Computer started crashing after clicking a link on the net

Solved
By Pete26
Oct 19, 2012
  1. Pete26

    Pete26 Newcomer, in training Topic Starter Posts: 30

    Could see your intstructions more clearly after getting some sleep. The "Illegal operation atttempted on a registry key that has been marked for deletion", disappeared after machine was restarted. Could not feel any issues with the machine - no uninvited pop ups, blue screen or misdirected to wrong web pages from google results, which were experienec earlier.
    Attached below are the OTL logs:

    OTL logfile created on: 10/21/2012 6:35:32 PM - Run 1
    OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Pradeep\Desktop
    64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
    Internet Explorer (Version = 9.0.8112.16421)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    2.00 Gb Total Physical Memory | 1.22 Gb Available Physical Memory | 61.03% Memory free
    4.00 Gb Paging File | 2.71 Gb Available in Paging File | 67.75% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
    Drive C: | 226.40 Gb Total Space | 135.14 Gb Free Space | 59.69% Space Free | Partition Type: NTFS
    Drive D: | 232.88 Gb Total Space | 209.72 Gb Free Space | 90.06% Space Free | Partition Type: NTFS
    Drive E: | 6.48 Gb Total Space | 0.87 Gb Free Space | 13.47% Space Free | Partition Type: NTFS

    Computer Name: PRADEEPS-PC | User Name: Pradeep | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
    Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

    ========== Processes (SafeList) ==========

    PRC - [2012/10/21 18:33:10 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Pradeep\Desktop\OTL.exe
    PRC - [2012/09/27 07:37:12 | 003,532,224 | ---- | M] (Tonec Inc.) -- C:\Program Files (x86)\Internet Download Manager\IDMan.exe
    PRC - [2012/07/27 15:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
    PRC - [2012/06/15 21:24:19 | 000,138,272 | R--- | M] (Symantec Corporation) -- C:\Program Files (x86)\Norton 360\Engine\6.4.0.9\ccsvchst.exe
    PRC - [2011/05/10 10:48:58 | 001,466,144 | ---- | M] (Nuance Communications, Inc.) -- C:\Program Files (x86)\Nuance\OmniPage18\omnipage.exe
    PRC - [2010/05/25 07:28:58 | 000,263,600 | ---- | M] (Tonec Inc.) -- C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
    PRC - [2010/05/21 13:40:26 | 000,324,976 | ---- | M] (Flexera Software, Inc.) -- C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe
    PRC - [2008/11/09 15:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
    PRC - [2008/06/10 04:27:04 | 000,144,784 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\Java\jre1.6.0_07\bin\jusched.exe


    ========== Modules (No Company Name) ==========

    MOD - [2012/02/20 21:29:04 | 000,087,912 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
    MOD - [2012/02/20 21:28:42 | 001,242,472 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
    MOD - [2011/06/17 11:46:04 | 008,626,176 | ---- | M] () -- C:\Program Files (x86)\Common Files\LightScribe\QtGui4.dll
    MOD - [2011/06/17 11:46:02 | 002,408,448 | ---- | M] () -- C:\Program Files (x86)\Common Files\LightScribe\QtCore4.dll
    MOD - [2011/06/17 11:46:02 | 000,212,992 | ---- | M] () -- C:\Program Files (x86)\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll


    ========== Services (SafeList) ==========

    SRV:64bit: - [2011/08/11 18:38:04 | 000,140,672 | ---- | M] (SUPERAntiSpyware.com) [Auto | Running] -- C:\Program Files\SUPERAntiSpyware\SASCore64.exe -- (!SASCORE)
    SRV:64bit: - [2009/07/13 20:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
    SRV:64bit: - [2009/07/13 20:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
    SRV - [2012/07/27 15:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
    SRV - [2012/06/15 21:24:19 | 000,138,272 | R--- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files (x86)\Norton 360\Engine\6.4.0.9\ccSvcHst.exe -- (N360)
    SRV - [2012/04/22 18:58:20 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
    SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
    SRV - [2010/02/19 13:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
    SRV - [2009/06/10 16:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
    SRV - [2008/11/09 15:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)


    ========== Driver Services (SafeList) ==========

    DRV:64bit: - [2012/09/27 13:07:26 | 000,160,992 | ---- | M] (Tonec Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\idmwfp.sys -- (IDMWFP)
    DRV:64bit: - [2012/07/05 21:17:58 | 000,037,536 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\N360x64\0604000.009\srtspx64.sys -- (SRTSPX)
    DRV:64bit: - [2012/07/05 21:17:57 | 000,737,952 | ---- | M] (Symantec Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\N360x64\0604000.009\srtsp64.sys -- (SRTSP)
    DRV:64bit: - [2012/06/30 12:55:53 | 000,175,736 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS -- (SymEvent)
    DRV:64bit: - [2012/06/06 23:43:38 | 000,167,072 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\N360x64\0604000.009\ccsetx64.sys -- (ccSet_N360)
    DRV:64bit: - [2012/05/21 20:37:12 | 001,129,120 | ---- | M] (Symantec Corporation) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\N360x64\0604000.009\symefa64.sys -- (SymEFA)
    DRV:64bit: - [2012/03/29 01:28:38 | 000,405,624 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\N360x64\0604000.009\symnets.sys -- (SymNetS)
    DRV:64bit: - [2012/03/29 01:28:25 | 000,451,192 | R--- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\N360x64\0604000.009\symds64.sys -- (SymDS)
    DRV:64bit: - [2012/03/29 01:06:25 | 000,190,072 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\N360x64\0604000.009\ironx64.sys -- (SymIRON)
    DRV:64bit: - [2012/03/01 01:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
    DRV:64bit: - [2012/02/15 11:01:50 | 000,052,736 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
    DRV:64bit: - [2011/11/03 03:01:00 | 000,056,208 | ---- | M] (Rovi Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64)
    DRV:64bit: - [2011/07/22 11:26:56 | 000,014,928 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys -- (SASDIFSV)
    DRV:64bit: - [2011/07/12 16:55:18 | 000,012,368 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\saskutil64.sys -- (SASKUTIL)
    DRV:64bit: - [2011/03/11 01:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
    DRV:64bit: - [2011/03/11 01:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
    DRV:64bit: - [2010/11/20 22:24:43 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
    DRV:64bit: - [2010/11/20 22:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
    DRV:64bit: - [2010/11/20 22:23:48 | 000,117,248 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tsusbhub.sys -- (tsusbhub)
    DRV:64bit: - [2010/11/20 22:23:48 | 000,088,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Synth3dVsc.sys -- (Synth3dVsc)
    DRV:64bit: - [2010/11/20 22:23:48 | 000,071,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)
    DRV:64bit: - [2010/11/20 22:23:48 | 000,034,816 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\terminpt.sys -- (terminpt)
    DRV:64bit: - [2010/11/20 22:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
    DRV:64bit: - [2010/11/20 22:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
    DRV:64bit: - [2009/10/09 02:41:02 | 001,394,176 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr)
    DRV:64bit: - [2009/07/13 20:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
    DRV:64bit: - [2009/07/13 20:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
    DRV:64bit: - [2009/07/13 20:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
    DRV:64bit: - [2009/06/10 16:01:11 | 001,485,312 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\VSTDPV6.SYS -- (VST64_DPV)
    DRV:64bit: - [2009/06/10 16:01:11 | 000,740,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\VSTCNXT6.SYS -- (winachsf)
    DRV:64bit: - [2009/06/10 16:01:11 | 000,411,136 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\VSTBS26.SYS -- (VST64HWBS2)
    DRV:64bit: - [2009/06/10 15:35:20 | 000,278,016 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\e1e6032e.sys -- (e1express)
    DRV:64bit: - [2009/06/10 15:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
    DRV:64bit: - [2009/06/10 15:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
    DRV:64bit: - [2009/06/10 15:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
    DRV:64bit: - [2009/06/10 15:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
    DRV:64bit: - [2009/05/18 13:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
    DRV:64bit: - [2007/05/14 16:06:18 | 000,027,520 | ---- | M] (Research In Motion Limited) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RimUsb_AMD64.sys -- (RimUsb)
    DRV - [2012/10/20 21:06:14 | 002,084,000 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.1.5\Definitions\VirusDefs\20121020.007\ex64.sys -- (NAVEX15)
    DRV - [2012/10/20 21:06:14 | 000,126,112 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.1.5\Definitions\VirusDefs\20121020.007\eng64.sys -- (NAVENG)
    DRV - [2012/10/11 19:07:40 | 000,138,912 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
    DRV - [2012/10/10 15:32:50 | 000,513,184 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.1.5\Definitions\IPSDefs\20121019.001\IDSviA64.sys -- (IDSVia64)
    DRV - [2012/08/31 17:09:13 | 001,385,120 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.1.5\Definitions\BASHDefs\20120928.001\BHDrvx64.sys -- (BHDrvx64)
    DRV - [2012/08/08 23:55:15 | 000,484,512 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys -- (eeCtrl)
    DRV - [2009/07/13 20:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)


    ========== Standard Registry (SafeList) ==========


    ========== Internet Explorer ==========

    IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
    IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
    IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={sea...putEncoding}&oe={outputEncoding}&sourceid=ie7
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
    IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
    IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
    IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={sea...putEncoding}&oe={outputEncoding}&sourceid=ie7


    IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


    IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    IE - HKU\S-1-5-21-2262249602-3662098830-2808129073-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?fr=fp-tyc8
    IE - HKU\S-1-5-21-2262249602-3662098830-2808129073-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
    IE - HKU\S-1-5-21-2262249602-3662098830-2808129073-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 34 12 01 FA E1 20 CD 01 [binary data]
    IE - HKU\S-1-5-21-2262249602-3662098830-2808129073-1000\..\URLSearchHook: {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
    IE - HKU\S-1-5-21-2262249602-3662098830-2808129073-1000\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
    IE - HKU\S-1-5-21-2262249602-3662098830-2808129073-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
    IE - HKU\S-1-5-21-2262249602-3662098830-2808129073-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={sea...putEncoding}&sourceid=ie7&rlz=1I7GZAG_enUS480
    IE - HKU\S-1-5-21-2262249602-3662098830-2808129073-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
    IE - HKU\S-1-5-21-2262249602-3662098830-2808129073-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local


    ========== FireFox ==========

    FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
    FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
    FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Pradeep\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
    FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Pradeep\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)

    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.1.5\IPSFFPlgn\ [2012/10/15 22:41:11 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.1.5\coFFPlgn\ [2012/10/21 18:27:41 | 000,000,000 | ---D | M]
    FF - HKEY_CURRENT_USER\software\mozilla\SeaMonkey\Extensions\\mozilla_cc@internetdownloadmanager.com: C:\Users\Pradeep\AppData\Roaming\IDM\idmmzcc5 [2012/10/06 17:26:43 | 000,000,000 | ---D | M]

    [2012/04/23 21:18:44 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Pradeep\AppData\Roaming\Mozilla\Extensions
    [2012/04/23 21:18:44 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Pradeep\AppData\Roaming\Mozilla\Extensions\celtx@celtx.com

    ========== Chrome ==========

    CHR - homepage: http://www.yahoo.com/?fr=fp-tyc8
    CHR - default_search_provider: Google (Enabled)
    CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:eek:riginalQueryForSuggestion}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
    CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
    CHR - homepage: http://www.yahoo.com/?fr=fp-tyc8
    CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
    CHR - plugin: Native Client (Enabled) = C:\Users\Pradeep\AppData\Local\Google\Chrome\Application\22.0.1229.94\ppGoogleNaClPluginChrome.dll
    CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Pradeep\AppData\Local\Google\Chrome\Application\22.0.1229.94\pdf.dll
    CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Pradeep\AppData\Local\Google\Chrome\Application\22.0.1229.94\gcswf32.dll
    CHR - plugin: Shockwave Flash (Disabled) = C:\Users\Pradeep\AppData\Local\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll
    CHR - plugin: Norton Confidential (Enabled) = C:\Users\Pradeep\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2012.5.3.7_0\npcoplgn.dll
    CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
    CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll
    CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
    CHR - Extension: YouTube = C:\Users\Pradeep\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
    CHR - Extension: Google Search = C:\Users\Pradeep\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
    CHR - Extension: IDM Integration = C:\Users\Pradeep\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmolcgpienlcieaajfkkdamlngancncm\6.12.21_0\
    CHR - Extension: Norton Identity Protection = C:\Users\Pradeep\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2012.5.6.10_0\
    CHR - Extension: Gmail = C:\Users\Pradeep\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

    O1 HOSTS File: ([2012/10/21 11:26:22 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
    O1 - Hosts: 127.0.0.1 localhost
    O2:64bit: - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll (Internet Download Manager, Tonec Inc.)
    O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
    O2 - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll (Internet Download Manager, Tonec Inc.)
    O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
    O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\6.4.0.9\coieplg.dll (Symantec Corporation)
    O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\6.4.0.9\ips\ipsbho.dll (Symantec Corporation)
    O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.)
    O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
    O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\6.4.0.9\coieplg.dll (Symantec Corporation)
    O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
    O3:64bit: - HKU\S-1-5-21-2262249602-3662098830-2808129073-1000\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
    O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
    O4 - HKLM..\Run: [AdobeCS6ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe (Adobe Systems Incorporated)
    O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
    O4 - HKLM..\Run: [ISUSPM] C:\ProgramData\FLEXnet\Connect\11\isuspm.exe (Flexera Software, Inc.)
    O4 - HKLM..\Run: [Nuance OmniPage 18-reminder] C:\Program Files (x86)\Nuance\OmniPage18\Ereg\Ereg.exe (Nuance Communications, Inc.)
    O4 - HKLM..\Run: [OmniPage Preload] C:\Program Files (x86)\Nuance\OmniPage18\OmniPage.exe (Nuance Communications, Inc.)
    O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files (x86)\Java\jre1.6.0_07\bin\jusched.exe (Sun Microsystems, Inc.)
    O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
    O4 - HKU\S-1-5-21-2262249602-3662098830-2808129073-1000..\Run: [IDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe (Tonec Inc.)
    O4 - HKU\S-1-5-21-2262249602-3662098830-2808129073-1000..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
    O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-21-2262249602-3662098830-2808129073-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-21-2262249602-3662098830-2808129073-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O8:64bit: - Extra context menu item: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm ()
    O8:64bit: - Extra context menu item: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm ()
    O8 - Extra context menu item: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm ()
    O8 - Extra context menu item: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm ()
    O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre1.6.0_07\bin\npjpi160_07.dll (Sun Microsystems, Inc.)
    O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
    O13 - gopher Prefix: missing
    O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab (QuickTime Plugin Control)
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files (x86)\Yahoo!\Common\Yinsthelper.dll (Installation Support)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
    O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 208.67.222.222 208.67.220.220 208.67.220.222
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1DC2EB72-102F-41F8-97AC-4E26CAF3015A}: DhcpNameServer = 208.67.222.222 208.67.220.220 208.67.220.222
    O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
    O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
    O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
    O18:64bit: - Protocol\Handler\mso-offdap11 - No CLSID value found
    O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
    O18:64bit: - Protocol\Filter\text/xml - No CLSID value found
    O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
    O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
    O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
    O32 - HKLM CDRom: AutoRun - 1
    O32 - AutoRun File - [2006/01/15 14:41:08 | 000,000,074 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
    O34 - HKLM BootExecute: (autocheck autochk *)
    O35:64bit: - HKLM\..comfile [open] -- "%1" %*
    O35:64bit: - HKLM\..exefile [open] -- "%1" %*
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
    O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
    O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
    O37 - HKLM\...com [@ = ComFile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*
    O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
    O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
    O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

    ========== Files/Folders - Created Within 30 Days ==========

    [2012/10/21 18:33:26 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Pradeep\Desktop\OTL.exe
    [2012/10/21 11:33:25 | 000,000,000 | ---D | C] -- C:\Windows\temp
    [2012/10/21 11:26:29 | 000,000,000 | ---D | C] -- C:\$RECYCLE.BIN
    [2012/10/21 11:10:50 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
    [2012/10/21 11:10:50 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
    [2012/10/21 11:10:50 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
    [2012/10/21 11:08:15 | 000,000,000 | ---D | C] -- C:\Qoobox
    [2012/10/21 11:07:32 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
    [2012/10/21 11:00:24 | 004,986,495 | R--- | C] (Swearware) -- C:\Users\Pradeep\Desktop\ComboFix.exe
    [2012/10/20 22:37:43 | 004,731,392 | ---- | C] (AVAST Software) -- C:\Users\Pradeep\Desktop\aswMBR.exe
    [2012/10/20 22:16:19 | 000,000,000 | ---D | C] -- C:\Users\Pradeep\Desktop\RK_Quarantine
    [2012/10/20 17:58:32 | 000,000,000 | ---D | C] -- C:\TDSSKiller_Quarantine
    [2012/10/19 23:34:30 | 000,000,000 | ---D | C] -- C:\FRST
    [2012/10/19 21:35:12 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA
    [2012/10/19 21:22:27 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA Corporation
    [2012/10/19 21:21:06 | 000,000,000 | ---D | C] -- C:\Program Files\NVIDIA Corporation
    [2012/10/18 21:47:34 | 000,000,000 | ---D | C] -- C:\Users\Pradeep\AppData\Roaming\SUPERAntiSpyware.com
    [2012/10/18 21:47:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
    [2012/10/18 21:47:11 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
    [2012/10/18 21:47:11 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
    [2012/10/18 21:42:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Kaspersky Lab
    [2012/10/17 21:37:03 | 000,000,000 | ---D | C] -- C:\Users\Pradeep\AppData\Roaming\Malwarebytes
    [2012/10/17 21:36:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
    [2012/10/17 21:36:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
    [2012/10/17 21:36:54 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
    [2012/10/17 21:36:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
    [2012/10/17 18:14:17 | 000,000,000 | ---D | C] -- C:\Users\Pradeep\AppData\Local\ElevatedDiagnostics
    [2012/10/16 21:57:18 | 000,000,000 | ---D | C] -- C:\Users\Pradeep\AppData\Local\NPE
    [2012/10/12 17:27:22 | 002,213,464 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\Pradeep\Desktop\TDSSKiller.exe
    [2012/10/10 22:05:19 | 000,000,000 | -HSD | C] -- C:\Windows\SysWow64\%APPDATA%
    [2012/10/10 21:55:16 | 000,000,000 | ---D | C] -- C:\Windows\Minidump
    [2012/10/08 21:39:28 | 000,000,000 | ---D | C] -- C:\Users\Pradeep\AppData\Local\CrashDumps
    [2012/10/08 08:43:33 | 000,000,000 | ---D | C] -- C:\w
    [2012/10/08 08:43:33 | 000,000,000 | ---D | C] -- C:\skins
    [2012/10/08 08:43:32 | 000,000,000 | ---D | C] -- C:\Cache
    [2012/10/06 20:01:59 | 000,000,000 | ---D | C] -- C:\Users\Pradeep\AppData\Roaming\Media Player Classic
    [2012/10/06 17:26:33 | 000,000,000 | ---D | C] -- C:\Users\Pradeep\AppData\Roaming\IDM
    [2012/10/06 17:26:32 | 000,000,000 | ---D | C] -- C:\Users\Pradeep\AppData\Roaming\DMCache
    [2012/10/06 17:26:24 | 000,000,000 | ---D | C] -- C:\Users\Pradeep\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager
    [2012/10/06 17:26:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager
    [2012/10/06 17:26:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Internet Download Manager
    [2012/10/06 16:26:25 | 000,000,000 | ---D | C] -- C:\Users\Pradeep\AppData\Local\Ilivid Player
    [2012/10/06 16:25:35 | 000,000,000 | -H-D | C] -- C:\ProgramData\{B49A644A-1076-4A3D-B124-DAA7862F2318}
    [2012/10/06 16:25:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iLivid
    [2012/10/06 16:24:41 | 000,000,000 | ---D | C] -- C:\Users\Pradeep\AppData\Local\PackageAware
    [2012/10/02 22:14:05 | 000,000,000 | ---D | C] -- C:\Windows\Sun
    [2012/10/01 23:19:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Java
    [2012/10/01 23:19:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
    [2012/10/01 22:12:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Yahoo SiteBuilder
    [2012/10/01 22:04:35 | 000,000,000 | ---D | C] -- C:\Users\Pradeep\Desktop\sites
    [2012/10/01 21:26:07 | 000,000,000 | ---D | C] -- C:\Users\Pradeep\Desktop\Website Thumbnails
    [2012/09/27 10:08:37 | 000,160,992 | ---- | C] (Tonec Inc.) -- C:\Windows\SysNative\drivers\idmwfp.sys

    ========== Files - Modified Within 30 Days ==========

    [2012/10/21 18:33:25 | 000,021,872 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    [2012/10/21 18:33:25 | 000,021,872 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    [2012/10/21 18:33:10 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Pradeep\Desktop\OTL.exe
    [2012/10/21 18:26:35 | 000,000,896 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
    [2012/10/21 18:25:47 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
    [2012/10/21 18:25:38 | 1609,396,224 | -HS- | M] () -- C:\hiberfil.sys
    [2012/10/21 18:23:37 | 000,000,864 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2262249602-3662098830-2808129073-1000Core.job
    [2012/10/21 18:23:34 | 000,000,916 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2262249602-3662098830-2808129073-1000UA.job
    [2012/10/21 18:23:34 | 000,000,900 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
    [2012/10/21 11:26:22 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
    [2012/10/21 11:00:57 | 004,986,495 | R--- | M] (Swearware) -- C:\Users\Pradeep\Desktop\ComboFix.exe
    [2012/10/20 22:45:07 | 000,000,512 | ---- | M] () -- C:\Users\Pradeep\Desktop\MBR.dat
    [2012/10/20 22:37:35 | 004,731,392 | ---- | M] (AVAST Software) -- C:\Users\Pradeep\Desktop\aswMBR.exe
    [2012/10/20 17:25:07 | 305,745,908 | ---- | M] () -- C:\Windows\MEMORY.DMP
    [2012/10/19 22:24:00 | 000,782,922 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
    [2012/10/19 22:24:00 | 000,663,010 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
    [2012/10/19 22:24:00 | 000,121,878 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
    [2012/10/19 21:20:51 | 001,442,105 | ---- | M] () -- C:\Windows\SysNative\drivers\N360x64\0604000.009\Cat.DB
    [2012/10/18 21:47:14 | 000,001,810 | ---- | M] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
    [2012/10/17 22:17:41 | 000,001,115 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    [2012/10/15 20:49:29 | 000,010,074 | ---- | M] () -- C:\Windows\SysNative\drivers\N360x64\0604000.009\VT20121008.022
    [2012/10/12 17:27:22 | 002,213,464 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\Pradeep\Desktop\TDSSKiller.exe
    [2012/10/11 10:50:26 | 000,002,504 | ---- | M] () -- C:\Users\Pradeep\Desktop\Google Chrome.lnk
    [2012/10/09 21:57:37 | 000,330,122 | ---- | M] () -- C:\Users\Pradeep\Desktop\Lab Requisition Form - Order 229.pdf
    [2012/10/08 08:43:34 | 000,000,370 | ---- | M] () -- C:\bmrc_1.gif
    [2012/10/08 08:43:34 | 000,000,367 | ---- | M] () -- C:\bmfav_1.gif
    [2012/10/08 08:43:34 | 000,000,355 | ---- | M] () -- C:\bmpref_1.gif
    [2012/10/08 08:43:34 | 000,000,235 | ---- | M] () -- C:\bmsearch_1.gif
    [2012/10/08 08:43:34 | 000,000,166 | ---- | M] () -- C:\bmfol_1_s0.gif
    [2012/10/06 16:25:33 | 000,000,957 | ---- | M] () -- C:\Users\Public\Desktop\iLivid Download Manager.lnk
    [2012/10/05 10:09:20 | 000,795,928 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
    [2012/10/03 21:47:51 | 000,005,297 | ---- | M] () -- C:\Users\Pradeep\Desktop\Art Beau.jpg
    [2012/10/03 14:21:45 | 000,000,380 | ---- | M] () -- C:\edu.bmp
    [2012/10/03 14:21:45 | 000,000,304 | ---- | M] () -- C:\dir.bmp
    [2012/10/03 14:21:45 | 000,000,284 | ---- | M] () -- C:\srch_map_1.gif
    [2012/10/03 14:21:45 | 000,000,279 | ---- | M] () -- C:\hj_1.gif
    [2012/10/03 14:21:45 | 000,000,277 | ---- | M] () -- C:\mov_1.gif
    [2012/10/03 14:21:45 | 000,000,274 | ---- | M] () -- C:\trav_1.gif
    [2012/10/03 14:21:45 | 000,000,273 | ---- | M] () -- C:\srch_stk_1.gif
    [2012/10/03 14:21:45 | 000,000,268 | ---- | M] () -- C:\ab_1.gif
    [2012/10/03 14:21:45 | 000,000,240 | ---- | M] () -- C:\srch_site_1.gif
    [2012/10/03 14:21:45 | 000,000,138 | ---- | M] () -- C:\flk2.gif
    [2012/10/03 14:21:45 | 000,000,121 | ---- | M] () -- C:\srch_nws_1.gif
    [2012/10/03 14:21:45 | 000,000,103 | ---- | M] () -- C:\del_1.gif
    [2012/10/03 14:21:44 | 000,000,265 | ---- | M] () -- C:\srch_ans_1.gif
    [2012/10/03 14:21:44 | 000,000,235 | ---- | M] () -- C:\srch_1.gif
    [2012/10/03 14:21:44 | 000,000,131 | ---- | M] () -- C:\srch_loc_1.gif
    [2012/10/03 14:21:44 | 000,000,123 | ---- | M] () -- C:\srch_sh_1.gif
    [2012/10/03 14:21:44 | 000,000,113 | ---- | M] () -- C:\srch_aud_1.gif
    [2012/10/03 14:21:44 | 000,000,112 | ---- | M] () -- C:\srch_vid_1.gif
    [2012/10/03 14:21:44 | 000,000,112 | ---- | M] () -- C:\srch_img_1.gif
    [2012/10/02 20:28:22 | 000,002,264 | ---- | M] () -- C:\Users\Public\Desktop\Norton 360.lnk
    [2012/10/01 23:21:26 | 000,002,008 | ---- | M] () -- C:\Users\Pradeep\Desktop\Yahoo! SiteBuilder.lnk
    [2012/09/30 16:24:20 | 000,423,531 | ---- | M] () -- C:\Users\Pradeep\Desktop\new%20notice%20board%202.png
    [2012/09/30 15:38:04 | 000,350,262 | ---- | M] () -- C:\Users\Pradeep\Desktop\noticeboard.png
    [2012/09/29 19:54:26 | 000,025,928 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
    [2012/09/27 13:07:26 | 000,160,992 | ---- | M] (Tonec Inc.) -- C:\Windows\SysNative\drivers\idmwfp.sys
    [2012/09/26 16:52:32 | 000,010,218 | ---- | M] () -- C:\Users\Pradeep\Desktop\imagesCA63ERNZ.jpg
    [2012/09/26 16:51:18 | 000,037,306 | ---- | M] () -- C:\Users\Pradeep\Desktop\dfsad.png
    [2012/09/26 16:50:04 | 000,031,044 | ---- | M] () -- C:\Users\Pradeep\Desktop\untitled.png
    [2012/09/26 05:52:07 | 000,000,172 | ---- | M] () -- C:\Windows\SysNative\drivers\N360x64\0604000.009\isolate.ini
    [2012/09/24 22:15:16 | 000,090,874 | ---- | M] () -- C:\Users\Pradeep\Desktop\iaza18999047392300_3.jpg
    [2012/09/24 22:13:31 | 000,065,058 | ---- | M] () -- C:\Users\Pradeep\Desktop\iaza18999047392300_2.jpg
    [2012/09/24 22:09:54 | 000,087,307 | ---- | M] () -- C:\Users\Pradeep\Desktop\iaza18999097403700.jpg

    ========== Files Created - No Company Name ==========

    [2012/10/21 11:10:50 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
    [2012/10/21 11:10:50 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
    [2012/10/21 11:10:50 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
    [2012/10/21 11:10:50 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
    [2012/10/21 11:10:50 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
    [2012/10/20 22:45:07 | 000,000,512 | ---- | C] () -- C:\Users\Pradeep\Desktop\MBR.dat
    [2012/10/18 21:47:14 | 000,001,810 | ---- | C] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
    [2012/10/17 22:06:04 | 305,745,908 | ---- | C] () -- C:\Windows\MEMORY.DMP
    [2012/10/17 21:36:56 | 000,001,115 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    [2012/10/09 21:57:37 | 000,330,122 | ---- | C] () -- C:\Users\Pradeep\Desktop\Lab Requisition Form - Order 229.pdf
    [2012/10/08 08:43:34 | 000,000,370 | ---- | C] () -- C:\bmrc_1.gif
    [2012/10/08 08:43:34 | 000,000,367 | ---- | C] () -- C:\bmfav_1.gif
    [2012/10/08 08:43:34 | 000,000,355 | ---- | C] () -- C:\bmpref_1.gif
    [2012/10/08 08:43:34 | 000,000,235 | ---- | C] () -- C:\bmsearch_1.gif
    [2012/10/08 08:43:34 | 000,000,166 | ---- | C] () -- C:\bmfol_1_s0.gif
    [2012/10/06 16:25:33 | 000,000,957 | ---- | C] () -- C:\Users\Public\Desktop\iLivid Download Manager.lnk
    [2012/10/03 14:21:45 | 000,000,380 | ---- | C] () -- C:\edu.bmp
    [2012/10/03 14:21:45 | 000,000,304 | ---- | C] () -- C:\dir.bmp
    [2012/10/03 14:21:45 | 000,000,284 | ---- | C] () -- C:\srch_map_1.gif
    [2012/10/03 14:21:45 | 000,000,279 | ---- | C] () -- C:\hj_1.gif
    [2012/10/03 14:21:45 | 000,000,277 | ---- | C] () -- C:\mov_1.gif
    [2012/10/03 14:21:45 | 000,000,274 | ---- | C] () -- C:\trav_1.gif
    [2012/10/03 14:21:45 | 000,000,273 | ---- | C] () -- C:\srch_stk_1.gif
    [2012/10/03 14:21:45 | 000,000,268 | ---- | C] () -- C:\ab_1.gif
    [2012/10/03 14:21:45 | 000,000,240 | ---- | C] () -- C:\srch_site_1.gif
    [2012/10/03 14:21:45 | 000,000,138 | ---- | C] () -- C:\flk2.gif
    [2012/10/03 14:21:45 | 000,000,121 | ---- | C] () -- C:\srch_nws_1.gif
    [2012/10/03 14:21:45 | 000,000,103 | ---- | C] () -- C:\del_1.gif
    [2012/10/03 14:21:44 | 000,000,265 | ---- | C] () -- C:\srch_ans_1.gif
    [2012/10/03 14:21:44 | 000,000,235 | ---- | C] () -- C:\srch_1.gif
    [2012/10/03 14:21:44 | 000,000,131 | ---- | C] () -- C:\srch_loc_1.gif
    [2012/10/03 14:21:44 | 000,000,123 | ---- | C] () -- C:\srch_sh_1.gif
    [2012/10/03 14:21:44 | 000,000,113 | ---- | C] () -- C:\srch_aud_1.gif
    [2012/10/03 14:21:44 | 000,000,112 | ---- | C] () -- C:\srch_vid_1.gif
    [2012/10/03 14:21:44 | 000,000,112 | ---- | C] () -- C:\srch_img_1.gif
    [2012/10/01 23:21:26 | 000,002,008 | ---- | C] () -- C:\Users\Pradeep\Desktop\Yahoo! SiteBuilder.lnk
    [2012/09/29 12:44:31 | 000,005,297 | ---- | C] () -- C:\Users\Pradeep\Desktop\Art Beau.jpg
    [2012/09/29 12:23:39 | 000,350,262 | ---- | C] () -- C:\Users\Pradeep\Desktop\noticeboard.png
    [2012/09/29 12:15:23 | 000,423,531 | ---- | C] () -- C:\Users\Pradeep\Desktop\new%20notice%20board%202.png
    [2012/09/26 16:52:48 | 000,010,218 | ---- | C] () -- C:\Users\Pradeep\Desktop\imagesCA63ERNZ.jpg
    [2012/09/26 16:51:18 | 000,037,306 | ---- | C] () -- C:\Users\Pradeep\Desktop\dfsad.png
    [2012/09/24 22:15:15 | 000,090,874 | ---- | C] () -- C:\Users\Pradeep\Desktop\iaza18999047392300_3.jpg
    [2012/09/24 22:13:31 | 000,065,058 | ---- | C] () -- C:\Users\Pradeep\Desktop\iaza18999047392300_2.jpg
    [2012/09/24 22:10:03 | 000,087,307 | ---- | C] () -- C:\Users\Pradeep\Desktop\iaza18999097403700.jpg
    [2012/08/25 17:00:57 | 000,001,456 | ---- | C] () -- C:\Users\Pradeep\AppData\Local\Adobe Save for Web 13.0 Prefs
    [2012/06/23 11:46:54 | 000,007,630 | ---- | C] () -- C:\Users\Pradeep\AppData\Local\Resmon.ResmonCfg
    [2012/05/06 17:28:45 | 000,000,376 | ---- | C] () -- C:\Windows\ODBC.INI
    [2012/05/06 17:18:52 | 000,165,376 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
    [2012/05/04 18:12:51 | 000,000,006 | -HS- | C] () -- C:\Users\Pradeep\AppData\Roaming\date
    [2012/05/04 18:12:40 | 000,000,002 | -HS- | C] () -- C:\Users\Pradeep\AppData\Roaming\evf9
    [2012/05/03 22:49:22 | 000,096,857 | ---- | C] () -- C:\Users\Pradeep\Panjabi - Selected.lsl
    [2012/04/25 18:37:38 | 000,000,403 | ---- | C] () -- C:\Windows\MAXLINK.INI
    [2012/04/25 18:31:01 | 000,795,928 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
    [2012/04/22 19:03:49 | 002,463,976 | ---- | C] () -- C:\Windows\SysWow64\NPSWF32.dll

    ========== ZeroAccess Check ==========

    [2009/07/13 23:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

    [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

    [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

    [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

    [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

    [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
    "" = C:\Windows\SysNative\shell32.dll -- [2012/06/09 00:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Apartment

    [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
    "" = %SystemRoot%\system32\shell32.dll -- [2012/06/08 23:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Apartment

    [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
    "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 20:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Free

    [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
    "" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 22:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Free

    [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
    "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 20:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Both

    [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

    ========== LOP Check ==========

    [2012/07/30 20:24:04 | 000,000,000 | ---D | M] -- C:\Users\Pradeep\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
    [2012/10/21 11:23:23 | 000,000,000 | ---D | M] -- C:\Users\Pradeep\AppData\Roaming\DMCache
    [2012/04/23 21:51:18 | 000,000,000 | ---D | M] -- C:\Users\Pradeep\AppData\Roaming\EPSON
    [2012/04/23 21:18:43 | 000,000,000 | ---D | M] -- C:\Users\Pradeep\AppData\Roaming\Greyfirst
    [2012/10/06 20:47:14 | 000,000,000 | ---D | M] -- C:\Users\Pradeep\AppData\Roaming\IDM
    [2012/04/25 18:37:03 | 000,000,000 | ---D | M] -- C:\Users\Pradeep\AppData\Roaming\Nuance
    [2012/05/15 23:50:41 | 000,000,000 | ---D | M] -- C:\Users\Pradeep\AppData\Roaming\PACE Anti-Piracy
    [2012/05/15 23:48:46 | 000,000,000 | ---D | M] -- C:\Users\Pradeep\AppData\Roaming\PDAppFlex
    [2012/04/25 18:42:31 | 000,000,000 | ---D | M] -- C:\Users\Pradeep\AppData\Roaming\ScanSoft
    [2012/04/25 18:42:35 | 000,000,000 | ---D | M] -- C:\Users\Pradeep\AppData\Roaming\Zeon

    ========== Purity Check ==========



    ========== Alternate Data Streams ==========

    @Alternate Data Stream - 218 bytes -> C:\ProgramData\TEMP:A303874F
    < End of report >
  2. Pete26

    Pete26 Newcomer, in training Topic Starter Posts: 30

    OTL Extras logfile created on: 10/21/2012 6:35:32 PM - Run 1
    OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Pradeep\Desktop
    64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
    Internet Explorer (Version = 9.0.8112.16421)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    2.00 Gb Total Physical Memory | 1.22 Gb Available Physical Memory | 61.03% Memory free
    4.00 Gb Paging File | 2.71 Gb Available in Paging File | 67.75% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
    Drive C: | 226.40 Gb Total Space | 135.14 Gb Free Space | 59.69% Space Free | Partition Type: NTFS
    Drive D: | 232.88 Gb Total Space | 209.72 Gb Free Space | 90.06% Space Free | Partition Type: NTFS
    Drive E: | 6.48 Gb Total Space | 0.87 Gb Free Space | 13.47% Space Free | Partition Type: NTFS

    Computer Name: PRADEEPS-PC | User Name: Pradeep | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
    Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

    ========== Extra Registry (SafeList) ==========


    ========== File Associations ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
    .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
    .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)

    ========== Shell Spawning ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [open] -- "%1" %*
    cmdfile [open] -- "%1" %*
    comfile [open] -- "%1" %*
    exefile [open] -- "%1" %*
    helpfile [open] -- Reg Error: Key error.
    htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
    inffile [install] -- %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
    InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
    InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
    piffile [open] -- "%1" %*
    regfile [merge] -- Reg Error: Key error.
    scrfile [config] -- "%1"
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
    scrfile [open] -- "%1" /S
    txtfile [edit] -- Reg Error: Key error.
    Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
    Directory [Bridge] -- C:\Program Files (x86)\Adobe\Adobe Bridge CS6\Bridge.exe "%L" (Adobe Systems, Inc.)
    Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [explore] -- Reg Error: Value error.
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [open] -- "%1" %*
    cmdfile [open] -- "%1" %*
    comfile [open] -- "%1" %*
    cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
    exefile [open] -- "%1" %*
    helpfile [open] -- Reg Error: Key error.
    piffile [open] -- "%1" %*
    regfile [merge] -- Reg Error: Key error.
    scrfile [config] -- "%1"
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
    scrfile [open] -- "%1" /S
    txtfile [edit] -- Reg Error: Key error.
    Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
    Directory [Bridge] -- C:\Program Files (x86)\Adobe\Adobe Bridge CS6\Bridge.exe "%L" (Adobe Systems, Inc.)
    Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [explore] -- Reg Error: Value error.
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    ========== Security Center Settings ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    "cval" = 1
    "FirewallDisableNotify" = 0
    "AntiVirusDisableNotify" = 0
    "UpdatesDisableNotify" = 0

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
    "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
    "AntiVirusOverride" = 0
    "AntiSpywareOverride" = 0
    "FirewallOverride" = 0

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

    ========== System Restore Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
    "DisableSR" = 0

    ========== Firewall Settings ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
    "EnableFirewall" = 1
    "DisableNotifications" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
    "EnableFirewall" = 1
    "DisableNotifications" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
    "EnableFirewall" = 1
    "DisableNotifications" = 0

    ========== Authorized Applications List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


    ========== Vista Active Open Ports Exception List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{0D3D17A6-8ECF-4556-9274-DC97A79BC51F}" = lport=138 | protocol=17 | dir=in | app=system |
    "{12FBE955-29ED-4D00-BE75-07D7F1932D62}" = rport=138 | protocol=17 | dir=out | app=system |
    "{2C24A448-34AA-465D-9806-AD97ECF5B1CF}" = rport=137 | protocol=17 | dir=out | app=system |
    "{2E544952-7A22-48BC-8B66-B2C93F749B36}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
    "{403A7857-D465-46DC-BA93-11E1D44C8A6F}" = lport=2869 | protocol=6 | dir=in | app=system |
    "{4E289B97-682F-48D6-9348-026F81A85B3A}" = lport=137 | protocol=17 | dir=in | app=system |
    "{4F1C2493-5D31-41EA-BA78-15383E02BAA6}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
    "{5595940B-E1DF-4E5D-84B0-DCCD529F4F1D}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
    "{6EC1F541-60EC-4ED7-9D84-0CA9C54F9480}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
    "{A2EAD659-60FE-45F7-9B5C-0E445A04E821}" = rport=139 | protocol=6 | dir=out | app=system |
    "{AB4D8796-BBEA-4280-B930-D1A30C160A3D}" = lport=10243 | protocol=6 | dir=in | app=system |
    "{ABFDCD1D-93DF-4C91-9A9E-F980068D08D2}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
    "{AEBFCD65-E861-4F90-B0B4-DC70C6B9C9FF}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
    "{AF7AF116-EF34-4162-A8B1-F5F63FE07CD8}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
    "{B1669E38-447A-488F-B0C6-06B4CE295AE3}" = rport=445 | protocol=6 | dir=out | app=system |
    "{C0BBB2C5-A875-4CD4-A881-D7FB3ADEC35B}" = rport=10243 | protocol=6 | dir=out | app=system |
    "{C760D805-6348-4E44-9E99-F4BEEAEB84C7}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
    "{D9455B04-A8AE-43C6-9803-BF163983046B}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
    "{D9EA80CF-2A9A-447C-8B86-98841186C25F}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
    "{DD31F8AF-D3AE-4FD8-875B-1A46D7DEE108}" = lport=445 | protocol=6 | dir=in | app=system |
    "{E548FC8C-4F4F-42B6-B832-C16CC3A0214F}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
    "{F6F413A3-F98B-4B10-9D60-C59EC0A87743}" = lport=139 | protocol=6 | dir=in | app=system |
    "{FD1D3093-C0E0-4667-913D-80C69145D6CF}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |

    ========== Vista Active Application Exception List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{004DCFBA-919E-4AC5-A36F-C69E37693216}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
    "{007C213B-6D2A-4832-924D-F6ECECA3EF20}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
    "{05634A16-13C0-4BA0-A877-D8D291A9FBFA}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
    "{066B4176-3A48-4D19-BDD6-E471D916E101}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
    "{07D8FDC5-7A78-4EE5-86F4-06445562416E}" = protocol=6 | dir=in | app=c:\program files (x86)\nuance\omnipage18\omnipage18.exe |
    "{1208FECA-F673-4BC2-9DCF-7E8C17951B4D}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
    "{1B586434-1310-48D3-8B61-75D0C78BCECB}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
    "{1DA8C4D2-F2EC-40EC-BE23-9C1CC9E23460}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
    "{35112494-2D0B-4718-A040-3ABEB5C24291}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
    "{36ADD9E9-F441-4769-9484-15F18F806472}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
    "{3915CA2D-B025-4752-B406-BACC7A072B7B}" = protocol=6 | dir=in | app=c:\program files (x86)\nuance\omnipage18\ereg\ereg.exe |
    "{3FA5D683-DB8B-47D2-A98D-3428D0317944}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
    "{4121C9AF-8168-48CC-89C2-6EFA782A69F2}" = protocol=6 | dir=in | app=c:\program files (x86)\nuance\omnipage18\ppmv.exe |
    "{47F77224-73E1-4F98-805A-F87ADC3A79CA}" = protocol=17 | dir=in | app=c:\program files (x86)\nuance\omnipage18\ppmv.exe |
    "{4A2774BF-BE67-4074-9412-578161B94CFD}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
    "{4E42DA90-2215-41C9-80A9-DC92B161165A}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
    "{5F082CB1-0E26-4919-8907-8D6BE26A42E0}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
    "{9055D408-F370-4883-A7B6-5FCEBCD0A59F}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
    "{AC472913-B802-4A8F-9D27-05013DF3B7DF}" = protocol=6 | dir=out | app=system |
    "{C7E3B5AA-C552-48AE-AD00-2765CCFCCA95}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
    "{CABEE31C-509E-40CA-9796-CA3ED876A372}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
    "{CFC2ACC1-7C16-4C2E-BBF8-EF7C1CE0A359}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
    "{D201DF51-D7E6-4B13-80D2-52A9A2BA3D9F}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
    "{D97E1EBA-7D98-4D6C-B048-8935EF17D6CC}" = protocol=17 | dir=in | app=c:\program files (x86)\nuance\omnipage18\omnipage18.exe |
    "{DBE585A7-4714-4578-AE5C-76A26D45D11C}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
    "{E6C6EDF6-FDB1-457C-8372-2BE0C037144A}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
    "{EA03FCB6-7BB4-4202-86CD-D76B38EA08E7}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
    "{EA9B1388-E449-40BF-9DCF-E0585515B00A}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
    "{F1A8F321-5BBD-4A6D-BECA-69EDCF327590}" = protocol=17 | dir=in | app=c:\program files (x86)\nuance\omnipage18\ereg\ereg.exe |
    "{F1FD333E-0012-4CE6-B8BE-D0F8F16C7FEE}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
    "{FEB26B02-F3BA-493A-AFF0-677EB8806701}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |

    ========== HKEY_LOCAL_MACHINE Uninstall List ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
    "{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll
    "{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
    "{6A76BEAF-6D1F-4273-A79B-DA8410A2E56B}" = Apple Mobile Device Support
    "{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}" = Microsoft Visual C++ 2005 Redistributable (x64)
    "{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
    "{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
    "{840A3BAA-4C68-4581-9C7A-6F8D6CF531B9}" = iTunes
    "{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
    "{A1F2C608-32D6-467D-B035-BBEF509042BA}_is1" = Free Opener
    "{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
    "{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
    "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
    "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
    "Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
    "NVIDIA Display Control Panel" = NVIDIA Display Control Panel
    "NVIDIA Drivers" = NVIDIA Drivers

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{0046FA01-C5B9-4985-BACB-398DC480FC05}" = Adobe Photoshop CS3
    "{0224CACC-994D-45F8-B973-D65056EA9C2F}" = Adobe XMP DVA Panels CS3
    "{0327FA9D-975C-448C-A086-577D57BB25B8}" = Adobe Soundbooth CS3 Codecs
    "{045D4EDF-8DC1-43D7-BAFC-7AAEF99C7168}" = Adobe Creative Suite 6 Production Premium
    "{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting
    "{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
    "{122ADF8C-DDA1-480C-9936-C88F2825B265}" = Apple Application Support
    "{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
    "{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin
    "{185F9795-9663-4F13-9EF9-307A282ADB5A}" = ph
    "{193EAFD0-1BAF-4FB4-B18F-79D5D6A4B285}" = Adobe After Effects CS3 Presets
    "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    "{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
    "{243DA072-8E39-424A-86A3-F63152021383}" = Adobe Glyphlet Creation Tool CS3
    "{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3
    "{2A075BB4-E976-4278-BF3F-E5C6945D84C0}" = bl
    "{2EFFFC71-1E66-454E-A6E6-CEEC800B96D2}" = Adobe Flash Video Encoder
    "{2FA75B40-17C9-4D22-88CA-80A5D52FAB13}" = LightScribe System Software
    "{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java(TM) 6 Update 7
    "{40F2BCF4-4EED-4AD4-BFB6-A58946C561A1}" = Adobe Creative Suite 3 Production Premium
    "{485ACF57-F364-440A-8496-E1E81C8FA1AA}" = Adobe Premiere Pro CS3 Third Party Content
    "{4ECA4128-8B48-44A0-90E8-B93C6A69CE4B}" = LightScribe Template Designs - Music Pack 1
    "{50F102CA-4BE2-41A9-9810-5BB05EB91B9A}" = Adobe Premiere Pro CS3 Functional Content
    "{51846830-E7B2-4218-8968-B77F0FF475B8}" = Adobe Color EU Extra Settings
    "{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3
    "{54B2EAD9-A110-43F7-B010-2859A1BD2AFE}" = Adobe Encore CS3
    "{58DCEEE5-532E-44F4-B1D7-A146EF9E9FDA}" = Adobe Premiere Pro CS3
    "{6ABE0BEE-D572-4FE8-B434-9E72A289431B}" = Adobe Fonts All
    "{6B52140A-F189-4945-BFFC-DB3F00B8C589}" = Adobe Flash CS3
    "{6B708481-748A-4EB4-97C1-CD386244FF77}" = Adobe MotionPicture Color Files
    "{6BBAA81D-6A7E-43AD-8889-2F002DCAAFDD}" = AHV content for Acrobat and Flash
    "{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3
    "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
    "{73E81E9B-7319-43AD-B7CC-1C61405E5089}" = Adobe After Effects CS3 Template Projects & Footage
    "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
    "{7ACFB90E-8FD0-4397-AD3A-5195412623A3}" = Adobe Help Viewer CS3
    "{7ECEF10B-F1C2-4FD5-861F-A3FCB4653304}" = Adobe After Effects CS3 Third Party Content
    "{83721450-E604-4C37-ABEB-CE7F18C587C8}" = LightScribe Template Labeler
    "{845A8DB9-8802-4FD3-9FE3-938A6C46A2EC}" = Adobe Video Profiles
    "{88D422DB-E9C7-4E16-9D80-2999F4FD6AD9}" = Adobe Flash Player 9 Plugin
    "{8D15E1B2-D2B7-4A17-B44B-D2DDE5981406}" = iLivid
    "{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3
    "{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}" = Adobe Type Support
    "{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3
    "{91120409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Standard Edition 2003
    "{92A300C0-E97B-48CC-9702-AB1AAED167E1}" = Adobe Soundbooth CS3 Scores
    "{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
    "{95655ED4-7CA5-46DF-907F-7144877A32E5}" = Adobe Color NA Recommended Settings
    "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    "{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3
    "{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}" = Adobe CMaps
    "{A2D81E70-2A98-4A08-A628-94388B063C5E}" = Adobe Color - Photoshop Specific
    "{A4C7E916-23CD-40ED-B18C-6ADE7B0C74DA}" = Nuance OmniPage 18
    "{A6B23EFA-6590-482C-A11F-5ACE1B91F5B9}" = Adobe Soundbooth CS3
    "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
    "{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.4)
    "{AF37176A-78CA-545B-34EF-8B6A21514DD1}" = Adobe Help Manager
    "{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0
    "{B8B7A4D8-80E1-4DAE-BD33-7FD535BA3931}" = Adobe Encore CS3 Codecs
    "{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}" = Adobe Default Language CS3
    "{BA67E3E1-25EE-4481-857D-D3CA99DA71C8}" = Adobe Setup
    "{BC4F8E84-5E29-49EC-B4E7-E6F9CB50986C}" = Adobe Flash Player 9 ActiveX
    "{BE5F3842-8309-4754-92D5-83E02E6077A3}" = Adobe Extension Manager CS3
    "{BFEAAE77-BD7F-4534-B286-9C5CB4697EB1}" = PDF Settings CS6
    "{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}" = Adobe ExtendScript Toolkit 2
    "{C5BD220A-EFE8-48A5-B70E-9503D535FACE}" = Adobe WAS CS3
    "{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client
    "{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}" = Adobe PDF Library Files
    "{D5A31AB1-345D-47C7-A87B-036A669F6DF1}" = Adobe XMP Panels CS3
    "{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}" = Adobe Color Common Settings
    "{DC017035-1939-425F-8F86-63B462C76C6A}" = PDF Settings
    "{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}" = Adobe Color JA Extra Settings
    "{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3
    "{EB0202F7-016A-410C-ADE4-40F848CCC661}" = Adobe After Effects CS3
    "{F08E8D2E-F132-4742-9C87-D5FF223A016A}" = Adobe Illustrator CS3
    "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
    "{F1D93F5B-881F-49E3-BA56-B4B8FA991059}" = Adobe Encore CS3 Library
    "{FE23D063-934D-4829-A0D8-00634CE79B4A}" = Adobe AIR
    "{FFB278E6-2945-4FF0-8F3F-268CDD09FCF6}" = Adobe OnLocation CS3
    "Adobe AIR" = Adobe AIR
    "Adobe_aefc483f26b23ab60cc5653016d5017" = Add or Remove Adobe Creative Suite 3 Production Premium
    "Celtx (2.9.7)" = Celtx (2.9.7)
    "chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Help Manager
    "EPSON Scanner" = EPSON Scan
    "iLivid" = iLivid
    "InstallShield_{FFB278E6-2945-4FF0-8F3F-268CDD09FCF6}" = Adobe OnLocation CS3
    "Internet Download Manager" = Internet Download Manager
    "IsoBuster_is1" = IsoBuster 3.0
    "KLiteCodecPack_is1" = K-Lite Codec Pack 7.0.0 (Standard)
    "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.65.1.1000
    "N360" = Norton 360
    "WinPcapInst" = WinPcap 4.1.2
    "Yahoo! Companion" = Yahoo! Toolbar
    "Yahoo! SiteBuilder" = Yahoo! SiteBuilder
    "Yahoo! Software Update" = Yahoo! Software Update
    "YInstHelper" = Yahoo! Install Manager
    "ZillaTube" = ZillaTube 5.2

    ========== HKEY_USERS Uninstall List ==========

    [HKEY_USERS\S-1-5-21-2262249602-3662098830-2808129073-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "Google Chrome" = Google Chrome

    ========== Last 20 Event Log Errors ==========

    [ Application Events ]
    Error - 10/21/2012 4:17:25 AM | Computer Name = Pradeeps-PC | Source = Bonjour Service | ID = 100
    Description = Task Scheduling Error: m->NextScheduledSPRetry 12539017

    Error - 10/21/2012 4:17:41 AM | Computer Name = Pradeeps-PC | Source = Bonjour Service | ID = 100
    Description = Task Scheduling Error: Continuously busy for more than a second

    Error - 10/21/2012 4:17:41 AM | Computer Name = Pradeeps-PC | Source = Bonjour Service | ID = 100
    Description = Task Scheduling Error: m->NextScheduledEvent 12554711

    Error - 10/21/2012 4:17:41 AM | Computer Name = Pradeeps-PC | Source = Bonjour Service | ID = 100
    Description = Task Scheduling Error: m->NextScheduledSPRetry 12554711

    Error - 10/21/2012 4:21:01 AM | Computer Name = Pradeeps-PC | Source = WinMgmt | ID = 10
    Description =

    Error - 10/21/2012 11:26:40 AM | Computer Name = Pradeeps-PC | Source = Bonjour Service | ID = 100
    Description = Task Scheduling Error: Continuously busy for more than a second

    Error - 10/21/2012 11:59:11 AM | Computer Name = Pradeeps-PC | Source = Bonjour Service | ID = 100
    Description = Task Scheduling Error: m->NextScheduledEvent 15819

    Error - 10/21/2012 11:59:11 AM | Computer Name = Pradeeps-PC | Source = Bonjour Service | ID = 100
    Description = Task Scheduling Error: m->NextScheduledSPRetry 15819

    Error - 10/21/2012 12:27:03 PM | Computer Name = Pradeeps-PC | Source = WinMgmt | ID = 10
    Description =

    Error - 10/21/2012 7:27:18 PM | Computer Name = Pradeeps-PC | Source = WinMgmt | ID = 10
    Description =

    [ System Events ]
    Error - 10/21/2012 12:48:45 AM | Computer Name = Pradeeps-PC | Source = Microsoft-Windows-HAL | ID = 12
    Description = The platform firmware has corrupted memory across the previous system
    power transition. Please check for updated firmware for your system.

    Error - 10/21/2012 4:49:49 AM | Computer Name = Pradeeps-PC | Source = Microsoft-Windows-HAL | ID = 12
    Description = The platform firmware has corrupted memory across the previous system
    power transition. Please check for updated firmware for your system.

    Error - 10/21/2012 12:18:33 PM | Computer Name = Pradeeps-PC | Source = Service Control Manager | ID = 7030
    Description = The PEVSystemStart service is marked as an interactive service. However,
    the system is configured to not allow interactive services. This service may not
    function properly.

    Error - 10/21/2012 12:21:47 PM | Computer Name = Pradeeps-PC | Source = Application Popup | ID = 1060
    Description = \??\C:\ComboFix\catchme.sys has been blocked from loading due to incompatibility
    with this system. Please contact your software vendor for a compatible version
    of the driver.

    Error - 10/21/2012 12:22:43 PM | Computer Name = Pradeeps-PC | Source = Service Control Manager | ID = 7030
    Description = The PEVSystemStart service is marked as an interactive service. However,
    the system is configured to not allow interactive services. This service may not
    function properly.

    Error - 10/21/2012 12:23:00 PM | Computer Name = Pradeeps-PC | Source = Service Control Manager | ID = 7030
    Description = The PEVSystemStart service is marked as an interactive service. However,
    the system is configured to not allow interactive services. This service may not
    function properly.

    Error - 10/21/2012 1:21:12 PM | Computer Name = Pradeeps-PC | Source = Microsoft-Windows-HAL | ID = 12
    Description = The platform firmware has corrupted memory across the previous system
    power transition. Please check for updated firmware for your system.

    Error - 10/21/2012 4:09:41 PM | Computer Name = Pradeeps-PC | Source = bowser | ID = 8003
    Description =

    Error - 10/21/2012 4:33:38 PM | Computer Name = Pradeeps-PC | Source = bowser | ID = 8003
    Description =

    Error - 10/21/2012 7:26:58 PM | Computer Name = Pradeeps-PC | Source = bowser | ID = 8003
    Description =


    < End of report >
  3. Broni

    Broni Malware Annihilator Posts: 45,217   +243

    Run OTL
    • Under the Custom Scans/Fixes box at the bottom, paste in the following

      Code:
      :OTL
      [2012/05/04 18:12:51 | 000,000,006 | -HS- | C] () -- C:\Users\Pradeep\AppData\Roaming\date
      [2012/05/04 18:12:40 | 000,000,002 | -HS- | C] () -- C:\Users\Pradeep\AppData\Roaming\evf9
      [2009/07/13 23:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
      
      [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
      
      [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
      
      [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
      
      [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
      
      [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
      "" = C:\Windows\SysNative\shell32.dll -- [2012/06/09 00:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
      "ThreadingModel" = Apartment
      
      [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
      "" = %SystemRoot%\system32\shell32.dll -- [2012/06/08 23:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
      "ThreadingModel" = Apartment
      
      [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
      "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 20:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
      "ThreadingModel" = Free
      
      [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
      "" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 22:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
      "ThreadingModel" = Free
      
      [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
      "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 20:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
      "ThreadingModel" = Both
      
      [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
      @Alternate Data Stream - 218 bytes -> C:\ProgramData\TEMP:A303874F
      
      :Services
      
      :Reg
      
      :Files
      
      :Commands
      [purity]
      [emptytemp]
      [emptyjava]
      [emptyflash]
      [Reboot]
      
    • Then click the Run Fix button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • You will get a log that shows the results of the fix. Please post it.

    NOTE. If for any reason OTL stalls (most likely at "killing processes..." step) run the fix from safe mode.

    ==================================

    Last scans....

    1. Download Security Check from HERE, and save it to your Desktop.
    • Double-click SecurityCheck.exe
    • Follow the onscreen instructions inside of the black box.
    • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

      NOTE SecurityCheck may produce some false warning(s), so leave the results reading to me.

    2. Please download Farbar Service Scanner (FSS) and run it on the computer with the issue.
    • Make sure the following options are checked:
      • Internet Services
      • Windows Firewall
      • System Restore
      • Security Center
      • Windows Update
      • Windows Defender
    • Press "Scan".
    • It will create a log (FSS.txt) in the same directory the tool is run.
    • Please copy and paste the log to your reply.

    3. Please download AdwCleaner by Xplode onto your desktop.
    • Close all open programs and internet browsers.
    • Double click on adwcleaner.exe to run the tool.
    • Click on Delete.
    • Confirm each time with Ok.
    • Your computer will be rebooted automatically. A text file will open after the restart.
    • Please post the contents of that logfile with your next reply.
    • You can find the logfile at C:\AdwCleaner[S1].txt as well.

    Next...

    • Double click on adwcleaner.exe to run the tool.
    • Click on Uninstall.
    • Confirm with yes.

    4. Download Temp File Cleaner (TFC)
    Alternate download: http://www.itxassociates.com/OT-Tools/TFC.exe
    • Double click on TFC.exe to run the program.
    • Click on Start button to begin cleaning process.
    • TFC will close all running programs, and it may ask you to restart computer.

    5. Please run a free online scan with the ESET Online Scanner

    • Disable your antivirus program
    • Tick the box next to YES, I accept the Terms of Use
    • Click Start
    • Accept any security warnings from your browser.
    • Check Scan archives
    • Click Start
    • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    • When the scan completes, click on List of found threats
    • Click on Export to text file , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
    • NOTE. If Eset won't find any threats, it won't produce any log.
  4. Pete26

    Pete26 Newcomer, in training Topic Starter Posts: 30

    OTL Fix Log attached below. Rest will post tomorrow.

    All processes killed
    ========== OTL ==========
    C:\Users\Pradeep\AppData\Roaming\date moved successfully.
    C:\Users\Pradeep\AppData\Roaming\evf9 moved successfully.
    C:\Windows\assembly\Desktop.ini moved successfully.
    File EY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 not found.
    File EY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] not found.
    File EY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64 not found.
    File EY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] not found.
    File EY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 not found.
    File EY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] not found.
    Folder EY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64\ not found.
    Folder EY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]\ not found.
    Folder EY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64\ not found.
    Folder EY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]\ not found.
    ADS C:\ProgramData\TEMP:A303874F deleted successfully.
    ========== SERVICES/DRIVERS ==========
    ========== REGISTRY ==========
    ========== FILES ==========
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: All Users

    User: Default
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 56475 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: Pradeep
    ->Temp folder emptied: 71931 bytes
    ->Temporary Internet Files folder emptied: 70991391 bytes
    ->Java cache emptied: 1619280 bytes
    ->Google Chrome cache emptied: 47369126 bytes
    ->Flash cache emptied: 57353 bytes

    User: Public
    ->Temp folder emptied: 0 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32 (64bit) .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 698 bytes
    %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 36030824 bytes
    RecycleBin emptied: 0 bytes

    Total Files Cleaned = 149.00 mb


    [EMPTYJAVA]

    User: All Users

    User: Default

    User: Default User

    User: Pradeep
    ->Java cache emptied: 0 bytes

    User: Public

    Total Java Files Cleaned = 0.00 mb


    [EMPTYFLASH]

    User: All Users

    User: Default
    ->Flash cache emptied: 0 bytes

    User: Default User
    ->Flash cache emptied: 0 bytes

    User: Pradeep
    ->Flash cache emptied: 0 bytes

    User: Public

    Total Flash Files Cleaned = 0.00 mb


    OTL by OldTimer - Version 3.2.69.0 log created on 10212012_233021
    Files\Folders moved on Reboot...
    File\Folder C:\Users\Pradeep\AppData\Local\Temp\Low\~DF3F48A6596742BC29.TMP not found!
    File\Folder C:\Users\Pradeep\AppData\Local\Temp\Low\~DF74E1A83E4B1580FB.TMP not found!
    C:\Users\Pradeep\AppData\Local\Temp\Low\~DFB74B12916334CD2F.TMP moved successfully.
    C:\Users\Pradeep\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZQ8GHCB0\B6957617[1].htm moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZQ8GHCB0\ping[3].js moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZQ8GHCB0\ping[4].js moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZQ8GHCB0\rt[3].js moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZQ8GHCB0\r[2].js moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\NB25QDD0\918[2].htm moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\NB25QDD0\page-2[1].htm moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\NB25QDD0\ping[3].js moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\NB25QDD0\ping[4].js moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\NB25QDD0\rt[3].js moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\NB25QDD0\rt[4].js moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BMNPX4HS\billboard[1].htm moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BMNPX4HS\partner[2].htm moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BMNPX4HS\partner[3].htm moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BMNPX4HS\ping[4].js moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BMNPX4HS\rsa[1].htm moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BMNPX4HS\rt[6].js moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BMNPX4HS\r[1].js moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\93OH316V\net[2].htm moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\93OH316V\ptj[3].js moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\93OH316V\rt[6].js moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\ED8654D5-B9F0-4DD9-B3E8-F8F560086FDF.dat moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\MSIMGSIZ.DAT moved successfully.
    PendingFileRenameOperations files...
    Registry entries deleted on Reboot...
  5. Pete26

    Pete26 Newcomer, in training Topic Starter Posts: 30

    Results of screen317's Security Check version 0.99.53
    Windows 7 Service Pack 1 x64 (UAC is enabled)
    Internet Explorer 9
    ``````````````Antivirus/Firewall Check:``````````````
    Windows Firewall Enabled!
    Norton 360
    WMI entry may not exist for antivirus; attempting automatic update.
    `````````Anti-malware/Other Utilities Check:`````````
    Malwarebytes Anti-Malware version 1.65.1.1000
    Java(TM) 6 Update 7
    Java version out of Date!
    Adobe Flash Player 9 Flash Player out of Date!
    Adobe Reader X (10.1.4)
    Google Chrome 21.0.1180.83
    Google Chrome 21.0.1180.89
    Google Chrome 22.0.1229.79
    Google Chrome 22.0.1229.92
    Google Chrome 22.0.1229.94
    ````````Process Check: objlist.exe by Laurent````````
    Norton ccSvcHst.exe
    `````````````````System Health check`````````````````
    Total Fragmentation on Drive C: 7%
    ````````````````````End of Log``````````````````````
  6. Pete26

    Pete26 Newcomer, in training Topic Starter Posts: 30

    Farbar Service Scanner Version: 19-10-2012
    Ran by Pradeep (administrator) on 22-10-2012 at 07:15:20
    Running from "C:\Users\Pradeep\Desktop"
    Microsoft Windows 7 Ultimate Service Pack 1 (X64)
    Boot Mode: Normal
    ****************************************************************
    Internet Services:
    ============
    Connection Status:
    ==============
    Localhost is accessible.
    LAN connected.
    Google IP is accessible.
    Google.com is accessible.
    Yahoo IP is accessible.
    Yahoo.com is accessible.

    Windows Firewall:
    =============
    Firewall Disabled Policy:
    ==================

    System Restore:
    ============
    System Restore Disabled Policy:
    ========================

    Action Center:
    ============
    Windows Update:
    ============
    Windows Autoupdate Disabled Policy:
    ============================

    Windows Defender:
    ==============
    WinDefend Service is not running. Checking service configuration:
    The start type of WinDefend service is set to Demand. The default start type is Auto.
    The ImagePath of WinDefend service is OK.
    The ServiceDll of WinDefend service is OK.

    Windows Defender Disabled Policy:
    ==========================
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
    "DisableAntiSpyware"=DWORD:1

    Other Services:
    ==============

    File Check:
    ========
    C:\Windows\System32\nsisvc.dll => MD5 is legit
    C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
    C:\Windows\System32\dhcpcore.dll => MD5 is legit
    C:\Windows\System32\drivers\afd.sys => MD5 is legit
    C:\Windows\System32\drivers\tdx.sys => MD5 is legit
    C:\Windows\System32\Drivers\tcpip.sys => MD5 is legit
    C:\Windows\System32\dnsrslvr.dll => MD5 is legit
    C:\Windows\System32\mpssvc.dll => MD5 is legit
    C:\Windows\System32\bfe.dll => MD5 is legit
    C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit
    C:\Windows\System32\SDRSVC.dll => MD5 is legit
    C:\Windows\System32\vssvc.exe => MD5 is legit
    C:\Windows\System32\wscsvc.dll => MD5 is legit
    C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit
    C:\Windows\System32\wuaueng.dll => MD5 is legit
    C:\Windows\System32\qmgr.dll => MD5 is legit
    C:\Windows\System32\es.dll => MD5 is legit
    C:\Windows\System32\cryptsvc.dll => MD5 is legit
    C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
    C:\Windows\System32\svchost.exe => MD5 is legit
    C:\Windows\System32\rpcss.dll => MD5 is legit

    **** End of log ****
  7. Pete26

    Pete26 Newcomer, in training Topic Starter Posts: 30

    # AdwCleaner v2.005 - Logfile created 10/22/2012 at 07:21:34
    # Updated 14/10/2012 by Xplode
    # Operating system : Windows 7 Ultimate Service Pack 1 (64 bits)
    # User : Pradeep - PRADEEPS-PC
    # Boot Mode : Normal
    # Running from : C:\Users\Pradeep\Desktop\adwcleaner.exe
    # Option [Delete]

    ***** [Services] *****

    ***** [Files / Folders] *****
    Folder Deleted : C:\Program Files (x86)\Free Offers from Freeze.com
    Folder Deleted : C:\ProgramData\{B49A644A-1076-4A3D-B124-DAA7862F2318}
    Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ilivid
    Folder Deleted : C:\Users\Pradeep\AppData\Local\Ilivid Player
    ***** [Registry] *****
    Key Deleted : HKCU\Software\ilivid
    Key Deleted : HKCU\Software\Softonic
    Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
    Key Deleted : HKLM\Software\Freeze.com
    Key Deleted : HKLM\Software\ilivid
    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SetupDataMngr_Searchqu_RASAPI32
    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SetupDataMngr_Searchqu_RASMANCS
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ilivid
    Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
    ***** [Internet Browsers] *****
    -\\ Internet Explorer v9.0.8112.16421
    [OK] Registry is clean.
    -\\ Google Chrome v22.0.1229.94
    File : C:\Users\Pradeep\AppData\Local\Google\Chrome\User Data\Default\Preferences
    [OK] File is clean.
    *************************
    AdwCleaner[S1].txt - [1685 octets] - [22/10/2012 07:21:35]
    ########## EOF - C:\AdwCleaner[S1].txt - [1745 octets] ##########
  8. Pete26

    Pete26 Newcomer, in training Topic Starter Posts: 30

    TFC cleaner was run as per your instructions and ran successfully.

    Getting "cannot get updates. Is proxy configured?" message when trying to run ESET Online Scanner and it will not progress further. Please advise...
  9. Broni

    Broni Malware Annihilator Posts: 45,217   +243

    Try different browser.
  10. Pete26

    Pete26 Newcomer, in training Topic Starter Posts: 30

    Ran ESET through Google Chrome. haa...it took a lot of time. Attached below is the log.

    C:\Qoobox\Quarantine\C\Users\Pradeep\Videos\iLividSetupV1.exe.vir Win32/Toolbar.SearchSuite application cleaned by deleting - quarantined
    C:\TDSSKiller_Quarantine\20.10.2012_17.56.15\mbr0000\tdlfs0000\tsk0000.dta a variant of Win32/Olmarik.AYI trojan cleaned by deleting - quarantined
    C:\TDSSKiller_Quarantine\20.10.2012_17.56.15\mbr0000\tdlfs0000\tsk0001.dta a variant of Win64/Olmarik.AM trojan cleaned by deleting - quarantined
    C:\TDSSKiller_Quarantine\20.10.2012_17.56.15\mbr0000\tdlfs0000\tsk0004.dta a variant of Win32/Rootkit.Kryptik.OX trojan cleaned by deleting - quarantined
    C:\TDSSKiller_Quarantine\20.10.2012_17.56.15\mbr0000\tdlfs0000\tsk0005.dta Win64/Olmarik.AN trojan cleaned by deleting - quarantined
    C:\TDSSKiller_Quarantine\20.10.2012_17.56.15\mbr0000\tdlfs0000\tsk0009.dta Win32/Olmarik.AFK trojan cleaned by deleting - quarantined
    C:\TDSSKiller_Quarantine\20.10.2012_17.56.15\mbr0000\tdlfs0000\tsk0010.dta Win64/Olmarik.AK trojan cleaned by deleting - quarantined
    C:\Users\Pradeep\Videos\utorrent_movies_download_jatt_and_juliet_720rip_hd.exe Win32/BundleInstaller application cleaned by deleting - quarantined
  11. Broni

    Broni Malware Annihilator Posts: 45,217   +243

    Update Adobe Flash Player
    Download the Latest Adobe Flash for Firefox and IE Without Any Extras: http://www.404techsupport.com/2010/...-flash-for-firefox-and-ie-without-any-extras/

    ==============================

    1. Update your Java version here: http://www.java.com/en/download/installed.jsp

    Note 1: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

    Note 2: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. If you don't want to run another extra service, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and restart your computer.

    2. Now, we need to remove old Java version and its remnants...

    Download JavaRa to your desktop and unzip it.
    • Run JavaRa.exe (Vista users! Right click on JavaRa.exe, click Run As Administrator), pick the language of your choice and click Select. Then click Remove Older Versions.
    • Accept any prompts.
    • Do NOT post JavaRa log.

    ================================

    Your computer is clean [​IMG]

    1. We need to reset system restore to prevent your computer from being accidentally reinfected by using some old restore point(s). We'll create fresh, clean restore point, using following OTL script:

    Run OTL

    • Under the Custom Scans/Fixes box at the bottom, paste in the following:

    Code:
    :OTL
    :Commands
    [purity]
    [emptytemp]
    [EMPTYFLASH]
    [emptyjava]
    [CLEARALLRESTOREPOINTS]
    [Reboot]
    • Then click the Run Fix button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • Post resulting log.

    2. Now, we'll remove all tools, we used during our cleaning process

    Clean up with OTL:

    • Double-click OTL.exe to start the program.
    • Close all other programs apart from OTL as this step will require a reboot
    • On the OTL main screen, press the CLEANUP button
    • Say Yes to the prompt and then allow the program to reboot your computer.

    If you still have any tools or logs leftover on your computer you can go ahead and delete those off of your computer now.

    3. Make sure, Windows Updates are current.

    4. If any trojans, rootkits or bootkits were listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately!

    5. Download, and install WOT (Web OF Trust): http://www.mywot.com/. It'll warn you (in most cases) about dangerous web sites.

    6. Run Malwarebytes "Quick scan" once in a while to assure safety of your computer.

    7. Run Temporary File Cleaner (TFC) weekly.

    8. Download and install Secunia Personal Software Inspector (PSI): http://secunia.com/vulnerability_scanning/personal/. The Secunia PSI is a FREE security tool designed to detect vulnerable and out-dated programs and plug-ins which expose your PC to attacks. Run it weekly.

    9. (optional) If you want to keep all your programs up to date, download and install FileHippo Update Checker.
    The Update Checker will scan your computer for installed software, check the versions and then send this information to FileHippo.com to see if there are any newer releases.

    10. (Windows XP only) Run defrag at your convenience.

    11. When installing\updating ANY program, make sure you always select "Custom " installation, so you can UN-check any possible "drive-by-install" (foistware), like toolbars etc., which may try to install along with the legitimate program. Do NOT click "Next" button without looking at any given page.

    12. Read:
    How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html
    Simple and easy ways to keep your computer safe and secure on the Internet: http://www.bleepingcomputer.com/tutorials/keep-your-computer-safe-online/

    13. Please, let me know, how your computer is doing.
  12. Pete26

    Pete26 Newcomer, in training Topic Starter Posts: 30

    All processes killed
    ========== OTL ==========
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: All Users

    User: Default
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: Pradeep
    ->Temp folder emptied: 1534824 bytes
    ->Temporary Internet Files folder emptied: 18689110 bytes
    ->Java cache emptied: 1834 bytes
    ->Google Chrome cache emptied: 10817978 bytes
    ->Flash cache emptied: 492 bytes

    User: Public
    ->Temp folder emptied: 0 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32 (64bit) .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 1396 bytes
    %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 0 bytes
    RecycleBin emptied: 0 bytes

    Total Files Cleaned = 30.00 mb


    [EMPTYFLASH]

    User: All Users

    User: Default
    ->Flash cache emptied: 0 bytes

    User: Default User
    ->Flash cache emptied: 0 bytes

    User: Pradeep
    ->Flash cache emptied: 0 bytes

    User: Public

    Total Flash Files Cleaned = 0.00 mb


    [EMPTYJAVA]

    User: All Users

    User: Default

    User: Default User

    User: Pradeep
    ->Java cache emptied: 0 bytes

    User: Public

    Total Java Files Cleaned = 0.00 mb

    Restore point Set: OTL Restore Point

    OTL by OldTimer - Version 3.2.69.0 log created on 10232012_183706
    Files\Folders moved on Reboot...
    C:\Users\Pradeep\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
    C:\Users\Pradeep\AppData\Local\Temp\~DFF4E1B5BE58939583.TMP moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\ED8654D5-B9F0-4DD9-B3E8-F8F560086FDF.dat moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YDLD95JN\aclk[1].htm moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YDLD95JN\aclk[2].htm moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YDLD95JN\ping[1].js moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YDLD95JN\rt[1].js moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RS63WKKE\billboard[1].htm moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RS63WKKE\DocumentDotWrite[1].js moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RS63WKKE\net[1].htm moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RS63WKKE\page-2[1].htm moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RS63WKKE\ping[1].js moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RS63WKKE\ptj[1].js moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RS63WKKE\rt[1].js moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RS63WKKE\sta[1].htm moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R871FJRA\91[1].js moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R871FJRA\partner[1].htm moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R871FJRA\partner[2].htm moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R871FJRA\ping[1].js moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R871FJRA\ping[2].js moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R871FJRA\rt[1].js moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R871FJRA\rt[2].js moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R871FJRA\r[1].js moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R871FJRA\sta[1].htm moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R871FJRA\sta[2].htm moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\N17MP8D1\bizo_multi[1].htm moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\N17MP8D1\ptj[1].js moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\N17MP8D1\rsa[1].htm moved successfully.
    C:\Users\Pradeep\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\N17MP8D1\sta[1].htm moved successfully.
    PendingFileRenameOperations files...
    Registry entries deleted on Reboot...
  13. Pete26

    Pete26 Newcomer, in training Topic Starter Posts: 30

    Hi there,
    Just wanted to provide you with an update on the macine.
    It is running perfectly fine now. No issues...
    Thanks for all your help!! You guys simply rock!!

    One small question: when trying to download WOT, I am getting the error message that it can be installed on IE vesion 6.0 or later. I have IE 9.0, not sure why this message is coming...
     
  14. Broni

    Broni Malware Annihilator Posts: 45,217   +243

    It won't let you install it?
  15. Pete26

    Pete26 Newcomer, in training Topic Starter Posts: 30

    Correct...it would just give an error message that the set up has ended prematurely due to an error.
  16. Broni

    Broni Malware Annihilator Posts: 45,217   +243

    Are you accessing WOT site with IE?
  17. Pete26

    Pete26 Newcomer, in training Topic Starter Posts: 30

    I downloaded WOT installer package on the desktop and trying to install it from there.
  18. Broni

    Broni Malware Annihilator Posts: 45,217   +243

  19. Broni

    Broni Malware Annihilator Posts: 45,217   +243

    The issue seems to be resolved.


Add New Comment

TechSpot Members
Login or sign up for free,
it takes about 30 seconds.
You may also...


Get complete access to the TechSpot community. Join thousands of technology enthusiasts that contribute and share knowledge in our forum. Get a private inbox, upload your own photo gallery and more.