This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Windows has encountered a critical error [Solved]

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Ahh sorry here is the log run after JRT.


OTL logfile created on: 30/01/2013 16:32:17 - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\User\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

7.92 Gb Total Physical Memory | 5.18 Gb Available Physical Memory | 65.36% Memory free
15.84 Gb Paging File | 12.79 Gb Available in Paging File | 80.76% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931.41 Gb Total Space | 668.68 Gb Free Space | 71.79% Space Free | Partition Type: NTFS

Computer Name: USER-PC | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2013/01/30 16:01:22 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\User\Desktop\OTL.exe
PRC - [2013/01/18 08:07:04 | 001,248,208 | —- | M] (Google Inc.) – C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
PRC - [2013/01/03 16:50:05 | 000,076,888 | —- | M] () – C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2012/12/18 14:28:08 | 000,065,192 | —- | M] (Adobe Systems Incorporated) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012/10/30 22:50:59 | 004,297,136 | —- | M] (AVAST Software) – C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2012/10/30 22:50:59 | 000,044,808 | —- | M] (AVAST Software) – C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2012/10/30 22:50:56 | 000,133,912 | —- | M] (AVAST Software) – C:\Program Files\AVAST Software\Avast\afwServ.exe
PRC - [2011/05/27 14:57:30 | 000,562,592 | —- | M] (Affinegy, Inc.) – C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinService.exe
PRC - [2011/05/27 14:57:28 | 002,015,136 | —- | M] (Affinegy, Inc.) – C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe
PRC - [2011/05/27 14:57:26 | 007,025,568 | —- | M] (Affinegy, Inc.) – C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinSetup.exe
PRC - [2011/05/18 17:28:16 | 001,641,888 | —- | M] (Affinegy, Inc.) – C:\Program Files (x86)\Belkin\Router Setup and Monitor\dlnaPlugin.exe


========== Modules (No Company Name) ==========

MOD - [2013/01/18 08:07:02 | 012,459,472 | —- | M] () – C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.56\PepperFlash\pepflashplayer.dll
MOD - [2013/01/18 08:07:02 | 000,460,240 | —- | M] () – C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.56\ppgooglenaclpluginchrome.dll
MOD - [2013/01/18 08:07:01 | 004,012,496 | —- | M] () – C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.56\pdf.dll
MOD - [2013/01/18 08:06:15 | 000,597,968 | —- | M] () – C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.56\libglesv2.dll
MOD - [2013/01/18 08:06:15 | 000,124,368 | —- | M] () – C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.56\libegl.dll
MOD - [2013/01/18 08:06:13 | 001,552,848 | —- | M] () – C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.56\ffmpegsumo.dll
MOD - [2011/05/27 14:57:32 | 000,022,944 | —- | M] () – C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinServicePS.dll
MOD - [2011/05/27 14:08:56 | 000,660,480 | —- | M] () – C:\Program Files (x86)\Belkin\Router Setup and Monitor\gateways\GenericBelkinGatewayLOC.dll
MOD - [2010/08/22 20:01:36 | 007,187,456 | —- | M] () – C:\Program Files (x86)\Belkin\Router Setup and Monitor\QtGui4.dll
MOD - [2010/08/22 20:01:08 | 000,325,632 | —- | M] () – C:\Program Files (x86)\Belkin\Router Setup and Monitor\QtXml4.dll
MOD - [2010/08/22 20:01:06 | 001,954,304 | —- | M] () – C:\Program Files (x86)\Belkin\Router Setup and Monitor\QtCore4.dll
MOD - [2010/08/22 20:01:06 | 000,847,360 | —- | M] () – C:\Program Files (x86)\Belkin\Router Setup and Monitor\QtNetwork4.dll
MOD - [2010/08/22 19:32:34 | 000,119,808 | —- | M] () – C:\Program Files (x86)\Belkin\Router Setup and Monitor\imageformats\qjpeg4.dll


========== Services (SafeList) ==========

SRV:64bit: - [2012/12/19 19:56:00 | 000,240,640 | —- | M] (AMD) [Auto | Running] – C:\Windows\SysNative\atiesrxx.exe – (AMD External Events Utility)
SRV:64bit: - [2012/10/30 22:50:59 | 000,044,808 | —- | M] (AVAST Software) [Auto | Running] – C:\Program Files\AVAST Software\Avast\AvastSvc.exe – (avast! Antivirus)
SRV:64bit: - [2012/10/30 22:50:56 | 000,133,912 | —- | M] (AVAST Software) [Auto | Running] – C:\Program Files\AVAST Software\Avast\afwServ.exe – (avast! Firewall)
SRV:64bit: - [2011/04/19 15:31:16 | 000,181,760 | —- | M] () [Auto | Running] – C:\Program Files\Belkin\Belkin USB Print and Storage Center\BkBackupScheduler.exe – (Belkin Local Backup Service)
SRV:64bit: - [2010/04/06 15:30:38 | 000,031,272 | —- | M] () [On_Demand | Stopped] – C:\Windows\SysNative\AppleChargerSrv.exe – (AppleChargerSrv)
SRV:64bit: - [2010/02/09 14:55:52 | 000,055,296 | —- | M] () [Auto | Running] – C:\Program Files\Belkin\Belkin USB Print and Storage Center\Bkapcs.exe – (Belkin Network USB Helper)
SRV:64bit: - [2009/07/14 01:41:27 | 001,011,712 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2013/01/18 22:44:07 | 000,541,608 | —- | M] (Valve Corporation) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Steam\SteamService.exe – (Steam Client Service)
SRV - [2013/01/08 20:28:11 | 000,251,400 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe – (AdobeFlashPlayerUpdateSvc)
SRV - [2013/01/03 16:50:05 | 000,076,888 | —- | M] () [Auto | Running] – C:\Windows\SysWOW64\PnkBstrA.exe – (PnkBstrA)
SRV - [2012/12/18 14:28:08 | 000,065,192 | —- | M] (Adobe Systems Incorporated) [Auto | Running] – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe – (AdobeARMservice)
SRV - [2012/12/14 16:49:28 | 000,682,344 | —- | M] (Malwarebytes Corporation) [Auto | Stopped] – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe – (MBAMService)
SRV - [2012/12/14 16:49:28 | 000,398,184 | —- | M] (Malwarebytes Corporation) [Auto | Stopped] – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe – (MBAMScheduler)
SRV - [2012/11/09 11:21:24 | 000,160,944 | R— | M] (Skype Technologies) [Auto | Stopped] – C:\Program Files (x86)\Skype\Updater\Updater.exe – (SkypeUpdate)
SRV - [2012/06/14 22:20:14 | 000,113,120 | —- | M] (Mozilla Foundation) [On_Demand | Stopped] – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe – (MozillaMaintenance)
SRV - [2012/03/19 22:44:20 | 000,276,248 | —- | M] (Intel Corporation) [On_Demand | Stopped] – C:\Windows\SysWOW64\IntelCpHeciSvc.exe – (cphs)
SRV - [2011/05/27 14:57:30 | 000,562,592 | —- | M] (Affinegy, Inc.) [Auto | Running] – C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinService.exe – (AffinegyService)
SRV - [2010/03/18 12:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2009/06/10 21:23:09 | 000,066,384 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2012/12/19 20:48:48 | 011,278,336 | —- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\atikmdag.sys – (amdkmdag)
DRV:64bit: - [2012/12/19 19:32:54 | 000,552,960 | —- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\atikmpag.sys – (amdkmdap)
DRV:64bit: - [2012/12/14 16:49:28 | 000,024,176 | —- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysNative\drivers\mbam.sys – (MBAMProtector)
DRV:64bit: - [2012/11/06 11:11:52 | 000,096,256 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\AtihdW76.sys – (AtiHDAudioService)
DRV:64bit: - [2012/10/30 22:51:56 | 000,059,728 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\Windows\SysNative\drivers\aswTdi.sys – (aswTdi)
DRV:64bit: - [2012/10/30 22:51:55 | 000,984,144 | —- | M] (AVAST Software) [File_System | System | Running] – C:\Windows\SysNative\drivers\aswSnx.sys – (aswSnx)
DRV:64bit: - [2012/10/30 22:51:55 | 000,370,288 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\Windows\SysNative\drivers\aswSP.sys – (aswSP)
DRV:64bit: - [2012/10/30 22:51:55 | 000,262,656 | —- | M] (AVAST Software) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\aswNdis2.sys – (aswNdis2)
DRV:64bit: - [2012/10/30 22:51:55 | 000,071,600 | —- | M] (AVAST Software) [File_System | Auto | Running] – C:\Windows\SysNative\drivers\aswMonFlt.sys – (aswMonFlt)
DRV:64bit: - [2012/10/30 22:51:55 | 000,021,136 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\Windows\SysNative\drivers\aswKbd.sys – (aswKbd)
DRV:64bit: - [2012/10/30 22:51:53 | 000,132,864 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\Windows\SysNative\drivers\aswFW.sys – (aswFW)
DRV:64bit: - [2012/10/30 22:51:53 | 000,025,232 | —- | M] (AVAST Software) [File_System | Auto | Running] – C:\Windows\SysNative\drivers\aswFsBlk.sys – (aswFsBlk)
DRV:64bit: - [2012/10/15 16:59:28 | 000,054,072 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\Windows\SysNative\drivers\aswRdr2.sys – (aswRdr)
DRV:64bit: - [2012/09/21 09:26:08 | 000,012,368 | —- | M] (ALWIL Software) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\aswNdis.sys – (aswNdis)
DRV:64bit: - [2012/03/19 22:32:04 | 014,745,600 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\igdkmd64.sys – (igfx)
DRV:64bit: - [2012/03/01 06:46:16 | 000,023,408 | —- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] – C:\Windows\SysNative\drivers\fs_rec.sys – (Fs_Rec)
DRV:64bit: - [2011/07/29 03:40:00 | 000,079,104 | —- | M] (Etron Technology Inc) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\EtronXHCI.sys – (EtronXHCI)
DRV:64bit: - [2011/07/29 03:40:00 | 000,056,960 | —- | M] (Etron Technology Inc) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\EtronHub3.sys – (EtronHub3)
DRV:64bit: - [2011/06/01 03:16:50 | 000,535,656 | —- | M] (Realtek ) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Rt64win7.sys – (RTL8167)
DRV:64bit: - [2011/03/11 06:41:12 | 000,107,904 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2011/03/11 06:41:12 | 000,027,008 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2011/01/10 17:16:08 | 000,021,104 | —- | M] () [Kernel | System | Running] – C:\Windows\SysNative\drivers\AppleCharger.sys – (AppleCharger)
DRV:64bit: - [2010/11/21 03:24:33 | 000,059,392 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV:64bit: - [2010/11/21 03:23:47 | 000,078,720 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2010/11/21 03:23:47 | 000,031,232 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbGD.sys – (TsUsbGD)
DRV:64bit: - [2010/10/19 22:34:26 | 000,056,344 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\HECIx64.sys – (MEIx64)
DRV:64bit: - [2010/10/14 17:28:16 | 000,317,440 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\IntcDAud.sys – (IntcDAud)
DRV:64bit: - [2009/08/13 21:10:18 | 000,073,984 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\xusb21.sys – (xusb21)
DRV:64bit: - [2009/07/14 01:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009/07/14 01:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009/07/14 01:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009/07/14 00:01:09 | 000,679,936 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\xnacc.sys – (xnacc)
DRV:64bit: - [2009/06/22 15:50:00 | 000,291,352 | —- | M] (silex technology, Inc.) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\sxuptp.sys – (sxuptp)
DRV:64bit: - [2009/06/10 20:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009/06/10 20:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009/06/10 20:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009/06/10 20:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:64bit: - [2009/02/17 17:22:22 | 000,017,792 | —- | M] (ASUSTeK Computer Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\asusgsb.sys – (asusgsb)
DRV - [2009/07/14 01:19:10 | 000,019,008 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\wimmount.sys – (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633ee93-d776-472f-a0ff-e1416b8b2e3a}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://uk.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-GB
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = FC CD F6 6E 29 EC CD 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com
IE - HKCU\..\SearchScopes,DefaultScope = {0633ee93-d776-472f-a0ff-e1416b8b2e3a}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{63B2D943-91F1-4a04-B9AA-390B3CE4A909}: "URL" = http://www.bing.com/search?q={searchTerms}…BR1&pc;=SPLH
IE - HKCU\..\SearchScopes\{89702040-18AF-416b-B0E0-7012894C77FE}: "URL" = http://uk.search.yahoo.com/search?p={searc…amp;type=IEBDSV
IE - HKCU\..\SearchScopes\{BABCB421-7CA1-4B5C-BB0A-2A118CB6305B}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2504091
IE - HKCU\..\SearchScopes\{E0F00850-AE0D-48d9-BE93-10117BA27B60}: "URL" = http://www.google.com/cse?cx=partner-pub-3…q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =

========== FireFox ==========

FF - prefs.js..extensions.enabledAddons: [removed]:7.0.1474
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_146.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_146.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.11.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.124\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.124\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@coreonline.com/run3d,version=1.0: C:\Users\User\AppData\LocalLow\Square Enix\nprun3d.dll (Square Enix)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKCU\Software\MozillaPlugins\ubisoft.com/uplaypc: C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2012/11/07 00:10:40 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/01/06 16:49:39 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins

[2013/01/06 16:50:02 | 000,000,000 | —D | M] (No name found) – C:\Users\User\AppData\Roaming\Mozilla\Extensions
[2013/01/10 17:39:01 | 000,000,000 | —D | M] (No name found) – C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\11nx87hu.default\extensions
[2013/01/06 16:57:13 | 000,804,627 | —- | M] () (No name found) – C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\11nx87hu.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2013/01/09 17:31:55 | 000,022,867 | —- | M] () – C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\11nx87hu.default\searchplugins\Web Search.xml
[2013/01/06 16:49:39 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/11/07 00:10:40 | 000,000,000 | —D | M] (avast! WebRep) – C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF
[2012/06/14 22:20:49 | 000,085,472 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/06/14 22:19:40 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/06/14 22:19:40 | 000,002,040 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - homepage: https://login.live.com/login.srf?wa=wsignin…=mai&snsc;=1
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie;={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl;={language}&q;={searchTerms}&sugkey;={google:suggestAPIKeyParameter},
CHR - homepage: https://login.live.com/login.srf?wa=wsignin…=mai&snsc;=1
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.56\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.56\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.56\pdf.dll
CHR - plugin: Conduit Chrome Plugin (Enabled) = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojpijjmpahflnipadmlpgbjmagmjchkk\10.13.20.29_0\plugins/ConduitChromeApiPlugin.dll
CHR - plugin: Conduit Radio Plugin (Enabled) = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojpijjmpahflnipadmlpgbjmagmjchkk\10.13.20.29_0\plugins/np-cwmp.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.124\npGoogleUpdate3.dll
CHR - plugin: Java™ Platform SE 7 U10 (Enabled) = C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: Uplay PC (Enabled) = C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_135.dll
CHR - plugin: Java Deployment Toolkit 7.0.100.18 (Enabled) = C:\Windows\SysWOW64\npDeployJava1.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - Extension: Bejeweled = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\adpkifcfcacgmnggcbpbjbkdijciiigm\2_0\
CHR - Extension: Google Drive = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: YouTube = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Crime City = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdbacnnicmbpfcmiapnfjbefkggclmco\1_0\
CHR - Extension: AdBlock = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.5.56_0\
CHR - Extension: Old /r/leagueoflegends Theme = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\hphhelabfkiefgapcfagibfcopbebfbd\1.8_0\
CHR - Extension: avast! WebRep = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\7.0.1474_0\
CHR - Extension: Gmail = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2009/06/10 21:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3:64bit: - HKLM\..\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3:64bit: - HKLM\..\Toolbar: (no name) - {ae07101b-46d4-4a98-af68-0333ea26e113} - No CLSID value found.
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No CLSID value found.
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [amd_dc_opt] C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe (AMD)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [InstaLAN] C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe (Affinegy, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~2\MICROS~3\Office14\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~2\MICROS~3\Office14\EXCEL.EXE/3000 File not found
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: sony.com ([]* in Trusted sites)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 10.10.2)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3AD91F80-4D5C-45E7-8D25-B6C5B3F817D9}: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18 - Protocol\Handler\ms-help - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013/01/30 16:14:54 | 000,000,000 | —D | C] – C:\Windows\ERUNT
[2013/01/30 16:14:22 | 000,000,000 | —D | C] – C:\JRT
[2013/01/30 16:11:05 | 000,537,243 | —- | C] (Oleg N. Scherbakov) – C:\Users\User\Desktop\JRT (1).exe
[2013/01/30 16:01:18 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\User\Desktop\OTL.exe
[2013/01/30 01:20:04 | 000,000,000 | —D | C] – C:\_OTL
[2013/01/27 15:31:52 | 000,000,000 | —D | C] – C:\ProgramData\ATI
[2013/01/27 15:31:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\AMD AVT
[2013/01/27 15:31:41 | 000,000,000 | —D | C] – C:\Program Files (x86)\AMD APP
[2013/01/27 15:31:21 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center
[2013/01/24 17:59:28 | 000,000,000 | —D | C] – C:\Users\User\AppData\Roaming\Malwarebytes
[2013/01/24 17:59:20 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/01/24 17:59:20 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2013/01/24 17:59:19 | 000,024,176 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2013/01/24 17:59:19 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2013/01/24 17:59:10 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\Programs
[2013/01/20 21:50:27 | 000,000,000 | —D | C] – C:\Users\User\Documents\Hitman Blood Money
[2013/01/20 21:48:42 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\Square Enix
[2013/01/16 22:56:57 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\Solid State Networks
[2013/01/16 22:56:39 | 000,000,000 | —D | C] – C:\Program Files (x86)\MeteorEntertainment
[2013/01/16 22:56:39 | 000,000,000 | —D | C] – C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Meteor Entertainment
[2013/01/10 17:29:00 | 000,000,000 | —D | C] – C:\Users\User\Documents\Outlook Files
[2013/01/07 20:10:54 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2013/01/06 17:05:10 | 000,000,000 | —D | C] – C:\Program Files (x86)\Google
[2013/01/06 16:54:23 | 000,000,000 | R–D | C] – C:\Program Files (x86)\Skype
[2013/01/06 16:54:23 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2013/01/06 16:54:23 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Skype
[2013/01/06 16:50:16 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\Macromedia
[2013/01/06 16:49:51 | 000,000,000 | —D | C] – C:\Users\User\AppData\Roaming\Mozilla
[2013/01/06 16:49:51 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\Mozilla
[2013/01/06 16:49:40 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Maintenance Service
[2013/01/06 16:49:40 | 000,000,000 | —D | C] – C:\ProgramData\Mozilla
[2013/01/06 16:49:38 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2013/01/06 16:45:37 | 000,000,000 | —D | C] – C:\Windows\SysWow64\Adobe
[2012/12/31 22:48:13 | 000,000,000 | —D | C] – C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
[2011/08/31 15:16:50 | 000,155,936 | —- | C] (Sysinternals) – C:\Users\User\sdelete.exe
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\User\Desktop\*.tmp files -> C:\Users\User\Desktop\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/01/30 16:28:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/01/30 16:14:00 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/01/30 16:11:18 | 000,537,243 | —- | M] (Oleg N. Scherbakov) – C:\Users\User\Desktop\JRT (1).exe
[2013/01/30 16:01:22 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\User\Desktop\OTL.exe
[2013/01/30 15:55:10 | 000,000,322 | —- | M] () – C:\Windows\tasks\HP Photo Creations Communicator.job
[2013/01/30 14:24:03 | 000,022,560 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/01/30 14:24:03 | 000,022,560 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/01/30 14:21:55 | 000,793,234 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/01/30 14:21:55 | 000,673,684 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/01/30 14:21:55 | 000,129,574 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/01/30 14:09:11 | 000,000,890 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/01/30 14:08:06 | 000,001,958 | —- | M] () – C:\Users\Public\Desktop\avast! Internet Security.lnk
[2013/01/30 14:08:02 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\config.nt
[2013/01/30 14:07:28 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/01/30 14:07:25 | 2082,299,903 | -HS- | M] () – C:\hiberfil.sys
[2013/01/28 00:19:14 | 560,918,836 | —- | M] () – C:\Windows\MEMORY.DMP
[2013/01/24 17:59:20 | 000,001,113 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/01/18 16:30:18 | 000,007,018 | —- | M] () – C:\Users\User\Documents\cc_20130118_163008.reg
[2013/01/18 16:28:57 | 000,000,822 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2013/01/11 20:37:50 | 000,281,688 | —- | M] () – C:\Windows\SysWow64\PnkBstrB.xtr
[2013/01/11 20:37:50 | 000,281,688 | —- | M] () – C:\Windows\SysWow64\PnkBstrB.exe
[2013/01/09 17:14:15 | 000,418,896 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2013/01/09 16:53:53 | 000,778,702 | —- | M] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2013/01/08 00:03:20 | 761,440,108 | —- | M] () – C:\Users\User\Desktop\Gw2.dat
[2013/01/07 23:55:47 | 022,301,248 | —- | M] (ArenaNet) – C:\Users\User\Desktop\Gw2.exe
[2013/01/07 00:06:20 | 000,281,688 | —- | M] () – C:\Windows\SysWow64\PnkBstrB.ex0
[2013/01/06 16:54:23 | 000,002,515 | —- | M] () – C:\Users\Public\Desktop\Skype.lnk
[2013/01/06 16:34:22 | 000,001,254 | —- | M] () – C:\Users\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2013/01/03 23:56:06 | 000,000,024 | —- | M] () – C:\Users\User\random.dat
[2013/01/03 21:13:38 | 000,000,043 | —- | M] () – C:\Users\User\jagex_cl_runescape_LIVE.dat
[2013/01/03 21:12:07 | 000,000,045 | —- | M] () – C:\Users\User\jagex_cl_loginapplet_LIVE.dat
[2013/01/03 16:50:05 | 000,076,888 | —- | M] () – C:\Windows\SysWow64\PnkBstrA.exe
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\User\Desktop\*.tmp files -> C:\Users\User\Desktop\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/01/25 15:28:40 | 560,918,836 | —- | C] () – C:\Windows\MEMORY.DMP
[2013/01/24 17:59:20 | 000,001,113 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/01/18 16:30:12 | 000,007,018 | —- | C] () – C:\Users\User\Documents\cc_20130118_163008.reg
[2013/01/07 20:09:49 | 000,000,894 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/01/07 20:09:48 | 000,000,890 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/01/06 16:54:23 | 000,002,515 | —- | C] () – C:\Users\Public\Desktop\Skype.lnk
[2013/01/06 16:49:43 | 000,001,146 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2012/11/12 15:04:01 | 000,000,045 | —- | C] () – C:\Users\User\jagex_cl_loginapplet_LIVE.dat
[2012/10/23 18:41:32 | 000,007,605 | —- | C] () – C:\Users\User\AppData\Local\Resmon.ResmonCfg
[2012/07/08 19:13:51 | 000,281,688 | —- | C] () – C:\Windows\SysWow64\PnkBstrB.exe
[2012/07/08 19:13:44 | 000,076,888 | —- | C] () – C:\Windows\SysWow64\PnkBstrA.exe
[2012/07/08 19:13:43 | 003,130,440 | —- | C] () – C:\Windows\SysWow64\pbsvc_blr.exe
[2012/06/29 19:39:11 | 000,000,092 | —- | C] () – C:\Users\User\AppData\Local\fusioncache.dat
[2012/05/04 20:01:13 | 000,778,702 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2012/05/02 13:58:10 | 000,029,184 | —- | C] () – C:\Windows\SysWow64\kdbsdk32.dll
[2012/04/20 15:36:56 | 000,000,262 | —- | C] () – C:\Windows\{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}_WiseFW.ini
[2012/04/13 19:11:43 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2012/04/07 16:10:15 | 000,000,043 | —- | C] () – C:\Users\User\jagex_cl_runescape_LIVE.dat
[2012/04/07 16:10:15 | 000,000,024 | —- | C] () – C:\Users\User\random.dat
[2012/04/06 11:20:21 | 000,008,192 | —- | C] () – C:\Windows\SysWow64\drivers\IntelMEFWVer.dll
[2012/04/06 11:16:26 | 000,145,804 | —- | C] () – C:\Windows\SysWow64\igcompkrng600.bin
[2012/04/06 11:12:53 | 000,000,010 | —- | C] () – C:\Windows\GSetup.ini
[2012/03/19 22:25:58 | 000,058,880 | —- | C] () – C:\Windows\SysWow64\igdde32.dll
[2012/03/19 21:21:14 | 013,212,672 | —- | C] () – C:\Windows\SysWow64\ig4icd32.dll
[2012/03/09 04:31:26 | 000,204,952 | —- | C] () – C:\Windows\SysWow64\ativvsvl.dat
[2012/03/09 04:31:26 | 000,157,144 | —- | C] () – C:\Windows\SysWow64\ativvsva.dat
[2012/02/14 17:47:06 | 000,963,912 | —- | C] () – C:\Windows\SysWow64\igkrng600.bin
[2012/02/14 17:47:06 | 000,261,208 | —- | C] () – C:\Windows\SysWow64\igfcg600m.bin
[2011/09/28 16:44:14 | 000,179,271 | —- | C] () – C:\Windows\SysWow64\xlive.dll.cat
[2011/09/12 22:06:16 | 000,003,917 | —- | C] () – C:\Windows\SysWow64\atipblag.dat

========== ZeroAccess Check ==========

[2009/07/14 04:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2012/06/09 05:43:10 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/09 04:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/14 01:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/21 03:24:25 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/14 01:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2012/04/06 12:22:12 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\AVG2012
[2013/01/18 16:29:48 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\Azureus
[2012/06/01 15:32:31 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\capy
[2012/06/01 22:07:37 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\fltk.org
[2012/06/15 16:44:20 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\Gyazo
[2012/04/06 18:55:11 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\LolClient
[2012/05/24 13:54:00 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\LolClient2
[2012/04/06 12:01:48 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\Splashtop
[2012/04/22 02:12:05 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\SplitMediaLabs
[2012/11/26 00:37:05 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\SystemRequirementsLab
[2012/04/09 13:41:00 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\Visan
[2012/08/23 13:38:09 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\wargaming.net

========== Purity Check ==========



< End of report >
Hi Derpina

Unfortunately we need to get rid of some of the same again.

Note: Please temporarily disable MalwareBytes Anti-Malware again for the duration of this fix as it may interfere with the successfully execution of the script below.

Run OTL
  • double click on the icon to run it.
  • copy/paste ALL the following text written inside the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    IE - HKCU\..\SearchScopes\{89702040-18AF-416b-B0E0-7012894C77FE}: "URL" = http://uk.search.yahoo.com/search?p={searc…amp;type=IEBDSV
    IE - HKCU\..\SearchScopes\{BABCB421-7CA1-4B5C-BB0A-2A118CB6305B}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2504091
    IE - HKCU\..\SearchScopes\{E0F00850-AE0D-48d9-BE93-10117BA27B60}: "URL" = http://www.google.com/cse?cx=partner-pub-3…q={searchTerms}
    CHR - plugin: Conduit Chrome Plugin (Enabled) = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojpijjmpahflnipadmlpgbjmagmjchkk\10.13.20.29_0\plugins/ConduitChromeApiPlugin.dll
    CHR - plugin: Conduit Radio Plugin (Enabled) = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojpijjmpahflnipadmlpgbjmagmjchkk\10.13.20.29_0\plugins/np-cwmp.dll
    O3:64bit: - HKLM\..\Toolbar: (no name) - {ae07101b-46d4-4a98-af68-0333ea26e113} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No CLSID value found.
    
    :Commands
    [purity]
    [emptytemp]
    [Reboot]

  • click the Run Fix button at the top
  • let the program run unhindered, reboot when it is done
  • post a new OTL log.
===============================================

Download and run ComboFix

Download Combofix from either of the links below, and save it to your desktop.

Link 1
Link 2

**Note: It is important that it is saved directly to your desktop**

——————————————————————–

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

——————————————————————–

Double click on ComboFix.exe & follow the prompts.
  • when finished, it will produce a report for you.
  • please post the C:\ComboFix.txt in you next post.
Logs to include in the next post:

