This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trojan Horse Hider victim? [Solved]

41 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Thanks Robybel! Here is the Malwarebytes log: Malwarebytes Anti-Malware 1.70.0.1100 www.malwarebytes.org Database version: v2013.02.07.08 Windows Vista Service Pack 1 x86 NTFS Internet Explorer 8.0.6001.19088 Dennis :: DENNIS-PC [administrator] 07/02/2013 19:18:59 mbam-log-2013-02-07 (19-18-59).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 232987 Time elapsed: 6 minute(s), 45 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) My ESET log: C:\Users\Dennis\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\7\5a014607-54ad0ce3 multiple threats C:\_OTL\MovedFiles\01312013_120007\C_Users\Dennis\7105783.exe a variant of Win32/Kryptik.ATKJ trojan Cheers
Hi Dirk4 ;)

Your java is out of date. Click your start button, open Control panel.
  • Locate the Java icon (it looks like a coffee cup)
  • double click it to open it
  • click the Update tab
  • Click update now

After the java is updated, reboot your computer if not prompted to.

Next, clear the java cache

To clear the Java Plug-in cache:
  • Click Start > Control Panel.
  • Double-click the Java icon in the control panel.
  • On the General tab, Click Settings under Temporary Internet Files.
  • On the Temporary Files Settings screen, Click Delete Files.
  • check all boxes
  • Click OK

Please let me know how your machine is running and if there are any outstanding issues
Hi Robybel, Done. But what about those infected files ESET found. Have they been removed? Rest seems ok. I am running AVG now, just to check. Edit: AVG found (and removed) a trojan: Whole computer scan High priority;"1";"1";"0" Folders selected for scanning:;"Scan whole computer" Started/finished:;"08/02/2013, 15:45:04 / 08/02/2013, 16:53:03" Total object scanned:;"2075276" User who launched the scan:;"Dennis" Status;"Priority";"Name";"Description";"Result" Healed;"High";"Trojan horse Generic31.ARJH";"C:\_OTL\MovedFiles\01312013_120007\C_Users\Dennis\7105783.exe";"Moved to Virus Vault" Cheers
Hi Dirk4 ;)

what about those infected files ESET found. Have they been removed?

The item AVG removed was already in the OTL quarantine :)

Now follow this step

Run OTL

  • Open OTL again and click the Quick Scan button (don't check the boxes beside LOP Check or Purity this time)
  • Post the OTL.txt log it produces in your next reply.

:wavey:
Hi Robybel,

Thanks. Here the scan log.
Strange thing is that I left the LOP Check or Purity boxes unchecked,as you suggested, but whenever i start the scan the are automatically checked!
I tried several times, but it always happens. Below the scan with LOP Check or Purity boxes checked:

OTL logfile created on: 10/02/2013 14:06:18 - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Dennis\Desktop
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19088)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.75 Gb Total Physical Memory | 2.41 Gb Available Physical Memory | 64.22% Memory free
7.67 Gb Paging File | 6.38 Gb Available in Paging File | 83.19% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 136.43 Gb Total Space | 15.11 Gb Free Space | 11.08% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 4.70 Gb Free Space | 47.00% Space Free | Partition Type: NTFS

Computer Name: DENNIS-PC | User Name: Dennis | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Program Files\AVG Secure Search\vprot.exe ()
PRC - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\14.0.1\ToolbarUpdater.exe ()
PRC - C:\Users\Dennis\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Steam\steam.exe (Valve Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Common Files\Comodo\launcher_service.exe (Comodo Security Solutions Inc.)
PRC - C:\Program Files\Common Files\Comodo\GeekBuddyRSP.exe (Comodo Security Solutions, Inc.)
PRC - C:\Program Files\AVG\AVG2013\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgemcx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Online Armor\oasrv.exe (Emsisoft GmbH)
PRC - C:\Program Files\Online Armor\oaui.exe (Emsisoft GmbH)
PRC - C:\Program Files\Online Armor\oahlp.exe (Emsisoft GmbH)
PRC - C:\Program Files\Online Armor\oacat.exe (Emsisoft GmbH)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe (IDT, Inc.)
PRC - C:\Windows\System32\stacsv.exe (IDT, Inc.)
PRC - C:\Windows\System32\AEstSrv.exe (Andrea Electronics Corporation)
PRC - C:\Windows\OEM02Mon.exe (Creative Technology Ltd.)
PRC - C:\Program Files\Dell\MediaDirect\PCMService.exe (CyberLink Corp.)
PRC - C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe (Creative Technology Ltd.)
PRC - C:\Program Files\DellTPad\hidfind.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\ApMsgFwd.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\ApntEx.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc)
PRC - C:\Program Files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe (Matsushita Electric Industrial Co., Ltd.)
PRC - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe (Sonic Solutions)
PRC - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe (Sonic Solutions)
PRC - C:\Program Files\Saitek\Software\SaiMfd.exe (Saitek)
PRC - C:\Program Files\Saitek\Software\ProfilerU.exe (Saitek)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\AVG Secure Search\vprot.exe ()
MOD - C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\14.0.1\SiteSafety.dll ()
MOD - C:\Program Files\Steam\sdl.dll ()
MOD - C:\Program Files\Steam\bin\libcef.dll ()
MOD - C:\Program Files\Steam\bin\avcodec-53.dll ()
MOD - C:\Program Files\Steam\bin\chromehtml.dll ()
MOD - C:\Program Files\Steam\bin\avformat-53.dll ()
MOD - C:\Program Files\Steam\bin\avutil-51.dll ()
MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\Program Files\Google\Google Desktop Search\gzlib.dll ()
MOD - C:\Program Files\Perfect Uninstaller\Contextmenu.dll ()
MOD - C:\Program Files\WinRAR\RarExt.dll ()
MOD - C:\Program Files\Dell\QuickSet\dadkeyb.dll ()
MOD - C:\Program Files\Common Files\Roxio Shared\9.0\DLLShared\LayoutDll9.dll ()
MOD - C:\Program Files\Common Files\Roxio Shared\9.0\DLLShared\ROXIPP41.dll ()
MOD - C:\Program Files\Saitek\Software\SAICFG.dll ()


========== Services (SafeList) ==========

SRV - (sprtsvc_dellsupportcenter) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe /service /p dellsupportcenter File not found
SRV - (vToolbarUpdater14.0.1) – C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\14.0.1\ToolbarUpdater.exe ()
SRV - (Steam Client Service) – C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
SRV - (CLPSLauncher) – C:\Program Files\Common Files\Comodo\launcher_service.exe (Comodo Security Solutions Inc.)
SRV - (GeekBuddyRSP) – C:\Program Files\Common Files\Comodo\GeekBuddyRSP.exe (Comodo Security Solutions, Inc.)
SRV - (avgwd) – C:\Program Files\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (SvcOnlineArmor) – C:\Program Files\Online Armor\oasrv.exe (Emsisoft GmbH)
SRV - (OAcat) – C:\Program Files\Online Armor\oacat.exe (Emsisoft GmbH)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (STacSV) – C:\Windows\System32\stacsv.exe (IDT, Inc.)
SRV - (AESTFilters) – C:\Windows\System32\AEstSrv.exe (Andrea Electronics Corporation)


========== Driver Services (SafeList) ==========

DRV - (NwlnkFwd) – system32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – system32\DRIVERS\nwlnkflt.sys File not found
DRV - (Lbd) – system32\DRIVERS\Lbd.sys File not found
DRV - (IpInIp) – system32\DRIVERS\ipinip.sys File not found
DRV - (catchme) – C:\Users\Dennis\AppData\Local\Temp\catchme.sys File not found
DRV - (blbdrive) – C:\Windows\system32\drivers\blbdrive.sys File not found
DRV - (avgtp) – C:\Windows\System32\drivers\avgtpx86.sys (AVG Technologies)
DRV - (CFRMD) – C:\Windows\System32\drivers\CFRMD.sys (Windows ® Win 7 DDK provider)
DRV - (Avgmfx86) – C:\Windows\System32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSDriver) – C:\Windows\System32\drivers\avgidsdriverx.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSHX) – C:\Windows\System32\drivers\avgidshx.sys (AVG Technologies CZ, s.r.o. )
DRV - (oahlpXX) – C:\Windows\System32\drivers\oahlp32.sys ()
DRV - (OAnet) – C:\Windows\System32\drivers\OAnet.sys (Emsisoft)
DRV - (OAmon) – C:\Windows\System32\drivers\OAmon.sys (Emsisoft)
DRV - (OADevice) – C:\Windows\System32\drivers\OADriver.sys ()
DRV - (Avgldx86) – C:\Windows\System32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgtdix) – C:\Windows\System32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avglogx) – C:\Windows\System32\drivers\avglogx.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSShim) – C:\Windows\System32\drivers\avgidsshimx.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgrkx86) – C:\Windows\System32\drivers\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (mferkdk) – C:\Windows\System32\drivers\mferkdk.sys (McAfee, Inc.)
DRV - (STHDA) – C:\Windows\System32\drivers\stwrt.sys (IDT, Inc.)
DRV - (OEM02Vfx) – C:\Windows\System32\drivers\OEM02Vfx.sys (EyePower Games Pte. Ltd.)
DRV - (OEM02Dev) – C:\Windows\System32\drivers\OEM02Dev.sys (Creative Technology Ltd.)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (Point32) – C:\Windows\System32\drivers\point32k.sys (Microsoft Corporation)
DRV - (NETw4v32) – C:\Windows\System32\drivers\NETw4v32.sys (Intel Corporation)
DRV - (ApfiltrService) – C:\Windows\System32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (bcm4sbxp) – C:\Windows\System32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (rimsptsk) – C:\Windows\System32\drivers\rimsptsk.sys (REDC)
DRV - (rismxdp) – C:\Windows\System32\drivers\rixdptsk.sys (REDC)
DRV - (rimmptsk) – C:\Windows\System32\drivers\rimmptsk.sys (REDC)
DRV - (R300) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (e1express) – C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (SaiNtBus) – C:\Windows\System32\drivers\SaiBus.sys (Saitek)
DRV - (SaiMini) – C:\Windows\System32\drivers\SaiMini.sys (Saitek)
DRV - (SaiH0461) – C:\Windows\System32\drivers\SaiH0461.sys (Saitek)
DRV - (ss_mdm) – C:\Windows\System32\drivers\ss_mdm.sys (MCCI)
DRV - (ss_mdfl) – C:\Windows\System32\drivers\ss_mdfl.sys (MCCI)
DRV - (ss_bus) – C:\Windows\System32\drivers\ss_bus.sys (MCCI)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {0633ee93-d776-472f-a0ff-e1416b8b2e3a}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…amp;rlz=1I7DKUK

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.co.uk/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
FF - prefs.js..browser.search.param.yahoo-fr: "chrf-comodo"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "chrf-comodo"
FF - prefs.js..browser.search.selectedEngine: "AVG Secure Search"
FF - prefs.js..extensions.enabledAddons: {CAFEEFAC-0016-0000-0039-ABCDEFFEDCBA}:6.0.39
FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:3.3.1
FF - prefs.js..extensions.enabledItems: {534EBA91-5C43-4711-AA70-5C4ECF671FED}:1.9.1
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_5_502_146.dll ()
FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\14.0.1\\npsitesafety.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_39: C:\Windows\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\ProgramData\AVG Secure Search\FireFoxExt\14.0.0.14 [2013/02/02 14:33:18 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/01/31 12:41:43 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/01/31 12:00:07 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{534EBA91-5C43-4711-AA70-5C4ECF671FED}: C:\Users\Dennis\AppData\Local\{534EBA91-5C43-4711-AA70-5C4ECF671FED}

[2009/02/17 20:25:06 | 000,000,000 | —D | M] (No name found) – C:\Users\Dennis\AppData\Roaming\Mozilla\Extensions
[2012/11/27 20:07:09 | 000,000,000 | —D | M] (No name found) – C:\Users\Dennis\AppData\Roaming\Mozilla\Firefox\Profiles\nulwxz0d.default\extensions
[2011/01/09 20:13:28 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Dennis\AppData\Roaming\Mozilla\Firefox\Profiles\nulwxz0d.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2013/02/08 15:27:50 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2013/02/08 15:27:50 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0039-ABCDEFFEDCBA}
[2012/11/26 21:52:22 | 000,097,208 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/11/26 21:52:19 | 000,001,525 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2013/02/02 14:33:17 | 000,003,598 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml
[2012/11/26 21:52:19 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/11/26 21:52:19 | 000,000,935 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
[2012/11/26 21:52:19 | 000,001,166 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
[2012/11/26 21:52:19 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml
[2012/11/26 21:52:19 | 000,001,121 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml

========== Chrome ==========


O1 HOSTS File: ([2013/02/02 14:58:09 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O4 - HKLM..\Run: [@OnlineArmor GUI] C:\Program Files\Online Armor\oaui.exe (Emsisoft GmbH)
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [AVG_UI] C:\Program Files\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [DELL Webcam Manager] C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [ECenter] C:\DELL\E-Center\EULALauncher.exe ( )
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NVHotkey] C:\Windows\System32\nvHotkey.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvSvc] C:\Windows\System32\nvsvc.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [PCMService] C:\Program Files\Dell\MediaDirect\PCMService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [Profiler] C:\Program Files\Saitek\Software\ProfilerU.exe (Saitek)
O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe (Sonic Solutions)
O4 - HKLM..\Run: [SaiMfd] C:\Program Files\Saitek\Software\SaiMfd.exe (Saitek)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [vProt] C:\Program Files\AVG Secure Search\vprot.exe ()
O4 - HKCU..\Run: [Steam] C:\Program Files\Steam\Steam.exe (Valve Corporation)
O4 - Startup: C:\Users\Dennis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\BeNaughtyChat.lnk = C:\Program Files\BeNaughtyChat\BeNaughtyChat.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnableShellExecuteHooks = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/8/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} http://dl.tvunetworks.com/TVUAx.cab (CTVUAxCtrl Object)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab (DivXBrowserPlugin Object)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_39)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-0016-0000-0039-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_39)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_39)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B1E45316-623A-47F4-AE3A-51183EE97AFA}: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (Logitech Inc.)
O18 - Protocol\Filter\application/x-internet-signup {A173B69A-1F9B-4823-9FDA-412F641E65D6} - C:\Program Files\Tiscali\Tiscali Internet\dlls\tiscalifilter.dll ()
O18 - Protocol\Filter\x-sdch - No CLSID value found
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Dennis\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Dennis\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O28 - HKLM ShellExecuteHooks: {4F07DA45-8170-4859-9B5F-037EF2970034} - C:\Program Files\Online Armor\oaevent.dll (Emsisoft GmbH)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 21:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2013/02/08 17:01:43 | 000,000,000 | —D | C] – C:\Users\Dennis\AppData\Roaming\OnlineArmor
[2013/02/08 17:01:43 | 000,000,000 | —D | C] – C:\ProgramData\OnlineArmor
[2013/02/08 16:59:28 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Online Armor
[2013/02/08 16:59:27 | 000,031,768 | —- | C] (Emsisoft) – C:\Windows\System32\drivers\OAnet.sys
[2013/02/08 16:59:27 | 000,027,648 | —- | C] (Emsisoft) – C:\Windows\System32\drivers\OAmon.sys
[2013/02/08 16:59:22 | 000,000,000 | —D | C] – C:\Program Files\Online Armor
[2013/02/08 15:44:57 | 000,000,000 | —D | C] – C:\Users\Dennis\AppData\Roaming\AVG2013
[2013/02/08 15:43:44 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
[2013/02/08 15:43:03 | 000,000,000 | -H-D | C] – C:\$AVG
[2013/02/08 15:43:02 | 000,000,000 | —D | C] – C:\ProgramData\AVG2013
[2013/02/08 15:41:18 | 000,000,000 | —D | C] – C:\Program Files\AVG
[2013/02/08 15:28:21 | 000,000,000 | —D | C] – C:\ProgramData\Sun
[2013/02/07 19:30:38 | 002,322,184 | —- | C] (ESET) – C:\Users\Dennis\Desktop\esetsmartinstaller_enu.exe
[2013/02/07 19:15:27 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/02/07 19:15:22 | 000,021,104 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2013/02/07 19:15:22 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2013/02/04 22:32:28 | 000,000,000 | —D | C] – C:\Windows\ERUNT
[2013/02/04 22:32:23 | 000,000,000 | —D | C] – C:\JRT
[2013/02/04 22:24:15 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2013/02/04 21:56:17 | 000,000,000 | —D | C] – C:\Users\Dennis\AppData\Local\Avg2013
[2013/02/04 21:40:59 | 000,547,275 | —- | C] (Oleg N. Scherbakov) – C:\Users\Dennis\Desktop\JRT.exe
[2013/02/02 14:38:22 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2013/02/02 14:38:22 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2013/02/02 14:38:22 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2013/02/02 14:36:40 | 000,000,000 | —D | C] – C:\Qoobox
[2013/02/02 14:36:11 | 000,000,000 | —D | C] – C:\Windows\erdnt
[2013/02/02 14:33:27 | 000,000,000 | —D | C] – C:\Users\Dennis\AppData\Local\AVG Secure Search
[2013/02/02 14:33:20 | 000,000,000 | —D | C] – C:\ProgramData\AVG Security Toolbar
[2013/02/02 14:33:12 | 000,031,576 | —- | C] (AVG Technologies) – C:\Windows\System32\drivers\avgtpx86.sys
[2013/02/02 14:33:07 | 000,000,000 | —D | C] – C:\Program Files\Common Files\AVG Secure Search
[2013/02/02 14:33:06 | 000,000,000 | —D | C] – C:\Program Files\AVG Secure Search
[2013/02/02 14:06:27 | 005,029,149 | R— | C] (Swearware) – C:\Users\Dennis\Desktop\ComboFix.exe
[2013/01/31 19:58:25 | 000,000,000 | —D | C] – C:\ProgramData\AVG Secure Search
[2013/01/31 12:00:07 | 000,000,000 | —D | C] – C:\_OTL
[2013/01/30 18:37:10 | 000,000,000 | —D | C] – C:\Users\Dennis\Desktop\tdsskiller
[2013/01/28 20:44:36 | 004,732,416 | —- | C] (AVAST Software) – C:\Users\Dennis\Desktop\aswMBR.exe
[2013/01/28 17:14:30 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Dennis\Desktop\OTL.exe
[2013/01/22 18:25:44 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\Dennis\Desktop\HiJackThis.exe
[2013/01/22 17:59:12 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2013/01/22 17:59:12 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2013/01/22 17:40:14 | 000,000,000 | —D | C] – C:\Users\Dennis\AppData\Local\Macromedia
[2013/01/22 14:43:00 | 000,000,000 | —D | C] – C:\Users\Dennis\AppData\Roaming\TuneUp Software
[2013/01/22 14:37:43 | 000,000,000 | -H-D | C] – C:\ProgramData\Common Files
[2013/01/22 14:37:43 | 000,000,000 | —D | C] – C:\Users\Dennis\AppData\Local\MFAData
[2013/01/22 14:37:43 | 000,000,000 | —D | C] – C:\ProgramData\MFAData
[2013/01/22 14:30:23 | 000,000,000 | —D | C] – C:\ProgramData\COMODO
[2013/01/22 14:29:58 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Comodo
[2013/01/22 14:29:42 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Comodo
[2013/01/22 14:29:41 | 000,000,000 | —D | C] – C:\Users\Dennis\AppData\Local\Comodo
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/02/10 14:17:59 | 000,000,564 | —- | M] () – C:\Windows\tasks\PCDoctorBackgroundMonitorTask.job
[2013/02/10 14:07:59 | 000,000,506 | —- | M] () – C:\Windows\tasks\SystemToolsDailyTest.job
[2013/02/10 14:03:47 | 000,101,990 | —- | M] () – C:\Users\Dennis\AppData\Roaming\nvModes.001
[2013/02/10 14:03:44 | 000,002,485 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\QuickSet.lnk
[2013/02/10 14:03:25 | 000,000,882 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore1cd990a101d3260.job
[2013/02/10 14:03:10 | 000,003,696 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013/02/10 14:03:09 | 000,003,696 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013/02/10 14:03:04 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/02/10 14:02:54 | 4024,479,744 | -HS- | M] () – C:\hiberfil.sys
[2013/02/08 16:55:09 | 000,000,876 | —- | M] () – C:\Users\Dennis\Desktop\AVG log.csv
[2013/02/08 15:43:44 | 000,000,844 | —- | M] () – C:\Users\Public\Desktop\AVG 2013.lnk
[2013/02/07 19:30:42 | 002,322,184 | —- | M] (ESET) – C:\Users\Dennis\Desktop\esetsmartinstaller_enu.exe
[2013/02/07 19:16:33 | 000,000,932 | —- | M] () – C:\Users\Dennis\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes Anti-Malware.lnk
[2013/02/07 19:16:33 | 000,000,908 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/02/06 21:38:09 | 000,198,144 | —- | M] () – C:\Users\Dennis\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/02/04 21:41:01 | 000,547,275 | —- | M] (Oleg N. Scherbakov) – C:\Users\Dennis\Desktop\JRT.exe
[2013/02/02 14:58:09 | 000,000,027 | —- | M] () – C:\Windows\System32\drivers\etc\hosts
[2013/02/02 14:33:01 | 000,031,576 | —- | M] (AVG Technologies) – C:\Windows\System32\drivers\avgtpx86.sys
[2013/02/02 14:06:36 | 005,029,149 | R— | M] (Swearware) – C:\Users\Dennis\Desktop\ComboFix.exe
[2013/01/31 12:40:02 | 000,580,235 | —- | M] () – C:\Users\Dennis\Desktop\adwcleaner.exe
[2013/01/30 18:34:52 | 002,195,061 | —- | M] () – C:\Users\Dennis\Desktop\tdsskiller.zip
[2013/01/28 20:50:59 | 000,000,575 | —- | M] () – C:\Users\Dennis\Desktop\MBR_Dirk4.zip
[2013/01/28 20:49:39 | 000,000,512 | —- | M] () – C:\Users\Dennis\Desktop\MBR.dat
[2013/01/28 20:44:53 | 004,732,416 | —- | M] (AVAST Software) – C:\Users\Dennis\Desktop\aswMBR.exe
[2013/01/28 17:14:33 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Dennis\Desktop\OTL.exe
[2013/01/22 18:25:45 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Dennis\Desktop\HiJackThis.exe
[2013/01/22 14:30:04 | 000,001,926 | —- | M] () – C:\Users\Public\Desktop\AntiError.lnk
[2013/01/22 14:30:04 | 000,001,922 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Start GeekBuddy.lnk
[2013/01/22 14:30:04 | 000,001,922 | —- | M] () – C:\Users\Public\Desktop\GeekBuddy.lnk
[2013/01/22 14:04:26 | 001,474,832 | —- | M] () – C:\Windows\System32\drivers\sfi.dat
[2013/01/20 19:26:22 | 000,101,990 | —- | M] () – C:\Users\Dennis\AppData\Roaming\nvModes.dat
[2013/01/17 16:20:20 | 000,001,997 | —- | M] () – C:\Users\Dennis\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/02/08 16:59:27 | 000,208,320 | —- | C] () – C:\Windows\System32\drivers\OADriver.sys
[2013/02/08 16:59:27 | 000,044,992 | —- | C] () – C:\Windows\System32\drivers\oahlp32.sys
[2013/02/08 16:55:09 | 000,000,876 | —- | C] () – C:\Users\Dennis\Desktop\AVG log.csv
[2013/02/08 15:43:44 | 000,000,844 | —- | C] () – C:\Users\Public\Desktop\AVG 2013.lnk
[2013/02/07 19:16:33 | 000,000,932 | —- | C] () – C:\Users\Dennis\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes Anti-Malware.lnk
[2013/02/07 19:16:33 | 000,000,908 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/02/07 19:13:36 | 4024,479,744 | -HS- | C] () – C:\hiberfil.sys
[2013/02/02 14:38:22 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2013/02/02 14:38:22 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2013/02/02 14:38:22 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2013/02/02 14:38:22 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2013/02/02 14:38:22 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2013/01/31 12:39:59 | 000,580,235 | —- | C] () – C:\Users\Dennis\Desktop\adwcleaner.exe
[2013/01/30 18:34:50 | 002,195,061 | —- | C] () – C:\Users\Dennis\Desktop\tdsskiller.zip
[2013/01/28 20:50:59 | 000,000,575 | —- | C] () – C:\Users\Dennis\Desktop\MBR_Dirk4.zip
[2013/01/28 20:49:39 | 000,000,512 | —- | C] () – C:\Users\Dennis\Desktop\MBR.dat
[2013/01/22 14:30:04 | 000,001,926 | —- | C] () – C:\Users\Public\Desktop\AntiError.lnk
[2013/01/22 14:30:04 | 000,001,922 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Start GeekBuddy.lnk
[2013/01/22 14:30:04 | 000,001,922 | —- | C] () – C:\Users\Public\Desktop\GeekBuddy.lnk
[2012/11/28 23:27:13 | 000,106,605 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2012/11/28 23:27:13 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2011/06/09 19:11:14 | 001,474,832 | —- | C] () – C:\Windows\System32\drivers\sfi.dat
[2011/03/06 21:34:03 | 000,011,882 | -HS- | C] () – C:\Users\Dennis\AppData\Local\1670194319
[2009/12/02 13:22:04 | 000,000,063 | —- | C] () – C:\Users\Dennis\.structure
[2008/09/08 09:11:42 | 000,008,268 | —- | C] () – C:\Users\Dennis\AppData\Local\d3d9caps.dat
[2008/03/03 23:08:38 | 000,000,000 | —- | C] () – C:\Users\Dennis\AppData\Roaming\wklnhst.dat
[2008/02/28 20:47:38 | 000,101,990 | —- | C] () – C:\Users\Dennis\AppData\Roaming\nvModes.001
[2008/02/28 19:54:26 | 000,101,990 | —- | C] () – C:\Users\Dennis\AppData\Roaming\nvModes.dat
[2008/02/28 18:58:55 | 000,198,144 | —- | C] () – C:\Users\Dennis\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

========== ZeroAccess Check ==========

[2006/11/02 12:54:22 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2011/01/21 15:46:32 | 011,582,464 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2009/03/03 04:36:24 | 000,615,424 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2008/01/19 07:36:49 | 000,347,648 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2011/07/07 21:46:19 | 000,000,000 | —D | M] – C:\Users\Dennis\AppData\Roaming\Akigo
[2013/02/08 15:44:57 | 000,000,000 | —D | M] – C:\Users\Dennis\AppData\Roaming\AVG2013
[2011/08/10 22:06:30 | 000,000,000 | —D | M] – C:\Users\Dennis\AppData\Roaming\BeNaughtyChat
[2012/07/07 23:24:50 | 000,000,000 | —D | M] – C:\Users\Dennis\AppData\Roaming\Dropbox
[2013/02/08 17:02:22 | 000,000,000 | —D | M] – C:\Users\Dennis\AppData\Roaming\OnlineArmor
[2008/04/04 16:24:01 | 000,000,000 | —D | M] – C:\Users\Dennis\AppData\Roaming\Panasonic
[2011/05/24 20:12:37 | 000,000,000 | —D | M] – C:\Users\Dennis\AppData\Roaming\PCDr
[2012/07/24 21:33:02 | 000,000,000 | —D | M] – C:\Users\Dennis\AppData\Roaming\Sports Interactive
[2008/03/03 23:08:39 | 000,000,000 | —D | M] – C:\Users\Dennis\AppData\Roaming\Template
[2013/01/22 14:43:00 | 000,000,000 | —D | M] – C:\Users\Dennis\AppData\Roaming\TuneUp Software
[2011/06/27 18:18:32 | 000,000,000 | —D | M] – C:\Users\Dennis\AppData\Roaming\Wutog

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Documents\Sports Interactive:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Documents\processPurchaseResponse.do_files:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Documents\Nationwide Internet banking signup_files:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Documents\My Received Files:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Documents\fcgheevi2.jpg:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Documents\fcgheevi1.jpg:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Documents\Dell Webcam Center:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Documents\bevestigingDVDpap_files:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Documents\aBHbAwAALilM.jpg:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Documents\__MACOSX:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Desktop\tdsskiller:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Desktop\Scotland march 2012:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Desktop\New Folder:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Desktop\[Classic, 1982] Taboo II (Dorothy LeMay, Honey Wilder).avi:Roxio EMC Stream

< End of report >
Hi Dirk4 ;)

You will need to have hidden files and folders showing for these next instructions (as explained in post 15.)

please navigate to the following folders and advise if they are empty, if they contain files, please list the content (if there are lots of files, just give an estimate of the number rather than list them out)

C:\Users\Dennis\AppData\Local\1670194319
C:\Users\Dennis\AppData\Roaming\Wutog

thanks B)

C:\Users\Dennis\AppData\Local\1670194319

This appears to be no folder, but just a file. A system file.

C:\Users\Dennis\AppData\Roaming\Wutog

One file called ynwyu.ymu
Hi Dirk4 ;)

Please go to: VirusTotal
  • [external image: Posted Image]
  • Click the Browse button and search for the following file:

    C:\Users\Dennis\AppData\Roaming\Wutog\ynwyu.ymu

  • Click Open
  • Then click Send File
  • Please be patient while the file is scanned.
  • Once the scan results appear, please provide them in your next reply.
If it says already scanned – click "reanalyze now"

Please repeat the steps for the following file

C:\Users\Dennis\AppData\Local\1670194319

Please post the results in your next reply.
Hi Robybel, Your link didn't work, so i had to go to the main page. I did the scan from there. It looked at little different, but I think it did the same analysis; SHA256: f8dcafd80aa4ee1bfc2d357d66aa28a95031458d50677af1aaf34daf5ab0ed32 SHA1: 81120079915cdc4695745136c06b7241991dffc1 MD5: a36b8af093d93c06670b75cf658213ea File size: 291.5 KB ( 298484 bytes ) File name: ynwyu.ymu File type: unknown Detection ratio: 0 / 45 Analysis date: 2013-02-13 18:58:53 UTC ( 0 minutes ago ) Antivirus Result Update ViRobot - 20130213 VIPRE - 20130213 VBA32 - 20130213 TrendMicro-HouseCall - 20130213 TrendMicro - 20130213 TotalDefense - 20130213 TheHacker - 20130212 Symantec - 20130213 SUPERAntiSpyware - 20130213 Sophos - 20130213 Rising - 20130205 PCTools - 20130213 Panda - 20130213 nProtect - 20130213 Norman - 20130213 NANO-Antivirus - 20130213 MicroWorld-eScan - 20130213 Microsoft - 20130213 McAfee-GW-Edition - 20130213 McAfee - 20130213 Malwarebytes - 20130213 Kingsoft - 20130204 Kaspersky - 20130213 K7AntiVirus - 20130213 Jiangmin - 20130213 Ikarus - 20130213 GData - 20130213 Fortinet - 20130213 F-Secure - 20130213 F-Prot - 20130213 ESET-NOD32 - 20130213 eSafe - 20130211 Emsisoft - 20130213 Comodo - 20130213 Commtouch - 20130213 ClamAV - 20130213 CAT-QuickHeal - 20130213 ByteHero - 20130211 BitDefender - 20130213 AVG - 20130213 Avast - 20130213 Antiy-AVL - 20130213 AntiVir - 20130213 AhnLab-V3 - 20130213 Agnitum - 20130213 SHA256: 2f8348a2c5b285fd842f698fd9931ae27dd7cc64ba1d01c541432fb3adb271ee SHA1: 1ff84cf094396bef9ed38f70c02f34ab4f20a85c MD5: 90ba81c239e61dcbab03a22d17fe35d3 File size: 11.6 KB ( 11882 bytes ) File name: 1670194319 File type: unknown Detection ratio: 1 / 45 Analysis date: 2013-02-13 19:04:36 UTC ( 1 minute ago ) Antivirus Result Update ViRobot - 20130213 VIPRE - 20130213 VBA32 - 20130213 TrendMicro-HouseCall - 20130213 TrendMicro - 20130213 TotalDefense - 20130213 TheHacker - 20130212 Symantec - 20130213 SUPERAntiSpyware - 20130213 Sophos Mal/FakeAvCn-C 20130213 Rising - 20130205 PCTools - 20130213 Panda - 20130213 nProtect - 20130213 Norman - 20130213 NANO-Antivirus - 20130213 MicroWorld-eScan - 20130213 Microsoft - 20130213 McAfee-GW-Edition - 20130213 McAfee - 20130213 Malwarebytes - 20130213 Kingsoft - 20130204 Kaspersky - 20130213 K7AntiVirus - 20130213 Jiangmin - 20130213 Ikarus - 20130213 GData - 20130213 Fortinet - 20130213 F-Secure - 20130213 F-Prot - 20130213 ESET-NOD32 - 20130213 eSafe - 20130211 Emsisoft - 20130213 Comodo - 20130213 Commtouch - 20130213 ClamAV - 20130213 CAT-QuickHeal - 20130213 ByteHero - 20130211 BitDefender - 20130213 AVG - 20130213 Avast - 20130213 Antiy-AVL - 20130213 AntiVir - 20130213 AhnLab-V3 - 20130213 Agnitum - 20130213
Hi Dirk4 ;)

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    [2011/03/06 21:34:03 | 000,011,882 | -HS- | C] () – C:\Users\Dennis\AppData\Local\1670194319
    [2011/06/27 18:18:32 | 000,000,000 | —D | M] – C:\Users\Dennis\AppData\Roaming\Wutog
    
    :Files
    ipconfig /flushdns /c
    
    :Commands
    [EMPTYFLASH]
    [REBOOT]
    [RESETHOSTS]
    [CREATERESTOREPOINT]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post Fix OTL log as well as a new OTL log by rerunning it after reboot without custom scans script.
Hi, Tried two runs but when rebooting I don't get an automatic fix log file. Also I can't find that file on my desktop? The otl log file on my desktop appears to be one generated a few days ago Please advise.
Hi Dirk4 ;)

Tried two runs but when rebooting I don't get an automatic fix log file

No problem :)

Re-Run OTL

  • Open OTL again and click the Quick Scan button (don't check the boxes beside LOP Check or Purity this time)
  • Post the OTL.txt log it produces in your next reply.
Hi Robybel,

Oops, I did the 'full scan'.

Here is the full scan log. I'll post the 'quick scan log' in a minute.:

OTL logfile created on: 17/02/2013 14:23:05 - Run 4
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Dennis\Desktop
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19088)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.75 Gb Total Physical Memory | 2.44 Gb Available Physical Memory | 65.00% Memory free
7.68 Gb Paging File | 6.31 Gb Available in Paging File | 82.16% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 136.43 Gb Total Space | 13.81 Gb Free Space | 10.12% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 4.54 Gb Free Space | 45.40% Space Free | Partition Type: NTFS

Computer Name: DENNIS-PC | User Name: Dennis | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Program Files\Steam\steam.exe (Valve Corporation)
PRC - C:\Program Files\AVG Secure Search\vprot.exe ()
PRC - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\14.1.7\ToolbarUpdater.exe ()
PRC - C:\Users\Dennis\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Common Files\Comodo\launcher_service.exe (Comodo Security Solutions Inc.)
PRC - C:\Program Files\Common Files\Comodo\GeekBuddyRSP.exe (Comodo Security Solutions, Inc.)
PRC - C:\Program Files\AVG\AVG2013\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgemcx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Online Armor\oasrv.exe (Emsisoft GmbH)
PRC - C:\Program Files\Online Armor\oaui.exe (Emsisoft GmbH)
PRC - C:\Program Files\Online Armor\oahlp.exe (Emsisoft GmbH)
PRC - C:\Program Files\Online Armor\oacat.exe (Emsisoft GmbH)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe (IDT, Inc.)
PRC - C:\Windows\System32\stacsv.exe (IDT, Inc.)
PRC - C:\Windows\System32\AEstSrv.exe (Andrea Electronics Corporation)
PRC - C:\Windows\OEM02Mon.exe (Creative Technology Ltd.)
PRC - C:\Program Files\Dell\MediaDirect\PCMService.exe (CyberLink Corp.)
PRC - C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe (Creative Technology Ltd.)
PRC - C:\Program Files\DellTPad\hidfind.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\ApMsgFwd.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\ApntEx.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc)
PRC - C:\Program Files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe (Matsushita Electric Industrial Co., Ltd.)
PRC - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe (Sonic Solutions)
PRC - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe (Sonic Solutions)
PRC - C:\Program Files\Saitek\Software\SaiMfd.exe (Saitek)
PRC - C:\Program Files\Saitek\Software\ProfilerU.exe (Saitek)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\AVG Secure Search\vprot.exe ()
MOD - C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\14.1.7\SiteSafety.dll ()
MOD - C:\Program Files\Steam\sdl.dll ()
MOD - C:\Program Files\Steam\bin\libcef.dll ()
MOD - C:\Program Files\Steam\bin\avcodec-53.dll ()
MOD - C:\Program Files\Steam\bin\chromehtml.dll ()
MOD - C:\Program Files\Steam\bin\avformat-53.dll ()
MOD - C:\Program Files\Steam\bin\avutil-51.dll ()
MOD - C:\Program Files\Perfect Uninstaller\Contextmenu.dll ()
MOD - C:\Program Files\WinRAR\RarExt.dll ()
MOD - C:\Program Files\Dell\QuickSet\dadkeyb.dll ()
MOD - C:\Program Files\Common Files\Roxio Shared\9.0\DLLShared\LayoutDll9.dll ()
MOD - C:\Program Files\Common Files\Roxio Shared\9.0\DLLShared\ROXIPP41.dll ()
MOD - C:\Program Files\Saitek\Software\SAICFG.dll ()


========== Services (SafeList) ==========

SRV - (sprtsvc_dellsupportcenter) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe /service /p dellsupportcenter File not found
SRV - (vToolbarUpdater14.1.7) – C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\14.1.7\ToolbarUpdater.exe ()
SRV - (Steam Client Service) – C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
SRV - (CLPSLauncher) – C:\Program Files\Common Files\Comodo\launcher_service.exe (Comodo Security Solutions Inc.)
SRV - (GeekBuddyRSP) – C:\Program Files\Common Files\Comodo\GeekBuddyRSP.exe (Comodo Security Solutions, Inc.)
SRV - (avgwd) – C:\Program Files\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (SvcOnlineArmor) – C:\Program Files\Online Armor\oasrv.exe (Emsisoft GmbH)
SRV - (OAcat) – C:\Program Files\Online Armor\oacat.exe (Emsisoft GmbH)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (STacSV) – C:\Windows\System32\stacsv.exe (IDT, Inc.)
SRV - (AESTFilters) – C:\Windows\System32\AEstSrv.exe (Andrea Electronics Corporation)


========== Driver Services (SafeList) ==========

DRV - (NwlnkFwd) – system32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – system32\DRIVERS\nwlnkflt.sys File not found
DRV - (Lbd) – system32\DRIVERS\Lbd.sys File not found
DRV - (IpInIp) – system32\DRIVERS\ipinip.sys File not found
DRV - (catchme) – C:\Users\Dennis\AppData\Local\Temp\catchme.sys File not found
DRV - (blbdrive) – C:\Windows\system32\drivers\blbdrive.sys File not found
DRV - (avgtp) – C:\Windows\System32\drivers\avgtpx86.sys (AVG Technologies)
DRV - (CFRMD) – C:\Windows\System32\drivers\CFRMD.sys (Windows ® Win 7 DDK provider)
DRV - (Avgmfx86) – C:\Windows\System32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSDriver) – C:\Windows\System32\drivers\avgidsdriverx.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSHX) – C:\Windows\System32\drivers\avgidshx.sys (AVG Technologies CZ, s.r.o. )
DRV - (oahlpXX) – C:\Windows\System32\drivers\oahlp32.sys ()
DRV - (OAnet) – C:\Windows\System32\drivers\OAnet.sys (Emsisoft)
DRV - (OAmon) – C:\Windows\System32\drivers\OAmon.sys (Emsisoft)
DRV - (OADevice) – C:\Windows\System32\drivers\OADriver.sys ()
DRV - (Avgldx86) – C:\Windows\System32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgtdix) – C:\Windows\System32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avglogx) – C:\Windows\System32\drivers\avglogx.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSShim) – C:\Windows\System32\drivers\avgidsshimx.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgrkx86) – C:\Windows\System32\drivers\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (mferkdk) – C:\Windows\System32\drivers\mferkdk.sys (McAfee, Inc.)
DRV - (STHDA) – C:\Windows\System32\drivers\stwrt.sys (IDT, Inc.)
DRV - (OEM02Vfx) – C:\Windows\System32\drivers\OEM02Vfx.sys (EyePower Games Pte. Ltd.)
DRV - (OEM02Dev) – C:\Windows\System32\drivers\OEM02Dev.sys (Creative Technology Ltd.)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (Point32) – C:\Windows\System32\drivers\point32k.sys (Microsoft Corporation)
DRV - (NETw4v32) – C:\Windows\System32\drivers\NETw4v32.sys (Intel Corporation)
DRV - (ApfiltrService) – C:\Windows\System32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (bcm4sbxp) – C:\Windows\System32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (rimsptsk) – C:\Windows\System32\drivers\rimsptsk.sys (REDC)
DRV - (rismxdp) – C:\Windows\System32\drivers\rixdptsk.sys (REDC)
DRV - (rimmptsk) – C:\Windows\System32\drivers\rimmptsk.sys (REDC)
DRV - (R300) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (e1express) – C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (SaiNtBus) – C:\Windows\System32\drivers\SaiBus.sys (Saitek)
DRV - (SaiMini) – C:\Windows\System32\drivers\SaiMini.sys (Saitek)
DRV - (SaiH0461) – C:\Windows\System32\drivers\SaiH0461.sys (Saitek)
DRV - (ss_mdm) – C:\Windows\System32\drivers\ss_mdm.sys (MCCI)
DRV - (ss_mdfl) – C:\Windows\System32\drivers\ss_mdfl.sys (MCCI)
DRV - (ss_bus) – C:\Windows\System32\drivers\ss_bus.sys (MCCI)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {0633ee93-d776-472f-a0ff-e1416b8b2e3a}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…amp;rlz=1I7DKUK

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.co.uk/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
FF - prefs.js..browser.search.param.yahoo-fr: "chrf-comodo"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "chrf-comodo"
FF - prefs.js..browser.search.selectedEngine: "AVG Secure Search"
FF - prefs.js..extensions.enabledAddons: {CAFEEFAC-0016-0000-0039-ABCDEFFEDCBA}:6.0.39
FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:3.3.1
FF - prefs.js..extensions.enabledItems: {534EBA91-5C43-4711-AA70-5C4ECF671FED}:1.9.1
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_5_502_146.dll ()
FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\14.1.7\\npsitesafety.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_39: C:\Windows\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\ProgramData\AVG Secure Search\FireFoxExt\14.1.0.10 [2013/02/13 23:40:13 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/01/31 12:41:43 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/01/31 12:00:07 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{534EBA91-5C43-4711-AA70-5C4ECF671FED}: C:\Users\Dennis\AppData\Local\{534EBA91-5C43-4711-AA70-5C4ECF671FED}

[2009/02/17 20:25:06 | 000,000,000 | —D | M] (No name found) – C:\Users\Dennis\AppData\Roaming\Mozilla\Extensions
[2012/11/27 20:07:09 | 000,000,000 | —D | M] (No name found) – C:\Users\Dennis\AppData\Roaming\Mozilla\Firefox\Profiles\nulwxz0d.default\extensions
[2011/01/09 20:13:28 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Dennis\AppData\Roaming\Mozilla\Firefox\Profiles\nulwxz0d.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2013/02/08 15:27:50 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2013/02/08 15:27:50 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0039-ABCDEFFEDCBA}
[2012/11/26 21:52:22 | 000,097,208 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/11/26 21:52:19 | 000,001,525 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2013/02/13 23:39:50 | 000,003,592 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml
[2012/11/26 21:52:19 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/11/26 21:52:19 | 000,000,935 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
[2012/11/26 21:52:19 | 000,001,166 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
[2012/11/26 21:52:19 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml
[2012/11/26 21:52:19 | 000,001,121 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml

========== Chrome ==========

CHR - homepage: http://isearch.avg.com/?cid={C0D01CCA-A789…mp;d=2013-02-02 14:33:13&v=14.0.0.14&pid=avg&sg=&sap=hp
CHR - default_search_provider: AVG Secure Search (Enabled)
CHR - default_search_provider: search_url = http://isearch.avg.com/search?cid={C0D01CC…mp;d=2013-02-02 14:33:13&v=14.0.0.14&pid=avg&sg=&sap=dsp&q={searchTerms}
CHR - default_search_provider: suggest_url =
CHR - homepage: http://isearch.avg.com/?cid={C0D01CCA-A789…mp;d=2013-02-02 14:33:13&v=14.0.0.14&pid=avg&sg=&sap=hp
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\24.0.1312.57\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\24.0.1312.57\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\24.0.1312.57\gcswf32.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 8.0\Reader\Browser\nppdf32.dll
CHR - plugin: BitTorrent (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npbittorrent.dll
CHR - plugin: DivX Web Player (Enabled) = C:\Program Files\DivX\DivX Web Player\npdivx32.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: AVG Security Toolbar = C:\Users\Dennis\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\14.1.0.10_0\

O1 HOSTS File: ([2013/02/16 20:42:40 | 000,000,098 | —- | M]) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\14.1.0.10\AVG Secure Search_toolbar.dll ()
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\14.1.0.10\AVG Secure Search_toolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O4 - HKLM..\Run: [@OnlineArmor GUI] C:\Program Files\Online Armor\oaui.exe (Emsisoft GmbH)
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [AVG_UI] C:\Program Files\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [DELL Webcam Manager] C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [ECenter] C:\DELL\E-Center\EULALauncher.exe ( )
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NVHotkey] C:\Windows\System32\nvHotkey.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvSvc] C:\Windows\System32\nvsvc.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [PCMService] C:\Program Files\Dell\MediaDirect\PCMService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [Profiler] C:\Program Files\Saitek\Software\ProfilerU.exe (Saitek)
O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe (Sonic Solutions)
O4 - HKLM..\Run: [SaiMfd] C:\Program Files\Saitek\Software\SaiMfd.exe (Saitek)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [vProt] C:\Program Files\AVG Secure Search\vprot.exe ()
O4 - HKCU..\Run: [Steam] C:\Program Files\Steam\Steam.exe (Valve Corporation)
O4 - Startup: C:\Users\Dennis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\BeNaughtyChat.lnk = C:\Program Files\BeNaughtyChat\BeNaughtyChat.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnableShellExecuteHooks = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/8/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} http://dl.tvunetworks.com/TVUAx.cab (CTVUAxCtrl Object)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab (DivXBrowserPlugin Object)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_39)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-0016-0000-0039-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_39)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_39)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B1E45316-623A-47F4-AE3A-51183EE97AFA}: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (Logitech Inc.)
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\14.1.7\ViProtocol.dll ()
O18 - Protocol\Filter\application/x-internet-signup {A173B69A-1F9B-4823-9FDA-412F641E65D6} - C:\Program Files\Tiscali\Tiscali Internet\dlls\tiscalifilter.dll ()
O18 - Protocol\Filter\x-sdch - No CLSID value found
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Dennis\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Dennis\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O28 - HKLM ShellExecuteHooks: {4F07DA45-8170-4859-9B5F-037EF2970034} - C:\Program Files\Online Armor\oaevent.dll (Emsisoft GmbH)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 21:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2013/02/17 00:09:27 | 000,000,000 | —D | C] – C:\ProgramData\WindowsSearch
[2013/02/08 17:01:43 | 000,000,000 | —D | C] – C:\Users\Dennis\AppData\Roaming\OnlineArmor
[2013/02/08 17:01:43 | 000,000,000 | —D | C] – C:\ProgramData\OnlineArmor
[2013/02/08 16:59:28 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Online Armor
[2013/02/08 16:59:27 | 000,031,768 | —- | C] (Emsisoft) – C:\Windows\System32\drivers\OAnet.sys
[2013/02/08 16:59:27 | 000,027,648 | —- | C] (Emsisoft) – C:\Windows\System32\drivers\OAmon.sys
[2013/02/08 16:59:22 | 000,000,000 | —D | C] – C:\Program Files\Online Armor
[2013/02/08 15:44:57 | 000,000,000 | —D | C] – C:\Users\Dennis\AppData\Roaming\AVG2013
[2013/02/08 15:43:44 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
[2013/02/08 15:43:03 | 000,000,000 | -H-D | C] – C:\$AVG
[2013/02/08 15:43:02 | 000,000,000 | —D | C] – C:\ProgramData\AVG2013
[2013/02/08 15:41:18 | 000,000,000 | —D | C] – C:\Program Files\AVG
[2013/02/08 15:28:21 | 000,000,000 | —D | C] – C:\ProgramData\Sun
[2013/02/08 15:27:47 | 000,477,616 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\npdeployJava1.dll
[2013/02/08 15:27:47 | 000,473,520 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\deployJava1.dll
[2013/02/08 15:27:47 | 000,158,128 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2013/02/08 15:27:47 | 000,149,936 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2013/02/08 15:27:47 | 000,149,936 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2013/02/07 19:30:38 | 002,322,184 | —- | C] (ESET) – C:\Users\Dennis\Desktop\esetsmartinstaller_enu.exe
[2013/02/07 19:15:27 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/02/07 19:15:22 | 000,021,104 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2013/02/07 19:15:22 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2013/02/04 22:32:28 | 000,000,000 | —D | C] – C:\Windows\ERUNT
[2013/02/04 22:32:23 | 000,000,000 | —D | C] – C:\JRT
[2013/02/04 22:24:15 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2013/02/04 21:56:17 | 000,000,000 | —D | C] – C:\Users\Dennis\AppData\Local\Avg2013
[2013/02/04 21:40:59 | 000,547,275 | —- | C] (Oleg N. Scherbakov) – C:\Users\Dennis\Desktop\JRT.exe
[2013/02/02 14:38:22 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2013/02/02 14:38:22 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2013/02/02 14:38:22 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2013/02/02 14:36:40 | 000,000,000 | —D | C] – C:\Qoobox
[2013/02/02 14:36:11 | 000,000,000 | —D | C] – C:\Windows\erdnt
[2013/02/02 14:33:27 | 000,000,000 | —D | C] – C:\Users\Dennis\AppData\Local\AVG Secure Search
[2013/02/02 14:33:20 | 000,000,000 | —D | C] – C:\ProgramData\AVG Security Toolbar
[2013/02/02 14:33:12 | 000,033,112 | —- | C] (AVG Technologies) – C:\Windows\System32\drivers\avgtpx86.sys
[2013/02/02 14:33:07 | 000,000,000 | —D | C] – C:\Program Files\Common Files\AVG Secure Search
[2013/02/02 14:33:06 | 000,000,000 | —D | C] – C:\Program Files\AVG Secure Search
[2013/02/02 14:06:27 | 005,029,149 | R— | C] (Swearware) – C:\Users\Dennis\Desktop\ComboFix.exe
[2013/01/31 19:58:25 | 000,000,000 | —D | C] – C:\ProgramData\AVG Secure Search
[2013/01/31 12:00:07 | 000,000,000 | —D | C] – C:\_OTL
[2013/01/30 18:37:10 | 000,000,000 | —D | C] – C:\Users\Dennis\Desktop\tdsskiller
[2013/01/28 20:44:36 | 004,732,416 | —- | C] (AVAST Software) – C:\Users\Dennis\Desktop\aswMBR.exe
[2013/01/28 17:14:30 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Dennis\Desktop\OTL.exe
[2013/01/22 18:25:44 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\Dennis\Desktop\HiJackThis.exe
[2013/01/22 17:59:12 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2013/01/22 17:59:12 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2013/01/22 17:40:14 | 000,000,000 | —D | C] – C:\Users\Dennis\AppData\Local\Macromedia
[2013/01/22 17:15:11 | 000,697,864 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerApp.exe
[2013/01/22 14:43:00 | 000,000,000 | —D | C] – C:\Users\Dennis\AppData\Roaming\TuneUp Software
[2013/01/22 14:37:43 | 000,000,000 | -H-D | C] – C:\ProgramData\Common Files
[2013/01/22 14:37:43 | 000,000,000 | —D | C] – C:\Users\Dennis\AppData\Local\MFAData
[2013/01/22 14:37:43 | 000,000,000 | —D | C] – C:\ProgramData\MFAData
[2013/01/22 14:30:23 | 000,000,000 | —D | C] – C:\ProgramData\COMODO
[2013/01/22 14:29:58 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Comodo
[2013/01/22 14:29:42 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Comodo
[2013/01/22 14:29:41 | 000,000,000 | —D | C] – C:\Users\Dennis\AppData\Local\Comodo
[2013/01/22 14:29:19 | 001,700,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\gdiplus.dll
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/02/17 14:29:00 | 000,000,506 | —- | M] () – C:\Windows\tasks\SystemToolsDailyTest.job
[2013/02/17 14:24:59 | 000,000,564 | —- | M] () – C:\Windows\tasks\PCDoctorBackgroundMonitorTask.job
[2013/02/17 12:54:51 | 000,003,696 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013/02/17 12:54:51 | 000,003,696 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013/02/17 10:55:36 | 000,002,485 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\QuickSet.lnk
[2013/02/17 10:55:35 | 000,101,990 | —- | M] () – C:\Users\Dennis\AppData\Roaming\nvModes.001
[2013/02/17 10:54:49 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/02/17 10:54:38 | 4024,479,744 | -HS- | M] () – C:\hiberfil.sys
[2013/02/16 20:42:40 | 000,000,098 | —- | M] () – C:\Windows\System32\drivers\etc\Hosts
[2013/02/13 23:39:44 | 000,033,112 | —- | M] (AVG Technologies) – C:\Windows\System32\drivers\avgtpx86.sys
[2013/02/12 23:07:00 | 000,000,882 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore1ce0975a975bc2f.job
[2013/02/08 16:55:09 | 000,000,876 | —- | M] () – C:\Users\Dennis\Desktop\AVG log.csv
[2013/02/08 15:43:44 | 000,000,844 | —- | M] () – C:\Users\Public\Desktop\AVG 2013.lnk
[2013/02/08 15:27:34 | 000,477,616 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\npdeployJava1.dll
[2013/02/08 15:27:34 | 000,473,520 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\deployJava1.dll
[2013/02/08 15:27:34 | 000,158,128 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2013/02/08 15:27:34 | 000,149,936 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2013/02/08 15:27:34 | 000,149,936 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2013/02/07 19:30:42 | 002,322,184 | —- | M] (ESET) – C:\Users\Dennis\Desktop\esetsmartinstaller_enu.exe
[2013/02/07 19:16:33 | 000,000,932 | —- | M] () – C:\Users\Dennis\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes Anti-Malware.lnk
[2013/02/07 19:16:33 | 000,000,908 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/02/06 21:38:09 | 000,198,144 | —- | M] () – C:\Users\Dennis\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/02/04 21:41:01 | 000,547,275 | —- | M] (Oleg N. Scherbakov) – C:\Users\Dennis\Desktop\JRT.exe
[2013/02/02 14:06:36 | 005,029,149 | R— | M] (Swearware) – C:\Users\Dennis\Desktop\ComboFix.exe
[2013/01/31 12:40:02 | 000,580,235 | —- | M] () – C:\Users\Dennis\Desktop\adwcleaner.exe
[2013/01/30 18:34:52 | 002,195,061 | —- | M] () – C:\Users\Dennis\Desktop\tdsskiller.zip
[2013/01/28 20:50:59 | 000,000,575 | —- | M] () – C:\Users\Dennis\Desktop\MBR_Dirk4.zip
[2013/01/28 20:49:39 | 000,000,512 | —- | M] () – C:\Users\Dennis\Desktop\MBR.dat
[2013/01/28 20:44:53 | 004,732,416 | —- | M] (AVAST Software) – C:\Users\Dennis\Desktop\aswMBR.exe
[2013/01/28 17:14:33 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Dennis\Desktop\OTL.exe
[2013/01/22 18:25:45 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Dennis\Desktop\HiJackThis.exe
[2013/01/22 17:15:11 | 000,697,864 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerApp.exe
[2013/01/22 17:15:11 | 000,074,248 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2013/01/22 14:30:04 | 000,001,926 | —- | M] () – C:\Users\Public\Desktop\AntiError.lnk
[2013/01/22 14:30:04 | 000,001,922 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Start GeekBuddy.lnk
[2013/01/22 14:30:04 | 000,001,922 | —- | M] () – C:\Users\Public\Desktop\GeekBuddy.lnk
[2013/01/22 14:29:19 | 001,700,352 | —- | M] (Microsoft Corporation) – C:\Windows\System32\gdiplus.dll
[2013/01/22 14:04:26 | 001,474,832 | —- | M] () – C:\Windows\System32\drivers\sfi.dat
[2013/01/20 19:26:22 | 000,101,990 | —- | M] () – C:\Users\Dennis\AppData\Roaming\nvModes.dat
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/02/12 23:07:00 | 000,000,882 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore1ce0975a975bc2f.job
[2013/02/08 16:59:27 | 000,208,320 | —- | C] () – C:\Windows\System32\drivers\OADriver.sys
[2013/02/08 16:59:27 | 000,044,992 | —- | C] () – C:\Windows\System32\drivers\oahlp32.sys
[2013/02/08 16:55:09 | 000,000,876 | —- | C] () – C:\Users\Dennis\Desktop\AVG log.csv
[2013/02/08 15:43:44 | 000,000,844 | —- | C] () – C:\Users\Public\Desktop\AVG 2013.lnk
[2013/02/07 19:16:33 | 000,000,932 | —- | C] () – C:\Users\Dennis\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes Anti-Malware.lnk
[2013/02/07 19:16:33 | 000,000,908 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/02/07 19:13:36 | 4024,479,744 | -HS- | C] () – C:\hiberfil.sys
[2013/02/02 14:38:22 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2013/02/02 14:38:22 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2013/02/02 14:38:22 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2013/02/02 14:38:22 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2013/02/02 14:38:22 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2013/01/31 12:39:59 | 000,580,235 | —- | C] () – C:\Users\Dennis\Desktop\adwcleaner.exe
[2013/01/30 18:34:50 | 002,195,061 | —- | C] () – C:\Users\Dennis\Desktop\tdsskiller.zip
[2013/01/28 20:50:59 | 000,000,575 | —- | C] () – C:\Users\Dennis\Desktop\MBR_Dirk4.zip
[2013/01/28 20:49:39 | 000,000,512 | —- | C] () – C:\Users\Dennis\Desktop\MBR.dat
[2013/01/22 14:30:04 | 000,001,926 | —- | C] () – C:\Users\Public\Desktop\AntiError.lnk
[2013/01/22 14:30:04 | 000,001,922 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Start GeekBuddy.lnk
[2013/01/22 14:30:04 | 000,001,922 | —- | C] () – C:\Users\Public\Desktop\GeekBuddy.lnk
[2012/11/28 23:27:13 | 000,106,605 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2012/11/28 23:27:13 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2011/06/09 19:11:14 | 001,474,832 | —- | C] () – C:\Windows\System32\drivers\sfi.dat
[2009/12/02 13:22:04 | 000,000,063 | —- | C] () – C:\Users\Dennis\.structure
[2008/09/08 09:11:42 | 000,008,268 | —- | C] () – C:\Users\Dennis\AppData\Local\d3d9caps.dat
[2008/03/03 23:08:38 | 000,000,000 | —- | C] () – C:\Users\Dennis\AppData\Roaming\wklnhst.dat
[2008/02/28 20:47:38 | 000,101,990 | —- | C] () – C:\Users\Dennis\AppData\Roaming\nvModes.001
[2008/02/28 19:54:26 | 000,101,990 | —- | C] () – C:\Users\Dennis\AppData\Roaming\nvModes.dat
[2008/02/28 18:58:55 | 000,198,144 | —- | C] () – C:\Users\Dennis\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

========== ZeroAccess Check ==========

[2006/11/02 12:54:22 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2011/01/21 15:46:32 | 011,582,464 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2009/03/03 04:36:24 | 000,615,424 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2008/01/19 07:36:49 | 000,347,648 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== Alternate Data Streams ==========

@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Documents\Sports Interactive:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Documents\processPurchaseResponse.do_files:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Documents\Nationwide Internet banking signup_files:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Documents\My Received Files:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Documents\fcgheevi2.jpg:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Documents\fcgheevi1.jpg:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Documents\Dell Webcam Center:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Documents\bevestigingDVDpap_files:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Documents\aBHbAwAALilM.jpg:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Documents\__MACOSX:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Desktop\tdsskiller:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Desktop\Scotland march 2012:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Desktop\New Folder:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Desktop\[Classic, 1982] Taboo II (Dorothy LeMay, Honey Wilder).avi:Roxio EMC Stream

< End of report >

Short scan log:

OTL logfile created on: 17/02/2013 16:08:50 - Run 4
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Dennis\Desktop
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19088)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.75 Gb Total Physical Memory | 2.24 Gb Available Physical Memory | 59.81% Memory free
7.68 Gb Paging File | 6.22 Gb Available in Paging File | 81.01% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 136.43 Gb Total Space | 13.52 Gb Free Space | 9.91% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 4.54 Gb Free Space | 45.40% Space Free | Partition Type: NTFS

Computer Name: DENNIS-PC | User Name: Dennis | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Program Files\Steam\steam.exe (Valve Corporation)
PRC - C:\Program Files\AVG Secure Search\vprot.exe ()
PRC - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\14.1.7\ToolbarUpdater.exe ()
PRC - C:\Users\Dennis\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Common Files\Comodo\launcher_service.exe (Comodo Security Solutions Inc.)
PRC - C:\Program Files\Common Files\Comodo\GeekBuddyRSP.exe (Comodo Security Solutions, Inc.)
PRC - C:\Program Files\AVG\AVG2013\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgemcx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Online Armor\oasrv.exe (Emsisoft GmbH)
PRC - C:\Program Files\Online Armor\oaui.exe (Emsisoft GmbH)
PRC - C:\Program Files\Online Armor\oahlp.exe (Emsisoft GmbH)
PRC - C:\Program Files\Online Armor\oacat.exe (Emsisoft GmbH)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe (IDT, Inc.)
PRC - C:\Windows\System32\stacsv.exe (IDT, Inc.)
PRC - C:\Windows\System32\AEstSrv.exe (Andrea Electronics Corporation)
PRC - C:\Windows\OEM02Mon.exe (Creative Technology Ltd.)
PRC - C:\Program Files\Dell\MediaDirect\PCMService.exe (CyberLink Corp.)
PRC - C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe (Creative Technology Ltd.)
PRC - C:\Program Files\DellTPad\hidfind.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\ApMsgFwd.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\ApntEx.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc)
PRC - C:\Program Files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe (Matsushita Electric Industrial Co., Ltd.)
PRC - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe (Sonic Solutions)
PRC - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe (Sonic Solutions)
PRC - C:\Program Files\Saitek\Software\SaiMfd.exe (Saitek)
PRC - C:\Program Files\Saitek\Software\ProfilerU.exe (Saitek)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\AVG Secure Search\vprot.exe ()
MOD - C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\14.1.7\SiteSafety.dll ()
MOD - C:\Program Files\Steam\sdl.dll ()
MOD - C:\Program Files\Steam\bin\libcef.dll ()
MOD - C:\Program Files\Steam\bin\avcodec-53.dll ()
MOD - C:\Program Files\Steam\bin\chromehtml.dll ()
MOD - C:\Program Files\Steam\bin\avformat-53.dll ()
MOD - C:\Program Files\Steam\bin\avutil-51.dll ()
MOD - C:\Program Files\Perfect Uninstaller\Contextmenu.dll ()
MOD - C:\Program Files\WinRAR\RarExt.dll ()
MOD - C:\Program Files\Dell\QuickSet\dadkeyb.dll ()
MOD - C:\Program Files\Common Files\Roxio Shared\9.0\DLLShared\LayoutDll9.dll ()
MOD - C:\Program Files\Common Files\Roxio Shared\9.0\DLLShared\ROXIPP41.dll ()
MOD - C:\Program Files\Saitek\Software\SAICFG.dll ()


========== Services (SafeList) ==========

SRV - (sprtsvc_dellsupportcenter) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe /service /p dellsupportcenter File not found
SRV - (vToolbarUpdater14.1.7) – C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\14.1.7\ToolbarUpdater.exe ()
SRV - (Steam Client Service) – C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
SRV - (CLPSLauncher) – C:\Program Files\Common Files\Comodo\launcher_service.exe (Comodo Security Solutions Inc.)
SRV - (GeekBuddyRSP) – C:\Program Files\Common Files\Comodo\GeekBuddyRSP.exe (Comodo Security Solutions, Inc.)
SRV - (avgwd) – C:\Program Files\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (SvcOnlineArmor) – C:\Program Files\Online Armor\oasrv.exe (Emsisoft GmbH)
SRV - (OAcat) – C:\Program Files\Online Armor\oacat.exe (Emsisoft GmbH)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (STacSV) – C:\Windows\System32\stacsv.exe (IDT, Inc.)
SRV - (AESTFilters) – C:\Windows\System32\AEstSrv.exe (Andrea Electronics Corporation)


========== Driver Services (SafeList) ==========

DRV - (NwlnkFwd) – system32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – system32\DRIVERS\nwlnkflt.sys File not found
DRV - (Lbd) – system32\DRIVERS\Lbd.sys File not found
DRV - (IpInIp) – system32\DRIVERS\ipinip.sys File not found
DRV - (catchme) – C:\Users\Dennis\AppData\Local\Temp\catchme.sys File not found
DRV - (blbdrive) – C:\Windows\system32\drivers\blbdrive.sys File not found
DRV - (avgtp) – C:\Windows\System32\drivers\avgtpx86.sys (AVG Technologies)
DRV - (CFRMD) – C:\Windows\System32\drivers\CFRMD.sys (Windows ® Win 7 DDK provider)
DRV - (Avgmfx86) – C:\Windows\System32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSDriver) – C:\Windows\System32\drivers\avgidsdriverx.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSHX) – C:\Windows\System32\drivers\avgidshx.sys (AVG Technologies CZ, s.r.o. )
DRV - (oahlpXX) – C:\Windows\System32\drivers\oahlp32.sys ()
DRV - (OAnet) – C:\Windows\System32\drivers\OAnet.sys (Emsisoft)
DRV - (OAmon) – C:\Windows\System32\drivers\OAmon.sys (Emsisoft)
DRV - (OADevice) – C:\Windows\System32\drivers\OADriver.sys ()
DRV - (Avgldx86) – C:\Windows\System32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgtdix) – C:\Windows\System32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avglogx) – C:\Windows\System32\drivers\avglogx.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSShim) – C:\Windows\System32\drivers\avgidsshimx.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgrkx86) – C:\Windows\System32\drivers\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (mferkdk) – C:\Windows\System32\drivers\mferkdk.sys (McAfee, Inc.)
DRV - (STHDA) – C:\Windows\System32\drivers\stwrt.sys (IDT, Inc.)
DRV - (OEM02Vfx) – C:\Windows\System32\drivers\OEM02Vfx.sys (EyePower Games Pte. Ltd.)
DRV - (OEM02Dev) – C:\Windows\System32\drivers\OEM02Dev.sys (Creative Technology Ltd.)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (Point32) – C:\Windows\System32\drivers\point32k.sys (Microsoft Corporation)
DRV - (NETw4v32) – C:\Windows\System32\drivers\NETw4v32.sys (Intel Corporation)
DRV - (ApfiltrService) – C:\Windows\System32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (bcm4sbxp) – C:\Windows\System32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (rimsptsk) – C:\Windows\System32\drivers\rimsptsk.sys (REDC)
DRV - (rismxdp) – C:\Windows\System32\drivers\rixdptsk.sys (REDC)
DRV - (rimmptsk) – C:\Windows\System32\drivers\rimmptsk.sys (REDC)
DRV - (R300) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (e1express) – C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (SaiNtBus) – C:\Windows\System32\drivers\SaiBus.sys (Saitek)
DRV - (SaiMini) – C:\Windows\System32\drivers\SaiMini.sys (Saitek)
DRV - (SaiH0461) – C:\Windows\System32\drivers\SaiH0461.sys (Saitek)
DRV - (ss_mdm) – C:\Windows\System32\drivers\ss_mdm.sys (MCCI)
DRV - (ss_mdfl) – C:\Windows\System32\drivers\ss_mdfl.sys (MCCI)
DRV - (ss_bus) – C:\Windows\System32\drivers\ss_bus.sys (MCCI)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {0633ee93-d776-472f-a0ff-e1416b8b2e3a}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…amp;rlz=1I7DKUK

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.co.uk/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
FF - prefs.js..browser.search.param.yahoo-fr: "chrf-comodo"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "chrf-comodo"
FF - prefs.js..browser.search.selectedEngine: "AVG Secure Search"
FF - prefs.js..extensions.enabledAddons: {CAFEEFAC-0016-0000-0039-ABCDEFFEDCBA}:6.0.39
FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:3.3.1
FF - prefs.js..extensions.enabledItems: {534EBA91-5C43-4711-AA70-5C4ECF671FED}:1.9.1
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_5_502_146.dll ()
FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\14.1.7\\npsitesafety.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_39: C:\Windows\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\ProgramData\AVG Secure Search\FireFoxExt\14.1.0.10 [2013/02/13 23:40:13 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/01/31 12:41:43 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/01/31 12:00:07 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{534EBA91-5C43-4711-AA70-5C4ECF671FED}: C:\Users\Dennis\AppData\Local\{534EBA91-5C43-4711-AA70-5C4ECF671FED}

[2009/02/17 20:25:06 | 000,000,000 | —D | M] (No name found) – C:\Users\Dennis\AppData\Roaming\Mozilla\Extensions
[2012/11/27 20:07:09 | 000,000,000 | —D | M] (No name found) – C:\Users\Dennis\AppData\Roaming\Mozilla\Firefox\Profiles\nulwxz0d.default\extensions
[2011/01/09 20:13:28 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Dennis\AppData\Roaming\Mozilla\Firefox\Profiles\nulwxz0d.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2013/02/08 15:27:50 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2013/02/08 15:27:50 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0039-ABCDEFFEDCBA}
[2012/11/26 21:52:22 | 000,097,208 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/11/26 21:52:19 | 000,001,525 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2013/02/13 23:39:50 | 000,003,592 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml
[2012/11/26 21:52:19 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/11/26 21:52:19 | 000,000,935 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
[2012/11/26 21:52:19 | 000,001,166 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
[2012/11/26 21:52:19 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml
[2012/11/26 21:52:19 | 000,001,121 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml

========== Chrome ==========

CHR - homepage: http://isearch.avg.com/?cid={C0D01CCA-A789…mp;d=2013-02-02 14:33:13&v=14.0.0.14&pid=avg&sg=&sap=hp
CHR - default_search_provider: AVG Secure Search (Enabled)
CHR - default_search_provider: search_url = http://isearch.avg.com/search?cid={C0D01CC…mp;d=2013-02-02 14:33:13&v=14.0.0.14&pid=avg&sg=&sap=dsp&q={searchTerms}
CHR - default_search_provider: suggest_url =
CHR - homepage: http://isearch.avg.com/?cid={C0D01CCA-A789…mp;d=2013-02-02 14:33:13&v=14.0.0.14&pid=avg&sg=&sap=hp
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\24.0.1312.57\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\24.0.1312.57\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\24.0.1312.57\gcswf32.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 8.0\Reader\Browser\nppdf32.dll
CHR - plugin: BitTorrent (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npbittorrent.dll
CHR - plugin: DivX Web Player (Enabled) = C:\Program Files\DivX\DivX Web Player\npdivx32.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: AVG Security Toolbar = C:\Users\Dennis\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\14.1.0.10_0\

O1 HOSTS File: ([2013/02/16 20:42:40 | 000,000,098 | —- | M]) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\14.1.0.10\AVG Secure Search_toolbar.dll ()
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\14.1.0.10\AVG Secure Search_toolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O4 - HKLM..\Run: [@OnlineArmor GUI] C:\Program Files\Online Armor\oaui.exe (Emsisoft GmbH)
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [AVG_UI] C:\Program Files\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [DELL Webcam Manager] C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [ECenter] C:\DELL\E-Center\EULALauncher.exe ( )
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NVHotkey] C:\Windows\System32\nvHotkey.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvSvc] C:\Windows\System32\nvsvc.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [PCMService] C:\Program Files\Dell\MediaDirect\PCMService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [Profiler] C:\Program Files\Saitek\Software\ProfilerU.exe (Saitek)
O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe (Sonic Solutions)
O4 - HKLM..\Run: [SaiMfd] C:\Program Files\Saitek\Software\SaiMfd.exe (Saitek)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [vProt] C:\Program Files\AVG Secure Search\vprot.exe ()
O4 - HKCU..\Run: [Steam] C:\Program Files\Steam\Steam.exe (Valve Corporation)
O4 - Startup: C:\Users\Dennis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\BeNaughtyChat.lnk = C:\Program Files\BeNaughtyChat\BeNaughtyChat.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnableShellExecuteHooks = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/8/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} http://dl.tvunetworks.com/TVUAx.cab (CTVUAxCtrl Object)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab (DivXBrowserPlugin Object)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_39)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-0016-0000-0039-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_39)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_39)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B1E45316-623A-47F4-AE3A-51183EE97AFA}: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (Logitech Inc.)
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\14.1.7\ViProtocol.dll ()
O18 - Protocol\Filter\application/x-internet-signup {A173B69A-1F9B-4823-9FDA-412F641E65D6} - C:\Program Files\Tiscali\Tiscali Internet\dlls\tiscalifilter.dll ()
O18 - Protocol\Filter\x-sdch - No CLSID value found
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Dennis\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Dennis\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O28 - HKLM ShellExecuteHooks: {4F07DA45-8170-4859-9B5F-037EF2970034} - C:\Program Files\Online Armor\oaevent.dll (Emsisoft GmbH)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 21:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2013/02/17 00:09:27 | 000,000,000 | —D | C] – C:\ProgramData\WindowsSearch
[2013/02/08 17:01:43 | 000,000,000 | —D | C] – C:\Users\Dennis\AppData\Roaming\OnlineArmor
[2013/02/08 17:01:43 | 000,000,000 | —D | C] – C:\ProgramData\OnlineArmor
[2013/02/08 16:59:28 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Online Armor
[2013/02/08 16:59:27 | 000,031,768 | —- | C] (Emsisoft) – C:\Windows\System32\drivers\OAnet.sys
[2013/02/08 16:59:27 | 000,027,648 | —- | C] (Emsisoft) – C:\Windows\System32\drivers\OAmon.sys
[2013/02/08 16:59:22 | 000,000,000 | —D | C] – C:\Program Files\Online Armor
[2013/02/08 15:44:57 | 000,000,000 | —D | C] – C:\Users\Dennis\AppData\Roaming\AVG2013
[2013/02/08 15:43:44 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
[2013/02/08 15:43:03 | 000,000,000 | -H-D | C] – C:\$AVG
[2013/02/08 15:43:02 | 000,000,000 | —D | C] – C:\ProgramData\AVG2013
[2013/02/08 15:41:18 | 000,000,000 | —D | C] – C:\Program Files\AVG
[2013/02/08 15:28:21 | 000,000,000 | —D | C] – C:\ProgramData\Sun
[2013/02/07 19:30:38 | 002,322,184 | —- | C] (ESET) – C:\Users\Dennis\Desktop\esetsmartinstaller_enu.exe
[2013/02/07 19:15:27 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/02/07 19:15:22 | 000,021,104 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2013/02/07 19:15:22 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2013/02/04 22:32:28 | 000,000,000 | —D | C] – C:\Windows\ERUNT
[2013/02/04 22:32:23 | 000,000,000 | —D | C] – C:\JRT
[2013/02/04 22:24:15 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2013/02/04 21:56:17 | 000,000,000 | —D | C] – C:\Users\Dennis\AppData\Local\Avg2013
[2013/02/04 21:40:59 | 000,547,275 | —- | C] (Oleg N. Scherbakov) – C:\Users\Dennis\Desktop\JRT.exe
[2013/02/02 14:38:22 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2013/02/02 14:38:22 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2013/02/02 14:38:22 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2013/02/02 14:36:40 | 000,000,000 | —D | C] – C:\Qoobox
[2013/02/02 14:36:11 | 000,000,000 | —D | C] – C:\Windows\erdnt
[2013/02/02 14:33:27 | 000,000,000 | —D | C] – C:\Users\Dennis\AppData\Local\AVG Secure Search
[2013/02/02 14:33:20 | 000,000,000 | —D | C] – C:\ProgramData\AVG Security Toolbar
[2013/02/02 14:33:12 | 000,033,112 | —- | C] (AVG Technologies) – C:\Windows\System32\drivers\avgtpx86.sys
[2013/02/02 14:33:07 | 000,000,000 | —D | C] – C:\Program Files\Common Files\AVG Secure Search
[2013/02/02 14:33:06 | 000,000,000 | —D | C] – C:\Program Files\AVG Secure Search
[2013/02/02 14:06:27 | 005,029,149 | R— | C] (Swearware) – C:\Users\Dennis\Desktop\ComboFix.exe
[2013/01/31 19:58:25 | 000,000,000 | —D | C] – C:\ProgramData\AVG Secure Search
[2013/01/31 12:00:07 | 000,000,000 | —D | C] – C:\_OTL
[2013/01/30 18:37:10 | 000,000,000 | —D | C] – C:\Users\Dennis\Desktop\tdsskiller
[2013/01/28 20:44:36 | 004,732,416 | —- | C] (AVAST Software) – C:\Users\Dennis\Desktop\aswMBR.exe
[2013/01/28 17:14:30 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Dennis\Desktop\OTL.exe
[2013/01/22 18:25:44 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\Dennis\Desktop\HiJackThis.exe
[2013/01/22 17:59:12 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2013/01/22 17:59:12 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2013/01/22 17:40:14 | 000,000,000 | —D | C] – C:\Users\Dennis\AppData\Local\Macromedia
[2013/01/22 14:43:00 | 000,000,000 | —D | C] – C:\Users\Dennis\AppData\Roaming\TuneUp Software
[2013/01/22 14:37:43 | 000,000,000 | -H-D | C] – C:\ProgramData\Common Files
[2013/01/22 14:37:43 | 000,000,000 | —D | C] – C:\Users\Dennis\AppData\Local\MFAData
[2013/01/22 14:37:43 | 000,000,000 | —D | C] – C:\ProgramData\MFAData
[2013/01/22 14:30:23 | 000,000,000 | —D | C] – C:\ProgramData\COMODO
[2013/01/22 14:29:58 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Comodo
[2013/01/22 14:29:42 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Comodo
[2013/01/22 14:29:41 | 000,000,000 | —D | C] – C:\Users\Dennis\AppData\Local\Comodo
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/02/17 16:15:00 | 000,000,564 | —- | M] () – C:\Windows\tasks\PCDoctorBackgroundMonitorTask.job
[2013/02/17 16:13:00 | 000,000,506 | —- | M] () – C:\Windows\tasks\SystemToolsDailyTest.job
[2013/02/17 15:45:02 | 000,198,144 | —- | M] () – C:\Users\Dennis\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/02/17 14:54:51 | 000,003,696 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013/02/17 14:54:51 | 000,003,696 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013/02/17 10:55:36 | 000,002,485 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\QuickSet.lnk
[2013/02/17 10:55:35 | 000,101,990 | —- | M] () – C:\Users\Dennis\AppData\Roaming\nvModes.001
[2013/02/17 10:54:49 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/02/17 10:54:38 | 4024,479,744 | -HS- | M] () – C:\hiberfil.sys
[2013/02/16 20:42:40 | 000,000,098 | —- | M] () – C:\Windows\System32\drivers\etc\Hosts
[2013/02/13 23:39:44 | 000,033,112 | —- | M] (AVG Technologies) – C:\Windows\System32\drivers\avgtpx86.sys
[2013/02/12 23:07:00 | 000,000,882 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore1ce0975a975bc2f.job
[2013/02/08 16:55:09 | 000,000,876 | —- | M] () – C:\Users\Dennis\Desktop\AVG log.csv
[2013/02/08 15:43:44 | 000,000,844 | —- | M] () – C:\Users\Public\Desktop\AVG 2013.lnk
[2013/02/07 19:30:42 | 002,322,184 | —- | M] (ESET) – C:\Users\Dennis\Desktop\esetsmartinstaller_enu.exe
[2013/02/07 19:16:33 | 000,000,932 | —- | M] () – C:\Users\Dennis\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes Anti-Malware.lnk
[2013/02/07 19:16:33 | 000,000,908 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/02/04 21:41:01 | 000,547,275 | —- | M] (Oleg N. Scherbakov) – C:\Users\Dennis\Desktop\JRT.exe
[2013/02/02 14:06:36 | 005,029,149 | R— | M] (Swearware) – C:\Users\Dennis\Desktop\ComboFix.exe
[2013/01/31 12:40:02 | 000,580,235 | —- | M] () – C:\Users\Dennis\Desktop\adwcleaner.exe
[2013/01/30 18:34:52 | 002,195,061 | —- | M] () – C:\Users\Dennis\Desktop\tdsskiller.zip
[2013/01/28 20:50:59 | 000,000,575 | —- | M] () – C:\Users\Dennis\Desktop\MBR_Dirk4.zip
[2013/01/28 20:49:39 | 000,000,512 | —- | M] () – C:\Users\Dennis\Desktop\MBR.dat
[2013/01/28 20:44:53 | 004,732,416 | —- | M] (AVAST Software) – C:\Users\Dennis\Desktop\aswMBR.exe
[2013/01/28 17:14:33 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Dennis\Desktop\OTL.exe
[2013/01/22 18:25:45 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Dennis\Desktop\HiJackThis.exe
[2013/01/22 14:30:04 | 000,001,926 | —- | M] () – C:\Users\Public\Desktop\AntiError.lnk
[2013/01/22 14:30:04 | 000,001,922 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Start GeekBuddy.lnk
[2013/01/22 14:30:04 | 000,001,922 | —- | M] () – C:\Users\Public\Desktop\GeekBuddy.lnk
[2013/01/22 14:04:26 | 001,474,832 | —- | M] () – C:\Windows\System32\drivers\sfi.dat
[2013/01/20 19:26:22 | 000,101,990 | —- | M] () – C:\Users\Dennis\AppData\Roaming\nvModes.dat
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/02/12 23:07:00 | 000,000,882 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore1ce0975a975bc2f.job
[2013/02/08 16:59:27 | 000,208,320 | —- | C] () – C:\Windows\System32\drivers\OADriver.sys
[2013/02/08 16:59:27 | 000,044,992 | —- | C] () – C:\Windows\System32\drivers\oahlp32.sys
[2013/02/08 16:55:09 | 000,000,876 | —- | C] () – C:\Users\Dennis\Desktop\AVG log.csv
[2013/02/08 15:43:44 | 000,000,844 | —- | C] () – C:\Users\Public\Desktop\AVG 2013.lnk
[2013/02/07 19:16:33 | 000,000,932 | —- | C] () – C:\Users\Dennis\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes Anti-Malware.lnk
[2013/02/07 19:16:33 | 000,000,908 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/02/07 19:13:36 | 4024,479,744 | -HS- | C] () – C:\hiberfil.sys
[2013/02/02 14:38:22 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2013/02/02 14:38:22 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2013/02/02 14:38:22 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2013/02/02 14:38:22 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2013/02/02 14:38:22 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2013/01/31 12:39:59 | 000,580,235 | —- | C] () – C:\Users\Dennis\Desktop\adwcleaner.exe
[2013/01/30 18:34:50 | 002,195,061 | —- | C] () – C:\Users\Dennis\Desktop\tdsskiller.zip
[2013/01/28 20:50:59 | 000,000,575 | —- | C] () – C:\Users\Dennis\Desktop\MBR_Dirk4.zip
[2013/01/28 20:49:39 | 000,000,512 | —- | C] () – C:\Users\Dennis\Desktop\MBR.dat
[2013/01/22 14:30:04 | 000,001,926 | —- | C] () – C:\Users\Public\Desktop\AntiError.lnk
[2013/01/22 14:30:04 | 000,001,922 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Start GeekBuddy.lnk
[2013/01/22 14:30:04 | 000,001,922 | —- | C] () – C:\Users\Public\Desktop\GeekBuddy.lnk
[2012/11/28 23:27:13 | 000,106,605 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2012/11/28 23:27:13 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2011/06/09 19:11:14 | 001,474,832 | —- | C] () – C:\Windows\System32\drivers\sfi.dat
[2009/12/02 13:22:04 | 000,000,063 | —- | C] () – C:\Users\Dennis\.structure
[2008/09/08 09:11:42 | 000,008,268 | —- | C] () – C:\Users\Dennis\AppData\Local\d3d9caps.dat
[2008/03/03 23:08:38 | 000,000,000 | —- | C] () – C:\Users\Dennis\AppData\Roaming\wklnhst.dat
[2008/02/28 20:47:38 | 000,101,990 | —- | C] () – C:\Users\Dennis\AppData\Roaming\nvModes.001
[2008/02/28 19:54:26 | 000,101,990 | —- | C] () – C:\Users\Dennis\AppData\Roaming\nvModes.dat
[2008/02/28 18:58:55 | 000,198,144 | —- | C] () – C:\Users\Dennis\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

========== ZeroAccess Check ==========

[2006/11/02 12:54:22 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2011/01/21 15:46:32 | 011,582,464 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2009/03/03 04:36:24 | 000,615,424 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2008/01/19 07:36:49 | 000,347,648 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2011/07/07 21:46:19 | 000,000,000 | —D | M] – C:\Users\Dennis\AppData\Roaming\Akigo
[2013/02/08 15:44:57 | 000,000,000 | —D | M] – C:\Users\Dennis\AppData\Roaming\AVG2013
[2011/08/10 22:06:30 | 000,000,000 | —D | M] – C:\Users\Dennis\AppData\Roaming\BeNaughtyChat
[2012/07/07 23:24:50 | 000,000,000 | —D | M] – C:\Users\Dennis\AppData\Roaming\Dropbox
[2013/02/08 17:02:22 | 000,000,000 | —D | M] – C:\Users\Dennis\AppData\Roaming\OnlineArmor
[2008/04/04 16:24:01 | 000,000,000 | —D | M] – C:\Users\Dennis\AppData\Roaming\Panasonic
[2011/05/24 20:12:37 | 000,000,000 | —D | M] – C:\Users\Dennis\AppData\Roaming\PCDr
[2012/07/24 21:33:02 | 000,000,000 | —D | M] – C:\Users\Dennis\AppData\Roaming\Sports Interactive
[2008/03/03 23:08:39 | 000,000,000 | —D | M] – C:\Users\Dennis\AppData\Roaming\Template
[2013/01/22 14:43:00 | 000,000,000 | —D | M] – C:\Users\Dennis\AppData\Roaming\TuneUp Software

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Documents\Sports Interactive:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Documents\processPurchaseResponse.do_files:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Documents\Nationwide Internet banking signup_files:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Documents\My Received Files:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Documents\fcgheevi2.jpg:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Documents\fcgheevi1.jpg:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Documents\Dell Webcam Center:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Documents\bevestigingDVDpap_files:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Documents\aBHbAwAALilM.jpg:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Documents\__MACOSX:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Desktop\tdsskiller:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Desktop\Scotland march 2012:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Desktop\New Folder:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Dennis\Desktop\[Classic, 1982] Taboo II (Dorothy LeMay, Honey Wilder).avi:Roxio EMC Stream

< End of report >
Hi Dirk4 ;)

Your logs appear to be clean :) SO LETS DO A COUPLE OF THINGS TO WRAP THIS UP!! :)

This infection appears to have been cleaned, but I can not give you any absolute guarantees. As a precaution, I would go ahead and change all of your passwords as this is especially important after an infection.


Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.


Unistall AdwCleaner

  • Double click on adwcleaner.exe to run the tool.
  • Click on Uninstall.
  • Confirm with yes.

Any of the logs that you created for use in the forums or remaining tools that have not yet been removed can be deleted so they aren't cluttering up your desktop.

MOST IMPORTANT: You Need to Update Windows and IE to get all the Latest Security Patches to protect your computer from the malware that is around on the internet.


Java is very easily exploited these days and it's a good idea to disable Java in the browser

Please read here

Here are some tips to reduce the potential for spyware infection in the future:

1. Make your Internet Explorer more secure - This can be done by following these simple instructions:
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
  • Next press the Apply button and then the OK to exit the Internet Properties page.
Make your Mozilla Firefox more secure - This can be done by adding these add-ons:

2. Enable Protected Mode in Internet Explorer. This helps Windows Vista users stay more protected from attack by running Internet Explorer with restricted privileges as well as reducing the ability to write, alter or destroy data on your system or install malicious code. To make sure this is running follow these steps:
  • Open Internet Explorer
  • Click on Tools > Internet Options
  • Press Security tab
  • Select Internet zone then place check next to Enable Protected Mode if not already done
  • Do the same for Local Intranet, Trusted Sites and Restricted Sites and then press Apply
  • Restart Internet Explorer and in the bottom right corner of your screen you will see Protected Mode: On showing you it is enabled.

3. Use and update an anti-virus software - I can not overemphasize the need for you to use and update your anti-virus application on a regular basis. With the ever increasing number of new variants of malware arriving on the scene daily, you become very susceptible to an attack without updated protection.


4.SPYWARE PREVENTION
This is a good time to set up protection against further attacks. In light of your recent problem, I'm sure you'd like to avoid any future infections. Please read these well written articles:
5. Consider a custom hosts file such as MVPS HOSTS. This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers. For information on how to download and install, please read this tutorial by WinHelp2002
Note: Be sure to follow the instructions to disable the DNS Client service before installing a custom hosts file.

6. WOT (Web of Trust) As "Googling" is such an integral part of internet life, this free browser add on warns you about risky websites that try to scam visitors, deliver malware or send spam. It is especially helpful when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites. WOT has an add-on available for Firefox, Internet Explorer as well as Google Chrome.

7.Finally, I strongly recommend that you read TonyKlein's good advice So how did I get infected in the first place?

Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI