Jump to content

Build Theme!
  •  
  • Infected?

big grin WE'RE SURE THAT YOU'LL LOVE US!

We invite you to ask questions, share experiences, and learn. It's 100% free. Did we mention that it's free. It is. It's free. Join 91521 other members! Anybody can ask, anybody can answer. Consistently helpful members with best answers are invited to staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Photo

Computer freeze during Avira Antivirus full scan [Solved]

Computer Hang Computer Freeze Antivirus scan Malware scan pc hang pc freeze PC crash Computer crash

  • This topic is locked This topic is locked
26 replies to this topic

#1 e_smurfs

e_smurfs

    New Member

  • Authentic Member
  • Pip
  • 13 posts

Posted 17 November 2013 - 02:39 AM

Hi, 

Since a week ago, my computer would freeze when running the scheduled full scan every night and I had to manually restart it by holding down the power button.
The computer is fine and has absolutely no problems until it runs a scan. It will freeze when it tries to scan the file WLanHC.dll.
And when I go into the System32 folder to look up the file, the computer will freeze.

I tried to do a scan using Malwarebytes Anti-Malware and the same thing happens. The computer will freeze when it scan up to the file WLanpref.dll. 

There is nothing I can do each time it freezes other than to restart it by holding down the power button.

I don't know how to save the log of the scan since it always hangs halfway and I have to reboot the computer.

 

I suspect it is a virus that's causing this problem but do not know how I should go abt dealing it.
Would appreciate if someone could help me out on this.
 

Thanks!


Edited by e_smurfs, 17 November 2013 - 03:09 AM.

    Advertisements

Register to Remove


#2 ----------------

----------------

    SuperMember

  • Authentic Member
  • PipPipPipPipPip
  • 1,095 posts

Posted 18 November 2013 - 03:04 AM

Hi there,
my name is Marius and I will assist you with your malware related problems.

Before we move on, please read the following points carefully.

  • First, read my instructions completely. If there is anything that you do not understand kindly ask before proceeding.
  • Perform everything in the correct order. Sometimes one step requires the previous one.
  • If you have any problems while following my instructions, Stop there and tell me the exact nature of your problem.
  • Do not run any other scans without instruction or add/remove software unless I tell you to do so. This would change the output of our tools and could be confusing for me.
  • Post all logfiles as a reply rather than as an attachment unless I specifically ask you. If you can not post all logfiles in one reply, feel free to use more posts.
  • If I don't hear from you within 3 days from this initial or any subsequent post, then this thread will be closed.
  • Stay with me. I will give you some advice about prevention after the cleanup process. Absence of symptoms does not always mean the computer is clean.
  • My first language is not english. So please do not use slang or idioms. It could be hard for me to read. Thanks for your understanding.

 

 

 

Scan with FRST in normal mode

Please download Farbar's Recovery Scan Tool to your desktop: FRST 32bit or FRST 64bit (If not sure: Start --> Computer (right click) --> properties)

  • Run FRST.
  • Don´t change one of the checkboxes and hit Scan.
  • Logfiles are created on your desktop.
  • Poste the FRST.txt and (after the first scan only!) the Addition.txt.

 

 

 

Scan with Gmer rootkit scanner

Please download Gmer from here by clicking on the "Download EXE" Button.

  • Double click on the randomly named GMER.exe. If asked to allow gmer.sys driver to load, please consent.
  • If it gives you a warning about rootkit activity and asks if you want to run scan...click on NO.
  • In the right panel, you will see several boxes that have been checked. Uncheck the following ...
    • Sections
    • IAT/EAT
    • Show All ( should be unchecked by default )
  • Leave everything else as it is.
  • Close all other running programs as well as your Browser.
  • Click the Scan button & wait for it to finish.
  • Once done click on the Save.. button, and in the File name area, type in "ark.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop.
  • Please post the content of the ark.txt here.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<--- ROOKIT" entries


Proud Member of UNITE & TB
 

#3 e_smurfs

e_smurfs

    New Member

  • Authentic Member
  • Pip
  • 13 posts

Posted 18 November 2013 - 10:57 AM

Hi Marius!

First of all, allow me to express my gratitude for helping me out. Your help is deeply appreciated! I'm not really IT savvy hence you probably have to be patient with me if I am not able to follow with you instructions.

 

Here is the FRST.txt:

 

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 17-11-2013 02

Ran by Eileen (administrator) on EILEEN-PC on 18-11-2013 23:08:32
Running from J:\
Microsoft® Windows Vista™ Home Premium  Service Pack 1 (X86) OS Language: English(US)
Internet Explorer Version 8
Boot Mode: Normal
 
==================== Processes (Whitelisted) ===================
 
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(IDT, Inc.) C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_030ac640\STacSV.exe
(Microsoft Corporation) C:\Windows\system32\SLsvc.exe
(Hewlett-Packard Corporation) C:\Windows\system32\Hpservice.exe
(Validity Sensors, Inc.) C:\Windows\system32\vfsFPService.exe
(DigitalPersona, Inc.) C:\Program Files\DigitalPersona\Bin\DpHostW.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(DigitalPersona, Inc.) C:\Program Files\DigitalPersona\Bin\DpAgent.exe
(Andrea Electronics Corporation) C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_030ac640\aestsrv.exe
(Agere Systems) C:\Windows\system32\agrsmsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
() C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
() C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
() C:\Windows\SMINST\BLService.exe
() C:\Program Files\CyberLink\Shared Files\RichVideo.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
( Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
( Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
(Google Inc.) F:\Gmail Notifier\gnotify.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(CyberLink Corp.) C:\Program Files\HP\QuickPlay\QPService.exe
(Hewlett-Packard Co.) F:\HP\HP Software Update\hpwuSchd2.exe
(FS2YOU) C:\Program Files\GridService\peer.exe
(Adobe Systems Inc.) F:\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Apple Inc.) F:\iTunes\iTunesHelper.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Hewlett-Packard Co.) F:\HP\Digital Imaging\bin\hpqtra08.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
(Microsoft Corporation) C:\Windows\system32\wbem\unsecapp.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
() C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
(Hewlett-Packard) c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
(Microsoft Corporation) C:\Windows\system32\wuauclt.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jucheck.exe
(http://www.emule-project.net) C:\Program Files\eMule\emule.exe
(Google Inc.) C:\Users\Eileen\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Eileen\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Eileen\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Eileen\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Eileen\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Eileen\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Eileen\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Eileen\AppData\Local\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\system32\conime.exe
(Google Inc.) C:\Users\Eileen\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Eileen\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Eileen\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Eileen\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Eileen\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Eileen\AppData\Local\Google\Chrome\Application\chrome.exe
 
==================== Registry (Whitelisted) ==================
 
HKLM\...\Run: [NvCplDaemon] - RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray.exe [442433 2008-04-16] (IDT, Inc.)
HKLM\...\Run: [IAAnotif] - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe [178712 2008-04-16] (Intel Corporation)
HKLM\...\Run: [UCam_Menu] - C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe [222504 2007-12-25] (CyberLink Corp.)
HKLM\...\Run: [DpAgent] - C:\Program Files\DigitalPersona\Bin\DpAgent.exe [699456 2008-03-13] (DigitalPersona, Inc.)
HKLM\...\Run: [Windows Defender] - C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation)
HKLM\...\Run: [QlbCtrl.exe] - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe [202032 2008-03-14] ( Hewlett-Packard Development Company, L.P.)
HKLM\...\Run: [OnScreenDisplay] - C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe [554288 2007-11-02] ( Hewlett-Packard Development Company, L.P.)
HKLM\...\Run: [hpWirelessAssistant] - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [488752 2007-11-20] (Hewlett-Packard Development Company, L.P.)
HKLM\...\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] - F:\Gmail Notifier\gnotify.exe [479232 2005-07-16] (Google Inc.)
HKLM\...\Run: [HP Health Check Scheduler] - C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [75008 2008-06-16] (Hewlett-Packard)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1033512 2008-01-18] (Synaptics, Inc.)
HKLM\...\Run: [QPService] - C:\Program Files\HP\QuickPlay\QPService.exe [468264 2008-04-24] (CyberLink Corp.)
HKLM\...\Run: [NvMediaCenter] - RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
HKLM\...\Run: [HP Software Update] - F:\HP\HP Software Update\hpwuSchd2.exe [49152 2006-12-10] (Hewlett-Packard Co.)
HKLM\...\Run: [SymLnch] - "C:\Program Files\Common Files\Symantec Shared\SymSetup\{C1C185CA-C531-49F5-A6FA-B838405A049D}_15_5_0_23\Support\SymLnch\SymLnch.exe" "C:\PROGRA~1\COMMON~1\SYMANT~1\SymSetup\{C1C18~1\Setup.exe" " /X"
HKLM\...\Run: [Grid Service] - C:\Program Files\GridService\peer.exe [4993024 2008-12-31] (FS2YOU)
HKLM\...\Run: [AdobeCS4ServiceManager] - C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe [611712 2008-08-14] (Adobe Systems Incorporated)
HKLM\...\Run: [Adobe Acrobat Speed Launcher] - F:\Adobe\Acrobat 9.0\Acrobat\acrobat_sl.exe [37232 2008-06-12] (Adobe Systems Incorporated)
HKLM\...\Run: [] - [x]
HKLM\...\Run: [Acrobat Assistant 8.0] - F:\Adobe\Acrobat 9.0\Acrobat\acrotray.exe [640376 2008-06-11] (Adobe Systems Inc.)
HKLM\...\Run: [Adobe_ID0ENQBO] - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4Tray.exe [378224 2008-08-15] (Adobe Systems Incorporated)
HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-11-28] (Apple Inc.)
HKLM\...\Run: [QuickTime Task] - F:\QuickTime\QTTask.exe [421888 2012-04-18] (Apple Inc.)
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [347192 2013-08-20] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [iTunesHelper] - F:\iTunes\iTunesHelper.exe [152544 2012-12-12] (Apple Inc.)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated)
HKLM\...\Run: [BrowserPlugInHelper] - C:\Program Files\iSkysoft\iTube Studio\BrowserPlugInHelper.exe
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
HKCU\...\Run: [AdobeBridge] - [x]
HKCU\...\Run: [service control] - C:\Program Files\service control\servicectrl.exe
HKCU\...\Run: [¿ì²¥Ó°ÊÓºÐ] - F:\qvodhd\play.exe /start
HKCU\...\Run: [pinomate] - C:\Users\Eileen\AppData\Local\PeeringPortal\Pino\pinomate.exe
HKCU\...\Run: [Easy-Hide-IP] - F:\Easy-Hide-IP\easy-hide-ip.exe
HKCU\...\Run: [Google Update] - C:\Users\Eileen\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2012-06-17] (Google Inc.)
HKCU\...\Run: [Orbitum] - C:\Users\Eileen\AppData\Local\Orbitum\Application\chrome.exe
HKCU\...\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\wmpnscfg.exe [202240 2008-01-21] (Microsoft Corporation)
HKCU\...\Run: [eMuleAutoStart] - C:\Program Files\eMule\emule.exe [5758976 2010-04-07] (http://www.emule-project.net)
HKCU\...\RunOnce: [FlashPlayerUpdate] - C:\Windows\system32\Macromed\Flash\FlashUtil32_11_9_900_117_Plugin.exe -update plugin [829832 2013-10-10] (Adobe Systems Incorporated)
HKU\Default\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
AppInit_DLLs: browse~1\23796~1.11\{16cdf~1\browse~1.dll  [ ] ()
Lsa: [Notification Packages] scecli DPPWDFLT
Startup: C:\Users\Eileen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
ShortcutTarget: OneNote 2007 Screen Clipper and Launcher.lnk -> G:\Office12\ONENOTEM.EXE (Microsoft Corporation)
 
==================== Internet (Whitelisted) ====================
 
ProxyServer: socks=127.0.0.1:4021;
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com.sg/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.h...avilion&pf=cnnb
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
HKCU\Software\Microsoft\Internet Explorer\Main,bProtector Start Page = http://www.claro-sea...0000016eabd2bce
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.h...avilion&pf=cnnb
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.h...avilion&pf=cnnb
URLSearchHook: HKLM - DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files\DVDVideoSoftTB\tbDVDV.dll (Conduit Ltd.)
URLSearchHook: HKCU - (No Name) - {ba14329e-9550-4989-b3f2-9732e92d17cc} -  No File
URLSearchHook: HKCU - DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files\DVDVideoSoftTB\tbDVDV.dll (Conduit Ltd.)
SearchScopes: HKLM - DefaultScope {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.condui...&ctid=CT2269050
SearchScopes: HKLM - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.condui...&ctid=CT2269050
SearchScopes: HKCU - ${searchCLSID} URL = http://us.yhs.search...p={searchTerms}
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.live.c...q={searchTerms}
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://search.babylo...t=290312_bexdll
SearchScopes: HKCU - {210073B5-670D-4ABE-A7CB-83EDBC77BF35} URL = http://search.orbitd...{inputEncoding}
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={sear
SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.condui...&ctid=CT2269050
SearchScopes: HKCU - {searchCLSID} URL = http://sg.yhs.search...p={searchTerms}
BHO: IE7Pro BHO - {00011268-E188-40DF-A514-835FCD78B1BF} - F:\IEPro\IEPro.dll (IE7Pro.com)
BHO: Octh Class - {000123B4-9B42-4900-B3F7-F4B073EFC214} - F:\Orbitdownloader\orbitcth.dll (Orbitdownloader.com)
BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - F:\Adobe\/Adobe Contribute CS4/contributeieplugin.dll (Adobe Systems Incorporated.)
BHO: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll No File
BHO: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} -  No File
BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll No File
BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files\DVDVideoSoftTB\tbDVDV.dll (Conduit Ltd.)
BHO: No Name - {889D2FEB-5411-4565-8998-1DD2C5261283} -  No File
BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO: SmartSelect Class - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKLM - Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - F:\Orbitdownloader\GrabPro.dll ()
Toolbar: HKLM - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKLM - Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - F:\Adobe\/Adobe Contribute CS4/contributeieplugin.dll (Adobe Systems Incorporated.)
Toolbar: HKLM - No Name - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} -  No File
Toolbar: HKLM - DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files\DVDVideoSoftTB\tbDVDV.dll (Conduit Ltd.)
Toolbar: HKCU - Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - F:\Orbitdownloader\GrabPro.dll ()
Toolbar: HKCU - No Name - {A057A204-BACC-4D26-C39E-35F1D2A32EC8} -  No File
Toolbar: HKCU - No Name - {A057A204-BACC-4D26-9990-79A187E2698E} -  No File
Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} -  No File
Toolbar: HKCU - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKCU - No Name - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} -  No File
Toolbar: HKCU - No Name - {BA14329E-9550-4989-B3F2-9732E92D17CC} -  No File
Toolbar: HKCU - DVDVideoSoftTB Toolbar - {872B5B88-9DB5-4310-BDD0-AC189557E5F5} - C:\Program Files\DVDVideoSoftTB\tbDVDV.dll (Conduit Ltd.)
DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macr...director/sw.cab
DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx...owserPlugin.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab
DPF: {8B9230ED-5766-43C9-855B-E742B0B2E871} http://www.servicema...emanagerdx2.ocx
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab
DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab
Handler: CDS300 - {AD43AA67-6860-4531-AC8A-0E68F9CF023E} - E:\Player\__CDS2.dll No File
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL No File
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL No File
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 202.156.1.16 218.186.2.16 218.186.2.6
 
FireFox:
========
FF ProfilePath: C:\Users\Eileen\AppData\Roaming\Mozilla\Firefox\Profiles\xkfmli2b.default
FF user.js: detected! => C:\Users\Eileen\AppData\Roaming\Mozilla\Firefox\Profiles\xkfmli2b.default\user.js
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.google.com.sg/
FF NetworkProxy: "http", "198.7.242.41"
FF NetworkProxy: "http_port", 3127
FF NetworkProxy: "socks_remote_dns", true
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin: @Apple.com/iTunes,version=1.0 - F:\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.3 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/WLPG,version=14.0.8117.0416 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @real.com/nppl3260;version=6.0.12.450 - F:\Real Alternative\browser\plugins\nppl3260.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprpjplug;version=6.0.12.448 - F:\Real Alternative\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Eileen\AppData\Local\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Eileen\AppData\Local\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF SearchPlugin: C:\Users\Eileen\AppData\Roaming\Mozilla\Firefox\Profiles\xkfmli2b.default\searchplugins\conduit.xml
FF SearchPlugin: C:\Users\Eileen\AppData\Roaming\Mozilla\Firefox\Profiles\xkfmli2b.default\searchplugins\firefox-add-ons.xml
FF SearchPlugin: C:\Users\Eileen\AppData\Roaming\Mozilla\Firefox\Profiles\xkfmli2b.default\searchplugins\live-search.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\answers.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\babylon.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
FF Extension: Xmarks - C:\Users\Eileen\AppData\Roaming\Mozilla\Firefox\Profiles\xkfmli2b.default\Extensions\foxmarks@kei(84).com
FF Extension: FoxyProxy Basic - C:\Users\Eileen\AppData\Roaming\Mozilla\Firefox\Profiles\xkfmli2b.default\Extensions\foxyproxy-basic@eric.h(150).jung
FF Extension: FoxyProxy Basic - C:\Users\Eileen\AppData\Roaming\Mozilla\Firefox\Profiles\xkfmli2b.default\Extensions\foxyproxy@eric.h(85).jung
FF Extension: FlashGot - C:\Users\Eileen\AppData\Roaming\Mozilla\Firefox\Profiles\xkfmli2b.default\Extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}(86)
FF Extension: DownloadHelper - C:\Users\Eileen\AppData\Roaming\Mozilla\Firefox\Profiles\xkfmli2b.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
FF Extension: flashgot - C:\Users\Eileen\AppData\Roaming\Mozilla\Firefox\Profiles\xkfmli2b.default\Extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}.xpi
FF Extension: No Name - C:\Users\Eileen\AppData\Roaming\Mozilla\Firefox\Profiles\xkfmli2b.default\Extensions\{35379F86-8CCB-4724-AE33-4278DE266C70}
FF Extension: DVDVideoSoft Menu - C:\Users\Eileen\AppData\Roaming\Mozilla\Firefox\Profiles\xkfmli2b.default\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi
FF Extension: No Name - C:\Users\Eileen\AppData\Roaming\Mozilla\Firefox\Profiles\xkfmli2b.default\Extensions\{DB9127A2-3381-41ec-82B3-1B6ED4C6F29A}.xpi
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF HKCU\...\Firefox\Extensions: [support@easy-hide-ip.com] - F:\Easy-Hide-IP\ff-extension
FF HKCU\...\Firefox\Extensions: [{b64982b1-d112-42b5-b1e4-d3867c4533f8}] - Browser Manager\2.3.796.11\{16cdff19-861d-48e3-a751-d99a27784753}\FirefoxExtension
 
Chrome: 
=======
CHR HomePage: hxxp://sg.yahoo.com/
CHR RestoreOnStartup: "hxxp://www.yahoo.com.sg/"
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Users\Eileen\AppData\Local\Google\Chrome\Application\31.0.1650.57\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Users\Eileen\AppData\Local\Google\Chrome\Application\31.0.1650.57\pdf.dll ()
CHR Plugin: (Shockwave Flash) - C:\Users\Eileen\AppData\Local\Google\Chrome\Application\31.0.1650.57\gcswf32.dll No File
CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32_11_3_300_257.dll No File
CHR Plugin: (         "name": "",) - C:\Users\Eileen\AppData\Local\Google\Chrome\User Data\Default\Extensions\bodddioamolcibagionmmobehnbhiakf\1.0.5_0\chromeNPAPI.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Mozilla Firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Microsoft\u00AE Windows Media Player Firefox Plugin) - C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll (Microsoft Corporation)
CHR Plugin: (Cyworld Music Player List Control) - C:\Program Files\Mozilla Firefox\plugins\npCMListControl.dll (SK Communications Inc.)
CHR Plugin: (Java Deployment Toolkit 6.0.310.5) - C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll No File
CHR Plugin: (Java™ Platform SE 6 U31) - C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
CHR Plugin: (2007 Microsoft Office system) - C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL (Microsoft Corporation)
CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
CHR Plugin: (Office Genuine Advantage) - C:\Program Files\Mozilla Firefox\plugins\npOGAPlugin.dll (Microsoft Corporation)
CHR Plugin: (RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) ) - C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll (RealNetworks, Inc.)
CHR Plugin: (RealPlayer Version Plugin) - C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll (RealNetworks, Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll (Apple Inc.)
CHR Plugin: (Windows Live\u00AE Photo Gallery) - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Google Update) - C:\Users\Eileen\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File
CHR Plugin: (iTunes Application Detector) - F:\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File
CHR Plugin: (Windows Presentation Foundation) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Extension: (YouTube) - C:\Users\Eileen\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Video Downloader professional) - C:\Users\Eileen\AppData\Local\Google\Chrome\User Data\Default\Extensions\elicpjhcidhpjomhibiffojpinpmmpil\1.97.37_0
CHR Extension: (Flash Video Downloader) - C:\Users\Eileen\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpokmaicekdgkapighofggglfcilkefn\2.0.5_0
CHR Extension: (Chrome to Mobile) - C:\Users\Eileen\AppData\Local\Google\Chrome\User Data\Default\Extensions\idknbmbdnapjicclomlijcgfpikmndhd\2_0
CHR Extension: (Speed Dial 2) - C:\Users\Eileen\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpfpebmajhhopeonhlcgidhclcccjcik\1.7.0_0
CHR Extension: (TouristEye Planner) - C:\Users\Eileen\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpjpejalhlnocbhggpnokneghfenoneg\9_0
CHR Extension: (Evernote Web) - C:\Users\Eileen\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbfehkoinhhcknnbdgnnmjhiladcgbol\1.0.7_0
CHR Extension: (Enter the name) - C:\Users\Eileen\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfjkgbjaikamkkojmakjclmkianficch\5.0.2_0
CHR Extension: (Quick Note) - C:\Users\Eileen\AppData\Local\Google\Chrome\User Data\Default\Extensions\mijlebbfndhelmdpmllgcfadlkankhok\1.6.0_0
CHR Extension: (Google Wallet) - C:\Users\Eileen\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0
CHR HKLM\...\Chrome\Extension: [pgafcinpmmpklohkojmllohdhomoefph] - Browser Manager\2.3.796.11\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.crx
CHR StartMenuInternet: Google Chrome - C:\Users\Eileen\AppData\Local\Google\Chrome\Application\chrome.exe
 
========================== Services (Whitelisted) =================
 
S3 Adobe Version Cue CS4; C:\Program Files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [284016 2008-08-15] (Adobe Systems Incorporated)
R2 AESTFilters; C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_030ac640\aestsrv.exe [73728 2008-02-13] (Andrea Electronics Corporation)
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-08-20] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-08-20] (Avira Operations GmbH & Co. KG)
R2 HP Health Check Service; c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [94208 2008-06-16] (Hewlett-Packard)
R3 hpqcxs08; F:\HP\Digital Imaging\bin\hpqcxs08.dll [225280 2007-03-26] (Hewlett-Packard Co.)
R2 hpqddsvc; F:\HP\Digital Imaging\bin\hpqddsvc.dll [131072 2007-03-26] (Hewlett-Packard Co.)
R2 HPSLPSVC; F:\HP\Digital Imaging\bin\HPSLPSVC32.DLL [585728 2006-12-10] (Hewlett-Packard Co.)
R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 QPCapSvc; C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe [292232 2008-04-24] ()
R2 QPSched; C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe [112008 2008-04-24] ()
R2 Recovery Service for Windows; C:\Windows\SMINST\BLService.exe [341328 2008-03-27] ()
R2 RichVideo; C:\Program Files\CyberLink\Shared Files\RichVideo.exe [272024 2007-01-09] ()
R2 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_030ac640\STacSV.exe [221239 2008-04-16] (IDT, Inc.)
S2 Browser Manager; Browser Manager\2.3.796.11\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe [x]
 
==================== Drivers (Whitelisted) ====================
 
R3 AVerBDA6x; C:\Windows\System32\DRIVERS\AVerBDA716x.sys [934912 2008-04-22] (AVerMedia TECHNOLOGIES, Inc.)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [88840 2013-09-03] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136672 2013-08-20] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-04-05] (Avira Operations GmbH & Co. KG)
S3 HpqRemHid; C:\Windows\System32\DRIVERS\HpqRemHid.sys [7168 2007-07-12] (Hewlett-Packard Development Company, L.P.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2012-08-27] (Avira GmbH)
U1 eabfiltr; 
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
S3 NOWMEMDF; \??\C:\Windows\system32\NOWMEMDF.sys [x]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]
S3 tcphoc; \??\C:\Program Files\Thunder Network\Thunder\XLDoctor\7.2.10.3694_1\Program\tcphoc.sys [x]
S3 UIUSys; system32\DRIVERS\UIUSYS.SYS [x]
U5 UnlockerDriver5; F:\Unlocker\UnlockerDriver5.sys [4096 2010-03-09] ()
 
==================== NetSvcs (Whitelisted) ===================
 
 
==================== One Month Created Files and Folders ========
 
2013-11-18 23:07 - 2013-11-18 23:07 - 00000000 ____D C:\FRST
2013-11-18 09:21 - 2013-11-18 21:21 - 104931504 _____ C:\Windows\system32\먺☟ᰴ
2013-11-17 09:57 - 2013-11-17 09:57 - 104637397 _____ C:\Windows\system32\▤ᰴ
2013-11-15 09:55 - 2013-11-15 09:55 - 00000000 ____D C:\Users\Eileen\AppData\Roaming\Malwarebytes
2013-11-15 09:55 - 2013-11-15 09:55 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-11-15 09:55 - 2013-11-15 09:55 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-11-15 09:55 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-11-15 08:59 - 2013-11-15 08:59 - 104278918 _____ C:\Windows\system32\ꃳ寔ᰴ£
2013-11-13 15:57 - 2013-11-13 15:57 - 104004073 _____ C:\Windows\system32\셄㵝ᰴ¦
2013-11-11 21:15 - 2013-11-11 21:15 - 103716811 _____ C:\Windows\system32\黁✛ᰴ¸
2013-11-11 13:33 - 2013-11-11 13:34 - 00000000 ____D C:\Users\Eileen\[00000001]
2013-11-10 21:21 - 2013-11-10 21:21 - 103467942 _____ C:\Windows\system32\ᩳ犻ᰴ
2013-11-10 18:18 - 2013-11-18 20:03 - 00012286 _____ C:\Users\Eileen\Desktop\MY_AUDIO_101113_1.p2g
2013-11-10 16:53 - 2013-11-10 16:53 - 00117552 _____ (VMware, Inc.) C:\Windows\system32\Drivers\vmhgfs.sys
2013-11-10 16:53 - 2013-11-10 16:53 - 00063920 _____ (VMware, Inc.) C:\Windows\system32\Drivers\vmx_svga.sys
2013-11-10 16:53 - 2013-11-10 16:53 - 00054960 _____ (VMware, Inc.) C:\Windows\system32\Drivers\vmci.sys
2013-11-10 16:53 - 2013-11-10 16:53 - 00019504 _____ (VMware, Inc.) C:\Windows\system32\Drivers\vmdebug.sys
2013-11-10 16:53 - 2013-11-10 16:53 - 00011696 _____ (VMware, Inc.) C:\Windows\system32\Drivers\vmmouse.sys
2013-11-10 16:52 - 2013-11-10 16:53 - 00025008 _____ (VMware, Inc.) C:\Windows\system32\Drivers\vmaudio.sys
2013-11-10 16:51 - 2013-11-10 16:51 - 00173232 _____ (VMware, Inc.) C:\Windows\system32\vmx_fb.dll
2013-11-10 16:51 - 2013-11-10 16:51 - 00111856 _____ (ThinPrint GmbH) C:\Windows\system32\TPVMW32.dll
2013-11-10 16:51 - 2013-11-10 16:51 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\WsmProv.dll
2013-11-10 16:51 - 2013-11-10 16:51 - 00035888 _____ (VMware, Inc.) C:\Windows\system32\vmhgfs.dll
2013-11-10 16:51 - 2013-11-10 16:51 - 00016432 _____ (VMware, Inc.) C:\Windows\system32\vmx_mode.dll
2013-11-10 16:51 - 2013-11-10 16:51 - 00009104 _____ (ThinPrint GmbH) C:\Windows\system32\TPVMMonUIjpn.dll
2013-11-10 16:51 - 2013-11-10 16:51 - 00001536 _____ (Microsoft Corporation) C:\Windows\system32\WsmCl.dll
2013-11-10 16:50 - 2013-11-10 16:51 - 00009104 _____ (ThinPrint GmbH) C:\Windows\system32\TPVMMonUIdeu.dll
2013-11-10 16:50 - 2013-11-10 16:50 - 00423208 _____ (ThinPrint GmbH) C:\Windows\system32\TPSvc.dll
2013-11-10 16:50 - 2013-11-10 16:50 - 00284016 _____ (ThinPrint GmbH) C:\Windows\system32\TPVMMon.dll
2013-11-10 16:50 - 2013-11-10 16:50 - 00133120 _____ (Microsoft Corporation) C:\Windows\system32\extmgr.dll
2013-11-10 16:50 - 2013-11-10 16:50 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\LANGWRBK.DLL
2013-11-10 16:50 - 2013-11-10 16:50 - 00079208 _____ (ThinPrint GmbH) C:\Windows\system32\TPVMMonUI.dll
2013-11-10 16:50 - 2013-11-10 16:50 - 00078336 _____ (Microsoft Corporation) C:\Windows\system32\ieencode.dll
2013-11-10 16:50 - 2013-11-10 16:50 - 00023960 _____ (ThinPrint GmbH) C:\Windows\system32\TPVMMondeu.dll
2013-11-10 16:50 - 2013-11-10 16:50 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\jnwmon.dll
2013-11-10 16:50 - 2013-11-10 16:50 - 00009632 _____ (ThinPrint GmbH) C:\Windows\system32\TPVMMonjpn.dll
2013-11-10 14:26 - 2013-11-10 14:27 - 00289280 _____ (Microsoft Corporation) C:\Windows\system32\StikyNot.exe
2013-11-10 14:26 - 2013-11-10 14:26 - 00275968 _____ (Microsoft Corporation) C:\Windows\system32\SnippingTool.exe
2013-11-10 14:19 - 2013-11-10 14:19 - 00000000 ____D C:\ProgramData\Weskysoft
2013-11-10 14:18 - 2013-11-10 14:18 - 00000000 ____D C:\Users\Eileen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dll Suite 2013
2013-11-10 10:34 - 2013-11-10 10:34 - 00000000 ____D C:\Program Files\DLLSuite
2013-11-10 09:19 - 2013-11-10 09:19 - 103387443 _____ C:\Windows\system32\쨂䓅ᰴ³
2013-11-09 21:53 - 2013-11-09 21:53 - 103378319 _____ C:\Windows\system32\꽷캇ᰴ
2013-11-09 02:53 - 2013-11-09 03:01 - 00000000 ____D C:\Program Files\DVDVideoSoft
2013-11-08 16:43 - 2013-11-09 03:01 - 00000000 ____D C:\Program Files\Common Files\DVDVideoSoft
2013-11-08 09:05 - 2013-11-08 09:05 - 103066299 _____ C:\Windows\system32\숬⌒ᰴ
2013-11-07 21:20 - 2013-11-07 21:20 - 102946670 _____ C:\Windows\system32\傁␸ᰴ
2013-11-02 09:33 - 2013-11-02 09:33 - 00000000 ____D C:\ProgramData\Oracle
2013-11-02 09:32 - 2013-11-02 09:33 - 00004734 _____ C:\Windows\system32\jupdate-1.7.0_45-b18.log
2013-11-02 09:24 - 2013-11-02 09:24 - 104569497 _____ C:\Windows\system32\馱ᰴ
2013-10-29 09:29 - 2013-10-29 09:29 - 103871884 _____ C:\Windows\system32\僋쫞ᰴ
2013-10-28 21:21 - 2013-10-28 21:21 - 103734365 _____ C:\Windows\system32\⍿歓ᰴ«
2013-10-23 15:17 - 2013-10-23 15:17 - 00000000 ____D C:\Program Files\K-Lite Codec Pack
2013-10-23 15:17 - 2013-09-13 02:00 - 00112640 _____ C:\Windows\system32\ff_vfw.dll
2013-10-23 15:17 - 2013-03-18 00:21 - 03649536 _____ (x264vfw project) C:\Windows\system32\x264vfw.dll
2013-10-23 15:17 - 2012-07-21 18:54 - 00122880 _____ (fccHandler) C:\Windows\system32\ac3acm.acm
2013-10-23 15:17 - 2011-12-08 01:32 - 00216064 _____ ( ) C:\Windows\system32\lagarith.dll
2013-10-23 15:17 - 2011-06-24 22:44 - 00243200 _____ C:\Windows\system32\xvidvfw.dll
2013-10-23 15:17 - 2011-06-24 22:28 - 00650752 _____ C:\Windows\system32\xvidcore.dll
 
==================== One Month Modified Files and Folders =======
 
2013-11-18 23:09 - 2012-07-30 00:56 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-11-18 23:07 - 2013-11-18 23:07 - 00000000 ____D C:\FRST
2013-11-18 23:07 - 2009-09-11 17:06 - 00000424 ____H C:\Windows\Tasks\User_Feed_Synchronization-{66A95A41-F5D3-46ED-876C-E78DF0ECA6FD}.job
2013-11-18 22:54 - 2010-08-16 19:55 - 00000248 ____H C:\Windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
2013-11-18 22:39 - 2010-08-16 19:55 - 00000290 ____H C:\Windows\Tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
2013-11-18 22:14 - 2012-06-17 15:19 - 00000912 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1630263006-122845437-3975794864-1003UA.job
2013-11-18 21:21 - 2013-11-18 09:21 - 104931504 _____ C:\Windows\system32\먺☟ᰴ
2013-11-18 21:19 - 2008-08-15 20:55 - 01167995 _____ C:\Windows\WindowsUpdate.log
2013-11-18 21:17 - 2006-11-02 20:47 - 00003216 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-11-18 21:17 - 2006-11-02 20:47 - 00003216 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-11-18 20:14 - 2012-06-17 15:19 - 00000860 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1630263006-122845437-3975794864-1003Core.job
2013-11-18 20:03 - 2013-11-10 18:18 - 00012286 _____ C:\Users\Eileen\Desktop\MY_AUDIO_101113_1.p2g
2013-11-18 20:03 - 2010-03-25 18:06 - 00000000 ____D C:\Users\Eileen\Desktop\New Folder (2)
2013-11-18 19:44 - 2010-12-24 15:52 - 00000000 ____D C:\Users\Eileen\AppData\Roaming\uTorrent
2013-11-18 19:18 - 2008-11-10 03:45 - 00000000 ____D C:\Users\Eileen\AppData\Roaming\Orbit
2013-11-18 19:16 - 2008-08-15 21:31 - 00174022 _____ C:\ProgramData\nvModes.001
2013-11-18 13:39 - 2013-10-02 16:29 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-11-18 09:18 - 2008-08-15 21:37 - 00003437 _____ C:\Users\Public\Documents\hpqp.ini
2013-11-18 09:18 - 2008-08-15 21:31 - 00174022 _____ C:\ProgramData\nvModes.dat
2013-11-18 09:17 - 2006-11-02 21:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-11-18 02:20 - 2008-08-15 20:56 - 00001660 _____ C:\Windows\bthservsdp.dat
2013-11-18 02:20 - 2006-11-02 21:01 - 00032606 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-11-17 20:53 - 2006-11-02 18:33 - 00703388 _____ C:\Windows\system32\PerfStringBackup.INI
2013-11-17 10:00 - 2008-07-01 15:41 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-11-17 09:57 - 2013-11-17 09:57 - 104637397 _____ C:\Windows\system32\▤ᰴ
2013-11-15 19:15 - 2012-06-17 15:20 - 00002047 _____ C:\Users\Eileen\Desktop\Google Chrome.lnk
2013-11-15 09:55 - 2013-11-15 09:55 - 00000000 ____D C:\Users\Eileen\AppData\Roaming\Malwarebytes
2013-11-15 09:55 - 2013-11-15 09:55 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-11-15 09:55 - 2013-11-15 09:55 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-11-15 08:59 - 2013-11-15 08:59 - 104278918 _____ C:\Windows\system32\ꃳ寔ᰴ£
2013-11-13 15:57 - 2013-11-13 15:57 - 104004073 _____ C:\Windows\system32\셄㵝ᰴ¦
2013-11-12 09:08 - 2009-05-26 09:29 - 00000052 _____ C:\Windows\system32\DOErrors.log
2013-11-11 21:15 - 2013-11-11 21:15 - 103716811 _____ C:\Windows\system32\黁✛ᰴ¸
2013-11-11 13:34 - 2013-11-11 13:33 - 00000000 ____D C:\Users\Eileen\[00000001]
2013-11-11 13:22 - 2008-04-10 18:26 - 00000000 ____D C:\Windows\SMINST
2013-11-10 21:21 - 2013-11-10 21:21 - 103467942 _____ C:\Windows\system32\ᩳ犻ᰴ
2013-11-10 16:53 - 2013-11-10 16:53 - 00117552 _____ (VMware, Inc.) C:\Windows\system32\Drivers\vmhgfs.sys
2013-11-10 16:53 - 2013-11-10 16:53 - 00063920 _____ (VMware, Inc.) C:\Windows\system32\Drivers\vmx_svga.sys
2013-11-10 16:53 - 2013-11-10 16:53 - 00054960 _____ (VMware, Inc.) C:\Windows\system32\Drivers\vmci.sys
2013-11-10 16:53 - 2013-11-10 16:53 - 00019504 _____ (VMware, Inc.) C:\Windows\system32\Drivers\vmdebug.sys
2013-11-10 16:53 - 2013-11-10 16:53 - 00011696 _____ (VMware, Inc.) C:\Windows\system32\Drivers\vmmouse.sys
2013-11-10 16:53 - 2013-11-10 16:52 - 00025008 _____ (VMware, Inc.) C:\Windows\system32\Drivers\vmaudio.sys
2013-11-10 16:51 - 2013-11-10 16:51 - 00173232 _____ (VMware, Inc.) C:\Windows\system32\vmx_fb.dll
2013-11-10 16:51 - 2013-11-10 16:51 - 00111856 _____ (ThinPrint GmbH) C:\Windows\system32\TPVMW32.dll
2013-11-10 16:51 - 2013-11-10 16:51 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\WsmProv.dll
2013-11-10 16:51 - 2013-11-10 16:51 - 00035888 _____ (VMware, Inc.) C:\Windows\system32\vmhgfs.dll
2013-11-10 16:51 - 2013-11-10 16:51 - 00016432 _____ (VMware, Inc.) C:\Windows\system32\vmx_mode.dll
2013-11-10 16:51 - 2013-11-10 16:51 - 00009104 _____ (ThinPrint GmbH) C:\Windows\system32\TPVMMonUIjpn.dll
2013-11-10 16:51 - 2013-11-10 16:51 - 00001536 _____ (Microsoft Corporation) C:\Windows\system32\WsmCl.dll
2013-11-10 16:51 - 2013-11-10 16:50 - 00009104 _____ (ThinPrint GmbH) C:\Windows\system32\TPVMMonUIdeu.dll
2013-11-10 16:50 - 2013-11-10 16:50 - 00423208 _____ (ThinPrint GmbH) C:\Windows\system32\TPSvc.dll
2013-11-10 16:50 - 2013-11-10 16:50 - 00284016 _____ (ThinPrint GmbH) C:\Windows\system32\TPVMMon.dll
2013-11-10 16:50 - 2013-11-10 16:50 - 00133120 _____ (Microsoft Corporation) C:\Windows\system32\extmgr.dll
2013-11-10 16:50 - 2013-11-10 16:50 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\LANGWRBK.DLL
2013-11-10 16:50 - 2013-11-10 16:50 - 00079208 _____ (ThinPrint GmbH) C:\Windows\system32\TPVMMonUI.dll
2013-11-10 16:50 - 2013-11-10 16:50 - 00078336 _____ (Microsoft Corporation) C:\Windows\system32\ieencode.dll
2013-11-10 16:50 - 2013-11-10 16:50 - 00023960 _____ (ThinPrint GmbH) C:\Windows\system32\TPVMMondeu.dll
2013-11-10 16:50 - 2013-11-10 16:50 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\jnwmon.dll
2013-11-10 16:50 - 2013-11-10 16:50 - 00009632 _____ (ThinPrint GmbH) C:\Windows\system32\TPVMMonjpn.dll
2013-11-10 14:27 - 2013-11-10 14:26 - 00289280 _____ (Microsoft Corporation) C:\Windows\system32\StikyNot.exe
2013-11-10 14:26 - 2013-11-10 14:26 - 00275968 _____ (Microsoft Corporation) C:\Windows\system32\SnippingTool.exe
2013-11-10 14:25 - 2006-11-02 19:18 - 00000000 ____D C:\Windows\Help
2013-11-10 14:19 - 2013-11-10 14:19 - 00000000 ____D C:\ProgramData\Weskysoft
2013-11-10 14:18 - 2013-11-10 14:18 - 00000000 ____D C:\Users\Eileen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dll Suite 2013
2013-11-10 10:34 - 2013-11-10 10:34 - 00000000 ____D C:\Program Files\DLLSuite
2013-11-10 09:19 - 2013-11-10 09:19 - 103387443 _____ C:\Windows\system32\쨂䓅ᰴ³
2013-11-09 21:53 - 2013-11-09 21:53 - 103378319 _____ C:\Windows\system32\꽷캇ᰴ
2013-11-09 09:49 - 2008-01-21 10:47 - 00361248 _____ C:\Windows\PFRO.log
2013-11-09 03:01 - 2013-11-09 02:53 - 00000000 ____D C:\Program Files\DVDVideoSoft
2013-11-09 03:01 - 2013-11-08 16:43 - 00000000 ____D C:\Program Files\Common Files\DVDVideoSoft
2013-11-09 03:00 - 2010-10-21 18:02 - 00000000 ____D C:\Users\Eileen\AppData\Roaming\DVDVideoSoft
2013-11-09 01:52 - 2013-05-04 06:56 - 00000000 ____D C:\Users\Eileen\AppData\Roaming\Skype
2013-11-08 16:45 - 2013-05-04 06:55 - 00000000 ___RD C:\Program Files\Skype
2013-11-08 16:45 - 2013-05-04 06:55 - 00000000 ____D C:\ProgramData\Skype
2013-11-08 09:05 - 2013-11-08 09:05 - 103066299 _____ C:\Windows\system32\숬⌒ᰴ
2013-11-07 21:20 - 2013-11-07 21:20 - 102946670 _____ C:\Windows\system32\傁␸ᰴ
2013-11-07 01:06 - 2006-11-02 19:18 - 00000000 ____D C:\Windows\system32\Msdtc
2013-11-07 01:06 - 2006-11-02 18:22 - 56360960 _____ C:\Windows\system32\config\software_previous
2013-11-07 01:06 - 2006-11-02 18:22 - 36700160 _____ C:\Windows\system32\config\components_previous
2013-11-07 01:06 - 2006-11-02 18:22 - 25165824 _____ C:\Windows\system32\config\system_previous
2013-11-07 01:06 - 2006-11-02 18:22 - 00524288 _____ C:\Windows\system32\config\default_previous
2013-11-07 01:06 - 2006-11-02 18:22 - 00262144 _____ C:\Windows\system32\config\security_previous
2013-11-07 01:06 - 2006-11-02 18:22 - 00262144 _____ C:\Windows\system32\config\sam_previous
2013-11-07 01:02 - 2012-06-25 19:54 - 00000000 ____D C:\Users\Eileen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite
2013-11-07 01:02 - 2009-03-31 17:10 - 00000000 ____D C:\ProgramData\FLEXnet
2013-11-07 01:02 - 2008-11-08 14:56 - 00000000 ____D C:\Users\Eileen\AppData\Local\QuickPlay
2013-11-07 01:02 - 2008-07-01 16:49 - 00000000 ____D C:\Program Files\Common Files\Java
2013-11-07 01:02 - 2006-11-02 19:18 - 00000000 ____D C:\Windows\system32\spool
2013-11-07 01:02 - 2006-11-02 19:18 - 00000000 ____D C:\Windows\registration
2013-11-02 19:15 - 2013-01-10 00:19 - 00000000 ____D C:\Windows\Minidump
2013-11-02 09:33 - 2013-11-02 09:33 - 00000000 ____D C:\ProgramData\Oracle
2013-11-02 09:33 - 2013-11-02 09:32 - 00004734 _____ C:\Windows\system32\jupdate-1.7.0_45-b18.log
2013-11-02 09:33 - 2008-07-01 16:49 - 00000000 ____D C:\Program Files\Java
2013-11-02 09:24 - 2013-11-02 09:24 - 104569497 _____ C:\Windows\system32\馱ᰴ
2013-10-29 09:29 - 2013-10-29 09:29 - 103871884 _____ C:\Windows\system32\僋쫞ᰴ
2013-10-28 21:21 - 2013-10-28 21:21 - 103734365 _____ C:\Windows\system32\⍿歓ᰴ«
2013-10-23 15:17 - 2013-10-23 15:17 - 00000000 ____D C:\Program Files\K-Lite Codec Pack
2013-10-19 16:47 - 2008-11-10 02:30 - 00036864 _____ C:\Users\Eileen\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
 
Files to move or delete:
====================
C:\Windows\Tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
C:\Windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
 
 
Some content of TEMP:
====================
C:\Users\Eileen\AppData\Local\Temp\appshat-distribution.exe
C:\Users\Eileen\AppData\Local\Temp\BI_RunOnce.exe
C:\Users\Eileen\AppData\Local\Temp\DiVapton_sm.exe
C:\Users\Eileen\AppData\Local\Temp\fmp-2.0.7-win32.exe
C:\Users\Eileen\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe
C:\Users\Eileen\AppData\Local\Temp\MoviesToolbarSetup_Somoto_9_10_2013.exe
C:\Users\Eileen\AppData\Local\Temp\ose00000.exe
C:\Users\Eileen\AppData\Local\Temp\ose00001.exe
C:\Users\Eileen\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Eileen\AppData\Local\Temp\temp~.DLL
C:\Users\Eileen\AppData\Local\Temp\temp~.EXE
C:\Users\Eileen\AppData\Local\Temp\UpdateCheckerSetup.exe
 
 
==================== Bamital & volsnap Check =================
 
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
 
 
LastRegBack: 2013-11-18 21:28
 
==================== End Of Log ============================
 
 
Here is the Addition.txt :
 
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 17-11-2013 02
Ran by Eileen at 2013-11-18 23:12:09
Running from J:\
Boot Mode: Normal
==========================================================
 
 
==================== Security Center ========================
 
AV: Avira Desktop (Disabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AS: Avira Desktop (Disabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
 Update for Microsoft Office 2007 (KB2508958)
µTorrent (Version: 3.1.2)
115ä¯ÀÀÆ÷ 1.2 (Version: 1.2)
32 Bit HP CIO Components Installer (Version: 1.0.0)
8700 (Version: 82.0.252.000)
8700_Help (Version: 82.0.252.000)
Acrobat.com (Version: 0.0.0)
Acrobat.com (Version: 1.2.443)
Activation Assistant for the 2007 Microsoft Office suites
Activation Assistant for the 2007 Microsoft Office suites (Version: 1.0)
Adobe Acrobat 9 Pro - English, Français, Deutsch (Version: 9.0.0)
Adobe AIR (Version: 3.8.0.1430)
Adobe Anchor Service CS4 (Version: 2.0)
Adobe Asset Services CS4 (Version: 4)
Adobe Bridge CS4 (Version: 3)
Adobe CMaps CS4 (Version: 2.0)
Adobe Color - Photoshop Specific CS4 (Version: 2.0)
Adobe Color EU Recommended Settings CS4 (Version: 2.0)
Adobe Color JA Extra Settings CS4 (Version: 2.0)
Adobe Color NA Extra Settings CS4 (Version: 2.0)
Adobe Color Video Profiles CS CS4 (Version: 2.0)
Adobe Contribute CS4 (Version: 5.0)
Adobe Creative Suite 4 Web Premium (Version: 4.0)
Adobe CS4 American English Speech Analysis Models (Version: 1)
Adobe CS4 French Speech Analysis Models (Version: 1)
Adobe CS4 German Speech Analysis Models (Version: 1)
Adobe CS4 International English Speech Analysis Models (Version: 1)
Adobe CS4 Italian Speech Analysis Models (Version: 1)
Adobe CS4 Japanese Speech Analysis Models (Version: 1)
Adobe CS4 Korean Speech Analysis Models (Version: 1)
Adobe CS4 Spanish Speech Analysis Models (Version: 1)
Adobe CSI CS4 (Version: 1)
Adobe Default Language CS4 (Version: 2.0)
Adobe Device Central CS4 (Version: 2)
Adobe Dreamweaver CS4 (Version: 10.0)
Adobe Drive CS4 (Version: 1)
Adobe Dynamiclink Support (Version: 1)
Adobe ExtendScript Toolkit CS4 (Version: 3.0.0)
Adobe Extension Manager CS4 (Version: 2.0)
Adobe Fireworks CS4 (Version: 10.0)
Adobe Flash CS4 (Version: 10.0)
Adobe Flash CS4 Extension - Flash Lite STI en (Version: 3.0)
Adobe Flash CS4 STI-en (Version: 10.0)
Adobe Flash Player 11 ActiveX (Version: 11.9.900.117)
Adobe Flash Player 11 Plugin (Version: 11.9.900.117)
Adobe Fonts All (Version: 2.0)
Adobe Illustrator CS4 (Version: 14.0)
Adobe Linguistics CS4 (Version: 4.0.0)
Adobe Media Encoder CS4 (Version: 1.0)
Adobe Media Encoder CS4 Importer (Version: 1.0)
Adobe Output Module (Version: 2.0)
Adobe PDF Library Files CS4 (Version: 9.0)
Adobe Photoshop CS4 (Version: 11.0)
Adobe Photoshop CS4 Support (Version: 11.0)
Adobe Photoshop Elements 2.0 (Version: 2.0)
Adobe Reader XI (11.0.03) (Version: 11.0.03)
Adobe Search for Help (Version: 1.0)
Adobe Service Manager Extension (Version: 1.0)
Adobe Setup (Version: 2.0)
Adobe Shockwave Player (Version: 10.2.0.023)
Adobe Soundbooth CS4 (Version: 2)
Adobe Soundbooth CS4 Codecs (Version: 2)
Adobe Type Support CS4 (Version: 9.0)
Adobe Update Manager CS4 (Version: 6.0.0)
Adobe Version Cue CS4 Server (Version: 4.0)
Adobe WinSoft Linguistics Plugin (Version: 1.1)
Adobe XMP Panels CS4 (Version: 2.0)
AdobeColorCommonSetCMYK (Version: 2.0)
AdobeColorCommonSetRGB (Version: 2.0)
Aegisub 2.1.7 (Version: 2.1.7)
Agere Systems HDA Modem
Apple Application Support (Version: 2.3.2)
Apple Mobile Device Support (Version: 6.0.1.3)
Apple Software Update (Version: 2.1.3.127)
AVerMedia MCE Encoder x86 3.2.1.84 (Version: 3.2.1.84)
Avira Free Antivirus (Version: 13.0.0.4052)
Bonjour (Version: 3.0.0.10)
Browser Manager
BSIZE_CDB_ProductContext (Version: 82.0.252.000)
BSIZE_CDB_Software (Version: 82.0.252.000)
BufferChm (Version: 82.0.173.000)
Canon DIGITAL CAMERA Solution Disk Software Guide (Version: 1.3.0.1)
Canon MOV Decoder (Version: 1.7.0.6)
Canon MOV Encoder (Version: 1.5.0.3)
Canon MovieEdit Task for ZoomBrowser EX (Version: 3.6.0.5)
Canon PowerShot S95 Camera User Guide (Version: 1.0.0.1)
Canon Utilities CameraWindow DC 8 (Version: 8.3.0.6)
Canon Utilities CameraWindow Launcher (Version: 7.5.0.2)
Canon Utilities Digital Photo Professional 3.9 (Version: 3.9.0.3)
Canon Utilities Movie Uploader for YouTube (Version: 1.1.0.4)
Canon Utilities MyCamera (Version: 7.4.0.2)
Canon Utilities PhotoStitch (Version: 3.1.22.46)
Canon Utilities ZoomBrowser EX (Version: 6.6.0.23)
Canon ZoomBrowser EX Memory Card Utility (Version: 1.4.0.4)
CCleaner (Version: 4.05)
Connect (Version: 1.0.0.1)
ConvertHelper 2.2
CustomerResearchQFolder (Version: 1.00.0000)
CyberLink DVD Suite (Version: 5.5.1519)
CyberLink YouCam (Version: 2.0.1616)
Destinations (Version: 82.0.173.000)
DeviceManagementQFolder (Version: 1.00.0000)
DigitalPersona Personal 3.0.1 (Version: 3.0.1)
DLL Suite 2013
DVDVideoSoftTB Toolbar (Version: )
eMule
eMule VeryCD 
eMule VeryCD°æ
eSupportQFolder (Version: 1.00.0000)
Evernote v. 4.5.7 (Version: 4.5.7.7146)
Foxreal YouTube FLV Downloader version: 1.0.1.1
Free FLV Converter V 6.93.0 (Version: 6.93.0.0)
Free Sound Recorder 2010 v9.2.1
Free Studio version 2013 (Version: 6.2.0.1029)
GOGOBOX (Version: 2.0.5.84)
Google Chrome (HKCU Version: 31.0.1650.57)
Google Gmail Notifier
Hewlett-Packard Active Check for Health Check (Version: 1.1.15.2)
Hewlett-Packard Asset Agent for Health Check (Version: 2.0.64.0)
HP Active Support Library (Version: 3.1.6.1)
HP Customer Experience Enhancements (Version: 5.7.0.2630)
HP Customer Participation Program 8.0 (Version: 8.0)
HP Doc Viewer (Version: 1.03.0001)
HP Easy Setup - Frontend (Version: 5.7.0.2630)
HP Help and Support (Version: 2.0.10.0)
HP Imaging Device Functions 8.0 (Version: 8.0)
HP Integrated Module with Bluetooth wireless technology 6.0.1.6200 (Version: 6.0.1.6200)
HP MiniCard Hybrid TV 1.3.0.48 (Version: 1.3.0.48)
HP MULTIPLE MODEM INSTALLER for VISTA (Version: 1.0.0.30)
HP Photosmart Printer Driver Software 8.0.B (Version: 8.0)
HP Product Assistant (Version: 100.000.001.000)
HP Quick Launch Buttons 6.40 D1 (Version: 6.40 D1)
HP QuickPlay 3.7
HP QuickTouch 1.00 D2 (Version: 1.0.9)
HP Solution Center 8.0 (Version: 8.0)
HP Total Care Advisor (Version: 2.1.3359.2635)
HP Update (Version: 4.000.010.008)
HP User Guides 0102 (Version: 1.01.0000)
HP Wireless Assistant (Version: 3.00 I2)
HPNetworkAssistant (Version: 1.1.70)
HPProductAssistant (Version: 82.0.173.000)
HPSSupply (Version: 2.1.3.0000)
IDT Audio (Version: 1.0.5893.0)
IE7Pro (Version: 2.4.8)
Intel® Matrix Storage Manager
iTunes (Version: 11.0.1.12)
Java 7 Update 25 (Version: 7.0.250)
Java Auto Updater (Version: 2.1.9.5)
Java™ 6 Update 31 (Version: 6.0.310)
Java™ 6 Update 5 (Version: 1.6.0.50)
Java™ 6 Update 7 (Version: 1.6.0.70)
JavaFX 2.1.1 (Version: 2.1.1)
JMicron JMB38X Flash Media Controller (Version: 1.00.10.04)
Junk Mail filter update (Version: 14.0.8117.416)
K-Lite Mega Codec Pack 10.0.5 (Version: 10.0.5)
kuler (Version: 2.0)
LabelPrint (Version: 2.20.2719)
LightScribe System Software  1.12.33.2 (Version: 1.12.33.2)
LiveUpdate (Symantec Corporation) (Version: 3.4.1.232)
Malwarebytes Anti-Malware version 1.75.0.1300 (Version: 1.75.0.1300)
MarketResearch (Version: 82.0.174.000)
Maxthon Browser (remove only)
MediaRing Talk (Version: 2.5.1.4)
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30320)
Microsoft Application Error Reporting (Version: 12.0.6012.5000)
Microsoft Choice Guard (Version: 2.0.48.0)
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office Excel MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Home and Student 2007 (Version: 12.0.6612.1000)
Microsoft Office Live Add-in 1.3 (Version: 2.0.2313.0)
Microsoft Office OneNote MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office PowerPoint MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proof (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proof (French) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proof (Spanish) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proofing (English) 2007 (Version: 12.0.4518.1014)
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
Microsoft Office Shared MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Shared Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Word MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs (Version: 12.0.4518.1014)
Microsoft Silverlight (Version: 5.1.20913.0)
Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000)
Microsoft SQL Server Native Client (Version: 9.00.3042.00)
Microsoft SQL Server Setup Support Files (English) (Version: 9.00.3042.00)
Microsoft SQL Server VSS Writer (Version: 9.00.3042.00)
Microsoft Sync Framework Runtime Native v1.0 (x86) (Version: 1.0.1215.0)
Microsoft Sync Framework Services Native v1.0 (x86) (Version: 1.0.1215.0)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (Version: 8.0.50727.4053)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (Version: 9.0.30729.5570)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (Version: 9.0.21022)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (Version: 10.0.40219)
Mozilla Firefox 24.0 (x86 en-US) (Version: 24.0)
Mozilla Maintenance Service (Version: 24.0)
MSVCRT (Version: 14.0.1468.721)
MSXML 4.0 SP2 (KB936181) (Version: 4.20.9848.0)
MSXML 4.0 SP2 (KB941833) (Version: 4.20.9849.0)
MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0)
muvee autoProducer 6.1 (Version: 6.10.050)
My HP Games (Version: 1.0.0.43)
NetDeviceManager (Version: 82.0.173.000)
NVIDIA Drivers
Orbit Downloader
PDF reDirect (remove only) (Version: v2.2.8)
PDF Settings CS4 (Version: 9.0)
Photoshop Camera Raw (Version: 5.0)
Pinnacle VideoSpin (Version: 2.0.0.669)
Pixel Bender Toolkit (Version: 1.0)
Power2Go (Version: 5.6.3919)
PowerDirector (Version: 6.5.2719)
Prism Video Converter
ProtectSmart Hard Drive Protection (Version: 3.10 A7)
QuickPlay SlingPlayer 0.4.6 (Version: 0.4.6)
QuickTime (Version: 7.72.80.56)
RaySource 2.1.10.8366 (Version: 2.1.10.8366)
Real Alternative 2.0.2 (Version: 2.0.2)
Realtek 8169 8168 8101E 8102E Ethernet Driver (Version: 1.00.0000)
Recuva
RichFLV (Version: 0.0.0)
RichFLV (Version: 4.2)
SAMSUNG USB Driver for Mobile Phones (Version: 1.5.5.0)
screen  Screen Saver
service control
Skype™ 6.10 (Version: 6.10.104)
SolutionCenter (Version: 82.0.188.000)
Status (Version: 82.0.173.000)
Subtitle Edit 3.2.8 (Version: 3.2.8.1220)
Subtitle Workshop 2.51
Suite Shared Configuration CS4 (Version: 1.0)
Switch Sound File Converter
Synaptics Pointing Device Driver (Version: 10.2.4.0)
Tipard DVD to MP3 Converter
Toolbox (Version: 82.0.173.000)
TrayApp (Version: 82.0.188.000)
TVAnts ActiveX Control 1.0
Uninstall 1.0.0.1
UnloadSupport (Version: 1.00.0000)
Unlocker 1.8.9 (Version: 1.8.9)
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 Help (KB963665)
Validity Sensors software (Version: 2.7.34)
VideoPad Video Editor
VobSub v2.23 (Remove Only)
WavePad Sound Editor (Version: 5.48)
WebReg (Version: 82.0.173.000)
Windows Live Call (Version: 14.0.8117.0416)
Windows Live Communications Platform (Version: 14.0.8117.416)
Windows Live Essentials (Version: 14.0.8117.0416)
Windows Live Essentials (Version: 14.0.8117.416)
Windows Live Mail (Version: 14.0.8117.0416)
Windows Live Messenger (Version: 14.0.8117.0416)
Windows Live Movie Maker (Version: 14.0.8117.0416)
Windows Live Photo Gallery (Version: 14.0.8117.416)
Windows Live Sign-in Assistant (Version: 5.000.818.6)
Windows Live Sync (Version: 14.0.8117.416)
Windows Live Upload Tool (Version: 14.0.8014.1029)
Windows Live Writer (Version: 14.0.8117.0416)
Windows Media Player Firefox Plugin (Version: 1.0.0.8)
WinRAR archiver
 
==================== Restore Points  =========================
 
10-11-2013 04:12:46 Scheduled Checkpoint
11-11-2013 02:24:45 Scheduled Checkpoint
12-11-2013 01:03:50 Scheduled Checkpoint
12-11-2013 16:00:08 Scheduled Checkpoint
13-11-2013 04:03:54 Scheduled Checkpoint
14-11-2013 04:01:42 Scheduled Checkpoint
16-11-2013 02:58:52 Scheduled Checkpoint
17-11-2013 01:59:42 Windows Update
18-11-2013 08:26:52 Scheduled Checkpoint
 
==================== Hosts content: ==========================
 
2006-11-02 18:23 - 2009-08-16 13:55 - 00000830 ____A C:\Windows\system32\Drivers\etc\hosts
221.143.22.124 www.dcinside.com
221.143.22.124 dcinside.com
121.125.60.241 gall.dcinside.com
 
 
==================== Scheduled Tasks (whitelisted) =============
 
Task: {075BF2ED-8755-44F5-8380-B9F001DFD426} - System32\Tasks\NCH Software\switchShakeIcon => C:\Program Files\NCH Software\Switch\switch.exe [2011-10-06] (NCH Software)
Task: {0809A579-883D-4F92-8EB1-6C4473942CF0} - System32\Tasks\HP Health Check => C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [2008-06-16] (Hewlett-Packard)
Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM
Task: {1FAB568B-9F60-48E5-BEEB-C9A911D932A1} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1630263006-122845437-3975794864-1003Core => C:\Users\Eileen\AppData\Local\Google\Update\GoogleUpdate.exe [2012-06-17] (Google Inc.)
Task: {2D23404C-C09A-403F-83F7-E426F2BD4CD3} - System32\Tasks\{22116563-108C-42c0-A7CE-60161B75E508} => C:\Users\Eileen\AppData\Local\Temp\Ahl.exe
Task: {320124A7-D70F-41DE-A9D1-D5E8E19D5D91} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI
Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages
Task: {43585A6B-C154-4222-9DEA-0C85A00625F9} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-08-22] (Piriform Ltd)
Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\System32\RacAgent.exe [2008-01-21] (Microsoft Corporation)
Task: {736ED2BD-9F55-4B27-BE42-672E24AE79CD} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {780B5712-24E6-4994-8186-EBB636D4F1CC} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1630263006-122845437-3975794864-1003UA => C:\Users\Eileen\AppData\Local\Google\Update\GoogleUpdate.exe [2012-06-17] (Google Inc.)
Task: {ACD5B504-B7E5-4FDC-BADF-704663491342} - System32\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C} => C:\Windows\Azimyb.exe
Task: {B0E300C5-9110-4459-9320-0F961767EE9A} - System32\Tasks\NCH Software\videopadShakeIcon => C:\Program Files\NCH Software\VideoPad\videopad.exe [2013-07-20] (NCH Software)
Task: {C24C66EC-1BF0-4559-89E1-9EEA5C9F3FEA} - System32\Tasks\Microsoft\Windows\WindowsCalendar\Reminders - Eileen
Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\System32\gatherWirelessInfo.vbs [2008-01-21] ()
Task: {F32E33C7-CFBB-477C-B599-3D74AFBC7030} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-10] (Adobe Systems Incorporated)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1630263006-122845437-3975794864-1003Core.job => C:\Users\Eileen\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1630263006-122845437-3975794864-1003UA.job => C:\Users\Eileen\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\User_Feed_Synchronization-{66A95A41-F5D3-46ED-876C-E78DF0ECA6FD}.job => C:\Windows\system32\msfeedssync.exe
Task: C:\Windows\Tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job => C:\Users\Eileen\AppData\Local\Temp\Ahl.exe
Task: C:\Windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job => C:\Windows\Azimyb.exe
 
==================== Loaded Modules (whitelisted) =============
 
2008-07-01 14:57 - 2008-04-24 14:51 - 00120200 _____ () C:\Program Files\HP\QuickPlay\Kernel\TV\CLSchMgr.dll
2008-07-01 14:57 - 2008-04-24 14:51 - 00038184 _____ () C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvcps.dll
2008-07-01 14:57 - 2008-04-24 14:51 - 00259472 _____ () C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapEngine.dll
2008-07-01 14:57 - 2008-04-24 14:51 - 00345384 _____ () C:\Program Files\HP\QuickPlay\Kernel\TV\CLTinyDB.dll
2012-05-30 20:06 - 2012-05-30 20:06 - 00087912 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2012-05-30 20:06 - 2012-05-30 20:06 - 01242512 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2013-11-15 19:15 - 2013-11-14 19:29 - 04055504 _____ () C:\Users\Eileen\AppData\Local\Google\Chrome\Application\31.0.1650.57\pdf.dll
2013-11-15 19:15 - 2013-11-14 19:29 - 00399312 _____ () C:\Users\Eileen\AppData\Local\Google\Chrome\Application\31.0.1650.57\ppGoogleNaClPluginChrome.dll
2013-11-15 19:15 - 2013-11-14 19:28 - 01619408 _____ () C:\Users\Eileen\AppData\Local\Google\Chrome\Application\31.0.1650.57\ffmpegsumo.dll
2012-06-22 15:43 - 2012-06-22 15:43 - 00137216 _____ () C:\Users\Eileen\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfjkgbjaikamkkojmakjclmkianficch\5.0.2_0\plugin\download_helper.dll
2013-11-15 19:15 - 2013-11-14 19:28 - 00702416 _____ () C:\Users\Eileen\AppData\Local\Google\Chrome\Application\31.0.1650.57\libglesv2.dll
2013-11-15 19:15 - 2013-11-14 19:28 - 00099792 _____ () C:\Users\Eileen\AppData\Local\Google\Chrome\Application\31.0.1650.57\libegl.dll
 
==================== Alternate Data Streams (whitelisted) =========
 
AlternateDataStreams: C:\ProgramData\TEMP:206E2596
AlternateDataStreams: C:\ProgramData\TEMP:63238B95
AlternateDataStreams: C:\ProgramData\TEMP:A66A990E
AlternateDataStreams: C:\ProgramData\TEMP:AD022376
 
==================== Safe Mode (whitelisted) ===================
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"
 
==================== Faulty Device Manager Devices =============
 
Name: Photosmart 8700 series
Description: Photosmart 8700 series
Class Guid: {4d36e971-e325-11ce-bfc1-08002be10318}
Manufacturer: HP
Service: 
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (11/18/2013 05:04:19 PM) (Source: Application Hang) (User: )
Description: The program wavepad.exe version 0.0.0.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Problem Reports and Solutions control panel.
Process ID: e20
Start Time: 01cee43d22e07492
Termination Time: 10
 
Error: (11/18/2013 09:21:11 AM) (Source: Application Error) (User: )
Description: Faulting application avnotify.exe, version 13.6.20.2100, time stamp 0x51e6b921, faulting module ntdll.dll, version 6.0.6001.18538, time stamp 0x4cb733dc, exception code 0xc0000374, fault offset 0x000b0dbc,
process id 0x1560, application start time 0xavnotify.exe0.
 
Error: (11/18/2013 09:20:32 AM) (Source: Microsoft-Windows-CAPI2) (User: )
Description: http://www.download....uthrootstl.cabA required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.
 
Error: (11/18/2013 09:19:21 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (11/17/2013 03:17:43 PM) (Source: Microsoft-Windows-CAPI2) (User: )
Description: http://www.download....uthrootstl.cabA required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.
 
Error: (11/17/2013 03:15:50 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (11/17/2013 09:56:38 AM) (Source: Microsoft-Windows-CAPI2) (User: )
Description: http://www.download....uthrootstl.cabA required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.
 
Error: (11/17/2013 09:54:54 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (11/16/2013 10:18:01 AM) (Source: Microsoft-Windows-CAPI2) (User: )
Description: http://www.download....uthrootstl.cabA required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.
 
Error: (11/16/2013 10:16:50 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
 
System errors:
=============
Error: (11/29/2012 02:50:22 PM) (Source: Dhcp) (User: )
Description: The IP address lease 192.168.1.105 for the Network Card with network address 0016EABD2BCE has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
 
Error: (11/29/2012 02:31:17 PM) (Source: Service Control Manager) (User: )
Description: SQL Server VSS Writer1
 
Error: (11/29/2012 02:31:03 PM) (Source: Service Control Manager) (User: )
Description: QuickPlay Task Scheduler (QTS)
 
Error: (11/29/2012 02:30:59 PM) (Source: Service Control Manager) (User: )
Description: QuickPlay Background Capture Service (QBCS)
 
Error: (11/29/2012 02:30:28 PM) (Source: Service Control Manager) (User: )
Description: Browser Manager%%2
 
Error: (11/29/2012 02:30:28 PM) (Source: Service Control Manager) (User: )
Description: Parallel port driver%%1058
 
Error: (11/29/2012 02:28:58 PM) (Source: HTTP) (User: )
Description: \Device\Http\ReqQueueKerberos
 
Error: (11/28/2012 10:28:09 PM) (Source: VDS Dynamic Provider) (User: )
Description: The provider failed while storing notifications from the driver. The Virtual Disk Service should be restarted. hr=80042505
 
Error: (11/28/2012 09:47:49 PM) (Source: VDS Dynamic Provider) (User: )
Description: The provider failed while storing notifications from the driver. The Virtual Disk Service should be restarted. hr=80042505
 
Error: (11/28/2012 09:46:46 PM) (Source: VDS Dynamic Provider) (User: )
Description: The provider failed while storing notifications from the driver. The Virtual Disk Service should be restarted. hr=80042505
 
 
Microsoft Office Sessions:
=========================
Error: (11/09/2012 02:30:24 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6662.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 14 seconds with 0 seconds of active time.  This session ended with a crash.
 
Error: (11/09/2012 02:29:43 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6662.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 29 seconds with 0 seconds of active time.  This session ended with a crash.
 
Error: (11/09/2012 02:28:26 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6662.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 68 seconds with 0 seconds of active time.  This session ended with a crash.
 
Error: (11/09/2012 02:27:12 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6662.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 174 seconds with 60 seconds of active time.  This session ended with a crash.
 
Error: (11/09/2012 02:23:54 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6662.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 9 seconds with 0 seconds of active time.  This session ended with a crash.
 
Error: (11/09/2012 02:23:33 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6662.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 494 seconds with 60 seconds of active time.  This session ended with a crash.
 
Error: (05/24/2011 09:50:38 AM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 270 seconds with 180 seconds of active time.  This session ended with a crash.
 
Error: (05/09/2011 00:34:55 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 69 seconds with 0 seconds of active time.  This session ended with a crash.
 
Error: (05/09/2011 00:33:35 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 93 seconds with 0 seconds of active time.  This session ended with a crash.
 
Error: (04/04/2011 10:20:04 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 343 seconds with 240 seconds of active time.  This session ended with a crash.
 
 
CodeIntegrity Errors:
===================================
  Date: 2013-11-18 23:11:38.914
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2013-11-18 23:11:38.777
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2013-11-18 23:11:38.531
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2013-11-18 23:11:38.392
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2013-11-18 23:11:38.230
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2013-11-18 23:11:38.092
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2013-11-18 23:11:37.955
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2013-11-18 23:11:37.809
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2013-11-15 14:12:58.729
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2013-11-15 14:12:58.476
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system.
 
 
==================== Memory info =========================== 
 
Percentage of memory in use: 58%
Total physical RAM: 3068.27 MB
Available physical RAM: 1269.65 MB
Total Pagefile: 6341.54 MB
Available Pagefile: 4186.01 MB
Total Virtual: 2047.88 MB
Available Virtual: 1885.18 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:147.25 GB) (Free:30.68 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (HP_RECOVERY) (Fixed) (Total:9.58 GB) (Free:1.7 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive f: (Applications) (Fixed) (Total:19.53 GB) (Free:9.21 GB) NTFS
Drive g: (Microsoft Office) (Fixed) (Total:2.93 GB) (Free:2.11 GB) NTFS
Drive h: (Music) (Fixed) (Total:9.77 GB) (Free:1.95 GB) NTFS
Drive i: (Photograph) (Fixed) (Total:9.77 GB) (Free:2.44 GB) NTFS
Drive j: (Msic) (Fixed) (Total:34.06 GB) (Free:10.8 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 233 GB) (Disk ID: 243F243F)
Partition 1: (Active) - (Size=147 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=20 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=57 GB) - (Type=OF Extended)
Partition 4: (Not Active) - (Size=10 GB) - (Type=07 NTFS)
 
==================== End Of Log ============================
 
 
I've tried to scan with Gmer but it half way thru the computer freezed and I had to restart it. I tried to scan for the 2nd time and it experience Blue Screen of Death and the computer restarts automatically. Do I still try to scan it again? 
 
Thanks you so much,
Yours truly Eileen


#4 ----------------

----------------

    SuperMember

  • Authentic Member
  • PipPipPipPipPip
  • 1,095 posts

Posted 19 November 2013 - 04:44 AM

Boot into safe mode.

 

 

Combofix

Combofix should only be run when adviced by a team member!

Link


Important - Save the file to your desktop!


  • Deactivate any and all of your antivirus programs /spyware scanners - they can prevent CF from doing its work.
  • Run Combofix.exe


When finished, Combofix creates a log file named C:\Combofix.txt. Please post its content in your next reply.

Note: When receiving an error message containing ""Illegal operation attempted on a registry key that has been marked for deletion" simply restart your computer to fix this.


Proud Member of UNITE & TB
 

#5 e_smurfs

e_smurfs

    New Member

  • Authentic Member
  • Pip
  • 13 posts

Posted 19 November 2013 - 05:45 AM

Hi,

 

Thank you once again. Here is the Combofix.txt:

 

ComboFix 13-11-19.01 - Eileen 19/11/2013  19:20:06.1.2 - x86 NETWORK

Microsoft® Windows Vista™ Home Premium   6.0.6001.1.1252.65.1033.18.3068.2396 [GMT 8:00]
Running from: c:\users\Eileen\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 * Created a new restore point
.
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\END
C:\Install.exe
c:\program files\BrowserCompanion
c:\program files\BrowserCompanion\blabbers-ch.crx
c:\program files\BrowserCompanion\logo.ico
c:\program files\skplus
c:\program files\skplus\skplus_uninstall.exe
c:\program files\smartdl
c:\program files\smartdl\cc
c:\program files\smartdl\gunzip.exe
c:\program files\smartdl\installid
c:\program files\smartdl\status
c:\program files\smartdl\TorrentSearch.exe
c:\program files\TSearch
c:\program files\TSearch\results
c:\programdata\114la.ico
C:\torrent.exe
c:\users\Eileen\AppData\Local\Google\Chrome\User Data\Default\bProtectorPreferences
c:\users\Eileen\AppData\Local\Microsoft\Windows\Temporary Internet Files\DANALAOD0.che
c:\users\Eileen\AppData\Local\Microsoft\Windows\Temporary Internet Files\DANALAOD1.che
c:\users\Eileen\AppData\Local\Microsoft\Windows\Temporary Internet Files\DANALAOD2.che
c:\users\Eileen\AppData\Local\Microsoft\Windows\Temporary Internet Files\DANALAOD3.che
c:\users\Eileen\AppData\Local\Microsoft\Windows\Temporary Internet Files\DANALAOD4.che
c:\users\Eileen\AppData\Local\Microsoft\Windows\Temporary Internet Files\DANALAOD5.che
c:\users\Eileen\AppData\Local\Microsoft\Windows\Temporary Internet Files\DANALAOD6.che
c:\users\Eileen\AppData\Local\Microsoft\Windows\Temporary Internet Files\DANALAOD7.che
c:\users\Eileen\AppData\Local\Microsoft\Windows\Temporary Internet Files\DANALAOD8.che
c:\users\Eileen\AppData\Local\Microsoft\Windows\Temporary Internet Files\DANALAOD9.che
c:\users\Eileen\AppData\Local\Microsoft\Windows\Temporary Internet Files\MNETV.cfg
c:\users\Eileen\AppData\Local\Microsoft\Windows\Temporary Internet Files\MNETV0.che
c:\users\Eileen\AppData\Local\Microsoft\Windows\Temporary Internet Files\MNETV1.che
c:\users\Eileen\AppData\Local\Microsoft\Windows\Temporary Internet Files\MNETV2.che
c:\users\Eileen\AppData\Local\Microsoft\Windows\Temporary Internet Files\MNETV3.che
c:\users\Eileen\AppData\Local\Microsoft\Windows\Temporary Internet Files\MNETV4.che
c:\users\Eileen\AppData\Local\Microsoft\Windows\Temporary Internet Files\MNETV5.che
c:\users\Eileen\AppData\Local\Microsoft\Windows\Temporary Internet Files\MNETV6.che
c:\users\Eileen\AppData\Local\Microsoft\Windows\Temporary Internet Files\MNETV7.che
c:\users\Eileen\AppData\Local\Microsoft\Windows\Temporary Internet Files\MNETV8.che
c:\users\Eileen\AppData\Local\Microsoft\Windows\Temporary Internet Files\MNETV9.che
c:\users\Eileen\AppData\Local\Microsoft\Windows\Temporary Internet Files\SKBGM.cfg
c:\users\Eileen\AppData\Local\Microsoft\Windows\Temporary Internet Files\SKBGM0.che
c:\users\Eileen\AppData\Local\Microsoft\Windows\Temporary Internet Files\SKBGM1.che
c:\users\Eileen\AppData\Local\Microsoft\Windows\Temporary Internet Files\SKBGM2.che
c:\users\Eileen\AppData\Local\Microsoft\Windows\Temporary Internet Files\SKBGM3.che
c:\users\Eileen\AppData\Local\Microsoft\Windows\Temporary Internet Files\SKBGM4.che
c:\users\Eileen\AppData\Local\Microsoft\Windows\Temporary Internet Files\SKBGM5.che
c:\users\Eileen\AppData\Local\Microsoft\Windows\Temporary Internet Files\SKBGM6.che
c:\users\Eileen\AppData\Local\Microsoft\Windows\Temporary Internet Files\SKBGM7.che
c:\users\Eileen\AppData\Local\Microsoft\Windows\Temporary Internet Files\SKBGM8.che
c:\users\Eileen\AppData\Local\Microsoft\Windows\Temporary Internet Files\SKBGM9.che
c:\users\Eileen\AppData\Roaming\115
c:\users\Eileen\AppData\Roaming\115\UDown\Accounts.ini
c:\users\Eileen\AppData\Roaming\115\UDown\Bootstap.dat
c:\users\Eileen\AppData\Roaming\115\UDown\Data\dbisam.lck
c:\users\Eileen\AppData\Roaming\115\UDown\Data\DelFileList.blb
c:\users\Eileen\AppData\Roaming\115\UDown\Data\DelFileList.dat
c:\users\Eileen\AppData\Roaming\115\UDown\Data\DelFileList.idx
c:\users\Eileen\AppData\Roaming\115\UDown\Data\DownFileHis.blb
c:\users\Eileen\AppData\Roaming\115\UDown\Data\DownFileHis.dat
c:\users\Eileen\AppData\Roaming\115\UDown\Data\DownFileHis.idx
c:\users\Eileen\AppData\Roaming\115\UDown\Data\HisData.db
c:\users\Eileen\AppData\Roaming\115\UDown\Data\UpFileHis.dat
c:\users\Eileen\AppData\Roaming\115\UDown\Data\UpFileHis.idx
c:\users\Eileen\AppData\Roaming\115\UDown\Data\UserData.db
c:\users\Eileen\AppData\Roaming\115\UDown\DownTask.lst
c:\users\Eileen\AppData\Roaming\115\UDown\Proxy.ini
c:\users\Eileen\AppData\Roaming\115\UDown\SaveDir.his
c:\users\Eileen\AppData\Roaming\115\UDown\Syscfg.ini
c:\users\Eileen\AppData\Roaming\115\UDown\TempFile.dat
c:\users\Eileen\AppData\Roaming\115\UDown\Update\115UDown_2.3.0.128.exe
c:\users\Eileen\AppData\Roaming\115\UDown\Update\115UDown_2.4.1.132.exe
c:\users\Eileen\AppData\Roaming\115\UDown\Update\115UDown_2.4.2.133.exe
c:\users\Eileen\AppData\Roaming\115\UDown\Update\115UDown_2.4.4.135.exe
c:\users\Eileen\AppData\Roaming\115\UDown\Update\115UDown_2.4.5.136.exe
c:\users\Eileen\AppData\Roaming\115\UDown\UpLoadList_3269425.lst
c:\users\Eileen\AppData\Roaming\Microsoft\Windows\Templates\iplustemp.ini
c:\windows\system32\ccrpTmr6.dll
c:\windows\system32\FlashPlayerApp.exe
c:\windows\system32\funshion.ini
c:\windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
.
.
(((((((((((((((((((((((((   Files Created from 2013-10-19 to 2013-11-19  )))))))))))))))))))))))))))))))
.
.
2013-11-19 11:31 . 2013-11-19 11:31 -------- d-----w- c:\users\Eileen\AppData\Local\temp
2013-11-19 11:31 . 2013-11-19 11:31 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-11-18 15:07 . 2013-11-18 15:07 -------- d-----w- C:\FRST
2013-11-15 01:55 . 2013-11-15 01:55 -------- d-----w- c:\users\Eileen\AppData\Roaming\Malwarebytes
2013-11-15 01:55 . 2013-11-15 01:55 -------- d-----w- c:\programdata\Malwarebytes
2013-11-15 01:55 . 2013-11-15 01:55 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2013-11-15 01:55 . 2013-04-04 06:50 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-11-11 05:33 . 2013-11-11 05:34 -------- d-----w- c:\users\Eileen\[00000001]
2013-11-10 08:53 . 2013-11-10 08:53 63920 ----a-w- c:\windows\system32\drivers\vmx_svga.sys
2013-11-10 08:53 . 2013-11-10 08:53 11696 ----a-w- c:\windows\system32\drivers\vmmouse.sys
2013-11-10 08:53 . 2013-11-10 08:53 117552 ----a-w- c:\windows\system32\drivers\vmhgfs.sys
2013-11-10 08:53 . 2013-11-10 08:53 19504 ----a-w- c:\windows\system32\drivers\vmdebug.sys
2013-11-10 08:53 . 2013-11-10 08:53 54960 ----a-w- c:\windows\system32\drivers\vmci.sys
2013-11-10 08:52 . 2013-11-10 08:53 25008 ----a-w- c:\windows\system32\drivers\vmaudio.sys
2013-11-10 08:52 . 2013-11-10 08:52 368749 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\TPWinPrn.dll
2013-11-10 08:52 . 2013-11-10 08:52 22528 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\jnwppr.dll
2013-11-10 08:51 . 2013-11-10 08:51 54784 ----a-w- c:\windows\system32\WsmProv.dll
2013-11-10 08:51 . 2013-11-10 08:51 1536 ----a-w- c:\windows\system32\WsmCl.dll
2013-11-10 08:51 . 2013-11-10 08:51 16432 ----a-w- c:\windows\system32\vmx_mode.dll
2013-11-10 08:51 . 2013-11-10 08:51 173232 ----a-w- c:\windows\system32\vmx_fb.dll
2013-11-10 08:51 . 2013-11-10 08:51 35888 ----a-w- c:\windows\system32\vmhgfs.dll
2013-11-10 08:51 . 2013-11-10 08:51 111856 ----a-w- c:\windows\system32\TPVMW32.dll
2013-11-10 08:51 . 2013-11-10 08:51 9104 ----a-w- c:\windows\system32\TPVMMonUIjpn.dll
2013-11-10 08:50 . 2013-11-10 08:51 9104 ----a-w- c:\windows\system32\TPVMMonUIdeu.dll
2013-11-10 08:50 . 2013-11-10 08:50 79208 ----a-w- c:\windows\system32\TPVMMonUI.dll
2013-11-10 08:50 . 2013-11-10 08:50 9632 ----a-w- c:\windows\system32\TPVMMonjpn.dll
2013-11-10 08:50 . 2013-11-10 08:50 23960 ----a-w- c:\windows\system32\TPVMMondeu.dll
2013-11-10 08:50 . 2013-11-10 08:50 284016 ----a-w- c:\windows\system32\TPVMMon.dll
2013-11-10 08:50 . 2013-11-10 08:50 423208 ----a-w- c:\windows\system32\TPSvc.dll
2013-11-10 08:50 . 2013-11-10 08:50 113664 ----a-w- c:\windows\system32\LANGWRBK.DLL
2013-11-10 08:50 . 2013-11-10 08:50 19968 ----a-w- c:\windows\system32\jnwmon.dll
2013-11-10 08:50 . 2013-11-10 08:50 78336 ----a-w- c:\windows\system32\ieencode.dll
2013-11-10 06:26 . 2013-11-10 06:27 289280 ----a-w- c:\windows\system32\StikyNot.exe
2013-11-10 06:26 . 2013-11-10 06:26 275968 ----a-w- c:\windows\system32\SnippingTool.exe
2013-11-10 06:19 . 2013-11-10 06:19 -------- d-----w- c:\programdata\Weskysoft
2013-11-10 02:34 . 2013-11-10 02:34 -------- d-----w- c:\program files\DLLSuite
2013-11-08 18:53 . 2013-11-08 19:01 -------- d-----w- c:\program files\DVDVideoSoft
2013-11-08 08:43 . 2013-11-08 19:01 -------- d-----w- c:\program files\Common Files\DVDVideoSoft
2013-11-02 01:33 . 2013-11-02 01:33 -------- d-----w- c:\programdata\Oracle
2013-10-23 07:17 . 2013-03-17 16:21 3649536 ----a-w- c:\windows\system32\x264vfw.dll
2013-10-23 07:17 . 2011-12-07 17:32 216064 ----a-w- c:\windows\system32\lagarith.dll
2013-10-23 07:17 . 2011-06-24 14:28 650752 ----a-w- c:\windows\system32\xvidcore.dll
2013-10-23 07:17 . 2012-07-21 10:54 122880 ----a-w- c:\windows\system32\ac3acm.acm
2013-10-23 07:17 . 2011-06-24 14:44 243200 ----a-w- c:\windows\system32\xvidvfw.dll
2013-10-23 07:17 . 2013-09-12 18:00 112640 ----a-w- c:\windows\system32\ff_vfw.dll
2013-10-23 07:17 . 2013-10-23 07:17 -------- d-----w- c:\program files\K-Lite Codec Pack
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-11-10 08:50 . 2013-11-10 08:50 2048 ----a-w- c:\windows\help\Tablet PC\TTRes.dll
2013-11-10 08:50 . 2013-11-10 08:50 2048 ----a-w- c:\windows\help\Tablet PC\PTRes.dll
2013-11-10 06:26 . 2013-11-10 06:26 159232 ----a-w- c:\windows\help\Tablet PC\TouchTraining.exe
2013-11-10 06:26 . 2013-11-10 06:25 231936 ----a-w- c:\windows\help\Tablet PC\PenTraining.exe
2013-10-10 03:09 . 2011-06-29 09:51 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-09-03 08:25 . 2012-12-18 02:56 88840 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2013-08-22 17:09 . 2010-03-22 13:23 217176 ----a-w- c:\windows\system32\unrar.dll
2009-05-04 05:14 . 2013-10-02 08:29 36864 ----a-w- c:\program files\mozilla firefox\components\NsThunderLoader.dll
2009-05-04 05:14 . 2013-10-02 08:29 53248 ----a-w- c:\program files\mozilla firefox\components\ThunderComponent.dll
.
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown 
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{872b5b88-9db5-4310-bdd0-ac189557e5f5}"= "c:\program files\DVDVideoSoftTB\tbDVDV.dll" [2010-04-27 2393184]
.
[HKEY_CLASSES_ROOT\clsid\{872b5b88-9db5-4310-bdd0-ac189557e5f5}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{872b5b88-9db5-4310-bdd0-ac189557e5f5}]
2010-04-27 02:08 2393184 ----a-w- c:\program files\DVDVideoSoftTB\tbDVDV.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{872b5b88-9db5-4310-bdd0-ac189557e5f5}"= "c:\program files\DVDVideoSoftTB\tbDVDV.dll" [2010-04-27 2393184]
.
[HKEY_CLASSES_ROOT\clsid\{872b5b88-9db5-4310-bdd0-ac189557e5f5}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{872B5B88-9DB5-4310-BDD0-AC189557E5F5}"= "c:\program files\DVDVideoSoftTB\tbDVDV.dll" [2010-04-27 2393184]
.
[HKEY_CLASSES_ROOT\clsid\{872b5b88-9db5-4310-bdd0-ac189557e5f5}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"eMuleAutoStart"="c:\program files\eMule\emule.exe" [2010-04-07 5758976]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-23 13539872]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2008-04-15 442433]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-04-16 178712]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-12-24 222504]
"DpAgent"="c:\program files\DigitalPersona\Bin\dpagent.exe" [2008-03-13 699456]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-03-14 202032]
"OnScreenDisplay"="c:\program files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe" [2007-11-02 554288]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-11-20 488752]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="f:\gmail notifier\gnotify.exe" [2005-07-15 479232]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-06-16 75008]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-01-18 1033512]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2008-04-24 468264]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-23 92704]
"HP Software Update"="f:\hp\HP Software Update\HPWuSchd2.exe" [2006-12-10 49152]
"Grid Service"="c:\program files\GridService\peer.exe" [2008-12-30 4993024]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-13 611712]
"Adobe Acrobat Speed Launcher"="f:\adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2008-06-11 37232]
"Acrobat Assistant 8.0"="f:\adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2008-06-11 640376]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-11-28 59280]
"QuickTime Task"="f:\quicktime\QTTask.exe" [2012-04-18 421888]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2013-08-20 347192]
"iTunesHelper"="f:\itunes\iTunesHelper.exe" [2012-12-12 152544]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-05-11 958576]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2013-03-11 253816]
.
c:\users\Eileen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - g:\office12\ONENOTEM.EXE /tsr [2009-2-26 97680]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-11-11 113664]
HP Digital Imaging Monitor.lnk - f:\hp\Digital Imaging\bin\hpqtra08.exe [2007-1-2 210520]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer4"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ   scecli DPPWDFLT
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
backup=c:\windows\pss\Bluetooth.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^Users^Eileen^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Orbit.lnk]
path=c:\users\Eileen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Orbit.lnk
backup=c:\windows\pss\Orbit.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2012-12-12 05:57 152544 ----a-w- f:\itunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
2008-02-26 21:08 2289664 ----a-w- c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1630263006-122845437-3975794864-1003]
"EnableNotificationsRef"=dword:00000001
.
R2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_030ac640\aestsrv.exe [2008-02-12 73728]
R3 Adobe Version Cue CS4;Adobe Version Cue CS4;c:\program files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [2008-08-14 284016]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ   BthServ
HPZ12 REG_MULTI_SZ   Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ   hpqcxs08 hpqddsvc
HPService REG_MULTI_SZ   HPSLPSVC
XLServicePlatform REG_MULTI_SZ   XLServicePlatform
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-02-26 21:06 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
.
2013-11-19 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-05 03:09]
.
2013-11-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1630263006-122845437-3975794864-1003Core.job
- c:\users\Eileen\AppData\Local\Google\Update\GoogleUpdate.exe [2012-06-17 07:19]
.
2013-11-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1630263006-122845437-3975794864-1003UA.job
- c:\users\Eileen\AppData\Local\Google\Update\GoogleUpdate.exe [2012-06-17 07:19]
.
2013-11-19 c:\windows\Tasks\User_Feed_Synchronization-{66A95A41-F5D3-46ED-876C-E78DF0ECA6FD}.job
- c:\windows\system32\msfeedssync.exe [2011-06-16 04:32]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.sg/
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_sg&c=83&bd=Pavilion&pf=cnnb
uInternet Settings,ProxyOverride = local;*.local
uInternet Settings,ProxyServer = socks=127.0.0.1:4021;
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Download by Orbit - f:\orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - f:\orbitdownloader\orbitmxt.dll/204
IE: &U????????? - f:\namirobot\Data\du.html
IE: &ʹÓÃÓŵ°ÏÂÔØ - f:\udown\getUrl.htm
IE: &ʹÓÃÓŵ°ÏÂÔØÈ«²¿Á´½Ó - f:\udown\getAllUrl.htm
IE: &??115???? - c:\users\Eileen\AppData\Roaming\115\UDown\getUrl.htm
IE: &??115???????? - c:\users\Eileen\AppData\Roaming\115\UDown\getAllUrl.htm
IE: Add to Evernote 4.0 - c:\program files\Evernote\Evernote\EvernoteIE.dll/204
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Do&wnload selected by Orbit - f:\orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - f:\orbitdownloader\orbitmxt.dll/202
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Free YouTube Download - c:\users\Eileen\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm
IE: Free YouTube to MP3 Converter - c:\users\Eileen\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: use Thunderbolt download - f:\thunder network\Thunder\Program\GetUrl.htm
IE: use Xunlei download all the links - f:\thunder network\Thunder\Program\GetAllUrl.htm
IE: {{09BA8F6D-CB54-424B-839C-C2A6C8E6B436}
Trusted Zone: 111222.cn\list1
Trusted Zone: pps.tv\kan
Trusted Zone: pps.tv\list1
Trusted Zone: pps.tv\tvguide
Trusted Zone: pps.tv\vodguide
Trusted Zone: ppstream.com\list1
Trusted Zone: ppstream.com\notice
Trusted Zone: ppstream.com\xml1
Trusted Zone: ppstream.com\xml2
Trusted Zone: ppstream.com\xml3
Trusted Zone: ppstream.net\list1
Trusted Zone: ppstv.com\list1
Trusted Zone: ppstv.net\list1
Trusted Zone: security_PPStream.exe
Trusted Zone: gogobox.com.tw
Trusted Zone: qq.com\cache.tv
Trusted Zone: qq.com\qqlivecaption
Trusted Zone: qq.com\qqlivehabit
Trusted Zone: qq.com\qqlivesearch
Trusted Zone: qq.com\video_1
TCP: DhcpNameServer = 202.156.1.16 218.186.2.16 218.186.2.6
Handler: CDS300 - {AD43AA67-6860-4531-AC8A-0E68F9CF023E} - 
DPF: {8B9230ED-5766-43C9-855B-E742B0B2E871} - hxxp://www.servicemanager.co.kr/ocx/servicemanagerdx2.ocx
FF - ProfilePath - c:\users\Eileen\AppData\Roaming\Mozilla\Firefox\Profiles\xkfmli2b.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.sg/
FF - prefs.js: network.proxy.http - 198.7.242.41
FF - prefs.js: network.proxy.http_port - 3127
FF - prefs.js: network.proxy.type - 0
FF - user.js: extensions.BabylonToolbar_i.id - 274f4e6d0000000000000016eabd2bce
FF - user.js: extensions.BabylonToolbar_i.hardId - 274f4e6d0000000000000016eabd2bce
FF - user.js: extensions.BabylonToolbar_i.instlDay - 15443
FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1716:43
FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar_i.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar_i.tlbrId - base
FF - user.js: extensions.BabylonToolbar_i.newTab - false
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=110854
FF - user.js: extensions.BabylonToolbar_i.babExt - 
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.BabylonToolbar_i.instlRef - sst
FF - user.js: extensions.claro.tlbrSrchUrl - 
FF - user.js: extensions.claro.id - 274f4e6d0000000000000016eabd2bce
FF - user.js: extensions.claro.appId - {C3110516-8EFC-49D6-8B72-69354F332062}
FF - user.js: extensions.claro.instlDay - 15663
FF - user.js: extensions.claro.vrsn - 1.8.3.10
FF - user.js: extensions.claro.vrsni - 1.8.3.10
FF - user.js: extensions.claro_i.vrsnTs - 1.8.3.100:08
FF - user.js: extensions.claro.prtnrId - claro
FF - user.js: extensions.claro.prdct - claro
FF - user.js: extensions.claro.aflt - babsst
FF - user.js: extensions.claro_i.smplGrp - none
FF - user.js: extensions.claro.tlbrId - base
FF - user.js: extensions.claro.instlRef - sst
FF - user.js: extensions.claro.dfltLng - en
FF - user.js: extensions.claro.excTlbr - false
FF - user.js: extensions.claro.admin - false
.
- - - - ORPHANS REMOVED - - - -
.
URLSearchHooks-{ba14329e-9550-4989-b3f2-9732e92d17cc} - (no file)
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{A057A204-BACC-4D26-C39E-35F1D2A32EC8} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{BA14329E-9550-4989-B3F2-9732E92D17CC} - (no file)
ShellIconOverlayIdentifiers-{4562B511-62E9-4533-B7B2-56A8BB10B482} - c:\program files\Common Files\Thunder Network\KanKan\xappex.1.1.1.38.(642).dll
HKCU-Run-AdobeBridge - (no file)
HKCU-Run-service control - c:\program files\service control\servicectrl.exe
HKCU-Run-¿ì²¥Ó°ÊӺР- f:\qvodhd\play.exe
HKCU-Run-pinomate - c:\users\Eileen\AppData\Local\PeeringPortal\Pino\pinomate.exe
HKCU-Run-Easy-Hide-IP - f:\easy-hide-ip\easy-hide-ip.exe
HKCU-Run-Orbitum - c:\users\Eileen\AppData\Local\Orbitum\Application\chrome.exe
HKLM-Run-SymLnch - c:\program files\Common Files\Symantec Shared\SymSetup\{C1C185CA-C531-49F5-A6FA-B838405A049D}_15_5_0_23\Support\SymLnch\SymLnch.exe
HKLM-Run-BrowserPlugInHelper - c:\program files\iSkysoft\iTube Studio\BrowserPlugInHelper.exe
SafeBoot-Wdf01000.sys
MSConfigStartUp-TkBellExe - c:\program files\Common Files\Real\Update_OB\realsched.exe
AddRemove-115ä¯ÀÀÆ÷ - c:\program files\115\browser\uninst.exe
AddRemove-screen - c:\windows\screen.scr
AddRemove-service control - c:\program files\service control\servicectrl.exe
AddRemove-Uninstall_is1 - c:\program files\Common Files\DVDVideoSoft\unins000.exe
AddRemove-01_Simmental - f:\usb drivers\01_Simmental\Uninstall.exe
AddRemove-02_Siberian - f:\usb drivers\02_Siberian\Uninstall.exe
AddRemove-03_Swallowtail - f:\usb drivers\03_Swallowtail\Uninstall.exe
AddRemove-04_semseyite - f:\usb drivers\04_semseyite\Uninstall.exe
AddRemove-05_Sloan - f:\usb drivers\05_Sloan\Uninstall.exe
AddRemove-06_Spencer - f:\usb drivers\06_Spencer\Uninstall.exe
AddRemove-07_Schorl - f:\usb drivers\07_Schorl\Uninstall.exe
AddRemove-08_EMPChipset - f:\usb drivers\08_EMPChipset\Uninstall.exe
AddRemove-09_Hsp - f:\usb drivers\09_Hsp\Uninstall.exe
AddRemove-11_HSP_Plus_Default - f:\usb drivers\11_HSP_Plus_Default\Uninstall.exe
AddRemove-16_Shrewsbury - f:\usb drivers\16_Shrewsbury\Uninstall.exe
AddRemove-17_EMP_Chipset2 - f:\usb drivers\17_EMP_Chipset2\Uninstall.exe
AddRemove-18_Zinia_Serial_Driver - f:\usb drivers\18_Zinia_Serial_Driver\Uninstall.exe
AddRemove-19_VIA_driver - f:\usb drivers\19_VIA_driver\Uninstall.exe
AddRemove-20_NXP_Driver - f:\usb drivers\20_NXP_Driver\Uninstall.exe
AddRemove-22_WiBro_WiMAX - f:\usb drivers\22_WiBro_WiMAX\Uninstall.exe
AddRemove-24_flashusbdriver - f:\usb drivers\24_flashusbdriver\Uninstall.exe
AddRemove-25_escape - f:\usb drivers\25_escape\Uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-11-19 19:31
Windows 6.0.6001 Service Pack 1 NTFS
.
scanning hidden processes ...  
.
scanning hidden autostart entries ... 
.
scanning hidden files ...  
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*B*D*ýV¤|ÌSí‹-NW[\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*c*o*m*ÿ,{4*5*J\~vó`z‚/g'YO ÿ]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*c*o*m*ÿ,{4*5*J\~vó`z‚/g'YO ÿ\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*Y*Y*c*a*F*-N‡eûÑ‹Hr,g\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*[*9\i`à`-N‡eQ6R]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*[*9\i`à`-N‡eQ6R\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*[*é—gRíp¿~6R\O]*]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*[*é—gRíp¿~6R\O]*\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*-Nñ‚W[U^]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*-Nñ‚W[U^\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*hQ:W-NW[]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*hQ:W-NW[\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.* R•Hr1*1*8*RŸ”\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*ýV¤|ÌSí‹]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*ýV¤|ÌSí‹\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*ýV¤|ÌSí‹-NW[]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*ýV¤|ÌSí‹-NW[\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*ù[bô‹ŒÕ‹Õ‹]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*ù[bô‹ŒÕ‹Õ‹\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*¥bSù[bô‹ŒÕ‹Õ‹9\i`à`ïSPN;T]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*¥bSù[bô‹ŒÕ‹Õ‹9\i`à`ïSPN;T\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*nmÎW'Y¨N]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*nmÎW'Y¨N\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*nmÎWŒ‹N]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*nmÎWŒ‹N\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\. ,{2 9 ãN[ 
N] [ Ó—žŠ!qW[] ]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\. ,{2 9 ãN[ 
N] [ Ó—žŠ!qW[] \OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*,{2*9*ãN[*N]*[*Ó—žŠ!qW[]*]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*,{2*9*ãN[*N]*[*Ó—žŠ!qW[]*\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\. ,{3 1 ãN[ 
N] [ Ó—žŠ!qW[] ]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\. ,{3 1 ãN[ 
N] [ Ó—žŠ!qW[] \OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*,{3*1*ãN[*N]*[*Ó—žŠ!qW[]*]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*,{3*1*ãN[*N]*[*Ó—žŠ!qW[]*\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*,{3*1*ãN[*-N]*[*Ó—žŠ!qW[]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*,{3*1*ãN[*-N]*[*Ó—žŠ!qW[\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*,{3*3*g]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*,{3*3*g\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*€{ŽYL*I*V*E*\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.*[*9\i`à`-N‡eQ6R]
@Allowed: (Read) (RestrictedCode)
"MRUListEx"=hex:00,00,00,00,ff,ff,ff,ff
"0"=hex:30,00,34,00,34,00,2e,00,5b,00,59,00,6f,00,6f,00,6e,00,45,00,75,00,6e,
   00,48,00,79,00,65,00,2e,00,43,00,4e,00,5d,00,2e,00,42,00,61,00,62,00,79,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'lsass.exe'(660)
c:\windows\system32\DPPWDFLT.dll
.
Completion time: 2013-11-19  19:34:32
ComboFix-quarantined-files.txt  2013-11-19 11:34
.
Pre-Run: 37,236,559,872 bytes free
Post-Run: 38,701,527,040 bytes free
.
- - End Of File - - CE5CA6C91346C62D3F6B28ABA51D1814
85D751F0E41B8E520AEE8C07A8DA777B


#6 ----------------

----------------

    SuperMember

  • Authentic Member
  • PipPipPipPipPip
  • 1,095 posts

Posted 19 November 2013 - 06:11 AM

Combofix scripting

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Download the attached CFScript.txt and save it to the location where Combofix is.


CFScriptB-4.gif


Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

Attached Files


Proud Member of UNITE & TB
 

#7 e_smurfs

e_smurfs

    New Member

  • Authentic Member
  • Pip
  • 13 posts

Posted 19 November 2013 - 09:11 AM

Here is the Combofix.txt:

 

ComboFix 13-11-19.01 - Eileen 19/11/2013  22:52:24.2.2 - x86

Microsoft® Windows Vista™ Home Premium   6.0.6001.1.1252.65.1033.18.3068.1905 [GMT 8:00]
Running from: c:\users\Eileen\Desktop\ComboFix.exe
Command switches used :: c:\users\Eileen\Desktop\CFScript.txt
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((   Files Created from 2013-10-19 to 2013-11-19  )))))))))))))))))))))))))))))))
.
.
2013-11-19 15:04 . 2013-11-19 15:04 -------- d-----w- c:\users\Eileen\AppData\Local\temp
2013-11-19 15:04 . 2013-11-19 15:04 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-11-18 15:07 . 2013-11-18 15:07 -------- d-----w- C:\FRST
2013-11-15 01:55 . 2013-11-15 01:55 -------- d-----w- c:\users\Eileen\AppData\Roaming\Malwarebytes
2013-11-15 01:55 . 2013-11-15 01:55 -------- d-----w- c:\programdata\Malwarebytes
2013-11-15 01:55 . 2013-11-15 01:55 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2013-11-15 01:55 . 2013-04-04 06:50 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-11-11 05:33 . 2013-11-11 05:34 -------- d-----w- c:\users\Eileen\[00000001]
2013-11-10 08:53 . 2013-11-10 08:53 63920 ----a-w- c:\windows\system32\drivers\vmx_svga.sys
2013-11-10 08:53 . 2013-11-10 08:53 11696 ----a-w- c:\windows\system32\drivers\vmmouse.sys
2013-11-10 08:53 . 2013-11-10 08:53 117552 ----a-w- c:\windows\system32\drivers\vmhgfs.sys
2013-11-10 08:53 . 2013-11-10 08:53 19504 ----a-w- c:\windows\system32\drivers\vmdebug.sys
2013-11-10 08:53 . 2013-11-10 08:53 54960 ----a-w- c:\windows\system32\drivers\vmci.sys
2013-11-10 08:52 . 2013-11-10 08:53 25008 ----a-w- c:\windows\system32\drivers\vmaudio.sys
2013-11-10 08:52 . 2013-11-10 08:52 368749 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\TPWinPrn.dll
2013-11-10 08:52 . 2013-11-10 08:52 22528 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\jnwppr.dll
2013-11-10 08:51 . 2013-11-10 08:51 54784 ----a-w- c:\windows\system32\WsmProv.dll
2013-11-10 08:51 . 2013-11-10 08:51 1536 ----a-w- c:\windows\system32\WsmCl.dll
2013-11-10 08:51 . 2013-11-10 08:51 16432 ----a-w- c:\windows\system32\vmx_mode.dll
2013-11-10 08:51 . 2013-11-10 08:51 173232 ----a-w- c:\windows\system32\vmx_fb.dll
2013-11-10 08:51 . 2013-11-10 08:51 35888 ----a-w- c:\windows\system32\vmhgfs.dll
2013-11-10 08:51 . 2013-11-10 08:51 111856 ----a-w- c:\windows\system32\TPVMW32.dll
2013-11-10 08:51 . 2013-11-10 08:51 9104 ----a-w- c:\windows\system32\TPVMMonUIjpn.dll
2013-11-10 08:50 . 2013-11-10 08:51 9104 ----a-w- c:\windows\system32\TPVMMonUIdeu.dll
2013-11-10 08:50 . 2013-11-10 08:50 79208 ----a-w- c:\windows\system32\TPVMMonUI.dll
2013-11-10 08:50 . 2013-11-10 08:50 9632 ----a-w- c:\windows\system32\TPVMMonjpn.dll
2013-11-10 08:50 . 2013-11-10 08:50 23960 ----a-w- c:\windows\system32\TPVMMondeu.dll
2013-11-10 08:50 . 2013-11-10 08:50 284016 ----a-w- c:\windows\system32\TPVMMon.dll
2013-11-10 08:50 . 2013-11-10 08:50 423208 ----a-w- c:\windows\system32\TPSvc.dll
2013-11-10 08:50 . 2013-11-10 08:50 113664 ----a-w- c:\windows\system32\LANGWRBK.DLL
2013-11-10 08:50 . 2013-11-10 08:50 19968 ----a-w- c:\windows\system32\jnwmon.dll
2013-11-10 08:50 . 2013-11-10 08:50 78336 ----a-w- c:\windows\system32\ieencode.dll
2013-11-10 06:26 . 2013-11-10 06:27 289280 ----a-w- c:\windows\system32\StikyNot.exe
2013-11-10 06:26 . 2013-11-10 06:26 275968 ----a-w- c:\windows\system32\SnippingTool.exe
2013-11-10 06:19 . 2013-11-10 06:19 -------- d-----w- c:\programdata\Weskysoft
2013-11-10 02:34 . 2013-11-10 02:34 -------- d-----w- c:\program files\DLLSuite
2013-11-08 18:53 . 2013-11-08 19:01 -------- d-----w- c:\program files\DVDVideoSoft
2013-11-08 08:43 . 2013-11-08 19:01 -------- d-----w- c:\program files\Common Files\DVDVideoSoft
2013-11-02 01:33 . 2013-11-02 01:33 -------- d-----w- c:\programdata\Oracle
2013-10-23 07:17 . 2013-03-17 16:21 3649536 ----a-w- c:\windows\system32\x264vfw.dll
2013-10-23 07:17 . 2011-12-07 17:32 216064 ----a-w- c:\windows\system32\lagarith.dll
2013-10-23 07:17 . 2011-06-24 14:28 650752 ----a-w- c:\windows\system32\xvidcore.dll
2013-10-23 07:17 . 2012-07-21 10:54 122880 ----a-w- c:\windows\system32\ac3acm.acm
2013-10-23 07:17 . 2011-06-24 14:44 243200 ----a-w- c:\windows\system32\xvidvfw.dll
2013-10-23 07:17 . 2013-09-12 18:00 112640 ----a-w- c:\windows\system32\ff_vfw.dll
2013-10-23 07:17 . 2013-10-23 07:17 -------- d-----w- c:\program files\K-Lite Codec Pack
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-11-19 14:22 . 2012-12-18 02:56 37352 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2013-11-19 14:22 . 2012-12-18 02:56 90400 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2013-11-19 14:22 . 2012-12-18 02:56 137208 ----a-w- c:\windows\system32\drivers\avipbb.sys
2013-11-10 08:50 . 2013-11-10 08:50 2048 ----a-w- c:\windows\help\Tablet PC\TTRes.dll
2013-11-10 08:50 . 2013-11-10 08:50 2048 ----a-w- c:\windows\help\Tablet PC\PTRes.dll
2013-11-10 06:26 . 2013-11-10 06:26 159232 ----a-w- c:\windows\help\Tablet PC\TouchTraining.exe
2013-11-10 06:26 . 2013-11-10 06:25 231936 ----a-w- c:\windows\help\Tablet PC\PenTraining.exe
2013-10-10 03:09 . 2011-06-29 09:51 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-08-22 17:09 . 2010-03-22 13:23 217176 ----a-w- c:\windows\system32\unrar.dll
2009-05-04 05:14 . 2013-10-02 08:29 36864 ----a-w- c:\program files\mozilla firefox\components\NsThunderLoader.dll
2009-05-04 05:14 . 2013-10-02 08:29 53248 ----a-w- c:\program files\mozilla firefox\components\ThunderComponent.dll
.
.
((((((((((((((((((((((((((((((((((((((((((((   Look   )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of c:\users\Eileen\[00000001] ----
.
2013-11-08 14:22 . 2013-11-08 14:22 14401861 ----a-w- c:\users\Eileen\[00000001]\2013-10-08 00-01-43.m4a
2013-11-08 14:22 . 2013-11-08 14:22 3342579 ----a-w- c:\users\Eileen\[00000001]\2013-10-08 01-20-29.m4a
2013-11-08 14:22 . 2013-11-08 14:22 895456 ----a-w- c:\users\Eileen\[00000001]\2013-10-08 22-33-09.m4a
2013-11-08 14:22 . 2013-11-08 14:22 1176663 ----a-w- c:\users\Eileen\[00000001]\2013-10-08 22-35-24.m4a
2013-11-08 14:22 . 2013-11-08 14:22 18337139 ----a-w- c:\users\Eileen\[00000001]\2013-10-08 22-38-02.m4a
2013-11-08 14:21 . 2013-11-08 14:21 8973217 ----a-w- c:\users\Eileen\[00000001]\2013-10-08 23-41-59.m4a
2013-11-08 14:21 . 2013-11-08 14:21 13486124 ----a-w- c:\users\Eileen\[00000001]\2013-10-08 23-14-52.m4a
2013-11-08 14:20 . 2013-11-08 14:20 3612223 ----a-w- c:\users\Eileen\[00000001]\2013-10-09 00-27-45.m4a
.
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown 
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{872b5b88-9db5-4310-bdd0-ac189557e5f5}"= "c:\program files\DVDVideoSoftTB\tbDVDV.dll" [2010-04-27 2393184]
.
[HKEY_CLASSES_ROOT\clsid\{872b5b88-9db5-4310-bdd0-ac189557e5f5}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{872b5b88-9db5-4310-bdd0-ac189557e5f5}]
2010-04-27 02:08 2393184 ----a-w- c:\program files\DVDVideoSoftTB\tbDVDV.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{872b5b88-9db5-4310-bdd0-ac189557e5f5}"= "c:\program files\DVDVideoSoftTB\tbDVDV.dll" [2010-04-27 2393184]
.
[HKEY_CLASSES_ROOT\clsid\{872b5b88-9db5-4310-bdd0-ac189557e5f5}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{872B5B88-9DB5-4310-BDD0-AC189557E5F5}"= "c:\program files\DVDVideoSoftTB\tbDVDV.dll" [2010-04-27 2393184]
.
[HKEY_CLASSES_ROOT\clsid\{872b5b88-9db5-4310-bdd0-ac189557e5f5}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"eMuleAutoStart"="c:\program files\eMule\emule.exe" [2010-04-07 5758976]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-23 13539872]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2008-04-15 442433]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-04-16 178712]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-12-24 222504]
"DpAgent"="c:\program files\DigitalPersona\Bin\dpagent.exe" [2008-03-13 699456]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-03-14 202032]
"OnScreenDisplay"="c:\program files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe" [2007-11-02 554288]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-11-20 488752]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="f:\gmail notifier\gnotify.exe" [2005-07-15 479232]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-06-16 75008]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-01-18 1033512]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2008-04-24 468264]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-23 92704]
"HP Software Update"="f:\hp\HP Software Update\HPWuSchd2.exe" [2006-12-10 49152]
"Grid Service"="c:\program files\GridService\peer.exe" [2008-12-30 4993024]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-13 611712]
"Adobe Acrobat Speed Launcher"="f:\adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2008-06-11 37232]
"Acrobat Assistant 8.0"="f:\adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2008-06-11 640376]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-11-28 59280]
"QuickTime Task"="f:\quicktime\QTTask.exe" [2012-04-18 421888]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2013-11-19 683576]
"iTunesHelper"="f:\itunes\iTunesHelper.exe" [2012-12-12 152544]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-05-11 958576]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2013-03-11 253816]
.
c:\users\Eileen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - g:\office12\ONENOTEM.EXE /tsr [2009-2-26 97680]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-11-11 113664]
HP Digital Imaging Monitor.lnk - f:\hp\Digital Imaging\bin\hpqtra08.exe [2007-1-2 210520]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer4"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ   scecli DPPWDFLT
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
backup=c:\windows\pss\Bluetooth.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^Users^Eileen^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Orbit.lnk]
path=c:\users\Eileen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Orbit.lnk
backup=c:\windows\pss\Orbit.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2012-12-12 05:57 152544 ----a-w- f:\itunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
2008-02-26 21:08 2289664 ----a-w- c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1630263006-122845437-3975794864-1003]
"EnableNotificationsRef"=dword:00000001
.
R3 Adobe Version Cue CS4;Adobe Version Cue CS4;c:\program files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [2008-08-14 284016]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_030ac640\aestsrv.exe [2008-02-12 73728]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ   BthServ
HPZ12 REG_MULTI_SZ   Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ   hpqcxs08 hpqddsvc
HPService REG_MULTI_SZ   HPSLPSVC
XLServicePlatform REG_MULTI_SZ   XLServicePlatform
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-02-26 21:06 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
.
2013-11-19 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-05 03:09]
.
2013-11-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1630263006-122845437-3975794864-1003Core.job
- c:\users\Eileen\AppData\Local\Google\Update\GoogleUpdate.exe [2012-06-17 07:19]
.
2013-11-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1630263006-122845437-3975794864-1003UA.job
- c:\users\Eileen\AppData\Local\Google\Update\GoogleUpdate.exe [2012-06-17 07:19]
.
2013-11-19 c:\windows\Tasks\User_Feed_Synchronization-{66A95A41-F5D3-46ED-876C-E78DF0ECA6FD}.job
- c:\windows\system32\msfeedssync.exe [2011-06-16 04:32]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.sg/
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_sg&c=83&bd=Pavilion&pf=cnnb
uInternet Settings,ProxyOverride = local;*.local
uInternet Settings,ProxyServer = socks=127.0.0.1:4021;
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Download by Orbit - f:\orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - f:\orbitdownloader\orbitmxt.dll/204
IE: &U????????? - f:\namirobot\Data\du.html
IE: &ʹÓÃÓŵ°ÏÂÔØ - f:\udown\getUrl.htm
IE: &ʹÓÃÓŵ°ÏÂÔØÈ«²¿Á´½Ó - f:\udown\getAllUrl.htm
IE: &??115???? - c:\users\Eileen\AppData\Roaming\115\UDown\getUrl.htm
IE: &??115???????? - c:\users\Eileen\AppData\Roaming\115\UDown\getAllUrl.htm
IE: Add to Evernote 4.0 - c:\program files\Evernote\Evernote\EvernoteIE.dll/204
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Do&wnload selected by Orbit - f:\orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - f:\orbitdownloader\orbitmxt.dll/202
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Free YouTube Download - c:\users\Eileen\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm
IE: Free YouTube to MP3 Converter - c:\users\Eileen\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: use Thunderbolt download - f:\thunder network\Thunder\Program\GetUrl.htm
IE: use Xunlei download all the links - f:\thunder network\Thunder\Program\GetAllUrl.htm
IE: {{09BA8F6D-CB54-424B-839C-C2A6C8E6B436}
Trusted Zone: 111222.cn\list1
Trusted Zone: pps.tv\kan
Trusted Zone: pps.tv\list1
Trusted Zone: pps.tv\tvguide
Trusted Zone: pps.tv\vodguide
Trusted Zone: ppstream.com\list1
Trusted Zone: ppstream.com\notice
Trusted Zone: ppstream.com\xml1
Trusted Zone: ppstream.com\xml2
Trusted Zone: ppstream.com\xml3
Trusted Zone: ppstream.net\list1
Trusted Zone: ppstv.com\list1
Trusted Zone: ppstv.net\list1
Trusted Zone: security_PPStream.exe
Trusted Zone: gogobox.com.tw
Trusted Zone: qq.com\cache.tv
Trusted Zone: qq.com\qqlivecaption
Trusted Zone: qq.com\qqlivehabit
Trusted Zone: qq.com\qqlivesearch
Trusted Zone: qq.com\video_1
TCP: DhcpNameServer = 192.168.1.254
Handler: CDS300 - {AD43AA67-6860-4531-AC8A-0E68F9CF023E} - 
DPF: {8B9230ED-5766-43C9-855B-E742B0B2E871} - hxxp://www.servicemanager.co.kr/ocx/servicemanagerdx2.ocx
FF - ProfilePath - c:\users\Eileen\AppData\Roaming\Mozilla\Firefox\Profiles\xkfmli2b.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.sg/
FF - prefs.js: network.proxy.http - 198.7.242.41
FF - prefs.js: network.proxy.http_port - 3127
FF - prefs.js: network.proxy.type - 0
FF - user.js: extensions.BabylonToolbar_i.id - 274f4e6d0000000000000016eabd2bce
FF - user.js: extensions.BabylonToolbar_i.hardId - 274f4e6d0000000000000016eabd2bce
FF - user.js: extensions.BabylonToolbar_i.instlDay - 15443
FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1716:43
FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar_i.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar_i.tlbrId - base
FF - user.js: extensions.BabylonToolbar_i.newTab - false
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=110854
FF - user.js: extensions.BabylonToolbar_i.babExt - 
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.BabylonToolbar_i.instlRef - sst
FF - user.js: extensions.claro.tlbrSrchUrl - 
FF - user.js: extensions.claro.id - 274f4e6d0000000000000016eabd2bce
FF - user.js: extensions.claro.appId - {C3110516-8EFC-49D6-8B72-69354F332062}
FF - user.js: extensions.claro.instlDay - 15663
FF - user.js: extensions.claro.vrsn - 1.8.3.10
FF - user.js: extensions.claro.vrsni - 1.8.3.10
FF - user.js: extensions.claro_i.vrsnTs - 1.8.3.100:08
FF - user.js: extensions.claro.prtnrId - claro
FF - user.js: extensions.claro.prdct - claro
FF - user.js: extensions.claro.aflt - babsst
FF - user.js: extensions.claro_i.smplGrp - none
FF - user.js: extensions.claro.tlbrId - base
FF - user.js: extensions.claro.instlRef - sst
FF - user.js: extensions.claro.dfltLng - en
FF - user.js: extensions.claro.excTlbr - false
FF - user.js: extensions.claro.admin - false
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-11-19 23:04
Windows 6.0.6001 Service Pack 1 NTFS
.
scanning hidden processes ...  
.
scanning hidden autostart entries ... 
.
scanning hidden files ...  
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*B*D*ýV¤|ÌSí‹-NW[\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*c*o*m*ÿ,{4*5*J\~vó`z‚/g'YO ÿ]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*c*o*m*ÿ,{4*5*J\~vó`z‚/g'YO ÿ\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*Y*Y*c*a*F*-N‡eûÑ‹Hr,g\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*[*9\i`à`-N‡eQ6R]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*[*9\i`à`-N‡eQ6R\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*[*é—gRíp¿~6R\O]*]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*[*é—gRíp¿~6R\O]*\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*-Nñ‚W[U^]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*-Nñ‚W[U^\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*hQ:W-NW[]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*hQ:W-NW[\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.* R•Hr1*1*8*RŸ”\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*ýV¤|ÌSí‹]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*ýV¤|ÌSí‹\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*ýV¤|ÌSí‹-NW[]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*ýV¤|ÌSí‹-NW[\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*ù[bô‹ŒÕ‹Õ‹]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*ù[bô‹ŒÕ‹Õ‹\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*¥bSù[bô‹ŒÕ‹Õ‹9\i`à`ïSPN;T]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*¥bSù[bô‹ŒÕ‹Õ‹9\i`à`ïSPN;T\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*nmÎW'Y¨N]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*nmÎW'Y¨N\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*nmÎWŒ‹N]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*nmÎWŒ‹N\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\. ,{2 9 ãN[ 
N] [ Ó—žŠ!qW[] ]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\. ,{2 9 ãN[ 
N] [ Ó—žŠ!qW[] \OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*,{2*9*ãN[*N]*[*Ó—žŠ!qW[]*]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*,{2*9*ãN[*N]*[*Ó—žŠ!qW[]*\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\. ,{3 1 ãN[ 
N] [ Ó—žŠ!qW[] ]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\. ,{3 1 ãN[ 
N] [ Ó—žŠ!qW[] \OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*,{3*1*ãN[*N]*[*Ó—žŠ!qW[]*]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*,{3*1*ãN[*N]*[*Ó—žŠ!qW[]*\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*,{3*1*ãN[*-N]*[*Ó—žŠ!qW[]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*,{3*1*ãN[*-N]*[*Ó—žŠ!qW[\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*,{3*3*g]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*,{3*3*g\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*€{ŽYL*I*V*E*\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.*[*9\i`à`-N‡eQ6R]
@Allowed: (Read) (RestrictedCode)
"MRUListEx"=hex:00,00,00,00,ff,ff,ff,ff
"0"=hex:30,00,34,00,34,00,2e,00,5b,00,59,00,6f,00,6f,00,6e,00,45,00,75,00,6e,
   00,48,00,79,00,65,00,2e,00,43,00,4e,00,5d,00,2e,00,42,00,61,00,62,00,79,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'lsass.exe'(736)
c:\windows\system32\DPPWDFLT.dll
.
- - - - - - - > 'Explorer.exe'(5112)
c:\program files\DigitalPersona\Bin\DpoFeedb.dll
.
Completion time: 2013-11-19  23:06:15
ComboFix-quarantined-files.txt  2013-11-19 15:06
ComboFix2.txt  2013-11-19 11:34
.
Pre-Run: 36,810,571,776 bytes free
Post-Run: 36,843,429,888 bytes free
.
- - End Of File - - 04948E2D93CAD7CA50FD8092149BEC42
85D751F0E41B8E520AEE8C07A8DA777B


#8 ----------------

----------------

    SuperMember

  • Authentic Member
  • PipPipPipPipPip
  • 1,095 posts

Posted 19 November 2013 - 09:59 AM

did you create this folder with its content?

 

 

 

---- Directory of c:\users\Eileen\[00000001] ----
.
2013-11-08 14:22 . 2013-11-08 14:22 14401861 ----a-w- c:\users\Eileen\[00000001]\2013-10-08 00-01-43.m4a
2013-11-08 14:22 . 2013-11-08 14:22 3342579 ----a-w- c:\users\Eileen\[00000001]\2013-10-08 01-20-29.m4a
2013-11-08 14:22 . 2013-11-08 14:22 895456 ----a-w- c:\users\Eileen\[00000001]\2013-10-08 22-33-09.m4a
2013-11-08 14:22 . 2013-11-08 14:22 1176663 ----a-w- c:\users\Eileen\[00000001]\2013-10-08 22-35-24.m4a
2013-11-08 14:22 . 2013-11-08 14:22 18337139 ----a-w- c:\users\Eileen\[00000001]\2013-10-08 22-38-02.m4a
2013-11-08 14:21 . 2013-11-08 14:21 8973217 ----a-w- c:\users\Eileen\[00000001]\2013-10-08 23-41-59.m4a
2013-11-08 14:21 . 2013-11-08 14:21 13486124 ----a-w- c:\users\Eileen\[00000001]\2013-10-08 23-14-52.m4a
2013-11-08 14:20 . 2013-11-08 14:20 3612223 ----a-w- c:\users\Eileen\[00000001]\2013-10-09 00-27-45.m4a

Proud Member of UNITE & TB
 

#9 e_smurfs

e_smurfs

    New Member

  • Authentic Member
  • Pip
  • 13 posts

Posted 19 November 2013 - 10:18 AM

Hi, 

I did not create this folder. However I recalled few days back I tried to recover these few audio files which I accidentally deleted. 

Perhaps this folder was created by the recovery program then without my knowledge.



#10 ----------------

----------------

    SuperMember

  • Authentic Member
  • PipPipPipPipPip
  • 1,095 posts

Posted 20 November 2013 - 02:17 AM

Ok, are you from singapore?


Proud Member of UNITE & TB
 

    Advertisements

Register to Remove


#11 e_smurfs

e_smurfs

    New Member

  • Authentic Member
  • Pip
  • 13 posts

Posted 20 November 2013 - 03:00 AM

yup I am.



#12 ----------------

----------------

    SuperMember

  • Authentic Member
  • PipPipPipPipPip
  • 1,095 posts

Posted 20 November 2013 - 03:18 AM

Combofix scripting

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Download the attached CFScript.txt and save it to the location where Combofix is.


CFScriptB-4.gif


Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

Attached Files


Proud Member of UNITE & TB
 

#13 e_smurfs

e_smurfs

    New Member

  • Authentic Member
  • Pip
  • 13 posts

Posted 20 November 2013 - 03:59 AM

Here is the Combofix.txt:

 

ComboFix 13-11-19.01 - Eileen 20/11/2013  17:41:42.3.2 - x86

Microsoft® Windows Vista™ Home Premium   6.0.6001.1.1252.65.1033.18.3068.1745 [GMT 8:00]
Running from: c:\users\Eileen\Desktop\ComboFix.exe
Command switches used :: c:\users\Eileen\Desktop\CFScript.txt
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\DVDVideoSoftTB
c:\program files\DVDVideoSoftTB\DVDVideoSoftTBToolbarHelper.exe
c:\program files\DVDVideoSoftTB\INSTALL.LOG
c:\program files\DVDVideoSoftTB\tbDVDV.dll
c:\program files\DVDVideoSoftTB\toolbar.cfg
c:\program files\DVDVideoSoftTB\UNWISE.EXE
f:\orbitdownloader
f:\orbitdownloader\addons\nporbit.dll
f:\orbitdownloader\addons\OneClickYouTubeDownloader\chrome.manifest
f:\orbitdownloader\addons\OneClickYouTubeDownloader\chrome\grabpro.jar
f:\orbitdownloader\addons\OneClickYouTubeDownloader\components\GrabKernel.dll
f:\orbitdownloader\addons\OneClickYouTubeDownloader\components\GrabXpcom.dll
f:\orbitdownloader\addons\OneClickYouTubeDownloader\components\GrabXpcom.xpt
f:\orbitdownloader\addons\OneClickYouTubeDownloader\components\winfile.dll
f:\orbitdownloader\addons\OneClickYouTubeDownloader\install.rdf
f:\orbitdownloader\addons\orbitff\chrome.manifest
f:\orbitdownloader\addons\orbitff\chrome\orbit.jar
f:\orbitdownloader\addons\orbitff\install.rdf
f:\orbitdownloader\banurl.ini
f:\orbitdownloader\changelog.txt
f:\orbitdownloader\download.dll
f:\orbitdownloader\gdiplus.dll
f:\orbitdownloader\Grab.exe
f:\orbitdownloader\GrabDll.dll
f:\orbitdownloader\GrabKernel.dll
f:\orbitdownloader\GrabPro.dll
f:\orbitdownloader\GrabVideo.exe
f:\orbitdownloader\idht.dll
f:\orbitdownloader\image\12.png
f:\orbitdownloader\image\askBtn.png
f:\orbitdownloader\image\backImg.png
f:\orbitdownloader\image\clientBack.png
f:\orbitdownloader\image\clientImg.png
f:\orbitdownloader\image\closeBtn.png
f:\orbitdownloader\image\configBtn.png
f:\orbitdownloader\image\defBtn.png
f:\orbitdownloader\image\handDown.png
f:\orbitdownloader\image\handUp.png
f:\orbitdownloader\image\logoImg.png
f:\orbitdownloader\image\maxBtn.png
f:\orbitdownloader\image\minBtn.png
f:\orbitdownloader\image\no_icon.ico
f:\orbitdownloader\image\refreshBtn.png
f:\orbitdownloader\image\ScrollBar.png
f:\orbitdownloader\image\searchClearBtn.png
f:\orbitdownloader\image\searchClearBtns.png
f:\orbitdownloader\image\searchInput.png
f:\orbitdownloader\image\searchTypeBtn.png
f:\orbitdownloader\image\searchTypeBtns.png
f:\orbitdownloader\image\softInfoBack.png
f:\orbitdownloader\image\softInfoBk.png
f:\orbitdownloader\image\softListBack.png
f:\orbitdownloader\image\softTitleImg.png
f:\orbitdownloader\image\SortDown.png
f:\orbitdownloader\image\SortNomal.png
f:\orbitdownloader\image\SortUp.png
f:\orbitdownloader\image\tabBtn1.png
f:\orbitdownloader\image\tabBtn1s.png
f:\orbitdownloader\image\tabBtn2.png
f:\orbitdownloader\image\tabBtn2s.png
f:\orbitdownloader\image\titleImg.png
f:\orbitdownloader\image\titleLineBoder.png
f:\orbitdownloader\image\userName.png
f:\orbitdownloader\image\visitBtn.png
f:\orbitdownloader\image\voteImg.png
f:\orbitdownloader\image\voteName.png
f:\orbitdownloader\image\wait.gif
f:\orbitdownloader\image\wait.html
f:\orbitdownloader\image\waitupdata.gif
f:\orbitdownloader\image\writeBtn.png
f:\orbitdownloader\Lang.ini
f:\orbitdownloader\language\obafr.ini
f:\orbitdownloader\language\obara.ini
f:\orbitdownloader\language\obbgr.ini
f:\orbitdownloader\language\obcat.ini
f:\orbitdownloader\language\obchs.ini
f:\orbitdownloader\language\obchs.ini~
f:\orbitdownloader\language\obcht.ini
f:\orbitdownloader\language\obcsy.ini
f:\orbitdownloader\language\obdeu.ini
f:\orbitdownloader\language\obell.ini
f:\orbitdownloader\language\obeng.ini
f:\orbitdownloader\language\obeng.ini~
f:\orbitdownloader\language\obesn.ini
f:\orbitdownloader\language\obeso.ini
f:\orbitdownloader\language\obesv.ini
f:\orbitdownloader\language\obfar.ini
f:\orbitdownloader\language\obfin.ini
f:\orbitdownloader\language\obfra.ini
f:\orbitdownloader\language\obheb.ini
f:\orbitdownloader\language\obhrv.ini
f:\orbitdownloader\language\obhun.ini
f:\orbitdownloader\language\obind.ini
f:\orbitdownloader\language\obita.ini
f:\orbitdownloader\language\objpn.ini
f:\orbitdownloader\language\obkor.ini
f:\orbitdownloader\language\obmki.ini
f:\orbitdownloader\language\obnld.ini
f:\orbitdownloader\language\obnor.ini
f:\orbitdownloader\language\obplk.ini
f:\orbitdownloader\language\obptb.ini
f:\orbitdownloader\language\obptg.ini
f:\orbitdownloader\language\obrom.ini
f:\orbitdownloader\language\obrus.ini
f:\orbitdownloader\language\obsky.ini
f:\orbitdownloader\language\obsqi.ini
f:\orbitdownloader\language\obsrb.ini
f:\orbitdownloader\language\obswe.ini
f:\orbitdownloader\language\obtha.ini
f:\orbitdownloader\language\obtrk.ini
f:\orbitdownloader\language\obukr.ini
f:\orbitdownloader\language\obvit.ini
f:\orbitdownloader\layout\client.xml
f:\orbitdownloader\layout\layerwnd.xml
f:\orbitdownloader\layout\main.xml
f:\orbitdownloader\libeay32.dll
f:\orbitdownloader\msvcp71.dll
f:\orbitdownloader\msvcr71.dll
f:\orbitdownloader\orbitcth.dll
f:\orbitdownloader\orbitdm.exe
f:\orbitdownloader\orbitmxt.dll
f:\orbitdownloader\orbitnet.exe
f:\orbitdownloader\orbitnet_AVG_RESTORED.exe
f:\orbitdownloader\saction.dll
f:\orbitdownloader\siteinfo.ini
f:\orbitdownloader\SoftUpdater.dll
f:\orbitdownloader\ssleay32.dll
f:\orbitdownloader\unins000.dat
f:\orbitdownloader\unins000.exe
f:\orbitdownloader\winfile.dll
f:\orbitdownloader\WinPcap_4_1_3.exe
f:\orbitdownloader\wtlctrl.dll
f:\orbitdownloader\xlayout.dll
.
.
(((((((((((((((((((((((((   Files Created from 2013-10-20 to 2013-11-20  )))))))))))))))))))))))))))))))
.
.
2013-11-20 09:52 . 2013-11-20 09:52 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-11-19 15:06 . 2013-11-20 09:52 -------- d-----w- c:\users\Eileen\AppData\Local\temp
2013-11-18 15:07 . 2013-11-18 15:07 -------- d-----w- C:\FRST
2013-11-15 01:55 . 2013-11-15 01:55 -------- d-----w- c:\users\Eileen\AppData\Roaming\Malwarebytes
2013-11-15 01:55 . 2013-11-15 01:55 -------- d-----w- c:\programdata\Malwarebytes
2013-11-15 01:55 . 2013-11-15 01:55 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2013-11-15 01:55 . 2013-04-04 06:50 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-11-11 05:33 . 2013-11-11 05:34 -------- d-----w- c:\users\Eileen\[00000001]
2013-11-10 08:53 . 2013-11-10 08:53 63920 ----a-w- c:\windows\system32\drivers\vmx_svga.sys
2013-11-10 08:53 . 2013-11-10 08:53 11696 ----a-w- c:\windows\system32\drivers\vmmouse.sys
2013-11-10 08:53 . 2013-11-10 08:53 117552 ----a-w- c:\windows\system32\drivers\vmhgfs.sys
2013-11-10 08:53 . 2013-11-10 08:53 19504 ----a-w- c:\windows\system32\drivers\vmdebug.sys
2013-11-10 08:53 . 2013-11-10 08:53 54960 ----a-w- c:\windows\system32\drivers\vmci.sys
2013-11-10 08:52 . 2013-11-10 08:53 25008 ----a-w- c:\windows\system32\drivers\vmaudio.sys
2013-11-10 08:52 . 2013-11-10 08:52 368749 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\TPWinPrn.dll
2013-11-10 08:52 . 2013-11-10 08:52 22528 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\jnwppr.dll
2013-11-10 08:51 . 2013-11-10 08:51 54784 ----a-w- c:\windows\system32\WsmProv.dll
2013-11-10 08:51 . 2013-11-10 08:51 1536 ----a-w- c:\windows\system32\WsmCl.dll
2013-11-10 08:51 . 2013-11-10 08:51 16432 ----a-w- c:\windows\system32\vmx_mode.dll
2013-11-10 08:51 . 2013-11-10 08:51 173232 ----a-w- c:\windows\system32\vmx_fb.dll
2013-11-10 08:51 . 2013-11-10 08:51 35888 ----a-w- c:\windows\system32\vmhgfs.dll
2013-11-10 08:51 . 2013-11-10 08:51 111856 ----a-w- c:\windows\system32\TPVMW32.dll
2013-11-10 08:51 . 2013-11-10 08:51 9104 ----a-w- c:\windows\system32\TPVMMonUIjpn.dll
2013-11-10 08:50 . 2013-11-10 08:51 9104 ----a-w- c:\windows\system32\TPVMMonUIdeu.dll
2013-11-10 08:50 . 2013-11-10 08:50 79208 ----a-w- c:\windows\system32\TPVMMonUI.dll
2013-11-10 08:50 . 2013-11-10 08:50 9632 ----a-w- c:\windows\system32\TPVMMonjpn.dll
2013-11-10 08:50 . 2013-11-10 08:50 23960 ----a-w- c:\windows\system32\TPVMMondeu.dll
2013-11-10 08:50 . 2013-11-10 08:50 284016 ----a-w- c:\windows\system32\TPVMMon.dll
2013-11-10 08:50 . 2013-11-10 08:50 423208 ----a-w- c:\windows\system32\TPSvc.dll
2013-11-10 08:50 . 2013-11-10 08:50 113664 ----a-w- c:\windows\system32\LANGWRBK.DLL
2013-11-10 08:50 . 2013-11-10 08:50 19968 ----a-w- c:\windows\system32\jnwmon.dll
2013-11-10 08:50 . 2013-11-10 08:50 78336 ----a-w- c:\windows\system32\ieencode.dll
2013-11-10 06:26 . 2013-11-10 06:27 289280 ----a-w- c:\windows\system32\StikyNot.exe
2013-11-10 06:26 . 2013-11-10 06:26 275968 ----a-w- c:\windows\system32\SnippingTool.exe
2013-11-10 06:19 . 2013-11-10 06:19 -------- d-----w- c:\programdata\Weskysoft
2013-11-10 02:34 . 2013-11-10 02:34 -------- d-----w- c:\program files\DLLSuite
2013-11-08 18:53 . 2013-11-08 19:01 -------- d-----w- c:\program files\DVDVideoSoft
2013-11-08 08:43 . 2013-11-08 19:01 -------- d-----w- c:\program files\Common Files\DVDVideoSoft
2013-11-02 01:33 . 2013-11-02 01:33 -------- d-----w- c:\programdata\Oracle
2013-10-23 07:17 . 2013-03-17 16:21 3649536 ----a-w- c:\windows\system32\x264vfw.dll
2013-10-23 07:17 . 2011-12-07 17:32 216064 ----a-w- c:\windows\system32\lagarith.dll
2013-10-23 07:17 . 2011-06-24 14:28 650752 ----a-w- c:\windows\system32\xvidcore.dll
2013-10-23 07:17 . 2012-07-21 10:54 122880 ----a-w- c:\windows\system32\ac3acm.acm
2013-10-23 07:17 . 2011-06-24 14:44 243200 ----a-w- c:\windows\system32\xvidvfw.dll
2013-10-23 07:17 . 2013-09-12 18:00 112640 ----a-w- c:\windows\system32\ff_vfw.dll
2013-10-23 07:17 . 2013-10-23 07:17 -------- d-----w- c:\program files\K-Lite Codec Pack
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-11-19 14:22 . 2012-12-18 02:56 37352 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2013-11-19 14:22 . 2012-12-18 02:56 90400 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2013-11-19 14:22 . 2012-12-18 02:56 137208 ----a-w- c:\windows\system32\drivers\avipbb.sys
2013-11-10 08:50 . 2013-11-10 08:50 2048 ----a-w- c:\windows\help\Tablet PC\TTRes.dll
2013-11-10 08:50 . 2013-11-10 08:50 2048 ----a-w- c:\windows\help\Tablet PC\PTRes.dll
2013-11-10 06:26 . 2013-11-10 06:26 159232 ----a-w- c:\windows\help\Tablet PC\TouchTraining.exe
2013-11-10 06:26 . 2013-11-10 06:25 231936 ----a-w- c:\windows\help\Tablet PC\PenTraining.exe
2013-10-10 03:09 . 2011-06-29 09:51 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-08-22 17:09 . 2010-03-22 13:23 217176 ----a-w- c:\windows\system32\unrar.dll
2009-05-04 05:14 . 2013-10-02 08:29 36864 ----a-w- c:\program files\mozilla firefox\components\NsThunderLoader.dll
2009-05-04 05:14 . 2013-10-02 08:29 53248 ----a-w- c:\program files\mozilla firefox\components\ThunderComponent.dll
.
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown 
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"eMuleAutoStart"="c:\program files\eMule\emule.exe" [2010-04-07 5758976]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-23 13539872]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2008-04-15 442433]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-04-16 178712]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-12-24 222504]
"DpAgent"="c:\program files\DigitalPersona\Bin\dpagent.exe" [2008-03-13 699456]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-03-14 202032]
"OnScreenDisplay"="c:\program files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe" [2007-11-02 554288]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-11-20 488752]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="f:\gmail notifier\gnotify.exe" [2005-07-15 479232]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-06-16 75008]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-01-18 1033512]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2008-04-24 468264]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-23 92704]
"HP Software Update"="f:\hp\HP Software Update\HPWuSchd2.exe" [2006-12-10 49152]
"Grid Service"="c:\program files\GridService\peer.exe" [2008-12-30 4993024]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-13 611712]
"Adobe Acrobat Speed Launcher"="f:\adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2008-06-11 37232]
"Acrobat Assistant 8.0"="f:\adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2008-06-11 640376]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-11-28 59280]
"QuickTime Task"="f:\quicktime\QTTask.exe" [2012-04-18 421888]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2013-11-19 683576]
"iTunesHelper"="f:\itunes\iTunesHelper.exe" [2012-12-12 152544]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-05-11 958576]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2013-03-11 253816]
.
c:\users\Eileen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - g:\office12\ONENOTEM.EXE /tsr [2009-2-26 97680]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-11-11 113664]
HP Digital Imaging Monitor.lnk - f:\hp\Digital Imaging\bin\hpqtra08.exe [2007-1-2 210520]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer4"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ   scecli DPPWDFLT
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
backup=c:\windows\pss\Bluetooth.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^Users^Eileen^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Orbit.lnk]
path=c:\users\Eileen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Orbit.lnk
backup=c:\windows\pss\Orbit.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2012-12-12 05:57 152544 ----a-w- f:\itunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
2008-02-26 21:08 2289664 ----a-w- c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1630263006-122845437-3975794864-1003]
"EnableNotificationsRef"=dword:00000001
.
R3 Adobe Version Cue CS4;Adobe Version Cue CS4;c:\program files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [2008-08-14 284016]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_030ac640\aestsrv.exe [2008-02-12 73728]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ   BthServ
HPZ12 REG_MULTI_SZ   Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ   hpqcxs08 hpqddsvc
HPService REG_MULTI_SZ   HPSLPSVC
XLServicePlatform REG_MULTI_SZ   XLServicePlatform
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-02-26 21:06 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
.
2013-11-20 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-05 03:09]
.
2013-11-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1630263006-122845437-3975794864-1003Core.job
- c:\users\Eileen\AppData\Local\Google\Update\GoogleUpdate.exe [2012-06-17 07:19]
.
2013-11-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1630263006-122845437-3975794864-1003UA.job
- c:\users\Eileen\AppData\Local\Google\Update\GoogleUpdate.exe [2012-06-17 07:19]
.
2013-11-20 c:\windows\Tasks\User_Feed_Synchronization-{66A95A41-F5D3-46ED-876C-E78DF0ECA6FD}.job
- c:\windows\system32\msfeedssync.exe [2011-06-16 04:32]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.sg/
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_sg&c=83&bd=Pavilion&pf=cnnb
uInternet Settings,ProxyOverride = local;*.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &U????????? - f:\namirobot\Data\du.html
IE: &??115???? - c:\users\Eileen\AppData\Roaming\115\UDown\getUrl.htm
IE: &??115???????? - c:\users\Eileen\AppData\Roaming\115\UDown\getAllUrl.htm
IE: Add to Evernote 4.0 - c:\program files\Evernote\Evernote\EvernoteIE.dll/204
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Free YouTube Download - c:\users\Eileen\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm
IE: Free YouTube to MP3 Converter - c:\users\Eileen\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {{09BA8F6D-CB54-424B-839C-C2A6C8E6B436}
TCP: DhcpNameServer = 202.156.1.16 218.186.2.16 218.186.2.6
FF - ProfilePath - c:\users\Eileen\AppData\Roaming\Mozilla\Firefox\Profiles\xkfmli2b.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.sg/
FF - prefs.js: network.proxy.http - 198.7.242.41
FF - prefs.js: network.proxy.http_port - 3127
FF - prefs.js: network.proxy.type - 0
.
- - - - ORPHANS REMOVED - - - -
.
AddRemove-DVDVideoSoftTB Toolbar - c:\progra~1\DVDVID~2\UNWISE.EXE
AddRemove-Orbit_is1 - f:\orbitdownloader\unins000.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-11-20 17:52
Windows 6.0.6001 Service Pack 1 NTFS
.
scanning hidden processes ...  
.
scanning hidden autostart entries ... 
.
scanning hidden files ...  
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*B*D*ýV¤|ÌSí‹-NW[\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*c*o*m*ÿ,{4*5*J\~vó`z‚/g'YO ÿ]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*c*o*m*ÿ,{4*5*J\~vó`z‚/g'YO ÿ\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*Y*Y*c*a*F*-N‡eûÑ‹Hr,g\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*[*9\i`à`-N‡eQ6R]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*[*9\i`à`-N‡eQ6R\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*[*é—gRíp¿~6R\O]*]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*[*é—gRíp¿~6R\O]*\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*-Nñ‚W[U^]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*-Nñ‚W[U^\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*hQ:W-NW[]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*hQ:W-NW[\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.* R•Hr1*1*8*RŸ”\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*ýV¤|ÌSí‹]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*ýV¤|ÌSí‹\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*ýV¤|ÌSí‹-NW[]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*ýV¤|ÌSí‹-NW[\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*ù[bô‹ŒÕ‹Õ‹]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*ù[bô‹ŒÕ‹Õ‹\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*¥bSù[bô‹ŒÕ‹Õ‹9\i`à`ïSPN;T]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*¥bSù[bô‹ŒÕ‹Õ‹9\i`à`ïSPN;T\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*nmÎW'Y¨N]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*nmÎW'Y¨N\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*nmÎWŒ‹N]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*nmÎWŒ‹N\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\. ,{2 9 ãN[ 
N] [ Ó—žŠ!qW[] ]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\. ,{2 9 ãN[ 
N] [ Ó—žŠ!qW[] \OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*,{2*9*ãN[*N]*[*Ó—žŠ!qW[]*]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*,{2*9*ãN[*N]*[*Ó—žŠ!qW[]*\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\. ,{3 1 ãN[ 
N] [ Ó—žŠ!qW[] ]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\. ,{3 1 ãN[ 
N] [ Ó—žŠ!qW[] \OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*,{3*1*ãN[*N]*[*Ó—žŠ!qW[]*]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*,{3*1*ãN[*N]*[*Ó—žŠ!qW[]*\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*,{3*1*ãN[*-N]*[*Ó—žŠ!qW[]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*,{3*1*ãN[*-N]*[*Ó—žŠ!qW[\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*,{3*3*g]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*,{3*3*g\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*€{ŽYL*I*V*E*\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.*[*9\i`à`-N‡eQ6R]
@Allowed: (Read) (RestrictedCode)
"MRUListEx"=hex:00,00,00,00,ff,ff,ff,ff
"0"=hex:30,00,34,00,34,00,2e,00,5b,00,59,00,6f,00,6f,00,6e,00,45,00,75,00,6e,
   00,48,00,79,00,65,00,2e,00,43,00,4e,00,5d,00,2e,00,42,00,61,00,62,00,79,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'lsass.exe'(732)
c:\windows\system32\DPPWDFLT.dll
.
Completion time: 2013-11-20  17:54:35
ComboFix-quarantined-files.txt  2013-11-20 09:54
ComboFix2.txt  2013-11-19 15:06
ComboFix3.txt  2013-11-19 11:34
.
Pre-Run: 34,722,861,056 bytes free
Post-Run: 34,720,497,664 bytes free
.
- - End Of File - - 711B491878F7BE6F49305F9B8EB9C403
85D751F0E41B8E520AEE8C07A8DA777B


#14 ----------------

----------------

    SuperMember

  • Authentic Member
  • PipPipPipPipPip
  • 1,095 posts

Posted 20 November 2013 - 06:28 AM

Combofix scripting

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Download the attached CFScript.txt and save it to the location where Combofix is.


CFScriptB-4.gif


Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

Attached Files


Proud Member of UNITE & TB
 

#15 e_smurfs

e_smurfs

    New Member

  • Authentic Member
  • Pip
  • 13 posts

Posted 20 November 2013 - 07:11 AM

Here the Combofix.txt:

 

ComboFix 13-11-19.01 - Eileen 20/11/2013  20:39:32.4.2 - x86

Microsoft® Windows Vista™ Home Premium   6.0.6001.1.1252.65.1033.18.3068.1537 [GMT 8:00]
Running from: c:\users\Eileen\Desktop\ComboFix.exe
Command switches used :: c:\users\Eileen\Desktop\CFScript.txt
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((   Files Created from 2013-10-20 to 2013-11-20  )))))))))))))))))))))))))))))))
.
.
2013-11-20 12:48 . 2013-11-20 12:48 -------- d-----w- c:\users\Eileen\AppData\Local\temp
2013-11-20 12:48 . 2013-11-20 12:48 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-11-18 15:07 . 2013-11-18 15:07 -------- d-----w- C:\FRST
2013-11-15 01:55 . 2013-11-15 01:55 -------- d-----w- c:\users\Eileen\AppData\Roaming\Malwarebytes
2013-11-15 01:55 . 2013-11-15 01:55 -------- d-----w- c:\programdata\Malwarebytes
2013-11-15 01:55 . 2013-11-15 01:55 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2013-11-15 01:55 . 2013-04-04 06:50 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-11-11 05:33 . 2013-11-11 05:34 -------- d-----w- c:\users\Eileen\[00000001]
2013-11-10 08:53 . 2013-11-10 08:53 63920 ----a-w- c:\windows\system32\drivers\vmx_svga.sys
2013-11-10 08:53 . 2013-11-10 08:53 11696 ----a-w- c:\windows\system32\drivers\vmmouse.sys
2013-11-10 08:53 . 2013-11-10 08:53 117552 ----a-w- c:\windows\system32\drivers\vmhgfs.sys
2013-11-10 08:53 . 2013-11-10 08:53 19504 ----a-w- c:\windows\system32\drivers\vmdebug.sys
2013-11-10 08:53 . 2013-11-10 08:53 54960 ----a-w- c:\windows\system32\drivers\vmci.sys
2013-11-10 08:52 . 2013-11-10 08:53 25008 ----a-w- c:\windows\system32\drivers\vmaudio.sys
2013-11-10 08:52 . 2013-11-10 08:52 368749 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\TPWinPrn.dll
2013-11-10 08:52 . 2013-11-10 08:52 22528 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\jnwppr.dll
2013-11-10 08:51 . 2013-11-10 08:51 54784 ----a-w- c:\windows\system32\WsmProv.dll
2013-11-10 08:51 . 2013-11-10 08:51 1536 ----a-w- c:\windows\system32\WsmCl.dll
2013-11-10 08:51 . 2013-11-10 08:51 16432 ----a-w- c:\windows\system32\vmx_mode.dll
2013-11-10 08:51 . 2013-11-10 08:51 173232 ----a-w- c:\windows\system32\vmx_fb.dll
2013-11-10 08:51 . 2013-11-10 08:51 35888 ----a-w- c:\windows\system32\vmhgfs.dll
2013-11-10 08:51 . 2013-11-10 08:51 111856 ----a-w- c:\windows\system32\TPVMW32.dll
2013-11-10 08:51 . 2013-11-10 08:51 9104 ----a-w- c:\windows\system32\TPVMMonUIjpn.dll
2013-11-10 08:50 . 2013-11-10 08:51 9104 ----a-w- c:\windows\system32\TPVMMonUIdeu.dll
2013-11-10 08:50 . 2013-11-10 08:50 79208 ----a-w- c:\windows\system32\TPVMMonUI.dll
2013-11-10 08:50 . 2013-11-10 08:50 9632 ----a-w- c:\windows\system32\TPVMMonjpn.dll
2013-11-10 08:50 . 2013-11-10 08:50 23960 ----a-w- c:\windows\system32\TPVMMondeu.dll
2013-11-10 08:50 . 2013-11-10 08:50 284016 ----a-w- c:\windows\system32\TPVMMon.dll
2013-11-10 08:50 . 2013-11-10 08:50 423208 ----a-w- c:\windows\system32\TPSvc.dll
2013-11-10 08:50 . 2013-11-10 08:50 113664 ----a-w- c:\windows\system32\LANGWRBK.DLL
2013-11-10 08:50 . 2013-11-10 08:50 19968 ----a-w- c:\windows\system32\jnwmon.dll
2013-11-10 08:50 . 2013-11-10 08:50 78336 ----a-w- c:\windows\system32\ieencode.dll
2013-11-10 06:26 . 2013-11-10 06:27 289280 ----a-w- c:\windows\system32\StikyNot.exe
2013-11-10 06:26 . 2013-11-10 06:26 275968 ----a-w- c:\windows\system32\SnippingTool.exe
2013-11-10 06:19 . 2013-11-10 06:19 -------- d-----w- c:\programdata\Weskysoft
2013-11-10 02:34 . 2013-11-10 02:34 -------- d-----w- c:\program files\DLLSuite
2013-11-08 18:53 . 2013-11-08 19:01 -------- d-----w- c:\program files\DVDVideoSoft
2013-11-08 08:43 . 2013-11-08 19:01 -------- d-----w- c:\program files\Common Files\DVDVideoSoft
2013-11-02 01:33 . 2013-11-02 01:33 -------- d-----w- c:\programdata\Oracle
2013-10-23 07:17 . 2013-03-17 16:21 3649536 ----a-w- c:\windows\system32\x264vfw.dll
2013-10-23 07:17 . 2011-12-07 17:32 216064 ----a-w- c:\windows\system32\lagarith.dll
2013-10-23 07:17 . 2011-06-24 14:28 650752 ----a-w- c:\windows\system32\xvidcore.dll
2013-10-23 07:17 . 2012-07-21 10:54 122880 ----a-w- c:\windows\system32\ac3acm.acm
2013-10-23 07:17 . 2011-06-24 14:44 243200 ----a-w- c:\windows\system32\xvidvfw.dll
2013-10-23 07:17 . 2013-09-12 18:00 112640 ----a-w- c:\windows\system32\ff_vfw.dll
2013-10-23 07:17 . 2013-10-23 07:17 -------- d-----w- c:\program files\K-Lite Codec Pack
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-11-19 14:22 . 2012-12-18 02:56 37352 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2013-11-19 14:22 . 2012-12-18 02:56 90400 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2013-11-19 14:22 . 2012-12-18 02:56 137208 ----a-w- c:\windows\system32\drivers\avipbb.sys
2013-11-10 08:50 . 2013-11-10 08:50 2048 ----a-w- c:\windows\help\Tablet PC\TTRes.dll
2013-11-10 08:50 . 2013-11-10 08:50 2048 ----a-w- c:\windows\help\Tablet PC\PTRes.dll
2013-11-10 06:26 . 2013-11-10 06:26 159232 ----a-w- c:\windows\help\Tablet PC\TouchTraining.exe
2013-11-10 06:26 . 2013-11-10 06:25 231936 ----a-w- c:\windows\help\Tablet PC\PenTraining.exe
2013-10-10 03:09 . 2011-06-29 09:51 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-08-22 17:09 . 2010-03-22 13:23 217176 ----a-w- c:\windows\system32\unrar.dll
2009-05-04 05:14 . 2013-10-02 08:29 36864 ----a-w- c:\program files\mozilla firefox\components\NsThunderLoader.dll
2009-05-04 05:14 . 2013-10-02 08:29 53248 ----a-w- c:\program files\mozilla firefox\components\ThunderComponent.dll
.
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown 
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"eMuleAutoStart"="c:\program files\eMule\emule.exe" [2010-04-07 5758976]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-23 13539872]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2008-04-15 442433]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-04-16 178712]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-12-24 222504]
"DpAgent"="c:\program files\DigitalPersona\Bin\dpagent.exe" [2008-03-13 699456]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-03-14 202032]
"OnScreenDisplay"="c:\program files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe" [2007-11-02 554288]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-11-20 488752]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="f:\gmail notifier\gnotify.exe" [2005-07-15 479232]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-06-16 75008]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-01-18 1033512]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2008-04-24 468264]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-23 92704]
"HP Software Update"="f:\hp\HP Software Update\HPWuSchd2.exe" [2006-12-10 49152]
"Grid Service"="c:\program files\GridService\peer.exe" [2008-12-30 4993024]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-13 611712]
"Adobe Acrobat Speed Launcher"="f:\adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2008-06-11 37232]
"Acrobat Assistant 8.0"="f:\adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2008-06-11 640376]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-11-28 59280]
"QuickTime Task"="f:\quicktime\QTTask.exe" [2012-04-18 421888]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2013-11-19 683576]
"iTunesHelper"="f:\itunes\iTunesHelper.exe" [2012-12-12 152544]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-05-11 958576]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2013-03-11 253816]
.
c:\users\Eileen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - g:\office12\ONENOTEM.EXE /tsr [2009-2-26 97680]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-11-11 113664]
HP Digital Imaging Monitor.lnk - f:\hp\Digital Imaging\bin\hpqtra08.exe [2007-1-2 210520]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer4"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ   scecli DPPWDFLT
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
backup=c:\windows\pss\Bluetooth.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^Users^Eileen^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Orbit.lnk]
path=c:\users\Eileen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Orbit.lnk
backup=c:\windows\pss\Orbit.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2012-12-12 05:57 152544 ----a-w- f:\itunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
2008-02-26 21:08 2289664 ----a-w- c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1630263006-122845437-3975794864-1003]
"EnableNotificationsRef"=dword:00000001
.
R3 Adobe Version Cue CS4;Adobe Version Cue CS4;c:\program files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [2008-08-14 284016]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_030ac640\aestsrv.exe [2008-02-12 73728]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ   BthServ
HPZ12 REG_MULTI_SZ   Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ   hpqcxs08 hpqddsvc
HPService REG_MULTI_SZ   HPSLPSVC
XLServicePlatform REG_MULTI_SZ   XLServicePlatform
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-02-26 21:06 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
.
2013-11-20 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-05 03:09]
.
2013-11-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1630263006-122845437-3975794864-1003Core.job
- c:\users\Eileen\AppData\Local\Google\Update\GoogleUpdate.exe [2012-06-17 07:19]
.
2013-11-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1630263006-122845437-3975794864-1003UA.job
- c:\users\Eileen\AppData\Local\Google\Update\GoogleUpdate.exe [2012-06-17 07:19]
.
2013-11-20 c:\windows\Tasks\User_Feed_Synchronization-{66A95A41-F5D3-46ED-876C-E78DF0ECA6FD}.job
- c:\windows\system32\msfeedssync.exe [2011-06-16 04:32]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.sg/
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_sg&c=83&bd=Pavilion&pf=cnnb
uInternet Settings,ProxyOverride = local;*.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &U????????? - f:\namirobot\Data\du.html
IE: &??115???? - c:\users\Eileen\AppData\Roaming\115\UDown\getUrl.htm
IE: &??115???????? - c:\users\Eileen\AppData\Roaming\115\UDown\getAllUrl.htm
IE: Add to Evernote 4.0 - c:\program files\Evernote\Evernote\EvernoteIE.dll/204
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Free YouTube Download - c:\users\Eileen\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm
IE: Free YouTube to MP3 Converter - c:\users\Eileen\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {{09BA8F6D-CB54-424B-839C-C2A6C8E6B436}
TCP: DhcpNameServer = 202.156.1.16 218.186.2.16 218.186.2.6
FF - ProfilePath - c:\users\Eileen\AppData\Roaming\Mozilla\Firefox\Profiles\xkfmli2b.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.sg/
FF - prefs.js: network.proxy.http - 198.7.242.41
FF - prefs.js: network.proxy.http_port - 3127
FF - prefs.js: network.proxy.type - 0
.
.
**************************************************************************
scanning hidden processes ...  
.
scanning hidden autostart entries ... 
.
scanning hidden files ...  
.
scan completed successfully
hidden files: 
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*B*D*ýV¤|ÌSí‹-NW[\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*c*o*m*ÿ,{4*5*J\~vó`z‚/g'YO ÿ]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*c*o*m*ÿ,{4*5*J\~vó`z‚/g'YO ÿ\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*Y*Y*c*a*F*-N‡eûÑ‹Hr,g\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*[*9\i`à`-N‡eQ6R]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*[*9\i`à`-N‡eQ6R\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*[*é—gRíp¿~6R\O]*]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*[*é—gRíp¿~6R\O]*\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*-Nñ‚W[U^]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*-Nñ‚W[U^\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*hQ:W-NW[]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*hQ:W-NW[\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.* R•Hr1*1*8*RŸ”\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*ýV¤|ÌSí‹]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*ýV¤|ÌSí‹\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*ýV¤|ÌSí‹-NW[]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*ýV¤|ÌSí‹-NW[\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*ù[bô‹ŒÕ‹Õ‹]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*ù[bô‹ŒÕ‹Õ‹\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*¥bSù[bô‹ŒÕ‹Õ‹9\i`à`ïSPN;T]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*¥bSù[bô‹ŒÕ‹Õ‹9\i`à`ïSPN;T\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*nmÎW'Y¨N]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*nmÎW'Y¨N\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*nmÎWŒ‹N]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*nmÎWŒ‹N\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\. ,{2 9 ãN[ 
N] [ Ó—žŠ!qW[] ]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\. ,{2 9 ãN[ 
N] [ Ó—žŠ!qW[] \OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*,{2*9*ãN[*N]*[*Ó—žŠ!qW[]*]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*,{2*9*ãN[*N]*[*Ó—žŠ!qW[]*\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\. ,{3 1 ãN[ 
N] [ Ó—žŠ!qW[] ]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\. ,{3 1 ãN[ 
N] [ Ó—žŠ!qW[] \OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*,{3*1*ãN[*N]*[*Ó—žŠ!qW[]*]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*,{3*1*ãN[*N]*[*Ó—žŠ!qW[]*\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*,{3*1*ãN[*-N]*[*Ó—žŠ!qW[]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*,{3*1*ãN[*-N]*[*Ó—žŠ!qW[\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*,{3*3*g]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*,{3*3*g\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*€{ŽYL*I*V*E*\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1630263006-122845437-3975794864-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.*[*9\i`à`-N‡eQ6R]
@Allowed: (Read) (RestrictedCode)
"MRUListEx"=hex:00,00,00,00,ff,ff,ff,ff
"0"=hex:30,00,34,00,34,00,2e,00,5b,00,59,00,6f,00,6f,00,6e,00,45,00,75,00,6e,
   00,48,00,79,00,65,00,2e,00,43,00,4e,00,5d,00,2e,00,42,00,61,00,62,00,79,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'lsass.exe'(732)
c:\windows\system32\DPPWDFLT.dll
.
- - - - - - - > 'Explorer.exe'(5600)
c:\program files\DigitalPersona\Bin\DpoFeedb.dll
.
Completion time: 2013-11-20  20:50:08
ComboFix-quarantined-files.txt  2013-11-20 12:50
ComboFix2.txt  2013-11-20 09:54
ComboFix3.txt  2013-11-19 15:06
ComboFix4.txt  2013-11-19 11:34
.
Pre-Run: 34,754,265,088 bytes free
Post-Run: 34,718,932,992 bytes free
.
- - End Of File - - 584BA4B0E6E19A07936DD7AC132448C8
85D751F0E41B8E520AEE8C07A8DA777B

Related Topics




Also tagged with one or more of these keywords: Computer Hang, Computer Freeze, Antivirus scan, Malware scan, pc hang, pc freeze, PC crash, Computer crash

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users