OTL log
ComboFix.txt


Thanks

Satchfan
Okay so I ran both of those scans, and they went fine, until ComboFix rebooted my Pc where I got a lil scared. I will attach a photo. Pretty much every time I tried to open a file the error message that is attached would appear. However after rebooting my pc again, everything seems to be working as normal. Not sure why this happened, maybe you do? Anyway here are both logs. All processes killed ========== SERVICES/DRIVERS ========== ========== OTL ========== Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{89702040-18AF-416b-B0E0-7012894C77FE}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{89702040-18AF-416b-B0E0-7012894C77FE}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BABCB421-7CA1-4B5C-BB0A-2A118CB6305B}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BABCB421-7CA1-4B5C-BB0A-2A118CB6305B}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{E0F00850-AE0D-48d9-BE93-10117BA27B60}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E0F00850-AE0D-48d9-BE93-10117BA27B60}\ not found. File C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojpijjmpahflnipadmlpgbjmagmjchkk\10.13.20.29_0\plugins/ConduitChromeApiPlugin.dll not found. File C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojpijjmpahflnipadmlpgbjmagmjchkk\10.13.20.29_0\plugins/np-cwmp.dll not found. 64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{ae07101b-46d4-4a98-af68-0333ea26e113} deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ae07101b-46d4-4a98-af68-0333ea26e113}\ deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}\ deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 53664 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Public User: User ->Temp folder emptied: 170808141 bytes ->Temporary Internet Files folder emptied: 3730272 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 0 bytes ->Google Chrome cache emptied: 366285449 bytes ->Flash cache emptied: 54523 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 200704 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 20910962 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 0 bytes RecycleBin emptied: 341179 bytes Total Files Cleaned = 536.00 mb OTL by OldTimer - Version 3.2.69.0 log created on 01312013_013559 Files\Folders moved on Reboot… C:\Users\User\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. File move failed. C:\Windows\temp\_avast_\Webshlock.txt scheduled to be moved on reboot. PendingFileRenameOperations files… Registry entries deleted on Reboot… ComboFix 13-01-30.04 - User 31/01/2013 1:44.1.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.8109.5855 [GMT 0:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . C:\Install.exe c:\programdata\ntuser.dat c:\users\User\AppData\Local\Temp\1.tmp\F_IN_BOX.dll c:\users\User\sdelete.exe c:\windows\SysWow64\URTTemp c:\windows\SysWow64\URTTemp\regtlib.exe . . ((((((((((((((((((((((((( Files Created from 2012-12-28 to 2013-01-31 ))))))))))))))))))))))))))))))) . . 2013-01-31 01:51 . 2013-01-31 01:51 ——– d—–w- c:\users\Default\AppData\Local\temp 2013-01-30 16:14 . 2013-01-30 16:14 ——– d—–w- c:\windows\ERUNT 2013-01-30 16:14 . 2013-01-30 16:14 ——– d—–w- C:\JRT 2013-01-30 14:13 . 2013-01-08 05:32 9161176 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{D3146701-47EA-46B7-AC38-C117FF29AAAD}\mpengine.dll 2013-01-30 01:20 . 2013-01-30 01:20 ——– d—–w- C:\_OTL 2013-01-27 15:31 . 2013-01-27 15:31 ——– d—–w- c:\programdata\ATI 2013-01-27 15:31 . 2013-01-27 15:31 ——– d—–w- c:\program files (x86)\AMD AVT 2013-01-27 15:31 . 2013-01-27 15:31 ——– d—–w- c:\program files (x86)\AMD APP 2013-01-24 17:59 . 2013-01-24 17:59 ——– d—–w- c:\users\User\AppData\Roaming\Malwarebytes 2013-01-24 17:59 . 2013-01-24 17:59 ——– d—–w- c:\programdata\Malwarebytes 2013-01-24 17:59 . 2013-01-30 14:05 ——– d—–w- c:\program files (x86)\Malwarebytes' Anti-Malware 2013-01-24 17:59 . 2012-12-14 16:49 24176 —-a-w- c:\windows\system32\drivers\mbam.sys 2013-01-24 17:59 . 2013-01-24 17:59 ——– d—–w- c:\users\User\AppData\Local\Programs 2013-01-20 21:48 . 2013-01-20 21:48 ——– d—–w- c:\users\User\AppData\Local\Square Enix 2013-01-19 16:46 . 2013-01-12 03:30 95648 —-a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll 2013-01-16 22:56 . 2013-01-17 00:16 ——– d—–w- c:\users\User\AppData\Local\Solid State Networks 2013-01-16 22:56 . 2013-01-17 00:16 ——– d—–w- c:\program files (x86)\MeteorEntertainment 2013-01-09 15:25 . 2012-11-09 05:45 750592 —-a-w- c:\windows\system32\win32spl.dll 2013-01-09 15:25 . 2012-11-09 04:43 492032 —-a-w- c:\windows\SysWow64\win32spl.dll 2013-01-09 15:23 . 2012-11-23 03:13 68608 —-a-w- c:\windows\system32\taskhost.exe 2013-01-09 15:23 . 2012-11-23 03:26 3149824 —-a-w- c:\windows\system32\win32k.sys 2013-01-06 17:05 . 2013-01-07 20:10 ——– d—–w- c:\program files (x86)\Google 2013-01-06 16:54 . 2013-01-06 16:54 ——– d—–w- c:\program files (x86)\Common Files\Skype 2013-01-06 16:54 . 2013-01-06 16:54 ——– d—–r- c:\program files (x86)\Skype 2013-01-06 16:50 . 2013-01-06 16:50 ——– d—–w- c:\users\User\AppData\Local\Macromedia 2013-01-06 16:49 . 2013-01-06 16:49 ——– d—–w- c:\users\User\AppData\Local\Mozilla 2013-01-06 16:49 . 2013-01-06 16:49 ——– d—–w- c:\program files (x86)\Mozilla Maintenance Service 2013-01-06 16:45 . 2013-01-06 16:45 ——– d—–w- c:\windows\SysWow64\Adobe . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-01-11 20:37 . 2012-07-08 19:15 281688 —-a-w- c:\windows\SysWow64\PnkBstrB.xtr 2013-01-11 20:37 . 2012-07-08 19:13 281688 —-a-w- c:\windows\SysWow64\PnkBstrB.exe 2013-01-09 16:49 . 2012-04-06 12:41 67599240 —-a-w- c:\windows\system32\MRT.exe 2013-01-08 20:28 . 2012-04-07 00:37 74248 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-01-08 20:28 . 2012-04-07 00:37 697864 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-01-07 00:06 . 2012-07-08 19:13 281688 —-a-w- c:\windows\SysWow64\PnkBstrB.ex0 2013-01-03 16:50 . 2012-07-08 19:13 76888 —-a-w- c:\windows\SysWow64\PnkBstrA.exe 2012-12-19 20:50 . 2012-07-28 04:09 5630200 —-a-w- c:\windows\SysWow64\atiumdag.dll 2012-12-19 20:48 . 2012-12-19 20:48 11278336 —-a-w- c:\windows\system32\drivers\atikmdag.sys 2012-12-19 20:29 . 2012-12-19 20:29 23461376 —-a-w- c:\windows\system32\atio6axx.dll 2012-12-19 20:22 . 2012-12-19 20:22 70144 —-a-w- c:\windows\system32\coinst_9.012.dll 2012-12-19 20:19 . 2012-12-19 20:19 163840 —-a-w- c:\windows\system32\atiapfxx.exe 2012-12-19 20:18 . 2012-12-19 20:18 51200 —-a-w- c:\windows\system32\aticalrt64.dll 2012-12-19 20:18 . 2012-12-19 20:18 46080 —-a-w- c:\windows\SysWow64\aticalrt.dll 2012-12-19 20:17 . 2012-12-19 20:17 44544 —-a-w- c:\windows\system32\aticalcl64.dll 2012-12-19 20:17 . 2012-12-19 20:17 44032 —-a-w- c:\windows\SysWow64\aticalcl.dll 2012-12-19 20:17 . 2012-12-19 20:17 16082944 —-a-w- c:\windows\system32\aticaldd64.dll 2012-12-19 20:13 . 2012-12-19 20:13 13703168 —-a-w- c:\windows\SysWow64\aticaldd.dll 2012-12-19 20:12 . 2012-12-19 20:12 18982400 —-a-w- c:\windows\SysWow64\atioglxx.dll 2012-12-19 20:09 . 2012-07-28 02:15 960512 —-a-w- c:\windows\SysWow64\aticfx32.dll 2012-12-19 20:08 . 2012-03-09 05:14 1151488 —-a-w- c:\windows\system32\aticfx64.dll 2012-12-19 20:06 . 2012-12-19 20:06 6681088 —-a-w- c:\windows\SysWow64\atidxx32.dll 2012-12-19 19:59 . 2012-12-19 19:59 5087744 —-a-w- c:\windows\system32\atiumd6a.dll 2012-12-19 19:57 . 2012-12-19 19:57 442368 —-a-w- c:\windows\system32\atidemgy.dll 2012-12-19 19:56 . 2012-12-19 19:56 550912 —-a-w- c:\windows\system32\atieclxx.exe 2012-12-19 19:56 . 2012-12-19 19:56 240640 —-a-w- c:\windows\system32\atiesrxx.exe 2012-12-19 19:54 . 2012-12-19 19:54 120320 —-a-w- c:\windows\system32\atitmm64.dll 2012-12-19 19:54 . 2012-12-19 19:54 21504 —-a-w- c:\windows\system32\atimuixx.dll 2012-12-19 19:54 . 2012-12-19 19:54 59392 —-a-w- c:\windows\system32\atiedu64.dll 2012-12-19 19:54 . 2012-12-19 19:54 43520 —-a-w- c:\windows\SysWow64\ati2edxx.dll 2012-12-19 19:49 . 2012-03-09 04:45 7370752 —-a-w- c:\windows\system32\atidxx64.dll 2012-12-19 19:44 . 2012-07-28 01:32 4162048 —-a-w- c:\windows\SysWow64\atiumdva.dll 2012-12-19 19:44 . 2012-12-19 19:44 6786560 —-a-w- c:\windows\system32\atiumd64.dll 2012-12-19 19:33 . 2012-12-19 19:33 56320 —-a-w- c:\windows\system32\atimpc64.dll 2012-12-19 19:33 . 2012-12-19 19:33 56320 —-a-w- c:\windows\system32\amdpcom64.dll 2012-12-19 19:33 . 2012-12-19 19:33 619008 —-a-w- c:\windows\system32\atiadlxx.dll 2012-12-19 19:33 . 2012-12-19 19:33 56832 —-a-w- c:\windows\SysWow64\atimpc32.dll 2012-12-19 19:33 . 2012-12-19 19:33 56832 —-a-w- c:\windows\SysWow64\amdpcom32.dll 2012-12-19 19:33 . 2012-12-19 19:33 421888 —-a-w- c:\windows\SysWow64\atiadlxy.dll 2012-12-19 19:33 . 2012-12-19 19:33 17920 —-a-w- c:\windows\system32\atig6pxx.dll 2012-12-19 19:33 . 2012-12-19 19:33 14848 —-a-w- c:\windows\SysWow64\atiglpxx.dll 2012-12-19 19:33 . 2012-12-19 19:33 14848 —-a-w- c:\windows\system32\atiglpxx.dll 2012-12-19 19:33 . 2012-12-19 19:33 41984 —-a-w- c:\windows\system32\atig6txx.dll 2012-12-19 19:33 . 2012-12-19 19:33 33280 —-a-w- c:\windows\SysWow64\atigktxx.dll 2012-12-19 19:32 . 2012-12-19 19:32 552960 —-a-w- c:\windows\system32\drivers\atikmpag.sys 2012-12-19 19:31 . 2012-03-09 03:57 130048 —-a-w- c:\windows\system32\atiuxp64.dll 2012-12-19 19:31 . 2012-12-19 19:31 109568 —-a-w- c:\windows\SysWow64\atiuxpag.dll 2012-12-19 19:31 . 2012-12-19 19:31 104448 —-a-w- c:\windows\system32\atiu9p64.dll 2012-12-19 19:30 . 2012-07-28 01:13 83968 —-a-w- c:\windows\SysWow64\atiu9pag.dll 2012-12-19 19:30 . 2012-12-19 19:30 53248 —-a-w- c:\windows\system32\drivers\ati2erec.dll 2012-12-19 15:45 . 2012-12-19 15:45 222720 —-a-w- c:\windows\system32\clinfo.exe 2012-12-19 15:44 . 2012-12-19 15:44 76288 —-a-w- c:\windows\system32\OpenVideo64.dll 2012-12-19 15:44 . 2012-12-19 15:44 65536 —-a-w- c:\windows\SysWow64\OpenVideo.dll 2012-12-19 15:44 . 2012-12-19 15:44 64000 —-a-w- c:\windows\system32\OVDecode64.dll 2012-12-19 15:44 . 2012-12-19 15:44 56320 —-a-w- c:\windows\SysWow64\OVDecode.dll 2012-12-19 15:44 . 2012-12-19 15:44 34518016 —-a-w- c:\windows\system32\amdocl64.dll 2012-12-19 15:38 . 2012-12-19 15:38 28732928 —-a-w- c:\windows\SysWow64\amdocl.dll 2012-12-19 15:34 . 2012-12-19 15:34 54784 —-a-w- c:\windows\system32\OpenCL.dll 2012-12-19 15:34 . 2012-12-19 15:34 50176 —-a-w- c:\windows\SysWow64\OpenCL.dll 2012-12-18 03:20 . 2012-06-15 20:44 859072 —-a-w- c:\windows\SysWow64\npdeployJava1.dll 2012-12-18 03:20 . 2012-04-07 00:40 779704 —-a-w- c:\windows\SysWow64\deployJava1.dll 2012-12-16 17:11 . 2012-12-21 16:02 46080 —-a-w- c:\windows\system32\atmlib.dll 2012-12-16 14:45 . 2012-12-21 16:02 367616 —-a-w- c:\windows\system32\atmfd.dll 2012-12-16 14:13 . 2012-12-21 16:02 295424 —-a-w- c:\windows\SysWow64\atmfd.dll 2012-12-16 14:13 . 2012-12-21 16:02 34304 —-a-w- c:\windows\SysWow64\atmlib.dll 2012-11-30 04:45 . 2013-01-09 15:24 44032 —-a-w- c:\windows\apppatch\acwow64.dll 2012-11-14 07:06 . 2012-12-12 17:34 17811968 —-a-w- c:\windows\system32\mshtml.dll 2012-11-14 06:32 . 2012-12-12 17:34 10925568 —-a-w- c:\windows\system32\ieframe.dll 2012-11-14 06:11 . 2012-12-12 17:34 2312704 —-a-w- c:\windows\system32\jscript9.dll 2012-11-14 06:04 . 2012-12-12 17:34 1346048 —-a-w- c:\windows\system32\urlmon.dll 2012-11-14 06:04 . 2012-12-12 17:34 1392128 —-a-w- c:\windows\system32\wininet.dll 2012-11-14 06:02 . 2012-12-12 17:34 1494528 —-a-w- c:\windows\system32\inetcpl.cpl 2012-11-14 06:02 . 2012-12-12 17:34 237056 —-a-w- c:\windows\system32\url.dll 2012-11-14 05:59 . 2012-12-12 17:34 85504 —-a-w- c:\windows\system32\jsproxy.dll 2012-11-14 05:58 . 2012-12-12 17:34 816640 —-a-w- c:\windows\system32\jscript.dll 2012-11-14 05:57 . 2012-12-12 17:34 599040 —-a-w- c:\windows\system32\vbscript.dll 2012-11-14 05:57 . 2012-12-12 17:34 173056 —-a-w- c:\windows\system32\ieUnatt.exe 2012-11-14 05:55 . 2012-12-12 17:34 2144768 —-a-w- c:\windows\system32\iertutil.dll 2012-11-14 05:55 . 2012-12-12 17:34 729088 —-a-w- c:\windows\system32\msfeeds.dll 2012-11-14 05:53 . 2012-12-12 17:34 96768 —-a-w- c:\windows\system32\mshtmled.dll 2012-11-14 05:52 . 2012-12-12 17:34 2382848 —-a-w- c:\windows\system32\mshtml.tlb 2012-11-14 05:46 . 2012-12-12 17:34 248320 —-a-w- c:\windows\system32\ieui.dll 2012-11-14 02:09 . 2012-12-12 17:34 1800704 —-a-w- c:\windows\SysWow64\jscript9.dll 2012-11-14 01:58 . 2012-12-12 17:34 1427968 —-a-w- c:\windows\SysWow64\inetcpl.cpl 2012-11-14 01:57 . 2012-12-12 17:34 1129472 —-a-w- c:\windows\SysWow64\wininet.dll 2012-11-14 01:49 . 2012-12-12 17:34 142848 —-a-w- c:\windows\SysWow64\ieUnatt.exe 2012-11-14 01:48 . 2012-12-12 17:34 420864 —-a-w- c:\windows\SysWow64\vbscript.dll 2012-11-14 01:44 . 2012-12-12 17:34 2382848 —-a-w- c:\windows\SysWow64\mshtml.tlb 2012-11-09 05:45 . 2012-12-12 16:17 2048 —-a-w- c:\windows\system32\tzres.dll 2012-11-09 04:42 . 2012-12-12 16:17 2048 —-a-w- c:\windows\SysWow64\tzres.dll 2012-11-08 11:29 . 2012-11-08 11:29 1402312 —-a-w- c:\windows\SysWow64\msxml4.dll 2012-11-06 11:11 . 2012-11-06 11:11 96256 —-a-w- c:\windows\system32\drivers\AtihdW76.sys 2012-11-02 05:59 . 2012-12-12 16:16 478208 —-a-w- c:\windows\system32\dpnet.dll 2012-11-02 05:11 . 2012-12-12 16:16 376832 —-a-w- c:\windows\SysWow64\dpnet.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2012-11-09 17877168] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "HP Software Update"="c:\program files (x86)\Hp\HP Software Update\HPWuSchd2.exe" [2010-06-09 49208] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352] "amd_dc_opt"="c:\program files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2008-07-22 77824] "InstaLAN"="c:\program files (x86)\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe" [2011-05-27 2015136] "avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-10-30 4297136] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-12-19 642808] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) . R1 EIO64;EIO Driver;c:\windows\system32\DRIVERS\EIO64.sys [x] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-12-14 398184] R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-12-14 682344] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-11-09 160944] R3 AppleChargerSrv;AppleChargerSrv;c:\windows\system32\AppleChargerSrv.exe [2010-04-06 31272] R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-12-14 24176] R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2012-04-06 1255736] S0 aswNdis;avast! Firewall NDIS Filter Service;c:\windows\system32\DRIVERS\aswNdis.sys [2012-09-21 12368] S0 aswNdis2;avast! Firewall Core Firewall Service; [x] S1 AppleCharger;AppleCharger;c:\windows\system32\DRIVERS\AppleCharger.sys [2011-01-10 21104] S1 aswFW;avast! TDI Firewall driver; [x] S1 aswKbd;aswKbd; [x] S1 aswSnx;aswSnx; [x] S1 aswSP;aswSP; [x] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2012-12-19 240640] S2 aswFsBlk;aswFsBlk; [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2012-10-30 71600] S2 avast! Firewall;avast! Firewall;c:\program files\AVAST Software\Avast\afwServ.exe [2012-10-30 133912] S2 Belkin Local Backup Service;Belkin Local Backup Service;c:\program files\Belkin\Belkin USB Print and Storage Center\BkBackupScheduler.exe [2011-04-19 181760] S2 Belkin Network USB Helper;Belkin Network USB Helper;c:\program files\Belkin\Belkin USB Print and Storage Center\Bkapcs.exe [2010-02-09 55296] S2 sxuptp;SXUPTP Driver;c:\windows\system32\DRIVERS\sxuptp.sys [2009-06-22 291352] S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2012-11-06 96256] S3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;c:\windows\system32\Drivers\EtronHub3.sys [2011-07-29 56960] S3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;c:\windows\system32\Drivers\EtronXHCI.sys [2011-07-29 79104] S3 IntcDAud;Intel® Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2010-10-14 317440] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2011-06-01 535656] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2013-01-24 02:15 1607120 —-a-w- c:\program files (x86)\Google\Chrome\Application\24.0.1312.56\Installer\chrmstp.exe . Contents of the 'Scheduled Tasks' folder . 2013-01-31 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-07 20:28] . 2013-01-31 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-01-07 20:09] . 2013-01-31 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-01-07 20:09] . 2013-01-31 c:\windows\Tasks\HP Photo Creations Communicator.job - c:\programdata\HP Photo Creations\MessageCheck.exe [2012-04-09 13:19] . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2012-10-30 22:50 133400 —-a-w- c:\program files\AVAST Software\Avast\ashShA64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-07-21 12632168] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-03-19 170264] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-03-19 398616] "Persistence"="c:\windows\system32\igfxpers.exe" [2012-03-19 439064] . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.google.com mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = uSearchAssistant = hxxp://www.google.com IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~3\Office14\EXCEL.EXE/3000 IE: Se&nd to OneNote - c:\progra~2\MICROS~3\Office14\ONBttnIE.dll/105 Trusted Zone: clonewarsadventures.com Trusted Zone: freerealms.com Trusted Zone: soe.com Trusted Zone: sony.com TCP: DhcpNameServer = 192.168.2.1 FF - ProfilePath - c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\11nx87hu.default\ FF - ExtSQL: 2013-01-06 16:57; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\11nx87hu.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi . - - - - ORPHANS REMOVED - - - - . Wow6432Node-HKLM-Run- - (no file) SafeBoot-BsScanner AddRemove-Coupon Printer for Windows5.0.0.0 - c:\program files (x86)\Coupons\uninstall.exe . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_146_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_146_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_146_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_146_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\DbgagD\1*] "value"="?\07\03\12\01'%U" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] @Denied: (A) (Everyone) "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0] "Key"="ActionsPane3" "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0\Solutions\http://schemas.microsoft.com/office/smartdocuments/2003\0] "Key"="http://schemas.microsoft.com/office/smartdocuments/2003" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0\Solutions\http://schemas.microsoft.com/office/smartdocuments/2003\0\{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}\Alias] "0"="Microsoft Actions Pane 3" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files\AVAST Software\Avast\AvastSvc.exe c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe c:\program files (x86)\Belkin\Router Setup and Monitor\BelkinService.exe c:\windows\SysWOW64\PnkBstrA.exe . ************************************************************************** . Completion time: 2013-01-31 01:56:21 - machine was rebooted ComboFix-quarantined-files.txt 2013-01-31 01:56 . Pre-Run: 717,874,159,616 bytes free Post-Run: 717,490,544,640 bytes free . - - End Of File - - 6F670E3D6B5BB21EA300F6030B5E01BD

Pretty much every time I tried to open a file the error message that is attached would appear. However after rebooting my pc again, everything seems to be working as normal.

That's quite normal and a reboot as you did, resolves the problem.

I am a bit busy today so will check and reply as soon as I can.

Meanwhile, can you post a new OTL log.

Thanks

Satchfan
That's fine, just reply when you have time, here is another OTL scan log that you have asked for.


OTL logfile created on: 31/01/2013 14:03:54 - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\User\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

7.92 Gb Total Physical Memory | 6.35 Gb Available Physical Memory | 80.20% Memory free
15.84 Gb Paging File | 14.10 Gb Available in Paging File | 89.06% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931.41 Gb Total Space | 668.21 Gb Free Space | 71.74% Space Free | Partition Type: NTFS

Computer Name: USER-PC | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2013/01/30 16:01:22 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\User\Desktop\OTL.exe
PRC - [2013/01/03 16:50:05 | 000,076,888 | —- | M] () – C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2012/12/18 14:28:08 | 000,065,192 | —- | M] (Adobe Systems Incorporated) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012/12/14 16:49:28 | 000,682,344 | —- | M] (Malwarebytes Corporation) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012/12/14 16:49:28 | 000,512,360 | —- | M] (Malwarebytes Corporation) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012/12/14 16:49:28 | 000,398,184 | —- | M] (Malwarebytes Corporation) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2012/10/30 22:50:59 | 004,297,136 | —- | M] (AVAST Software) – C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2012/10/30 22:50:59 | 000,044,808 | —- | M] (AVAST Software) – C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2012/10/30 22:50:56 | 000,133,912 | —- | M] (AVAST Software) – C:\Program Files\AVAST Software\Avast\afwServ.exe
PRC - [2011/05/27 14:57:30 | 000,562,592 | —- | M] (Affinegy, Inc.) – C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinService.exe
PRC - [2011/05/27 14:57:28 | 002,015,136 | —- | M] (Affinegy, Inc.) – C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe
PRC - [2011/05/27 14:57:26 | 007,025,568 | —- | M] (Affinegy, Inc.) – C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinSetup.exe
PRC - [2011/05/18 17:28:16 | 001,641,888 | —- | M] (Affinegy, Inc.) – C:\Program Files (x86)\Belkin\Router Setup and Monitor\dlnaPlugin.exe


========== Modules (No Company Name) ==========

MOD - [2011/05/27 14:57:32 | 000,022,944 | —- | M] () – C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinServicePS.dll
MOD - [2011/05/27 14:08:56 | 000,660,480 | —- | M] () – C:\Program Files (x86)\Belkin\Router Setup and Monitor\gateways\GenericBelkinGatewayLOC.dll
MOD - [2010/08/22 20:01:36 | 007,187,456 | —- | M] () – C:\Program Files (x86)\Belkin\Router Setup and Monitor\QtGui4.dll
MOD - [2010/08/22 20:01:08 | 000,325,632 | —- | M] () – C:\Program Files (x86)\Belkin\Router Setup and Monitor\QtXml4.dll
MOD - [2010/08/22 20:01:06 | 001,954,304 | —- | M] () – C:\Program Files (x86)\Belkin\Router Setup and Monitor\QtCore4.dll
MOD - [2010/08/22 20:01:06 | 000,847,360 | —- | M] () – C:\Program Files (x86)\Belkin\Router Setup and Monitor\QtNetwork4.dll
MOD - [2010/08/22 19:32:34 | 000,119,808 | —- | M] () – C:\Program Files (x86)\Belkin\Router Setup and Monitor\imageformats\qjpeg4.dll


========== Services (SafeList) ==========

SRV:64bit: - [2012/12/19 19:56:00 | 000,240,640 | —- | M] (AMD) [Auto | Running] – C:\Windows\SysNative\atiesrxx.exe – (AMD External Events Utility)
SRV:64bit: - [2012/10/30 22:50:59 | 000,044,808 | —- | M] (AVAST Software) [Auto | Running] – C:\Program Files\AVAST Software\Avast\AvastSvc.exe – (avast! Antivirus)
SRV:64bit: - [2012/10/30 22:50:56 | 000,133,912 | —- | M] (AVAST Software) [Auto | Running] – C:\Program Files\AVAST Software\Avast\afwServ.exe – (avast! Firewall)
SRV:64bit: - [2011/04/19 15:31:16 | 000,181,760 | —- | M] () [Auto | Running] – C:\Program Files\Belkin\Belkin USB Print and Storage Center\BkBackupScheduler.exe – (Belkin Local Backup Service)
SRV:64bit: - [2010/04/06 15:30:38 | 000,031,272 | —- | M] () [On_Demand | Stopped] – C:\Windows\SysNative\AppleChargerSrv.exe – (AppleChargerSrv)
SRV:64bit: - [2010/02/09 14:55:52 | 000,055,296 | —- | M] () [Auto | Running] – C:\Program Files\Belkin\Belkin USB Print and Storage Center\Bkapcs.exe – (Belkin Network USB Helper)
SRV:64bit: - [2009/07/14 01:41:27 | 001,011,712 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2013/01/18 22:44:07 | 000,541,608 | —- | M] (Valve Corporation) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Steam\SteamService.exe – (Steam Client Service)
SRV - [2013/01/08 20:28:11 | 000,251,400 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe – (AdobeFlashPlayerUpdateSvc)
SRV - [2013/01/03 16:50:05 | 000,076,888 | —- | M] () [Auto | Running] – C:\Windows\SysWOW64\PnkBstrA.exe – (PnkBstrA)
SRV - [2012/12/18 14:28:08 | 000,065,192 | —- | M] (Adobe Systems Incorporated) [Auto | Running] – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe – (AdobeARMservice)
SRV - [2012/12/14 16:49:28 | 000,682,344 | —- | M] (Malwarebytes Corporation) [Auto | Running] – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe – (MBAMService)
SRV - [2012/12/14 16:49:28 | 000,398,184 | —- | M] (Malwarebytes Corporation) [Auto | Running] – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe – (MBAMScheduler)
SRV - [2012/11/09 11:21:24 | 000,160,944 | R— | M] (Skype Technologies) [Auto | Stopped] – C:\Program Files (x86)\Skype\Updater\Updater.exe – (SkypeUpdate)
SRV - [2012/06/14 22:20:14 | 000,113,120 | —- | M] (Mozilla Foundation) [On_Demand | Stopped] – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe – (MozillaMaintenance)
SRV - [2012/03/19 22:44:20 | 000,276,248 | —- | M] (Intel Corporation) [On_Demand | Stopped] – C:\Windows\SysWOW64\IntelCpHeciSvc.exe – (cphs)
SRV - [2011/05/27 14:57:30 | 000,562,592 | —- | M] (Affinegy, Inc.) [Auto | Running] – C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinService.exe – (AffinegyService)
SRV - [2010/03/18 12:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2009/06/10 21:23:09 | 000,066,384 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2012/12/19 20:48:48 | 011,278,336 | —- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\atikmdag.sys – (amdkmdag)
DRV:64bit: - [2012/12/19 19:32:54 | 000,552,960 | —- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\atikmpag.sys – (amdkmdap)
DRV:64bit: - [2012/12/14 16:49:28 | 000,024,176 | —- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] – C:\Windows\SysNative\drivers\mbam.sys – (MBAMProtector)
DRV:64bit: - [2012/11/06 11:11:52 | 000,096,256 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\AtihdW76.sys – (AtiHDAudioService)
DRV:64bit: - [2012/10/30 22:51:56 | 000,059,728 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\Windows\SysNative\drivers\aswTdi.sys – (aswTdi)
DRV:64bit: - [2012/10/30 22:51:55 | 000,984,144 | —- | M] (AVAST Software) [File_System | System | Running] – C:\Windows\SysNative\drivers\aswSnx.sys – (aswSnx)
DRV:64bit: - [2012/10/30 22:51:55 | 000,370,288 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\Windows\SysNative\drivers\aswSP.sys – (aswSP)
DRV:64bit: - [2012/10/30 22:51:55 | 000,262,656 | —- | M] (AVAST Software) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\aswNdis2.sys – (aswNdis2)
DRV:64bit: - [2012/10/30 22:51:55 | 000,071,600 | —- | M] (AVAST Software) [File_System | Auto | Running] – C:\Windows\SysNative\drivers\aswMonFlt.sys – (aswMonFlt)
DRV:64bit: - [2012/10/30 22:51:55 | 000,021,136 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\Windows\SysNative\drivers\aswKbd.sys – (aswKbd)
DRV:64bit: - [2012/10/30 22:51:53 | 000,132,864 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\Windows\SysNative\drivers\aswFW.sys – (aswFW)
DRV:64bit: - [2012/10/30 22:51:53 | 000,025,232 | —- | M] (AVAST Software) [File_System | Auto | Running] – C:\Windows\SysNative\drivers\aswFsBlk.sys – (aswFsBlk)
DRV:64bit: - [2012/10/15 16:59:28 | 000,054,072 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\Windows\SysNative\drivers\aswRdr2.sys – (aswRdr)
DRV:64bit: - [2012/09/21 09:26:08 | 000,012,368 | —- | M] (ALWIL Software) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\aswNdis.sys – (aswNdis)
DRV:64bit: - [2012/03/19 22:32:04 | 014,745,600 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\igdkmd64.sys – (igfx)
DRV:64bit: - [2012/03/01 06:46:16 | 000,023,408 | —- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] – C:\Windows\SysNative\drivers\fs_rec.sys – (Fs_Rec)
DRV:64bit: - [2011/07/29 03:40:00 | 000,079,104 | —- | M] (Etron Technology Inc) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\EtronXHCI.sys – (EtronXHCI)
DRV:64bit: - [2011/07/29 03:40:00 | 000,056,960 | —- | M] (Etron Technology Inc) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\EtronHub3.sys – (EtronHub3)
DRV:64bit: - [2011/06/01 03:16:50 | 000,535,656 | —- | M] (Realtek ) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Rt64win7.sys – (RTL8167)
DRV:64bit: - [2011/03/11 06:41:12 | 000,107,904 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2011/03/11 06:41:12 | 000,027,008 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2011/01/10 17:16:08 | 000,021,104 | —- | M] () [Kernel | System | Running] – C:\Windows\SysNative\drivers\AppleCharger.sys – (AppleCharger)
DRV:64bit: - [2010/11/21 03:24:33 | 000,059,392 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV:64bit: - [2010/11/21 03:23:47 | 000,078,720 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2010/11/21 03:23:47 | 000,031,232 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbGD.sys – (TsUsbGD)
DRV:64bit: - [2010/10/19 22:34:26 | 000,056,344 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\HECIx64.sys – (MEIx64)
DRV:64bit: - [2010/10/14 17:28:16 | 000,317,440 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\IntcDAud.sys – (IntcDAud)
DRV:64bit: - [2009/08/13 21:10:18 | 000,073,984 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\xusb21.sys – (xusb21)
DRV:64bit: - [2009/07/14 01:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009/07/14 01:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009/07/14 01:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009/07/14 00:01:09 | 000,679,936 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\xnacc.sys – (xnacc)
DRV:64bit: - [2009/06/22 15:50:00 | 000,291,352 | —- | M] (silex technology, Inc.) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\sxuptp.sys – (sxuptp)
DRV:64bit: - [2009/06/10 20:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009/06/10 20:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009/06/10 20:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009/06/10 20:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:64bit: - [2009/02/17 17:22:22 | 000,017,792 | —- | M] (ASUSTeK Computer Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\asusgsb.sys – (asusgsb)
DRV - [2009/07/14 01:19:10 | 000,019,008 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\wimmount.sys – (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633ee93-d776-472f-a0ff-e1416b8b2e3a}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-GB
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = FC CD F6 6E 29 EC CD 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com
IE - HKCU\..\SearchScopes,DefaultScope = {0633ee93-d776-472f-a0ff-e1416b8b2e3a}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{63B2D943-91F1-4a04-B9AA-390B3CE4A909}: "URL" = http://www.bing.com/search?q={searchTerms}…BR1&pc;=SPLH
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =

========== FireFox ==========

FF - prefs.js..extensions.enabledAddons: [removed]:7.0.1474
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_146.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_146.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.11.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.124\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.124\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@coreonline.com/run3d,version=1.0: C:\Users\User\AppData\LocalLow\Square Enix\nprun3d.dll (Square Enix)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKCU\Software\MozillaPlugins\ubisoft.com/uplaypc: C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2012/11/07 00:10:40 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/01/06 16:49:39 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins

[2013/01/06 16:50:02 | 000,000,000 | —D | M] (No name found) – C:\Users\User\AppData\Roaming\Mozilla\Extensions
[2013/01/10 17:39:01 | 000,000,000 | —D | M] (No name found) – C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\11nx87hu.default\extensions
[2013/01/06 16:57:13 | 000,804,627 | —- | M] () (No name found) – C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\11nx87hu.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2013/01/09 17:31:55 | 000,022,867 | —- | M] () – C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\11nx87hu.default\searchplugins\Web Search.xml
[2013/01/06 16:49:39 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/11/07 00:10:40 | 000,000,000 | —D | M] (avast! WebRep) – C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF
[2012/06/14 22:20:49 | 000,085,472 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/06/14 22:19:40 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/06/14 22:19:40 | 000,002,040 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - homepage: https://login.live.com/login.srf?wa=wsignin…=mai&snsc;=1
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie;={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl;={language}&q;={searchTerms}&sugkey;={google:suggestAPIKeyParameter},
CHR - homepage: https://login.live.com/login.srf?wa=wsignin…=mai&snsc;=1
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.56\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.56\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.56\pdf.dll
CHR - plugin: Conduit Chrome Plugin (Enabled) = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojpijjmpahflnipadmlpgbjmagmjchkk\10.13.20.29_0\plugins/ConduitChromeApiPlugin.dll
CHR - plugin: Conduit Radio Plugin (Enabled) = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojpijjmpahflnipadmlpgbjmagmjchkk\10.13.20.29_0\plugins/np-cwmp.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.124\npGoogleUpdate3.dll
CHR - plugin: Java™ Platform SE 7 U10 (Enabled) = C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: Uplay PC (Enabled) = C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_135.dll
CHR - plugin: Java Deployment Toolkit 7.0.100.18 (Enabled) = C:\Windows\SysWOW64\npDeployJava1.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - Extension: Bejeweled = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\adpkifcfcacgmnggcbpbjbkdijciiigm\2_0\
CHR - Extension: Google Drive = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: YouTube = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Crime City = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdbacnnicmbpfcmiapnfjbefkggclmco\1_0\
CHR - Extension: AdBlock = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.5.56_0\
CHR - Extension: Old /r/leagueoflegends Theme = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\hphhelabfkiefgapcfagibfcopbebfbd\1.8_0\
CHR - Extension: avast! WebRep = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\7.0.1474_0\
CHR - Extension: Gmail = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2013/01/31 01:52:50 | 000,000,027 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3:64bit: - HKLM\..\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [amd_dc_opt] C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe (AMD)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [InstaLAN] C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe (Affinegy, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:64bit: - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~2\MICROS~3\Office14\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~2\MICROS~3\Office14\EXCEL.EXE/3000 File not found
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: sony.com ([]* in Trusted sites)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 10.10.2)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3AD91F80-4D5C-45E7-8D25-B6C5B3F817D9}: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18 - Protocol\Handler\ms-help - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = ComFile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013/01/31 01:56:23 | 000,000,000 | —D | C] – C:\Windows\temp
[2013/01/31 01:52:57 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2013/01/31 01:43:18 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2013/01/31 01:43:18 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2013/01/31 01:43:18 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2013/01/31 01:43:12 | 000,000,000 | —D | C] – C:\Qoobox
[2013/01/31 01:42:56 | 000,000,000 | —D | C] – C:\Windows\erdnt
[2013/01/31 01:40:09 | 005,028,065 | R— | C] (Swearware) – C:\Users\User\Desktop\ComboFix.exe
[2013/01/30 16:14:54 | 000,000,000 | —D | C] – C:\Windows\ERUNT
[2013/01/30 16:14:22 | 000,000,000 | —D | C] – C:\JRT
[2013/01/30 16:11:05 | 000,537,243 | —- | C] (Oleg N. Scherbakov) – C:\Users\User\Desktop\JRT (1).exe
[2013/01/30 16:01:18 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\User\Desktop\OTL.exe
[2013/01/30 01:20:04 | 000,000,000 | —D | C] – C:\_OTL
[2013/01/27 15:31:52 | 000,000,000 | —D | C] – C:\ProgramData\ATI
[2013/01/27 15:31:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\AMD AVT
[2013/01/27 15:31:41 | 000,000,000 | —D | C] – C:\Program Files (x86)\AMD APP
[2013/01/27 15:31:21 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center
[2013/01/24 17:59:28 | 000,000,000 | —D | C] – C:\Users\User\AppData\Roaming\Malwarebytes
[2013/01/24 17:59:20 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/01/24 17:59:20 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2013/01/24 17:59:19 | 000,024,176 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2013/01/24 17:59:19 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2013/01/24 17:59:10 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\Programs
[2013/01/20 21:50:27 | 000,000,000 | —D | C] – C:\Users\User\Documents\Hitman Blood Money
[2013/01/20 21:48:42 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\Square Enix
[2013/01/16 22:56:57 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\Solid State Networks
[2013/01/16 22:56:39 | 000,000,000 | —D | C] – C:\Program Files (x86)\MeteorEntertainment
[2013/01/16 22:56:39 | 000,000,000 | —D | C] – C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Meteor Entertainment
[2013/01/10 17:29:00 | 000,000,000 | —D | C] – C:\Users\User\Documents\Outlook Files
[2013/01/07 20:10:54 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2013/01/06 17:05:10 | 000,000,000 | —D | C] – C:\Program Files (x86)\Google
[2013/01/06 16:54:23 | 000,000,000 | R–D | C] – C:\Program Files (x86)\Skype
[2013/01/06 16:54:23 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2013/01/06 16:54:23 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Skype
[2013/01/06 16:50:16 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\Macromedia
[2013/01/06 16:49:51 | 000,000,000 | —D | C] – C:\Users\User\AppData\Roaming\Mozilla
[2013/01/06 16:49:51 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\Mozilla
[2013/01/06 16:49:40 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Maintenance Service
[2013/01/06 16:49:40 | 000,000,000 | —D | C] – C:\ProgramData\Mozilla
[2013/01/06 16:49:38 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2013/01/06 16:45:37 | 000,000,000 | —D | C] – C:\Windows\SysWow64\Adobe
[1 C:\Users\User\Desktop\*.tmp files -> C:\Users\User\Desktop\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/01/31 14:00:35 | 000,000,890 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/01/31 14:00:15 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/01/31 14:00:11 | 2082,299,903 | -HS- | M] () – C:\hiberfil.sys
[2013/01/31 04:14:00 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/01/31 03:55:10 | 000,000,322 | —- | M] () – C:\Windows\tasks\HP Photo Creations Communicator.job
[2013/01/31 03:28:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/01/31 02:07:54 | 000,022,560 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/01/31 02:07:54 | 000,022,560 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/01/31 01:52:50 | 000,000,027 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2013/01/31 01:40:19 | 005,028,065 | R— | M] (Swearware) – C:\Users\User\Desktop\ComboFix.exe
[2013/01/30 16:51:20 | 000,000,600 | —- | M] () – C:\Users\User\Desktop\League of Legends.lnk
[2013/01/30 16:11:18 | 000,537,243 | —- | M] (Oleg N. Scherbakov) – C:\Users\User\Desktop\JRT (1).exe
[2013/01/30 16:01:22 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\User\Desktop\OTL.exe
[2013/01/30 14:21:55 | 000,793,234 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/01/30 14:21:55 | 000,673,684 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/01/30 14:21:55 | 000,129,574 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/01/30 14:08:06 | 000,001,958 | —- | M] () – C:\Users\Public\Desktop\avast! Internet Security.lnk
[2013/01/30 14:08:02 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\config.nt
[2013/01/28 00:19:14 | 560,918,836 | —- | M] () – C:\Windows\MEMORY.DMP
[2013/01/24 17:59:20 | 000,001,113 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/01/18 16:30:18 | 000,007,018 | —- | M] () – C:\Users\User\Documents\cc_20130118_163008.reg
[2013/01/18 16:28:57 | 000,000,822 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2013/01/11 20:37:50 | 000,281,688 | —- | M] () – C:\Windows\SysWow64\PnkBstrB.xtr
[2013/01/11 20:37:50 | 000,281,688 | —- | M] () – C:\Windows\SysWow64\PnkBstrB.exe
[2013/01/09 17:14:15 | 000,418,896 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2013/01/09 16:53:53 | 000,778,702 | —- | M] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2013/01/08 00:03:20 | 761,440,108 | —- | M] () – C:\Users\User\Desktop\Gw2.dat
[2013/01/07 23:55:47 | 022,301,248 | —- | M] (ArenaNet) – C:\Users\User\Desktop\Gw2.exe
[2013/01/07 00:06:20 | 000,281,688 | —- | M] () – C:\Windows\SysWow64\PnkBstrB.ex0
[2013/01/06 16:54:23 | 000,002,515 | —- | M] () – C:\Users\Public\Desktop\Skype.lnk
[2013/01/06 16:34:22 | 000,001,254 | —- | M] () – C:\Users\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2013/01/03 23:56:06 | 000,000,024 | —- | M] () – C:\Users\User\random.dat
[2013/01/03 21:13:38 | 000,000,043 | —- | M] () – C:\Users\User\jagex_cl_runescape_LIVE.dat
[2013/01/03 21:12:07 | 000,000,045 | —- | M] () – C:\Users\User\jagex_cl_loginapplet_LIVE.dat
[2013/01/03 16:50:05 | 000,076,888 | —- | M] () – C:\Windows\SysWow64\PnkBstrA.exe
[1 C:\Users\User\Desktop\*.tmp files -> C:\Users\User\Desktop\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/01/31 01:43:18 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2013/01/31 01:43:18 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2013/01/31 01:43:18 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2013/01/31 01:43:18 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2013/01/31 01:43:18 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2013/01/30 16:51:20 | 000,000,600 | —- | C] () – C:\Users\User\Desktop\League of Legends.lnk
[2013/01/25 15:28:40 | 560,918,836 | —- | C] () – C:\Windows\MEMORY.DMP
[2013/01/24 17:59:20 | 000,001,113 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/01/18 16:30:12 | 000,007,018 | —- | C] () – C:\Users\User\Documents\cc_20130118_163008.reg
[2013/01/07 20:09:49 | 000,000,894 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/01/07 20:09:48 | 000,000,890 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/01/06 16:54:23 | 000,002,515 | —- | C] () – C:\Users\Public\Desktop\Skype.lnk
[2013/01/06 16:49:43 | 000,001,146 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2012/11/12 15:04:01 | 000,000,045 | —- | C] () – C:\Users\User\jagex_cl_loginapplet_LIVE.dat
[2012/10/23 18:41:32 | 000,007,605 | —- | C] () – C:\Users\User\AppData\Local\Resmon.ResmonCfg
[2012/07/08 19:13:51 | 000,281,688 | —- | C] () – C:\Windows\SysWow64\PnkBstrB.exe
[2012/07/08 19:13:44 | 000,076,888 | —- | C] () – C:\Windows\SysWow64\PnkBstrA.exe
[2012/07/08 19:13:43 | 003,130,440 | —- | C] () – C:\Windows\SysWow64\pbsvc_blr.exe
[2012/06/29 19:39:11 | 000,000,092 | —- | C] () – C:\Users\User\AppData\Local\fusioncache.dat
[2012/05/04 20:01:13 | 000,778,702 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2012/05/02 13:58:10 | 000,029,184 | —- | C] () – C:\Windows\SysWow64\kdbsdk32.dll
[2012/04/20 15:36:56 | 000,000,262 | —- | C] () – C:\Windows\{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}_WiseFW.ini
[2012/04/13 19:11:43 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2012/04/07 16:10:15 | 000,000,043 | —- | C] () – C:\Users\User\jagex_cl_runescape_LIVE.dat
[2012/04/07 16:10:15 | 000,000,024 | —- | C] () – C:\Users\User\random.dat
[2012/04/06 11:20:21 | 000,008,192 | —- | C] () – C:\Windows\SysWow64\drivers\IntelMEFWVer.dll
[2012/04/06 11:16:26 | 000,145,804 | —- | C] () – C:\Windows\SysWow64\igcompkrng600.bin
[2012/04/06 11:12:53 | 000,000,010 | —- | C] () – C:\Windows\GSetup.ini
[2012/03/19 22:25:58 | 000,058,880 | —- | C] () – C:\Windows\SysWow64\igdde32.dll
[2012/03/19 21:21:14 | 013,212,672 | —- | C] () – C:\Windows\SysWow64\ig4icd32.dll
[2012/03/09 04:31:26 | 000,204,952 | —- | C] () – C:\Windows\SysWow64\ativvsvl.dat
[2012/03/09 04:31:26 | 000,157,144 | —- | C] () – C:\Windows\SysWow64\ativvsva.dat
[2012/02/14 17:47:06 | 000,963,912 | —- | C] () – C:\Windows\SysWow64\igkrng600.bin
[2012/02/14 17:47:06 | 000,261,208 | —- | C] () – C:\Windows\SysWow64\igfcg600m.bin
[2011/09/28 16:44:14 | 000,179,271 | —- | C] () – C:\Windows\SysWow64\xlive.dll.cat
[2011/09/12 22:06:16 | 000,003,917 | —- | C] () – C:\Windows\SysWow64\atipblag.dat

========== ZeroAccess Check ==========

[2009/07/14 04:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2012/06/09 05:43:10 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/09 04:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/14 01:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/21 03:24:25 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/14 01:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2012/04/06 12:22:12 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\AVG2012
[2013/01/18 16:29:48 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\Azureus
[2012/06/01 15:32:31 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\capy
[2012/06/01 22:07:37 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\fltk.org
[2012/06/15 16:44:20 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\Gyazo
[2012/04/06 18:55:11 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\LolClient
[2012/05/24 13:54:00 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\LolClient2
[2012/04/06 12:01:48 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\Splashtop
[2012/04/22 02:12:05 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\SplitMediaLabs
[2012/11/26 00:37:05 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\SystemRequirementsLab
[2012/04/09 13:41:00 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\Visan
[2012/08/23 13:38:09 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\wargaming.net

========== Purity Check ==========



< End of report >
That OTL log showed that all the entries that we tried to eliminate heve gone except the two Chrome ones:

CHR - plugin: Conduit Chrome Plugin (Enabled) = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojpijjmpahflnipadmlpgbjmagmjchkk\10.13.20.29_0\plugins/ConduitChromeApiPlugin.dll
CHR - plugin: Conduit Radio Plugin (Enabled) = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojpijjmpahflnipadmlpgbjmagmjchkk\10.13.20.29_0\plugins/np-cwmp.dll


As I've said before, Chrome offers no way to remove them and the only option is to uninstall Chrome and all your settings.


An online scan should now show that all is clear. If it is clear, which I expect it to be, I’ll give you a link to another of our forums to see if there is a hardware/software problem that caused you to restore your system recently.

Run ESET Online Scan

IMPORTANT Please make sure you uncheck the box next to Remove found threats. Eset will detect anything that looks even slightly suspicious, which could include legitimate program files. If you do not uncheck the box, Eset will automatically remove all suspicious files which could leave some of your software inoperable.

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Hold down Control and click on the following link to open ESET OnlineScan in a new window.

ESET OnlineScan 1. Click the Eset online Scanner button.
2. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)

• Click on esetinstaller.exe to download the ESET Smart Installer. Save it to your desktop.
• Double click on the Eset installer icon on your desktop.

3. Check Yes, I accept the Terms of Use
4. Click the Start button.
5. Accept any security warnings from your browser.
6. Check Scan archives
7. Push the Start button.
8. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
9. When the scan completes, push List of found threats
10. Push Export to Text file and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
Note - if ESET doesn't find any threats, no report will be created.
11. Push the back button.
12. Push Finish
If a log has been produced post it in your next reply.

Satchfan
Good work Derpina, your computer appears to be clean.

Now that you’re free from malware, as long as your computer seems to be running well, please follow these simple steps to tidy up you computer and decrease the likelihood of getting infected again:

Uninstall Combofix

Follow these steps to uninstall Combofix
  • click START then RUN
  • now type Combofix /uninstall in the runbox and click OK.
Note the space between the X and the /, it needs to be there.
🖼Click to load external image (Posted Image)
  • please follow the prompts to uninstall Combofix.
  • once it's finished uninstalling itself you will receive a message saying Combofix was uninstalled successfully.
===================================================

Uninstall OTL
  • Double-click OTL.exe
  • Click the CleanUp! button.
  • Select Yes when the Begin cleanup Process? prompt appears.
  • If you are prompted to reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes, if not delete it by yourself.
NOTE: If you receive a warning from your firewall or other security programs regarding OTL attempting to contact the internet, please allow it to do so.

You can just delete all other logs and programs we’ve used that are on your desktop. Just click on them and press Delete.

===================================================

Update installed programs

Your version of Java is out-of-date and therefore vulnerable to infections

Remove all versions of Java or JRE environment1. From the Start menu, select Control Panel.
2. In Classic View, double-click Programs and Features. In Control Panel Home view, under "Programs", click Uninstall a program.
3. Select the program you want to remove, and click Uninstall. Alternatively, right-click the program and select Uninstall.
Install the latest version of Java from here

===================================================

P2P - I see you have P2P software, (vuze\azureus), installed on your machine.

We are not here to pass judgment on file-sharing as a concept but we will warn you that engaging in this activity will always make your computer very susceptible to infection and re-infection.

If your computer is infected, it almost certainly contributed to your current situation.

Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are more often than not, infected. Those who write malware use P2P file-sharing as a major vehicle to spread their wares.

Please see this topic for more information:

Perils of P2P File Sharing.

I would strongly recommend that you uninstall it now. You can do so via Control Panel, Programs, and then Programs and Features.

===================================================

Recommended programs

SpywareBlaster. SpywareBlaster protects against bad ActiveX, it immunizes your PC against them. It blocks over 11,000 bad sites and uses no resources of your computer.

===================================================

Install Spybot - Search and Destroy - Download and install Spybot Search and Destroy which provides real time spyware and hijacker protection .

You should scan your computer with the program on a regular basis as you would with your anti-virus software.

A tutorial on installing and using SS&D can be found here:

===================================================

Update and run Malwarebytes. This really is an excellent program that you should also update and run on a regular basis, probably weekly.

===================================================

It’s important to keep programs up to date so that malware doesn't exploit any old security flaws.

FileHippo Update Checker is an extremely helpful program that will tell you which of your programs need to be updated.

===================================================

MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

===================================================

I also recommend that you read the following:

How to prevent malware by miekiemoes

If I hear nothing for 24 hours I shall assume all is well and close the topic.

Safe computing

Satchfan
Thats good to hear, uninstalled all programs now. I did get BSoD after my comp restarted from OTL wanting too reboot. Thank you very much for all your help.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI