube Video as MP3 - res://C:\Program Files\Common Files\DVDVideoSoft\Dll\IEContextMenuY.dll/scriptY2MP3.htm File not found
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 10.5.1)
O16 - DPF: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_33)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 10.5.1)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{92F20E4E-BFB9-4777-BBF6-886222C8412A}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{940AB514-CF60-4CF9-A04B-5887F4D92A41}: DhcpNameServer = 192.168.0.1 [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A4F030BC-DB9B-4FAF-8BB5-6940A10227D9}: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\wlmailhtml - No CLSID value found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Kiki Wiki\AppData\Roaming\Mozilla\Firefox\Desktop Background.bmp
O24 - Desktop BackupWallPaper: C:\Users\Kiki Wiki\AppData\Roaming\Mozilla\Firefox\Desktop Background.bmp
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 14:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2012/08/10 23:07:19 | 000,040,776 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2012/08/08 15:24:00 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auslogics
[2012/08/07 20:36:47 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ManyCam
[2012/08/07 20:34:09 | 000,000,000 | —D | C] – C:\Users\Kiki Wiki\AppData\Local\ManyCam
[2012/08/07 20:34:08 | 000,000,000 | —D | C] – C:\ProgramData\ManyCam
[2012/08/07 20:34:06 | 000,000,000 | —D | C] – C:\Users\Kiki Wiki\AppData\Roaming\ManyCam
[2012/08/07 20:32:57 | 000,000,000 | —D | C] – C:\Program Files\ManyCam
[2012/08/07 20:32:45 | 000,000,000 | —D | C] – C:\ProgramData\Ask
[2012/08/03 22:27:26 | 000,000,000 | —D | C] – C:\Users\Kiki Wiki\AppData\Local\DDMSettings
[2012/08/03 22:24:19 | 000,000,000 | —D | C] – C:\Users\Kiki Wiki\AppData\Local\Procaster
[2012/08/03 22:24:15 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Livestream Procaster
[2012/08/03 22:24:15 | 000,000,000 | —D | C] – C:\Program Files\Livestream Procaster
[2012/07/14 12:40:05 | 000,000,000 | —D | C] – C:\Users\Kiki Wiki\AppData\Roaming\DVDVideoSoftIEHelpers
[2012/07/14 12:37:05 | 000,405,144 | —- | C] (Newtonsoft) – C:\Windows\System32\Newtonsoft.Json.Net20.dll
[2012/07/13 21:46:52 | 000,000,000 | —D | C] – C:\Program Files\dvd43
[2012/07/13 21:41:57 | 000,000,000 | —D | C] – C:\ProgramData\DVD Shrink
[1 C:\Users\Kiki Wiki\Documents\*.tmp files -> C:\Users\Kiki Wiki\Documents\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/08/10 23:07:19 | 000,040,776 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2012/08/10 22:25:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/08/10 22:23:12 | 000,004,160 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/08/10 22:23:12 | 000,004,160 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/08/10 18:40:17 | 000,000,132 | —- | M] () – C:\Users\Kiki Wiki\AppData\Roaming\Adobe PNG Format CS6 Prefs
[2012/08/10 06:22:57 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/08/08 17:45:26 | 003,677,608 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2012/08/08 15:24:00 | 000,001,010 | —- | M] () – C:\Users\Kiki Wiki\Desktop\Auslogics Disk Defrag.lnk
[2012/08/07 23:52:14 | 010,800,640 | —- | M] () – C:\Users\Kiki Wiki\Documents\manycam test.avi
[2012/08/07 20:36:47 | 000,000,853 | —- | M] () – C:\Users\Public\Desktop\ManyCam.lnk
[2012/08/03 22:24:29 | 000,000,866 | —- | M] () – C:\Users\Public\Desktop\Livestream Procaster.lnk
[2012/08/02 10:25:31 | 000,426,184 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerApp.exe
[2012/08/02 10:25:31 | 000,070,344 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2012/08/02 10:18:55 | 000,001,409 | —- | M] () – C:\Users\Kiki Wiki\Desktop\DivX Movies.lnk
[2012/08/02 10:18:31 | 000,000,888 | —- | M] () – C:\Users\Public\Desktop\DivX Plus Player.lnk
[2012/07/25 10:50:08 | 000,002,187 | —- | M] () – C:\Users\Kiki Wiki\Desktop\Advanced Uninstaller PRO 11.lnk
[2012/07/21 00:34:11 | 000,642,934 | —- | M] () – C:\Windows\System32\perfh009.dat
[2012/07/21 00:34:11 | 000,120,054 | —- | M] () – C:\Windows\System32\perfc009.dat
[2012/07/14 12:39:58 | 000,001,003 | —- | M] () – C:\Users\Kiki Wiki\Desktop\DVDVideoSoft Free Studio.lnk
[2012/07/12 17:13:40 | 000,405,144 | —- | M] (Newtonsoft) – C:\Windows\System32\Newtonsoft.Json.Net20.dll
[2012/07/12 10:27:43 | 000,000,877 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[1 C:\Users\Kiki Wiki\Documents\*.tmp files -> C:\Users\Kiki Wiki\Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/08/08 17:43:22 | 003,677,608 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2012/08/08 15:24:00 | 000,001,010 | —- | C] () – C:\Users\Kiki Wiki\Desktop\Auslogics Disk Defrag.lnk
[2012/08/08 09:17:50 | 000,810,496 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2012/08/08 09:17:50 | 000,183,808 | —- | C] () – C:\Windows\System32\xvidvfw.dll
[2012/08/08 09:17:50 | 000,080,896 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2012/08/08 09:17:47 | 000,389,120 | —- | C] () – C:\Windows\System32\actskn43.ocx
[2012/08/07 23:49:43 | 010,800,640 | —- | C] () – C:\Users\Kiki Wiki\Documents\manycam test.avi
[2012/08/07 20:36:47 | 000,000,853 | —- | C] () – C:\Users\Public\Desktop\ManyCam.lnk
[2012/08/03 22:24:29 | 000,000,866 | —- | C] () – C:\Users\Public\Desktop\Livestream Procaster.lnk
[2012/08/02 10:18:31 | 000,000,888 | —- | C] () – C:\Users\Public\Desktop\DivX Plus Player.lnk
[2012/07/08 12:48:01 | 000,001,451 | —- | C] () – C:\Users\Kiki Wiki\AppData\Roaming\net_telestream_wirecast_partner_NO_SHOWCASTER_AFFILIATE_ID_brandingimage_de
stination.png
[2012/07/08 12:47:59 | 000,004,755 | —- | C] () – C:\Users\Kiki Wiki\AppData\Roaming\net_telestream_wirecast_partner_NO_BAMBUSER_AFFILIATE_ID_brandingimage_dest
ination.png
[2012/07/08 12:47:59 | 000,003,123 | —- | C] () – C:\Users\Kiki Wiki\AppData\Roaming\net_telestream_wirecast_partner_NO_DACAST_AFFILIATE_ID_brandingimage_destin
ation.png
[2012/07/08 12:47:56 | 000,014,543 | —- | C] () – C:\Users\Kiki Wiki\AppData\Roaming\net_telestream_wirecast_partner_AFL9067099885_brandingimage_destination.png
[2012/07/08 12:47:56 | 000,014,186 | —- | C] () – C:\Users\Kiki Wiki\AppData\Roaming\net_telestream_wirecast_partner_AFL9067099885_brandingimage_main.png
[2012/07/08 12:47:55 | 000,014,120 | —- | C] () – C:\Users\Kiki Wiki\AppData\Roaming\net_telestream_wirecast_partner_AFL0681655000_brandingimage_destination.png
[2012/07/08 12:47:55 | 000,005,028 | —- | C] () – C:\Users\Kiki Wiki\AppData\Roaming\net_telestream_wirecast_partner_AFL0681655000_brandingimage_main.png
[2012/07/08 12:47:51 | 000,026,720 | —- | C] () – C:\Users\Kiki Wiki\AppData\Roaming\net.telestream.wirecast.xml
[2012/07/07 00:17:30 | 000,000,132 | —- | C] () – C:\Users\Kiki Wiki\AppData\Roaming\Adobe GIF Format CS6 Prefs
[2012/07/03 21:39:54 | 000,001,456 | —- | C] () – C:\Users\Kiki Wiki\AppData\Local\Adobe Save for Web 13.0 Prefs
[2012/06/27 15:18:59 | 000,000,680 | —- | C] () – C:\Users\Kiki Wiki\AppData\Local\d3d9caps.dat
[2012/06/20 22:28:47 | 000,000,218 | —- | C] () – C:\Users\Kiki Wiki\.recently-used.xbel
[2012/06/04 01:46:27 | 000,000,132 | —- | C] () – C:\Users\Kiki Wiki\AppData\Roaming\Adobe PNG Format CS6 Prefs
[2012/04/24 18:36:36 | 000,009,278 | —- | C] () – C:\Users\Kiki Wiki\dadpininfo.png
[2012/03/18 17:54:51 | 000,016,304 | —- | C] () – C:\Windows\System32\apl003.sys
[2012/03/18 17:54:51 | 000,013,232 | —- | C] () – C:\Windows\System32\apf003.sys
[2011/11/23 14:58:11 | 000,012,920 | —- | C] () – C:\Windows\System32\apl001.sys
[2011/11/23 14:58:11 | 000,010,872 | —- | C] () – C:\Windows\System32\apf001.sys
[2011/03/21 19:56:22 | 000,059,904 | —- | C] () – C:\Windows\System32\OVDecode.dll
[2010/12/24 19:31:07 | 000,000,118 | —- | C] () – C:\Windows\wininit.ini
[2010/03/18 13:01:56 | 000,000,092 | —- | C] () – C:\Users\Kiki Wiki\mm.cfg
[2010/03/18 12:02:48 | 000,000,160 | —- | C] () – C:\Users\Kiki Wiki\.gtkrc-2.0
[2009/10/21 17:41:46 | 000,000,104 | —- | C] () – C:\Users\Kiki Wiki\Games - Shortcut.lnk

========== Alternate Data Streams ==========

@Alternate Data Stream - 64 bytes -> C:\Users\Kiki Wiki\Documents\Pop'n Music 1 - Free Mode - I really want to hurt you(Hard).avi:TOC.WMV
@Alternate Data Stream - 64 bytes -> C:\Users\Kiki Wiki\Documents\clip0026.avi:TOC.WMV
@Alternate Data Stream - 64 bytes -> C:\Users\Kiki Wiki\Documents\clip0025.avi:TOC.WMV
@Alternate Data Stream - 64 bytes -> C:\Users\Kiki Wiki\Documents\clip0021.avi:TOC.WMV
@Alternate Data Stream - 64 bytes -> C:\Users\Kiki Wiki\Documents\clip0004.avi:TOC.WMV
@Alternate Data Stream - 64 bytes -> C:\Users\Kiki Wiki\Documents\clip0001.avi:TOC.WMV
@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:5C321E34

< End of report >
Hi Somethingsimple,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.


Let's try this:

Download ComboFix:

http://download.bleepingcomputer.com/sUBs/ComboFix.exe

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://forums.whatthetech.com/How_Disable_…ams_t96260.html

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
ComboFix 12-08-10.02 - Kiki Wiki 08/12/2012 13:51:20.3.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3453.1885 [GMT -7:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
SP: Microsoft Security Essentials *Disabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Kiki Wiki\AppData\Local\.#
c:\users\Kiki Wiki\Documents\~WRL0005.tmp
.
.
((((((((((((((((((((((((( Files Created from 2012-07-12 to 2012-08-12 )))))))))))))))))))))))))))))))
.
.
2012-08-12 21:01 . 2012-08-12 21:02 ——– dc—-w- c:\users\Kiki Wiki\AppData\Local\temp
2012-08-12 21:01 . 2012-08-12 21:01 ——– dc—-w- c:\users\Default\AppData\Local\temp
2012-08-12 21:01 . 2012-08-12 21:01 ——– d—–w- c:\users\Public\AppData\Local\temp
2012-08-12 19:57 . 2012-08-12 20:46 ——– dc—-w- c:\users\Kiki Wiki\AppData\Local\MigWiz
2012-08-12 17:21 . 2012-08-12 17:21 29904 -c–a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{4ABEB7D7-3EFC-4221-9F33-05DFF6643804}\MpKslf3611ee0.sys
2012-08-12 16:22 . 2012-08-12 16:22 63115 -c–a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\USERTILE.JS
2012-08-12 16:22 . 2012-08-12 16:22 4599 -c–a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\UIRESOURCE.JS
2012-08-12 16:22 . 2012-08-12 16:22 9310 -c–a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\TEXTBOX.JS
2012-08-12 16:22 . 2012-08-12 16:22 8646 -c–a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\TILEBOX.JS
2012-08-12 16:22 . 2012-08-12 16:22 8613 -c–a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\SAVEDUSER.JS
2012-08-12 16:22 . 2012-08-12 16:22 6429 -c–a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\UICORE.JS
2012-08-12 16:22 . 2012-08-12 16:22 5927 -c–a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\TEXT.JS
2012-08-12 16:22 . 2012-08-12 16:22 1651 -c–a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\QUERYSTRING.JS
2012-08-12 16:22 . 2012-08-12 16:22 6910 -c–a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\NEWUSERCOMM.JS
2012-08-12 16:22 . 2012-08-12 16:22 18541 -c–a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\LOCALIZATION.JS
2012-08-12 16:21 . 2012-08-12 16:21 8288 -c–a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\IMAGE.JS
2012-08-12 16:21 . 2012-08-12 16:21 6208 -c–a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\LINK.JS
2012-08-12 16:21 . 2012-08-12 16:21 51852 -c–a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\EXTERNALWRAPPER.JS
2012-08-12 16:21 . 2012-08-12 16:21 20719 -c–a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\DIVWRAPPER.JS
2012-08-12 16:21 . 2012-08-12 16:21 8782 -c–a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\BUTTON.JS
2012-08-12 16:21 . 2012-08-12 16:21 7271 -c–a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\CHECKBOX.JS
2012-08-12 16:21 . 2012-08-12 16:21 23327 -c–a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\COMBOBOX.JS
2012-08-11 18:28 . 2012-06-29 08:44 6891424 -c–a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{4ABEB7D7-3EFC-4221-9F33-05DFF6643804}\mpengine.dll
2012-08-09 17:45 . 2012-06-29 08:44 6891424 -c–a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-08-08 16:17 . 2012-01-03 07:03 810496 —-a-w- c:\windows\system32\xvidcore.dll
2012-08-08 16:17 . 2012-01-03 07:03 80896 —-a-w- c:\windows\system32\ff_vfw.dll
2012-08-08 16:17 . 2012-01-03 07:03 183808 —-a-w- c:\windows\system32\xvidvfw.dll
2012-08-08 16:17 . 2012-01-03 07:03 389120 —-a-w- c:\windows\system32\actskn43.ocx
2012-08-08 03:34 . 2012-08-08 03:39 ——– dc—-w- c:\users\Kiki Wiki\AppData\Local\ManyCam
2012-08-08 03:34 . 2012-08-08 03:34 ——– dc—-w- c:\programdata\ManyCam
2012-08-08 03:34 . 2012-08-08 03:39 ——– d—–w- c:\users\Kiki Wiki\AppData\Roaming\ManyCam
2012-08-08 03:32 . 2012-08-08 03:36 ——– dc—-w- c:\program files\ManyCam
2012-08-08 03:32 . 2012-08-08 03:32 ——– dc—-w- c:\programdata\Ask
2012-08-04 05:27 . 2012-08-04 05:27 ——– dc—-w- c:\users\Kiki Wiki\AppData\Local\DDMSettings
2012-08-04 05:24 . 2012-08-08 23:52 ——– dc—-w- c:\users\Kiki Wiki\AppData\Local\Procaster
2012-08-04 05:24 . 2012-08-04 05:24 ——– dc—-w- c:\program files\Livestream Procaster
2012-07-19 16:28 . 2012-07-19 16:28 2106216 -c–a-w- c:\program files\Mozilla Firefox\D3DCompiler_43.dll
2012-07-19 16:28 . 2012-07-19 16:28 18912 -c–a-w- c:\program files\Mozilla Firefox\AccessibleMarshal.dll
2012-07-19 16:28 . 2012-07-19 16:28 136672 -c–a-w- c:\program files\Mozilla Firefox\components\browsercomps.dll
2012-07-19 16:28 . 2012-07-19 16:28 117728 -c–a-w- c:\program files\Mozilla Firefox\crashreporter.exe
2012-07-19 16:28 . 2012-07-19 16:28 1998168 -c–a-w- c:\program files\Mozilla Firefox\d3dx9_43.dll
2012-07-19 16:28 . 2012-07-19 16:28 913888 -c–a-w- c:\program files\Mozilla Firefox\firefox.exe
2012-07-19 16:28 . 2012-07-19 16:28 573920 -c–a-w- c:\program files\Mozilla Firefox\gkmedias.dll
2012-07-19 16:28 . 2012-07-19 16:28 258528 -c–a-w- c:\program files\Mozilla Firefox\freebl3.dll
2012-07-19 16:28 . 2012-07-19 16:28 82400 -c–a-w- c:\program files\Mozilla Firefox\libEGL.dll
2012-07-19 16:28 . 2012-07-19 16:28 425952 -c–a-w- c:\program files\Mozilla Firefox\libGLESv2.dll
2012-07-19 16:28 . 2012-07-19 16:28 113120 -c–a-w- c:\program files\Mozilla Firefox\maintenanceservice.exe
2012-07-14 19:40 . 2012-07-14 19:40 ——– d—–w- c:\users\Kiki Wiki\AppData\Roaming\DVDVideoSoftIEHelpers
2012-07-14 19:37 . 2012-07-13 00:13 405144 —-a-w- c:\windows\system32\Newtonsoft.Json.Net20.dll
2012-07-14 04:46 . 2012-07-14 05:05 ——– dc—-w- c:\program files\dvd43
2012-07-14 04:41 . 2012-07-14 04:41 ——– dc—-w- c:\programdata\DVD Shrink
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-08-02 17:25 . 2012-04-04 03:57 426184 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-08-02 17:25 . 2011-05-16 23:17 70344 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-07-08 19:32 . 2012-07-08 19:32 278992 —-a-w- c:\users\Kiki Wiki\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Telestream\Wirecast\Wirecast_4.exe
2012-07-03 20:46 . 2010-05-11 21:50 22344 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-06-13 13:40 . 2012-07-10 20:05 2047488 —-a-w- c:\windows\system32\win32k.sys
2012-06-05 16:47 . 2012-07-10 18:47 1401856 —-a-w- c:\windows\system32\msxml6.dll
2012-06-05 16:47 . 2012-07-10 18:47 1248768 —-a-w- c:\windows\system32\msxml3.dll
2012-06-04 15:26 . 2012-07-10 18:48 440704 —-a-w- c:\windows\system32\drivers\ksecdd.sys
2012-06-02 22:19 . 2012-06-24 03:47 171904 —-a-w- c:\windows\system32\wuwebv.dll
2012-06-02 22:19 . 2012-06-24 03:48 45080 —-a-w- c:\windows\system32\wups2.dll
2012-06-02 22:19 . 2012-06-24 03:48 53784 —-a-w- c:\windows\system32\wuauclt.exe
2012-06-02 22:19 . 2012-06-24 03:47 35864 —-a-w- c:\windows\system32\wups.dll
2012-06-02 22:19 . 2012-06-24 03:47 577048 —-a-w- c:\windows\system32\wuapi.dll
2012-06-02 22:19 . 2012-06-24 03:48 1933848 —-a-w- c:\windows\system32\wuaueng.dll
2012-06-02 22:12 . 2012-06-24 03:48 2422272 —-a-w- c:\windows\system32\wucltux.dll
2012-06-02 22:12 . 2012-06-24 03:47 33792 —-a-w- c:\windows\system32\wuapp.exe
2012-06-02 22:12 . 2012-06-24 03:47 88576 —-a-w- c:\windows\system32\wudriver.dll
2012-06-02 08:33 . 2012-07-10 19:59 1800192 —-a-w- c:\windows\system32\jscript9.dll
2012-06-02 08:25 . 2012-07-10 19:59 1129472 —-a-w- c:\windows\system32\wininet.dll
2012-06-02 08:25 . 2012-07-10 19:59 1427968 —-a-w- c:\windows\system32\inetcpl.cpl
2012-06-02 08:20 . 2012-07-10 19:59 142848 —-a-w- c:\windows\system32\ieUnatt.exe
2012-06-02 08:16 . 2012-07-10 19:59 2382848 —-a-w- c:\windows\system32\mshtml.tlb
2012-06-02 00:04 . 2012-07-10 18:48 278528 —-a-w- c:\windows\system32\schannel.dll
2012-06-02 00:03 . 2012-07-10 18:48 204288 —-a-w- c:\windows\system32\ncrypt.dll
2012-07-19 16:28 . 2012-07-19 16:28 136672 -c–a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2012-07-13 17418928]
"DeSmuMe"="c:\users\Kiki Wiki\Desktop\DeSmuME - Shortcut.lnk" [2012-01-31 971]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-03-20 1451304]
"SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2011-03-28 10029672]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920]
"StartCCC"="c:\program files\ATI\ATI.ACE\Core-Static\CLIStart.exe" [2010-02-11 61440]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2012-04-04 446392]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-27 931200]
"AdobeCS6ServiceManager"="c:\program files\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" [2012-06-25 1073352]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-17 252296]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Secunia PSI Tray.lnk - c:\program files\Secunia\PSI\psi_tray.exe [2010-12-21 291896]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
"HideFastUserSwitching"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^NETGEAR WG111T Smart Wizard.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\NETGEAR WG111T Smart Wizard.lnk
backup=c:\windows\pss\NETGEAR WG111T Smart Wizard.lnk.CommonStartup
backupExtension=.CommonStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon]
2011-09-27 14:22 59240 —-a-w- c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BambooCore]
2011-09-27 03:45 646232 —-a-w- c:\program files\Bamboo Dock\BambooCore.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2012-04-19 03:56 421888 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2012-01-17 18:07 252296 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
.
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [x]
.
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - MPKSLF3611EE0
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
.
2012-08-12 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-04 17:25]
.
.
——- Supplementary Scan ——-
.
uInternet Settings,ProxyOverride = *.local;
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Free YouTube Download - c:\users\Kiki Wiki\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm
IE: Free YouTube to MP3 Converter - c:\users\Kiki Wiki\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Save YouTube Video as MP3 - c:\program files\Common Files\DVDVideoSoft\Dll\IEContextMenuY.dll/scriptY2MP3.htm
TCP: DhcpNameServer = 192.168.0.1 [removed]
FF - ProfilePath - c:\users\Kiki Wiki\AppData\Roaming\Mozilla\Firefox\Profiles\ibtx2mq3.default\
FF - prefs.js: browser.startup.homepage - hxxp://go.microsoft.com/fwlink/?LinkId=69157
FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.interrupt.parsing - true
FF - user.js: content.max.tokenizing.time - 2250000
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 750000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 750000
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 0
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
FF - user.js: general.useragent.extra.brc -
.
.
——- File Associations ——-
.
JSEFile=NOTEPAD.EXE %1
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - (no file)
MSConfigStartUp-AdobeCS5ServiceManager - c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-08-12 14:02
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
.
c:\users\KIKIWI~1\AppData\Local\Temp\catchme.dll 53248 bytes executable
.
scan completed successfully
hidden files: 1
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
Completion time: 2012-08-12 14:06:10
ComboFix-quarantined-files.txt 2012-08-12 21:06
.
Pre-Run: 79,577,333,760 bytes free
Post-Run: 79,528,173,568 bytes free
.
- - End Of File - - EBE4BC41F7BA34CE2AA3DFF2BEF1CABD

Question, I recently tried to transfer old files via my network connection from here to my new laptop before running combofix. The transfer didn't complete (I stopped it) but I'm worried that I infected my new laptop.
That's a possibility… but honestly I haven't really found a problem with your computer as far as malware goes. All that's been done so far is a little straightening up.

Let's get an online scan.

Go here to run an online scanner from ESET.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan completes, press the LIST OF THREATS FOUND button
  • Press EXPORT TO TEXT FILE , name the file ESETSCAN and save it to your desktop
  • Include the contents of this report in your next reply.
  • Press the BACK button.
  • Press Finish
C:\Users\Kiki Wiki\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Telestream\Wirecast\Wirecast_4.exe Win32/Adware.1ClickDownload.C application
COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    File::
    C:\Users\Kiki Wiki\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Telestream\Wirecast\Wirecast_4.exe
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
ComboFix 12-08-10.02 - Kiki Wiki 08/12/2012 21:03:20.4.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3453.1730 [GMT -7:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\Kiki Wiki\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
SP: Microsoft Security Essentials *Disabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\users\Kiki Wiki\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Telestream\Wirecast\Wirecast_4.exe"
.
.
((((((((((((((((((((((((( Files Created from 2012-07-13 to 2012-08-13 )))))))))))))))))))))))))))))))
.
.
2012-08-13 04:12 . 2012-08-13 04:12 ——– dc—-w- c:\users\Kiki Wiki\AppData\Local\temp
2012-08-13 04:12 . 2012-08-13 04:12 ——– dc—-w- c:\users\Guest\AppData\Local\temp
2012-08-13 04:12 . 2012-08-13 04:12 ——– dc—-w- c:\users\Default\AppData\Local\temp
2012-08-13 04:12 . 2012-08-13 04:12 ——– d—–w- c:\users\Public\AppData\Local\temp
2012-08-13 01:02 . 2012-08-13 01:02 ——– dc—-w- c:\program files\ESET
2012-08-12 22:39 . 2012-08-12 22:39 56200 -c–a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{9E1C432D-F6EF-4346-AEFD-CC3C97770F15}\offreg.dll
2012-08-12 22:37 . 2012-06-29 08:44 6891424 -c–a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{9E1C432D-F6EF-4346-AEFD-CC3C97770F15}\mpengine.dll
2012-08-12 19:57 . 2012-08-12 20:46 ——– dc—-w- c:\users\Kiki Wiki\AppData\Local\MigWiz
2012-08-12 16:22 . 2012-08-12 16:22 63115 -c–a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\USERTILE.JS
2012-08-12 16:22 . 2012-08-12 16:22 4599 -c–a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\UIRESOURCE.JS
2012-08-12 16:22 . 2012-08-12 16:22 9310 -c–a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\TEXTBOX.JS
2012-08-12 16:22 . 2012-08-12 16:22 8646 -c–a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\TILEBOX.JS
2012-08-12 16:22 . 2012-08-12 16:22 8613 -c–a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\SAVEDUSER.JS
2012-08-12 16:22 . 2012-08-12 16:22 6429 -c–a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\UICORE.JS
2012-08-12 16:22 . 2012-08-12 16:22 5927 -c–a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\TEXT.JS
2012-08-12 16:22 . 2012-08-12 16:22 1651 -c–a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\QUERYSTRING.JS
2012-08-12 16:22 . 2012-08-12 16:22 6910 -c–a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\NEWUSERCOMM.JS
2012-08-12 16:22 . 2012-08-12 16:22 18541 -c–a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\LOCALIZATION.JS
2012-08-12 16:21 . 2012-08-12 16:21 8288 -c–a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\IMAGE.JS
2012-08-12 16:21 . 2012-08-12 16:21 6208 -c–a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\LINK.JS
2012-08-12 16:21 . 2012-08-12 16:21 51852 -c–a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\EXTERNALWRAPPER.JS
2012-08-12 16:21 . 2012-08-12 16:21 20719 -c–a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\DIVWRAPPER.JS
2012-08-12 16:21 . 2012-08-12 16:21 8782 -c–a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\BUTTON.JS
2012-08-12 16:21 . 2012-08-12 16:21 7271 -c–a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\CHECKBOX.JS
2012-08-12 16:21 . 2012-08-12 16:21 23327 -c–a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\COMBOBOX.JS
2012-08-11 18:28 . 2012-06-29 08:44 6891424 -c–a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-08-08 16:17 . 2012-01-03 07:03 810496 —-a-w- c:\windows\system32\xvidcore.dll
2012-08-08 16:17 . 2012-01-03 07:03 80896 —-a-w- c:\windows\system32\ff_vfw.dll
2012-08-08 16:17 . 2012-01-03 07:03 183808 —-a-w- c:\windows\system32\xvidvfw.dll
2012-08-08 16:17 . 2012-01-03 07:03 389120 —-a-w- c:\windows\system32\actskn43.ocx
2012-08-08 03:34 . 2012-08-08 03:39 ——– dc—-w- c:\users\Kiki Wiki\AppData\Local\ManyCam
2012-08-08 03:34 . 2012-08-08 03:34 ——– dc—-w- c:\programdata\ManyCam
2012-08-08 03:34 . 2012-08-08 03:39 ——– d—–w- c:\users\Kiki Wiki\AppData\Roaming\ManyCam
2012-08-08 03:32 . 2012-08-08 03:36 ——– dc—-w- c:\program files\ManyCam
2012-08-08 03:32 . 2012-08-08 03:32 ——– dc—-w- c:\programdata\Ask
2012-08-04 05:27 . 2012-08-04 05:27 ——– dc—-w- c:\users\Kiki Wiki\AppData\Local\DDMSettings
2012-08-04 05:24 . 2012-08-08 23:52 ——– dc—-w- c:\users\Kiki Wiki\AppData\Local\Procaster
2012-08-04 05:24 . 2012-08-04 05:24 ——– dc—-w- c:\program files\Livestream Procaster
2012-07-19 16:28 . 2012-07-19 16:28 2106216 -c–a-w- c:\program files\Mozilla Firefox\D3DCompiler_43.dll
2012-07-19 16:28 . 2012-07-19 16:28 18912 -c–a-w- c:\program files\Mozilla Firefox\AccessibleMarshal.dll
2012-07-19 16:28 . 2012-07-19 16:28 136672 -c–a-w- c:\program files\Mozilla Firefox\components\browsercomps.dll
2012-07-19 16:28 . 2012-07-19 16:28 117728 -c–a-w- c:\program files\Mozilla Firefox\crashreporter.exe
2012-07-19 16:28 . 2012-07-19 16:28 1998168 -c–a-w- c:\program files\Mozilla Firefox\d3dx9_43.dll
2012-07-19 16:28 . 2012-07-19 16:28 913888 -c–a-w- c:\program files\Mozilla Firefox\firefox.exe
2012-07-19 16:28 . 2012-07-19 16:28 573920 -c–a-w- c:\program files\Mozilla Firefox\gkmedias.dll
2012-07-19 16:28 . 2012-07-19 16:28 258528 -c–a-w- c:\program files\Mozilla Firefox\freebl3.dll
2012-07-19 16:28 . 2012-07-19 16:28 82400 -c–a-w- c:\program files\Mozilla Firefox\libEGL.dll
2012-07-19 16:28 . 2012-07-19 16:28 425952 -c–a-w- c:\program files\Mozilla Firefox\libGLESv2.dll
2012-07-19 16:28 . 2012-07-19 16:28 113120 -c–a-w- c:\program files\Mozilla Firefox\maintenanceservice.exe
2012-07-14 19:40 . 2012-07-14 19:40 ——– d—–w- c:\users\Kiki Wiki\AppData\Roaming\DVDVideoSoftIEHelpers
2012-07-14 19:37 . 2012-07-13 00:13 405144 —-a-w- c:\windows\system32\Newtonsoft.Json.Net20.dll
2012-07-14 04:46 . 2012-07-14 05:05 ——– dc—-w- c:\program files\dvd43
2012-07-14 04:41 . 2012-07-14 04:41 ——– dc—-w- c:\programdata\DVD Shrink
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-08-02 17:25 . 2012-04-04 03:57 426184 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-08-02 17:25 . 2011-05-16 23:17 70344 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-07-08 19:32 . 2012-07-08 19:32 278992 —-a-w- c:\users\Kiki Wiki\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Telestream\Wirecast\Wirecast_4.exe
2012-07-03 20:46 . 2010-05-11 21:50 22344 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-06-13 13:40 . 2012-07-10 20:05 2047488 —-a-w- c:\windows\system32\win32k.sys
2012-06-05 16:47 . 2012-07-10 18:47 1401856 —-a-w- c:\windows\system32\msxml6.dll
2012-06-05 16:47 . 2012-07-10 18:47 1248768 —-a-w- c:\windows\system32\msxml3.dll
2012-06-04 15:26 . 2012-07-10 18:48 440704 —-a-w- c:\windows\system32\drivers\ksecdd.sys
2012-06-02 22:19 . 2012-06-24 03:47 171904 —-a-w- c:\windows\system32\wuwebv.dll
2012-06-02 22:19 . 2012-06-24 03:48 45080 —-a-w- c:\windows\system32\wups2.dll
2012-06-02 22:19 . 2012-06-24 03:48 53784 —-a-w- c:\windows\system32\wuauclt.exe
2012-06-02 22:19 . 2012-06-24 03:47 35864 —-a-w- c:\windows\system32\wups.dll
2012-06-02 22:19 . 2012-06-24 03:47 577048 —-a-w- c:\windows\system32\wuapi.dll
2012-06-02 22:19 . 2012-06-24 03:48 1933848 —-a-w- c:\windows\system32\wuaueng.dll
2012-06-02 22:12 . 2012-06-24 03:48 2422272 —-a-w- c:\windows\system32\wucltux.dll
2012-06-02 22:12 . 2012-06-24 03:47 33792 —-a-w- c:\windows\system32\wuapp.exe
2012-06-02 22:12 . 2012-06-24 03:47 88576 —-a-w- c:\windows\system32\wudriver.dll
2012-06-02 08:33 . 2012-07-10 19:59 1800192 —-a-w- c:\windows\system32\jscript9.dll
2012-06-02 08:25 . 2012-07-10 19:59 1129472 —-a-w- c:\windows\system32\wininet.dll
2012-06-02 08:25 . 2012-07-10 19:59 1427968 —-a-w- c:\windows\system32\inetcpl.cpl
2012-06-02 08:20 . 2012-07-10 19:59 142848 —-a-w- c:\windows\system32\ieUnatt.exe
2012-06-02 08:16 . 2012-07-10 19:59 2382848 —-a-w- c:\windows\system32\mshtml.tlb
2012-06-02 00:04 . 2012-07-10 18:48 278528 —-a-w- c:\windows\system32\schannel.dll
2012-06-02 00:03 . 2012-07-10 18:48 204288 —-a-w- c:\windows\system32\ncrypt.dll
2012-07-19 16:28 . 2012-07-19 16:28 136672 -c–a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2012-07-13 17418928]
"DeSmuMe"="c:\users\Kiki Wiki\Desktop\DeSmuME - Shortcut.lnk" [2012-01-31 971]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-03-20 1451304]
"SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2011-03-28 10029672]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920]
"StartCCC"="c:\program files\ATI\ATI.ACE\Core-Static\CLIStart.exe" [2010-02-11 61440]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2012-04-04 446392]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-27 931200]
"AdobeCS6ServiceManager"="c:\program files\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" [2012-06-25 1073352]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-17 252296]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Secunia PSI Tray.lnk - c:\program files\Secunia\PSI\psi_tray.exe [2010-12-21 291896]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
"HideFastUserSwitching"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^NETGEAR WG111T Smart Wizard.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\NETGEAR WG111T Smart Wizard.lnk
backup=c:\windows\pss\NETGEAR WG111T Smart Wizard.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon]
2011-09-27 14:22 59240 —-a-w- c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BambooCore]
2011-09-27 03:45 646232 —-a-w- c:\program files\Bamboo Dock\BambooCore.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2012-04-19 03:56 421888 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2012-01-17 18:07 252296 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
.
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [x]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
.
2012-08-13 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-04 17:25]
.
.
——- Supplementary Scan ——-
.
uInternet Settings,ProxyOverride = *.local;
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Free YouTube Download - c:\users\Kiki Wiki\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm
IE: Free YouTube to MP3 Converter - c:\users\Kiki Wiki\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Save YouTube Video as MP3 - c:\program files\Common Files\DVDVideoSoft\Dll\IEContextMenuY.dll/scriptY2MP3.htm
TCP: DhcpNameServer = 192.168.0.1 [removed]
FF - ProfilePath - c:\users\Kiki Wiki\AppData\Roaming\Mozilla\Firefox\Profiles\ibtx2mq3.default\
FF - prefs.js: browser.startup.homepage - hxxp://go.microsoft.com/fwlink/?LinkId=69157
FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.interrupt.parsing - true
FF - user.js: content.max.tokenizing.time - 2250000
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 750000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 750000
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 0
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
FF - user.js: general.useragent.extra.brc -
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-08-12 21:12
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
Completion time: 2012-08-12 21:15:36
ComboFix-quarantined-files.txt 2012-08-13 04:15
ComboFix2.txt 2012-08-12 21:06
.
Pre-Run: 79,139,557,376 bytes free
Post-Run: 79,092,416,512 bytes free
.
- - End Of File - - 2F92B646977684F87A7FFBC6FF598631
Let's have a look at some services.

Please download Farbar Service Scanner and run it on the computer with the issue.
  • Make sure "Include All Files" option remains checked.
  • Press "Scan".
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please copy and paste the log to your reply.
Farbar Service Scanner Version: 06-08-2012 Ran by [removed] (administrator) on 12-08-2012 at 21:41:29 Running from "C:\Users\Kiki Wiki\Downloads" Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) Boot Mode: Normal **************************************************************** Internet Services: ============ Connection Status: ============== Localhost is accessible. LAN connected. Google IP is accessible. Google.com is accessible. Yahoo IP is accessible. Yahoo.com is accessible. Windows Firewall: ============= Firewall Disabled Policy: ================== System Restore: ============ System Restore Disabled Policy: ======================== Security Center: ============ Windows Update: ============ Windows Autoupdate Disabled Policy: ============================ Windows Defender: ============== WinDefend Service is not running. Checking service configuration: The start type of WinDefend service is set to Demand. The default start type is Auto. The ImagePath of WinDefend service is OK. The ServiceDll of WinDefend service is OK. Windows Defender Disabled Policy: ========================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender] "DisableAntiSpyware"=DWORD:1 Other Services: ============== File Check: ======== C:\Windows\system32\nsisvc.dll => MD5 is legit C:\Windows\system32\Drivers\nsiproxy.sys => MD5 is legit C:\Windows\system32\dhcpcsvc.dll => MD5 is legit C:\Windows\system32\Drivers\afd.sys => MD5 is legit C:\Windows\system32\Drivers\tdx.sys => MD5 is legit C:\Windows\system32\Drivers\tcpip.sys => MD5 is legit C:\Windows\system32\dnsrslvr.dll => MD5 is legit C:\Windows\system32\mpssvc.dll => MD5 is legit C:\Windows\system32\bfe.dll => MD5 is legit C:\Windows\system32\Drivers\mpsdrv.sys => MD5 is legit C:\Windows\system32\SDRSVC.dll => MD5 is legit C:\Windows\system32\vssvc.exe => MD5 is legit C:\Windows\system32\wscsvc.dll => MD5 is legit C:\Windows\system32\wbem\WMIsvc.dll => MD5 is legit C:\Windows\system32\wuaueng.dll => MD5 is legit C:\Windows\system32\qmgr.dll => MD5 is legit C:\Windows\system32\es.dll => MD5 is legit C:\Windows\system32\cryptsvc.dll => MD5 is legit C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit C:\Windows\system32\ipnathlp.dll [2009-06-23 14:43] - [2008-01-18 23:34] - 0288256 ____A (Microsoft Corporation) E1499BD0FF76B1B2FBBF1AF339D91165 C:\Windows\system32\svchost.exe => MD5 is legit C:\Windows\system32\rpcss.dll => MD5 is legit **** End of log ****
That's all good.

I'm thinking this isn't a malware issue so I'm of little help to you. I suggest that you seek help from the Tech Team in the Windows forum. When you post there, please include a link back to this thread so that they can see the information you have posted here.

But first, we need to cleanup.

  • Click START then RUN
  • Now type ComboFix /Uninstall in the runbox and click OK.
  • Note the space between the X and the U, it needs to be there.
  • [external image: Posted Image]
The above procedure will:
  • Implement some cleanup procedures.
  • Reset System Restore.

  • Double click on OTL to run it.
  • Click on CleanUp!
  • When done, you will be prompted to restart your computer. Please restart your computer.

Please re-enable any security that was disabled.


The following is my standard advice for the future. Use what you can and pat yourself on the back for what you're already doing.

Please take time to read Preventing Malware - Tools and Practices for Safe Computing. Very important information for your consideration is contained therein.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein


Also: "How to prevent malware"
by miekiemoes

Please respond back that you understand the above and let me know if you have any questions. Otherwise, this thread will be closed Resolved. :thumbup:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI